子域名挖掘全局流程
本篇定位:这是子域名挖掘方法板块的入口。读完基础知识六篇,你知道了 DNS、CDN、TLS 这些底层概念;但从这里开始,我们讲"怎么挖"。本篇只给框架------挖掘分几步、每步做什么、步骤之间怎么衔接,不展开方法细节。
阅读建议:如果你已经做过子域名收集,可以直接看 3.2 各阶段速览和 3.5 关键决策点。如果是新手,从头读,建立全局框架后再进入后续各章。
一、为什么需要结构化的挖掘流程
没有流程时,子域名挖掘是什么样的?拿到一个目标域名,直接上字典爆破------跑完发现遗漏了 CT Logs 里的子域;补上 CT Logs------又发现通配符 DNS 制造了一堆假阳性;好不容易清洗完------ HTTP 探测时才想起没判断 CDN,一半 IP 打在 CDN 节点上。
这些问题------散点收集、遗漏、重复、低效------的根本原因是没有流程。
流程的核心价值:从"碰运气"变成"系统性覆盖"。每一步有明确的输入和输出,前一步的输出是后一步的输入,每一步都知道自己该做什么、为什么在这做。
一句话概括整个流程:从已知域名出发,逐层扩大发现范围。
二、全局流程概览
#mermaid-svg-McKOxgU9NcpofAXj{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;fill:#333;}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#mermaid-svg-McKOxgU9NcpofAXj .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#mermaid-svg-McKOxgU9NcpofAXj .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#mermaid-svg-McKOxgU9NcpofAXj .error-icon{fill:#552222;}#mermaid-svg-McKOxgU9NcpofAXj .error-text{fill:#552222;stroke:#552222;}#mermaid-svg-McKOxgU9NcpofAXj .edge-thickness-normal{stroke-width:1px;}#mermaid-svg-McKOxgU9NcpofAXj .edge-thickness-thick{stroke-width:3.5px;}#mermaid-svg-McKOxgU9NcpofAXj .edge-pattern-solid{stroke-dasharray:0;}#mermaid-svg-McKOxgU9NcpofAXj .edge-thickness-invisible{stroke-width:0;fill:none;}#mermaid-svg-McKOxgU9NcpofAXj .edge-pattern-dashed{stroke-dasharray:3;}#mermaid-svg-McKOxgU9NcpofAXj .edge-pattern-dotted{stroke-dasharray:2;}#mermaid-svg-McKOxgU9NcpofAXj .marker{fill:#333333;stroke:#333333;}#mermaid-svg-McKOxgU9NcpofAXj .marker.cross{stroke:#333333;}#mermaid-svg-McKOxgU9NcpofAXj svg{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;}#mermaid-svg-McKOxgU9NcpofAXj p{margin:0;}#mermaid-svg-McKOxgU9NcpofAXj .label{font-family:"trebuchet ms",verdana,arial,sans-serif;color:#333;}#mermaid-svg-McKOxgU9NcpofAXj .cluster-label text{fill:#333;}#mermaid-svg-McKOxgU9NcpofAXj .cluster-label span{color:#333;}#mermaid-svg-McKOxgU9NcpofAXj .cluster-label span p{background-color:transparent;}#mermaid-svg-McKOxgU9NcpofAXj .label text,#mermaid-svg-McKOxgU9NcpofAXj span{fill:#333;color:#333;}#mermaid-svg-McKOxgU9NcpofAXj .node rect,#mermaid-svg-McKOxgU9NcpofAXj .node circle,#mermaid-svg-McKOxgU9NcpofAXj .node ellipse,#mermaid-svg-McKOxgU9NcpofAXj .node polygon,#mermaid-svg-McKOxgU9NcpofAXj .node path{fill:#ECECFF;stroke:#9370DB;stroke-width:1px;}#mermaid-svg-McKOxgU9NcpofAXj .rough-node .label text,#mermaid-svg-McKOxgU9NcpofAXj .node .label text,#mermaid-svg-McKOxgU9NcpofAXj .image-shape .label,#mermaid-svg-McKOxgU9NcpofAXj .icon-shape .label{text-anchor:middle;}#mermaid-svg-McKOxgU9NcpofAXj .