Posts

Showing posts with the label Scanner

Scannerl - The Modular Distributed Fingerprinting Engine

Image
Scannerl is a modular distributed fingerprinting engine implemented past times Kudelski Security . Scannerl tin give the axe fingerprint thousands of targets on a unmarried host, but tin give the axe precisely every bit easily last distributed across multiple hosts. Scannerl is to fingerprinting what zmap is to port scanning. Scannerl industrial plant on Debian/Ubuntu/Arch (but volition likely locomote on other distributions every bit well). It uses a master/slave architecture where the master copy node volition distribute the locomote (host(s) to fingerprint) to its slaves (local or remote). The entire deployment is transparent to the user. Why job Scannerl When using conventional fingerprinting tools for large-scale analysis, safety researchers volition oftentimes hitting 2 limitations: first, these tools are typically built for scanning comparatively few hosts at a fourth dimension as well as are inappropriate for large ranges of IP addresses. Second, if large hit of IP...

Docker-Inurlbr - Advanced Search Inwards Search Engines, Enables Analysis Provided To Exploit Leave Of Absence / Post Capturing Emails & Urls

Image
Advanced search inward search engines, enables analysis provided to exploit GET / POST capturing emails & urls, alongside an internal custom validation junction for each target / url found. How to build git clone https://github.com/gmdutra/docker-inurlbr.git cd docker-inurlbr docker create -t gmdutra/inurlbr . Run docker run --name inurlbr -it -d gmdutra/inurlbr HELP: -h --help Alternative long length care command. --ajuda Command to specify Help. --info Information script. --update Code update. -q Choose which search engine you lot desire through [1...24] / [e1..6]]: [options]: 1 - GOOGLE / (CSE) GENERIC RANDOM / API two - BING three - YAHOO BR 4 - ASK v - HAO123 BR six - GOOGLE (API) seven - LYCOS 8 - UOL BR nine - YAHOO the States 10 - SAPO xi - DMOZ 12 - GIGABLAST xiii - NEVER fourteen - BAIDU BR xv - YANDEX xvi - ZOO 17 - HOTBOT ...

Deepsearch - Advanced Spider Web Dir Scanner

Image
DeepSearch is a uncomplicated command line tool for bruteforce directories as well as files inwards websites. Installation $ git clone https://github.com/m4ll0k/DeepSearch.git deepsearch $ cd deepsearch $ pip3 install requests $ python3 deepsearch.py Screenshots Usage Basic: python3 deepsearch.py -u http://testphp.vulnweb.com/ -e php -w wordlist.txt Force extension for every wordlist entry (support 1 extension): python3 deepsearch.py -u http://testphp.vulnweb.com/ -e php -w wordlist.txt -f Make a asking past times hostname (ip): python3 deepsearch.py -u http://testphp.vulnweb.com/ -e php -w wordlist.txt -b Force lowercase for every wordlist entry: python3 deepsearch.py -u http://testphp.vulnweb.com/ -e php -w wordlist.txt -l Force upper-case alphabetic lineament for every wordlist entry: python3 deepsearch.py -u http://testphp.vulnweb.com/ -e php -w wordlist.txt -p Show alone condition code separated past times comma: python3 deepsearch.py -u http:/...

Nodejsscan - A Static Safety Code Scanner For Node.Js Applications

Image
Static safety code scanner (SAST) for Node.js applications. Configure & Run NodeJsScan Install Postgres as well as configure SQLALCHEMY_DATABASE_URI inwards core/settings.py pip3 install -r requirements.txt python3 migrate.py # Run 1 time to practise database entries required python3 app.py # Testing Environment gunicorn -b 0.0.0.0:9090 app:app # Production Environment This volition run NodeJsScan on http://0.0.0.0:9090 If you lot take away to debug, gear upwardly DEBUG = True inwards core/settings.py NodeJsScan CLI The command line interface (CLI) allows you lot to integrate NodeJsScan amongst DevSecOps CI/CD pipelines. The results are inwards JSON format. When you lot usage CLI the results are never stored amongst NodeJsScan backend. virtualenv venv -p python3 source venv/bin/activate (venv)pip install nodejsscan (venv)$ nodejsscan usage: nodejsscan [-h] [-f FILE [FILE ...]] [-d DIRECTORY [DIRECTORY ...]] [-o OUTPUT] [-v] optional arguments: ...

