Hey Folks, today in this tutorial we are going to discuss a web application security testing tool called “hakrawler“. hakrawler is a Go web crawler designed for easy, quick discovery of endpoints and assets within a web application. It can be used to discover :
- Forms
- Endpoints
- Subdomains
- Related domains
- JavaScript files
Let’s take a look !!
Install Golang
The tool is coded in the Go language, so we have to configure the go utility by using the following command to operate this tool.
1 | apt install golang |
data:image/s3,"s3://crabby-images/eaa44/eaa44a0c2005f749749c91653b7ebe5c36d234bf" alt=""
Installation of Hakrawler
Now the time has come to install this tool using Go utility. We only have to execute the following command to install this tool.
1 | go get github.com/hakluke/hakrawler |
data:image/s3,"s3://crabby-images/1565e/1565e30f0359a1196ded7fb1bfa0efbdb91b346c" alt=""
The tool has automatically reached to the binary location of kali linux which means that we can access it from anywhere.
1 | hakrawler -h |
data:image/s3,"s3://crabby-images/3186e/3186eec66bb13d426b2de93a33c8a10e8d9ee284" alt=""
Robots.txt Parsing
Basically robots.txt is a standard used by websites to communicate with web crawlers and other web robots which we can find with the help of this tool.
1 | hakrawler -url < website > -robots |
data:image/s3,"s3://crabby-images/b2ef2/b2ef2a817d0a02b2bb7c70e508a2748d8ecaf38f" alt=""
Subdomains
Finding a sub-domain is a common feature but you can also use it.
1 | hakrawler -url fintaxico.in -subs |
data:image/s3,"s3://crabby-images/decca/decca49dbb626f18dcbaad5cc78834a896d14889" alt=""
Depth Scan
If you want to crawl the website completely with depth then you can use the following command and also increase the depth accordingly.
1 | hakrawler -url secnhack.in -depth 10 |
data:image/s3,"s3://crabby-images/0d203/0d2038e2cd588e91548a05ab3235d5e852304d8a" alt=""
Likewise, this tool has many features that can give you a good experience while crawling any web application.
data:image/s3,"s3://crabby-images/df479/df479597605c73ae84914b87c9be0be0699e3a76" alt=""
Post a Comment