{"id":13516982,"url":"https://github.com/rurbin3/xHaust","last_synced_at":"2025-03-31T07:30:43.004Z","repository":{"id":152342536,"uuid":"289824758","full_name":"rurbin3/xHaust","owner":"rurbin3","description":":muscle: :zap: Blazingly fast brute forcer made in Node.js, exhausting your logins... For science.","archived":false,"fork":false,"pushed_at":"2020-08-23T19:57:47.000Z","size":190,"stargazers_count":1,"open_issues_count":0,"forks_count":4,"subscribers_count":1,"default_branch":"master","last_synced_at":"2024-11-01T21:35:55.211Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://www.npmjs.com/package/xhaust","language":null,"has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/rurbin3.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2020-08-24T04:07:42.000Z","updated_at":"2022-07-04T07:22:09.000Z","dependencies_parsed_at":null,"dependency_job_id":"45b497ba-5556-46db-a274-8eb90f99bfc1","html_url":"https://github.com/rurbin3/xHaust","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rurbin3%2FxHaust","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rurbin3%2FxHaust/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rurbin3%2FxHaust/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rurbin3%2FxHaust/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/rurbin3","download_url":"https://codeload.github.com/rurbin3/xHaust/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246432907,"owners_count":20776481,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T05:01:28.132Z","updated_at":"2025-03-31T07:30:42.643Z","avatar_url":"https://github.com/rurbin3.png","language":null,"funding_links":[],"categories":["JavaScript"],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://i.imgur.com/ycMP8RV.png\"\u003e\n\u003c/p\u003e\n\n### xHaust\n\nA fast brute forcer made in Node.js, mostly capable of HTTP attacks. The main mantra of xHaust is **speed, reliability and speed**\n\n**xHaust** achieves it's top speed by using the [async](https://caolan.github.io/async/v3/) module, it can execute password tries in parallel with a set limit. Note that Node.js is still single threaded and so is this library. Due to performance reasons the choice to not create multiple threads for this module has been respected, this is because most password tries are finished by the CPU before any other task completes and the CPU can easily exhaust (heh) request speeds before the requests can exhaust the CPU, making threads costly for this kind of goal.\n\n# THIS PROJECT IS NOT YET FINISHED, PLEASE COME BACK LATER\n\n#### Installation\n\n```bash\nnpm install -g xhaust\n```\n\n#### Usage\n\n```\nUsage: xhaust [options]\n\nOptions:\n  -V, --version                        output the version number\n  -a, --attackUri \u003cattackUri\u003e          protocol URI to attack\n  -u, --user \u003cuser\u003e                    username to use in attack payload\n  -U, --userfile \u003cuserfile\u003e            file full of usernames to use in attack payload\n  -p, --pass \u003cpass\u003e                    password to use in attack payload\n  -P, --passfile \u003cpassfile\u003e            file full of passwords to use in attack payload\n  -l, --limitParallel \u003climitParallel\u003e  max parallel requests at a time\n  -b, --batchSize \u003cbatchSize\u003e          the get and post requests batch size\n  -d, --dry-run \u003cdryRun\u003e               executes the attack in dry run mode\n  -T, --test                           run attack on in built local http server for testing\n  -t, --tags \u003ctags\u003e                    tags to use for this attack seperated by hypens (Ex. http-post-urlencoded)\n  -i, --input \u003cinput\u003e                  input string to use as first scan structure data (Ex. form input names configurations)\n  -o, --output \u003coutput\u003e                output string to use as payload for attack, will replace :username: :password: and :csrf: with respectable values\n  -g, --useGui                         enable gui\n  -h, --help                           display help for command\n```\n\n##### Example call:\n\n```bash\n  $ xhaust -a https://website.com -t -a http://somewebsite.com http-post-urlencoded -u admin -P passwords.txt -s 1000 -l 130 -i \"csrf=token\" -o \"username=:username:\u0026password=:password:\u0026csrftoken=:csrf:\"`\n```\n\n#### Project Layout\n\n    .\n    ├── ...\n    ├── xhaust.js               # Main class file of xHaust, handles most control flow\n    ├── entry.js                # Entry file for unit tests, cli or otherwise\n    ├── attacks                 # Houses attack middleware files, these are the\n    ├── classes                 # Any class files that are not instanced automatically by xHaust\n    ├── logs                    # Log files created by xHaust\n    ├── metadata                # Metadata folder stores arbitrary data for example attack files\n    ├── modules                 # A simple module object that performs basic tasks\n    ├── packages                # Packages are classes that are imported and instanced by xHaust and are the internal workings\n    ├── test                    # Test folder that holds all test scripts\n    └── ...\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frurbin3%2FxHaust","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frurbin3%2FxHaust","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frurbin3%2FxHaust/lists"}