MindMap Gallery collect message
Introduced open information collection, active information collection, Dig deeper and more. Points to note when collecting information, as well as some tools that are often used!
Edited at 2024-01-23 17:56:38Avatar 3 centers on the Sully family, showcasing the internal rift caused by the sacrifice of their eldest son, and their alliance with other tribes on Pandora against the external conflict of the Ashbringers, who adhere to the philosophy of fire and are allied with humans. It explores the grand themes of family, faith, and survival.
This article discusses the Easter eggs and homages in Zootopia 2 that you may have discovered. The main content includes: character and archetype Easter eggs, cinematic universe crossover Easter eggs, animal ecology and behavior references, symbol and metaphor Easter eggs, social satire and brand allusions, and emotional storylines and sequel foreshadowing.
[Zootopia Character Relationship Chart] The idealistic rabbit police officer Judy and the cynical fox conman Nick form a charmingly contrasting duo, rising from street hustlers to become Zootopia police officers!
Avatar 3 centers on the Sully family, showcasing the internal rift caused by the sacrifice of their eldest son, and their alliance with other tribes on Pandora against the external conflict of the Ashbringers, who adhere to the philosophy of fire and are allied with humans. It explores the grand themes of family, faith, and survival.
This article discusses the Easter eggs and homages in Zootopia 2 that you may have discovered. The main content includes: character and archetype Easter eggs, cinematic universe crossover Easter eggs, animal ecology and behavior references, symbol and metaphor Easter eggs, social satire and brand allusions, and emotional storylines and sequel foreshadowing.
[Zootopia Character Relationship Chart] The idealistic rabbit police officer Judy and the cynical fox conman Nick form a charmingly contrasting duo, rising from street hustlers to become Zootopia police officers!
collect message
Public information collection
company level
Company Name
domain name
telephone number
main in-charge
Websites and tools
National Enterprise Credit Information Disclosure System: This is the most authoritative official industrial and commercial information query website. The information provided includes registration, filing information, chattel mortgage registration, equity pledge registration, etc. You can query the basic industrial and commercial information and credit information of enterprises.
Tianyancha: This is a platform focused on personal and corporate information inquiry. It provides company inquiry, industrial and commercial information inquiry, corporate credit information inquiry and other related information, and can quickly understand corporate information.
Qichacha: This platform provides enterprise information inquiry, industrial and commercial inquiry, enterprise credit evaluation inquiry, etc. Its information comes from multiple official channels such as the National Enterprise Credit Information Publicity System, and the data is relatively comprehensive.
JD Blue Whale Credit Reference: This is a professional platform for corporate credit reference services approved by the central bank under the JD Group, providing corporate credit reference, credit evaluation and other services.
ENScan_GO: A tool based on major enterprise information APIs to solve various information collection problems encountered by domestic enterprises. One-click collection and export of holding company ICP filing, APP, mini program, WeChat public account and other information.
network level
DNS record query
Online website
Racent DNS Check: https://www.racent.com/dns-check
DNS Checker: https://dnschecker.org/
MX Toolbox: https://mxtoolbox.com/DNSLookup.aspx
WhatsMyDNS.net: https://www.whatsmydns.net/
DNS Lookup Tool by UltraTools: https://www.ultratools.com/tools/dnsLookup
DNSViz (mainly for DNSSEC verification): https://dnsviz.net/
tool
nslookup
dig
whois query
website
Webmaster’s Home: https://whois.chinaz.com/
Jucha: http://www.jucha.com/whois/
Aizhan website: https://whois.aizhan.com/
Tencent Cloud: https://whois.cloud.tencent.com/
ICANN WHOIS: https://whois.icann.org/en
Who.is: https://who.is/
CentralNic WHOIS: https://www.centralnic.com/support/whois/
GoDaddy WHOIS Lookup: https://www.godaddy.com/whois
Command line tools
Whois: This is the most basic Whois command line tool, usually included in Linux and Unix systems. You can obtain relevant information by entering "whois" on the command line plus the domain name or IP address you want to query.
WhoisThisDomain: This is a free tool developed by Nirsoft and supports Windows systems. It provides a user-friendly interface to query domain name Whois information, and can export query results to multiple formats.
NetToolset: This is a more advanced domain name Whois information query tool that provides many additional functions, such as batch query, custom query, etc.
Axence netTools: This is a network toolset that supports Windows. In addition to Whois query, it also supports ping, traceroute, bandwidth testing, port scanning and other functions.
