Barcha
Barcha is your Swiss‑Army knife for SQL Injection reconnaissance 🔍. Written in Go, it automates: Shodan enumeration of SSL hosts 🕵️♂️ Liveness & redirect checks (ignores bad certs) 🔄 Automated Ghauri tests for each host 🛡️ SQLite logging of every scan 🔖
Install / Use
/learn @S1N6H/BarchaQuality Score
Category
Development & EngineeringSupported Platforms
Tags
README
🚀 Barcha
Barcha is your Swiss‑Army knife for SQL Injection reconnaissance 🔍. Written in Go, it automates:
- Shodan enumeration of SSL hosts 🕵️♂️
- Liveness & redirect checks (ignores bad certs) 🔄
- Automated Ghauri tests for each host 🛡️
- SQLite logging of every scan 🔖
🌟 Features
-
📡 Shodan Dork: hostname:"*.example.com" -403 -503 -http.title:"Invalid URL" -302 -404
-
🖧 Reverse DNS: IP → hostname, skips
amazonawsNAT addresses -
🔀 Redirect Handling: Follows HTTP ↔ HTTPS transparently
-
🔐 TLS Flexibility: Ignores expired/self‑signed certs
-
🛠️ Ghauri Integration: ghauri -u <URL> --random-agent --confirm --force-ssl --level=3 --dbs --dump --batch
-
📊 History: Logs into
barcha_history.db
📸 Screenshots
<p align="center"> <img src="docs/screenshots/run1.png" alt="Barcha Scan Preview 1" width="600"/><br> <em>Figure 1. Per‑host SQLi testing via Ghauri. </em> </p> <p align="center"> <img src="docs/screenshots/run2.png" alt="Barcha Ghauri Integration" width="600"/><br> <em>Figure 2. Live host detection & redirect checks.</em> </p>📋 Requirements
- Go 1.18+
- Ghauri installed & on
PATH - A Shodan API key in
SHODAN_API_KEY
⚡ Installation
go install github.com/S1N6H/Barcha@latest
🏃 Usage Export your Shodan key
export SHODAN_API_KEY="YOUR_SHODAN_API_KEY" Run Barcha
./barcha
Enter your target domain when prompted (e.g. example.com)
Watch it go! 🎉
Related Skills
node-connect
352.2kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
111.1kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
352.2kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
qqbot-media
352.2kQQBot 富媒体收发能力。使用 <qqmedia> 标签,系统根据文件扩展名自动识别类型(图片/语音/视频/文件)。
