Finding subdomains with dnsmap

dnsmap works a bit differently from the tools we looked at in the previous examples. dnsmap attempts to enumerate the subdomains of an organization's domain name by querying a built-in wordlist on the Kali Linux operating system. Once a subdomain has been found, dnsmap will attempt to resolve the IP address.

Using the dnsmap command, we are able to find subdomains for the organization and their corresponding IP addresses:

dnsmap results

As mentioned in a previous section, discovering the subdomains of an organization can lead to finding hidden and sensitive portals and directories in a domain.

As you may have noticed, each tool we have used so far gives us a bit more detail. In the next section, we will use a more aggressive tool to help us to extract more details about a target domain.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.