{"id":13845937,"url":"https://github.com/Ciyfly/y_subdomain","last_synced_at":"2025-07-12T03:33:01.887Z","repository":{"id":42677615,"uuid":"186804471","full_name":"Ciyfly/y_subdomain","owner":"Ciyfly","description":"🐗 造轮子之子域名获取工具","archived":false,"fork":false,"pushed_at":"2022-12-08T05:47:07.000Z","size":48536,"stargazers_count":14,"open_issues_count":3,"forks_count":0,"subscribers_count":2,"default_branch":"master","last_synced_at":"2024-07-30T14:19:05.835Z","etag":null,"topics":["python3","security-tools","subdomain-scanner"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Ciyfly.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2019-05-15T10:31:32.000Z","updated_at":"2024-07-30T14:19:05.836Z","dependencies_parsed_at":"2023-01-24T16:16:22.011Z","dependency_job_id":null,"html_url":"https://github.com/Ciyfly/y_subdomain","commit_stats":null,"previous_names":["ciyfly/y-subdomain"],"tags_count":6,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ciyfly%2Fy_subdomain","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ciyfly%2Fy_subdomain/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ciyfly%2Fy_subdomain/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ciyfly%2Fy_subdomain/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Ciyfly","download_url":"https://codeload.github.com/Ciyfly/y_subdomain/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225791452,"owners_count":17524790,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["python3","security-tools","subdomain-scanner"],"created_at":"2024-08-04T17:03:56.026Z","updated_at":"2024-11-21T19:30:53.222Z","avatar_url":"https://github.com/Ciyfly.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"# y_subdomain\n\n子域名获取工具\n\n\n## 使用\n\n使用加速下载\n`git clone https://github.com.cnpmjs.org/Ciyfly/y_subdomain.git`\n\n**如果是下载的zip 或者tar包需要修改文件夹名为 y_subdomain**\n\n**基于python3 linux环境下**\n\n适用于 扫描器前置信息收集 简单子域名获取 学习等  \n基本使用内置原生库\n\n[![asciicast](https://asciinema.org/a/m7mqlsHux1TinM2oWB6D6LZoD.png)](https://asciinema.org/a/m7mqlsHux1TinM2oWB6D6LZoD)\n\n\n### 泛解析的解决办法\n先测试一个不存在的域名然后是否成功解析\n\n\n### 为什么要做\n1. 重复造轮子 深入理解轮子 做出更好用的轮子\n2. 是大扫描器的信息收集的一部分功能的实现\n3. 工作中擅于使用轮子 学习中擅于造轮子  \n\n\n## 实现  \n### 接口的实现\n这里参考 poc的形式 动态的从script文件夹下的脚本\n动态载入实例化并执  \n继承Base类默认有个 `self.enable=True` 可以控制是否开启脚本  \n如果使用 -e 指定接口 enable是False也会强制执行  \n对于接口返回的域名会使用线程池再去dns解析验证 (默认线程池大小 50)\n\n**接口引擎脚本完成：**\n1. 百度云检测  \n2. hackertarget\n3. virustotal (**需要在config/config.py 中添加api key才能使用不然默认不会执行**)\n4. 