渗透信息收集速查手册(FOFA / Google / WHOIS / 域名与证书收集)

本手册仅用于授权的安全测试(渗透测试、红队、SRC/众测项目)。对未经授权的资产进行扫描探测属于违法行为,动手前务必确认授权范围与书面授权。 命令示例以 Linux / Windows PowerShell 两种环境给出,可按需替换。


目录

  1. FOFA 语法与使用场景
  2. Google Dorking(高级搜索语法)
  3. WHOIS 域名信息
  4. 域名 / 子域名收集方法
  5. 证书收集(Certificate Transparency)
  6. 推荐的信息收集工作流
  7. 常用命令速查表
  8. 复制即用模板(Copy-Paste 区)

一、FOFA 语法与使用场景

FOFA(fofa.so)是面向"主机资产"的网络空间搜索引擎,检索结果直接是 IP/端口级别的资产,适合快速圈定目标边界、发现暴露面。

1.1 核心字段

字段 说明 示例
host IP / 域名 / 主机名 host=example.com、host=10.0.0.0/8
domain 域名(含子域) domain=example.com(匹配 example.com 及其所有子域)
cert 证书 CN / SAN cert=example.com
ip 精确 IP ip=8.8.8.8
port 端口 port=443、port in 22,80,443
title 网页标题 title=管理后台
app 应用指纹(名称+版本) app="Apache:httpd-2.4.41"
service 服务指纹 service="OpenSSH"
banner 原始 banner(含 HTTP 头、SSH banner 等) banner="Server: nginx/1.18"
webserver Web 服务器 webserver="nginx"
component 组件/框架 component="ThinkPHP"
wapp Wappalyzer 指纹 wapp="WordPress"
country / city / region 地理信息 country="China"、city="Beijing"
idc 机房/IDC idc="阿里云"、idc="AWS"
as ASN as="4134"
header HTTP 响应头 header="X-Powered-By"
server Server 头 server="IIS"
os 操作系统 os="Windows"
fingerprint 自定义指纹(名称:内容) fingerprint="test"(配合高级搜索)
ics 工控设备 ics="Siemens:plc-s7-400"
device 设备 device="路由器"

1.2 运算符

  • and / or / not:逻辑组合。
  • = 精确匹配;~ 模糊匹配(如 ~管理 匹配 title 包含"管理")。
  • in 列表:port in 22,3389;host in a.com,b.com。
  • in_range:port in_range(8000,9000)。
  • 字符串字段建议用引号包裹空格内容:title="Admin Console"。
  • 字段名支持英文,中文界面下"主机=域名"写法(主机=example.com)也可用。

1.3 典型查询场景(直接套用改条件)

① 圈定公司资产边界(攻击面盘点)

domain=example.com
cert=example.com

先拿到全部 IP/端口,再和 WHOIS/子域枚举结果做交叉比对,发现"证书上出现过、但 DNS 已删"的僵尸子域。

② 找特定框架/组件(漏洞面定位)

component="ThinkPHP" && port=80
app="Apache:httpd-2.4.49"
wapp="Struts2"

配合已披露的 CVE 筛选组件版本,快速找高危版本暴露点。

③ 暴露后台 / 管理面板 / 调试接口

title="phpMyAdmin"
title="Web管理"
banner="X-Powered-By: JSP" && port=8080
host=example.com && (title="admin" || title="管理")

④ 信息泄露页面(未授权接口、敏感文件)

host=example.com && (banner="Server: Microsoft-IIS" && title="错误")
inurl 类似能力用 `title`/`banner` 组合近似替代;FOFA 没有 inurl,
需要 URL 级搜索时改用 Google dork / 直接爬取。

⑤ 默认口令面板(SRC 常见靶子)

title="设备管理" && service="HTTP"
app="华为:webOS"
ics="H3C"

⑥ 同 IP / 同证书反查(挖新资产)

ip=203.0.113.5          # 同 IP 上还有哪些域名
cert="example.com"      # 同证书 CN/SAN 有哪些域名

⑦ 机房/云厂商筛选

domain=example.com && idc="阿里云"
port=22 && country="China"

⑧ SSL 证书过期/配置粗糙 = 运维盲区

domain=example.com && service="SSL"

拿回资产后本地再验证证书有效期、弱密码套件(见第五节 openssl 部分)。

1.4 FOFA 使用注意

  • 需要账号;免费额度有限,搜索有频次限制(qsearch 语法),大量数据用 API(开发者文档)。
  • FOFA 结果是"最近一次扫描"的快照,可能漏掉新下线/新上线资产,务必与 DNS 枚举交叉。
  • 输出可导出 CSV,配合 Excel/Pandas 去重、按 title/app 聚类。

二、Google Dorking

Google(含 Bing/Startpage 等)的 site:/inurl: 等高级语法,用于发现具体 URL 与文件,是 FOFA 的重要补充(FOFA 无 inurl/filetype 能力)。

