oopso
An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines.
Version: 1.0
Features
- Multi-engine support: Automatically translates fingerprints into native query syntax for Shodan, FOFA, ZoomEye, and Censys
- Extensive coverage: Built-in signatures for 24 different web file managers (Tiny File Manager, elFinder, phpMyAdmin, etc.)
- Dual target modes: Hunt for instances with missing authentication (Exposed mode) or pinpoint login portals (Login mode)
- Language-agnostic: Relies on structural fingerprints (HTML IDs, CSS classes) instead of language-dependent text to ensure highly accurate detection
- Granular filtering: Narrow down your reconnaissance by specific countries or custom ports (Shodan only)
- Client-side only: 100% static HTML, CSS, and vanilla JavaScript. Runs entirely in your browser with zero dependencies
How It Works
- Select search engines: Choose one or more supported platforms (Shodan, FOFA, ZoomEye, Censys).
- Pick a file manager: Select the specific web-based file manager you want to hunt for.
- Choose a mode: Decide if you want to find exposed instances (no auth) or login pages.
- Apply filters (optional): Set a country code or specify target ports.
- Generate queries: Click the button and oopso instantly builds multiple query variants tailored for each selected engine.
- Execute search: Use the "Open ↗" button to launch the search in a new tab, or copy the raw query string for automated tools.
Live Demo
Try oopso directly in your browser:
https://b3rito.github.io/oopso/
Disclaimer
This tool is intended for educational, defensive, and authorized research purposes only. The generated queries should only be used to identify and map attack surfaces on infrastructure you own, manage, or have explicit permission to test (e.g., authorized penetration tests or bug bounty programs).
Author
Written by b3rito at mes3hacklab