अपडेट पर वापस जाएँ
New releaseJul 14, 2026

sj v2.7.0

एक्सपोज़्ड (Swagger/OpenAPI) परिभाषा फ़ाइलों में परिभाषित एंडपॉइंट्स के ऑडिटिंग के लिए एक उपकरण।

साझा करें

sj (Swagger Jacker)

sj एक कमांड लाइन उपकरण है जिसे एक्सपोज़ किए गए Swagger/OpenAPI परिभाषा फ़ाइलों के ऑडिटिंग में सहायता के लिए डिज़ाइन किया गया है। यह संबंधित API एंडपॉइंट्स पर कमजोर प्रमाणीकरण की जाँच करता है। यह मैन्युअल भेद्यता परीक्षण के लिए कमांड टेम्पलेट भी प्रदान करता है।

यह परिभाषा फ़ाइल को पार्स करके पथ, पैरामीटर और स्वीकृत विधियों का पता लगाता है, फिर परिणामों का उपयोग पाँच उप-कमांडों में से एक के साथ करता है:

  • automate - अनुरोधों की एक श्रृंखला तैयार करता है और प्रतिक्रिया की स्थिति कोड का विश्लेषण करता है।
  • prepare - मैन्युअल परीक्षण के लिए उपयोग करने के लिए कमांड की एक सूची उत्पन्न करता है।
  • endpoints - कच्चे API मार्गों की एक सूची उत्पन्न करता है। पथ मानों को परीक्षण डेटा से प्रतिस्थापित नहीं किया जाएगा।
  • brute - सामान्य रूप से उपयोग किए जाने वाले फ़ाइल पथों के आधार पर ऑपरेशन परिभाषाएँ खोजने के लिए लक्ष्य पर अनुरोधों की एक श्रृंखला भेजता है।
  • convert - एक परिभाषा फ़ाइल को v2 से v3 में परिवर्तित करता है।

बिल्ड

स्रोत से संकलित करने के लिए, सुनिश्चित करें कि आपके पास Go संस्करण >= 1.22.5 स्थापित है और रिपॉजिटरी के अंदर go build चलाएँ:

$ git clone https://github.com/BishopFox/sj.git
$ cd sj/
$ go build .

इंस्टॉल करना

टूल का नवीनतम संस्करण स्थापित करने के लिए, चलाएँ:

$ go install github.com/BishopFox/sj@latest

# नोट: आपको अपने Go बाइनरी के पथ को अपने PATH एनवायरनमेंट वेरिएबल में रखने की भी आवश्यकता हो सकती है:
$ export PATH=$PATH:~/go/bin

उपयोग

प्रत्येक परिभाषित एंडपॉइंट पर अनुरोधों की एक श्रृंखला भेजने और प्रत्येक प्रतिक्रिया की स्थिति कोड का विश्लेषण करने के लिए automate कमांड का उपयोग करें।

$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080               

Gathering API details.
Title: Swagger Petstore
Description: This is a sample server Petstore server.  You can find out more about Swagger at [http://swagger.io](http://swagger.io) or on [irc.freenode.net, #swagger](http://swagger.io/irc/).  For this sample, you can use the api key `special-key` to test the authorization filters.
✓  GET  200  /v2/pet/findByStatus
✓  GET  200  /v2/user/logout
⚠  POST  400  /v2/user/createWithArray
⚠  POST  400  /v2/store/order
✗  GET  404  /v2/store/order/1
⚠  POST  400  /v2/pet
⚠  PUT  415  /v2/pet
⚠  POST  400  /v2/user/createWithList
✗  GET  404  /v2/user/bishopfox
⚠  PUT  415  /v2/user/bishopfox
⚠  POST  400  /v2/user
⚠  POST  415  /v2/pet/1/uploadImage
✓  GET  200  /v2/pet/findByTags
✗  GET  404  /v2/pet/1
⚠  POST  415  /v2/pet/1
✓  GET  200  /v2/store/inventory
✓  GET  200  /v2/user/login

आप मिलान किए गए अनुरोधों को एक अलग प्रॉक्सी (जैसे, Burp Suite) के माध्यम से पुनः चलाने के लिए --replay-proxy ध्वज का उपयोग कर सकते हैं। इससे आप एक प्रॉक्सी (या सीधे) के माध्यम से सभी ट्रैफ़िक को रूट कर सकते हैं जबकि केवल दिलचस्प परिणाम अपने इंटरसेप्शन प्रॉक्सी को भेज सकते हैं:

$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi --replay-proxy http://127.0.0.1:8080

आप इसे --proxy के साथ भी जोड़ सकते हैं ताकि स्कैनिंग ट्रैफ़िक को एक अलग प्रॉक्सी के माध्यम से रूट किया जा सके जबकि मैचों को Burp पर पुनः चलाया जा सके:

$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://proxy:9090 --replay-proxy http://127.0.0.1:8080

