
CRLFMap é uma ferramenta para encontrar vulnerabilidades de HTTP Splitting
CRLFMap é uma ferramenta para encontrar vulnerabilidades de divisão HTTP (HTTP Splitting)
go get github.com/ryandamour/crlfmap
Available Commands:
help Help about any command
scan A scanner for all your CRLF needs
Flags:
-h, --help help for crlfmap
scancrlfmap scan --domains domains.txt --output results.txt --slack-webhook "https://hooks.slack.com/services/XXX/YYYZZZ"
===============================================================
CRLFMap v0.0.1
by Ryan D'Amour @ryandamour
===============================================================
_ __
| |/ _|
___ _ __| | |_ _ __ ___ __ _ _ __
/ __| '__| | _| '_ ' _ \/ _' | '_ \
| (__| | | | | | | | | | | (_| | |_) |
\___|_| |_|_| |_| |_| |_|\__,_| .__/
| |
|_|
v0.0.1
-----------------------
:: Domains : domains.txt
:: Payloads : payloads.txt
:: Threads : 1
:: Output : results.txt
:: User Agent : Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36
:: Timeout : 10
:: Delay : 0
-----------------------
[+]http://localhost:3000/v1/%0AInjected-Header:CRLFInjecttest.json: is Vulnerable
[+]http://localhost:3000/v1/%20%0AInjected-Header:CRLFInjecttest.json: is Vulnerable
Pull requests são bem-vindos. Para mudanças significativas, por favor abra primeiro uma issue para discutir o que gostaria de alterar.
Por favor, certifique-se de atualizar os testes conforme apropriado.
