Subdomain Enumeration — TryHackMe Walkthrough


Subdomain Enumeration is the process of finding subdomains for a domain name. We do this to spread out our attack surface and endeavor to find more potential vulnerabilities to exploit." There are three different subdomain enumeration methods:
Brute Force
OSINT
Virtual Host
OSINT - SSL/TLS Certificates
When an SSL/TLS (Secure Sockets Layer/Transport Layer Security) certificate is generated for a domain by a Certificate Authority (CA), the CA participates in a process known as "Certificate Transparency (CT) logs". These logs are publicly accessible and document every SSL/TLS certificate issued for a domain name. The main objective of Certificate Transparency logs is to prevent the misuse of malicious or mistakenly issued certificates. However, we can leverage this service to our advantage by utilizing it to uncover subdomains associated with a domain. Online platforms like https://crt.sh and https://ui.ctsearch.entrust.com/ui/ctsearchui provide searchable databases of certificates, displaying both current and historical results.

OSINT - Search Engines
Search Engines Search engines house an immense number of links, spanning trillions, directing to over a billion websites, making them a valuable resource for uncovering new subdomains. By employing sophisticated search techniques on platforms like Google, utilizing filters such as the site: operator, it is possible to refine the search results. For instance, the query "-site:www.domain.com site:*.domain.com" would exclusively display outcomes associated with the domain name, while excluding any links to www.domain.com. This approach enables us to isolate and identify solely the subdomain names belonging to domain.com.

DNS Bruteforce
Bruteforce DNS enumeration is the method of trying from tens to millions of different possible subdomains from a pre-defined list of commonly used subdomains. Due to this method requires many request, we automate it with tools to make the process quicker.
In this example we gonna use dnsrecon to bruteforce subdomain.
Brute-force: dnsrecon -d acmeitsupport.thm -D wordlist.txt -t brt
OSINT - Sublist3r
To speed up the process of OSINT subdomain discovery, we can automate the method we've used previously with help of tools like Sublist3r.
python sublist3r.py -d acmeitsupport.thm
Virtual Host
Some subdomains may not always be publicly accessible through DNS results. These could include development versions of web applications or administration portals. In such cases, the DNS records might be stored on a private DNS server or listed in the developer's local /etc/hosts file (or c:\windows\system32\drivers\etc\hosts file for Windows users), which maps domain names to IP addresses.
Web servers can host multiple websites from a single server. When a client requests a website, the server utilizes the Host header to identify which specific website the client wants. Exploiting this Host header, we can modify its contents and observe the server's response to determine if we have discovered a new website.
Similar to DNS brute-forcing, this process can be automated by employing a wordlist containing commonly used subdomains.
ffuf -w /home/ghost/Documents/SecLists/Discovery/DNS/namelist.txt -H "host: FUZZ.acmeitsupport.thm" -u http://10.10.218.36 -fs 2395
The above command uses the -w switch to specify the location of the wordlist that we're going to use. The -H switch modifies or adds a header (in this instance, the host header). The word 'FUZZ' is the subdomain that we're going to try with all the words from our wordlist. This is the place of the subdomain. -u specify the target URL. -fs switch filters the most occurring value of the HTTP response size.




