Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
x8 — 숨겨진 파라미터 탐지 스위트 | Kitploit
도구/GitHubGitHub/sh1yo/x8
ReconnaissanceVulnerability AnalysisInformation GatheringWeb Security
GitHubsh1yo/x8

x8

숨겨진 파라미터 탐지 스위트

저장소 보기
2.1k196702년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Twitter stars issues

Latest Version crates.io crates_downloads github_downloads

x8

Rust로 작성된 숨겨진 파라미터 발견 도구 모음입니다.

이 도구는 다른 테스터가 놓칠 수 있는, 취약하거나 흥미로운 기능을 드러낼 수 있는 숨겨진 파라미터를 식별하는 데 도움을 줍니다. 페이지의 줄 단위 비교, 응답 코드 비교, 반사(reflection) 비교를 통해 높은 정확도를 달성합니다.

문서

모든 기능을 설명하는 문서는 https://sh1yo.art/x8docs/에서 확인할 수 있습니다. 문서의 원본은 /docs.md에 있습니다.

목차

  • 기능
  • 예제
  • 테스트 사이트
  • 사용법
  • 워드리스트
  • Burp Suite 통합
  • 설치

기능

  • 빠름.
  • 템플릿과 인젝션 포인트를 사용하여 유연한 요청 구성 제공.
  • 확장성이 뛰어나 한 번의 실행으로 수천 개의 URL을 확인 가능.
  • 유사한 도구에 비해 특히 어려운 경우 높은 정확도 제공.
  • admin=true와 같이 무작위가 아닌 값을 가진 파라미터도 발견 가능.
  • 다양한 사용자 정의 옵션으로 구성이 매우 용이.
  • 외부 라이브러리 수정을 통해 거의 원시(raw) 요청 수준 달성.

예제

쿼리에서 파라미터 확인

x8 -u "https://example.com/" -w <wordlist>

기본 파라미터 사용:

x8 -u "https://example.com/?something=1" -w <wordlist>

/?something=1은 /?something=1&%s와 동일합니다.

본문(body)을 통해 파라미터 전송

x8 -u "https://example.com/" -X POST -w <wordlist>

또는 사용자 정의 본문 사용:

x8 -u "https://example.com/" -X POST -b '{"x":{%s}}' -w <wordlist>

%s는 {"x":{"a":"b3a1a", "b":"ce03a", ...}}와 같이 다양한 파라미터로 대체됩니다.

여러 URL을 병렬로 확인

x8 -u "https://example.com/" "https://4rt.one/" -W0

사용자 정의 템플릿

x8 -u "https://example.com/" --param-template "user[%k]=%v" -w <wordlist>

이제 모든 요청이 /?user[a]=hg2s4&user[b]=a34fa&... 형태가 됩니다.

퍼센트 인코딩

때로는 파라미터를 인코딩해야 합니다. 다음도 가능합니다:

x8 -u "https://example.com/?path=..%2faction.php%3f%s%23" --encode -w <wordlist>
GET /?path=..%2faction.php%3fWTDa8%3Da7UOS%26rTIDA%3DexMFp...%23 HTTP/1.1
Host: example.com

헤더 검색

x8 -u "https://example.com" --headers -w <wordlist>

헤더 값 검색

개별 헤더를 대상으로 지정할 수도 있습니다:

x8 -u "https://example.com" --headers -H "Cookie: %s" -w <wordlist>

테스트 사이트

다음 URL에서 도구를 테스트하고 다른 도구와 비교할 수 있습니다:

https://4rt.one/level1 (GET)

https://4rt.one/level3 (GET)

사용법

USAGE:
    x8 [FLAGS] [OPTIONS]

FLAGS:
        --append                       Append to the output file instead of overwriting it.
    -B                                 Equal to -x http://localhost:8080
        --check-binary                 Check the body of responses with binary content types
        --disable-additional-checks    Private
        --disable-colors
        --disable-custom-parameters    Do not automatically check parameters like admin=true
        --disable-progress-bar
        --disable-trustdns             Can solve some dns related problems
        --encode                       Encodes query or body before making a request, i.e & -> %26, = -> %3D
                                       List of chars to encode: ", `, , <, >, &, #, ;, /, =, %
    -L, --follow-redirects             Follow redirections
        --force                        Force searching for parameters on pages > 25MB. Remove an error in case there's 1
                                       worker with --one-worker-per-host option.
    -h, --help                         Prints help information
        --headers                      Switch to header discovery mode.
                                       NOTE Content-Length and Host headers are automatically removed from the list
        --invert                       By default, parameters are sent within the body only in case PUT or POST methods
                                       are used.
                                       It's possible to overwrite this behavior by specifying the option
        --mimic-browser                Add default headers that browsers usually set.
        --one-worker-per-host          Multiple urls with the same host will be checked one after another,
                                       while urls with different hosts - are in parallel.
                                       Doesn't increase the number of workers
        --reflected-only               Disable page comparison and search for reflected parameters only.
        --remove-empty                 Skip writing to file outputs of url:method pairs without found parameters
        --replay-once                  If a replay proxy is specified, send all found parameters within one request.
        --strict                       Only report parameters that have changed the different parts of a page
        --test                         Prints request and response
    -V, --version                      Prints version information
        --verify                       Verify found parameters.

OPTIONS:
    -b, --body <body>                                       Example: --body '{"x":{%s}}'
                                                            Available variables: {{random}}
    -c <concurrency>                                        The number of concurrent requests per url [default: 1]
        --custom-parameters <custom-parameters>
            Check these parameters with non-random values like true/false yes/no
            (default is "admin bot captcha debug disable encryption env show sso test waf")
        --custom-values <custom-values>
            Values for custom parameters (default is "1 0 false off null true yes no")
도구 다운로드