2.1 核心运算符

运算符 说明 示例
site: 限定站点 site:example.com
inurl: URL 路径包含 inurl:/admin
intitle: 标题包含 intitle:"system administrator"
intext: 正文包含 intext:confidential
filetype: 文件类型 filetype:pdf
"短语" 精确短语 site:example.com "password"
- 排除 site:example.com -www、filetype:pdf -inurl:.aspx
OR / 引号组合 多值 site:a.com OR site:b.com
cache: 缓存(现已基本失效,改用 Wayback) —
related: 相似站 related:example.com

2.2 常用 dork 模板

敏感文件泄露(历史有效、现在命中多为老站/测试站,但配合 SRC 仍值得跑)

site:example.com ext:pdf
site:example.com ext:doc
site:example.com ext:xls inurl:config
site:example.com filetype:sql
site:example.com ext:bak inurl:web.config
site:example.com ext:env
site:example.com ext:log

后台 / 管理面板

inurl:admin.php site:example.com
inurl:console site:example.com
intitle:"admin login" site:example.com
inurl:manager site:example.com
intitle:"后台管理" site:example.com

接口文档 / 调试端点(现代 Web 项目高频命中)

inurl:swagger site:example.com
inurl:actuator site:example.com
intitle:"swagger-ui"
inurl:debug site:example.com
inurl:phpinfo

子域名 / 影子资产挖掘(Google 索引的子域)

site:example.com -www.example.com
site:*.example.com
site:example.com inurl:/api/

泄露的凭证 / 内部信息(只对被授权目标用!)

site:github.com "example.com" password
intext:"accessKey"
site:pastebin.com "example.com"

2.3 Dork 使用注意

  • Google 对大量 dork 有反滥用限速(验证码/拒绝),可换 Bing:site:x.com ext:pdf 在 Bing 同样支持大部分运算符。
  • 结果受 Google 索引新鲜度影响;对"已删除但被 Google 缓存过"的页面,查 Wayback Machine(http://web.archive.org/cdx/search/cdx?url=example.com*&output=json&fl=original,timestamp,statuscode&collapse=urlkey 可批量拉取历史 URL,是挖旧后台/旧子域的神器)。
  • 多关键词组合要加引号:"system administrator" intitle:"index of"。

三、WHOIS 域名信息

3.1 查询内容(能拿到什么)

  • 注册人 / 注册机构、注册日期与到期日期(判断域名生命周期、临期=可抢注/变更风险)
  • 域名状态(serverTransferProhibited 等锁定期状态)
  • Name Server(NS 记录) → 发现使用的 DNS 服务商
  • 注册邮箱 → 可反查该邮箱名下其他域名(whois -h whois.verisign-grs.com "email xxx" 或专门查 RDAP)
  • 滥用联系方式(abuse contact)→ 用于报 0day/滥用
  • 部分注册局的"持有者"信息(注意 GDPR 后欧美域名大多已匿名化,中国 .cn 仍可能返回真实信息)

3.2 命令用法

Linux / WSL

whois example.com                 # 自动路由到 .com 注册局 (Verisign)
whois example.cn                  # 路由到 中央 registry
whois -h whois.verisign-grs.com "registrar name XXX"   # 查某注册商名下所有域名
whois -h whois.cnnic.cn "example.cn"                   # 指定注册局服务器
whois -T                          # 以文本列表输出
whois -H                          # 显示 header
# 批量:for d in $(cat doms.txt); do whois "$d" | grep -Ei 'Domain Name|Registrar|Expir' ; done

注意:whois 有速率限制(Verisign 对单 IP 批量查询会直接拒绝),批量场景要加 sleep 或用付费数据源(DomainBigData、SecurityTrails 等)。 部分 TLD(.us/.cc/.us/.tk 等)返回信息极少,优先用 RDAP。

Windows PowerShell(无原生 whois,三种方案)

# 方案 1:winget / choco 装 whois
winget install whois.whois        # 或 choco install whois
whois example.com

# 方案 2:用 PowerShell 直连 43 端口(无 whois 命令时的兜底)
$tcp = New-Object System.Net.Sockets.TcpClient("whois.verisign-grs.com", 43)
$stream = $tcp.GetStream()
$bytes = [System.Text.Encoding]::UTF8.GetBytes("example.com`r`n")
$stream.Write($bytes, 0, $bytes.Length)
$buf = New-Object byte[] 65535
$read = $stream.Read($buf, 0, $buf.Length)
[System.Text.Encoding]::UTF8.GetString($buf, 0, $read)
$tcp.Close()

# 方案 3:在线 RDAP(免安装,HTTP API,见下)

RDAP(REST 版 whois,推荐,浏览器直接可用)

https://rdap.org/domain/example.com          # 自动重定向到正确注册局
https://rdap.verisign.com/v2/domain/example.com
curl -s https://rdap.org/domain/example.com
# PowerShell:
Invoke-RestMethod https://rdap.org/domain/example.com | ConvertTo-Json -Depth 5

