Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
sj — एक्सपोज़्ड (Swagger/OpenAPI) परिभाषा फ़ाइलों में परिभाषित एंडपॉइंट्स के ऑडिटिंग के लिए एक उपकरण। | Kitploit
उपकरण/GitHubGitHub/bishopfox/sj
भेद्यता स्कैनरएपीआई सुरक्षा परीक्षणवेब सुरक्षापेनिट्रेशन टेस्टिंग
GitHubbishopfox/sj

sj

एक्सपोज़्ड (Swagger/OpenAPI) परिभाषा फ़ाइलों में परिभाषित एंडपॉइंट्स के ऑडिटिंग के लिए एक उपकरण।

रिपॉजिटरी देखें
867113422 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
# sj (Swagger Jacker)

![](https://assets.kitploit.com/production/public/readmes/6268/d69b4e45e89d795400d5696d7ca5699a54d29fe151feb330f01b8ca9fc8be51f.png)

sj एक कमांड लाइन टूल है जिसे उजागर Swagger/OpenAPI परिभाषा फ़ाइलों का ऑडिट करने में सहायता के लिए डिज़ाइन किया गया है, जो संबंधित API एंडपॉइंट्स की कमजोर प्रमाणीकरण के लिए जाँच करता है। यह मैन्युअल भेद्यता परीक्षण के लिए कमांड टेम्पलेट्स भी प्रदान करता है।

यह परिभाषा फ़ाइल से पथ, पैरामीटर और स्वीकृत विधियों को पार्स करके ऐसा करता है, फिर परिणामों का उपयोग पाँच उप-कमांड्स में से एक के साथ करता है:
- `automate` - अनुरोधों की एक श्रृंखला तैयार करता है और प्रतिक्रिया के स्टेटस कोड का विश्लेषण करता है।
- `prepare` - मैन्युअल परीक्षण के लिए उपयोग किए जाने वाले कमांड्स की सूची उत्पन्न करता है।
- `endpoints` - कच्चे API रूट्स की सूची उत्पन्न करता है। *पथ मानों को परीक्षण डेटा से प्रतिस्थापित नहीं किया जाएगा*।
- `brute` - सामान्यतः उपयोग किए जाने वाले फ़ाइल पथों के आधार पर ऑपरेशन परिभाषाओं को खोजने के लिए लक्ष्य पर अनुरोधों की एक श्रृंखला भेजता है।
- `convert` - एक परिभाषा फ़ाइल को v2 से v3 में परिवर्तित करता है।

## Build

स्रोत से संकलित करने के लिए, सुनिश्चित करें कि आपके पास Go संस्करण `>= 1.22.5` स्थापित है और रिपॉजिटरी के भीतर से `go build` चलाएँ:

```bash
$ git clone https://github.com/BishopFox/sj.git
$ cd sj/
$ go build .
```

## Install

टूल का नवीनतम संस्करण स्थापित करने के लिए, चलाएँ:

```bash
$ go install github.com/BishopFox/sj@latest

# Note: you may also need to place the path to your Go binaries within your PATH environment variable:
$ export PATH=$PATH:~/go/bin
```

## Usage

> प्रत्येक परिभाषित एंडपॉइंट पर अनुरोधों की एक श्रृंखला भेजने और प्रत्येक प्रतिक्रिया के स्टेटस कोड का विश्लेषण करने के लिए `automate` कमांड का उपयोग करें।

```bash
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080               

Gathering API details.
⚠  POST     500  /v2/pet
⚠  PUT      500  /v2/pet
✓  GET      200  /v2/pet/findByStatus
✓  GET      200  /v2/pet/findByTags
✓  GET      200  /v2/pet/1
✓  POST     200  /v2/pet/1
⚠  POST     N/A  /v2/pet/1/uploadImage
✓  GET      200  /v2/store/inventory
⚠  POST     N/A  /v2/store/order
⚠  GET      N/A  /v2/store/order/1
✓  POST     200  /v2/user
⚠  POST     N/A  /v2/user/createWithArray
⚠  POST     N/A  /v2/user/createWithList
✓  GET      200  /v2/user/login
✓  GET      200  /v2/user/logout
✓  GET      200  /v2/user/bishopfox
✓  PUT      200  /v2/user/bishopfox
```

