当前位置: 首页 > news >正文

兼具本地式与分布式优势、针对大类通用型Web漏洞、插件外部动态化导入的轻量级主被动扫描器

工具介绍

兼具本地式与分布式优势、针对大类通用型Web漏洞、插件外部动态化导入的轻量级主被动扫描器

工具功能

工具使用

Ling - 可视化

z0 - 命令行

✔ 被动扫描

被动扫描的默认配置(将浏览器流量转发到端口5920):

z0 scan -s 127.0.0.1:5920  

常用推荐配置:

z0 scan -s 127.0.0.1:5920 --risk 0,1,2,3 --level 2 --disable cmdi,unauth  

被动扫描控制台界面

✔ 主动扫描

主动扫描的默认配置:

# 通过Burp/Yakit请求流量启动主动检测(推荐)  
z0 scan -s 127.0.0.1:5920  

# 直接检测  
z0 scan -u https://example.com/?id=1  
# 从URL列表进行批量检测  
z0 scan -f urls.txt  

🔖 插件列表

  • PerPage
Plugin NameDescriptionRisk
sqli-boolSQL Boolean-based Blind Injection2
sqli-timeSQL Time-based Blind Injection2
sqli-errorSQL Error-based Injection2
codei-aspASP Code Execution3
codei-phpPHP Code Execution3
cmdiCommand Execution3
other-objectdeseDeserialization Parameter Analysis3
sensi-jsJS Sensitive Information Leak0
sensi-jsonpJsonp Sensitive Information Leak1
sensi-php-realpathPHP Real Path Discovery0
redirectRedirect Vulnerability1
sensi-webpackWebpack Source Code Leak1
other-webdav-passiveWebDAV Service Passive Detection1
xpathi-errorError-based XPATH Injection2
trave-pathPath Traversal2
sensi-backup_1Backup File Detection (File-based)1
sensi-viewstateUnencrypted VIEWSTATE Discovery0
xssJS Semantic-based XSS Scanning1
crlf_1CRLF Vulnerability Detection2
cors-passiveCORS Vulnerability (Passive Analysis)2
unauthUnauthorized Access Vulnerability2
leakpwd-page-passiveWeak Password on Login Page2
sensi-editfileEditor Backup File Leak1
sensi-sourcecodeSource Code Leak1
captcha-bypassCAPTCHA Bypass0
sensi-retirejsOutdated JS Component Detection-1
sstiSSTI Vulnerability Detection3
ssti-angularjsAngularJS Client-Side Template Injection Detector2
ssrfSSRF plugin detects server-side request forgery vulnerabilities via crafted payloads.2
xxeXXE plugin detects XML external entity injection vulnerabilities via malicious payloads.3
xxe-blindBlind XXE plugin detects out-of-band data exfiltration.3
codei-javaJava Code Injection Vulnerability Scanner (EL/SpEL/OGNL)3
other-redosRegular Expression Denial of Service (ReDoS) Vulnerability Scanner-1
other-jndi-errorJNDI Injection Vulnerability Scanner3
  • PerDir
Plugin NameDescriptionRisk
sensi-backup_2Backup File Scan (Directory-based)1
trave-list_2Directory Listing2
sensi-filesSensitive File Leak (e.g., phpinfo, .git)1
upload-ossOSS Bucket Arbitrary File Upload2
sensi-frontpageFrontPage Configuration Leak1
  • PerDomain
Plugin NameDescriptionRisk
sensi-errorpageError Page Sensitive Information Leak0
xss-net.NET Universal XSS1
other-dns-zonetransferDNS Zone Transfer Vulnerability1
xss-flashFlash Universal XSS1
other-idea-parseIdea Directory Parsing1
other-xstXST Vulnerability Detection-1
other-webdav-activeWebDAV Service Discovery1
upload-putPUT-based Arbitrary File Upload3
sensi-backup_3Backup File Detection (Domain-based)1
cors-activeCORS Vulnerability (Active Detection)2
crlf_3CRLF Line Injection Vulnerability2
other-hostiHost Header Injection Detection1
other-oss-takeoverOSS Bucket Takeover Vulnerability3
sensi-iis-shortnameIIS Short Filename Vulnerability0
other-clickjackingClickjacking Vulnerability-1
other-baselineService Version Leak-1
other-smugglingRequest Smuggling Vulnerability3
trave-list_3Directory Listing2
  • PerHost
Plugin NameDescription
leakpwd-mssqlWeak Password on MSSQL Server
leakpwd-mysqlWeak Password on MySQL Server
leakpwd-postgresqlWeak Password on PostgreSQL Server
leakpwd-redisWeak Password on Redis Server
leakpwd-smbWeak Password on SMB Server
other-ftp-anonymousFTP anonymous Login
other-solr-rceApache Solr RCE via Velocity
unauth-dockerDocker Unauthorized Access
unauth-jenkinsJenkins Unauthorized Access
unauth-memcachedMemcached Unauthorized Access
unauth-mongodbMongodb Unauthorized Access
unauth-resisRedis Unauthorized Access
unauth-rsyncRsync Unauthorized Access
unauth-solrApache Solr Unauthorized Access
unauth-zookeeperZookeeper Unauthorized access

工具下载

https://github.com/JiuZero/z0scan
http://www.dtcms.com/a/453452.html

相关文章:

  • 第4章 文件管理
  • JavaScript初识及基本语法讲解
  • RabbitMQ中Consumer的可靠性
  • 自学网站建设作业抖音代运营公司收费
  • drupal做虚拟发货网站做网站如何将一张图片直接变体
  • 监控系统1 - 项目框架 | 线程邮箱
  • CTFHub SQL注入通关笔记3:报错注入(手注法+脚本法)
  • 开源UML工具完全指南:从图形化建模到文本驱动绘图
  • 优秀网站设计欣赏北京公司网站建设公司
  • 基于 Python 构建的安全 gRPC 服务——TLS、mTLS 与 Casbin 授权实战
  • 【Java核心技术/IO】35道Java IO面试题与答案
  • ICT 数字测试原理 10 - -VCL 向量如何执行之数字单元
  • 网站目录爬行wordpress怎么做信息分类
  • 专题三:二分查找~
  • 360小工具合集,用39个小工具
  • GreenTuber 0.1.7.6| 纯净无广的油管第三方,支持4K下载
  • UVa 235 Typesetting
  • 东莞营销网站建设哪个平台好十大app排行榜
  • asp网站开发工具现在的企业一般用的什么邮箱
  • 企业区块链重新崛起
  • 【SSH】同一局域网下windows使用Xshell SSH连接另一台 ubuntu 22.04 电脑
  • [随手记] docker 镜像拉取记录
  • Ruoyi 赋能,百度天气不止当下:打造面向未来的预报实战
  • 网站搭建流程负责人长春制作网站哪家好
  • 日语学习-日语知识点小记-进阶-JLPT-N1阶段应用练习(7):语法 +考え方20+2022年7月N1
  • 天天爱天天做网站广告联盟没有网站怎么做
  • 1688 关键词搜索接口深度开发:从精准匹配到供应链筛选的技术实现
  • 网站多域名怎么做绿色网站模板大全
  • 深入理解 Vue 3 组件间数据传递的多种方式
  • 华威桥网站建设wordpress去除更新