{"id":444,"date":"2014-07-07T05:40:51","date_gmt":"2014-07-07T05:40:51","guid":{"rendered":"http:\/\/ixyzero.com\/blog\/?p=444"},"modified":"2014-07-07T05:40:51","modified_gmt":"2014-07-07T05:40:51","slug":"dns%e6%9e%9a%e4%b8%be-email%e4%bf%a1%e6%81%af%e6%90%9c%e9%9b%86","status":"publish","type":"post","link":"https:\/\/ixyzero.com\/blog\/archives\/444.html","title":{"rendered":"DNS\u679a\u4e3e-Email\u4fe1\u606f\u641c\u96c6"},"content":{"rendered":"<p style=\"color: #454545;\">\u4e4b\u524d\u5728\u6d4b\u8bd5DNS\u57df\u4f20\u9001\u6f0f\u6d1e\u65f6\u8bb0\u5f55\u7684\u5de5\u5177\u4f7f\u7528\u8bb0\u5f55\uff1a<\/p>\n<hr \/>\n<p style=\"color: #454545;\">\n<p style=\"color: #454545;\">\u4e00\u4e9b\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<ul>\n<li><a href=\"http:\/\/hi.baidu.com\/hackloft\/item\/861b4bd8870bf9ea3dc2cb9d\" target=\"_blank\">\u4f7f\u7528theHarvester\u548cMSF3\u5feb\u901f\u6709\u6548\u7684\u6536\u96c6Email\u767b\u9646\u8d26\u6237<\/a><\/li>\n<li><a href=\"http:\/\/www.freebuf.com\/tools\/7348.html\" target=\"_blank\">\u793e\u4f1a\u5de5\u7a0b\u5b66\u795e\u5668\u2014\u4fe1\u606f\u6536\u96c6\u5de5\u5177theHarvester v2.2a<\/a><\/li>\n<\/ul>\n<p style=\"color: #454545;\">\u901a\u8fc7theHarvester\u8fd9\u4e2a\u5de5\u5177\uff0c\u548cbaidu.com\u3001google.com\u7b49\u641c\u7d22\u5f15\u64ce\uff0c\u53ef\u4ee5\u6536\u96c6\u4e00\u4e9b\u516c\u53f8\u7684\u5458\u5de5\u4fe1\u606f\u3002<\/p>\n<p style=\"color: #454545;\">#\u7528Nmap\u626b\u63cf\u7684\u65f6\u5019\u53d1\u73b0\u6709\u4e2a\u63d2\u4ef6\u4e5f\u8d77\u5230\u4e86\u7c7b\u4f3c\u7684\u4f5c\u7528\uff1aNmap scripts(http-email-harvest)<\/p>\n<p style=\"color: #454545;\">\u5b9e\u9645\u6d4b\u8bd5\u4e86\u4e0a\u9762\u7684\u6587\u7ae0\u4e2d\u63d0\u5230\u7684theHarvest\u548cMetasploit\u4e2d\u7684\u90a3\u4e2aRuby\u811a\u672c\uff0c\u4f46\u662f\u90fd\u6ca1\u7528\u4e86\u73b0\u5728\uff08\u6211\u4e4b\u524d\u4e5f\u5f04\u8fc7\u4e00\u6b21\u4e5f\u6ca1\u4ec0\u4e48\u6548\u679c\uff0c\u96be\u9053\u662fGoogle\u5c4f\u853d\u4e86\u8fd8\u662f\u516c\u53f8\u7f51\u5740\u4e0a\u6ca1\u6709\u4ec0\u4e48Email\u4fe1\u606f\u4e86\uff1f\uff09<\/p>\n<p style=\"color: #454545;\">\u4e0d\u8fc7\u53ef\u4ee5\u8bd5\u8bd5Nmap\uff1a<\/p>\n<p style=\"color: #454545;\">root@xxx:~ # nmap -sV -p 80 -T4 &#8211;script http*,default targetIP\/targetWebsite<\/p>\n<p style=\"color: #454545;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n<p style=\"color: #454545;\">\u521a\u521a\u53c8\u53d1\u73b0\u4e86\u4e00\u4e2aDNS\u4fe1\u606f\u641c\u96c6\u7684\u5de5\u5177\uff0c\u8fd8\u662f\u5728\u7ebf\u7684\uff1a<\/p>\n<p style=\"color: #454545;\">Sitedossier &#8211; profiles for millions of sites on the web <a href=\"http:\/\/www.sitedossier.com\/\" target=\"_blank\">http:\/\/www.sitedossier.com\/<\/a><\/p>\n<ul>\n<li>\u5de5\u5177\uff1afierce<\/li>\n<\/ul>\n<p