Git Product home page Git Product logo

crlfuzz's Introduction

๐Ÿ” PGP Fingerprint: 3EFE F626 BA6E A31D 037F 77AA D192 CC08 1616 30BD
-----BEGIN PGP PUBLIC KEY BLOCK-----
KeyID: D192CC08161630BD

mQINBGMXmXEBEACoxh0uhXJ/NA40iGiOYNob+IHU4/Ll1CBcNJHtDAjOiH7FaOzu
HMxkuEsS49KLojUX9jkHAMutdV2e7pI+HEwWnS4VwNsP0p80Da7sZP7yZ/GWHCeW
ft1tZ9HfP8oxtN4zliCsTejQElHQGfKJSOGxsDtGa8J9Oys8PBZETWVXrzIiYIdY
VRYEN3kVyO4xpIzo7OnyfNPUezIVReN4xnj6X7oo145c/Ocg0ON3hmMbB/QhbTSQ
3diDa5SpagtidLE/MCjnCDAdIlG+5ZSMIrglPs2oLvQ7iiiVyTOSZ3qq9bXiCV6C
sXs04S0AnnLPN+PvPIyy3PU/OM0TUMNS1Oo2I1cUZ6KlfmO0dYtpXPyiG8bsfdNT
fRDoP8TXtjIL51gUaL8wjw77EhsoZ8UTz5cVRWY2A3DO/K2l+htho2TRubso9Oez
daoXRpz3h1PKa2qbDL2iYD6KccXfM+AR2yEHI6cF34CEnHaemr3KAs+SaM38aXwx
aCkBMaZa96W4bvQJRCVUVIbwcO1etrOGja4LP3OS/FPjnlm1F2aOQchOPGBr3MM+
LjNJwvQOvdQ7uSnLJ/oHCGAiRPVZlwOnJWdcEk32izk92TljKIYVNwZG8rhWLNQk
R7QPPHqVQlj9c3yyqcOzj/1SUlJ7GzAgC0wHmOSiSRLWV1DKCWQMd/IDWwARAQAB
tB5Ed2kgU2lzd2FudG8gKGdpdCkgPG1lQGR3MS5pbz6JAk4EEwEKADgWIQQ+/vYm
um6jHQN/d6rRkswIFhYwvQUCYxeZcQIbAwULCQgHAgYVCgkICwIEFgIDAQIeAQIX
gAAKCRDRkswIFhYwvUtBD/9PLtBzMaV7uoHaNannXyVgg8d6LzePTr+EpEHSYpqS
icU335rGs24kDOIQbVOl5l7dE/EnOPp7AYF5xHr/eGqgYrTuwBMuvwdBNFSBejJs
00raFRwZMd1PA3MTIhBfypg2lDdKrbkilsrZBjaWcLX0Es6NN62f15Ff0eyt1KSE
Gwkt2OTrKdYC+6Gj3LRm46jY5ACIgpoxxk9Y/HHALK4+wY/zn3LKf88Kj5iavidA
y8MhAV0bJBrZGPhPuNwvI98W1neNU9Gh2y0bvgxFbs/YizsOHl5K0wBxrPFQxUYy
QO+yeB3NpGUD0e66GsR3cWx7fmjNkq9syzOa5dYmwlr/7+R8KHzM76xdPbchuuYV
7HzhS2pRLyOKWPHaGypyEj5AmW3y6WovyPm+Ru/Fnlr2fS/zKvMuWIHOcmHLu8aK
AQ2SZ29Jb4YHE9oVW9wsMLeaFVd+0+b8gFpKMy2sh3CYujRzTVFG0IlgrPJxGy7O
6V5XaAqGI777JTwdcPzIsNgepMQN5OEqQlHWfFAyR7kw4Smqo6yN3O9kYqafCBE1
