Kali Linux

4-ZERO-3 : 403/401 Bypass Methods + Bash Automation

4-ZERO-3 Tool to bypass 403/401. This script contain all the possible techniques to do the same.

  • NOTE : If you see multiple [200 Ok]/bypasses as output, you must check the Content-Length. If the content-length is same for multiple [200 Ok]/bypasses means false positive. Reason can be “301/302” or “../” [Payload] DON’T PANIC.
  • Script will print cURL PAYLOAD if possible bypass found.

Preview

Help

root@me_dheeraj:$ bash 403-bypass.sh -h

 Usage / Modes

  • Scan with specific payloads:

--header ] Support HEADER based bypasses/payloads

root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –header

--protocol ] Support PROTOCOL based bypasses/payloads

root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –protocol

 --port ] Support PORT based bypasses/payload

root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –port

--HTTPmethod ] Support HTTP Method based bypasses/payload

root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –HTTPmethod

--encode ] Support URL Encoded bypasses/payload

root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –encode

--SQLi ] Support MySQL mod_Security & libinjection bypasses/payloads [** New **]

root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –SQLi

  • Complete Scan {includes all exploits/payloads} for an endpoint [ –exploit ]

root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret –exploit

R K

Recent Posts

Kali Linux 2024.4 Released, What’s New?

Kali Linux 2024.4, the final release of 2024, brings a wide range of updates and…

6 hours ago

Lifetime-Amsi-EtwPatch : Disabling PowerShell’s AMSI And ETW Protections

This Go program applies a lifetime patch to PowerShell to disable ETW (Event Tracing for…

6 hours ago

GPOHunter – Active Directory Group Policy Security Analyzer

GPOHunter is a comprehensive tool designed to analyze and identify security misconfigurations in Active Directory…

2 days ago

2024 MITRE ATT&CK Evaluation Results – Cynet Became a Leader With 100% Detection & Protection

Across small-to-medium enterprises (SMEs) and managed service providers (MSPs), the top priority for cybersecurity leaders…

5 days ago

SecHub : Streamlining Security Across Software Development Lifecycles

The free and open-source security platform SecHub, provides a central API to test software with…

1 week ago

Hawker : The Comprehensive OSINT Toolkit For Cybersecurity Professionals

Don't worry if there are any bugs in the tool, we will try to fix…

1 week ago