Surface Sonar

Attack-surface checker · v2
Detect-only

Masukkan domain dari inventory yang disetujui. Sonar memeriksa file sensitif, listing folder, header, dan signature webshell. Hasil yang belum lengkap ditandai tanpa grade.

Yang diperiksa (semua pasif, GET saja)

File sensitif.env, .git, *.sql, wp-config.bak, phpinfo
Listing folder/uploads, /backup, /db kebuka
Path webshell15 backdoor klasik known
CMS & versigenerator terdeteksi; versi perlu verifikasi
Header keamananHSTS, CSP, framing, nosniff
Mixed contentresource http di halaman https
Cloak/redirectredirect HTTP dan tujuan dari halaman
Catch-all guardanti false-positive parking/SPA