appscan又更新啦
虽然咱也不知道更新了啥
官网说更新了啥玩意儿引擎?
管他的,作为一个工具收藏家
可以不用,但不能没有
官网更新内容网址
https://help.hcltechsw.com/appscan/ASoC/appseccloud_whats_new_cm.html#whats_new_cm__section_ipz_qdb_m5b
安装破解步骤
首先下载压缩包(下载地址文末获取)
解压后双击exe文件安装
安装完成后打开破解文件夹
复制两个DLL文件
放进安装目录文件夹即可
然后我们就可以正常打开奔放啦,哒哒哒哒~
-------------------------------我是分割线-------------------------------
我们在面对大量url的时候
比如从佛学工具搞得?又或者刷src混礼盒?
使用appscan或者awvs之类重型武器
始终不太得劲
比如我用awvs扫九百个目标
想开把LOL,打个大虫子,偶尔还会掉帧
这时,BBscan或许是个好选择
BBScan 是一个高并发、轻量级的信息泄露扫描工具。
它可以在短时间内完成数十万目标的扫描,帮助渗透工程师从大量无标签的主机中,定位到可能存在弱点的目标,进行下一步半自动化测试,或者是开启重量级扫描器。它可以作为一个轻量级插件,集成到自动化扫描系统中。
因为其python插件扫描,跟作者即将释出的工具高度一致。2.0之后的版本,我们将只关注信息泄露扫描
Require python3.6+
pip3 install -r requirements.txt
python BBScan.py -f urls.txt
python BBScan.py --rule git_and_svn -f urls.txt
Targets:
--host [HOST [HOST ...]]
Scan several hosts from command line
-f TargetFile Load new line delimited targets from TargetFile
-d TargetDirectory Load all *.txt files from TargetDirectory
--crawler CrawlDirectory
Load all *.log crawl files from CrawlDirectory
--network MASK Scan all Target/MASK neighbour hosts,
should be an integer between 8 and 31HTTP SCAN:
--rule [RuleFileName [RuleFileName ...]]
Import specified rule files only.
-n, --no-crawl No crawling, sub folders will not be processed
-nn, --no-check404 No HTTP 404 existence check
--full Process all sub directoriesScripts SCAN:
--scripts-only Scan with user scripts only
--script [ScriptName [ScriptName ...]]
Execute specified scripts only
--no-scripts Disable all scriptsCONCURRENT:
-p PROCESS Num of processes running concurrently, 30 by default
-t THREADS Num of scan threads for each scan process, 3 by defaultOTHER:
--proxy Proxy Set HTTP proxy server
--timeout Timeout Max scan minutes for each target, 10 by default
-md Save scan report as markdown format
--save-ports PortsDataFile
Save open ports to PortsDataFile
--debug Show verbose debug info
-nnn, --no-browser Do not open web browser to view report
-v show program's version number and exit
两个工具的下载链接
后台回复:0814
祝各位哒哒哒哒出一堆漏洞