OWASP / wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
https://owasp.org/www-project-web-security-testing-guide/
Creative Commons Attribution Share Alike 4.0 International
7.11k stars 1.31k forks source link

Add new section on Domain enumeration and CT Harvesting? #570

Open kingthorin opened 3 years ago

kingthorin commented 3 years ago

I think we should add some domain lookup (ala amass etc) and cert transparency harvesting details to the guide.

I'm thinking of adding this to a new section like 4.1.11 but we could fairly reasonably just rename 4.1.1 and include it there (in order to maintain some semblance of workflow/order-of-operations).

So I'm looking for:

  1. Thoughts on where to locate it.
  2. Tools and other suggestions for content.
github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 3 years ago

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 2 years ago

Please comment if you are still working on this issue, as it has been inactive for 90 days. To give everyone a chance to contribute, we are releasing it to new contributors.

github-actions[bot] commented 2 years ago

Please comment if you are still working on this issue, as it has been inactive for 90 days. To give everyone a chance to contribute, we are releasing it to new contributors.