Superscan: In addition to its own Whois query function, this tool also integrates port scanning, ping and route tracing functions.
Graphical tools
Domain Punch Pro:
This is a professional Whois query tool that provides a graphical user interface to make queries more intuitive and simple.
It supports a variety of query methods, including directly entering domain names, batch queries, and querying by importing domain name lists through files.
Query results can be exported to a variety of formats, such as TXT, CSV, HTML, etc.
WhoisXP:
This is a lightweight Whois client that provides an easy-to-use graphical interface.
WhoisXP can also save query history to facilitate user review and management.
It supports queries for most top-level domains (TLDs) and many country code top-level domains (ccTLDs).
Whoister:
This is a simple and efficient Whois query tool, especially suitable for users who need to quickly query Whois information.
It provides basic query functions, and the query results are displayed in a clear way in the graphical interface.
VisualWhois:
This is a feature-rich Whois client that provides an intuitive graphical interface and powerful query capabilities.
It supports multi-tab query, can query multiple domain names at the same time, and query results can be easily compared and exported.
VisualWhois also supports monitoring domain name status changes, such as registration information changes, expiration time, etc.
Domain Name Pro:
This is a comprehensive domain name management tool that not only provides Whois query function, but also includes domain name registration, renewal, transfer and other management functions.
It has an intuitive graphical interface that allows users to easily manage their domain name portfolios.
API interface and library
interface
DevOps Club's Whois API: This is a free, open source and stable Whois query API interface. You can query the Whois information of a domain name by sending a GET request to the specified URL. The official website address of the API is https://api.devopsclub.cn. You can find detailed interface documentation and usage examples on the website.
Whois API of K780: K780 also provides a Whois query API interface, supporting HTTP and HTTPS requests. You can query the Whois information of a domain name by sending a GET or POST request with the corresponding request parameters. The API's return results support JSON and XML formats. You can find detailed API usage instructions and request examples on K780's official website.
Library
Python: The python-whois library is a Whois client library for Python, which provides a simple and easy-to-use interface to query Whois information.
PHP: phpWhois is a popular PHP Whois library that supports multiple Whois servers and has flexible query options.
Ruby: whois-parser is a Ruby library for parsing Whois query results and providing easy-to-process data structures.
Java: jWhois is a Whois client library implemented in Java, which supports multiple query methods and Whois servers.
Port collection
website
fofa
zoomeye
quake: https://quake.360.net/
Eagle Map: https://hunter.qianxin.com/
Diting: https://www.ditecting.com/ (industrial control safety)
Shodan
tool
nmap
Edgeworth Port Scanner
KScan
Fscan
goon
sweetbabyscan
Supports brute force cracking and high-risk POC scanning
front-end framework
middleware
database
Available tools
web application level
Website content
tool
Chrome DevTools: The developer tools that come with the Chrome browser provide powerful JavaScript debugging functions, which can view and analyze the JS interface, network requests, DOM structure, etc. of the website.
Postman: This is a popular API development tool. Although it is mainly used for testing and developing RESTful APIs, it can also be used to analyze and understand JS interfaces, especially those implemented through technologies such as AJAX and Fetch.
Apify: This is a web scraping and API automation platform. It provides some tools to help users extract data from websites, including data from JS interfaces.
JSFinder: This is a JavaScript-specific tool that can extract URLs and subdomains from a website’s JS files, which may be helpful in some cases for understanding the JS interface.
Octoparse: This is a code-free web data scraping tool that allows users to extract data from websites, including JS interface data, through simple clicks and selections.
browser plug-in
FindSomething
Der Spiegel:
superSearchPlus
Hidden directory
Sensitive documents
Available tools
dirsearch
dirpro
Edgeworth catalog scan
bypass-403
SSL certificate
Active information collection
network level
port scan
Host detection
ICMP (ping) exploration
TCP SYN (semi-open scan)
TCP ACK scan
ARP request
SNMP query
DNS query
Fingerprint recognition
tider fingerprint identification tool
web application level
API interface
Fingerprint recognition
Weak password attack
ssh
ftp
telnet
http Basic Auth
Management background
Sensitive documents
Hidden directory
Dig
File contains
command execution
Override attack
vertical override
Horizontal ultra vires
Unauthorized access
Asset correlation
Other sites on the same server
Other ports on the same server
Social engineering attack