आप मिलान किए गए अनुरोधों को एक अलग प्रॉक्सी (जैसे, Burp Suite) के माध्यम से रीप्ले करने के लिए `--replay-proxy` फ़्लैग का उपयोग कर सकते हैं। यह आपको सभी ट्रैफ़िक को एक प्रॉक्सी (या सीधे) के माध्यम से रूट करने की सुविधा देता है, जबकि केवल रुचिकर परिणाम आपके इंटरसेप्शन प्रॉक्सी को भेजता है:

```bash
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi --replay-proxy http://127.0.0.1:8080
```

आप इसे `--proxy` के साथ भी जोड़ सकते हैं ताकि स्कैनिंग ट्रैफ़िक को एक अलग प्रॉक्सी के माध्यम से रूट किया जा सके, जबकि मिलानों को Burp पर रीप्ले किया जा सके:

```bash
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://proxy:9090 --replay-proxy http://127.0.0.1:8080
```

आप आंशिक (या पूर्ण) प्रतिक्रिया देखने के लिए वर्बोज़ आउटपुट का अनुरोध भी कर सकते हैं:

```bash
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080 -v           

Gathering API details.
⚠  POST     500  /v2/pet
   {"code":500,"type":"unknown","message":"something 
⚠  PUT      500  /v2/pet
   {"code":500,"type":"unknown","message":"something 
✓  GET      200  /v2/pet/findByStatus
   []
✓  GET      200  /v2/pet/findByTags
   []
✓  GET      200  /v2/pet/1
   {"id":1,"category":{"id":1,"name":"cat"},"name":"d
✓  POST     200  /v2/pet/1
   {"code":200,"type":"unknown","message":"1"}
⚠  POST     N/A  /v2/pet/1/uploadImage
✓  GET      200  /v2/store/inventory
   {"sold":115,"bishopfox":1,"SOLD":1,"string":224,"d
⚠  POST     N/A  /v2/store/order
⚠  GET      N/A  /v2/store/order/1
✓  POST     200  /v2/user
   {"code":200,"type":"unknown","message":"1"}
⚠  POST     N/A  /v2/user/createWithArray
⚠  POST     N/A  /v2/user/createWithList
✓  GET      200  /v2/user/login
   {"code":200,"type":"unknown","message":"logged in 
✓  GET      200  /v2/user/logout
   {"code":200,"type":"unknown","message":"ok"}
✓  GET      200  /v2/user/bishopfox
   {"id":1,"username":"bishopfox","firstName":"bishop
✓  PUT      200  /v2/user/bishopfox
   {"code":200,"type":"unknown","message":"1"}
```

> मैन्युअल परीक्षण के लिए कमांड्स की सूची तैयार करने के लिए `prepare` कमांड का उपयोग करें। वर्तमान में `curl` और `sqlmap` दोनों का समर्थन करता है। आपको संभवतः इन्हें थोड़ा संशोधित करना होगा।

```bash
$ sj prepare -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080

$ curl -X POST "https://petstore.swagger.io/v2/pet" -H 'Content-Type: application/json' -d '{"category":{"id":1,"name":"bishopfox"},"id":1,"name":"doggie","photoUrls":"https://bishopfox.com","status":"available","tags":[{"id":1,"name":"bishopfox"}]}'
$ curl -X PUT "https://petstore.swagger.io/v2/pet" -H 'Content-Type: application/json' -d '{"category":{"id":1,"name":"bishopfox"},"id":1,"name":"doggie","photoUrls":"https://bishopfox.com","status":"available","tags":[{"id":1,"name":"bishopfox"}]}'
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByStatus?status=1"
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByTags?tags=1"
$ curl -X GET "https://petstore.swagger.io/v2/pet/1"
$ curl -X POST "https://petstore.swagger.io/v2/pet/1" -H 'Content-Type: application/x-www-form-urlencoded' -d 'name=bishopfox&status=bishopfox'
$ curl -X POST "https://petstore.swagger.io/v2/pet/1/uploadImage" -H 'Content-Type: application/x-www-form-urlencoded' -d 'additionalMetadata=bishopfox&file=1'
$ curl -X GET "https://petstore.swagger.io/v2/store/inventory"
$ curl -X POST "https://petstore.swagger.io/v2/store/order" -H 'Content-Type: application/json' -d '{"complete":true,"id":1,"petId":1,"quantity":1,"shipDate":"1990-01-01","status":"placed"}'
$ curl -X GET "https://petstore.swagger.io/v2/store/order/1"
$ curl -X POST "https://petstore.swagger.io/v2/user" -H 'Content-Type: application/json' -d '{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}'
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithArray" -H 'Content-Type: application/json' -d '[{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}]'
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithList" -H 'Content-Type: application/json' -d '[{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}]'
$ curl -X GET "https://petstore.swagger.io/v2/user/login?username=bishopfox&password=bishopfox"
$ curl -X GET "https://petstore.swagger.io/v2/user/logout"
$ curl -X GET "https://petstore.swagger.io/v2/user/bishopfox"
$ curl -X PUT "https://petstore.swagger.io/v2/user/bishopfox" -H 'Content-Type: application/json' -d '{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}'
```

