sublist3r https://github.com/aboul3la/Sublist3r
amass https://github.com/caffix/amass
subfinder https://github.com/subfinder/subfinder
Certificate transparency tools like CTFR (https://github.com/UnaPibaGeek/ctfr) work only if certs are registered.
You could go old school and use a tool like Sublist3r (https://github.com/aboul3la/Sublist3r) or Punter (https://github.com/nethunteros/punter), but ymmv as API endpoints are savvy to these tools and actively work to snub them out.
AXFR queries can be useful if the DNS server allows for it (my experience: 0-15).
Best of luck.
https://security.stackexchange.com/questions/94503/does-dnss...
https://nmap.org/nsedoc/scripts/dns-nsec3-enum.html
There are tools for online brute force, but that's not very polite :)
These days many domains are configured to refuse AXFR queries though. Then there's a misguided but common phenomenon called split-horizon DNS is also common, where you serve different records as answers to the same query based on what the query originator's address is.
citation needed.
I had no idea that some would consider it 'very confrontational'; that's the exact opposite of my intent.
Speaking transparently, when I write 'Citation Needed', it's usually because I do disagree with the statement in question, but that my disagreement is not sufficiently supported. It also means that I'm open to being corrected with additional information.
It is as if some people don't have time to ask politely for sources.
I also think it might trigger the "passive agressive"-detector for some people here. (I think that description has been overused a lot though and don't want to classify it as such.)
This might not be your intention but I wouldn't be very sad to see those words less often here.
And one more thing: using wikipedia as an example for how to behave in society might not be a good idea IMO.
It also means that I'm open to being wrong in my disagreement.
So, in short, I don't state disagreement in these cases because the strength of my opinion is too weak to merit it.
https://lists.opendnssec.org/pipermail/opendnssec-user/2012-...
> "I was scanning Valve's network to check for accessible web servers where I thought information about the game might have been held. Valve's network was reasonably secure from the outside, but the weakness was that their name server allowed anonymous AXFRs, which gave me quite a bit of information."
AXFR stands for Asynchronous Full Zone Transfer, a tool used to synchronise backup DNS servers with the same data as the primary server. But it's also a protocol used by hackers to sneak a peek at a website's data. By transferring this data, Gembe was able to discover the names of all the subdomains of ValveSoftware.com.
"In the port scan logs, I found an interesting server which was in Valve's network range from another corporation named Tangis that specialised in wearable computing devices," he says.
"This server had a publically writable web root where I could upload ASP scripts and execute them via the web server. Valve didn't firewall this server from its internal network."
https://www.eurogamer.net/articles/2011-02-21-the-boy-who-st...
Re the Valve case: this could have been also found with a simple ip range port scan, or a bunch of other ways. In the end it was just a server in the network with no access control configured and they happened to spot it in the DNS records first.
"In the port scan logs, I found an interesting server which was in Valve's network range from another corporation named Tangis that specialised in wearable computing devices," he says."
Also, in the modern world, you can see the web servers in a domain in the public cert transparency logs.
Do you consider the whole functionality of views to be misguided, or just predicating the selection of view solely on source address?
I'm not sure if there's a way to handle multi-homed hosts in a more simple/elegant fashion than with views.
Merely for serving distinct "internal" and "external" zones from the same server, it seems like a convenience fraught with pitfalls.
Sure, but that statement is only true in the past tense and only for a sufficiently-past definition of "everything". One could make a similar complaint about the breakdown of classful routing and subnets, but the Internet has morphed beyond its original design, in response to the realities of how it's been used [1].
Regardless, it seems your objection is to the non-global-uniqueness of private addressing, which existed well before split-dns.
Is there any separate objection you have to split-dns?
[1] The wisdom of each particular decision is debatable, but I, personally, find little interest in exploring alternate-history/what-if scenarios, technical or otherwise.
Anyway, consider a basic use case like an application (correctly) caching DNS records for the duration of their time-to-live metadata - and moving between networks that yield different reponses to these queries. With the added twist that different applications cache differently so now you have an incoherent view of the DNS on the same system. Another comment said it won't work with DNSSEC, that's another example stemming from going against the design and basic principles of the DNS.
It's true that there are some reasonable use cases context dependent DNS replies, such CDN's returning a nearby address from a set of geographically replicated content servers, but the common internal/external split-dns setup is fundamentally unsound.
As an analogy, it doesn't directly apply to your particular point, which is why it's an analogy. It would apply to, say, a network engineer.
> an application (correctly) caching DNS records
I'm pretty sure that merely putting the word "correctly" in parentheses doesn't make it so, nor, more to the point, remove the fact of the controversy on that point.
> that different applications cache differently
This is merely an argument in favor of the caching being done by the OS, which would also be aware of a device moving networks. Device mobility (without reboot) is one of those relatively recent uses imposed onto the Internet.
> Another comment said it won't work with DNSSEC, that's another example stemming from going against the design and basic principles of the DNS.
One could lay the blame for incompatibility at the feet of DNSSEC, too, as that technology is also a response to modern needs of the Internet that has little, if anything, to do with any original design or basic principles.
> the common internal/external split-dns setup is fundamentally unsound.
So, again, I still can't tell what it is you're opposed to, on so fundamental a level that you would call it "unsound", with split-dns specifically, separate from the issue of private addressing being used.
Is it any different if two separate nameservers are used instead of split-dns on one?
Perhaps, most importantly, what's the sound, not-misguided, alternative that provides a comparable (maybe even better) experience for the user?
That's what I've been trying to do all along, which I admit requires talking past whatever point you're trying to make about private addressing and non-uniqueness. I have made a concerted attempt to address those points as they pertain specifically to my question.
Of course, I also hope you'd share your proposed alternative, even for 1918. I doubt anyone here actually enjoys the pain brought about by forced NAT and non-unique IPs (naive VPNs!).
Now don't do it by hand people have already built tools. I recommend sublist3r https://github.com/aboul3la/Sublist3r, however, grab other subdomain bruteforcer wordlists and append them all together.
Go to https://opendata.rapid7.com/, download the reverse DNS and Forward DNS and grep for your domain. I.E grep "*.mydomain.com" These are amazing.
I will make a note, sometimes if you are looking for servers related to a company specifically people miss ones that aren't in a company's zone file. You need to use a service like Shodan or Censys which regularly scan the internet and index these. It can be a pain to parse through these results but if you are strapped for ideas on getting a foodhold try this. I have found some juicy servers with this in mind.
If you are on a pentest it is completely ok to ask your client for permission to view their zone file/route53 as well. This will save you a lot of time up front.
https://medium.com/@jonathanbouman/how-i-hacked-apple-com-un...
Used a tool called Aquatone:
https://github.com/michenriksen/aquatone/
I have not used Aquatone; I just remembered this from a post on HN pretty recently.
But otherwise just use nslookup/dig/host
- sublist3r - amass - subfinder
They're all on Github.