Pathprober - Probe And Discover HTTP Pathname Using Brute-Force Methodology And Filtered By Specific Word Or 2 Words At Once
http://www.kitploit.com/2021/07/pathprober-probe-and-discover-http.html
http://www.kitploit.com/2021/07/pathprober-probe-and-discover-http.html
Probe and discover (https://www.kitploit.com/search/label/Discover) HTTP pathname using brute-force (https://www.kitploit.com/search/label/Brute-force) methodology and filtered by specific word or 2 words at once.
Purpose
Brute-forcing website (https://www.kitploit.com/search/label/Website) directories or HTTP pathname and validate using HTTP response code is not relevant anymore. This tool will help you to perform a penetration test, because it could validate the directories using specific-word or 2 words at once and the results will more accurate.
It will help you to find:
Web administrator/login panel Credential in some paths Third-party token Etc
Installation
git clone https://github.com/xchopath/pathprober
cd pathprober/
Requirements
pip3 install -r requirements.txt
Support
Multiple URL targets (in a file separated by newline) or single URL target Multiple paths (in a file separated by newline) or single path 1 word or 2 words (filter) Save valid results to another file Multi-threading
Sample usage
Multiple target, multiple path, and multiple words: python3 pathprober.py -T target.txt -P path.txt -w "APP_NAME" -w2 "DB_PASSWORD"
Single target, multiple path, and single word: python3 pathprober.py -t https://redacted.com/ -P path.txt -w "APP_NAME"
Multiple target, single path, multiple words, and save output to file: python3 pathprober.py -T target.txt -p /.env -w "APP_NAME" -w2 "TWILIO" -o output.txt
Need more help?
bash:~/pathprober$ python3 pathprober.py --help
___ ____ ___ _ _ ___ ____ ____ ___ ____ ____
|__] |__| | |__| |__] |__/ | | |__] |___ |__/
| | | | | | | | \ |__| |__] |___ | \
Probe HTTP pathname filtered by words
usage: pathprober.py [-h] [-t https://example.com] [-p pathname] [-T target.txt] [-P path.txt] [-w Word] [-w2 Word] [-o output.txt]
PathProber - Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once
optional arguments:
-h, --help show this help message and exit
-t https://example.com
Single website target
-p pathname Single pathname
-T target.txt Multiple target separated by newline
-P path.txt Multiple pathname separated by newline
-w Word A word that you want to find in a path
-w2 Word A secon d word that you want to find in a path
-o output.txt Save the results to file
Contributors
@xchopath (https://github.com/xchopath) (from @zerobyte-id (https://github.com/zerobyte-id))
Download Pathprober (https://github.com/xchopath/pathprober)
Purpose
Brute-forcing website (https://www.kitploit.com/search/label/Website) directories or HTTP pathname and validate using HTTP response code is not relevant anymore. This tool will help you to perform a penetration test, because it could validate the directories using specific-word or 2 words at once and the results will more accurate.
It will help you to find:
Web administrator/login panel Credential in some paths Third-party token Etc
Installation
git clone https://github.com/xchopath/pathprober
cd pathprober/
Requirements
pip3 install -r requirements.txt
Support
Multiple URL targets (in a file separated by newline) or single URL target Multiple paths (in a file separated by newline) or single path 1 word or 2 words (filter) Save valid results to another file Multi-threading
Sample usage
Multiple target, multiple path, and multiple words: python3 pathprober.py -T target.txt -P path.txt -w "APP_NAME" -w2 "DB_PASSWORD"
Single target, multiple path, and single word: python3 pathprober.py -t https://redacted.com/ -P path.txt -w "APP_NAME"
Multiple target, single path, multiple words, and save output to file: python3 pathprober.py -T target.txt -p /.env -w "APP_NAME" -w2 "TWILIO" -o output.txt
Need more help?
bash:~/pathprober$ python3 pathprober.py --help
___ ____ ___ _ _ ___ ____ ____ ___ ____ ____
|__] |__| | |__| |__] |__/ | | |__] |___ |__/
| | | | | | | | \ |__| |__] |___ | \
Probe HTTP pathname filtered by words
usage: pathprober.py [-h] [-t https://example.com] [-p pathname] [-T target.txt] [-P path.txt] [-w Word] [-w2 Word] [-o output.txt]
PathProber - Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once
optional arguments:
-h, --help show this help message and exit
-t https://example.com
Single website target
-p pathname Single pathname
-T target.txt Multiple target separated by newline
-P path.txt Multiple pathname separated by newline
-w Word A word that you want to find in a path
-w2 Word A secon d word that you want to find in a path
-o output.txt Save the results to file
Contributors
@xchopath (https://github.com/xchopath) (from @zerobyte-id (https://github.com/zerobyte-id))
Download Pathprober (https://github.com/xchopath/pathprober)
Deep Web
Onion Websites
hello, is there a hacking way for onion websites? You can help with documents and links.
submitted by /u/0__Parzival__0
[link] [comments]
Onion Websites
hello, is there a hacking way for onion websites? You can help with documents and links.
submitted by /u/0__Parzival__0
[link] [comments]
reddit
Onion Websites
hello, is there a hacking way for onion websites? You can help with documents and links.
Not valid bug that leads to us a multiple Valid Report in Facebook
I’m here again to share my 2nd and 3rd valid report. It’s all about page admin disclosure in Facebook Lite. In my Initial report, Facebook…Continue reading on Medium »
Read more...
I’m here again to share my 2nd and 3rd valid report. It’s all about page admin disclosure in Facebook Lite. In my Initial report, Facebook…Continue reading on Medium »
Read more...
DNS, Subdomains & a tale of Takeovers
https://mrigendrasoni.medium.com/dns-subdomains-a-tale-of-takeovers-99b50297abac?source=rss------bug_bounty-5
https://mrigendrasoni.medium.com/dns-subdomains-a-tale-of-takeovers-99b50297abac?source=rss------bug_bounty-5
In working my way towards learning the various, different bug types and their complexities, I gained a better understanding of how the…Continue reading on Medium » (https://mrigendrasoni.medium.com/dns-subdomains-a-tale-of-takeovers-99b50297abac?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DNS, Subdomains & a tale of Takeovers
https://cdn-images-1.medium.com/max/852/1*GW4OSqANN5zzpeonqUFgKA.png
In working my way towards learning the various, different bug types and their complexities, I gained a better understanding of how the…
Continue reading on Medium »
DNS, Subdomains & a tale of Takeovers
https://cdn-images-1.medium.com/max/852/1*GW4OSqANN5zzpeonqUFgKA.png
In working my way towards learning the various, different bug types and their complexities, I gained a better understanding of how the…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Thorchain why was it hacked? Review.
https://cdn-images-1.medium.com/max/600/0*1ihSgfqm4rKPUUrU
Hey guys. For 2 weeks, we were visited by several sad things about Thorchain, the first hack occurred last week, which allowed hackers to…
Continue reading on Medium »
Thorchain why was it hacked? Review.
https://cdn-images-1.medium.com/max/600/0*1ihSgfqm4rKPUUrU
Hey guys. For 2 weeks, we were visited by several sad things about Thorchain, the first hack occurred last week, which allowed hackers to…
Continue reading on Medium »
hacking: security in practice
How do exploits even happen?
Newbie here, I'm just asking how the fuck exploits even happen, internet requests in most formats are just bytes to be read as data formats, JSON, Bytes for a file, just text; How the hell are exploits still ran into? It seems most of them like SQL Injection are only things due to old software, But hasnt the software been updated since then? How are these mistakes still ran into?
Any explanation would be helpful.
submitted by /u/Oracuda
[link] [comments]
How do exploits even happen?
Newbie here, I'm just asking how the fuck exploits even happen, internet requests in most formats are just bytes to be read as data formats, JSON, Bytes for a file, just text; How the hell are exploits still ran into? It seems most of them like SQL Injection are only things due to old software, But hasnt the software been updated since then? How are these mistakes still ran into?
Any explanation would be helpful.
submitted by /u/Oracuda
[link] [comments]
reddit
How do exploits even happen?
Newbie here, I'm just asking how the fuck exploits even happen, internet requests in most formats are just bytes to be read as data formats, JSON,...
DNS, Subdomains & a tale of Takeovers
In working my way towards learning the various, different bug types and their complexities, I gained a better understanding of how the…Continue reading on Medium »
Read more...
In working my way towards learning the various, different bug types and their complexities, I gained a better understanding of how the…Continue reading on Medium »
Read more...
GraphQL Top 10: Attempt #1
My goal is to create GraphQL Top 10, and I was able to come up with 7 concrete issues and some generic ones, but excluding generic issues…Continue reading on Medium »
Read more...
My goal is to create GraphQL Top 10, and I was able to come up with 7 concrete issues and some generic ones, but excluding generic issues…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Metasploit for Pentester: Database & Workspace
In this series of articles, we are focusing on the various mechanisms of the Metasploit Framework that can be used by Penetration Testers. Today we are going to learn about the workspace and database commands of the Metasploit Framework. Table of Content Introduction Creating a Workspace Hosts Database Vulnerabilities Database
The post Metasploit for Pentester: Database & Workspace appeared first on Hacking Articles.
Metasploit for Pentester: Database & Workspace
In this series of articles, we are focusing on the various mechanisms of the Metasploit Framework that can be used by Penetration Testers. Today we are going to learn about the workspace and database commands of the Metasploit Framework. Table of Content Introduction Creating a Workspace Hosts Database Vulnerabilities Database
The post Metasploit for Pentester: Database & Workspace appeared first on Hacking Articles.
GraphQL Top 10: Attempt #1
https://securitygoat.medium.com/graphql-top-10-attempt-1-5bf41fd22d75?source=rss------bug_bounty-5
https://securitygoat.medium.com/graphql-top-10-attempt-1-5bf41fd22d75?source=rss------bug_bounty-5