
Google खोज परिणामों में कमज़ोरियों को स्कैन करने के लिए कमांड-लाइन टूल

Google (या अन्य) खोज परिणामों में कमजोरियों की स्कैनिंग करें।
dorkbot एक मॉड्यूलर कमांड-लाइन टूल है जो Google खोज क्वेरी या अन्य समर्थित स्रोतों द्वारा लौटाए गए वेबपेजों के सेट के विरुद्ध कमजोरियों की स्कैनिंग करता है। यह मॉड्यूल के दो सेटों में विभाजित है:
लक्ष्यों को डेटाबेस में संग्रहीत किया जाता है जैसे-जैसे वे इंडेक्स होते हैं। स्कैन होने के बाद, एक मानक JSON रिपोर्ट तैयार की जाती है जिसमें कोई भी पाई गई कमजोरियाँ होती हैं। इंडेक्सिंग और स्कैनिंग प्रक्रियाओं को अलग-अलग या एक ही कमांड में संयोजित किया जा सकता है (प्रत्येक में अधिकतम एक)।
$ pip3 install dorkbot wapiti3
$ dorkbot -i google_api -o key=your_api_credential_here -o engine=your_engine_id_here -o query="filetype:php inurl:id"
$ dorkbot -s wapiti
-h, --help Show program (or specified module) help
--show-defaults Show default values in help output
usage: dorkbot [-c CONFIG] [-r DIRECTORY] [--source [SOURCE]]
[--show-defaults] [--count COUNT] [--random] [-h] [--log LOG]
[-v] [-V] [-d DATABASE] [-u] [--drop-tables]
[--retries RETRIES] [--retry-on RETRY_ON] [--show-stats] [-l]
[-n] [--list-sources] [--add-target TARGET]
[--delete-target TARGET] [--flush-targets] [-m] [-e]
[-i INDEXER] [-o INDEXER_ARG] [-s SCANNER] [-p SCANNER_ARG]
[-t] [-x] [--mark-unscanned MARK_UNSCANNED] [-g] [-f]
[--fingerprint-max FINGERPRINT_MAX] [--list-blocklist]
[--add-blocklist-item ITEM] [--delete-blocklist-item ITEM]
[--flush-blocklist] [-b EXTERNAL_BLOCKLIST]
options:
-c, --config CONFIG Configuration file
-r, --directory DIRECTORY
Dorkbot directory (default location of db, tools,
reports)
--source [SOURCE] Label associated with targets
--show-defaults Show default values in help output
-h, --help Show program (or specified module) help
--log LOG Path to log file
-v, --verbose Enable verbose logging (can be used multiple times to
increase verbosity)
-V, --version Print version
retrieval:
--count COUNT number of targets to retrieve (0/unset = all)
--random retrieve targets in random order
database:
-d, --database DATABASE
Database file/uri
-u, --prune Apply fingerprinting and blocklist without scanning
--drop-tables Delete and recreate tables
--retries RETRIES Number of retries when an operation fails
--retry-on RETRY_ON Error strings that should result in a retry (can be
used multiple times)
--show-stats Show the total/unscanned target and fingerprint counts
targets:
-l, --list-targets List targets in database
-n, --unscanned-only Only include unscanned targets
--list-sources List sources in database
--add-target TARGET Add a url to the target database
--delete-target TARGET
Delete a url from the target database
--flush-targets Delete all targets
-m, --delete-on-match
Delete target if it matches blocklist item
-e, --delete-on-error
Delete target if error encountered while processing it
indexing:
-i, --indexer INDEXER
Indexer module to use
-o, --indexer-arg INDEXER_ARG
Pass an argument to the indexer module (can be used
multiple times)
scanning:
-s, --scanner SCANNER
Scanner module to use
-p, --scanner-arg SCANNER_ARG
Pass an argument to the scanner module (can be used
multiple times)
-t, --test Fetch next scannable target but do not mark it scanned
-x, --reset-scanned Reset scanned status of all targets
--mark-unscanned MARK_UNSCANNED
Reset scanned status of given target
fingerprints:
-g, --generate-fingerprints
Generate fingerprints for all targets
-f, --flush-fingerprints
Delete all generated fingerprints
--fingerprint-max FINGERPRINT_MAX
Maximum matches per fingerprint before deleting new
matches
blocklist:
--list-blocklist List internal blocklist entries
--add-blocklist-item ITEM
Add an ip/host/regex pattern to the internal blocklist
--delete-blocklist-item ITEM
Delete an item from the internal blocklist
--flush-blocklist Delete all internal blocklist items
-b, --external-blocklist EXTERNAL_BLOCKLIST
Supplemental external blocklist file/db (can be used
multiple times)
डेटाबेस ड्राइवर:
स्कैनर:
आवश्यकतानुसार, dorkbot निम्नलिखित क्रम में उपकरणों की खोज करेगा:
सभी SQLite डेटाबेस, उपकरण और रिपोर्ट dorkbot निर्देशिका में सहेजे जाते हैं, जो डिफ़ॉल्ट रूप से वर्तमान निर्देशिका है। आप --directory फ़्लैग के साथ एक विशिष्ट निर्देशिका को बाध्य कर सकते हैं। इस निर्देशिका के अंतर्गत डिफ़ॉल्ट फ़ाइल पथ इस प्रकार हैं:
कॉन्फ़िगरेशन फ़ाइलें डिफ़ॉल्ट रूप से ~/.config/dorkbot/ (Linux / MacOS) या Application Data फ़ोल्डर (Windows) से पढ़ी जाती हैं, $XDG_CONFIG_HOME / %APPDATA% का सम्मान करते हुए। इस निर्देशिका के अंतर्गत डिफ़ॉल्ट फ़ाइल पथ इस प्रकार हैं:
कॉन्फ़िगरेशन फ़ाइल (dorkbot.ini) का उपयोग कुछ कमांड-लाइन फ़्लैग को पूर्व-भरने के लिए किया जा सकता है।
उदाहरण dorkbot.ini:
[dorkbot] database=/opt/dorkbot/dorkbot.db [dorkbot.indexers.wayback] domain=example.com [dorkbot.scanners.arachni] path=/opt/arachni/bin report_dir=/tmp/reports
लक्ष्य डेटाबेस स्कैन किए जाने वाले URL और उनके स्रोतों को संग्रहीत करता है। यह प्रत्येक अद्वितीय पृष्ठ + पैरामीटर सेट के लिए फ़िंगरप्रिंट की सूची बनाकर और नए लक्ष्यों की मौजूदा फ़िंगरप्रिंट से तुलना करके प्रत्येक URL की स्कैन स्थिति को ट्रैक करता है। फ़िंगरप्रिंट केवल एक बार उत्पन्न करने की आवश्यकता होती है और आवश्यकतानुसार मांग पर उत्पन्न की जाएगी। फ़िंगरप्रिंट और स्कैन स्थिति को स्वतंत्र रूप से रीसेट किया जा सकता है।
समर्थित डेटाबेस पते: