Hacker News new | ask | show | jobs
by PostPlummer 2153 days ago
It is the new "zone transfer" without the IP addresses :)

There are companies that use private (not publicly resolvable) domains for which they create public certificates for internal hosts, that get published via CT.

Nice for OpsSec sleuthing.

Edit: how to find these "private domains"? Often public certificates contain more than one DNS names, of which one might be "private". YMMV