Application Stack Traceroute v4.0.1 è live

🚀 la suite open-source di web security testing più avanzata dal punto di vista matematico per bug bounty hunter.

Application Stack Traceroute v4.0.1
Open Source · Bug Bounty Suite · v4.0.1-stable

Application Stack
Traceroute

security-traceroute & security-crawler
v4.0.1 · Released 2026-03-28
$ security-traceroute https://target.com
security-traceroute
Maps the complete request processing chain. Finds parsing discrepancies between WAF and backend. Generates and validates custom bypass techniques automatically.
22+ discrepancy techniques
11 infra layers
bypass generation
–debug flag
$ security-crawler https://target.com
security-crawler
Intelligent vulnerability scanner with behavioral analysis, recursive wordlist scanning, mutation engine, and technology-aware payload selection.
10+ vuln categories
150+ payloads/type
7 mutation operators
auth support
🌐 CDN Cloudflare · Akamai
Fastly · CloudFront
🛡️ WAF ModSecurity · AWS
Imperva · F5
⚖️ Load Balancer HAProxy · nginx
Traefik · Envoy
🔀 Reverse Proxy nginx · Apache
Caddy · Varnish
⚙️ Backend PHP · Python · Java
Node · Ruby · Go
WAF Parses Request As:
GET /admin HTTP/1.1
Transfer-Encoding: chunked
Host: target.com
X-Original-URL: /safe
→ ✅ Allowed (sees /safe)
Backend Parses Request As:
GET /admin HTTP/1.1
Content-Length: 0
Host: target.com
X-Original-URL: /admin
→ 🔓 Executes /admin
Bayesian Inference
P(bypass|E) ∝ P(E|bypass) × P(bypass)
score = 0.5 + (ceil − 0.5) × conf
Dynamic bypassability score. Each infrastructure signal updates probability. Convergence bonus per agreeing classifier. No hardcoded percentages.
Graph Theory · DAG
A* + Dijkstra
min-cost attack path · 7 technique nodes
Attack chains as Directed Acyclic Graphs. A* with domain heuristics finds the optimal exploit sequence. Adaptive replanning after each Bayesian update.
Shannon Entropy
H = −Σ p(x) log₂ p(x)
Response bodies scored for information leakage. Low entropy post-probe signals WAF normalization. Used as fingerprint dimension in feature space.
Mahalanobis Distance
D² = (x−μ)ᵀ Σ⁻¹ (x−μ)
7-dim feature vector per response
HTTP responses projected in 7D feature space (status, size, timing, entropy, header count, unique ratio, reflections). Distance exposes inter-layer discrepancies.
Semantic NLP Engine
Ontology-based fuzzy classifier
+ IntelligentBypassValidator
Error messages classified via fuzzy logic + ontology. Multi-strategy retry with ResponseDifferentialAnalyzer. Confirmed bypasses upgraded to CRITICAL severity.
📋 v4.0.1 Release Notes
Fixed
security-traceroute — crash KeyError: ‘api_gateway’ on targets with missing API gateway layer
security-traceroute — 4 false-positive bypass reports via homepage fingerprint filter
security-traceroute — output path always resolved to canonical results/ directory
security-crawler — corrected auth flags: –auth-login-url · –auth-username · –auth-password
Mutation engine — diversified candidate selection: all 7 operators guaranteed coverage
Graph chain — SSRF node now has executor + fallback log (no longer silently skipped)
Added
security-traceroute –debug — logs all HTTP I/O, headers and data flows to debug_*.json
Bypassability score — dynamic formula replacing hardcoded percentages per error type
Adaptive replanning — always shows before/after probability comparison after Bayesian update
IntelligentBypassValidator — integrated into graph chain via _confirm_chain_hit() helper
14 practical usage examples with correct flag names in README
0 Vulns · testphp
0% Detection Rate +
0 Discrepancy Techniques
0+ Payloads / Vuln Type
SQL Injection
Remote Code Execution
XSS
SSTI
XXE
LFI
CRLF Injection
XPath Injection
CSRF
Open Redirect
WAF Bypass Generation
Behavioral Anomaly Detection
Phase 01
📡
Protocol Discovery
HTTP/1.1, HTTP/2, HTTP/3, WebSocket
Phase 02
🔬
Stack Fingerprinting
11 layers · 4-dimension confidence
Phase 03
⚡
Discrepancy Testing
22+ parser discrepancy techniques
Phase 04
🧬
Bypass Generation
Custom payloads per fingerprint
Phase 05
✅
Validation
IntelligentBypassValidator · real-time
Phase 06
📄
Report Export
JSON + text report · PoC generation
Confidence Scoring System — 100pt Scale
HTTP Header Analysis
40 pts
Body Pattern Matching
30 pts
Behavioral Testing
20 pts
Timing Analysis
10 pts

Mesi di ricerca e sviluppo condensati in v4.0.1-stable: due tool, una suite unificata, installati in un venv e richiamati direttamente:


🧠 Cosa la rende diversa?

