Web Reconnaissance
HTTP Headers Reference
Request Headers (Useful for Recon)
Header
Description
Response Headers (Look For)
Header
Description
Security Headers (Missing = Potential Issue)
Header
Description
Web Fingerprinting
Identify Server & Tech Stack (curl)
whatweb (tech stack)
WAF Detection (wafw00f)
Nikto Fingerprinting
robots.txt Analysis
Key Directives
Directive
Description
Exposed .git Directory
Detection
Dumping with git-dumper
Manual Enumeration
Common Findings
File
Content
Example: Backdrop/Drupal settings.php
.well-known URIs
Useful .well-known URIs
URI
Description
Google Dorking
Operators
Operator
Description
Example
Common Dorks
Google Hacking Database
Wayback Machine
Web Interface
Command Line
Recon Value
VHost / subdomain fuzzing
Parameter Discovery & Fuzzing
GET Parameter Fuzzing
POST Parameter Fuzzing
Parameter Value Fuzzing
Using Burp Intruder
Source Code Analysis
Useful Wordlists for Parameter Discovery
Web Crawling
Burp Suite Spider
OWASP ZAP Spider
ReconSpider (Custom Tool)
Scrapy (Python)
Automation Frameworks
Tool
Description
FinalRecon
Recon-ng
Last updated