Pentest Book
Search…
Public info gathering

Web resources

1
https://osintframework.com/
2
https://i-intelligence.eu/uploads/public-documents/OSINT_Handbook_2020.pdf
3
https://start.me/p/DPYPMz/the-ultimate-osint-collection
4
https://docs.google.com/spreadsheets/d/18rtqh8EG2q1xBo2cLNyhIDuK9jrPGwYr9DI2UncoqJQ
Copied!

OSINT websites

1
# Multipurpose
2
https://shodan.io/
3
https://app.netlas.io/
4
https://fullhunt.io/
5
https://www.zoomeye.org/
6
https://leakix.net/
7
https://www.yougetsignal.com/
8
https://intelx.io/
9
https://pentest-tools.com/
10
https://gofindwhois.com/
11
https://gofindwho.com/
12
13
# Analytics
14
https://publicwww.com/
15
https://intelx.io/tools?tab=analytics
16
https://dnslytics.com/reverse-analytics
17
https://builtwith.com/
18
19
# DNS Recon
20
https://domainbigdata.com/
21
https://viewdns.info/
22
http://bgp.he.net/
23
https://rapiddns.io/
24
https://dnsdumpster.com/
25
https://www.whoxy.com/
26
http://ipv4info.com/
27
28
# Mailserver blacklists
29
http://multirbl.valli.org/
30
31
# Dark web exposure
32
https://immuniweb.com/radar/
33
34
# New acquisitions
35
https://crunchbase.com/
36
37
# Email
38
https://hunter.io/
Copied!

Whois/Registrant Tools

1
# https://github.com/jpf/domain-profiler
2
./profile target.com
3
4
whois
5
6
# Whoxy api
7
#https://github.com/MilindPurswani/whoxyrm
8
#https://github.com/vysecurity/DomLink
Copied!

Dorks

Google

1
# Google Dorks Cli
2
# https://github.com/six2dez/degoogle_hunter
3
degoogle_hunter.sh company.com
4
5
# Google dorks helper
6
https://dorks.faisalahmed.me/
7
8
# Code share sites
9
site:http://ideone.com | site:http://codebeautify.org | site:http://codeshare.io | site:http://codepen.io | site:http://repl.it | site:http://jsfiddle.net "company"
10
# GitLab/GitHub/Bitbucket
11
site:github.com | site:gitlab.com | site:bitbucket.org "company"
12
# Stackoverflow
13
site:stackoverflow.com "target.com"
14
# Project management sites
15
site:http://trello.com | site:*.atlassian.net "company"
16
# Pastebin-like sites
17
site:http://justpaste.it | site:http://pastebin.com "company"
18
# Config files
19
site:target.com ext:xml | ext:conf | ext:cnf | ext:reg | ext:inf | ext:rdp | ext:cfg | ext:txt | ext:ora | ext:env | ext:ini
20
# Database files
21
site:target.com ext:sql | ext:dbf | ext:mdb
22
# Backup files
23
site:target.com ext:bkf | ext:bkp | ext:bak | ext:old | ext:backup
24
# .git folder
25
inurl:"/.git" target.com -github
26
# Exposed documents
27
site:target.com ext:doc | ext:docx | ext:odt | ext:pdf | ext:rtf | ext:sxw | ext:psw | ext:ppt | ext:pptx | ext:pps | ext:csv
28
# Other files
29
site:target.com intitle:index.of | ext:log | ext:php intitle:phpinfo "published by the PHP Group" | inurl:shell | inurl:backdoor | inurl:wso | inurl:cmd | shadow | passwd | boot.ini | inurl:backdoor | inurl:readme | inurl:license | inurl:install | inurl:setup | inurl:config | inurl:"/phpinfo.php" | inurl:".htaccess" | ext:swf
30
# SQL errors
31
site:target.com intext:"sql syntax near" | intext:"syntax error has occurred" | intext:"incorrect syntax near" | intext:"unexpected end of SQL command" | intext:"Warning: mysql_connect()" | intext:"Warning: mysql_query()" | intext:"Warning: pg_connect()"
32
# PHP errors
33
site:target.com "PHP Parse error" | "PHP Warning" | "PHP Error"
34
# Login pages
35
site:target.com inurl:signup | inurl:register | intitle:Signup
36
# Open redirects
37
site:target.com inurl:redir | inurl:url | inurl:redirect | inurl:return | inurl:src=http | inurl:r=http
38
# Apache Struts RCE
39
site:target.com ext:action | ext:struts | ext:do
40
# Search in pastebin
41
site:pastebin.com target.com
42
# Linkedin employees
43
site:linkedin.com employees target.com
44
# Wordpress files
45
site:target.com inurl:wp-content | inurl:wp-includes
46
# Subdomains
47
site:*.target.com
48
# Sub-subdomains
49
site:*.*.target.com
50
#Find S3 Buckets
51
site:.s3.amazonaws.com | site:http://storage.googleapis.com | site:http://amazonaws.com "target"
52
# Traefik
53
intitle:traefik inurl:8080/dashboard "target"
54
# Jenkins
55
intitle:"Dashboard [Jenkins]"
Copied!

