Infrastructure

Check List

Cheat Sheet

Search Engine

Sub Domains

site:$WEBSITE

HTTP Title

intitle:"login" |
intitle:"admin" |
intitle:"administrator"
site:$WEBSITE

URI

inurl:conf |
inurl:env |
inurl:cgi |
inurl:bin |
inurl:etc |
inurl:root |
inurl:sql |
inurl:backup |
inurl:admin |
inurl:php
site:$WEBSITE

File Types

filetype:pdf |
filetype:csv |
filetype:xls |
filetype:xlsx
site:$WEBSITE

Extensions

ext:log | 
ext:txt | 
ext:conf | 
ext:cnf | 
ext:ini | 
ext:env | 
ext:sh | 
ext:bak | 
ext:backup | 
ext:swp | 
ext:old | 
ext:~ | 
ext:git | 
ext:svn | 
ext:htpasswd | 
ext:htaccess | 
ext:json | 
ext:daf 
site:$WEBSITE

Exact Phrase

"choose file" site:$WEBSITE 

Cache

cache:"$WEBSITE"

Port

port:22

Country

country:"IR"

City

city:"Tehran"

Organization

org:"United States Department"

Product

product:"Apache"

Date

product:"apache" after:"22/02/2009" before:"14/3/2010"

Service

services.service_name: "HTTP"

Country

location.country: "Iran"

TLS Cipher

services.tls.certificate.parsed.subject.common_name: "$WEBSITE"

ASN

autonomous_system.asn: 15169

Banner

services.banner: "Apache"

Port

port:80

Application

app:"Apache"

Country

country:"Iran"

IP

ip:"$TARGET"

City

city:"Tehran"

OS

os:"Windows"

Useful Website

Whois

Whois

Revers Whois

DNS

IP Address

Domain Scan

Create New Graph

Get IP Address

DNS Records

Name Servers

Mail Servers

Whois Information

Emails Related to Domain

Subdomains

Phone Numbers

Run Recon-ng

recon-ng

List Commands

[recon-ng][default] > help

View All Modules

[recon-ng][default] > marketplace search

Install a Module

[recon-ng][default] > marketplace install recon/domains-contacts/hunter_io

Load a Module

[recon-ng][default] > modules load hunter_io

List Module Options

[recon-ng][default][hunter_io] > options list

Set Module Options

[recon-ng][default][hunter_io] > options set SOURCE $WEBSITE

Run Module

[recon-ng][default][hunter_io] > run

List API Keys

[recon-ng][default] > keys list

Add API Key

[recon-ng][default] > keys add hunter_io 9918b4ea[...]b46a73f071 

Remove API Key

[recon-ng][default] > keys remove hunter_io 

Metadata Extraction

metagoofil -d $WEBSITE -t pdf,xls,xlsx,csv -l 100 -n 7 -f ~/result.html

exiftool $FILE

Last updated