endsfuzzer 是一款简单的工具,用于对域名列表中的特定端点进行模糊测试。它会先检查列表中所有域名的一个端点,然后移至下一个端点继续检查。
endsfuzzer 需要 Golang 才能运行。
go get -u github.com/ameenalkurdy/endsfuzzer
Usage of endsfuzzer:
-dL string
Path to domains list (required)
-eL string
Path to endpoints list (required)
-threads int
Threads Number (default 40)
-timeout int
Connection timeout in seconds (default 15)
文件中的被测试主机不能带有协议(https/http)。
endsfuzzer -dL domains.txt -eL quickhits.txt
endsfuzzer -dL domains.txt -eL quickhits.txt -timeout 20 -threads 50
输出:
https://about.example.com/admin 403
http://dev.example.com/admin 302 -> https://www.example.com/
https://secure.example.com/admin 200
https://about.example.com/cgi-bin 403
http://dev.example.com/cgi-bin 302 -> https://www.example.com/
https://secure.example.com/cgi-bin 403