GitHub

1
".mlab.com password"
2
"access_key"
3
"access_token"
4
"amazonaws"
5
"api.googlemaps AIza"
6
"api_key"
7
"api_secret"
8
"apidocs"
9
"apikey"
10
"apiSecret"
11
"app_key"
12
"app_secret"
13
"appkey"
14
"appkeysecret"
15
"application_key"
16
"appsecret"
17
"appspot"
18
"auth"
19
"auth_token"
20
"authorizationToken"
21
"aws_access"
22
"aws_access_key_id"
23
"aws_key"
24
"aws_secret"
25
"aws_token"
26
"AWSSecretKey"
27
"bashrc password"
28
"bucket_password"
29
"client_secret"
30
"cloudfront"
31
"codecov_token"
32
"config"
33
"conn.login"
34
"connectionstring"
35
"consumer_key"
36
"credentials"
37
"database_password"
38
"db_password"
39
"db_username"
40
"dbpasswd"
41
"dbpassword"
42
"dbuser"
43
"dot-files"
44
"dotfiles"
45
"encryption_key"
46
"fabricApiSecret"
47
"fb_secret"
48
"firebase"
49
"ftp"
50
"gh_token"
51
"github_key"
52
"github_token"
53
"gitlab"
54
"gmail_password"
55
"gmail_username"
56
"herokuapp"
57
"internal"
58
"irc_pass"
59
"JEKYLL_GITHUB_TOKEN"
60
"key"
61
"keyPassword"
62
"ldap_password"
63
"ldap_username"
64
"login"
65
"mailchimp"
66
"mailgun"
67
"master_key"
68
"mydotfiles"
69
"mysql"
70
"node_env"
71
"npmrc _auth"
72
"oauth_token"
73
"pass"
74
"passwd"
75
"password"
76
"passwords"
77
"pem private"
78
"preprod"
79
"private_key"
80
"prod"
81
"pwd"
82
"pwds"
83
"rds.amazonaws.com password"
84
"redis_password"
85
"root_password"
86
"secret"
87
"secret.password"
88
"secret_access_key"
89
"secret_key"
90
"secret_token"
91
"secrets"
92
"secure"
93
"security_credentials"
94
"send.keys"
95
"send_keys"
96
"sendkeys"
97
"SF_USERNAME salesforce"
98
"sf_username"
99
"site.com" FIREBASE_API_JSON=
100
"site.com" vim_settings.xml
101
"slack_api"
102
"slack_token"
103
"sql_password"
104
"ssh"
105
"ssh2_auth_password"
106
"sshpass"
107
"staging"
108
"stg"
109
"storePassword"
110
"stripe"
111
"swagger"
112
"testuser"
113
"token"
114
"x-api-key"
115
"xoxb "
116
"xoxp"
117
[WFClient] Password= extension:ica
118
access_key
119
bucket_password
120
dbpassword
121
dbuser
122
extension:avastlic "support.avast.com"
123
extension:bat
124
extension:cfg
125
extension:env
126
extension:exs
127
extension:ini
128
extension:json api.forecast.io
129
extension:json googleusercontent client_secret
130
extension:json mongolab.com
131
extension:pem
132
extension:pem private
133
extension:ppk
134
extension:ppk private
135
extension:properties
136
extension:sh
137
extension:sls
138
extension:sql
139
extension:sql mysql dump
140
extension:sql mysql dump password
141
extension:yaml mongolab.com
142
extension:zsh
143
filename:.bash_history
144
filename:.bash_history DOMAIN-NAME
145
filename:.bash_profile aws
146
filename:.bashrc mailchimp
147
filename:.bashrc password
148
filename:.cshrc
149
filename:.dockercfg auth
150
filename:.env DB_USERNAME NOT homestead
151
filename:.env MAIL_HOST=smtp.gmail.com
152
filename:.esmtprc password
153
filename:.ftpconfig
154
filename:.git-credentials
155
filename:.history
156
filename:.htpasswd
157
filename:.netrc password
158
filename:.npmrc _auth
159
filename:.pgpass
160
filename:.remote-sync.json
161
filename:.s3cfg
162
filename:.sh_history
163
filename:.tugboat NOT _tugboat
164
filename:_netrc password
165
filename:apikey
166
filename:bash
167
filename:bash_history
168
filename:bash_profile
169
filename:bashrc
170
filename:beanstalkd.yml
171
filename:CCCam.cfg
172
filename:composer.json
173
filename:config
174
filename:config irc_pass
175
filename:config.json auths
176
filename:config.php dbpasswd
177
filename:configuration.php JConfig password
178
filename:connections
179
filename:connections.xml
180
filename:constants
181
filename:credentials
182
filename:credentials aws_access_key_id
183
filename:cshrc
184
filename:database
185
filename:dbeaver-data-sources.xml
186
filename:deployment-config.json
187
filename:dhcpd.conf
188
filename:dockercfg
189
filename:environment
190
filename:express.conf
191
filename:express.conf path:.openshift
192
filename:filezilla.xml
193
filename:filezilla.xml Pass
194
filename:git-credentials
195
filename:gitconfig
196
filename:global
197
filename:history
198
filename:htpasswd
199
filename:hub oauth_token
200
filename:id_dsa
201
filename:id_rsa
202
filename:id_rsa or filename:id_dsa
203
filename:idea14.key
204
filename:known_hosts
205
filename:logins.json
206
filename:makefile
207
filename:master.key path:config
208
filename:netrc
209
filename:npmrc
210
filename:pass
211
filename:passwd path:etc
212
filename:pgpass
213
filename:prod.exs
214
filename:prod.exs NOT prod.secret.exs
215
filename:prod.secret.exs
216
filename:proftpdpasswd
217
filename:recentservers.xml
218
filename:recentservers.xml Pass
219
filename:robomongo.json
220
filename:s3cfg
221
filename:secrets.yml password
222
filename:server.cfg
223
filename:server.cfg rcon password
224
filename:settings
225
filename:settings.py SECRET_KEY
226
filename:sftp-config.json
227
filename:sftp-config.json password
228
filename:sftp.json path:.vscode
229
filename:shadow
230
filename:shadow path:etc
231
filename:spec
232
filename:sshd_config
233
filename:token
234
filename:tugboat
235
filename:ventrilo_srv.ini
236
filename:WebServers.xml
237
filename:wp-config
238
filename:wp-config.php
239
filename:zhrc
240
HEROKU_API_KEY language:json
241
HEROKU_API_KEY language:shell
242
HOMEBREW_GITHUB_API_TOKEN language:shell
243
jsforce extension:js conn.login
244
language:yaml -filename:travis
245
msg nickserv identify filename:config
246
org:Target "AWS_ACCESS_KEY_ID"
247
org:Target "list_aws_accounts"
248
org:Target "aws_access_key"
249
org:Target "aws_secret_key"
250
org:Target "bucket_name"
251
org:Target "S3_ACCESS_KEY_ID"
252
org:Target "S3_BUCKET"
253
org:Target "S3_ENDPOINT"
254
org:Target "S3_SECRET_ACCESS_KEY"
255
password
256
path:sites databases password
257
private -language:java
258
PT_TOKEN language:bash
259
redis_password
260
root_password
261
secret_access_key
262
SECRET_KEY_BASE=
263
shodan_api_key language:python
264
WORDPRESS_DB_PASSWORD=
265
xoxp OR xoxb OR xoxa
266
s3.yml
267
.exs
268
beanstalkd.yml
269
deploy.rake
270
.sls
Copied!