RDAP 返回 JSON,字段含 nameservers、events(registration/expiration)、entities(registrant/registrar,脱敏状态看 publicIds 与 vcardArray)。

3.3 WHOIS 使用场景

场景 做法
目标边界确认 查主域 NS + 注册机构 → 用注册商邮箱/注册机构反查其名下其他域名(whois -h whois.verisign-grs.com "email=xxx")
域名到期抢注(授权范围内) 查 Expiry Date,临期域名可被抢注改绑,属于供应链风险点
判断域名是否"僵尸域" 注册时间远早于当前业务 + whois 无更新 = 可能遗留资产
DNS 服务商识别 NS 记录 → 判断 DNSPod/阿里云/Cloudflare/自建 DNS,为后续 DNS 爆破/子域收集定策略
隐私泄露 whois 未脱敏 = 可直接拿邮箱/电话,用于社会工程(仅授权内)

3.4 相关命令

dig NS example.com          # 权威 NS
dig +short MX example.com   # 邮件服务器(MX 常暴露测试环境/子域)
dig +short TXT example.com  # SPF/DMARC,SPF 里常带第三方服务域名
dig +short CAA example.com  # CAA 记录(限制谁可签证书)

四、域名 / 子域名收集方法

信息收集的骨架:主域 → 子域(主动 DNS + 被动数据源)→ IP 反查 → 端口 → 服务 → 指纹。

4.1 DNS 基础记录收集

# 一条命令全记录
dig example.com ANY
dig +short A example.com; dig +short AAAA example.com
dig +short CNAME *.example.com   # 不能通配,配合子域枚举
dig +short MX example.com        # MX 里常有 test.mail / 三方
dig +short TXT _dmarc.example.com
dig +short NS example.com

# PowerShell
Resolve-DnsName example.com -DnsOnly
Resolve-DnsName example.com -Type MX -DnsOnly

通配 DNS(wildcard):随机乱码子域也返回 IP = 该域启用了通配解析,爆破会全是假阳性。用 dig +short $(cat /dev/urandom | head -c 16).example.com 探测,或用 httpx -probe 过滤(只保留真实有 HTTP 响应的)。

4.2 被动数据源(不触网目标,最安全、最优先)

数据源 用法
crt.sh 证书透明度日志,见第五节(子域收集主力)
Wayback Machine (CDX API) http://web.archive.org/cdx/search/cdx?url=*.example.com*&output=json&collapse=urlkey&fl=original → 挖历史子域/旧后台
Common Crawl 全量爬取索引,CC 的 commoncrawl-index 可直接按 domain=example.com 查 URL
VirusTotal / urlscan.io 输入 IP/域名看关联域名、证书 SAN、扫描历史
AlienVault OTX / IntelMine / 微步/奇安信威胁情报 威胁情报关联 IOC
SecurityTrails / 子域名数据(subdomains.info、dnsthat等) 商业/免费子域 API
GitHub 代码搜索 https://github.com/search?q=example.com&type=code → 挖测试环境/内网域名/硬编码密钥(intext 思路)
Shodan / FOFA / Censys / ZoomEye 直接按 domain=/cert= 拉资产,见第一节
DNS 历史(SecurityTrails passive DNS) 历史上解析过的 IP 关联

4.3 主动枚举(工具)

工具 说明
subfinder 被动 + 主动子域枚举主力,subfinder -d example.com -all -o sub.txt
amass 深度,支持 passive/active 多阶段,amass enum -d example.com -o out.json
OneForAll 国内常用,聚合大量国内数据源(含被动 API)
assetnote / 手工 见上
字典爆破 feroxbuster 不适用子域;用 dnsrecon -domain example.com -brute example(带字典 wordlist),或 gobuster dns -d example.com -w wordlist
dnsx 批量解析子域全部记录:dnsx -l subs.txt -a -aaaa -cname -mx -txt -resp
httpx 子域 → 活站过滤:httpx -l subs.txt -follow-redirects -json(识别通配假阳性)

推荐流水线(Linux)

subfinder -d example.com -all -o raw_subs.txt
cat raw_subs.txt | dnsx -a -resp -silent > subs_resolved.txt
cat subs_resolved.txt | httpx -follow-redirects -nonstd -title -tech-detect -o alive.txt

Wordlist 推荐:SecLists/Discovery/DNS/subdomains-top1million-20000.txt、自研业务词表(公司名+常见前缀 test/dev/staging/admin/api/mgmt/git + 员工姓氏)。

4.4 子域 → IP → 反查

# 子域解析出的 IP 反查 C 段 / PTR
dig +short A web.example.com | xargs dig +short -x
# 同 IP 还有哪些域名(配合 FOFA / Shodan)
shodan host 1.2.3.4
# nmap 批量端口
nmap -p- -sV -oN ports.txt $(cat ips.txt)

