Giter Site home page Giter Site logo

we5ter / scanners-box Goto Github PK

View Code? Open in Web Editor NEW
8.2K 405.0 2.4K 7.2 MB

A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

pentesting-tools hacker-tools vulnerability-scanners information-security redteam-tools penetration-testing devsecops security-automation smart-contracts privacy-compliance

scanners-box's Issues

Photon

Photon is an incredibly fast web crawler which extracts URLs, website accounts, emails, aws buckets, files and more.

https://github.com/s0md3v/Photon

One more thing, please change all the occurrences of UltimateHackers to s0md3v as I changed my username recently.

Thanks ^_^

一些小建议

一、可以把扫描器改称为“安全行业从业人员自研开源安全工具合集”,把扫描器放在下面的一个分支里,现在的话局限性有点大,很多不错的工具都无法收录。

二、推出英语版,针对外国安全研究者在github上方便搜索

请求移除项目

这个"webshell检测或木马分析工具" 条目中的项目 https://github.com/ym2011/ScanBackdoor 不是我的,但是发现代码都没写完,是个半成品,不能运行。个人认为不能加入Scanners-Box中,请求移除项目,减轻对寻求相关项目人士的误导。

关于工具18F/domain-scan的说明

从此工具的官方描述、代码注释以及代码来看,此工具非子域名枚举工具,我几个月前就已移除,只是大家在fork之后未及时更新,给大家说声抱歉,最早收集的时候没有仔细看。


Scans domains for data on their HTTPS configuration and assorted other things.

scanners/subdomains.py用于筛选满足条件的子域名:

##
# == subdomains ==
#
# This scanner takes a CSV full of *potential* subdomains (e.g. a list of DNS requests)
# and produces a resulting subdomains.csv of likely "public websites".
#
# Given three input files:
#
# 1. CSV of potential subdomains (the main input CSV)
# 2. CSV of subdomains to be excluded (e.g. from manual review)
# 3. CSV of second-levels with a metadata field in 3rd column (e.g. .gov domain list)
#
# This scanner filters out:
#
# * second-level domains (or www subdomains)
# * subdomains that didn't get the "inspect" scanner run on them
# * subdomains that weren't reachable by HTTP/HTTPS over the public internet
# * subdomains that matched a wildcard DNS record AND whose "canonical" endpoint
#   returned a *non-200* status code. 200 status codes should be manually reviewed.
# * subdomains which appear on the provided exclusion list (input CSV #2)
#
# And includes fields for:
#
# * Subdomain's parent second-level domain's metadata (input CSV #3)
# * Whether the subdomain appears to redirect to another second-level domain
# * Whether the subdomain appears to redirect to another subdomain within the same second-level
# * The HTTP status code returned by the subdomain's "canonical" endpoint (best guess)
# * Whether the subdomain appears to match a wildcard DNS record
#
##

因此我认为将其添加到中间件扫描器为妥!

Remove XSSight

You should remove XSSight from XSS Scanner list because it got upgraded to XSStrike.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.