Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Pegasus---Forbidden-Buster — 一个用于绕过HTTP 401/403响应的渗透测试工具,利用多种头部操作技术和路径模糊测试。 | Kitploit
工具/GitHubGitHub/sobri3195/pegasus---forbidden-buster
漏洞扫描器IDS/IPS规避信息收集WAF绕过Web安全渗透测试
GitHubsobri3195/pegasus---forbidden-buster

Pegasus---Forbidden-Buster

一个用于绕过HTTP 401/403响应的渗透测试工具,利用多种头部操作技术和路径模糊测试。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
3161年前尚未审核
分享

Pegasus - 禁忌破解者

作者: Letda Kes dr. Sobri, S.Kom.

一款渗透测试工具,用于通过多种HTTP头操作技术和路径模糊测试绕过HTTP 401/403响应。

功能特性

  • 测试多种头部操作(X-Forwarded-For、X-Original-URL、X-Rewrite-URL等)
  • Unicode路径绕过技术
  • User-Agent模糊测试
  • 实时终端日志记录
  • 速率限制控制
  • 代理支持
  • 成功绕过检测
  • Cookie操作攻击向量
  • 参数污染技术
  • 内容发现能力
  • 多格式报告生成(HTML、JSON、文本)
  • IP轮换以避免基于IP的封锁
  • 支持多线程扫描
  • HTTP基本认证绕过尝试
  • 路径遍历(深度可自定义)

安装

# 克隆仓库
git clone https://github.com/sobri3195/pegasus-forbidden-buster.git
cd pegasus-forbidden-buster

# 安装依赖
pip install -r requirements.txt

使用方法

基本用法:

python pegasus_cli.py -u https://example.com/restricted-area

高级用法:

python pegasus_cli.py -u https://example.com/admin -m POST -H "Authorization: Basic YWRtaW46YWRtaW4=" -d '{"username":"admin"}' -p http://127.0.0.1:8080 --rate-limit 5 --include-all --threads 10 --output report.html --format html

命令行选项

选项描述
-u, --url目标URL(必需)
-m, --method使用的HTTP方法(默认:GET)
-H, --header添加自定义头(格式:"Name: Value")
-d, --data请求体数据(支持JSON字符串)
-p, --proxy使用的代理(格式:http://ip:port)
--rate-limit每秒请求速率限制(默认:10)
--threads并行扫描线程数(默认:5)
--include-unicode启用Unicode路径模糊测试
--include-user-agent启用User-Agent模糊测试
--include-params启用参数污染攻击
--include-cookies启用Cookie操作技术
--include-all启用所有绕过技术
--discover启用内容发现模式
--wordlist内容发现词表文件路径
--extensions逗号分隔的尝试扩展名列表
--output保存结果的输出文件
--format输出格式(json、html、text)
-v, --verbose启用详细输出
-q, --quiet抑制横幅和非必要输出
--timeout请求超时秒数(默认:10)
--user-agent使用的自定义User-Agent
--cookies使用的Cookie(格式:"name1=value1; name2=value2")
--authHTTP基本认证(格式:"username:password")
--depth路径遍历深度(默认:3)

示例

# 基本扫描
python pegasus_cli.py -u https://example.com/admin

# 全量扫描(使用所有技术)
python pegasus_cli.py -u https://example.com/admin --include-all 

# 内容发现扫描
python pegasus_cli.py -u https://example.com/admin --discover --wordlist wordlists/common.txt --extensions php,html,txt

# 生成HTML报告
python pegasus_cli.py -u https://example.com/admin --include-all --output reports/report.html --format html

# 使用自定义头和代理
python pegasus_cli.py -u https://example.com/admin -H "X-Custom-Header: Value" -H "Authorization: Bearer token" -p http://127.0.0.1:8080

项目结构

pegasus-forbidden-buster/
├── pegasus_cli.py          # Main CLI entry point
├── requirements.txt        # Dependencies
├── README.md               # Documentation
├── src/
│   ├── core/               # Core scanner functionality
│   ├── modules/            # Bypass technique modules
│   ├── utils/              # Utility functions
│   └── data/               # Data files and payloads
├── reports/                # Generated reports
└── examples/               # Example configurations

贡献

欢迎贡献!请随时提交Pull Request。

联系方式

  • 作者: Letda Kes dr. Sobri, S.Kom.
  • GitHub: github.com/sobri3195
  • 邮箱: [email protected]

支持本项目

如果您觉得这个工具有用,可以考虑支持开发:

  • 捐赠: https://lynk.id/muhsobrimaulana

免责声明

本工具仅供合法渗透测试和安全研究使用。未经明确许可对任何系统使用本软件是违法的,并非本软件的预期用途。

许可证

本项目采用MIT许可证 - 详情请参阅LICENSE文件。

下载工具