forked from imran-parray/Web-Sec-CheatSheet
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathEnumeration
78 lines (54 loc) · 1.18 KB
/
Enumeration
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
Crossdomain.xml
Nmap ‘*’
httprint
clustered [ clusterd -i 127.0.0.1 -o linux –fingerprint ]
nikto
-->Run a Spider<--
==================
inputScanner
============
>Change Burp to Scope only
>Spider the Host
>Copy All the Links
>Paste in /opt/lampp/htdocs/InputScanner/url.txt
>open http://127.0.0.1/InputScanner/
>Done !
>Copy output-js.txt from Output folder
>Paste it into ../htdocs/Jscanner/
>Visit http://127.0.0.1/Jscanner/
Subdomains
==========
https://virustotal.com
https://dnsdumpster.com/
subdomain Bruteforce
-sublist3r
-knockpy
-aquatone
-massdns
Takeover Check
-Manually
-sub6.py
-aquatone -takeover
-EyeWitness
Github
======
using github
trufflehog http://www.github.com/invis/jshjsd.git
“badoo.com” API_key
“badoo.com” secret_key
“badoo.com” aws_key
“badoo.com” Password
“badoo.com” FTP
“badoo.com” login
“badoo.com” github_token
"badoo.com" password
"badoo.com" dev
"api.badoo.com"
http methods [curl -vX TRACE "https://gratipay.com"]
use head on restricted areas
Amazon S3 Buckets
=================
amazon s3 buckets. [ ruby lazys3.rb badoo ]
amazon s3 buckets
site:amazonaws.com -s3 badoo
site:amazonaws.com inurl:badoo