A Vulnerability Scanning Tools For Penetration Testing
Download • Contributors • PoC
不动明王 |
雪山 |
White-hua |
123456 |
ifofor |
Air |
执着 |
purple-WL |
throat |
Secx |
冰河 |
Sheen |
a16 |
A1 |
rainbow2972 |
wuha0926 |
茄子 |
lei_sec |
G-H-Z |
wh1te |
清月 |
york |
7eleven.eth |
Double-q1015 |
ICEY_ |
lazy |
Lay0us |
m4sk |
沉默树人 |
陈麻子 |
leonardo-o1 |
江湖人称魏神 |
若兮风 |
-sudo |
Cuerz |
laohuan12138 |
afrog is an excellent performance, fast and stable, PoC customizable vulnerability scanning (hole digging) tool. PoC involves CVE, CNVD, default password, information leakage, fingerprint identification, unauthorized access, arbitrary file reading, command execution, etc. It helps network security practitioners quickly verify and fix vulnerabilities in a timely manner.
- Open Source
- Fast, stable, low false positives
- Detailed html vulnerability report
- PoC can be customized and updated stably
- Active community exchange group
Basic usage
# Scan a target
afrog -t https://127.0.0.1
# Scan multiple targets
afrog -T urls.txt
# Specify a scan report file
afrog -t https://127.0.0.1 -o result.html
Advanced usage
# Test PoC
afrog -t https://127.0.0.1 -P ./test/
afrog -t https://127.0.0.1 -P ./test/demo.yaml
# Scan by PoC Keywords
afrog -t https://127.0.0.1 -s tomcat,springboot,shiro
# Scan by PoC Vulnerability Severity Level
afrog -t https://127.0.0.1 -S high,critical
# Online update afrog-pocs
afrog -up
# Disable fingerprint recognition
afrog -t https://127.0.0.1 -nf
For WeChat group, please add afrog personal account first, and remark "afrog", and then everyone will be pulled into the afrog communication group.
afrog has joined 404Starlink
This tool is only for legally authorized enterprise security construction behavior. If you need to test the usability of this tool, please build a target environment by yourself.
In order to avoid malicious use, all PoCs included in this project are theoretical judgments of vulnerabilities, there is no vulnerability exploitation process, and no real attacks or exploits will be launched on the target.
When using this tool for detection, you should ensure that the behavior complies with local laws and regulations and has obtained sufficient authorization. **Do not scan unauthorized targets. **
If you have any illegal behavior in the process of using this tool, you shall bear the corresponding consequences by yourself, and we will not bear any legal and joint responsibility.
Before installing and using this tool, please must read carefully and fully understand the contents of each clause. Restrictions, disclaimers or other clauses involving your significant rights and interests may be bolded or underlined to remind you to pay attention . Unless you have fully read, fully understood and accepted all the terms of this agreement, please do not install and use this tool. Your use behavior or your acceptance of this agreement in any other express or implied manner shall be deemed that you have read and agreed to be bound by this agreement.