अपडेट पर वापस जाएँ
New releaseSep 13, 2026

sj v2.8.2

एक्सपोज़्ड (Swagger/OpenAPI) परिभाषा फ़ाइलों में परिभाषित एंडपॉइंट्स के ऑडिटिंग के लिए एक उपकरण।

साझा करें

sj (Swagger Jacker)

sj एक कमांड लाइन टूल है जिसे उजागर Swagger/OpenAPI परिभाषा फ़ाइलों का ऑडिट करने में सहायता के लिए डिज़ाइन किया गया है, जो संबंधित API एंडपॉइंट्स की कमजोर प्रमाणीकरण के लिए जाँच करता है। यह मैन्युअल भेद्यता परीक्षण के लिए कमांड टेम्पलेट्स भी प्रदान करता है।

यह परिभाषा फ़ाइल से पथ, पैरामीटर और स्वीकृत विधियों को पार्स करके ऐसा करता है, फिर परिणामों का उपयोग पाँच उप-कमांड्स में से एक के साथ करता है:

  • automate - अनुरोधों की एक श्रृंखला तैयार करता है और प्रतिक्रिया के स्टेटस कोड का विश्लेषण करता है।
  • prepare - मैन्युअल परीक्षण के लिए उपयोग किए जाने वाले कमांड्स की सूची उत्पन्न करता है।
  • endpoints - कच्चे API रूट्स की सूची उत्पन्न करता है। पथ मानों को परीक्षण डेटा से प्रतिस्थापित नहीं किया जाएगा।
  • brute - सामान्यतः उपयोग किए जाने वाले फ़ाइल पथों के आधार पर ऑपरेशन परिभाषाओं को खोजने के लिए लक्ष्य पर अनुरोधों की एक श्रृंखला भेजता है।
  • convert - एक परिभाषा फ़ाइल को v2 से v3 में परिवर्तित करता है।

Build

स्रोत से संकलित करने के लिए, सुनिश्चित करें कि आपके पास Go संस्करण >= 1.22.5 स्थापित है और रिपॉजिटरी के भीतर से go build चलाएँ:

$ git clone https://github.com/BishopFox/sj.git
$ cd sj/
$ go build .

Install

टूल का नवीनतम संस्करण स्थापित करने के लिए, चलाएँ:

$ go install github.com/BishopFox/sj@latest

# Note: you may also need to place the path to your Go binaries within your PATH environment variable:
$ export PATH=$PATH:~/go/bin

Usage

प्रत्येक परिभाषित एंडपॉइंट पर अनुरोधों की एक श्रृंखला भेजने और प्रत्येक प्रतिक्रिया के स्टेटस कोड का विश्लेषण करने के लिए automate कमांड का उपयोग करें।

$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080               

Gathering API details.
⚠  POST     500  /v2/pet
⚠  PUT      500  /v2/pet
✓  GET      200  /v2/pet/findByStatus
✓  GET      200  /v2/pet/findByTags
✓  GET      200  /v2/pet/1
✓  POST     200  /v2/pet/1
⚠  POST     N/A  /v2/pet/1/uploadImage
✓  GET      200  /v2/store/inventory
⚠  POST     N/A  /v2/store/order
⚠  GET      N/A  /v2/store/order/1
✓  POST     200  /v2/user
⚠  POST     N/A  /v2/user/createWithArray
⚠  POST     N/A  /v2/user/createWithList
✓  GET      200  /v2/user/login
✓  GET      200  /v2/user/logout
✓  GET      200  /v2/user/bishopfox
✓  PUT      200  /v2/user/bishopfox

आप मिलान किए गए अनुरोधों को एक अलग प्रॉक्सी (जैसे, Burp Suite) के माध्यम से रीप्ले करने के लिए --replay-proxy फ़्लैग का उपयोग कर सकते हैं। यह आपको सभी ट्रैफ़िक को एक प्रॉक्सी (या सीधे) के माध्यम से रूट करने की सुविधा देता है, जबकि केवल रुचिकर परिणाम आपके इंटरसेप्शन प्रॉक्सी को भेजता है:

$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi --replay-proxy http://127.0.0.1:8080

आप इसे --proxy के साथ भी जोड़ सकते हैं ताकि स्कैनिंग ट्रैफ़िक को एक अलग प्रॉक्सी के माध्यम से रूट किया जा सके, जबकि मिलानों को Burp पर रीप्ले किया जा सके:

$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://proxy:9090 --replay-proxy http://127.0.0.1:8080

आप आंशिक (या पूर्ण) प्रतिक्रिया देखने के लिए वर्बोज़ आउटपुट का अनुरोध भी कर सकते हैं:

