summary of reconnaissance for web application bug hunting 🕷
2022-08-26 - Rainhynn
notes:
- in this article if you found text like this
hereis a tools or platforms. you just search that on google or other search engines. - this article will be to always updated if me found new techniques or methods.
base
- whois:
whois - ssl information:
sslscan - dns enumeration:
dnsreconnslookupdnsxdnsenum - identify web technology:
whatwebwappalyzercmsmap - check webapp firewall:
wafw00f - check security headers:
shcheck - subdo enumeration:
subfindersublist3rknock - extracting all IP from collected subdodomain
- port scanning & banner grabbing:
nmapamassaquatonenaabu - check domain takeover:
subzy - domain & subdo osint:
shodancensys - check http(s) 80/443:
httpx>altdns>nuclei - reverse IP lookup
hackertargetgoogledorkbing
Content discovery
Fuzzing
getting directory, files, sensitive data. scan error like system crash, sql injection, etc. with fuzzing technique
wfuzz:Web application fuzzerffuf:Fast web fuzzer written in GofuzzdbDictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
links and urls
getting js files, php, aspx and other interesting files or urls. for scanning endpoint, API path, etc.
gau:Fetch known URLs from AlienVault’s Open Threat Exchange, the Wayback Machine, and Common Crawl.waybackurls:Fetch all the URLs that the Wayback Machine knows about for a domaingetJS:A tool to fastly get all javascript sources/fileslinkfinder:A python script that finds endpoints in JavaScript filesassetfinder:Find domains and subdomains related to a given domain
Parameters
parameth:This tool can be used to brute discover GET and POST parametersParamSpider:Mining parameters from dark corners of Web ArchivesffufcommixOther helpergobuster:Directory/File, DNS and VHost busting tool written in Gogospider:Gospider - Fast web spider written in Gohakrawler:Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web applicationgit-hound:Reconnaissance tool for GitHub code search. Finds exposed API keys using pattern matching, commit history searching, and a unique result scoring system.pagodo:pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
Extra resources for you :3
- Cool Recon techniques every hacker misses! 🔥🔥
https://infosecwriteups.com/cool-recon-techniques-every-hacker-misses-1c5e0e294e89
© 2021-2025 HnvDie
Powered By Hugo ᯓᡣ𐭩