nskge/abaddon
GitHub: nskge/abaddon
Abaddon 是一款模块化异步 Web 漏洞扫描器,通过模板驱动引擎与编排化扫描在授权测试中自动检测十余类 Web 漏洞并提供攻击路径关联。
Stars: 0 | Forks: 0
# Abaddon
```
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡀⠀⠀⠀⠀⠀⢡⡀⢀⣠⣤⠤⠷⠤⣤⣄⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠳⣄⠀⠀⣀⡴⠟⠉⢠⡀⠠⢤⣄⣠⠀⠉⠻⢦⡀⠀⢀⡴⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣠⠄⠀⠀⠈⢳⡞⠉⠀⠀⠀⣠⡇⢀⠄⠀⢷⡀⠀⠀⠀⠘⣶⡋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣰⡟⠉⠒⠦⣄⣠⡏⠀⠀⠀⠀⢰⣿⢀⣴⣶⣦⡄⣻⠄⢀⢀⣠⣤⢧⣄⣠⠤⠒⠂⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⢀⣤⣶⣶⣿⡋⠀⠀⠀⠀⠀⡟⠀⠀⢠⣠⠀⠀⠹⣿⣿⣿⣿⣿⠋⠀⠈⡍⠀⠀⠈⣿⠀⠀⠀⠀⠒⢦⠀⠐⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⢀⣴⣿⣿⣿⣿⡏⠀⠀⠀⣀⣀⣸⠁⠀⠀⣆⠙⣿⣆⢠⣿⣷⣿⣿⣷⠀⣠⣾⣷⡞⠀⠀⢹⣀⣀⣀⣀⠀⢸⣷⣧⣤⣀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⢀⣼⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠸⡄⠀⢀⡘⢦⣿⣿⣿⣿⣿⣿⣿⣿⣶⣿⣿⣩⠇⡀⠀⢸⠀⠀⠀⠀⠉⢸⣿⣿⣿⣮⡁⡀⠀⠀⠀⠀
⠀⠀⠀⣠⣿⣿⣿⣿⣿⣿⣿⣿⣿⢄⡀⠀⠀⠀⢀⣷⡸⣄⣙⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣖⡚⠁⢀⣞⡀⠀⠀⠀⢠⣿⣿⣿⣿⣿⣿⡴⣔⠀⠀⠀
⠀⠀⣸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⡀⠀⠐⠺⡏⣍⣁⠀⣽⣿⣿⣿⣿⣿⣿⣽⣿⣯⣽⣿⣿⣿⣍⢁⡜⠉⠉⠓⢤⣄⣾⣿⣿⣿⣿⣿⣿⣿⣿⣄⠀⠀
⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⡀⠠⣷⣿⣗⡤⠈⣹⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠻⠛⢤⡀⠀⠀⣨⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡆⠀
⠀⣿⣿⣿⣿⣿⠿⢿⣿⣿⠿⢿⣿⣿⣿⣿⣷⡀⠈⣿⣿⣄⠀⣿⣿⣿⠁⠹⣿⣿⣿⣿⣿⢿⣿⣗⠀⠀⠀⠉⠂⣠⣿⣿⡿⠿⣿⣿⣿⣿⣿⣿⣿⣿⣷⠀
⢀⡿⡿⠉⣿⡟⠀⢸⣿⠏⠀⠀⢹⠿⠿⢿⣿⣷⣄⠚⢿⣿⣿⣿⡿⠃⢈⣹⣿⣿⣿⣿⣿⡎⢿⣿⣇⠀⠀⣶⣴⣿⣿⣿⣿⣻⣿⣿⣿⣿⣿⣿⣿⣿⣿⡄
⢸⣿⣿⣾⣿⡇⠀⢸⠋⠀⠀⠀⠸⠀⠀⠀⠉⠛⣿⣷⣟⣙⠿⣿⡁⣠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣾⡿⢿⣿⠟⢿⡏⠀⢸⠉⠁⠀⠈⢹⢿⣿⣿⣿⡇
⢸⣿⣿⣿⣿⡇⠀⠾⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠻⠍⠛⢿⠷⣶⣽⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⢿⣿⣆⠀⠁⠀⠀⠀⠀⠈⠀⠀⠀⠀⠞⠀⠘⣿⣿⣟
⢸⣿⣿⣏⣿⡗⠀⠀⠀⠀⠀⠀⣠⠒⠊⠉⠉⠉⢉⣒⠦⣄⠀⣸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⣤⣿⣿⠿⠶⠶⢤⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⣿⣿⡇
⠘⣿⣷⣿⡝⠁⠀⠀⠀⠀⠀⠉⢁⠀⠀⠀⠀⠀⠀⠈⢹⣮⣿⣿⣟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠙⠀⠀⠀⠀⠀⠀⠈⠛⢆⠀⠀⠀⠀⠀⠀⠀⠋⢻⡇
⠀⠻⣿⣤⠁⠀⠀⠀⠀⠀⣤⠈⠋⠀⠀⠀⠀⠀⠀⠀⠈⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠳⡄⠀⠀⠀⠀⠀⢠⡿⠁
⠀⠀⢻⣧⡀⠀⠀⠀⠀⠀⢸⡀⠀⠀⠀⠀⠀⠀⢀⣤⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⡀⠀⠀⠀⠀⣼⠃⠀
⠀⠀⠈⢿⡄⠀⠀⠀⠀⠀⠙⣧⠀⠀⠀⠀⠀⠀⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢠⣧⠀⠀⣀⡼⠁⠀⠀
