06.03 / 55 min

Use DNS, WHOIS, subdomain, and port discovery responsibly

Understand the public recon modules, their scope requirements, and why a localhost lab cannot fabricate passive internet truth.

By the endDefine authorized assetsSeparate passive and active sourcesValidate discovered services
Controlled exercise

Use only the Academy Lab on 127.0.0.1:5177. Do not copy these tests to a public system without explicit written authorization.

01

Write the scope first

List approved roots, excluded domains, IP ranges, ports, rate limits, and time window. Do not infer that a parent company domain authorizes every subsidiary or provider.

02

Run DNS and WHOIS

Query only the authorized domain. Record source, timestamp, resolver, registration data, and uncertainty. WHOIS privacy or missing fields are normal, not findings.

03

Find subdomains

Separate passive-source names from active DNS validation. Deduplicate, resolve, and keep wildcard-DNS controls. Never claim a localhost route is a public subdomain.

04

Scan approved ports

Use a narrow port list, low concurrency, and explicit IP scope. Confirm service banners before reporting exposure and stop when a provider or host falls outside authorization.

05

Document the Academy limitation

The downloadable lab teaches HTTP service mapping on loopback. DNS, WHOIS, passive subdomain, and external-port results require your own authorized test domain.

MASTERY CHECKPOINT

Prove it before moving on.

You can produce a source-attributed asset inventory without scanning any unapproved host.