La maggior parte degli scanner lancia payload e conta le risposte. Questo ragiona.

Il motore è costruito su fondamenta matematiche formali:

→ Inferenza Bayesiana — ogni segnale infrastrutturale aggiorna la probabilità di bypass. Lo score è dinamico: 0.5 + (ceiling − 0.5) × confidence, con bonus di convergenza per ogni classificatore concorde. Nessuna percentuale hardcoded.

→ Teoria dei Grafi (DAG + A* + Dijkstra) — le catene di attacco sono Directed Acyclic Graph. Il planner trova il percorso a costo minimo verso il bypass con euristiche di dominio.

→ Entropia di Shannon — i body delle risposte vengono analizzati per information leakage. Bassa entropia post-probe = normalizzazione WAF = segnale di fingerprint.

→ Distanza di Mahalanobis — le risposte HTTP proiettate in spazio feature 7-dimensionale. La distanza tra fingerprint di layer espone le discrepanze di parsing tra CDN, WAF e backend.

→ Semantic Fingerprinting NLP-inspired — messaggi di errore classificati via fuzzy logic + ontologia. Il motore distingue semanticamente i tipi di blocco e adatta la strategia.


📊 Benchmark reali:
✅ 27 vulnerabilità — testphp.vulnweb.com — 21.7 min
✅ 15 vulnerabilità — DVWA — 18 min
✅ +114% detection rate vs v3.5
✅ 1.269 richieste HTTP — stabilità 99.9% — 76MB memoria media

Application Stack Traceroute — Installation & License Guide

This guide walks you through cloning the repository, setting up a Python virtual environment, installing the suite, and activating your complimentary license key.


Prerequisites

  • Python 3.8 or higher
  • Git
  • An internet connection (required for license activation)

Verify your Python version:


Step 1 — Clone the Repository


Step 2 — Create and Activate the Virtual Environment

Your prompt will change to show (venv) — this confirms the environment is active. All subsequent commands must be run inside this environment.

Note: Every time you open a new terminal session you need to re-activate the environment before using the tools:


Step 3 — Install the Suite

With the virtual environment active, install the package in editable mode:

This installs both tools and registers their entry points. Once complete, the following commands become available directly in your shell:

Verify the installation:


Step 4 — Activate Your License

The complimentary license key for LinkedIn readers is:

Run the activation command from within the virtual environment:

The tool will contact the license server, register your key, and confirm activation. If a license is already active on your machine, the existing activation slot is released automatically before the new key is registered — no manual deactivation required.

Check your license status at any time:

Expected output:


Step 5 — Run Your First Scan

Infrastructure analysis:

Vulnerability scan:

Combined workflow (recommended):

Authenticated scan:


Deactivating the Virtual Environment

When you are done, deactivate the environment with:


Troubleshooting

security-traceroute: command not found The virtual environment is not active. Run source venv/bin/activate first.

pip install -e . fails with permission errors Make sure you are inside the virtual environment before running pip. Never use sudo pip inside a venv.

License activation fails — “unable to reach license server” Check your internet connection. If you are behind a proxy, set the standard HTTP_PROXY / HTTPS_PROXY environment variables before running the activation command.

License activation fails — “key already in use” The key has reached its activation limit. Contact me directly via LinkedIn message to request a reset.


This key is provided exclusively for readers of the LinkedIn announcement post. Authorized security testing only — always obtain explicit permission before scanning any target.


Solo per authorized security testing. Ottenere sempre la giusta autorizzazione prima di testare.

BugBounty #PenetrationTesting #CyberSecurity #EthicalHacking #WebSecurity #WAF #Python #OpenSource #SecurityResearch #AppSec #InfoSec


Potrebbe interessarti anche

ItalianoitItalianoItaliano