Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
insect — 高性能 Web 路径发现与目录暴力破解工具。通过可自定义的字典、过滤器和递归扫描,发现隐藏文件、目录及端点,适用于渗透测试。 | Kitploit
工具/GitHubGitHub/nu11secur1ty/insect
侦察漏洞扫描器信息收集Web安全模糊测试渗透测试
GitHubnu11secur1ty/insect

insect

高性能 Web 路径发现与目录暴力破解工具。通过可自定义的字典、过滤器和递归扫描,发现隐藏文件、目录及端点,适用于渗透测试。

查看仓库
1513年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

insect - Web 路径发现

当前版本: v1.4 (20222.09.03)

一个高级命令行工具,用于暴力破解 Web 服务器中的目录和文件,也称为 Web 路径扫描器

想法 来自 @maurosoria 和 @shelld3v

Developement-2022 由 @nu11secur1ty 积极开发中

目录

  • 安装
  • 字典列表
  • 选项
  • 配置
  • 如何使用
    • 简单用法
    • 暂停进度
    • 递归
    • 线程
    • 前缀 / 后缀
    • 黑名单
    • 过滤器
    • 原始请求
    • 字典格式
    • 排除扩展名
    • 扫描子目录
    • 代理
    • 报告
    • 更多示例命令
  • 支持 Docker
    • 在 Linux 上安装 Docker
    • 构建 insect 镜像
    • 使用 insect
  • 参考
  • 提示
  • 贡献
  • 许可证

工具:

  • Attack-Modules-2022

安装与使用

要求: python 3.10.5 或更高版本

选择以下安装方式之一:

  • 使用 git 安装: git clone https://github.com/nu11secur1ty/insect.git --depth 1(推荐)
  • 使用 ZIP 文件安装: 在此下载
  • 使用 Docker 安装: docker build -t "insect:latest" .(更多信息可以在此处找到)

通过包管理器安装:

  • 使用 PyPi 安装: pip3 install dirsearch
  • 在 Kali Linux 上安装: sudo apt-get install dirsearch(已弃用)

字典列表(重要)

摘要:

  • 字典是一个文本文件,每行是一个路径。
  • 关于扩展名,与其他工具不同,dirsearch 和 insect 仅用 -e 标志中的扩展名替换 %EXT% 关键字。
  • 对于没有 %EXT% 的字典(如 SecLists),需要使用 -f | --force-extensions 开关来为字典中的每个单词添加扩展名,以及 /。
  • 要将您的扩展名应用于已有扩展名的字典条目,请使用 -O | --overwrite-extensions(注意:某些扩展名被排除在覆盖之外,例如 .log、.json、.xml、... 或媒体扩展名如 .jpg、.png)
  • 要使用多个字典,可以用逗号分隔您的字典。示例:wordlist1.txt,wordlist2.txt。

示例:

  • 普通扩展名:``` index.%EXT%
将 **asp** 和 **aspx** 作为扩展名传递将生成以下字典:```
index
index.asp
index.aspx
  • 强制扩展:``` admin
使用 **-f**/**--force-extensions** 标志传递 **php** 和 **html** 作为扩展名,将生成以下字典:```
admin
admin.php
admin.html
admin/
  • 覆盖扩展名:``` login.html
将 **jsp** 和 **jspa** 作为扩展名与 **-O**/**--overwrite-extensions** 标志一起传递,将生成以下字典:```
login.html
login.jsp
login.jspa

选项 -------``` Usage: insect.py [-u|--url] target [-e|--extensions] extensions [options]

Options: --version show program's version number and exit -h, --help show this help message and exit

Mandatory: -u URL, --url=URL Target URL(s), support multiple flags -l PATH, --url-file=PATH URL list file --stdin Read URL(s) from STDIN --cidr=CIDR Target CIDR --raw=PATH Load raw HTTP request from file (use --scheme flag to set the scheme) -s SESSION_FILE, --session=SESSION_FILE Session file --config=PATH Full path to config file, see 'config.ini' for example (Default: config.ini)

Dictionary Settings: -w WORDLISTS, --wordlists=WORDLISTS Customize wordlists (separated by commas) -e EXTENSIONS, --extensions=EXTENSIONS Extension list separated by commas (e.g. php,asp) -f, --force-extensions Add extensions to the end of every wordlist entry. By default insect only replaces the %EXT% keyword with extensions -O, --overwrite-extensions Overwrite other extensions in the wordlist with your extensions (selected via -e) --exclude-extensions=EXTENSIONS Exclude extension list separated by commas (e.g. asp,jsp) --remove-extensions Remove extensions in all paths (e.g. admin.php -> admin) --prefixes=PREFIXES Add custom prefixes to all wordlist entries (separated by commas) --suffixes=SUFFIXES Add custom suffixes to all wordlist entries, ignore directories (separated by commas) -U, --uppercase Uppercase wordlist -L, --lowercase Lowercase wordlist -C, --capital Capital wordlist

General Settings: -t THREADS, --threads=THREADS Number of threads -r, --recursive Brute-force recursively --deep-recursive Perform recursive scan on every directory depth (e.g. api/users -> api/) --force-recursive Do recursive brute-force for every found path, not only directories -R DEPTH, --max-recursion-depth=DEPTH Maximum recursion depth --recursion-status=CODES Valid status codes to perform recursive scan, support ranges (separated by commas) --subdirs=SUBDIRS Scan sub-directories of the given URL[s] (separated by commas) --exclude-subdirs=SUBDIRS Exclude the following subdirectories during recursive scan (separated by commas) -i CODES, --include-status=CODES Include status codes, separated by commas, support ranges (e.g. 200,300-399) -x CODES, --exclude-status=CODES Exclude status codes, separated by commas, support ranges (e.g. 301,500-599) --exclude-sizes=SIZES Exclude responses by sizes, separated by commas (e.g. 0B,4KB) --exclude-texts=TEXTS Exclude responses by texts, separated by commas (e.g. 'Not found', 'Error') --exclude-regex=REGEX Exclude responses by regex (e.g. '^Error$') --exclude-redirect=STRING Exclude responses if this regex (or text) matches redirect URL (e.g. '/index.html') --exclude-response=PATH Exclude responses similar to response of this page, path as input (e.g. 404.html) --skip-on-status=CODES Skip target whenever hit one of these status codes, separated by commas, support ranges --min-response-size=LENGTH Minimum response length --max-response-size=LENGTH Maximum response length --max-time=SECONDS Maximum runtime for the scan

下载工具