Introducing Snallygaster - a Tool to Scan for Secrets on Web Servers

Hanno's Blog

Wednesday, April 11. 2018

Introducing Snallygaster - a Tool to Scan for Secrets on Web Servers


Trackbacks

No Trackbacks

Comments
Display comments as (Linear | Threaded)

> the tool that comes closest is probably Nikto, but testing it I felt it comes with a lot of checks - thus it's slow [..]

I am afraid that as soon as people start contributing to Snallygaster it will share the same fate ("slow") as there will be just more URLs to test for. Or what do you think?
#1 Dirk (Homepage) on 2018-04-11 21:06 (Reply)
We will see :-)

I intend to not add every imaginable test, but try to keep some balance. I wrote something about that in CONTRIBUTING.md - i.e. I want to have a good balance between test cost (in time), prevalence and impact of findings.
#1.1 Hanno (Homepage) on 2018-04-11 21:09 (Reply)
Hi,
do you know the SecList Project? https://github.com/danielmiessler/SecLists

So most of the files you are searching for are already there for example in
https://github.com/danielmiessler/SecLists/blob/befbd5b20d1a74e229d1407fc1e68df055fd5dc3/Discovery/Web-Content/quickhits.txt

So just using Burp intruder or something like patator brings simular results, ...
#2 Horst (Homepage) on 2018-04-11 21:58 (Reply)

Add Comment

E-Mail addresses will not be displayed and will only be used for E-Mail notifications.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

 
 

About

This blog is written by Hanno Böck. Unless noted otherwise, its content is licensed as CC0.

You can find my web page with links to my work as a journalist here.

I am also publishing a newsletter about climate change and decarbonization technologies.

The blog uses the free software Serendipity and is hosted at schokokeks.org.

Hanno on Mastodon | Contact / Imprint | Privacy / Datenschutz