Sububy 是一款用 Ruby 编写的一站式子域名枚举套件,它专注于准确性与质量,并允许你单独调用部分模块而无需遵循工具的执行流程,从而能够将之集成到你的工作流中。

Sububy 总共包含九个模块,其中六个用于枚举,其余执行枚举后操作。
| 类别 | 模块 | 描述 |
|---|---|---|
| 枚举 | Cert | 从证书透明度日志中检索子域名。 |
| Brute | 使用提供的字典暴力枚举子域名。 | |
| Dnsd | 从 DnsDumpster 获取子域名(需要 API 密钥:免费)。 | |
| Vtotal | 从 VirusTotal 获取子域名(需要 API 密钥:免费)。 | |
| WebArch | 从互联网网页档案馆获取子域名 | |
| Csp | 从已发现存活域名的 CSP 中获取子域名。 | |
| 后枚举 | Sort | 对已发现的子域名进行排序,去除重复项以及不属于目标域名的主机。 |
| Live | 识别运行有活跃网页服务器的子域名。 | |
| Sshot | 使用 HTTP 和 HTTPS 协议截取屏幕截图。 | |
| Info | 允许你检索基本 HTTP 信息,如响应状态码和响应头。 |
git clone https://github.com/A3h1nt/Sububy.git
cd Sububy
bundle install
Sububy.rb 中配置 API 密钥,可通过以下 URL 获取:ruby Sububy.rb <domain> <cn> <wordlist> <output-dir>

Sububy 的模块设计允许你单独调用,无需反复运行整个工具。在开始使用单个模块之前,你需要先在 Ruby shell 中加载文件。在终端输入 irb 启动 Ruby shell,然后加载 sububy 文件。
irb(main):002:0> require_relative 'Sububy.rb'
irb(main):002:0> # Set the output directory
irb(main):002:0> $output_dir = '/path/to/output_dir'
只想枚举子域名?
Cert.get(domain) #-> cert.txt
Brute.bruteforce(domain,wordlist) #-> brute.txt
Dnsd.getsub(domain) #-> dnsd.txt
Vtotal.getsub(domain) #-> vtotal.txt
WebArch.get(domain) #-> webarchive.txt
已经有一个子域名列表,需要排序?
Sort.domain(domain,file) #-> returns identified_host.txt with domain name mentioned in subdomain
Sort.uniq(file1,file2) #-> combine and returns unique subdomains
已经有一个子域名列表,需要找出存活的?
Live.get(host_file) #-> returns live_host.txt with list of alive host
已经有一个子域名列表,想要截取屏幕截图?
Sshot.http(host_file) #-> returns http screenshots in http/
Sshot.https(host_file) #-> returns https screenshoots in https/
想获取关于子域名的更多信息?
Info.info "hosts.txt" #-> Initiates the info module, you need to run this before you can use other methods
Info.headers "hostname" #-> Returns response headers for a particular host
Info.headersall #-> Returns response headers for all hosts specified in the file
Info.status "hostname" #-> Returns response status code for a particular host
Info.statusall #-> Returns response status for all hosts specified in the file
Info.title "hostname" #-> Returns webpage title for a particular host
Info.titleall #-> Returns webpage title for all hosts specified in the file
Info.comments #-> Writes scaraped comments to file
Info.links #-> Writes scraped links to file
Sububy 使用一些全局变量来存储数据,这些变量也可以直接访问。
$dnsdumpster_api_key # API key for dnsdumpster
$virustotal_api_key # API key for virustotal
$live_host # Array of live host
$csp_list = [] # Array of host identified from CSP
$output_dir # Path to output directory