• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

Sn1per v7.2 Automated Pentest Recon Scanner

Status
Not open for further replies.

itsMe

*KillmeMories*
Staff member
Administrator
Super Moderator
Hacker
Specter
Crawler
Shadow
Joined
Jan 8, 2019
Messages
56,612
Solutions
2
Reputation
32
Reaction score
100,454
Points
2,313
Credits
32,640
‎6 Years of Service‎
 
76%
snipper.png


Sn1per Community Edition is an automated scanner that can be used during a penetration test to enumerate and scan for vulnerabilities. Sn1per Professional is Xero Security’s premium reporting add-on for Professional Penetration Testers, Bug Bounty Researchers and Corporate Security teams to manage large environments and pentest scopes.

FEATURES:

    Automatically collects basic recon (ie. whois, ping, DNS, etc.)
    Automatically launches Google hacking queries against a target domain
    Automatically enumerates open ports via Nmap port scanning
    Automatically brute forces sub-domains gathers DNS info and checks for zone transfers
    Automatically checks for sub-domain hijacking
    Automatically runs targeted Nmap scripts against open ports
    Automatically runs targeted Metasploit scan and exploit modules
    Automatically scans all web applications for common vulnerabilities
    Automatically brute forces ALL open services
    Automatically test for anonymous FTP access
    Automatically runs WPScan, Arachni and Nikto for all web services
    Automatically enumerates NFS shares
    Automatically test for anonymous LDAP access
    Automatically enumerate SSL/TLS cyphers, protocols and vulnerabilities
    Automatically enumerate SNMP community strings, services and users
    Automatically list SMB users and shares, check for NULL sessions and exploit MS08-067
    Automatically exploit vulnerable JBoss, Java RMI and Tomcat servers
    Automatically tests for open X11 servers
    Auto-pwn added for Metasploitable, ShellShock, MS08-067, Default Tomcat Creds
    Performs high-level enumeration of multiple hosts and subnets
    Automatically integrates with Metasploit Pro, MSFConsole and Zenmap for reporting
    Automatically gathers screenshots of all websites
    Create individual workspaces to store all scan output

Changelog

    v7.2 – Added experimental OpenVAS API integration
    v7.2 – Improved Burpsuite 2.x API integration with vuln reporting
    v7.2 – Added hunter.io API integration to recon mode scans
    v7.2 – Added Cisco IKE Key Disclosure MSF exploit
    v7.2 – Added JBoss MSF vuln scanner module
    v7.2 – Added Apache CouchDB RCE MSF exploit
    v7.2 – Added IBM Tivoli Endpoint Manager POST Query Buffer Overflow exploit
    v7.2 – Added Java RMI MSF scanner
    v7.2 – New scan mode “vulnscan”
    v7.2 – New scan mode “massportscan”
    v7.2 – New scan mode “massweb”
    v7.2 – New scan mode “masswebscan”
    v7.2 – New scan mode “massvulnscan”
    v7.2 – Added additional Slack API notification settings
    v7.2 – Improved NMap port detection and scan modes
    v7.2 – Fixed issue with Censys API being enabled by default
    v7.2 – Fixed verbose errors in subjack/subover tools
    v7.2 – Fixed issue with NMap http scripts not working

To see this hidden content, you must like this content.
 
Status
Not open for further replies.
Back
Top