π¦
Finding vulnerable subdomains using CensysCensys is like
Shodan and Google Dorks, but powered up. We already talked about it in detail in the article How to Use Censys. Today, we will analyze it from the perspective of searching for vulnerabilities in subdomains.
The best way to find subdomains using search engines is to use filters called dorks that are better understood by the Internet itself. We cannot simply tell Google find all Microsoft subdomains please. We need to speak computer language, not human language.
Bug Bounty is a reward program that a website owner conducts to attract external information security specialists to find vulnerabilities. When participating in Bug Bounty, one must act ethically and follow established rules.
π»
Search for Microsoft subdomainsLet us try to find Microsoft subdomains. Go to
Censys Search and copy and paste the following query into the search bar.
(services.tls.certificates.leaf_data.names: microsoft.com) and services.http.response.status_code=200
After execution, a list of working subdomains of the site will appear. The results show active domains that respond with HTTP status code 200, meaning they are live and accessible.
β‘οΈ
Enable virtual hosts filterFor a better result, click on the settings icon next to the search panel and select the Virtual Hosts option. This setting expands your search beyond just the primary domain. Now, with Virtual Hosts enabled, you can see all subdomains available to Microsoft services and possibly find attack vectors.
The Virtual Hosts feature is particularly valuable because many organizations host multiple services on the same IP address. By enabling this option, Censys reveals which subdomains share infrastructure and what services they expose publicly.
π
Real bug bounty exampleIn one scenario from a HackerOne report, a bug hunter discovered an interesting subdomain with registration enabled for internal users this way. Then, after registration, the hacker was able to access personal data through
Broken Access Control and ended up receiving a decent bounty.
This case demonstrates why thorough subdomain enumeration matters. Many organizations forget to secure internal-facing endpoints, leaving them exposed to anyone who knows how to query the right databases.
π²
Additional tips for effective searchingCombine multiple filters to narrow down your results. You can search for specific technologies, open ports, or certificate information. The more precise your query, the better the chances of finding overlooked assets.
Regular monitoring of your own infrastructure through these tools helps identify what attackers might see. What looks secure internally may appear quite different to the outside world.
π
If you enjoyed the article share it with your friends and follow us.#Censys #Vulnerability #Search #OSINT #Pentesting
@PrivacyNotACrime π½ β¨οΈ Chat