Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
crithit — एक एकल वर्डलिस्ट आइटम लेता है और अगले पर जाने से पहले वेबसाइटों के बड़े संग्रह पर एक-एक करके इसका परीक्षण करता है। कई होस्टों पर कमजोरियों की क्रॉस-चेक करने के लिए सिग्नेचर बनाएं। | Kitploit
उपकरण/GitHubGitHub/codingo/crithit
भेद्यता स्कैनरजानकारी एकत्र करनाWAF बाईपासवेब सुरक्षापेनिट्रेशन टेस्टिंग
GitHubcodingo/crithit

crithit

एक एकल वर्डलिस्ट आइटम लेता है और अगले पर जाने से पहले वेबसाइटों के बड़े संग्रह पर एक-एक करके इसका परीक्षण करता है। कई होस्टों पर कमजोरियों की क्रॉस-चेक करने के लिए सिग्नेचर बनाएं।

रिपॉजिटरी देखें
212446 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

crithit

वेबसाइट निर्देशिका और फ़ाइल ब्रूट फ़ोर्सिंग अत्यधिक पैमाने पर।

License Twitter

CritHit एक एकल वर्डलिस्ट आइटम लेता है और उसे एक बड़े होस्ट संग्रह पर एक-एक करके परीक्षण करता है, फिर अगले वर्डलिस्ट आइटम पर जाता है। इस प्रकार ब्रूट फ़ोर्स करने का उद्देश्य निम्न सीमा वाले वेब एप्लिकेशन फ़ायरवॉल (WAF) प्रतिबंधों से बचना और ब्रूट फ़ोर्सिंग को सामान्य से अधिक तेज चलाने की अनुमति देना है, जब एक साथ कई अनुरोधों के साथ किसी एक होस्ट से संपर्क किया जाता है।

CritHit एकाधिक प्रॉक्सी सूचियों का उपयोग करके परिणामों की कई सत्यापन कर सकता है, साथ ही वेबसाइटों को बेसलाइन करके शोर को फ़िल्टर कर सकता है। इसके अतिरिक्त, यदि आप बड़ी संख्या में वेबसाइटों पर किसी विशिष्ट वस्तु की खोज कर रहे हैं (अधिक होस्ट पर किसी भेद्यता की तुलना करने के लिए), तो आप केवल विशिष्ट डेटा बिंदुओं वाले होस्ट को आउटपुट फ़ाइल में लिखने के लिए --signatures बना और उपयोग कर सकते हैं।

सर्वोत्तम परिणाम CritHit से प्राप्त किए जा सकते हैं इसे एक छोटी (100 महत्वपूर्ण आइटम) वर्डलिस्ट, एक बहुत बड़ी लक्ष्य सूची के साथ एक त्वरित "पहले पास" के रूप में उपयोग करके, और फिर एक परियोजना जैसे ffuf के साथ अधिक सीधे गहराई से खोज करके जहां परिणाम पाए जाते हैं।

श्रेय

EdOverflows के Megplus और TomNomNom के meg परियोजनाओं से प्रेरित जिन्होंने समान विचार पर काम किया।

साथ ही Hakluke और sml555_ को भी धन्यवाद जिन्होंने मुख्य विचार को परिष्कृत किया, प्रोत्साहन दिया, और परीक्षण किया।

चेतावनी

यह डिफ़ॉल्ट सेटिंग्स का उपयोग करके बहुत तेज़ चलता है। यदि आप डोमेन पर साझा WAF वाले लक्ष्य पर काम करते हैं, तो आप जल्दी से प्रतिबंधित हो सकते हैं। आवश्यकतानुसार -n (टाइमआउट) और -c (थ्रेड्स) को समायोजित करें।

स्थापना

निर्भरताएँ स्थापित करें:

