{"id":13842193,"url":"https://github.com/ethicalhackingplayground/tprox","last_synced_at":"2025-04-23T08:40:57.234Z","repository":{"id":57626013,"uuid":"401209091","full_name":"ethicalhackingplayground/tprox","owner":"ethicalhackingplayground","description":"TProx is a fast reverse proxy path traversal detector and directory bruteforcer.","archived":false,"fork":false,"pushed_at":"2021-09-16T15:46:54.000Z","size":35764,"stargazers_count":28,"open_issues_count":0,"forks_count":4,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-04-17T22:10:20.943Z","etag":null,"topics":["hacking","misconfigurations","pentesting","proxy","vulnerabilities"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ethicalhackingplayground.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-08-30T03:52:02.000Z","updated_at":"2024-08-12T20:16:00.000Z","dependencies_parsed_at":"2022-08-30T12:50:55.806Z","dependency_job_id":null,"html_url":"https://github.com/ethicalhackingplayground/tprox","commit_stats":null,"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ethicalhackingplayground%2Ftprox","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ethicalhackingplayground%2Ftprox/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ethicalhackingplayground%2Ftprox/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ethicalhackingplayground%2Ftprox/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ethicalhackingplayground","download_url":"https://codeload.github.com/ethicalhackingplayground/tprox/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250400664,"owners_count":21424414,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["hacking","misconfigurations","pentesting","proxy","vulnerabilities"],"created_at":"2024-08-04T17:01:29.075Z","updated_at":"2025-04-23T08:40:57.212Z","avatar_url":"https://github.com/ethicalhackingplayground.png","language":"Go","funding_links":[],"categories":["Go"],"sub_categories":[],"readme":"\u003ch1 align=\"center\"\u003e\n  \u003cbr\u003e\n\u003cimg src=\"static/icon.png\" width=\"200px\" alt=\"TProx\"\u003e\n\u003c/h1\u003e\n\n\u003ch4 align=\"center\"\u003eTProx is a fast reverse proxy path traversal detector and directory bruteforcer\u003c/h4\u003e\n\n\u003cp align=\"center\"\u003e\n\u003ca href=\"https://goreportcard.com/report/github.com/ethicalhackingplayground/tprox\"\u003e\u003cimg src=\"https://goreportcard.com/badge/github.com/ethicalhackingplayground/tprox\"\u003e\u003c/a\u003e\n\u003ca href=\"https://github.com/ethicalhackingplayground/tprox/issues\"\u003e\u003cimg src=\"https://img.shields.io/badge/contributions-welcome-brightgreen.svg?style=flat\"\u003e\u003c/a\u003e\n\u003ca href=\"https://github.com/ethicalhackingplayground/tprox/releases\"\u003e\u003cimg src=\"https://img.shields.io/github/release/ethicalhackingplayground/tprox\"\u003e\u003c/a\u003e\n\u003ca href=\"https://twitter.com/z0idsec\"\u003e\u003cimg src=\"https://img.shields.io/twitter/follow/z0idsec.svg?logo=twitter\"\u003e\u003c/a\u003e\n\u003ca href=\"https://discord.gg/MQWCem5b\"\u003e\u003cimg src=\"https://img.shields.io/discord/862900124740616192.svg?logo=discord\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"#install\"\u003eInstall\u003c/a\u003e •\n  \u003ca href=\"#usage\"\u003eUsage\u003c/a\u003e •\n  \u003ca href=\"#examples\"\u003eExamples\u003c/a\u003e •\n  \u003ca href=\"https://discord.gg/MQWCem5b\"\u003eJoin Discord\u003c/a\u003e \n\u003c/p\u003e\n\n---\n\n### Install Options\n\n#### From Source\n\n```sh\n▶  GO111MODULE=on go get -v  github.com/ethicalhackingplayground/tprox/tprox\n```\n\n#### Docker\n\n```sh\n▶  git clone https://github.com/ethicalhackingplayground/tprox \u0026\u0026 cd tprox \u0026\u0026 docker build -t tprox .\n```\n\n---\n\n### Usage\n\n```sh\n▶ tprox -h\n```\n\n```sh\n▶  docker run tprox -h\n```\n\n\n\nThis will display help for the tool. Here are all the switches it supports.\n\n\u003cdetails\u003e\n\u003csummary\u003e 👉 tprox help menu 👈\u003c/summary\u003e\n\n```\nUsage of ./tprox:\n  -c int\n        The number of concurrent requests (default 10)\n  -check\n        Check if a path/folder/file is internal\n  -crawl\n        crawl the resolved domain while testing for proxy misconfigs\n  -depth int\n        The crawl depth (default 5)\n  -discover\n        Discover path/folder/file with already found traversal\n  -o string\n        Output the results to a file\n  -progress\n        This flag will allow you to turn on the progress bar\n  -regex string\n        Filter crawl with regex pattern\n  -scope string\n        Specify a scope to crawl with in using regexs\n  -silent\n        Show Silent output\n  -test\n        Enable/Disable test mode only\n  -traverse\n        This flag will allow you to turn on traversing\n  -w string\n        The wordlist to use against a valid endpoint to traverse\n```\n\n\u003c/details\u003e\n\n### Examples\n\n#### Traversal with Brute\n\n```sh\n▶ echo \"https://example.com/api/v1\" | tprox -w wordlist -traverse\n```\n\n#### Traversal with Crawling \u0026 Brute\n\n```sh\n▶ echo \"https://example.com\" | tprox -w wordlist -crawl -traverse\n```\n\n#### Traversal with Crawling, Regex Match \u0026 Brute\n\n```sh\n▶ echo \"https://example.com\" | tprox -w wordlist -crawl -traverse -regex \"/api/\"\n```\n\n#### Traversal With Crawling InScope \u0026 Brute\n\n```sh\n▶ echo \"https://example.com\" | tprox -w wordlist -crawl -traverse -regex \"/api/\" -scope \".*.\\.example.com\"\n```\n\n#### Traversal with Test Only\n\n```sh\n▶ echo \"https://example.com/api\" | tprox -test -traverse\n```\n\n#### Check if File is Internal\n\n```sh\n▶ echo \"https://example.com/api/internalfile.html\" | tprox -check\n```\n\n#### Discover Content \n\n```sh\n▶ echo \"https://example.com/api/..%2f\" | tprox -discover -progress -w wordlist\n```\n\n\n\u003ch1 align=\"center\"\u003e\n  \u003cbr\u003e\n\u003cimg src=\"static/example.png\" alt=\"example\"\u003e\n\u003c/h1\u003e\n\n--- \n\n### Changes\n\n- Added some additional flags to help aid finding traversal misconfigurations\n- Optimised the crawler\n- Added a flag to disable/enable the progress bar\n- Fixed the silent flag\n- Added check,test \u0026 discover flags\n\n### Fixes\n\n- Fixed a crawling bug.\n- Fixed a traversal bug, it now only prints internal files \u0026 endpoints very low % of false positives.\n- Made some optimization fixes.\n- Discover content fix, it was not finding content.\n- Optimisation fixes.\n\n### Known Fixes\n\nif for some reason the program fails to install or update run:\n\n```sh\nsudo rm -r /home/\u003cuser-name\u003e/go/pkg/mod/github.com/ethicalhackingplayground/tprox\ngo clean --modcache\ngo clean\n```\n\nThen try and install it again.\n\n### License\n\nTprox is distributed under [MIT License](https://github.com/ethicalhackingplayground/tprox/blob/main/LICENSE)\n\n\u003ch1 align=\"left\"\u003e\n  \u003ca href=\"https://discord.gg/MQWCem5b\"\u003e\u003cimg src=\"static/Join-Discord.png\" width=\"380\" alt=\"Join Discord\"\u003e\u003c/a\u003e\n\u003c/h1\u003e\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fethicalhackingplayground%2Ftprox","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fethicalhackingplayground%2Ftprox","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fethicalhackingplayground%2Ftprox/lists"}