nskge/abaddon

GitHub: nskge/abaddon

Abaddon 是一款模块化异步 Web 漏洞扫描器,通过模板驱动引擎与编排化扫描在授权测试中自动检测十余类 Web 漏洞并提供攻击路径关联。

Stars: 0 | Forks: 0

# Abaddon ``` ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡀⠀⠀⠀⠀⠀⢡⡀⢀⣠⣤⠤⠷⠤⣤⣄⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠳⣄⠀⠀⣀⡴⠟⠉⢠⡀⠠⢤⣄⣠⠀⠉⠻⢦⡀⠀⢀⡴⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣠⠄⠀⠀⠈⢳⡞⠉⠀⠀⠀⣠⡇⢀⠄⠀⢷⡀⠀⠀⠀⠘⣶⡋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣰⡟⠉⠒⠦⣄⣠⡏⠀⠀⠀⠀⢰⣿⢀⣴⣶⣦⡄⣻⠄⢀⢀⣠⣤⢧⣄⣠⠤⠒⠂⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⢀⣤⣶⣶⣿⡋⠀⠀⠀⠀⠀⡟⠀⠀⢠⣠⠀⠀⠹⣿⣿⣿⣿⣿⠋⠀⠈⡍⠀⠀⠈⣿⠀⠀⠀⠀⠒⢦⠀⠐⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⢀⣴⣿⣿⣿⣿⡏⠀⠀⠀⣀⣀⣸⠁⠀⠀⣆⠙⣿⣆⢠⣿⣷⣿⣿⣷⠀⣠⣾⣷⡞⠀⠀⢹⣀⣀⣀⣀⠀⢸⣷⣧⣤⣀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⢀⣼⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠸⡄⠀⢀⡘⢦⣿⣿⣿⣿⣿⣿⣿⣿⣶⣿⣿⣩⠇⡀⠀⢸⠀⠀⠀⠀⠉⢸⣿⣿⣿⣮⡁⡀⠀⠀⠀⠀ ⠀⠀⠀⣠⣿⣿⣿⣿⣿⣿⣿⣿⣿⢄⡀⠀⠀⠀⢀⣷⡸⣄⣙⣷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣖⡚⠁⢀⣞⡀⠀⠀⠀⢠⣿⣿⣿⣿⣿⣿⡴⣔⠀⠀⠀ ⠀⠀⣸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⡀⠀⠐⠺⡏⣍⣁⠀⣽⣿⣿⣿⣿⣿⣿⣽⣿⣯⣽⣿⣿⣿⣍⢁⡜⠉⠉⠓⢤⣄⣾⣿⣿⣿⣿⣿⣿⣿⣿⣄⠀⠀ ⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⡀⠠⣷⣿⣗⡤⠈⣹⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠻⠛⢤⡀⠀⠀⣨⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡆⠀ ⠀⣿⣿⣿⣿⣿⠿⢿⣿⣿⠿⢿⣿⣿⣿⣿⣷⡀⠈⣿⣿⣄⠀⣿⣿⣿⠁⠹⣿⣿⣿⣿⣿⢿⣿⣗⠀⠀⠀⠉⠂⣠⣿⣿⡿⠿⣿⣿⣿⣿⣿⣿⣿⣿⣷⠀ ⢀⡿⡿⠉⣿⡟⠀⢸⣿⠏⠀⠀⢹⠿⠿⢿⣿⣷⣄⠚⢿⣿⣿⣿⡿⠃⢈⣹⣿⣿⣿⣿⣿⡎⢿⣿⣇⠀⠀⣶⣴⣿⣿⣿⣿⣻⣿⣿⣿⣿⣿⣿⣿⣿⣿⡄ ⢸⣿⣿⣾⣿⡇⠀⢸⠋⠀⠀⠀⠸⠀⠀⠀⠉⠛⣿⣷⣟⣙⠿⣿⡁⣠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣾⡿⢿⣿⠟⢿⡏⠀⢸⠉⠁⠀⠈⢹⢿⣿⣿⣿⡇ ⢸⣿⣿⣿⣿⡇⠀⠾⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠻⠍⠛⢿⠷⣶⣽⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⢿⣿⣆⠀⠁⠀⠀⠀⠀⠈⠀⠀⠀⠀⠞⠀⠘⣿⣿⣟ ⢸⣿⣿⣏⣿⡗⠀⠀⠀⠀⠀⠀⣠⠒⠊⠉⠉⠉⢉⣒⠦⣄⠀⣸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⣤⣿⣿⠿⠶⠶⢤⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⣿⣿⡇ ⠘⣿⣷⣿⡝⠁⠀⠀⠀⠀⠀⠉⢁⠀⠀⠀⠀⠀⠀⠈⢹⣮⣿⣿⣟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠙⠀⠀⠀⠀⠀⠀⠈⠛⢆⠀⠀⠀⠀⠀⠀⠀⠋⢻⡇ ⠀⠻⣿⣤⠁⠀⠀⠀⠀⠀⣤⠈⠋⠀⠀⠀⠀⠀⠀⠀⠈⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠳⡄⠀⠀⠀⠀⠀⢠⡿⠁ ⠀⠀⢻⣧⡀⠀⠀⠀⠀⠀⢸⡀⠀⠀⠀⠀⠀⠀⢀⣤⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⡀⠀⠀⠀⠀⣼⠃⠀ ⠀⠀⠈⢿⡄⠀⠀⠀⠀⠀⠙⣧⠀⠀⠀⠀⠀⠀⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢠⣧⠀⠀⣀⡼⠁⠀⠀ ⠀⠀⠀⠀⠙⢶⡀⠀⠀⠀⠀⢿⣷⠀⠀⢀⣠⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠓⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⡟⠀⠀⠛⠁⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠉⠀⠀⠀⠙⠏⠉⠀⣠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣿⢿⣿⣿⣿⣿⣿⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣸⠁⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⣿⣿⣿⣿⣿⣿⣿⣟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⡼⠃⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣟⣷⣀⠀⠀⠀⠀⠀⠀⠀⠀⢀⠞⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⢠⣞⣿⣿⣿⣿⣿⣿⣿⣼⣿⣿⣿⡿⣾⢻⣿⣿⡟⢻⣿⣿⣿⣿⣿⣿⠙⠳⢤⣀⣀⣀⣠⡤⠖⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⢨⣿⣿⣿⣿⣿⣿⣿⠇⣿⣿⣿⣿⢳⣿⣿⣿⣿⡇⣾⣿⣿⣿⣿⣿⠹⠄⠀⠀⠀⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⢠⣿⣿⣿⣟⣿⣿⣿⣿⣻⣿⣾⣿⣿⢸⣿⣿⣿⣿⡇⣿⣿⣿⢹⣿⣿⣇⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⣾⣅⡿⣫⠟⣿⣿⡿⢹⡿⠿⣿⣿⣧⢸⣿⣿⣿⣿⠇⣿⣿⠇⡞⣿⡏⠉⢷⠴⠂⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⣸⡿⠿⠟⠁⠀⡇⢸⡇⢀⣧⡤⢰⣿⡟⢸⡇⡏⢹⣿⠀⣿⡟⠀⢳⣿⡇⠠⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠞⠁⠀⠀⡠⠀⠀⠁⣿⠃⢸⣿⠙⢺⣻⡗⠸⡇⠡⢸⣿⣰⠈⠀⠀⢘⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠉⢸⠁⠀⠀⠀⣿⠀⠘⣿⡄⠀⠁⠁⠀⠃⠀⠈⣿⠿⠀⠀⠀⠘⠀⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⠀⠀⠙⡇⠀⠀⠀⠀⠀⠀⢀⣏⣥⠀⠀⠀⢠⣤⠔⠀⠦⠤⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡙⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ A B A D D O N async offensive engine · authorized testing only ╭─ MENU ───────────────────────────────────────────────────────────────────────────────────────────────────────────────╮ │ 1 Quick Scan Run every module against a target │ │ 2 Single Module Pick one vulnerability class │ │ 3 Abaddon Engine Async template-based scan (OAST, fuzzing) │ │ 4 Recon Tools Port scan / path & subdomain discovery │ │ 5 Options Threads, proxy, scope, WAF evasion, timeout │ │ 6 Help / About Usage and safety notes │ │ 0 Exit Leave Abaddon │ ╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯ ``` 为渗透测试人员和漏洞赏金猎人构建的**模块化 + 异步 Web 漏洞扫描器**。 交互式菜单、暗紫色 TUI 以及模板驱动的异步引擎。 —— **v2.13.0} ## 模块 | 模块 | 检测内容 | |--------|-----------------| | **SQLi** | 基于错误、布尔盲注、时间盲注 (MySQL / MSSQL / Oracle / PostgreSQL / SQLite) | | **XSS** | 带上下文检测的反射型 XSS (HTML / 属性 / JavaScript) | | **LFI** | 路径遍历、PHP filter wrapper、编码绕过、空字节 | | **CMDi** | OS 命令注入 —— 基于输出 + 基于时间 (Unix 和 Windows) | | **SSTI** | 模板注入 (Jinja2, Twig, Freemarker, Mako, ERB, Smarty, Velocity) | | **CRLF** | Header 注入、Set-Cookie 注入、响应拆分 | | **Redirect** | 通过 Location、meta-refresh、JavaScript 实现的开放重定向 | | **Headers** | 缺失的安全 Header、服务器信息泄露、CORS 错误配置 (被动通配符 + 主动反射来源探测) | | **JWT** | alg:none 绕过、弱 HS256 密钥暴力破解、敏感 payload 字段 | | **SSRF** | 云元数据 (AWS/GCP/Azure)、localhost、内部服务 (Redis/ES/k8s) —— 并行探测 | | **XXE** | 原始 XML POST、XML 参数注入、XML 提示参数 —— 6 种 payload 变体 | | **403 Bypass** | Header 