

ドメインのリストを渡してURLをクロールし、エンドポイント、シークレット、APIキー、ファイル拡張子、トークンなどをスキャンします
Coded with 💙 by edoardottt
Share on Twitter!
インストール • 使い方 • はじめに • 変更履歴 • コントリビューション • ライセンス
brew install cariddi
sudo snap install cariddi
go install -v github.com/edoardottt/cariddi/cmd/cariddi@latest
pacman -Syu cariddi
nix-shell -p cariddi
Go (>=1.24.0) が必要です
git clone https://github.com/edoardottt/cariddi.git
cd cariddi
go get ./...
make linux # (to install)
make unlinux # (to uninstall)
ワンライナー: git clone https://github.com/edoardottt/cariddi.git && cd cariddi && go get ./... && make linux
実行ファイルは cariddi フォルダ内でのみ動作することに注意してください。
git clone https://github.com/edoardottt/cariddi.git
cd cariddi
go get ./...
.\make.bat windows # (to install)
.\make.bat unwindows # (to uninstall)
単一のターゲットのみをスキャンしたい場合は、次を使用できます
echo https://edoardottt.com/ | cariddi
複数のターゲットの場合は、代わりにファイルを使用できます。例えば、以下を含む urls.txt:
https://edoardottt.com/
http://testphp.vulnweb.com/
Windows の場合:
powershell.exe -Command "cat urls.txt | .\cariddi.exe" を使用するcat urls.txt | cariddi.exe を実行するcariddi -version (バージョンを表示)cariddi -h (ヘルプを表示)cariddi -examples (使用例を表示)cat urls.txt | cariddi -intensive (サブドメインも検索してクロール、*.target.com と同じ)cat urls.txt | cariddi -s (シークレットを探索)cat urls.txt | cariddi -err (ウェブサイト内のエラーを探索)cat urls.txt | cariddi -e (有用なエンドポイントを探索)cat urls.txt | cariddi -info (ウェブサイト内の有用な情報を探索)cat urls.txt | cariddi -ext 2 (有用なファイル (7段階中レベル2) を探索)cat urls.txt | cariddi -e -ef endpoints_file (カスタムエンドポイントを探索)cat urls.txt | cariddi -s -sf secrets_file (カスタムシークレットを探索)cat urls.txt | cariddi -ie pdf,png,jpg (スキャン中にこれらの拡張子を無視)デフォルト: png, svg, jpg, jpeg, bmp, jfif, gif, webp, woff, woff2, ttf, tiff, tif, mp4, webm, mkv, avi, mov, flv, wmv, mp3, wav, flac, ogg, m4a, aac, ico, cur, eot, otf はシークレット、情報、エラーのスキャン中に無視されます。
cat urls.txt | cariddi -proxy http://127.0.0.1:8080 (プロキシを設定、http と socks5 をサポート)cat urls.txt | cariddi -d 2 (ページのクロール間隔を2秒に設定)cat urls.txt | cariddi -c 200 (同時実行レベルを200に設定)cat urls.txt | cariddi -i forum,blog,community,open (これらの単語を含むURLを無視)cat urls.txt | cariddi -it ignore_file (入力ファイル内の少なくとも1行を含むURLを無視)cat urls.txt | cariddi -cache (.cariddi_cache フォルダをキャッシュとして使用)cat urls.txt | cariddi -t 5 (リクエストのタイムアウトを設定)cat urls.txt | cariddi -headers "Cookie: auth=admin;type=2;; X-Custom: customHeader"cat urls.txt | cariddi -headersfile headers.txt (外部ファイルからカスタムヘッダーを読み込む)cat urls.txt | cariddi -ua "Custom User Agent" (カスタム User Agent を使用)cat urls.txt | cariddi -rua (リクエストごとにランダムなブラウザの user agent を使用)cat urls.txt | cariddi -plain (結果のみを表示)cat urls.txt | cariddi -ot target_name (結果を txt ファイルに出力)cat urls.txt | cariddi -oh target_name (結果を html ファイルに出力)cat urls.txt | cariddi -json (出力を JSON として stdout に表示)cat urls.txt | cariddi -sr (HTTP レスポンスを保存)cat urls.txt | cariddi -debug (クロール中にデバッグ情報を表示)cat urls.txt | cariddi -md 3 (最大深度レベル3)cariddi -h でヘルプを表示します。
Usage of cariddi:
-c int
Concurrency level. (default 20)
-cache
Use the .cariddi_cache folder as cache.
-d int
Delay between a page crawled and another.
-debug
Print debug information while crawling.
-e Hunt for juicy endpoints.
-ef string
Use an external file (txt, one per line) to use custom parameters for endpoints hunting.
-err
Hunt for errors in websites.
-examples
Print the examples.
-ext int
Hunt for juicy file extensions. Integer from 1(juicy) to 7(not juicy).
-h Print the help.
-headers string
Use custom headers for each request E.g. -headers "Cookie: auth=yes;;Client: type=2".
-headersfile string
Read from an external file custom headers (same format of headers flag).
-json
Print the output as JSON in stdout.
-md
Maximum depth level the crawler will follow from the initial target URL.
-i string
Ignore the URL containing at least one of the elements of this array.
-ie value
Comma-separated list of extensions to ignore while scanning.
-info
Hunt for useful informations in websites.
-intensive
Crawl searching for resources matching 2nd level domain.
-it string
Ignore the URL containing at least one of the lines of this file.
-oh string
Write the output into an HTML file.
-ot string
Write the output into a TXT file.
-plain
Print only the results.
-proxy string
Set a Proxy to be used (http and socks5 supported).
-rua
Use a random browser user agent on every request.
-s Hunt for secrets.
-sf string
Use an external file (txt, one per line) to use custom regexes for secrets hunting.
-sr
Store HTTP responses.
-t int
Set timeout for the requests. (default 10)
-ua string
Use a custom User Agent.
-version
Print the version.
通常、Burpsuite はブラウザ内で使用するため、ブラウザで burpsuite の証明書を信頼するだけで完了です。
cariddi を BurpSuite プロキシで使用するには、さらにいくつかの手順を実行する必要があります。
-proxy http://127.0.0.1:8080 オプションを付けて cariddi を使用しようとすると、burpsuite のエラーログセクションに次のエラーが表示されます:
Received fatal alert: bad_certificate (or something similar related to the certificate).
cariddi を Burpsuite で正常に動作させるには、ブラウザだけでなく PC 全体で証明書を信頼する必要もあります。以下は従うべき手順です:
Bupsuite の Proxy タブに移動し、次に Options を開きます。CA Certificate ボタンをクリックし、証明書を DER 形式でエクスポートします
openssl x509 -in burp.der -inform DER -out burp.pem -outform PEM
sudo chown root:root burp.pem
sudo chmod 644 burp.pem
sudo cp burp.pem /usr/local/share/ca-certificates/
sudo c_rehash
cd /etc/ssl/certs/
sudo ln -s /usr/local/share/ca-certificates/burp.pem
sudo c_rehash .
出典: Trust Burp Proxy certificate in Debian/Ubuntu
これらの手順の後、cariddi を Burpsuite で使用するには次を行います:
-proxy http://127.0.0.1:8080 フラグ付きで使用します。各リリースの詳細な変更点は リリースノート に記載されています。
issue/pull request を開くだけです。