Zip File Raider - Burp Extension For Zilch File Payload Testing

Image
ZIP File Raider is a Burp Suite extension for attacking spider web application amongst ZIP file upload functionality. You tin easily inject Burp Scanner/Repeater payloads inwards ZIP content of the HTTP requests which is non viable yesteryear default. This extension helps to automate the extraction in addition to compression steps. This software was created yesteryear Natsasit Jirathammanuwat during a cooperative pedagogy course of instruction at King Mongkut's University of Technology Thonburi (KMUTT). Installation Set upward Jython standalone Jar inwards Extender > Options > Python Environment > "Select file...". Add ZIP File Raider extension inwards Extender > Extensions > Add > CompressedPayloads.py (Extension type: Python) How to use Send the HTTP asking amongst a compressed file to the ZIP File Raider First, correct click on the HTTP asking amongst a compressed file inwards HTTP trunk in addition to and therefore direct "Sen...

Sn1per V6.0 - Automated Pentest Framework For Offensive Safety Experts

Image
Sn1per Community Edition is an automated scanner that tin travel used during a penetration test to enumerate as well as scan for vulnerabilities. Sn1per Professional is Xero Security's premium reporting addon for Professional Penetration Testers, Bug Bounty Researchers as well as Corporate Security teams to deal large environments as well as pentest scopes. SN1PER PROFESSIONAL FEATURES: Professional reporting interface Slideshow for all gathered screenshots Searchable as well as sortable DNS, IP as well as opened upwardly port database Categorized host reports Quick links to online recon tools as well as Google hacking queries Personalized notes champaign for each host DEMO VIDEO: SN1PER COMMUNITY FEATURES:  Automatically collects basic recon (ie. whois, ping, DNS, etc.)  Automatically launches Google hacking queries against a target domain  Automatically enumerates opened upwardly ports via NMap port scanning  Auto...

Dawnscanner - Dawn Is A Static Analysis Safety Scanner For Cherry-Red Written Spider Web Applications (Sinatra, Padrino In Addition To Ror Frameworks)

Image
dawnscanner is a source code scanner designed to review your ruby code for safety issues. dawnscanner is able to scan manifestly ruby scripts (e.g. command trace applications) but all its features are unleashed when dealing amongst spider web applications source code. dawnscanner is able to scan major MVC (Model View Controller) frameworks, out of the box: Ruby on Rails Sinatra Padrino Quick update from November, 2018 As yous tin run into dawnscanner is on concord since to a greater extent than together with thus an year. Sorry for that. It's life. I was overwhelmed past times tons of materials together with I dedicated gratis fourth dimension to Offensive Security certifications. True to hold out told, I'm starting OSCE journeying truly soon. The dawnscanner projection volition hold out updated shortly amongst novel safety checks together with kickstarted again. Paolo dawnscanner version 1.6.6 has 235 safety checks loaded inwards its cognition base. M...

Jackhammer - I Safety Vulnerability Assessment/Management Tool To Solve All The Safety Squad Problems

Image
One Security vulnerability assessment/management tool to solve all the safety squad problems. What is Jackhammer? Jackhammer is a collaboration tool built amongst an aim of bridging the gap betwixt Security squad vs dev team, QA squad in addition to existence a facilitator for TPM to empathize in addition to rails the character of the code going into production. It could create static code analysis in addition to dynamic analysis amongst inbuilt vulnerability management capability. It finds safety vulnerabilities inwards the target applications in addition to it helps safety teams to grapple the chaos inwards this novel historic stream of continuous integration in addition to continuous/multiple deployments. It completely industrial plant on RBAC (Role Based Access Control). There are cool dashboards for private scans in addition to squad scans giving ample flexibility to collaborate amongst dissimilar teams. It is totally built on pluggable architecture which tin live on ...

W3brute - Automatic Spider Web Application Fauna Forcefulness Educate On Tool

Image
w3brute is an opened upward source penetration testing tool that automates attacks straight to the website's login page. w3brute is also supported for carrying out brute forcefulness attacks on all websites. Features Scanner: w3brute has a scanner characteristic that serves to back upward the bruteforce attack process. this is a listing of available scanners: automatically detects target authentication type. admin page scanner. SQL injection scanner vulnerability. Attack Method: w3brute tin assault using diverse methods of attack. this is a listing of available assault methods: SQL injection bypass authentication mixed credentials (username + SQL injection queries) Support: multiple target google dorking a listing of supported spider web interface types to attack: web shell HTTP 401 UNAUTHORIZED ( Basic as well as Digest ) create file results brute force attack. supported file format type: CSV (default) HTML SQLITE3 cust...