Gather information about target systems using publicly available knowledge without directly engaging with the target.
Certificate Transparency
When passively gathering information, we can use third-party services to understand our target better. The main website is oftentimes what should be scrutinized first. Inspecting the SSL certificate for the target domain can expose sibling subdomains that share the same certificate, and cross-referencing Certificate Transparency logs on crt.sh helps surface newly issued certificates for related hosts.
# output results in json format
curl -s https://crt.sh/\?q\=$DOMAIN\&output\=json | jq .
# filter by subdomain
curl -s https://crt.sh/\?q\=inlanefreight.com\&output\=json | jq . | grep name | cut -d":" -f2 | grep -v "CN=" | cut -d'"' -f2 | awk '{gsub(/\\n/,"\n");}1;' | sort -uDNS Records
Reviewing DNS records complements these efforts by enumerating hostnames and revealing how the organization structures its public presence. Several records exist:
Arecords: the IP addresses that point to specific (sub)domain.MXrecords: The mail server records show us which mail server is responsible for managing the email for the company.NSrecords: show which name servers are used to resolve the FQDN to IP addresses =TXTrecords: this type of record often contains verification keys for different 3rd party providers or other security features.
dig any $DOMAINSubdomain IP Mapping
Once Certificate Transparency or DNS enumeration gives subdomains, resolve them into IP addresses for service mapping.
# from that subdomain list we can generate a list of IP addresses
for i in $(cat subdomainlist);do host $i | grep "has address" | grep inlanefreight.com | cut -d" " -f1,4;doneShodan Exposure Review
Tools such as Shodan enumerate Internet-facing systems by scanning for open TCP/IP ports, letting us map exposed services quickly.
# from an IP list query Shodan for more info
for i in $(cat ip-addresses.txt);do shodan host $i;doneCloud Resources
Cloud resources can be vulnerable if configured improperly. Often cloud storage is added to the DNS list when used for administrative purposes (for easier access by employees).
- Google Dorking is effective for this. Using search parameters such as
inurl:andintext:can reveal files that are publicly accessible. - domain.glass can also tell us about the company’s infrastructure.
- GrayHatWarfareis can also passively find files on a given cloud storage.
Staff
Discovering employees on social media platforms can reveal a lot about what technologies are being used based on their skillset.