Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
InfoLeak-Scanner — Web扫描器,用于检测目标网站的CMS版本、插件、易受攻击的JavaScript库、电子邮件地址和电话号码,并对信息泄露风险进行评分。 | Kitploit
工具/GitHubGitHub/siwecos/infoleak-scanner
OSINT (开源情报)漏洞扫描器信息收集Web安全电子邮件收集Archived
GitHubsiwecos/infoleak-scanner

InfoLeak-Scanner

Web扫描器,用于检测目标网站的CMS版本、插件、易受攻击的JavaScript库、电子邮件地址和电话号码,并对信息泄露风险进行评分。

查看仓库
179203年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

InfoLeak-Scanner

Docker

首先运行 docker run --rm -p 8000:80 siwecos/infoleak-scanner。

打开浏览器使用扫描器:http://localhost/?url=<URL>

安装

安装 php5、curl 和网络服务器:

sudo apt-get install apache2 php5 php5-curl

将应用程序复制到网络服务器目录:

cp -R . /var/www/html/

这是什么?

内容管理系统(CMS)

  • Drupal
  • Joomla
  • vbulletin
  • Webspell
  • Webspell-NOR
  • Wordpress
  • xt-commerce
  • Contenido
  • magento2
  • shopsys
  • shopify
  • squarespace
  • blogger
  • 1C-Bitrix
  • TYPO3
  • prestashop

插件

搜索检测到的 CMS 的插件。最大的列表(wordpress)包含 980 个不同的插件。

JavaScript 库

搜索存在漏洞且最常用的 JavaScript 库。

邮件地址

搜索邮件地址。对垃圾邮件和/或社会工程学攻击有价值。

电话号码

搜索电话号码。对社会工程学攻击和/或诈骗有价值。

评分

| 发现项              | 评分 (0-100) |
|---------------------+---------------|
| CMS_ONLY            |           100 |
| CMS_VERSION         |            96 |
| CMS_VERSION_VULN    |     见下方说明 |
| PLUGIN_ONLY         |            99 |
| PLUGIN_VERSION      |            96 |
| PLUGIN_VERSION_VULN |     见下方说明 |
| JS_LIB_ONLY         |            99 |
| JS_LIB_VERSION      |            96 |
| JS_LIB_VULN_VERSION |     见下方说明 |
| EMAIL_FOUND         |            96 |
| NUMBER_FOUND        |            98 |

如果发现以下类型:

	CMS_VERSION_VULN
	PLUGIN_VERSION_VULN
	JS_LIB_VULN_VERSION

则总分将上限为 20 分,并且每多一个漏洞将扣减 10 分。这意味着,如果同时返回
CMS_VERSION_VULN、PLUGIN_VERSION_VULN 和 JS_LIB_VULN_VERSION,总分将为 0 分。

此外,在 Wordpress 网站上发现 jQuery v1.12.4 时,不会像普通易受攻击库那样评分。
此类发现将导致 90 分的评分,但占位符仍为 JS_LIB_VULN_VERSION,因为它是一个易受攻击的库。

运行扫描器

您可以通过 POST 和 GET 请求运行扫描器。

POST

如果您希望通过 POST 请求运行扫描器,必须以 JSON 编码格式发送参数:

{
  "url": "string",
  "dangerLevel": 0,
  "callbackurls": [
    "string"
  ],
  "userAgent": "string"
}

url 定义要扫描的 URL。 dangerLevel 不相关,只需设置为 0。 callbackurls 是一个 URL 数组。这些 URL 将接收扫描结果(通过 POST 发送)。 userAgent 定义您希望在扫描时发送的自定义用户代理。

GET

通过 GET 请求运行扫描器更简单。您只需提供一个 URL 即可运行应用程序:

http://localhost/?url=<URL>

输出

所有扫描均未发现结果:

{
    "name": "InfoLeak-Scanner",
    "version": "1.0.0",
    "hasError": false,
    "errorMessage": null,
    "score": 100,
    "tests": [
        {
            "name": "CMS",
            "hasError": false,
            "errorMessage": null,
            "score": 100,
            "scoreType": "info",
            "testDetails": null
        },
        {
            "name": "CMS_PLUGINS",
            "hasError": false,
            "errorMessage": null,
            "score": 100,
            "scoreType": "warning",
            "testDetails": null
        },
        {
            "name": "JS_LIB",
            "hasError": false,
            "errorMessage": null,
            "score": 100,
            "scoreType": "warning",
            "testDetails": null
        },
        {
            "name": "EMAIL_ADDRESS",
            "hasError": false,
            "errorMessage": null,
            "score": 100,
            "scoreType": "info",
            "testDetails": null
        },
        {
            "name": "PHONE_NUMBER",
            "hasError": false,
            "errorMessage": null,
            "score": 100,
            "scoreType": "info",
            "testDetails": null
        }
    ]
}

每次扫描至少发现一个问题:

{
    "name": "InfoLeak-Scanner",
    "version": "1.0.0",
    "hasError": false,
    "errorMessage": null,
    "score": 20,
    "tests": [
        {
            "name": "CMS",
            "hasError": false,
            "errorMessage": null,
            "score": 96,
            "scoreType": "info",
            "testDetails": [
                {
                    "placeholder": "CMS_VERSION",
                    "values": {
                        "cms": "wordpress",
                        "version": "4.9.6",
                        "node": "meta",
                        "node_content": "WordPress 4.9.6"
                    }
                }
            ]
        },
        {
            "name": "CMS_PLUGINS",
            "hasError": false,
            "errorMessage": null,
            "score": 99,
            "scoreType": "warning",
            "testDetails": [
                {
                    "placeholder": "PLUGIN_ONLY",
                    "values": {
                        "plugin": "contact-form-7",
                        "node": "href",
                        "node_content": "https://[...]/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.0.2"
                    }
                }
            ]
        },
        {
            "name": "JS_LIB",
            "hasError": false,
            "errorMessage": null,
            "score": 0,
            "scoreType": "warning",
            "testDetails": [
                {
                    "placeholder": "JS_LIB_VULN_VERSION",
                    "values": {
                        "js_lib_name": "jquery",
                        "js_lib_version": "1.12.4",
                        "node": "src",
                        "node_content": "https://[...]/wp-includes/js/jquery/jquery.js?ver=1.12.4"
                    }
                }
            ]
        },
        {
            "name": "EMAIL_ADDRESS",
            "hasError": false,
            "errorMessage": null,
            "score": 96,
            "scoreType": "info",
            "testDetails": [
                {
                    "placeholder": "EMAIL_FOUND",
                    "values": {
                        "email_adress": [
                            [
                                "[email protected]"
                            ]
                        ]
                    }
                }
            ]
        },
        {
            "name": "PHONE_NUMBER",
            "hasError": false,
            "errorMessage": null,
            "score": 98,
            "scoreType": "info",
            "testDetails": [
                {
                    "placeholder": "NUMBER_FOUND",
                    "values": {
                        "number": [
                            "1234-12 11 22-3",
                            "123-11 22 333-4"
                        ]
                    }
                }
            ]
        }
    ]
}

扫描器界面值

InfoLeak-Scanner

消息

下载工具