Footprinting

Subdomain finder

curl -s https://crt.sh/?q=inlanefreight.com&output=json | jq .

Finding unique subdomains using crt.sh

curl -s https://crt.sh/?q=inlanefreight.com&output=json | jq . | grep name | cut -d":" -f2 | grep -v "CN=" | cut -d'"' -f2 | awk '{gsub(/\n/,"\n");}1;' | sort -u

Running Shodan CLI

for i in $(cat subdomainlist);do host $i | grep "has address" | grep inlanefreight.com | cut -d" " -f4 >> ip-addresses.txt;done
for i in $(cat ip-addresses.txt); do shodan host $i; done;

SAmple output:

DNS Records

Infrastructure

Last updated

Was this helpful?