Shodan

1
port:"9200" elastic
2
product:"docker"
3
product:"kubernetes"
4
hostname:"target.com"
5
host:"10.10.10.10"
6
# Spring boot servers, look for /env or /heapdump
7
org:YOUR_TAGET http.favicon.hash:116323821
Copied!

ASN/CIDR Tools

1
# https://github.com/nitefood/asn
2
asn -n 8.8.8.8
3
4
# https://github.com/j3ssie/metabigor
5
echo "company" | metabigor net --org
6
echo "ASN1111" | metabigor net --asn
7
8
# https://github.com/yassineaboukir/Asnlookup
9
python asnlookup.py -m -o <Organization>
10
11
# https://github.com/harleo/asnip
12
asnip -t domain.com -p
13
14
# https://github.com/projectdiscovery/mapcidr
15
echo 10.10.10.0/24 | mapcidr
16
17
# https://github.com/eslam3kl/3klector
18
python 3klector.py -t company
19
20
# https://github.com/SpiderLabs/HostHunter
21
python3 hosthunter.py targets.txt
Copied!

General / AIO

Amass

1
# Get ASN and do amass intel
2
# Get ASN
3
amass intel -org "whatever"
4
# Reverse whois
5
amass intel -active -asn NUMBER -whois -d domain.com
6
# SSL Cert Grabbing
7
amass enum -active -d example.com -cidr IF.YOU.GOT.THIS/24 -asn NUMBER
Copied!

