/ | __ __/ /_____ / __ \(_)____/ /_ __ _______/ /____ _____
/ /| |/ / / / __/ __ \/ / / / / ___/ __ \/ / / / ___/ __/ _ \/ ___/
/ ___ / /_/ / /_/ /_/ / /_/ / / / / /_/ / /_/ (__ ) /_/ __/ /
/_/ |_\__,_/\__/\____/_____/_/_/ /_.___/\__,_/____/\__/\___/_/
### 自动运行并保存多个IP的ffuf扫描结果
## 目录
* [快速运行](#quick-run)
* [常见问题](#faq)
* [为什么?](#why)
* [推荐用法?](#what-is-the-recommended-usage)
* [需要什么数据?](#what-data-does-this-need)
* [这个脚本如何工作?](#how-does-this-script-work)
* [程序无法工作](#this-program-isnt-working)
* [使用](#usage)
## 快速运行
git clone https://github.com/NetSPI/AutoDirbuster.git cd AutoDirbuster && pip3 install -r requirements.txt python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt
## 常见问题
### 为什么?
Ffuf 是一个很棒的目录爆破工具,但针对多个IP和端口运行它是一个非常手动化的过程,扫描之间会有大量空档时间。本脚本尝试自动化该过程,并消除扫描之间的空档时间。
### 推荐用法?
**如果是攻击多个目标:**
* 运行Nmap并查找开放端口
* 查看Nmap结果,创建一个IP:port列表,每行一个
* 对开放端口运行AutoDirbuster
* AutoDirbuster将判断服务是否基于HTTP
* `python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt --combine`
**如果是攻击单个目标:**
* `python AutoDirbuster.py -u example.com:80 -w my_wordlist.txt`
**有用的选项包括:**
| 选项 | 用途 |
|-----------------|-------------------------------------------------------------------|
| --dns | 将IP解析为主机名 |
| --extensions | 扫描时使用的文件扩展名 |
| --rate | 每秒请求速率 |
| --timeout | 为每个主机设置超时值(分钟) |
| --match-codes | 匹配提供的HTTP状态码 |
| --combine | 扫描后将所有CSV结果合并到一个文件中 |
| --quiet | 抑制ffuf的stderr输出(等效于2>/dev/null) |
| --custom-option | 指定AutoDirbuster默认不支持的ffuf选项 |
指定`--help`标志以获取完整选项列表。
### 需要什么数据?
程序可以接受两个数据源:
1. IP:port或hostname:port的列表,每行一个
* `python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt`
2. 单个目标
* `python AutoDirbuster.py -u example.com:80 -w my_wordlist.txt`
### 这个脚本如何工作?
* 提供一个目标列表
* 发送HTTPS和HTTP请求,以判断服务是否基于HTTP以及是否需要TLS(HTTP请求本身作为连通性检查——无需单独进行TCP端口扫描)
* 如果HTTPS因TLS协商错误失败,则在回退到普通HTTP之前尝试宽松的TLS上下文
* 如果服务是HTTP,则检查同一目录中是否存在之前的报告文件
* 报告文件的格式为:`ffuf-report-{proto}_{target}_{port}`
* 使用Python的`subprocess.Popen()`运行ffuf
* 下一个IP:port经历相同的流程(HTTP服务查询,目录爆破)
### 程序无法工作
请确保以下事项:
* 是否已安装`requirements.txt`中列出的所有依赖项?
* `ffuf`是否已安装并在系统路径中?
* 尝试运行`ffuf -V`
* 安装说明可在[ffuf GitHub仓库页面](https://github.com/ffuf/ffuf)找到
* 您可能需要使用Python 3.11+
* 版本信息可通过运行`python -V`获取
## 使用
usage: ___ __ ____ _ __ __ / | __ / /___ / __ ()/ / __ / / _____ / /| |/ / / / __/ __ / / / / / __/ __ / / / / __/ __/ _ / __/ / ___ / // / // // / // / / / / // / // ( ) // __/ / // |_,/_/_/_____/// /./_,//_/___/_/
AutoDirbuster.py [options] {target file}
Automatically run and save ffuf scans for multiple IPs
options: -h, --help show this help message and exit
AutoDirbuster options: target Target file with IP:port, one per line -u, --url Single target mode, positional argument is target in IP:port format -f, --force Force mode; don't check if report file exists, this will result in previous reports being overwritten --dns Automatically resolve IP address to hostname to use during dirbust --debug Show debugging information --combine Combine all CSV results into a single file after scanning --quiet Suppress ffuf's stderr output (equivalent of 2>/dev/null); AutoDirbuster's own output and ffuf stdout are unaffected
ffuf options: -w WORDLIST, --wordlist WORDLIST Wordlist to use for list based brute force -X METHOD, --method METHOD HTTP method to use; default=GET -e EXTENSIONS, --extensions EXTENSIONS File extension list (e.g.: "asp,aspx"); default is None -t THREADS, --threads THREADS Override the default number of ffuf threads --rate RATE Rate of requests per second -to TIMEOUT, --timeout TIMEOUT Set a timeout value for each host in minutes; default is None -fr, --follow-redirects Follow redirects; default is False -r, --recursive Recursive mode; default is False -s STARTPOINT, --startpoint STARTPOINT Start point of the scan; default=/ -of OUTPUT_FORMAT, --output-format OUTPUT_FORMAT Output format to write results to; default=csv -mc MATCH_CODES, --match-codes MATCH_CODES Match HTTP status codes; default=200,204,301,302,307,401,403,405,500 -nac, --no-auto-calibrate Do not automatically calibrate filtering options -H HEADER, --header HEADER HTTP header "Name: Value", separated by colon --custom-option CUSTOM_OPTION [CUSTOM_OPTION ...] Specify ffuf option that AutoDirbuster doesn't support by default. Argument should be a key/value pair separated by a comma with no leading '-', example: --custom-option=ml,1. If the provided argument is a boolean, provide an empty value: --custom-option=sa,
Examples: python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt python AutoDirbuster.py -st example.com:80 -w my_wordlist.txt -mc 200,500 python AutoDirbuster.py ip_port_list.txt -w my_wordlist.txt -r -e "php,html" --dns