The script aims to help find vulnerabilities in web applications. The methodology derived from RecoX can identify weaknesses in addition to the top ten of OWASP.
The script presents information against the destination system. Gathers information retrospectively into each subdomain and IP addr for an advanced attack.
RecoX automates many functions and saves significant time required throughout a manual penetration test.
Installation and use
git clone https://github.com/samhaxr/recox
chmod +x recox.sh
mv recox.sh /usr/local/bin/recox
The deep scan includes many controls, such as subdomain takeover, A record, passive scan, active scan, CORS misconfiguration, zone transfer test and web content discovery.