⠀⠀⠀⠀⠙⢶⡀⠀⠀⠀⠀⢿⣷⠀⠀⢀⣠⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠓⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⡟⠀⠀⠛⠁⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠉⠀⠀⠀⠙⠏⠉⠀⣠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣿⢿⣿⣿⣿⣿⣿⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣸⠁⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⣿⣿⣿⣿⣿⣿⣿⣟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⡼⠃⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣟⣷⣀⠀⠀⠀⠀⠀⠀⠀⠀⢀⠞⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⢠⣞⣿⣿⣿⣿⣿⣿⣿⣼⣿⣿⣿⡿⣾⢻⣿⣿⡟⢻⣿⣿⣿⣿⣿⣿⠙⠳⢤⣀⣀⣀⣠⡤⠖⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⢨⣿⣿⣿⣿⣿⣿⣿⠇⣿⣿⣿⣿⢳⣿⣿⣿⣿⡇⣾⣿⣿⣿⣿⣿⠹⠄⠀⠀⠀⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⢠⣿⣿⣿⣟⣿⣿⣿⣿⣻⣿⣾⣿⣿⢸⣿⣿⣿⣿⡇⣿⣿⣿⢹⣿⣿⣇⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⣾⣅⡿⣫⠟⣿⣿⡿⢹⡿⠿⣿⣿⣧⢸⣿⣿⣿⣿⠇⣿⣿⠇⡞⣿⡏⠉⢷⠴⠂⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⣸⡿⠿⠟⠁⠀⡇⢸⡇⢀⣧⡤⢰⣿⡟⢸⡇⡏⢹⣿⠀⣿⡟⠀⢳⣿⡇⠠⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠞⠁⠀⠀⡠⠀⠀⠁⣿⠃⢸⣿⠙⢺⣻⡗⠸⡇⠡⢸⣿⣰⠈⠀⠀⢘⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠉⢸⠁⠀⠀⠀⣿⠀⠘⣿⡄⠀⠁⠁⠀⠃⠀⠈⣿⠿⠀⠀⠀⠘⠀⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⠀⠀⠙⡇⠀⠀⠀⠀⠀⠀⢀⣏⣥⠀⠀⠀⢠⣤⠔⠀⠦⠤⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡙⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
A B A D D O N
async offensive engine · authorized testing only
╭─ MENU ───────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ 1 Quick Scan Run every module against a target │
│ 2 Single Module Pick one vulnerability class │
│ 3 Abaddon Engine Async template-based scan (OAST, fuzzing) │
│ 4 Recon Tools Port scan / path & subdomain discovery │
│ 5 Options Threads, proxy, scope, WAF evasion, timeout │
│ 6 Help / About Usage and safety notes │
│ 0 Exit Leave Abaddon │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯
```
为渗透测试人员和漏洞赏金猎人构建的**模块化 + 异步 Web 漏洞扫描器**。
交互式菜单、暗紫色 TUI 以及模板驱动的异步引擎。 —— **v2.13.0}
## 模块
| 模块 | 检测内容 |
|--------|-----------------|
| **SQLi** | 基于错误、布尔盲注、时间盲注 (MySQL / MSSQL / Oracle / PostgreSQL / SQLite) |
| **XSS** | 带上下文检测的反射型 XSS (HTML / 属性 / JavaScript) |
| **LFI** | 路径遍历、PHP filter wrapper、编码绕过、空字节 |
| **CMDi** | OS 命令注入 —— 基于输出 + 基于时间 (Unix 和 Windows) |
| **SSTI** | 模板注入 (Jinja2, Twig, Freemarker, Mako, ERB, Smarty, Velocity) |
| **CRLF** | Header 注入、Set-Cookie 注入、响应拆分 |
| **Redirect** | 通过 Location、meta-refresh、JavaScript 实现的开放重定向 |
| **Headers** | 缺失的安全 Header、服务器信息泄露、CORS 错误配置 (被动通配符 + 主动反射来源探测) |
| **JWT** | alg:none 绕过、弱 HS256 密钥暴力破解、敏感 payload 字段 |
| **SSRF** | 云元数据 (AWS/GCP/Azure)、localhost、内部服务 (Redis/ES/k8s) —— 并行探测 |
| **XXE** | 原始 XML POST、XML 参数注入、XML 提示参数 —— 6 种 payload 变体 |
| **403 Bypass** | Header 欺骗 (X-Original-URL, X-Forwarded-For, …)、路径操纵 (16 种变体)、动词篡改 |
| **GraphQL** | 自省暴露、GraphiQL/Playground IDE、批量查询、字段建议 —— 探测 12 个常见 endpoint 路径 |
| **IDOR** | 数字 ID 和 UUID 参数枚举、路径段 ID 遍历 —— 双基线稳定性防护、大小相似性门控以抑制误报 |
| **CVE 检测** | 涵盖 14 种服务 (Apache, Nginx, PHP, IIS, Tomcat, OpenSSL, jQuery, WordPress, Drupal, Struts, Spring, WebLogic, Confluence, Joomla) 的 34 个 CVE,包含 CVSS、Metasploit 模块、NVD 链接 |
## 功能
- **侦察阶段** —— 在每次扫描前进行 DNS、IP、延迟、服务器/技术指纹、CVE 检查
- **经过身份验证的、编排化的扫描** (`--auth-user`/`--auth-pass`, `--orchestrated`) —— 仅登录一次,为应用爬取 + 所有模块重用 session,并运行具有 session 感知的检查:**认证绕过 SQLi**、**破坏的访问控制** (authz 矩阵)、**批量赋值**、**IDOR/BOLA** (双重身份)、**存储型/二阶 XSS** 和 **CSRF**
- **带外 (OAST) 检测** —— 盲测和二阶发现 (例如仅在管理员浏览器中触发的存储型 XSS) 通过本地回调监听器和捕获日志轮询进行确认,然后重放被盗取的 session 以提取受限的机密信息
- **静态目标检测** —— 检测 CDN/SPA 目标 (缓存 Header + 响应哈希) 并自动跳过注入模块以消除误报
- **差分时间确认** —— 盲时间型 SQLi/CMDi 候选对象将在 2 倍睡眠时间下重新测试,并且仅在延迟成比例缩放时才报告,从而消除延迟高峰导致的误报
- **布尔重新确认** —— 布尔盲注 SQLi 信号必须在报告之前在第二次请求中重现 (动态页面误报防护)
- **攻击路径关联** —— Bloodhound 风格的链接将已确认的发现组合成提权路径 (例如 SQLi + 弱 JWT → 账户接管,SSRF → 云凭据窃取),显示在控制台和 JSON 中
- **感知 JS 的爬取** —— 通过 Playwright 驱动无头 Chromium;点击模态框/按钮 (Register, Login, Cadastrar…),拦截 XHR/Fetch,查找没有 `name` 属性的输入框 (`--js-crawl`)
- **子域接管** —— CNAME 链解析 → 未声明服务指纹检查 (12 种服务)
- **端口扫描器** —— 并发 TCP 探测 31 个常见端口并抓取 banner (`--port-scan`)
- **路径发现** —— 并发探测 130 个常见路径 (`--discover-paths`)
- **子域名枚举** —— 通过 DNS 解析 80 个常见前缀 (`--discover-subs`)
- **WAF 绕过** —— 跨越 3 个逐级递增级别的 6 种 payload 转换 (`--waf-evasion 1|2|3`)
- **自适应限流器** —— 遇到 429/503 时进行指数退避,遇到 200 时自动恢复 (`--rate-limit`)
- **漏洞赏金模式** —— 范围验证、X-Bug-Bounty Header、UA 程序标签 (`--bb-note`, `--scope`)
- **Ctrl+C 恢复** —— 优雅中断,返回迄今为止收集的所有发现
- **并发扫描** —— 模块并行运行 (可配置 `--threads`)
- **报告导出** —— TXT 和 JSON 格式,包含 curl + msfconsole 复现步骤
- **ABADDON 异步引擎** —— 可选的高并发核心 (`python -m abaddon`):`httpx.AsyncClient` + HTTP/2,Nuclei 风格的 YAML 模板 (Pydantic V2 验证),智能匹配器 (OAST 带外、时间/熵差分、上下文感知反射) 与多信号**置信度关联**,每主机自适应限流,以及用于 SIEM 的 JSONL 输出
- **424 个单元测试** —— 外加 `tools/ctf_recall.py`,用于测量针对具有基准真实性的 CTF 的检测召回率 (目前为 **9/9**)
## 安装
```
git clone https://github.com/nskge/abaddon.git
cd abaddon
pip install -r requirements.txt
# JS 感知 crawl(可选)
pip install playwright && python -m playwright install chromium
```
**要求:** Python 3.10+
```
python main.py # launch the interactive menu
python main.py --version # Abaddon v2.13.0
```
## 菜单
运行时不带参数即可进入交互式 TUI:
```
python main.py
python -m abaddon
