Arjun v1.3 – HTTP Parameter Discovery Suite

0
5
Arjun v1.3 - HTTP Parameter Discovery Suite

Features

  • Multi-threading
  • Four modes of detection
  • A typical scan takes 30 seconds
  • Regex powered heuristic scanning
  • Huge checklist of 25,980 parameter names
  • Makes simply 30-35 requests to the goal


Usage

Note: Arjun would not work with python < 3.4

Discover parameters
To discover GET parameters, you may merely do:
python3 arjun.py -u https://api.instance.com/endpoint --get
Similarly, use --post to search out POST parameters.

Multi-threading
Arjun makes use of 2 threads by default however you may tune its performance in line with your community connection.
python3 arjun.py -u https://api.instance.com/endpoint --get -t 22

Delay between requests
You can delay the request by utilizing the -d choice as follows:
python3 arjun.py -u https://api.instance.com/endpoint --get -d 2

Including presistent knowledge
Let’s say you’ve gotten an API key that you want to ship with each request, to inform Arjun to try this you should utilize the --include choice as follows:
python3 arjun.py -u https://api.instance.com/endpoint --get --include 'api_key=xxxxx'
OR
python3 arjun.py -u https://api.instance.com/endpoint --get --include '{"api_key":"xxxxx"}'
To embrace a number of parameters, use & to seperate them or cross them as a legitimate json object.

JSON Output
You can save the lead to a JSON format by utilizing the -o as follows:
python3 arjun.py -u https://api.instance.com/endpoint --get -o outcome.json

Adding HTTP Headers
Using the --headers change will open an interactive immediate the place you may paste your headers. Press Ctrl + S to save lots of and Ctrl + X to procced.

Note: Arjun makes use of nano because the default editor for the immediate however you may change it by tweaking /core/immediate.py.

Credits
The parameter names are taken from @SecLists.

MoreTip.com

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.