1wyOMhFY1CDbgrblQrFuLnSYjnGNeucHx6FX3jjEe4Wm6H/Ul/4MoPJpbgDolLcl
CICNMpTS36xyBwhETOqP0XjQG8yBra5ZG9zY3tIYz6mKESlEa2LlaRpnVOFi2fOY
frkCDQRjF5lxARAAobVmjg87F7JuJFVMN+Fm+4BVUb9XNsmbkBHlNoBsyKrSaGp2
gxi1eUsCVnarJ0fO6rFrz2tvBFic9hfU7pIaKNATs4bK8hO3reU18Z/xPUWlQU97
tYckMyGBv97HQ1Brb45p4g6aFCtQB48rW2E7XFI4CAm6GxfWD9sVKp4jypJHoZl1
5wilTsGK44bYOHnakQo4NVmynKbRt+1/4CsW2BxTwklWp4K9jtgSUigV8GE6yDIy
FAliSrLZAZUNkoMYTpMp3R6q9ECWBN4VRV2nQyUae+WyEUQOfvQ7jW9J6xGU1fOy
Y0HjSQt4t6OucZtrt4LyrAA7+Z0B4BAno69OgiY5NPf/BbfGs8WnLCMY36EK1FIy
LY/nWRIgf258fLo5Bbd/gzNNfoz7Bh3gQ/0mJfcRceyKIsEG9pHjbelxMZ2LmgsC
RTdAs5+NuEbKWujM+5CgSML72qQ2KEXJxCf2EyjwAHkGDiUAT44Y/zqGNfhZHJnO
V49uut+YCKB+MUdtAHE5viM5KgUgqznBj+7wwDX88BeWcJAPxVXEkrs2mIQXnCyS
vr8eW2aKuPPyYGB02AgLi1OLX9Xd75BVwCPoNgcR01nU9PHReAag0HDdzDl7kMag
3C9r3z8Q+JQJm1RYEmrwdI4CB+l4IaQEAbkgldJjfTbnKVV1nHiH9D+Vc2UAEQEA
AYkCNgQYAQoAIBYhBD7+9ia6bqMdA393qtGSzAgWFjC9BQJjF5lxAhsMAAoJENGS
zAgWFjC9160QAJbzlSCyIf0zfdjgnwZ9JqOon7oB0hKTJg9vqjAZtXDohWW2hDRC
b3vp/ij2nEmAFAbNn4Ut7nmkGIjBAcxXiWLfL4oavkLQ5bQbxQ0E3R7VBTUB2dga
Msd51NOVV+yWA/ueNNvkunZ0W9xsxJgOhQRILG2RjjCcQ2bFvHeOhN5U42lhqSJo
+CNdUfGMRBPggRtjsPP1hhMKICkjiezCqz7G4GvfoStM7fig0DU1cUV7jwdMMnSX
0yiYTwXjOCOh+KlDAiGyIcBtD+sj8S27rtONHTWyhr7AoNDplNtVwCtchDxflvkN
6ly6C3sgsZyKJW1hjLvQuUCnIJDIS9H0LpXOKd3QIATe4VyQtvZlZwefI3NDhqqG
O1lXkY91nLslmTTV45Yc5MhKydWRNv/DvJM+7GEiCQijrcahCLHLbPGJcZf/SIcH
aGvNjdsfWytVePcOORXU4JyWh1tbDF4p3D7Gc0OMvFFTYzOoAAxKdVzZomv5mGD5
/AeQs5IZoWad765WLEtIsBn5n+aR/HZirEIldyRSACEHwXn1hxs/0dBE2aCH4/Ry
0SgmNd+OLrhz0Vi4/j9jnU0IxCa44HH/58xgiIB52qxD2TkyC/NasWGHdlKlYANw
uDU6cbA4HflnGe2Zkt2PMXSitj4PsDUc8rUVNfyCBfj/mz/YjVMtVmcX
=ks+t

