EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesHard

A penetration tester is performing a black-box assessment against a client's web application. They need to identify all subdomains associated with `example.com` to expand their attack surface. Which of the following methods would be most comprehensive for discovering subdomains without relying solely on DNS brute-forcing?

  1. ADirectly contacting the client's IT department for a list of all subdomains.
  2. BPerforming a `ping` sweep across the entire C-class network of `example.com`.
  3. CUsing passive subdomain enumeration tools that leverage Certificate Transparency logs and search engine indexing.
  4. DQuerying public DNS records using `dig` for `example.com`.
Show answer & explanation

Correct answer: C. Using passive subdomain enumeration tools that leverage Certificate Transparency logs and search engine indexing.

Passive subdomain enumeration tools gather information from publicly available sources like Certificate Transparency logs (which record all SSL/TLS certificates issued for a domain and its subdomains) and search engine results. This method is highly effective and comprehensive without being intrusive or requiring brute-forcing, which can be noisy.

Why the other options are wrong

  • A. Directly asking the client's IT department is not a reconnaissance technique used in a black-box penetration test; it bypasses the objective of discovering information as an external attacker would.
  • B. `ping` sweeps identify live hosts, but do not directly reveal subdomain names, and sweeping an entire C-class network might be too broad or trigger alerts.
  • D. `dig` queries only publicly available DNS records and might miss many subdomains, especially if they are not explicitly published or are internal.

Passive Subdomain Enumeration

Passive subdomain enumeration involves discovering subdomains of a target domain by querying publicly available datasets and services without directly interacting with the target's DNS servers or web servers.

  • Leverages sources like Certificate Transparency logs, DNS databases, search engines, and third-party APIs.
  • Examples of tools include Amass, Sublist3r, and online services.
  • It is a stealthier approach compared to active DNS brute-forcing.

Memory trick: Subdomains are branches; find them all without shaking the tree.

More Reconnaissance Techniques questions