Giter VIP home page Giter VIP logo

d3ckx1 / fvuln Goto Github PK

View Code? Open in Web Editor NEW
1.1K 1.1K 142.0 20.84 MB

F-vuln(全称:Find-Vulnerability)是为了自己工作方便专门编写的一款自动化工具,主要适用于日常安全服务、渗透测试人员和RedTeam红队人员,它集合的功能包括:存活IP探测、开放端口探测、web服务探测、web漏洞扫描、smb爆破、ssh爆破、ftp爆破、mssql爆破等其他数据库爆破工作以及大量web漏洞检测模块。

fvuln's Introduction

fvuln's People

Contributors

d3ckx1 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

fvuln's Issues

请问师傅这是什么意思?

我是py3.7.6。命令是 .\Fvuln_v1.2.exe -f .\ip.txt,ip.txt 里面就是ip 10.x.x.x 这样的,一行一个。
请问师傅这是什么情况?
image

误报率太高!!!

有一些网站的重定向也误认为有漏洞 ,去验证根本没有,重定向误报,情况太严重,随便找几个网站都能误报很多个

是否可以添加-y选项

多IP扫描时,爆破SSH、redis等之前需要手动输入y或n来确认,是否可以添加-y选项来自动确认

建议添加多线程

建议添加多线程,100个目标,扫了1天都没扫完,效率太低

1核2G服务器扫描过程中的各种占用情况很低

图片

cmd

cmd中使用有乱码现象

无人值守命令

批量执行:Fvuln.exe -f ip.txt
遇到SSH、FTP等,总是询问我是否要爆破,没有无人值守命令?如SQLMAP的--batch

【Fvuln问题】误报|误判|输出结果

1.PoC判断对状态码302响应的判断存在漏洞,相信这个肯定是有问题。
2.输出的结果是以txt文本格式,如果输出的结果是Excel会让结果方便分析。
3.Python对结果分析输出报告的能力,并生成Word报告,让执行漏洞脆弱性扫描的人阅读整体的风险态势,呈现给一个技术+文档的自动化报告。

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.