Find Sub Domains in a minute

What is a Sub Domain?

A subdomain is a domain that is part of a larger domain, the only domain that is not also a subdomain is the root domain. For example, www.google.com is the Root domain and www.google.in or wwww.google.uk are the subdomains.

What is the use of Discovering Subdomains?

Discovering subdomains of a domain is an essential part of hacking reconnaissance and thanks to following online tools which makes life easier.
Having an unsecured subdomain can lead to a serious risk to your business, and lately, there were some security incidents where the hacker used subdomains tricks.


  • Censys

Censys is probably one of the first search engines to check for subdomains. Along with subdomain, you can also find some of the exciting stuff as following.


  1. IP details (can be useful to find origin IP)
  2. Certificate details
  3. Allowed port
  4. SSL/TLS handshake protocol and cipher suites (useful to find weak cipher/protocol)



  • Pentest-Tools

Pentest-tools search for subdomain using multiple methods like DNS zone transfer, DNS enumeration based on wordlist, and public search engine.

  • FindSubdomains

Findsubdomains is a handcrafted search engine that allows you to discover subdomains of any domain. It is just one of several tools made by Spyse, and it’s closely connected to all other tools that allow you to get much more info about subdomains.


  • ImmuniWeb

Finding a subdomain is easy with SSLScan. You provide the URL to scan, and within a few seconds, results are shown with discovered subdomain along with other SSL information.


  • DNS Dumpster

DNSDumpster is a domain research tool to find host-related information. It’s the HackerTarget.com project.

Not just subdomain but it gives you information about DNS server, MX record, TXT record and nice mapping of your domain.


  • Sublist3r

Sublist3r is a python tool to find subdomains using a search engine. Currently, it supports Google, Yahoo, Bing, Baidu, Ask, Netcraft, Virustotal, ThreatCrowd, DNSdumpster, and PassiveDNS.

Sublist3r is supported only on python 2.7 version and has few dependencies in a library.


  • Netcraft

Netcraft has a large number of a domain database, and you don’t want to miss this in finding public subdomain information.

The search result will contain all the domain and subdomain with first seen, netblock, and OS information.

If you need more information about the website, then click the on-site report and you will be given tons of information about technologies, ranking, etc.


  • SubBrute 

SubBrute is one of the most popular and accurate subdomain enumeration tools. It’s a community-driven project, and it uses open resolver as a proxy, so SubBrute doesn’t send traffic to the domain’s name servers.

It’s not an online tool, and you need to install this on your computer. You can use Windows or UNIX based OS and installation is very easy. 

Comments

Popular posts from this blog

CAREER TECHNOLOGY CYBER SECURITY INDIA PVT LTD.

Cyber Security Audits

Some Dark web Links