The script aims to help find vulnerabilities in applications Web. The methodology derived from RecoX can detect weaknesses in addition to the OWASP top ten.
The script presents information against the destination system. Gathers information retrospectively into each subdomain and IP addr for an advanced attack.
RecoX automates many functions and saves significant time required throughout a manual penetration test.
Installation and use
git clone https://github.com/samhaxr/recox chmod + x recox.sh ./recox.sh
mv recox.sh / usr / local / bin / recox
The deep scan includes many checks, such as subdomains takeover, A record, passive scan, active scan, CORS misconfiguration, zone transfer test and web content discovery.
Video guide