github编辑

Main domains

Gathering

1) Based company name

ICP License

# https://github.com/y00k1sec/hacking-gadgets/blob/main/icpquery.py
cat companies.txt | icpquery | tee domains_icp.json
cat domains_icp.json | jq -s 'map(.params.list[]) | group_by(.unitName) | map({unitName: .[0].unitName, domain: map(.domain)})'

# https://github.com/wgpsec/ENScan_GO
./enscan-<version> -n <company_name> -type all -field icp
./enscan-<version> -f <company.txt> -type all -field icp

# Company name to ICP licensed domains
https://www.beianx.cn/search/
https://0.zone/
https://www.qcc.com/
https://aiqicha.baidu.com/
https://shuidi.cn/
https://www.tianyancha.com/
https://icp.chinaz.com/
https://beian.miit.gov.cn/

# Latest ICP
https://shangjibao.baidu.com

# ICP history
https://icp.chinaz.com/record

2) Based on existing domain

Internal NameServer

3) Based on existing website

SSL/TLS Certificate

CSP (Content Security Policies)

Favicon Hash

Google Analytics ID

Location Headers

Analysis

最后更新于