We don't always we have a situation where a client has defined a full detailed scope of what needs to be pentested. So we will use the following mentioned recipes to gather as much information as we can to perform a pentest.
Getting a list of subdomains
Fierce
We start with jumping into Kali's Terminal and using the first and most widely used tool fierce.
How to do it...
The following steps demonstrate the use of fierce:
- To launch fierce, we type fierce -h to see the help menu:
- To perform a subdomain scan we use the following command:
fierce -dns...