Update dns_powershell.md

This commit is contained in:
Smukx ♠
2024-08-28 23:15:53 +05:30
committed by GitHub
parent 86ba9cabd4
commit 1ce78d632f
+46
View File
@@ -114,3 +114,49 @@ servers, and reverse DNS lookups as part of a penetration test. These examples d
how PowerShell can be utilized for DNS-related tasks, aiding network administrators and IT
professionals in managing and diagnosing network resources.
The Test-DnsServer cmdlet can be a valuable addition to a penetration tester’s toolkit
when assessing the DNS infrastructure of a target. Here’s how it can be used:
* DNS enumeration: During the information-gathering phase, a penetration tester might want
to gather DNS-related information about the target network. Using Test-DnsServer, they
can enumerate DNS records to uncover valuable information such as domain names, mail
exchange servers, and authoritative name servers. This information helps the tester build a
comprehensive profile of the target. Some DNS records, such as SVR, can be used to identify
detailed service information and, hence, potential vulnerabilities
Here’s an example:
```
$Domain = "snowcapcyber.com"
$DnsServer = "192.168.1.1"
# Enumerate MX records
$MXRecords = Test-DnsServer -IPAddress $DnsServer -Name $Domain
-Type MX
if ($MXRecords) {
Write-Host "MX records for $Domain:"
$MXRecords.QueryResults | ForEach-Object {
Write-Host "Server: $($_.MailExchange)" }
} else {
Write-Host "No MX records found for $Domain"}
```
* DNS spoofing and cache poisoning tests: Penetration testers may attempt to exploit DNS
vulnerabilities such as cache poisoning to redirect traffic to malicious servers. By testing the
target’s DNS responses using Test-DnsServer, they can assess whether the DNS server is
vulnerable to spoofing attacks.
Here’s an example:
```
$DnsServer = "192.168.1.1"
$MaliciousServer = "malicious.com"
$TargetDomain = "snowcapcyber.com"
# Test if DNS server resolves to malicious IP
$DnsResponse = Test-DnsServer -IPAddress $DnsServer -Name
$TargetDomain -Type A
if ($DnsResponse.QueryResults.IPAddress -eq "malicious_IP") {
Write-Host "Server vulnerable to spoofing."
} else {
Write-Host "DNS server is not vulnerable."}
```