{"id":13841511,"url":"https://github.com/tdr130/assetnote","last_synced_at":"2026-02-23T05:11:02.945Z","repository":{"id":43921749,"uuid":"56568399","full_name":"tdr130/assetnote","owner":"tdr130","description":"Push notifications for passive DNS data","archived":false,"fork":false,"pushed_at":"2016-04-18T14:02:10.000Z","size":689,"stargazers_count":106,"open_issues_count":0,"forks_count":120,"subscribers_count":5,"default_branch":"master","last_synced_at":"2024-08-05T17:28:15.751Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"JavaScript","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tdr130.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2016-04-19T05:51:33.000Z","updated_at":"2024-06-25T01:05:43.000Z","dependencies_parsed_at":"2022-08-24T08:30:54.644Z","dependency_job_id":null,"html_url":"https://github.com/tdr130/assetnote","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tdr130%2Fassetnote","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tdr130%2Fassetnote/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tdr130%2Fassetnote/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tdr130%2Fassetnote/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tdr130","download_url":"https://codeload.github.com/tdr130/assetnote/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225720419,"owners_count":17513597,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:01:12.979Z","updated_at":"2026-02-23T05:11:02.916Z","avatar_url":"https://github.com/tdr130.png","language":"JavaScript","funding_links":[],"categories":["JavaScript","JavaScript (485)"],"sub_categories":[],"readme":"# Assetnote\n\n![logo](http://i.imgur.com/nY80uWj.png)\n\nAssetnote notifies you of assets that have been found through scraping passive data stores. By using [Pushover's](https://pushover.net) push notification API, as soon as a new subdomain is found for an asset, a push notification is sent to your mobile phone (iOS/Android) with the data found.\n\nFor public release, I have included an example `manager` script for assetnote. This is Threatcrowd's public yet passive DNS data store. Assetnote can be extended very easily by writing scripts that interact with the `assetnote.db` SQLite database. The more scripts that have been made to scrape data sources, the more success one will have with this tool.\n\nAssetnote was created mainly for bug bounties, to assist with finding bugs before others do. You get a push notification that a new subdomain has been put online, you're now probably one of the first people to know of this new asset. This means fewer duplicate findings and a higher success rate in finding security flaws in an organization.\n\n## Screenshots\n\nLogin:\n\n\u003cimg src=\"https://i.imgur.com/ZkwWrga.png\" width=\"512\"\u003e\n\nSent notifications:\n\n\u003cimg src=\"https://i.imgur.com/R1ShMcG.png\" width=\"512\"\u003e\n\nAdding assets:\n\n\u003cimg src=\"https://i.imgur.com/xZWHiLB.png\" width=\"512\"\u003e\n\nPush notification assets seen on the phone:\n\n\u003cimg src=\"https://i.imgur.com/71SzMB4.png\" width=\"256\"\u003e\n\n## Concepts\n\nAssetnote is simply a web interface around the SQLite database `assetnote.db`. This database contains two columns, one that stores the domains that you'd like to monitor and another that stores every found subdomain through managers.\n\nThe core concept is that when a script within the `managers` folder finds a new subdomain, it is inserted as a domain in the `sent_notifications` column of the SQLite database. This ensures that you don't receive notifications of subdomains you already know about.\n\n## Installation\n\nThe installation process is annoying - if I get bugged about this enough, I'll work on making it easier.\n\nThis is a full installation guide for a Debian server hosted on Digital Ocean. This should cover most people, even those with very basic devops knowlege.\n\n1. Run the following commands to get a MySQL server installed:\n\n```\nsudo apt-get update\nsudo apt-get install mysql-server\nsudo mysql_secure_installation\nsudo mysql_install_db\n```\n\nYou'll have to provide a password to set up the MySQL server.\n\nWhen running `mysql_secure_installation`, use the following answers:\n\n```\nChange the root password? [Y/n] n\n ... skipping.\n\n Remove anonymous users? [Y/n] y\n ... Success!\n\n Disallow root login remotely? [Y/n] y\n ... Success!\n\n Remove test database and access to it? [Y/n] Y\n - Dropping test database...\n\n Reload privilege tables now? [Y/n] Y\n ... Success!\n```\n\n2. Create a database for Assetnote on your MySQL server:\n\n```\n$ mysql -uroot -p\n\n# login with your mysql user set up in step 1\n\n# create the assetnote database\n\nmysql\u003e CREATE DATABASE assetnote;\nQuery OK, 1 row affected (0.00 sec)\n\n# exit\n\nmysql\u003e exit;\nBye\n```\n\n2. Clone this git repo:\n\n`git clone https://github.com/infosec-au/assetnote`\n\n3. Create a new pushover application:\n\nVisit https://pushover.net/login and sign up:\n\n![signup](https://cms-assets.tutsplus.com/uploads/users/317/posts/22264/image/signup.jpg)\n\n![pushovernewapp](https://cms-assets.tutsplus.com/uploads/users/317/posts/22264/image/new-app.jpg)\n\n4. Modify the following files:\n\n- `config.py`\n\n```\nSECRET_KEY = 'CHANGEME'\nSQLALCHEMY_DATABASE_URI = 'mysql://root:test@localhost:3389/assetnote'\nSECURITY_PASSWORD_SALT = 'CHANGEME'\nPUSHOVER_KEY = 'PUSHOVERKEY'\n```\n\nChange the above configuration to have random, hard to guess secret keys/salts. Change the database credentials as needed.\n\nPut your pushover's application key in `PUSHOVER_KEY`.\n\n- `assetnote.py`\n\nLine 21: Modify this to use your database credentials instead\n\n```\nengine = sqlalchemy.create_engine('mysql://root:testing@localhost:3389/assetnote')\n```\n\nLine 59: Change the username and password that will be used to login to assetnote\n\n```\nuser_datastore.create_user(email='shubs', password='testing')\n```\n\n5. Get pip:\n\n`apt-get install python-pip`\n\n6. Install the required headers for MySQL-python and install python-bcrypt:\n\n`apt-get install python-dev libmysqlclient-dev`\n`apt-get install python-bcrypt`\n\n7. Install the required modules:\n\nWhen your user is currently in the assetnote directory, run - `pip install -r requirements.txt`\n\n8. Update your crontab to run your assetnote managers every 30 minutes:\n\n`crontab -e`\n\n`*/11 * * * * /usr/bin/timeout 30m python /home/deploy/assetnote/managers/threatcrowd.py \u003e /home/deploy/tc_log.txt 2\u003e\u00261`\n\nThis will run the script every 30 minutes and with a timeout of 30 minutes. Modify the path's as needed.\n\n## Support / help\n\nContact me via Twitter if any help is needed [@infosec_au](https://twitter.com/infosec_au).\n\n## Release details\n\n![BSides Canberra](https://i.imgur.com/SDnAepz.png)\n\n[bsidesau.com.au](http://bsidesau.com.au)\n\nThis was released at BSides Canberra by [@infosec_au](https://twitter.com/infosec_au) and [@nnwakelam](https://twitter.com/nnwakelam) for the talk \"Scrutiny on the bug bounty\".\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftdr130%2Fassetnote","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftdr130%2Fassetnote","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftdr130%2Fassetnote/lists"}