
Encore un autre moniteur de sous-domaines.
Certains disent que le bug bounty ne consiste pas seulement à trouver des bugs, mais à être le "premier" à les trouver. Je construis cet outil pour avertir les chasseurs lorsque de nouveaux sous-domaines apparaissent.

scan ou planifier un scan.
cd backend# install tools
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest
go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest
# add GOPATH/bin to PATH
export PATH=$PATH:$(go env GOPATH)/bin
# save the above command to `~/.bashrc`
source ~/.bashrc # or ~/.zshrc
# optional env vars for backend
export DB_NAME="database.db"
export DISCORD_WEBHOOK_URL="YOUR-DISCORD-WEBHOOK"
# create a virtual env
python -m venv venv
source venv/bin/activate
pip install -r requirements.txt
# run fastapi service
python -m app.main
# run worker in a new terminal
python -m app.services.worker
# check Swagger doc
http://localhost:8000/docs
# check ReDoc
http://localhost:8000/redoc
cd frontend# run frontend
npm i
npm install node
npm run dev
Depuis la racine du projet :
# optional: create env file and set Discord webhook for alerts
cp .env.example .env
# then edit .env and set DISCORD_WEBHOOK_URL
# build and start frontend + backend + worker
docker compose up --build -d
Ouvrez :
http://localhost:5173http://localhost:8000/docs# stop services
docker compose down
flowchart TD
U[User / Frontend] -->|Scan Target| A[FastAPI Backend]
U -->|Schedule Scan| A
A -->|Create or update ScanRun = queued| DB[(SQLite)]
W[Worker Loop] -->|Poll queued jobs + enqueue due schedules| DB
W -->|Pick next queued ScanRun| S[Scanner Pipeline]
S --> SF[subfinder]
SF --> DX[dnsx]
DX --> HX[httpx]
HX --> D[Diff with existing subdomains]
D -->|Insert new subdomain| DB
D -->|Mark missing subdomain| DB
D -->|Send new findings| DIS[Discord Webhook]
S -->|success / failed| W
W -->|Update ScanRun status| DB
ScanRun (queued, running, success, failed).subfinder -> dnsx -> httpx, compare les résultats, met à jour la base de données et envoie des alertes Discord pour les nouveaux sous-domaines.