
Default signature for Jaeles Scanner
Este proyecto formaba parte de Osmedeus Engine. Consulta cómo se integró en @OsmedeusEngine
jaeles config init
O
Intenta clonar la carpeta de firmas a algún lugar como este
git clone --depth=1 https://github.com/jaeles-project/jaeles-signatures /tmp/jaeles-signatures/
luego recárgalas en la base de datos con este comando.
jaeles config -a reload --signDir /tmp/jaeles-signatures
Scan Usage example:
jaeles scan -s <signature> -u <url>
jaeles scan -c 50 -s <signature> -U <list_urls> -L <level-of-signatures>
jaeles scan -c 50 -s <signature> -U <list_urls>
jaeles scan -c 50 -s <signature> -U <list_urls> -p 'dest=xxx.burpcollaborator.net'
jaeles scan -c 50 -s <signature> -U <list_urls> -f 'noti_slack "{{.vulnInfo}}"'
jaeles scan -v -c 50 -s <signature> -U list_target.txt -o /tmp/output
jaeles scan -s <signature> -s <another-selector> -u http://example.com
jaeles scan -G -s <signature> -s <another-selector> -x <exclude-selector> -u http://example.com
cat list_target.txt | jaeles scan -c 100 -s <signature>
jaeles scan -s '/tmp/custom-signature/sensitive/.*' -L 2 --fi
Examples:
jaeles scan -s 'jira' -s 'ruby' -u target.com
jaeles scan -c 50 -s 'java' -x 'tomcat' -U list_of_urls.txt
jaeles scan -G -c 50 -s '/tmp/custom-signature/.*' -U list_of_urls.txt
jaeles scan -v -s '~/my-signatures/products/wordpress/.*' -u 'https://wp.example.com/blog/' -p 'root=[[.URL]]'
cat urls.txt | grep 'interesting' | jaeles scan -c 50 -s /tmp/jaeles-signatures/cves/sample.yaml -U list_of_urls.txt --proxy http://127.0.0.1:8080
Config Command examples:
# Init default signatures
jaeles config init
# Update latest signatures
jaeles config update
jaeles config update --repo http://github.com/jaeles-project/another-signatures --user admin --pass admin
jaeles config update --repo [email protected]/jaeles-project/another-signatures -K your_private_key
# Reload signatures from a standard signatures folder (contain passives + resources)
jaeles config reload --signDir ~/standard-signatures/
# Add custom signatures from folder
jaeles config add --signDir ~/custom-signatures/
# Clean old stuff
jaeles config clean
# More examples
jaeles config add --signDir /tmp/standard-signatures/
jaeles config cred --user sample --pass not123456
For full Usage:
jaeles -hh
Jaeles busca firmas como un único archivo, por lo que puedes estructurarlas como quieras. Esto es solo un ejemplo.
Las firmas Fuzz pueden tener muchos falsos positivos porque no puedo definir exactamente qué es vulnerable en cada caso. Así que asegúrate de saber lo que estás haciendo aquí.
Conviértete en un contribuyente financiero y ayúdanos a mantener nuestra comunidad. [Contribuir]
Explora las últimas vulnerabilidades en cvebase.com
Jaeles está hecho con ♥ por @j3ssiejjj y se publica bajo la licencia MIT.
| Page | Description |
|---|
| common | Implementa detección de configuraciones incorrectas en algunas aplicaciones populares |
| cves | Implementa algunos CVE |
| sensitvie | Algunas rutas comunes con información sensible |
| probe | Se utiliza para detectar alguna tecnología usada por el objetivo |
| passives | Se utiliza para la detección pasiva |
| fuzz | Algunos casos comunes para el modo fuzz (sé que hay muchos falsos positivos aquí) |
| routines | Ejemplo de rutinas |