openRedScan 是一个基于 python 的工具,可以测试每个 URL 并检查开放重定向漏洞。
主要特点
基于标头的重定向
基于 Javascript 的重定向
基于元标记的重定向
安装
git clone https://github.com/thenurhabib/openredscan.gitcd openredscanbash setup.shpython3 openredscan.py -h
用法
┌──(habib㉿kali)-[~/Desktop/OpenRedScan]└─$ python3 openredacan.py -h__ __ ___ __ ___ __ __ __/ \ |__) |__ |\ | |__) |__ | \ /__` / ` /\ |\ |\__/ | |___ | \| | \ |___ |__/ .__/ \__, /~~\ | \|Multifunctional Open Redirection Vulnerability Scanner~ by @thenurhabibusage: Help Menuoptional arguments:-h, --help show this help message and exit-u URL Domain Name.-l PATH Multiple targets. (Ex: domains.txt)-crlf Scan CRLF Injection.-p PAYLOAD Use payloads file.--proxy use proxy--wayback fetch URLs from waybackmachine
作者
Name : Md. Nur habibMedium : thenurhabib.medium.comTwitter : https://twitter.com/thenurhab1bHackerRank : https://www.hackerrank.com/thenurhabib
项目地址:https://github.com/thenurhabib/openredscan