### Multiple request body content types

एक ऑपरेशन अक्सर कई कंटेंट प्रकारों के अंतर्गत एक ही बॉडी घोषित करता है। डिफ़ॉल्ट रूप से `sj` वह भेजता है जो स्वीकार किए जाने की सबसे अधिक संभावना है, पहले `application/json`, फिर `application/x-www-form-urlencoded`, फिर `multipart/form-data`, फिर XML को प्राथमिकता देता है। चयन नियतात्मक है, इसलिए बार-बार चलाने पर समान कमांड उत्पन्न होते हैं।

चूँकि JSON पार्सर और XML पार्सर अलग-अलग हमले की सतह हैं, `--all-content-types` केवल पसंदीदा के बजाय प्रत्येक घोषित प्रकार भेजता है:

```bash
$ sj prepare -l spec.yaml -T https://api.example.com -q --all-content-types

$ curl -X POST "https://api.example.com/multi" -H 'Content-Type: application/json' -d '{"name":"bishopfox","size":1}'
$ curl -X POST "https://api.example.com/multi" -H 'Content-Type: application/x-www-form-urlencoded' -d 'name=bishopfox&size=1'
$ curl -X POST "https://api.example.com/multi" -F 'name=bishopfox' -F 'size=1'
$ curl -X POST "https://api.example.com/multi" -H 'Content-Type: application/xml' -d '<name>bishopfox</name><size>1</size>'
```

ध्यान दें कि यह लक्ष्य पर भेजे जाने वाले अनुरोधों की संख्या को कई गुना बढ़ा देता है, और यह कि `--replay-proxy` उनमें से प्रत्येक को प्राप्त करता है।

एक विशिष्ट एन्कोडिंग का परीक्षण करने के लिए, इसे `-H` के साथ पास करें। जब ऑपरेशन उस प्रकार को घोषित करता है, तो `sj` उसके अंतर्गत मेल खाती बॉडी भेजता है:

```bash
$ sj prepare -l spec.yaml -T https://api.example.com -q -H "Content-Type: application/xml"
```

जब ऑपरेशन इसे घोषित *नहीं* करता है, तो `sj` चेतावनी देता है और आपके हेडर के अंतर्गत पसंदीदा बॉडी वैसे भी भेजता है, जो पार्सर-डिफरेंशियल परीक्षण के लिए उपयोगी है। जिन कंटेंट प्रकारों के लिए `sj` बॉडी एन्कोड नहीं कर सकता (`application/octet-stream`, `text/plain`), उन्हें भ्रामक हेडर के अंतर्गत खाली बॉडी के रूप में भेजने के बजाय छोड़ दिया जाता है।

> प्रदान की गई परिभाषा फ़ाइल से कच्चे एंडपॉइंट्स की सूची उत्पन्न करने के लिए `endpoints` कमांड का उपयोग करें।

```bash
$ sj endpoints -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080

INFO[0000] Gathering endpoints.
                        
/v2/store/inventory
/v2/store/order/{orderId}
/v2/pet
/v2/pet
/v2/store/order
/v2/user/createWithList
/v2/pet/{petId}/uploadImage
/v2/pet/findByTags
/v2/pet/{petId}
/v2/pet/{petId}
/v2/user/{username}
/v2/user/{username}
/v2/user/createWithArray
/v2/pet/findByStatus
/v2/user/login
/v2/user/logout
/v2/user
```

