
bbot v3.0.1
ํด์ปค๋ฅผ ์ํ ์ฌ๊ท์ ์ธํฐ๋ท ์ค์บ๋. ๐งก
BEEยทbot์ Spiderfoot์์ ์๊ฐ์ ๋ฐ์ ๋ค๋ชฉ์ ์ค์บ๋๋ก, Recon(๋ฆฌ์ฝ), Bug Bounties(๋ฒ๊ทธ ๋ฐ์ดํฐ), ASM์ ์๋ํํ๋๋ก ์ ์๋์์ต๋๋ค!
https://github.com/blacklanternsecurity/bbot/assets/20261699/e539e89b-92ea-46fa-b893-9cde94eebf81
VivaGraphJS๋ก ์๊ฐํํ ์ค์๊ฐ BBOT ์ค์บ
์ค์น
# stable version
pipx install bbot
# bleeding edge (dev branch)
pipx install --pip-args '\--pre' bbot
Docker๋ฅผ ํฌํจํ ๋ ๋ง์ ์ค์น ๋ฐฉ๋ฒ์ Getting Started๋ฅผ ์ฐธ์กฐํ์ธ์
2.x์์ ์ ๊ทธ๋ ์ด๋ํ์๋์? BBOT 3.0์๋ CLI, ํ๋ฆฌ์ , ๋ชจ๋, ์ด๋ฒคํธ ๋ฐ Python API์ ๋ํ ์ฃผ์ ๋ณ๊ฒฝ ์ฌํญ์ด ํฌํจ๋์ด ์์ต๋๋ค. ์ ๊ทธ๋ ์ด๋ ์ ์ 2.x โ 3.0 ๋ง์ด๊ทธ๋ ์ด์ ๊ฐ์ด๋(์์ค)๋ฅผ ํ์ธํ์ธ์.
์๋ ํ: BBOT์ DNS ๋ฆฌ์กธ๋ฒ(blastdns)๋
/etc/resolv.conf์ ๋ฆฌ์กธ๋ฒ๋ง๋ค ์ฌ๋ฌ ์ค๋ ๋๋ฅผ ์์ฑํฉ๋๋ค. ํํฐ๋ง๋์ง ์์ ๋ฆฌ์กธ๋ฒ๋ฅผ ๋ ์ถ๊ฐํ๋ฉด ์ค์บ ์๋๊ฐ ํฌ๊ฒ ๋นจ๋ผ์ง๋๋ค. ์์ธํ ๋ด์ฉ์ ์ํ resolv.conf์ ํ๊ณผ ์๋ น์ ์ฐธ์กฐํ์ธ์.
์์ ๋ช ๋ น์ด
1) ์๋ธ๋๋ฉ์ธ ํ์ธ๋
ํจ์๋ธ API ์์ค์ ํ๊ฒ๋ณ ์๋ธ๋๋ฉ์ธ ๋ณํ์ ์ด์ฉํ ์ฌ๊ท์ DNS ๋ฌด์ฐจ๋ณ ๋์ (brute-force).
# find subdomains of evilcorp.com
bbot -t evilcorp.com -p subdomain-enum
# passive sources only
bbot -t evilcorp.com -p subdomain-enum -rf passive
subdomain-enum.yml
description: Enumerate subdomains via APIs, brute-force
flags:
# enable every module with the subdomain-enum flag
- subdomain-enum
output_modules:
# output unique subdomains to TXT file
- subdomains
config:
dns:
threads: 25
brute_threads: 1000
# put your API keys here
# modules:
# github:
# api_key: ""
# chaos:
# api_key: ""
# securitytrails:
# api_key: ""
BBOT์ ๋ค๋ฅธ ๋๊ตฌ๋ณด๋ค ์ง์์ ์ผ๋ก 20-50% ๋ ๋ง์ ์๋ธ๋๋ฉ์ธ์ ์ฐพ์๋ ๋๋ค. ๋๋ฉ์ธ์ด ํด์๋ก ๊ทธ ์ฐจ์ด๋ ๋ ์ปค์ง๋๋ค. ์ด๊ฒ์ด ์ด๋ป๊ฒ ๊ฐ๋ฅํ์ง ์์๋ณด๋ ค๋ฉด ์๋ ๋ฐฉ์์ ์ฐธ์กฐํ์ธ์.

2) ์น ์คํ์ด๋
# crawl evilcorp.com, extracting emails and other goodies
bbot -t evilcorp.com -p spider
spider.yml
description: Recursive web spider
modules:
- http
blacklist:
# Prevent spider from invalidating sessions by logging out
- "RE:/.*(sign|log)[_-]?out"
config:
web:
# how many links to follow in a row
spider_distance: 2
# don't follow links whose directory depth is higher than 4
spider_depth: 4
# maximum number of links to follow per page
spider_links_per_page: 25
3) ์ด๋ฉ์ผ ์์ง๊ธฐ
# quick email enum with free APIs + scraping
bbot -t evilcorp.com -p email-enum
# pair with subdomain enum + web spider for maximum yield
bbot -t evilcorp.com -p email-enum subdomain-enum spider
email-enum.yml
description: Enumerate email addresses from APIs, web crawling, etc.
flags:
- email-enum
output_modules:
- emails
4) ์น ์ค์บ๋
# run a light web scan against www.evilcorp.com
bbot -t www.evilcorp.com -p web
# run a heavy web scan against www.evilcorp.com
bbot -t www.evilcorp.com -p web-heavy
web.yml
description: Quick web scan
include:
- iis-shortnames
flags:
- web
web-heavy.yml
description: Aggressive web scan
include:
# include the web preset
- web
flags:
- web-heavy
5) ๋ชจ๋ ๊ฒ์ ํ๊บผ๋ฒ์
# everything everywhere all at once
bbot -t evilcorp.com -p kitchen-sink
# roughly equivalent to:
bbot -t evilcorp.com -p subdomain-enum cloud-enum code-enum email-enum spider web paramminer webbrute web-screenshots
kitchen-sink.yml
description: Everything everywhere all at once
include:
- subdomain-enum
- cloud-enum
- code-enum
- email-enum
- spider
- web
- paramminer
- webbrute
- web-screenshots
- baddns-heavy
config:
modules:
dnsbrute:
recursive_mutations: true
dnscommonsrv:
recursive_mutations: true
webbrute:
avoid_wafs: False
wayback:
urls: True
parameters: True
archive: True
์๋ ๋ฐฉ์
์๋ ๊ทธ๋ํ๋ฅผ ํด๋ฆญํ์ฌ BBOT์ ๋ด๋ถ ๋์ ๋ฐฉ์์ ์ดํด๋ณด์ธ์.

