업데이트로 돌아가기
New releaseAug 31, 2026

httpx v1.11.0

빠르고 다중 프로브를 사용하는 HTTP 툴킷으로, 정찰 및 정보 수집을 위한 도구입니다. TLS, CSP, 헤더, 기술 스택, CDN을 검사합니다. 매처, 필터 및 JSON 출력을 지원하여 자동화된 보안 테스트에 사용됩니다.

공유

httpx

기능 • 설치 • 사용법 • 문서 • 참고사항 • Discord 참여

httpx는 retryablehttp 라이브러리를 사용하여 여러 프로브를 실행할 수 있는 빠르고 다목적 HTTP 툴킷입니다. 스레드 수를 늘려도 결과 신뢰성을 유지하도록 설계되었습니다.

기능

httpx

  • 기여하기 쉬운 단순하고 모듈화된 코드 베이스.
  • 여러 요소를 프로브할 수 있는 빠르고 완전히 구성 가능한 플래그.
  • 여러 HTTP 기반 프로브 지원.
  • 기본적으로 https에서 http로의 스마트 자동 폴백.
  • 호스트, URL 및 CIDR을 입력으로 지원.
  • WAF 처리 등을 위한 재시도, 백오프 등 에지 케이스 처리.

지원되는 프로브

프로브기본 확인프로브기본 확인
URLtrueIPtrue
TitletrueCNAMEtrue
Status CodetrueRaw HTTPfalse
Content LengthtrueHTTP2false
TLS CertificatetrueHTTP Pipelinefalse
CSP HeadertrueVirtual hostfalse
Line CounttrueWord Counttrue
Location HeadertrueCDNfalse
Web ServertruePathsfalse
Web SockettruePortsfalse
Response TimetrueRequest Methodtrue
Favicon HashfalseProbe Statusfalse
Body HashtrueHeader Hashtrue
Redirect chainfalseURL Schemetrue
JARM HashfalseASNfalse

설치 방법

httpx를 성공적으로 설치하려면 go >=1.25.0이 필요합니다. 다음 명령을 실행하여 리포지토리를 가져오세요:

go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest

httpx 설치에 대한 자세한 내용은 https://docs.projectdiscovery.io/tools/httpx/install 를 참조하세요.

❗ 면책 조항
이 프로젝트는 활발히 개발 중입니다. 릴리스에 따라 주요 변경 사항이 발생할 수 있습니다. 업데이트 전에 변경 로그를 검토하세요.
이 프로젝트는 주로 독립형 CLI 도구로 사용하기 위해 구축되었습니다. 서비스로 실행하면 보안 위험이 발생할 수 있습니다. 주의하여 사용하고 추가 보안 조치를 취하는 것이 좋습니다.

사용법

httpx -h

이 명령은 도구의 도움말을 표시합니다. 아래는 지원되는 모든 스위치입니다.

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

Usage:
  ./httpx [flags]

Flags:
INPUT:
   -l, -list string              input file containing list of hosts to process
   -rr, -request string          file containing raw request
   -u, -target string[]          input target host(s) to probe
   -im, -input-mode string       mode of input file (burp)

PROBES:
   -sc, -status-code                      display response status-code
   -cl, -content-length                   display response content-length
   -ct, -content-type                     display response content-type
   -location                              display response redirect location
   -favicon                               display mmh3 hash for '/favicon.ico' file
   -hash string                           display response body hash (supported: md5,mmh3,simhash,sha1,sha256,sha512)
   -jarm                                  display jarm fingerprint hash
   -rt, -response-time                    display response time
   -lc, -line-count                       display response body line count
   -wc, -word-count                       display response body word count
   -title                                 display page title
   -bp, -body-preview                     display first N characters of response body (default 100)
   -server, -web-server                   display server name
   -td, -tech-detect                      display technology in use based on wappalyzer dataset
   -cff, -custom-fingerprint-file string  path to a custom fingerprint file for technology detection
   -method                                display http request method
   -ws, -websocket                        display server using websocket
   -ip                                    display host ip
   -cname                                 display host cname
   -extract-fqdn, -efqdn                  get domain and subdomains from response body and header in jsonl/csv output
   -asn                                   display host asn information
   -cdn                                   display cdn/waf in use (default true)
   -probe                                 display probe status

HEADLESS:
   -ss, -screenshot                 enable saving screenshot of the page using headless browser
   -system-chrome                   enable using local installed chrome for screenshot
   -ho, -headless-options string[]  start headless chrome with additional options
   -esb, -exclude-screenshot-bytes  enable excluding screenshot bytes from json output
   -ehb, -exclude-headless-body     enable excluding headless header from json output
   -no-screenshot-full-page         disable saving full page screenshot
   -st, -screenshot-timeout value   set timeout for screenshot in seconds (default 10s)
   -sid, -screenshot-idle value     set idle time before taking screenshot in seconds (default 1s)
   -jsc, -javascript-code string[]  execute JavaScript code after navigation

MATCHERS:
   -mc, -match-code string            match response with specified status code (-mc 200,302)
   -ml, -match-length string          match response with specified content length (-ml 100,102)
   -mlc, -match-line-count string     match response body with specified line count (-mlc 423,532)
   -mwc, -match-word-count string     match response body with specified word count (-mwc 43,55)
   -mfc, -match-favicon string[]      match response with specified favicon hash (-mfc 1494302000)
   -ms, -match-string string[]        match response with specified string (-ms admin)
   -mr, -match-regex string[]         match response with specified regex (-mr admin)
   -mcdn, -match-cdn string[]         match host with specified cdn provider (cloudfront, fastly, google, etc.)
   -mrt, -match-response-time string  match response with specified response time in seconds (-mrt '< 1')
   -mdc, -match-condition string      match response with dsl expression condition

EXTRACTOR:
   -er, -extract-regex string[]   display response content with matched regex
   -ep, -extract-preset string[]  display response content matched by a pre-defined regex (url,ipv4,mail)

카테고리