4 ms·
Is this just searching certificate transparency logs?
by Kab1r 2y ago
Is this just searching certificate transparency logs?
- flemhans 2y agoI think it's a mix of different sources. Certainly, some of my subdomains there never had an SSL certificate.
- yup_sto 2y agoI'd imagine it's a combination of - CT log monitoring (https://github.com/CaliDog/CertStream-Server https://github.com/CaliDog/CertStream-Server) - Mass-Scanning across ipv4 on 80/443 at the least? - Brute-forcing subdomains on wildcards with large DNS wordlist (like something from assetnote: https://wordlists-cdn.assetnote.io/data/manual/best-dns-wordlist.txt https://wordlists-cdn.assetnote.io/data/manual/best-dns-word...) - Scraping/extracting subdomains/domains from JS But I've never attempted to enumerate subdomains on this scale before, so I could be missing something obvious
- Eikon 2y agoWell, CT logs are a data dump, they are not searchable, ingesting all that data near-real time and making it searchable in a useful and fast way (especially with wildcards) is actually quite challenging!
- stavros 2y agoWhere does one ingest them from?
- supriyo-biswas 2y agohttps://github.com/google/certificate-transparency-community-site/blob/master/docs/google/known-logs.md https://github.com/google/certificate-transparency-community...
- stavros 2y agoThanks!
- remram 2y agoI have subdomains with (non-wildcard) certificates that aren't on there.
- yup_sto 2y ago[dead]