# DNS - 53

### Zone Transfer

```
dig axfr inlanefreight.local @10.129.229.147

; <<>> DiG 9.18.28-1~deb12u2-Debian <<>> axfr inlanefreight.local @10.129.229.147
;; global options: +cmd
inlanefreight.local.	86400	IN	SOA	ns1.inlanfreight.local. dnsadmin.inlanefreight.local. 21 604800 86400 2419200 86400
inlanefreight.local.	86400	IN	NS	inlanefreight.local.
inlanefreight.local.	86400	IN	A	127.0.0.1
blog.inlanefreight.local. 86400	IN	A	127.0.0.1
careers.inlanefreight.local. 86400 IN	A	127.0.0.1
dev.inlanefreight.local. 86400	IN	A	127.0.0.1
flag.inlanefreight.local. 86400	IN	TXT	"HTB{DNs_ZOn3_Tr@nsf3r}"
gitlab.inlanefreight.local. 86400 IN	A	127.0.0.1
ir.inlanefreight.local.	86400	IN	A	127.0.0.1
status.inlanefreight.local. 86400 IN	A	127.0.0.1
support.inlanefreight.local. 86400 IN	A	127.0.0.1
tracking.inlanefreight.local. 86400 IN	A	127.0.0.1
vpn.inlanefreight.local. 86400	IN	A	127.0.0.1
inlanefreight.local.	86400	IN	SOA	ns1.inlanfreight.local. dnsadmin.inlanefreight.local. 21 604800 86400 2419200 86400
;; Query time: 90 msec
;; SERVER: 10.129.229.147#53(10.129.229.147) (TCP)
;; WHEN: Fri Jan 17 21:07:45 CST 2025
;; XFR size: 14 records (messages 1, bytes 448)
```

### VHost Enumeration

```
ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -u http://inlanefreight.local:80/ -H 'Host: FUZZ.inlanefreight.local' -fw 1055
```

```


        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://inlanefreight.local:80/
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt
 :: Header           : Host: FUZZ.inlanefreight.local
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response words: 1055
________________________________________________

dev                     [Status: 200, Size: 2048, Words: 643, Lines: 74, Duration: 1832ms]
status                  [Status: 200, Size: 878, Words: 105, Lines: 43, Duration: 153ms]
monitoring              [Status: 200, Size: 56, Words: 3, Lines: 4, Duration: 108ms]
careers                 [Status: 200, Size: 51806, Words: 22041, Lines: 732, Duration: 119ms]
blog                    [Status: 200, Size: 8708, Words: 1509, Lines: 232, Duration: 3854ms]
tracking                [Status: 200, Size: 35211, Words: 10413, Lines: 791, Duration: 128ms]
vpn                     [Status: 200, Size: 1578, Words: 414, Lines: 35, Duration: 4855ms]
support                 [Status: 200, Size: 26635, Words: 11730, Lines: 523, Duration: 4863ms]
ir                      [Status: 200, Size: 28548, Words: 2885, Lines: 210, Duration: 1697ms]
gitlab                  [Status: 302, Size: 113, Words: 5, Lines: 1, Duration: 118ms]
www.monitoring          [Status: 200, Size: 56, Words: 3, Lines: 4, Duration: 89ms]
:: Progress: [19966/19966] :: Job [1/1] :: 421 req/sec :: Duration: [0:00:49] :: Errors: 0 ::
```
