maxpawer20
Privacy Consultant
LEVEL 1
400 XP
data:image/s3,"s3://crabby-images/045ae/045ae6bac0725f62c99e1faff05fcf49c8d2e7f2" alt="Blue-Orange-and-White-Artist-Photo-Musicians-Collection-YouTube-Thumbnail.png"
Hey Folks, in this tutorial we are going to talk about an web reconnaissance tool called “BillCipher“. It’s an information gathering tool for a Website or IP address, use some ideas from Devploit. BillCipher can work on any operating system if they have and support Python 2, Python 3, and Ruby. It use following combinations of tools.
Features
- Host Finder
- IP-Locator
- Find Shared DNS Servers
- Get Robots.txt
- Host DNS Finder
- DNS Lookup
- Whois Lookup
- GeoIP Lookup
- Subnet Lookup
- Port Scanner
- Page Links
- Zone Transfer
- HTTP Header
- Reserve IP Lookup
- Email Gathering (use Infoga)
- Subdomain listing (use Sublist3r)
- Find Admin login site (use Breacher)
- Check and Bypass CloudFlare (use HatCloud)
Let’s take a look
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
Install Dependencies
Our first mission will be to install all the dependencies of this tool and for this we will use the following command.
sudo apt update && sudo apt install ruby python python-pip python3 python3-pip
sudo apt install httrack whatweb12sudo apt update&&sudo apt install ruby python python-pip python3 python3-pipsudo apt install httrack whatweb
data:image/s3,"s3://crabby-images/97809/978090b1d9ea504a01c49c31f4b42a6b7f29503a" alt="1-16.png"
Installation
After completing the dependency installation we will proceed to the installation of this tool. Just execute the following commands one by one and the tool will be configured automatically.
git clone https://github.com/GitHackTools/BillCipher
cd BillCipher
pip install -r requirements.txt
pip3 install -r requirements.txt1234git clone
https://github.com/GitHackTools/BillCiphercd BillCipherpip install-rrequirements.txtpip3 install-rrequirements.txt
data:image/s3,"s3://crabby-images/b1584/b1584a6e5c48be60ed237a529cae25ae0d0fb513" alt="2-16.png"
Done
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
python3 billcipher.py1python3 billcipher.py
data:image/s3,"s3://crabby-images/15ec4/15ec4bf5b7950f3a4d7e2ddb66ff9e83845d9566" alt="3-16.png"
DNS Lookup
After entering the target details we get the following options to collect information about the web application. Now we select the first option and as you can see it has dumped all the sensitive details related to the domain.
data:image/s3,"s3://crabby-images/06df4/06df49d84528bcc6045457dbf09820f0a3d5e040" alt="4-13.png"
Whois Lookup
WHOIS is a query and response protocol that is widely used for querying databases that store the registered users or assignees of an Internet resource. You can use also use this facility in this tool.
data:image/s3,"s3://crabby-images/0be61/0be6188a9f33e52b23243f0382170153bff64ddd" alt="5-11.png"
Port Scan
Sometimes the services that are running on the target web server are vulnerable that’s why we take the help of such a tool to take advantage of that vulnerability.
data:image/s3,"s3://crabby-images/f7299/f72994b12bd69cf855d97729d0fd57e6b117c5fc" alt="6-12.png"
Website Copier
The following feature is used to clone the entire website with just one click.
data:image/s3,"s3://crabby-images/b81c5/b81c5224d8526a447f02379efec14c54f6ee7911" alt="7-8.png"
After download the entire resource of web application they will saved on particular location that you need to host on your apache server to look at view of the clone web page.
data:image/s3,"s3://crabby-images/c18e4/c18e404838aeff106d98ab50676637b6b558a0bc" alt="8-9.png"
Great
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
data:image/s3,"s3://crabby-images/3ae52/3ae5260d32383b1130ed73b331c393ad389e4660" alt="9-7.png"
Hmm
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
data:image/s3,"s3://crabby-images/81d16/81d16a965cbc1ce2e5661eb98c7934955b36d928" alt="10-5.png"