Skip to main content

Nemesis

Nemesis Code Grade Code Quality

Description

A simple tool for scanning urls for vulnerabilites and sensitive information. It has lot of pre defined regexes for dom xss possibility detection, secrets leakage, hidden parameters, extra links and much more.

Features

  1. Supports scanning of both html and javascript urls
  2. Pre defined regexes for dom xss (sinks & sources), web services, hidden parameters, endpoints and a lot more are already present.
  3. Shannon entropy helps to find additional suspicious data that can be missed by regexes but may generate false positive so disabled by default.

Usage

usage: Nemesis.py [-h] [--- | -w WORDLIST | -u URL] [-o OUTPUT] [-e] [-t THREADS] [-b]

Nemesis

optional arguments:
  -h, --help            show this help message and exit
  ---, ---              Stdin
  -w WORDLIST, --wordlist WORDLIST
                        Absolute path of wordlist
  -u URL, --url URL     url to scan
  -o OUTPUT, --output OUTPUT
                        Output file
  -e, --enable-entropy  Enable entropy search
  -t THREADS, --threads THREADS
                        Number of threads
  -b, --banner          Print banner and exit

Enjoy bug hunting

Example

  1. Scan a single url
  • Nemesis -u google.com or Nemesis -u https://google.com/closurelibrary.js
  1. Scan from URLs
  • Nemesis -w hakrawler.txt

Limitations

  • Output maybe repeated such as same links again and again
  • Output to file saving is in work
  • Additional logical errors and false positivies from faulty regex

Support

If you wanted to support me freely for the tools I create, chekout this out.

Release files for nemesis-scan 1.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for nemesis-scan 1.0.4
File Size Uploaded
nemesis-scan-1.0.4.tar.gz 9.4 kB Details

Release files / nemesis-scan-1.0.4.tar.gz

Download URL nemesis-scan-1.0.4.tar.gz
Size 9.4 kB
Tags Source
SHA-256 checksum
How to use checksums
49a51e1024621cf8ad8cd9918297efd379ab933faa43d75b0b25ee27dd91f1bc
BLAKE2b-256 checksum
How to use checksums
5ad629f85e9e936c92d3b85398d56d140e0a88a8c924c00b98cafbd4361ca4e6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.4.2 importlib_metadata/4.8.1 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.7

Release history Release notifications | RSS feed

This release

1.0.4 This release

1 release file

1.0.3

1 release file

1.0.2

1 release file

1.0.1

1 release file

1.0.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page