All Projects → SummerSec → BypassSuper

SummerSec / BypassSuper

Licence: other
Bypass 403 or 401 or 404

Programming Languages

python
139335 projects - #7 most used programming language

Projects that are alternatives of or similar to BypassSuper

Hack
🔰渗透测试资源库🔰黑客工具🔰维基解密文件🔰木马免杀🔰信息安全🔰技能树🔰数据库泄露🔰
Stars: ✭ 460 (+467.9%)
Mutual labels:  bypass, burpsuite
Burpsuitehttpsmuggler
A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques
Stars: ✭ 529 (+553.09%)
Mutual labels:  bypass, burpsuite
K8tools
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
Stars: ✭ 4,173 (+5051.85%)
Mutual labels:  scanner, bypass
Prox5
🧮 SOCKS5/4/4a 🌾 validating proxy pool and upstream SOCKS5 server for 🤽 LOLXDsoRANDum connections 🎋
Stars: ✭ 39 (-51.85%)
Mutual labels:  bypass
N-WEB
WEB PENETRATION TESTING TOOL 💥
Stars: ✭ 56 (-30.86%)
Mutual labels:  scanner
sslscanner
SSL Scanner written in Crystal
Stars: ✭ 18 (-77.78%)
Mutual labels:  scanner
rc-scanner
Remote control your police scanner
Stars: ✭ 22 (-72.84%)
Mutual labels:  scanner
ioc-scanner
Search a filesystem for indicators of compromise (IoC).
Stars: ✭ 31 (-61.73%)
Mutual labels:  scanner
burp-piper-custom-scripts
Custom scripts for the PIPER Burp extensions.
Stars: ✭ 85 (+4.94%)
Mutual labels:  burpsuite
memory signature
A small wrapper class providing an unified interface to search for various memory signatures
Stars: ✭ 69 (-14.81%)
Mutual labels:  scanner
magicRecon
MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.
Stars: ✭ 478 (+490.12%)
Mutual labels:  scanner
porteye
Detect alive host and open port .
Stars: ✭ 17 (-79.01%)
Mutual labels:  scanner
flex-bison-indentation
An example of how to correctly parse python-like indentation-scoped files using flex (and bison).
Stars: ✭ 32 (-60.49%)
Mutual labels:  scanner
moneta
Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs
Stars: ✭ 384 (+374.07%)
Mutual labels:  scanner
polscan
Zero-setup SSH-based scanner with extensive visualizations for Debian server inventory, policy compliance and vulnerabilities
Stars: ✭ 57 (-29.63%)
Mutual labels:  scanner
DInvoke shellcodeload CSharp
ShellCodeLoader via DInvoke
Stars: ✭ 41 (-49.38%)
Mutual labels:  bypass
PSMemory
Automation Capable Multi Search 64 Bit Windows Memory Scanner
Stars: ✭ 25 (-69.14%)
Mutual labels:  scanner
nmap-formatter
A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot). Simply put it's nmap converter.
Stars: ✭ 129 (+59.26%)
Mutual labels:  scanner
Jira-Lens
Fast and customizable vulnerability scanner For JIRA written in Python
Stars: ✭ 185 (+128.4%)
Mutual labels:  scanner
sgCheckup
sgCheckup generates nmap output based on scanning your AWS Security Groups for unexpected open ports.
Stars: ✭ 77 (-4.94%)
Mutual labels:  scanner

BypassSuper

一款针对403/401页面进行快速、高效尝试Bypass的扫描工具

BypassSuper BypassSuper Forks Release Stars Follower SecSummers

                ______                            _____
                | ___ \                          /  ___|
                | |_/ /_   _ _ __   __ _ ___ ___ \ `--. _   _ _ __   ___ _ __
                | ___ \ | | | '_ \ / _` / __/ __| `--. \ | | | '_ \ / _ \ '__|
                | |_/ / |_| | |_) | (_| \__ \__ \/\__/ / |_| | |_) |  __/ |
                \____/ \__, | .__/ \__,_|___/___/\____/ \__,_| .__/ \___|_|
                        __/ | |                              | |
                       |___/|_|                              |_|
                    author: summersec
                    version: 1.0
                    Github: https://github.com/SummerSec/BypassSuper

👮🏻‍♀️ 免责声明

   由于传播、利用BypassSuper工具(下简称本工具)提供的检测功能而造成的任何直接或者间接的后果及损失,均由使用者本人负责,开发者本人不为此承担任何责任

   本工具会根据使用者检测结果自动生成扫描结果报告,本报告内容及其他衍生内容均不能代表本人的立场及观点。

   请在使用本工具时遵循使用者以及目标系统所在国当地的相关法律法规,一切未授权测试均是不被允许的。若出现相关违法行为,我们将保留追究您法律责任的权利,并全力配合相关机构展开调查。

🐉来龙去脉

   在某群里看到大佬发了个这个项目BurpSuite_403Bypasser,然后看了一眼这个具体实现功能。因为在此之前在推特上看到国际友人发过类似的tips,当时就挺感兴趣的。但找了一圈并没有发现有什么现成的扫描器或者burp插件,当时是不了了之。这个项目发现之后,我第一时间就去看了一眼源代码,输出日志,发生很多payload和内容开发者是理解错的,或者是姿势不对。当然我发现之后,我开始动手在此源码上开始我的修改之路。截至本文发布时间为止,也有人发现这个问题,详情参考:sting8k/BurpSuite_403Bypasser#4


Installation

BypassSuper-Burp

   BurpSuite -> Extender -> Extensions -> Add -> Extension Type: Python -> Select file: BypassSuper-Burp.py -> Next till Fininsh


BypassSuper

   pip3 install -r requirements.txt --> python3 BypassSuper.py -h


👏 参数介绍

   您可以使用python3 BypassSuper.py [options]命令来运行本工具,options内容表述如下:

  • -h(--help)

    帮助命令,无需附加参数,查看本工具支持的全部参数及其对应简介;

  • -u (--url) 要扫描的网站网址路径,为必填选项之一,例如:-u https://www.baidu.com

  • -f (--file) 要扫描的网站网址路径文件,为必填选项之一,例如:-f target.txt

  • -t (--threads) 扫描线程数量,为选填选项,配合-f参数使用,要求必须target数量大于线程数量(默认20)不然无法执行,例如:-f target.txt -t 20


🎬Screenshot

在这里插入图片描述

   安装完成后自动扫描,在两个地方可以查看到扫描结果。第一个:在target里面,设置过滤器全部显示或者显示4xx。 在这里插入图片描述

两个

   第二个地方在仪表盘 在这里插入图片描述    在插件拓展里面可以的UI可以查看扫描过程(建议直接输出到文件方便查看,UI里面只能查看部分,会被覆盖)。 在这里插入图片描述 在这里插入图片描述


🎬实际案例

   靶场案例URL-based access control can be circumvented,这个是portswigger官方给的实际案例。悄咪咪说一句,上面给的截屏是一个真实SRC案例! 实用burp插件效果 在这里插入图片描述

使用BypassSuper脚本效果 在这里插入图片描述


📝 TODO

  • 添加参数Bypass规则
  • 重构代码,目前所有源码都在一个文件中,太杂了
  • 自动扫描网页中的api接口实现BypassSuper中的“JSFinder”
  • 目录爆破,配合JSFinder
  • 自动爬取网页实现爬虫功能发现更多页面和接口

📝 意见交流


   您可以直接在GIthub仓库中提交ISSUE:https://github.com/SummerSec/BypassSuper亦或者发送邮件到summersec[@]qq.com

♨️已知问题


📖 References


Stargazers over time

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].