
또 하나의 서브도메인 모니터.
어떤 사람들은 버그 바운티가 단지 버그를 찾는 것이 아니라 '가장 먼저' 찾는 것이라고 말합니다. 저는 사냥꾼들이 새로운 서브도메인이 나타날 때 알림을 받을 수 있도록 이 도구를 만들고 있습니다.

scan을 클릭하거나 스캔을 schedule할 수 있습니다.
cd backend# install tools
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest
go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest
# add GOPATH/bin to PATH
export PATH=$PATH:$(go env GOPATH)/bin
# save the above command to `~/.bashrc`
source ~/.bashrc # or ~/.zshrc
# optional env vars for backend
export DB_NAME="database.db"
export DISCORD_WEBHOOK_URL="YOUR-DISCORD-WEBHOOK"
# create a virtual env
python -m venv venv
source venv/bin/activate
pip install -r requirements.txt
# run fastapi service
python -m app.main
# run worker in a new terminal
python -m app.services.worker
# check Swagger doc
http://localhost:8000/docs
# check ReDoc
http://localhost:8000/redoc
cd frontend# run frontend
npm i
npm install node
npm run dev
프로젝트 루트에서:
# optional: create env file and set Discord webhook for alerts
cp .env.example .env
# then edit .env and set DISCORD_WEBHOOK_URL
# build and start frontend + backend + worker
docker compose up --build -d
열기:
http://localhost:5173http://localhost:8000/docs# stop services
docker compose down
flowchart TD
U[User / Frontend] -->|Scan Target| A[FastAPI Backend]
U -->|Schedule Scan| A
A -->|Create or update ScanRun = queued| DB[(SQLite)]
W[Worker Loop] -->|Poll queued jobs + enqueue due schedules| DB
W -->|Pick next queued ScanRun| S[Scanner Pipeline]
S --> SF[subfinder]
SF --> DX[dnsx]
DX --> HX[httpx]
HX --> D[Diff with existing subdomains]
D -->|Insert new subdomain| DB
D -->|Mark missing subdomain| DB
D -->|Send new findings| DIS[Discord Webhook]
S -->|success / failed| W
W -->|Update ScanRun status| DB
ScanRun에 상태를 저장합니다 (queued, running, success, failed).subfinder -> dnsx -> httpx를 실행하고, 결과를 비교하며, 데이터베이스를 업데이트하고, 새로운 서브도메인에 대한 Discord 알림을 보냅니다.