web-attack-surface.md (8021B)
1 --- 2 title: "Web Attack Surface" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/access/web-attack-surface.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/web-attack-surface.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Web Attack Surface 12 13 ## Summary 14 15 * [Enumerate Subdomains](#enumerate-subdomains) 16 * [Subdomains Databases](#subdomains-databases) 17 * [Bruteforce Subdomains](#bruteforce-subdomains) 18 * [Certificate Transparency Logs](#certificate-transparency-logs) 19 * [DNS Resolution](#dns-resolution) 20 * [Technology Discovery](#technology-discovery) 21 * [Subdomain Takeover](#subdomain-takover) 22 * [References](#references) 23 24 ## Enumerate Subdomains 25 26 Subdomain enumeration is the process of identifying all subdomains associated with a main domain (e.g., finding `blog.example.com`, `shop.example.com`, etc., for `example.com`). 27 28 ### Subdomains Databases 29 30 Many databases and tools aggregate data from a variety of online sources, such as DNS databases, certificate transparency logs, APIs (e.g., Shodan, VirusTotal), and other publicly available sources to compile a comprehensive list of potential subdomains. 31 32 * [projectdiscovery/chaos-client](https://github.com/projectdiscovery/chaos-client) - Go client to communicate with Chaos DB API. 33 34 ```ps1 35 chaos -d hackerone.com 36 ``` 37 38 * [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) - Fast passive subdomain enumeration tool. 39 40 ```ps1 41 subfinder -d hackerone.com 42 ``` 43 44 * [owasp-amass/amass](https://github.com/owasp-amass/amass) - In-depth attack surface mapping and asset discovery 45 46 ```ps1 47 amass enum -d example.com 48 ``` 49 50 * [Findomain/Findomain](https://github.com/Findomain/Findomain) - The complete solution for domain recognition. 51 52 ```ps1 53 findomain -t example.com -u /tmp/example.com.out 54 ``` 55 56 ### Bruteforce Subdomains 57 58 Subdomain brute-forcing is a technique used to discover subdomains of a target domain by systematically trying out potential subdomain names against it. This is done by using a predefined list of common or likely subdomain names, known as a wordlist. Each word in the wordlist is appended to the target domain (e.g., admin.example.com, mail.example.com) to check if it resolves to a valid subdomain. 59 60 * [assetnote/wordlists](https://github.com/assetnote/wordlists) 61 * [danielmiessler/SecLists/Discovery/DNS](https://github.com/danielmiessler/SecLists/tree/master/Discovery/DNS) 62 * [jhaddix/all.txt](https://gist.github.com/jhaddix/f64c97d0863a78454e44c2f7119c2a6a) 63 64 Unlike passive subdomain enumeration, which relies on existing data from sources, brute-forcing actively queries DNS records to discover live subdomains that may not be listed in public databases. 65 66 * [infosec-au/altdns](https://github.com/infosec-au/altdns) - Generates permutations, alterations and mutations of subdomains and then resolves them. 67 68 ```powershell 69 altdns.py -i /tmp/inputdomains.txt -o /tmp/out.txt -w ./words.txt 70 ``` 71 72 * [owasp-amass/amass](https://github.com/owasp-amass/amass) - In-depth attack surface mapping and asset discovery. 73 74 ```ps1 75 amass enum -active -brute -o /tmp/hosts.txt -d $1 76 ``` 77 78 * [projectdiscovery/dnsx](https://github.com/projectdiscovery/dnsx) - A fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers. 79 80 ```ps1 81 dnsx -silent -d facebook.com -w dns_worldlist.txt 82 ``` 83 84 * [subfinder/goaltdns](https://github.com/subfinder/goaltdns) - A permutation generation tool written in golang. 85 86 ```ps1 87 altdns -l ./input_domains.txt -o ./output.txt 88 ``` 89 90 ### Certificate Transparency Logs 91 92 Certificate Transparency (CT) logs are public databases that record all SSL/TLS certificates issued by certificate authorities (CAs). These logs are designed to improve the security and transparency of the SSL/TLS ecosystem by making it easier to monitor and audit certificates. 