
利用ceye批量检测CVE-2020-9484
This tool is only for security research and internal audits. Using this tool to launch illegal attacks is prohibited. The user shall be responsible for any consequences.
This tool is only for security research and internal audits. Using this tool to launch illegal attacks is prohibited. The user shall be responsible for any consequences.
This tool is only for security research and internal audits. Using this tool to launch illegal attacks is prohibited. The user shall be responsible for any consequences.
The script is based on https://github.com/threedr3am/tomcat-cluster-session-sync-exp, using multiple processes to call tomcat-cluster-session-sync-exp-1.0-SNAPSHOT-jar-with-dependencies.jar, and proving whether the vulnerability actually exists through ceye.io.
Note: The script has not been tested yet and may not be usable!
IP<space>PORT, refer to ips.txt;pool = ProcessPoolExecutor(10), default is 10 processes;