hakrevdns is a lightweight, high-performance utility written in Go designed for conducting bulk reverse DNS queries. By accepting a stream of IP addresses, it returns the corresponding hostnames. This capability is particularly valuable for security researchers and system administrators aiming too discover subdomains and infrastructure associated with specific target organizations.
Installation
To deploy the tool, execute the following command using the Go compiler:
go install github.com/hakluke/hakrevdns@latest
Basic Usage
The standard workflow involves piping a list of IP addresses directly into the binary. In the example below, a subnet range is generated and piped into hakrevdns to identify associated hostnames.
$ prips 192.0.2.0/29 | hakrevdns
192.0.2.1 mail.example.com.
192.0.2.2 ns1.example.com.
192.0.2.3 www.example.com.
192.0.2.5 vpn.example.com.
...
Configuration Options
The utility supports several flags to customize the resolutoin process:
Usage:
hakrevdns [OPTIONS]
Application Options:
-t, --threads= Concurrent thread count (balance between speed and rate-limiting)
-r, --resolver= IP address of the specific DNS resolver to query
-P, --protocol=[tcp|udp] Transport protocol for DNS queries (default: udp)
-p, --port= Target port on the DNS resolver (default: 53)
-d, --domain Output exclusively domain names, omitting IP addresses
Help Options:
-h, --help Show this help message
Advanced Scenarios
To override the system's default DNS resolver and use a specific server (e.g., Cloudflare's DNS), utilize the -r flag:
$ echo "8.8.8.8" | hakrevdns -r 1.1.1.1
8.8.8.8 dns.google.
If your objective is to harvest only the domain names for further processing, apply the -d flag to strip the IP addresses from the output:
$ echo "8.8.8.8" | hakrevdns -d
dns.google.
The tool is designed for seamless integration into pipelines. For instance, the output can be redirected directly to HTTP probing tools to check for live web services:
$ echo "192.0.2.1" | hakrevdns -d | httprobe