ReconDrop ์ ์์: Faizad Khan
A passive client-side recon tool for security professionals. Scans web pages for exposed API endpoints, secrets, DOM sinks, inline events, and framework fingerprints.
์คํ์ ์คํ์
ํ์ฅ ๋ฉํ ๋ฐ์ดํฐ
์ ๋ณด
ReconDrop is a browser-based passive reconnaissance extension designed for penetration testers and security researchers.
Features:
- ๐ Framework fingerprinting (48 frameworks detected)
- ๐ Secret detection โ AWS keys, JWTs, API tokens
- ๐ URL & endpoint collection (4-layer deep scan)
- โ ๏ธ DOM sink detection โ innerHTML, eval, document.write
- ๐ฏ Inline event handler mapping
- ๐ฅ Export all findings as JSON
ReconDrop runs entirely in the page context โ no data is sent externally. All results are displayed locally and can be exported for reporting.
Built for use during authorized penetration testing engagements only.
Features:
- ๐ Framework fingerprinting (48 frameworks detected)
- ๐ Secret detection โ AWS keys, JWTs, API tokens
- ๐ URL & endpoint collection (4-layer deep scan)
- โ ๏ธ DOM sink detection โ innerHTML, eval, document.write
- ๐ฏ Inline event handler mapping
- ๐ฅ Export all findings as JSON
ReconDrop runs entirely in the page context โ no data is sent externally. All results are displayed locally and can be exported for reporting.
Built for use during authorized penetration testing engagements only.
3๋ช
์ด 5์ ์ผ๋ก ํ๊ฐํจ
๊ถํ ๋ฐ ๋ฐ์ดํฐ
์ ํ์ ๊ถํ:
- ๋ชจ๋ ์น์ฌ์ดํธ์์ ์ฌ์ฉ์์ ๋ฐ์ดํฐ์ ์ ๊ทผ
๋ฐ์ดํฐ ์์ง:
- ๊ฐ๋ฐ์๊ฐ ์ด ํ์ฅ ๊ธฐ๋ฅ์ ๋ฐ์ดํฐ ์์ง์ด ํ์ํ์ง ์๋ค๊ณ ํฉ๋๋ค.
์ถ๊ฐ ์ ๋ณด
- ๋ถ๊ฐ ๊ธฐ๋ฅ ๋งํฌ
- ๋ฒ์
- 3.0
- ํฌ๊ธฐ
- 35.96 KB
- ๋ง์ง๋ง ์ ๋ฐ์ดํธ
- 8์ผ ์ (2026๋ 4์ 24์ผ)
- ๊ด๋ จ ์นดํ ๊ณ ๋ฆฌ
- ๋ผ์ด์ ์ค
- MIT ๋ผ์ด์ ์ค
- ๋ฒ์ ๋ชฉ๋ก
- ๋ชจ์์ง์ ์ถ๊ฐ