Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
kiterunner — 컴파일된 Swagger 데이터셋을 사용하여 경로를 무차별 대입하는 고속 API 및 웹 콘텐츠 발견 도구로, 깊이 스캔, 사용자 정의 워드리스트, 동시 호스트 스캔을 지원합니다. | Kitploit
도구/GitHubGitHub/assetnote/kiterunner
ReconnaissanceWeb Vulnerability ScannersDynamic Code Analysis (DAST)Web Application ExploitationAPI Security TestingInformation GatheringWeb SecurityAPI SecurityAPI Security #1위API Security Testing #1위
3.2k340415년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Dynamic Code Analysis (DAST) #14위
Web Application Exploitation #15위
Web Security #14위
Web Vulnerability Scanners #14위
GitHubassetnote/kiterunner

kiterunner

컴파일된 Swagger 데이터셋을 사용하여 경로를 무차별 대입하는 고속 API 및 웹 콘텐츠 발견 도구로, 깊이 스캔, 사용자 정의 워드리스트, 동시 호스트 스캔을 지원합니다.

저장소 보기

Kiterunner

GoDoc GitHub release Go Report Card

소개

오랫동안 콘텐츠 디스커버리는 파일과 폴더를 찾는 데 집중되어 왔습니다. 이 접근 방식은 정적 파일을 호스팅하거나 부분 경로에 대해 3xx 응답을 반환하는 레거시 웹 서버에는 효과적이지만, 최신 웹 애플리케이션, 특히 API에는 더 이상 효과적이지 않습니다.

시간이 지남에 따라 더 큰 단어 목록을 사용할 수 있도록 콘텐츠 디스커버리 도구를 더 빠르게 만드는 데 많은 시간이 투자되었지만, 콘텐츠 디스커버리의 기술 자체는 혁신되지 않았습니다.

Kiterunner는 기존의 콘텐츠 디스커버리를 매우 빠른 속도로 수행할 수 있을 뿐만 아니라, 최신 애플리케이션에서 라우트/엔드포인트를 브루트포싱할 수 있는 도구입니다.

Flask, Rails, Express, Django 등과 같은 최신 애플리케이션 프레임워크는 특정 HTTP 메서드, 헤더, 파라미터 및 값을 기대하는 라우트를 명시적으로 정의하는 패러다임을 따릅니다.

기존의 콘텐츠 디스커버리 도구를 사용할 때 이러한 라우트는 종종 놓치기 쉬우며 쉽게 발견할 수 없습니다.

Swagger 사양 데이터셋을 수집하여 자체 스키마로 압축함으로써, Kiterunner는 이 데이터셋을 사용하여 각 요청에 대해 올바른 HTTP 메서드, 헤더, 경로, 파라미터 및 값을 전송하여 API 엔드포인트를 브루트포싱할 수 있습니다.

Swagger 파일은 인터넷 전체에서 가장 일반적인 swagger 경로 40개 이상을 스캔하는 등 여러 데이터 소스에서 수집되었습니다. 다른 데이터 소스로는 GitHub via BigQuery와 APIs.guru가 있습니다.

목차

  • Kiterunner
  • 소개
  • 설치
    • 릴리스 다운로드
    • 소스에서 빌드
    • AUR을 통한 설치
  • 사용법
    • 빠른 시작
    • CLI 도움말
    • 입력/호스트 형식
    • API 스캐닝
    • 일반 브루트포싱
    • Dirsearch 브루트포싱
  • 기술적 특징
    • 깊이 스캐닝
    • Assetnote 워드리스트 사용
      • Head 문법
    • 동시성 설정/빠르게 실행하기
    • 파일 형식 간 변환
    • 요청 재전송
  • 기술적 구현
    • 중간 데이터 타입 (PRoutes)
    • Kite 파일 형식

설치

릴리스 다운로드

https://github.com/assetnote/kiterunner/releases 에서 미리 빌드된 복사본을 다운로드할 수 있습니다.

소스에서 빌드```bash

build the binary

make build

symlink your binary

ln -s $(pwd)/dist/kr /usr/local/bin/kr

compile the wordlist

kr kb compile <input.json> <output.kite>

kr kb compile routes.json routes.kite

scan away

kr scan hosts.txt -w routes.kite -x 20 -j 100 --ignore-length=1053

JSON 데이터셋은 아래에서 찾을 수 있습니다:

- [routes-large.json](https://wordlists-cdn.assetnote.io/rawdata/kiterunner/routes-large.json.tar.gz) (118MB 압축, 2.6GB 압축 해제)
- [routes-small.json](https://wordlists-cdn.assetnote.io/rawdata/kiterunner/routes-small.json.tar.gz) (14MB 압축, 228MB 압축 해제)

또는, 아래 링크에서 컴파일된 `.kite` 파일을 다운로드할 수 있습니다:

