Bashter : Web Crawler, Scanner & Analyser Framework

Bashter is a Shell-Script based Web Crawler, Scanner, and Analyser Framework. Bashter is a tool for scanning a Web-based Application. Bashter is very suitable for doing Bug Bounty or Penetration Testing.

It is designed like a framework so you can easily add a script for detect vulnerability.

For Example

To be more powerful, You can add something script (custom) like this:

modules/form/yourscript.bash {WEB-URL} {SOURCECODE}
modules/url/yourscript.bash {WEB-URL} {SOURCECODE}

modules/header/yourscript.bash {WEB-URL} {SOURCECODE}

For the sample, you can follow existing scripts.

Also Read – EvilClippy : For Creating Malicious MS Office Documents

Disable Script

You only need to change the extension, for example .bash => .bashx.

By Default:

  • Web Crawler
  • Gather Input Form
  • Detect Missconfigured CORS
  • Detect missing X-FRAME-OPTIONS (Clickjacking Potential)
  • Detect Reflected XSS via URL
  • Detect Reflected XSS via Form
  • Detect HTTP Splitting Response via CRLF Injection
  • Detect Open Redirect

How to Run:

git clone https://github.com/zerobyte-id/Bashter.git
cd Bashter/
bash bashter.bash

Notes: This tool will consume a lot of disk usage, so don’t forget to housekeep bashter-tempdata and scan-logs.

Credits: Schopath, Suhada , Abay

R K

Recent Posts

What Is a Data Protection Platform and Why Your Organization Needs One

A data protection platform is a unified system that helps organizations discover, classify, monitor, and…

3 hours ago

How Swiss Privacy Rules Affect AI Companies Under GDPR

AI companies operating in or around Switzerland face a compliance challenge that most legal teams…

1 day ago

Swiss FADP vs EU GDPR: Key Differences for AI and Data Privacy

Two major data privacy laws now govern how organizations handle personal data across Europe; the…

2 days ago

Kali Linux Commands Cheat Sheet: Complete Quick Reference

This cheat sheet covers the essential Kali Linux commands every pentester and ethical hacker uses…

1 month ago

What I Wish I Knew Before Learning Malware Analysis and Reverse Engineering

When I first started learning malware analysis and reverse engineering, I thought the hardest part…

1 month ago

git fetch vs git pull: How They Work and When to Use Each

Both git fetch and git pull talk to a remote repository, but they do very different things to your…

2 months ago