Skip to content

Latest commit

 

History

18 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

JSlooting logo

JSlooting

Offline JavaScript sensitive/interesting info extractor

Disclaimer

This tool is provided for authorized security research and educational purposes only.

  • Only use this tool on systems you own or have explicit written permission to test
  • The authors assume no liability for misuse or damage caused by this tool
  • Users are responsible for complying with all applicable local, state, and federal laws
  • This tool comes with no warranty - use at your own risk

By using this software, you agree that you will not use it for any illegal or unauthorized activities.

About

JSlooting is a tool built for authorized penetration tests and security research.

Please note that some of the tool's results might be false positives

Please note that the tool might miss, not find, or not show something

Prerequisites

  • Python 3.7+ (3.9+ recommended)
  • tkinter

Installation + Usage:

git clone https://github.com/SAsecurityN/JSlooting.git
cd JSlooting

# Use the tool:
python3 jslooting.py

A look at the tool: JSlooting interface

Usage

Upload .js file or just paste its contents into the tool, then press Scan and the tool will search for:

  • Secrets / API Keys
  • URLs
  • Relative endpoints
  • Cloud storage buckets
  • IPs & Emails
  • Hosts/Subdomains And show the output in the FINDINGS section.

Output showcase: Output showcase 1 Output showcase 2 Output showcase 3 Output showcase 4 Press Clear button to clear the contents of current input.

LICENSE

MIT

About

JSlooting is a tool designed to help in authorized penetration testing and security research with analyzing found .js files.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages