TGViewer
Privacy Not A Crime Privacy Not A Crime @privacynotacrime · 669 subscribers
Post #518 183
🦠 Finding vulnerable subdomains using Censys

Censys is like Shodan and Google Dorks, but powered up. We already talked about it in detail in the article How to Use Censys. Today, we will analyze it from the perspective of searching for vulnerabilities in subdomains.

The best way to find subdomains using search engines is to use filters called dorks that are better understood by the Internet itself. We cannot simply tell Google find all Microsoft subdomains please. We need to speak computer language, not human language.

Bug Bounty is a reward program that a website owner conducts to attract external information security specialists to find vulnerabilities. When participating in Bug Bounty, one must act ethically and follow established rules.

💻 Search for Microsoft subdomains

Let us try to find Microsoft subdomains. Go to Censys Search and copy and paste the following query into the search bar.

(services.tls.certificates.leaf_data.names: microsoft.com) and services.http.response.status_code=200


After execution, a list of working subdomains of the site will appear. The results show active domains that respond with HTTP status code 200, meaning they are live and accessible.

⚡️ Enable virtual hosts filter

For a better result, click on the settings icon next to the search panel and select the Virtual Hosts option. This setting expands your search beyond just the primary domain. Now, with Virtual Hosts enabled, you can see all subdomains available to Microsoft services and possibly find attack vectors.

The Virtual Hosts feature is particularly valuable because many organizations host multiple services on the same IP address. By enabling this option, Censys reveals which subdomains share infrastructure and what services they expose publicly.

🔘 Real bug bounty example

In one scenario from a HackerOne report, a bug hunter discovered an interesting subdomain with registration enabled for internal users this way. Then, after registration, the hacker was able to access personal data through Broken Access Control and ended up receiving a decent bounty.

This case demonstrates why thorough subdomain enumeration matters. Many organizations forget to secure internal-facing endpoints, leaving them exposed to anyone who knows how to query the right databases.

🔲 Additional tips for effective searching

Combine multiple filters to narrow down your results. You can search for specific technologies, open ports, or certificate information. The more precise your query, the better the chances of finding overlooked assets.

Regular monitoring of your own infrastructure through these tools helps identify what attackers might see. What looks secure internally may appear quite different to the outside world.

😊 If you enjoyed the article share it with your friends and follow us.

#Censys #Vulnerability #Search #OSINT #Pentesting

@PrivacyNotACrime 🗽 ⌨️ Chat
  • 👌 5
More from @privacynotacrime
  1. Oct 2, 2026💻 Spectre bypasses Linux defenses via stale processor records A new attack known as Branc…
  2. Oct 2, 2026Admin has been task with pulling together all the best tips for how to set up GrapheneOS,…
  3. Oct 2, 2026💜 Advanced command and control framework for implant management during Red Team operation…
  4. Oct 2, 2026■■■□□ Apple Zero-Day active exploitation.
  5. Oct 1, 2026❗️ Active now: Attackers are mimicking AI tools like Claude, DeepSeek, and ChatGPT to deli…
  6. Sep 30, 2026Bring back CRT!
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →