Katana does not respect the scope #1341
-
katana version:
Current Behavior:When using the
Expected Behavior:Browser should stop crawling when reaching out of scope site Steps To Reproduce:
Anything else:Note that in non-headless mode, the scope is also exceeded, but to a slightly lesser extent.
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
hello, I think it seems that the behavior is not a bug but rather related to the scope filtering settings. To restrict the scope more strictly, one of the following flags should be used: Example: katana -hl -u http://php.testsparker.com -fs fqdn
__ __
/ /_____ _/ /____ ____ ___ _
/ '_/ _ / __/ _ / _ \/ _ /
/_/\_\\_,_/\__/\_,_/_//_/\_,_/
projectdiscovery.io
[INF] Current katana version v1.2.1 (latest)
[INF] Started headless crawling for => http://php.testsparker.com
http://php.testsparker.com/nslookup.php
http://php.testsparker.com/style.css
http://php.testsparker.com/products.php?pro=url
http://php.testsparker.com/artist.php?id=test
http://php.testsparker.com/process.php?file=Generics/about.nsp
http://php.testsparker.com/hello.php?name=Visitor
http://php.testsparker.com/auth/
http://php.testsparker.com
http://php.testsparker.com/phpinfo.php
http://php.testsparker.com/process.php?file=Generics/contact.nsp
http://php.testsparker.com/process.php?file=Generics/index.nsp
http://php.testsparker.com/phpinfo.php?=PHPE9568F34-D428-11d2-A769-00AA001ACF42
http://php.testsparker.com/phpinfo.php?=PHPE9568F35-D428-11d2-A769-00AA001ACF42
http://php.testsparker.com/Generics/style.css
http://php.testsparker.com/auth/style.css
http://php.testsparker.com/phpinfo.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000
http://php.testsparker.com/artist.php
http://php.testsparker.com/function.mysql-connect
http://php.testsparker.com/url
http://php.testsparker.com/products.php?pp=+DAST
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i13!2i4764!3i3074!4i256!2m1!1e1!3m12!2sen!3sUS!5e289!12m3!1e37!2m1!1ssmartmaps!12m4!1e26!2m2!1sstyles!2zcy5lOmx8cC52Om9mZg!4e0!5m1!1e3!23i47083502&client=google-maps-embed&token=54017
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38115!3i24593!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=42312
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38114!3i24594!4i256!2m3!1e0!2sm!3i741500852!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=63523
http://php.testsparker.com/hello.php?hpp=Acunetix&pp= DAST
http://php.testsparker.com/hello.php?hpp=Netsparker&pp=+DAST&irc=
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38115!3i24594!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=89494
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38116!3i24593!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=110180
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38116!3i24594!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=26291
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38114!3i24593!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=105515
http://php.testsparker.com/auth/login.php katana -hl -u http://php.testsparker.com -fs dn
__ __
/ /_____ _/ /____ ____ ___ _
/ '_/ _ / __/ _ / _ \/ _ /
/_/\_\\_,_/\__/\_,_/_//_/\_,_/
projectdiscovery.io
[INF] Current katana version v1.2.1 (latest)
[INF] Started headless crawling for => http://php.testsparker.com
http://php.testsparker.com
http://php.testsparker.com/nslookup.php
http://php.testsparker.com/hello.php?name=Visitor
http://php.testsparker.com/process.php?file=Generics/about.nsp
http://php.testsparker.com/artist.php?id=test
http://php.testsparker.com/style.css
http://php.testsparker.com/auth/
http://php.testsparker.com/products.php?pro=url
http://php.testsparker.com/phpinfo.php
http://php.testsparker.com/process.php?file=Generics/contact.nsp
http://php.testsparker.com/process.php?file=Generics/index.nsp
http://php.testsparker.com/phpinfo.php?=PHPE9568F34-D428-11d2-A769-00AA001ACF42
