
Herramienta para verificar la bandera de cookie en múltiples sitios
Herramienta para verificar la bandera de cookie en múltiples sitios.
Herramienta creada para facilitar el proceso de verificar la bandera de cookie cuando estamos analizando múltiples servidores web.
Si quieres saber por qué podría ser útil esta herramienta?
https://www.owasp.org/index.php/SecureFlag
https://www.owasp.org/index.php/HttpOnly
https://www.owasp.org/index.php/Testing_for_cookies_attributes_%28OTG-SESS-002%29
Usage: cookiescanner.py [options]
Example: ./cookiescanner.py -i ips.txt
Options:
-h, --help show this help message and exit
-i INPUT, --input=INPUT
File input with the list of webservers
-u URL, --url=URL URL
-f FORMAT, --format=FORMAT
Output format (json, xml, csv, normal, grepable)
-g GOOGLE, --google=GOOGLE
Search in google by domain
--nocolor Disable color (for the normal format output)
-I, --info More info
Performance:
-t TIMEOUT Timeout of response
-d DELAY Delay between requests
requests >= 2.8.1
BeautifulSoup >= 4.2.1
pip3 install --upgrade -r requirements.txt
Añadir inteligencia para reconocer el tipo de valor en la cookie.
Manuel Mancera ([email protected]/@sinkmanu)