Giter Site home page Giter Site logo

Comments (6)

shelld3v avatar shelld3v commented on August 11, 2024

Also, sorry if bad English 🌝

from smuggler.

amralihassan740 avatar amralihassan740 commented on August 11, 2024

Why there is no answer ?
Did you know shelld3v how to use it?

from smuggler.

shelld3v avatar shelld3v commented on August 11, 2024

I don't know :) But I think I am going to close this thing now since there is no answer. Gonna learn other stuff, hate Request smuggling with this bad response :)

from smuggler.

defparam avatar defparam commented on August 11, 2024

Hey thanks for being patient,

This tool isn't an exploitation tool it is a recon tool. It simply finds problematic HTTP requests that should be looked into further. It doesn't stage or teach how to stage any desync attacks. It provides you with the payload of the HTTP request that is problematic and you are expected to know how to exploit using Turbo Intruder and other tools.

My intention with this project is not to teach the exploitation of desync attacks, it is just to search for them. However if you want to take the payload and use it for exploitation you have to know how to read the payload file using python in the Turbo Intruder script and issue the attack with the request. This information is out of scope for this project so am not covering it here.

from smuggler.

shelld3v avatar shelld3v commented on August 11, 2024

OK, @defparam! Is there no other option except quiet and don't care about this issue? Very well, then I will close this soon.

Thanks for letting me know:)

from smuggler.

defparam avatar defparam commented on August 11, 2024

To be clear, the point of this tool isn’t to actively exploit hosts. It’s to find potential issues and give you the payload which caused it. It’s not this project’s concern that you don’t know what to do with the payloads it produces and it’s not my mission to teach you how to use turbo intruder.

from smuggler.

Related Issues (17)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.