CRLFISCANNER 是一款专业的 Node.js CLI 工具,用于通过发送基于 payload 的 HTTP 请求、分析响应头来检测 CRLF 注入漏洞,并可选择将结果报告给 API/Telegram 机器人。
CRLFISCANNER 是一款为安全研究人员打造的漏洞赏金自动化 CLI,用于快速检测目标端点中的 CRLF 注入漏洞。
它通过以下方式简化扫描:
⚠️ 免责声明:仅可将此工具用于授权的安全测试与教育。未经授权的攻击属于违法行为。
crlfi、包含 cappriciosec 的 Set-Cookie)npm install crlfi-scanner -g
crlfi-scanner -h
打开 Telegram 并搜索
👉 @CappricioSecuritiesTools_bot
点击 Start 或发送 /start,然后点击 Get Chat ID 按钮。
复制机器人显示的 Chat ID。
crlfi-scanner --chatid yourchatid
#EG : crlfi-scanner --chatid 1151520582
💡 提示: 配置完成后,您将直接在 Telegram 中收到 crlfi-scanner 的实时通知和警报。
crlfi-scanner -u https://example.com
urls.txt:
https://example.com
https://site2.com
crlfi-scanners -l urls.txt
crlfi-scanner -u https://example.com -p 127.0.0.1:8080 -o output.txt --chatid 12345
| Flag | 描述 |
|---|---|
-h, --help | 显示帮助 |
-u, --url | 单个目标 URL |
-l, --list | 包含 URL 的文件 |
-p, --proxy | 可选代理 host:port |
-o, --output | 保存存在漏洞的 URL |
--chatid | 用于报告的 Telegram/chat id |
crlfiscanner -u http://localhost:8000
██████╗██████╗ ██╗ ███████╗██╗
██╔════╝██╔══██╗██║ ██╔════╝██║
██║ ██████╔╝██║ █████╗ ██║
██║ ██╔══██╗██║ ██╔══╝ ██║
╚██████╗██║ ██║███████╗██║ ██║
╚═════╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝
███████╗ ██████╗ █████╗ ███╗ ██╗███╗ ██╗███████╗██████╗
██╔════╝██╔════╝██╔══██╗████╗ ██║████╗ ██║██╔════╝██╔══██╗
███████╗██║ ███████║██╔██╗ ██║██╔██╗ ██║█████╗ ██████╔╝
╚════██║██║ ██╔══██║██║╚██╗██║██║╚██╗██║██╔══╝ ██╔══██╗
███████║╚██████╗██║ ██║██║ ╚████║██║ ╚████║███████╗██║ ██║
╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝
Website: cappriciosec.com
crlfi-scanner - CRLF injection scanner
[+] Starting CRLF injection scan for 1 target(s)...
Checking ===> http://localhost:8000/end/www.cappriciosec.com
Checking ===> http://localhost:8000/end/%0D%0ASet-Cookie:cappriciosec=cappriciosec
💸[Vulnerable] ======> http://localhost:8000/end
📸PoC-Url->$ http://localhost:8000/end/%0D%0ASet-Cookie:cappriciosec=cappriciosec
[+] Bot reported vulnerability for http://localhost:8000/end
[+] Saved 1 vulnerable URL(s) to output.txt
crlfiscanner/
├── crlfiscanner.js
├── includes/
│ ├── help.js
│ ├── utils.js
│ ├── filereader.js
│ ├── validate.js
│ ├── scan.js
│ ├── bot.js
│ ├── db.js
│ ├── app.js
├── LICENSE
├── package.json
Invalid URL → 确保 URL 以 http:// 或 https:// 开头Either -u/--url or -l/--list is required. → 提供一种输入模式MIT License
KarthiTheHacker
KarthiTheHacker