Code Monkey home page Code Monkey logo

arjun's Introduction


Arjun
Arjun

HTTP Parameter Discovery Suite

demo

The Improvment

Wonder what's modified in this Arjun version?

Simple, nowdays many platforms uses Javascript for their frontends, and usually they stores those interesting parameters in Javascript Arrays.

This Arjun version grabs variable names from strings like {"name":"value"}. Lately I got MANY injections from GET/POST/Cookies scraping those, and later escaping with </script>. This happened me in many programs including big ones like PayPal, Yahoo, etc and this little trick helped me a lot. When you are fuzzing a no response page go dictionary fuzzing, but if its a responding website this heuristic technique usually is faster and better.

Introduction

Web applications use parameters (or queries) to accept user input, take the following example into consideration

http://api.example.com/v1/userinfo?id=751634589

This URL seems to load user information for a specific user id, but what if there exists a parameter named admin which when set to True makes the endpoint provide more information about the user?
This is what Arjun does, it finds valid HTTP parameters with a huge default dictionary of 25,980 parameter names.

The best part? It takes less than 30 seconds to go through this huge list while making just 50-60 requests to the target.
Want to know how Arjun does that? Here's how.

Donations

You can encourage me to contribute more to the open source with donations.

Do you want to sponsor Arjun and get mentioned here? Email me s0md3v[at]gmail[dot]com

Features

  • Multi-threading
  • Thorough detection
  • Automatic rate limit handling
  • A typical scan takes 30 seconds
  • GET/POST/JSON methods supported
  • Huge list of 25,980 parameter names

Note: Arjun doesn't work with python < 3.4

How to use Arjun?

A detailed usage guide is available on Usage section of the Wiki.\

An index of options is given below:

Credits

The parameter names are taken from @SecLists.

arjun's People

Contributors

s0md3v avatar edduu avatar bberastegui avatar craigharley avatar sinakheirkhah avatar pacbypass avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.