Vuln Scanner With Python

Overview

VulnScanner

Code

Version Language GitHub Repo stars


Features

Web Application Firewall (WAF) detection.

Cross Site Scripting (XSS) tests.

SQL injection time based test.

SQL injection error based test.

Local File Inclusion (LFI) test.

Cross Site Tracing (XST) test.


How To Run

git clone https://github.com/NullS0UL/VulnScanner

cd VulnScanner

python3 vulnscan.py http://example.com/page.php?cat=1

Example of Output

python3 vulnscan.py http://example.com/page.php?cat=1

[*] No WAF Detected.

Target: http://example.com/page.php?cat=1

Powered: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1

[!] Testing Cross Site Scripting (XSS)
[!] 10 Payloads.
[+] 9 Payloads were found.

[*] Payload found!
[!] Payload: <script>alert("inject")</script>
[!] POC: http://example.com/page.php?cat=<script>alert("inject")</script>

[*] Payload found!
[!] Payload: %3Cscript%3Ealert%28%22inject%22%29%3C%2Fscript%3E
[!] POC: http://example.com/page.php?cat=%3Cscript%3Ealert%28%22inject%22%29%3C%2Fscript%3E

[!] Testing SQLInjection
[*] Blind SQL injection time based found!
[!] Payload: 1-SLEEP(2)
[!] POC: http://example.com/page.php?cat=1-SLEEP(2)

[*] SQL Error found.
[!] Payload: '
[!] POC: http://example.com/page.php?cat='

[!] Testing Local File Inclussion (LFI)
[*] Payload found!
[!] Payload: ../../../../etc/passwd
[!] POC: http://example.com/page.php?cat=../../../../etc/passwd


[!] Testing Cross Site Tracing (XST)
[*] This site seems vulnerable to Cross Site Tracing (XST)!


Discaimer

Usage of the VulnScanner for attack targets without prior mutual consent is illegal. 
It is the end user's responsability to obey all applicable local, state, federal and international laws. 
Developer assume no liability and not responsible for any misuse or damage caused by this program.

Find me on

Facebook Telegram

Visit my Blog Site

  • Blogs
  • Owner
    < / N u l l S 0 U L >
    Use your brain , Make GOOGLE your friend 😘
    < / N u l l S 0 U L >
    Wonk is a tool for combining a set of AWS policy files into smaller compiled policy sets.

    Wonk is a tool for combining a set of AWS policy files into smaller compiled policy sets.

    Amino, Inc 140 Dec 16, 2022
    This project is all about building an amazing application that will help users manage their passwords and even generate new passwords for them

    An amazing application that will help us manage our passwords and even generate new passwords for us.

    1 Jan 23, 2022
    This is a multi-password‌ cracking tool that can help you hack facebook accounts very quickly

    Pro_Crack Facebook Fast Cracking Tool This is a multi-password‌ cracking tool that can help you hack facebook accounts very quickly Installation On Te

    •JINN• 1 Jan 16, 2022
    Anti-Nuke capabilities, powerful moderation features, auto punishments, captcha-verification and more.

    Server-Security-Discord-Bot Anti-Nuke capabilities, powerful moderation features, auto punishments, captcha-verification and more. Installation Instal

    20 Apr 07, 2022
    Simple yara rule manager

    Yara Manager A simple program to manage your yara ruleset in a (sqlite) database. Todos Search rules and descriptions Cluster rules in rulesets Enforc

    Nils Kuhnert 65 Nov 17, 2022
    Remote control your Greenbone Vulnerability Manager (GVM)

    Greenbone Vulnerability Management Tools The Greenbone Vulnerability Management Tools gvm-tools are a collection of tools that help with remote contro

    Greenbone 130 Dec 17, 2022
    Hack computer in the form of RAR files from all types of clients, even Linux

    Program Features 📌 Hide malware 📌 Vulnerability software vulnerabilities RAR 📌 Creating malware 📌 Access client files 📌 Client Hacking 📌 Link Do

    hack4lx 5 Nov 25, 2022
    This tool help you to check if your Windows machine has hidden miner.

    Hidden Miner Detector This tool help you to check if your Windows machine has hidden miner. Miners track when you open antivirus software or task mana

    Николай Борщёв 2 Oct 05, 2022
    CVE-2021-43936 is a critical vulnerability (CVSS3 10.0) leading to Remote Code Execution (RCE) in WebHMI Firmware.

    CVE-2021-43936 CVE-2021-43936 is a critical vulnerability (CVSS3 10.0) leading to Remote Code Execution (RCE) in WebHMI Firmware. This vulnerability w

    Jeremiasz Pluta 8 Jul 05, 2022
    An easy-to-use wrapper for NTFS-3G on macOS

    ezNTFS ezNTFS is an easy-to-use wrapper for NTFS-3G on macOS. ezNTFS can be used as a menu bar app, or via the CLI in the terminal. Installation To us

    Matthew Go 34 Dec 01, 2022
    CVE-2021-45232-RCE-多线程批量漏洞检测

    CVE-2021-45232-RCE CVE-2021-45232-RCE-多线程批量漏洞检测 FOFA 查询 title="Apache APISIX Das

    孤桜懶契 36 Sep 21, 2022
    Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)

    使用方法&免责声明 该脚本为Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)。 使用方法:Python CVE-2020-17519.py urls.txt urls.txt 中每个url为一行,漏洞地址输出在vul.txt中 影响版本: Apache Flink 1

    45 Sep 21, 2022
    Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1

    CVE-2021-22911 Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1 The getPasswordPolicy method is vulnerable to NoS

    Enox 47 Nov 09, 2022
    Automated tool to exploit basic buffer overflow remotely and locally & x32 and x64

    Automated tool to exploit basic buffer overflow (remotely or locally) & (x32 or x64)

    5 Oct 09, 2022
    对naabu的端口扫描结果,调用nmap进行指纹识别

    naabu2nmap 对naabu的端口扫描结果,调用nmap进行指纹识别

    Se7en 12 Nov 22, 2022
    SQLi Google Dork Scanner (new version)

    XGDork² - ViraX Google Dork Scanner SQLi Google Dork Scanner by ViraX @ 2021 for Python 2.7 - compatible Android(NoRoot) - Termux A simple 'naive' pyt

    8 Dec 20, 2022
    Generate obfuscated meterpreter shells

    Generator Evade AV with obfuscated payloads Installation must install dotnet prior to running the script with net45 Running ./generator.py -ip Your-I

    Fawaz Al-Mutairi 219 Nov 28, 2022
    Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

    GoodHound ______ ____ __ __ / ____/___ ____ ____/ / / / /___ __ ______ ____/ / / / __/ __ \/ __ \/ __

    idna 352 Jan 02, 2023
    BF-Hash - A Python Tool to decrypt hashes by brute force

    BF-Hash Herramienta para descifrar hashes por fuerza bruta Instalación git clone

    5 Apr 09, 2022
    The ultimate Metasploit apk binder with legit apk written in python3

    Infector is a python3 based script which is officially made for linux based distro . It binds metasploit payload with original apk with avast antivirus bypassed .

    27 Dec 25, 2022