This is one of the first articles in our Backtrack tutorial series. Alex and I will be be going through the entire distro of Backtrack 4 and writing a post on each tool. There is no one blog or web site which has a tutorial on each tool in backtrack so we are going to attempt to do that.

Today I will be writing about Dnswalk. Dnswalk is a DNS debugger. It performs zone transfers of specified domains, and checks the database in numerous ways for internal consistency, as well as for correctness according to accepted practices with the Domain Name System. A zone transfer is when a DNS server performs a complete dump of the database for a domain and sends the information from the primary DNS server to the secondary DNS servers. The domain name specified on the command line MUST end with a ‘.’. You can specify a forward domain, such as dnswalk or a reverse domain, such as dnswalk

Lets take a look at the help section:

root@bt:/pentest/enumeration/dns/dnswalk# ./dnswalk --help
./dnswalk version [unknown] calling Getopt::Std::getopts (version 1.05 [paranoid]),
running under Perl version 5.10.0.

Usage: dnswalk [-OPTIONS [-MORE_OPTIONS]] [--] [PROGRAM_ARG1 ...]

The following single-character options are accepted:
        With arguments: -D
        Boolean (without arguments): -r -f -i -a -d -m -F -l

Options may be merged together.  -- stops processing of options.
Space is not required between options and their arguments.
  [Now continuing due to backward compatibility and excessive paranoia.
   See ``perldoc Getopt::Std'' about $Getopt::Std::STANDARD_HELP_VERSION.]
Usage: dnswalk domain
domain MUST end with a '.'

One thing that is anoying about the help section for this tool is that none of the command line switches and arguments are explained. Luckily Dnswalk has a man page online.

Recursively descend sub-domains of the specified domain. Use with care.
Turn on warning of duplicate A records. (see below)
Print debugging and ‘status’ information to stderr. (Use only if redirecting stdout) See DIAGNOSTICS section.
Perform checks only if the zone has been modified since the previous run.
perform “fascist” checking. When checking an A record, compare the PTR name for each IP address with the forward name and report mismatches. (see below) I recommend you try this option at least once to see what sorts of errors pop up – you might be surprised!.
Suppress check for invalid characters in a domain name. (see below)
Perform “lame delegation” checking. For every NS record, check to see that the listed host is indeed returning authoritative answers for this domain.

Ok so lets try a example:
NOTE: The domain was end in a “.” in order for Dnswalk to be able to use it.

root@bt:/pentest/enumeration/dns/dnswalk# ./dnswalk -r -d
Getting zone transfer of from
WARN: A no PTR record
WARN: A no PTR record
WARN: A no PTR record
WARN: A no PTR record
WARN: A no PTR record
0 failures, 5 warnings, 0 errors.

In this example we didn’t really get any useful output because zone -transfers are becoming increasingly difficult to preform however sometimes it can still return some useful information.

List Price: $49.99 USD
New From: $49.99 USD In Stock
Used from: $0.45 USD In Stock

Penetration Tester's Open Source Toolkit, Vol. 2 (Paperback)

By (author): Jeremy Faircloth, Chris Hurley, Jesse Varsalone

List Price: $61.95 USD
New From: $44.68 USD In Stock
Used from: $2.75 USD In Stock

Tags: , , , , , , , , ,
5 Responses to “Backtrack 4: Information Gathering: DNS: Dnswalk – A DNS database debugger”
  1. Jonathan says:

    I wish I could donate for providing this tutorials. Any way it is a great thing and thank u…
    keep up the good spirit.


    alex Reply:

    Hello Jonathon,

    Thanks for leaving feedback! We do accept donations via PayPal by clicking the Donations link.



  2. Spiralout says:

    I cannot believe how lucky I am to have found this resource. As a beginner moving slowly into early-intermediate status, I can’t believe my luck. I had been searching for full length tutorials on specific Backtrack 4 tools for some now (having trouble finding W3af material these days), so far I can only find “bits and pieces” here and there. This has actually been a huge obstacle that really delayed my progress with Linux in general, and BT in specific. Coming from a Windows platform, I was hoping that more tutorials were available to help familiarise me with the new landscape, so this is more appreciated than words can say. Thank you both for your hard work. You are sure to make many Backtrack converts here.


    alex Reply:

    Hello Spiralout,

    No problem at all. Thanks for the kind words and for taking the time to leave feedback.



Leave a Reply

*Type the letter/number combination in the abvoe field before clicking submit.