Part 1:
- tcm-sec.com
- “tcm-sec.com”
- site:tcm-sec.com
- site:tcm-sec.com heath -academy
- site:tesla.com -www -shop -service
- good for finding subdomains
- BuiltWith - https://builtwith.com/
- Tells you what’s used to build the website
- Centralops.net
- whois records
- DNS records
- Service scan
- sometimes sees more subdomains or server data (LiteSpeed on TCM sec was leaking)
- PHP
- DNSlytics - https://dnslytics.com/reverse-ip
- finds what other websites are hosted on the same IP (View DNS looks cleaner)
- find the IP from CentralOps
- SpyOnWeb - https://spyonweb.com/
- Same owner
- Virus Total - https://www.virustotal.com/
- after a scan, under details, you can see a lot of info.
- Google tag manager, you can see the UA code
- This would let you search for it under SpyOnWeb and see if the same tracker is used on another website
- AKA tying websites together
- Reddit Domains: reddit.com/domain/bargainify.co/
- (This one actually works): thecybermentor.com on reddit.com
- hit or miss but you can see if this website has been posted. Potentially who posted it/owner and link things together
- Visual Ping - https://visualping.io/
- looking for website changes for free
- Back Link Watch - http://backlinkwatch.com/index.php
- find where the website has been posted on a website
- good for finding profiles, events sponsored, original designer/coder/etc
- View DNS - https://viewdns.info/
- So many options, pretty clean
Part 2:
- urlscan.io - https://urlscan.io/
- Gain info
- DNSdumpster - https://dnsdumpster.com/
- domain mapping
- Web Check - https://web-check.as93.net/
- subdomains
- txt files
- security best practices
- crt.sh - https://crt.sh/ (his favorite?)
- finding subdomains thru certificate search
- finding subdomains on tesla:
- %.tesla.com
- You can find dev related if you are trying to hack into them
- adm for admin
- stg for staging
Part 3:
- Shodan (I got premium!): https://shodan.io
- Explore (Explore (shodan.io))
- Most used feature: Webcam
- Search for IP to find vulnerabilities
- how he searches for clients:
- city:atlanta
- what if we want misconfiguration? RDP open to the internet? port 3389:
- city:atlanta port:3389
- narrow it to an organization:
- city:atlanta port:3389 org:choopa
- city:atlanta port:3389 org:"Equifax Inc.”
- narrow it down to maybe ISP business lines
- his example was AT&T Business after finding out many are AT&T
- Wayback Machine - https://web.archive.org/
- view page history
- Cache
- can bypass paywall, websites that don’t work anymore, or hidden data
- Google:
- cache:tesla.com
- cache:websiteYouWantHere.com