Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
TIDoS-Framework — Das offensive manuelle Framework für Webanwendungs-Penetrationstests. | Kitploit
Tools/GitHubGitHub/0xinfection/tidos-framework
OSINT (Open-Source-Intelligence)AufklärungSchwachstellenscannerPasswortangriffePort-ScanningExploitationWebanwendungs-ExploitationInformationsbeschaffungFuzzingSubdomain-Enumeration
GitHub0xinfection/tidos-framework

TIDoS-Framework

1.9k391vor 5 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Das offensive manuelle Framework für Webanwendungs-Penetrationstests.

Repository anzeigen


TIDoS


Das offensive Framework für Penetrationstests von Webanwendungen.

WICHTIG:

Die neue Qt5-Oberfläche ist fertig, hat aber zusätzliche Abhängigkeiten. Werfen Sie einen Blick auf die aktualisierten Installationsanweisungen.

Highlights :-

Hier ein Überblick, worum es in dem Framework geht:

  • Ein komplettes, vielseitiges Framework, das alles von der Aufklärung bis zur Schwachstellenanalyse abdeckt.
  • Hat 5 Hauptphasen, unterteilt in 14 Unterphasen mit insgesamt 108 Modulen.
  • Die Aufklärungsphase hat 50 eigene Module (einschließlich aktiver und passiver Aufklärung, Informationspreisgabe).
  • Die Scan- & Enumeration-Phase hat 16 Module (einschließlich Portscans, WAF-Analyse usw.).
  • Die Schwachstellenanalyse-Phase hat 37 Module (einschließlich der häufigsten Schwachstellen in Aktion).
  • Exploits Castle hat nur 1 Exploit. (rein entwicklungsbedingt)
  • Und schließlich haben die Hilfsmodule 4 Module. (weitere in Entwicklung)
  • Alle vier Phasen haben jeweils ein Auto-Awesome-Modul, das jedes Modul für Sie automatisiert.
  • enorme Leistungssteigerung durch Multiprocessing
  • Angriffe über Tor leiten (noch nicht überall implementiert)
  • Sie brauchen nur die Domain, den Rest erledigt dieses Tool.
  • TIDoS unterstützt vollständige ausführliche Ausgabe, sodass Sie wissen, was passiert.
  • Angriffe jetzt noch einfacher mit einer neuen GUI

Wichtigste neue Funktionen

  • die Programmiersprache: TIDoS wurde vollständig auf Python3 portiert
  • die Benutzeroberfläche: TIDoS bietet eine neue, Metasploit-ähnliche Konsolenoberfläche
  • Parallelisierung: TIDoS nutzt Multiprocessing zur Beschleunigung von Angriffen
  • Eine alternative CLI-Oberfläche für schnellere Interaktion mit einem bestimmten Modul
  • Anonymität: Angriffe über Tor sind möglich (95 % fertig)
  • Modulabschluss: Einige Module wurden funktional erweitert (z. B. mehr Umgehungen, Unterstützung von mehr als einem Abfrageparameter)
  • Einige neue Module: arpscan
  • Eine grafische Benutzeroberfläche für eine einfachere Interaktion mit dem Toolkit
  • Unterstützt nicht standardmäßige http(s)-Ports

In Kürze

  • Ergebnisse von Modulen werden in einer Datenbank gespeichert
  • neue Module: nikto&photon

Installation :-

Installationsskript (Global) :

Um das Framework global in /opt zu installieren, führen Sie das bereitgestellte Skript core/install.py als root aus. Danach können Sie TIDoS einfach durch Eingabe von tidos in der Befehlszeile starten.

Manuelle Installation (Lokal) :

  • Klonen Sie das Repository lokal und wechseln Sie dorthin:
root@kitploit:~
git clone https://github.com/0xinfection/tidos-framework.git
cd tidos-framework

TIDoS benötigt einige Bibliotheken, die über die Paketverwaltung aptitude oder dnf installiert werden können.

root@kitploit:~
sudo apt-get install libncurses5 libxml2 nmap tcpdump libexiv2-dev build-essential python3-pip libmariadbclient18 libmysqlclient-dev tor konsole

Nachdem diese Abhängigkeiten installiert sind, müssen wir die restlichen Python-Paketabhängigkeiten installieren, führen Sie daher aus:

root@kitploit:~
pip3 install -r requirements.txt

TIDoS verwendet Vailyn, um in einem neuen, verbesserten Pfadtraversierungsmodul nach Pfadüberschreitungen zu suchen. Wenn Sie dieses Modul verwenden möchten, gehen Sie zu https://github.com/VainlyStrain/Vailyn und folgen Sie den dortigen Installationsanweisungen.

Das wars. Sie haben nun TIDoS zur Verfügung. Starten Sie es mit:

root@kitploit:~
python3 tidv2               #Qt5 interface
sudo python3 tidconsole.py  #console interface

Docker-Image :

Sie können es aus dem Dockerfile erstellen:

root@kitploit:~
git clone https://github.com/0xinfection/tidos-framework.git
cd tidos-framework/core/docker
docker build -t tidos .

