chevron_left chevron_right
Login Register invert_colors photo_library
Thread Rating:
  • 0 Vote(s) - 0 Average


filter_list Sn1per - Automated Pentest Recon Scanner
Author
Message
Sn1per - Automated Pentest Recon Scanner #1
Sn1per - Automated Pentest Recon Scanner

Sn1per is an automated scanner that can be used during a penetration test to enumerate and scan for vulnerabilities.

git clone https://github.com/1N3/Sn1per
chmod +x install.sh
./install.sh
sniper example.com

[Image: Sn1per.jpg]

FEATURES
• Automatically collects basic recon (ie. whois, ping, DNS, etc.)
• Automatically launches Google hacking queries against a target domain
• Automatically enumerates open ports via NMap port scanning
• Automatically brute forces sub-domains, gathers DNS info and checks for zone transfers
• Automatically checks for sub-domain hijacking
• Automatically runs targeted NMap scripts against open ports
• Automatically runs targeted Metasploit scan and exploit modules
• Automatically scans all web applications for common vulnerabilities
• Automatically brute forces ALL open services
• Automatically test for anonymous FTP access
• Automatically runs WPScan, Arachni and Nikto for all web services
• Automatically enumerates NFS shares
• Automatically test for anonymous LDAP access
• Automatically enumerate SSL/TLS ciphers, protocols and vulnerabilities
• Automatically enumerate SNMP community strings, services and users
• Automatically list SMB users and shares, check for NULL sessions and exploit MS08-067
• Automatically tests for open X11 servers
• Automatically exploit vulnerable JBoss, Java RMI and Tomcat servers
• Auto-pwn added for Metasploitable, ShellShock, MS08-067, Default Tomcat Creds
• Performs high level enumeration of multiple hosts and subnets
• Automatically integrates with Metasploit Pro, MSFConsole and Zenmap for reporting
• Automatically gathers screenshots of all web sites
• Create individual workspaces to store all scan output


Quote:MODES
REPORT: Outputs all results to text in the loot directory for later reference. To enable reporting, append 'report' to any sniper mode or command.
STEALTH: Quickly enumerate single targets using mostly non-intrusive scans to avoid WAF/IPS blocking
DISCOVER: Parses all hosts on a subnet/CIDR (ie. 192.168.0.0/16) and initiates a sniper scan against each host. Useful for internal network scans.
PORT: Scans a specific port for vulnerabilities. Reporting is not currently available in this mode.
FULLPORTONLY: Performs a full detailed port scan and saves results to XML.
WEB: Adds full automatic web application scans to the results (port 80/tcp & 443/tcp only). Ideal for web applications but may increase scan time significantly.
WEBPORTHTTP: Launches a full HTTP web application scan against a specific host and port.
WEBPORTHTTPS: Launches a full HTTPS web application scan against a specific host and port.
NOBRUTE: Launches a full scan against a target host/domain without brute forcing services.
AIRSTRIKE: Quickly enumerates open ports/services on multiple hosts and performs basic fingerprinting. To use, specify the full location of the file which contains all hosts, IP's that need to be scanned and run ./sn1per /full/path/to/targets.txt airstrike to begin scanning.
NUKE: Launch full audit of multiple hosts specified in text file of choice. Usage example: ./sniper /pentest/loot/targets.txt nuke.
LOOT: Automatically organizes and displays loot folder in your browser and opens Metasploit Pro and Zenmap GUI with all port scan results. To run, type 'sniper loot'.
UPDATE: Checks for updates and upgrades all components used by sniper.

Quote:USAGE
sniper <target> <report>
sniper <target> stealth <report>
sniper <CIDR> discover
sniper <target> port <portnum>
sniper <target> fullportonly <portnum>
sniper <target> web <report>
sniper <target> webporthttp <port>
sniper <target> webporthttps <port>
sniper <target> nobrute <report>
sniper <targets.txt> airstrike <report>
sniper <targets.txt> nuke <report>
sniper loot
sniper update
(This post was last modified: 10-02-2017, 10:52 PM by Locked. Edit Reason: Bad English )
Locked.

Reply

RE: Sn1per - Automated Pentest Recon Scanner #2
What is that in the photo? It looks like a tablet.
[Image: Y3jduas.png]

Reply

RE: Sn1per - Automated Pentest Recon Scanner #3
Just making you aware that the link you've provided Is not working.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: Sn1per - Automated Pentest Recon Scanner #4
(10-02-2017, 03:57 PM)mothered Wrote: Just making you aware that the link you've provided Is not working.
Sorry, the problem has already been fixed.
Locked.

Reply

RE: Sn1per - Automated Pentest Recon Scanner #5
(10-02-2017, 10:51 PM)Locked Wrote: Sorry, the problem has already been fixed.

All good, I just brought It to your attention as an awareness factor.

Thanks for updating It.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: Sn1per - Automated Pentest Recon Scanner #6
Looks like a cool tool. I love seeing new tools arise like this. I will take a look at the source code and see if I can learn some stuff myself! Thanks.
#yellowheartsforsarah

[+] 1 user Likes Synthx's post
Reply

RE: Sn1per - Automated Pentest Recon Scanner #7
Ill take a look at this thanks a lot bro

[+] 1 user Likes MesaGFX's post
Reply

RE: Sn1per - Automated Pentest Recon Scanner #8
I have this tool.. In need of how to get it cheap? buzz me up on eazihacker at gmail dot com . I will tell u where to find me at MIT campus

Reply

RE: Sn1per - Automated Pentest Recon Scanner #9
(10-09-2017, 03:40 AM)mayweather Wrote: I have this tool.. In need of how to get it cheap?  

I'm not following here. What do you mean by "cheap?".

As per the OP's link, the tool Is available on GitHub.
[Image: AD83g1A.png]

Reply

RE: Sn1per - Automated Pentest Recon Scanner #10
Why would you come here, post the room for cheap when it's a free tool and then post your email... Please take that shit back to hackforums bro lol
@Skullmeat @phyrrus9 @Bish0pQ @mr.kurd and @Ender are my best friends on SL

Reply






Users browsing this thread: 1 Guest(s)