????NmapDNS???????
????DNS??????????????????????????????????????????????У?????????′η?????????????????????η????????ν??????????????????????????????棬?????趨????佫?????????Nmap?У?dns-cache-snoop??????????????????е?DNS?????????????????????????
????nmap -sU -p 53 --script dns-cache-snoop.nse --script-args 'dns-cache-snoop.mode=timed??dns-cache-snoop.domains={host1??host2??host3}'
????????????“-sU”????????UDP????“-p”??????????DNSЭ????????53??“dns-cache-snoop.mode”???????????????????????????????????????????nonrecursive??timed?????У?nonrecursive?????????“dns-cache-snoop.domains”???????????????????????????????????????????????м????????
?????????1-8????????????RHEL 6.4???DNS?????????????????????????
root@localhost:~# nmap -sU -p 53 --script dns-cache-snoop.nse 192.168.1.104
Starting Nmap 6.47 ( http://nmap.org ) at 2015-06-03 16:42 CST
Nmap scan report for localhost (192.168.1.104)
Host is up (0.00036s latency).
PORT   STATE SERVICE
53/udp open  domain
| dns-cache-snoop: 1 of 100 tested domains are cached.          #?????
|_www.baidu.com
MAC Address: 00:0C:29:2A:69:34 (VMware)
Nmap done: 1 IP address (1 host up) scanned in 0.52 seconds
?????????????????У?????????????100??????????????????????檔?????????У????????????????????www.baidu.com??
????Nmap???????????????????б?
??????????????????????????DNS?????????proxy??????????Nmap?У?dns-blacklist?????????????????????????DNS?????????proxy???????????У???????????????
????nmap -sn --script dns-blacklist [???]
????????????“-sn”???????????Ping??衣
?????????1-9????????????RHEL 6.4????????????б??????????????????
root@localhost:~# nmap -sn --script dns-blacklist 192.168.1.104
Starting Nmap 6.47 ( http://nmap.org ) at 2015-06-05 16:00 CST
Nmap scan report for localhost (192.168.1.104)
Host is up (0.00028s latency).
MAC Address: 00:0C:29:2A:69:34 (VMware)
Host script results:
| dns-blacklist:
|   PROXY                                                                         #PROXYЭ??
|     dnsbl.tornevall.org - PROXY
|       IP marked as "abusive host"
|       ?
|     dnsbl.ahbl.org - PROXY
|   SPAM                                                                                    #SPAMЭ??
|     dnsbl.ahbl.org - SPAM
|     l2.apews.org - FAIL
|_    list.quorum.to - SPAM
Nmap done: 1 IP address (1 host up) scanned in 12.58 seconds
?????????????????У????????????????????DNS?????????proxy????????