
ماسح ثغرات تهريب طلبات HTTP
بناءً على البحث الرائع الذي أجراه James Kettle. يمكن للأداة المساعدة في العثور على الخوادم التي قد تكون عرضة لثغرة تهريب الطلبات.
تحتاج الأداة إلى الكثير من التحسينات، وليس لدي وقت كافٍ لدعمها لأن لدي مشروعًا كبيرًا آخر - x8. سأعود إلى هذا المشروع ربما في المستقبل.
USAGE:
request_smuggler [OPTIONS] --url <url>
FLAGS:
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
--amount-of-payloads <amount-of-payloads> low/medium/all [default: low]
-t, --attack-types <attack-types>
[ClTeMethod, ClTePath, ClTeTime, TeClMethod, TeClPath, TeClTime] [default: "ClTeTime" "TeClTime"]
--file <file>
send request from a file
you need to explicitly pass \r\n at the end of the lines
-H, --header <headers> Example: -H 'one:one' 'two:two'
-X, --method <method> [default: POST]
-u, --url <url>
-v, --verbose <verbose>
0 - print detected cases and errors only,
1 - print first line of server responses
2 - print requests [default: 0]
--verify <verify> how many times verify the vulnerability [default: 2]
لينكس
git clone https://github.com/Sh1Yo/request_smuggler
cd request_smuggler
cargo build --release
cargo install request_smuggler --version 0.1.0-alpha.2
ماك
git clone https://github.com/Sh1Yo/request_smuggler
cd request_smuggler
cargo build --release
cargo install request_smuggler --version 0.1.0-alpha.2
ويندوز