Finding subdomains with dnsmap

dnsmap works a bit differently from the tools we looked at in the previous examples. dnsmap attempts to enumerate the subdomains of an organization's domain name by querying a built-in wordlist on the Kali Linux operating system. Once a subdomain has been found, dnsmap will attempt to resolve the IP address.

Using the dnsmap microsoft.com command, we are able to find subdomains for the organization and their corresponding IP addresses:

dnsmap results

As mentioned in a previous section, discovering the subdomains of an organization can lead to finding hidden and sensitive portals and directories in a domain.

Get Learn Kali Linux 2019 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.