finds.dev← search

// the find

nahamsec/bbht

★ 1,238 · Shell · updated Jul 2024

A script to set up a quick Ubuntu 17.10 x64 box with tools I use.

A shell script that clones and installs a set of recon and bug bounty tools (dirsearch, Sublist3r, sqlmap, massdns, waybackurls, httprobe, SecLists and others) onto a fresh Ubuntu box, then pulls in the aliases from nahamsec's recon_profile repo. It is aimed at bug bounty hunters who want a new VM set up in one command.

- It is a short, readable install.sh with no build step, so you can see exactly what it clones and where it puts things before you run it.

- The tool list is a sensible starter kit: subdomain enumeration, DNS resolution, live host probing, archived URL collection and wordlists cover the usual first hour of recon.

- Each tool comes straight from its upstream repo rather than a bundled copy, so you get the project's own code instead of a stale fork.

- It targets Ubuntu 17.10, which reached end of life years ago. Expect package and Python 2/3 breakage on any current release, and the README says nothing about that.

- Last push was July 2024 and nothing in the README suggests the script is maintained, so some of the cloned repos may be archived or moved by now. Nothing is pinned to a tag or commit, so a fresh run pulls whatever HEAD is that day.

- It pulls aliases from another person's repo and sources them into your shell. Read recon_profile before running this, because you are trusting its contents with your shell config.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →