当前位置:网站首页>干货|值得收藏的三款子域名收集工具
干货|值得收藏的三款子域名收集工具
2022-07-24 17:31:00 【网络安全自修室】
前言
收集子域名的工具和方式有很多,但是有很多工具并不是很好用,我觉得在爆破子域名的时候有几个参数值是很重要的
一个就是工具收集子域名的途径是否齐全,再一个是是否会显示title信息以及子域名的响应状态码
title以及响应状态码能帮助我们迅速的识别该网站大概是干什么的以及是否可供访问,能提高我们web打点的速度
整理一下自己常用的几款工具:
oneforall fofa_view 搜索引擎
一、利用工具
oneforall
首先推荐的就是oneforall这款工具,具体介绍可看文末项目地址
依赖环境:python3
tips:工具所在的目录不能存在有空格的目录名称,否则文件无法保存
首先安装依赖:
pip install -r requirements.txt
配置文件设置(个人喜好,不是必须)
(1)打开\OneForAll-master\config\setting.py,将result_export_alive = False改为True,不存活的子域不保存
(2)打开\OneForAll-master\config\default.py,给small_ports添加扫描的端口 small_ports = [80, 443, 8000, 8080, 8001, 8090, 7001, 8443]
常用用法
(1)爆破目标子域,并保存为CSV文件
oneforall.py --target jd.com --fmt csv run
结果保存在 \OneForAll-master\results\jd.csv 中

打开结果文件,但是东西有点多,比较乱,我们可以着重关注如下框柱的字段,其他可以删了

二、利用搜索引擎
fofa_view
就是将fofa做成了一个图形化工具,然后引入fofa的api接口。比在浏览器中更好用。具体介绍可看文末项目地址
我们下载jdk文件

配置fofa api,没有fofa会员的话用不了
打开config.properties 配置email和key值(登录fofa后点击头像个人中心——个人资料——复制联系邮箱和api key)

2. 新建fafa.bat文件
填写:java -jar fofaviewer.jar
双击bat文件启动fofa_view
和浏览器中的fofa语法相同,如搜索子域名

google语法
推荐使用google搜索引擎
搜索子域名,排除www主域
site:jd.com -www

经过这三款工具的收集,子域就大差不差了!
参考资料
[7]OneForAll:https://github.com/shmilylty/OneForAll
[8]fofa_viewer:https://github.com/wgpsec/fofa_viewer/releases
边栏推荐
- Use yarn
- Is computer monitoring true? Four experiments to find out
- [how to optimize her] teach you how to locate unreasonable SQL? And optimize her~~~
- Introduction and use of Pinia
- What is the meaning of void 0? Is undefined changeable?
- 2022 牛客暑期多校 K - Link with Bracket Sequence I(线性dp)
- nc 端口转发
- Scept: consistent and strategy based trajectory prediction for planned scenarios
- [spoken English] 01 - Introduction to atom
- 微信朋友圈的高性能复杂度分析
猜你喜欢

Opencv has its own color operation

Step by step introduction to the development framework based on sqlsugar (12) -- split the content of the page module into components to realize the division and rule processing

hcip第三天

portmap 端口转发

Exception handling - a small case that takes you to solve NullPointerException

Atcoder Beginner 202 E - Count Descendants(离线查询 重链剖分树上启发式合并)

es(1)

近30所高校,获教育部点名表扬!

2022 Yangtze River Delta industrial automation exhibition will be held in Nanjing International Exhibition Center in October

Trends of semiconductor industry
随机推荐
Coldplay weekly issue 10
UFW port forwarding
Atcoder beginer 202 e - count descendants (heuristic merge on heavy chain split tree for offline query)
pinia 入门及使用
JS & TS learning summary
Ipaylinks, a cross-border payment integration service, won the 3A Asia Award of treasury
Atcoder Beginner 202 E - Count Descendants(离线查询 重链剖分树上启发式合并)
The results of the second quarter online moving people selection of "China Internet · moving 2022" were announced
Supervisor common commands
OpenCV 图片旋转
Natbypass port forwarding
Image information is displayed by browser: data:image/png; Base64, + image content
20 -- validate palindrome string
Scept: consistent and strategy based trajectory prediction for planned scenarios
安全:如何为行人提供更多保护
ShardingSphere数据库读写分离
Trends of semiconductor industry
Getaverse, a distant bridge to Web3
Iftnews | Christie's launched its venture capital department, aiming at Web3 and metauniverse industries
Portmap port forwarding