v3n0m : for finding and executing various vulnerabilities.

v3n0m is a free and open source scanner.This program is for finding and executing various vulnerabilities. It scavenges the web using dorks and organizes the URLs it finds. it has adapted several new features that improve fuctionality and usability.
Features :

  • Remote Code Execution [RCE]
  • Local File Inclusion [LFI]
  • Cross Site Scripting [XSS]
  • SQL Injection [SQLi]
  • Extremely Large D0rk Target Lists
  • FTP Crawler
  • DNS BruteForcer
  • MITM Detection

To Do:

  • Largest and most powerful d0rker online, 18k+d0rks searched over 13 Engines at once.
  • Free and Open /src/
  • CrossPlatform Python based toolkit
  • Licensed under GPLv2
  • Tested on: Linux 3.2.6 Ubuntu/Debian, CentOS 6 (with some errors), Win7 (with some errors)


root@bt: v3n0m.py

Now you may follow the simple prompts.

[0x100] Choose your target (domain) :
Example : .com
it is necessary to add you can also use a specific website (www.example.com)

[0x200] Choose the number of random dorks (0 for all.. may take awhile!) :
Example : 0 = This will choose all of the XSS, File Inclusion, RCE and SQLi dorks

[0x300] Choose the number of threads :
Example : 50

[0x400] Enter the number of pages to search through :
Example : 50

The program will print out your desired settings and start searching.
It then creates files for the collected and valid URLs for later.
It takes a while to scan because it utilizes either TOR, which you can specify
if you wish to do so, or regular HTTP requests over a long period of time.

After a while, it will feed you the percentage of the scan until completion.
At this point, it will have saved the valid URLs in the files it created earlier.
The program utilizes over 10k dorks now, be careful how you use them!
Enjoy. :]

Download : V3n0m.scanner.master.zip (359 KB) | repo git
Sources :  V3n0m