3 ms·
Ah, the classical network pentester's problem. There's really no one good way to go about this. Certificate transparency tools like CTFR (https://github.com/Un
by haloux 8y ago
Ah, the classical network pentester's problem. There's really no one good way to go about this.
Certificate transparency tools like CTFR (https://github.com/UnaPibaGeek/ctfr https://github.com/UnaPibaGeek/ctfr) work only if certs are registered.
You could go old school and use a tool like Sublist3r (https://github.com/aboul3la/Sublist3r https://github.com/aboul3la/Sublist3r) or Punter (https://github.com/nethunteros/punter https://github.com/nethunteros/punter), but ymmv as API endpoints are savvy to these tools and actively work to snub them out.
AXFR queries can be useful if the DNS server allows for it (my experience: 0-15).
Best of luck.