
أداة متقدمة متعددة المنصات تعمل على أتمتة عملية اكتشاف واستغلال ثغرات حقن SQL الأمنية.
أداة متقدمة عبر المنصات تعمل على أتمتة عملية اكتشاف واستغلال ثغرات حقن SQL.

pip3python3 -m pip install --upgrade -r requirements.txtpython3 setup.py install أو python3 -m pip install -e .ghauri --help.أو
يمكنك تحميل أحدث إصدار من Ghauri عن طريق استنساخ مستودع GitHub.
git clone https://github.com/r0oth3x49/ghauri.git
--proxy.-r file.txt--start 1 --stop 2--skip-urlencode--sql-shell (تجريبي)--fresh-queries--hostname--update
Author: Nasir khan ()
usage: ghauri -u URL [OPTIONS]
A cross-platform python based advanced sql injections detection & exploitation tool.
General:
-h, --help Shows the help.
--version Shows the version.
--update update ghauri
-v VERBOSE Verbosity level: 1-5 (default 1).
--batch Never ask for user input, use the default behavior
--flush-session Flush session files for current target
--fresh-queries Ignore query results stored in session file
--test-filter Select test payloads by titles (experimental)
Target:
At least one of these options has to be provided to define the
target(s)
-u URL, --url URL Target URL (e.g. 'http://www.site.com/vuln.php?id=1).
-m BULKFILE Scan multiple targets given in a textual file
-r REQUESTFILE Load HTTP request from a file
Request:
These options can be used to specify how to connect to the target URL
-A , --user-agent HTTP User-Agent header value
-H , --header Extra header (e.g. "X-Forwarded-For: 127.0.0.1")
--mobile Imitate smartphone through HTTP User-Agent header
--random-agent Use randomly selected HTTP User-Agent header value
--host HTTP Host header value
--data Data string to be sent through POST (e.g. "id=1")
--cookie HTTP Cookie header value (e.g. "PHPSESSID=a8d127e..")
--referer HTTP Referer header value
--headers Extra headers (e.g. "Accept-Language: fr\nETag: 123")
--proxy Use a proxy to connect to the target URL
--delay Delay in seconds between each HTTP request
--timeout Seconds to wait before timeout connection (default 30)
--retries Retries when the connection related error occurs (default 3)
--confirm Confirm the injected payloads.
--ignore-code Ignore (problematic) HTTP error code(s) (e.g. 401)
--skip-urlencode Skip URL encoding of payload data
--force-ssl Force usage of SSL/HTTPS
Optimization:
These options can be used to optimize the performance of ghauri
--threads THREADS Max number of concurrent HTTP(s) requests (default 1)
Injection:
These options can be used to specify which parameters to test for,
provide custom injection payloads and optional tampering scripts
-p TESTPARAMETER Testable parameter(s)
--dbms DBMS Force back-end DBMS to provided value
--prefix Injection payload prefix string
--suffix Injection payload suffix string
--safe-chars Skip URL encoding of specific character(s): (e.g:- --safe-chars="[]")
--fetch-using Fetch data using different operator(s): (e.g: --fetch-using=between/in)
Detection:
These options can be used to customize the detection phase
--level LEVEL Level of tests to perform (1-3, default 1)
--code CODE HTTP code to match when query is evaluated to True
--string String to match when query is evaluated to True
--not-string String to match when query is evaluated to False
--text-only Compare pages based only on the textual content
Techniques:
These options can be used to tweak testing of specific SQL injection
techniques
--technique TECH SQL injection techniques to use (default "BEST")
--time-sec TIMESEC Seconds to delay the DBMS response (default 5)
Enumeration:
These options can be used to enumerate the back-end database
management system information, structure and data contained in the
tables.
-b, --banner Retrieve DBMS banner
--current-user Retrieve DBMS current user
--current-db Retrieve DBMS current database
--hostname Retrieve DBMS server hostname
--dbs Enumerate DBMS databases
--tables Enumerate DBMS database tables
--columns Enumerate DBMS database table columns
--count Retrieve number of entries for table(s)
--dump Dump DBMS database table entries
-D DB DBMS database to enumerate
-T TBL DBMS database tables(s) to enumerate
-C COLS DBMS database table column(s) to enumerate
--start Retrieve entries from offset for dbs/tables/columns/dump
--stop Retrieve entries till offset for dbs/tables/columns/dump
--sql-shell Prompt for an interactive SQL shell (experimental)
Example:
ghauri -u http://www.site.com/vuln.php?id=1 --dbs
استخدام Ghauri لمهاجمة أهداف دون موافقة مسبقة متبادلة غير قانوني.
تقع على عاتق المستخدم النهائي مسؤولية الامتثال لجميع القوانين المحلية والولائية والاتحادية المعمول بها.
لا يتحمل المطور أي مسؤولية ولا يكون مسؤولاً عن أي سوء استخدام أو ضرر ناتج عن هذا البرنامج.
هناك العديد من المقالات والمنشورات التي تسلط الضوء على النجاح الذي حققه المستخدمون مع Ghauri مقارنة بـ SQLMap. بينما لا أقارن Ghauri مباشرة بـ SQLMap، فقد فعل ذلك العديد من المستخدمين. بدأت هذا المشروع لأنني في عملي اليومي كنت أواجه تحديات كبيرة في تكوين واستخدام SQLMap بشكل فعال، حتى في حالات حقن SQL التي تبدو بسيطة. على الرغم من أن هذه الحقن تبدو مباشرة، إلا أن SQLMap غالبًا ما يفشل في اكتشافها. بتشجيع من صديق، قررت إنشاء أداتي الخاصة. لقد قمت بتطوير العديد من البرامج النصية للاستغلال، كل منها مصمم لحالات محددة، وأدركت الفائدة المحتملة من دمج هذه التقنيات في وحدة واحدة. أدى ذلك إلى إنشاء Ghauri، الذي لقي استحسان المجتمع، وحصل على ردود فعل إيجابية ونجوم بسبب فعاليته.
حتى Stamparam أشاد بـ Ghauri، واصفًا إياه بأنه "إعادة كتابة للدواخل" في تغريدة، مما يؤكد أهمية آلياته الداخلية.
على سبيل المثال، يمكنك حفظ طلب HTTP ضعيف في ملف (SQLi خلف مصادقة) وتقديمه إلى كل من Ghauri و SQLMap باستخدام التبديل -r. ستتحدث النتائج عن نفسها دون الحاجة إلى تكوينات مخصصة.
يعمل Ghauri بطريقة تشبه المتصفح وكذلك بطرقه الفريدة، ويتحول تلقائيًا إلى تقنيات وتجاوزات مختلفة لاستخراج البيانات. مرة أخرى، هذه ليست مقارنة مباشرة لأن Ghauri لا يزال لديه العديد من الميزات التي يجب تنفيذها، بينما SQLMap غني بالميزات بالفعل. ومع ذلك، يؤدي Ghauri باستمرار المهام المطلوبة.
منذ تطوير هذه الأداة، نادرًا ما أستخدم SQLMap، إلا في حالات قليلة حيث لا يزال Ghauri قيد التحسين.
أشجعك على تجربتها بنفسك. شكرًا لك.
ghauri --update للحصول على أحدث إصدار من ghauri.--ignore-code--count-m (تجريبي)--random-agent, --mobile