GET YOUR VULNERABILITY AND THREAT DATABASE SUBSCRIPTION
EKOLABS 2016


Tools logo_github

Published on January 6th, 2016 | by MaxiSoler

1

Bluto v1.1.14 – Passive Recon Tool

Bluto is a Passive Reconnaissance Tool. The target domain is queried for MX and NS records. Sub-domains are passively gathered via NetCraft. The target domain NS records are each queried for potential Zone Transfers. If none of them gives up their spinach, Bluto will brute force subdomains using parallel sub processing on the top 20000 of the ‘The Alexa Top 1 Million subdomains’. NetCraft results are presented individually and are then compared to the brute force results, any duplications are removed and particularly interesting results are highlighted.

Bluto now does email address enumeration based on the target domain, currently using Bing and Google search engines. It is configured in such a way to use a random User Agent: on each request and does a country look up to select the fastest Google server in relation to your egress address. Each request closes the connection in an attempt to further avoid captchas, however exsesive lookups will result in captchas (Bluto will warn you if any are identified).

 




Tags: , , ,


About the Author

ToolsWatcher :) @maxisoler



One Response to Bluto v1.1.14 – Passive Recon Tool

  1. tester says:

    latest version has some good features

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to Top ↑