- MapperPlus facilitates the validation and retrieval of all .js/.js.map files from a specified target or a list of targets. It subsequently employs SourceMapper to extract source code for all your designated targets.
- MapperPlus utilizes a Chrome Headless browser to intercept every request and response, ensuring the download of JavaScript files goes beyond heuristic scans or regular expressions, and includes the handling of all requested JS files.
- MapperPlus is based on an already existing tool called SourceMapper which helps you extract the source code from a single .map file.
MapperPlus could be used with httpx , jsluice or Trufflehog and more. (https://github.com/BishopFox/jsluice/ , https://github.com/projectdiscovery/httpx , https://github.com/trufflesecurity/trufflehog )
- You can use httpx to retrieve live webservers and then use its output as an input of MapperPlus.
- After downloading and extracting all JS files, use JSluice to extract endpoints from every target and then go beyond your recon process.
- You can use Jsluice or trufflehog also to extract secrets from your source code JS files.
- And more...!
MapperPlus requires :
- Google Chrome : You can install it using the following command :
apt install google-chrome-stable
- Node.Js : You can install it using the following command:
apt install nodejs
- Npm : You can install it using the following command:
apt install npm
- Go
- Python
- SourceMapper : You can download it from here: https://github.com/denandz/sourcemapper
- Run the requirements.sh script in order to download the latest version of required node modules.
- Make sure Chrome is installed in your machine: Run this command to verify
google-chrome --version
- Make sure you have npm, Node.js and Sourcemapper installed.
MapperPlus have some features and accepts some arguments:
- To download all .map files for a specific website, utilize the
-u
option with the URL of your target, and the-t
option with the destination directory where the JS files will be saved. (-u
and-t
are required.)python3 mapperplus.py -u https://www.example.com/ -t
MapperPlus also offers the option to include cookies and custom headers if needed. You can use -c
to specify a cookie file and -h
to provide custom headers.
Example 1: python3 mapperplus.py -u https://www.example.com/ -t example_output_directory -c cookiefile.txt -h "Authorization: Basic YWRtaW46YWRtaW4="
- In order to download and extract source codes of multiple targets at once, you can use the
-r
with the list of your targets.
Example 2: python3 mapperplus.py -r targets.txt -t example_output_directory -c cookiefile.txt -h "Authorization: Basic YWRtaW46YWRtaW4="
- Download Lazy loaded .js files/chunks and look for their .map files too. (This will uncover the hidden parts of a number of websites) - Security By Obscurity.
- Address specific scenarios: When retrieving multiple .js files from multiple sources, some websites may require specific cookies to avoid encountering 4xx errors.
You can add more ideas or contact me on my X profile to share your ideas or needs: https://twitter.com/silentgh00st