通过证书获取\n\n### 暴力穷举的实现  \n一口气加载字典到内存中 占内存不大  \n使用共享队列+多线程的形式进行解析dns 默认线程开启100个  \n这个地方有进度条功能 可以在实例化穷举类的时候进行选择是否开启  \n\n\n## 版本\n\n**v1.2**   \n2021 0520\n去掉大字典 影响下载速度  \n保存的结果拆分为 ip ipc段 域名 域名+ip  \n增加获取title功能 `--title`  \n增加动态生成字典加入测试字典功能 `--gen`  \n\n**v1.1.0**   \n修改一些bug  \n增加三级四级域名穷举  \n修改为默认小字典2w (使用的onforall的字典)  \n指定`big_dict` 可以使用大字典200w  \n增加可以指定字典参数  \n穷举增加超时时间 默认为2h  \ndns增加超时时间10s  \n\n**v1.0.0**  \n修改bug  \n进度条增加find输出  \n增加对内网ip的剔除参数  \n增加指定字典的参数  \n\n**V0.2**  \n修改 穷举采用共享队列+多线程的形式  \n去除多余代码  \n修改了代码结构 便于作为api使用  \n穷举增加了进度条  \n扩大了字典 目前字典 2350706 (235w) (跑一次大概 40分钟左右)  \n增加了HUP小调试 发起HUP信号会输出 此时队列大小 (在 api形式使用不输出进度条的时候 如果长时间未结束可调试使用)  \n`kill -HUP 进程id`  \n\n**V0.1**  \n采用多接口的形式获取域名 动态插件形式添加接口脚本  \n接口验证和穷举都采用线程池的形式进行dns解析  \n\n\n\n# api形式使用  \n使用接口解析\n```python\nfrom y_subdomain.lib.core import EngineScan\n\nengine_scan = EngineScan(scan_domain, engine)\n# scan_domain 为扫描的域名 engine 是指定的接口 空的话就全部都跑 默认也是全部都跑  \nengine_domain_ips_dict = engine_scan.run()\n# 调用 run方法会返回 解析的结果 是 字典形式 子域名对应ip列表  \n\n接口类如下:\nclass EngineScan(object):\n    \"\"\"接口解析类\n    :param scan_domain 测试域名\n    :param engine 指定引擎列表 默认全部\n    :param thread_count 线程 默认100\n    :param get_black_ip 是否返回泛解析的ip 默认不返回\n    :param is_private 是否保留内网ip 默认不保留\n    :return domain_ips_dict, (black_ip) 选择返回泛解析ip则有第二个 否则只返回域名对于ip\n    \n    \"\"\"\n```\n使用穷举解析\n```python\nfrom y_subdomain.lib.core import ExhaustionScan\nscan_domain = \"测试域名\" # 穷举只支持单个域名\nexhaustion_scan =  ExhaustionScan(scan_domain, thread_count=100, is_output=True)\n# is_output 是否输出进度条 默认是False的\nexh_domain_ips_dict = exhaustion_scan.run()\n\n穷举类如下:\nclass ExhaustionScan(object):\n    \"\"\"暴力穷举\n    :param scan_domain 要测试的域名\n    :param thread_count 线程数 默认100\n    :param is_output 是否输出进度条 默认不输出\n    :param black_ip 泛解析的ip     默认为空\n    :param is_private 是否保留内网ip 默认不保留\n    :param sub_dict 指定的字典 默认读取配置文件下字典 \n    :param next_sub 是否是三级或者四级的域名扫描\n    :param timeout 超时时间 默认穷举超时时间为 2h\n    :return domain_ips_dict 域名对应解析的ip结果\n    \n    \"\"\"\n```  \n\n## update\n2019 0813\n修改一些bug  \n增加三级四级域名穷举  \n修改为默认小字典2w (使用的onforall的字典)  \n指定`big_dict` 可以使用大字典200w  \n增加可以指定字典参数  \n穷举增加超时时间 默认为2h  \ndns增加超时时间10s  \n\n---\n\n2019 0719  \n修改bug  \n进度条增加find输出  \n增加对内网ip的剔除参数  \n增加指定字典的参数 \n\n---\n2019 0711  \n增加对内网ip的忽略 默认是清除掉的 可以通过命令行参数进行控制  \n增加指定字典的功能参数  \n增加只进行穷举的功能参数  \n没有把去除内网ip的方法写到savedata中是为了当接口api使用的时候 对内网ip的处理类内部就进行处理\n\n---\n2019 0709  \n经测试 修改对于泛解析的解决  \n如果随机字符串跑出来泛解析还继续进行穷举但是过滤掉这个泛解析的ip  \n对于接口里的也进行泛解析剔除  \n对于暴力穷举的会默认使用配置文件中的 50 阈值 作为判断泛解析的条件 当超过50个域名指向一个ip进行剔除  \n\n\n# TODO\n多增加几个模块\n优化下代码结构\n\n## 参考\n\n[ESD](https://github.com/FeeiCN/ESD)  \n\n[wydomain](https://github.com/ring04h/wydomain)  \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FCiyfly%2Fy_subdomain","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FCiyfly%2Fy_subdomain","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FCiyfly%2Fy_subdomain/lists"}