style=\"color: #454545;\">\u6027\u8d28\u8ddfdnsmap\/dnsenum\u5dee\u4e0d\u591a\uff0c\u5c31\u662f\u4e00\u5b50\u57df\u540d\u626b\u63cf\u3001\u4fe1\u606f\u641c\u96c6\u5de5\u5177\uff08\u4f46\u4e0d\u77e5\u9053\u600e\u4e48\u7684\uff0c\u5f88\u591a\u7684\u5de5\u5177\u73b0\u5728\u57fa\u672c\u6ca1\u4ec0\u4e48\u5b9e\u9645\u6548\u7528\uff0c\u96be\u9053\u662fGoogle\u8fd9\u4e9b\u628a\u8fd9\u4e2a\u90fd\u5c4f\u853d\u6389\u4e86\uff1f\uff09<\/p>\n<p style=\"color: #454545;\">\u7f51\u5740\uff1aFierce Domain Scan <a href=\"http:\/\/ha.ckers.org\/fierce\/\" target=\"_blank\">http:\/\/ha.ckers.org\/fierce\/<\/a><\/p>\n<ul>\n<li>\u5de5\u5177\uff1adnsmap<\/li>\n<\/ul>\n<p style=\"color: #454545;\">\u7f51\u5740\uff1a<a href=\"http:\/\/code.google.com\/p\/dnsmap\/\" target=\"_blank\">http:\/\/code.google.com\/p\/dnsmap\/<\/a><\/p>\n<ul>\n<li>\u5de5\u5177\uff1adnsenum<\/li>\n<\/ul>\n<p style=\"color: #454545;\">\u7f51\u5740\uff1a<a href=\"http:\/\/code.google.com\/p\/dnsenum\/\" target=\"_blank\">http:\/\/code.google.com\/p\/dnsenum\/<\/a><\/p>\n<p style=\"color: #454545;\">\u521a\u624d\u5206\u522b\u5728Kali Linux\u4e0a\u90fd\u4f7f\u7528\u4e86\u4e00\u4e0b\u8fd93\u6b3eDNS\u4fe1\u606f\u641c\u96c6\u7684\u5de5\u5177\uff0c\u4e2a\u4eba\u4f7f\u7528\u611f\u53d7\u5982\u4e0b\uff1a<\/p>\n<p style=\"color: #454545;\">dnsenum\u8fd9\u4e2a\u901f\u5ea6\u6700\u5feb\uff0c\u800c\u4e14\u4e5f\u6709\u4e2a\u5206\u7c7b\uff0c\u8fd9\u4e2a\u4f7f\u7528\u8d77\u6765\u8fd8\u4e0d\u9519\uff08\u4f46\u662f\u901f\u5ea6\u662f\u4e0d\u662f\u592a\u5feb\u4e86\uff1f\u5bfc\u81f4\u6211\u5bf9\u5168\u9762\u6027\u548c\u51c6\u786e\u6027\u90fd\u6709\u4e9b\u6000\u7591\u4e86\uff09\uff1b<\/p>\n<p style=\"color: #454545;\">dnsmap\u548cfierce\u8fd9\u4e24\u4e2a\u90fd\u5f88\u6162\uff0c\u4e0d\u8fc7\u6162\u7684\u597d\u5904\u5c31\u662f\u641c\u96c6\u5230\u7684\u4e1c\u897f\u591a\uff0c\u5728\u4f7f\u7528\u7684\u65b9\u4fbf\u7a0b\u5ea6\u4e0a\u9762\uff0c\u6211\u8fd8\u662f\u89c9\u5f97dnsmap\u8fd9\u8981\u6bd4fierce\u8981\u597d\uff0c\u4e00\u4e2a\u662f\u76f4\u63a5\uff0c\u518d\u4e00\u4e2a\u5c31\u662ffierce\u8fd9\u8fd8\u9700\u8981\u540c\u65f6\u63d0\u4f9bhosts.txt\u6587\u4ef6\uff0c\u7565\u663e\u9ebb\u70e6\u3002\uff08PS:fierce\u8fd9\u4e2a\u5de5\u5177\u5728\u78b0\u5230\u6bd4\u8f83\u5c11\u89c1\u7684\u57df\u540d\u65f6\uff0c\u90a3\u901f\u5ea6\u771f\u7684\u4e0d\u662f\u4e00\u822c\u7684\u6162\uff0c\u800c\u4e14\u8fde\u4e2a\u8fdb\u5ea6\u90fd\u6ca1\u6709\uff0c\u8ba9\u4eba\u7b49\u7684\u63ea\u5fc3\u554a\uff01PS2:\u624d\u53d1\u73b0\uff0c\u539f\u6765fierce\u53ef\u4ee5\u6307\u5b9athread\u9009\u9879\u4ee5\u63d0\u9ad8\u901f\u5ea6\uff09<\/p>\n<p style=\"color: #454545;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;\u6d4b\u8bd5\u5982\u4e0b&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n<p style=\"color: #454545;\"><strong><span style=\"color: #ff0000;\">root@xxx:~# dnsenum baidu.com<\/span><\/strong><\/p>\n<p style=\"color: #454545;\">dnsenum.pl VERSION:1.2.2<br \/>\n&#8230;&#8230;<\/p>\n<p style=\"color: #454545;\"><strong><span style=\"color: #ff0000;\">root@xxx:~# dnsmap baidu.com<\/span><\/strong><\/p>\n<p style=\"color: #454545;\">dnsmap 0.30 &#8211; DNS Network Mapper by pagvac (gnucitizen.org)<br \/>\n[+] searching (sub)domains for baidu.com using built-in wordlist<br \/>\n[+] using maximum random delay of 10 millisecond(s) between requests<br \/>\na.baidu.com<br \/>\nIP address #1: 123.125.114.38<br \/>\nab.baidu.com<br \/>\nIP address #1: 10.26.209.25<br \/>\n[+] warning: internal IP address disclosed<br \/>\naccounts.baidu.com<br \/>\nIP address #1: 10.11.252.74<br \/>\n[+] warning: internal IP address disclosed #dnsmap\u8fd8\u4f1a\u68c0\u6d4b\u5185\u90e8IP\u5730\u5740\u662f\u5426\u5b58\u5728\u6cc4\u6f0f\u7684\u95ee\u9898<br \/>\nad.baidu.com<br \/>\nIP address #1: 202.108.23.200<br \/>\n\u2026\u2026\u2026\u2026\u2026\u2026<br \/>\n250 (sub)domains and 290 IP address(es) found #dnsmap\u662f\u6700\u6162\u7684\uff0c\u4e0d\u8fc7\u68c0\u67e5\u51fa\u6765\u7684\u4e1c\u897f\u662f\u6700\u591a\u7684\uff0c\u800c\u4e14\u5728\u6700\u540e\u4f1a\u7ed9\u51fa\u4e00\u4e9b\u626b\u63cf\u4fe1\u606f\u51fa\u6765<br \/>\n[+] 89 internal IP address(es) disclosed<br \/>\n[+] completion time: 1298 second(s)<\/p>\n<p style=\"color: #454545;\"><span style=\"color: rgb(255, 0, 0);\">root@xxx:~\/Desktop# <strong>.\/fierce.pl baidu.com #\u8fd8\u5f97\u52a0\u4e0a\u4e2a\u201c-dns\u201d\u9009\u9879<\/strong><\/span><br \/>\nYou have to use the -dns switch with a domain after it.<br \/>\nType: perl fierce.pl -h for help<br \/>\nExiting&#8230;<br \/>\n<span style=\"color: rgb(255, 0, 0);\">root@xxx:~\/Desktop# <strong>.\/fierce.pl -dns baidu.com<\/strong><\/span><br \/>\nDNS Servers for baidu.com:<br \/>\nns3.baidu.com<br \/>\nns7.baidu.com<br \/>\nns2.baidu.com<br \/>\nns4.baidu.com<br \/>\ndns.baidu.com<br \/>\nTrying zone transfer first&#8230;<br \/>\nTesting ns3.baidu.com<br \/>\nRequest timed out or transfer not allowed.<br \/>\nTesting ns7.baidu.com<br \/>\nRequest timed out or transfer not allowed.<br \/>\nTesting ns2.baidu.com<br \/>\nRequest timed out or transfer not allowed.<br \/>\nTesting ns4.baidu.com<br \/>\nRequest timed out or transfer not allowed.<br \/>\nTesting dns.baidu.com<br \/>\nRequest timed out or transfer not allowed.<br \/>\nUnsuccessful in zone transfer (it was worth a shot) #\u9996\u5148\uff0cfierce\u4f1a\u5c1d\u8bd5\u57df\u4f20\u9001\u6f0f\u6d1e\u7684\u68c0\u6d4b<br \/>\nOkay, trying the good old fashioned way&#8230; brute force<br \/>\nChecking for wildcard DNS&#8230; #\u5c1d\u8bd5DNS\u7684\u901a\u914d\u7b26\u68c0\u6d4b<br \/>\nNope. Good.<br \/>\nNow performing 2280 test(s)&#8230; #\u5c1d\u8bd5\u6b21\u6570\u548c\u5b57\u5178\u6587\u4ef6\u6709\u5173<br \/>\n10.11.252.74 accounts.baidu.com<br \/>\n180.76.2.25 antivirus.baidu.com<br \/>\n&#8230;&#8230;<br \/>\n\u2026\u2026\u2026\u2026Found 118 entries.\u2026\u2026\u2026\u2026<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n\u51b3\u5b9a\u4ee5\u540e\u5c31\u4f7f\u7528dnsmap\u4f5c\u4e3a\u8fd9\u65b9\u9762\u7684\u4e3b\u529b\u5de5\u5177\u4e86\uff01<br \/>\n\/usr\/share\/dnsmap\/wordlist_TLAs.txt #17576\u884c\uff08\u5c31\u662f\u4eceaaa-zzz\uff09<br \/>\nroot@xxx:~# find \/ -name &#8220;*dnsmap*&#8221;<br \/>\n\u2026\u2026<br \/>\n\/usr\/share\/wordlists\/dnsmap.txt<br \/>\n\u2026\u2026<br \/>\n<strong><span style=\"color: #ff0000;\">\u6ce8\u610f\u4e00\u4e0bKali Linux\u4e0b\u7684\u8fd9\u4e2a\u6587\u4ef6\u5939\uff1a\/usr\/share\/wordlists<\/span><\/strong><br \/>\nroot@xxx:\/usr\/share\/wordlists# ll<br \/>\n\u603b\u7528\u91cf 52128<br \/>\ndrwxr-xr-x \u00a0 2 root root \u00a0 \u00a0 4096 \u00a09\u6708 29 14:19 .<br \/>\ndrwxr-xr-x 464 root root \u00a0 \u00a016384 11\u6708 17 18:57 ..<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 25 \u00a09\u6708 29 14:19 dirb -&gt; \/usr\/share\/dirb\/wordlists<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 30 \u00a09\u6708 29 14:19 dirbuster -&gt; \/usr\/share\/dirbuster\/wordlists<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 35 \u00a09\u6708 29 14:19 dnsmap.txt -&gt; \/usr\/share\/dnsmap\/wordlist_TLAs.txt<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 41 \u00a09\u6708 29 14:19 fasttrack.txt -&gt; \/usr\/share\/set\/src\/fasttrack\/wordlist.txt<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 45 \u00a09\u6708 29 14:19 fern-wifi -&gt; \/usr\/share\/fern-wifi-cracker\/extras\/wordlists<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 46 \u00a09\u6708 29 14:19 metasploit -&gt; \/usr\/share\/metasploit-framework\/data\/wordlists<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 51 \u00a09\u6708 29 14:19 metasploit-jtr -&gt; \/usr\/share\/metasploit-framework\/data\/john\/wordlists<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 39 \u00a09\u6708 29 14:19 metasploit-pro -&gt; \/opt\/metasploit\/apps\/pro\/data\/wordlists<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 41 \u00a09\u6708 29 14:19 nmap.lst -&gt; \/usr\/share\/nmap\/nselib\/data\/passwords.lst<br \/>\n-rw-r&#8211;r&#8211; \u00a0 1 root root 53357341 \u00a03\u6708 \u00a03 \u00a02013 rockyou.txt.gz<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 34 \u00a09\u6708 29 14:19 sqlmap.txt -&gt; \/usr\/share\/sqlmap\/txt\/wordlist.txt<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 57 \u00a09\u6708 29 14:19 termineter.txt -&gt; \/usr\/share\/termineter\/framework\/data\/smeter_passwords.txt<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 