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#mermaid-svg-McKOxgU9NcpofAXj .rough-node .label,#mermaid-svg-McKOxgU9NcpofAXj .node .label,#mermaid-svg-McKOxgU9NcpofAXj .image-shape .label,#mermaid-svg-McKOxgU9NcpofAXj .icon-shape .label{text-align:center;}#mermaid-svg-McKOxgU9NcpofAXj .node.clickable{cursor:pointer;}#mermaid-svg-McKOxgU9NcpofAXj .root .anchor path{fill:#333333!important;stroke-width:0;stroke:#333333;}#mermaid-svg-McKOxgU9NcpofAXj .arrowheadPath{fill:#333333;}#mermaid-svg-McKOxgU9NcpofAXj .edgePath .path{stroke:#333333;stroke-width:2.0px;}#mermaid-svg-McKOxgU9NcpofAXj .flowchart-link{stroke:#333333;fill:none;}#mermaid-svg-McKOxgU9NcpofAXj .edgeLabel{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-McKOxgU9NcpofAXj .edgeLabel p{background-color:rgba(232,232,232, 0.8);}#mermaid-svg-McKOxgU9NcpofAXj .edgeLabel rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-McKOxgU9NcpofAXj .labelBkg{background-color:rgba(232, 232, 232, 0.5);}#mermaid-svg-McKOxgU9NcpofAXj .cluster rect{fill:#ffffde;stroke:#aaaa33;stroke-width:1px;}#mermaid-svg-McKOxgU9NcpofAXj .cluster text{fill:#333;}#mermaid-svg-McKOxgU9NcpofAXj .cluster span{color:#333;}#mermaid-svg-McKOxgU9NcpofAXj div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:12px;background:hsl(80, 100%, 96.2745098039%);border:1px solid #aaaa33;border-radius:2px;pointer-events:none;z-index:100;}#mermaid-svg-McKOxgU9NcpofAXj .flowchartTitleText{text-anchor:middle;font-size:18px;fill:#333;}#mermaid-svg-McKOxgU9NcpofAXj rect.text{fill:none;stroke-width:0;}#mermaid-svg-McKOxgU9NcpofAXj .icon-shape,#mermaid-svg-McKOxgU9NcpofAXj .image-shape{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-McKOxgU9NcpofAXj .icon-shape p,#mermaid-svg-McKOxgU9NcpofAXj .image-shape p{background-color:rgba(232,232,232, 0.8);padding:2px;}#mermaid-svg-McKOxgU9NcpofAXj .icon-shape .label rect,#mermaid-svg-McKOxgU9NcpofAXj .image-shape .label rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-McKOxgU9NcpofAXj .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#mermaid-svg-McKOxgU9NcpofAXj .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#mermaid-svg-McKOxgU9NcpofAXj :root{--mermaid-font-family:"trebuchet ms",verdana,arial,sans-serif;} 递归回路
新子域回到阶段 2
定期复扫
差异对比
阶段 6:HTTP 探测与价值评估
状态码语义
