[tags]osint,ips,subdomains,shodan,api,cves,leaks,ports[/tags]
[short_descr]Passive open source intelligence automated reconnaissance.[/short_descr]
[link] https://github.com/Dheerajmadhukar/karma_v2 [/link]
[link] https://github.com/Dheerajmadhukar/karma_v2 [/link]
[long_descr]
karma v2 can be used by Infosec Researchers, Penetration Testers, Bug Hunters to find deep information, more assets, WAF/CDN bypassed IPs, Internal/External Infra, Publicly exposed leaks and many more about their target. Shodan Premium API key is required to use this automation. Output from the karma v2 is displayed to the screen and saved to files/directories.
Features:
Powerful and flexible results via Shodan Dorks
SSL SHA1 checksum/fingerprint Search
Only hit In-Scope IPs
Verify each IP with SSL/TLS certificate issuer match RegEx
Provide Out-Of-Scope IPs
Find out all ports including well known/uncommon/dynamic
Grab all targets vulnerabilities related to CVEs
Banner grab for each IP, Product, OS, Services & Org etc.
Grab favicon Icons
Generate Favicon Hash using python3 mmh3 Module
Favicon Technology Detection using nuclei custom template
ASN Scan
BGP Neighbour
IPv4 & IPv6 Profixes for ASN
Interesting Leaks like Indexing, NDMP, SMB, Login, SignUp, OAuth, SSO, Status 401/403/500, VPN, Citrix, Jfrog, Dashboards, OpenFire, Control Panels, Wordpress, Laravel, Jetty, S3 Buckets, Cloudfront, Jenkins, Kubernetes, Node Exports, Grafana, RabbitMQ, Containers, GitLab, MongoDB, Elastic, FTP anonymous, Memcached, DNS Recursion, Kibana, Prometheus, Default Passwords, Protected Objects, Moodle, Spring Boot, Django, Jira, Ruby, Secret Key and many more...
[/long_descr]
[image] https://raw.githubusercontent.com/gwen001/offsectools_www/main/tmp/4cf54b40b730ce8429180f048290ffb9.png [/image]
[tags]osint,ips,subdomains,shodan,api,cves,leaks,ports[/tags] [short_descr]Passive open source intelligence automated reconnaissance.[/short_descr] [link] https://github.com/Dheerajmadhukar/karma_v2 [/link] [link] https://github.com/Dheerajmadhukar/karma_v2 [/link] [long_descr] karma v2 can be used by Infosec Researchers, Penetration Testers, Bug Hunters to find deep information, more assets, WAF/CDN bypassed IPs, Internal/External Infra, Publicly exposed leaks and many more about their target. Shodan Premium API key is required to use this automation. Output from the karma v2 is displayed to the screen and saved to files/directories.
Features: