Trixsec
502 subscribers
25 photos
3 videos
10 files
79 links
Creating Own Tools
#Hacktheplanet
Download Telegram
Trixsec pinned «New Waymap Update Soon 🦦🦦»
WAYMAP New Update - v6.2.8 πŸš€πŸš€
- Added Time Based Sqli Scanning Logic
- Added Scan Results Saving Logic
- Added Interactive Prompt Based and Argument Based Scanning Logic
- Updated The UI

Try Out

https://github.com/TrixSec/waymap
WAYMAP New Update - v6.2.9 πŸš€πŸš€

- Bug Fixed
- Optimised
- Reduced Lag

Try Out

https://github.com/TrixSec/waymap
New Crazy Tool Soon πŸ€™πŸΌπŸ‘…
πŸ†’4
πŸ”₯ New Tool Release: HexaCloner πŸ”₯

Clone any website with advanced options, blazing speed, and a beautiful CLI!

Selective resource cloning
Resume support
Authentication
Progress bar & colored output
Cross-platform
Get it now:
πŸ”— https://github.com/TrixSec/HexaCloner

By Trix Cyrus (@TrixSec)
#opensource #python #webtools
πŸ”₯5❀2
What next dork searcher separately or integrated in waymap?
πŸš€ WAYMAP v7.0.0 - MAJOR RELEASE! πŸš€

πŸŽ‰ The biggest update yet is here!

We're thrilled to announce Waymap v7.0.0 - a complete UI/UX overhaul that makes vulnerability scanning more professional and consistent than ever before!

━━━━━━━━━━━━━━━━━━━━━━━━━━

✨ WHAT'S NEW

🎨 Complete UI Standardization
β€’ All 15 scan modules now have consistent formatting
β€’ Professional cyan headers across all scans
β€’ Standardized icons and color scheme:
[β€’] Cyan - Information
[βœ“] Green - Vulnerabilities
[⚠️] Yellow - Warnings
[βœ—] Red - Errors
[βš™οΈ] Blue - Debug output

πŸ› Critical Bug Fixes
β€’ Fixed JSON structure crashes
β€’ Resolved circular import issues
β€’ Fixed result saving across all modules
β€’ Enhanced threading consistency
β€’ Graceful exit handling everywhere

πŸ”§ Enhanced Features
β€’ Verbose mode for detailed debugging
β€’ Consistent user prompts
β€’ Proper completion messages
β€’ Better error handling
β€’ Improved threading performance

━━━━━━━━━━━━━━━━━━━━━━━━━━

πŸ“¦ 15 MODULES STANDARDIZED

βœ… Injection Scans (7)
LFI β€’ CMDi β€’ SSTI β€’ CRLF β€’ CORS β€’ Open Redirect β€’ XSS

βœ… SQL Injection (3)
Boolean-based β€’ Error-based β€’ Time-based

βœ… Profile Scans (3)
High-Risk β€’ Critical-Risk β€’ Deep Scan

━━━━━━━━━━━━━━━━━━━━━━━━━━

⚑️ INSTALL NOW

pip install waymap==7.0.0


Or upgrade:
pip install --upgrade waymap


━━━━━━━━━━━━━━━━━━━━━━━━━━

πŸ”— LINKS

πŸ“¦ PyPI: https://pypi.org/project/waymap/7.0.0/
πŸ™ GitHub: https://github.com/TrixSec/waymap
πŸ“š Docs: https://github.com/TrixSec/waymap/blob/main/README.md

━━━━━━━━━━━━━━━━━━━━━━━━━━

πŸ’‘ QUICK START

# Basic scan
waymap --target https://example.com --scan xss

# Profile scan
waymap --target https://example.com --profile high-risk

# Verbose mode
waymap --target https://example.com --scan sqli --verbose


━━━━━━━━━━━━━━━━━━━━━━━━━━

🎯 WHY UPGRADE?

