Git Product home page Git Product logo

tsojanscan's People

Contributors

thecryinggame avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

tsojanscan's Issues

实战三场红蓝,快准狠,误报难免,期待后续版本

增加去重功能

相同路径不同数据包会报出相同的漏洞,导致相同的漏洞出现多次,建议增加去重功能。同时也可以减少发包量。

域名黑名单批量添加

添加域名的黑名单只能一个个域名的添加,可不可以一次性加完所有的黑名单?

log4j被动扫描导致一直请求dns地址

在插件中配置dns地址后,被动用log4j去扫描地址。后续几天没使用burp过,一直看到目标去请求log4j-payload的请求,这是什么原因?流量太大了

fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1

fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1
fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1
fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1
fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1
fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1
fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1
fastjson 扫描出错java.lang.IllegalArgumentException: URLDecoder: Illegal hex characters in escape (%) pattern - Error at index 0 in: ")�"
fastjson 扫描出错java.lang.IllegalArgumentException: URLDecoder: Illegal hex characters in escape (%) pattern - Error at index 0 in: "�ޭ"
fastjson 扫描出错java.lang.IllegalArgumentException: URLDecoder: Illegal hex characters in escape (%) pattern - Error at index 0 in: ">�"

导入burp1.7或2020版本报错,1.4.4

java.lang.NumberFormatException: null
at java.lang.Integer.parseInt(Unknown Source)
at java.lang.Integer.parseInt(Unknown Source)
at burp.ScanFun.SQLIScan.ParamEchoScan(SQLIScan.java:85)
at burp.BurpExtender.doPassiveScan(BurpExtender.java:1436)
at burp.r5d.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
java.lang.NumberFormatException: null
at java.lang.Integer.parseInt(Unknown Source)
at java.lang.Integer.parseInt(Unknown Source)
at burp.ScanFun.SQLIScan.ParamEchoScan(SQLIScan.java:85)
at burp.BurpExtender.doPassiveScan(BurpExtender.java:1436)
at burp.r5d.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
java.lang.NumberFormatException: null
at java.lang.Integer.parseInt(Unknown Source)
at java.lang.Integer.parseInt(Unknown Source)
at burp.ScanFun.SQLIScan.ParamEchoScan(SQLIScan.java:198)
at burp.BurpExtender.doPassiveScan(BurpExtender.java:1436)
at burp.r5d.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)

burpsuite UI

target 、 proxy 前面的图标是怎么弄的?

关于dnslog的一个小建议

首先感谢作者们的努力让我工作又可以轻松一截。不过我在使用过程中有个小建议,可否能设置为自定义dnslog(ceye之类的)或者采用备用dnslog的的方式。目前工具自带的dnslog出现“initDomain failed: Failed to connect“的情况。

sql注入误报严重

sql注入报错,特别是时间盲注总是出错,实际上放在参数中,因为测试payload自带的空格会导致payload根本起不到作用,因而误报严重
image

1.4.5仍然异常报错呢

java.lang.NumberFormatException: null
at java.lang.Integer.parseInt(Unknown Source)
at java.lang.Integer.parseInt(Unknown Source)
at burp.ScanFun.SQLIScan.ParamEchoScan(SQLIScan.java:85)
at burp.BurpExtender.doPassiveScan(BurpExtender.java:1516)
at burp.ck3.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
java.lang.NumberFormatException: null
at java.lang.Integer.parseInt(Unknown Source)
at java.lang.Integer.parseInt(Unknown Source)
at burp.ScanFun.SQLIScan.ParamEchoScan(SQLIScan.java:85)
at burp.BurpExtender.doPassiveScan(BurpExtender.java:1516)
at burp.ck3.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)

Ueditor 扫描出错java.lang.NumberFormatException: null

插件卡顿

您好,我在使用的过程中burp2023.7专业版使用插件的时候 有时候会扫到一些成果的时候点开插件查看就会出现卡顿,不知道其他小伙伴会不会出现这种情况呢

burp 2023.7版本报错

能正常加载插件,但是测试pikachu的时候,有明显的sql报错语句未检测出。而且插件那里会报错:java.lang.NumberFormatException: Cannot parse null string
at java.base/java.lang.Integer.parseInt(Integer.java:630)
at java.base/java.lang.Integer.parseInt(Integer.java:786)
at burp.ScanFun.SQLIScan.ParamEchoScan(SQLIScan.java:198)
at burp.BurpExtender.doPassiveScan(BurpExtender.java:1436)
at burp.Zm3y.passiveAudit(Unknown Source)
at burp.Zst5.run(Unknown Source)
at java.base/java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:539)
at java.base/java.util.concurrent.FutureTask.run(FutureTask.java:264)
at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1136)
at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)
at java.base/java.lang.Thread.run(Thread.java:833)

Log4j漏洞结果不准确

在扫描中有大量的扫描,然后提供的漏洞位置不准确。
例如:
漏洞位置为请求头中的Accept,但是在VulPanel中展示的结果记录的是其他位置的。

这样的情况导致在扫描的时候获取准确结果只能开启logger++根据dnslog的回显地址查找准确的漏洞信息。

Shiro 和 Fastjson 扫描出错

fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 0 out of bounds for length 0
fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1
shiro 判断出错java.lang.NullPointerException: Cannot invoke "burp.api.montoya.http.message.responses.HttpResponse.headers()" because "" is null
shiro 判断出错java.lang.NullPointerException: Cannot invoke "burp.api.montoya.http.message.responses.HttpResponse.headers()" because "" is null
shiro 判断出错java.lang.NullPointerException: Cannot invoke "burp.api.montoya.http.message.responses.HttpResponse.headers()" because "" is null
shiro 判断出错java.lang.NullPointerException: Cannot invoke "burp.api.montoya.http.message.responses.HttpResponse.headers()" because "" is null
shiro 判断出错java.lang.NullPointerException: Cannot invoke "burp.api.montoya.http.message.responses.HttpResponse.headers()" because "" is null
fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1
fastjson 扫描出错java.lang.ArrayIndexOutOfBoundsException: Index 1 out of bounds for length 1

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.