Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Aron - A simple GO script for finding hidden GET & POST parameters with Brute-force
- Installation
- sudo su
- apt update
- apt install golang golang-1.10 golang-1.10-src golang-1.10-go golang-1.10-doc golang-1.9 golang-1.9-src golang-1.9-go golang-1.9-doc
- git clone https://github.com/m4ll0k/Aron
- cd Aron
- go get github.com/m4ll0k/printer
- go env | grep -i gopath
- go run aron.go
- go build aron.go
- cp aron /usr/bin/
- aron
- Usage:
- ___
- / | _________ ___
- / /| | / ___/ __ \/ __\
- / ___ |/ / / /_/ / / / /
- /_/ |_/_/ \____/_/ /_/ (v0.1.0 beta)
- ----------------------------
- Momo (M4ll0k) Outaadi
- Usage of aron:
- -data="": Set post data
- -get=false: Set get method
- -post=false: Set post method
- -url="": Set target URL
- -wordlist="dict.txt": Set your wordlist
- GET BRUTEFORCE:
- go run aron.go -url http://www.test.com/index.php -get
- go run aron.go -url http://www.test.com/index.php<[?|id=1|id=1&]> -get
- go run aron.go -url http://www.test.com/index.php<[?|id=1|id=1&]> -get -wordlist my_wordlist.txt
- <[?|id=1|id=1&]> => Possible end URL
- OR Note: in this case aron need the wordlist path
- aron -url http://www.test.com/index.php -get -wordlist path/wordlist.txt
- aron -url http://www.test.com/index.php<[?|id=1|id=1&]> -get -wordlist path/wordlist.txt
- POST BRUTEFORCE:
- go run aron.go -url http://www.test.com/index.php -post
- go run aron.go -url http://www.test.com/index.php<[?id=1]> -post
- go run aron.go -url http://www.test.com/index.php<[?id=1]> -post -data "user=1"
- go run aron.go -url http://www.test.com/index.php<[?id=1]> -post -data "user=1" -wordlist my_wordlist
- OR Note: in this case aron need the wordlist path
- aron -url http://www.test.com/index.php -post -wordlist path/wordlist.txt
- aron -url http://www.test.com/index.php<[?id=1]> -post -data "user=1" -wordlist path/wordlist.txt
- Download Aron: https://github.com/m4ll0k/Aron
Add Comment
Please, Sign In to add comment