
빠르고 멀티스레드 방식의 HTTP 공격 표면 분석기로, 대규모 호스트 목록에서 스크린샷을 찍고 응답을 검사하며 도메인을 해석하여 신속한 정찰을 수행합니다.
HttpDoom - HTTP 공격 표면 분석기
매우 빠르고 신뢰할 수 있는 방식으로 대규모 HTTP 기반 공격 표면을 검증합니다. Aquatone에서 영감을 받았습니다.
dotnet SDK 버전 6 이상이 필요합니다:
$ dotnet pack -c Release -o nupkg
$ dotnet tool install --global --add-source .\nupkg\ httpdoom.console
제거:
$ dotnet tool uninstall -g httpdoom.console
CLI의 설명(--help)으로 충분합니다:
HttpDoom.Console
Minimalist (and VERY fast) HTTP-based attack surface analysis tool
Usage:
HttpDoom.Console [options]
Options:
-H, --headers <headers> Headers to be used in every request
-p, --ports <ports> Default ports for testing (default is 80, 443).
-w, --wordlist <wordlist> (REQUIRED) Path to the wordlist with targets to flyover against
-o, --output <output> Directory to save all the enumerated information
-sR, --screenshot-resolution <screenshot-resolution> If -S, the resolution of the screenshot (default is 1920x1080)
-a, --allow-automatic-redirect If HttpDoom will follow HTTP redirects (default is true)
-S, --screenshot If HttpDoom will take screenshots from the website (default is false)
-v, --verbose If HttpDoom will print errors, only useful for debugging (default is false)
-s, --show-details If HttpDoom will print with details in stdout all the information got (default is false)
-i, --ignore-tls If HttpDoom will ignore invalid TLS for HTTPS requests (default is true)
-r, --resolve Resolve the domain enumerating the nameservers (default is false)
-aL, --max-allowed-redirect <max-allowed-redirect> Set the limit of automatic redirects if -a is true (default is 4)
-T, --timeout <timeout> Set the timeout for HTTP responses (default is 4000)
-t, --threads <threads> Set how many threads will HttpDoom utilize in runtime (default is 4)
--version Show version information
-?, -h, --help Show help and usage information
HttpDoom 프로젝트 아이콘은 Flaticon의 Freepik이 제작했습니다. 소스 코드는 WTFPL에 따라 라이선스가 부여됩니다.