
Strumento di test di autorizzazione web multi-thread che valuta i privilegi degli utenti controllando l'accesso ai token di sessione su un elenco di URL, evidenziando potenziali problemi di controllo degli accessi interrotti.
SessionProbe è uno strumento di pentesting multi-thread progettato per aiutare nella valutazione dei privilegi utente nelle applicazioni web. Prende il token di sessione di un utente e verifica per una lista di URL se l'accesso è possibile, evidenziando potenziali problemi di autorizzazione. SessionProbe deduplica le liste di URL e fornisce logging in tempo reale e monitoraggio dell'avanzamento.
SessionProbe è pensato per essere utilizzato con la funzionalità "Copy URLs in this host" di Burp Suite nella scheda Target (disponibile nella versione gratuita Community Edition).
Nota: Potresti voler modificare il filter nella scheda Target di Burps's per includere file o immagini. Altrimenti, questi URL non verrebbero copiati da "Copy URLs in this host" e non verrebbero testati da SessionProbe.
L'aiuto è integrato!
sessionprobe --help - mostra l'aiuto.Usage:
sessionprobe [flags]
Flags:
-u, --urls string file containing the URLs to be checked (required)
-H, --headers string HTTP headers to be used in the requests in the format "Key1:Value1;Key2:Value2;..."
-h, --help help for sessionprobe
--ignore-css ignore URLs ending with .css (default true)
--ignore-js ignore URLs ending with .js (default true)
-o, --out string output file (default "output.txt")
-p, --proxy string proxy URL (default: "")
-r, --filter-regex string exclude HTTP responses using a regex. Responses whose body matches this regex will not be part of the output.
-l, --filter-lengths string exclude HTTP responses by body length. You can specify lengths separated by commas (e.g., "123,456,789").
--skip-verification skip verification of SSL certificates (default false)
-t, --threads int number of threads (default 10)
--check-all Check POST, DELETE, PUT & PATCH methods (default false)
--check-delete Check DELETE method (default false)
--check-patch Check PATCH method (default false)
--check-post Check POST method (default false)
--check-put Check PUT method (default false)
Examples:
./sessionprobe -u ./urls.txt
./sessionprobe -u ./urls.txt --out ./unauthenticated-test.txt --threads 15
./sessionprobe -u ./urls.txt -H "Cookie: .AspNetCore.Cookies=<cookie>" -o ./output.txt
./sessionprobe -u ./urls.txt -H "Authorization: Bearer <token>" --proxy http://localhost:8080
./sessionprobe -u ./urls.txt -r "Page Not Found"
./sessionprobe -u ./urls.txt -H "Cookie: .AspNetCore.Cookies=<cookie>;Cookie: <another-cookie>=<another_value>"
file di URL.docker run -it --rm -v "$(pwd):/app/files" --name sessionprobe fw10/sessionprobe [flags]
file di URL deve trovarsi nella directory corrente e anche il tuo file di output sarà in questa directory.listener Burp in esecuzione su tutte le interfacce se intendi utilizzare l'opzione --proxy.go run .go builddocker build . -t fw10/sessionprobego test o go test -v (per maggiori dettagli).css, .js), e fornisce la lunghezzaBurpResponses with Status Code: 200
https://example.com/<some-path> => Length: 12345
https://example.com/<some-path> => Length: 40
...
Responses with Status Code: 301
https://example.com/<some-path> => Length: 890
https://example.com/<some-path> => Length: 434
...
Responses with Status Code: 302
https://example.com/<some-path> => Length: 0
...
Responses with Status Code: 404
...
Responses with Status Code: 502
...
Releases contiene alcuni binari già compilati per te, così potresti non dover compilare lo strumento da solo.release Mac, il tuo Mac potrebbe mostrare un avviso ("cannot be opened because it is from an unidentified developer")
Configurazione).Se trovi un bug, per favore apri una segnalazione (Issue) direttamente su GitHub, e cercherò di risolverlo tempestivamente.