当前位置:网站首页>Dry goods | three sub domain name collection tools worth collecting
Dry goods | three sub domain name collection tools worth collecting
2022-07-24 17:38:00 【Network security self-study room】
Preface
There are many tools and ways to collect subdomain names , But there are many tools that are not very easy to use , I think it's important to have several parameter values when blasting subdomains
One is whether there are complete ways for tools to collect subdomain names , Another is whether it will display title Information and response status code of subdomain name
title And the response status code can help us quickly identify what the website is about and whether it is accessible , Can improve us web The speed of dotting
Sort out several tools you often use :
oneforall fofa_view Search engine
One 、 utilize an instrument
oneforall
The first recommendation is oneforall This tool , See the project address at the end of the text for details
Depend on the environment :python3
tips: The directory where the tool is located cannot have a directory name with spaces , Otherwise, the file cannot be saved
Install dependencies first :
pip install -r requirements.txt
Profile Settings ( Individual be fond of , It's not necessary )
(1) open \OneForAll-master\config\setting.py, take result_export_alive = False Change it to True, Non surviving subdomains are not saved
(2) open \OneForAll-master\config\default.py, to small_ports Add scanned port small_ports = [80, 443, 8000, 8080, 8001, 8090, 7001, 8443]
Common usage
(1) Blasting target subdomain , And save for CSV file
oneforall.py --target jd.com --fmt csv run
The results are stored in \OneForAll-master\results\jd.csv in

Open the result file , But there are a lot of things , More chaotic , We can focus on the following fields of Frame Columns , Others can be deleted

Two 、 Using search engines
fofa_view
Will be fofa Made a graphical tool , Then introduce the fofa Of api Interface . Better than in a browser . See the project address at the end of the text for details
We download jdk file

To configure fofa api, No, fofa Members' words don't work
open config.properties To configure email and key value ( Sign in fofa Click the avatar personal Center —— The personal data —— Copy contact email and api key)

2. newly build fafa.bat file
Fill in :java -jar fofaviewer.jar
double-click bat File to start the fofa_view
And in the browser fofa The grammar is the same , Such as searching sub domain name

google grammar
Recommended google Search engine
Search subdomain , exclude www Main domain
site:jd.com -www

After the collection of these three tools , The subdomain is very different !
Reference material
[7]OneForAll:https://github.com/shmilylty/OneForAll
[8]fofa_viewer:https://github.com/wgpsec/fofa_viewer/releases
边栏推荐
- How the computer accesses the Internet (IV) LAN and server response
- ansible自动化运维详解(五)ansible中变量的设定使用、JINJA2模板的使用以及ansible的加密控制
- 2022 牛客暑期多校 K - Link with Bracket Sequence I(线性dp)
- Preliminary study of Oracle pl/sql
- Introduction and use of Pinia
- Today, I met a 38K from Tencent, which let me see the ceiling of the foundation
- Tensorflow introductory tutorial (37) -- DC Vnet
- 快速完成intelij idea的单元测试JUnit4设置
- AutoCAD - join merge command
- C语言实现静态版本的通讯录
猜你喜欢

Separation and merging of channels

C语言自定义类型讲解 — 结构体

地表最强程序员装备“三件套”,你知道是什么吗?

The latest Zhejiang construction safety officer simulation question bank and answers in 2022

Tensorflow introductory tutorial (38) -- V2 net

实习报告1——人脸三维重建方法

Practical application cases of digital Twins - Smart Park

Portfwd port forwarding

别再到处乱放配置文件了!试试我司使用 7 年的这套解决方案,稳的一秕

电脑监控是真的吗?4个实验一探究竟
随机推荐
Atcoder Beginner 202 E - Count Descendants(离线查询 重链剖分树上启发式合并)
Scept: consistent and strategy based trajectory prediction for planned scenarios
Huawei machine test - topic core test point
Step by step introduction to the development framework based on sqlsugar (12) -- split the content of the page module into components to realize the division and rule processing
Ipaylinks, a cross-border payment integration service, won the 3A Asia Award of treasury
HCNP Routing&Switching之DHCP中继
Socat port forwarding
Getaverse,走向Web3的远方桥梁
20 -- validate palindrome string
Wallys/3 × 3/2 × 2 MIMO 802.11ac Mini PCIe Wi-Fi Module, Dual Band, 2,4GHz / 5GHz/QCN9074
Yolopose practice: one-stage human posture estimation with hands + code interpretation
滚动条调整亮度和对比度
一个实际使用SwiftUI 4.0中ViewThatFits自适应视图的例子
700. 二叉搜索树中的搜索-dfs法
Link editing tips of solo blog posts illegal links
Scroll bar adjust brightness and contrast
portmap 端口转发
I'll teach you how to use NPs to build intranet penetration services. When you go out, you can easily connect your lightweight notebook to your home game console to play remotely
Openlayers: point aggregation effect
Pat class A - check in and check out