Git Product home page Git Product logo

cappricio-securities / crlfi Goto Github PK

View Code? Open in Web Editor NEW
1.0 1.0 0.0 351 KB

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

Home Page: https://blogs.cappriciosec.com/application/138/Cappricio%20Securities%20Discovers%20CRLF%20Injection%20Vulnerability%20in%20Popular%20Website,%20Responsible%20Disclosure%20Earns%20Bounty

License: MIT License

Python 100.00%
bugbounty bugbounty-tool crlf-injection crlf-injection-scanner crlfi

crlfi's Introduction

logo

Badges

MIT License PyPI - Version PyPI - Downloads GitHub all releases Profile_view Follow Twitter

License

MIT

Installation

  1. Install Python3 and pip Instructions Here (If you can't figure this out, you shouldn't really be using this)

    • Install via pip
      •    pip install crlfi
    • Run bellow command to check
      • crlfi -h

Configurations

  1. We integrated with the Telegram API to receive instant notifications for vulnerability detection.

Usages

  1. This tool has multiple use cases.

    • To Check Single URL
      •    crlfi -u http://example.com 
    • To Check List of URL
      •   crlfi -i urls.txt 
    • Save output into TXT file
      •   crlfi -i urls.txt -o out.txt
    • Want to Learn about crlfi? Then Type Below command
      •   crlfi -b

๐Ÿšจ Disclaimer

This tool is created for security bug identification and assistance; Cappricio Securities is not liable for any illegal use. Use responsibly within legal and ethical boundaries. ๐Ÿ”๐Ÿ›ก๏ธ

Working PoC Video

asciicast

Help menu

Get all items

๐Ÿ‘‹ Hey Hacker
                                v1.0
   __________  __    __________
  / ____/ __ \/ /   / ____/  _/
 / /   / /_/ / /   / /_   / /
/ /___/ _, _/ /___/ __/ _/ /
\____/_/ |_/_____/_/   /___/

                                Developed By https://cappriciosec.com


crlfi : Bug scanner for WebPentesters and Bugbounty Hunters 

$ crlfi [option]

Usage: crlfi [options]
Argument Type Description Examples
-u --url URL to scan crlfi -u https://target.com
-i --input filename Read input from txt crlfi -i target.txt
-o --output filename Write output in txt file crlfi -i target.txt -o output.txt
-c --chatid Creating Telegram Notification crlfi --chatid yourid
-b --blog To Read about crlfi Bug crlfi -b
-h --help Help Menu crlfi -h

๐Ÿ”— Links

Website linkedin twitter

Author

Feedback

If you have any feedback, please reach out to us at [email protected]

crlfi's People

Contributors

cyber-karthi avatar karthi-the-hacker avatar

Stargazers

 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.