
Default signature for Jaeles Scanner
यह प्रोजेक्ट Osmedeus Engine का हिस्सा था। देखें कि इसे @OsmedeusEngine पर कैसे एकीकृत किया गया था।
jaeles config init
Or
Try to clone signatures folder to somewhere like this
git clone --depth=1 https://github.com/jaeles-project/jaeles-signatures /tmp/jaeles-signatures/
then reload them in the DB with this command.
jaeles config -a reload --signDir /tmp/jaeles-signatures
Scan Usage example:
jaeles scan -s <signature> -u <url>
jaeles scan -c 50 -s <signature> -U <list_urls> -L <level-of-signatures>
jaeles scan -c 50 -s <signature> -U <list_urls>
jaeles scan -c 50 -s <signature> -U <list_urls> -p 'dest=xxx.burpcollaborator.net'
jaeles scan -c 50 -s <signature> -U <list_urls> -f 'noti_slack "{{.vulnInfo}}"'
jaeles scan -v -c 50 -s <signature> -U list_target.txt -o /tmp/output
jaeles scan -s <signature> -s <another-selector> -u http://example.com
jaeles scan -G -s <signature> -s <another-selector> -x <exclude-selector> -u http://example.com
cat list_target.txt | jaeles scan -c 100 -s <signature>
jaeles scan -s '/tmp/custom-signature/sensitive/.*' -L 2 --fi
Examples:
jaeles scan -s 'jira' -s 'ruby' -u target.com
jaeles scan -c 50 -s 'java' -x 'tomcat' -U list_of_urls.txt
jaeles scan -G -c 50 -s '/tmp/custom-signature/.*' -U list_of_urls.txt
jaeles scan -v -s '~/my-signatures/products/wordpress/.*' -u 'https://wp.example.com/blog/' -p 'root=[[.URL]]'
cat urls.txt | grep 'interesting' | jaeles scan -c 50 -s /tmp/jaeles-signatures/cves/sample.yaml -U list_of_urls.txt --proxy http://127.0.0.1:8080
Config Command examples:
# Init default signatures
jaeles config init
# Update latest signatures
jaeles config update
jaeles config update --repo http://github.com/jaeles-project/another-signatures --user admin --pass admin
jaeles config update --repo [email protected]/jaeles-project/another-signatures -K your_private_key
# Reload signatures from a standard signatures folder (contain passives + resources)
jaeles config reload --signDir ~/standard-signatures/
# Add custom signatures from folder
jaeles config add --signDir ~/custom-signatures/
# Clean old stuff
jaeles config clean
# More examples
jaeles config add --signDir /tmp/standard-signatures/
jaeles config cred --user sample --pass not123456
For full Usage:
jaeles -hh
Jaeles सिग्नेचर को एक एकल फ़ाइल के रूप में खोजता है, इसलिए आप इसे अपनी इच्छानुसार संरचित कर सकते हैं। यह केवल एक उदाहरण है।
फ़ज़ सिग्नेचर में बहुत सारे गलत-सकारात्मक परिणाम हो सकते हैं क्योंकि मैं यह सटीक रूप से परिभाषित नहीं कर सकता कि हर चीज़ के लिए क्या असुरक्षित है। इसलिए सुनिश्चित करें कि आप जानते हैं कि आप यहाँ क्या कर रहे हैं।
वित्तीय योगदानकर्ता बनें और हमारे समुदाय को बनाए रखने में मदद करें। [योगदान करें]
नवीनतम भेद्यताओं को cvebase.com पर देखें
Jaeles को ♥ के साथ @j3ssiejjj द्वारा बनाया गया है और इसे MIT लाइसेंस के तहत जारी किया गया है।
| Page | Description |
|---|
| common | कुछ लोकप्रिय ऐप्स के लिए गलत कॉन्फ़िगरेशन लागू करता है |
| cves | कुछ CVE लागू करता है |
| sensitvie | संवेदनशील जानकारी वाले कुछ सामान्य पथ |
| probe | लक्ष्य द्वारा उपयोग की जाने वाली कुछ तकनीक का पता लगाने के लिए उपयोग किया जाता है |
| passives | निष्क्रिय पहचान के लिए उपयोग किया जाता है |
| fuzz | फ़ज़ मोड के लिए कुछ सामान्य मामले (मुझे पता है कि यहाँ बहुत सारे गलत-सकारात्मक परिणाम हैं) |
| routines | रूटीन का उदाहरण |