Um TIDoS auszuführen:

root@kitploit:~
docker run --interactive --tty --rm tidos bash
tidos

Update: TIDoS ist jetzt auf Docker Hub verfügbar. Installieren und starten Sie den Container wie folgt:

root@kitploit:~
docker run -it vainlystrain/tidos-framework

TIDoS aktualisieren :

Um die aktuelle Version von TIDoS zu erhalten, wechseln Sie in das Installationsverzeichnis und führen Sie (sudo) git pull #sudo if installed by install.py aus. Alternativ können Sie den Befehl fetch in tidconsole verwenden.

Erste Schritte :-

Um zu beginnen, müssen Sie Ihre eigenen API KEYS für verschiedene OSINT- und Scanning- und Enumeration-Zwecke festlegen. Öffnen Sie dazu API_KEYS.py im Verzeichnis files/ und setzen Sie Ihre eigenen Schlüssel und Zugriffstoken für SHODAN, CENSYS, FULL CONTACT, GOOGLE und WHATCMS.

GUTE NACHRICHT:

Die neueste Version von TIDoS enthält standardmäßig alle API KEYS und ACCESS TOKENS für SHODAN, CENSYS, FULL CONTACT, GOOGLE und WHATCMS. Ich habe diese Tokens in verschiedenen Repositories auf GitHub selbst gefunden. Sie können nun alle Module verwenden, die die API KEYS nutzen. :)

Befehle :-

root@kitploit:~
__                                                    __                                                        
 !  attack    Attack specified target(s)              M
 :  clear     Clear terminal.                         :
 V  creds     Handle target credentials.              
 :  fetch     Check for and install updates.          :
 :  find      Search a module.                        :
    help      Show help message.                      :
    info      Show description of current module.     M
 :  intro     Display Intro.                          :
 :  leave     Leave module.                           M
    list      List all modules of a category.         :
 :  load      Load module.                            :
 :  netinfo   Show network information.               :
 :  opts      Show options of current module.         M
    phpsploit Load the phpsploit framework.           :
              (needs to be downloaded externally)
 :  processes Set number of processes in parallelis.  :
    q         Terminate TIDoS session.                :
 :  sessions  Interact with cached sessions.          :
 :  set       Set option value of module.             M
 :  tor       Pipe Attacks through the Tor Network.   :
    vicadd    Add Target to list.                     :
    vicdel    Delete Target from list.                :
    viclist   List all targets.                       :

  Avail. Cmds
    M needs loaded modvle
    V [! potentially] need loaded target(s)

Makellose Funktionen :-

TIDoS unterstützt derzeit Folgendes: and more modules are under active development

  • Reconnaissance + OSINT

    • Passive Reconnaissance:

      • Nping Enumeration Via external APi
      • WhoIS Lookup Domain info gathering
      • GeoIP Lookup Pinpoint physical location
      • DNS Configuration Lookup DNSDump
      • Subdomains Lookup Indexed ones
      • Reverse DNS Lookup Host Instances
      • Reverse IP Lookup Hosts on same server
      • Subnets Enumeration Class Based
      • Domain IP History IP Instances
      • Web Links Gatherer Indexed ones
      • Google Search Manual search
      • Google Dorking (multiple modules) Automated
  • Auxillary Modules

    • Hash Generator MD5, SHA1, SHA256, SHA512
    • String & Payload Encoder 7 Categories
    • Forensic Image Analysis Metadata Extraction
    • Web HoneyPot Probability ShodanLabs HoneyScore
  • Exploitation purely developmental

    • ShellShock

Andere Werkzeuge:

  • net_info.py - Zeigt Informationen über Ihr Netzwerk an. Erreichbar über den Befehl 'netinfo'.

TIDoS in Aktion:

asciicast

Version:

root@kitploit:~
v2.0.1-5 [latest release] [#beta]

Haftungsausschluss:

TIDoS wird als offensives Framework für Webanwendungs-Audits bereitgestellt. Es verfügt über integrierte Module, die potenzielle Fehlkonfigurationen und Schwachstellen in Webanwendungen aufdecken können, die möglicherweise böswillig ausgenutzt werden könnten.

DAHER SIND WEDER DER AUTOR NOCH DIE MITWIRKENDEN FÜR JEGLICHEN MISSBRAUCH ODER SCHÄDEN DURCH DIESES TOOLKIT VERANTWORTLICH.

