fuxploider

File upload vulnerability scanner and exploitation tool.

Github星跟蹤圖

fuxploider

Python 3.6 License

Fuxploider is an open source penetration testing tool that automates the process of detecting and exploiting file upload forms flaws. This tool is able to detect the file types allowed to be uploaded and is able to detect which technique will work best to upload web shells or any malicious file on the desired web server.

Screenshots

screenshot

Installation

You will need Python 3.6 at least.

git clone https://github.com/almandin/fuxploider.git
cd fuxploider
pip3 install -r requirements.txt

For Docker installation

# Build the docker image
docker build -t almandin/fuxploider .

Usage

To get a list of basic options and switches use :

python3 fuxploider.py -h

Basic example :

python3 fuxploider.py --url https://awesomeFileUploadService.com --not-regex "wrong file type"

[!] legal disclaimer : Usage of fuxploider for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

主要指標

概覽
名稱與所有者almandin/fuxploider
主編程語言Python
編程語言Python (語言數: 4)
平台
許可證GNU General Public License v3.0
所有者活动
創建於2017-07-14 09:30:06
推送於2025-05-08 09:00:36
最后一次提交2025-05-08 11:00:36
發布數3
最新版本名稱v1.0 (發布於 )
第一版名稱v0.1.2 (發布於 )
用户参与
星數3.2k
關注者數69
派生數517
提交數143
已啟用問題?
問題數0
打開的問題數0
拉請求數16
打開的拉請求數0
關閉的拉請求數2
项目设置
已啟用Wiki?
已存檔?
是復刻?
已鎖定?
是鏡像?
是私有?