Некоторые способы поиска админ-панелей компании

Tomcat

Professional
Messages
1,516
Reputation
5
Reaction score
246
Points
63
1. Используя Google дорки:

Code:
site:target.com inurl:admin | administrator | adm | login | l0gin | wp-login

intitle:"login" "admin" site:target.com

intitle:"index of /admin" site:target.com

inurl:admin intitle:admin intext:admin

2. Используя httpx (https://github.com/projectdiscovery/httpx) и список слов (https://github.com/emadshanab/admin-login/blob/main/admin-login.txt):

Code:
httpx -l hosts.txt -paths /root/admin-login.txt -threads 100 -random-agent -x GET,POST  -tech-detect -status-code -follow-redirects -title -content-length

httpx -l hosts.txt-ports 80,443,8009,8080,8081,8090,8180,8443 -paths /root/admin-login.txt -threads 100 -random-agent -x GET,POST -tech-detect -status-code -follow-redirects -title -content-length

3. Используя утилиты:


4. Используя поисковые системы:

Shodan (https://www.shodan.io/):

Code:
ssl.cert.subject.cn:"company.com" http.title:"admin"

ssl:"company.com" http.title:"admin"

ssl.cert.subject.cn:"company.com" admin

ssl:"company.com" admin

Fofa (https://fofa.so/):

Code:
cert="company.com" && title="admin"

cert.subject="company" && title="admin"

cert="company.com" && body="admin"

cert.subject="company" && body="admin"

ZoomEye (https://www.zoomeye.org/):

Code:
ssl:company.com +title:"admin"

ssl:company.com +admin

Censys (IPv4 (https://censys.io/ipv4)):

Code:
(services.tls.certificates.leaf_data.issuer.common_name:company.com) AND services.http.response.html_title:admin

(services.tls.certificates.leaf_data.issuer.common_name:company.com) AND services.http.response.body:admin
 
Top