
GyoiThon ist ein wachsendes Penetrationstest-Tool mit maschinellem Lernen.

Japanische Seite ist hier.
Das neue GyoiThon (Version 0.0.4) kann Ihre im Internet verfügbaren Subdomains auflisten. Und wenn die Subdomain als Webdienst veröffentlicht ist, führt GyoiThon einen Health-Check durch, der eine nicht-destruktive Schwachstellenbewertung darstellt.
| Hinweis |
|---|
| Die neue Funktion verwendet eine Google Custom Search API. Wenn Sie diese Funktion nutzen, müssen Sie daher einen API-Schlüssel für die Google Custom Search bereitstellen. |
domain_list.csv vorbereiten: ```
"Domain Name"
mbsd.jp"? But we are to output only the translation. So we output "Und Sie führen folgenden Befehl aus. " with two trailing spaces? Typically trailing spaces are significant in Markdown for line breaks. So we preserve.
But also consider the original might be part of a sentence. The chunk starts with "And you execute following command." So it's a standalone sentence. Translate as "Und Sie führen folgenden Befehl aus."
But ensure not to translate code or anything else. There is no code here.
Thus final output: "Und Sie führen folgenden Befehl aus. " (with two spaces at end). Also note the original had a period and then two spaces. Ensure the translation ends with period and two spaces.Und Sie führen folgenden Befehl aus. ```
root@kali:~/GyoiThon# python3 gyoithon.py -i --domain_list
Als Ergebnis erhalten Sie eine Liste von Subdomains, die mit der angegebenen Domain verknüpft sind.
| Index | Domain | Subdomain | IP-Adresse | Zugriffsstatus (http) | Ort (http) | Zugriffsstatus (https) | Ort (https) | Whois-Einträge |
|---|---|---|---|---|---|---|---|---|
| 1 | mbsd.jp | mbsd.jp | ['40.115.251.148'] | 301 | https://www.mbsd.jp/ | 301 | https://www.mbsd.jp/ | *** |
| 2 | mbsd.jp | www.mbsd.jp | ['40.115.251.148'] | 301 | https://www.mbsd.jp/ | 200 | - | - |
| 3 | mbsd.jp | www2.mbsd.jp | ['40.115.251.148'] | 301 | https://www.mbsd.jp/ | 200 | - | - |
As a result, you get a list of subdomains and assessment report.
|Index|Domain|Sub-Domain|IP Address|Access Status (http)|Location (http)|Access Status (https)|Location (https)|Whois records|Assessment results|
|:--:|:--:|:--:|:--:|:--:|:--:|:--:|:--:|:--:|:--:|
|1|mbsd.jp|mbsd.jp|['40.115.251.148']|301|https://www.mbsd.jp/|301|https://www.mbsd.jp/|***|***|
|2|mbsd.jp|www.mbsd.jp|['40.115.251.148']|301|https://www.mbsd.jp/|200|-|-|***|
|3|mbsd.jp|www2.mbsd.jp|['40.115.251.148']|301|https://www.mbsd.jp/|200|-|-|***|
## Übersicht
GyoiThon ist ein **Intelligence Gathering Tool** für Webserver.
GyoiThon führt **Remote-Zugriff** auf den Ziel-Webserver durch und **identifiziert Produkte, die auf dem Server betrieben werden**, wie CMS, Webserver-Software, Framework, Programmiersprache usw. Außerdem kann es **Exploit-Module** für identifizierte Produkte mit Metasploit ausführen. GyoiThon führt die oben genannten Aktionen **vollautomatisch** durch.
Die Hauptfunktionen von GyoiThon sind die folgenden:
* Remote-Zugriff/Vollautomatisch
GyoiThon kann die Informationen des Ziel-Webservers **vollautomatisch** nur über **Remote-Zugriff** sammeln. Sie müssen GyoiThon nur einmal für Ihren Betrieb ausführen.
* Zerstörungsfreier Test
GyoiThon kann Informationen des Ziel-Webservers nur über **normalen Zugriff** sammeln.
Wenn Sie jedoch eine Teiloption verwenden, führt GyoiThor abnormale Zugriffe aus, wie z. B. das Senden von Exploit-Modulen.
* Sammeln verschiedener Informationen
GyoiThon verfügt über verschiedene Intelligence-Gathering-Engines wie Web-Crawler, Google Custom Search API, Censys, Explorer für Standardinhalte, Prüfung von Cloud-Diensten usw. Durch die Analyse der gesammelten Informationen mittels **String Pattern Matching** und **maschinellem Lernen** kann GyoiThon **Produkt/Version/CVE-Nummer** identifizieren, die auf dem Ziel-Webserver betrieben werden, **unnötige HTML-Kommentare**/**Debug-Meldungen**, **Login-Seite** usw.
* Prüfung echter Sicherheitslücken
GyoiThon kann Exploit-Module für identifizierte Produkte mit Metasploit ausführen.
Dadurch kann es **echte Sicherheitslücken des Ziel-Webservers untersuchen**.

| Hinweis |
|:--------|
| Falls Sie interessiert sind, **verwenden Sie sie bitte in einer von Ihnen kontrollierten Umgebung und auf eigenes Risiko**. |
## <a name='Installation'>Installation</a>
1. git clone GyoiThon's repository.```
root@kali:~# git clone https://github.com/gyoisamurai/GyoiThon.git
3. Installieren Sie die erforderlichen Python-Pakete.```
root@kali:~# cd GyoiThon
root@kali:~/GyoiThon# pip3 install -r requirements.txt
root@kali:~/GyoiThon# apt install python3-tk
config.ini bearbeiten.