Sublist3r was one of the first most used tools to search subdomains successfully, it also integrated subbrute to add a DNS brute force module, but lately it has been replaced by others like amass or subfinder due to lack of updates, sources and maintenance.

When brute forcing subdomains, the hacker iterates through a wordlist and based on the response can determine whether or not the host is valid.

recon-ng use use recon/domains-hosts/ # This will give you a vast amount of alternatives.


Bruteforce DNS (Domain Name System) enumeration is the method of trying tens, hundreds, thousands or even millions of different possible subdomains from a pre-defined list of commonly used subdomains.

In this video, I demonstrate how to perform DNS bruteforcing and subdomain enumeration with nmap, dnsmap, and fierce. SubBrute uses DNS Scan for finding subdomains of the target domain. To brute force a login form with a clusterbomb attack, with HTTP request, ffuf -request req.txt -request-proto http -mode clusterbomb -w usernames.txt:HFUZZ -w passwords.txt:WFUZZ SubBrute Tool For Subdomain Brute Force Last Updated : 14 Sep, 2021 SubBrute is a free and open-source tool available on GitHub. In a recent post, I showed you how to Brute-force Subdomains w/ WFuzz.

Brute forcing by using a user-supplied word list (as opposed to the built-in word list). This app will bruteforce for exisiting subdomains and provide the following information: + IP address + Host + if the 3rd party host has been properly setup. Improved built-in subdomains wordlist. In this example, `-a` is equivalent to `ANY` that is, it signals that the output will be verbose and `-l` signifies the use of zone transfer. Windows: python subenum.py -d example.com -w subdomain.txt. Bruteforce DNS is one of the enumeration methods used for finding commonly used subdomains. What is the first subdomain found with the dnsrecon tool? Sublis3r is the automation tool for finding subdomains. What is the first subdomain discovered by sublist3r? SubBrute is a community driven project with the goal of creating the fastest, and most accurate subdomain brute-forcing tool. As I mentioned earlier, it has the following dependencies, and you can install it using a yum command.

