😀Reconnaissance
"Hackers make the mistake of paying attention to the exploitation process, and neglecting the information gathering stage “
💭 Whoami :
🛫 Plan
Most hackers, when they set a specific target, do not know where to start! So, let me explain my path in the reconnaissance process ..
I am seeking to obtain the following:
1) AS Number :
1) theHarvester
b) Amass
2) CIDR :
a) whois
2- BGP
3) Network Sweeping :
Are all hosts down IP really host down? Or the firewall plays a malicious role?
4- Subdomain Enumeration
(a) Subfinder
• Navigate to the following directory

(b) Amass
(c) Assetfinder
(d) GetAllUrls [GAU]
(e) SubEnum
(f) theHarvester

(j) Favicon
h) https://CRT.sh
5) Filter Alive Hosts - Info - CName
a) Httpx
(5) Js Files - Directory - Parameters - Robot.txt
(a) Yes, it's (gau) ..
(b) Js Scanner
(c) GoSpider
(d) Find all JS File
e) Katana
6- Emails
Now we have the following:

II) Brute-Force & Fuzzing
1) Subdomain Brute Force
a) PureDNS
2) Directory Fuzzing
a) httprobe
2) FuFF
3) Parameter Fuzzing
a) Fuff
b) Parampampam
c) arjun
4) VHost Fuzzing
a) GoBuster
b) VHostScan
5) Resolve IPs to Domains
a) HostHunter
b) nmap
6) Resolve Domains to IPs
III ) Dorks & Secrets & Leaks , Open Source Code
1)Credintials Leaks
2) Dorks
a) GitHub Dorking With [GitRob]
b) Google Dorking
I ) GooFuzz
II ) DorkGen
III ) Pentest-Tool
Shodan Dorks
City:
Country:
Geo:
Location
Hostname:
Net:
Organization
Autonomous System Number (ASN)
OS:
Port:
Before/after:
SSL/TLS Certificates
Device Type
Operating System
Product
Customer Premises Equipment (CPE)
Server
ssh fingerprints
Web
Pulse Secure
PEM Certificates
Databases
MySQL
MongoDB
elastic
Memcached
CouchDB
PostgreSQL
Riak
Redis
Cassandra
Industrial Control Systems
Samsung Electronic Billboards
Gas Station Pump Controllers
Fuel Pumps connected to internet:
Automatic License Plate Readers
Traffic Light Controllers / Red Light Cameras
Voting Machines in the United States
Open ATM:
Telcos Running Cisco Lawful Intercept Wiretaps
Prison Pay Phones
Tesla PowerPack Charging Status
Electric Vehicle Chargers
Maritime Satellites
Submarine Mission Control Dashboards
CAREL PlantVisor Refrigeration Units
Nordex Wind Turbine Farms
C4 Max Commercial Vehicle GPS Trackers
DICOM Medical X-Ray Machines
GaugeTech Electricity Meters
Siemens Industrial Automation
Siemens HVAC Controllers
Door / Lock Access Controllers
Railroad Management
Tesla Powerpack charging Status:
XZERES Wind Turbine
PIPS Automated License Plate Reader
Modbus
Niagara Fox
GE-SRTP
MELSEC-Q
CODESYS
S7
BACnet
HART-IP
Omron FINS
IEC 60870-5-104
DNP3
EtherNet/IP
PCWorx
Crimson v3.0
ProConOS
Remote Desktop
Unprotected VNC
Windows RDP
Network Infrastructure
Hacked routers:
Redis open instances
Citrix:
Weave Scope Dashboards
MongoDB
Mongo Express Web GUI
Jenkins CI
Jenkins:
Docker APIs
Docker Private Registries
Pi-hole Open DNS Servers
Already Logged-In as root via Telnet
Telnet Access:
Polycom video-conference system no-auth shell
NPort serial-to-eth / MoCA devices without password
Android Root Bridges
Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords
Citrix Virtual Apps
Cisco Smart Install
PBX IP Phone Gateways
Polycom Video Conferencing
Telnet Configuration:
Bomgar Help Desk Portal
Intel Active Management CVE-2017-5689
HP iLO 4 CVE-2017-12542
Lantronix ethernet adapter’s admin interface without password
Wifi Passwords:
Misconfigured Wordpress Sites:
Outlook Web Access:
Exchange 2007
Exchange 2010
Exchange 2013 / 2016
Lync / Skype for Business
Network Attached Storage (NAS)
SMB (Samba) File Shares
Specifically domain controllers:
Concerning default network shares of QuickBooks files:
FTP Servers with Anonymous Login
Iomega / LenovoEMC NAS Drives
Buffalo TeraStation NAS Drives
Logitech Media Servers
Plex Media Servers
Tautulli / PlexPy Dashboards
Home router attached USB
Webcams
D-Link webcams
Hipcam
Yawcams
webcamXP/webcam7
Android IP Webcam Server
Security DVRs
Surveillance Cams:
Printers & Copiers:
HP Printers
Xerox Copiers/Printer
Epson Printer
Canon Printers
Home Devices
Yamaha Stereos
Apple AirPlay Receivers
Chromecasts / Smart TVs
Crestron Smart Home Controllers
Random Stuff
OctoPrint 3D Printer Controllers
Etherium Miner
Apache Directory Listings
Misconfigured WordPress
Too Many Minecraft Servers
Literally Everything in North Korea
Finally Don’t forget OSINT tools :
Last updated