<div>All,</div>
<div> </div>
<div>While reading through chapter 4.2 on Information Gathering, I found some opportunities where we could add some more tools to the testing phase for section "4.2.5 Application Discovery"</div>
<div> </div>
<div>In the "Approaches to address issue 1 - non-standard URLs" section, we could make reference to applications like OWASP's DirBuster and Nikto which can be used to try to find "hidden urls".</div>
<div>In the "Approaches to address issue 3 - virtual hosts" section, we could make reference to a tool like 'dnsenum' which tries to brute force subdomains. Comparing the resolved IP addresses of found subdomains might give you some more Virtual Hosts.</div>
<div> </div>
<div>I'm pretty sure we can add the references to DirBuster and Nikto, so I'll update the text on the wiki. </div>
<div>However, I'm not so sure we could add dnsenum, since there we would be querying the DNS server and not the webserver.</div>
<div> </div>
<div>What's your opinion about this?</div>
<div> </div>
<div>Regards,</div>
<div> </div>
<div>Lode<br>-- <br>Lode Vanstechelman, CISA<br>www.vanstechelman.eu<br></div>