आप आंशिक (या पूर्ण) प्रतिक्रिया देखने के लिए विस्तृत आउटपुट का अनुरोध भी कर सकते हैं:

$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080 -v           

Gathering API details.
Title: Swagger Petstore
Description: This is a sample server Petstore server.  You can find out more about Swagger at [http://swagger.io](http://swagger.io) or on [irc.freenode.net, #swagger](http://swagger.io/irc/).  For this sample, you can use the api key `special-key` to test the authorization filters.
✗  GET  404  /v2/user/bishopfox
   {"code":1,"type":"error","message":"User not found
⚠  PUT  415  /v2/user/bishopfox
   {"code":415,"type":"unknown","message":"com.sun.je
✓  GET  200  /v2/user/logout
   {"code":200,"type":"unknown","message":"ok"}
⚠  POST  400  /v2/user/createWithArray
   {"code":400,"type":"unknown","message":"bad input"
⚠  POST  400  /v2/user/createWithList
   {"code":400,"type":"unknown","message":"bad input"
✗  GET  404  /v2/pet/1
   {"code":1,"type":"error","message":"Pet not found"
⚠  POST  415  /v2/pet/1
   {"code":415,"type":"unknown"}
✓  GET  200  /v2/store/inventory
   {"sold":117,"string":26,"invalidStatus":1,"-1":1,"
⚠  POST  400  /v2/store/order
   {"code":400,"type":"unknown","message":"bad input"
✓  GET  200  /v2/user/login
   {"code":200,"type":"unknown","message":"logged in 
⚠  POST  400  /v2/pet
   {"code":400,"type":"unknown","message":"bad input"
⚠  PUT  415  /v2/pet
   {"code":415,"type":"unknown","message":"com.sun.je
✓  GET  200  /v2/pet/findByStatus
   []
✓  GET  200  /v2/pet/findByTags
   []
✗  GET  404  /v2/store/order/1
   {"code":1,"type":"error","message":"Order not foun
⚠  POST  400  /v2/user
   {"code":400,"type":"unknown","message":"bad input"
⚠  POST  415  /v2/pet/1/uploadImage
   {"code":415,"type":"unknown"}

मैन्युअल परीक्षण के लिए कमांड की एक सूची तैयार करने के लिए prepare कमांड का उपयोग करें। वर्तमान में curl और sqlmap दोनों का समर्थन करता है। आपको संभवतः इनमें थोड़ा बदलाव करना होगा।

$ sj prepare -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080      

INFO[0000] Gathering API details.
                      
Title: Swagger Petstore
Description: This is a sample server Petstore server.  You can find out more about Swagger at [http://swagger.io](http://swagger.io) or on [irc.freenode.net, #swagger](http://swagger.io/irc/).  For this sample, you can use the api key `special-key` to test the authorization filters.
$ curl -X POST "https://petstore.swagger.io/v2/pet/{petId}"
$ curl -X GET "https://petstore.swagger.io/v2/pet/{petId}"
$ curl -X GET "https://petstore.swagger.io/v2/store/inventory"
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithList" -d 'body=1'
$ curl -X GET "https://petstore.swagger.io/v2/user/logout"
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithArray" -d 'body=1'
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByStatus"
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByTags"
$ curl -X POST "https://petstore.swagger.io/v2/store/order" -d 'petId=1&quantity=1&shipDate=bishopfox&status=bishopfox&complete=1&id=1&body='
$ curl -X POST "https://petstore.swagger.io/v2/pet/{petId}/uploadImage"
$ curl -X POST "https://petstore.swagger.io/v2/pet" -d 'photoUrls=1&tags=1&status=bishopfox&id=1&category=&name=doggie&body='
$ curl -X PUT "https://petstore.swagger.io/v2/pet" -d 'id=1&category=&name=doggie&photoUrls=1&tags=1&status=bishopfox&body='
$ curl -X GET "https://petstore.swagger.io/v2/user/{username}"
$ curl -X PUT "https://petstore.swagger.io/v2/user/{username}" -d 'email=bishopfox&password=bishopfox&phone=bishopfox&userStatus=1&id=1&username=bishopfox&firstName=bishopfox&lastName=bishopfox&body='
$ curl -X GET "https://petstore.swagger.io/v2/user/login"
$ curl -X POST "https://petstore.swagger.io/v2/user" -d 'phone=bishopfox&userStatus=1&id=1&username=bishopfox&firstName=bishopfox&lastName=bishopfox&email=bishopfox&password=bishopfox&body='
$ curl -X GET "https://petstore.swagger.io/v2/store/order/{orderId}"

प्रदान की गई परिभाषा फ़ाइल से कच्चे एंडपॉइंट की सूची उत्पन्न करने के लिए endpoints कमांड का उपयोग करें।

$ sj endpoints -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080

श्रेणियाँ