
멀티스레드 웹 권한 부여 테스트 도구로, URL 목록에서 세션 토큰 접근을 확인하여 사용자 권한을 평가하고 잠재적인 취약한 접근 제어 문제를 강조합니다.
SessionProbe는 웹 애플리케이션의 사용자 권한 평가를 지원하도록 설계된 멀티스레드 침투 테스트 도구입니다. 사용자의 세션 토큰을 사용하여 URL 목록에 액세스 가능한지 확인하고 잠재적인 권한 부여 문제를 강조합니다. SessionProbe는 URL 목록을 중복 제거하고 실시간 로깅 및 진행 상황 추적을 제공합니다.
SessionProbe는 Burp Suite의 Target 탭에 있는 "Copy URLs in this host" 기능(무료 Community Edition에서 사용 가능)과 함께 사용하도록 설계되었습니다.
참고: Burp의 Target 탭에서 필터를 변경하여 파일이나 이미지를 포함하도록 할 수 있습니다. 그렇지 않으면 이러한 URL이 "Copy URLs in this host"에 의해 복사되지 않아 SessionProbe로 테스트되지 않습니다.
도움말이 내장되어 있습니다!
sessionprobe --help - 도움말을 출력합니다.Usage:
sessionprobe [flags]
Flags:
-u, --urls string file containing the URLs to be checked (required)
-H, --headers string HTTP headers to be used in the requests in the format "Key1:Value1;Key2:Value2;..."
-h, --help help for sessionprobe
--ignore-css ignore URLs ending with .css (default true)
--ignore-js ignore URLs ending with .js (default true)
-o, --out string output file (default "output.txt")
-p, --proxy string proxy URL (default: "")
-r, --filter-regex string exclude HTTP responses using a regex. Responses whose body matches this regex will not be part of the output.
-l, --filter-lengths string exclude HTTP responses by body length. You can specify lengths separated by commas (e.g., "123,456,789").
--skip-verification skip verification of SSL certificates (default false)
-t, --threads int number of threads (default 10)
--check-all Check POST, DELETE, PUT & PATCH methods (default false)
--check-delete Check DELETE method (default false)
--check-patch Check PATCH method (default false)
--check-post Check POST method (default false)
--check-put Check PUT method (default false)
Examples:
./sessionprobe -u ./urls.txt
./sessionprobe -u ./urls.txt --out ./unauthenticated-test.txt --threads 15
./sessionprobe -u ./urls.txt -H "Cookie: .AspNetCore.Cookies=<cookie>" -o ./output.txt
./sessionprobe -u ./urls.txt -H "Authorization: Bearer <token>" --proxy http://localhost:8080
./sessionprobe -u ./urls.txt -r "Page Not Found"
./sessionprobe -u ./urls.txt -H "Cookie: .AspNetCore.Cookies=<cookie>;Cookie: <another-cookie>=<another_value>"
URLs 파일이 있는 디렉토리로 이동하세요.docker run -it --rm -v "$(pwd):/app/files" --name sessionprobe fw10/sessionprobe [flags]
URLs 파일이 현재 디렉토리에 있어야 하며 출력 파일도 이 디렉토리에 생성됩니다.--proxy 옵션을 사용하려면 Burp 리스너가 모든 인터페이스에서 실행 중이어야 합니다.go run .을 통해 이 도구를 간단히 실행할 수 있습니다.go build를 통해 직접 도구를 빌드할 수 있습니다.docker build . -t fw10/sessionprobe를 통해 직접 Docker 이미지를 빌드할 수 있습니다.go test 또는 go test -v(자세한 내용)를 실행하세요..css, .js)별로 URL을 정렬하고 길이를 제공합니다.Burp를 통해 전달하는 프록시 기능Responses with Status Code: 200
https://example.com/<some-path> => Length: 12345
https://example.com/<some-path> => Length: 40
...
Responses with Status Code: 301
https://example.com/<some-path> => Length: 890
https://example.com/<some-path> => Length: 434
...
Responses with Status Code: 302
https://example.com/<some-path> => Length: 0
...
Responses with Status Code: 404
...
Responses with Status Code: 502
...
릴리스 섹션에는 이미 컴파일된 바이너리가 포함되어 있어 도구를 직접 빌드하지 않아도 됩니다.Mac 릴리스의 경우, Mac에서 경고("인증되지 않은 개발자로부터 온 앱이므로 열 수 없습니다")가 표시될 수 있습니다.
설정 참조).버그를 발견하면 GitHub에서 바로 Issue를 등록해 주세요. 신속하게 해결하도록 노력하겠습니다.