Sign in to follow this
Followers
0
-
Similar Content
-
By itsMe
Hidden Content
Give reaction to this post to see the hidden content.
Hidden Content
Give reaction to this post to see the hidden content. What can i do with this?
with this software, you will be able to search your dorks in supported search engines and scan grabbed urls to find their vulnerabilities. in addition , you will be able to generate dorks, scan urls and saerch dorks separately when ever you want
Supported search engines
Google
Yahoo
Bing
Supported vulnerabilities
SQL Injection
XSS
LFI
Whats new in version 2 (most important updates)?
adding custom payloads
you can edit payloads.json file which will be created when you open and close software once, and add payloads as much as you want , easier than drinking water
adding custom error checks
once a payload injected in url, software will looks for errors in new website source, you can also customize those errors too. what you have to do is easily edit payloadserror.json file which will be created when you open and close software once. you can also use regexes as error , with REIT|your regex here format
multy vulnerability check
in old version, you were not able to choose more than 1 vulnerabilites to check, but in v2, you can do this easily.
multy search engine grabber
in old version, you were not able to choose more than 1 saerchengines to saerch in, but in v2, you can do this easily.
memory management
we`ve added memory management to avoid lack of memory in your system
dork generator
you can generate dorks and save them very fast with your custom configurations and keywords. valid configuration format should contain {DORK} that will be replaced with each keyword in dork generation process
updates list (all)
new threading system based on microsoft task
using linq technology
dork generator part
ability to add regexes as payloads error
low usage
moving from WPF to Windows form (just because my designes are bad, contact me if you can do better)
ability to use scanner-graber separately and simultaneously
and ....
Hidden Content
Give reaction to this post to see the hidden content. -
By itsMe
Hidden Content
Give reaction to this post to see the hidden content. This is a modern platform for sharing media content, an analogue of social networks such as twitter, instagram.
Hidden Content
Give reaction to this post to see the hidden content.
Hidden Content
Give reaction to this post to see the hidden content. -
By itsMe
Hidden Content
Give reaction to this post to see the hidden content. Summary
This is a simple script intended to perform a full recon on an objective with multiple subdomains
Features
Tools checker
Google Dorks (based on deggogle_hunter)
Subdomain enumeration (passive, resolution, bruteforce and permutations)
Sub TKO (subjack and nuclei)
Web Prober (httpx)
Web screenshot (aquatone)
Template scanner (nuclei)
Port Scanner (naabu)
Url extraction (waybackurls, gau, hakrawler, github-endpoints)
Pattern Search (gf and gf-patterns)
Param discovery (paramspider and arjun)
XSS (Gxss and dalfox)
Open redirect (Openredirex)
SSRF checks (from m4ll0k/Bug-Bounty-Toolz/SSRF.py)
Github Check (git-hound)
Favicon Real IP (fav-up)
JS Checks (LinkFinder, SecretFinder, scripts from JSFScan)
Fuzzing (ffuf)
Cors (Corsy)
SSL Check (testssl)
Interlace integration
Custom output folder (default under Recon/target.com/)
Run standalone steps (subdomains, subtko, web, gdorks...)
Polished installer compatible with most distros
Verbose mode
Update tools script
Hidden Content
Give reaction to this post to see the hidden content. -
By itsMe
Hidden Content
Give reaction to this post to see the hidden content. WhatWeb identifies websites. Its goal is to answer the question, “What is that Website?”. It recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 1700 plugins, each to recognize something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more.
WhatWeb can be stealthy and fast, or thorough but slow. WhatWeb supports an aggression level to control the tradeoff between speed and reliability. When you visit a website in your browser, the transaction includes many hints of what web technologies are powering that website. Sometimes a single webpage visit contains enough information to identify a website but when it does not, WhatWeb can interrogate the website further. The default level of aggression, called ‘stealthy’, is the fastest and requires only one HTTP request of a website. This is suitable for scanning public websites. More aggressive modes were developed for use in penetration tests.
Most WhatWeb plugins are thorough and recognize a range of cues from subtle to obvious. For example, most WordPress websites can be identified by the meta HTML tag, e.g. ‘<meta name=”generator” content=”WordPress 2.6.5″>’, but a minority of WordPress websites remove this identifying tag but this does not thwart WhatWeb. The WordPress WhatWeb plugin has over 15 tests, which include checking the favicon, default installation files, login pages, and checking for “/wp-content/” within relative links.
Features:
Over 1800 plugins
Control the trade-off between speed/stealth and reliability
Performance Tuning. Control how many websites to scan concurrently.
Multiple log formats: Brief (greppable), Verbose (human readable), XML, JSON, MagicTree, RubyObject, MongoDB, ElasticSearch, SQL.
Proxy support including TOR
Custom HTTP headers
Basic HTTP authentication
Control over webpage redirection
IP address ranges
Fuzzy matching
Result certainty awareness
Custom plugins defined on the command line
IDN (International Domain Name) support
Changelog v.0.5.5
FIXES
#358 Fixed escape_for_sql method (@juananpe)
NEW PLUGINS
Apache Flink (@juananpe)
Dell-OpenManage-Switch-Administrator (@themaxdavitt)
FLIR AX8 (@urbanadventurer)
Huginn (@urbanadventurer)
OpenResty (@urbanadventurer)
Telerik UI (@definity)
Umbraco (@definity / @ChadBrigance
VMware Horizon (@themaxdavitt)
PLUGIN UPDATES
Joomla (@juananpe)
phpMyAdmin (@juananpe)
Microsoft IIS (@themaxdavitt)
Hidden Content
Give reaction to this post to see the hidden content. -
By itsMe
Hidden Content
Give reaction to this post to see the hidden content. Start your own website like OnlyFans.com or Patreon.com and grow like mad. It’s like a social network but allows content creators to directly earn MONEY from their FANS for their PREMIUM content.
Hidden Content
Give reaction to this post to see the hidden content.
Hidden Content
Give reaction to this post to see the hidden content.
-