Finding subdomains with dnsmap

dnsmap works a bit differently from the tools we looked at in the previous examples. dnsmap attempts to enumerate the subdomains of an organization's domain name by querying a built-in wordlist on the Kali Linux operating system. Once a subdomain has been found, dnsmap will attempt to resolve the IP address.

Using the dnsmap microsoft.com command, we are able to find subdomains for the organization and their corresponding IP addresses:

dnsmap results

As mentioned in a previous section, discovering the subdomains of an organization can lead to finding hidden and sensitive portals and directories in a domain.

As you may have noticed, each tool we have used so far gives us a bit more detail. In the next section, we will use a more aggressive tool to help us to extract more details about a target domain.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.117.158.47