欺骗 (X-Original-URL, X-Forwarded-For, …)、路径操纵 (16 种变体)、动词篡改 | | **GraphQL** | 自省暴露、GraphiQL/Playground IDE、批量查询、字段建议 —— 探测 12 个常见 endpoint 路径 | | **IDOR** | 数字 ID 和 UUID 参数枚举、路径段 ID 遍历 —— 双基线稳定性防护、大小相似性门控以抑制误报 | | **CVE 检测** | 涵盖 14 种服务 (Apache, Nginx, PHP, IIS, Tomcat, OpenSSL, jQuery, WordPress, Drupal, Struts, Spring, WebLogic, Confluence, Joomla) 的 34 个 CVE,包含 CVSS、Metasploit 模块、NVD 链接 | ## 功能 - **侦察阶段** —— 在每次扫描前进行 DNS、IP、延迟、服务器/技术指纹、CVE 检查 - **经过身份验证的、编排化的扫描** (`--auth-user`/`--auth-pass`, `--orchestrated`) —— 仅登录一次,为应用爬取 + 所有模块重用 session,并运行具有 session 感知的检查:**认证绕过 SQLi**、**破坏的访问控制** (authz 矩阵)、**批量赋值**、**IDOR/BOLA** (双重身份)、**存储型/二阶 XSS** 和 **CSRF** - **带外 (OAST) 检测** —— 盲测和二阶发现 (例如仅在管理员浏览器中触发的存储型 XSS) 通过本地回调监听器和捕获日志轮询进行确认,然后重放被盗取的 session 以提取受限的机密信息 - **静态目标检测** —— 检测 CDN/SPA 目标 (缓存 Header + 响应哈希) 并自动跳过注入模块以消除误报 - **差分时间确认** —— 盲时间型 SQLi/CMDi 候选对象将在 2 倍睡眠时间下重新测试,并且仅在延迟成比例缩放时才报告,从而消除延迟高峰导致的误报 - **布尔重新确认** —— 布尔盲注 SQLi 信号必须在报告之前在第二次请求中重现 (动态页面误报防护) - **攻击路径关联** —— Bloodhound 风格的链接将已确认的发现组合成提权路径 (例如 SQLi + 弱 JWT → 账户接管,SSRF → 云凭据窃取),显示在控制台和 JSON 中 - **感知 JS 的爬取** —— 通过 Playwright 驱动无头 Chromium;点击模态框/按钮 (Register, Login, Cadastrar…),拦截 XHR/Fetch,查找没有 `name` 属性的输入框 (`--js-crawl`) - **子域接管** —— CNAME 链解析 → 未声明服务指纹检查 (12 种服务) - **端口扫描器** —— 并发 TCP 探测 31 个常见端口并抓取 banner (`--port-scan`) - **路径发现** —— 并发探测 130 个常见路径 (`--discover-paths`) - **子域名枚举** —— 通过 DNS 解析 80 个常见前缀 (`--discover-subs`) - **WAF 绕过** —— 跨越 3 个逐级递增级别的 6 种 payload 转换 (`--waf-evasion 1|2|3`) - **自适应限流器** —— 遇到 429/503 时进行指数退避,遇到 200 时自动恢复 (`--rate-limit`) - **漏洞赏金模式** —— 范围验证、X-Bug-Bounty Header、UA 程序标签 (`--bb-note`, `--scope`) - **Ctrl+C 恢复** —— 优雅中断,返回迄今为止收集的所有发现 - **并发扫描** —— 模块并行运行 (可配置 `--threads`) - **报告导出** —— TXT 和 JSON 格式,包含 curl + msfconsole 复现步骤 - **ABADDON 异步引擎** —— 可选的高并发核心 (`python -m abaddon`):`httpx.AsyncClient` + HTTP/2,Nuclei 风格的 YAML 模板 (Pydantic V2 验证),智能匹配器 (OAST 带外、时间/熵差分、上下文感知反射) 与多信号**置信度关联**,每主机自适应限流,以及用于 SIEM 的 JSONL 输出 - **424 个单元测试** —— 外加 `tools/ctf_recall.py`,用于测量针对具有基准真实性的 CTF 的检测召回率 (目前为 **9/9**) ## 安装 ``` git clone https://github.com/nskge/abaddon.git cd abaddon pip install -r requirements.txt # JS 感知 crawl(可选) pip install playwright && python -m playwright install chromium ``` **要求:** Python 3.10+ ``` python main.py # launch the interactive menu python main.py --version # Abaddon v2.13.0 ``` ## 菜单 运行时不带参数即可进入交互式 TUI: ``` python main.py python -m abaddon ``` ``` 1 Quick Scan Run all modules against a target URL 2 Single Module Pick one vulnerability class (SQLi, XSS, IDOR, …) 3 Abaddon Engine Async template scan — OAST, fuzzing, confidence correlation 4 Recon Tools Port scan + path and subdomain discovery 5 Options Threads, proxy, scope globs, WAF evasion level, timeout 6 Help / About Usage notes and version info 0 Exit ``` 经典的基于 flag 的 CLI 仍然可用 —— 在 `main.py` 之后的任何参数都会跳过菜单。 ## 用法 ``` # 完整扫描 — 所有模块,所有参数 python main.py -u "http://target/page?id=1" # 异步 template 引擎(OAST, fuzzing, confidence correlation) python -m abaddon -u "http://target/" --scope "*.target.com" # 自动检测并测试 HTML forms python main.py -u "http://target/search.php" --crawl # 特定模块针对特定参数 python main.py -u "http://target/page?id=1" --scan-type sqli -p id # POST form python main.py -u "http://target/login" -m POST -d "user=admin&pass=x" --scan-type xss # Recon 附加项:端口扫描 + 路径发现 python main.py -u "http://target/?id=1" --port-scan --discover-paths --discover-subs # WAF evasion 级别 2 python main.py -u "http://target/?q=1" --waf-evasion 2 # 自适应速率限制器(请求间至少 0.3s) python main.py -u "http://target/?id=1" --rate-limit --rate-delay 0.3 # 带 scope 检查的 Bug bounty 模式 python main.py -u "http://api.target.com/?url=x" \ --scan-type ssrf \ --bb-note researcher@example.com \ --bb-program h1/target-slug \ --scope "*.target.com" # 对受保护 endpoint 进行 403 bypass python main.py -u "http://target/admin?x=1" --scan-type bypass403 # 经过认证的、编排化的扫描 — 登录 + crawl + session 感知检查 # (auth-bypass, broken access, mass assignment, IDOR/BOLA, stored XSS, CSRF) python main.py -u "http://target/" --auth-user alice --auth-pass secret --login-url /login # 添加第二个身份以进行跨账户 IDOR/BOLA 确认 python main.py -u "http://target/" --auth-user alice --auth-pass a \ --auth-user2 bob --auth-pass2 b # 针对 ground-truth CTF 衡量检测 recall python tools/ctf_recall.py --base http://127.0.0.1:5000 \ --gabarito ../CaptureTheOkr/expected_findings.json # JS 感知 crawl — 发现隐藏在 modals/SPA routes 后面的输入 python main.py -u "http://target/" --js-crawl # GraphQL endpoint 探测 python main.py -u "http://target/" --scan-type graphql # 通过 Burp Suite 路由 python main.py -u "http://target/?q=test" --proxy http://127.0.0.1:8080 # 导出 JSON 报告 python main.py -u "http://target/?id=1" -o report.json --format json ``` ### 选项 ``` Target: -u, --url URL Target URL (required) -m, --method GET|POST HTTP method (default: GET) -d, --data POST body e.g. 'user=admin&pass=test' -p, --param NAME Test only this parameter Scan options: --scan-type TYPE sqli|xss|lfi|redirect|cmdi|crlf|ssti|headers| jwt|ssrf|xxe|bypass403|graphql|idor|all (default: all) --crawl Auto-detect HTML forms --js-crawl JS-aware crawl via headless Chromium (finds SPA inputs) --payloads FILE Custom payload file (one per line) --delay SECS Time-based detection threshold (default: 5.0) --threads N Concurrent module threads (default: 4) --waf-evasion LEVEL 0=off 1=url+null 2=+double+case 3=+html+sql (default: 0) Authenticated scan: --auth-user USER Log in and reuse the session everywhere (implies orchestrated) --auth-pass PASS Password for --auth-user --login-url URL Login form URL/path (default: /login) --auth-user2 USER Second identity for cross-account IDOR/BOLA --auth-pass2 PASS Password for --auth-user2 --orchestrated Run the orchestrated checks without credentials Recon extras: --port-scan Fast TCP port scan during recon --discover-paths Probe 130 common URL paths --discover-subs Enumerate 80 common subdomains Rate limiting: --rate-limit Enable adaptive rate limiter (auto back-off on 429/503) --rate-delay SECS Minimum delay between requests (default: 0.0) Bug bounty: --bb-note EMAIL Add X-Bug-Bounty header identifying you as the researcher --bb-program SLUG Append BugBounty/slug to User-Agent --scope PATTERNS Comma-separated glob patterns e.g. '*.example.com' Aborts scan if target is out of scope HTTP options: --headers HEADER ... Extra headers e.g. 'Authorization: Bearer tok' --cookies COOKIES Cookie string e.g. 'session=abc; role=admin' --proxy URL HTTP proxy e.g. http://127.0.0.1:8080 --timeout N Request timeout in seconds (default: 10) --user-agent UA Override User-Agent --follow-redirects Follow HTTP redirects Output: -o, --output FILE Save report to file --format txt|json Report format (default: txt) -v, --verbose Debug logging -q, --quiet Findings only (no banner/recon) --no-color Disable ANSI colors ``` ## 测试 ``` python -m pytest tests/ -v # 424 tests ``` ## 架构 ``` scanner/ ├── __init__.py version ├── core.py Scanner orchestrator (recon + parallel module dispatch) ├── http_client.py HTTPClient with rate limiter integration ├── rate_limiter.py AdaptiveRateLimiter (exponential back-off) ├── waf_evasion.py Payload transforms (6 