
Recon Notes




  • …
  • …

Date: September 22, 2023

Topic: Passive Recon


  1. Host Lookup
  2. Robots.txt, Sitemap.xml

  3. Whois Lookup
  4. Netcraft
  5. DNS Recon
  6. WAF
  7. Subdomain Enum
  8. Google Dorks

  9. Email Harvesting

  10. Leaked Password Database


  • look for ip and hosts
  • Robots.txt: The robots.txt file is a text file that webmasters create to instruct web robots (typically search engine robots) how to crawl and index pages on their website. It controls and restricts access to certain areas of a website by specifying which parts should not be crawled or indexed.
  • Sitemap.xml: A sitemap is an XML file that lists all the pages of a website and provides additional metadata about each URL, such as when it was last updated. It helps search engines understand the structure of a website and crawl and index its pages more efficiently.

  • check for registration date and registrar info
  • gives all data like whois, dns, SSL/TLS, etc.
  • wafw00f to identify firewall on web app
  • Sublist3r
  • GHDB,

    Google dork cheatsheet

  • theHarvester,

  • Spyse

  • haveibeenpwned
This post is licensed under CC BY 4.0 by the author.

Trending Tags