同 IP 共享服务器(尤其云厂商)是"影子资产"最大来源;IP 段内邻居(/24)也值得 nmap -sn 扫存活。

4.5 其他域名级技巧

  • 证书 SAN 挖域名:见第五节(crt.sh 一条 JSON 就能拿全)。
  • 拼写变体:.com/.cn/.net/.top、example.com.cn vs example.com vs example.net,逐个 whois。
  • 短服务/云存储桶:s3.amazonaws.com 桶名爆破(rclone lsd s3: / 自建 cloud_enum)、azurewebsites.net 自定义域。
  • CNAME 追踪:CNAME → CDN/API 网关,反查 CNAME 目标可发现同厂商其他站点。
  • 邮件域反查:MX 指向的 mail.xxx.com、mx.mail0.xyz 常是独立子域。

五、证书收集(Certificate Transparency)

证书透明度(CT)日志公开了全球 CA 签发的所有证书,免费、批量、不触网目标,是挖"DNS 已删但证书里还有"的僵尸子域最有效的手段。

5.1 主力工具:crt.sh

# 浏览器 / curl
https://crt.sh/?q=%25.example.com
# %25 = URL 编码的 %,匹配 example.com 及所有子域
# 直接 curl JSON(脚本化首选):
curl -s "https://crt.sh/?q=%25.example.com&output=json"
# PowerShell:
Invoke-RestMethod "https://crt.sh/?q=%25.example.com&output=json" | ConvertTo-Json

JSON 每条记录含 value(域名,*.sub.example.com 形式)与 identifier_value,一条命令抽子域:

curl -s "https://crt.sh/?q=%25.example.com&output=json" \
 | jq -r '.[].name_value' \
 | sort -u > crt_subs.txt
# 去掉通配符: sed 's/^\*\.//' crt_subs.txt

大域(万级子域)crt.sh 会截断分页,改用 certspotter(免费 API,带限速):

https://api.certspotter.com/v1/issuances?domain=example.com&include_subdomains=true&expand=dns_names

5.2 其他 CT / 证书数据源

数据源 用法
censys search?query=domains:example.com,证书历史全
Shodan domain:example.com 结果带证书序列号
ZoomEye domain:example.com / cert:example.com
VirusTotal 证书序列号反查
SSL Labs (Qualys) 单主机证书+套件完整评估(弱算法/过期/链不完整)
Censys CT API / Google CT Monitor 原始 CT log 查询

5.3 本地验证(不依赖在线服务)

# 证书全量查看(有效期、SAN、issuer、序列号)
openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -text -dates

# 只看 SAN(找隐藏子域)
openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"

# 批量拉子域证书 SAN(脚本化)
for h in $(cat subs.txt); do
  timeout 5 openssl s_client -connect "$h:443" -servername "$h" 2>/dev/null \
   | openssl x509 -noout -ext subjectAltName 2>/dev/null | grep -oP '(?<=DNS:).*'
done | sort -u

# 证书指纹(比较两个站是否同一张证书)
openssl s_client -connect a.com:443 2>/dev/null | openssl x509 -noout -fingerprint -sha256

Windows PowerShell(无 openssl 时)

# .NET 直接拉证书
$cert = (New-Object System.Net.Sockets.TcpClient("example.com",443)).GetStream() |
        # 实际用下面的完整写法:
$tcp = New-Object System.Net.Sockets.TcpClient("example.com", 443)
$ssl = New-Object System.Net.Security.SslStream($tcp.GetStream(), $false, { $true })
$ssl.AuthenticateAsClient("example.com")
$cert = $ssl.RemoteCertificate
$cert.Subject; $cert.Issuer; $cert.NotAfter; $cert.Thumbprint
# SAN(需要读证书原文):
$asn1 = [System.Security.Cryptography.X509Certificates.X509Certificate2]::new($cert.Export("PKCS12"))
# 简单办法:用 Get-ChildItem 读本机信任库 / 直接 curl 在线服务

批量 SAN 枚举建议 WSL / 脚本 + curl crt.sh,比 PowerShell 手写 TLS 干净。

5.4 证书收集的渗透价值(重点)

场景 说明
僵尸子域(Stale Subdomains) 证书 SAN 里有 old-mgmt.example.com,DNS 已删但证书还有效(最长 90 天 CT 可见窗口)→ HTTP 请求仍可能命中原服务器(CNAME 残留/裸 IP 访问/泛解析)。这是子域接管(Subdomain Takeover)的主要入口
子域接管判定 子域 CNAME 指向已释放的 S3/Azure/GitHub Pages/Heroku 资源 → 抢注该资源接管整站(CT 日志帮你找候选)
证书链异常 = 弱运维 自签/中间 CA/证书过期/不匹配 SAN → 提示目标安全水位低,横向探测价值高
HSTS / 证书 pinning openssl s_client 看响应头 strict-transport-security,评估降级攻击可行性
弱套件 SSL Labs 评估:SHA1 签名、RSA<2048、TLS 1.0/1.1、RC4 → 记录 + 可选降级
CA 供应链 看 issuer 是否为目标自建 CA(内部 PKI 泄露到公网 = 重大发现)

