Skip to content
A fuzzer for any GET entries
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
demo
wordlist
README.md Update README.md May 28, 2019
brutality.py Add cores May 20, 2019
requirements.txt

README.md

Brutality

made-with-python

What is this?

A 'brutality' fuzzer for any GET entries

Features

  • Multi-threading on demand
  • Fuzzing, bruteforcing GET params
  • Find admin panels
  • Colored output
  • Hide results by return code, word numbers
  • Proxy support
  • Big wordlist

Usages

  • Install
git clone https://github.com/ManhNho/brutality.git
chmod 755 -R brutality/
cd brutality/
pip install -r requirements.txt
  • Helps
python brutality -h

Examples

  • Use default wordlist with 5 threads (-t 5) and hide 404 messages (–e 404) to fuzz the given URL (http://192.168.1.1/FUZZ):
python brutality.py -u 'http://192.168.1.1/FUZZ' -t 5 -e 404
python brutality.py -u 'http://192.168.1.1/brute.php?username=admin&password=FUZZ&submit=submit#' -f ./wordlist/common_pass.txt -r 6969 -p http://127.0.0.1:8080

Images

Example

Videos

Demo

ToDo

  • Smooth output
  • Export file report
  • Modularization

References

You can’t perform that action at this time.