python3 sublist3r.py -d gitlab.com -o /root/Desktop/subdomain
dmitry -wnse gitlab.com -o /root/Desktop/dmitry
subfinder -d gitlab.com -all -silent
nslookup gitlab.com
$ sslscan gitlab.com:80 > /root/Desktop/sslscan.txt$ sslscan gitlab.com:80:6061 > /root/Desktop/sslscan.txt$ sslscan gitlab.com:80:443 > /root/Desktop/sslscan.txt
nmap -sC -sV -p- -A -oN /root/Desktop/nmap gitlab.com
masscan 5.134.6.214 --ports 0-10000
rustscan -T 1500 -b 500 13.58.194.87 -A -sC
nikto -h gitlab.com
./httpscreenshot.py -i \<gnmapFile\> -p -w 40 -a -vH
python3 JSFinder.py -u https://gitlab.com -d -j -ou /root/Desktop/Endpoint
gau gitlab.com |grep -iE '\.js'|grep -ivE '\.json'|sort -u >> GitLabJS.txt
python3 do-search.py
wappalyzer: https://www.wappalyzer.comwhat CMS: https://whatcms.org/Sublist3r: https://github.com/aboul3la/Sublist3rSubfinder: https://github.com/projectdiscovery/subfinderdmitry: https://github.com/jaygreig86/dmitryVirusTotal: https://www.virustotal.com/gui/home/searchhttpstatus: https://httpstatus.ionslookup: --> apt install dnsutilsshodan.iocensys.ioipinfo.iosslscan: https://github.com/rbsec/sslscannmap: https://github.com/nmap/nmapmasscan: https://github.com/robertdavidgraham/masscanrustscan: https://github.com/RustScan/RustScannikto: https://github.com/sullo/niktoGobuster: https://github.com/OJ/gobusterLinkFinder: https://github.com/GerbenJavado/LinkFinderTheHarvester: https://github.com/laramies/theHarvesterdirb: https://github.com/v0re/dirbffuf: https://github.com/ffuf/ffufwaybackurls: https://github.com/tomnomnom/waybackurlsSeclist: https://github.com/danielmiessler/SecListsHttpScreenShot: https://github.com/breenmachine/httpscreenshotrecon-ng: https://github.com/lanmaster53/recon-ngjsfinder:https://github.com/Threezh1/JSFindergau: https://github.com/lc/gaudo-search:https://github.com/BlackWolfed/do-searchGHDB: https://www.exploit-db.com/google-hacking-database
链接:https://github.com/BlackWolfed/RedTeamRecon
学习更多技术,关注我: