What problem does it solve?
Moving and relocation company websites frequently store sensitive customer personally identifiable information (PII) and have unpatched WordPress misconfigurations that generic recon tools often miss, leaving exposed data and exploitable vulnerabilities undetected.
Core Features & Use Cases
- Sector-Targeted Domain Discovery: Finds moving company, relocation service, and logistics domains using common naming patterns and certificate transparency logs.
- PII and Form Data Hunting: Locates exposed quote request submissions, customer inventory lists, and move details stored in upload directories and debug logs.
- WordPress and CRM Recon: Checks for common WordPress vulnerabilities, open XMLRPC endpoints, CORS misconfigurations, and exposed customer tracking portals integrated with moving CRM tools.
- Use Case: For example, during an authorized penetration test of a regional moving company, this skill can identify an exposed debug log containing customer names, addresses, phone numbers, and move dates, as well as a directory listing with exported quote CSV files.
Quick Start
Use the recon-moving-companies skill to run full sector-specific reconnaissance on the target moving company domain and compile a report of all exposed sensitive data, vulnerable endpoints, and CMS misconfigurations.