```
```
1 Quick Scan Run all modules against a target URL
2 Single Module Pick one vulnerability class (SQLi, XSS, IDOR, …)
3 Abaddon Engine Async template scan — OAST, fuzzing, confidence correlation
4 Recon Tools Port scan + path and subdomain discovery
5 Options Threads, proxy, scope globs, WAF evasion level, timeout
6 Help / About Usage notes and version info
0 Exit
```
经典的基于 flag 的 CLI 仍然可用 —— 在 `main.py` 之后的任何参数都会跳过菜单。
## 用法
```
# 完整扫描 — 所有模块,所有参数
python main.py -u "http://target/page?id=1"
# 异步 template 引擎(OAST, fuzzing, confidence correlation)
python -m abaddon -u "http://target/" --scope "*.target.com"
# 自动检测并测试 HTML forms
python main.py -u "http://target/search.php" --crawl
# 特定模块针对特定参数
python main.py -u "http://target/page?id=1" --scan-type sqli -p id
# POST form
python main.py -u "http://target/login" -m POST -d "user=admin&pass=x" --scan-type xss
# Recon 附加项:端口扫描 + 路径发现
python main.py -u "http://target/?id=1" --port-scan --discover-paths --discover-subs
# WAF evasion 级别 2
python main.py -u "http://target/?q=1" --waf-evasion 2
# 自适应速率限制器(请求间至少 0.3s)
python main.py -u "http://target/?id=1" --rate-limit --rate-delay 0.3
# 带 scope 检查的 Bug bounty 模式
python main.py -u "http://api.target.com/?url=x" \
--scan-type ssrf \
--bb-note researcher@example.com \
--bb-program h1/target-slug \
--scope "*.target.com"
# 对受保护 endpoint 进行 403 bypass
python main.py -u "http://target/admin?x=1" --scan-type bypass403
# 经过认证的、编排化的扫描 — 登录 + crawl + session 感知检查
# (auth-bypass, broken access, mass assignment, IDOR/BOLA, stored XSS, CSRF)
python main.py -u "http://target/" --auth-user alice --auth-pass secret --login-url /login
# 添加第二个身份以进行跨账户 IDOR/BOLA 确认
python main.py -u "http://target/" --auth-user alice --auth-pass a \
--auth-user2 bob --auth-pass2 b
# 针对 ground-truth CTF 衡量检测 recall
python tools/ctf_recall.py --base http://127.0.0.1:5000 \
--gabarito ../CaptureTheOkr/expected_findings.json
# JS 感知 crawl — 发现隐藏在 modals/SPA routes 后面的输入
python main.py -u "http://target/" --js-crawl
# GraphQL endpoint 探测
python main.py -u "http://target/" --scan-type graphql
# 通过 Burp Suite 路由
python main.py -u "http://target/?q=test" --proxy http://127.0.0.1:8080
# 导出 JSON 报告
python main.py -u "http://target/?id=1" -o report.json --format json
```
### 选项
```
Target:
-u, --url URL Target URL (required)
-m, --method GET|POST HTTP method (default: GET)
