Scanner avanzato di SQL Injection con analisi basata sull'intelligenza artificiale, framework di conformità etica e reportistica professionale.
Scanner per SQL injection pronto per la produzione con 6 metodi di rilevamento, remediation basata su intelligenza artificiale, output SARIF e integrazione CI/CD.
Avvio rapido · Documentazione · Docker · Analisi AI · Metti una stella su GitHub
Report HTML — panoramica dei risultati con badge di gravità e mapping OWASP |
Tabella dei risultati — codici PYTHIA-SQL, rilevamento DBMS, mapping CWE-89 |
Pythia è uno scanner per il rilevamento di SQL injection pronto per la produzione che mette l'etica al primo posto. Progettato per penetration tester, ricercatori di sicurezza e ingegneri DevSecOps, identifica le vulnerabilità di SQL injection con 6 metodi di rilevamento e si integra direttamente nelle pipeline CI/CD.
--fail-on, --sarif, --diff per l'integrazione nei pipeline~/.argos/argos.db)| Metodo di Rilevamento | Descrizione | Modalità Richiesta |
|---|---|---|
| Basato su errori | Errori SQL nelle risposte (MySQL, PostgreSQL, MSSQL, Oracle, SQLite) | Sicura |
| Boolean-Blind | Differenze nelle risposte tra condizioni VERO/FALSO | Sicura |
| Time-Based Blind | Ritardi nelle risposte tramite payload SLEEP/WAITFOR | Aggressiva |
| Basato su UNION | Estrazione di dati tramite UNION SELECT | Aggressiva |
| Second-Order | Pattern di iniezione store→retrieve (catena POST→GET) | Aggressiva |
| Iniezione ORDER BY | Iniezione di parametri di ordinamento numerici | Aggressiva |
python -m pyth --target http://example.com/products?id=1 --html
- **14 Finding Codes**: specifici per DBMS (MySQL, PostgreSQL, MSSQL, Oracle, SQLite) + specifici per tecnica
- **DBMS Fingerprinting**: rilevamento automatico del tipo e della versione del database
- **WAF Bypass**: 170+ payload di bypass in modalità aggressiva (hex, codifica URL, commenti inline, varianti di maiuscole/minuscole)
- **Session-Variable Detection**: catena POST→GET per pattern di autenticazione in stile DVWA-high
- **Smart Crawler**: BFS con estrazione di popup/onclick (`--js`), sitemap, robots.txt
- **False Positive Hardening**: punteggio di similarità SequenceMatcher + conferma multi-payload
### Integrazione CI/CD```bash
# Pipeline-friendly: exit 10 if high+ findings found
python -m pyth --target https://staging.app.com --aggressive --fail-on high
echo $? # 0=clean, 10=findings found, 1=error
# SARIF for GitHub Security / GitLab SAST
python -m pyth --target https://app.com --aggressive --sarif > results.sarif
# Compare vs last scan — show what's new, what's fixed
python -m pyth --target https://app.com --aggressive --diff last --html
python -m pyth --target https://api.example.com/v1/users
--auth-header "Authorization: Bearer eyJhbGc..."
--auth-header "X-API-Key: sk-prod-xxx"
--aggressive --html
Passa `--auth-header` più volte per più intestazioni.
### Analisi basata sull'IA
Scegli il tuo provider di IA dalla riga di comando:
| Provider | Ideale per | Velocità | Costo | Privacy |
| -------------------------------- | --------------------------------- | ---------- | ----------- | ------------ |
| **OpenAI gpt-4o-mini** (predefinito) | Qualità di produzione, basso costo | Veloce | ~$0.02/scan | Standard |
| **Anthropic Claude** | Focalizzato sulla privacy, correzione del codice | Veloce | ~$0.06/scan | Migliorata |
| **Ollama (Locale)** | Privacy completa | Lento (CPU) | Gratuito | 100% Offline |```bash
# Standard analysis
python -m pyth --target http://example.com --use-ai --ai-tone technical --html
# Agent mode: AI queries NVD for real CVEs (no API key for NVD)
python -m pyth --target http://example.com --use-ai --ai-agent --html
# Multi-provider comparison
python -m pyth --target http://example.com --use-ai \
--ai-compare "openai:gpt-4o-mini,anthropic:claude-3-5-haiku-20241022" --html
# With budget cap
python -m pyth --target http://example.com --use-ai --ai-budget 0.05 --html