[linux]Enumerating subdomain

A server has a dns service and its ip address is, so I use nslookup and change the server to, and find out what is its fqdn.


It is revealed that its fqdn is ns1.cronos.htb, so I am guessing the domain name would be cronos.htb too.

To find out its sub domains in the dns server with the axfr (zone transfer) option I do this dig @ cronos.htb axfr
you will need to provide the name server fqdn or ip address after the @ symbol. The AXFR (zone transfer) is supported by the server hence the dns server reviews these:

As I am not going to change the dns server I am changing it in my hosts file so that admin.cronos.htb is resolvable.



Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s