All Projects → YagamiiLight → Cerberus

YagamiiLight / Cerberus

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能

Programming Languages

python
139335 projects - #7 most used programming language

Projects that are alternatives of or similar to Cerberus

Recsech
Recsech is a tool for doing Footprinting and Reconnaissance on the target web. Recsech collects information such as DNS Information, Sub Domains, HoneySpot Detected, Subdomain takeovers, Reconnaissance On Github and much more you can see in Features in tools .
Stars: ✭ 173 (-55.53%)
Mutual labels:  security-tools, penetration-testing, hacking-tool, websecurity
Nosqlmap
Automated NoSQL database enumeration and web application exploitation tool.
Stars: ✭ 1,928 (+395.63%)
Mutual labels:  security-tools, penetration-testing, hacking-tool, sql-injection
Arachni
Web Application Security Scanner Framework
Stars: ✭ 2,942 (+656.3%)
Mutual labels:  penetration-testing, xss, sql-injection
Reconnoitre
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
Stars: ✭ 1,824 (+368.89%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Cheatsheet God
Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
Stars: ✭ 3,521 (+805.14%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Osmedeus
Fully automated offensive security framework for reconnaissance and vulnerability scanning
Stars: ✭ 3,391 (+771.72%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Cloudbunny
CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to search domain information: Shodan, Censys and Zoomeye.
Stars: ✭ 273 (-29.82%)
Mutual labels:  proxy, waf, bypass
vulnerabilities
List of every possible vulnerabilities in computer security.
Stars: ✭ 14 (-96.4%)
Mutual labels:  xss, penetration-testing, sql-injection
Evillimiter
Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access.
Stars: ✭ 764 (+96.4%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Awesome Bbht
A bash script that will automatically install a list of bug hunting tools that I find interesting for recon, exploitation, etc. (minus burp) For Ubuntu/Debain.
Stars: ✭ 190 (-51.16%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Crithit
Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
Stars: ✭ 182 (-53.21%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Katana
A Python Tool For google Hacking
Stars: ✭ 355 (-8.74%)
Mutual labels:  proxy, security-tools, hacking-tool
Jwtxploiter
A tool to test security of json web token
Stars: ✭ 130 (-66.58%)
Mutual labels:  security-tools, penetration-testing, websecurity
Horn3t
Powerful Visual Subdomain Enumeration at the Click of a Mouse
Stars: ✭ 120 (-69.15%)
Mutual labels:  security-tools, penetration-testing, websecurity
Scilla
🏴‍☠️ Information Gathering tool 🏴‍☠️ DNS / Subdomains / Ports / Directories enumeration
Stars: ✭ 116 (-70.18%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Minesweeper
A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).
Stars: ✭ 162 (-58.35%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Interlace
Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.
Stars: ✭ 760 (+95.37%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Vhostscan
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
Stars: ✭ 767 (+97.17%)
Mutual labels:  security-tools, penetration-testing, hacking-tool
Broxy
An HTTP/HTTPS intercept proxy written in Go.
Stars: ✭ 912 (+134.45%)
Mutual labels:  proxy, penetration-testing, websecurity
Cameradar
Cameradar hacks its way into RTSP videosurveillance cameras
Stars: ✭ 2,775 (+613.37%)
Mutual labels:  security-tools, penetration-testing, hacking-tool

Cerberus

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能

asciicast

主要功能

  • 😈单url漏洞扫描

    支持SQL注入, XSS, 命令执行,文件包含, ssrf

    进行单站点漏洞扫描

    python3 cerberus.py -target www.qq.com

    asciicast

  • 🌸 线程设置

    多线程,默认7线程

    python3 cerberus.py -target www.qq.com -thread 7

  • 👿子域名异步批量扫描

    使用aioDNS,asyncio异步,子域名爆破后,加入扫描队列,覆盖目标全方位资产进行批量漏洞扫描

    python3 cerberus.py -target www.qq.com -subdomain

    asciicast

  • 💀 代理IP收集

    爬取了9个站点的实时免费代理IP,但IP存活率较低,大概在20%左右,检测IP是否存活的过程中可能会阻塞扫描过程。

    python3 cerberus.py -target www.qq.com -proxy

    asciicast

  • 👹Waf信息收集

    国内外100+款waf信息,强大的指纹库,包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案

    请务必提供带有参数的URL进行WAF测试!

    python3 cerberus.py -target https://open.weixin.qq.com/frame?t=home/web_tmpl&lang=zh_CN -waf

  • 🙈中间件信息收集

    信息收集完毕后,根据获取结果,自动进行中间件漏洞扫描

    • WAF

    • CDN

    • CMS

    • Web Servers

    • Web Frameworks

    • Operating Systems

    python3 cerberus.py -target -detectMid

    asciicast

  • 🐼 指定中间件漏洞扫描

    如果已知目标部分中间件信息,可以指定类型,直接进行扫描

    • Thinkphp CVE-2018-5955

    • Phpmyadmain CVE-2018-12613

    • Dedecms

    • Tomcat CVE-2018-11759

    • Weblogic

    • Wordpress

    python3 cerberus.py -target www.qq.com -midlleware weblogic

  • 输入文件批量扫描

    • 文件路径需为绝对路径

    • 需为txt文本格式,确保每一行只有一个域名

    python3 cerberus.py -file absolute path

  • 🍪 设置Cookie

    python3 cerberus.py -cookie cookie

  • 🙊 输出漏洞扫描报告

    python3 cerberus.py -outfile

🐰 Praise me!

  • 😽 如果您认为本项目对您有一定帮助,为了更好的开源安全工具!请赞赏我!感谢您的赞赏!

praise

声明

本项目仅供学习交流,使用本工具所造成的任何违法后果,与本人无关!!

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].