FavFreak: arrow-up-right Weaponizing favicon.ico for BugBounties , OSINT and what not.
Copy $ git clone https://github.com/devanshbatham/FavFreak
$ cd FavFreak
$ virtualenv -p python3 env
$ source env/bin/activate
$ python3 -m pip install mmh3
$ cat urls.txt | python3 favfreak.py
Copy $ cat urls.txt | python3 favfreak.py -o output http.favicon.hash:[Favicon hash here]
Copy $ shodan search org:"Target" http.favicon.hash:116323821 --fields ip_str,port --separator " " | awk '{print $1":"$2}' Reference: https://medium.com/@Asm0d3us/weaponizing-favicon-ico-for-bugbounties-osint-and-what-not-ace3c214e139arrow-up-right
Goohak arrow-up-right : Automatically launch google hacking queries against a target domain to find vulnerabilities and enumerate a target.
Smap arrow-up-right : passive Nmap like scanner built with shodan.io.
urlhunter arrow-up-right : urlhunter is a recon tool that allows searching on URLs that are exposed via shortener services such as bit.ly and goo.gl. The project is written in Go.
//grep.app arrow-up-right : Search across a half million git repos.
domain-check-2 arrow-up-right : Domain Expiration Check Shell Script Forked and Maintained by nixCraft.
dns-domain-expiration-checker arrow-up-right : Send notifications when DNS domains are about to expire.
sigurlfind3r is a passive reconnaissance tool, it fetches known URLs from AlienVault's OTX arrow-up-right , Common Crawl arrow-up-right , URLScan arrow-up-right , Github arrow-up-right and the Wayback Machine arrow-up-right .
sherlock arrow-up-right : Hunt down social media accounts by username across social networks.
TheHarvester arrow-up-right : E-mails, subdomains and names Harvester - OSINT.
Usernamesearch arrow-up-right (web) : Uncover social media profiles and real people behind a username.
IntelX arrow-up-right (web): Discovering everything.
Spiderfoot arrow-up-right : SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Creepy arrow-up-right : A geolocation OSINT tool. Offers geolocation information gathering through social networking platforms.
Twint arrow-up-right : An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations.
Reddit Analyzer arrow-up-right : Reddit data correlation.
Googleadvcs arrow-up-right : Google advance search.
Telegram OSINT arrow-up-right : Resources about Telegram OSINT.
Reverse email search arrow-up-right : Email Lookup tool.
Reverse phone searh: arrow-up-right Phone Lookup tool.
Holehe OSINT arrow-up-right : Email to Registered Accounts.
Thephonebook arrow-up-right : Phone numbers.
Hinter.io: arrow-up-right Find email addreesses in secounds.
411.com arrow-up-right : Find Contact Information on yourself or anyone else.
Fonefinder arrow-up-right : Fone Finder query form.
BuiltWith arrow-up-right : BuiltWith is a website profiling tool that shows current and historical information about a website's technology usage, technology versions, and hosting.
ReNgine arrow-up-right : reNgine is an automated reconnaissance framework used for OSINT gathering that streamlines the recon process.
Mac Address Lookup arrow-up-right : Find MAC vendors.
> Truepeoplesearcharrow-up-right
> Thatsthemarrow-up-right
> Whitepagesarrow-up-right
> Spokeoarrow-up-right
> Idcrawlarrow-up-right
> Zabasearcharrow-up-right
> Inteliusarrow-up-right
> Lullararrow-up-right
> Piplarrow-up-right
> Peekyouarrow-up-right
> Familytreenowarrow-up-right
> Beenverifiedarrow-up-right
> Peoplefinderarrow-up-right
> Unicourtarrow-up-right
> Jailbasearrow-up-right
> Publicrecordsdirarrow-up-right
Images And Videos
> Exifdataarrow-up-right
> Pimeyesarrow-up-right
> Tineyearrow-up-right
> Youtube Metadataarrow-up-right
megagoofil arrow-up-right : Scan for documents from a domain (-d kali.org) that are PDF files (-t pdf), searching 100 results (-l 100), download 25 files (-n 25), saving the downloads to a directory (-o kalipdf), and saving the output to a file (-f kalipdf.html).
> Maltegoarrow-up-right
> Recon-ngarrow-up-right
> Theharvesterarrow-up-right
> Archive.orgarrow-up-right
> Archive.isarrow-up-right
> Archivedwebarrow-up-right
> Arquivo.ptarrow-up-right