Saturday, 22 February 2020

On 12:46 by admin   No comments

From a long time I wanted to write a blog on "Recon", every time in community meet-ups or my friends were asking about "How to do Recon".

So, I decided to write this blog and tried to include such tools and services which helps me a lot while hunting.

Reconnaissance is the act of gathering preliminary data or intelligence on your target. The data is gathered in order to better plan for your attack. Reconnaissance can be performed actively or passively.

Why Recon ?

  •     Info to increase attack surface
  •     Sensitive information
  •     Infrastructure details

Before starting I recommend to install "Swiftness" it helps a lot in target tracking and Notes keeping.

In this post I’ll provide the results of a simple and straightforward evaluation of the following sub-domain enumeration tools:

I start my recon process by using the Subfinder.


For Visual Recon I mostly use:

More assets ~ Great Extend


Check for wayback URL's

Domains from CSP

Virtual Host Discovery

JS is 💛
Github For Recon

For Manual Analysis, please check
  •     API and key. (Get some more endpoints and find API keys.)
  •     token
  •     secret
  •     TODO
  •     password
  •     http:// & https://
  •     comments
Leaked Buckets
Certificate Transparency
 
Blog : https://blog.appsecco.com/certificate-transparency-part-3-the-dark-side-9d401809b025

Online Scarping


Add-ons

  • Retire.js: Outdated libraries
  • Wappalyzer: Uncovers the technologies used on websites.
Best of luck for Hunting.
 
If you have questions about the post you want to ask me, Please contact me via twitter/fb.

Feed backs and edits are welcome.

0 comments:

Post a Comment