http://php.testsparker.com/phpinfo.php?=PHPE9568F35-D428-11d2-A769-00AA001ACF42
http://php.testsparker.com/auth/style.css
http://php.testsparker.com/phpinfo.php
http://php.testsparker.com/phpinfo.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000
http://php.testsparker.com/url
http://php.testsparker.com/products.php?pp=+DAST
http://php.testsparker.com/phpinfo.php
http://aspnet.testsparker.com/administrator/
http://php.testsparker.com/process.php?file=Generics/contact.nsp
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i13!2i4764!3i3074!4i256!2m1!1e1!3m12!2sen!3sUS!5e289!12m3!1e37!2m1!1ssmartmaps!12m4!1e26!2m2!1sstyles!2zcy5lOmx8cC52Om9mZg!4e0!5m1!1e3!23i47083502&client=google-maps-embed&token=54017
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38116!3i24594!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=26291
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38116!3i24593!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=110180
http://php.testsparker.com/phpinfo.php
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38114!3i24593!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=105515
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38115!3i24593!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=42312
http://php.testsparker.com/phpinfo.php
http://php.testsparker.com/process.php?file=Generics/contact.nsp
http://aspnet.testsparker.com/
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38114!3i24594!4i256!2m3!1e0!2sm!3i741500852!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=63523
http://php.testsparker.com/process.php?file=Generics/contact.nsp
http://php.testsparker.com/maps/vt?pb=!1m5!1m4!1i16!2i38115!3i24594!4i256!2m3!1e0!2sm!3i741500816!2m3!1e2!2sspotlit!5i1!3m13!2sen!3sUS!5e289!12m5!1e68!2m2!1sset!2sRoadmap!4e2!12m3!1e37!2m1!1ssmartmaps!4e0!5m1!1e3!23i47083502!27m14!299174093m13!14m12!1m8!1m2!1y1498251969722647901!2y18207593223800132837!2s%2Fg%2F11xjs7_9t!4m2!1x409063123!2x293748345!15sgcid%3Amarine_supply_store!2b0!6b0!8b0&client=google-maps-embed&token=89494
http://php.testsparker.com/hello.php?hpp=Acunetix&pp= DAST
http://php.testsparker.com/hello.php?hpp=Netsparker&pp=+DAST&irc=
http://php.testsparker.com/phpinfo.php
http://php.testsparker.com/function.mysql-connect
http://php.testsparker.com/phpinfo.php
http://aspnet.testsparker.com/statics/style.css
http://aspnet.testsparker.com/Guestbook.aspx
http://aspnet.testsparker.com/About.aspx?hello=visitor
http://aspnet.testsparker.com/Help.aspx
http://aspnet.testsparker.com/administrator/Login.aspx
http://aspnet.testsparker.com/Request.aspx?r=/statics/download/
http://aspnet.testsparker.com/Contact.aspx
http://aspnet.testsparker.com/Converter.aspx
http://aspnet.testsparker.com/Shop.aspx
http://aspnet.testsparker.com/Blogs.aspx
http://aspnet.testsparker.com/Default.aspx
http://php.testsparker.com/process.php?file=Generics/contact.nsp
http://php.testsparker.com/Generics/style.css
http://php.testsparker.com/artist.php
http://php.testsparker.com/auth/login.php
http://php.testsparker.com/process.php?file=Generics/contact.nsp
http://php.testsparker.com/process.php?file=Generics/contact.nsp
[ERR] Error closing page: context deadline exceeded
http://aspnet.testsparker.com/redirect.aspx?site=bitcoin.org This ensures that subdomains like aspnet.testsparker.com or maps.google.com will be skipped during crawling. |
Beta Was this translation helpful? Give feedback.
-
Oh thanks a lot @jjhwan-h , effectively it seems to work with fqdn, i close this issue |
Beta Was this translation helpful? Give feedback.
hello, I think it seems that the behavior is not a bug but rather related to the scope filtering settings.
To restrict the scope more strictly, one of the following flags should be used:
-fs fqdn → Only allow exact FQDN match (php.testsparker.com)
-fs dn → Allow only that specific domain, not its siblings
Example: