3 ms·
Toy project: an HTTP(S) brute forcing tool using Python as a templating language. Why is it cool: high performance using async IO, powerful templating for Pytho
by bitexploder 13y ago
Toy project: an HTTP(S) brute forcing tool using Python as a templating language. Why is it cool: high performance using async IO, powerful templating for Python programmers, very easy to take HTTP requests and turn them into a fuzzing template that mutates request in a combinatoric fashion. Similar to features built into Burp proxy for those that are familiar with it.
Real project: A system that will help organizations understand their overall, and application, security risk and manage it across time. Why is it cool: because security is hard and this will make it easier in a non-snake oil fashion. Many organizations are flying blind about their actual risk. A good view of your risk can help you prioritize security budgets.
- meowface 13y agoIn regards to the first one: Sounds like a cool idea. Might I also suggest an overall fuzzing engine? Sulley and Peach Fuzzer both have fairly ugly APIs and config formats, in my opinion. A pretty DSL that lets you describe a template, also with the ability to add custom Python functions and integrate them on the fly, would be great.
- bitexploder 13y agoIt, more or less, has a separate "Fuzzing Template" system which it uses to generate the brute force test cases. It was never meant to rise to the complexity of Sulley's fuzzing system. I wanted an in between complexity for the dumbest fuzzing and something completely flexible like Sulley and Peach. To solve that 80% problem of, "OK, I just grabbed an HTTP request, let's turn it into a quick and dirty fuzzing template." and from that, "And make sure it runs really fast on a single machine". In the time boxed assessment world you rarely have time to do all that you would like so this seemed to be a reasonable solution. I will put it up at http://github.com/bitexploder http://github.com/bitexploder soon (a week? Maybe two?). The beauty of the "fuzzing engine" I built is that there is nothing to it really. You put in "scriptlets", which are really just small bits of Python that generate lists or sequences, and it combines all of them. My goal was to just write up a lot of the common HTTP fuzzing scenarios (integer sequences, alphabetical sequences, demonstrate common encoding and other scenarios giving you a simple list of things you can copy/paste/modify into a template. And then it runs, logging it all into a SQLite database.
- meowface 13y agoCertainly sounds interesting. I'll be sure to check it out.
- tkmop 13y agoI'd really like to take a look at your fuzzing project. Is it opensource? I'm coding something quite simular at the moment and would like to leech from / contribute to / test your project. If you're interested - tkmop / lenta.ru
- bitexploder 13y agoIt will be. It has languished for a very long time, but I have resolved to get it out the door soon. I will put it up on a github repo (https://github.com/bitexploder https://github.com/bitexploder) so watch there.