Before v7.0.0:
❌ Inconsistent output formatting
❌ Different colors for different scans
❌ Varying prompt styles
❌ Result saving bugs

After v7.0.0:
βœ… 100% Consistent UI/UX
βœ… Professional output
βœ… Reliable performance
βœ… Production ready

━━━━━━━━━━━━━━━━━━━━━━━━━━

🌟 75+ WEB VULNERABILITIES

Waymap can scan for over 75 different web vulnerabilities including:
β€’ SQL Injection (All types)
β€’ XSS (Cross-Site Scripting)
β€’ Command Injection
β€’ SSTI (Template Injection)
β€’ LFI (File Inclusion)
β€’ CORS Misconfigurations
β€’ CRLF Injection
β€’ Open Redirects
β€’ CMS-specific CVEs
β€’ And much more!

━━━━━━━━━━━━━━━━━━━━━━━━━━

πŸ”₯ FEATURES

βœ… Multi-threaded scanning
βœ… Profile-based scans (High-Risk, Critical, Deep)
βœ… WAF/IPS detection (160+ types)
βœ… Automated crawling
βœ… Result saving in JSON
βœ… No-prompt mode for automation
βœ… Verbose debugging mode
βœ… CMS detection (WordPress, Drupal)

━━━━━━━━━━━━━━━━━━━━━━━━━━

πŸ‘¨β€πŸ’» DEVELOPED BY
Trix Cyrus (Vicky)
Β© 2024-25 Trixsec Org

━━━━━━━━━━━━━━━━━━━━━━━━━━

⭐️ SUPPORT THE PROJECT

Star us on GitHub: https://github.com/TrixSec/waymap
Report issues: https://github.com/TrixSec/waymap/issues

━━━━━━━━━━━━━━━━━━━━━━━━━━

🎊 This is our most polished release yet!

Every scan module has been carefully standardized to provide you with a professional, consistent experience. Whether you're a penetration tester, security researcher, or ethical hacker - Waymap v7.0.0 is ready for production use!

Install now and experience the difference!

pip install waymap==7.0.0


#Waymap #WebSecurity #VulnerabilityScanner #PenTesting #EthicalHacking #CyberSecurity #InfoSec #BugBounty #SecurityTools #TrixSec

━━━━━━━━━━━━━━━━━━━━━━━━━━

πŸ’¬ Join our community:
πŸ“± Telegram: @Trixsec
πŸ™ GitHub: TrixSec/waymap

Happy Hacking! 🎯
πŸ‘1πŸ”₯1
Trixsec pinned Β«πŸš€ WAYMAP v7.0.0 - MAJOR RELEASE! πŸš€ πŸŽ‰ The biggest update yet is here! We're thrilled to announce Waymap v7.0.0 - a complete UI/UX overhaul that makes vulnerability scanning more professional and consistent than ever before! ━━━━━━━━━━━━━━━━━━━━━━━━━━ βœ¨β€¦Β»
v7.1.0 - API Security, Auth & Reporting πŸš€

Release Date: December 2024

Fast, Optimized, and Comprehensive Web Vulnerability Scanner

Waymap v7.1.0 introduces powerful new capabilities for API security testing, advanced authentication, and professional reporting.

🌟 What's New?

πŸ”Œ API Security Testing
REST API Scanning: Test endpoints for missing auth, IDOR, and rate limiting.

GraphQL Support: Detect introspection, query depth issues, and schema exposure.

Method Testing: Automated testing of GET, POST, PUT, DELETE, PATCH methods.

πŸ” Advanced Authentication
Multi-Protocol Support: Form-based, HTTP Basic, Digest, Bearer Token, and API Key.

Session Management: Maintain authenticated sessions across scans.

Custom Headers: Inject custom authentication headers.

