Recon-ng V5 - Adding API Keys (Shodan & BuiltWith)
Skills:
Security Basics70%
Key Takeaways
The video demonstrates how to add API keys for Shodan and BuiltWith in Recon-ng V5, a full-featured reconnaissance framework for open-source web-based reconnaissance.
Full Transcript
[Music] hey guys welcome back to the recon ng version 5 series uh in this video we're going to be talking about apis in recon ng and yeah so let's get started uh without any further ado so first of all i just want to let you know that i've saved my showdown api key here and for those of you will be warning me in the comments section that it's a dangerous thing to expose i will have already reset my api key after i finish recording this video uh then we also have built with right so i have my built with domain api right over here so we'll be going through the very showdown and built with modules and how to add the various api keys here okay so let's get started so first of all if i type in help you can see we have the uh where is it we have the keys option here so this uh essentially allows you to manage third-party resource credentials right so a good example of this would be showdown you know you require an api uh that will then allow you to uh to actually access their their search engine to you know perform queries of whatever sort uh you know ones that are dictated by them by the module that you in you will install here so uh what we're gonna do is uh we are gonna if we say keys right and you can then take a look at the options we can list the keys that we have we can remove an ad etc etc but an easy way of doing this is by taking a look at the module we're going to be dealing with so let's talk to let's get started with showdown first of all right so we're essentially going to say marketplace uh search and we're going to look for showdown modules uh that uh you know related to showdown so an interesting one here is the domains uh hosts uh module which is again the showdown host name here we also have the showdown ip and you can you can note something very important that they all require the api key integration and that is noted by the asterisk here for each of them uh they're currently updated uh you can see in 2019 which is great um so we can also take we also have the push pins um netblocks uh uh we showed a net uh so we'll first of all try the the showdown host name here so we'll copy this and uh what we'll do is again we'll just simply install it marketplace install and we'll paste in the relative path here you can see that it will tell us we have an error that is denoted by an exclamation mark within the brackets so showed an api a key was not set showed in hostname module will likely fail at runtime so in order to add it we say keys add and then we can use the tab autocompletion and that will say showdown api do you want to specify the api key for showdown api and we say yes and then we want to get the the actual api here i'm going to copy my showdown api and we specify it right over here and we hit enter all right so now it's added the showdown api key excellent so now we can say modules uh modules load and we're looking for the showdown so that is right over here so there's also recon domains and hosts and we're looking for showdown host name load this if we take a look at the information here we can see we have this will harvest hosts from the showdown api by using the host name search operator and this will update the hosts table important information there we can limit the amount of api requests per input source so zero is unlimited and one is i've just currently set the value to 1 because i because i want to demonstrate something you can see i also set my source here so what we'll do is we'll say options on unset and we'll say unset the source here and we'll clear that out and uh let's just display the info one more time and let's uh let's actually get started so we're gonna say options set uh yeah we wanna set this and we wanna set the source here and the source is gonna be uh bbc info uh sorry bbc.com not bbc info when hit enter that's going to set the source um so we can now hit run and you can see it's going to search the showdown api for the hostname bbc.com so we're just gonna let this run and immediately you can see we have a lot more results than any of the other search engine engines we were using so this shows you the power of showdown first of all and secondly the power of recon ng thirdly the power of the of the showdown hostname module so uh you can see um we have the ip address uh the uh the port which gives us some ideas to the protocol we're dealing with here so we have mail.bbc uh we have various various domains and host names here um so we can go through this one will be generating reports we have 55 total seven new hosts found uh and you can see that um we get the various uh the various domains here but that's besides the point so that's essentially how to use the show that api key how to add it and then how to use it in conjunction with a module right now i'm not going to be talking about the showdown modules let's take a look at build with because i also had a few options with built with so we'll say marketplace search and we're looking for built with because it's it's a great module that allows you to uh to build a profile of the various web technologies that are used on a website so for example it'll allow you to tell if a website is using a cms like wordpress or like joomla etc you get the idea you can also see that this requires an api key integration here so we're just going to copy the relative path again same syntax marketplace install uh and we want to paste in the relative path that is going to install it it's going to give us the same error telling us that the built with api key was not set uh so the built with module will likely fail etc so you can say keys add and we can use the tab auto completion and we say we want to specify the build with api here so i'll just go into my browser and