Spiderfoot

1
spiderfoot -s domain.com
Copied!

theHarvester

1
# theHarvester
2
theHarvester -d domain.com -b all
Copied!

recon-ng

1
recon-ng
Copied!

URLs & IPs

waybackurls / gau / shorteners

1
# https://github.com/lc/gau
2
gau example.com
3
4
# https://github.com/utkusen/urlhunter
5
urlhunter -keywords keywords.txt -date latest
6
7
# https://github.com/tomnomnom/waybackurls
8
go get github.com/tomnomnom/waybackurls
9
10
# Wayback machine dorks
11
https://web.archive.org/web/*/website.com/*
12
13
https://gist.githubusercontent.com/mhmdiaa/adf6bff70142e5091792841d4b372050/raw/56366e6f58f98a1788dfec31c68f77b04513519d/waybackurls.py
14
https://gist.githubusercontent.com/mhmdiaa/2742c5e147d49a804b408bfed3d32d07/raw/5dd007667a5b5400521761df931098220c387551/waybackrobots.py
Copied!

favicon tools

1
# https://github.com/devanshbatham/FavFreak
2
cat urls.txt | python3 favfreak.py
3
# https://github.com/pielco11/fav-up
4
favUp.py -k SHODANKEY -w website.com
Copied!

Rapid 7 Sonar DNS database

1
# https://opendata.rapid7.com/sonar.fdns_v2/
2
# https://github.com/cgboal/sonarsearch
3
4
go get -u github.com/cgboal/sonarsearch/crobat
5
crobat -s site.com
Copied!

Creds leaks

pymeta - metadata analyzer

1
# https://github.com/m8r0wn/pymeta
2
pymeta -d example.com
Copied!

pwndb - leaked creds (tor enabled)

1
# https://github.com/davidtavarez/pwndb
2
python3 pwndb.py --target [email protected]
Copied!

Websites

1
https://hunter.io/
2
https://link-base.org/index.php
3
http://xjypo5vzgmo7jca6b322dnqbsdnp3amd24ybx26x5nxbusccjkm4pwid.onion/
4
http://pwndb2am4tzkvold.onion
5
https://weleakinfo.to/
6
https://www.dehashed.com/search?query=
7
https://haveibeenpwned.com
8
https://breachchecker.com
9
https://vigilante.pw/
10
https://leak.sx/
11
https://intelx.io
12
https://breachdirectory.org/
Copied!

Email tools

1
# https://github.com/SimplySecurity/SimplyEmail
2
./SimplyEmail.py
3
4
pip3 install mailspoof
5
sudo mailspoof -d domain.com
6
7
# Test email spoof
8
https://emkei.cz/
9
10
# https://github.com/sham00n/buster
11
12
13
# https://github.com/m4ll0k/Infoga
14
python infoga.py
15
16
# https://github.com/martinvigo/email2phonenumber
17
python email2phonenumber.py scrape -e [email protected]
18
19
# https://github.com/jkakavas/creepy/
Copied!

GIT tools

1
# https://github.com/obheda12/GitDorker
2
python3 GitDorker.py -tf TOKENSFILE -q tesla.com -d dorks/DORKFILE -o target
3
4
# https://github.com/dxa4481/truffleHog
5
trufflehog https://github.com/Plazmaz/leaky-repo
6
trufflehog --regex --entropy=False https://github.com/Plazmaz/leaky-repo
7
8
# https://github.com/eth0izzle/shhgit
9
shhgit --search-query AWS_ACCESS_KEY_ID=AKIA
10
11
# https://github.com/d1vious/git-wild-hunt
12
python git-wild-hunt.py -s "extension:json filename:creds language:JSON"
13
14
# https://shhgit.darkport.co.uk/
15
16
# GitLab (API token required)
17
# https://github.com/codeEmitter/token-hunter
18
./token-hunter.py -g 123456
Copied!

Social Media

1
# Twitter
2
# https://github.com/twintproject/twint
3
twint -u username
4
5
# Google account
6
# https://github.com/mxrch/ghunt
7
python hunt.py [email protected]
8
9
# Instagram
10
# https://github.com/th3unkn0n/osi.ig
11
python3 main.py -u username
12
13
# Websites
14
emailrep.io # Accounts registered by email
15
tinfoleak.com # Twitter
16
mostwantedhf.info # Skype
17
searchmy.bio # Instagram
18
search.carrot2.org # Results grouped by topic
19
boardreader.com # forums
20
searchcode.com # search by code in repositories
21
swisscows.com # semantic search engine
22
publicwww.com # search by source page code
23
psbdmp.ws # search in pastebin
24
kribrum.io # social-media search engine
25
whatsmyname.app
Copied!
Last modified 16d ago