  • सबसे पहले, Boost 1.70 को https://www.boost.org/users/history/version_1_70_0.html से डाउनलोड करें और लाइब्रेरी को किसी भी निर्देशिका में निकालें। Boost का एक Unix बिल्ड इस भंडार के /dep/ में स्थित है, अन्य वातावरणों के लिए बिल्ड करने के लिए इसे बदलने की आवश्यकता होगी।
  • एनवायरनमेंट वेरिएबल BOOST_ROOT को निकाली गई लाइब्रेरी के रूट पर सेट करें।
  • यदि आप OpenSSL के बजाय LibreSSL का उपयोग करते हैं। आपको अपने /usr/lib निर्देशिका में libcrypto.so.1.1 और libssl.so.1.1 होना चाहिए, जो इस रेपो की dep/ निर्देशिका में शामिल है।

फिर:

root@kitploit:~
sudo apt-get install libssl-dev

CMake फ़ाइलें बनाएं (वैकल्पिक यदि /codingo/opt में हैं)

root@kitploit:~
cmake -G "Unix Makefiles" 

समाधान बनाएं

root@kitploit:~
make

बिल्ड स्क्रिप्ट

वैकल्पिक रूप से, अपने लक्ष्य वातावरण के लिए नीचे दिए गए को संशोधित करें:

root@kitploit:~
wget "https://dl.bintray.com/boostorg/release/1.70.0/source/boost_1_70_0.tar.gz"
tar -xvzf boost_1_70_0.tar.gz
export BOOST_ROOT="/home/boost_1_70_0"
cd crithit/crithit
cmake -G "Unix Makefiles"
make
./crithit -w _wordlist_ -t _hostnames_

डॉकर

root@kitploit:~
cd crithit/crithit
docker build -t crithit .
docker run -v $(pwd):/input -t crithit -w  /input/_wordlist_ -t /input/_hostnames_

उपयोग

उचित दस्तावेज़ इस भंडार में जोड़े जाने तक इनपुट पैरामीटरों की समीक्षा करने की अनुशंसा की जाती है।

root@kitploit:~
USAGE:

   ./crithit  [--os <filename>] [--signatures <filename>] [-e <filename>]
              [-n <integer>] [--read-for <integer>] [-p <filename>]
              [--max-sockets <integer>] [-V <integer>] [-r] [-b <string>]
              [-s <string>] [-c <integer>] [-t <filename>] [-T <domain
              name>] [--verbose] -w <filename> [-o <filename>] [--]
              [--version] [-h]


Where:

   --os <filename>
     if --signatures is specified, this specifies the output file to write
     result to

   --signatures <filename>
     file containing list of signatures to look out for in top-level
     domains

   -e <filename>,  --exceptions <filename>
     filename containing words...

   -n <integer>,  --wait-for <integer>
     wait N seconds to connect/send data to server(default: 5secs)

   --read-for <integer>
     wait N seconds to receive data from server(default: 10secs)

   -p <filename>,  --proxy <filename>
     a filename containing list of proxy names and port(IP:port)

   --max-sockets <integer>
     Number of sockets to use

   -V <integer>,  --verify <integer>
     verify successful results with different proxies

   -r,  --randomize-agent
     use random user agents for requests

   -b <string>,  --statuscodesblacklist <string>
     Negative status codes (will override statuscodes if set)

   -s <string>,  --statuscodes <string>
     Positive status codes (will be overwritten with statuscodesblacklist
     if set)(default 200,204,301,302,307,401,403,408)

   -c <integer>,  --threads <integer>
     Number of threads to use(default: 12)

   -t <filename>,  --target-list <filename>
     a filename containing the list of targets

   -T <domain name>,  --target <domain name>
     the target

   --verbose
     be verbose with output

   -w <filename>,  --word-list <filename>
     (required)  a filename containing list of words to use

   -o <filename>,  --output <filename>
     output result to (default: stdout)

   --,  --ignore_rest
     Ignores the rest of the labeled arguments following this flag.

   --version
     Displays version information and exits.

   -h,  --help
     Displays usage information and exits.
टूल डाउनलोड करें