Sublist3r

Task 1 Intro

You can also use this site if you don't want to run Sublist3r: https://dnsdumpster.com/arrow-up-right

You can find Sublist3r herearrow-up-right! We'll install this in the next task.

circle-check

Task 2 Installation

First, let's change to our opt directory: cd /opt

circle-check

Next, let's clone the Sublist3r repository into opt: git clone https://github.com/aboul3la/Sublist3r.gitarrow-up-right

circle-check

Now let's move into the Sublist3r directory we've just created: cd /opt/Sublist3r

circle-check

Finally, let's install the requirements for running Sublist3r: pip3 install -r requirements.txt

circle-check

Task 3 Switchboard

What switch can we use to set our target domain to perform recon on?

circle-check

How about setting which engines we'll use for searching? (i.e. google, bing, etc)

circle-check

Saving our output is important both so we don't have to run recon again but also so we can return to our returns and review them at a later time. What switch do we use to define an output file?

circle-check

Sublist3r can sometimes take some time to run but we can speed through up the use of threads. Which switch allows us to set the number of threads?

circle-check

Last but not least, we can also bruteforce the domains for our target. This isn't always the most useful, however, it can sometimes find a key domain that we might have missed. What switch allows us to enable brute forcing?

circle-check

Task 4 Scans away!

Let's run sublist3r now against nbc.com, a fairly large American news company. Run this now with the command: python3 sublist3r.py -d nbc.com -o sub-output-nbc.txt

circle-check

Once that completes open up your results and take a look through them. Email domains are almost always interesting and typically have an email portal (usually Outlook) located at them. Which subdomain is likely the email portal?

circle-check

Administrative control panels should never be exposed to the internet! Which subdomain is exposed that shouldn't be?

circle-check

Company blogs can sometimes reveal information about internal activities, which subdomain has the company blog at it?

circle-check

Development sites are often vulnerable to information disclosure or full-blown attacks. Two developer sites are exposed, which one is associated directly with web development?

circle-check

Customer and employee help desk portals can often reveal internal nomenclature and other potentially sensitive information, which dns record might be a helpdesk portal?

circle-check

Single sign-on is a feature commonly used in corporate domains, which dns record is directly associated with this feature? Include both parts of this subdomain separated by a period.

circle-check
circle-check

Last updated