
Uma ferramenta Python fácil de usar para realizar enumeração de subdomínios, reconhecimento de endpoints e mais
O objetivo desta ferramenta é ajudar caçadores de bugs e pentesters durante o reconhecimento...
Pode ser usado em qualquer sistema com python3
Você pode instalar facilmente o SR-71 usando pip:
pip3 install SR-71
Para usá-lo, basta digitar "SR-71" no seu terminal
Se quiser instalar a partir do código fonte:
git clone https://gitlab.com/Edu0x01/SR-71.git
cd SR-71
pip3 install -r requirements.txt
SR-71 - All in One Recon Tool
options:
-h, --help show this help message and exit
-d DOMAIN, --domain DOMAIN domain to search its subdomains
-o OUTPUT, --output OUTPUT file to store the scan output
-t TOKEN, --token TOKEN api token of hunter.io to discover mail accounts and employees
-p, --portscan perform a fast and stealthy scan of the most common ports
-a, --axfr try a domain zone transfer attack
-m, --mail try to enumerate mail servers
-e, --extra look for extra dns information
-n, --nameservers try to enumerate the name servers
-i, --ip it reports the ip or ips of the domain
-6, --ipv6 enumerate the ipv6 of the domain
-w, --waf discover the WAF of the domain main page
-b, --backups discover common backups files in the web page
-s, --subtakeover check if any of the subdomains are vulnerable to Subdomain Takeover
-r, --repos try to discover valid repositories and s3 servers of the domain (still improving it)
-c, --check check active subdomains and store them into a file
--secrets crawl the web page to find secrets and api keys (e.g. Google Maps API Key)
--enum stealthily enumerate and identify common technologies
--whois perform a whois query to the domain
--wayback find useful information about the domain and his different endpoints using The Wayback Machine and other services
--all perform all the enumeration at once (best choice)
--quiet dont print the banner
--version display the script version
Uma lista de exemplos para usar a ferramenta de diferentes maneiras
python3 SR-71.py -d example.com
python3 SR-71.py -d example.com --output domains.txt
python3 SR-71.py -d example.com --quiet
python3 SR-71.py -d example.com -n -p -w -b --whois --enum # Você pode usar outros parâmetros, consulte o painel de ajuda
python3 SR-71.py -d domain.com --all
☑ Enumeração de subdomínios usando técnicas passivas (como "subfinder")
☑ Muitas consultas extras para enumerar DNS
☑ Ataque de Transferência de Zona de Domínio
☑ Detecção de tipo de WAF
☑ Enumeração comum (CMSs, proxies reversos, jquery...)
☑ Domínio alvo "Whois"
☑ Verificador de Aquisição de Subdomínio
☑ Verificar portas abertas comuns
☑ Verifica subdomínios ativos (como "httprobe")
☑ Suporte à Wayback Machine para enumerar endpoints (como "waybackurls")
☑ Coleta de E-mails
A ferramenta usa diferentes serviços para obter subdomínios de diferentes maneiras
O detector de WAF foi modificado e adaptado a partir do conceito CRLFSuite <3
Todas as consultas DNS usam dns-python 100%, sem necessidade de digging ou qualquer ferramenta extra
As funções de coleta de e-mail são feitas usando a API Hunter.io com token pessoal (registro gratuito)
##Extra
Se você achar este projeto útil, eu realmente agradeceria seu apoio dando uma estrela neste repositório ou comprando um café para mim.
Copyright © 2023, Edu0x01