Oh yeah by the way i was thinking of using google cloud shell or even GitHub codespace but they both have a policy for high traffic so basically until i find a vps or recieve my pc I don't think i will be able to a thing but till then i guess idk maybe design posters cuz i ain't studying shii
So basically happy news for devs, I have made a tool easy to use for you guys, where you can use this tool your website after deployment it will scan for basic, advanced and deep search on your website to check if your website is vulnerable to already known CVE's(Common Vulnerability and Exposure) which means after scanning it will tell you if your website is a victim to CVE's and other Vulnerabilities like sql injection, it will check if your website is sanitized. With detailed report you can use to secure your website.
🔥1
I have used my school website( I know this is a massive OPSEC but our document is on paper it won't matter) and so found three vulnerabilities as seen on the screenshots. I will post my tool on github for everyone to access.
The tool is officially done and the repository is live for everyone to access.
Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments.
KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, and deep scans to check for known CVEs, parameter sanitization issues, and flaws like SQL injection.
Instead of just giving you a standard report showing what's broken, it actually outputs a hardening matrix with the exact configuration patches for Nginx, Apache, and Laravel so you can secure your website straight away. It also includes an automated setup script to link the tool globally to your terminal environment.
Quick start:
Go check out the repository, read through the documentation, and drop a star on the project:
https://github.com/PicasoTheDeal/KASCVE
Following up on the spoiler from earlier where I tested it on my school website and found those three vulnerabilities, you can now grab the source code and run it on your own deployments.
KASCVE is designed to be completely straightforward. You throw a website at it post-deployment, and it executes basic, advanced, and deep scans to check for known CVEs, parameter sanitization issues, and flaws like SQL injection.
Instead of just giving you a standard report showing what's broken, it actually outputs a hardening matrix with the exact configuration patches for Nginx, Apache, and Laravel so you can secure your website straight away. It also includes an automated setup script to link the tool globally to your terminal environment.
Quick start:
git clone https://github.com/PicasoTheDeal/KASCVE.git
cd KASCVE && sudo ./install.sh
KASCVE targetdomain.com
Go check out the repository, read through the documentation, and drop a star on the project:
https://github.com/PicasoTheDeal/KASCVE
GitHub
GitHub - PicasoTheDeal/KASCVE: Automated attack surface mapper & CVE evaluator. Packed with multi-tier SecLists directory fuzzing…
Automated attack surface mapper & CVE evaluator. Packed with multi-tier SecLists directory fuzzing, forgotten staging asset identification, and prioritized defensive hardening blueprints fo...