commit 742c5791258440ee1c018c0479138f9ace814ef2
parent 0f04b61e66d7acda4a3318358502a85dbe3f0010
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Fri, 18 Sep 2026 23:26:34 +0100
update
Diffstat:
1 file changed, 39 insertions(+), 2 deletions(-)
diff --git a/src/content/sheets/pentest-workflow/recon-and-host-discovery.md b/src/content/sheets/pentest-workflow/recon-and-host-discovery.md
@@ -7,7 +7,7 @@ order: 2
tags: ["htb", "cpts", "htb-attack-flow", "htb-attack-flow-stage-01", "pentest-workflow"]
tools: ["RustScan", "Nmap", "dig", "Kerberos"]
difficulty: intermediate
-updated: "2026-08-29"
+updated: "2026-09-17"
source: "vault:Pentest Attack Flow/02 - Stage 01 - Recon and Host Discovery.md"
---
> [!dashboard] Attack-flow navigation
@@ -346,10 +346,16 @@ nmap -sn -PS22,80,135,445,3389 10.10.110.0/24 -oA ./recon/lan-discover
### 10. Vhosts & DNS → feed `/etc/hosts`
-**What to look for** → hostnames the IP scan hints at but doesn't route: cert CN/SANs, HTTP redirects/titles, and DNS zone data. Every new name goes into `/etc/hosts` so web + Kerberos work.
+**What to look for** → hostnames the IP scan hints at but doesn't route: cert CN/SANs, HTTP redirects/titles, DNS zone data, and reverse-PTR records. Every new name goes into `/etc/hosts` so web + Kerberos work.
**Enumerate**
```bash
+# Reverse PTR lookup — ask the box's own DNS server to resolve its own IP.
+# On plenty of HTB/AD boxes the reverse zone is auto-populated for the DC,
+# so this hands you $DOMAIN from nothing but $IP, before nmap even finishes.
+dig -x $IP @$IP +noall +answer
+# 166.11.10.10.in-addr.arpa. 604800 IN PTR trick.htb.
+
# Names leak from TLS certs and HTTP on web ports
nmap -p443,8443 --script=ssl-cert $IP
nmap -sV -p80,443,8080,8443 --script=http-title,http-headers,http-server-header $IP
@@ -362,8 +368,39 @@ dig axfr $DOMAIN @$IP
echo "$IP $DOMAIN www.$DOMAIN mail.$DOMAIN" | sudo tee -a /etc/hosts
```
+> [!tip] Reading the PTR answer
+> `dig -x` is shorthand for a `PTR` query against `<reversed-octets>.in-addr.arpa` — `@$IP` points it at the target's *own* resolver since that's usually the only DNS server that has the zone. The FQDN in the `ANSWER` section (`trick.htb.` above) is your `$DOMAIN` — export it and go straight to §0's `/etc/hosts`/krb5.conf setup. No PTR record / `NXDOMAIN` is common and means try TLS-cert CNs or AXFR instead, not that something's broken.
+
> [!note] If a web port serves a different site per `Host:` header, that's vhost routing — fuzz it in STAGE 2 (`ffuf ... -H "Host: FUZZ.$DOMAIN"`). Zone transfer denied is the *expected* result on a sane DNS server, not an error. Port→service reference: Common Ports and Services Cheatsheet 2026.
+**SRV records — AD publishes its own service map, unauthenticated**
+
+**What to look for** → every DC, the PDC emulator, and Global Catalog servers, straight from DNS — no LDAP bind or Kerberos ticket needed.
+
+```bash
+# _msdcs is the AD-specific subzone; these four cover 95% of what you need
+dig srv _ldap._tcp.dc._msdcs.$DOMAIN @$DC +short # every domain controller
+dig srv _kerberos._tcp.dc._msdcs.$DOMAIN @$DC +short # every KDC (usually == DC list)
+dig srv _ldap._tcp.pdc._msdcs.$DOMAIN @$DC +short # the PDC emulator specifically
+dig srv _gc._tcp.$DOMAIN @$DC +short # Global Catalog (multi-DC forest only)
+
+# nslookup form — same data, useful from a Windows foothold where dig isn't installed
+nslookup -type=srv _ldap._tcp.dc._msdcs.$DOMAIN $DC
+```
+
+> [!tools] dnsrecon / adidnsdump
+> [dnsrecon](https://github.com/darkoperator/dnsrecon) automates the whole DNS pass above in one command:
+> ```bash
+> dnsrecon -d $DOMAIN -n $DC -t std,srv,axfr # std = A/AAAA/MX/NS/TXT/SOA, srv = the AD SRV set, axfr = zone transfer attempt
+> ```
+> [adidnsdump](https://github.com/dirkjanm/adidnsdump) is a different job — it needs **any** authenticated domain account (any tier) and dumps the *entire* AD-integrated DNS zone via LDAP, not just the public SRV/PTR subset. Revisit once creds land in [Stage 04](/sheets/pentest-workflow/active-directory-enumeration):
+> ```bash
+> adidnsdump -u $DOMAIN\$U -p $P $DC # writes records.csv — every internal name, including ones with no PTR
+> ```
+
+> [!tip] Why bother when nmap already found the DC
+> A single-DC lab box makes SRV records feel redundant — but on a multi-DC forest they're how you find the **PDC emulator** (the one DC that matters for password/lockout state and time sync) and the **Global Catalog** (needed for forest-wide LDAP searches in Stage 04) without guessing which of five DCs to point tools at. `_msdcs.$DOMAIN` is also queryable straight off an external resolver on internet-facing AD — same passive-recon value as the PTR trick in §8 of [Stage 00](/sheets/pentest-workflow/passive-external-recon).
+
---
### 11. Kerberos on 88 = it's AD (tell + first users)