Recon-ng V5 - Adding API Keys (Shodan & BuiltWith)

HackerSploit · Intermediate ·🔐 Cybersecurity ·6y ago

Key Takeaways

The video demonstrates how to add API keys for Shodan and BuiltWith in Recon-ng V5, a full-featured reconnaissance framework for open-source web-based reconnaissance.

Full Transcript

[Music] hey guys welcome back to the recon ng version 5 series uh in this video we're going to be talking about apis in recon ng and yeah so let's get started uh without any further ado so first of all i just want to let you know that i've saved my showdown api key here and for those of you will be warning me in the comments section that it's a dangerous thing to expose i will have already reset my api key after i finish recording this video uh then we also have built with right so i have my built with domain api right over here so we'll be going through the very showdown and built with modules and how to add the various api keys here okay so let's get started so first of all if i type in help you can see we have the uh where is it we have the keys option here so this uh essentially allows you to manage third-party resource credentials right so a good example of this would be showdown you know you require an api uh that will then allow you to uh to actually access their their search engine to you know perform queries of whatever sort uh you know ones that are dictated by them by the module that you in you will install here so uh what we're gonna do is uh we are gonna if we say keys right and you can then take a look at the options we can list the keys that we have we can remove an ad etc etc but an easy way of doing this is by taking a look at the module we're going to be dealing with so let's talk to let's get started with showdown first of all right so we're essentially going to say marketplace uh search and we're going to look for showdown modules uh that uh you know related to showdown so an interesting one here is the domains uh hosts uh module which is again the showdown host name here we also have the showdown ip and you can you can note something very important that they all require the api key integration and that is noted by the asterisk here for each of them uh they're currently updated uh you can see in 2019 which is great um so we can also take we also have the push pins um netblocks uh uh we showed a net uh so we'll first of all try the the showdown host name here so we'll copy this and uh what we'll do is again we'll just simply install it marketplace install and we'll paste in the relative path here you can see that it will tell us we have an error that is denoted by an exclamation mark within the brackets so showed an api a key was not set showed in hostname module will likely fail at runtime so in order to add it we say keys add and then we can use the tab autocompletion and that will say showdown api do you want to specify the api key for showdown api and we say yes and then we want to get the the actual api here i'm going to copy my showdown api and we specify it right over here and we hit enter all right so now it's added the showdown api key excellent so now we can say modules uh modules load and we're looking for the showdown so that is right over here so there's also recon domains and hosts and we're looking for showdown host name load this if we take a look at the information here we can see we have this will harvest hosts from the showdown api by using the host name search operator and this will update the hosts table important information there we can limit the amount of api requests per input source so zero is unlimited and one is i've just currently set the value to 1 because i because i want to demonstrate something you can see i also set my source here so what we'll do is we'll say options on unset and we'll say unset the source here and we'll clear that out and uh let's just display the info one more time and let's uh let's actually get started so we're gonna say options set uh yeah we wanna set this and we wanna set the source here and the source is gonna be uh bbc info uh sorry bbc.com not bbc info when hit enter that's going to set the source um so we can now hit run and you can see it's going to search the showdown api for the hostname bbc.com so we're just gonna let this run and immediately you can see we have a lot more results than any of the other search engine engines we were using so this shows you the power of showdown first of all and secondly the power of recon ng thirdly the power of the of the showdown hostname module so uh you can see um we have the ip address uh the uh the port which gives us some ideas to the protocol we're dealing with here so we have mail.bbc uh we have various various domains and host names here um so we can go through this one will be generating reports we have 55 total seven new hosts found uh and you can see that um we get the various uh the various domains here but that's besides the point so that's essentially how to use the show that api key how to add it and then how to use it in conjunction with a module right now i'm not going to be talking about the showdown modules let's take a look at build with because i also had a few options with built with so we'll say marketplace search and we're looking for built with because it's it's a great module that allows you to uh to build a profile of the various web technologies that are used on a website so for example it'll allow you to tell if a website is using a cms like wordpress or like joomla etc you get the idea you can also see that this requires an api key integration here so we're just going to copy the relative path again same syntax marketplace install uh and we want to paste in the relative path that is going to install it it's going to give us the same error telling us that the built with api key was not set uh so the built with module will likely fail etc so you can say keys add and we can use the tab auto completion and we say we want to specify the build with api here so i'll just go into my browser and we'll copy this api let me just refresh this so that i think i'd reset it before so let's just copy it one more time and by the way i'll put a link in the description to where you can sign up for build with it's absolutely free and you have some free credits that you can use so we have added the built with api so if we say keys sorry where you say keys we can say list the keys that we have so you can see we have the built with api keys we have the showdown api key added here so again we can look we say modules load and we're looking for the built with module here so that is also another recon module let me just paste in the relative path here and the module we're using so we can see it is set now uh so you can see this leverages the built with api to identify hosts technologies and contacts associated with a domain interesting stuff so again this uh the first option we have here is unique so that is the show or option that allows us to display the technologies and we want to set the value to true so this will show us all the the technologies that are currently using secondly is the source so let me just unset this um i'm going to say source that is the source there and we can now set the option one more time and so we're going to say options uh set and i'm gonna say source this is the source here and bbc.com hit enter and uh we can now hit run and i had a few issues with this module so you can see it really doesn't display any options now i don't know whether this is a problem on my end but again if we take a look at the uh overview here uh we can see that the built with api uh you can see if i take a look at my usage here i have pretty much zero requests uh since the beginning of me since the beginning of me uh actually opening this account so uh you can see that uh we have the domi the domain api and we also have the free api so this is the one i've been using so the free api is really limited to one request per second if you're not purchased api uh credits so again we if we take a look at the um i think i'll take a look at the tools uh the domain uh what are my current credits if i say buy credits here uh let's see how many current it doesn't tell me how many credits i currently have uh so let me just go back into my usage here uh so nothing here so maybe it's just a problem with my account where i don't have enough uh i don't have enough credits but let me know how it goes with you guys it's a great uh it's a great module and that's why i've covered it in this video again you can get the browser extension as well that works just great but again this this can be this can be used to automate the process of gathering that information and all be useful in building a report all right so that's pretty much all i wanted to cover in this video now there are plenty of other modules that require an api uh you know one of them is bing so you can search for those modules and you can go through them so again we just go back and we can say marketplace search if we hit enter you can see the various ones here that require an api like twitter for example really great stuff uh so we can get push pins uh for both twitter youtube so they all require an api integration so we have bing let's see which other one we have we have virus total so you can go through all of them uh hopefully i've covered how to uh you know how to use keys and how to integrate them with recon ng uh by the way if you want to delete a key so we say keys and we'll say remove and we specify the name here so we can remove the build with api key and they'll get that will get rid of it all right if you want to get rid of a particular module let me just end with that so we can say marketplace um or we can actually use modules but let me just show you so if we type modules right so you can see we can only load reload and search for one if we hit marketplace we can pretty much install and uninstall them from the marketplace so we say marketplace remove remove and we can use the tab auto completion this gives us an idea of all the modules we have installed we want to get rid of the built with module again just copy the entire name and relative path hit enter that's going to remove the module and you know so on and so forth so that's pretty much going to be it for this video in the next video we'll be talking about interacting with the database and generating reports [Music] you

