/Oralyzer

Open Redirection Analyzer

Primary LanguagePythonGNU General Public License v3.0GPL-3.0

Introduction

Oralyzer, a simple python script, capable of identifying the open redirection vulnerability in a website. It does that by fuzzing the url i.e. provided as the input.

Features

Oralyzer can identify different types of Open Redirect Vulnerabilities:

  • Header Based
  • Javascript Based
  • Meta Tag Based

Oralyzer uses waybackurls to fetch URLs from web.archive.org, it then separates the URLs that have specific parameters in them, parameters that are more likely to be vulnerable.

Installation

Use python v3.7

$ git clone https://github.com/r0075h3ll/Oralyzer.git
$ pip3 install -r requirements.txt
$ go get github.com/tomnomnom/waybackurls

Usage

Upcoming Features

  • Improved DOM XSS detection mechanism
  • Test multiple parameters in one run
  • Improved speed
  • CRLF Injection Detection

Contribution

You can contribute to this program in following ways:

  • Create pull requests
  • Report bugs
  • Hit me up on Twitter with a new idea/feature