zan8in / afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming.
MIT License
3.43k stars 385 forks source link

Mac #20

Closed Teicu closed 2 years ago

Teicu commented 2 years ago

Hello

can someone show me the steps to install this tool on a MacBook?
Thanks

zan8in commented 2 years ago

download afrog_arm.tar.gz if MacBook M1,otherwise download afrog_macos.tar.gz

Teicu commented 2 years ago

Hello,

I just ran afrog_macos -t http://testphp.vulnweb.com and can't find anything. What did I do wrong? because this site is still a test site used for testing and have a lot of flaws

Thanks

Teicu commented 2 years ago

afrog_macos -t http://testphp.vulnweb.com -P afrog/pocs/afrog-pocs
NAME: afrog 漫天星辰 - v1.3.6

PATH: /Users/root/.config/afrog/afrog-config.yaml v0 (0.1.58) /Users/root/afrog/pocs/afrog-pocs ./reports/20220802-105849.html

TIPS: 坚持,是一种品格!

http://testphp.vulnweb.com 200 Home of Acunetix Art 000 2022-08-02 10:58:50 Fingerprint INFO 649/649 | 100% %

Teicu commented 2 years ago

Ok, I scanned again a list of about 700 URLs, the result is the same, no vulnerabilities found by the scanner

the cmd I used are:

frog_macos -T targets.txt -P /afrog/pocs/afrog-pocs

and even

frog_macos -T targets.txt -o result.html

what's wrong? what am I doing wrong?

Screenshot 2022-08-02 at 13 51 28

Thanks

zan8in commented 2 years ago

You search some URLs from shodan, and input to targets.txt and run : frog_macos -T targets.txt -o r.html shodan-query: http.title:"NS-ASG" or shodan-query: title:"MinIO Browser"