Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
syntribos — OpenStack सुरक्षा समूह से Python API सुरक्षा परीक्षण उपकरण | Kitploit
उपकरण/GitHubGitHub/openstack-archive/syntribos
भेद्यता स्कैनरएपीआई सुरक्षा परीक्षणवेब सुरक्षाफज़िंगपेनिट्रेशन टेस्टिंगArchived
GitHubopenstack-archive/syntribos

syntribos

OpenStack सुरक्षा समूह से Python API सुरक्षा परीक्षण उपकरण

रिपॉजिटरी देखें
27172206 साल पहलेKitploit द्वारा समीक्षित
वेबसाइट

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

टीम और रिपॉजिटरी टैग

.. image:: http://governance.openstack.org/badges/syntribos.svg :target: http://governance.openstack.org/reference/tags/index.html

.. image:: http://img.shields.io/badge/docs-latest-brightgreen.svg?style=flat :target: http://docs.openstack.org/developer/syntribos/

.. image:: http://img.shields.io/pypi/v/syntribos.svg :target: http://pypi.python.org/pypi/syntribos/

.. image:: http://img.shields.io/pypi/pyversions/syntribos.svg :target: http://pypi.python.org/pypi/syntribos/

.. image:: http://img.shields.io/pypi/wheel/syntribos.svg :target: http://pypi.python.org/pypi/syntribos/

.. image:: http://img.shields.io/irc/%23openstack-security.png :target: http://webchat.freenode.net/?channels=openstack-security

================================================= Syntribos, एक स्वचालित API सुरक्षा परीक्षण उपकरण

Syntribos एक ओपन सोर्स स्वचालित API सुरक्षा परीक्षण उपकरण है जिसे OpenStack सुरक्षा परियोजना <https://wiki.openstack.org/wiki/Security>_ के सदस्यों द्वारा बनाए रखा जाता है।

एक सरल कॉन्फ़िगरेशन फ़ाइल और एक उदाहरण HTTP अनुरोध दिए जाने पर, syntribos किसी भी API URL, URL पैरामीटर, HTTP हेडर और अनुरोध निकाय फ़ील्ड को दिए गए स्ट्रिंग्स के सेट से बदल सकता है। Syntribos स्वचालित रूप से अनुरोध में प्रत्येक स्थान पर पुनरावृत्ति करता है। Syntribos का उद्देश्य सामान्य सुरक्षा दोषों जैसे SQL इंजेक्शन, LDAP इंजेक्शन, बफर ओवरफ़्लो आदि का स्वचालित रूप से पता लगाना है। इसके अलावा, syntribos का उपयोग स्वचालित फ़ज़िंग द्वारा नए सुरक्षा दोषों की पहचान करने में भी किया जा सकता है।

Syntribos किसी भी API का परीक्षण करने में सक्षम है, लेकिन इसे OpenStack <https://www.openstack.org/>__ अनुप्रयोगों को ध्यान में रखते हुए डिज़ाइन किया गया है।

परीक्षणों की सूची~~~~~~~~~~~~~

With syntribos, you can initiate automated testing of any API with minimal configuration effort. Syntribos is ideal for testing the OpenStack API as it will help you in automatically downloading a set of templates of some of the bigger OpenStack projects like nova, neutron, keystone, etc.

A short list of tests that can be run using syntribos is given below:

  • Buffer Overflow
  • Command Injection
  • CORS Wildcard
  • Integer Overflow
  • LDAP Injection
  • SQL Injection
  • String Validation
  • XML External Entity
  • Cross Site Scripting (XSS)
  • Regex Denial of Service (ReDoS)
  • JSON Parser Depth Limit
  • User Defined

Buffer Overflow

Buffer overflow_ attacks, in the context of a web application, force an application to handle more data than it can hold in a buffer. In syntribos, a buffer overflow test is attempted by injecting a large string into the body of an HTTP request.

Command Injection

Command injection_ attacks are done by injecting arbitrary commands in an attempt to execute these commands on a remote system. In syntribos, this is achieved by injecting a set of strings that have been proven as successful executors of injection attacks.

CORS Wildcard

CORS wildcard_ tests are used to verify if a web server allows cross-domain resource sharing from any external URL (wild carding of Access-Control-Allow-Origin header), rather than a white list of URLs.

Integer Overflow

Integer overflow_ tests in syntribos attempt to inject numeric values that the remote application may fail to represent within its storage. For example, injecting a 64 bit number into a 32 bit integer type.

LDAP Injection

Syntribos attempts LDAP injection_ attacks by injecting LDAP statements into HTTP requests; if an application fails to properly sanitize the request content, it may be possible to execute arbitrary commands.

SQL Injection

SQL injection_ attacks are one of the most common web application attacks. If the user input is not properly sanitized, it is fairly easy to execute SQL queries that may result in an attacker reading sensitive information or gaining control of the SQL server. In syntribos, an application is tested for SQL injection vulnerabilities by injecting SQL strings into the HTTP request.

String Validation

Some string patterns are not sanitized effectively by the input validator and may cause the application to crash. String validation attacks in syntribos try to exploit this by inputting characters that may cause string validation vulnerabilities. For example, special unicode characters, emojis, etc.

XML External Entity

XML external entity_ attacks target the web application's XML parser. If an XML parser allows processing of external entities referenced in an XML document then an attacker might be able to cause a denial of service, or leakage of information, etc. Syntribos tries to inject a few malicious strings into an XML body while sending requests to an application in an attempt to obtain an appropriate response.

Cross Site Scripting (XSS)

XSS_ attacks inject malicious JavaScript into a web application. Syntribos tries to find potential XSS issues by injecting string containing "script" and other HTML tags into request fields.

Regex Denial of Service (ReDoS)

ReDoS_ attacks attempt to produce a denial of service by providing a regular expression that takes a very long time to evaluate. This can cause the regex engine to backtrack indefinitely, which can slow down some parsers or even cause a processing halt. The attack exploits the fact that most regular expression implementations have an exponential time worst case complexity.

JSON Parser Depth Limit

There is a possibility that the JSON parser will reach depth limit and crash, resulting in a successful overflow of the JSON parsers depth limit, leading to a DoS vulnerability. Syntribos tries to check for this, and raises an issue if the parser crashes.

User defined Test

This test gives users the ability to fuzz using user defined fuzz data and provides an option to look for failure strings provided by the user. The fuzz data needs to be provided using the config option [user_defined].

Example::

[user_defined] payload=<payload_file> failure_strings=<[list_of_failure_strings] # optional

Other than these built-in tests, you can extend syntribos by writing your own custom tests. To do this, download the source code and look at the tests in the syntribos/tests directory. The CORS test may be an easy one to emulate. In the same way, you can also add different extensions to the tests. To see how extensions can be written please see the syntribos/extensions directory.

.. _buffer overflow: https://en.wikipedia.org/wiki/Buffer_overflow .. _Command injection: https://www.owasp.org/index.php/Command_Injection .. _CORS wildcard: https://www.owasp.org/index.php/Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007) .. _Integer overflow: https://en.wikipedia.org/wiki/Integer_overflow .. _LDAP injection: https://www.owasp.org/index.php/LDAP_injection .. _SQL injection: https://www.owasp.org/index.php/SQL_Injection .. _XML external entity: https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing .. _XSS: https://www.owasp.org/index.php/Cross-site_Scripting_(XSS) .. _ReDoS: https://en.wikipedia.org/wiki/ReDoS

Details

  • Documentation_
  • Free software: Apache license_
  • Launchpad project_
  • Blueprints_
  • Bugs_
  • Source code_

Supported Operating Systems

Syntribos मुख्य रूप से Linux और Mac वातावरण में विकसित किया गया है और अधिकांश Unix और Linux आधारित ऑपरेटिंग सिस्टम पर काम करेगा। इस समय, हम Windows का समर्थन नहीं कर रहे हैं, लेकिन भविष्य में यह बदल सकता है।
टूल डाउनलोड करें