5.5 证书 → 新 IP 的闭环

crt.sh 子域 → 批量 A 记录(dnsx)→ httpx 活站 → nmap 端口 → 指纹

同时把证书 serial 记下来,后续在 Censys/Shodan 按序列号查"同一张证书被签发在哪些主机"。


六、推荐的信息收集工作流(完整链路)

输入:目标公司 / 主域 example.com
  │
  ├─ 1. WHOIS / RDAP:NS、注册商、注册邮箱 → 反查邮箱名下其他域(whois -h whois.verisign-grs.com)
  ├─ 2. 域名变体:.cn/.com/.net、com.cn、corp.example.com… 逐个 dig + RDAP
  ├─ 3. 被动子域:crt.sh + certspotter + Wayback CDX + GitHub 代码搜索 + Shodan/FOFA/ZoomEye 的 domain= 检索
  ├─ 4. 主动子域:subfinder/amass/OneForAll + 字典爆破(feroxbuster 不适用,用 gobuster/dnsrecon)
  ├─ 5. 合并去重 → 通配 DNS 探测 → dnsx 解析全记录(A/AAAA/CNAME/MX/TXT/CAA)
  ├─ 6. httpx 活站过滤(-title -tech-detect,识别 CDN)
  ├─ 7. 同 IP 反查(FOFA ip= / Shodan host / 邻居 /24 nmap -sn)
  ├─ 8. 端口服务指纹:nmap -sV -sC + FOFA host= 交叉(拿 title/app/banner)
  ├─ 9. URL 级:对每个活站跑目录爆破(feroxbuster/gobuster dir)+ Swagger 探测(/swagger.json /swagger-ui.html /api-docs /actuator)
  ├─ 10. 证书:openssl s_client 拉全量证书 + SSL Labs 弱项
  └─ 11. 归档:资产清单(域/IP/端口/服务/版本/证书/NS/MX/邮箱)→ 授权范围内挑高价值目标渗透

优先级口诀:被动先于主动(不触网、不留痕、最快)→ 子域/证书挖影子资产 → 活站过滤 → 端口与指纹 → 目录/接口爆破。


七、常用命令速查表

目的 命令
全记录 DNS dig example.com ANY / Resolve-DnsName example.com -DnsOnly
子域 DNS dig +short A web.example.com
反查 IP 域名 dig +short -x 1.2.3.4
WHOIS(Linux) whois example.com
WHOIS(注册商域名字典) whois -h whois.verisign-grs.com "email=reg@example.com"
RDAP curl -s https://rdap.org/domain/example.com
crt.sh JSON curl -s "https://crt.sh/?q=%25.example.com&output=json"
Wayback 历史 URL curl "http://web.archive.org/cdx/search/cdx?url=example.com*&output=json&fl=original,statuscode&collapse=urlkey"
子域枚举 subfinder -d example.com -all -o sub.txt
子域解析 dnsx -l sub.txt -a -cname -mx -txt -resp
活站过滤 httpx -l sub.txt -title -tech-detect -follow-redirects
端口 nmap -sV -sC -p- -T4 -oN scan.txt <ip>
证书 SAN openssl s_client -connect h:443 -servername h </dev/null 2>/dev/null | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"
Google dork site:example.com ext:pdf / inurl:swagger site:example.com
FOFA domain=example.com / title=后台 && host=example.com / cert=example.com
邮件/SPF 挖三方域 dig +short TXT example.com | grep -oE "[a-z0-9.-]+\.[a-z]{2,}" | sort -u

合规提醒(每次渗透前重读)

  1. 只扫授权范围内的资产;NS/注册商/同 IP 邻居等"越界探测"前先确认授权文本是否涵盖(很多合同只写主域)。
  2. 被动数据源(crt.sh、Wayback、Shodan、GitHub)不触网目标,任何时候都可以做。
  3. 主动爆破(nmap -sV、目录爆破、子域爆破)对目标产生直接流量,控制在授权窗口与速率内。
  4. 发现的漏洞走漏洞报告流程,不要直接利用(除非授权明确允许 POC 验证)。

八、复制即用模板

所有模板统一约定:把 example.com 替换成目标主域即可直接运行。Linux 模板在 bash/WSL 下运行,PowerShell 模板在 Windows 下运行。

8.1 FOFA 查询模板(浏览器直接粘贴搜索框)

# ── 目标全部资产(先跑这条)────────────────
domain=example.com
cert=example.com

# ── 框架 / 组件 / 版本面 ─────────────────────
component="ThinkPHP" && port=80
app="Apache:httpd-2.4.49"
wapp="WordPress" && country="China"

# ── 暴露后台 / 面板(限定目标域)────────────
host=example.com && (title="管理" || title="admin" || title="console" || title="swagger")

