All in one tool for Information Gathering, Vulnerability Scanning and Crawling
RED HAWK is An All In One Tool For Information Gathering, SQL Vulnerability Scannig and Crawling. Coded In PHP.
Features:
- Basic Scan
- Site Title NEW
- IP Address
- Web Server Detection
IMPROVED
- CMS Detection
- Cloudflare Detection
- robots.txt Scanner
- Whois Lookup
IMPROVED
- Geo-IP Lookup
- Grab Banners
IMPROVED
- DNS Lookup
- Subnet Calculator
- Nmap Port Scan
- Sub-Domain Scanner
IMPROVED
- Sub Domain
- IP Address
- Reverse IP Lookup & CMS Detection
IMPROVED
- Hostname
- IP Address
- CMS
- Error Based SQLi Scanner
- Bloggers View NEW
- HTTP Response Code
- Site Title
- Alexa Ranking
- Domain Authority
- Page Authority
- Social Links Extractor
- Link Grabber
- WordPress Scan NEW
- Sensitive Files Crawling
- Version Detection
- Version Vulnerability Scanner
- Crawler
- MX Lookup NEW
- Scan For Everything - The Old Lame Scanner
Released Versions:
- Version 1.0.0 [11-06-2017]
- Version 1.1.0 [15-06-2017]
- Version 2.0.0 [11-08-2017]
Changelog:
- Version 1.0.0
- Initial Launch
- Version 1.1.0
- Updated The
fix
command
- Updated The
- Version 2.0.0
- Separated all scans so that you are served the amount of information you need
Sub-Domain Scanner
improvedfix
command improvedWeb Server Detection
ImprovedCMS Detection
ImprovedBanner Grabbing
Improved- Added
WordPress Scanner
- Added
Bloggers View
- Added
MX Lookup
- Added
Update
option - RED HAWK Banner Updated
- Many Other Internal Fixes
Installation:
- Run The Tool and Type
fix
This will Install All Required Modules. - For The Bloggers View To Work Properly you have to configure RED HAWK with moz.com's api keys for that follow the following steps:
- Create an account in moz follow this link : https://moz.com/community/join
- After successful account creation and completing the verification you need to generate the API Keys
- You can get your API Keys here: https://moz.com/products/mozscape/access
- Get your AccessID and SecretKey and replace the
$accessID
and$secretKey
variable's value in theconfig.php
file - All set, now you can enjoy the bloggers view.
Usage:
- git clone
https://github.com/Tuhinshubhra/RED_HAWK
- cd RED_HAWK
- php rhawk.php
- Use the "help" command to see the command list or type in the domain name you want to scan (without Http:// OR Https://).
- Select whether The Site Runs On HTTPS or not.
- Select the type of scan you want to perform
- Leave the rest to the scanner
List of CMS Supported
RED HAWK's
CMS Detector
currently is able to detect the following CMSs (Content Management Systems) in case the website is using some other CMS, Detector will return could not detect.- WordPress
- Joomla
- Drupal
- Magento
Video Demonstration
TODOs
- Make a proper update option ( Installs current version automatically )
- Add more CMS to the detector
- Improve The WordPress Scanner ( Add User, Theme & Plugins Enumeration )
- Create a web version of the scanner
- Add XSS & LFI Scanner
- Improve the Links grabber thingy under bloggers view
- Add some other scans under the Bloggers View