
أداة بسيطة للتفاعل مع صدفات الويب وثغرات حقن الأوامر
عميل شل ويب
Wshlient هو عميل شل ويب مصمم ليكون بسيطًا إلى حد كبير ومتعدد الاستخدامات. كل ما عليك فعله هو إنشاء ملف نصي يحتوي على طلب HTTP وإعلام Wshlient بمكان حقن الأوامر، ثم يمكنك الاستمتاع بالشل.
https://github.com/user-attachments/assets/eafcf666-4c52-4e28-a341-a03bba93fe89
إذا لم يعمل الفيديو أعلاه معك:
بخلاف المكتبات المضمنة في بايثون، يستخدم Wshlient فقط requests. قم بتثبيته مباشرة أو باستخدام requirements.txt:
$ git clone https://github.com/gildasio/wshlient
$ cd wshlient
$ pip install -r requirements.txt
$ ./wshlient.py -h
بدلاً من ذلك، يمكنك أيضًا إنشاء رابط رمزي في $PATH لاستخدامه مباشرة في أي مكان في النظام:
$ ln -s $PWD/wshlient.py /usr/local/bin/wshlient
$ ./wshlient.py -h
usage: wshlient.py [-h] [-d] [-i] [-ne] [-it INJECTION_TOKEN] [-st START_TOKEN] [-et END_TOKEN] req
positional arguments:
req File containing raw http request
options:
-h, --help show this help message and exit
-d, --debug Enable debug output
-i, --ifs Replaces whitespaces with $IFS
-ne, --no-url-encode Disable command URL encode
-it INJECTION_TOKEN, --injection-token INJECTION_TOKEN
Token to be replaced by commands (default: INJECT)
-st START_TOKEN, --start-token START_TOKEN
Token that marks the output beginning
-et END_TOKEN, --end-token END_TOKEN
Token that marks the output ending
يمكنك المساهمة في Wshlient من خلال:
لا تتردد في القيام بذلك، لكن ضع في اعتبارك إبقاء الأمور بسيطة.