Posts

Showing posts with the label dns

Hacking CronOS (htb)

Image
  As usual, we start with an nmap scan - in this case, we find ports 22, 53 and 80 open.     Seeing port 53 over tcp is interesting since port 53 over udp is used to make dns inquiries. dns uses tcp port 53 for zone transfers and it is always useful to enumerate dns to widen attack surfaces - for example find subdomains to attack. Before attempting a zone transfer, I thought I would have a go at manually enumerating dns with the intention of trying to find interesting subdomains. I started by trying a reverse dns lookup using the dig tool. When it comes to dns records, some will have a ptr record which is where the reverse dns request looks. The ptr record just maps an ipv4 address to a domain name so we can find the domain name by specifying the ipv4 address. This is the opposite of how dns requests are usually made - usually a domain is specified and the ipv4 address is returned from the a record. In the dig command seen in the picture below, the @ symbol lets us specif...

Enumerating DNS Servers

Image
The goal of this lab on ine   was to enumerate the DNS server to discover as much as possible about the domain witrap.com In my other (first) post about enumerating DNS servers (Information Gathering Lab) I mentioned that I would show how we can brute-force subdomains and look for machines which only respond to reverse DNS lookups. These techniques are covered in this post. My first job was to find out more about the network my attacking machine was connected to. The ip addr command revealed that it was on a /24 network 192.36.208.0/24 The IP address of the attacking machine was 192.36.208.2 I decided to start off by using nmap to perform an ICMP scan. I followed this up with a fast half-open SYN scan as sometimes ICMP traffic is blocked or dropped by firewalls. I then specifically targeted DNS servers by performing a UDP scan against port 53 and then another half-open SYN scan against port 53 but with the --source-port switch set to 53 as sometimes DNS servers will only...