CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
A penetration tester is performing a black-box assessment of a client's web application. During the discovery phase, the tester wants to identify publicly exposed subdomains that might not be directly linked from the main website but could host other applications or services. Which passive reconnaissance technique would be most effective for this purpose?
- ABrute-forcing common subdomain names with a wordlist.
- BUsing a search engine to query for `site:clientdomain.com`.
- CChecking Certificate Transparency logs for the client's domain.
- DPerforming a WHOIS lookup on the client's main domain.
Show answer & explanationAnswer & explanation
Correct answer: C. Checking Certificate Transparency logs for the client's domain.
Certificate Transparency logs publicly record all SSL/TLS certificates issued for domains. Reviewing these logs for a client's domain can reveal subdomains that might not be advertised elsewhere, as each subdomain often requires its own certificate.
Why the other options are wrong
- A. Brute-forcing subdomains is an active reconnaissance technique, not passive, and while effective, it's not the 'most effective passive technique' for initial discovery.
- B. Using `site:clientdomain.com` in a search engine will show indexed pages and subdomains, but it's limited to what search engines have crawled and indexed.
- D. WHOIS lookups provide registration information for a domain but generally do not list subdomains.
Certificate Transparency Logs
Public records of all SSL/TLS certificates issued by Certificate Authorities, designed to improve security by allowing domain owners to monitor for misissued certificates.
- Contains domain and subdomain names for which certificates were issued.
- Publicly accessible and searchable.
- Excellent source for passive subdomain enumeration.
Memory trick: Subdomains hide like branches on a digital tree.