# ── 调试 / 运维接口 ─────────────────────────
host=example.com && (banner="X-DEBUG" || title="phpinfo")

# ── 默认口令面板(全互联网,限定机房)────────
title="设备管理" && idc="阿里云"
ics="Huawei" && port=80

# ── 同 IP 反查 / 同证书反查 ─────────────────
ip=203.0.113.5
cert="example.com" && host!=203.0.113.5

8.2 Google / Bing dork 模板(搜索框直接粘贴)

# 站点全量 + 排除主站
site:example.com -www.example.com

# 敏感文件(四个 ext 一起跑,命中即记录)
site:example.com ext:pdf
site:example.com ext:env
site:example.com ext:bak
site:example.com ext:log inurl:admin

# 接口文档 / 调试端点
inurl:swagger site:example.com
inurl:actuator site:example.com
inurl:phpinfo site:example.com
inurl:.git site:example.com

# 后台入口
inurl:admin.php site:example.com
intitle:"后台管理" site:example.com
inurl:console site:example.com

8.3 在线查询链接模板(浏览器直接打开,替换域名)

https://rdap.org/domain/example.com                  # RDAP 域名注册信息(JSON)
https://crt.sh/?q=%25.example.com                    # CT 证书子域(网页版)
https://api.certspotter.com/v1/issuances?domain=example.com&include_subdomains=true&expand=dns_names
http://web.archive.org/cdx/search/cdx?url=example.com*&output=json&fl=original,statuscode&collapse=urlkey   # 历史 URL
https://github.com/search?q=example.com&type=code    # 代码泄露(域名/密钥/测试环境)
https://urlscan.io/search/#domain:example.com        # 扫描历史 + 证书 SAN
https://ssl-tools.site/audit/?d=example.com          # 证书 / 套件评估

8.4 WHOIS 模板(bash,Linux/WSL)

# ── 单域名基础信息(过滤关键字段)──────────────────────────
whois example.com | grep -Ei "Domain Name|Registrar:|Registrant|Created|Expir|Name Server|Status|Email"

# ── 用注册商邮箱反查名下所有域名(先拿到 Email 再填)──────
whois -h whois.verisign-grs.com "email=reg@example.com"

# ── 批量查一批域名的注册信息(注意限速,sleep 调大)────────
# 域名放 doms.txt,一行一个
while read d; do
  echo "===== $d ====="
  whois "$d" | grep -Ei "Domain Name|Expir|Name Server" || echo "(no data / rate limited)"
  sleep 3
done < doms.txt

8.5 子域名收集一条流水线(bash,需要 subfinder/dnsx/httpx)

# ── 一键收集:被动源 + 主动枚举 + 解析 + 活站过滤 ───────────
T=example.com
mkdir -p osint_$T && cd osint_$T

# ① 被动:crt.sh + certspotter + subfinder 被动部分
curl -s "https://crt.sh/?q=%25.$T&output=json" \
  | jq -r '.[].name_value' | sed 's/^\*\.//;s/\.$//' | sort -u > crt.txt
curl -s "https://api.certspotter.com/v1/issuances?domain=$T&include_subdomains=true&expand=dns_names" \
  | jq -r '.[].dns_names[]' | sort -u > certspotter.txt
subfinder -d $T -all -o subfinder.txt 2>/dev/null

# ② 合并去重 → 解析全部记录
cat crt.txt certspotter.txt subfinder.txt | sort -u | tr '\n' ' ' > all.txt
dnsx -l all.txt -a -aaaa -cname -mx -txt -resp -silent > resolved.txt

# ③ 活站过滤(顺带识别通配 DNS 假阳性:拿一个随机子域先探测)
httpx -l all.txt -follow-redirects -nonstd -title -tech-detect -o alive.txt

# ④ 僵尸子域判定:resolved 里有 IP、但 alive 里没有 → 逐个查 CNAME 是否悬空
comm -23 <(sort resolved.txt) <(sort alive.txt) > stale_candidates.txt

8.6 证书 SAN 批量提取(bash,配合 8.5 的 alive.txt)

# 从活站列表提取 443 证书 SAN,发现证书里的隐藏子域
while read -r h; do
  timeout 5 openssl s_client -connect "$h:443" -servername "$h" </dev/null 2>/dev/null \
    | openssl x509 -noout -text 2>/dev/null \
    | grep -oP '(?<=DNS:)[^,]+'
done < alive.txt | sort -u > cert_sans.txt
comm -13 <(sort alive.txt) <(sort cert_sans.txt) > new_subs_from_cert.txt

8.7 PowerShell 一键模板(Windows,无 openssl 依赖)

$Target = "example.com"
New-Item -ItemType Directory -Force "osint_$Target" | Out-Null
Set-Location "osint_$Target"

# ① DNS 全记录
Resolve-DnsName $Target -DnsOnly | Format-Table -AutoSize | Out-File dns.txt
Resolve-DnsName $Target -Type MX  -DnsOnly | Out-File mx.txt
Resolve-DnsName $Target -Type TXT -DnsOnly | Out-File txt.txt

