バグバウンティとは、バグを見つけることだけでなく、それを「最初に」見つけることだと言われることもあります。このツールは、新しいサブドメインが出現したときにハンターに通知するために開発しています。

scan をクリックするか、スキャンを schedule(予約)できます。
cd backend# install tools
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest
go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest
# add GOPATH/bin to PATH
export PATH=$PATH:$(go env GOPATH)/bin
# save the above command to `~/.bashrc`
source ~/.bashrc # or ~/.zshrc
# optional env vars for backend
export DB_NAME="database.db"
export DISCORD_WEBHOOK_URL="YOUR-DISCORD-WEBHOOK"
# create a virtual env
python -m venv venv
source venv/bin/activate
pip install -r requirements.txt
# run fastapi service
python -m app.main
# run worker in a new terminal
python -m app.services.worker
# check Swagger doc
http://localhost:8000/docs
# check ReDoc
http://localhost:8000/redoc
cd frontend# run frontend
npm i
npm install node
npm run dev
プロジェクトルートから:
# optional: create env file and set Discord webhook for alerts
cp .env.example .env
# then edit .env and set DISCORD_WEBHOOK_URL
# build and start frontend + backend + worker
docker compose up --build -d
開く:
http://localhost:5173http://localhost:8000/docs# stop services
docker compose down
flowchart TD
U[User / Frontend] -->|Scan Target| A[FastAPI Backend]
U -->|Schedule Scan| A
A -->|Create or update ScanRun = queued| DB[(SQLite)]
W[Worker Loop] -->|Poll queued jobs + enqueue due schedules| DB
W -->|Pick next queued ScanRun| S[Scanner Pipeline]
S --> SF[subfinder]
SF --> DX[dnsx]
DX --> HX[httpx]
HX --> D[Diff with existing subdomains]
D -->|Insert new subdomain| DB
D -->|Mark missing subdomain| DB
D -->|Send new findings| DIS[Discord Webhook]
S -->|success / failed| W
W -->|Update ScanRun status| DB
ScanRun の状態(queued、running、success、failed)をストアに保存します。subfinder -> dnsx -> httpx を実行し、結果を差分比較して DB を更新し、新しいサブドメインがあれば Discord アラートを送信します。