
محلل DNS ذو أداء عالي للاستعلامات الجماعية والاستطلاع (تعداد النطاقات الفرعية)
ماسديإنإس هو محلل DNS بسيط وعالي الأداء يستهدف أولئك الذين يسعون إلى حل عدد هائل من أسماء النطاقات بملايين أو حتى مليارات. دون تكوين خاص، يستطيع ماسديإنإس حل أكثر من 350,000 اسم في الثانية باستخدام محللات متاحة للعموم.
استنسخ مستودع git ثم cd إلى مجلد جذر المشروع. ثم شغّل make للبناء من المصدر. إذا كنت لا تستخدم لينكس، شغّل make nolinux. على ويندوز، مطلوب حزم Cygwin التالية: gcc-core و git و make.
Usage: ./bin/massdns [options] [domainlist]
-b --bindto Bind to IP address and port. (Default: 0.0.0.0:0)
--busy-poll Use busy-wait polling instead of epoll.
-c --resolve-count Number of resolves for a name before giving up. (Default: 50)
--drop-group Group to drop privileges to when running as root. (Default: nogroup)
--drop-user User to drop privileges to when running as root. (Default: nobody)
--extended-input Input names are followed by a space-separated list of resolvers.
These are used before falling back to the resolvers file.
--filter Only output packets with the specified response code.
--flush Flush the output file whenever a response was received.
-h --help Show this help.
--ignore Do not output packets with the specified response code.
-i --interval Interval in milliseconds to wait between multiple resolves of the same
domain. (Default: 500)
-l --error-log Error log file path. (Default: /dev/stderr)
--norecurse Use non-recursive queries. Useful for DNS cache snooping.
-o --output Flags for output formatting.
--predictable Use resolvers incrementally. Useful for resolver tests.
--processes Number of processes to be used for resolving. (Default: 1)
-q --quiet Quiet mode.
--rand-src-ipv6 Use a random IPv6 address from the specified subnet for each query.
--rand-src-ipv6-file Use a random IPv6 address from the specified file.
--rcvbuf Size of the receive buffer in bytes.
--retry Unacceptable DNS response codes.
(Default: All codes but NOERROR or NXDOMAIN)
-r --resolvers Text file containing DNS resolvers.
--root Do not drop privileges when running as root. Not recommended.
-s --hashmap-size Number of concurrent lookups. (Default: 10000)
--sndbuf Size of the send buffer in bytes.
--status-format Format for real-time status updates, json or ansi (Default: ansi)
--sticky Do not switch the resolver when retrying.
--socket-count Socket count per process. (Default: 1)
-t --type Record type to be resolved. (Default: A)
--verify-ip Verify IP addresses of incoming replies.
-w --outfile Write to the specified output file instead of standard output.
Output flags:
L - domain list output
S - simple text output
F - full text output
B - binary output
J - ndjson output
Advanced flags for the domain list output mode:
0 - Include NOERROR replies without answers.
Advanced flags for the simple output mode:
d - Include records from the additional section.
i - Indent any reply record.
l - Separate replies using a line feed.
m - Only output reply records that match the question name.
n - Include records from the answer section.
q - Print the question.
r - Print the question with resolver IP address, Unix timestamp and return code prepended.
s - Separate packet sections using a line feed.
t - Include TTL and record class within the output.
u - Include records from the authority section.
Advanced flags for the ndjson output mode:
e - Write a record for each terminal query failure.
للحصول على وصف مفصل لواجهة سطر الأوامر، يُرجى الاطلاع على صفحة الدليل باستخدام man ./doc/massdns.1.
حل جميع سجلات AAAA من النطاقات داخل domains.txt باستخدام المحللات داخل resolvers.txt في lists وتخزين النتائج في results.txt:
$ ./bin/massdns -r lists/resolvers.txt -t AAAA domains.txt > results.txt
هذا مكافئ لـ:
$ ./bin/massdns -r lists/resolvers.txt -t AAAA -w results.txt domains.txt
افتراضيًا، سيخرج ماسديإنإس حزم الاستجابة بتنسيق نصي يشبه ما يلي:
;; Server: 77.41.229.2:53
;; Size: 93
;; Unix time: 1513458347
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 51298
;; flags: qr rd ra ; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 0
;; QUESTION SECTION:
example.com. IN A
;; ANSWER SECTION:
example.com. 45929 IN A 93.184.216.34
;; AUTHORITY SECTION:
example.com. 24852 IN NS b.iana-servers.net.
example.com. 24852 IN NS a.iana-servers.net.
يتم تضمين عنوان IP للمحلل لتسهيل تصفية الإخراج إذا اكتشفت أن بعض المحللات تنتج نتائج سيئة.
يتضمن المستودع الملف resolvers.txt الذي يتكون من مجموعة فرعية مُرشحة من المحللات المقدمة من مشروع subbrute.
يُرجى ملاحظة أن استخدام ماسديإنإس قد يسبب حملاً كبيرًا على المحللات المستخدمة ويؤدي إلى إرسال شكاوى إساءة الاستخدام إلى مزود الخدمة الخاص بك.
لاحظ أيضًا أن المحللات المقدمة ليست مضمونة الموثوقية. قائمة المحللات حالياً قديمة مع نسبة كبيرة من المحللات غير العاملة.
تطبيق DNS المخصص لماسديإنإس والخالي من malloc يدعم حالياً السجلات الأكثر شيوعًا فقط. نرحب بمساعدتكم في تغيير هذا من خلال التعاون.
يتضمن ماسديإنإس نصًا برمجيًا بلغة بايثون يسمح لك بحل جميع سجلات PTR الخاصة بـ IPv4 عن طريق طباعة استعلاماتها إلى الإخراج القياسي.
$ ./scripts/ptr.py | ./bin/massdns -r lists/resolvers.txt -t PTR -w ptr.txt
يُرجى ملاحظة أن التسميات داخل in-addr.arpa معكوسة. لحل اسم النطاق لـ 1.2.3.4، يتوقع ماسديإنإس 4.3.2.1.in-addr.arpa كاسم استعلام مدخل.
ونتيجة لذلك، لا يحل النص البرمجي لبايثون السجلات بترتيب تصاعدي، وهو ميزة لأن القمم المفاجئة في خوادم أسماء الشبكات الفرعية IPv4 يتم تجنبها.
قم بإجراء عمليات مسح استطلاعية بمسؤولية واضبط المعامل -s لعدم إرباك خوادم الأسماء الموثوقة.
على غرار subbrute، يسمح لك ماسديإنإس بتخمين النطاقات الفرعية باستخدام النص البرمجي المضمن subbrute.py:
$ ./scripts/subbrute.py example.com lists/names.txt | ./bin/massdns -r lists/resolvers.txt -t A -o S -w results.txt
كطريقة استطلاع إضافية، يستخرج النص البرمجي ct.py النطاقات الفرعية من سجلات شفافية الشهادات عن طريق كشط البيانات من crt.sh:
$ ./scripts/ct.py example.com | ./bin/massdns -r lists/resolvers.txt -t A -o S -w results.txt
تحتوي الملفات names.txt و names_small.txt، التي تم نسخها من مشروع subbrute، على أسماء نطاقات فرعية شائعة الاستخدام. فكر أيضًا في استخدام تجميع النطاقات الفرعية لجيسون هاديكس الذي يحتوي على أكثر من 1,000,000 اسم أو قائمة كلمات Assetnote التي تحتوي على أكثر من 9,000,000 مليون اسم.