Attacking Organizations with big scopes

https://www.youtube.com/watch?v=vFk0XtHfuSg

Subdomain Enumeration

Reverse Whois

Virtual Hosts Identification

  • Using Burp Intruder

  • Using FFUF

  • Gobuster

ASN Mapping

Brute force IPs & Subdomains

Web Fuzzing

Create Custom Wordlist of the target

  • Grap All URLs using (gau,katana)

  • LinkFinder on all urls

  • Sorting

  • Dorking The asterisks (*) are wildcards that match any character(s). In this case, the dork will match any domain or subdomain that contains the word "example".

  • Bing Dorking

    • Remember the IP list we got from ASN?

    • Use bing to find valid hosts on the server

Last updated

Was this helpful?