01 Recon02 Vulnerabilidades03 Recursos
Recon
Enumeración pasiva
- Certificate transparency: cada cert SSL es registro público (crt.sh).
- Subfinder pasivo + assetfinder, merge y dedup.
copiar✕
# cert transparency
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | anew crtsh.txt
subfinder -d target.com -all -silent > subs_sf.txt
assetfinder --subs-only target.com > subs_af.txt
cat subs_*.txt | sort -u > all_subs.txt
Enumeración activa
- Bruteforce DNS + permutación (puredns).
- Monitoreo de cert transparency en vivo (gungnir).
- Hosts vivos + enriquecimiento (httpx) y screenshots (gowitness).
- Puertos + servicios (naabu).
- Escaneo automatizado por templates (nuclei).
copiar✕
# puredns
puredns bruteforce $DNS_WORDLIST target.com -r resolvers.txt -o subs_pd.txt
# gungnir
gungnir -d target.com
copiar✕
cat all_subs.txt | httpx -silent -status-code -title -tech-detect -web-server -follow-redirects -o alive.txt
# screenshot para ver visualmente
gowitness file -f alive.txt -P ./shots/
copiar✕
naabu -list alive.txt -p - -rate 1000 -c 50 -nmap-cli 'nmap -sV -sC' -o ports.txt
copiar✕
nuclei -l alive.txt -t nuclei-templates/http/ -severity critical,high,medium -rl 30 -o nuclei.txt
nuclei -l alive.txt -t nuclei-templates/http/exposures/
JavaScript & Secretos
- URLs históricas + crawling (gau, waybackurls, katana).
- Categorizar URLs por clase de bug (grep).
- Parámetros y endpoints ocultos (linkfinder, arjun).
- Secretos / API keys en JS (mantra, trufflehog).
copiar✕
cat alive.txt | gau --threads 200 > urls_gau.txt
cat alive.txt | waybackurls > urls_wb.txt
# katana: JS crawler
katana -u alive.txt -jc -kf all -d 5 -headless -silent > urls_kat.txt
cat urls_*.txt | anew all_urls.txt
copiar✕
grep -iE '.js(?|$)' all_urls.txt > js_urls.txt
grep -Ei "login|signin|auth|oauth|reset" all_urls.txt > auth.txt
grep -Ei '[0-9]{2,}' all_urls.txt > idor_candidates.txt
grep -Ei "redirect|callback|goto|return|url=" all_urls.txt > openredir.txt
copiar✕
# linkfinder: endpoints dentro del JS
python3 linkfinder.py -i https://target.com/app.js -o cli
# arjun: parámetros GET/POST no documentados
arjun -u "https://target.com/api" -m GET --stable
copiar✕
# mantra: scanner de secretos en JS
cat js_urls.txt | mantra
# trufflehog: solo secretos verificados
trufflehog github --org=target --token=$GITHUB_TOKEN --only-verified
Enumeración de endpoints de API
- Fuzz de rutas API con wordlist específica.
- Probar versiones/prefijos: /api/v2, /api/internal, /api/beta.
copiar✕
ffuf -u https://api.target.com/FUZZ -w apiroutes.txt -mc 200,201,204,301,302,401,403 -ac -t 40
Fuzzing general
- Fuzzing de directorios.
- Fuzzing por extensión de archivo.
- Fuzzing de VHOST / subdominios por Host header.
copiar✕
# directorios
ffuf -w /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u https://target.com/FUZZ
# por extensión
ffuf -w /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u https://target.com/FUZZ.js
copiar✕
# subdominios por Host header
ffuf -u https://target.com -H "Host: FUZZ.target.com" -w /usr/share/wordlists/subdomains.txt -t 100 -fc 403 | tee ffuf_subs.txt
Vulnerabilidades en APIs
- IDOR: Objeto de otro usuario accesible cambiando un ID.
- Mass assignment: mandás campos que el server no esperaba.
- Broken auth: endpoints que no revalidan sesión/permiso.
- Excessive data exposure: el endpoint devuelve más de lo que la UI muestra.
Configuraciones y headers
- Headers de seguridad: CSP, HSTS, X-Frame-Options, X-Content-Type.
- Archivos viejos/backup sin referencia (.bak, .old, .zip, .DS_Store).
- Métodos HTTP habilitados (PUT, DELETE, TRACE).
- Host Header Injection: Host, X-Forwarded-Host, X-Forwarded-For, X-HTTP-Host-Override.
copiar✕
nuclei -u https://target.com -t nuclei-templates/http/misconfiguration/ -t nuclei-templates/http/exposures/
curl -sk -i -X OPTIONS https://target.com | grep -i "allow|^x-|content-security"
Autenticación
- Enum de usuarios (error o timing distinto en login/reset).
- Bypass de auth, logins default.
- Flujo de reset: token predecible/reusable, host header en el link.
- MFA: bypass por response manipulation, sin rate-limit en el OTP.
Sesión & CSRF
- Flags de cookie: httpOnly, Secure, SameSite; scope (path/domain).
- Token nuevo al login y al cambiar de rol; invalidación real al logout.
- Fixation, session puzzling, sesiones simultáneas.
- CSRF en acciones sensibles (sin token o SameSite=None sin validar).
copiar✕
# aleatoriedad de tokens
curl -sk -I https://target.com | grep -i set-cookie
Autorización
- Endpoints con ID (numérico o UUID): cambialo entre dos cuentas tuyas.
- Escalada vertical (user -> admin) y horizontal (user -> otro user).
- Path traversal, forced browsing a rutas admin, falta de authz.
- Intentá acciones/permisos que suelen ser solo de admin.
Inyecciones
- XXE (XML con DOCTYPE externo), NoSQL ([$ne]=), XPath.
- Open Redirect, HTTP Request Smuggling, HTTP Verb Tampering.
- HTTP Parameter Pollution, client-side vs server-side.
- XSS
- SQL Injection
- Local File Inclusion
- Server-Side Request Forgery
- Command Injection
- Server-Side Template Injection
copiar✕
# dalfox
cat params.txt | dalfox pipe -o xss.txt
dalfox url "https://target.com/?q=test"
copiar✕
# sqlmap: SQL Injection
sqlmap -u "https://target.com/item?id=1" --batch --random-agent --dbs
sqlmap -r request.txt --batch --level 3 --risk 2
# SSRF: metadata cloud
https://target.com/fetch?url=http://169.254.169.254/latest/meta-data/