> For the complete documentation index, see [llms.txt](https://sallam.gitbook.io/sec-88/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sallam.gitbook.io/sec-88/web-appsec/reconnaissance/attacking-organizations-with-big-scopes.md).

# Attacking Organizations with big scopes

https\://www\.youtube.com/watch?v=vFk0XtHfuSg

### Subdomain Enumeration

* Use BBOT it is the best <https://github.com/blacklanternsecurity/bbot>
* ```
  bbot -t ebay.com -f subdomain-enum
  ```

<figure><img src="https://2308035028-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWeYzWCIl8fzqyot9mus5%2Fuploads%2FhOkLNKKgVomCZL42GF5Z%2Fimage.png?alt=media&amp;token=beffc278-1f97-499f-b7c0-3a492d360bef" alt=""><figcaption></figcaption></figure>

### Reverse Whois

* <https://www.whoxy.com/>

### Virtual Hosts Identification

* Using Burp Intruder

<figure><img src="https://2308035028-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWeYzWCIl8fzqyot9mus5%2Fuploads%2F1CtWP9uTea0bbD8gu8Lt%2Fimage.png?alt=media&amp;token=2f1ef0c6-68a8-431d-aae4-3237e67ba30b" alt=""><figcaption></figcaption></figure>

* Using FFUF

```bash
ffuf -w namelist.txt -u http://10.129.184.109 -H "HOST: FUZZ.inlanefreight.htb".
```

* Gobuster

{% code overflow="wrap" %}

```bash
gobuster vhost -u http://10.129.118.153 -w namelist.txt -p pattern --exclude-length 301 -t 10
```

{% endcode %}

### ASN Mapping

* <https://bgp.he.net/>

```bash
cat iplist | cut -fi 
for i in $(cat iplist | cut -fi); do prips $i >> ips;done
cat fbsubs  
```

### Brute force IPs & Subdomains

```bash
for i in $(cat ips);do ffuf -w subs -u https://$i -H 'Host: FUZZ' -of csv -o $1.csv ; done
```

### Web Fuzzing&#x20;

> Create Custom Wordlist of the target

* Grap All URLs using (gau,katana)

```bash
cat "$RESULTS_DIR/subs.txt" | gau | sort -u >> "$RESULTS_DIR/urls"
cat domains | httpx | katana | sort -u >> "$RESULTS_DIR/urls"
```

* LinkFinder on all urls

```bash
cat urls | rush -j10 "python3 LinkFinder/linkfinder.py -o cli -i {} | sort -u >> ouput"
```

* Sorting

```bash
cat urls output | tr "/" "\n" | sort -u | more 
```

* Dorking\
  The asterisks (\*) are wildcards that match any character(s). In this case, the dork will match any domain or subdomain that contains the word "example".

```bash
site:*<example>* 
site:atlassian>*
site:*<atlassian.*>* 
site:*<*yahoo.*>*
site:*yahoo.*
```

* Bing Dorking
  * Remember the IP list we got from ASN?&#x20;
  * Use bing to find valid hosts on the server

```bash
Dork: “ip:127.0.0.1”
inbody:example
instreamset:(title url):example
```
