
أداة بايثون سهلة الاستخدام لإجراء تعداد النطاقات الفرعية، والتعرف على نقاط النهاية، والمزيد.
الغرض من هذه الأداة هو مساعدة صائدي الثغرات ومختبرِي الاختراق أثناء عملية الاستطلاع...
يمكن استخدامها على أي نظام مثبت عليه بايثون 3
يمكنك تثبيت SR-71 بسهولة باستخدام pip:
pip3 install SR-71
لاستخدامها، ما عليك سوى كتابة "SR-71" في الطرفية
إذا كنت ترغب في تثبيتها من المصدر:
git clone https://gitlab.com/Edu0x01/SR-71.git
cd SR-71
pip3 install -r requirements.txt
SR-71 - All in One Recon Tool
options:
-h, --help show this help message and exit
-d DOMAIN, --domain DOMAIN domain to search its subdomains
-o OUTPUT, --output OUTPUT file to store the scan output
-t TOKEN, --token TOKEN api token of hunter.io to discover mail accounts and employees
-p, --portscan perform a fast and stealthy scan of the most common ports
-a, --axfr try a domain zone transfer attack
-m, --mail try to enumerate mail servers
-e, --extra look for extra dns information
-n, --nameservers try to enumerate the name servers
-i, --ip it reports the ip or ips of the domain
-6, --ipv6 enumerate the ipv6 of the domain
-w, --waf discover the WAF of the domain main page
-b, --backups discover common backups files in the web page
-s, --subtakeover check if any of the subdomains are vulnerable to Subdomain Takeover
-r, --repos try to discover valid repositories and s3 servers of the domain (still improving it)
-c, --check check active subdomains and store them into a file
--secrets crawl the web page to find secrets and api keys (e.g. Google Maps API Key)
--enum stealthily enumerate and identify common technologies
--whois perform a whois query to the domain
--wayback find useful information about the domain and his different endpoints using The Wayback Machine and other services
--all perform all the enumeration at once (best choice)
--quiet dont print the banner
--version display the script version
قائمة أمثلة لاستخدام الأداة بطرق مختلفة
python3 SR-71.py -d example.com
python3 SR-71.py -d example.com --output domains.txt
python3 SR-71.py -d example.com --quiet
python3 SR-71.py -d example.com -n -p -w -b --whois --enum # Você pode usar outros parâmetros, consulte o painel de ajuda
python3 SR-71.py -d domain.com --all
☑ تعداد النطاقات الفرعية باستخدام تقنيات سلبية (مثل "subfinder")
☑ الكثير من الاستعلامات الإضافية لتعداد DNS
☑ هجوم نقل المنطقة
☑ اكتشاف نوع جدار الحماية
☑ التعداد الشائع (أنظمة إدارة المحتوى، وكلاء عكسيون، جيكويري...)
☑ "Whois**" للنطاق المستهدف
☑ مدقق الاستيلاء على النطاق الفرعي
☑ التحقق من المنافذ المفتوحة الشائعة
☑ التحقق من النطاقات الفرعية النشطة (مثل "httprobe")
☑ دعم آلة Wayback لتعداد نقاط النهاية (مثل "waybackurls")
☑ جمع البريد الإلكتروني
تستخدم الأداة خدمات مختلفة للحصول على النطاقات الفرعية بطرق مختلفة
تم تعديل ومطابقة كاشف جدار الحماية من مفهوم CRLFSuite <3
جميع استعلامات DNS تستخدم dns-python بنسبة 100%، ولا حاجة لـ dig أو أي أدوات إضافية
يتم جمع البريد الإلكتروني باستخدام واجهة برمجة تطبيقات Hunter.io مع رمز مميز شخصي (تسجيل مجاني)
##إضافات
إذا وجدت هذا المشروع مفيدًا، سأكون ممتنًا جدًا لدعمك لي بإعطاء هذا المستودع نجمة أو شراء قهوة لي.
حقوق النشر © 2023، Edu0x01