File dns-brute
Script types:
prerule, hostrule
Categories:
intrusive, discovery
Download: http://nmap.org/svn/scripts/dns-brute.nse
User Summary
Attempts to enumerate DNS hostnames by brute force guessing of common subdomains.
Script Arguments
dns-brute.threads
Thread to use (default 5).
dns-brute.domain
Domain name to brute force if no host is specified
newtargets
Add discovered targets to nmap scan queue
dns-brute.hostlist
The filename of a list of host strings to try.
dns-brute.srv
Perform lookup for SRV records
max-newtargets
See the documentation for the target library.Example Usage
nmap --script dns-brute --script-args dns-brute.domain=foo.com,dns-brute.threads=6,dns-brute.hostlist=./hostfile.txt,newtargets -sS -p 80 nmap --script dns-brute www.foo.com
Script Output
Pre-scan script results: | dns-brute: | DNS Brute-force hostnames | www.foo.com - 127.0.0.1 | mail.foo.com - 127.0.0.2 | blog.foo.com - 127.0.1.3 | ns1.foo.com - 127.0.0.4 |_ admin.foo.com - 127.0.0.5
Requires
Author: Cirrus
License: Same as Nmap--See http://nmap.org/book/man-legal.html


