Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
feroxfuzz — ابنِ أدوات اختبار تشويش (Fuzzing) لبروتوكول HTTP بأسلوب الصندوق الأسود تراعي بنية البيانات في Rust، مع محولات (Mutators) ومجدولات (Schedulers) ومراقبين (Observers) ومقررات (Deciders) ومعالجات (Processors) قابلة للتركيب، لإجراء اختبارات مخصصة للويب وواجهات برمجة التطبيقات (API). | Kitploit
أدوات/GitHubGitHub/epi052/feroxfuzz
اختبار أمان APIأمن الويبالاختبار العشوائيالأدوات والمكونات
GitHubepi052/feroxfuzz

feroxfuzz

ابنِ أدوات اختبار تشويش (Fuzzing) لبروتوكول HTTP بأسلوب الصندوق الأسود تراعي بنية البيانات في Rust، مع محولات (Mutators) ومجدولات (Schedulers) ومراقبين (Observers) ومقررات (Deciders) ومعالجات (Processors) قابلة للتركيب، لإجراء اختبارات مخصصة للويب وواجهات برمجة التطبيقات (API).

عرض المستودع
2231917منذ 8 أشهرتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة


🚀 FeroxFuzz 🚀

مكتبة Fuzzing لـ HTTP واعية بالبنية


🤔 فيروكس آخر؟ لماذا؟ 🤔

اهدأ، إنها ليست أداة سطر أوامر أخرى، هذه المرة مكتبة! 😁

بتعبير أدق، FeroxFuzz هي مكتبة Fuzzing لـ HTTP واعية بالبنية.

كان الهدف الأساسي من كتابة FeroxFuzz هو نقل بعض المكوّنات الأساسية من feroxbuster إلى مكان يمكن أن تكون فيه مفيدة بشكل عام للآخرين. ومن خلال ذلك، آمل أن يتمكن أي شخص يرغب في كتابة أدوات ويب و/أو أدوات Fuzzing ويب لمرة واحدة بلغة Rust من القيام بذلك بأقل جهد ممكن.

التصميم

التصميم العام لـ FeroxFuzz مستمد من LibAFL. تنفذ FeroxFuzz معظم المكوّنات المذكورة في LibAFL: A Framework to Build Modular and Reusable Fuzzers (pre-print). وعندما تحيد FeroxFuzz عن ذلك، فعادةً ما يكون السبب هو دعم الكود غير المتزامن (async).

على غرار LibAFL، تُعد FeroxFuzz مكتبة Fuzzing قابلة للتركيب (composable). ومع ذلك، وعلى عكس LibAFL، تركز FeroxFuzz حصريًا على Fuzzing HTTP بالصندوق الأسود (black box).

تدفق تنفيذ حلقة Fuzz

فيما يلي تمثيل مرئي للمكوّنات المختلفة والخطافات (hooks) وتدفق التحكم التي تستخدمها FeroxFuzz.

fuzz-flow

🚧 تحذير: قيد الإنشاء 🚧

تتمتع FeroxFuzz بقدرات كبيرة، وقد صُنعت لتلائم جميع احتياجاتي المخطط لها لنسخة جديدة من feroxbuster. ومع ذلك، ما زلت أتوقع أن تتغير واجهة برمجة التطبيقات (API) الخاصة بـ FeroxFuzz، ولو بشكل طفيف، مع بدء العمل على النسخة الجديدة من feroxbuster.

حتى تستقر واجهة API، ستحدث تغييرات جذرية قد بالتأكيد.

البدء

أسهل طريقة للبدء هي تضمين FeroxFuzz في ملف Cargo.toml الخاص بمشروعك.

[dependencies]
feroxfuzz = { version = "1.0.0-rc.13" }

التوثيق

بالإضافة إلى مجلد examples/، تحتوي وثائق API على توثيق شامل للمكوّنات إلى جانب أمثلة على استخدامها.

