
Default signature for Jaeles Scanner
该项目是 Osmedeus Engine 的一部分。查看其在 @OsmedeusEngine 的集成方式
jaeles config init
或者
尝试将签名文件夹克隆到某个位置,例如:
git clone --depth=1 https://github.com/jaeles-project/jaeles-signatures /tmp/jaeles-signatures/
然后使用以下命令将它们重新加载到数据库中。
jaeles config -a reload --signDir /tmp/jaeles-signatures
Scan Usage example:
jaeles scan -s <signature> -u <url>
jaeles scan -c 50 -s <signature> -U <list_urls> -L <level-of-signatures>
jaeles scan -c 50 -s <signature> -U <list_urls>
jaeles scan -c 50 -s <signature> -U <list_urls> -p 'dest=xxx.burpcollaborator.net'
jaeles scan -c 50 -s <signature> -U <list_urls> -f 'noti_slack "{{.vulnInfo}}"'
jaeles scan -v -c 50 -s <signature> -U list_target.txt -o /tmp/output
jaeles scan -s <signature> -s <another-selector> -u http://example.com
jaeles scan -G -s <signature> -s <another-selector> -x <exclude-selector> -u http://example.com
cat list_target.txt | jaeles scan -c 100 -s <signature>
jaeles scan -s '/tmp/custom-signature/sensitive/.*' -L 2 --fi
Examples:
jaeles scan -s 'jira' -s 'ruby' -u target.com
jaeles scan -c 50 -s 'java' -x 'tomcat' -U list_of_urls.txt
jaeles scan -G -c 50 -s '/tmp/custom-signature/.*' -U list_of_urls.txt
jaeles scan -v -s '~/my-signatures/products/wordpress/.*' -u 'https://wp.example.com/blog/' -p 'root=[[.URL]]'
cat urls.txt | grep 'interesting' | jaeles scan -c 50 -s /tmp/jaeles-signatures/cves/sample.yaml -U list_of_urls.txt --proxy http://127.0.0.1:8080
Config Command examples:
# Init default signatures
jaeles config init
# Update latest signatures
jaeles config update
jaeles config update --repo http://github.com/jaeles-project/another-signatures --user admin --pass admin
jaeles config update --repo [email protected]/jaeles-project/another-signatures -K your_private_key
# Reload signatures from a standard signatures folder (contain passives + resources)
jaeles config reload --signDir ~/standard-signatures/
# Add custom signatures from folder
jaeles config add --signDir ~/custom-signatures/
# Clean old stuff
jaeles config clean
# More examples
jaeles config add --signDir /tmp/standard-signatures/
jaeles config cred --user sample --pass not123456
For full Usage:
jaeles -hh
Jaeles 将签名视为单个文件,因此你可以按任何方式组织它。以下只是一个示例。
Fuzz 签名可能会有很多误报,因为我无法精确地定义哪些内容存在漏洞。所以请确保你清楚自己在做什么。
成为财务贡献者,帮助我们维持社区运转。[贡献]
在 cvebase.com 上探索最新的漏洞
Jaeles 由 @j3ssiejjj 用 ♥ 打造,并以 MIT 许可证发布。
| 目录 | 描述 |
|---|
| common | 为一些流行的应用程序实现错误配置检测 |
| cves | 实现一些 CVE 检测 |
| sensitvie | 一些包含敏感信息的常见路径 |
| probe | 用于检测目标所使用的某些技术 |
| passives | 用于被动检测 |
| fuzz | fuzz 模式的一些常见案例(我知道这里会有很多误报) |
| routines | 例程示例 |