
컴파일된 Swagger 데이터셋을 사용하여 경로를 무차별 대입하는 고속 API 및 웹 콘텐츠 발견 도구로, 깊이 스캔, 사용자 정의 워드리스트, 동시 호스트 스캔을 지원합니다.

오랫동안 콘텐츠 디스커버리는 파일과 폴더를 찾는 데 집중되어 왔습니다. 이 접근 방식은 정적 파일을 호스팅하거나 부분 경로에 대해 3xx 응답을 반환하는 레거시 웹 서버에는 효과적이지만, 최신 웹 애플리케이션, 특히 API에는 더 이상 효과적이지 않습니다.
시간이 지남에 따라 더 큰 단어 목록을 사용할 수 있도록 콘텐츠 디스커버리 도구를 더 빠르게 만드는 데 많은 시간이 투자되었지만, 콘텐츠 디스커버리의 기술 자체는 혁신되지 않았습니다.
Kiterunner는 기존의 콘텐츠 디스커버리를 매우 빠른 속도로 수행할 수 있을 뿐만 아니라, 최신 애플리케이션에서 라우트/엔드포인트를 브루트포싱할 수 있는 도구입니다.
Flask, Rails, Express, Django 등과 같은 최신 애플리케이션 프레임워크는 특정 HTTP 메서드, 헤더, 파라미터 및 값을 기대하는 라우트를 명시적으로 정의하는 패러다임을 따릅니다.
기존의 콘텐츠 디스커버리 도구를 사용할 때 이러한 라우트는 종종 놓치기 쉬우며 쉽게 발견할 수 없습니다.
Swagger 사양 데이터셋을 수집하여 자체 스키마로 압축함으로써, Kiterunner는 이 데이터셋을 사용하여 각 요청에 대해 올바른 HTTP 메서드, 헤더, 경로, 파라미터 및 값을 전송하여 API 엔드포인트를 브루트포싱할 수 있습니다.
Swagger 파일은 인터넷 전체에서 가장 일반적인 swagger 경로 40개 이상을 스캔하는 등 여러 데이터 소스에서 수집되었습니다. 다른 데이터 소스로는 GitHub via BigQuery와 APIs.guru가 있습니다.
https://github.com/assetnote/kiterunner/releases 에서 미리 빌드된 복사본을 다운로드할 수 있습니다.
make build
ln -s $(pwd)/dist/kr /usr/local/bin/kr
kr kb compile routes.json routes.kite
kr scan hosts.txt -w routes.kite -x 20 -j 100 --ignore-length=1053
JSON 데이터셋은 아래에서 찾을 수 있습니다:
- [routes-large.json](https://wordlists-cdn.assetnote.io/rawdata/kiterunner/routes-large.json.tar.gz) (118MB 압축, 2.6GB 압축 해제)
- [routes-small.json](https://wordlists-cdn.assetnote.io/rawdata/kiterunner/routes-small.json.tar.gz) (14MB 압축, 228MB 압축 해제)
또는, 아래 링크에서 컴파일된 `.kite` 파일을 다운로드할 수 있습니다:
- [routes-large.kite](https://wordlists-cdn.assetnote.io/data/kiterunner/routes-large.kite.tar.gz) (40MB 압축, 183M 압축 해제)
- [routes-small.kite](https://wordlists-cdn.assetnote.io/data/kiterunner/routes-small.kite.tar.gz) (2MB 압축, 35MB 압축 해제)
## AUR
Arch 기반 배포판을 사용하는 사용자는 [AUR](https://aur.archlinux.org/packages/kiterunner-bin/)에서 미리 빌드된 바이너리를 다운로드할 수 있습니다.
`yay`와 같은 "AUR 헬퍼"를 사용하여 kiterunner를 설치할 수 있습니다.```
yay -S kiterunner-bin
kr [scan|brute] [flags]
- `<input>`는 파일, 도메인 또는 URI일 수 있습니다. 알아서 처리해 드리겠습니다. 자세한 내용은 [Input/Host Formatting](#inputhost-formatting)을 참조하세요.```
# Just have a list of hosts and no wordlist
kr scan hosts.txt -A=apiroutes-210328:20000 -x 5 -j 100 --fail-status-codes 400,401,404,403,501,502,426,411
# You have your own wordlist but you want assetnote wordlists too
kr scan target.com -w routes.kite -A=apiroutes-210328:20000 -x 20 -j 1 --fail-status-codes 400,401,404,403,501,502,426,411
# Bruteforce like normal but with the first 20000 words
kr brute https://target.com/subapp/ -A=aspx-210328:20000 -x 20 -j 1
# Use a dirsearch style wordlist with %EXT%
kr brute https://target.com/subapp/ -w dirsearch.txt -x 20 -j 1 -exml,asp,aspx,ashx -D
Usage: kite scan [flags]
Flags: -A, --assetnote-wordlist strings use the wordlists from wordlist.assetnote.io. specify the type/name to use, e.g. apiroutes-210228. You can specify an additional maxlength to use only the first N values in the wordlist, e.g. apiroutes-210228;20000 will only use the first 20000 lines in that wordlist --blacklist-domain strings domains that are blacklisted for redirects. We will not follow redirects to these domains --delay duration delay to place inbetween requests to a single host --disable-precheck whether to skip host discovery --fail-status-codes ints which status codes blacklist as fail. if this is set, this will override success-status-codes --filter-api strings only scan apis matching this ksuid --force-method string whether to ignore the methods specified in the ogl file and force this method -H, --header strings headers to add to requests (default [x-forwarded-for: 127.0.0.1]) -h, --help help for scan --ignore-length strings a range of content length bytes to ignore. you can have multiple. e.g. 100-105 or 1234 or 123,34-53. This is inclusive on both ends --kitebuilder-full-scan perform a full scan without first performing a phase scan. -w, --kitebuilder-list strings ogl wordlist to use for scanning -x, --max-connection-per-host int max connections to a single host (default 3) -j, --max-parallel-hosts int max number of concurrent hosts to scan at once (default 50) --max-redirects int maximum number of redirects to follow (default 3) -d, --preflight-depth int when performing preflight checks, what directory depth do we attempt to check. 0 means that only the docroot is checked (default 1) --profile-name string name for profile output file --progress a progress bar while scanning. by default enabled only on Stderr (default true) --quarantine-threshold int if the host return N consecutive hits, we quarantine the host as wildcard. Set to 0 to disable (default 10) --success-status-codes ints which status codes whitelist as success. this is the default mode -t, --timeout duration timeout to use on all requests (default 3s) --user-agent string user agent to use for requests (default "Chrome. Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.96 Safari/537.36") --wildcard-detection can be set to false to disable wildcard redirect detection (default true)
Global Flags: --config string config file (default is $HOME/.kiterunner.yaml) -o, --output string output format. can be json,text,pretty (default "pretty") -q, --quiet quiet mode. will mute unecessarry pretty text -v, --verbose string level of logging verbosity. can be error,info,debug,trace (default "info")
무차별 대입 플래그 (위의 모든 플래그 +)```
-D, --dirsearch-compat this will replace %EXT% with the extensions provided. backwards compat with dirsearch because shubs loves him some dirsearch
-e, --extensions strings extensions to append while scanning
-w, --wordlist strings normal wordlist to use for scanning
입력이 제공되면 kiterunner는 다음 순서로 입력을 확인합니다:
"도메인"을 제공했지만, 현재 디렉토리에 google.com이라는 txt 파일도 존재하는 경우,
먼저 발견되었기 때문에 google.com 텍스트 파일을 로드합니다.
도메인 구문 분석