  • وثائق API الخاصة بـ FeroxFuzz: وثائق API الخاصة بـ FeroxFuzz، والتي يتم إنشاؤها تلقائيًا من تعليقات التوثيق في هذا المستودع.
  • الأمثلة الرسمية: أمثلة FeroxFuzz المخصصة والقابلة للتشغيل، وهي رائعة للتعمق في مفاهيم محددة ومليئة بالتعليقات.

مثال

المثال أدناه (examples/async-simple.rs) يوضح الحد الأدنى لكتابة أداة Fuzzer باستخدام FeroxFuzz.

إذا كنت تستخدم الكود المصدري، يمكن تشغيل المثال من دليل feroxfuzz/ باستخدام الأمر التالي:

ملاحظة: ما لم يكن لديك خادم ويب يعمل على جهازك على المنفذ 8000، فستحتاج إلى تغيير الهدف المُمرَّر في Request::from_url

cargo run --example async-simple
#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    // create a new corpus from the given list of words
    let words = Wordlist::from_file("./examples/words")?
        .name("words")
        .build();

    // pass the corpus to the state object, which will be shared between all of the fuzzers and processors
    let mut state = SharedState::with_corpus(words);

    // bring-your-own client, this example uses the reqwest library
    let req_client = reqwest::Client::builder().build()?;

    // with some client that can handle the actual http request/response stuff
    // we can build a feroxfuzz client, specifically an asynchronous client in this
    // instance.
    //
    // feroxfuzz provides both a blocking and an asynchronous client implementation
    // using reqwest. 
    let client = AsyncClient::with_client(req_client);

    // ReplaceKeyword mutators operate similar to how ffuf/wfuzz work, in that they'll
    // put the current corpus item wherever the keyword is found, as long as its found
    // in data marked fuzzable (see ShouldFuzz directives below)
    let mutator = ReplaceKeyword::new(&"FUZZ", "words");

    // fuzz directives control which parts of the request should be fuzzed
    // anything not marked fuzzable is considered to be static and won't be mutated
    //
    // ShouldFuzz directives map to the various components of an HTTP request
    let request = Request::from_url(
        "http://localhost:8000/?admin=FUZZ",
        Some(&[ShouldFuzz::URLParameterValues]),
    )?;

    // a `StatusCodeDecider` provides a way to inspect each response's status code and decide upon some Action
    // based on the result of whatever comparison function (closure) is passed to the StatusCodeDecider's
    // constructor
    //
    // in plain english, the `StatusCodeDecider` below will check to see if the request's http response code
    // received is equal to 200/OK. If the response code is 200, then the decider will recommend the `Keep`
    // action be performed. If the response code is anything other than 200, then the recommendation will
    // be to `Discard` the response.
    //
    // `Keep`ing the response means that the response will be allowed to continue on for further processing
    // later in the fuzz loop.
    let decider = StatusCodeDecider::new(200, |status, observed, _state| {
        if status == observed {
            Action::Keep
        } else {
            Action::Discard
        }
    });

    // a `ResponseObserver` is responsible for gathering information from each response and providing
    // that information to later fuzzing components, like Processors. It knows things like the response's
    // status code, content length, the time it took to receive the response, and a bunch of other stuff.
    let response_observer: ResponseObserver<AsyncResponse> = ResponseObserver::new();

    // a `ResponseProcessor` provides access to the fuzzer's instance of `ResponseObserver`
    // as well as the `Action` returned from calling `Deciders` (like the `StatusCodeDecider` above).
    // Those two objects may be used to produce side-effects, such as printing, logging, calling out to
    // some other service, or whatever else you can think of.
    let response_printer = ResponseProcessor::new(
        |response_observer: &ResponseObserver<AsyncResponse>, action, _state| {
            if let Some(Action::Keep) = action {
                println!(
                    "[{}] {} - {} - {:?}",
                    response_observer.status_code(),
                    response_observer.content_length(),
                    response_observer.url(),
                    response_observer.elapsed()
                );
            }
        },
    );
تنزيل الأداة