Original Description

Hey guys! in this video series we will be taking a look at the updated version of Recon-ng V5. Recon-ng is a full-featured reconnaissance framework designed with the goal of providing a powerful environment to conduct open-source web-based reconnaissance quickly and thoroughly. Github Repository: https://github.com/lanmaster53/recon-ng ◼️Get Our Courses: Python For Ethical Hacking: https://www.udemy.com/python-for-ethical-hacking-develop-pentesting-tools/?couponCode=PFEHJUN Ethical Hacking Bootcamp: https://www.udemy.com/the-complete-ethical-hacking-bootcamp/?couponCode=TCEHB2019 ◼️Our Platforms: Blog: https://hsploit.com/ HackerSploit Forum: https://hackersploit.org/ HackerSploit Cybersecurity Services: https://hackersploit.io HackerSploit Academy: https://www.hackersploit.academy HackerSploit Discord: https://discord.gg/j3dH7tK HackerSploit Podcast: https://soundcloud.com/hackersploit iTunes: https://itunes.apple.com/us/podcast/the-hackersploit-podcast/id1439732519?mt=2 ◼️Support us by using the following links: Patreon: http://patreon.com/hackersploit I hope you enjoy/enjoyed the video. If you have any questions or suggestions feel free to post them in the comments section or on my social networks. Social Networks - Connect With Us! ------------------------------- Facebook: https://www.facebook.com/HackerSploit/ Twitter: https://twitter.com/HackerSploit Instagram: https://www.instagram.com/hackersploit/ Patreon: http://patreon.com/hackersploit -------------------------------- Thanks for watching! Благодаря за гледането Kiitos katsomisesta Danke fürs Zuschauen! 感谢您观看 Merci d'avoir regardé دیکھنے کے لیے شکریہ देखने के लिए धन्यवाद Grazie per la visione Gracias por ver شكرا للمشاهدة #recon-ng#OSINT
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from HackerSploit · HackerSploit · 0 of 60

