zan8in / afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming.
MIT License
3.43k stars 385 forks source link

hi #2

Closed sasholy closed 2 years ago

sasholy commented 2 years ago

How to install in Kali Linux

启动 afrog 出错,rerverse CeyeApiKey or CeyeDomain is Empty in your /home/[yourname]/.config/afrog/afrog-config.yaml

thx

zan8in commented 2 years ago
  1. Open the website http://ceye.io/ and register an account, CeyeApiKey and CeyeDomain in your account profile.
  2. vim ~/.config/afrog/afrog-config.yaml, edit api-key and domain
sasholy commented 2 years ago

┌──(kali㉿kali)-[~] └─$ /home/kali/Desktop/afrog_linux_amd64 -t http://testphp.vulnweb.com/ -o result.html A tool for finding vulnerabilities - afrog V1.2.2 Default Conf /home/kali/.config/afrog/afrog-config.yaml Default Pocs /home/kali/afrog-pocs v0.0.1 输出文件 result.html 442/442 | 100%

is invulnerable? thx

zan8in commented 2 years ago

sorry, afrog does not support scanning for generic vulnerabilities, Acunetix Web Vulnerability Scanner(AWVS) does a better job.

afrog is good at scanning non-universal vulnerabilities, such as CVE, CNVD, etc., to make up for the shortcomings of AWVS