
Panoptic은 경로 탐색(path traversal) 취약점을 통해 일반적인 로그 및 구성 파일의 콘텐츠를 검색하고 추출하는 과정을 자동화하는 오픈 소스 침투 테스트 도구입니다.

Panoptic은 경로 탐색(path traversal) 취약점을 통해 일반적인 로그 및 설정 파일의 검색과 조회를 자동화하는 오픈 소스 침투 테스트 도구입니다.

--concurrency)--header 또는
--data 값에 FUZZ 배치--base64)/etc/passwd,
binlog 파일은 mysql-bin.index 파싱--output-format)--resume-file)--config)0600 권한으로 강화된 민감한 아티팩트 및
OS가 지원하는 경우 최종 구성 요소 심볼릭 링크 보호--update)httpx[socks], rich, rich-argparse,
tomligit clone https://github.com/lightos/Panoptic.git
cd Panoptic
python3 -m venv .venv
source .venv/bin/activate
python -m pip install -e .
panoptic --version
Windows 명령 프롬프트에서는 .venv\Scripts\activate.bat로 활성화하고,
PowerShell에서는 .venv\Scripts\Activate.ps1을 사용합니다. 편집 가능(editable) 설치는
Panoptic이 --update를 위해 이 체크아웃에 연결된 상태로 유지되므로 디렉터리를 제자리에
두어야 합니다. pip install panoptic을 실행하지 마십시오. 해당 PyPI 이름은
관련 없는 프로젝트의 것입니다.
개발용:
python -m pip install -e ".[dev]"
panoptic --url "http://target/include.php?file=test.txt"
panoptic --url "http://target/include.php?file=test.txt"
panoptic --url "http://target/include.php?file=test.txt&id=1" \
--param file
panoptic --url "http://target/include.php" \
--data "file=test.txt&id=1" --param file
panoptic --url "http://target/view.php/test.txt" --path-based
panoptic --url "http://target/load.php?file=dGVzdC50eHQ=" \
--base64 --auto
panoptic --url "http://target/page.php" \
--header "Cookie: lang=FUZZ" --auto
panoptic --url "http://target/api/load" \
--data '{"file":"FUZZ"}' --auto
panoptic --url "http://target/page.php" \
--header "X-Template: FUZZ" --auto
panoptic --url "http://target/view.php?file=test&type=txt" \
--param file --ext-param type
panoptic --url "http://target/filtered.php?file=test.txt" \
--prefix "....//....//....//....//"
panoptic --url "http://target/include.php?file=test.txt" \
--os "*NIX" --type conf
panoptic --url "http://target/include.php?file=test.txt" \
--software PostgreSQL
panoptic --url "http://target/include.php?file=test.txt" \
--output-format json --output-file results.json \
--resume-file scan.checkpoint
panoptic --url "https://target/include.php?file=test.txt" \
--proxy "socks5://127.0.0.1:9050" --invalid-ssl
panoptic --list software
panoptic --list category
panoptic --list os
panoptic --url "http://target/include.php?file=test.txt" \
--auto --all-versions --concurrency 8
주입 지점을 표시하려면 --header 또는 --data 값의 아무 곳에나 FUZZ를
배치하십시오. Panoptic은 스캔 중에 FUZZ를 각 파일 경로로 대체합니다.
이를 통해 --param으로는 도달할 수 없는 주입 지점을 테스트할 수 있습니다:
| 주입 유형 | 예 |
|---|---|
| 쿠키 값 | --header "Cookie: theme=FUZZ" |
| 사용자 지정 헤더 | --header "X-Include: FUZZ" |
| JSON 본문 | --data '{"template":"FUZZ"}' |
| 중첩 값 | --header "Cookie: sid=abc; lang=FUZZ" |
FUZZ가 있으면 --param은 필요하지 않습니다.
Panoptic은 영구 설정을 위한 TOML 설정 파일을 지원합니다:
panoptic --url "http://target/include.php?file=test.txt" \
--config ~/.config/panoptic/config.toml
기본 설정 위치: ~/.config/panoptic/config.toml (--config 없이도
존재하면 자동으로 로드됩니다).
