NoMore403 自动化 Bypass 403/40X

admin 2024年3月10日21:50:26评论6 views字数 2872阅读9分34秒阅读模式

NoMore403 自动化 Bypass 403/40X

NoMore403 自动化 Bypass 403/40X

NoMore403

介绍

nomore403是一款创新工具,旨在帮助网络安全专业人士和爱好者绕过 Web 安全评估期间遇到的 HTTP 40X 错误。与其他解决方案不同,nomore403它自动化各种技术来无缝地绕过这些访问限制,提供从标头操纵到方法篡改的广泛策略。

先决条件

在安装并运行之前nomore403,请确保您具备以下条件:

  • 您的计算机上安装了 Go 1.15 或更高版本。

从源代码编译

如果您更喜欢自己编译该工具:

git clone https://github.com/devploit/nomore403cd nomore403go getgo build

用法

输出示例

    ________  ________  ________  ________  ________  ________  ________  ________  ________        ╱  ╲╱        ╲╱    ╱   ╲╱        ╲╱        ╲╱        ╲╱    ╱   ╲╱        ╲╱__      ╲           ╱    ╱    ╱         ╱    ╱    ╱    ╱    ╱       __╱         ╱    ╱    ╱__       ╱          ╱         ╱         ╱         ╱        _╱       __/____     ╱         ╱         ╱ ╲__╱_____╱╲________╱╲__╱__╱__╱╲________╱╲____╱___╱╲________╱    ╱____╱╲________╱╲________╱  Target:     https://domain.com/adminHeaders:                falseProxy:                  falseUser Agent:             Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0; 1ButtonTaskbar)Method:                 GETPayloads folder:        payloadsCustom bypass IP:       falseFollow Redirects:       falseRate Limit detection:   falseVerbose:                false━━━━━━━━━━━━━ DEFAULT REQUEST ━━━━━━━━━━━━━403     429 bytes https://domain.com/admin━━━━━━━━━━━━━ VERB TAMPERING ━━━━━━━━━━━━━━━━━━━━━━━━━━━ HEADERS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ CUSTOM PATHS ━━━━━━━━━━━━━━━━200    2047 bytes https://domain.com/;///..admin━━━━━━━━━━━━━ HTTP VERSIONS ━━━━━━━━━━━━━━━403      429 bytes HTTP/1.0403      429 bytes HTTP/1.1403      429 bytes HTTP/2━━━━━━━━━━━━━ CASE SWITCHING ━━━━━━━━━━━━━━200    2047 bytes https://domain.com/%61dmin
基本用法
./nomore403 -u https://domain.com/admin
详细模式+代理
./nomore403 -u https://domain.com/admin -x http://127.0.0.1:8080 -v
使用自定义标头+特定IP地址进行绕过
./nomore403 -u https://domain.com/admin -H "Environment: Staging" -b 8.8.8.8
设置新的 goroutine 最大值 + 在请求之间添加延迟
./nomore403 -u https://domain.com/admin -m 10 -d 200
./nomore403 -hCommand line application that automates different ways to bypass 40X codes.Usage:  nomore403 [flags]Flags:  -i, --bypass-ip string      Use a specified IP address or hostname for bypassing access controls. Injects this IP in headers like 'X-Forwarded-For'.  -d, --delay int             Specify a delay between requests in milliseconds. Helps manage request rate (default: 0ms).  -f, --folder string         Specify the folder location for payloads if not in the same directory as the executable.  -H, --header strings        Add one or more custom headers to requests. Repeatable flag for multiple headers.  -h, --help                  help for nomore403      --http                  Use HTTP instead of HTTPS for requests defined in the request file.  -t, --http-method string    Specify the HTTP method for the request (e.g., GET, POST). Default is 'GET'.  -m, --max-goroutines int    Limit the maximum number of concurrent goroutines to manage load (default: 50). (default 50)      --no-banner             Disable the display of the startup banner (default: banner shown).  -x, --proxy string          Specify a proxy server for requests, e.g., 'http://server:port'.      --random-agent          Enable the use of a randomly selected User-Agent.  -l, --rate-limit            Halt requests upon encountering a 429 (rate limit) HTTP status code.  -r, --redirect              Automatically follow redirects in responses.      --request-file string   Load request configuration and flags from a specified file.  -u, --uri string            Specify the target URL for the request.  -a, --user-agent string     pecify a custom User-Agent string for requests (default: 'nomore403').  -v, --verbose               Enable verbose output for detailed request/response logging.
项目地址:
https://github.com/devploit/nomore403

原文始发于微信公众号(Ots安全):NoMore403 自动化 Bypass 403/40X

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2024年3月10日21:50:26
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   NoMore403 自动化 Bypass 403/40Xhttp://cn-sec.com/archives/2564192.html

发表评论

匿名网友 填写信息