Source2URL


Source2URL

Table of Contents

Source2URL is a simple tool (currently bash only) designed to aid the content discovery phase of a web application security assessment. It parses a given directory containing source code and creates a URL list for all discovered resources.

Once this is complete it then makes an HTTP request to each URL, through a configured proxy, so that visibility of that resource is attained and spidering can then ensue/continue. A text file containing all the URLs is left behind for use with other tools as desired.

Code

The code is available from my GitHub page.

Syntax

You invoke the command like so:

./Source2URL /some/code/path/ basedir proxyhost:proxyport domain.tld

Next Steps

Here are some next steps:

  1. Improve the delimiter definition functionality so less manual editing of the script is needed.
  2. Write a C# GUI that does the same thing.
  3. Add the ability to exclude image files.
  4. Integrate with BurpSuite.

Any ideas, thoughts, or recommendations would be appreciated.

::


Comments


blog comments powered by Disqus

Top

Popular

Information Security / Technology

Politics

Philosophy & Religion

Technology & Science

Culture & Society

Miscellaneous

Arguments

Projects

Collections

Twitter

  • I can't beat Belial because I can't even move. Major lag in a single player game is completely ridiculous. This is unprogress. #blizzardfail
  • Error 37 is the new fail whale, except after a 5-Hour Energy at midnight after waiting for four years...it's quite a bit more serious.
  • Every cliché has a silver lining: they're tells for laziness.
  • Go download Greyhound, by Swedish House Mafia and turn it up loud. It'll turn Monday into a Friday before a six day weekend.

What I'm Reading

Favorite Books and Essays

Top Blog Categories

Inputs