1 Star 0 Fork 0

ltfafei/IIS-ShortName-Scanner

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
文件
该仓库未声明开源许可证文件(LICENSE),使用请关注具体项目描述及其代码上游依赖。
克隆/下载
config.xml 4.71 KB
一键复制 编辑 原始数据 按行查看 历史
soroush dalili 提交于 2017-02-05 19:57 . v2.3.9
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE properties SYSTEM "http://java.sun.com/dtd/properties.dtd">
<properties>
<comment>IIS Short File/Folder Name (8.3) Scanner - Configuration File</comment>
<!-- To enabled maximum verbose messages -->
<entry key="debug">false</entry>
<!-- To save all outputs in a file -->
<entry key="saveOutput">false</entry>
<entry key="outputFile">iis_shortname_scanner_logfile.txt</entry>
<!-- It will not ask any questions even when proxy / time delay are not configured - it will ignore them. It is useful for automation -->
<entry key="hassleFree">true</entry>
<!-- You can change the user-agent if it is needed -->
<entry key="userAgent"><![CDATA[Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10]]></entry>
<!-- Your cookie information. Can be a hidden value that will pass your WAF. -->
<entry key="cookies">IIS_Tilde_Scanner=1;</entry>
<!-- Additional headers such as Authorization header can be defined here -->
<entry key="headersDelimiter">@@</entry>
<entry key="headers">X-Forwarded-For: 127.0.0.1@@X-Originating-IP: 127.0.0.1@@X-Cluster-Client-Ip: 127.0.0.1</entry>
<!-- In order to see the errors better than a normal request you can use aspxerrorpath=/ -->
<entry key="URLSuffix"><![CDATA[?&aspxerrorpath=/]]></entry>
<!-- discard any of these to have more speed! -->
<!-- default is based on letter frequencies http://en.wikipedia.org/wiki/Letter_frequency -->
<entry key="inScopeCharacters"><![CDATA[ETAONRISHDLFCMUGYPWBVKJXQZ0123456789_-$~()&!#%'@^`{}]]></entry>
<!-- in Milliseconds -->
<entry key="maxConnectionTimeOut">20000</entry>
<entry key="maxRetryTimes">10</entry>
<!-- Proxy will be ignored if this is empty -->
<entry key="proxyServerName"></entry>
<entry key="proxyServerPort"></entry>
<!-- Delay after each request in milliseconds - 0 may cause false positive results -->
<entry key="maxDelayAfterEachRequest">1</entry>
<entry key="magicFinalPartDelimiter">,</entry>
<entry key="magicFinalPartList"><![CDATA[\a.aspx,\a.asp,/a.aspx,/a.asp,/a.shtml,/a.asmx,/a.ashx,/a.config,/a.php,/a.jpg,/webresource.axd,/a.xxx]]></entry>
<!-- in Windows we can sometimes use > instead of ? -->
<entry key="questionMarkSymbol"><![CDATA[?]]></entry>
<!-- in Windows we can sometimes use < instead of * - only change this if you need to (it misses items) -->
<entry key="asteriskSymbol"><![CDATA[*]]></entry>
<!-- "*" will be replaced with asteriskSymbol variable later -->
<entry key="magicFileName"><![CDATA[*~1*]]></entry>
<!-- "*" will be replaced with asteriskSymbol variable later -->
<entry key="magicFileExtension"><![CDATA[*]]></entry>
<!-- This will be used to compare the different responses and accept them as equal if their length difference is equal or less than this -->
<!-- -1 can be used to ignore this rule completely -->
<!-- This may make the scan result unreliable so must be very small value or -1 -->
<entry key="acceptableDifferenceLengthBetweenResponses">10</entry>
<entry key="requestMethodDelimiter">,</entry>
<entry key="requestMethod"><![CDATA[DEBUG,OPTIONS,GET,POST,HEAD,TRACE]]></entry>
<!-- This will be used to find file or directory names that start with this string - should be less than 6 characters -->
<entry key="nameStartsWith"><![CDATA[]]></entry>
<!-- This will be used to find file or directory extensions that start with this string - should be less than 4 characters -->
<!-- This may not be reliable when the extension discovery is not reliable on a target -->
<entry key="extStartsWith"><![CDATA[]]></entry>
<!-- This will be used to set a maximum value on the "NUMBER_HERE" parameter in FILENAME~NUMBER_HERE (example: DEFAUL~2.ASP) -->
<!-- The minimum value for this parameter is 1 -->
<entry key="maxNumericalPart">3</entry>
<!-- This will be used to set a maximum value on the "NUMBER_HERE" parameter in FILENAME~NUMBER_HERE even when the previous number is not available -->
<!-- For instance, if it is set to 3, when we have DEFAUL~1.ASP and we do not have DEFAULT~2.ASP, it still checks DEFAUL~3.asp -->
<!-- This parameter automatically override the "maxNumericalPart" parameter when "forceNumericalPart > maxNumericalPart" -->
<!-- The minimum value for this parameter is 1 -->
<!-- Anything greater than 1 may lead to false positive results -->
<entry key="forceNumericalPart">1</entry>
<!-- This will be used to show the potential/actual names in final results if possible -->
<entry key="showActualNames">true</entry>
<!-- This can be used in special situations such as when the target is accessible via SSRF e.g. http://proxyweb/proxy?url=http://targetIIS/ -->
<entry key="useProvidedURLWithoutChange">false</entry>
</properties>
马建仓 AI 助手
尝试更多
代码解读
代码找茬
代码优化
1
https://gitee.com/afei00123/IIS-ShortName-Scanner.git
git@gitee.com:afei00123/IIS-ShortName-Scanner.git
afei00123
IIS-ShortName-Scanner
IIS-ShortName-Scanner
master

搜索帮助

0d507c66 1850385 C8b1a773 1850385