πŸ“Š Professional Reporting
HTML Reports: Interactive dashboards with charts and detailed findings.
CSV Exports: Spreadsheet-compatible data for analysis.
Markdown: Documentation-ready reports.
PDF Reports: Professional PDF summaries.
❀1
Search for Vulnerability πŸ“‘

SearchSploit

sudo apt-get install exploitdb
searchsploit xxx | grep linux


Dorks

site:exploit-db.com APP VERSION
site:rapid7.com "set TARGET" Sendmail
site:rapid7.com "use auxiliary" MSSQL
search type:exploit port:139
search samba type:exploit port:445


Vulnerable Scan 🎯

WhatWeb

whatweb <ip>


Golismero

golismero SCAN <ip>


Nikto

nikto -h <ip> -p 1234 <ip>
nikto -C all -h <ip> -p 80
nikto -C all -h <ip> -p 443


Nmap

nmap -v -sS -sV --script=vulscan.nse --script-args vulscandb=exploitdb.csv <ip>

nmap -sS -sV --script=vulscan.nse --script-args vulscandb=exploitdb.csv -p80 <ip>

nmap -sV --script=vuln <ip>

nmap -PN -sS -sV --script=all --script-args vulscancorrelation=1 <ip>


HTTP Enumerating 🌐

β˜‘οΈBrute-force , check http , https website ,enumerate one by one
β˜‘οΈDefault login for service or application , check reset password
β˜‘οΈCheck Default credentials for software
β˜‘οΈSQL-injectable GET/POST params
β˜‘οΈLFI/RFI through ?page=foo type params /etc/passwd , ../../../../../boot.ini
β˜‘οΈ Check config.php and get sql login
β˜‘οΈ Heartbleed / CRIME find out potential correct vhost to GET , any names that could be usernames for bruteforce/guessing

Xprobe2 OS fingerprinting πŸ‘£

xprobe2 -v -p tcp:80:open <ip>
❀1
Trixsec pinned Β«v7.1.0 - API Security, Auth & Reporting πŸš€ Release Date: December 2024 Fast, Optimized, and Comprehensive Web Vulnerability Scanner Waymap v7.1.0 introduces powerful new capabilities for API security testing, advanced authentication, and professional reporting.…»
πŸ”’ Waymap v7.2.1 Released
This release focuses on stability, reliability, and security hardening.
Highlights
β€’ Thread-safe result saving with the new ResultManager
β€’ Secure XML parsing using defusedxml (XXE protection)
β€’ Improved time-based SQLi baseline to reduce false positives
β€’ Fixed boolean and error-based SQLi detection
β€’ Improved CRLF detection (headers + body)
β€’ Open Redirect now works on Windows (no curl required)
β€’ Fixed CMDi query-string handling
β€’ Report loading fixed across all output formats
β€’ Fixed WAF module imports and project path resolution
β€’ Improved Windows Unicode support
All 12+ scanner modules have been updated to use the centralized ResultManager for safer, more reliable scanning.
Install
pip install waymap==7.2.1

πŸ“¦ PyPI: https://pypi.org/project/waymap/7.2.1/
πŸ’» GitHub: https://github.com/TrixSec/waymap
If Waymap has been useful to you, consider starring the repository. It helps the project grow.
Trixsec pinned Β«πŸ”’ Waymap v7.2.1 Released This release focuses on stability, reliability, and security hardening. Highlights β€’ Thread-safe result saving with the new ResultManager β€’ Secure XML parsing using defusedxml (XXE protection) β€’ Improved time-based SQLi baseline to…»
πŸš€ Waymap v8.0.0 is now available!

This is the biggest Waymap release so far.
What's new?
β€’ AI-powered vulnerability analysis
β€’ AI adaptive payload generation
β€’ AI attack surface discovery
β€’ AI false positive reduction
β€’ AI vulnerability chain analysis
β€’ Union, Inline and Stacked SQLi techniques
β€’ Database enumeration
β€’ Event-driven architecture
β€’ Improved crawler
β€’ Better reconnaissance engine
β€’ Fingerprint engine for request deduplication
β€’ Enhanced HTTP performance and reliability
Waymap continues to use deterministic detection while AI assists with reasoning, prioritization, and analysis.

GitHub:
https://github.com/TrixSec/waymap
Feedback and bug reports are always appreciated.

Don't forget to STAR
❀1
Trixsec pinned Β«πŸš€ Waymap v8.0.0 is now available! This is the biggest Waymap release so far. What's new? β€’ AI-powered vulnerability analysis β€’ AI adaptive payload generation β€’ AI attack surface discovery β€’ AI false positive reduction β€’ AI vulnerability chain analysis β€’ Union…»