名称 | 简介 | 添加时间 | ||||||||||
|
||||||||||||
|
||||||||||||
详情 | ||||||||||||
作者:闲云野鸡 发表于[2017-07-05] [2022-02-21]被用户:ecawen 修改过
本文共 [595] 位读者顶过
很多网站都会禁止或有限防止扫描目录,这样的网站配置是相对较安全的,因为WEB攻击时代,目录扫描重中之重,但是,您的网站安全吗?[出自:jiwo.org] cwebpath 6.3 ---------------------------------------------------------------------------------| Help: this tool can test if dir or file exist on dst. made by ecawen.jiwo.org. | --------------------------------------------------------------------------------- Usage: cwebpath.sh -u url -d dic [-m mode] [-p pre] [-S https] [-s sleep] [-t type] [-e ext] [-i uri[-n]] [-k str] [-f range] [-j str[-r]] [-x] -D -u url target url. -d dic dictionary file. -m mode dic mode. 0:no change; 1:upper first character; 2:upper all. default:0 -p prefix prefix on the dictionary file every line when try. -S no arg, https mode -s second sleep time scan loop. default:1s -t type scan type. 1:dir; 2:file; 3:dir+file; 4:params or special. default:3 if -t=4, url like this: "http://jiwo.org/index.php?mod={dic}admin&user=ecawen" -e ext file extension. default:.php -A str additional bin(wget) args, eg: -A --header="Cookie:PHPSESSID=jjlsrs9aodphehq5mnt3kiblh3;" -i uri can visit uri. this option can de-defense detect '404' num -n num with -i, distanse try num. default 2 -k filter filter serfile. str is not exist str! -f filter filter fake serfile size. eg. 50-200 -j filter2 exact judge head. then ignore other judge internal, often use scan tomcat dir '/' can auto add in url if dir exist on tomcat -r filter2 negative, no arg. -x seconds pppoe redial when work be locked. 0:no redial; other:redial and work after seconds input 300s is good. default:0. pppoe should debian/ubuntu who use pon/poff for pppoe -y num 0:no use proxy; 1: use local proxychains. default:0. priority low than -x proxychains can use tor or not. if use tor should use with -z -z torarg with -y, tor control ip:port:passwd(eg:192.168.0.2:9051:passwd). need write torproxyip to proxychains. -D level debug mode, 0-9, default 0 eg. cwebpath -u www.jiwo.org/web -d dir.txt -s 1 -t 3 -e .php --------------------------------------------------------------------------------------------------------------- |