recon-property-management

Discover tenant portals, property APIs, and debug logs on property management sites.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill recon-property-management
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-property-management
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/recon-property-management
Command: npx skills add https://github.com/uphiago/recon-skills --skill recon-property-management

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Generic recon workflows miss sector-specific attack surfaces unique to property management, apartment rental, and real estate management company websites, which often store highly sensitive tenant PII (SSNs, bank account details, lease agreements) and run niche platforms and plugins that require targeted discovery techniques.

Core Features & Use Cases

  • Sector-specific endpoint discovery: Automatically identifies tenant portals, property listing APIs, maintenance request systems, and common property management software (AppFolio, Buildium, Yardi) fingerprints.
  • WordPress and SaaS stack recon: Includes checks for CORS credential reflection, unauthenticated REST API endpoints, exposed debug logs, and vulnerable plugins common to property management sites.
  • Field-validated workflows: Built from a 20-target batch recon across US property management companies, with real-world examples of common findings like exposed lease PDFs with tenant SSNs and unauthenticated property data APIs. Use case: A pentester scoping a property management firm can use this skill to quickly locate exposed tenant portals and debug logs containing sensitive financial data without manual trial-and-error of generic recon tools.

Quick Start

Use the recon-property-management skill to conduct a complete sector-specific recon against a target property management company domain, including tenant portal discovery, WordPress vulnerability checks, and maintenance request endpoint enumeration.

Frequently Asked Questions about recon-property-management

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed tenant PII and unauthenticated APIs during property management website recon?

Property management recon identifies exposed tenant PII by discovering unauthenticated property listing APIs, maintenance request endpoints, and debug logs containing sensitive tenant financial and personal data.

What specific vulnerabilities should I look for in AppFolio, Buildium, and Yardi tenant portals?

For AppFolio, Buildium, and Yardi tenant portals, check for CORS credential reflection, unauthenticated REST API endpoints, exposed lease PDFs with tenant SSNs, and sector-specific plugin vulnerabilities.

Does this recon workflow work on custom PHP real estate stacks or only WordPress property sites?

This recon workflow works on both WordPress property sites and custom PHP real estate stacks, targeting tenant portals, property listing APIs, and maintenance request systems across diverse platforms.

How do I locate exposed maintenance request systems and debug logs on apartment rental websites?

Locate exposed maintenance request systems and debug logs on apartment rental websites by applying targeted discovery workflows that fingerprint common property management software and check for unauthenticated endpoints.

Why do generic recon workflows miss vulnerabilities on real estate management company websites?

Generic recon workflows miss real estate management vulnerabilities because they lack targeted discovery for niche platforms, tenant portal attack surfaces, and property listing APIs that store sensitive tenant PII.

Can I use this to enumerate unauthenticated property data APIs and WordPress plugin vulnerabilities?

Yes, you can enumerate unauthenticated property data APIs and check for WordPress plugin vulnerabilities common to property management sites, including CORS credential reflection and exposed debug logs.