← Previous Next →
1 How To Install Kali Linux 2.0 On Virtual Box
How To Install Kali Linux 2.0 On Virtual Box
HackerSploit
2 100 Subscriber Q&A! - How I Learned Ethical Hacking
100 Subscriber Q&A! - How I Learned Ethical Hacking
HackerSploit
3 BlackArch Linux Review - Better Than Kali Linux?
BlackArch Linux Review - Better Than Kali Linux?
HackerSploit
4 How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
HackerSploit
5 Wireshark Tutorial for Beginners - Installation
Wireshark Tutorial for Beginners - Installation
HackerSploit
6 Wireshark Tutorial for Beginners - Overview of the environment
Wireshark Tutorial for Beginners - Overview of the environment
HackerSploit
7 Wireshark Tutorial for Beginners - Capture options
Wireshark Tutorial for Beginners - Capture options
HackerSploit
8 Wireshark Tutorial for Beginners - Filters
Wireshark Tutorial for Beginners - Filters
HackerSploit
9 Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
HackerSploit
10 Complete Ethical Hacking Course #2 - Installing Kali Linux
Complete Ethical Hacking Course #2 - Installing Kali Linux
HackerSploit
11 Parrot OS 3.5 Review | The Best Kali Linux Alternative
Parrot OS 3.5 Review | The Best Kali Linux Alternative
HackerSploit
12 Nmap Tutorial For Beginners - 1 - What is Nmap?
Nmap Tutorial For Beginners - 1 - What is Nmap?
HackerSploit
13 Katoolin | How To Install Pentesting Tools On Any Linux Distro
Katoolin | How To Install Pentesting Tools On Any Linux Distro
HackerSploit
14 Nmap Tutorial For Beginners - 2 - Advanced Scanning
Nmap Tutorial For Beginners - 2 - Advanced Scanning
HackerSploit
15 Nmap Tutorial For Beginners - 3 - Aggressive Scanning
Nmap Tutorial For Beginners - 3 - Aggressive Scanning
HackerSploit
16 Zenmap Tutorial For Beginners
Zenmap Tutorial For Beginners
HackerSploit
17 How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
HackerSploit
18 How To Setup Proxychains In Kali Linux - #2 - Change Your IP
How To Setup Proxychains In Kali Linux - #2 - Change Your IP
HackerSploit
19 How To Change Mac Address In Kali Linux | Macchanger
How To Change Mac Address In Kali Linux | Macchanger
HackerSploit
20 How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
HackerSploit
21 Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
HackerSploit
22 VPN And DNS For Beginners | Kali Linux
VPN And DNS For Beginners | Kali Linux
HackerSploit
23 Tails OS Installation And Review - Access The Deep Web/Dark Net
Tails OS Installation And Review - Access The Deep Web/Dark Net
HackerSploit
24 Steganography Tutorial - Hide Messages In Images
Steganography Tutorial - Hide Messages In Images
HackerSploit
25 The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
HackerSploit
26 Best Linux Distributions For Penetration Testing
Best Linux Distributions For Penetration Testing
HackerSploit
27 Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
HackerSploit
28 Gaining Access - Web Server Hacking - Metasploitable - #1
Gaining Access - Web Server Hacking - Metasploitable - #1
HackerSploit
29 Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
HackerSploit
30 How To Install Kali Linux On VMware  - Complete Guide 2018
How To Install Kali Linux On VMware - Complete Guide 2018
HackerSploit
31 Q&A #1 - Best Cyber-security Certifications?
Q&A #1 - Best Cyber-security Certifications?
HackerSploit
32 Terminator - Kali Linux - Multiple Terminals
Terminator - Kali Linux - Multiple Terminals
HackerSploit
33 Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
HackerSploit
34 Q&A #2 - Mr Robot?
Q&A #2 - Mr Robot?
HackerSploit
35 Metasploit Community Web GUI  - Installation And Overview
Metasploit Community Web GUI - Installation And Overview
HackerSploit
36 Linux Expl0rer - Forensics Toolbox - Installation & Configuration
Linux Expl0rer - Forensics Toolbox - Installation & Configuration
HackerSploit
37 QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
HackerSploit
38 Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
HackerSploit
39 Metasploit For Beginners - #2 - Understanding Metasploit Modules
Metasploit For Beginners - #2 - Understanding Metasploit Modules
HackerSploit
40 Kali Linux Quick Tips - #1 - Adding a non-root user
Kali Linux Quick Tips - #1 - Adding a non-root user
HackerSploit
41 Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
HackerSploit
42 Spectre Meltdown Vulnerability  - How To Check Your System
Spectre Meltdown Vulnerability - How To Check Your System
HackerSploit
43 Metasploit For Beginners - #4 - Basic Exploitation
Metasploit For Beginners - #4 - Basic Exploitation
HackerSploit
44 ARP Spoofing With arpspoof - MITM
ARP Spoofing With arpspoof - MITM
HackerSploit
45 WordPress Vulnerability Scanning With WPScan
WordPress Vulnerability Scanning With WPScan
HackerSploit
46 Generating A PHP Backdoor with weevely
Generating A PHP Backdoor with weevely
HackerSploit
47 Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
HackerSploit
48 How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
HackerSploit
49 Stacer - System Optimizer And Monitoring Tool For Linux
Stacer - System Optimizer And Monitoring Tool For Linux
HackerSploit
50 Kali Linux 2018.1 - Kernel Updates & Patches
Kali Linux 2018.1 - Kernel Updates & Patches
HackerSploit
51 MITM With Ettercap - ARP Poisoning
MITM With Ettercap - ARP Poisoning
HackerSploit
52 Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
HackerSploit
53 How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
HackerSploit
54 Channel Updates - How To Post Questions & Video Suggestions
Channel Updates - How To Post Questions & Video Suggestions
HackerSploit
55 Web App Penetration Testing - #1 - Setting Up Burp Suite
Web App Penetration Testing - #1 - Setting Up Burp Suite
HackerSploit
56 Web App Penetration Testing - #2 - Spidering & DVWA
Web App Penetration Testing - #2 - Spidering & DVWA
HackerSploit
57 Cl0neMast3r - GitHub Repository Cloning Tool
Cl0neMast3r - GitHub Repository Cloning Tool
HackerSploit
58 Kali Linux On Windows 10 Official - WSL - Installation & Configuration
Kali Linux On Windows 10 Official - WSL - Installation & Configuration
HackerSploit
59 DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
HackerSploit
60 Web App Penetration Testing - #3 - Brute Force With Burp Suite
Web App Penetration Testing - #3 - Brute Force With Burp Suite
HackerSploit

