openRedScan 是一个基于 python 的工具,可以测试每个 URL 并检查开放重定向漏洞。
主要特点
基于标头的重定向
基于 Javascript 的重定向
基于元标记的重定向
安装
git clone https://github.com/thenurhabib/openredscan.git
cd openredscan
bash setup.sh
python3 openredscan.py -h
用法
┌──(habib㉿kali)-[~/Desktop/OpenRedScan]
└─$ python3 openredacan.py -h
__ __ ___ __ ___ __ __ __
/ \ |__) |__ |\ | |__) |__ | \ /__` / ` /\ |\ |
\__/ | |___ | \| | \ |___ |__/ .__/ \__, /~~\ | \|
Multifunctional Open Redirection Vulnerability Scanner
~ by @thenurhabib
usage: Help Menu
optional arguments:
-h, --help show this help message and exit
-u URL Domain Name.
-l PATH Multiple targets. (Ex: domains.txt)
-crlf Scan CRLF Injection.
-p PAYLOAD Use payloads file.
--proxy use proxy
--wayback fetch URLs from waybackmachine
作者
Name : Md. Nur habib
Medium : thenurhabib.medium.com
Twitter : https://twitter.com/thenurhab1b
HackerRank : https://www.hackerrank.com/thenurhabib
项目地址:https://github.com/thenurhabib/openredscan