Project Name | Stars | Downloads | Repos Using This | Packages Using This | Most Recent Commit | Total Releases | Latest Release | Open Issues | License | Language |
---|---|---|---|---|---|---|---|---|---|---|
Reconftw | 4,304 | a day ago | 28 | gpl-3.0 | HTML | |||||
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities | ||||||||||
Vulnx | 1,632 | 11 days ago | 2 | June 04, 2019 | 18 | gpl-3.0 | Python | |||
vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information collection (including sub-domain name, ip address, country information, organizational information and time zone, etc.) and vulnerability scanning. | ||||||||||
Dnstake | 727 | 4 months ago | 5 | April 15, 2022 | 8 | mit | Go | |||
DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover | ||||||||||
Subzy | 676 | 15 days ago | 4 | April 23, 2021 | 3 | gpl-2.0 | Go | |||
Subdomain takeover vulnerability checker | ||||||||||
Garud | 577 | 10 months ago | mit | Shell | ||||||
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically. | ||||||||||
Aort | 556 | 5 months ago | 8 | October 12, 2022 | 4 | gpl-3.0 | Python | |||
All in One Recon Tool for Bug Bounty | ||||||||||
Sub404 | 257 | 5 months ago | 1 | gpl-3.0 | Python | |||||
A python tool to check subdomain takeover vulnerability | ||||||||||
Cazador_unr | 119 | 4 months ago | ||||||||
Hacking tools | ||||||||||
Takeover V1 | 91 | 4 months ago | 1 | gpl-3.0 | Shell | |||||
Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover vulnerability. | ||||||||||
Firebase | 85 | 4 years ago | mit | Python | ||||||
Exploiting misconfigured firebase databases |
Read README.md before Installation
Scripts:
amass
assetfinder
findomain
gau
knockpy
sublist3r
takeover
v1d0m
Domains:
api.hackertarget.com
crt.sh
dns.bufferover.run
riddler.io
securitytrails.com
sonar.omnisint.io
threatcrowd.org
web.archive.org
$ git clone https://github.com/z3dc0ps/0x0p1n3r
$ cd 0x0p1n3r
$ sudo apt-get install dos2unix
$ sudo dos2unix ./*
$ sudo bash setup.sh
$ bash run.sh -u
$ cd ../0x0p1n3r ; dos2unix ./*
$ bash setup.sh
Go to https://www.virustotal.com/ and Login
Go to API key which in Top Right Option Menu
Copy API key and Paste in config.json
$ bash run.sh
@Tom Hudson
@Corben Leo
@Ahmed Aboul-Ela
@Nacho Brihuega
@KingOfBugbounty
@mallok