Code Monkey home page Code Monkey logo

ph-recon's Introduction

PH-RECON

Bug Bounty Automation Recon Scirpt

Requirements:

Below are all the tools that must be installed so install these https://github.com/mrco24/OK-VPS tools first and your terminal must be rooted otherwise it may be a problem to install the tools and script in add your Resolver path

Installation:

Usage:

  • ./PH-Recon.sh sub.txt

Current Features:

  • This script will collect all the subdomains using amass, assetfinder, subfinder, findomain, and crt.sh, riddler.io, jldc.me, nmap.bufferover.run
  • Gather all the subdomains and put them in a single .txt file.
  • Resolves all the subdomains using massdns
  • Check http/https services on the given domains using httpx tool.
  • All Active Subdomain Screenshot
  • This script will collect all the urls using Waybackurl, Gau, gospider, ParamSpider, hakrawler.
  • Gather all the urls and put them in a single .txt file.
  • This script will Able to sort all the good Urals by filtering.
  • FFUF is used in this script to find valid urls.
  • Gf tool and its patterns installation and also will set their path automatically.
  • It will check for the Following Vulnerablities:
  • Subdomain takeover
  • Http-Request-Smugglingr
  • Open_Port_Find
  • CloudFlare_Checker
  • Nuclei scan All Active Subdomain
  • Advance XSS Scanner
  • Sqli Scan All urls
  • LFI Scan All urls
  • Open Redirect Scan All urls
  • Fuzzing mass Subdomain
  • Fuzzing All Urls Endpoint

TOOLS Used:

Subdomain

  • Subfinder
  • Amass
  • Assetfinder
  • findomain
  • crt.sh
  • riddler.io
  • bufferover.run
  • jldc.me

Subdomain-Resolver

  • httprobe

Subdomain-takeover

  • Nuclei

Http-Request-Smugglingr

  • Smuggle

Open_Port_Find

  • Naabu

Web-screenshot

  • Gowitness

CloudFlare_Checker

  • Cf-Chack

Vulnerability Scan All Subdomain

  • Nuclei

Urls-find

  • Gospider
  • Hakrawler
  • ParamSpider
  • gau
  • waybackurls
  • paramspider

Url_endpoints

  • Using Bash Script

Gf-patterns

  • sqli
  • xss
  • lfi
  • Open Redirect
  • csrf
  • Etc

Sql-injection

  • sqlmap
  • nuclei

XSS

  • dalfox
  • kxss
  • Gxss

Bilnd_xss

LFI

  • Nuclei

Open Redirect

  • nuclei

Fuzzing mass Subdomain

  • content discovery

Fuzzing All Urls Endpoint

  • content discovery

Author:

ph-recon's People

Contributors

mrco24 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.