Skip to content

cornerpirate/iRecon

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

14 Commits
 
 
 
 
 
 

Repository files navigation

iRecon - another reconnaissaince script

There are many recon scripts out there which are useful and probably better by miles. This is just one I needed to land grab info relevant to me about a target. This will simply do the following:

  • Given a FQDN (a full hostname) like "www.google.co.uk".
  • It will resolve the IP if resolvable
  • It will extract the domain from the hostname i.e. "google.co.uk"
  • It will then make the following queries
    • whois <ip>
    • whois <domainname>
    • nmap -sn -PE <ip> # check if ICMP echo responses are enabled on the target.
    • nmap -sS -sU -P0 --top-ports 20 <ip> # check for the 20 most common TCP/UDP ports.
    • nmap -p <open port> -tr <ip> # issue a TCP traceroute to any one open TCP port discovered by previous command.
    • nmap -sS -P0 --reason -p 1-65535 -sV -A # do full SYN scan ports 1-65535
    • nmap -sU -P0 --reason --top-ports 500 # Increase UDP to 500 most common

Pre-Requisites

About

Of the thousands of lazy reconnaissance scripts, this one is by far the one in this repository.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages