Overview of Entire Methodology
- Identify IPs and Main TLDs
- Domain Scraping for Discovered TLDs
- Domain Bruteforcing, Resolve && Add new IP Ranges
- Portscan
- Visual Identification
- Platform Identification
- Content Discovery
- Parameter Discovery
Discovering IP Space
- Autonomous System Number â http://bgp.he.net
- Arin & Ripe â https://whois.arin.net/ui/query.do
https://apps.db.ripe.net/db-web-ui/#/fulltextsearch - Reverse Whois
https://reverse.report/ - Shodan Organization -
https://www.shodan.io/search?query=org%3A%22Tesla+Motors%22
Discovering New Targets (Brands & TLDs)
- Linked Discovery
1) Turn off passive scanning
2) Set forms auto to submit
3) Set scope to advanced control and use string of target name
4) Walk + Browse, Then Spider all hosts recursively
5) Profit - Be careful with email generating forms
- Setup Keyword search in host/ip Range
- Right Click all hosts found and click spider â Regex based on keyword
Domlink (Tool)
- Take an assigned domain and lookup on whoisâ¦