Arjun v1.3 – HTTP Parameter Discovery Suite

FeaturesMulti-threading4 modes of detectionA typical scan takes 30 secondsRegex powered heuristic scanningHuge list of 25,980 parameter namesMakes just 30-35 requests to the targetUsageNote: Arjun doesn’t work with python < 3.4Discover parametersTo find GET parameters, you can simply do:python3 arjun.py -u https://api.example.com/endpoint --getSimilarly, use --post to find POST parameters.Multi-threadingArjun uses 2 threads by default but you can tune its performance according to your network connection.python3 arjun.py -u https://api.example.com/endpoint --get -t 22Delay between requestsYou can delay the request by using the -d option as follows:python3 arjun.py -u https://api.example.com/endpoint --get -d 2Including presistent dataLet's say you have an API key that you need to send with every request, to tell Arjun to do that you can use the --include option as follows:python3 arjun.py -u https://api.example.com/endpoint --get --include 'api_key=xxxxx'ORpython3 arjun.py -u https://api.example.com/endpoint --get --include '{"api_key":"xxxxx"}'To include multiple parameters, use & to seperate them or pass them as a valid json object.JSON OutputYou can save the result in a JSON format by using the -o as follows:python3 arjun.py -u https://api.example.com/endpoint --get -o result.jsonAdding HTTP HeadersUsing the --headers switch will open an interactive prompt where you can paste your headers. Press Ctrl + S to save and Ctrl + X to procced.Note: Arjun uses nano as the default editor for the prompt but you can change it by tweaking /core/prompt.py.CreditsThe parameter names are taken from @SecLists.Download Arjun

Link: http://www.kitploit.com/2019/03/arjun-v13-http-parameter-discovery-suite.html