Coder Social home page Coder Social logo

optionalg / sherlock-1 Goto Github PK

View Code? Open in Web Editor NEW

This project forked from gbiagomba/sherlock

0.0 1.0 0.0 12.35 MB

This script is designed to help expedite a web application assessment by automating some of the assessment steps (e.g., running nmap, sublist3r, metasploit, etc.)

License: GNU General Public License v3.0

Shell 100.00%

sherlock-1's Introduction

alt tag

Sherlock - Web Inspector

Over the years I have had to do various web application and network pentests and I realized I was spending a lot of time performing the asset discovery, network vulnerability and web vulnerability scans. So I wrote this script to help handle that and I figuered I should share it with the world. Be advised, this tool was written for educational, and research purposes, please do not use this tool on systems you do not own.

Pre-requisite

Though I am planning to make a version of this script that can run on other NIX/UNX systems, however for the time being this was written to run best on debian based systems.

Install

cd /opt/
git clone https://github.com/gbiagomba/Sherlock
cd Sherlock
./install.sh

Usage

sherlock targetfile projectName

Do not worry, if you forget to supply a field, the prompt(s) will be asked as the tool runs.

Uninstall

cd /opt/Sherlock/
./uninstall.sh

TODO

  • Un-initialize variables
  • Add multi-thread parallel processing
  • Limit amount of data stored to disk, use more variables
  • Add SSL (e.g., sslyze, ssltest or testssl) checking later [done]
  • Add zipping of all content and sending it via some medium (e.g., email, ftp, etc) [done]
  • Write install script [done]
  • Add DNS recon [done]
  • Add SSH audit [done]
  • Add XSSTrike [done]
  • Add FTP testing [inprogress]
  • Add SMTP testing [inprogress]
  • Add SMB testing [inprogress]
  • Add RDP testing [inprogress]
  • Add DB/SQL testing [inprogress]
  • Add Tenable API scanning/support [Queued]
  • Add joomscan [Queued]
  • Add docker run --rm asannou/droopescan scan [Queued]
  • Add function to check if the script is running on latest version [inprogress]
  • Switch sublister with subfinder [https://github.com/projectdiscovery/subfinder]
  • Switch grep with ripgrep [inprogress]
  • Add arjun [https://github.com/s0md3v/Arjun] [done]
  • Add exclusion list config file

Future Plans

I plan on converting this into a python script later down the road...just an FYI

           ."""-.
          /      \
          |  _..--'-.
          >.`__.-"";"`
         / /(     ^\    (
         '-`)     =|-.   )s
          /`--.'--'   \ .-.
        .'`-._ `.\    | J /
  jgs  /      `--.|   \__/

sherlock-1's People

Contributors

gbiagomba avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.