host megacorpone.com (basic)
host –mx megacorpone.com (MX records search)
host –tx megacorpone.com (TX records search)
#Forward lookup bruteforce (requires list of potential hosts)
Cat list.txt
www http proxy ftp router mail
#Use bash script to automate research
for ip in $(cat list.txt); do host $ip.megacorpone.com; done
#seclists has custom wordlist for dns bruteforcing
#Reverse lookup bruteforce script
for ip in $(seq 50 100); do host 38.100.193.$ip; done | grep -v "not found"