93 94 * [CertStream Calidog](https://certstream.calidog.io/) 95 * [Meta Certificate Transparency](https://developers.facebook.com/docs/certificate-transparency) 96 * [Google Certificate Transparency](certificate.transparency.dev) 97 98 ### DNS Resolution 99 100 Once you've generated a list of potential subdomains, the next step is to resolve them to retrieve their DNS records (A and AAAA) to obtain their IPv4 and IPv6 addresses. 101 102 * [blechschmidt/massdns](https://github.com/blechschmidt/massdns) 103 104 ```ps1 105 cat /tmp/results_subfinder.txt | massdns -r ./resolvers.txt -t A -o S -w /tmp/results_subfinder_resolved.txt 106 ``` 107 108 * [projectdiscovery/dnsx](https://github.com/projectdiscovery/dnsx) - a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers. 109 110 ```ps1 111 subfinder -silent -d hackerone.com | dnsx -silent -a -resp 112 subfinder -silent -d hackerone.com | dnsx -silent -cname -resp 113 subfinder -silent -d hackerone.com | dnsx -silent -asn 114 echo 173.0.84.0/24 | dnsx -silent -resp-only -ptr 115 echo AS17012 | dnsx -silent -resp-only -ptr 116 ``` 117 118 ## Technology Discovery 119 120 Technology discovery is the process of identifying the underlying technologies, software, and frameworks used by a website or digital infrastructure. This often includes detecting web servers, CMS platforms, programming languages, databases, JavaScript libraries, and other software components. 121 122 * [projectdiscovery/httpx](https://github.com/projectdiscovery/httpx) - A fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library. 123 124 ```ps1 125 httpx -u 'https://example.com' -title -tech-detect -status-code -follow-redirects 126 ``` 127 128 * [projectdiscovery/wappalyzergo](https://github.com/projectdiscovery/wappalyzergo) - A high performance go implementation of Wappalyzer Technology Detection Library. 129 * [michenriksen/aquatone](https://github.com/michenriksen/aquatone) - A Tool for Domain Flyovers 130 131 ```ps1 132 cat hosts.txt | aquatone -ports 80,443,3000,3001 133 ``` 134 135 * [rverton/webanalyze](https://github.com/rverton/webanalyze) - Port of Wappalyzer in Go 136 137 ```ps1 138 webanalyze -host example.com -crawl 1 139 ``` 140 141 * [wappalyzer](https://www.wappalyzer.com/) - Identify technologies on websites. 142 143 ## Subdomain Takover 144 145 A subdomain takeover is a type of security vulnerability that occurs when a subdomain (e.g., `sub.example.com`) is still live but its DNS records point to a service or platform (like AWS S3, GitHub Pages, or Heroku) that is no longer active or properly configured. This situation can allow an attacker to claim the unclaimed resource and take control of the subdomain, enabling them to host malicious content or impersonate the legitimate website. 146 147 For example, if `sub.example.com` points to an AWS S3 bucket that has been deleted or abandoned, an attacker could create a new S3 bucket with the same name, gaining control over the subdomain and potentially causing security risks, like phishing attacks or reputational damage to the main domain. 148 149 Refer to [EdOverflow/can-i-take-over-xyz](https://github.com/EdOverflow/can-i-take-over-xyz) for a list of services and guidance on claiming subdomains with dangling DNS records. 150 151 * [projectdiscovery/nuclei-templates/http/takeovers](https://github.com/projectdiscovery/nuclei-templates/tree/main/http/takeovers) - Community curated list of templates for the nuclei engine to find security vulnerabilities. 152 153 ```powershell 154 nuclei -t nuclei-templates/http/takeovers -u https://example.com 155 ``` 156 157 * [anshumanbh/tko-subs](https://github.com/anshumanbh/tko-subs) - A tool that can help detect and takeover subdomains with dead DNS records 158 159 ```powershell 160 ./bin/tko-subs -domains=./lists/domains_tkos.txt -data=./lists/providers-data.csv 161 ``` 162 163 ## References 164 165 * [Subdomain Takeover: Proof Creation for Bug Bounties - Patrik Hudak (@0xpatrik) - May 21, 2018](https://0xpatrik.com/takeover-proofs/) 166 * [Subdomain Takeover: Basics - Patrik Hudak (@0xpatrik) - June 27, 2018](https://0xpatrik.com/subdomain-takeover-basics/)