ÐÅÏ¢ÍøÂçµ½´òµã´óÖÂÎҾͷÖΪ
ÆóÒµÐÅÏ¢½á¹¹ÍøÂç
Ãô¸ÐÐÅÏ¢ÍøÂç
ÓòÃû×Ô¶¯±»¶¯ÍøÂç
ÕûÀíÓòÃûip×ʲú
ɨÃè¼ì²â´òµã
ÆäÖÐÿһ²½ÐèÒªÍøÂçºÃ¼¸¸ö·½ÃæµÄÐÅÏ¢£¬ÊÖ¶¯ºÜÀÛÒ²ºÜÂý
Ò»¡¢ÆóÒµÐÅÏ¢½á¹¹ÍøÂç
ÆóÒµÐÅÏ¢½á¹¹ÍøÂç°üÀ¨¶ÔÅÌÎÊÄ¿µÄÆóÒµµÄ¹«Ë¾ÐÅÏ¢£¬Éæ¼°µ½ÄÄЩÖ÷Õ¾ÓòÃû£¬ÓÐÄÄЩ¿Ø¹ÉÐí¶àµÄ×Ó¹«Ë¾£¬ÕâЩ×Ó¹«Ë¾Éæ¼°µ½ÄÄЩÓòÃû£¬È»ºóÔÙ¾ÙÐб¸°¸·´²é£¬ÄãÓÖ»á»ñµÃһЩÐµĹ«Ë¾£¬Í¬ÀíÒ²ÄÜÔٴλñµÃһЩеÄÖ÷Õ¾ÓòÃû£¬½«ÕâЩ¾ÙÐÐÕûÀí---->»ñµÃÒ»Åú´ý±¬ÆÆµÄÓòÃû¡£
ÉÐÓеľÍÊdzýÁËÕâЩ²éµ½µÄÖ÷Õ¾ÓòÃû£¬ÍùÍùÆóÒµ»áÓÐapp¡¢¹«Öںš¢Ð¡³ÌÐòÕâЩ×ʲú£¬Ò²Òª¶ÔÕâЩ×ʲú¾ÙÐÐÍøÂ磬ȻºóÄãÓÖÄõ½ÁËÒ»ÅúÓòÃû¡£
ÊÖ¶¯ÅÌÎʵϰ´ÓÒÔÏÂÅÌÎÊ
ÌìÑÛ²é ²éÆóÒµ/×Ó¹«Ë¾/ÓòÃû/¹«ÖںŠhttps://www.tianyancha.com/
°®Æó²é https://aiqicha.www.szcwtygs.com/
Æó²éÅÌÎÊ https://www.qcc.com/
ÆôÐű¦ https://www.qixin.com/
¹¤¾ß:
ÍÆ¼öcSubsidiaryʹÓÃÌìÑÛ²éÅÌÎÊÆóÒµ×Ó¹«Ë¾https://github.com/canc3s/cSubsidiaryÉÐÓÐpigat£ºhttps://github.com/teamssix/pigat¹«ÖںźÍappµÄÍøÂ磺https://github.com/wgpsec/ENScanhttps://github.com/wgpsec/ENScan_GO go°æ±¾
¶þ¡¢Ãô¸ÐÐÅÏ¢ÍøÂç
ʹÓÃËÑË÷ÒýÇæ¡¢githubµÈÍÐ¹ÜÆ½Ì¨ÅäºÏһЩdorks¾Í¿ÉÒÔËѵ½Ðí¶àÐÅÏ¢¡£
ÊìÖªµÄgooglehack£¬gitdork£¬ÍøÅÌй¶µÈµÈ¡£
Ãô¸ÐÐÅÏ¢Ò»¹²ÒªËѼ¯Õâ¸ö¼¸¸ö·½Ã棺
googlehackÓï·¨
githubй¶
Ä¿µÄÖ°Ô±ÐÕÃû/ÊÖ»ú/ÓÊÏä
1.googlehack
µ«ºÃ±Ègooglehack£¬ÄãÐèÒªËѵĺü¸ÌõÓï·¨¼ÓÉÏÓòÃû
ºÃ±È£º
site:*.domain.com
inurl:domain.com
intitle:keyword
keyword filetyle:doc|pdf
Ò»¸öÓòÃû¿ÉÒÔÅäºÏ¶à¸öÓï·¨ËÑ£¬ÄÇô¶àÓòÃûÊÖ¶¯ÊäÈëËѺÜÂý£¬ÍƼö¹¤¾ß:
https://github.com/r00tSe7en/GoogleHackingTool ÔÚÏßGoogle Hacking С¹¤¾ß
https://www.exploit-db.com/google-hacking-database Óï·¨£¬×Ô¼º¿ÉÒԾ籾ÀïÅúÁ¿ËÑ
2.githubй¶Ãô¸ÐÐÅÏ¢£º
һЩ³£ÓÃgithub dorks,Ö±½ÓËѶÔӦĿµÄÐÅÏ¢£º
xxxxx.com "Authorization" #"Authorization: Bearer"
xxxxx.com "filename£ºvim_settings.xml"
xxxxx.com "language£ºPHP"
Ò²¿ÉÒÔÔÚgithub¶ÔÖÖÖÖÐÅÏ¢ËÑË÷£¬ºÃ±ÈÎļþÀàÐÍ
filename:manifest.xml
filename:travis.yml
filename:vim_settings.xml
filename:database
filename:prod.exs NOT prod.secret.exs
filename:prod.secret.exs
filename:.npmrc _auth
filename:.dockercfg auth
filename:WebServers.xml
filename:.bash_history <Domain name>
filename:sftp-config.json
filename:sftp.json path:.vscode
filename:secrets.yml password
filename:.esmtprc password
filename:passwd path:etc
filename:dbeaver-data-sources.xml
path:sites databases password
filename:config.php dbpasswd
filename:prod.secret.exs
filename:configuration.php JConfig password
filename:.sh_history
°üÀ¨Òªº¦×ÖµÄÖ¸¶¨ÓïÑÔ£º
language:python usernamelanguage:php usernamelanguage:sql usernamelanguage:html passwordlanguage:perl passwordlanguage:shell usernamelanguage:java apiHOMEBREW_GITHUB_API_TOKEN language:shell
ËÑAPI/KEYS/TOEKNSÒªº¦×Ö£º
api_key
¡°api keys¡±
authorization_bearer:
oauth
auth
authentication
client_secret
api_token:
¡°api token¡±
client_id
password
user_password
user_pass
passcode
client_secret
secret
password hash
OTP
user auth
Ðí¶àÒªº¦×Ö¿ÉÒÔËÑ£¬ÕÕ¾ÉÅúÁ¿ËѸßЧ£¬¹¤¾ß£º
https://github.com/obheda12/GitDorker
https://github.com/michenriksen/gitrob
https://github.com/dxa4481/truffleHog
https://github.com/techgaun/github-dorks
ÕâÀ๤¾ßÐèÒªÉèÖÃgitÁîÅÆ£¬¸½ÉÏgitrobÀú³Ì£¬²È¿Ó:²»ÒªÏÂrelase £¬×Ô¼º±àÒë×îºÃ£º
git clone https://github.com/michenriksen/gitrob.git
go mod init #to use go mod ÈôÊDZ¨´í ÔËÐÐgo mod init github.com/michenriksen/gitrob
rm Gopkg* #remove the old stuff
go build #to build it
./build.sh
ÉèÖÃgitÁîÅÆ
set GITROB_ACCESS_TOKEN=xxxxx
ʹÓúó¿ÉÒÔÉó²éͼÐνçÃæµÄЧ¹û£º

3. Ä¿µÄÖ°Ô±ÐÕÃû/ÊÖ»ú/ÓÊÏä
ͨ¹ý¿ªÔ´ÐÅÏ¢ÍøÂçÄ¿µÄÖ°Ô±ÐÕÃû/ÊÖ»ú/ÓÊÏ䣬ΪºóÃæ´òµã×ö×Öµä×ö×¼±¸¡£
https://github.com/laramies/theHarvester
ͨ¹ýËÑË÷ÒýÇæ¡¢PGP·þÎñÆ÷ÒÔ¼°SHODANÊý¾Ý¿âÍøÂçÓû§µÄemail£¬×ÓÓòÃû£¬Ö÷»ú£¬¹ÍÔ±Ãû£¬¿ª·Å¶Ë¿ÚºÍbannerÐÅÏ¢¡£
ʹÓãº
-d ¿ª¹ØÓÃÓÚ½ç˵ÓòÃû£¬-l ÓÃÓÚÏÞÖÆÐ§¹ûÊýÄ¿
theHarvester -d kali.org -l 200 -b
anubis,baidu,pentesttools,projectdiscovery,qwant,rapiddns,
rocketreach,securityTrails,spyse,sublist3r,threatcrowd,threatminer,
trello,twitter,urlscan,virustotal,yahoo,zoomeye,bing,binaryedge,
bingapi,bufferoverun,censys,certspotter,crtsh,dnsdumpster,duckduckgo,
fullhunt,github-code,google,hackertarget,hunter,intelx,linkedin,
linkedin_links,n45ht,omnisint,otx
°´githubÅܾÍÊÇÁË£¬¿ÉÊÇÓеã¿Óµã£º
ÉèÖÃapi-keysÔÚ/etc/theHarvester Ŀ¼ÏÂapi-keys.yamlÌîÈë¶ÔÓ¦µÄapi key¼´¿É

Óиö¿ÓµãÊÇkey:ºóÒª¼Ó¸ö¿Õ¸ñÔÚ·Åkey×Ö·û´®£¬²»È»Åܲ»ÆðÀ´
Ö°Ô±ÓÊÏä×ÖµäµÄ½á¹¹£º
https://github.com/pry0cc/GoogLinked/blob/master/GoogLinked.rb

»¹¿ÉÒÔʹÓÃһЩÉ繤ÐÅÏ¢À´×ö×ֵ䣬ÕâÑùµÄ¹¤¾ßÐí¶àÁË£¬ÓÃÒ»¸ö¾Í¹»ÁËûÐëÒªÓÃËùÓУºCupp/Cewl
https://github.com/r3nt0n/bopscrk
python3 bopscrk.py -i
Èý¡¢ÓòÃû×Ô¶¯±»¶¯ÍøÂç
ÓòÃû×Ô¶¯ÐÅÏ¢ÍøÂçÄÚÈݾÍÓеãÔÓÁË¡£
ͨ¹ý1¡¢2µãÎÒÃÇÄõ½ÁËÒ»ÅúÆÚ´ý±¬ÆÆµÄÓòÃûºÍÖ°Ô±µÄÐÅÏ¢£¬ÒÔ¼°Ð¹Â¶µÄһЩÃô¸ÐÐÅÏ¢(ÔËÆøºÃµÄ»°ÓÃй¶µÄÐÅÏ¢ÒѾ´òµ½µãÁË¡£)
ÏÖÔÚÐèÒª¶ÔÓòÃû¾ÙÐÐwhoisÐÅÏ¢ÅÌÎÊ¡¢dnsÓòÃûÕý·´ÅÌÎÊ¡¢×ÓÓòÃû̽²â±¬ÆÆÈý¸ö·½ÃæÍøÂç¡£
1.whoisÐÅÏ¢ÅÌÎÊ
whoisÐèÒªÅÌÎÊÓòÃûµÄwhois£¬È»ºóƾ֤whoisÐÅÏ¢À´ÅÌÎÊÀúÊ·ºÍ·´²é£¬ÕâÑùÄã¾Í»ñµÃÁËһЩÓÊÏäºÍ¿ÉÒÉÓòÃû¡£
²éÓòÃûÐÅϢûʲô˵µÄ£¬Ö÷Òª¿´ÍøÖ·×¢²áÈË¡¢µ½ÆÚ¼Í¼¡¢½¨ÉèÓòµÄʱ¼ä¡¢Ãû³Æ·þÎñÆ÷ºÍÁªÏµÐÅÏ¢µÈ£¬²é×îеÄÒ»Ñùƽ³£¶¼ÊÇÍйܵÄÐÅÏ¢£¬¶øÉó²éÀúÊ·ÐÅÏ¢¾ÍÓпÉÄÜ²éµ½ÕæÊµÁªÏµÈËÓÊÏäµç»°µÈ:

һЩ³£¼ûwhoisÅÌÎÊ£¬ÊÖ¶¯µÄʱ¼ä¿ÉÒÔÅÌÎÊ:
https://domaineye.com/reverse-whoishttps://www.reversewhois.io/https://tool.domains/whois-researchhttps://tools.webservertalk.com/reverse-whoishttps://reverse-whois-api.whoisxmlapi.com/http://whois.domaintools.com/https://viewdns.info/reversewhois/https://www.domainiq.com/reverse_whois
³ýÁËÕýÏòÅÌÎÊwhois£¬»¹ÒªÅÌÎÊwhoisÀúÊ·ÐÅÏ¢:
ÒÔϼ¸¸öÍøÕ¾ÔÊÐíÓû§»á¼ûÅþÁ¬µÄ WHOIS Êý¾Ý¿âÒÔ¾ÙÐÐÊӲ졣ÕâЩ¼Í¼ÊÇÊ®¶àÄêÀ´¶ÔÓйØÓò×¢²áµÄÓÐÓÃÊý¾Ý¾ÙÐÐÍøÂçÅÀÈ¡µÄЧ¹û:
https://whois.domaintools.com/https://drs.whoisxmlapi.com/?ts=gp&ref=hackernoon.comhttps://whois-history-api.whoisxmlapi.com/?ts=gp&ref=hackernoon.comhttps://www.whoxy.com/
whoisÀúÊ·ÐÅÏ¢ÅÌÎʲ»¿É´í¹ý£¬ÏÔ×Å¿ÉÒÔÔÚwhoisÀúÊ·ÐÅÏ¢Öп´ÕæÊµÓÊÏä²¢·´²é¶ø²»ÊÇÏÖÔÚÍйܵÄÓÊÏ䣬ÒÔ¼°·ÇÍйܵÄdns·þÎñÆ÷:

whois ÐÅÏ¢·´²é
ͨ¹ýÀúÊ·whoisÐÅÏ¢ÕÒµ½ÕæÊµÓÊÏäor×éÖ¯Ãû£¬ÔÙ·´²éÓòÃû£¬ÓÖ¿ÉÒÔ»ñµÃÒ»Åú×ʲú£º

other:
https://www.reversewhois.io/

ÕûÀíÒ»ÏÂwhois·ÖÁËÈý²½£¬ÏÈwhoisÅÌÎÊÒ»¸öÓòÃû£¬È»ºó¶ÔÅÌÎʵÄÐÅÏ¢¾ÙÐÐÀúÊ·whoisÅÌÎʺͷ´²é,×îºó»ñµÃÒ»ÅúÓÊÏäºÍÓòÃû¡£ÊÖ¶¯ÖªµÀÀú³Ì¾ÍÐУ¬ÏÖʵ×öÏîÄ¿Óù¤¾ßÅúÁ¿²éÁËÕûÀí£º
https://github.com/xugj-gits/domain-tool ÅúÁ¿whoisÅÌÎÊ
https://github.com/melbadry9/WhoEnum
2.dnsÓòÃûÕýÏò·´ÏòÅÌÎÊ
dnsÓòÃûÅÌÎÊ·ÖÁ½¸ö²¿·Ö£¬ÀúÊ·¼Í¼ºÍip·´²é£º
DNSÀúÊ·¼Í¼(doamin2ips)
Dnsdumpster ÊÇÒ»¸öÔÚÏßÊÊÓóÌÐò£¬ÎÒÃÇʹÓÃËüÀ´²éÕÒ×ÓÓò¡¢Ä¿µÄµÄ DNS ¼Í¼¡£

VTÒ²ÊÇ¿ÉÒÔ¿´dnsÊý¾ÝÐÅÏ¢µÄ:

ip·´²é(ip2domains)
ͬipÅÌÎʶà¸öÆÊÎöµ½Õâ¸öipµÄÓòÃû£¬Ñ°ÕÒ¸ü¶àweb×ʲú
https://viewdns.info/reverseip/

https://dnslytics.com/

ip·´²éÒ²¿ÉÒÔʹÓÃdig¡¢nslookup¡¢hostÏÂÁîÍê³É£º

¹¤¾ßÍÆ¼ö£º
https://www.infobyip.com/ipbulklookup.php ÅúÁ¿ip·´²é
https://github.com/Sma11New/ip2domain º£ÄÚÓòÃûÍÆ¼öip2domain£¬»áÅÌÎÊÈ¨ÖØ¡¢ICP±¸°¸µÈ

ͨ¹ýdnsÅÌÎÊ£¬ÎÒÃÇÄõ½ÁËһЩÓòÃûºÍ¿ÉÒÉip¶Î
3.×ÓÓòÃû̽²â±¬ÆÆ
ûɶºÃ˵µÄ£¬Ö÷ÒªÊÇÍøÂçµÄÇþµÀÈ«¡¢¹ýÂË·ºÆÊÎö¡£
³£¼ûÊÖ·¨±¬ÆÆ×ÓÓòÃû¡¢Ö¤Êé͸Ã÷¶È¡¢ËÑË÷ÒýÇæ¡¢ÐÅϢй¶¡¢ASNºÅµÈµÈ£¬Ðí¶à¹¤¾ßÒѾ×öÁËÕâЩÊÂÇé
https://github.com/shmilylty/OneForAllhttps://github.com/six2dez/reconftwhttps://github.com/P1-Team/AlliNhttps://github.com/d3mondev/puredns
ËÄ¡¢ÕûÀíÓòÃûip×ʲú
µ½ÕâÀï´óÖµÄÍøÂç¾Í¿¢ÊÂÁË£¬¾ÍÊÇÒª¶ÔÍøÂçЧ¹û¾ÙÐÐÕûÀí£¬Í¨¹ýÉÏÃæÍøÂçÄÜÄõ½£º
Ò»Åú´ý̽²â´æ»îµÄÓòÃû
Ò»Åú´ýÈ·¶¨µÄip¶Î
һЩÓÊÏ䣬ÐÕÃû£¬ÊÖ»úºÅ
һЩÃô¸ÐÎļþ¡¢ÐÅÏ¢¡¢Í¨ÓÃÃÜÂë(Ãô¸ÐÐÅÏ¢ÍøÂç½×¶Î¿´Á³)
ÕûÀíºó´óÖÂÈçÉÏ£¬ÓÐÒ»²½ÐèÒª×öµÄ¾ÍÊǰÑÍøÂçµÄÕâЩÓòÃû£¬×ª³Éip¶Î£¬¿ÉÊÇÊÇÐèÒªÅжÏÕâ¸öipÊô²»ÊôÓÚcdn£¬Êô²»ÊôÓÚ·ºÆÊÎöµÄip£¬È»ºóת³ÉipºóÒªÅжÏip¶ÎµÄÈ¨ÖØ£¬ÄÄЩ¶Î²Å¿ÉÄÜÊÇÄ¿µÄÖ÷ÒªµÄC¶Î¡£
https://github.com/EdgeSecurityTeam/Eeyes ¶ÔsubdomainÊý¾Ý´¦Öóͷ£¡¢»ñÈ¡ÆäÖÐÕæÊµIP²¢ÕûÀí³Éc¶Î
https://github.com/canc3s/cIPR ÕûÀíºóÉó²éÈ¨ÖØ

Îå¡¢ ɨÃè¼ì²â´òµã
Õâ²½¾Í×îÏÈ¿ìËÙ´òµãÁË¡£
ÉÏÃæÕûÀíºóµÄ×ʲú£¬ÐèÒªÎÒÃÇ̽²âµÄÊÇÒ»ÅúÓòÃûºÍÒ»ÅúC¶Î
ÓòÃûÐèÒª×öµÄÊ£º
̽²â´æ»î
title¡¢bannerÌáÈ¡¡¢Ö¸ÎÆÊ¶±ð
ÅÀ³æ¡¢Ä¿Â¼ÇáÁ¿É¨Ãè¡¢ÇáÁ¿Â©É¨
C¶ÎÐèÒª×öµÄÊ£º
ɨÃè¶Ë¿Ú£¬Ì½²â´æ»î
½«É¨µÄwebºÍ·Çweb¾ÙÐзÖÀ࣬°Ñɨµ½µÄweb×ʲú¼ÓÈëµ½ÓòÃûÐèÒª×öµÄÊ£¬ºÍ¿´´ýÓòÃûÃ»Çø±ð
½«É¨µ½µÄ·Çweb(Êý¾Ý¿â/Ô¶³ÌµÇ¼ÐÒé)¾ÙÐб¬ÆÆ£¬ºÃ±Èmysql±¬ÆÆ£¬rdp±¬ÆÆ
Ò»ÅúÓòÃûºÍÒ»ÅúC¶Î¾ÍÕâÑù×ö²î±ðµÄÊ£¬À´ÏÈ̽²âÊÇ·ñÓÐųÈõµÄµã£¬×îºó²ÅÊǻعéͨÀýweb£¬Ò»¸öÕ¾Ò»¸öÕ¾µÄȥ˺
һЩ¹¤¾ß£º
https://github.com/broken5/WebAliveScan web´æ»îÅжÏ
https://github.com/fadinglr/EHole ºì¶ÓÖØµã¹¥»÷ÏµÍ³Ö¸ÎÆÌ½²â¹¤¾ß
https://github.com/k8gege/K8CScan Îó²îɨÃè¡¢ÃÜÂë±¬ÆÆ
https://github.com/b1gcat/DarkEye Ö÷»ú·¢Ã÷+±¬ÆÆ
https://github.com/Adminisme/ServerScan ¸ß²¢·¢ÍøÂçɨÃè¡¢·þÎñ̽²â¹¤¾ß
https://github.com/dean2021/titlesearch ÅúÁ¿×¥È¡ÓòÃûtitle¹¤¾ß
https://github.com/pmiaowu/PmWebDirScan ÅúÁ¿É¨Ä¿Â¼±¸·Ý
ÉÐÓеľÍÊÇһЩ¸÷È˶¼ÊìÖªµÄxray£¬vulmapÖ®ÀàµÄÎó²î£¬ÅúÁ¿ÇáÁ¿È¥É¨Ãèһϼ´¿É¡£
°ÑÉÏÃæµÄ¼¸¸ö°ì·¨£¬¹¤¾ß´®ÆðÀ´£¬ÐгɿìËÙÐÅÏ¢ÍøÂ磬¿ìËÙ̽²â´òµã£¬×îºÃд¸ö¹á´®Á÷³ÌµÄ¹¤¾ßŲÓõľ籾£¬×Ô¼ºÐ´¹ýЧ¹û²»´íµ«´úÂëÇ·ºÃ¾Í²»ÄóöÀ´¶ªÈËÁË£¬»ù±¾ÕâÑù¹ýÒ»±é¾ÍÈÝÒ×´òµ½Ò»Ð©½ÏÁ¿Å³ÈõµÄµã¡£
ÔÎÄʼ·¢ÓÚ΢ÐŹ«Öںţ¨HACKÖ®µÀ£©
- Òªº¦´Ê±êÇ©£º
- BevictorΰµÂ ºì¶ÓÉøÍ¸ Íø°²¹¤¾ß