重定向链
TLS 二次分析
价值分级
阶段 5:DNS 清洗
多 DNS 轮询
通配符过滤
CNAME 链跟踪
阶段 4:进阶发现
递归发现
ASN 反查
网页爬取
阶段 3:主动探测
字典爆破
AXFR
排列扫描
阶段 2:被动发现
CT Logs
搜索引擎
历史数据
DNS 聚合
代码泄漏
阶段 1:准备
界定范围
选字典
配环境
目标根域名
example.com
阶段 7:输出与监控
每阶段一句话定位
| 阶段 | 定位 |
|---|---|
| 1 准备 | 界定范围、选字典、配环境 |
| 2 被动发现 | 不接触目标,从公开数据找子域 |
| 3 主动探测 | 向目标 DNS"敲门",找被动遗漏的子域 |
| 4 进阶发现 | 以已发现的子域为跳板,递归扩大 |
| 5 DNS 清洗 | 把原始数据变成可信数据 |
| 6 HTTP 探测 | 判断"存活"且"有价值" |
| 7 输出与监控 | 结果归档、定期复扫 |
阶段间的数据流向
每个阶段的输出,是下一阶段的输入:
准备(根域名 + 字典)
→ 被动发现(子域名列表,60-80% 覆盖)
→ 主动探测(补充遗漏的子域名)
→ 进阶发现(以新子域为跳板,递归扩大)
→ DNS 清洗(可信的子域名 + IP 列表)
→ HTTP 探测(存活的 + 有价值的子域名列表)
→ 输出(资产清单 + 价值分级)
三、各阶段速览
阶段 1:准备
做什么:界定目标范围(哪些根域名在范围内)、选字典(通用字典 + 目标定制字典)、配环境(DNS 解析器、并发参数、限速策略)。
为什么必要:没有范围界定,会挖到不相关的域名;没有合适的字典,主动探测的命中率极低;没有环境配置,批量解析时会被 DNS 服务器限速或封禁。
主要方法:根域名确认、字典选择(通用 + 定制)、多 DNS 解析器配置、并发与限速参数调优。
阶段 2:被动发现
做什么:不接触目标服务器,从公开数据源里找子域名。
为什么在第一步:零风险------不向目标发任何请求,不会触发 WAF 或 IDS。覆盖率高------CT Logs、搜索引擎、历史 DNS 数据加起来,通常能覆盖已知子域的 60-80%。
主要方法:CT Logs(crt.sh、Certspotter)、搜索引擎(Google dork、FOFA、Shodan)、历史数据(Wayback Machine、CDX API)、DNS 聚合(SecurityTrails、DNSDumpster)、代码泄漏(GitHub 搜索)、威胁情报(VirusTotal)。
阶段 3:主动探测
做什么:向目标的 DNS 服务器发查询,"敲门"发现被动方法找不到的子域名。
为什么在被动后面:被动方法有盲区------内部子域、未收录的子域、新上线的子域。主动探测能覆盖这些盲区,但有风险------会触发目标的检测系统。
主要方法:DNS 字典爆破(通用字典 + 并发控制 + 多级爆破)、DNS 域传送(AXFR,配置错误时能拿到全量记录)、DNS 排列扫描(基于已发现子域生成变体,altdns/dnsgen/gotator)。
阶段 4:进阶发现
做什么:把已发现的子域名作为跳板,继续发现更多子域名和 IP 资产。
为什么在主动后面:先穷尽常规方法能发现的子域,再以这些子域为种子做递归。直接上递归会浪费资源------你还没发现的子域,没法当种子。
主要方法:递归发现(对新子域重新跑被动 + 主动)、ASN 与 IP 反查(WHOIS + BGP → IP 段 → PTR 反查 → 正向验证)、网页爬取与 JavaScript 分析(页面里的接口、配置、域名)、冷门方法(APK 逆向、SNI 握手探测、邮件头分析、WHOIS 反向查询)。
阶段 5:DNS 清洗
做什么:把前四个阶段收集的"原始子域名列表"清洗为"可信的子域名 + IP 列表"。
为什么在 HTTP 前面:原始列表里有假阳性(通配符 DNS 制造的假子域)、过时数据(已下线的子域仍解析到旧 IP)、重复项。拿垃圾数据做 HTTP 探测,浪费时间和请求配额。
主要环节:多 DNS 轮询解析(避免单 DNS 服务器缓存偏差)、通配符检测与过滤(随机子域验证)、CNAME 链跟踪(识别 CDN、第三方服务、接管风险)、输入输出校验(数量对比,防丢包)。
阶段 6:HTTP 探测与价值评估
做什么:对清洗后的子域名做 HTTP 请求,判断哪些"存活"且"有价值"。
为什么在最后:前面五个阶段只管"有没有这个子域名",这一步管"这个子域名背后有没有服务、服务值不值得打"。DNS 存在不等于有价值------可能是个空域名、可能是个 404、可能是 CDN 背后的死站。
主要环节:状态码语义(200/401/403/404 的挖掘意义)、重定向链跟踪(可能暴露新子域)、TLS 证书二次分析(SAN 可能藏着更多子域)、价值分级(高/中/低/信息/CDN 后资产)。
阶段 7:输出与监控
做什么:把探测结果归档为资产清单,定期复扫发现新增子域。
为什么不是终点:子域名不是静态的------目标天天在上线新服务、下线旧服务。一次挖掘的成果会过期。定期复扫 + 差异对比,才能持续跟踪目标的攻击面变化。
主要环节:字段规范(子域名、IP、CNAME、状态码、价值等级、发现来源、发现时间)、定期扫描(周/月级)、差异对比(新增子域 → 回到阶段 2 递归)、递归回路(新发现触发新一轮挖掘)。
四、章节地图
#mermaid-svg-9QhE5nzGamy6bXjR{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;fill:#333;}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#mermaid-svg-9QhE5nzGamy6bXjR .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#mermaid-svg-9QhE5nzGamy6bXjR .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#mermaid-svg-9QhE5nzGamy6bXjR .error-icon{fill:#552222;}#mermaid-svg-9QhE5nzGamy6bXjR .error-text{fill:#552222;stroke:#552222;}#mermaid-svg-9QhE5nzGamy6bXjR .edge-thickness-normal{stroke-width:1px;}#mermaid-svg-9QhE5nzGamy6bXjR .edge-thickness-thick{stroke-width:3.5px;}#mermaid-svg-9QhE5nzGamy6bXjR .edge-pattern-solid{stroke-dasharray:0;}#mermaid-svg-9QhE5nzGamy6bXjR .edge-thickness-invisible{stroke-width:0;fill:none;}#mermaid-svg-9QhE5nzGamy6bXjR .edge-pattern-dashed{stroke-dasharray:3;}#mermaid-svg-9QhE5nzGamy6bXjR .edge-pattern-dotted{stroke-dasharray:2;}#mermaid-svg-9QhE5nzGamy6bXjR .marker{fill:#333333;stroke:#333333;}#mermaid-svg-9QhE5nzGamy6bXjR .marker.cross{stroke:#333333;}#mermaid-svg-9QhE5nzGamy6bXjR svg{font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:16px;}#mermaid-svg-9QhE5nzGamy6bXjR p{margin:0;}#mermaid-svg-9QhE5nzGamy6bXjR .label{font-family:"trebuchet ms",verdana,arial,sans-serif;color:#333;}#mermaid-svg-9QhE5nzGamy6bXjR .cluster-label text{fill:#333;}#mermaid-svg-9QhE5nzGamy6bXjR .cluster-label span{color:#333;}#mermaid-svg-9QhE5nzGamy6bXjR .cluster-label span p{background-color:transparent;}#mermaid-svg-9QhE5nzGamy6bXjR .label text,#mermaid-svg-9QhE5nzGamy6bXjR span{fill:#333;color:#333;}#mermaid-svg-9QhE5nzGamy6bXjR .node rect,#mermaid-svg-9QhE5nzGamy6bXjR .node circle,#mermaid-svg-9QhE5nzGamy6bXjR .node ellipse,#mermaid-svg-9QhE5nzGamy6bXjR .node polygon,#mermaid-svg-9QhE5nzGamy6bXjR .node path{fill:#ECECFF;stroke:#9370DB;stroke-width:1px;}#mermaid-svg-9QhE5nzGamy6bXjR .rough-node .label text,#mermaid-svg-9QhE5nzGamy6bXjR .node .label text,#mermaid-svg-9QhE5nzGamy6bXjR .image-shape .label,#mermaid-svg-9QhE5nzGamy6bXjR .icon-shape .label{text-anchor:middle;}#mermaid-svg-9QhE5nzGamy6bXjR .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#mermaid-svg-9QhE5nzGamy6bXjR .rough-node .label,#mermaid-svg-9QhE5nzGamy6bXjR .node .label,#mermaid-svg-9QhE5nzGamy6bXjR .image-shape .label,#mermaid-svg-9QhE5nzGamy6bXjR .icon-shape .label{text-align:center;}#mermaid-svg-9QhE5nzGamy6bXjR .node.clickable{cursor:pointer;}#mermaid-svg-9QhE5nzGamy6bXjR .root .anchor path{fill:#333333!important;stroke-width:0;stroke:#333333;}#mermaid-svg-9QhE5nzGamy6bXjR .arrowheadPath{fill:#333333;}#mermaid-svg-9QhE5nzGamy6bXjR .edgePath .path{stroke:#333333;stroke-width:2.0px;}#mermaid-svg-9QhE5nzGamy6bXjR .flowchart-link{stroke:#333333;fill:none;}#mermaid-svg-9QhE5nzGamy6bXjR .edgeLabel{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-9QhE5nzGamy6bXjR .edgeLabel p{background-color:rgba(232,232,232, 0.8);}#mermaid-svg-9QhE5nzGamy6bXjR .edgeLabel rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-9QhE5nzGamy6bXjR .labelBkg{background-color:rgba(232, 232, 232, 0.5);}#mermaid-svg-9QhE5nzGamy6bXjR .cluster rect{fill:#ffffde;stroke:#aaaa33;stroke-width:1px;}#mermaid-svg-9QhE5nzGamy6bXjR .cluster text{fill:#333;}#mermaid-svg-9QhE5nzGamy6bXjR .cluster span{color:#333;}#mermaid-svg-9QhE5nzGamy6bXjR div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:"trebuchet ms",verdana,arial,sans-serif;font-size:12px;background:hsl(80, 100%, 96.2745098039%);border:1px solid #aaaa33;border-radius:2px;pointer-events:none;z-index:100;}#mermaid-svg-9QhE5nzGamy6bXjR .flowchartTitleText{text-anchor:middle;font-size:18px;fill:#333;}#mermaid-svg-9QhE5nzGamy6bXjR rect.text{fill:none;stroke-width:0;}#mermaid-svg-9QhE5nzGamy6bXjR .icon-shape,#mermaid-svg-9QhE5nzGamy6bXjR .image-shape{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-9QhE5nzGamy6bXjR .icon-shape p,#mermaid-svg-9QhE5nzGamy6bXjR .image-shape p{background-color:rgba(232,232,232, 0.8);padding:2px;}#mermaid-svg-9QhE5nzGamy6bXjR .icon-shape .label rect,#mermaid-svg-9QhE5nzGamy6bXjR .image-shape .label rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-9QhE5nzGamy6bXjR .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#mermaid-svg-9QhE5nzGamy6bXjR .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#mermaid-svg-9QhE5nzGamy6bXjR :root{--mermaid-font-family:"trebuchet ms",verdana,arial,sans-serif;} 流程阶段
阶段1
准备
阶段2
被动发现
阶段3
主动探测
阶段4
进阶发现
阶段5
DNS清洗
阶段6
HTTP探测
阶段7
输出与监控
第3章
被动发现
第4章
主动探测
第5章
进阶发现
第6章
DNS解析与清洗
第7章
HTTP探测与价值评估
第8章
踩坑实录
| 阶段 | 对应章节 | 解决什么问题 | 覆盖维度 |
|---|---|---|---|
| 1 准备 | 第 2 章 | 范围、字典、环境 | 目标范围 |
| 2 被动 | 第 3 章 | 零风险覆盖 60-80% | 域名与子域名 |
| 3 主动 | 第 4 章 | 覆盖被动盲区 | 域名与子域名 |
| 4 进阶 | 第 5 章 | 以子域为跳板递归扩大 | 域名与子域名 + IP 与端口 + 基础设施 |
| 5 清洗 | 第 6 章 | 假阳性过滤、数据可信化 | 域名与子域名 |
| 6 HTTP | 第 7 章 | 存活判断 + 价值分级 | Web 应用入口 + 技术栈 |
| 7 输出 | 第 8 章 | 实战中的陷阱与预防 | 全维度 |
| --- 总结 | 流程总结 | 全链路复盘 | 全维度 |
阅读顺序建议:
- 新手:按顺序读第 3 章到第 8 章
- 老手:跳到需要的阶段,看各章方法分类
- 快速查阅:看本篇 3.2 各阶段速览 + 流程总结的速查表
五、阶段间的衔接逻辑
为什么是这个顺序?
