Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
Log in
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
massdns — एक उच्च-प्रदर्शन DNS स्टब रिज़ॉल्वर, बल्क लुकअप और रीकॉनिसेंस (सबडोमेन एनुमरेशन) के लिए। | Kitploit
उपकरण/GitHubGitHub/blechschmidt/massdns
OSINT (खुला स्रोत खुफिया)टोहीDNS और सबडोमेन गणनाजानकारी एकत्र करनासबडोमेन एनुमरेशनDNS फज़िंगDNS विश्लेषणDNS विश्लेषण में शीर्ष #4DNS फज़िंग में शीर्ष #1DNS और सबडोमेन गणना में शीर्ष #7
3.6k5041003 महीने पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
सबडोमेन एनुमरेशन में शीर्ष #7
GitHubblechschmidt/massdns

massdns

एक उच्च-प्रदर्शन DNS स्टब रिज़ॉल्वर, बल्क लुकअप और रीकॉनिसेंस (सबडोमेन एनुमरेशन) के लिए।

रिपॉजिटरी देखें

MassDNS

एक उच्च-प्रदर्शन DNS स्टब रिज़ॉल्वर

MassDNS एक सरल उच्च-प्रदर्शन DNS स्टब रिज़ॉल्वर है जो उन लोगों को लक्षित करता है जो लाखों या अरबों की संख्या में डोमेन नामों को हल करना चाहते हैं। बिना विशेष कॉन्फ़िगरेशन के, MassDNS सार्वजनिक रूप से उपलब्ध रिज़ॉल्वर का उपयोग करके प्रति सेकंड 350,000 से अधिक नामों को हल करने में सक्षम है।

योगदानकर्ता

  • Quirin Scheitle, म्यूनिख की तकनीकी विश्वविद्यालय

संकलन

गिट रिपॉजिटरी को क्लोन करें और प्रोजेक्ट रूट फ़ोल्डर में cd करें। फिर स्रोत से बनाने के लिए make चलाएँ। यदि आप लिनक्स पर नहीं हैं, तो make nolinux चलाएँ। विंडोज़ पर, Cygwin पैकेज gcc-core, git और make आवश्यक हैं।

उपयोग

Usage: ./bin/massdns [options] [domainlist]
  -b  --bindto             Bind to IP address and port. (Default: 0.0.0.0:0)
      --busy-poll          Use busy-wait polling instead of epoll.
  -c  --resolve-count      Number of resolves for a name before giving up. (Default: 50)
      --drop-group         Group to drop privileges to when running as root. (Default: nogroup)
      --drop-user          User to drop privileges to when running as root. (Default: nobody)
      --extended-input     Input names are followed by a space-separated list of resolvers.
                           These are used before falling back to the resolvers file.
      --filter             Only output packets with the specified response code.
      --flush              Flush the output file whenever a response was received.
  -h  --help               Show this help.
      --ignore             Do not output packets with the specified response code.
  -i  --interval           Interval in milliseconds to wait between multiple resolves of the same
                           domain. (Default: 500)
  -l  --error-log          Error log file path. (Default: /dev/stderr)
      --norecurse          Use non-recursive queries. Useful for DNS cache snooping.
  -o  --output             Flags for output formatting.
      --predictable        Use resolvers incrementally. Useful for resolver tests.
      --processes          Number of processes to be used for resolving. (Default: 1)
  -q  --quiet              Quiet mode.
      --rand-src-ipv6      Use a random IPv6 address from the specified subnet for each query.
      --rand-src-ipv6-file Use a random IPv6 address from the specified file.
      --rcvbuf             Size of the receive buffer in bytes.
      --retry              Unacceptable DNS response codes.
                           (Default: All codes but NOERROR or NXDOMAIN)
  -r  --resolvers          Text file containing DNS resolvers.
      --root               Do not drop privileges when running as root. Not recommended.
  -s  --hashmap-size       Number of concurrent lookups. (Default: 10000)
      --sndbuf             Size of the send buffer in bytes.
      --status-format      Format for real-time status updates, json or ansi (Default: ansi)
      --sticky             Do not switch the resolver when retrying.
      --socket-count       Socket count per process. (Default: 1)
  -t  --type               Record type to be resolved. (Default: A)
      --verify-ip          Verify IP addresses of incoming replies.
  -w  --outfile            Write to the specified output file instead of standard output.

Output flags:
  L - domain list output
  S - simple text output
  F - full text output
  B - binary output
  J - ndjson output

Advanced flags for the domain list output mode:
  0 - Include NOERROR replies without answers.

Advanced flags for the simple output mode:
  d - Include records from the additional section.
  i - Indent any reply record.
  l - Separate replies using a line feed.
  m - Only output reply records that match the question name.
  n - Include records from the answer section.
  q - Print the question.
  r - Print the question with resolver IP address, Unix timestamp and return code prepended.
  s - Separate packet sections using a line feed.
  t - Include TTL and record class within the output.
  u - Include records from the authority section.

Advanced flags for the ndjson output mode:
  e - Write a record for each terminal query failure.