57 \u00a09\u6708 29 14:19 w3af.txt -&gt; \/usr\/share\/w3af\/core\/controllers\/bruteforce\/passwords.txt<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 29 \u00a09\u6708 29 14:19 webslayer -&gt; \/usr\/share\/webslayer\/wordlist<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 25 \u00a09\u6708 29 14:19 wfuzz -&gt; \/usr\/share\/wfuzz\/wordlist<br \/>\nlrwxrwxrwx \u00a0 1 root root \u00a0 \u00a0 \u00a0 53 \u00a09\u6708 29 14:19 wfuzz.txt -&gt; \/usr\/share\/golismero\/wordlist\/wfuzz\/Discovery\/all.txt<\/p>\n<p style=\"color: #454545;\">\u53ef\u4ee5\u770b\u5230\u8be5\u6587\u4ef6\u5939\u4e0b\u5305\u542b\u4e86\u5f88\u591aKali Linux\u4e0b\u7684\u66b4\u529b\u7834\u89e3\u5de5\u5177\u7b49\u7684\u5b57\u5178\u6587\u4ef6\u7684\u8f6f\u94fe\u63a5\u3002\uff08\u5176\u4e2d\u8fd8\u5305\u62ec\u6211\u4e4b\u524d\u6ca1\u6709\u4f7f\u7528\u8fc7\u7684dirbuster\/fasttrack\/wfuzz\/webslayer\u7b49\u5de5\u5177\uff09<\/p>\n<p style=\"color: #454545;\">\u7136\u540e\uff0c\u6211\u67e5\u770b\u4e4b\u524d\u4f7f\u7528fierce\u5de5\u5177\u5728\u4f7f\u7528\u7684\u65f6\u5019\u81ea\u5e26\u7684hosts.txt\u6587\u4ef6\uff0c\u5176\u4e2d\u5171\u5305\u542b2280\u884c\uff0c\u4e0d\u518d\u662f\u4eceaaa-zzz\u7684\u7b80\u5355\u5b57\u7b26\u679a\u4e3e\u4e86\uff0c\u52a0\u4e0a\u4e86\u4e00\u4e9b\u6570\u5b57\u548c\u5e38\u89c1\u7684\u5b50\u57df\u540d\u524d\u7f00\uff0c\u53ef\u4ee5\u627e\u5230dnsmap\u627e\u4e0d\u5230\u7684\u4e00\u4e9b\u81ea\u5b9a\u4e49\u5b50\u57df\u540d\u4fe1\u606f\u3002<\/p>\n<p style=\"color: #454545;\">\u5bf9\u4e86\uff0c\u5728Metasploit\u6846\u67b6\u4e2d\uff0c\u4e5f\u6709\u4e0d\u5c11DNS\u4fe1\u606f\u641c\u96c6\u5de5\u5177(search dns \u5149\u662f\u4fe1\u606f\u641c\u96c6\u811a\u672c\u5c31\u67095\u4e2a)\uff0c\u53ef\u4ee5\u5c1d\u8bd5\u4e00\u4e0b\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e4b\u524d\u5728\u6d4b\u8bd5DNS\u57df\u4f20\u9001\u6f0f\u6d1e\u65f6\u8bb0\u5f55\u7684\u5de5\u5177\u4f7f\u7528\u8bb0\u5f55\uff1a \u4e00\u4e9b\u53c2\u8003\u94fe\u63a5\uff1a \u4f7f\u7528theHarvester\u548cMSF3\u5feb\u901f\u6709 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,25,12],"tags":[205,206,207,208],"class_list":["post-444","post","type-post","status-publish","format-standard","hentry","category-linux","category-security","category-tools","tag-dns","tag-dnsenum","tag-dnsmap","tag-fierce"],"views":8323,"_links":{"self":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/comments?post=444"}],"version-history":[{"count":0,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/444\/revisions"}],"wp:attachment":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/media?parent=444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/categories?post=444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/tags?post=444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}