当前位置:网站首页>[download attached] several scripts commonly used in penetration testing that are worth collecting
[download attached] several scripts commonly used in penetration testing that are worth collecting
2022-07-23 14:26:00 【Network security self-study room】
1.dirsearch Directory scanning 2.OneForAll-master Asset collection 3.sqlmap 4.awvs Batch scan 5.ip decode
Be careful : Install your computer before using it python2x and python3x Environment .
At the end of the article, get all the script Baidu cloud download links
dirsearch Directory scanning
Dirsearch Is a probe WEB Sensitive files under the server / Directory command line tools .

Input cmd

The order is as follows
Python dirsearch.py -u https://www.baidu.com/ -e * -x 999
The generated directory will be in the folder resports in .
OneForAll-master Asset collection
Powerful feature collection capability , Please read the description of the collection module for detailed modules
Use certificate transparency to collect subdomains ( There are 6 A module :censys_api,certdb_api,certspotter,crtsh,entrust,google)
General check collection subdomain ( There are 4 A module : Domain transport exploit axfr, Check the cross domain policy file cdx, Check HTTPS certificate cert, Check the content security policy csp, Check robots file robots, Check sitemap file sitemap, Check will be added later NSEC Record ,NSEC3 Record and other modules )- Use web crawler files to collect subdomains ( There are 2 A module :archivecrawl,commoncrawl, This module is still being debugged , The module needs to be added and improved )
utilize DNS Data set collection sub domain ( There are 16 A module :binaryedge_api, circl_api, hackertarget, riddler, bufferover, dnsdb, ipv4info, robtex, chinaz, dnsdb_api, netcraft, securitytrails_api, chinaz_api, dnsdumpster, ptrarchive, sitedossier)
utilize DNS Query collection sub domain ( There are 1 A module : By enumerating common SRV Record and query to collect subdomains srv, The module needs to be added and improved )
Use threat intelligence platform data collection sub domain ( There are 5 A module :riskiq_api,threatbook_api,threatminer,virustotal,virustotal_api The module needs to be added and improved )
Use search engines to find subdomains ( There are 15 A module :ask, bing_api, fofa_api, shodan_api, yahoo, baidu, duckduckgo, google, so, yandex, bing, exalead, google_api, sogou, zoomeye_api), In the search module, except for special search engines , General search engines support automatic exclusion of search , Full search , Recursively searching .
Powerful processing function , The subdomain results found support automatic removal , Automatically DNS analysis ,HTTP Request detection , Automatically remove invalid subdomains , Expand the of subdomains Banner Information , The final supported export formats are csv, tsv, json, yaml, html, xls, xlsx, dbf, latex, ods.
Speed is extremely fast , The collection module uses multithreaded calls , The blasting module uses asynchronous multiprocess multiprocess ,DNS Analytic and HTTP The request uses asynchronous multiprocessing .


The order is as follows
python oneforall.py --target https://www.baidu.com run
Will be in results Create a .csv file , You can see the port number , Subdomain name and other information , Very easy to use .
sqlmap

The order is as follows
python sqlmap.py -u https://www.baidu.com?id=1 --batch --level 3 --risk 3 -dbs

Here are some commonly used sqlmap Injection order

awvs Batch scan
When our asset collection is complete , You can copy the collected subdomain names to a txt In the document

The order is as follows
python awvs.py -f ./4.txt

These two directories will be imported into awvs in , Start automatic scanning .
Common commands
view help
python awvs.py -h
Add a target and scan -u
python awvs.py -u https://www.baidu.com
Read text and scan -f
python awvs.py -f ./4.txt
Delete all targets and scanning tasks -d
python awvs.py -d
ip decode
If you encounter internal ip Address disclosure vulnerability , You may need to check the... In the caught bag ip decode , Here's the picture .

The order is as follows
python 1.py 3557624597.7033.0000

Reference material
[1] Collection module description :https%3A//github.com/shmilylty/OneForAll/docs/collection_modules.md*
[2] Collection module :https%3A//github.com/shmilylty/OneForAll/oneforall/collect.py*
[3] Blasting module :https%3A//github.com/shmilylty/OneForAll/oneforall/aiobrute.py*
边栏推荐
- [baiqihang] Niuer education helps colleges and universities visit enterprises, expand posts and promote employment
- What level is the notebook core i5 1135g7 equivalent to? How about i5 1135g7 performance
- Canvas eraser function
- What is Tianji 920 equivalent to a snapdragon? How much is Tianji 920 equivalent to a snapdragon? How about Tianji 920
- Pagehepler lost the pit of the original SQL order by condition
- How to judge whether an object is empty
- Pacific Atlantic current problem
- Shell实践:一键启动进程、关闭进程、查看进程状态
- Okrk3399 Development Board Reserved i2c4 Mounting EEPROM
- Rtx3080ti and rtx3080 gap 3080 and 3080ti parameter comparison
猜你喜欢

Rtx3080ti and rtx3080 gap 3080 and 3080ti parameter comparison
![[baiqihang] Niuer education helps colleges and universities visit enterprises, expand posts and promote employment](/img/41/6ef8f24732d9c75046ca8c55fd4841.png)
[baiqihang] Niuer education helps colleges and universities visit enterprises, expand posts and promote employment

What level is rtx3090ti? What level is rtx3090ti graphics card? How about rtx3090ti graphics card

Is machine learning difficult to get started? Tell me how I started machine learning quickly!

ValidationError: Invalid options object. Dev Server has been initialized using an options object th

鸡与蛋,产品与策略

ArcGIS uses DEM data to delineate the specific steps and processes of catchment area

Day 12 notes

STM32 outputs SPWM wave, Hal library, cubemx configuration, and outputs 1kHz sine wave after filtering

What is Tianji 920 equivalent to a snapdragon? How much is Tianji 920 equivalent to a snapdragon? How about Tianji 920
随机推荐
Stream stream is used for classification display.
VK36N5D抗电源干扰/手机干扰 5键5通道触摸检测芯片防呆功能触摸区域积水仍可操作
JS realize random generation of UUID
Rtx3080 is equivalent to GTX. What kind of graphics card is rtx3080? What level is rtx3080
Canvas eraser function
Drag and drop----
求岛屿最大面积--深度优先搜索(染色法)
Towhee 每周模型
How many processors is Tianji 820 equivalent to Xiaolong? How about Tianji 1100 equivalent to Xiaolong? How about Tianji 820
How do FPGA engineers design complex systems?
链下数据互操作
Comparison of iqoo 10 pro and Xiaomi 12 ultra configurations
子序列 --- 编辑距离
How about the performance of Intel Celeron 7305? What level is it equivalent to
Shell实践:一键启动进程、关闭进程、查看进程状态
ArcGIS使用DEM数据划定汇水区具体步骤过程
How about the nuclear display performance of Ruilong R7 Pro 6850h? What level is it equivalent to
LabVIEW运行中改变Chart的历史长度
Uiscrollview (uicollectionview) prohibits horizontal and vertical sliding at the same time
接口interface