{"repo":"franccesco/getaltname","free":true,"listed":false,"github":"https://github.com/franccesco/getaltname","clone":"git clone https://github.com/franccesco/getaltname.git","description":"Extract subdomains from SSL certificates in HTTPS sites.","language":"Python","stars":390,"topics":["ssl","discovery","ssl-certificate","subdomain","pentesting","pentest","pentest-tool","pentest-scripts","information-retrieval","infosec"],"license":"MIT","category":"security-tools","readme_excerpt":"GSAN - Get Subject Alternative Names GSAN is a tool that can extract Subject Alternative Names (SAN) found in SSL Certificates directly from https servers which can provide you with DNS names (subdomains) or virtual servers. It doesn't rely on Certificate Transparency logs, it connects directly to the server and extracts the SANs from the certificate, which can be specially useful when you're analyzing internal servers or self-signed certificates. Installation Use pip (or pipx - recommended) to avoid contaminating your system with a bunch of dependencies. You can also install and run it using Docker. Usage Basic usage is just passing the domain of an HTTPS server to the tool, and it will return a list of subdomains found in the certificate. Alternatively, you can pass a text file with a list of domains to scan by using the xargs command. If you're using the dockerized version, you can achieve the same by doing: You can combine gsan with other tools like shodan to get a list of SANs found in a list of domains or IP addresses as long as you respect the IP DOMAIN:PORT format. You can also output to a file by using the --output flag which can be useful to then pass the output to other tools such as Nmap. Or, if you have a large list of domains: Or, if you want chaos to take the world:","default_branch":null,"files":null,"tree":[],"storefront":"/r/franccesco","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/franccesco/getaltname/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}