arjun - HTTP parameter discovery suite
Contents
Description
Arjun can find query parameters for URL endpoints. If you don't get what that means, it's okay, read
along. Web applications use parameters (or queries) to accept user input, take the following example
into consideration:
http://api.example.com/v1/userinfo?id=751634589
This URL seems to load user information for a specific user id, but what if there exists a parameter
named admin which when set to True makes the endpoint provide more information about the user? This is
what Arjun does, it finds valid HTTP parameters with a huge default dictionary of 25,890 parameter names.
The best part? It takes less than 10 seconds to go through this huge list while making just 50-60
requests to the target. Here's how.
- Supports GET/POST/POST-JSON/POST-XML requests
- Automatically handles rate limits and timeouts
- Export results to: BurpSuite, text or JSON file
- Import targets from: BurpSuite, text file or a raw request file
- Can passively extract parameters from JS or 3 external sources
Examples
arjun-harjun-uhttp://site.example.com/test.phparjun-uhttp://site.example.com/test.php-o test.json arjun-uhttp://site.example.com-t 5 arjun-uhttp://site.example.com--stable
Name
arjun - HTTP parameter discovery suite
Options
-h,--help
show this help message and exit.
-uURL Target URL.
-oJSON_FILE,-oJJSON_FILE
Path for json output file.
-oTTEXT_FILE
Path for text output file.
-oB[BURP_PORT]
Port for output to Burp Suite Proxy. Default port is 8080.
-dDELAY
Delay between requests in seconds. (default: 0).
-tTHREADS
Number of concurrent threads. (default: 5).
-wWORDLIST
Wordlist file path. (default: /usr/lib/python3/dist-packages/arjun/db/large.txt).
-mMETHOD
Request method to use: GET/POST/XML/JSON/HEADERS. (default: GET).
-i[IMPORT_FILE]
Import target URLs from file.
-TTIMEOUT
HTTP request timeout in seconds. (default: 15).
-cCHUNKS
Chunk size. The number of parameters to be sent at once.
-q Quiet mode. No output.
--headers[HEADERS]
Add headers. Separate multiple headers with a new line.
--passive[PASSIVE]
Collect parameter names from passive sources like wayback, commoncrawl and otx.
--stable
Prefer stability over speed.
--includeINCLUDE
Include this data in every request.
--disable-redirects
disable redirects.
Synopsis
arjun [-h] [-uURL] [-oJSON_FILE] [-oTTEXT_FILE] [-oB [BURP_PORT]] [-dDELAY] [-tTHREADS] [-wWORDLIST] [-mMETHOD] [-i [IMPORT_FILE]]
[-TTIMEOUT] [-cCHUNKS] [-q] [--headers [HEADERS]] [--passive [PASSIVE]] [--stable] [--includeINCLUDE] [--disable-redirects]
