-
-
[原创]信息收集思路&工具分享
-
发表于: 2022-6-16 09:50 6958
-
信息收集
1. 企查查-爱企查-天眼查
获取公司及子公司信息
- 域名
- 小程序
- 微信公众号
- APP
- 微博
- 邮箱
- 生活号
1 2 3 4 5 | https: / / github.com / cqkenuo / appinfoscanner https: / / e69K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4q4U0j5#2)9J5k6h3y4G2L8b7`.`. / https: / / 39cK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4c8A6j5h3&6&6j5h3&6U0K9r3q4Q4x3X3g2U0L8$3@1`. / https: / / aiqicha.baidu.com / google.com \ baidu.com \ bing.cn |
2. 收集子域名
收集目标子域名信息
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 | https: / / x.threatbook.cn / https: / / github.com / shmilylty / OneForAll Layer子域名挖掘机 https: / / github.com / lijiejie / subDomainsBrute https: / / github.com / Jewel591 / SubDomainFinder https: / / github.com / aboul3la / Sublist3r https: / / github.com / knownsec / ksubdomain https: / / github.com / Threezh1 / JSFinder google.com \ baidu.com \ bing.cn http: / / tool.chinaz.com / dns https: / / 518K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3c8F1M7$3c8T1i4K6u0W2K9h3)9`. https: / / fofa.so / https: / / 596K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4A6G2L8$3#2W2P5h3g2Q4x3X3g2G2M7X3M7`. / https: / / 8d1K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4y4Z5L8$3c8S2L8W2)9J5k6h3W2G2 / https: / / censys.io / DNSenum nslookup https: / / 81fK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3W2K6j5#2)9J5k6h3!0J5k6H3`.`. / download / https: / / code.google.com / archive / p / dnsmap / https: / / github.com / 0x727 / ShuiZe_0x727 |
3. 域名指纹识别
对上面收集到的域名进行识别
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | https: / / github.com / EdgeSecurityTeam / EHole https: / / github.com / al0ne / Vxscan https: / / github.com / EASY233 / Finger https: / / github.com / TideSec / TideFinger https: / / github.com / urbanadventurer / WhatWeb https: / / gobies.org / https: / / ef0K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4W2#2L8Y4y4W2k6g2)9J5k6h3y4F1 / https: / / github.com / s7ckTeam / Glass https: / / github.com / TideSec / TideFinger https: / / scan.dyboy.cn / web / https: / / fp.shuziguanxing.com / #/ https: / / builtwith.com / zh / https: / / github.com / FortyNorthSecurity / EyeWitness https: / / e1dK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4W2#2L8Y4y4W2k6g2)9J5k6h3y4F1 / https: / / 3cfK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4N6S2M7s2m8S2L8s2W2*7k6i4u0Q4x3X3g2U0L8$3@1`. / https: / / github.com / 0x727 / ObserverWard https: / / github.com / 0x727 / ShuiZe_0x727 https: / / github.com / P1 - Team / AlliN https: / / github.com / dr0op / bufferfly |
4. IP收集、C段收集、端口
根据域名收集对应的IP
如果遇到CDN可以考虑以下方法:
查看dns解析记录
- 12345
https:
/
/
dnsdb.io
/
zh
-
cn
/
###DNS查询
https:
/
/
x.threatbook.cn
/
###微步在线
http:
/
/
toolbar.netcraft.com
/
site_report?url
=
###在线域名信息查询
http:
/
/
viewdns.info
/
###DNS、IP等查询
https:
/
/
tools.ipip.net
/
cdn.php
###CDN查询IP
[SecurityTrails](c26K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6K6k6h3y4#2M7X3W2@1P5i4c8J5j5h3W2D9M7#2)9J5k6h3y4G2L8g2)9J5c8W2)9J5z5b7`.`.
平台找子域名的IP
- 微步在线
bb8K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6V1L8Y4y4V1j5W2)9J5k6h3W2G2i4K6u0r3
xxxx.com.cn type:A
- 子域名扫描器
网络空间搜索引擎
- shodan
- fofa
- zoomeye
- 全球鹰
- quake
SSL证书
HTTP头
利用网站返回内容特征搜索
国外主机访问
网站漏洞
- phpinfo
- xss
- ssrf
邮件订阅(RSS)
zmap
F5 LTM
如果没有CDN就直接扫
1 2 3 4 5 6 | nmap masscan https: / / github.com / EdgeSecurityTeam / Eeyes https: / / github.com / shadow1ng / fscan https: / / github.com / Adminisme / ServerScan https: / / github.com / EdgeSecurityTeam / EHole |
5. 目录扫描
1 2 3 4 5 6 7 | https: / / github.com / maurosoria / dirsearch dirbuster gobuster dirb https: / / github.com / xmendez / wfuzz https: / / github.com / foryujian / yjdirscan https: / / github.com / H4ckForJob / dirmap |
6. 漏洞扫描
1 2 3 4 5 6 7 8 9 10 11 12 | nessus wavs https: / / github.com / H4ckForJob / dirmap https: / / github.com / chaitin / xray https: / / github.com / wgpsec / DBJ https: / / github.com / sullo / nikto https: / / github.com / zhzyker / vulmap / https: / / github.com / projectdiscovery / nuclei https: / / github.com / greenbone / openvas - scanner https: / / github.com / wpscanteam / wpscan http: / / 8fcK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3g2F1j5$3!0J5k6h3y4G2L8Y4y4#2L8s2c8A6L8X3N6Q4x3X3g2U0L8$3@1`. / 3 - 10 - AppScan.html https: / / github.com / 78778443 / QingScan |
7. 微信小程序信息收集
8. 微信公众号信息收集
9. 支付宝小程序信息收集
10. APP信息收集
- 733K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6U0M7h3E0W2L8Y4g2G2i4K6u0r3j5i4m8H3K9h3&6X3L8%4y4U0j5h3&6F1k6i4t1`.
1 2 | https: / / github.com / projectdiscovery / nuclei / blob / master / README_CN.md https: / / github.com / smicallef / spiderfoot |
11. 网站JS信息收集
1 2 3 4 | https: / / github.com / Threezh1 / JSFinder https: / / github.com / GerbenJavado / LinkFinder https: / / github.com / rtcatc / Packer - Fuzzer (webpack) https: / / github.com / momosecurity / FindSomething |
12. 其他信息收集
- 用户名
- 密码
- GitHub
- 网盘
- 钉钉
- 语雀
- 码云
- gitree
- 微信
- 邮箱
- 备份文件
- 知乎
- 贴吧
- 社工库
- 等
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课
赞赏
他的文章
赞赏
雪币:
留言: