4-ZERO-3 – 403/401 Bypass Methods + Bash Automation

>_ Introduction

4-ZERO-3 Tool to bypass 403/401. This script contain all the possible techniques to do the same.

  • NOTE : If you see multiple [200 Ok]/bypasses as output, you must check the Content-Length. If the content-length is same for multiple [200 Ok]/bypasses means false positive. Reason can be “301/302” or “../” [Payload] DON’T PANIC.
  • Script will print cURL PAYLOAD if possible bypass found.

>_ Preview

AVvXsEhoGba3T9vdnrum WQkW5c vF d 26pES7w1AR Xsn3rjBWXZIgIKGtQQqvC0SC2T693Rw4yqewJnCcU4S5M6oHOaeoD2w97yvKEx6jGeuGjRfeicF 6GdI7G4oSja0xmwacc4GybJZbOzbROjMe0WzRFzsVUxR5 o1ZPpY2eqqQ joLIm6Zm8oVfDfpA=w640 h306

>_ Help

root@me_dheeraj:$ bash 403-bypass.sh -h

AVvXsEgDvAlbr3MFwWUB0wVGBAuJPiR cIhDn1a FXzBhNR RgYkvpkgsUl19bcNQ9 K6KcoWgJ qM9cFMn3Ss9c3fZj0I83 Yqp6RxN9w7thB1WMtz0 m QXlAvt B7d9LFoNjVZQsqffiS7JPOR1kJtxTdeN iyHOBKRr 6 a8EDOaJmjQpX0jRXb68brvkg=w640 h310

 

>_ Usage / Modes

  • Scan with specific payloads:
    • [ --header ] Support HEADER based bypasses/payloads
      root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret --header
    • [ --protocol ] Support PROTOCOL based bypasses/payloads
      root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret --protocol
    • [ --port ] Support PORT based bypasses/payloads
      root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret --port
    • [ --HTTPmethod ] Support HTTP Method based bypasses/payloads
      root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret --HTTPmethod
    • [ --encode ] Support URL Encoded bypasses/payloads
      root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret --encode
    • [ --SQLi ] Support MySQL mod_Security & libinjection bypasses/payloads [** New **]
      root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret --SQLi
  • Complete Scan {includes all exploits/payloads} for an endpoint [ –exploit ]
root@me_dheeraj:$ bash 403-bypass.sh -u https://target.com/secret --exploit
Prerequisites
  • apt install curl [Debian]

click here to read full Article

Read More on Pentesting Tools

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *

%d bloggers like this: