
अपाचे टॉमकैट सर्वर की कमजोरियों को स्कैन करने के लिए एक Python स्क्रिप्ट।

Apache Tomcat सर्वर कमजोरियों को स्कैन करने के लिए एक पायथन स्क्रिप्ट।
-tt/--target विकल्प से अलग-अलग लक्ष्य (IP/DNS/CIDR) पढ़ना।-tu/--target-url विकल्प से अलग-अलग लक्ष्य URL पढ़ना।/manager/html की पहुँच की जाँच।--list-cves विकल्प के साथ प्रत्येक संस्करण के CVEs की सूची, --show-cves-descriptions के साथ विस्तृत CVE विवरण दिखाएं।अब आप इसे PyPI से स्थापित कर सकते हैं (नवीनतम संस्करण है) इस आदेश के साथ:
sudo python3 -m pip install apachetomcatscanner
$ ./ApacheTomcatScanner.py -h
Apache Tomcat Scanner v3.4 - by Remi GASCOU (Podalirius)
usage: ApacheTomcatScanner.py [-h] [-v] [--debug] [-C] [--show-cves-descriptions] [-T THREADS] [-s] [--no-colors] [--only-http] [--only-https] [--export-xlsx EXPORT_XLSX] [--export-json EXPORT_JSON] [--export-sqlite EXPORT_SQLITE]
[-PI PROXY_IP] [-PP PROXY_PORT] [-rt REQUEST_TIMEOUT] [--tomcat-username TOMCAT_USERNAME] [--tomcat-usernames-file TOMCAT_USERNAMES_FILE] [--tomcat-password TOMCAT_PASSWORD]
[--tomcat-passwords-file TOMCAT_PASSWORDS_FILE] [-tf TARGETS_FILE] [-tt TARGET] [-tu TARGET_URL] [-tp TARGET_PORTS] [-ad AUTH_DOMAIN] [-ai AUTH_DC_IP] [-au AUTH_USER] [-ap AUTH_PASSWORD]
[-ah AUTH_HASHES] [--ldaps] [--subnets]
Apache Tomcat सर्वर कमजोरियों को स्कैन करने के लिए एक पायथन स्क्रिप्ट।
options:
-h, --help show this help message and exit
-v, --verbose Verbose mode. (default: False)
--debug Debug mode, for huge verbosity. (default: False)
-C, --list-cves List CVE ids affecting each version found. (default: False)
--show-cves-descriptions
Show description of found CVEs. (default: False)
-T THREADS, --threads THREADS
Number of threads (default: 250)
-s, --servers-only If querying ActiveDirectory, only get servers and not all computer objects. (default: False)
--no-colors Disable colored output. (default: False)
--only-http Scan only with HTTP scheme. (default: False, scanning with both HTTP and HTTPs)
--only-https Scan only with HTTPs scheme. (default: False, scanning with both HTTP and HTTPs)
Export results:
--export-xlsx EXPORT_XLSX
Output XLSX file to store the results in.
--export-json EXPORT_JSON
Output JSON file to store the results in.
--export-sqlite EXPORT_SQLITE
Output SQLITE3 file to store the results in.
Advanced configuration:
-PI PROXY_IP, --proxy-ip PROXY_IP
Proxy IP.
-PP PROXY_PORT, --proxy-port PROXY_PORT
Proxy port
-rt REQUEST_TIMEOUT, --request-timeout REQUEST_TIMEOUT
Set the timeout of HTTP requests.
--tomcat-username TOMCAT_USERNAME
Single tomcat username to test for login.
--tomcat-usernames-file TOMCAT_USERNAMES_FILE
File containing a list of tomcat usernames to test for login
--tomcat-password TOMCAT_PASSWORD
Single tomcat password to test for login.
--tomcat-passwords-file TOMCAT_PASSWORDS_FILE
File containing a list of tomcat passwords to test for login
Targets:
-tf TARGETS_FILE, --targets-file TARGETS_FILE
Path to file containing a line by line list of targets.
-tt TARGET, --target TARGET
Target IP, FQDN or CIDR.
-tu TARGET_URL, --target-url TARGET_URL
Target URL to the tomcat manager.
-tp TARGET_PORTS, --target-ports TARGET_PORTS
Target ports to scan top search for Apache Tomcat servers.
-ad AUTH_DOMAIN, --auth-domain AUTH_DOMAIN
Windows domain to authenticate to.
-ai AUTH_DC_IP, --auth-dc-ip AUTH_DC_IP
IP of the domain controller.
-au AUTH_USER, --auth-user AUTH_USER
Username of the domain account.
-ap AUTH_PASSWORD, --auth-password AUTH_PASSWORD
Password of the domain account.
-ah AUTH_HASHES, --auth-hashes AUTH_HASHES
LM:NT hashes to pass the hash for this user.
--ldaps Use LDAPS (default: False)
--subnets Get all subnets from the domain and use them as targets (default: False)

आप --list-cves विकल्प के साथ प्रत्येक संस्करण के CVEs को भी सूचीबद्ध कर सकते हैं:

स्कैनर में एक स्वचालित CVE डेटाबेस अपडेट जाँच शामिल है ताकि आपके पास हमेशा नवीनतम कमजोरी डेटा हो।
जब आप स्कैनर चलाते हैं, तो यह स्वचालित रूप से जाँचता है कि CVE डेटाबेस 30 दिनों से पुराना है या नहीं। यदि पुराना है, तो आप देखेंगे:
[!] CVE database is outdated (last update: 2025-11-01T13:00:00)
[*] You can update it by running: python apachetomcatscanner/data/update_db_nvd.py
[?] Would you like to update now? This may take several minutes. (y/N):
अभी अपडेट करने के लिए y टाइप करें, या स्किप करके स्कैन जारी रखने के लिए Enter दबाएं।
अपडेट जाँच को पूरी तरह से छोड़ने के लिए, --no-auto-update फ्लैग का उपयोग करें:
python ApacheTomcatScanner.py -tt target.com --list-cves --no-auto-update
आप किसी भी समय मैन्युअल रूप से CVE डेटाबेस अपडेट कर सकते हैं:
cd apachetomcatscanner/data
python update_db_nvd.py
नोट: अपडेट आधिकारिक NVD API का उपयोग करता है जिसमें दर सीमा (प्रति 30 सेकंड में 5 अनुरोध) है। इस प्रक्रिया में कुछ मिनट लग सकते हैं लेकिन इसे कभी भी बाधित और फिर से शुरू किया जा सकता है। तेज़ अपडेट के लिए मुफ्त NVD API कुंजी प्राप्त करने पर विचार करें: https://nvd.nist.gov/developers/request-an-api-key
पुल अनुरोधों का स्वागत है। यदि आप अन्य सुविधाएँ जोड़ना चाहते हैं तो एक मुद्दा खोलने में संकोच न करें।