Skip to content
KitploitKITPLOIT
أدواتالمدونة
Log in
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
أدوات/GitHubGitHub/nu11secur1ty/insect
الاستطلاعماسحات الثغرات الأمنيةجمع المعلوماتأمن الويبالاختبار العشوائياختبار الاختراق
GitHubnu11secur1ty/insect

insect

أداة عالية الأداء لاكتشاف مسارات الويب وفرض القوة الغاشمة على الدلائل. تكتشف الملفات والدلائل ونقاط النهاية المخفية باستخدام قوائم كلمات قابلة للتخصيص وفلاتر وفحص تكراري لاختبار الاختراق.

عرض المستودع
151منذ 3 سنواتلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

insect - اكتشاف مسارات الويب

الإصدار الحالي: v1.4 (20222.09.03)

أداة سطر أوامر متقدمة مصممة لتخمين الدلائل والملفات في خوادم الويب، وتُعرف أيضًا باسم ماسح مسارات الويب

الفكرة بواسطة @maurosoria و@shelld3v

Developement-2022 يتم تطويره بنشاط بواسطة @nu11secur1ty

جدول المحتويات

  • التثبيت
  • قوائم الكلمات
  • الخيارات
  • الإعدادات
  • كيفية الاستخدام
    • الاستخدام البسيط
    • إيقاف التقدم مؤقتًا
    • العودية
    • الخيوط
    • البادئات / اللواحق
    • القائمة السوداء
    • المرشحات
    • طلب خام
    • صيغ قوائم الكلمات
    • استبعاد الامتدادات
    • فحص الدلائل الفرعية
    • البروكسيات
    • التقارير
    • مزيد من أمثلة الأوامر
  • دعم Docker
    • تثبيت Docker على لينكس
    • بناء صورة insect
    • استخدام insect
  • المراجع
  • نصائح
  • المساهمة
  • الترخيص

الأدوات:

  • Attack-Modules-2022

التثبيت والاستخدام

المتطلب: python 3.10.5 أو أحدث

اختر أحد خيارات التثبيت التالية:

  • التثبيت عبر git: git clone https://github.com/nu11secur1ty/insect.git --depth 1 (موصى به)
  • التثبيت عبر ملف ZIP: نزّل من هنا
  • التثبيت عبر Docker: docker build -t "insect:latest" . (يمكن العثور على مزيد من المعلومات هنا)

التثبيت من مدير الحزم:

  • التثبيت عبر PyPi: pip3 install dirsearch
  • التثبيت عبر Kali Linux: sudo apt-get install dirsearch (مهمل)

قوائم الكلمات (مهم)

الملخص:

  • قائمة الكلمات هي ملف نصي، كل سطر فيه مسار.
  • بخصوص الامتدادات، على عكس الأدوات الأخرى، يستبدل dirsearch و insect فقط الكلمة المفتاحية %EXT% بامتدادات من خيار -e.
  • بالنسبة لقوائم الكلمات التي لا تحتوي على %EXT% (مثل SecLists)، فإن مفتاح -f | --force-extensions مطلوب لإلحاق الامتدادات بكل كلمة في قائمة الكلمات، بالإضافة إلى /.
  • لتطبيق امتداداتك على مدخلات قائمة الكلمات التي تحتوي على امتدادات بالفعل، استخدم -O | --overwrite-extensions (ملاحظة: بعض الامتدادات مستثناة من الاستبدال مثل .log, .json, .xml, ... أو امتدادات الوسائط مثل .jpg, .png)
  • لاستخدام قوائم كلمات متعددة، يمكنك فصل قوائم الكلمات بفواصل. مثال: wordlist1.txt,wordlist2.txt.

أمثلة:

  • الامتدادات العادية:``` index.%EXT%
سيؤدي تمرير **asp** و **aspx** كامتدادات إلى توليد القاموس التالي:```
index
index.asp
index.aspx
  • فرض الامتدادات:``` admin
سيؤدي تمرير **php** و **html** كامتدادات مع علامة **-f**/**--force-extensions** إلى إنشاء القاموس التالي:```
admin
admin.php
admin.html
admin/
  • الكتابة فوق الامتدادات:``` login.html
عند تمرير **jsp** و**jspa** كامتدادات مع العلم **-O**/**--overwrite-extensions** سيتم توليد القاموس التالي:```
login.html
login.jsp
login.jspa

الخيارات -------``` Usage: insect.py [-u|--url] target [-e|--extensions] extensions [options]

Options: --version show program's version number and exit -h, --help show this help message and exit

Mandatory: -u URL, --url=URL Target URL(s), support multiple flags -l PATH, --url-file=PATH URL list file --stdin Read URL(s) from STDIN --cidr=CIDR Target CIDR --raw=PATH Load raw HTTP request from file (use --scheme flag to set the scheme) -s SESSION_FILE, --session=SESSION_FILE Session file --config=PATH Full path to config file, see 'config.ini' for example (Default: config.ini)

Dictionary Settings: -w WORDLISTS, --wordlists=WORDLISTS Customize wordlists (separated by commas) -e EXTENSIONS, --extensions=EXTENSIONS Extension list separated by commas (e.g. php,asp) -f, --force-extensions Add extensions to the end of every wordlist entry. By default insect only replaces the %EXT% keyword with extensions -O, --overwrite-extensions Overwrite other extensions in the wordlist with your extensions (selected via -e) --exclude-extensions=EXTENSIONS Exclude extension list separated by commas (e.g. asp,jsp) --remove-extensions Remove extensions in all paths (e.g. admin.php -> admin) --prefixes=PREFIXES Add custom prefixes to all wordlist entries (separated by commas) --suffixes=SUFFIXES Add custom suffixes to all wordlist entries, ignore directories (separated by commas) -U, --uppercase Uppercase wordlist -L, --lowercase Lowercase wordlist -C, --capital Capital wordlist

General Settings: -t THREADS, --threads=THREADS Number of threads -r, --recursive Brute-force recursively --deep-recursive Perform recursive scan on every directory depth (e.g. api/users -> api/) --force-recursive Do recursive brute-force for every found path, not only directories -R DEPTH, --max-recursion-depth=DEPTH Maximum recursion depth --recursion-status=CODES Valid status codes to perform recursive scan, support ranges (separated by commas) --subdirs=SUBDIRS Scan sub-directories of the given URL[s] (separated by commas) --exclude-subdirs=SUBDIRS Exclude the following subdirectories during recursive scan (separated by commas) -i CODES, --include-status=CODES Include status codes, separated by commas, support ranges (e.g. 200,300-399) -x CODES, --exclude-status=CODES Exclude status codes, separated by commas, support ranges (e.g. 301,500-599) --exclude-sizes=SIZES Exclude responses by sizes, separated by commas (e.g. 0B,4KB) --exclude-texts=TEXTS Exclude responses by texts, separated by commas (e.g. 'Not found', 'Error') --exclude-regex=REGEX Exclude responses by regex (e.g. '^Error$') --exclude-redirect=STRING Exclude responses if this regex (or text) matches redirect URL (e.g. '/index.html') --exclude-response=PATH Exclude responses similar to response of this page, path as input (e.g. 404.html) --skip-on-status=CODES Skip target whenever hit one of these status codes, separated by commas, support ranges --min-response-size=LENGTH Minimum response length --max-response-size=LENGTH Maximum response length --max-time=SECONDS Maximum runtime for the scan

تنزيل الأداة