SMK Muhammadiyah 2 Palembang
Ctrlk
  • Introducation
  • The Basics
  • Windows
  • Scripting With Python
  • Recon and Information Gathering Phase
    • Passive information gathering
    • Identify IP-addresses and Subdomains
      • Dorking Find Subdomains
      • Find Subdomains
      • DNS Basics
      • DNS Zone Transfer Attack
      • Identifying People
      • Search Engine Discovery
      • Active information gathering
      • Port Scanning
  • Vulnerability analysis
  • Password Cracking
  • Pivoting - Port forwarding - Tunneling
  • Network traffic
  • Wifi
  • Physical access to machine
  • Literature
Powered by GitBook
On this page
  1. Recon and Information Gathering Phase
  2. Identify IP-addresses and Subdomains

Find Subdomains

Finding subdomains is fundamental. The more subdomains you find, the bigger attack surface you have. Which means bigger possibility of success.

For now this seems to be a very comprehensive list of tools to find subdomains.

LogoSubdomain Finder - C99.nlsubdomainfinder.c99.nl
https://www.shodan.io/www.shodan.io
LogoURL and website scanner - urlscan.iourlscan.io
LogoVirusTotalVirusTotal
LogoDNSDumpster - Find & lookup dns records for recon & researchDNSDumpster.com
https://securitytrails.com/list/apex_domain/google.comsecuritytrails.com
LogoReverse IP Lookup - Find Other Web Sites Hosted on a Web Serverwww.yougetsignal.com
PreviousDorking Find SubdomainsNextDNS Basics

Last updated 3 years ago