Redis-dumper on steroids.
-
Have a list of domains to target
-
Find which AS they all belong to
-
Extract CIDR blocks for the AS responsible for hosting the domain
-
Scan all CIDR blocks for Redis port
-
See if we can connect to it
-
See if it's unauthenticated
-
Dump all the contents we can get our hands on