Files
OneForAll-mirror/docs/en-us/usage_help.md
T
Jing Ling 482c7d6ba2 优化
2020-08-17 18:32:02 +08:00

7.8 KiB
Raw Blame History

🤔Help

The command line parameters only provide some common parameters. For more detailed parameter configuration, please see config.py if you think Some parameters are frequently used in the command interface or missing parameters. Feedback is welcome. For well-known reasons, if you want to use some of the wall's collection interface, please go to config.py to configure the proxy, some collection Modules need to provide APIs (most of which are freely available for registered accounts). If you need to use them, please go to api.py to configure the API. Information, if not used, please ignore the error message. (For detailed modules, please read collection module description)

The OneForAll command line interface is based on Fire. For more advanced usage of Fire, please refer to using the Fire CLI, if you have any doubts during the use, please feel free to give me feedback.

oneforall.py is the main program entry, and oneforall.py can call aiobrute.py, takerover.py and dbexport.py and other modules, in order to facilitate the sub-field blasting, aiobrute.py is isolated independently, in order to facilitate the subdomain takeover risk check independently takeover.py, in order to facilitate the database export independently dbexport.py, these modules can be run separately, and the parameters accepted are more abundant.

Note: When you encounter some problems or doubts during use, please use Issues to search for answers. Also see Q&A.

  1. oneforall.py help

    python oneforall.py --help
    
    NAME
        oneforall.py - OneForAll help summary page
    
    SYNOPSIS
        oneforall.py COMMAND | <flags>
    
    DESCRIPTION
        OneForAll is a powerful subdomain integration tool
    
        Example:
            python3 oneforall.py version
            python3 oneforall.py check
            python3 oneforall.py --target example.com run
            python3 oneforall.py --targets ./domains.txt run
            python3 oneforall.py --target example.com --alive False run
            python3 oneforall.py --target example.com --brute True run
            python3 oneforall.py --target example.com --port medium run
            python3 oneforall.py --target example.com --format csv run
            python3 oneforall.py --target example.com --dns False run
            python3 oneforall.py --target example.com --req False run
            python3 oneforall.py --target example.com --takeover False run
            python3 oneforall.py --target example.com --show True run
    
    
        Note:
            --alive  True/False         Only export alive subdomains or not (default False)
            --port   small/medium/large  See details in ./config/setting.py(default small)
            --format rst/csv/tsv/json/yaml/html/jira/xls/xlsx/dbf/latex/ods (result format)
            --path   Result path (default None, automatically generated)
    
    FLAGS
        --target=TARGET
         One domain (target or targets parameters must be provided)
        --targets=TARGETS
            File path of one domain per line
        --brute=BRUTE
            Use brute module (default False)
        --dns=DNS
            Use DNS resolution (default True)
        --req=REQ
            HTTP request subdomains (default True)
        --port=PORT
            The port range to request (default small port is 80,443)
        --alive=ALIVE
            Only export alive subdomains (default False)
        --format=FORMAT
            Result format (default csv)
        --path=PATH
            Result path (default None, automatically generated)
        --takeover=TAKEOVER
            Scan subdomain takeover (default False)
    
    COMMANDS
        COMMAND is one of the following:
    
        check
          Check if there is a new version and exit
    
        version
          Print version information and exit
    
  2. aiobrute.py help

    With regard to the handling of the universal parsing problem, first of all, OneForAll accesses a random subdomain to determine whether universal parsing is used, and if universal parsing is used, it is handled by the following judgment:

    • First, it is mainly compared with the pan-parsed IP set and TTL values, see this article.

    • Second, the number of times to resolve to the same IP collection multiple times (the default is 10, which can be set to size in config.py).

    • Third, considering the blasting efficiency, there is no HTTP response volume similarity comparison and response volume content judgment, this function has not been implemented yet, and will be implemented if necessary.

    python aiobrute.py --help
    
    NAME
        aiobrute.py - OneForAll multi-process multi-correlation asynchronous subdomain blasting module
    
    SYNOPSIS
        aiobrute.py --target=TARGET <flags>
    
    DESCRIPTION
        Example
            python3 aiobrute.py --target example.com run
            python3 aiobrute.py --target ./domains.txt run
            python3 aiobrute.py --target example.com --process 4 --coroutine 64 run
            python3 aiobrute.py --target example.com --wordlist subdomains.txt run
            python3 aiobrute.py --target example.com --recursive True --depth 2 run
            python3 aiobrute.py --target m.{fuzz}.a.bz --fuzz True --rule [a-z] run
    
        Note:
            Parameter valid optional value 1, 0, none indicates that the export is 
            valid, invalid, and all subdomains, respectively.
    
            Parameter format have optional values 'txt', 'rst', 'csv', 'tsv', 'json', 
            'yaml', 'html', 'jira', 'xls', 'xlsx', 'dbf', 'latex', 'ods'.
            If the parameter path is None, the appropriate file is generated in the 
            project result directory based on the format parameter and the domain 
            name.
    
    ARGUMENTS
        TARGET
            Single domain name or file path for one domain name per line (required)
    
    FLAGS
        --process=PROCESS
            Number of processes blasted (default CPU core count)
        --coroutine=COROUTINE
            Number of coroutines per blasting process (default 1024)
        --wordlist=WORDLIST
            Specify the dictionary path used for blasting (config.py is used by default)
        --recursive=RECURSIVE
            Whether to use recursive blasting (default False)
        --depth=DEPTH
            Depth of recursive blasting (default 2)
        --namelist=NAMELIST
            Specifies the dictionary path used by recursive blasting (configured by default using config.py)
        --fuzz=FUZZ
            Whether to use the fuzz mode for blasting (default False, you must specify the fuzz regular rule)
        --rule=RULE
            Regular rules used by fuzz mode (configured by default using config.py)
        --export=EXPORT
            Whether to export the blast result (default True)
        --valid=VALID
            Export validity of subdomains (default None)
        --format=FORMAT
            Export format (default xls)
        --path=PATH
            Export path (default None)
        --show=SHOW
            Terminal display exported data (default False)