strategies, 3 levels) ├── port_scanner.py Concurrent TCP port scanner ├── discovery.py Subdomain enumeration + URL path discovery ├── cve_db.py CVE database + version matching ├── banner.py ASCII banner ├── parser.py URL/form parsing helpers ├── reporter.py TXT/JSON report writer ├── logger.py Logging setup └── modules/ ├── base.py BaseModule ABC + Finding dataclass ├── sqli.py ├── xss.py ├── lfi.py ├── cmdi.py ├── ssti.py ├── crlf.py ├── open_redirect.py ├── headers.py ├── jwt_analyzer.py ├── ssrf.py ├── xxe.py ├── bypass403.py ├── graphql.py └── idor.py js_crawler.py Playwright-based JS crawl for SPA/modal input discovery abaddon/ Async engine (python -m abaddon) ├── network/ │ ├── engine.py AsyncEngine: httpx.AsyncClient, semaphore, bounded queue │ ├── throttle.py TokenBucket + per-host AdaptiveThrottle │ └── evasion.py UA rotation, IP-spoof headers, payload mutation ├── parsers/ │ └── template_engine.py Load + strictly validate YAML templates ├── models/ │ └── schemas.py Pydantic V2 template DSL (extra="forbid") ├── core/ │ ├── matchers.py word/regex/status/time/entropy/reflection/oast matchers │ ├── correlation.py Multi-signal noisy-OR confidence engine │ ├── oast.py OAST provider (mock + webhook) for blind detection │ ├── scope.py Allowlist enforcement (host glob + CIDR) │ ├── runner.py Scanner orchestration + {{oast}}/{{marker}} interpolation │ └── logger.py structlog console + JSONL result sink ├── templates/ Bundled YAML templates └── cli.py rich CLI ``` ### 添加模块 (经典引擎) 1. 创建 `scanner/modules/mymodule.py` —— 继承 `BaseModule` 子类,实现 `scan_parameter()` 2. 在 `scanner/core.py` 的 `_MODULE_MAP` 中注册 3. 添加到 `main.py` 中的 `--scan-type` 选项中 ### 添加 ABADDON 模板 将一个 `.yaml` 文件放入 `abaddon/templates/` 目录中 (加载时将根据 `abaddon/models/schemas.py` 进行验证)。无需 Python 代码: ``` id: my-check info: {name: My Check, severity: high} requests: - method: GET path: ["/admin"] matchers-condition: and matchers: - {type: status, status: [200], confidence: 0.4} - {type: word, words: ["dashboard"], confidence: 0.6} ``` ## 免责声明 **Abaddon 仅用于合法、授权的安全测试。** 1. **仅限授权使用。** 仅测试您拥有或获得明确书面许可进行测试的系统。 2. **无责任。** 按“原样”提供,不提供任何担保。作者对因使用或不当使用造成的损害或法律后果不承担任何责任。 3. **您的责任。** 在测试任何目标之前,请确保遵守所有适用法律。 4. **不保证准确性。** 在报告之前,手动验证所有发现。 未经授权的访问是犯罪行为 (CFAA, Computer Misuse Act, Art. 154-A Brazilian Penal Code)。 ## 许可证 [MIT 许可证](LICENSE)
标签:CISA项目, Web安全, XSS检测, 特征检测, 蓝队分析, 逆向工具