Bashter: Web Crawler, Scanner, and Analyzer Framework
Bashter
Web Crawler, Scanner, and Analyzer Framework (Shell-Script based)
Bashter is a tool for scanning a Web-based Application. Bashter is very suitable for doing Bug Bounty or Penetration Testing. It is designed like a framework so you can easily add a script to detect vulnerability.
Feature
- Web Crawler
- Gather Input Form
- Detect Misconfigured CORS
- Detect missing X-FRAME-OPTIONS (Clickjacking Potential)
- Detect Reflected XSS via URL
- Detect Reflected XSS via Form
- Detect HTTP Splitting Response via CRLF Injection
- Detect Open Redirect
Install
git clone https://github.com/zerobyte-id/Bashter.git
Use
For Example
To be more powerful, You can add something script (custom) like this:
modules/form/yourscript.bash {WEB-URL} {SOURCECODE}
modules/url/yourscript.bash {WEB-URL} {SOURCECODE}
modules/header/yourscript.bash {WEB-URL} {SOURCECODE}
Copyright (c) 2019, ZeroByte.ID Warehouse
Source: https://github.com/zerobyte-id/