# ② RDAP 注册信息
Invoke-RestMethod "https://rdap.org/domain/$Target" | ConvertTo-Json -Depth 5 | Out-File rdap.json

# ③ crt.sh 子域
(Invoke-RestMethod "https://crt.sh/?q=%25.$Target&output=json").name_value -replace '^\*\.','' | Sort-Unique | Out-File crt_subs.txt

# ④ 证书 SAN + 有效期(.NET 直连 443)
try {
  $tcp  = New-Object System.Net.Sockets.TcpClient($Target, 443)
  $ssl  = New-Object System.Net.Security.SslStream($tcp.GetStream(), $false, { $true })
  $ssl.AuthenticateAsClient($Target)
  $c    = $ssl.RemoteCertificate
  "Subject   : $($c.Subject)"
  "Issuer    : $($c.Issuer)"
  "NotAfter  : $($c.NotAfter)"
  "Thumbprint: $($c.Thumbprint)"
  $ssl.Close(); $tcp.Close()
} catch { "TLS 连接失败: $_" } | Out-File cert.txt

# ⑤ whois(若已装 whois 工具,否则用 ② 的 rdap.json 代替)
if (Get-Command whois -ErrorAction SilentlyContinue) {
  whois $Target | Select-String "Domain Name|Registr|Expir|Name Server|Email" | Out-File whois.txt
}

8.8 资产清单记录模板(边收集边填,交付前必交)

# 目标资产清单 — {目标名}(授权编号:{xxx})
收集日期:{YYYY-MM-DD}    收集人:{xxx}

## 域名与 IP
| 域名 | IP | 存活 | 服务/版本 | 备注(CDN? 僵尸? 接管风险?) |
|---|---|---|---|---|
| web.example.com | 1.2.3.4 | ✔ | nginx/1.18, PHP 8.1 | 主站 |
| old-mgmt.example.com | 5.6.7.8 | ✘(CNAME 悬空) | — | 子域接管候选 |

## DNS
- NS:{...}    MX:{...}    SPF/DMARC:{...}
- 通配 DNS:{有/无}(探测子域:{随机串} → {结果})

## 证书
| 域名 | 有效期 | SAN | Issuer | 弱点(SHA1/短RSA/过期/自签) |
|---|---|---|---|---|

## WHOIS / 注册信息
- 注册商:{...}  注册邮箱:{...}(反查名下域名:{列表})
- 到期日:{...}  NS 服务商:{...}

## 指纹摘要(FOFA 导出)
| IP | 端口 | app | title | 高危 CVE 命中 |
|---|---|---|---|---|

## 发现的接口 / 文件
- [ ] /swagger.json({状态})
- [ ] /actuator/env({状态})
- [ ] /backup.sql({状态})

8.9 一键全量收集脚本(保存为 collect.sh,./collect.sh example.com 直接跑)

#!/usr/bin/env bash
# 用法: ./collect.sh example.com      (依赖: dig/whois/curl/jq, 可选 subfinder/dnsx/httpx)
set -u
T="$1"
mkdir -p "osint_$T" && cd "osint_$T"

echo "[1/6] WHOIS / RDAP"
whois "$T" 2>/dev/null | grep -Ei "Domain Name|Registrar:|Created|Expir|Name Server|Status" | tee whois.txt || true
curl -s "https://rdap.org/domain/$T" > rdap.json 2>/dev/null || echo "RDAP 获取失败"

echo "[2/6] DNS 全记录"
for r in A AAAA CNAME MX TXT NS SOA CAA; do
  echo ";== $r =="; dig +short "$r" "$T"
done > dns_records.txt

echo "[3/6] 被动子域 (crt.sh + certspotter)"
curl -s "https://crt.sh/?q=%25.$T&output=json" 2>/dev/null \
  | jq -r '.[].name_value' 2>/dev/null | sed 's/^\*\.//;s/\.$//' | sort -u > crt.txt
curl -s "https://api.certspotter.com/v1/issuances?domain=$T&include_subdomains=true&expand=dns_names" 2>/dev/null \
  | jq -r '.[].dns_names[]' 2>/dev/null | sort -u > certspotter.txt
echo "  crt.sh: $(wc -l < crt.txt) 条 / certspotter: $(wc -l < certspotter.txt) 条"

echo "[4/6] 主动枚举 + 解析 + 活站 (若装了 subfinder/dnsx/httpx)"
if command -v subfinder >/dev/null && command -v dnsx >/dev/null && command -v httpx >/dev/null; then
  cat crt.txt certspotter.txt | sort -u | tr '\n' ' ' > all.txt
  subfinder -d "$T" -all -o subfinder.txt 2>/dev/null
  cat all.txt subfinder.txt | sort -u | tr '\n' ' ' > all.txt
  dnsx -l all.txt -a -aaaa -cname -mx -txt -resp -silent > resolved.txt
  httpx -l all.txt -follow-redirects -nonstd -title -tech-detect -o alive.txt
  comm -23 <(sort resolved.txt) <(sort alive.txt) > stale_candidates.txt
  echo "  已解析: $(wc -l < resolved.txt) / 活站: $(wc -l < alive.txt) / 僵尸候选: $(wc -l < stale_candidates.txt)"
else
  echo "  [跳过] 未安装 subfinder/dnsx/httpx(安装参考第 4.3 节)"
fi

