Skip to content

Commit 9c13036

Browse files
committed
simplify JS download, parallel analysis, fix alive URL merge
1 parent 683b918 commit 9c13036

3 files changed

Lines changed: 144 additions & 304 deletions

File tree

‎README.md‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -103,7 +103,7 @@ What changes in CTF mode:
103103
| 8 | Vulnerability scanning | nuclei, nikto, dalfox, sqlmap, crlfuzz, corsy, wpscan, commix |
104104
| 9 | SSL/TLS analysis | sslyze, testssl.sh |
105105

106-
JS analysis runs on **locally downloaded files** - katana saves responses to disk with `-store-response`, then linkfinder, SecretFinder, trufflehog, and semgrep analyze the files directly instead of making redundant HTTP requests. If katana doesn't capture enough JS files, r0zscope downloads them from discovered URLs as a fallback.
106+
JS analysis runs on **locally downloaded files** - JS URLs discovered by katana/gospider/waybackurls are filtered, downloaded via wget in parallel, then linkfinder, SecretFinder, trufflehog, and semgrep analyze the local files. Each analysis tool runs in its own goroutine, and linkfinder/SecretFinder process individual files with parallel workers.
107107

108108
---
109109

@@ -158,8 +158,9 @@ recon-output/example.com/
158158
├── subfinder/
159159
├── assetfinder/
160160
├── katana/
161-
│ ├── urls.txt
162-
│ └── js-responses/ ← JS files saved to disk
161+
│ └── urls.txt
162+
├── _jsfiles/
163+
│ └── downloaded/ ← JS files downloaded via wget
163164
├── linkfinder/
164165
│ └── endpoints.txt ← extracted from local JS
165166
├── secretfinder/

0 commit comments

Comments
 (0)