This video teaches how to add API keys for Shodan and BuiltWith in Recon-ng V5, enabling users to conduct thorough open-source web-based reconnaissance. Recon-ng V5 is a powerful framework for reconnaissance, and adding API keys enhances its capabilities.

Key Takeaways
  1. Install Recon-ng V5
  2. Obtain API keys for Shodan and BuiltWith
  3. Add API keys to Recon-ng V5
  4. Configure Recon-ng V5 for web-based reconnaissance
  5. Conduct reconnaissance using Recon-ng V5
💡 Adding API keys for Shodan and BuiltWith enhances the capabilities of Recon-ng V5, allowing for more comprehensive open-source web-based reconnaissance.

Related Reads

📰
Secured MCP Complete Guide: OWASP Top 10, Best Practices, Security Guardrails, and Compliance
Secure your MCP with OWASP Top 10, best practices, and compliance using a practical reference architecture
Medium · AI
📰
Whose ASN Goes on Your Leased IPv4 Prefix?
Learn how to handle ASN for leased IPv4 prefixes in BGP routing
Dev.to · Artem Kohanevich
📰
Blank Identifier: Idiomatic Go or Vulnerability Trap?
Learn how blank identifiers in Go can be either idiomatic code or a vulnerability trap and why it matters for cybersecurity
Medium · Cybersecurity
📰
Kinetix Browser Review: The Ultimate Solution for Fast, Secure, and Private Web Surfing
Discover how Kinetix Browser provides fast, secure, and private web surfing using machine learning, and why it matters for online security
Medium · Machine Learning
Up next
Dual Boot macOS Golden Gate & TAHOE: Install the macOS 27 Beta WITHOUT Losing Your Data
Ksk Royal
Watch →