SCANter
SCANter copied to clipboard
Websites Vulnerability Scanner
SCANter - Web Security Scanner ๐
๐ Description ๐
-
Detect This vulnerabilities
-
Remote Code Execution
- Linux
-
XSS Reflected
-
Template Injection
- Jinja2
- ERB
- Java
- Twig
- Freemarker
-
SQl Injection
-
๐ธ Screenshot ๐ธ
OS Support
-
Kali Linux
-
Android - Termux
-
Windows
๐ฟ Installation ๐ฟ
Linux data:image/s3,"s3://crabby-images/e1761/e17613d6a9fd602ae73eee8e91caa4df0a31421f" alt="alt tag"
- open your terminal
- enter this command
$ git clone https://github.com/Err0r-ICA/SCANter $ cd SCANter $ python3 -m pip install -r requirements.txt
Android data:image/s3,"s3://crabby-images/a0437/a0437713e80e0d62ba63f1f67e06e6ddb61c0b25" alt=""
- Download Termux App
- open termux app
- enter this command
$ pkg install python -y
$ pkg install git -y
$ git clone https://github.com/Err0r-ICA/SCANter
$ cd SCANter
$ python3 -m pip install -r requirements.txt
Windows data:image/s3,"s3://crabby-images/43869/438690673be120d374f4ab74ef703390f824035e" alt=""
- Download python3 and install it
- open your cmd
- enter this command
$ python3 -m pip install -r requirements.txt
๐งพ Usage ๐งพ
Options:
-h, --help | Show help message and exit
--version | Show program's version number and exit
-u URL, --url=URL | Target URL (e.g."http://www.target.com/vuln.php?id=1")
--data=DATA | Data string to be sent through POST (e.g. "id=1")
--list=FILE | Get All Urls from List
--threads | Max number of concurrent HTTP(s) requests (default 10)
--timeout | Seconds to wait before timeout connection
--proxy | Start The Connection with http(s) proxy
--cookies | HTTP Cookie header value (e.g. "PHPSESSID=a8d127e..")
--encode | How Many encode the payload (default 1)
--allow-redirect | Allow the main redirect
--verify | Skip HTTPS Cert Error
--user-agent | add custom user-agent
--scan-headers | Try to inject payloads in headers not parameters (user-agent,referrer)
--skip-headers | Skip The Headers scanning processe
--sleep | Sent one request after some Seconds
--batch | Never ask for user input, use the default behavior
--module | add custom module (e.g. "google.py")
โ ๏ธ Input Example โ ๏ธ
$ python3 ICAscanner -u 'http://localhost/dvwa/vulnerabilities/exec/' --data='ip=localhost&Submit=Submit' --cookies='PHPSESSID=safasf'