{"repo":"BishopFox/eyeballer","free":true,"listed":false,"github":"https://github.com/BishopFox/eyeballer","clone":"git clone https://github.com/BishopFox/eyeballer.git","description":"Convolutional neural network for analyzing pentest screenshots","language":"Python","stars":1290,"topics":["security-tools","machine-learning","ai","python","tensorflow","pentesting-tools"],"license":"GPL-3.0","category":"machine-learning","readme_excerpt":"Eyeballer Give those screenshots of yours a quick eyeballing. Eyeballer is meant for large-scope network penetration tests where you need to find \"interesting\" targets from a huge set of web-based hosts. Go ahead and use your favorite screenshotting tool like normal (EyeWitness or GoWitness) and then run them through Eyeballer to tell you what's likely to contain vulnerabilities, and what isn't. Give it a try live at: https://eyeballer.bishopfox.com Example Labels Old-Looking Sites Login Pages ------ :-----: Webapp Custom 404's ------ :-----: Parked Domains ------ What the Labels Mean Old-Looking Sites Blocky frames, broken CSS, that certain \"je ne sais quoi\" of a website that looks like it was designed in the early 2000's. You know it when you see it. Old websites aren't just ugly, they're also typically super vulnerable. When you're looking to hack into something, these websites are a gold mine. Login Pages Login pages are valuable to pen testing, they indicate that there's additional functionality you don't currently have access to. It also means there's a simple follow-up process of credential enumeration attacks. You might think that you can set a simple heuristic to find login pages, but in practice it's really hard. Modern sites don't just use a simple input tag we can grep for. Webapp This tells you that there is a larger group of pages and functionality available here that can serve as surface area to attack. This is in contrast to a simple login page, with no other ","default_branch":null,"files":null,"tree":[],"storefront":"/r/BishopFox","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/BishopFox/eyeballer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}