echo "[5/6] 证书 SAN 提取(对活站)"
if [ -f alive.txt ] && command -v openssl >/dev/null; then
  grep -oP '^[a-z0-9.-]+\.[a-z]{2,}' alive.txt | sort -u | while read -r h; do
    timeout 5 openssl s_client -connect "$h:443" -servername "$h" </dev/null 2>/dev/null \
      | openssl x509 -noout -text 2>/dev/null | grep -oP '(?<=DNS:)[^,]+'
  done | sort -u > cert_sans.txt
  [ -s cert_sans.txt ] && comm -13 <(sort <(grep -oP '^[a-z0-9.-]+\.[a-z]{2,}' alive.txt)) <(sort cert_sans.txt) > new_subs_from_cert.txt
fi

echo "[6/6] 通配 DNS 探测"
RAND=$(head -c 8 /dev/urandom | od -An -tx1 | tr -d ' \n')
W=$(dig +short "aaaaaaaa${RAND}.example.com" || dig +short "${RAND}.$T")
[ -n "$(eval "dig +short '${RAND}.$T'")" ] && echo "  ⚠️ 疑似通配 DNS: ${RAND}.$T 返回了解析" || echo "  未发现通配解析"

echo "完成 → 目录: $(pwd)"

8.10 端口与服务指纹模板(nmap)

# ── 全端口快速扫描(已知目标 IP,授权范围内)────────────
nmap -sn 203.0.113.5/24 -oG alive_hosts.txt          # 先探 /24 存活
nmap -sS -p- -T4 --min-rate 3000 -oG full_scan.txt 203.0.113.5

# ── 开放端口版本指纹 + 默认脚本 ──────────────────────────
nmap -sV -sC -p 22,80,443,8080,8443,3389,9090,9100 203.0.113.5 -oN ver.txt

# ── 高危服务默认脚本集(一次性多拿点信息)─────────────────
nmap -sV -sC "ssh-enum,http-enum,http-title,http-robots.txt,vuln" -p 80,443 203.0.113.5

8.11 接口 / 敏感路径探测模板(curl 批量,免装工具)

# 把目标地址存着,逐条打(记录 200/301/403 的都要跟进)
B=http://web.example.com
for p in swagger.json swagger-ui.html actuator actuator/env actuator/health \
         api-docs .env .git/config backup.sql phpinfo.php test.phpinfo \
         wp-admin/wp-login.php manager/html console druid/index.html \
         phpmyadmin pma admin login debug; do
  code=$(curl -sk -o /dev/null -w "%{http_code}" "$B/$p" --max-time 5)
  [ "$code" != "404" ] && echo "  $code  $B/$p"
done | tee probe_result.txt

# 只看 200/401/403(这三个最值得人工跟进):
grep -E "^  (200|401|403)" probe_result.txt

8.12 FOFA API 模板(批量拉数据,需 API key)

# 在 https://fofa.so/user 获取 keyid / key,base64("keyid:key") 即 token
T="example.com"
curl -s -X POST "https://fofa.so/api?q=$(python3 -c "import base64;print(base64.b64encode(b'domain=$T').decode())")&size=10000&fields=host,port,title,app,country,idc&kb=0" \
  -u "$(echo -n "你的keyid:你的key" | base64):" | jq -r '.results[]' | column -t
# PowerShell 版:
# Invoke-RestMethod -Method Post "https://fofa.so/api?q=..." -Credential $(New-Object PSCredential "你的keyid:你的key", $null)

8.13 信息收集结果汇总清单(交付前自查)

- [ ] WHOIS/RDAP:注册商 / 注册邮箱 / NS / 到期日
- [ ] 域名变体:.com/.cn/.net/.com.cn 全部查过
- [ ] 子域:crt.sh + certspotter + subfinder + Wayback 已合并去重
- [ ] 僵尸子域:stale_candidates.txt 已逐个查 CNAME 是否悬空(接管风险)
- [ ] 通配 DNS:已探测,假阳性已排除
- [ ] 活站:alive.txt 已标题/技术栈识别,CDN 已标注
- [ ] 证书:SAN 已提取,有效期/弱项已记录
- [ ] 同 IP 反查:FOFA ip= / Shodan host 已跑
- [ ] 接口探测:8.11 模板已对每个活站跑过
- [ ] GitHub/代码搜索:域名、密钥、内网地址已查
- [ ] 资产清单(8.8 模板)已填完并归档

参考(本次写作核对过的入口):FOFA 官网、FOFA 开发者文档、crt.sh、SSL Labs、Wayback Machine CDX API