CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing reconnaissance against a target organization's web infrastructure. They have identified the main domain and want to find as many associated subdomains as possible without directly interacting with the target's DNS servers. They need a tool that can leverage various public data sources to achieve this passively. Which tool is best suited for this purpose?

  1. ANmap with `--script=dns-brute`
  2. BBurp Suite's 'Target' tab
  3. CMetasploit's 'auxiliary/gather/dns/dns_enum'
  4. DAmass
Show answer & explanation

Correct answer: D. Amass

Amass is a powerful and versatile open-source tool specifically designed for extensive passive subdomain enumeration. It gathers subdomain information from a multitude of public data sources like search engines, Certificate Transparency logs, WHOIS records, and more, without directly querying the target's DNS.

Why the other options are wrong

  • A. Nmap's dns-brute script performs active brute-forcing of DNS, directly interacting with the target's DNS.
  • B. Burp Suite's Target tab primarily maps the web application during active browsing, not for extensive passive subdomain discovery.
  • C. Metasploit's dns_enum module performs active DNS enumeration and zone transfer attempts, which are not passive.

Amass for Subdomain Enumeration

An open-source tool used for extensive passive subdomain enumeration by collecting data from various public OSINT sources like search engines, CT logs, and WHOIS records.

  • Aggregates data from many public sources.
  • Performs passive subdomain discovery.
  • Avoids direct interaction with target DNS servers.
  • Highly effective for comprehensive subdomain mapping.

Memory trick: AMASS Many Subdomains Quietly

More Reconnaissance and Enumeration questions