- 目录
- 1. 序章
- 2. 计算机网络与协议
- 3. 信息收集
- 4. 常见漏洞攻防
- 5. 语言与框架
- 6. 内网渗透
- 7. 云安全
- 8. 防御技术
- 9. 认证机制
- 10. 工具与资源
- 11. 手册速查
- 12. 其他
文章来源于网络收集而来,版权归原创者所有,如有侵权请及时联系!
10.3. 信息收集
10.3. 信息收集
10.3.1. Whois
10.3.2. 网站备案
10.3.3. CDN查询
10.3.4. 子域爆破
- Amass In-depth Attack Surface Mapping and Asset Discovery
- subDomainsBrute
- wydomain
- broDomain
- ESD
- aiodnsbrute
- OneForAll
- subfinder
- altdns Generates permutations, alterations and mutations of subdomains and then resolves them
10.3.5. 域名获取
- the art of subdomain enumeration
- sslScrape
- aquatone A Tool for Domain Flyovers
- teemo A Domain Name & Email Address Collection Tool
- DNS DB 历史记录
10.3.6. 弱密码爆破
10.3.7. Git信息泄漏
- GitHack By lijiejie
- GitHack By BugScan
- GitTools
- Zen
- dig github history
- gitrob Reconnaissance tool for GitHub organizations
- git secrets
- shhgit Find GitHub secrets in real time
- GitHound GitHound pinpoints exposed API keys on GitHub using pattern matching, commit history searching, and a unique result scoring system. A batch-catching, pattern-matching, patch-attacking secret snatcher
- x patrol Github leaked patrol
- GitDorker scrape secrets from GitHub through usage of a large repository of dorks
10.3.8. Github监控
- Github Monitor Github Sensitive Information Leakage Monitor
- Github Dorks
- GSIL
- Hawkeye
- gshark
- GitGot
- gitGraber monitor GitHub to search and find sensitive data in real time for different online services
10.3.9. 路径及文件扫描
10.3.10. 路径爬虫
- crawlergo A powerful dynamic crawler for web vulnerability scanners
10.3.11. 指纹识别
- Wappalyzer
- whatweb
- Wordpress Finger Print
- CMS指纹识别
- JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way
- TideFinger
- JARM active Transport Layer Security (TLS) server fingerprinting tool
- fingerprintjs Browser fingerprinting library with the highest accuracy and stability
10.3.12. Waf指纹
10.3.13. 端口扫描
- nmap
- zmap
- masscan
- ShodanHat
- lzr LZR quickly detects and fingerprints unexpected services running on unexpected ports
- ZGrab2 Fast Go Application Scanner
- RustScan The Modern Port Scanner
- DNS
dnsenum nslookup dig fierce
- SNMP
snmpwalk
10.3.14. DNS数据查询
10.3.15. DNS关联
10.3.16. 云服务
10.3.17. 数据查询
10.3.18. Password
- Probable Wordlists Wordlists sorted by probability originally created for password generation and testing
- Common User Passwords Profiler
- chrome password grabber
- DefaultCreds cheat sheet One place for all the default credentials to assist the pentesters during an engagement
- SuperWordlist
10.3.19. CI信息泄露
- secretz minimizing the large attack surface of Travis CI
10.3.20. 个人数据画像
- GHunt Investigate Google Accounts with emails
10.3.21. 邮箱收集
10.3.22. 其他
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论