DepFine
DepFine Is a tool to find the unregistered dependency based on dependency confusion valunerablility and lead to RCE
Installation:
- You Can install the tool using the following command by pip3 -r requirmentes.txt install and the tool requirmentes will be installed inside your machine
Idea:
- The tool until now is running for node.js dependencies only but in next realase will be allow for the other frameworks like gemfile, pypi
Usage :
- You can use the tool using the following command by type:
python3 DepFine.py RawForPackage.com
Example usage:
Warning:
-
to use the tool the package.json file must be in a raw data for example If you found it on a outdated domain you should move it to a raw becuase If you run the proccess using the normal link or json type the tool will be coruupted and not run
-
Thanks