Git Product home page Git Product logo

wvsm's Introduction

WVSM(WEB漏洞扫描管理平台) 写完功能介绍后上传代码

image image image image

一、平台简介

  • 目前都有什么功能 ?
1. 可以对项目进行越权测试,需要两个不同权限的用户;
2. 可以对项目对应的IP进行端口测试;
3. 支持对探测到的端口进行简单的漏洞扫描;
4. 支持对项目IP对应的端口信息以及端口漏洞信息一键导出;
5. 支持人工排查越权漏洞,增加了手工对漏洞是否为误报进行设置;
6. 支持一键导出项目所有存在越权的URL信息;
7. 支持对项目的某些接口做白名单设置;
  • 目前支持检测哪些漏洞 ?
1. fastjson 反序列化RCE
2. shiro 反序列化RCE
3. weblogic 反序列化RCE
4. redis 未授权漏洞
5. ZooKeeper未授权访问
6. Tomcat Ajp 文件读取漏洞
7. elasticsearch未授权访问漏洞
8. Docker Remote API 未授权访问漏洞
9. CVE-2019-7238 Nexus Repository Manager RCE

还有一些需要后期进行整合

  • 附加实用工具
1. 密文类型判断功能

二、功能界面预览

  • 管理台主界面

image

  • 新增任务界面

image

  • 任务列表界面

image

  • 越权扫描任务详情界面

image

  • 端口扫描任务详情界面

image

  • 项目端口扫描结果展示界面

image

  • 项目越权扫描结果展示界面

image

wvsm's People

Contributors

menthol1024 avatar

Stargazers

 avatar atkx avatar taoyao avatar  avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.