added demo, features, credits

This commit is contained in:
Somdev Sangwan
2018-12-30 03:53:30 +05:30
committed by GitHub
parent 8ee5c0bf01
commit c76a00b6e9

View File

@@ -20,8 +20,31 @@
</a> </a>
</p> </p>
![demo](https://i.ibb.co/mTtHTGP/Screenshot-2018-12-30-03-42-26.png)
### Important ### Important
Bolt is in alpha phase of development which means it's full of bugs. Any production use of this tool discouraged. Bolt is in alpha phase of development which means it's full of bugs. Any production use of this tool discouraged.
Pull requests and issues are welcome. I also suggest you to put this repo on watch if you are interested in it.
### Current Features
- Crawling
- Complete HTTP Support
- Checks
- Entropy
- Replay attack
- Absence of CSRF protection when requested from a mobile
- Removing CSRF token parameter from request
- Removing CSRF token from parameter
- Requesting resources with a fake token
- Potenial race condition
### Features to be added
- Support CSRF tokens in cookies
- Referrer and Origin based checks
- Checks
- True entropy of tokens
- Checking if server checks the token to a specific length
and more...
### Usage ### Usage
@@ -37,3 +60,6 @@ Other options and switches:
- `--delay` delay between requests - `--delay` delay between requests
- `--timeout` http request timeout - `--timeout` http request timeout
- `--headers` supply http headers - `--headers` supply http headers
#### Credits
Regular Expressions for detecting hashes are taken from [hashID](https://github.com/psypanda/hashID).