Web Enumeration
Recon, fuzzing and crawling
Recon
nmap -p 80,443,8000,8080,8180,8888,1000 --open -oA web_discovery -iL scope_listSSL / TLS
HTTP/2 - DoS
HTTP Downgrading
HTTP Methods
HTTP Verb TamperingApache Vulnerability Testing
Scan for credz
Header Exploit
Common files

Cloudflare
Real IP adress
Internal IP leakage
sitemap.xml
SQL InjectionMisconfigurations on popular third-party services

Git Exposed
Credentials in git reposGitHub - finding vulnerabilitiesSVN Expoxed
PHPMyAdmin
AdminDirectoryFinder
WSAAR
OWASP Noir
URLScan.io
Information GatheringPostman

WaybackLister
Wayback Machine
Information GatheringJWTxplorer
Backup Files
Fuzzili
Burp Extension
Archived Backups
Extract URLs and paths from web pages
Manually


Carridi
Gourlex
xnLinkFinder
Hakrawler
Waybackurls
Katana & Urlfinder
GetAllURL - gau
LinkFinder
GoLinkFinder
LazyEgg
ReconSpider
BadSecrets - Cookies
Name
Description
Secrets in Response
Metadata
Metadata and Hidden infosJS Files
Sensitive JS Files
Burp




JSFScan.sh
Morgan
Gouge - Burp extension to extract URLs which are seen in JS files
GetJS
JSHunter
Javascript Deobfuscator
API Endpoint - Burp History

API Endpoint in JS File
JSNinja
JS Link Finder
Jsluice
APISensitive data in JS Files

JS Miner - Burp Extension
X-Keys - Burp Extension
jsluice++ - Burp Extension

SecretFinder
JS-Snitch
Mantra
Testing API Key
Google Maps API Key
Algolia API Key
Hidden Parameter

Parameters fuzzing
Burp - Param Miner



Burp - GAP
x8
Arjun
Parmahunter
Wordlists
Fuzz using different HTTP methods
Admin interfaces
Backups
Config files
SQL files
Vulnerability Assessment
Vulnerability ScannersPort ScanLostfuzzer
Admin interface
Password listsCMS
CMSCrawling
Crawl with 2 separate user-agent

Gospider
Hakrawler
With Burp
With Zap


Fuzz
FuzzingAdmin interface=> Password guessing
Banner grabbing
Information GatheringDNS Subdomain Enumeration
DNS Subdomain EnumerationCloudflare Bypass for Web Scraping
Interesting Books
Interesting BooksSupport this Gitbook
Last updated
