I wrote a script to resolve lists of domains from stdin, since dnsx and the like does not like my VPN settings.

(feedback appreciated - Bash noob)

github.com/n0kovo/dnsplz

#bugbounty #dns #dnsrecon #bash #shellscript #shellscripting #bashscript #enumeration #dnsenumeration #infosec

Last updated 2 years ago

rye · @rmaloley
124 followers · 600 posts · Server infosec.exchange

OK InfoSec what are we using for basic discovery/enumeration in a blackbox engagement? If I'm on Windows I would normally use AngryIP to discover subnets. On Linux however AngryIP is giving me a lot of false positives.

Ideally the tool shouldn't depend on open ports. Focus on ICMP _and_ portscan discovery capabilities that can be tailed to keep a running list of hosts/subnets.

#pentesting #enumeration #discovery #linux #kali

Last updated 2 years ago

ath0 · @scottlink
242 followers · 394 posts · Server infosec.exchange

: day 41 : Tinkered around with Docker some more. Experimenting with building an image w/enumeration tools. Getting rust onto the system for feroxbuster has me a bit stymied.

#hack100days #infosec #enumeration

Last updated 2 years ago

capaVirus · @capacityvirus
8 followers · 15 posts · Server infosec.exchange

Just posted a new blog on the topic of Passive Information Gathering.

In the post, we explore the various tools and techniques used for gathering information about a target system without directly interacting with it. Check it out to learn more about the power of and the benefits of using a tool like the Netcraft, Whois, and Google Dorking.

firewallchronicles.wordpress.c

Stay tuned for more updates on this subject, including additional tools and techniques to enhance your knowledge of Passive Information Gathering.

#InformationGathering #passiveinformationgathering #netcraft #enumeration #hacking #cybersecurity #tech #tools

Last updated 2 years ago

ΰΈΏ@πŸ…‚Ξ΅DΜ½Ν“:parrot: · @1337
16 followers · 136 posts · Server h4x0r.army

Red Team Tips February 1st: Safe Active Directory with m.youtube.com/watch?v=MRLZO17Z

#opsec #enumeration #silenthound

Last updated 2 years ago

Would anyone know if Mimecast works for on prem Exchange servers? I am working on enumerating a domain and have found a Microsoft TXT record, but can't find much outside of the MX being tied to Mimecast.

What I am trying to confirm now is if Mimecast would be sitting in front of Exchange in the cloud or if it can even support on prem.

Any input would be extremely helpful. Thanks!

#security #dns #mx #email #mimecast #phishing #enumeration

Last updated 2 years ago

sudoheader :verified: · @sudoheader
14 followers · 42 posts · Server infosec.exchange
WorldPopProject · @WorldPopProject
209 followers · 74 posts · Server mapstodon.space

New project - led by Dr Sarchil Qader and Edith Darin - Exploring the automatic pre-Enumeration Areas Tool for surveys on forced displacement -

#Refugees #Cameroon #unhcr #enumeration #survey

Last updated 2 years ago

Hey Masto. I recently made a highly efficient subdomain discovery wordlist by scanning the entire IPv4 space for SSL certs.

I've written a full article on the project, which is, in fact, my first public InfoSec article ever!

I would love to hear what you think!

You can read it here:
n0kovo.github.io/posts/subdoma

(boosts appreciated ❀️)

#infosec #writeup #redteam #pentesting #recon #reconnaissance #enumeration #subdomain #subdomains #wordlist #masscan #osint #bugbounty #bughunter #hacking

Last updated 2 years ago

Xenograg · @Xenograg
49 followers · 233 posts · Server dice.camp

I just noticed that tool phploc counts each as a . πŸ€·β€β™‚οΈ

#php #enumeration #class

Last updated 2 years ago

· @postmodern
817 followers · 430 posts · Server infosec.exchange

Which wordlists do people use the most frequently or know by name?

#infosec #wordlists #recon #enumeration #bruteforcing

Last updated 2 years ago

Evodefense · @evodefense
44 followers · 25 posts · Server infosec.exchange
Evodefense · @evodefense
40 followers · 23 posts · Server infosec.exchange
jmau111 · @jmau111
0 followers · 3 posts · Server infosec.exchange
jmau111 · @jmau111
0 followers · 4 posts · Server infosec.exchange

Need a quick way to find related domains?

I did, so I wrote a quick tool that abuses the SecurityTrails domain search suggestion API to grab a list of domains that start with [string].

I call it DomainDouche, since it's clearly using their API in a very unintended way and they probably wouldn't like it.

Grab it while it still works :)

github.com/n0kovo/DomainDouche

#osint #tool #domains #enumeration #recon #reconnaissance #InformationGathering #attacksurface #pentesting #redteam #infosec

Last updated 2 years ago

Evodefense · @evodefense
33 followers · 17 posts · Server infosec.exchange