Tool herunterladen
  • Email to Domain Resolver Email WhoIs
  • Wayback Machine Lookups Find Backups
  • Breached Email Check Pwned Email Accounts
  • Enumeration via Google Groups Emails Only
  • Check Alias Availability Social Networks
  • Find PasteBin Posts Domain Based
  • LinkedIn Gathering Employees & Company
  • Google Plus Gathering Domain Profiles
  • Public Contact Info Scraping FULL CONTACT
  • Censys Intel Gathering Domain Based
  • Threat Intelligence Gathering Bad IPs
  • Active Reconnaissance:

    • Ping Enumeration Advanced
    • CMS Detection (185+ CMSs supported) IMPROVED
    • Advanced Traceroute IMPROVED
    • robots.txt and sitemap.xml Checker
    • Grab HTTP Headers Live Capture
    • Find HTTP Methods Allowed via OPTIONS
    • Detect Server Type IMPROVED
    • Examine SSL Certificate Absolute
    • Apache Status Disclosure Checks File Based
    • WebDAV HTTP Enumeration PROFIND & SEARCH
    • PHPInfo File Enumeration via Bruteforce
    • Comments Scraper Regex Based
    • Find Shared DNS Hosts Name Server Based
    • Alternate Sites Discovery User-Agent Based
    • Discover Interesting Files via Bruteforce
      • Common Backdoor Locations shells, etc.
      • Common Backup Locations .bak, .db, etc.
      • Common Password Locations .pgp, .skr, etc.
      • Common Proxy Path Configs. .pac, etc.
      • Multiple Index Paths index, index1, etc.
      • Common Dot Files .htaccess, .apache, etc
      • Common Logfile Locations .log, .changelog, etc
  • Information Disclosure:

    • Credit Cards Disclosure If Plaintext
    • Email Harvester IMPROVED
    • Fatal Errors Enumeration Includes Full Path Disclosure
    • Internal IP Disclosure Signature Based
    • Phone Number Havester Signature Based
    • Social Security Number Harvester US Ones
  • Scanning & Enumeration

    • Remote Server WAF Enumeration Generic 54 WAFs
    • Port Scanning Ingenious Modules
      • Simple Port Scanner via Socket Connections
      • TCP SYN Scan Highly reliable
      • TCP Connect Scan Highly Reliable
      • XMAS Flag Scan Reliable Only in LANs
      • FIN Flag Scan Reliable Only in LANs
      • Port Service Detector
    • Web Technology Enumeration Absolute
    • Complete SSL Enumeration Absolute
    • Operating System Fingerprinting IMPROVED
    • Banner Grabbing of Services via Open Ports
    • Interactive Scanning with NMap 16 preloaded modules
    • Internet Wide Servers Scan Using CENSYS Database
    • Web and Links Crawlers
      • Depth 1 Indexed Uri Crawler
      • Depth 2 Single Page Crawler
      • Depth 3 Web Link Crawler
    • ARP Scanner NEW
  • Vulnerability Analysis

    Web-Bugs & Server Misconfigurations

    • Insecure CORS Absolute
    • Same-Site Scripting Sub-domain based
    • Zone Transfer DNS Server based
    • Clickjacking
      • Frame-Busting Checks
      • X-FRAME-OPTIONS Header Checks
    • Security on Cookies
      • HTTPOnly Flag
      • Secure Flag on Cookies
    • Cloudflare Misconfiguration Check
      • DNS Misconfiguration Checks
      • Online Database Lookup For Breaches
    • HTTP Strict Transport Security Usage
      • HTTPS Enabled but no HSTS
    • Domain Based Email Spoofing
      • Missing SPF Records
      • Missing DMARC Records
    • Host Header Injection
      • Port Based Web Socket Based
      • X-Forwarded-For Header Injection
    • Security Headers Analysis Live Capture
    • Cross-Site Tracing HTTP TRACE Method
    • Session Fixation via Cookie Injection
    • Network Security Misconfig.
      • Checks for TELNET Enabled via Port 23

    Serious Web Vulnerabilities

    • File Inclusions
      • Local File Inclusion (LFI) Param based
      • Remote File Inclusion (RFI) IMPROVED
        • Parameter Based
        • Pre-loaded Path Based
    • OS Command Injection Linux & Windows (RCE)
    • Path Traversal ENHANCED
    • Cross-Site Request Forgery Absolute
    • SQL Injection
      • Error Based Injection
        • Cookie Value Based
        • Referer Value Based
        • User-Agent Value Based
        • Auto-gathering IMPROVED
      • Blind Based Injection Crafted Payloads
        • Cookie Value Based
        • Referer Value Based
        • User-Agent Value Based
        • Auto-gathering IMPROVED
    • LDAP Injection Parameter Based
    • HTML Injection Parameter Based
    • Bash Command Injection ShellShock

    Other

    • PlainText Protocol Default Credential Bruteforce

      • FTP Protocol Bruteforce
      • SSH Protocol Bruteforce
      • POP 2/3 Protocol Bruteforce
      • SQL Protocol Bruteforce
      • (XMPP Protocol Bruteforce) BROKEN:DEP
      • SMTP Protocol Bruteforce
      • TELNET Protocol Bruteforce
  • Apache Struts Shock Apache RCE
  • XPATH Injection Parameter Based
  • Cross-Site Scripting IMPROVED
    • Cookie Value Based
    • Referer Value Based
    • User-Agent Value Based
    • Parameter Value Based Manual
  • Unvalidated URL Forwards Open Redirect
  • PHP Code Injection Windows + Linux RCE
  • CRLF Injection HTTP Response Splitting
    • User-Agent Value Based
    • Parameter value Based Manual
  • Sub-domain Takeover 50+ Services
    • Single Sub-domain Manual
    • All Subdomains Automated