Route 53 is a great service to spend some time looking at for a few different reasons. The main reason would be reconnaissance, as it allows us to associate IPs and host names and discover domains and sub-domains, which is what we are going to cover here. It is also a very fruitful service for some more malicious attacks that we aren't going to be going into in-depth because they are not useful to us as penetration testers, but we will cover them at the end to make you aware of what a real malicious hacker might try and do once gaining access.
Route 53
Hosted zones
The first thing we will want to do is get a list of hosted zones in Route 53. We can gather this information with the following AWS CLI command (we can leave...