Hacker News new | ask | show | jobs
by EQYV 465 days ago
Question: How does a subdomain get discovered by a member of the public if there are no references to it anywhere online?

The only thing I can think of that would let you do that would be a DNS zone transfer request, but those are almost always disallowed from most origin IPs.

https://en.m.wikipedia.org/wiki/DNS_zone_transfer

3 comments

See my comment above https://news.ycombinator.com/item?id=43289743 there are many techniques!
Certificate transparency logs.