複数のサイトでCookieフラグを確認するためのツール。
複数のWebサーバーを分析する際に、Cookieフラグの確認プロセスをより簡単にするために作成されたツールです。
このツールがなぜ役立つのか知りたい場合はこちら:
https://www.owasp.org/index.php/SecureFlag
https://www.owasp.org/index.php/HttpOnly
https://www.owasp.org/index.php/Testing_for_cookies_attributes_%28OTG-SESS-002%29
Usage: cookiescanner.py [options]
Example: ./cookiescanner.py -i ips.txt
Options:
-h, --help show this help message and exit
-i INPUT, --input=INPUT
File input with the list of webservers
-u URL, --url=URL URL
-f FORMAT, --format=FORMAT
Output format (json, xml, csv, normal, grepable)
-g GOOGLE, --google=GOOGLE
Search in google by domain
--nocolor Disable color (for the normal format output)
-I, --info More info
Performance:
-t TIMEOUT Timeout of response
-d DELAY Delay between requests
requests >= 2.8.1
BeautifulSoup >= 4.2.1
pip3 install --upgrade -r requirements.txt
Cookie内の値の種類を識別するためのインテリジェンスを追加。
Manuel Mancera ([email protected]/@sinkmanu)