This tool do a passive recon using Wayback Machine
Project description
WaybackRecon
WaybackRecon is a tool designed to fetch and categorize URLs from the Wayback Machine, allowing users to identify and highlight specific patterns, potential leaks, and other important information from archived web content. This tool supports outputting results to JSON and SQLite databases and offers easy searching and categorization.
Features
- Fetch URLs: Retrieve URLs from the Wayback Machine for a specified target domain.
- Categorization: Categorize URLs based on patterns such as APIs, leaks, file extensions, and CMS identifiers.
- Highlighting: Highlight keywords in URLs to easily identify important information.
- Output: Save results to JSON and SQLite databases.
- Search: Search and display specific categories of URLs.
Installation
pip install wayback-recon
Usage
Command-line Arguments
-t, --target
: Target domain to fetch URLs for (required).-p, --pattern-file
: Path to the pattern config JSON file (default:pattern_config.json
).-o, --output-file
: Output file name for the JSON results.-s, --search
: Search and display specific categories (e.g., apis, leaks, extensions, cms).--status-code
: Filter by status codes (e.g., 200, 301, 302).
Examples
-
Fetch and categorize URLs for a target domain:
wayback-recon -t example.com
-
Search for specific categories in the results:
wayback-recon -s apis leaks
-
Specify a custom pattern configuration file:
wayback-recon -t example.com -p custom_pattern_config.json
-
Output results to a specific JSON file:
wayback-recon -t example.com -o results.json
-
Filter URLs by status codes:
wayback-recon -t example.com --status-code 200,301
Configuration
The pattern configuration is stored in a JSON file (pattern_config.json
) and can be customized to include different patterns for categorization. The default configuration includes patterns for APIs, leaks, file extensions, and CMS identifiers.
Default Configuration
{
"apis": ["/api", "/v1", "/v2", "/services", "/rest", "/graphql", "/json"],
"leaks": ["aws", "apikey", "secret", "password", "auth", "token", "key", "access", "credential", "jwt", "kong", "kong-key", "AIza"],
"extensions": [".js", ".css", ".html", ".php", ".asp", ".aspx", ".jsp", ".json", ".xml", ".txt", ".csv"],
"cms": ["wp-", "wordpress", "joomla", "drupal", "magento", "typo3", "shopify", "prestashop"]
}
You can add or remove strings to be filtered.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Hashes for wayback_recon-0.2.3-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 6a11769930d824d3d80dfd46099069db9769e44d27d2e92e17d7221b5f4c26b1 |
|
MD5 | 2db6687df8248ee5fe838ab3cf2e1341 |
|
BLAKE2b-256 | 71f71e00323de42f764be8696a07790f2896b737e00da9b3bd0a86c06483bcfb |