How to Uncover Hidden Subdomains to Reveal Internal Services with CT-Exposer
Most companies have services like employee login portals, internal-only subdomains, and test servers they would prefer to keep private. Red teams and white hat hackers can find these obscure and often vulnerable services using a tool designed to help protect users from fraudulent certificates. What Is a Certificate Trust Log? Certificates are issued to companies operating online services by a certificate authority to protect users from being directed to fraudulent websites. In 2011, limitations in the ability of certificates to protect users were demonstrated by attacks against certificate... more
from WonderHowTo https://ift.tt/2xRWYos
via IFTTT
