
複数のHTTPメソッドとフィンガープリンティング技術を使用してWebアプリケーションのデバッグモードの設定ミスを検出し、露出した機密情報を特定するPythonベースのスキャナー。
dbgdtctは、Webアプリケーションがデバッグモードでデプロイされているかどうかを検出するためのPythonベースのツールです。デバッグモードは、本番環境で機密情報を露出させ、悪用のリスクを高める重大な設定ミスです。
git clone https://github.com/yousseflahouifi/dbdtct.git
仮想環境を作成します
python3 -m venv myenv
source myenv/bin/activate
パッケージをインストールします
pip3 install aiohttp requests
単一のターゲットアプリケーションをスキャンする場合
python dbdtct.py -u https://target.com
複数のターゲットとURLをスキャンする場合
python dbdtct.py -l list.txt
python dbdtct.py -u https://target.com
,--.,--. ,--. ,--. ,--.
,-| || |-. ,-| |,-' '-. ,---.,-' '-.
' .-. || .-. '' .-. |'-. .-'| .--''-. .-'
\ `-' || `-' |\ `-' | | | \ `--. | |
`---' `---' `---' `--' `---' `--'
dbdtct — Web Debug Mode Detection Tool
Created by: Youssef Lahouifi
Supervised by : Redouan Korchiyne
[ Debug Mode Scanner - Test various methods to detect debug mode ]
[*] Starting scan at 2025-04-12 23:01:12
[*] Testing 1 target(s)
[+] Potential Debug Mode Detected on https://target.com
-> Technique: HTTP Method POST
-> Fingerprint: Symfony\Component\
-> Technique: HTTP Method PUT
-> Fingerprint: Symfony\Component\
-> Technique: Malformed JSON ({"foo":"bar")
-> Fingerprint: Symfony\Component\
[*] Scan Summary:
-> Completed in: 7.35 seconds
-> Targets scanned: 1
-> Vulnerable targets: 1
-> Success rate: 100.0%