DNS Recon Redux – Zone Transfers (plus a time machine) for When You Can’t do a Zone Transfer, (Wed, Feb 15th)
When in the recon phase of a security assessment or penetration test, quite often you want to collect the dns names for all hosts in a scope of IP addresses. I covered how to do that with a few different APIs in this story: (https://isc.sans.edu/diary/Using+Passive+DNS+sources+for+Reconnaissance+and+Enumeration/28596)