Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
feroxfuzz — Rust में संरचना-जागरूक ब्लैक-बॉक्स HTTP फ़ज़र विकसित करें, जिसमें कस्टम वेब और API परीक्षण के लिए कंपोज़ेबल म्यूटेटर, शेड्यूलर, ऑब्ज़र्वर, डिसाइडर और प्रोसेसर शामिल हों। | Kitploit
उपकरण/GitHubGitHub/epi052/feroxfuzz
एपीआई सुरक्षा परीक्षणवेब सुरक्षाफज़िंगउपयोगिताएँ और फ्रेमवर्क
GitHubepi052/feroxfuzz

feroxfuzz

Rust में संरचना-जागरूक ब्लैक-बॉक्स HTTP फ़ज़र विकसित करें, जिसमें कस्टम वेब और API परीक्षण के लिए कंपोज़ेबल म्यूटेटर, शेड्यूलर, ऑब्ज़र्वर, डिसाइडर और प्रोसेसर शामिल हों।

रिपॉजिटरी देखें
22319178 महीने पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें


🚀 FeroxFuzz 🚀

एक संरचना-जागरूक HTTP फ़ज़िंग लाइब्रेरी


🤔 एक और ferox? क्यों? 🤔

कोई बात नहीं, यह कोई और कमांड-लाइन टूल नहीं है, यह एक लाइब्रेरी है! 😁

अधिक विशेष रूप से, FeroxFuzz एक संरचना-जागरूक HTTP फ़ज़िंग लाइब्रेरी है।

FeroxFuzz लिखने का प्राथमिक लक्ष्य feroxbuster से कुछ मुख्य हिस्सों को निकालकर ऐसी जगह ले जाना था जहाँ वे अन्य लोगों के लिए सामान्य रूप से उपयोगी हो सकें। ऐसा करके, मेरी आशा है कि जो कोई भी Rust में वेब टूलिंग और/या एकमुश्त वेब फ़ज़र लिखना चाहता है, वह न्यूनतम प्रयास के साथ ऐसा कर सकता है।

डिज़ाइन

FeroxFuzz का समग्र डिज़ाइन LibAFL से लिया गया है। FeroxFuzz LibAFL: A Framework to Build Modular and Reusable Fuzzers (pre-print) में सूचीबद्ध अधिकांश घटकों को लागू करता है। जब FeroxFuzz विचलित होता है, तो यह आमतौर पर async कोड का समर्थन करने के कारण होता है।

LibAFL के समान, FeroxFuzz एक संयोजनीय फ़ज़िंग लाइब्रेरी है। हालाँकि, LibAFL के विपरीत, FeroxFuzz पूरी तरह से ब्लैक बॉक्स HTTP फ़ज़िंग पर केंद्रित है।

फ़ज़-लूप निष्पादन प्रवाह

नीचे FeroxFuzz द्वारा उपयोग किए जाने वाले विभिन्न घटकों, हुकों और नियंत्रण प्रवाह का एक दृश्य चित्रण है।

fuzz-flow

🚧 चेतावनी: निर्माणाधीन 🚧

FeroxFuzz बहुत सक्षम है, और इसे नए feroxbuster के लिए मेरी सभी नियोजित आवश्यकताओं को पूरा करने के लिए बनाया गया था। हालाँकि, मुझे अभी भी उम्मीद है कि feroxbuster के नए संस्करण पर काम शुरू होने पर FeroxFuzz का API, कम से कम थोड़ा बदल जाएगा।

जब तक API स्थिर नहीं हो जाता, breaking changes हो सकते हैं होंगे।

आरंभ करना

आरंभ करने का सबसे आसान तरीका है अपने प्रोजेक्ट के Cargo.toml में FeroxFuzz को शामिल करना।

[dependencies]
feroxfuzz = { version = "1.0.0-rc.13" }

दस्तावेज़

examples/ फ़ोल्डर के अलावा, API दस्तावेज़ों में घटकों का व्यापक दस्तावेज़ीकरण और उनके उपयोग के उदाहरण हैं।

  • FeroxFuzz API Docs: FeroxFuzz के API दस्तावेज़, जो इस रिपॉजिटरी में doc टिप्पणियों से स्वचालित रूप से उत्पन्न होते हैं।
  • Official Examples: FeroxFuzz के समर्पित, चलाने योग्य उदाहरण, जो विशिष्ट अवधारणाओं में गहराई से जाने के लिए बहुत अच्छे हैं और अत्यधिक टिप्पणी किए गए हैं।

उदाहरण

नीचे दिया गया उदाहरण (examples/async-simple.rs) FeroxFuzz का उपयोग करके fuzzer लिखने के लिए न्यूनतम आवश्यकता दिखाता है।

यदि सोर्स का उपयोग कर रहे हैं, तो उदाहरण को निम्न कमांड का उपयोग करके feroxfuzz/ निर्देशिका से चलाया जा सकता है:

नोट: जब तक आपकी मशीन पर पोर्ट 8000 पर एक वेबसर्वर नहीं चल रहा है, आपको Request::from_url में पास किए गए लक्ष्य को बदलना होगा।

cargo run --example async-simple
#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    // create a new corpus from the given list of words
    let words = Wordlist::from_file("./examples/words")?
        .name("words")
        .build();

    // pass the corpus to the state object, which will be shared between all of the fuzzers and processors
    let mut state = SharedState::with_corpus(words);

    // bring-your-own client, this example uses the reqwest library
    let req_client = reqwest::Client::builder().build()?;

    // with some client that can handle the actual http request/response stuff
    // we can build a feroxfuzz client, specifically an asynchronous client in this
    // instance.
    //
    // feroxfuzz provides both a blocking and an asynchronous client implementation
    // using reqwest. 
    let client = AsyncClient::with_client(req_client);

    // ReplaceKeyword mutators operate similar to how ffuf/wfuzz work, in that they'll
    // put the current corpus item wherever the keyword is found, as long as its found
    // in data marked fuzzable (see ShouldFuzz directives below)
    let mutator = ReplaceKeyword::new(&"FUZZ", "words");

    // fuzz directives control which parts of the request should be fuzzed
    // anything not marked fuzzable is considered to be static and won't be mutated
    //
    // ShouldFuzz directives map to the various components of an HTTP request
    let request = Request::from_url(
        "http://localhost:8000/?admin=FUZZ",
        Some(&[ShouldFuzz::URLParameterValues]),
    )?;

    // a `StatusCodeDecider` provides a way to inspect each response's status code and decide upon some Action
    // based on the result of whatever comparison function (closure) is passed to the StatusCodeDecider's
    // constructor
    //
    // in plain english, the `StatusCodeDecider` below will check to see if the request's http response code
    // received is equal to 200/OK. If the response code is 200, then the decider will recommend the `Keep`
    // action be performed. If the response code is anything other than 200, then the recommendation will
    // be to `Discard` the response.
    //
    // `Keep`ing the response means that the response will be allowed to continue on for further processing
    // later in the fuzz loop.
    let decider = StatusCodeDecider::new(200, |status, observed, _state| {
        if status == observed {
            Action::Keep
        } else {
            Action::Discard
        }
    });

    // a `ResponseObserver` is responsible for gathering information from each response and providing
    // that information to later fuzzing components, like Processors. It knows things like the response's
    // status code, content length, the time it took to receive the response, and a bunch of other stuff.
    let response_observer: ResponseObserver<AsyncResponse> = ResponseObserver::new();
टूल डाउनलोड करें