Information Gathering & Penetration Testing Tool: Sn1per

Gauloran

Moderasyon Ekibi Lideri
7 Tem 2013
8,198
672
Information Gathering & Penetration Testing Tool: Sn1per

There are many ways to scan a website. You can do it manuel scan or you can do it using various tools, they all work for the same purpose. Today, I'm going to tell you about sn1per. This tool almost contains all website scanning programs.

rNHAln.png


What is The Purpose of Sn1per?


Sn1per is a web penetration testing framework used for information gathering and vulnerabilities assessments. The biggest advantage is that it contains dozens of website scanning tools. Sn1per is used on Kali Linux but it can be used in Termux with the condition of installing Katana Framework. Sn1per takes the information from nmap, google hacking, basic information (whois, dns, ping, subdomain etc.)

rNHAln.png


Sn1per contains these tools: nmap, arachni, amap, cisco-torch, dnsenum, enum4linux, golismero, hydra, met@sploit-framework, nbtscan, nmap smtp-user-enum, sqlmap, sslscan, theharvester, w3af, wapiti, whatweb, whois, nikto, wpscan.

rNHAln.png


How to Install Sn1per

Kod:
cd Desktop

Kod:
git clone https://github.com/1N3/Sn1per.git

yFsLyp.jpg


We installed the sn1per

Kod:
cd sn1per/

Kod:
ls

yFp450.jpg


with "cd" command, we go to the sn1per directory and we use the "ls" command to view the contents.

Kod:
chmod +x install.sh

Kod:
./install.sh

yMS61S.jpg


We gave the right to change permissions and we are downloading the files inside the tool.

rNHAln.png


How to Use Sn1per


I will not put any image after this because I don't want to show the information of any website.

Simple Scan will show you:

Host address
Server names
Email address of the website
Ping status
Ports
Nmap scan result

If you want to simple scan, you can use this command:

Kod:
sniper -t www.hedef.site.com

Scanning with OSINT

OSINT is data collected from publicly available sources to be used in an intelligence context.

Host address
Email address of the website
Ping status
Ports
Phone number (if there is one)

You can use this command to scan with OSINT:

Kod:
sniper -t|--target <Www.targetwebsite.com > -m|--Mode osint -o|

Sthealth Scan

Sthealth Scan causes to deep scan. It is pretty hidden when scanning so it can scan a little slowly.

Kod:
sniper -t|--target <www.targetwebsite.com> -m|--mode stealth -o

rNHAln.png


Other Important Codes

Discover

Kod:
sniper -t|--www.hedefsite.com <CIDR> -m|--mode discover -w|--workspace <WORSPACE_ALIAS&gt

Flyover

Kod:
sniper -t|--target <www.hedefsite.com> -m|--mode flyover -w|--workspace <WORKSPACE_ALIAS>

rNHAln.png


Source: https://www.turkhackteam.org/sosyal-muhendislik/1922059-bilgi-toplama-ve-pentest-araci-sn1per.html

Translator dRose98
 
Üst

Turkhackteam.org internet sitesi 5651 sayılı kanun’un 2. maddesinin 1. fıkrasının m) bendi ile aynı kanunun 5. maddesi kapsamında "Yer Sağlayıcı" konumundadır. İçerikler ön onay olmaksızın tamamen kullanıcılar tarafından oluşturulmaktadır. Turkhackteam.org; Yer sağlayıcı olarak, kullanıcılar tarafından oluşturulan içeriği ya da hukuka aykırı paylaşımı kontrol etmekle ya da araştırmakla yükümlü değildir. Türkhackteam saldırı timleri Türk sitelerine hiçbir zararlı faaliyette bulunmaz. Türkhackteam üyelerinin yaptığı bireysel hack faaliyetlerinden Türkhackteam sorumlu değildir. Sitelerinize Türkhackteam ismi kullanılarak hack faaliyetinde bulunulursa, site-sunucu erişim loglarından bu faaliyeti gerçekleştiren ip adresini tespit edip diğer kanıtlarla birlikte savcılığa suç duyurusunda bulununuz.