CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy
A penetration tester is performing initial reconnaissance against a target organization. They want to identify publicly accessible subdomains associated with the main domain without directly interacting with the target's servers. Which of the following techniques would be most effective for this purpose?
- AQuerying Certificate Transparency logs.
- BRunning a Metasploit auxiliary scanner module for subdomain enumeration.
- CUsing 'dig axfr' against the target's DNS server.
- DPerforming a full TCP connect scan on common web ports.
Show answer & explanationAnswer & explanation
Correct answer: A. Querying Certificate Transparency logs.
Querying Certificate Transparency logs is a passive method to discover subdomains. These logs record all SSL/TLS certificates issued, which often include subdomains, without directly interacting with the target's infrastructure.
Why the other options are wrong
- B. Metasploit modules often perform active scans or brute-force, which is not passive.
- C. This is an active method and often blocked by properly configured DNS servers.
- D. This is an active scanning method that would directly interact with the target and could be detected.
Certificate Transparency (CT) Logs
Publicly auditable logs that record all SSL/TLS certificates issued by Certificate Authorities. They are a valuable resource for passive subdomain enumeration.
- Maintains a public record of all issued SSL/TLS certificates.
- Can reveal subdomains associated with an organization's primary domain.
- A passive reconnaissance technique as it doesn't interact with the target.
Memory trick: Certificates Reveal Hidden Names.