
TheftFuzzer é uma ferramenta que fuzza implementações de Cross-Origin Resource Sharing para configurações incorretas comuns.
┌┬┐┬ ┬┌─┐┌─┐┌┬┐┌─┐┬ ┬┌─┐┌─┐┌─┐┬─┐
│ ├─┤├┤ ├┤ │ ├┤ │ │┌─┘┌─┘├┤ ├┬┘
┴ ┴ ┴└─┘└ ┴ └ └─┘└─┘└─┘└─┘┴└─
TheftFuzzer é uma ferramenta que fuzza implementações de Cross-Origin Resource Sharing para configurações incorretas comuns.
python theftfuzzer.py -d 'http://example.com/api/data'
python theftfuzzer.py -h
~$ python theftfuzzer.py -h
usage: theftfuzzer.py [-h] -d DOMAIN [-c COOKIE]
Cross Origin Resource Sharing Fuzzer por Corben Leo
optional arguments:
-h, --help show this help message and exit
-d DOMAIN, --domain DOMAIN
URL / Alvo para fuzzar
-c COOKIE, --cookie COOKIE
Arquivo contendo cookie para enviar nas requisições de fuzzing