
Инструмент безопасности для разведки и сбора информации на веб-сайте. (python 3.x)

Инструмент безопасности для разведки и сбора информации о веб-сайте. (python 3.x)
- Добавлена функция прокси
- Переопределение приоритетов/задач
- Отладка результатов сертификатов поддоменов
- Отображение текущего номера обхода во время сканирования ("CB:")
- Пасхальное яйцо на Рождество :)
- Опция -nfs (не первый шаг) для пропуска первых этапов разведки
- Google CSE перед сканированием
- Создание WIKI
- Обнаружение потенциального раскрытия пути в HTML-странице
- Обнаружение скрытых каталогов
(за подробностями обращайтесь к CHANGELOG.md)
- git clone https://github.com/c0dejump/HawkScan.git && sudo python3 HawkScan/setup.py install
- pip(3) install -r requirements.txt
- python3 -m pip install -r requirements.txt
P1 — самый важный
[WIP] Множественное исключение, например: --exclude 403,1337b [P1] [В процессе] (см. Примеры)
[WIP] Анонимная маршрутизация через прокси (список http/s прокси) [P1] [В процессе]
[WIP] Перестроение отчёта сканирования [P1]
[WIP] HExHTTP замена "header information" перед сканированием
usage: hawkscan.py [-h] [-u URL] [-f FILE_URL] [-t THREAD] [--exclude EXCLUDE [EXCLUDE ...]] [--auto] [--update] [-w WORDLIST] [-b [BACKUP ...]] [-p PREFIX] [-H HEADER_] [-a USER_AGENT] [--redirect] [--auth AUTH] [--timesleep TS] [--proxie PROXIE] [-r] [-s SUBDOMAINS] [--js] [--nfs] [--ffs] [--notify] [-o OUTPUT] [-of OUTPUT_TYPE]
> General:
-u URL URL to scan [required]
-f FILE_URL file with multiple URLs to scan
-t THREAD Number of threads to use for URL Fuzzing. Default: 30
--exclude EXCLUDE [EXCLUDE ...] Exclude page, response code, response size. (Exemples: --exclude 500,337b)
--auto Automatic threads depending response to website. Max: 30
--update For automatic update
--lightmode For a just simple fuzzing 1 request per second & a new session for each request
> Wordlist Settings:
-w WORDLIST Wordlist used for Fuzzing the desired webite. Default: dichawk.txt
-b Adding prefix/suffix backup extensions during the scan. (Exemples: exemple.com/~ex/, exemple.com/ex.php.bak...) /!\ beware, take more longer
-p PREFIX Add prefix in wordlist to scan
> Request Settings:
-H HEADER_ Modify header. (Exemple: -H "cookie: test")
-a USER_AGENT Choice user-agent. Default: Random
--redirect For scan with redirect response (301/302)
--auth AUTH HTTP authentification. (Exemples: --auth admin:admin)
--timesleep TS To define a timesleep/rate-limit if app is unstable during scan.
> Tips:
-r Recursive dir/files
-s SUBDOMAINS Subdomain tester
--js For try to found keys, token, sensitive endpoints... in the javascript page
--nfs Not the first step of scan during the first running (waf, vhosts, wayback etc...)
--ffs Force the first step of scan during the first running (waf, vhosts, wayback etc...)
--notify For receveid notify when the scan finished (only work on linux)
> Export Settings:
-o OUTPUT Output to site_scan.txt (default in website directory)
-of OUTPUT_TYPE Output file format. Available formats: json, csv, txt
//Basic
python hawkscan.py -u https://www.exemple.com/
//With specific dico
python hawkscan.py -u https://www.exemple.com/ -w dico_extra.txt
//with 30 threads
python hawkscan.py -u https://www.exemple.com/ -t 30
//With backup files scan
python hawkscan.py -u https://www.exemple.com/ -b
//With an exclude page
python hawkscan.py -u https://www.exemple.com/ --exclude profile.php
//With an exclude response code
python hawkscan.py -u https://www.exemple.com/ --exclude 403
//With an exclude bytes number
python hawkscan.py -u https://www.exemple.com/ --exclude 1337b
//With two excludes type
python hawkscan.py -u https://www.exemple.com/ --exclude 1337b,403
Layno (https://github.com/Clayno/) [Технический помощник]
Sanguinarius (https://twitter.com/sanguinarius_Bt) [Технический помощник]
Jamb0n69 (https://twitter.com/jamb0n69) [Технический помощник]
Cyber_Ph4ntoM (https://twitter.com/__PH4NTOM__) [Бета-тестер и графический дизайнер логотипа]
https://www.paypal.me/c0dejump
Или если хотите угостить меня кофе :)
Этот скрипт использует "WafW00f" для обнаружения WAF на первом этапе (https://github.com/EnableSecurity/wafw00f)
Этот скрипт использует "Sublist3r" для сканирования поддоменов (https://github.com/aboul3la/Sublist3r)