awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
r0oth3x49 avatar

r0oth3x49/ghauri

0
View on GitHub↗
4,032 stars·423 forks·Python·MIT·6 views

Ghauri

Ghauri is an automated SQL injection scanner and exploitation tool designed to detect and extract data from vulnerable databases. It functions as a database exfiltration framework that identifies security flaws and retrieves system banners, hostnames, and database schemas.

The tool identifies boolean, error, time-based, and stacked query vulnerabilities across multiple input vectors, including HTTP headers, cookies, JSON, SOAP, and XML. It provides capabilities for automated database exfiltration and the processing of bulk target lists to identify flaws across multiple environments.

The system includes network traffic obfuscation through proxy routing and user-agent randomization to bypass security restrictions. It also manages session state persistence to allow the resumption of interrupted data extraction processes and provides controls to limit the volume of retrieved records.

Features

  • Automated Database Exfiltration - Extracts structured data from vulnerable databases, including table names, column entries, and system banners, using automated scripts.
  • SQL Injection Scanners - Provides automated scanning to detect boolean, error, time-based, and stacked query SQL injection vulnerabilities.
  • Database Enumerators - Retrieves system banners, hostnames, current users, and full database schemas including table entries.
  • Bulk Vulnerability Scanning - Enables processing bulk vulnerability tests by loading lists of target addresses or HTTP requests from text files.
  • Automated Vulnerability Detection - Identifies security flaws by injecting boolean, error, time-based, and stacked query sequences into targeted input vectors.
  • Database Exfiltration Frameworks - Implements a system for retrieving database structures, table entries and system banners through various HTTP input vectors.
  • Security Vulnerability Scanning - Performs bulk security tests against lists of target addresses to identify SQL injection flaws across multiple environments.
  • SQL Injection Tools - Automates the detection and extraction of data from databases by exploiting SQL injection vulnerabilities.
  • Vulnerability Analysis - Probes various HTTP input vectors including JSON, SOAP, XML, and cookies to identify exploitable injection points.
  • Web Application Penetration Testing - Evaluates the security of web services by probing multiple input vectors like HTTP headers, cookies, and JSON payloads.
  • Session State Persistence - Allows the resumption of interrupted exploitation phases by controlling cached results and session file persistence.
  • Exploitation State Persisters - Saves exploitation progress to local files to allow resuming data extraction without restarting the discovery phase.
  • File-Based Target Loading - Loads sets of target addresses or raw HTTP requests from text files for automated sequential vulnerability testing.
  • HTTP Request Customizations - Allows modification of connection parameters including custom user agents, proxy settings, headers, timeouts, and request delays.
  • Traffic Masking Proxies - Redirects outbound HTTP requests through a proxy server to mask the origin and bypass network restrictions.
  • User Agent Rotation - Rotates the identity string sent in HTTP headers to evade detection by security systems during bulk scanning.
  • Network Traffic Obfuscators - Routes security tests through proxies and uses randomized user agents to bypass detection systems.
  • Input Type Abstractions - Standardizes payload delivery across various transport formats like JSON, SOAP, XML, cookies, and HTTP headers.
  • Exploitation Tools - Automates detection and exploitation of SQL injection.
  • Specialized Vulnerability Scanners - Automated tool for detecting and exploiting SQL injection flaws.
  • XSS and Injection Testing - Automated SQL injection detection and exploitation tool.

Star history

Star history chart for r0oth3x49/ghauriStar history chart for r0oth3x49/ghauri

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does r0oth3x49/ghauri do?

Ghauri is an automated SQL injection scanner and exploitation tool designed to detect and extract data from vulnerable databases. It functions as a database exfiltration framework that identifies security flaws and retrieves system banners, hostnames, and database schemas.

What are the main features of r0oth3x49/ghauri?

The main features of r0oth3x49/ghauri are: Automated Database Exfiltration, SQL Injection Scanners, Database Enumerators, Bulk Vulnerability Scanning, Automated Vulnerability Detection, Database Exfiltration Frameworks, Security Vulnerability Scanning, SQL Injection Tools.

What are some open-source alternatives to r0oth3x49/ghauri?

Open-source alternatives to r0oth3x49/ghauri include: jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… sqlmapproject/sqlmap — This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It… nullarray/autosploit — AutoSploit is an automated exploitation framework designed for discovering remote hosts and executing exploit modules… s0md3v/xsstrike — XSStrike is an automated security scanning engine designed for web application discovery, input. hahwul/dalfox — Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site… commixproject/commix — Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It…

Open-source alternatives to Ghauri

Similar open-source projects, ranked by how many features they share with Ghauri.
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • sqlmapproject/sqlmapsqlmapproject avatar

    sqlmapproject/sqlmap

    37,676View on GitHub↗

    This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris

    Pythondatabasedetectionexploitation
    View on GitHub↗37,676
  • nullarray/autosploitNullArray avatar

    NullArray/AutoSploit

    5,240View on GitHub↗

    AutoSploit is an automated exploitation framework designed for discovering remote hosts and executing exploit modules at scale to establish reverse shells. It functions as a network reconnaissance tool and a remote code execution orchestrator, managing the deployment of attack modules against multiple targets. The system features a proxy-based traffic masker that routes network requests through external servers and rotates HTTP headers and user agents to obscure the source of activity. It allows for custom exploit orchestration through the integration of external attack modules and the manage

    Python
    View on GitHub↗5,240
  • s0md3v/xsstrikes0md3v avatar

    s0md3v/XSStrike

    14,752View on GitHub↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Pythonwaf-detectionxssxss-bruteforce
    View on GitHub↗14,752
  • See all 30 alternatives to Ghauri→