Saturday, 22 February 2020
On 12:46 by admin No comments
From a long time I wanted to write a blog on "Recon", every time in community meet-ups or my friends were asking about "How to do Recon".
So, I decided to write this blog and tried to include such tools and services which helps me a lot while hunting.
Reconnaissance is the act of gathering preliminary data or intelligence on your target. The data is gathered in order to better plan for your attack. Reconnaissance can be performed actively or passively.
Why Recon ?
- Info to increase attack surface
- Sensitive information
- Infrastructure details
Before starting I recommend to install "Swiftness" it helps a lot in target tracking and Notes keeping.
In this post I’ll provide the results of a simple and straightforward evaluation of the following sub-domain enumeration tools:
I start my recon process by using the Subfinder.
- Subfinder (https://github.com/ice3man543/subfinder)
- Knock (https://github.com/guelfoweb/knock)
- Sudomy (https://github.com/Screetsec/Sudomy)
- Lazy Recon (https://github.com/nahamsec/lazyrecon)
- Findomain (https://github.com/Edu4rdSHL/findomain)
- Amass (https://github.com/caffix/amass)
- Shodan (https://github.com/incogbyte/shosubgo)
For Visual Recon I mostly use:
- EyeWitness (https://github.com/FortyNorthSecurity/EyeWitness)
- Webscreenshot (https://github.com/maaaaz/webscreenshot)
- Aquatone (https://github.com/michenriksen/aquatone)
More assets ~ Great Extend
- https://github.com/0xbharath/censys-enumeration
- https://github.com/tomnomnom/assetfinder
- https://github.com/MilindPurswani/Syborg
- https://github.com/0xbharath/assets-from-spf/
Check for wayback URL's
- Waybackurls (https://github.com/tomnomnom/waybackurls)
- https://gist.github.com/mhmdiaa/2742c5e147d49a804b408bfed3d32d07
- http://ptrarchive.com/
- ReconCat (https://github.com/daudmalik06/ReconCat)
Domains from CSP
- Domain from CSP (https://github.com/0xbharath/domains-from-csp)
- Virtual Host Discovery (https://github.com/jobertabma/virtual-host-discovery)
- https://pentest-tools.com/information-gathering/find-virtual-hosts
3>
- Meg (https://github.com/tomnomnom/meg)3>
- JSParser (https://github.com/nahamsec/JSParser)3>
- Link Finder (https://github.com/GerbenJavado/LinkFinder)3>
- SubJS (https://github.com/lc/subjs)3>
- GetJS (https://github.com/003random/getJS)3>
- https://javascriptbeautifier.com/3>
Github For Recon
3>
3>
- TruffleHog (https://github.com/dxa4481/truffleHog)3>
- Gitrob (https://github.com/michenriksen/gitrob)3>
- Github Cloner (https://github.com/mazen160/GithubCloner)3>
- Shhgit (https://github.com/eth0izzle/shhgit)3>
- Git all Secrets (https://github.com/anshumanbh/git-all-secrets)3>
For Manual Analysis, please check
3>
- API and key. (Get some more endpoints and find API keys.)3>
- token3>
- secret3>
- TODO3>
- password3>
- http:// & https://3>
- comments3>
Leaked Buckets
3>
3>
- S3Scanner (https://github.com/sa7mon/S3Scanner)3>
- Lazys3 (https://github.com/nahamsec/lazys3)3>
- Spaces Finder (https://github.com/appsecco/spaces-finder)3>
- CloudFlare Enumeration (https://github.com/mandatoryprogrammer/cloudflare_enum)3>
Certificate Transparency
3>
3>
- https://certdb.com/3>
- https://crt.sh/?q=%25target.com3>
- https://developers.facebook.com/tools/ct/search/3>
- https://transparencyreport.google.com/https/certificates?hl=en3>
- https://searchdns.netcraft.com/
Online Scarping
3>
- https://virustotal.com/3>
- https://www.shodan.io/3>
- https://censys.io3>
- http://dnsgoodies.com3>
- https://viewdns.info/3>
- https://dnsdumpster.com/3>
- https://www.threatcrowd.org/searchApi/v2/domain/report/?domain=xyz.com3>
- https://api.hackertarget.com/hostsearch/?q=xyz.com
3>
- Retire.js: Outdated libraries3>
- Wappalyzer: Uncovers the technologies used on websites.3>
3>
If you have questions about the post you want to ask me, Please contact me via twitter/fb.3>
Feed backs and edits are welcome.3>
Subscribe to:
Post Comments (Atom)

0 comments:
Post a Comment