[TOOL] txdns - Aggressive Multithreaded DNS digger/brute-forcer



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



txdns - Aggressive Multithreaded DNS digger/brute-forcer
------------------------------------------------------------------------


SUMMARY



DETAILS

TXDNS is a Win32 aggressive multithreaded DNS digger. Capable of placing,
on the wire, thousands of DNS queries per minute. TXDNS main goal is to
expose a domain namespace trough a number of techniques:
* Typos
* TLD rotation
* Dictionary attack
* Brute force

TXDNS may be used to:
* Fill the reconnaissance gap left due to DNS servers hardening, as
DNS-zone transfers are much like to fail.
* Dig a given domain name for possible phishing variations based on
common well-know typo algorithms and return DNS queries on both used and
not used names.
* Stress-test DNS servers due is configurable aggressive behavior.

TXDNS provides some cool options, such as:
* Perform queries only for a given Resource Record type: A, CNAME, HINFO,
NS, TXT & SOA
* Perform non-recursive queries
* Perform queries against a given DNS server


ADDITIONAL INFORMATION

The information has been provided by <mailto:arleybls@xxxxxxxxxxx> Arley
Silveira.
To keep updated with the tool visit the project's homepage at:
<http://www.txdns.net/> http://www.txdns.net/



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [UNIX] Symantec Enterprise Firewall DNSD Cache Poisoning Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... false DNS server look like authoritative of a zone, ... DNS server responds to a query, but not necessarily with an answer, fills ... org. ...
    (Securiteam)
  • [NEWS] Zyxel P2000W VoIP Wifi Phone Multiple Vulnerabilties
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... An undocumented open port and a static DNS record allow attackers to gain ... The Zyxel P2000W v.1 VOIP WIFI phone uses hard coded DNS servers located ... all Zyxel phone users worldwide are ...
    (Securiteam)
  • [NEWS] Multiple DNS Implementation DoS
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... a DNS service must translate the name into the corresponding ... followed by the characters themselves. ... of the label length byte are 1, the remaining 14 bits specify an offset ...
    (Securiteam)
  • [UNIX] Remote DoS in libevent DNS Parsing
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Remote DoS in libevent DNS Parsing ... support for non-blocking DNS resolution was added to libevent. ... DNS reply containing a pointer loop, ...
    (Securiteam)
  • [TOOL] Snorter - Snort HTML Reporting Engine
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Snorter is an HTML reporting tool for the network IDS (intrusion detection ... * Making reports on events with sorting by IPSRC address, IPDST address, ... * Investigating on events with whois queries, snortDB queries, ... ...
    (Securiteam)