Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
insect — 고성능 웹 경로 탐색 및 디렉터리 무차별 대입 도구. 침투 테스트를 위해 사용자 정의 가능한 워드리스트, 필터, 재귀 스캔을 사용하여 숨겨진 파일, 디렉터리 및 엔드포인트를 발견합니다. | Kitploit
도구/GitHubGitHub/nu11secur1ty/insect
ReconnaissanceVulnerability ScannersInformation GatheringWeb SecurityFuzzingPenetration Testing
GitHubnu11secur1ty/insect

insect

고성능 웹 경로 탐색 및 디렉터리 무차별 대입 도구. 침투 테스트를 위해 사용자 정의 가능한 워드리스트, 필터, 재귀 스캔을 사용하여 숨겨진 파일, 디렉터리 및 엔드포인트를 발견합니다.

저장소 보기
1513년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

insect - 웹 경로 탐색

현재 릴리스: v1.4 (20222.09.03)

웹 서버의 디렉터리와 파일을 무차별 대입(brute force)하도록 설계된 고급 명령줄 도구, 일명 웹 경로 스캐너

아이디어 by @maurosoria and @shelld3v

Developement-2022는 @nu11secur1ty에 의해 활발히 개발되고 있습니다

Table of Contents

  • 설치
  • 워드리스트
  • 옵션
  • 구성
  • 사용 방법
    • 간단한 사용법
    • 진행 일시 중지
    • 재귀
    • 스레드
    • 접두사 / 접미사
    • 블랙리스트
    • 필터
    • 원시 요청
    • 워드리스트 형식
    • 확장자 제외
    • 하위 디렉터리 스캔
    • 프록시
    • 보고서
    • 추가 예제 명령
  • Docker 지원
    • Linux에 Docker 설치
    • insect 이미지 빌드
    • insect 사용
  • 참조
  • 팁
  • 기여
  • 라이선스

Tools:

  • Attack-Modules-2022

설치 및 사용

요구 사항: python 3.10.5 이상

다음 설치 옵션 중 하나를 선택하세요:

  • git으로 설치: git clone https://github.com/nu11secur1ty/insect.git --depth 1 (권장)
  • ZIP 파일로 설치: 여기에서 다운로드
  • Docker로 설치: docker build -t "insect:latest" . (자세한 정보는 여기에서 확인할 수 있습니다)

패키지 관리자로 설치:

  • PyPi로 설치: pip3 install dirsearch
  • Kali Linux로 설치: sudo apt-get install dirsearch (지원 중단됨)

워드리스트 (중요)

요약:

  • 워드리스트는 텍스트 파일이며, 각 줄은 경로입니다.
  • 확장자에 관해서는, 다른 도구와 달리 dirsearch와 insect는 %EXT% 키워드를 -e 플래그의 확장자로만 대체합니다.
  • %EXT%가 없는 워드리스트(예: SecLists)의 경우, -f | --force-extensions 스위치를 사용하여 워드리스트의 모든 단어와 /에 확장자를 추가해야 합니다.
  • 이미 확장자가 있는 워드리스트 항목에 확장자를 적용하려면 -O | --overwrite-extensions를 사용하세요 (참고: .log, .json, .xml 등 일부 확장자나 .jpg, .png 같은 미디어 확장자는 덮어쓰기에서 제외됩니다)
  • 여러 워드리스트를 사용하려면 쉼표로 구분할 수 있습니다. 예: wordlist1.txt,wordlist2.txt.

예시:

  • 일반 확장자:``` index.%EXT%
확장자로 **asp**와 **aspx**를 전달하면 다음 사전이 생성됩니다:```
index
index.asp
index.aspx
  • 강제 확장자:``` admin
**-f**/**--force-extensions** 플래그와 함께 **php** 및 **html**을 확장자로 전달하면 다음 사전이 생성됩니다:```
admin
admin.php
admin.html
admin/
  • 확장 프로그램 덮어쓰기:``` login.html
**jsp** 및 **jspa**를 **-O**/**--overwrite-extensions** 플래그와 함께 확장자로 전달하면 다음 사전이 생성됩니다:```
login.html
login.jsp
login.jspa

옵션 -------``` Usage: insect.py [-u|--url] target [-e|--extensions] extensions [options]

Options: --version show program's version number and exit -h, --help show this help message and exit

Mandatory: -u URL, --url=URL Target URL(s), support multiple flags -l PATH, --url-file=PATH URL list file --stdin Read URL(s) from STDIN --cidr=CIDR Target CIDR --raw=PATH Load raw HTTP request from file (use --scheme flag to set the scheme) -s SESSION_FILE, --session=SESSION_FILE Session file --config=PATH Full path to config file, see 'config.ini' for example (Default: config.ini)

Dictionary Settings: -w WORDLISTS, --wordlists=WORDLISTS Customize wordlists (separated by commas) -e EXTENSIONS, --extensions=EXTENSIONS Extension list separated by commas (e.g. php,asp) -f, --force-extensions Add extensions to the end of every wordlist entry. By default insect only replaces the %EXT% keyword with extensions -O, --overwrite-extensions Overwrite other extensions in the wordlist with your extensions (selected via -e) --exclude-extensions=EXTENSIONS Exclude extension list separated by commas (e.g. asp,jsp) --remove-extensions Remove extensions in all paths (e.g. admin.php -> admin) --prefixes=PREFIXES Add custom prefixes to all wordlist entries (separated by commas) --suffixes=SUFFIXES Add custom suffixes to all wordlist entries, ignore directories (separated by commas) -U, --uppercase Uppercase wordlist -L, --lowercase Lowercase wordlist -C, --capital Capital wordlist

General Settings: -t THREADS, --threads=THREADS Number of threads -r, --recursive Brute-force recursively --deep-recursive Perform recursive scan on every directory depth (e.g. api/users -> api/) --force-recursive Do recursive brute-force for every found path, not only directories -R DEPTH, --max-recursion-depth=DEPTH Maximum recursion depth --recursion-status=CODES Valid status codes to perform recursive scan, support ranges (separated by commas) --subdirs=SUBDIRS Scan sub-directories of the given URL[s] (separated by commas) --exclude-subdirs=SUBDIRS Exclude the following subdirectories during recursive scan (separated by commas) -i CODES, --include-status=CODES Include status codes, separated by commas, support ranges (e.g. 200,300-399) -x CODES, --exclude-status=CODES Exclude status codes, separated by commas, support ranges (e.g. 301,500-599) --exclude-sizes=SIZES Exclude responses by sizes, separated by commas (e.g. 0B,4KB) --exclude-texts=TEXTS Exclude responses by texts, separated by commas (e.g. 'Not found', 'Error') --exclude-regex=REGEX Exclude responses by regex (e.g. '^Error$') --exclude-redirect=STRING Exclude responses if this regex (or text) matches redirect URL (e.g. '/index.html') --exclude-response=PATH Exclude responses similar to response of this page, path as input (e.g. 404.html) --skip-on-status=CODES Skip target whenever hit one of these status codes, separated by commas, support ranges --min-response-size=LENGTH Minimum response length --max-response-size=LENGTH Maximum response length --max-time=SECONDS Maximum runtime for the scan

도구 다운로드