[defaults]
# Any long option name (with dashes as underscores) is accepted here,
# including the target and output destinations.
url = "http://target/include.php?file=test.txt"
concurrency = 8
verbose = true
automatic = true
all_versions = true
output_format = "json"
output_file = "results.json"
log_file = "scan.log"
resume_file = "scan.checkpoint"
[proxy]
url = "socks5://127.0.0.1:9050"
[headers]
user_agent = "Mozilla/5.0"
cookie = "sid=foobar; auth=1"
values = ["X-Forwarded-For: 127.0.0.1"]
우선순위: CLI 인자 > 설정 파일 > 기본 내장값.
[defaults] 테이블은 성능 조정뿐만 아니라 모든 스캔 옵션을 허용합니다.
특히 다음을 영구 저장할 수 있습니다:
url — 기본 대상 (--url로 실행 시마다 재정의 가능)output_format, output_file — 기계 판독 가능 결과가 저장되는 위치log_file — 콘솔 출력을 파일에 미러링resume_file — 재개 가능한 스캔을 위한 체크포인트 위치Panoptic이 작성하는 민감한 아티팩트 — 로그 파일, 결과/목록 출력 파일,
--write-files로 저장된 모든 파일 — 는 POSIX에서 소유자 전용 0600 권한으로
강제 설정됩니다. O_NOFOLLOW를 제공하는 플랫폼은 또한 최종 경로 구성 요소에
이미 존재하는 심볼릭 링크를 원자적으로 거부합니다.
O_NOFOLLOW가 없는 플랫폼에서 Panoptic은 최선 노력(best-effort) 방식으로
열기 전 심볼릭 링크/정션 검사를 수행하지만, 이 검사로 경합(race) 조건을
완전히 제거할 수는 없습니다. Windows 모드 비트는 NTFS ACL을 구성하지 않으므로,
아티팩트에 민감한 데이터가 포함될 수 있는 경우 적절히 제한된 디렉터리를
사용하십시오.
모든 부울 플래그에는 --no- 대응 형태가 있으므로, 설정 파일에서 true로
설정된 값을 파일을 편집하지 않고 단일 실행에서 끌 수 있습니다:
# config.toml sets verbose = true and automatic = true
panoptic --url "http://target/x.php?file=test.txt" --no-verbose --no-auto
생략된 부울 플래그는 (false로 기본 설정되는 대신) 설정되지 않은 상태로
남으므로, 플래그 또는 해당 --no- 형태를 명시적으로 전달하지 않는 한
설정 값이 사용됩니다.
HTTP(S) 또는 SOCKS 프록시를 통해 트래픽을 라우팅합니다:
panoptic --url "https://target/x.php?file=test.txt" \
--proxy "socks5://127.0.0.1:9050"
http://, https://, socks5://, socks5h://
(socks5h는 프록시를 통해 DNS를 해석합니다 — Tor에 유용하며
로컬 DNS 누출을 방지합니다). SOCKS4는 기본 HTTP 클라이언트에서
지원되지 않습니다. 스캔 시작 전에 스킴과 호스트가 검증됩니다.httpx[socks] 확장에서 제공됩니다.HTTP_PROXY / HTTPS_PROXY /
NO_PROXY 환경 변수를 존중합니다. 이를 우회하고 직접 연결하려면
--ignore-proxy를 전달하십시오 (환경 변수로 구성된 프록시도
비활성화됩니다).--invalid-ssl과
함께 사용하십시오. 이는 인증서 검증을 비활성화하며 신뢰할 수 없는
네트워크에서는 안전하지 않습니다.--all-versions)번들에 포함된 일부 경로는 버전 템플릿입니다 (예: [JBOSS]로 표기된
JBoss 릴리스 디렉터리). 리터럴 [JBOSS] 경로는 실제 파일과 일치할 수
없으므로 기본적으로 이러한 템플릿 행은 건너뜁니다.
--all-versions를 전달하면 각 템플릿이 번들 버전 목록에 대해 확장되어
알려진 각 버전마다 하나의 구체적인 경로를 추가합니다 — 훨씬 더 크지만
훨씬 더 철저한 스캔이 됩니다:
panoptic --url "http://target/x.php?file=test.txt" --auto --all-versions