Keyboard Shortcuts

Keyboard shortcuts are available for common actions and site navigation.

Skip to content
  • Home Home Home, current page.
  • About
  • Have an account? Log in
midnight_comms's profile
tilden-swans
tilden-swans
tilden-swans
@midnight_comms

Tweets

tilden-swans

@midnight_comms

void

Joined May 2019

Tweets

  • © 2019 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
tilden-swans‏ @midnight_comms

1. determine base domain

8:43 AM - 9 Dec 2019
  • 26 Retweets
  • 66 Likes
  • mikey Basibozuks Z | 0x5a . Sarah Picanso Nayssaj flux. Tuomo Makkonen T
2 replies 26 retweets 66 likes
    1. New conversation
    2. tilden-swans‏ @midnight_comms 21h21 hours ago

      2. use base domain to determine SSL/TLS organizational (O) strings and organizational unit (OU) strings -- you can use certificate transparency logs (https://www.certificate-transparency.org/ ), http://crt.sh , @censysio , https://transparencyreport.google.com/https/certificates …

      1 reply 0 retweets 0 likes
      Show this thread
    3. tilden-swans‏ @midnight_comms 21h21 hours ago

      3. determine DNS information derived from the base domain - items of note (A,AAAA,MX, NS, SPF, TXT, DKIM, SOA,CNAME,PTR) - more information here:https://www.farsightsecurity.com/txt-record/2017/12/01/stsauver-dnsrecords/…

      1 reply 0 retweets 1 like
      Show this thread
    4. tilden-swans‏ @midnight_comms 21h21 hours ago

      4. using the base domain, find all associated ASNs like this: inurl:bgpview intext:@domain.com

      1 reply 0 retweets 2 likes
      Show this thread
    5. tilden-swans‏ @midnight_comms 21h21 hours ago

      5. use the derived ssl O strings in @shodanhq to determine top items (most used) for a given organization. for example, find the most common favicons: `shodan stats ssl:"o=blah" --facets http.favicon.hash`

      1 reply 0 retweets 2 likes
      Show this thread
    6. tilden-swans‏ @midnight_comms 21h21 hours ago

      use the returned hashes and pair them with items in this table (if they are documented)https://github.com/sansatart/scrapts/blob/master/shodan-favicon-hashes.csv…

      1 reply 0 retweets 1 like
      Show this thread
    7. tilden-swans‏ @midnight_comms 20h20 hours ago

      there are some other useful facets as well: product, title, http.component, org, asn, vuln, etc

      1 reply 0 retweets 1 like
      Show this thread
    8. tilden-swans‏ @midnight_comms 20h20 hours ago

      6. once you've figured out the ASNs (earlier step) use them as a combined search to find odd or non-standard things: `shodan stats asn:1,2,3,4,5,6 --facets port` -- searches like this will highlight non-standard, or low count port utilization for a given organization

      1 reply 0 retweets 1 like
      Show this thread
    9. tilden-swans‏ @midnight_comms 20h20 hours ago

      7. find goodies using the ssl/tls strings you found before - example "o=blah" AND ldap OR "o=blah" AND emailaddress OR "o=blah" AND parsed.extensions.basic_constraints.is_ca: true || h/t @censysio - do all these searches using derived base domains too

      1 reply 0 retweets 2 likes
      Show this thread
    10. tilden-swans‏ @midnight_comms 20h20 hours ago

      8. reverse whois is a given (use the registrant email address) but also look for related domains using subs identified in filings (https://www.sec.gov/edgar/searchedgar/companysearch.html …), SOA pivots (other domains w/ same), SPF (^), adsense IDs, etc

      1 reply 0 retweets 1 like
      Show this thread
    11. tilden-swans‏ @midnight_comms 20h20 hours ago

      keep in mind SSL/TLS certificates have these little gems called alt-DNS AND the base O string will often be used to cut all certs for a given organization (including subsidiaries) -- so even if they use whoisprotect, etc, they still need to register that certificate

      1 reply 0 retweets 1 like
      Show this thread
    12. tilden-swans‏ @midnight_comms 20h20 hours ago

      no more freebies today- just keep in mind #osint #infosec #DFIR - asset management and #recon aren't difficult, people are still just approaching it using mechanisms that more than likely won't work in 2019

      0 replies 1 retweet 3 likes
      Show this thread
    13. End of conversation
    • © 2019 Twitter
    • About
    • Help Center
    • Terms
    • Privacy policy
    • Cookies
    • Ads info