Skip to content

Latest commit

 

History

History
60 lines (59 loc) · 1.67 KB

readme.md

File metadata and controls

60 lines (59 loc) · 1.67 KB
  1. Checking Whois Info
  2. View DNS Info Using ViewDNS
  3. Tech Stack Fingerprinting
    • Using WhatRun
    • Using Wappalyzer
    • Using WhatWeb
  4. Google & GitHub Dorks
    • Githound
    • Gitdorks_go
  5. Shodan Search and Look for Past Vulnerability Research
  6. Pastebin and .Git Secrets
  7. Finding Subdomains
    • Using Amass
    • Using Assetfinder
  8. Bruteforce Subdomains
    • Using FFUF
    • Using Your Secret Wordlist ;)
  9. Checking Cert Validity and More Subdomains
    • Using crt.sh
  10. Check for Subdomain Takeovers
    • Using Httpx
    • Using Subzy
    • Using a Nuclei Template
  11. Enumerating Live Subdomains Using Httpx
  12. Check for Cloud Assets Using Cloudenum
  13. Identify Web Server, Technologies, and Database
    • Using Httpx
    • Try to Locate:
      • /robots.txt
      • /crossdomain.xml
      • /clientaccesspolicy.xml
      • /sitemap.xml
      • /.well-known/
  14. Review Comments on Source Code
    • Using Burp Engagement Tools
  15. Filter Interesting Subdomains
    • If a Lot of Live Subdomains
    • Using gf
  16. Directory Bruteforcing All of Them
  17. Take Screenshot
    • Using Aquatone
    • Using Eyewitness
  18. Identify WAF (Web Application Firewall)
    • Using Wafw00f
  19. Crawl
    • Using Arjun
    • Using Waybackurls
    • Using Hakcrawler
  20. Get All JS Files
    • Using Subjs
    • Using XnLinkFinder
  21. Broken Link Hijacking (BLC)
  22. Run Automated Scanner
    • Using Nuclei
  23. Test CORS (Cross-Origin Resource Sharing)
    • Using CORScanner
    • Using Corsy
  24. Start Hunting 😄

This formatting should make the text more organized and easier to read.