| 衔接 | 逻辑 |
|---|---|
| 被动 → 主动 | 被动零风险,先覆盖 60-80%,再让主动探测补盲区------风险后置 |
| 主动 → 进阶 | 先穷尽常规方法,再以已发现的子域为种子做递归------没种子没法递归 |
| 进阶 → 清洗 | 前三步收集的原始数据有假阳性、重复、过时------不清洗直接用会浪费时间 |
| 清洗 → HTTP | 垃圾数据做 HTTP 探测浪费请求配额------先确保每个子域都是可信的 |
| HTTP → 输出 | 前面只管"有没有",HTTP 管有没有价值------没价值的标记后跳过 |
| 输出 → 被动(回路) | 新发现子域触发递归回路,回到阶段 2 重新跑被动------挖掘是迭代的 |
关键认知:这个流程不是一次性的------进阶发现的新子域会回到阶段 2 重新跑被动,定期复扫也会回到阶段 2。流程是循环的,不是线性的。
六、关键决策点
流程中不是每一步都走直线,有几个地方需要做选择:
| 决策点 | 要决定什么 | 影响 |
|---|---|---|
| 被动覆盖率够不够 | 60-80% 够不够?要不要上主动? | 上主动有风险,但能补盲区 |
| 通配符检测发现通配符 | 怎么处理假阳性? | 不过滤 → 假子域污染数据;过滤 → 可能漏掉真子域 |
| CDN 节点 IP | 要不要绕过找源站? | 绕过耗时且不一定成功;不绕过 → 端口扫描打在 CDN 上 |
| HTTP 403 | 是 WAF 拦截还是真管理后台? | 判断错 → 浪费时间或错过高价值目标 |
| 进阶递归深度 | 到哪停? | 太浅 → 遗漏;太深 → 资源耗尽 |
这些决策点的详细处理方法在后续各章和踩坑实录里讲。
七、与基础知识的衔接
每个阶段用到哪些基础知识:
| 阶段 | 用到的基础知识 | 回指 |
|---|---|---|
| 1 准备 | URL 结构、域名级别 | 基础 01 |
| 2 被动 | DNS 记录类型、CNAME 链 | 基础 04 |
| 3 主动 | DNS 查询(UDP/TCP)、本地与公共 DNS | 基础 02 |
| 4 进阶 | ASN、CIDR、CDN 调度 | 基础 06、05 |
| 5 清洗 | DNS 解析流程、通配符 DNS | 基础 02、04 |
| 6 HTTP | HTTP/HTTPS、TLS 证书、SNI/SAN、状态码 | 基础 05 |
| 7 输出 | 网络架构(CDN/LB/WAF) | 基础 05、06 |
如果某个阶段用到的概念你不熟,回到对应的基础知识文档复习。
八、阅读建议
| 读者类型 | 路径 |
|---|---|
| 新手 | 按顺序读第 3 → 4 → 5 → 6 → 7 → 8 章,每章读完做一遍 |
| 老手 | 跳到需要的阶段,看各章方法分类和踩坑实录 |
| 快速查阅 | 看本篇各阶段速览 + 流程总结的速查表 |
下一篇:第 3 章------被动发现,从零接触目标的信息收集开始。