当前位置:网站首页>Rad+xray vulnerability scanning tool
Rad+xray vulnerability scanning tool
2022-07-03 19:47:00 【There is no longer a lingering setting sun】
rad full name Radium
rad It is also a directory crawling tool developed for Changting Technology ,
So combine rad It can automatically crawl more efficiently . Be careful rad Just crawl the directory of the target , Do not crawl subdomains .
Download address
https://github.com/chaitin/rad
Basic use
Google browser should be installed in advance , To use this tool .
rad -t http://example.com
When you need to log in manually
rad -t http://example.com -wait-login
Executing the above command will automatically disable headless browsing mode , Open a browser for manual login . After logging in, click enter on the command line interface to continue crawling .
rad -t http://example.com -text-output vuln.txt
The above command will climb to URL Output to vuln.txt in
Export complete request
rad -t http://example.com -full-text-output result.txt
The perfect syntax is as follows
rad_windows_amd64.exe -t http://example.com -text-output vuln.txt -wait-login
xray Scanner
It is a community version vulnerability scanning artifact extracted from the Changting Dongjian core engine ,
Support initiative 、 Passive multiple scanning modes , Own blind printing platform 、 Flexible definition of POC, Rich functions and simple calls ,
Support Windows / macOS / Linux Multiple operating systems , It can meet the automation of safety practitioners Web Vulnerability detection requirements .
Download address
https://github.com/chaitin/xray
Basic usage
Use the basic crawler to crawl and scan the links crawled by the crawler , I usually scan actively
xray webscan --basic-crawler http://www.baidu.com --html-output 1.html
Use HTTP Agent performs passive scanning , Browser proxy to xray, You can scan
xray webscan --listen 127.0.0.1:7777 --html-output 2.html
Scan only a single url, Do not use crawlers
xray webscan --url http://example.com/?a=b --html-output 3.html
Manually specify the plug-in to run this time
In case of recognition , All built-in plug-ins will be enabled , You can use the following command to specify the plug-ins enabled for this scan .
The following specifications are injection plug-ins
xray webscan --plugins cmd-injection,sqldet --url http://example.com
xray webscan --plugins cmd-injection,sqldet --listen 127.0.0.1:7777
rad+xray Efficient scanning
rad High speed crawler agent to xray Realize fast scanning
Reptiles are xray Weaknesses , adopt rad You can achieve more efficient scanning
xray Enable agent monitoring
xray_windows_amd64.exe webscan --listen 127.0.0.1:7777 --html-output proxy.html
rad Climb the target , Proxy to xray On
rad_windows_amd64.exe -t http://www.baidu.com -http-proxy 127.0.0.1:7777 -wait-login
边栏推荐
- What is the difference between a kill process and a close process- What are the differences between kill process and close process?
- 2022 - 06 - 30 networker Advanced (XIV) Routing Policy Matching Tool [ACL, IP prefix list] and policy tool [Filter Policy]
- 第一章:求同吗小数和s(d, n)
- How to improve data security by renting servers in Hong Kong
- Chapter 1: simplify the same code decimal sum s (D, n)
- Chapter 1: sum of three factorials, graph point scanning
- BUUCTF
- Redis master-slave synchronization, clustering, persistence
- unittest框架基本使用
- Acquisition and transmission of parameters in automatic testing of JMeter interface
猜你喜欢
Phpstudy set LAN access
Use of aggregate functions
Acquisition and transmission of parameters in automatic testing of JMeter interface
2022-06-30 网工进阶(十四)路由策略-匹配工具【ACL、IP-Prefix List】、策略工具【Filter-Policy】
QT -- qfile file read / write operation
第一章:拓广同码小数和s(d, n)
Part 28 supplement (XXVIII) busyindicator (waiting for elements)
2022 Xinjiang latest road transportation safety officer simulation examination questions and answers
第二章:基于分解的求水仙花数,基于组合的求水仙花数, 兰德尔数,求[x,y]内的守形数,探求n位守形数,递推探索n位逐位整除数
01 - QT OpenGL display OpenGL window
随机推荐
2022-06-28 advanced network engineering (XIII) IS-IS route filtering, route summary, authentication, factors affecting the establishment of Isis neighbor relations, other commands and characteristics
6. Data agent object Defineproperty method
第二章:求a,b的最大公约与最小公倍数经典求解,求a,b的最大公约与最小公倍数常规求解,求n个正整数的的最大公约与最小公倍数
Kubernetes cluster builds efk log collection platform
kubernetes集群搭建efk日志收集平台
第一章: 舍罕王失算
第一章: 舍罕王失算
04 -- QT OpenGL two sets of shaders draw two triangles
交叉编译Opencv带Contrib
Make a simple text logo with DW
PR 2021 quick start tutorial, material import and management
Zhang Fei hardware 90 day learning notes - personal record on day 5. Please see my personal profile / homepage for the complete record
February 14-20, 2022 (osgear source code debugging +ue4 video +ogremain source code transcription)
Bool blind note - score query
2022-06-27 advanced network engineering (XII) IS-IS overhead type, overhead calculation, LSP processing mechanism, route revocation, route penetration
Compared with 4G, what are the advantages of 5g to meet the technical requirements of industry 4.0
Rd file name conflict when extending a S4 method of some other package
第二章:4位卡普雷卡数,搜索偶数位卡普雷卡数,搜索n位2段和平方数,m位不含0的巧妙平方数,指定数字组成没有重复数字的7位平方数,求指定区间内的勾股数组,求指定区间内的倒立勾股数组
Meso tetra [P - (p-n-carbazole benzylidene imino)] phenylporphyrin (tcipp) /eu (tcipp) [pc( α- 2-oc8h17) 4] and euh (tcipp) [pc (a-2-oc8h17) 4] supplied by Qiyue
NFT without IPFs and completely on the chain?