कमांड लाइन इंटरफ़ेस के विस्तृत विवरण के लिए, कृपया man ./doc/massdns.1 का उपयोग करके मैन पेज देखें।

उदाहरण

domains.txt में डोमेन के सभी AAAA रिकॉर्ड को lists में resolvers.txt के रिज़ॉल्वर का उपयोग करके हल करें और परिणामों को results.txt में संग्रहीत करें:

$ ./bin/massdns -r lists/resolvers.txt -t AAAA domains.txt > results.txt

यह इसके समतुल्य है:

$ ./bin/massdns -r lists/resolvers.txt -t AAAA -w results.txt domains.txt

उदाहरण आउटपुट

डिफ़ॉल्ट रूप से, MassDNS टेक्स्ट प्रारूप में प्रतिक्रिया पैकेट आउटपुट करेगा जो निम्नलिखित जैसा दिखता है:

;; Server: 77.41.229.2:53
;; Size: 93
;; Unix time: 1513458347
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 51298
;; flags: qr rd ra ; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 0

;; QUESTION SECTION:
example.com. IN A

;; ANSWER SECTION:
example.com. 45929 IN A 93.184.216.34

;; AUTHORITY SECTION:
example.com. 24852 IN NS b.iana-servers.net.
example.com. 24852 IN NS a.iana-servers.net.

रिज़ॉल्वर IP पता शामिल किया गया है ताकि यदि आपको लगे कि कुछ रिज़ॉल्वर खराब परिणाम उत्पन्न कर रहे हैं तो आउटपुट को फ़िल्टर करना आसान हो।

समाधान

रिपॉजिटरी में resolvers.txt फ़ाइल शामिल है जिसमें subbrute प्रोजेक्ट द्वारा प्रदान किए गए रिज़ॉल्वर का एक फ़िल्टर्ड उपसमूह है। कृपया ध्यान दें कि MassDNS का उपयोग उपयोग किए गए रिज़ॉल्वर पर महत्वपूर्ण भार डाल सकता है और इसके परिणामस्वरूप आपके ISP को दुरुपयोग की शिकायतें भेजी जा सकती हैं। यह भी ध्यान दें कि प्रदान किए गए रिज़ॉल्वर विश्वसनीय होने की गारंटी नहीं है। रिज़ॉल्वर सूची वर्तमान में पुरानी है और बड़ी संख्या में रिज़ॉल्वर निष्क्रिय हैं।

MassDNS का कस्टम, malloc-मुक्त DNS कार्यान्वयन वर्तमान में केवल सबसे सामान्य रिकॉर्ड का समर्थन करता है। आप सहयोग करके इसे बदलने में मदद करने के लिए स्वागत है।

PTR रिकॉर्ड

MassDNS में एक Python स्क्रिप्ट शामिल है जो आपको सभी IPv4 PTR रिकॉर्ड को हल करने की अनुमति देती है, उनके संबंधित क्वेरी को मानक आउटपुट पर प्रिंट करके।

$ ./scripts/ptr.py | ./bin/massdns -r lists/resolvers.txt -t PTR -w ptr.txt

कृपया ध्यान दें कि in-addr.arpa के अंदर लेबल उलटे हैं। 1.2.3.4 के डोमेन नाम को हल करने के लिए, MassDNS इनपुट क्वेरी नाम के रूप में 4.3.2.1.in-addr.arpa की अपेक्षा करता है। परिणामस्वरूप, Python स्क्रिप्ट रिकॉर्ड को आरोही क्रम में हल नहीं करती है, जो एक लाभ है क्योंकि IPv4 सबनेट के नाम सर्वरों पर अचानक भारी स्पाइक्स से बचा जाता है।

सबडोमेन को ब्रूट-फ़ोर्स करके टोह लेना

टोह स्कैन जिम्मेदारी से करें और आधिकारिक नाम सर्वरों पर अत्यधिक भार न डालने के लिए -s पैरामीटर को समायोजित करें।

subbrute के समान, MassDNS आपको शामिल subbrute.py स्क्रिप्ट का उपयोग करके सबडोमेन को ब्रूट फ़ोर्स करने की अनुमति देता है:

$ ./scripts/subbrute.py example.com lists/names.txt | ./bin/massdns -r lists/resolvers.txt -t A -o S -w results.txt

टोह लेने की एक अतिरिक्त विधि के रूप में, ct.py स्क्रिप्ट crt.sh से डेटा स्क्रैप करके सर्टिफिकेट पारदर्शिता लॉग से सबडोमेन निकालती है:

$ ./scripts/ct.py example.com | ./bin/massdns -r lists/resolvers.txt -t A -o S -w results.txt

फ़ाइलें names.txt और names_small.txt, जिन्हें subbrute प्रोजेक्ट से कॉपी किया गया है, में सामान्यतः उपयोग किए जाने वाले सबडोमेन के नाम हैं। 1,000,000 से अधिक नामों वाले Jason Haddix के सबडोमेन संकलन या 9,000,000 मिलियन से अधिक नामों वाली Assetnote वर्डलिस्ट का उपयोग करने पर भी विचार करें।

टूल डाउनलोड करें