evilsocket / dnssearch

A subdomain enumeration tool.
GNU General Public License v3.0
892 stars 140 forks source link

[FIX] Do not parse TLD to allow running thought X.TLD.COM just as well #13

Closed AvnerCohen closed 7 years ago

AvnerCohen commented 7 years ago

Issue: ./dnssearch -domain env.tld.com

Will search through tld.com instead of env.tld.com

As a user of the lib, I really felt like I want to be protected from empty string, but beyond that, I want to have full control on the domain pattern I want to run my search over.

ehsandeep commented 7 years ago

@evilsocket, this is something dnssearch and dirsearch both share same issues so in xray as well, i guess you fixed that in xray, but this is something u can see, to allow scan the things for subdomain as well just not TLD.

evilsocket commented 7 years ago

The whole point of this tool is finding new subdomains given the domain.tld, if you provide an URL with a subdomain in it, your PR will make the tool leave the subdomain and therefore every scan will be for:

<subdomain>.<provided-subdomain>.domain.tld

Which is wrong.

evilsocket commented 7 years ago

Note: Of course that is wrong for domains like www.google.com etc, which are the majority of what ppl feed the tool with.

evilsocket commented 7 years ago

@AvnerCohen Maybe a new command line option to enable/disable this behaviour would make both of us happy? :)