$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080 -v           

Gathering API details.
⚠  POST     500  /v2/pet
   {"code":500,"type":"unknown","message":"something 
⚠  PUT      500  /v2/pet
   {"code":500,"type":"unknown","message":"something 
✓  GET      200  /v2/pet/findByStatus
   []
✓  GET      200  /v2/pet/findByTags
   []
✓  GET      200  /v2/pet/1
   {"id":1,"category":{"id":1,"name":"cat"},"name":"d
✓  POST     200  /v2/pet/1
   {"code":200,"type":"unknown","message":"1"}
⚠  POST     N/A  /v2/pet/1/uploadImage
✓  GET      200  /v2/store/inventory
   {"sold":115,"bishopfox":1,"SOLD":1,"string":224,"d
⚠  POST     N/A  /v2/store/order
⚠  GET      N/A  /v2/store/order/1
✓  POST     200  /v2/user
   {"code":200,"type":"unknown","message":"1"}
⚠  POST     N/A  /v2/user/createWithArray
⚠  POST     N/A  /v2/user/createWithList
✓  GET      200  /v2/user/login
   {"code":200,"type":"unknown","message":"logged in 
✓  GET      200  /v2/user/logout
   {"code":200,"type":"unknown","message":"ok"}
✓  GET      200  /v2/user/bishopfox
   {"id":1,"username":"bishopfox","firstName":"bishop
✓  PUT      200  /v2/user/bishopfox
   {"code":200,"type":"unknown","message":"1"}

मैन्युअल परीक्षण के लिए कमांड्स की सूची तैयार करने के लिए prepare कमांड का उपयोग करें। वर्तमान में curl और sqlmap दोनों का समर्थन करता है। आपको संभवतः इन्हें थोड़ा संशोधित करना होगा।

$ sj prepare -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080

$ curl -X POST "https://petstore.swagger.io/v2/pet" -H 'Content-Type: application/json' -d '{"category":{"id":1,"name":"bishopfox"},"id":1,"name":"doggie","photoUrls":"https://bishopfox.com","status":"available","tags":[{"id":1,"name":"bishopfox"}]}'
$ curl -X PUT "https://petstore.swagger.io/v2/pet" -H 'Content-Type: application/json' -d '{"category":{"id":1,"name":"bishopfox"},"id":1,"name":"doggie","photoUrls":"https://bishopfox.com","status":"available","tags":[{"id":1,"name":"bishopfox"}]}'
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByStatus?status=1"
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByTags?tags=1"
$ curl -X GET "https://petstore.swagger.io/v2/pet/1"
$ curl -X POST "https://petstore.swagger.io/v2/pet/1" -H 'Content-Type: application/x-www-form-urlencoded' -d 'name=bishopfox&status=bishopfox'
$ curl -X POST "https://petstore.swagger.io/v2/pet/1/uploadImage" -H 'Content-Type: application/x-www-form-urlencoded' -d 'additionalMetadata=bishopfox&file=1'
$ curl -X GET "https://petstore.swagger.io/v2/store/inventory"
$ curl -X POST "https://petstore.swagger.io/v2/store/order" -H 'Content-Type: application/json' -d '{"complete":true,"id":1,"petId":1,"quantity":1,"shipDate":"1990-01-01","status":"placed"}'
$ curl -X GET "https://petstore.swagger.io/v2/store/order/1"
$ curl -X POST "https://petstore.swagger.io/v2/user" -H 'Content-Type: application/json' -d '{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}'
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithArray" -H 'Content-Type: application/json' -d '[{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}]'
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithList" -H 'Content-Type: application/json' -d '[{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}]'
$ curl -X GET "https://petstore.swagger.io/v2/user/login?username=bishopfox&password=bishopfox"
$ curl -X GET "https://petstore.swagger.io/v2/user/logout"
$ curl -X GET "https://petstore.swagger.io/v2/user/bishopfox"
$ curl -X PUT "https://petstore.swagger.io/v2/user/bishopfox" -H 'Content-Type: application/json' -d '{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}'

Multiple request body content types

एक ऑपरेशन अक्सर कई कंटेंट प्रकारों के अंतर्गत एक ही बॉडी घोषित करता है। डिफ़ॉल्ट रूप से sj वह भेजता है जो स्वीकार किए जाने की सबसे अधिक संभावना है, पहले application/json, फिर application/x-www-form-urlencoded, फिर multipart/form-data, फिर XML को प्राथमिकता देता है। चयन नियतात्मक है, इसलिए बार-बार चलाने पर समान कमांड उत्पन्न होते हैं।

चूँकि JSON पार्सर और XML पार्सर अलग-अलग हमले की सतह हैं, --all-content-types केवल पसंदीदा के बजाय प्रत्येक घोषित प्रकार भेजता है:

श्रेणियाँ