mirror of
https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters
synced 2026-06-06 15:04:28 +00:00
Update dns_powershell.md
This commit is contained in:
@@ -114,3 +114,49 @@ servers, and reverse DNS lookups as part of a penetration test. These examples d
|
||||
how PowerShell can be utilized for DNS-related tasks, aiding network administrators and IT
|
||||
professionals in managing and diagnosing network resources.
|
||||
|
||||
The Test-DnsServer cmdlet can be a valuable addition to a penetration tester’s toolkit
|
||||
when assessing the DNS infrastructure of a target. Here’s how it can be used:
|
||||
|
||||
* DNS enumeration: During the information-gathering phase, a penetration tester might want
|
||||
to gather DNS-related information about the target network. Using Test-DnsServer, they
|
||||
can enumerate DNS records to uncover valuable information such as domain names, mail
|
||||
exchange servers, and authoritative name servers. This information helps the tester build a
|
||||
comprehensive profile of the target. Some DNS records, such as SVR, can be used to identify
|
||||
detailed service information and, hence, potential vulnerabilities
|
||||
|
||||
Here’s an example:
|
||||
|
||||
```
|
||||
$Domain = "snowcapcyber.com"
|
||||
$DnsServer = "192.168.1.1"
|
||||
# Enumerate MX records
|
||||
$MXRecords = Test-DnsServer -IPAddress $DnsServer -Name $Domain
|
||||
-Type MX
|
||||
if ($MXRecords) {
|
||||
Write-Host "MX records for $Domain:"
|
||||
$MXRecords.QueryResults | ForEach-Object {
|
||||
Write-Host "Server: $($_.MailExchange)" }
|
||||
} else {
|
||||
Write-Host "No MX records found for $Domain"}
|
||||
```
|
||||
|
||||
* DNS spoofing and cache poisoning tests: Penetration testers may attempt to exploit DNS
|
||||
vulnerabilities such as cache poisoning to redirect traffic to malicious servers. By testing the
|
||||
target’s DNS responses using Test-DnsServer, they can assess whether the DNS server is
|
||||
vulnerable to spoofing attacks.
|
||||
|
||||
Here’s an example:
|
||||
|
||||
```
|
||||
$DnsServer = "192.168.1.1"
|
||||
$MaliciousServer = "malicious.com"
|
||||
$TargetDomain = "snowcapcyber.com"
|
||||
|
||||
# Test if DNS server resolves to malicious IP
|
||||
$DnsResponse = Test-DnsServer -IPAddress $DnsServer -Name
|
||||
$TargetDomain -Type A
|
||||
if ($DnsResponse.QueryResults.IPAddress -eq "malicious_IP") {
|
||||
Write-Host "Server vulnerable to spoofing."
|
||||
} else {
|
||||
Write-Host "DNS server is not vulnerable."}
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user