Coder Social home page Coder Social logo

Suggestions !! about finalrecon HOT 16 OPEN

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024
Suggestions !!

from finalrecon.

Comments (16)

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024 1

@attacker34 facebook developer api added, update to v1.0.4, you will see a new directory : conf inside it you will see keys.json add your auth token there and test :)

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024 1

https://github.com/thewhiteh4t/FinalRecon#configuration

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024 1

@attacker34 Wayback machine integrated in crawler and directory search module, pulls data from last 1 year, please update to v1.0.6

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024 1

Sure, I will test fprobe and analyse the ouput quality

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024 1

@chestervdb this is a nice tool, currently finalrecon only looks for urls in javascripts, api keys etc would be really nice, i dont intend to add another tool in finalrecon but i can definitely implement it 👍

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024

Great! I will try and implement these in next update, my goal for APIs was to include ones which don't need an auth key, I can add others which require keys if they really add value to the tool

from finalrecon.

attacker34 avatar attacker34 commented on May 30, 2024

Hi @thewhiteh4t Agree with you ... Yes, these services will surely add more value to this amazing tool, adding more results... You can ask the user to add "API Keys" instead of giving it your own API Keys (as findomain or other tools are doing). This Will surely become best ever Tool with these Enhancements.

One more thing to add here.. ffuf is amazing tool.. You can just feed the subdomains list to it against word list for Directory Bruteforcing.

Thanks again !!

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024

Yes that's a better way to implement it, please compare my implementation of directory searching with fuff, what is missing in my implementation? Also is fuff better than gobuster and lulzbuster?

from finalrecon.

attacker34 avatar attacker34 commented on May 30, 2024

Hi @thewhiteh4t I am only suggesting ffuf due to its multiple features which you can see on their documentation & its specially good when we wanna directory bruteforce "list of domains"..
On other hand, gobuster & lulzbuster can't work well with list of domains i think and they also not have multiple options to be tested against.

Sincerely,

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024

Alright, thanks a lot, I will look into it and will do some testing too!

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024

@attacker34 do you have pro api of spyse?
with free version we cannot get more than 100 results,

{"error":{"code":"validation_error","message":"validation error","errors":[{"code":"max","location":"limit","message":"limit must be 100 or less"}]}}

if you have pro api, can you tell me how many subdomain results you are getting for google.com

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024

We are already getting a lot of subdomains from free sources and facebook api unlike spyse

from finalrecon.

attacker34 avatar attacker34 commented on May 30, 2024

Hi @thewhiteh4t that's great... Now, In order to get more Good results you can attach it with "fprobe" for displaying only alive links..

https://github.com/theblackturtle/fprobe

With ./waybackurls we get a ton of data which can include dead links.

./waybackurls example.com > output.txt | ./fprobe -c 200

from finalrecon.

thewhiteh4t avatar thewhiteh4t commented on May 30, 2024

@attacker34 thanks! That will be very useful and it's easy to implement without even using fprobe or any other tool, will update soon

from finalrecon.

attacker34 avatar attacker34 commented on May 30, 2024

Hi @thewhiteh4t Great.. But try to display the Content size of Response...

from finalrecon.

chestervdb avatar chestervdb commented on May 30, 2024

Is it possible to include a secret finder (e,g, https://github.com/m4ll0k/SecretFinder) in the tool?

from finalrecon.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.