Skip to content

Releases: Brum3ns/firefly

v1.4.3

17 Jun 23:25
Compare
Choose a tag to compare

What's changed

Bug fixes

  • Old option -fH and -mH was not used but showed as an option

New features

  • New options added:
    • -fdH Filter dynamic header in response
    • -fH Filter header in response
    • -mH Match header in response
  • Firefly now use filters in difference scans such as dynamic header detection. This is to remove false positive in the result.
  • A new more advanced HTTP filter package has been developed that replace the old one.
  • Randomness and dynamic detection has been heavily improved and have an accuracy of: ~90% in detection rate when a random/dynamic string appear in the HTTP response that is a least 16 chars long (common for CSRF, Sessions etc). The accuracy is near ~99% when a string has a length of 23 chars or more (This can be tested in the /tests folder).

Full Changelog: v1.4.2...v1.4.3

v1.4.2

05 May 16:12
Compare
Choose a tag to compare

What's changed

Bugs fixed

  • Fixed version info

v1.4.1

05 May 15:56
Compare
Choose a tag to compare

What's changed

Bugs fixed

  • Removed print of URL before banner
  • Setup process is now fixed and use the CLI tool git instead of svn

New features

v1.4.0

05 May 14:09
Compare
Choose a tag to compare

What's changed

Bugs fixed

  • Invalid regex verification check for URL scheme
  • A fix to an issue that caused Firefly to not detect new HTML tags in the response that were in the payload.

New features

  • New option -detail make it able to view all difference details in the fuzzing process
  • Headers are now analyzed more advanced to detect differences
  • Header difference are now being displayed in the running process

Other

  • Option: "-D" (Delay) renamed to "-timeout"

v1.3.1

16 Dec 20:19
Compare
Choose a tag to compare

What's changed

Bugs fixed

  • The scheme option included http even if only https had been specified by the user.
  • Crash due to non-validated value (out of range)

New features

  • Automatic detection and insertion of payloads in the requests. Support for URL, body and cookies parameters.

Other

  • Option: "-te" (scanner engine threads) renamed to "-tS"

v1.2.0

29 Sep 15:27
Compare
Choose a tag to compare
v1.2.0