User-Agent , X-Forwarded-For and Referer SQLI Fuzzer made with python
Works on linux and unix based systems
Installation
pip
sudo pip install userefuzz
setup
git clone https://github.com/root-tanishq/userefuzz
cd userefuzz
sudo python3 setup.py install
Usage
Parsing URLs
Parsing a list of URLs
$ userefuzz -l <LIST>
Parsing a URL
$ userefuzz -u <URL>
Parsing stdin URLs
$ <STDIN LIST> | userefuzz
Use
-vswitch for verbose(includes non-vuln detected URLs) output
Multi Processing
Multi Processing will create more process and will increase the speed of the tool.
$ userefuzz <LIST / URL> -w <WORKER COUNT>
Proxy Interception And Custom Injection
Proxy interception of vulnerable request
$ userefuzz <LIST/URL> -p <PROXY>
Custom message in request
$ userefuzz <LIST/URL> -m <MESSAGE>
Custom payload with custom sleep
Replace
sleep timewith$UFZ$variable for double verification of userefuzz
$ userefuzz <LIST/URL> -i <CUSTOM SQLI PAYLOAD> -s <SLEEP COUNT IN THE PAYLOAD>
Multi payload with custom sleep
Replace
sleep timewith$UFZ$variable for double verification of userefuzz
$ userefuzz <LIST/URL> -i <SQLI PAYLOAD FILE> -s <SLEEP COUNT IN THE PAYLOAD>
Custom header injection
$ userefuzz <LIST/URL> -ch <CUSTOM HEADER NAME>
Multi header injection
For multiple headers use
|as shown below.
$ userefuzz <LIST/URL> -ch <CUSTOM HEADER NAME|OTHER HEADERS>
Output
Markdown output
$ userefuzz <LIST/URL> -o <OUTPUT FILE NAME WITHOUT EXT>
Output file content
Metadata
Release files for userefuzz 2.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| userefuzz-2.2.0.tar.gz | 7.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| userefuzz-2.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.9 kB
Release files / userefuzz-2.2.0.tar.gz
| Download URL | userefuzz-2.2.0.tar.gz |
|---|---|
| Size | 7.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b79be0dceec09032d270e7812e8eadac2d1acdeee0fced9987a2bcd11e25cc5f
|
|
BLAKE2b-256 checksum How to use checksums |
452fc888cb6114f9af2f86b76443c2e4f9694b66fd474dd940ac9928b62de4b8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.2
|
Release files / userefuzz-2.2.0-py3-none-any.whl
| Download URL | userefuzz-2.2.0-py3-none-any.whl |
|---|---|
| Size | 7.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2f472f096eafeb31b4a3e1fea34050088e0e4bb0d0e630fc2c2f462c98d6b7cd
|
|
BLAKE2b-256 checksum How to use checksums |
4c5ec86cd7e22b078972a0b33cd51d39da2ad01188725a2756b450a7f27667a5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.2
|