> लक्ष्य पर एक परिभाषा फ़ाइल खोजने के प्रयास में अनुरोधों की एक श्रृंखला भेजने के लिए `brute` कमांड का उपयोग करें।

```bash
$ sj brute -u https://petstore.swagger.io -qi -p http://127.0.0.1:8080 -e
INFO[0000] Sending 2173 requests. This could take a while... 
Request: 343
INFO[0033] Definition file found: https://petstore.swagger.io/v2/swagger 
```

> एक परिभाषा फ़ाइल को संस्करण 2 से संस्करण 3 में परिवर्तित करने के लिए `convert` कमांड का उपयोग करें।

```bash
$ sj convert -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080 -o openapi.json

INFO[0000] Gathering API details.
                      
INFO[0000] Wrote file to /current/directory/openapi.json 
```

## Help

कमांड्स की पूरी सूची `--help` फ़्लैग का उपयोग करके पाई जा सकती है:

```bash
$ sj --help
The process of reviewing and testing exposed API definition files is often tedious and requires a large investment of time for a thorough review.

sj (swaggerjacker) is a CLI tool that can be used to perform an initial check of API endpoints identified through exposed Swagger/OpenAPI definition files. 
Once you determine what endpoints require authentication and which do not, you can use the "prepare" command to generate command templates for further (manual) testing.

Example usage:

Perform a quick check of endpoints which require authentication:
$ sj automate -u https://petstore.swagger.io/v2/swagger.json

Generate a list of commands to use for manual testing:
$ sj prepare -u https://petstore.swagger.io/v2/swagger.json

Generate a list of raw API routes for use with custom scripts:
$ sj endpoints -u https://petstore.swagger.io/v2/swagger.json

Perform a brute-force attack against the target to identify hidden definition files:
$ sj brute -u https://petstore.swagger.io

Convert a Swagger (v2) definition file to an OpenAPI (v3) definition file:
$ sj convert -u https://petstore.swagger.io/v2/swagger.json -o openapi.json

Usage:
  sj [flags]
  sj [command]

Available Commands:
  automate    Sends a series of automated requests to the discovered endpoints.
  brute       Sends a series of automated requests to discover hidden API operation definitions.
  convert     Converts a Swagger definition file to an OpenAPI v3 definition file.
  endpoints   Prints a list of endpoints from the target.
  help        Help about any command
  prepare     Prepares a set of commands for manual testing of each endpoint.

Flags:
  -A, --agent string            Set the User-Agent string. (default "Swagger Jacker (github.com/BishopFox/sj)")
      --all-content-types       Send a separate request for every request body content type an operation declares, instead of only the preferred one.
  -b, --base-path string        Set the API base path if not defined in the definition file (i.e. /V2/).
  -f, --format string           Declare the format of the definition file (json/yaml/yml/js). (default "json")
  -H, --headers stringArray     Add custom headers, separated by a colon ("Name: Value"). Multiple flags are accepted.
  -h, --help                    help for sj
  -i, --insecure                Ignores server certificate validation.
  -l, --local-file string       Loads the documentation from a local file.
  -o, --outfile string          Output the results to a file. Only supported for the 'automate' and 'brute' commands at this time.
  -p, --proxy string            Proxy host and port. Example: http://127.0.0.1:8080 (default "NOPROXY")
  -q, --quiet                   Do not prompt for user input - uses default values for all requests.
      --replay-proxy string     Replay matched requests using this proxy.
      --randomize-user-agent    Randomizes the user agent string. Default is 'false'.
  -s, --safe-word stringArray   Avoids 'dangerous word' check for the specified word(s). Multiple flags are accepted.
  -T, --target string           Manually set a target for the requests to be made if separate from the host the documentation resides on.
  -t, --timeout int             Set the request timeout period. (default 30)
  -u, --url string              Loads the documentation file from a URL
  -v, --version                 version for sj

Use "sj [command] --help" for more information about a command.
```
टूल डाउनलोड करें