Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
gaia — 글로벌 API 무결성 평가 도구 | Kitploit
도구/GitLabGitLab/functori/dev/gaia
Vulnerability ScannersAPI Security TestingWeb SecurityFuzzing
GitLabfunctori/dev/gaia

gaia

글로벌 API 무결성 평가 도구

저장소 보기
1년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Gaia: 글로벌 API 무결성 평가자

종속성

  • opam을(를) 설치하여 테스트 API를 빌드합니다.

  • git, python3, pip 및 .NET을(를) 설치하여 RESTler 및 Schemathesis를 빌드합니다.

  • cargo를 설치하여 Gaia를 빌드합니다.

  • docker v26.0.1 및 docker compose v2.26.1을(를) 설치하여 ELK Stack과 함께 Gaia를 빌드합니다 (선택 사항, 그렇지 않으면 필요 없음).

  • node >= v18.0.0 및 npm >= v8.6.0을(를) 설치합니다.

  • opam 로컬 스위치를 생성하려면:

root@kitploit:~
make opam-switch
  • 모든 종속성을 설치하려면:
root@kitploit:~
make deps

빌드

  • Gaia를 빌드하려면:
root@kitploit:~
make build
  • 테스트 API를 빌드하려면:
root@kitploit:~
make build-test

OpenAPI 명세

  • 테스트를 위한 OpenAPI 명세를 생성하려면:
root@kitploit:~
make generate-swagger
  • 테스트를 위한 OpenAPI 명세를 제거하려면:
root@kitploit:~
make clean-swagger

포매팅

  • 프로젝트를 포맷하려면 (테스트 + 소스):
root@kitploit:~
make format

정리

  • 빌드 파일을 정리하려면 (테스트 + 소스):
root@kitploit:~
make clean-build-files
  • 모든 것을 정리하려면:
root@kitploit:~
make clean

실행

  • 빌드 후, GAIA 옵션을 확인하려면:
root@kitploit:~
./_bin/gaia --help
  • GAIA 사용법:
root@kitploit:~
gaia --configuration <configuration> --openapi-path <openapi-path> --workdir-path <workdir-path> --verbose <verbose>

  • workdir-path: 퍼저의 다양한 로그를 찾을 수 있는 작업 디렉토리입니다.

  • openapi-path: 실제 API의 OpenAPI 파일 경로입니다. 퍼징 또는 모니터링 사용 시 필수, 통계 시에는 불필요

  • verbose : 상세도 수준 {NOTHING, LOW, MID, HIGH, ALL} (기본값: NOTHING)

  • configuration: 다음 내용을 포함하는 JSON 파일의 경로:

root@kitploit:~
{
  "configuration": {
    // One of : fuzzing or monitoring
    "fuzzing": {
      //Required
      "config_fuzzer": {
        //Required
        // In hours
        "timeout": 1,
        //Optional
        // Disable fuzzers
        "disable_fuzzers": [{
           "Restler":{
             // Bfs, BfsFast, BfsCheap or RandomWalk
             "strategy" : "Bfs" 
            }
          },
          "Schemathesis",
          {"Custom": {"id": "1"}}
        ],
        //Optional
        "custom_fuzzers": [
          "<command line that can accept `--output_dir <PATH>`, `--openapi_path <PATH>` and `--timeout <FLOAT>` as arguments>"
        ],
        //Optional
        "generation_config": {
          //optional (Required if you set a function to generate a value)
          "lib_path": "Absolute path to the dynamic library (.so, .dll, or .rs).",
          //Optional
          "generate_string": {
            //One of : Command, Value, File path or Function
            "command": "<command line that returns a string array>",
            //Or
            "value": ["fuzzstring"],
            //Or
            "function": "<function() that returns a string array>",
            //Or
            "file": "The file path to the dictionary of values"
          },
          //Optional
          "generate_datetime": {
            //One of : Command, Value, File path or Function
            "command": "<command line that returns a datetime array in a string format>",
            //Or
            "value": ["2019-06-26T20:20:39+00:00"],
            //Or
            "function": "<function() that returns a datetime array in a string format>",
            //Or
            "file": "The file path to the dictionary of values"
          },
          //Optional
          "generate_date": {
            //One of : Command, Value, File path or Function
            "command": "<command line that returns a date array in a string format>",
            //Or
            "value": ["2019-06-26"],
            //Or
            "function": "<function() that returns a date array in a string format>",
            //Or
            "file": "The file path to the dictionary of values"
          },
          //Optional
          "generate_int": {
            //One of : Command, Value, File path or Function
            "command": "<command line that returns an int array in a string format>",
            //Or
            "value": ["0"],
            //Or
            "function": "<function() that returns an int array in a string format>",
            //Or
            "file": "The file path to the dictionary of values"
          },
          //Optional
          "generate_number": {
            //One of : Command, Value, File path or Function
            "command": "<command line that returns a float array in a string format>",
            //Or
            "value": ["1.5"],
            //Or
            "function": "<function() that returns a float array in a string format>",
            //Or
            "file": "The file path to the dictionary of values"
          },
          //Optional
          "generate_object": {
            //One of : Command, Value, File path or Function
            "command": "<command line that returns a json object array in a string format>",
            //Or
            "value": ["{\"k\" : {\"v\" : \"value\" }}"],
            //Or
            "function": "<function() that returns a json object array in a string format>",
            //Or
            "file": "The file path to the dictionary of values"
          },
          //Optional
          "generate_path_parameter": {
            //One of : Command, Value, File path or Function
            "command": "<command line that returns a key-value map with a string key referring to a path parameter and a string array of values>",
            //Or
            "value": {
              "k": {
                "v": ["value"]
              }
            },
            //Or
            "function": "<function() that returns a key-value map with a string key referring to a path parameter and a string array of values>",
            //Or
            "file": "The file path to the dictionary of values"
          },
          //Optional
          "generate_query_parameter": {
            //One of : Command, Value, File path or Function
            "command": "<command line that returns a key-value map with a string key referring to a query parameter and a string array of values>",
            //Or
            "value": {
              "k": {
                "v": ["value"]
              }
            },
            //Or
            "function": "<function() that returns a key-value map with a string key referring to a query parameter and a string array of values>",
            //Or
            "file": "The file path to the dictionary of values"
          }
        }
      },
      //Required
      "config_process_manager": {
        //Optional
        "config_reset": {
          //Required
          "reset_lib": "Absolute path to the dynamic library (.so, .dll, or .rs).",
          //Required
          "function": "Function name that takes two strings as arguments and returns a unit. The first string represents the log in JSON format, and the second represents the path to the real-time log file."
        },
        //Required
        "config_proxy": {
          //Optional
          "headers_config": {
            //Optional
            "custom_headers": [
              {
                //Required
                "title": "title",
                //Required
                "header_type": {
                  //One of : Command or Value
                  "Command": {
                    //Required
                    "cmd": "<Command that returns the value of the header>",
                    //Required
                    //Refresh value in milliseconds
                    "duration": 0
                  },
                  // or
                  "Value": { "value": "Header value" }
                }
              }
            ]
          },
          //Optional
          "openapi_config": {
            //Optional
            "responses_to_string": true, // Change the type of the responses to string
            //Optional
            "requests_config": {
              //One of : Exclude or Only
              "only": {
                //Required
                "requests": [
                  {
                    //Required
                    "path": "Regex that represents a path",
                    //Required
                    "methods": [
                      "Get",
                      "Put",
                      "Post",
                      "Delete",
                      "Options",
                      "Head",
                      "Patch",
                      "Trace"
                    ]
                  }
                ]
              },
              //Or
              "Exclude": {
                //Required
                "requests": [
                  {
                    //Required
                    "path": "Regex that represents a path",
                    //Optional: Defaults to all methods if not specified.
                    "methods": [
                      "Get",
                      "Put",
                      "Post",
                      "Delete",
                      "Options",
                      "Head",
                      "Patch",
                      "Trace"
                    ]
                  }
                ]
              }
            }
          },
          //Optional
          "stream_response_services": [
            {
              //Required
              "path": "Regex that represents a path",
              //Optional: Defaults to all methods if not specified.
              "methods": [
                "Get",
                "Put",
                "Post",
                "Delete",
                "Options",
                "Head",
                "Patch",
                "Trace"
              ]
            }
          ]
        },
        //Optional
        "use_sync_requests" : true
      }
    },
    "monitoring": {
      "config_monitoring": {
        //One of : log_file_path or service
        "log_file_path": {
          //Required
          "path": "/home/log.log"
        },
        "service": {
          //Required
          "url": "http://localhost:3000/log"
        }
      }
    }
  },
  //Optional
  "config_checker": {
    //Optional
    "checkers_cmd": [
      "<command line that take a string as an argument and return unit. This string represents the log in JSON format>"
    ],
    //Optional
    "checkers_lib": [
      {
        //Required
        "checkers_lib": "Absolute path to the dynamic library (.so, .dll, or .rs).",
        //Required
        "function_names": [
          "Function names that take a string as an argument and return unit. This string represents the log in JSON format"
        ]
      }
    ]
  },
  //Optional
  "config_checker_elk_stack": {
    //Required
    "kibana_port": 5602 //Kibana url : http://localhost:{kibana_port}
  },
  //Optional
  "config_statistics": {
    //Required
    "process": {
      //One of : docker, process or service
      "docker": {
        //Required
        "container_id": "89u32eew2r"
      },
      "process": {
        //Required
        "pid": 1100293
      },
      "service": {
        //Required
        "url": "http://localhost:3000/statistics"
      }
    }
  },
  //Optional
  "scanner": true
}
  • 로그 JSON 형식 예시:
root@kitploit:~
{
  "id" : 9009,
  "request": {
    "method": "GET",
    "url": "http://localhost:8080/api/data",
    "headers": [
      ["connection", "keep-alive"],
      ["accept", "*/*"],
      ["user-agent", "schemathesis/3.24.3"],
      ["host", "localhost:8081"],
      ["accept-encoding", "gzip, deflate"],
      ["authorization", "Bearer"],
      ["x-schemathesis-testcaseid", "97pK1I"],
      ["authorization", "Bearer Test"]
    ],
    "params": [],
    "body": "",
    "timestamp": "2024-06-17T12:43:21.717+00:00"
  },
  "response": {
    "status_code": 403,
    "headers": [
      ["access-control-allow-headers", "accept, content-type"],
      ["access-control-allow-origin", "*"],
      ["content-type", "application/json"],
      ["content-length", "70"]
    ],
    "body": "{\"error\":\"get_data\",\"exception\":\"sender Test should be connected\"}",
    "timestamp": "2024-06-17T12:43:21.717+00:00"
  },
  "reset": false
}
root@kitploit:~
{
  "request": {
    "method": "POST",
    "url": "http://localhost:20000/injection/block",
    "headers": [
      ["user-agent", "restler/9.2.3"],
      ["content-type", "application/json"],
      ["accept", "application/json"],
      ["x-restler-sequence-id", "20f34e2b-13e8-4861-a7aa-77df3dff5ad6"],
      ["host", "localhost:22333"],
      ["content-length", "225"]
    ],
    "params": [
      ["async", "fuzzstring"],
      ["force", "fuzzstring"],
      ["chain", "fuzzstring"]
    ],
    "body": {
      "data": "fuzzstring",
      "operations": [[{ "branch": { "fuzz": false }, "data": "fuzzstring" }]]
    },
    "timestamp": "2024-06-17T12:43:21.717+00:00"
  },
  "response": {
    "status_code": 400,
    "headers": [
      ["content-type", "text/plain"],
      ["transfer-encoding", "chunked"]
    ],
    "body": null,
    "timestamp": "2024-06-17T12:43:21.722+00:00"
  },
  "reset": false
}

라이선스

저작권 © 2024, Functori [email protected].

도구 다운로드