https://github.com/six2dez/reconftw
Google Hacking Database: https://www.exploit-db.com/google-hacking-database
OSINT harvesting: emails, hosts, subdomains from public sources (passive)
theHarvester -d example.com -b all
theHarvester -d example.com -b bing,duckduckgo,crtsh,otx
Check Server, X-Powered-By, and other response headers
Compare headers against known signatures
Check version via banner grabbing and/or error pages
curl -I example.com # Very noisy
whatweb -a 1 example.com # Stealthy
whatweb -a 3 example.com # Aggressive
# nmap service version, very noisy, rarity level 2
sudo nmap -sV --version-light example.com
Other tools:
Map version to CVEs: https://www.exploit-db.com/
searchsploit wordpress 6.4 # Map known versions to exploits
robots.txt, sitemap.xml/.well-known if available, for example /.well-known/security.txthumans.txt, crossdomain.xml, clientaccesspolicy.xml<meta> tags and generator stringssublist3r -d example.com # Subdomain enumeration, passive
subfinder -d example.com -silent # Subdomain enumeration, passive, part of ProjectDiscovery ecosystem
subfinder -d example.com -silent | httpx -silent -title -tech-detect
# Full port sweep, SYN scan
sudo nmap -sS -p- -T3 example.com
# Can also use dnsdumpster.com
dnsrecon -d example.com # DNS recon
dnsenum example.com # Passive + Active DNS recon, perform DNS zone transfer
# Virtual host brute force
gobuster vhost -u "example.com" --domain example.com -w /path/to/wordlist --append-domain --exclude-length 250-320
# Crawler, maps out every URL, endpoint, JS file, form, and parameter
katana -u -silent example.com
katana -u -silent example.com -jc -kf all -o output.txt # Parse JS to find hidden endpoints
katana -u -silent example.com -jc -kf -hl # Find dynamic routings
# Fuzz for hidden endpoints, different from Katana
ffuf -w /path/to/wordlist -u example.com/FUZZ -mc 200,301 # Filter status code
## While using ffuf, can add .old extension at end, example.com/FUZZ.old
## Virtual host fuzzing
ffuf -u <https://target.com/> -H "Host: FUZZ.target.com" -w /path/to/wordlist -fs 0