Recon - Hostnames discovery
DNS
SSL/TLS certificate
Virtual Hosts brute force
awk '{print $0 ".%s"}' <ORIGINAL_WORDLIST> > <WORDLIST>ruby scan.rb --ip=<IP> --host=<DOMAIN>
ruby scan.rb --ssl=on --wordlist=<WORDLIST> --ignore-http-codes=<HTTP_ERROR_CODE, [...]> --ip=<IP> --host=<DOMAIN>
VHostScan -t <IP> -b <DOMAIN>
VHostScan -t <IP> --ssl -w <WORDLIST> -b <DOMAIN> --ignore-http-codes <HTTP_ERROR_CODE, [...]>Last updated