
숨겨진 파라미터 탐지 스위트
이 도구는 다른 테스터가 놓칠 수 있는, 취약하거나 흥미로운 기능을 드러낼 수 있는 숨겨진 파라미터를 식별하는 데 도움을 줍니다. 페이지의 줄 단위 비교, 응답 코드 비교, 반사(reflection) 비교를 통해 높은 정확도를 달성합니다.
모든 기능을 설명하는 문서는 https://sh1yo.art/x8docs/에서 확인할 수 있습니다. 문서의 원본은 /docs.md에 있습니다.
admin=true와 같이 무작위가 아닌 값을 가진 파라미터도 발견 가능.x8 -u "https://example.com/" -w <wordlist>
기본 파라미터 사용:
x8 -u "https://example.com/?something=1" -w <wordlist>
/?something=1은 /?something=1&%s와 동일합니다.
x8 -u "https://example.com/" -X POST -w <wordlist>
또는 사용자 정의 본문 사용:
x8 -u "https://example.com/" -X POST -b '{"x":{%s}}' -w <wordlist>
%s는 {"x":{"a":"b3a1a", "b":"ce03a", ...}}와 같이 다양한 파라미터로 대체됩니다.
x8 -u "https://example.com/" "https://4rt.one/" -W0
x8 -u "https://example.com/" --param-template "user[%k]=%v" -w <wordlist>
이제 모든 요청이 /?user[a]=hg2s4&user[b]=a34fa&... 형태가 됩니다.
때로는 파라미터를 인코딩해야 합니다. 다음도 가능합니다:
x8 -u "https://example.com/?path=..%2faction.php%3f%s%23" --encode -w <wordlist>
GET /?path=..%2faction.php%3fWTDa8%3Da7UOS%26rTIDA%3DexMFp...%23 HTTP/1.1
Host: example.com
x8 -u "https://example.com" --headers -w <wordlist>
개별 헤더를 대상으로 지정할 수도 있습니다:
x8 -u "https://example.com" --headers -H "Cookie: %s" -w <wordlist>
다음 URL에서 도구를 테스트하고 다른 도구와 비교할 수 있습니다:
https://4rt.one/level1 (GET)
https://4rt.one/level3 (GET)
USAGE:
x8 [FLAGS] [OPTIONS]
FLAGS:
--append Append to the output file instead of overwriting it.
-B Equal to -x http://localhost:8080
--check-binary Check the body of responses with binary content types
--disable-additional-checks Private
--disable-colors
--disable-custom-parameters Do not automatically check parameters like admin=true
--disable-progress-bar
--disable-trustdns Can solve some dns related problems
--encode Encodes query or body before making a request, i.e & -> %26, = -> %3D
List of chars to encode: ", `, , <, >, &, #, ;, /, =, %
-L, --follow-redirects Follow redirections
--force Force searching for parameters on pages > 25MB. Remove an error in case there's 1
worker with --one-worker-per-host option.
-h, --help Prints help information
--headers Switch to header discovery mode.
NOTE Content-Length and Host headers are automatically removed from the list
--invert By default, parameters are sent within the body only in case PUT or POST methods
are used.
It's possible to overwrite this behavior by specifying the option
--mimic-browser Add default headers that browsers usually set.
--one-worker-per-host Multiple urls with the same host will be checked one after another,
while urls with different hosts - are in parallel.
Doesn't increase the number of workers
--reflected-only Disable page comparison and search for reflected parameters only.
--remove-empty Skip writing to file outputs of url:method pairs without found parameters
--replay-once If a replay proxy is specified, send all found parameters within one request.
--strict Only report parameters that have changed the different parts of a page
--test Prints request and response
-V, --version Prints version information
--verify Verify found parameters.
OPTIONS:
-b, --body <body> Example: --body '{"x":{%s}}'
Available variables: {{random}}
-c <concurrency> The number of concurrent requests per url [default: 1]
--custom-parameters <custom-parameters>
Check these parameters with non-random values like true/false yes/no
(default is "admin bot captcha debug disable encryption env show sso test waf")
--custom-values <custom-values>
Values for custom parameters (default is "1 0 false off null true yes no")