Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
lulzbuster — أداة متعددة الخيوط، سريعة جدًا وذكية لتخمين الدلائل والملفات عبر HTTP(S)، مكتوبة بلغة C فوق مكتبة libcurl | Kitploit
أدوات/GitHubGitHub/noptrix/lulzbuster
الاستطلاعماسحات الثغرات الأمنية للويبجمع المعلوماتأمن الويبالاختبار العشوائياختبار الاختراق
GitHubnoptrix/lulzbuster

lulzbuster

أداة متعددة الخيوط، سريعة جدًا وذكية لتخمين الدلائل والملفات عبر HTTP(S)، مكتوبة بلغة C فوق مكتبة libcurl

عرض المستودع
14121منذ شهر واحدتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
الموقع الإلكتروني

الوصف

أداة متعددة الخيوط، سريعة جدًا وذكية لفحص الدلائل والملفات عبر HTTP(S) مكتوبة بلغة C باستخدام libcurl.

باستخدام عنوان URL مستهدف وقائمة كلمات، تقوم بتعداد المسارات الصالحة عبر إرسال طلبات HTTP متزامنة والإبلاغ عن الردود التي تبدو وكأنها نتائج حقيقية (أي رموز الحالة التي لم يستبعدها المستخدم).

وهي موجهة لمختبر الاختراق، صائدي الثغرات، ومشاركي CTF الذين يريدون أداة صغيرة وسريعة وقابلة للتشغيل عبر النصوص وتقوم بشيء واحد بشكل جيد.

الاستخدام

root@kitploit:~
$ lulzbuster -H
    __      __      __               __
   / /_  __/ /___  / /_  __  _______/ /____  _____
  / / / / / /_  / / __ \/ / / / ___/ __/ _ \/ ___/
 / / /_/ / / / /_/ /_/ / /_/ (__  ) /_/  __/ /
/_/\__,_/_/ /___/_.___/\__,_/____/\__/\___/_/

        --==[ by nullsecurity.net ] ==--

usage

  lulzbuster -s <arg> [opts] | <misc>

target options

  -s <url>       - start url to begin scan with

http options

  -h <type>      - http request type (default: GET) - ? to list types
  -x <code>      - exclude http status codes (default: 400,404,500,501,502,503
                   multi codes separated by ',')
  -f             - follow http redirects. hint: better try appending a '/'
                   with '-A' option first instead of using '-f'
  -F <num>       - num level to follow http redirects (default: -1 = unlimited)
  -u <str>       - user-agent string (default: built-in windows edge)
  -U             - use random built-in user-agents
  -c <str>       - pass custom header(s) (e.g. 'Cookie: foo=bar; lol=lulz')
  -a <creds>     - http auth credentials (format: <user>:<pass>)
  -r             - turn on auto update referrer
  -j <num>       - define http version (default: curl's default) - ? to list

tls options

  -i             - insecure mode (skips ssl/tls cert verification)
  -E <file>      - client cert file (PEM) for mTLS
  -y <file>      - client key file (PEM) for mTLS
  -Y <pass>      - passphrase for an encrypted client key

timeout options

  -D <num>       - num seconds for delay between requests (default: 0)
  -C <num>       - num seconds for connect timeout (default: 10)
  -R <num>       - num seconds for request timeout (default: 30)
  -T <num>       - num seconds to give up and exit lulzbuster completely
                   (default: none)

tuning options

  -t <num>       - num threads for concurrent scanning (default: 35)
  -g <num>       - per-thread connection cache size for curl (default: 35)
                   note: each worker thread keeps its own cache; 1 conn
                   per host suffices, higher only helps across many hosts

wordlist options

  -w <file>      - wordlist file
                   (default: /usr/local/share/lulzbuster/lists/medium.txt)
  -A <str>       - append any words separated by comma (e.g. '/,.php,~bak)

proxy options

  -p <addr>      - proxy address (format: <scheme>://<host>:<port>) - ? to
                   list supported schemes
  -P <creds>     - proxy auth credentials (format: <user>:<pass>)

body filter options

  -m <size>      - skip hits with body smaller than <size> bytes.
                   suffix K/M/G accepted (e.g. 100, 10K, 5M)
  -M <size>      - skip hits with body bigger than <size> bytes.
                   suffix K/M/G accepted (e.g. 1M, 1G)
  -b <regex>     - keep only hits whose body matches the POSIX extended
                   regex (e.g. 'admin|login'). evaluated on first ~1MB
                   of body. complements -x (codes) and -m/-M (size)
  -B <regex>     - drop hits whose body matches the POSIX extended
                   regex (e.g. 'page not found'). useful against CMS
                   targets that return custom 200 'soft 404' pages

smart options

  -S             - smart mode aka: eliminate false-positives, show more
                   infos, etc. use this if speed is not your 1st priority!
  -K <num>       - smart mode cluster threshold (default: 8). after N
                   hits with same (code, size_bucket) further matches
                   are suppressed as wildcard noise

recursion options

  -d <num>       - max recursion depth (default: 0 = no recursion).
                   recurses into hits ending with '/' that returned
                   200/301/302/401/403
  -e <str>       - paths to exclude from recursion (substring match)
                   multi separated by ',' (e.g. '/admin/,logout')

output options

  -l <file>      - log hits to file. with single -O format the path
                   is used exact; with multiple formats the path is
                   a stem and '.<ext>' is appended per format. without
                   -O the format defaults to 'log' (text)
  -O <fmts>      - opt in to logging and pick format(s): 'log', 'csv',
                   'jsonl', 'all' or comma-list (e.g. 'log,jsonl').
                   without -l each format gets an auto-derived name
                   (e.g. https-www-nullsecurity-net_foo.<ext>)
  -N             - disable colored output (also auto-disabled when not
                   on a TTY or when NO_COLOR env var is set)

other options

  -n <str>       - nameservers (default: '1.1.1.1,8.8.8.8,208.67.222.222'
                   multi separated by ',')
  -z <file>      - resume from a session file written on prev ctrl+c
                   (only level 0 saves are supported)

misc

  -X             - print built-in user-agents
  -V             - print version of lulzbuster and exit
  -H             - print this help and exit

المؤلف

noptrix

ملاحظات

كود نظيف؛ مشروع حقيقي lulzbuster معبأ ومتوفر بالفعل لـ BlackArch Linux فروع master لدي دائمًا مستقرة؛ يتم إنشاء فروع dev للعمل الحالي. جميع محتوياتي العامة التي تجدها يتم الإعلان عنها رسميًا ونشرها عبر nullsecurity.net.

الترخيص

راجع docs/LICENSE.

إخلاء مسؤولية

نؤكد هنا أن المحتويات المتعلقة بالاختراق الموجودة على nullsecurity.net مخصصة فقط للأغراض التعليمية. لسنا مسؤولين عن أي أضرار. أنت مسؤول عن أفعالك الخاصة.

تنزيل الأداة