Automated reconnaissance wrapper — TomNomNom's meg on steroids.
Built by TomNomNom and EdOverflow.
You will need Golang and PHP to use all the features provided by this tool. On top of that, make sure to install meg, waybackurls, and gio.
go get github.com/tomnomnom/meg
go get github.com/tomnomnom/waybackurls
You can either scan a list of hosts or use your HackerOne X-Auth-Token
token to scan all the bug bounty programs that you participate in.
$ ./megplus.sh
Usage: ./megplus.sh <list of domains>
Usage: ./megplus.sh -x <H1 X-Auth-Token>
Example: ./megplus.sh domains
Example: ./megplus.sh -x XXXXXXXXXXXXXXXX
meg+ will scan for the following things:
[+] Finding configuration files.
[+] Finding interesting strings.
[+] Finding open redirects.
[+] Finding CRLF injection.
[+] Finding CORS misconfigurations.
[+] Finding path-based XSS.
[+] Searching for (sub)domain takeovers.
I welcome contributions from the public.
The issue tracker is the preferred channel for bug reports and features requests.
The bug tracker utilizes several labels to help organize and identify issues.
Use the GitHub issue search — check if the issue has already been reported.