
🦚 Набор инструментов для тестирования на проникновение веб-приложений, написанный на Rust .
Kanha - Набор для пентестинга веб-приложений, написанный на rust 🦀Installation
⦾
Subcommands
⦾
Contribute
![-----------------------------------------------------][line]

Kanha — это инструмент, который может помочь вам выполнять различные атаки на основе целевого домена. С помощью одного только kanha вы можете выполнять, [Fuzzing][wiki-fuzzing], [Reverse dns lookup][wiki-dns-lookup], [common http response][wiki-http], [subdomain takeover detection][wiki-subdomain] и многие [more][commands].
Проект вдохновлён [mini.nvim][mini], в основном помогая вам быть продуктивным с меньшим количеством tools(plugins), установленных на вашей системе, и быть ненавязчивым и функционировать как автономный single binary из коробки.
Создан с нуля с учётом производительности, простоты использования и переносимости на вашем любимом языке программирования [rust][rust] 💝
Binary jq, curl, tar и wgetwget -qO- "$(curl -qfsSL "https://api.github.com/repos/pwnwriter/kanha/releases/latest" | jq -r '.assets[].browser_download_url' | grep -Ei "$(uname -m).*$(uname -s).*musl" | grep -v "\.sha")" | tar -xzf - --strip-components=1
./kanha -h
[!IMPORTANT] Для апстрим-обновлений рекомендуется собирать
kanhaиз исходного кода!
Source git clone --depth=1 https://github.com/pwnwriter/kanha --branch=main
cd kanha
cargo build --release
Cargo Используя [crates.io][crate]
cargo install kanha
Используя [binstall][binstall]
cargo binstall kanha
Примечание ⚠️ Для этого требуется рабочая настройка rust/cargo и binstall.
METIS Linux sudo/doas pacman -Syyy kanha
Arch user repository paru/yay -S kanha-git
On Nix # Build from source and run
nix run github:pwnwriter/kanha
# without flakes:
nix-env -iA nixpkgs.kanha
# with flakes:
nix profile install nixpkgs#kanha
➊ Status :- Просто возвращает HTTP-код ответа URL-адресов
$ kanha status -h
Just return the HTTP response code of URLs
Usage: kanha status [OPTIONS]
Options:
-f, --filename <FILENAME> A file containing multiple urls
-t, --tasks <TASKS> Define the maximum concurrent tasks [default: 20]
--stdin Reads input from the standard in
--exclude <EXCLUDE> Define your status code for selective exclusion
-h, --help Print help
-V, --version Print version
➋ fuzz :- Фаззинг URL-адресов и возврат кодов ответа
$ kanha fuzz -h
Fuzz a URL and return the response codes
Usage: kanha fuzz [OPTIONS] --payloads <PAYLOADS>
Options:
-p, --payloads <PAYLOADS> A file containing a list of payloads
-u, --url <URL> A single url
-f, --file-path <FILE_PATH> Path of the file containing multiple urls
-t, --tasks <TASKS> Define the maximum concurrent tasks [default: 20]
--exclude <EXCLUDE> Define your status code for selective exclusion
--stdin Reads input from the standard in
-h, --help Print help
-V, --version Print version
➌ rdns :- Обратный DNS-запрос
$ kanha rdns -h
Reverse dns lookup
Usage: kanha rdns [OPTIONS] --filename <FILENAME>
Options:
-f, --filename <FILENAME> a file containing a list of possible wordlists
--stdin Reads input from the standard in
-h, --help Print help
-V, --version Print version
➍ Takeover :- Проверка возможного перехвата поддомена
$ kanha takeover -h
Check possible subdomain takeover vulnerability
Usage: kanha takeover [OPTIONS]
Options:
-u, --url <URL> A single url
-f, --file-path <FILE_PATH> Path of the file containing multiple urls
-j, --json-file <JSON_FILE> A json file containing signature values of different services
--stdin Reads input from the standard in
-h, --help Print help
-V, --version Print version
➎ urldencode :- (Де|За)кодирование URL-адресов
$ kanha urldencode -h
(De|En) code urls
Usage: kanha urldencode [OPTIONS]
Options:
--encode <ENCODE> Provide a url to encode
--decode <DECODE> Provide a url to dencode
-h, --help Print help
-V, --version Print version
haylxon][haylxon] :- Молниеносно быстрый инструмент для захвата скриншотов вашего списка доменов прямо из терминала, написанный на rust 🦀httpx][httpx] :- httpx — это быстрый многоцелевой HTTP-инструментарий.ffuf][ffuf] :- Быстрый веб-фаззер, написанный на Go