Differences between Hunt Methods
|Hunt Method||CLI name||Type||Brute F.||Injection||DoS||Time-Con.|
|Structure Brute Force||structbf||Y (Deep)||N||N||Y (Very)|
|Old & Backup Files||fileold||Y||N||N||Y|
|Top 5 (OWASP PHP)||top5||N||P (TOP5)||N||N|
|Cross-Site Scripting||xss||N||P (XSS)||N||N|
|SQL Injection||sqlinj||N||P (SQL)||N||N|
|File Inclusion||fileinc||N||P (FI)||N||N|
|Unvalidated Redirects||unvredir||N||P (UR)||N||N|
|Malware Content||malscan||P (Malware)||P (Malware)||N||N|
|Complete Scan||complete||Y||Y||Y||Y (Very)|
|Complete Scan, No DoS||compnodos||Y||Y||N||Y (Very)|
|Complete Scan, Paranoid||comppnoid||Y (Deep)||Y||Y||Y (Very)|
Letters: Yes/No/Partial (Y/N/P)
Type of Testing
- - Hybrid (Gray Box), Dynamic & Code
- - Dynamic Only (Black Box)
- - Code Only (White Box)
Identifies flaws in custom web applications. This scan method crawls the web site and performs attacks against the web site structure and the web applications. This includes looking for fault injection vulnerabilities such as XSS, SQL Injection, File Inclusion, and more.
Structure Brute Force
A structure brute force will check for:
- Common Vulnerable Scripts
- Common File Checks
- Custom File Checks (User File Checks)
- Database Disclosure
- Web-Based Backdoors
The number of checks is influenced by the number of directories found during the spidering stage.
OWASP PHP Top 5
Scans specifically for the OWASP Top Five List of PHP Vulnerabilities. Remote Command Execution, XSS, SQL Injection and File Inclusion flaws
Scans specifically for fault injection vulnerabilities. If this scan method is selected, all other checks that does not require injection are disabled and Syhunt will then specifically check for SQL injection, XSS, file inclusion, and similar flaws.
Cross-Site Scripting (XSS)
Scans specifically for XSS vulnerabilities.
Scans specifically for SQL & NoSQL Injection vulnerabilities.
Scans for all kinds of web application vulnerabilities using all kinds of mutantions and pen-tester methods. A Complete Scan can sometimes be very time-consuming when performed against a web server that has a large quantity of web folders and entry points.
Complete Scan (No DoS)
Same as before, but with denial-of-service tests disabled.
Complete Scan (Paranoid)
Scans for all kinds of web application vulnerabilities using deep structure brute force, all kinds of mutantions and pen-tester methods. This scan method can be very time-consuming, specially when executed against large web sites. This method also executes triple checking structure brute force, which applies to case-sensitive servers - Syhunt will try all file name possibilities (all uppercase, all lowercase, all leading capitals, etc).
For additional product documentation, visit syhunt.com/docs