
Assinatura padrão para o Jaeles Scanner
Este projeto fazia parte do Osmedeus Engine. Veja como ele foi integrado em @OsmedeusEngine
jaeles config init
Ou
Tente clonar a pasta de assinaturas para algum lugar como este
git clone --depth=1 https://github.com/jaeles-project/jaeles-signatures /tmp/jaeles-signatures/
em seguida, recarregue-as no banco de dados com este comando.
jaeles config -a reload --signDir /tmp/jaeles-signatures
Scan Usage example:
jaeles scan -s <signature> -u <url>
jaeles scan -c 50 -s <signature> -U <list_urls> -L <level-of-signatures>
jaeles scan -c 50 -s <signature> -U <list_urls>
jaeles scan -c 50 -s <signature> -U <list_urls> -p 'dest=xxx.burpcollaborator.net'
jaeles scan -c 50 -s <signature> -U <list_urls> -f 'noti_slack "{{.vulnInfo}}"'
jaeles scan -v -c 50 -s <signature> -U list_target.txt -o /tmp/output
jaeles scan -s <signature> -s <another-selector> -u http://example.com
jaeles scan -G -s <signature> -s <another-selector> -x <exclude-selector> -u http://example.com
cat list_target.txt | jaeles scan -c 100 -s <signature>
jaeles scan -s '/tmp/custom-signature/sensitive/.*' -L 2 --fi
Examples:
jaeles scan -s 'jira' -s 'ruby' -u target.com
jaeles scan -c 50 -s 'java' -x 'tomcat' -U list_of_urls.txt
jaeles scan -G -c 50 -s '/tmp/custom-signature/.*' -U list_of_urls.txt
jaeles scan -v -s '~/my-signatures/products/wordpress/.*' -u 'https://wp.example.com/blog/' -p 'root=[[.URL]]'
cat urls.txt | grep 'interesting' | jaeles scan -c 50 -s /tmp/jaeles-signatures/cves/sample.yaml -U list_of_urls.txt --proxy http://127.0.0.1:8080
Config Command examples:
# Init default signatures
jaeles config init
# Update latest signatures
jaeles config update
jaeles config update --repo http://github.com/jaeles-project/another-signatures --user admin --pass admin
jaeles config update --repo [email protected]/jaeles-project/another-signatures -K your_private_key
# Reload signatures from a standard signatures folder (contain passives + resources)
jaeles config reload --signDir ~/standard-signatures/
# Add custom signatures from folder
jaeles config add --signDir ~/custom-signatures/
# Clean old stuff
jaeles config clean
# More examples
jaeles config add --signDir /tmp/standard-signatures/
jaeles config cred --user sample --pass not123456
For full Usage:
jaeles -hh
O Jaeles procura a assinatura como um único arquivo, então você pode estruturá-la como quiser. Isto é apenas um exemplo.
| Page | Description |
|---|---|
| common | Implementa configurações incorretas para alguns aplicativos populares |
| cves | Implementa alguns CVEs |
| sensitvie | Alguns caminhos comuns com informações sensíveis |
| probe | Usado para detectar alguma tecnologia usada pelo alvo |
| passives | Usado para detecção passiva |
| fuzz | Alguns casos comuns para o modo fuzz (eu sei que há muitos falsos positivos aqui) |
| routines | Exemplo de rotinas |
As assinaturas Fuzz podem ter muitos falsos positivos, porque não consigo definir exatamente o que é vulnerável para tudo. Portanto, certifique-se de saber o que você está fazendo aqui.
Torne-se um contribuidor financeiro e ajude-nos a sustentar nossa comunidade. [Contribuir]
Explore as vulnerabilidades mais recentes em cvebase.com
Jaeles é feito com ♥ por @j3essiejjj e é lançado sob a licença MIT.