CAT RELOADED
DIFFERENT METHODOLOGY
TO RECON TARGETS
~$Eslam Akl
2020
$~:whoami
eslam3kl
Penetration tester
CAT Reloaded Cyber Security member
Python script lover, Technical blogger and Vuln
machine attacker
$~:Agenda
Hunting & Penetration testing Steps.
Recon Types.
Before & After Recon.
Recon based on SCOPE.
Small Scope required information
Medium Scope required information
Large Scope required information
Recommended options.
Simple Methodology
Automation framework 3klcon v1.0
Practice on real target.
Juicy links and resources.
Hunting & Penetration testing Steps:
Recon / Information Gathering
Scanning
Vuln. Assessment
Post-Exploitation
Reporting
Recon Types:
1. Passive Recon
Collecting information about the target without any type
of interaction with it.
> Scan web application itself ! We don’t do that here D:
2. Active Recon
Scan the web application domain, subdomains,
acquisitions, servers, etc
> Actually, we do that here :)
Before Recon After Recon
Company name Subdomains
Available scope ASN&Acquisitions
User credentials Service info
to login (more Database info
Backend technology
than account)
used
Overview about the
Information
company business,
Exposure
works and logic
Interesting
Information from directories&
program page Endpoints
related to Juicy links which
security purposes may be vulnerable
More and more
Recon based SCOPE
Small Scope Target > domain or subdomain
Ex. [Link] / [Link] / [Link]
Medium Scope Target > list of subdomains
Ex. *.[Link]
Large Scope Target > All website related to the
company is in scope
Small Scope required information
! All processes here will be performed on specific subdomain
Directory enum. Waybackurls enum.
GitHub Dorking Parameter discovery
Server enum. Automation vulnerability
Database enum. scanning
Google dorking for JS file analysis
sensitive files Backend enum.
Extract juicy WAF detection
vulnerable links by GitHub search links
GF-Patterns Port scan
Medium Scope required information
! All processes here will be performed on all subdomains
List of subdomains Waybackurls enum.
Subdomains takeover Parameter discovery
Misconfiguration in Automation vulnerability
Storage vuln (S3 scanning
buckets) JS file analysis
Directory enum. Backend enum.
GitHub Dorking Search Engine
GitHub search links discovery(Shodan, Spyse,
Server enum. Censys, etc)
Google dorking for Port scan
sensitive files WAF detection
Database enum.
Large Scope required information
! All processes here will be performed on all targets
Seeds/Roots Waybackurls enum.
ASN to get IP ranges Parameter discovery
Acquisitions Automation vulnerability
DNS & SSL enum. scanning
List of subdomains JS file analysis
Subdomains takeover Backend enum.
Misconfiguration in Search Engine discovery
Storage vuln (S3 (Shodan, Spyse, Censys, etc)
buckets) Port scan
Directory enum. WAF detection
GitHub Dorking Database enum.
GitHub search links Server enum.
sensitive files Google dorking for
Simple Methodology
Recommended options
Don’t perform all this steps MANUALLY!
Automate it <3
Let your remote machine discover
vulnerabilities while sleeping. VPS machines
via Amazon or Google
Stay in touch with new tools and technologies
to update your framework! Update it every week
<3
Use bash or python to script any process which
may take much time like using regex to extract
special pattern of data
3klcon v2.0 Automation Recon framework
Link: [Link]
That’s enough !
Let’s
PRACTICE !!
Juicy references and resources.
GitHub Dorking
[Link]
sensitive-data-exposure/
Js analysis
[Link]
javascript-for-pen-testers-and-bug-bounty-hunters-f1cb1a5d5288
Just another recon methodology from jhaddix
Just another Recon Guide for Pentesters and Bug Bounty Hunters |
Offensity
Bug bounty hunting methodology v4.0 from jhaddix (Recommended)
[Link]
Active recon by using Nmap, Metasploit, etc
[Link]
recon-active-information-gathering-and-vulnerability-search/
Don’t forget !
Google
Is your friend <3
Thank you <3
Stay in Touch !
Medium Blog | GitHub | Twitter