tachyon v3.2.1 releases: Fast Multi-Threaded Web Discovery Tool

Tachyon is a Fast Multi-Threaded Web Discovery Tool.

The main goal of it is to help webadmins find leftover files in their site installation, permission problems and web server configuration errors. It is not a vulnerability scanner or a web crawler.
Features

It provides:

  • Plugin support
  • SSL support
  • Robots.txt support
  • Common directory lookup
  • Fast Multi-Threaded execution
  • Automatic variable rate limiter
  • Recursive scanning

Changelog

v3.2.1

  • Added file checks for Spring Boot Actuator

v3.2.0

  • Upgraded to hammertime-http 0.6.0
  • Improved compatibility with Python 3.5 to 3.7

Install

Requirements

A mainstream OS (Windows, Linux, Mac OS X)
Python 3.x (Could still work with 2.7, with minor issues)
urllib3 1.1+

git clone https://github.com/delvelabs/tachyon.git
pip install -r requirements.txt

How to help (for sysadmins)

  • Run tachyon on your domain
  • Run a recursive directory listing of your domain (I don’t need to know what the domain is)
  • Send me the result list and the directory listing

Usage

python3 tachyon.py -h
Usage: tachyon.py <host> [options]

Options:
-h, –help show this help message and exit
-d Enable debug [default: False]
-f search only for files [default: False]
-s search only for subdirs [default: False]
-c COOKIES load cookies from file [default: none]
-a Allow plugin to download files to ‘output/’ [default:
False]
-b Search for subdirs recursively [default: False]
-l LIMIT limit recursive depth [default: 2]
-e Eval-able output [default: False]
-j JSON output [default: False]
-m MAXTIMEOUT Max number of timeouts for a given request [default:
500]
-w WORKERS Number of worker threads [default: 50]
-v VHOST forge destination vhost [default: <host>]
-z Only run plugins then exit [default: False]
-u AGENT User-agent [default: Mozilla/5.0 (Windows NT 6.1)
AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/41.0.2228.0 Safari/537.36]
-p PROXY Use http proxy <scheme://url:port> [default: no proxy]
-x PLUGIN:OPTION_STRING, –plugin-configure=PLUGIN:OPTION_STRING
Plugin-specific configuration options.

Existing plugins:

  • HostProcessor: This plugin process the hostname to generate host and filenames relatives to it.
  • PathGenerator: Generate simple paths with letters and digits (ex: /0).
  • Robots: Add the paths in robots.txt to the paths database.
  • SitemapXML: Add paths and files found in the site map to the database.
  • Svn: Fetch /.svn/entries and parse for target paths.

Copyright 2018- Delve Labs Inc.

Source: https://github.com/delvelabs

Share