- [routes-large.kite](https://wordlists-cdn.assetnote.io/data/kiterunner/routes-large.kite.tar.gz) (40MB 압축, 183M 압축 해제)
- [routes-small.kite](https://wordlists-cdn.assetnote.io/data/kiterunner/routes-small.kite.tar.gz) (2MB 압축, 35MB 압축 해제)

## AUR
Arch 기반 배포판을 사용하는 사용자는 [AUR](https://aur.archlinux.org/packages/kiterunner-bin/)에서 미리 빌드된 바이너리를 다운로드할 수 있습니다.
`yay`와 같은 "AUR 헬퍼"를 사용하여 kiterunner를 설치할 수 있습니다.```
yay -S kiterunner-bin

사용법

빠른 시작```

kr [scan|brute] [flags]

- `<input>`는 파일, 도메인 또는 URI일 수 있습니다. 알아서 처리해 드리겠습니다. 자세한 내용은 [Input/Host Formatting](#inputhost-formatting)을 참조하세요.```
# Just have a list of hosts and no wordlist
kr scan hosts.txt -A=apiroutes-210328:20000 -x 5 -j 100 --fail-status-codes 400,401,404,403,501,502,426,411

# You have your own wordlist but you want assetnote wordlists too
kr scan target.com -w routes.kite -A=apiroutes-210328:20000 -x 20 -j 1 --fail-status-codes 400,401,404,403,501,502,426,411

# Bruteforce like normal but with the first 20000 words
kr brute https://target.com/subapp/ -A=aspx-210328:20000 -x 20 -j 1

# Use a dirsearch style wordlist with %EXT%
kr brute https://target.com/subapp/ -w dirsearch.txt -x 20 -j 1 -exml,asp,aspx,ashx -D

CLI 도움말```

Usage: kite scan [flags]

Flags: -A, --assetnote-wordlist strings use the wordlists from wordlist.assetnote.io. specify the type/name to use, e.g. apiroutes-210228. You can specify an additional maxlength to use only the first N values in the wordlist, e.g. apiroutes-210228;20000 will only use the first 20000 lines in that wordlist --blacklist-domain strings domains that are blacklisted for redirects. We will not follow redirects to these domains --delay duration delay to place inbetween requests to a single host --disable-precheck whether to skip host discovery --fail-status-codes ints which status codes blacklist as fail. if this is set, this will override success-status-codes --filter-api strings only scan apis matching this ksuid --force-method string whether to ignore the methods specified in the ogl file and force this method -H, --header strings headers to add to requests (default [x-forwarded-for: 127.0.0.1]) -h, --help help for scan --ignore-length strings a range of content length bytes to ignore. you can have multiple. e.g. 100-105 or 1234 or 123,34-53. This is inclusive on both ends --kitebuilder-full-scan perform a full scan without first performing a phase scan. -w, --kitebuilder-list strings ogl wordlist to use for scanning -x, --max-connection-per-host int max connections to a single host (default 3) -j, --max-parallel-hosts int max number of concurrent hosts to scan at once (default 50) --max-redirects int maximum number of redirects to follow (default 3) -d, --preflight-depth int when performing preflight checks, what directory depth do we attempt to check. 0 means that only the docroot is checked (default 1) --profile-name string name for profile output file --progress a progress bar while scanning. by default enabled only on Stderr (default true) --quarantine-threshold int if the host return N consecutive hits, we quarantine the host as wildcard. Set to 0 to disable (default 10) --success-status-codes ints which status codes whitelist as success. this is the default mode -t, --timeout duration timeout to use on all requests (default 3s) --user-agent string user agent to use for requests (default "Chrome. Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.96 Safari/537.36") --wildcard-detection can be set to false to disable wildcard redirect detection (default true)

Global Flags: --config string config file (default is $HOME/.kiterunner.yaml) -o, --output string output format. can be json,text,pretty (default "pretty") -q, --quiet quiet mode. will mute unecessarry pretty text -v, --verbose string level of logging verbosity. can be error,info,debug,trace (default "info")

무차별 대입 플래그 (위의 모든 플래그 +)```
  -D, --dirsearch-compat              this will replace %EXT% with the extensions provided. backwards compat with dirsearch because shubs loves him some dirsearch
  -e, --extensions strings            extensions to append while scanning
  -w, --wordlist strings              normal wordlist to use for scanning

입력/호스트 형식

입력이 제공되면 kiterunner는 다음 순서로 입력을 확인합니다:

  1. 입력이 파일인지 확인합니다. 파일이면 파일의 모든 줄을 별도의 도메인으로 읽습니다.
  2. 입력을 "도메인"으로 처리합니다.

"도메인"을 제공했지만, 현재 디렉토리에 google.com이라는 txt 파일도 존재하는 경우, 먼저 발견되었기 때문에 google.com 텍스트 파일을 로드합니다.

도메인 구문 분석

도구 다운로드