finds.dev← search

// the find

jhaddix/domain

★ 941 · Python · updated Nov 2020

Setup script for Regon-ng

A bash/Python wrapper script around Recon-ng and Altdns that automates subdomain enumeration across one or more domains in a single run. It's for pentesters and bug bounty hunters who want recon-ng's scraping modules (Google, Bing, Baidu, Yahoo, Netcraft) plus bruteforce and permutation-based discovery without manually driving the recon-ng console.

Chains multiple free OSINT sources (search engine scraping, Netcraft, bruteforce) instead of relying on a single API, so it still surfaces results if one source gets rate-limited or blocked. Supports batch mode across multiple domains in one invocation, which recon-ng's interactive console doesn't do cleanly. Only one module needs an API key, so most of it runs with zero signup friction.

Depends on recon-ng's old BitBucket source install and a deprecated clone URL format (LaNMaSteR53@bitbucket.org), which has likely stopped working since BitBucket dropped Mercurial-era auth and many of these legacy repos moved or went read-only. No commits since 2020, so it predates recon-ng's own v5 rewrite (pip-installable, plugin API changed) and is almost certainly broken against any current recon-ng install. Google/Bing/Baidu/Yahoo scraping modules it leans on are exactly the kind of thing that breaks silently when the search engines change their HTML or add captchas, and there's no error handling or fallback mentioned for that. No tests, no CI, no packaging — it's a personal script, not a maintained tool.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →