假如你是手动编译的,可能script的存放路径会有差异
子域名爆破
这个是自带的
使用示例
nmap --script dns-brute --script-args dns-brute.domain=foo.com,dns-brute.threads=6,dns-brute.hostlist=./hostfile.txt,newtargets -sS -p 80
nmap --script dns-brute www.foo.com
比如百度
root@giantbranch:~# nmap -p 80 --script dns-brute.nse baidu.com
Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-14 10:47 CST
Nmap scan report for baidu.com (220.181.57.216)
Host is up (0.15s latency).
Other addresses for baidu.com (not scanned): 123.125.114.144
PORT STATE SERVICE
80/tcp filtered http
Host script results:
| dns-brute:
| DNS Brute-force hostnames:
| mx.baidu.com - 61.135.163.61
| admin.baidu.com - 10.26.109.19
| svn.baidu.com - 10.65.211.174
| ads.baidu.com - 10.42.4.225
| mx1.baidu.com - 220.181.50.185
| mx1.baidu.com - 61.135.165.120
| id.baidu.com - 103.235.47.123
| mysql.baidu.com - 10.105.97.153
| test.baidu.com - 61.135.185.109
| news.baidu.com - 103.235.46.122
| images.baidu.com - 182.61.62.50
| info.baidu.com - 111.206.223.208
| info.baidu.com - 61.135.185.62
| alpha.baidu.com - 111.206.223.252
| dns.baidu.com - 202.108.22.220
| internet.baidu.com - 103.235.46.122
| ap.baidu.com - 111.202.114.63
| ns1.baidu.com - 202.108.22.220
| ns2.baidu.com - 220.181.33.31
| ns3.baidu.com - 112.80.248.64
| dns1.baidu.com - 220.181.38.10
| app.baidu.com - 103.235.47.17
| ntp.baidu.com - 10.48.49.44
| ipv6.baidu.com - 111.13.101.208
| ipv6.baidu.com - 123.125.114.144
| ipv6.baidu.com - 220.181.57.216
| ipv6.baidu.com - 220.181.57.217
| ipv6.baidu.com - 2400:da00:2:0:0:0:0:29
| ops.baidu.com - 10.26.3.240
| ops.baidu.com - 10.46.7.36
| ops.baidu.com - 10.91.160.44
| vpn.baidu.com - 12.1.72.36
| lab.baidu.com - 180.149.132.122
| lab.baidu.com - 180.149.144.192
| web.baidu.com - 10.48.30.87
| owa.baidu.com - 12.0.243.39
| auth.baidu.com - 111.206.37.69
| linux.baidu.com - 10.99.31.43
| whois.baidu.com - 123.125.114.172
| exchange.baidu.com - 10.26.109.19
| backup.baidu.com - 10.143.145.28
| beta.baidu.com - 111.206.37.130
| log.baidu.com - 10.26.39.14
| www.baidu.com - 104.193.88.123
| www.baidu.com - 104.193.88.77
| mail.