Git Product home page Git Product logo

cve-2018-2628's Introduction

CVE-2018-2628漏洞批量检测脚本


须知

  • Author:liaoxinxi
  • 本脚本为绿盟出品,但一次只能检测一个网站,而且每次都要编辑代码.
  • 所以我给她加了个批量检测的轮子,让她跑得更远。
  • 存在问题:脚本通过死循环来检测漏洞,不存在漏洞的网站会卡住。解决思路如下:(多次测试,不存在漏洞的网站,接收的Payload请求长度为0)
  • 一、通过长度直接判断是否存在漏洞
  • 二、自定义不存在漏洞网站的超时时间

Windows乱码

Windows下发现乱码,导入模块即可:

from __future__ import unicode_literals

IP格式

192.168.31.1:443
192.168.31.100:443
  • 命名为url.txt保存在同目录下执行脚本即可。
  • 输出效果请自己注释!


weblogic_poc-cve-2018-2628-update.py(建议使用这个)

  • 1、把测试的IP添加到列表,全部检测完成后在终端输出。
  • 2、凑合着用吧
  • 3、自定义不存在漏洞网站的检测超时时间,而不是直接判断接收的长度。

使用方法

python weblogic_poc-cve-2018-2628-update.py 3

3 是不存在漏洞网站的检测超时时间,单位秒,可以设置为0,也就是接收长度为0,检测漏洞时间为0秒。



weblogic_poc-cve-2018-2628.py

  • 1、直接通过接收的Payload长度,来判断漏洞是否存在。

使用方法

python weblogic_poc-cve-2018-2628.py

原脚本注释请看:http://www.freebuf.com/vuls/169138.html 参考:https://github.com/jas502n/CVE-2018-2628

cve-2018-2628's People

Watchers

James Cloos avatar root@localhost:~# whoami avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.