Gather information about target systems using publicly available knowledge without directly engaging with the target.

Certificate Transparency

When passively gathering information, we can use third-party services to understand our target better. The main website is oftentimes what should be scrutinized first. Inspecting the SSL certificate for the target domain can expose sibling subdomains that share the same certificate, and cross-referencing Certificate Transparency logs on crt.sh helps surface newly issued certificates for related hosts.

# output results in json format
curl -s https://crt.sh/\?q\=$DOMAIN\&output\=json | jq .
 
# filter by subdomain
curl -s https://crt.sh/\?q\=inlanefreight.com\&output\=json | jq . | grep name | cut -d":" -f2 | grep -v "CN=" | cut -d'"' -f2 | awk '{gsub(/\\n/,"\n");}1;' | sort -u

DNS Records

Reviewing DNS records complements these efforts by enumerating hostnames and revealing how the organization structures its public presence. Several records exist:

  • A records: the IP addresses that point to specific (sub)domain.
  • MX records: The mail server records show us which mail server is responsible for managing the email for the company.
  • NS records: show which name servers are used to resolve the FQDN to IP addresses =
  • TXT records: this type of record often contains verification keys for different 3rd party providers or other security features.
dig any $DOMAIN

Subdomain IP Mapping

Once Certificate Transparency or DNS enumeration gives subdomains, resolve them into IP addresses for service mapping.

# from that subdomain list we can generate a list of IP addresses
for i in $(cat subdomainlist);do host $i | grep "has address" | grep inlanefreight.com | cut -d" " -f1,4;done

Shodan Exposure Review

Tools such as Shodan enumerate Internet-facing systems by scanning for open TCP/IP ports, letting us map exposed services quickly.

# from an IP list query Shodan for more info
for i in $(cat ip-addresses.txt);do shodan host $i;done

Cloud Resources

Cloud resources can be vulnerable if configured improperly. Often cloud storage is added to the DNS list when used for administrative purposes (for easier access by employees).

  • Google Dorking is effective for this. Using search parameters such as inurl: and intext: can reveal files that are publicly accessible.
  • domain.glass can also tell us about the company’s infrastructure.
  • GrayHatWarfareis can also passively find files on a given cloud storage.

Staff

Discovering employees on social media platforms can reveal a lot about what technologies are being used based on their skillset.