daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

web-attack-surface.md (8021B)


      1 ---
      2 title: "Web Attack Surface"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/access/web-attack-surface.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/web-attack-surface.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Web Attack Surface
     12 
     13 ## Summary
     14 
     15 * [Enumerate Subdomains](#enumerate-subdomains)
     16     * [Subdomains Databases](#subdomains-databases)
     17     * [Bruteforce Subdomains](#bruteforce-subdomains)
     18     * [Certificate Transparency Logs](#certificate-transparency-logs)
     19     * [DNS Resolution](#dns-resolution)
     20     * [Technology Discovery](#technology-discovery)
     21 * [Subdomain Takeover](#subdomain-takover)
     22 * [References](#references)
     23 
     24 ## Enumerate Subdomains
     25 
     26 Subdomain enumeration is the process of identifying all subdomains associated with a main domain (e.g., finding `blog.example.com`, `shop.example.com`, etc., for `example.com`).
     27 
     28 ### Subdomains Databases
     29 
     30 Many databases and tools aggregate data from a variety of online sources, such as DNS databases, certificate transparency logs, APIs (e.g., Shodan, VirusTotal), and other publicly available sources to compile a comprehensive list of potential subdomains.
     31 
     32 * [projectdiscovery/chaos-client](https://github.com/projectdiscovery/chaos-client) - Go client to communicate with Chaos DB API.
     33 
     34   ```ps1
     35   chaos -d hackerone.com
     36   ```
     37 
     38 * [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) - Fast passive subdomain enumeration tool.
     39 
     40   ```ps1
     41   subfinder -d hackerone.com
     42   ```
     43 
     44 * [owasp-amass/amass](https://github.com/owasp-amass/amass) - In-depth attack surface mapping and asset discovery
     45 
     46   ```ps1
     47   amass enum -d example.com
     48   ```
     49 
     50 * [Findomain/Findomain](https://github.com/Findomain/Findomain) - The complete solution for domain recognition.
     51 
     52   ```ps1
     53   findomain -t example.com -u /tmp/example.com.out
     54   ```
     55 
     56 ### Bruteforce Subdomains
     57 
     58 Subdomain brute-forcing is a technique used to discover subdomains of a target domain by systematically trying out potential subdomain names against it. This is done by using a predefined list of common or likely subdomain names, known as a wordlist. Each word in the wordlist is appended to the target domain (e.g., admin.example.com, mail.example.com) to check if it resolves to a valid subdomain.
     59 
     60 * [assetnote/wordlists](https://github.com/assetnote/wordlists)
     61 * [danielmiessler/SecLists/Discovery/DNS](https://github.com/danielmiessler/SecLists/tree/master/Discovery/DNS)
     62 * [jhaddix/all.txt](https://gist.github.com/jhaddix/f64c97d0863a78454e44c2f7119c2a6a)
     63 
     64 Unlike passive subdomain enumeration, which relies on existing data from sources, brute-forcing actively queries DNS records to discover live subdomains that may not be listed in public databases.
     65 
     66 * [infosec-au/altdns](https://github.com/infosec-au/altdns) - Generates permutations, alterations and mutations of subdomains and then resolves them.
     67 
     68   ```powershell
     69   altdns.py -i /tmp/inputdomains.txt -o /tmp/out.txt -w ./words.txt
     70   ```
     71 
     72 * [owasp-amass/amass](https://github.com/owasp-amass/amass) - In-depth attack surface mapping and asset discovery.
     73 
     74   ```ps1
     75   amass enum -active -brute -o /tmp/hosts.txt -d $1
     76   ```
     77 
     78 * [projectdiscovery/dnsx](https://github.com/projectdiscovery/dnsx) - A fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.
     79 
     80   ```ps1
     81   dnsx -silent -d facebook.com -w dns_worldlist.txt
     82   ```
     83 
     84 * [subfinder/goaltdns](https://github.com/subfinder/goaltdns) - A permutation generation tool written in golang.
     85 
     86   ```ps1
     87   altdns -l ./input_domains.txt -o ./output.txt
     88   ```
     89 
     90 ### Certificate Transparency Logs
     91 
     92 Certificate Transparency (CT) logs are public databases that record all SSL/TLS certificates issued by certificate authorities (CAs). These logs are designed to improve the security and transparency of the SSL/TLS ecosystem by making it easier to monitor and audit certificates.
     93 
     94 * [CertStream Calidog](https://certstream.calidog.io/)
     95 * [Meta Certificate Transparency](https://developers.facebook.com/docs/certificate-transparency)
     96 * [Google Certificate Transparency](certificate.transparency.dev)
     97 
     98 ### DNS Resolution
     99 
    100 Once you've generated a list of potential subdomains, the next step is to resolve them to retrieve their DNS records (A and AAAA) to obtain their IPv4 and IPv6 addresses.
    101 
    102 * [blechschmidt/massdns](https://github.com/blechschmidt/massdns)
    103 
    104   ```ps1
    105   cat /tmp/results_subfinder.txt | massdns -r ./resolvers.txt -t A -o S -w /tmp/results_subfinder_resolved.txt
    106   ```
    107 
    108 * [projectdiscovery/dnsx](https://github.com/projectdiscovery/dnsx) - a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.
    109 
    110   ```ps1
    111   subfinder -silent -d hackerone.com | dnsx -silent -a -resp
    112   subfinder -silent -d hackerone.com | dnsx -silent -cname -resp
    113   subfinder -silent -d hackerone.com | dnsx -silent  -asn
    114   echo 173.0.84.0/24 | dnsx -silent -resp-only -ptr
    115   echo AS17012 | dnsx -silent -resp-only -ptr 
    116   ```
    117 
    118 ## Technology Discovery
    119 
    120 Technology discovery is the process of identifying the underlying technologies, software, and frameworks used by a website or digital infrastructure. This often includes detecting web servers, CMS platforms, programming languages, databases, JavaScript libraries, and other software components.
    121 
    122 * [projectdiscovery/httpx](https://github.com/projectdiscovery/httpx) - A fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
    123 
    124   ```ps1
    125   httpx -u 'https://example.com' -title -tech-detect -status-code -follow-redirects
    126   ```
    127 
    128 * [projectdiscovery/wappalyzergo](https://github.com/projectdiscovery/wappalyzergo) - A high performance go implementation of Wappalyzer Technology Detection Library.
    129 * [michenriksen/aquatone](https://github.com/michenriksen/aquatone) - A Tool for Domain Flyovers
    130 
    131   ```ps1
    132   cat hosts.txt | aquatone -ports 80,443,3000,3001
    133   ```
    134 
    135 * [rverton/webanalyze](https://github.com/rverton/webanalyze) - Port of Wappalyzer in Go
    136 
    137   ```ps1
    138   webanalyze -host example.com -crawl 1
    139   ```
    140 
    141 * [wappalyzer](https://www.wappalyzer.com/) - Identify technologies on websites.
    142 
    143 ## Subdomain Takover
    144 
    145 A subdomain takeover is a type of security vulnerability that occurs when a subdomain (e.g., `sub.example.com`) is still live but its DNS records point to a service or platform (like AWS S3, GitHub Pages, or Heroku) that is no longer active or properly configured. This situation can allow an attacker to claim the unclaimed resource and take control of the subdomain, enabling them to host malicious content or impersonate the legitimate website.
    146 
    147 For example, if `sub.example.com` points to an AWS S3 bucket that has been deleted or abandoned, an attacker could create a new S3 bucket with the same name, gaining control over the subdomain and potentially causing security risks, like phishing attacks or reputational damage to the main domain.
    148 
    149 Refer to [EdOverflow/can-i-take-over-xyz](https://github.com/EdOverflow/can-i-take-over-xyz) for a list of services and guidance on claiming subdomains with dangling DNS records.
    150 
    151 * [projectdiscovery/nuclei-templates/http/takeovers](https://github.com/projectdiscovery/nuclei-templates/tree/main/http/takeovers) - Community curated list of templates for the nuclei engine to find security vulnerabilities.
    152 
    153     ```powershell
    154     nuclei -t nuclei-templates/http/takeovers -u https://example.com
    155     ```
    156 
    157 * [anshumanbh/tko-subs](https://github.com/anshumanbh/tko-subs) - A tool that can help detect and takeover subdomains with dead DNS records
    158 
    159     ```powershell
    160     ./bin/tko-subs -domains=./lists/domains_tkos.txt -data=./lists/providers-data.csv  
    161     ```
    162 
    163 ## References
    164 
    165 * [Subdomain Takeover: Proof Creation for Bug Bounties - Patrik Hudak (@0xpatrik) - May 21, 2018](https://0xpatrik.com/takeover-proofs/)
    166 * [Subdomain Takeover: Basics - Patrik Hudak (@0xpatrik) - June 27, 2018](https://0xpatrik.com/subdomain-takeover-basics/)