we'll copy this api let me just refresh this so that i think i'd reset it before so let's just copy it one more time and by the way i'll put a link in the description to where you can sign up for build with it's absolutely free and you have some free credits that you can use so we have added the built with api so if we say keys sorry where you say keys we can say list the keys that we have so you can see we have the built with api keys we have the showdown api key added here so again we can look we say modules load and we're looking for the built with module here so that is also another recon module let me just paste in the relative path here and the module we're using so we can see it is set now uh so you can see this leverages the built with api to identify hosts technologies and contacts associated with a domain interesting stuff so again this uh the first option we have here is unique so that is the show or option that allows us to display the technologies and we want to set the value to true so this will show us all the the technologies that are currently using secondly is the source so let me just unset this um i'm going to say source that is the source there and we can now set the option one more time and so we're going to say options uh set and i'm gonna say source this is the source here and bbc.com hit enter and uh we can now hit run and i had a few issues with this module so you can see it really doesn't display any options now i don't know whether this is a problem on my end but again if we take a look at the uh overview here uh we can see that the built with api uh you can see if i take a look at my usage here i have pretty much zero requests uh since the beginning of me since the beginning of me uh actually opening this account so uh you can see that uh we have the domi the domain api and we also have the free api so this is the one i've been using so the free api is really limited to one request per second if you're not purchased api uh credits so again we if we take a look at the um i think i'll take a look at the tools uh the domain uh what are my current credits if i say buy credits here uh let's see how many current it doesn't tell me how many credits i currently have uh so let me just go back into my usage here uh so nothing here so maybe it's just a problem with my account where i don't have enough uh i don't have enough credits but let me know how it goes with you guys it's a great uh it's a great module and that's why i've covered it in this video again you can get the browser extension as well that works just great but again this this can be this can be used to automate the process of gathering that information and all be useful in building a report all right so that's pretty much all i wanted to cover in this video now there are plenty of other modules that require an api uh you know one of them is bing so you can search for those modules and you can go through them so again we just go back and we can say marketplace search if we hit enter you can see the various ones here that require an api like twitter for example really great stuff uh so we can get push pins uh for both twitter youtube so they all require an api integration so we have bing let's see which other one we have we have virus total so you can go through all of them uh hopefully i've covered how to uh you know how to use keys and how to integrate them with recon ng uh by the way if you want to delete a key so we say keys and we'll say remove and we specify the name here so we can remove the build with api key and they'll get that will get rid of it all right if you want to get rid of a particular module let me just end with that so we can say marketplace um or we can actually use modules but let me just show you so if we type modules right so you can see we can only load reload and search for one if we hit marketplace we can pretty much install and uninstall them from the marketplace so we say marketplace remove remove and we can use the tab auto completion this gives us an idea of all the modules we have installed we want to get rid of the built with module again just copy the entire name and relative path hit enter that's going to remove the module and you know so on and so forth so that's pretty much going to be it for this video in the next video we'll be talking about interacting with the database and generating reports [Music] you
Original Description
Hey guys! in this video series we will be taking a look at the updated version of Recon-ng V5. Recon-ng is a full-featured reconnaissance framework designed with the goal of providing a powerful environment to conduct open-source web-based reconnaissance quickly and thoroughly.
Github Repository: https://github.com/lanmaster53/recon-ng
◼️Get Our Courses:
Python For Ethical Hacking: https://www.udemy.com/python-for-ethical-hacking-develop-pentesting-tools/?couponCode=PFEHJUN
Ethical Hacking Bootcamp: https://www.udemy.com/the-complete-ethical-hacking-bootcamp/?couponCode=TCEHB2019
◼️Our Platforms:
Blog: https://hsploit.com/
HackerSploit Forum: https://hackersploit.org/
HackerSploit Cybersecurity Services: https://hackersploit.io
HackerSploit Academy: https://www.hackersploit.academy
HackerSploit Discord: https://discord.gg/j3dH7tK
HackerSploit Podcast: https://soundcloud.com/hackersploit
iTunes: https://itunes.apple.com/us/podcast/the-hackersploit-podcast/id1439732519?mt=2
◼️Support us by using the following links:
Patreon: http://patreon.com/hackersploit
I hope you enjoy/enjoyed the video.
If you have any questions or suggestions feel free to post them in the comments section or on my social networks.
Social Networks - Connect With Us!
-------------------------------
Facebook: https://www.facebook.com/HackerSploit/
Twitter: https://twitter.com/HackerSploit
Instagram: https://www.instagram.com/hackersploit/
Patreon: http://patreon.com/hackersploit
--------------------------------
Thanks for watching!
Благодаря за гледането
Kiitos katsomisesta
Danke fürs Zuschauen!
感谢您观看
Merci d'avoir regardé
دیکھنے کے لیے شکریہ
देखने के लिए धन्यवाद
Grazie per la visione
Gracias por ver
شكرا للمشاهدة
#recon-ng#OSINT
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from HackerSploit · HackerSploit · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
How To Install Kali Linux 2.0 On Virtual Box
HackerSploit
100 Subscriber Q&A! - How I Learned Ethical Hacking
HackerSploit
BlackArch Linux Review - Better Than Kali Linux?
HackerSploit
How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
HackerSploit
Wireshark Tutorial for Beginners - Installation
HackerSploit
Wireshark Tutorial for Beginners - Overview of the environment
HackerSploit
Wireshark Tutorial for Beginners - Capture options
HackerSploit
Wireshark Tutorial for Beginners - Filters
HackerSploit
Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
HackerSploit
Complete Ethical Hacking Course #2 - Installing Kali Linux
HackerSploit
Parrot OS 3.5 Review | The Best Kali Linux Alternative
HackerSploit
Nmap Tutorial For Beginners - 1 - What is Nmap?
HackerSploit
Katoolin | How To Install Pentesting Tools On Any Linux Distro
HackerSploit
Nmap Tutorial For Beginners - 2 - Advanced Scanning
HackerSploit
Nmap Tutorial For Beginners - 3 - Aggressive Scanning
HackerSploit
Zenmap Tutorial For Beginners
HackerSploit
How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
HackerSploit
How To Setup Proxychains In Kali Linux - #2 - Change Your IP
HackerSploit
How To Change Mac Address In Kali Linux | Macchanger
HackerSploit
How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
HackerSploit
Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
HackerSploit
VPN And DNS For Beginners | Kali Linux
HackerSploit
Tails OS Installation And Review - Access The Deep Web/Dark Net
HackerSploit
Steganography Tutorial - Hide Messages In Images
HackerSploit
The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
HackerSploit
Best Linux Distributions For Penetration Testing
HackerSploit
Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
HackerSploit
Gaining Access - Web Server Hacking - Metasploitable - #1
HackerSploit
Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
HackerSploit
How To Install Kali Linux On VMware - Complete Guide 2018
HackerSploit
Q&A #1 - Best Cyber-security Certifications?
HackerSploit
Terminator - Kali Linux - Multiple Terminals
HackerSploit
Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
HackerSploit
Q&A #2 - Mr Robot?
HackerSploit
Metasploit Community Web GUI - Installation And Overview
HackerSploit
Linux Expl0rer - Forensics Toolbox - Installation & Configuration
HackerSploit
QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
HackerSploit
Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
HackerSploit
Metasploit For Beginners - #2 - Understanding Metasploit Modules
HackerSploit
Kali Linux Quick Tips - #1 - Adding a non-root user
HackerSploit
Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
HackerSploit
Spectre Meltdown Vulnerability - How To Check Your System
HackerSploit
Metasploit For Beginners - #4 - Basic Exploitation
HackerSploit
ARP Spoofing With arpspoof - MITM
HackerSploit
WordPress Vulnerability Scanning With WPScan
HackerSploit
Generating A PHP Backdoor with weevely
HackerSploit
Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
HackerSploit
How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
HackerSploit
Stacer - System Optimizer And Monitoring Tool For Linux
HackerSploit
Kali Linux 2018.1 - Kernel Updates & Patches
HackerSploit
MITM With Ettercap - ARP Poisoning
HackerSploit
Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
HackerSploit
How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
HackerSploit
Channel Updates - How To Post Questions & Video Suggestions
HackerSploit
Web App Penetration Testing - #1 - Setting Up Burp Suite
HackerSploit
Web App Penetration Testing - #2 - Spidering & DVWA
HackerSploit
Cl0neMast3r - GitHub Repository Cloning Tool
HackerSploit
Kali Linux On Windows 10 Official - WSL - Installation & Configuration
HackerSploit
DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
HackerSploit
Web App Penetration Testing - #3 - Brute Force With Burp Suite
HackerSploit
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
Secured MCP Complete Guide: OWASP Top 10, Best Practices, Security Guardrails, and Compliance
Medium · AI
Whose ASN Goes on Your Leased IPv4 Prefix?
Dev.to · Artem Kohanevich
Blank Identifier: Idiomatic Go or Vulnerability Trap?
Medium · Cybersecurity
Kinetix Browser Review: The Ultimate Solution for Fast, Secure, and Private Web Surfing
Medium · Machine Learning
🎓
Tutor Explanation
DeepCamp AI