              .__....._             _.....__,
               .": o :':         ;': o :".
               `. `-' .'.       .'. `-' .'
                  `---'             `---'
   
       _...----...      ...   ...      ...----..._
    .-'__..-""'----    `.  `"`  .'    ----'""-..__`-.
   '.-'   _.--"""'       `-._.-'       '"""--._   `-.`
   '  .-"'                  :                  `"-.  `
     '   `.              _.'"'._              .'   `
           `.       ,.-'"       "'-.,       .'
             `.                           .'
               `-._                   _.-'
                   `"'--...___...--'"`

-----END PGP PUBLIC KEY BLOCK-----

Tip

Spotify - dw1
Last played:

spotify-github-profile


Note

Check these hot repos ๐Ÿฅตโ€Ž๏ธโ€๐Ÿ”ฅ

mubeng teler-waf noizy


Important

If you've made some impact using my tools or just want to encourage me to continue creating stuff, please consider giving back or supporting my efforts and helping it grow by buy me a cup of coffee โ€” but only if you're definitely able to! ๐Ÿ˜Š๐ŸŽ‰

GitHub Sponsors - dwisiswant0 Buy Me a Coffee - dw1 Trakteer - dwisiswant0 Ko-fi - dwisiswant0 PayPal - dw1s


Pesawat Kemanusiaan Indonesia untuk Palestina

crlfuzz's People

Contributors

adilsoybali avatar dependabot[bot] avatar dwisiswant0 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

crlfuzz's Issues

[FEATURE] Specify requests per second or delay between requests

I would like to incorporate this tool into my automated suite for bug hunting, but it ends up breaking my internet connection due to producing too many request,

It would be great if an option to specify requests per second or to specify the delay between requests was added, something like the --delay option on sqlmap.

Thanks!

second feature of the tool for fuzzing on urls is not working !

Describe the bug

A clear and concise description of what the bug is.

To Reproduce

  1. install crlfuzz

  2. run crlfuzz -l

  3. not giving any output just showing this

crlfuzz -l ~/Desktop/recon/urls.txt


| | __ | | | | _ ___ ___
| --| -| |
| | | |- _|- _|
|
||||| |||__|

  v1.4.0 - @dwisiswant0

[WRN] Use with caution. You are responsible for your actions
[WRN] Developers assume no liability and are not responsible for any misuse or damage.

4.while you run the crlfuzz -u "http://test.com"

working fine

  1. while subfinder target.com | crlfuzz

working fine

Steps to reproduce the behavior:

** it is expected to run tool while giving input as file**

A clear and concise description of what you expected to happen.

[****](url
Screenshot from 2020-11-29 00-16-56
Screenshot from 2020-11-29 00-16-54

)

If applicable, add screenshots to help explain your problem.

Environment (please complete the following information):

  • OS: [linux]
  • OS version: [Linux kali 5.9.0-kali2-amd64 #1 SMP Debian 5.9.6-1kali1 (2020-11-11) x86_64 GNU/Linux
    ]
  • CRLFuzz Version [crlfuzz -- v1.4.0]

Cant able to pass list in crlfuzz

Hey mate,

I tried curlfuzz with -l flag defined wordlist and theres a error in output.

โ””โ”€โ”€โ•ผ #crlfuzz -l /root/Desktop/domains.resolved.txt


| | __ | | | | _ ___ ___
| --| -| |
| | | |- _|- _|
|
||||| |||__|

  v1.4.0 - @dwisiswant0

[WRN] Use with caution. You are responsible for your actions
[WRN] Developers assume no liability and are not responsible for any misuse or damage.

All i get is blank result.

[FEATURE]

Is your feature request related to a problem? Please describe.
A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]

Describe the solution you'd like
A clear and concise description of what you want to happen.

Describe alternatives you've considered
A clear and concise description of any alternative solutions or features you've considered.

Additional context
Add any other context or screenshots about the feature request here.

Output for results

Hi , Please create a -o results.txt which saves all the vulnerable urls in the results.txt file. While running this awesome tool on thousands of domains makes it difficult to scroll and search for the results.

Adding custom header breaks the tool

Hi, :)
Describe the bug

While adding custom headers tools break.

To Reproduce

cat live_targets.txt | crlfuzz -H "User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0"

cat targets.txt | httpx | crlfuzz -H "User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0"

Expected behavior

The tool should able to add a custom header in every HTTP request.

Environment (please complete the following information):

  • OS: tested in both Ubuntu and in kali
  • OS version: 18.04 and 5.10.13-1kali1 (2021-02-08) x86_64
  • CRLFuzz Version: CRLFuzz 1.4.0

Additional context

Below is the error log.

[signal SIGSEGV: segmentation violation code=0x1 addr=0x38 pc=0x659cc9]

goroutine 40 [running]:
github.com/dwisiswant0/crlfuzz/pkg/crlfuzz.Scan(0xc0000f6480, 0x37, 0x0, 0x0, 0x0, 0x0, 0xc0000a0bf0, 0x1, 0x1, 0x0, ...)
        /root/go/pkg/mod/github.com/dwisiswant0/[email protected]/pkg/crlfuzz/crlfuzz.go:22 +0x3e9
github.com/dwisiswant0/crlfuzz/internal/runner.(*Options).run(0xc0000bea00, 0xc0000f6480, 0x37)
        /root/go/pkg/mod/github.com/dwisiswant0/[email protected]/internal/runner/runner.go:41 +0xb2
github.com/dwisiswant0/crlfuzz/internal/runner.New.func1(0xc000096180, 0xc0000bea00, 0xc0000b82e0)
        /root/go/pkg/mod/github.com/dwisiswant0/[email protected]/internal/runner/runner.go:22 +0x65
created by github.com/dwisiswant0/crlfuzz/internal/runner.New
        /root/go/pkg/mod/github.com/dwisiswant0/[email protected]/internal/runner/runner.go:20 +0xcc```

Let me know if any additional information required.
Take care,
unstabl3

[BUG] net/url: invalid control character in URL

Describe the bug

Hello, thanks for this great tool. However when I run the tool I get this error:
image


   _____ _____ __    _____             
  |     | __  |  |  |   __|_ _ ___ ___ 
  |   --|    -|  |__|   __| | |- _|- _|
  |_____|__|__|_____|__|  |___|___|___|

      v1.4.0 - @dwisiswant0

[WRN] Use with caution. You are responsible for your actions
[WRN] Developers assume no liability and are not responsible for any misuse or damage.
[ERR] parse "https://example.com/\r\tSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/\rSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/\r%20Set-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/\r\nSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/\r\n%20Set-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/\r\n\tSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/crlfuzz\rSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/crlfuzz\r%20Set-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/crlfuzz\r\nSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/crlfuzz\r\n%20Set-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/crlfuzz\r\n\tSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/crlfuzz\r\tSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/?crlfuzz=\r%20Set-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/?crlfuzz=\r\nSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/?crlfuzz=\r\n%20Set-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/?crlfuzz=\r\n\tSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/?crlfuzz=\r\tSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL
[ERR] parse "https://example.com/?crlfuzz=\rSet-Cookie:param=crlfuzz;": net/url: invalid control character in URL

I got the same error even though I tested it on 2 different linux machines.

Environment:

  • OS: linux
  • OS version:
    1- Linux tester 5.11.0-1027-azure #30~20.04.1-Ubuntu SMP Wed Jan 12 20:56:50 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
    2- Linux kali 5.10.0-kali9-amd64 #1 SMP Debian 5.10.46-4kali1 (2021-08-09) x86_64 GNU/Linux
  • CRLFuzz Version: CRLFuzz 1.4.0

This link may be helpful: https://stackoverflow.com/questions/55945325/golang-url-parse-always-return-invalid-control-character-url

Thanks

[BUG] somehow your go command is not working

C:\Users\user>go get -u -v github.com/dwisiswant0/crlfuzz/cmd/crlfuzz
github.com/dwisiswant0/crlfuzz (download)
unrecognized import path "dw1.io/crlfuzz/internal/runner": https fetch: Get "https://dw1.io/crlfuzz/internal/runner?go-get=1": dial tcp 5.189.188.232:443: connectex: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.

tried this too
go get -v -u dw1.io/crlfuzz/cmd/crlfuzz
same error , please take a look at it., However i have done it with git clone but still.

go version used : go version go1.14.2 windows/amd64

Thank You

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.