Subdomain Enumeration — TryHackMe Walkthrough 2022 (2024)

Subdomain Enumeration — TryHackMe Walkthrough 2022 (3)

Task 1: Brief

Subdomain enumeration is the process of finding valid subdomains for a domain, but why do we do this? We do this to expand our attack surface to try and discover more potential points of vulnerability.

We will explore three different subdomain enumeration methods: Brute Force, OSINT (Open-Source Intelligence) and Virtual Host.

What is a subdomain enumeration method beginning with B?

>> Brute Force

What is a subdomain enumeration method beginning with O?

>> OSINT

What is a subdomain enumeration method beginning with V?

>> Virtual Host

Task 2: OSINT — SSL/TLS Certificates

SSL/TLS Certificates

When an SSL/TLS (Secure Sockets Layer/Transport Layer Security) certificate is created for a domain by a CA (Certificate Authority), CA’s take part in what’s called “Certificate Transparency (CT) logs”. These are publicly accessible logs of every SSL/TLS certificate created for a domain name. The purpose of Certificate Transparency logs is to stop malicious and accidentally made certificates from being used. We can use this service to our advantage to discover subdomains belonging to a domain, sites like https://crt.sh and https://transparencyreport.google.com/https/certificates offer a searchable database of certificates that shows current and historical results.

Go to crt.sh and search for the domain name tryhackme.com, find the entry that was logged at 2020–12–26 and enter the domain below to answer the question.

What domain was logged on crt.sh at 2020–12–26?

Subdomain Enumeration — TryHackMe Walkthrough 2022 (4)

Task 3: OSINT — Search Engines

Search Engines

Search engines contain trillions of links to more than a billion websites, which can be an excellent resource for finding new subdomains. Using advanced search methods on websites like Google, such as the site: filter, can narrow the search results. For example, “-site:www.domain.com site:*.domain.com” would only contain results leading to the domain name domain.com but exclude any links to www.domain.com; therefore, it shows us only subdomain names belonging to domain.com.

Go to Google and use the search term -site:www.tryhackme.com site:*.tryhackme.com, which should reveal a subdomain for tryhackme.com; use that subdomain to answer the question below.

What is the TryHackMe subdomain beginning with B discovered using the above Google search?

Subdomain Enumeration — TryHackMe Walkthrough 2022 (5)

Task 4: DNS Bruteforce

Bruteforce DNS (Domain Name System) enumeration is the method of trying tens, hundreds, thousands or even millions of different possible subdomains from a pre-defined list of commonly used subdomains. Because this method requires many requests, we automate it with tools to make the process quicker. In this instance, we are using a tool called dnsrecon.

What is the first subdomain found with the dnsrecon tool?

Subdomain Enumeration — TryHackMe Walkthrough 2022 (6)

Task 5: OSINT — Sublist3r

Automation Using Sublist3r

To speed up the process of OSINT subdomain discovery, we can automate the above methods with the help of tools like Sublist3r.

What is the first subdomain discovered by sublist3r?

Subdomain Enumeration — TryHackMe Walkthrough 2022 (7)

Follow On: Linkedin | Twitter

Written By: Pratik Dhavade

Subdomain Enumeration — TryHackMe Walkthrough 2022 (2024)
Top Articles
Valentine's Day
Maximising Your Garden's Potential with Mushroom Compost | Daisy's Garden Supplies
Target Dummies 101 - The Dummy Research/Tutorial Thread
Best Places To Get Free Furniture Near Me | Low Income Families
Petco Clinic Hours
6 Underground movie review & film summary (2019) | Roger Ebert
Retail Jobs For Teens Near Me
Strange World Showtimes Near Harkins Metrocenter 12
Mta Bus Time Q85
Ucf Off Campus Partners
1v1 lol unblocked Game- Play Unblocked Game Online for Free!
Food Stamp System Down
Sites Like SkiptheGames Alternatives
Nail Shops Open Sunday Near Me
Spirited Showtimes Near Gqt Kalamazoo 10
The Athenaeum's Fan Fiction Archive & Forum
Envy Nail Bar Memphis
Busse Bladeforums
Retire Early Wsbtv.com Free Book
Greensboro, NC Breaking News Headlines Today | Ground News
Black Adam Showtimes Near Linden Boulevard Multiplex Cinemas
Craiglist Galveston
Southern Food Buffet Near Me
Venus Nail Lounge Lake Elsinore
Rhonda Rousey Nipple Slip
Adventhealth Employee Handbook 2022
Andhrajyoti
How to get tink dissipator coil? - Dish De
Myrtle Beach, South Carolina: Abwechslungsreicher Freizeitspaß unter der Südstaaten-Sonne
How to Grow Boston Fern Plants Outside - Gardening Channel
Bryant Air Conditioner Parts Diagram
Official Klj
10 Best Laptops for FL Studio in 2023 | Technize
Balmorhea Fishing Resort & Rv Spaces
Weather Tomorrow Hourly At My Location On Netflix Movies
Natalya's Vengeance Set Dungeon
Metalico Sharon Pa
Puppies For Sale in Netherlands (98) | Petzlover
Best Pizza In Ft Myers
Giant Egg Classic Wow
How to Survive (and Succeed!) in a Fast-Paced Environment | Exec Learn
Subway Surfers Unblocked 76
Bonbast قیمت ارز
Alvin Isd Ixl
Craigslist Nokomis Fl
Braveheart Parents Guide
World of Warcraft Battle for Azeroth: La Última Expansión de la Saga - EjemplosWeb
Salmon Fest 2023 Lineup
El Craigslist
Diora Thothub
Sdn Michigan State Osteopathic 2023
Fitgirl Starfield
Latest Posts
Article information

Author: Frankie Dare

Last Updated:

Views: 5594

Rating: 4.2 / 5 (53 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Frankie Dare

Birthday: 2000-01-27

Address: Suite 313 45115 Caridad Freeway, Port Barabaraville, MS 66713

Phone: +3769542039359

Job: Sales Manager

Hobby: Baton twirling, Stand-up comedy, Leather crafting, Rugby, tabletop games, Jigsaw puzzles, Air sports

Introduction: My name is Frankie Dare, I am a funny, beautiful, proud, fair, pleasant, cheerful, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.