-d, --data POST body e.g. 'user=admin&pass=test'
-p, --param NAME Test only this parameter
Scan options:
--scan-type TYPE sqli|xss|lfi|redirect|cmdi|crlf|ssti|headers|
jwt|ssrf|xxe|bypass403|graphql|idor|all (default: all)
--crawl Auto-detect HTML forms
--js-crawl JS-aware crawl via headless Chromium (finds SPA inputs)
--payloads FILE Custom payload file (one per line)
--delay SECS Time-based detection threshold (default: 5.0)
--threads N Concurrent module threads (default: 4)
--waf-evasion LEVEL 0=off 1=url+null 2=+double+case 3=+html+sql (default: 0)
Authenticated scan:
--auth-user USER Log in and reuse the session everywhere (implies orchestrated)
--auth-pass PASS Password for --auth-user
--login-url URL Login form URL/path (default: /login)
--auth-user2 USER Second identity for cross-account IDOR/BOLA
--auth-pass2 PASS Password for --auth-user2
--orchestrated Run the orchestrated checks without credentials
Recon extras:
--port-scan Fast TCP port scan during recon
--discover-paths Probe 130 common URL paths
--discover-subs Enumerate 80 common subdomains
Rate limiting:
--rate-limit Enable adaptive rate limiter (auto back-off on 429/503)
--rate-delay SECS Minimum delay between requests (default: 0.0)
Bug bounty:
--bb-note EMAIL Add X-Bug-Bounty header identifying you as the researcher
--bb-program SLUG Append BugBounty/slug to User-Agent
--scope PATTERNS Comma-separated glob patterns e.g. '*.example.com'
Aborts scan if target is out of scope
HTTP options:
--headers HEADER ... Extra headers e.g. 'Authorization: Bearer tok'
--cookies COOKIES Cookie string e.g. 'session=abc; role=admin'
--proxy URL HTTP proxy e.g. http://127.0.0.1:8080
--timeout N Request timeout in seconds (default: 10)
--user-agent UA Override User-Agent
--follow-redirects Follow HTTP redirects
Output:
-o, --output FILE Save report to file
--format txt|json Report format (default: txt)
-v, --verbose Debug logging
-q, --quiet Findings only (no banner/recon)
--no-color Disable ANSI colors
```
## 测试
```
python -m pytest tests/ -v # 424 tests
```
## 架构
```
scanner/
├── __init__.py version
├── core.py Scanner orchestrator (recon + parallel module dispatch)
├── http_client.py HTTPClient with rate limiter integration
├── rate_limiter.py AdaptiveRateLimiter (exponential back-off)
├── waf_evasion.py Payload transforms (6 strategies, 3 levels)
├── port_scanner.py Concurrent TCP port scanner
├── discovery.py Subdomain enumeration + URL path discovery
├── cve_db.py CVE database + version matching
├── banner.py ASCII banner
├── parser.py URL/form parsing helpers
├── reporter.py TXT/JSON report writer
├── logger.py Logging setup
└── modules/
├── base.py BaseModule ABC + Finding dataclass
├── sqli.py
├── xss.py
├── lfi.py
├── cmdi.py
├── ssti.py
├── crlf.py
├── open_redirect.py
├── headers.py
├── jwt_analyzer.py
├── ssrf.py
├── xxe.py
├── bypass403.py
├── graphql.py
└── idor.py
js_crawler.py Playwright-based JS crawl for SPA/modal input discovery
abaddon/ Async engine (python -m abaddon)
├── network/
│ ├── engine.py AsyncEngine: httpx.AsyncClient, semaphore, bounded queue
│ ├── throttle.py TokenBucket + per-host AdaptiveThrottle
│ └── evasion.py UA rotation, IP-spoof headers, payload mutation
├── parsers/
│ └── template_engine.py Load + strictly validate YAML templates
├── models/
│ └── schemas.py Pydantic V2 template DSL (extra="forbid")
├── core/
│ ├── matchers.py word/regex/status/time/entropy/reflection/oast matchers
│ ├── correlation.py Multi-signal noisy-OR confidence engine
│ ├── oast.py OAST provider (mock + webhook) for blind detection
│ ├── scope.py Allowlist enforcement (host glob + CIDR)
│ ├── runner.py Scanner orchestration + {{oast}}/{{marker}} interpolation
│ └── logger.py structlog console + JSONL result sink
├── templates/ Bundled YAML templates
└── cli.py rich CLI
```
### 添加模块 (经典引擎)
1. 创建 `scanner/modules/mymodule.py` —— 继承 `BaseModule` 子类,实现 `scan_parameter()`
2. 在 `scanner/core.py` 的 `_MODULE_MAP` 中注册
3. 添加到 `main.py` 中的 `--scan-type` 选项中
### 添加 ABADDON 模板
将一个 `.yaml` 文件放入 `abaddon/templates/` 目录中 (加载时将根据 `abaddon/models/schemas.py` 进行验证)。无需 Python 代码:
```
id: my-check
info: {name: My Check, severity: high}
requests:
- method: GET
path: ["/admin"]
matchers-condition: and
matchers:
- {type: status, status: [200], confidence: 0.4}
- {type: word, words: ["dashboard"], confidence: 0.6}
```
## 免责声明
**Abaddon 仅用于合法、授权的安全测试。**
1. **仅限授权使用。** 仅测试您拥有或获得明确书面许可进行测试的系统。
2. **无责任。** 按“原样”提供,不提供任何担保。作者对因使用或不当使用造成的损害或法律后果不承担任何责任。
3. **您的责任。** 在测试任何目标之前,请确保遵守所有适用法律。
4. **不保证准确性。** 在报告之前,手动验证所有发现。
未经授权的访问是犯罪行为 (CFAA, Computer Misuse Act, Art. 154-A Brazilian Penal Code)。
## 许可证
[MIT 许可证](LICENSE)
标签:CISA项目, Web安全, XSS检测, 特征检测, 蓝队分析, 逆向工具