Bashter is a Shell-Script based Web Crawler, Scanner, and Analyser Framework. Bashter is a tool for scanning a Web-based Application. Bashter is very suitable for doing Bug Bounty or Penetration Testing.
It is designed like a framework so you can easily add a script for detect vulnerability.
For Example
To be more powerful, You can add something script (custom) like this:
modules/form/yourscript.bash {WEB-URL} {SOURCECODE}
modules/url/yourscript.bash {WEB-URL} {SOURCECODE}
modules/header/yourscript.bash {WEB-URL} {SOURCECODE}
For the sample, you can follow existing scripts.
Also Read – EvilClippy : For Creating Malicious MS Office Documents
Disable Script
You only need to change the extension, for example .bash => .bashx.
By Default:
How to Run:
git clone https://github.com/zerobyte-id/Bashter.git
cd Bashter/
bash bashter.bash
Notes: This tool will consume a lot of disk usage, so don’t forget to housekeep bashter-tempdata and scan-logs.
Credits: Schopath, Suhada , Abay
bomber is an application that scans SBOMs for security vulnerabilities. So you've asked a vendor…
Embed a payload within a PNG file by splitting the payload across multiple IDAT sections.…
Exploit-Street, where we dive into the ever-evolving world of cybersecurity with a focus on Local…
Shadow Dumper is a powerful tool used to dump LSASS (Local Security Authority Subsystem Service)…
shadow-rs is a Windows kernel rootkit written in Rust, demonstrating advanced techniques for kernel manipulation…
Extract and execute a PE embedded within a PNG file using an LNK file. The…