Sn1per Professional /. Part 1 Penetration testing software for offensive security experts

DrEngerek

Kıdemli Üye
20 Kas 2015
2,344
1
Teşkilat
Sn1per-Professional-v7.0-Dashboard2.png


Product FAQ

1) What is Sn1per?
Sn1per Community Edition is an automated scanner that can be used during a penetration test to enumerate and scan for vulnerabilities. Sn1per Professional is XeroSecurity’s premium reporting addon for professional penetration testers, bug bounty researchers and Corporate security teams to manage large environments and pentest scopes.


2) I have Sn1per Professional installed. Can I still apply updates from Sn1per Community Edition on GitHub?
Yes, updating Sn1per Community Edition will not effect your Sn1per Professional installation in any way. You can still get all the benefits of the Community Edition with your Professional installation.

3) I received an error XYZ in the Sn1per Community Edition script. Should I contact with the error message?
Premium support via

is only offered to Sn1per Professional licenses and for the pro.sh script (Professional portion) only. For all other Sn1per related issues, please submit an issue ticket at.

4) Can I run Sn1per on other operating systems other than Kali Linux or Debian?
Sn1per was designed to run in Kali Linux and Debian, and because of its dependencies we only provide support for installations under these operating systems. That said, you can also run a Kali VM on top of a Mac host OS, but that requires VMWare Fusion or VirtualBox.

5) How does the Professional version differ from the Community version?
The short answer… the Professional version requires a paid license that provides you with a professional reporting interface generated from each scan (and top notch customer support). For the long answer, we encourage you to click around the site and learn more about Sn1per Professional.

6) Help! My scanner appears to be stuck when running a scan.
If you are certain your scanner is stuck (keep in mind some scans can take longer than others), it can often mean you are being blocked by the target. In either case, you should be able to bypass this by typing “killall nmap”. Another alternative is in a separate terminal, run sniper –status to get the PIDs of any running sniper processes. Run kill-9 <PID> to kill off the problematic process to allow the scan to continue.

7) When will the next version of Sn1per Professional be released?
We don’t publish a schedule, but if you want to be the first to know make sure you sign up for our newsletter or follow us on Twitter.

8) How is the price of Sn1per Professional determined?
Prices reflect the value the product gives you (such as more features and functionality). Each product is priced per license. If you need more than one user you would need to adjust your cart quantity accordingly.


9) How many people can use Sn1per Professional?
Our licenses are single user, that means it is just for you – one person. If you need to purchase one for you and your friend, you will need to purchase multiple single user licenses.


10) Can I install Sn1per Professional on multiple computers using the same license?
While Sn1per Professional is a single user license, we do limit the number of systems you may install it on to 5 systems per license.

11) How long do you support previous versions of Sn1per Professional?
We maintain usability in previous versions as long as possible and guarantee functionality for up to 1 year from the release date. Support currently on Sn1per Professional v.6 is 6 months and Sn1per Professional v.7 is 12 months.

12) What is the difference between Sn1per Community and Sn1per Professional?
There are two components to Sn1per:

Sn1per Community Edition which is found on GitHub and makes up the scan engine/terminal application of Sn1per.
Sn1per Professional is comprised of the web UI/reporting front end to Sn1per and works in conjuction to the scan engine found in the Community Edition.
These two components are independent of each other and function together to provide additional functionality and value as seen below. The versions of both components do not necessarily always match or need to in order to function.

For all issues related to the Community Edition (scan engine), we ask that users open a new GitHub issue here for assistance. Premium support at Sni1per is only provided for the web reporting interface (Sn1per Professional).


System Requirements

Sn1per Professional requires the following to run correctly:
  • A Debian Linux based operating system (Kali Linux 2.x is preferred).
  • "root" user access to the host OS.
  • Access to the host X windows GUİ environment (İe. KDE/Gnome/Blackbox, etc).
    [*]an acitive internet connection is required

Sn1perProDiagramNumbered6.0.png


Sn1per Professional Dashboard
Provides quick access to all Sn1per reports, online tools, configuration files, target lists, and XeroSecurity links.

Top menu features:


1. Sn1per Professional v6.0 – a quick link to XeroSecurity website
2. Home – a quick link to the main dashboard
3. Quick Links – one click access to Sn1per ********ation, Sn1per GitHub, XeroSecurity support, etc.
4. Online Tools – one click access to pentesting methodologies and testing checklists, as well as essential hacking utilities
5. Files – quick access to the Sn1per configuration files, as well as the scanned and unscanned targets list and total domain list
6. Reports – contains links to all Sn1per Community Edition HTML reports

Side bar features:
7. “Top” icon – returns to the top of the page
8. “Slideshow” icon – jumps to the slideshow widget
9. “Host List” icon – jumps to the host list widget
10. “Email” icon – jumps to email container
11. “Takeovers” icon – jumps to the takeovers container
12. “Notepad” icon – jumps to the notepad widget

Dashboard
13. Shortcut to XeroSecurity Twitter
14. Shortcut to the XeroSecurity website
15. Shortcut to the workspace directory
16. Displays total domains, scanned targets, and unscanned targets with quick links to each
17. Scan progress bar displays percentage of scanned vs unscanned hosts in the workspace


Slideshow

Sn1per-v6_screenshot6b.png



Flip through all collected screenshots to find interesting hosts and view the corresponding host report by clicking on the screenshot.

Enumeration



Sn1per-v6_screenshot10.png


Search and sort all subdomains, open ports, DNS info, and more. Displays searchable scan tags for each host scanned by Sn1per Professional. The search bar allows multiple types of searches including: hostnames, IP addresses, scan mode tags, HTTP titles, server headers, port numbers, etc.

Email and Takeovers


Sn1per-v6_screenshot16.png
Quickly check if any hosts in your workspace are vulnerable to email spoofing or domain hijacking/takeover.

HTML5 Notepad


Sn1per-v6_screenshot15.png


Store your notes for each workspace directly on the report, which will save a local copy automatically every few seconds. No need to re-import or save manually!

Detailed Host View


Sn1per-v6_screenshot13.png

Gain high level insight into each host in your workspace to dig deeper into the target environment.
 
Üst

Turkhackteam.org internet sitesi 5651 sayılı kanun’un 2. maddesinin 1. fıkrasının m) bendi ile aynı kanunun 5. maddesi kapsamında "Yer Sağlayıcı" konumundadır. İçerikler ön onay olmaksızın tamamen kullanıcılar tarafından oluşturulmaktadır. Turkhackteam.org; Yer sağlayıcı olarak, kullanıcılar tarafından oluşturulan içeriği ya da hukuka aykırı paylaşımı kontrol etmekle ya da araştırmakla yükümlü değildir. Türkhackteam saldırı timleri Türk sitelerine hiçbir zararlı faaliyette bulunmaz. Türkhackteam üyelerinin yaptığı bireysel hack faaliyetlerinden Türkhackteam sorumlu değildir. Sitelerinize Türkhackteam ismi kullanılarak hack faaliyetinde bulunulursa, site-sunucu erişim loglarından bu faaliyeti gerçekleştiren ip adresini tespit edip diğer kanıtlarla birlikte savcılığa suç duyurusunda bulununuz.