
利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点
🦄 POC bomber is a vulnerability detection/exploitation tool designed to quickly gain permissions on target servers by leveraging a large number of high-impact vulnerability POCs/EXPs
This project collects various high-impact vulnerabilities from the internet, such as RCE · arbitrary file upload · deserialization · SQL injection, which can grant core server permissions. These POCs/EXPs are integrated into the POC bomber arsenal, using a large number of high-impact POCs to fuzz single or multiple targets, thereby quickly discovering vulnerable assets and gaining target server permissions. Applicable scenarios include but are not limited to:
POC bomber's POCs support vulnerability detection for vulnerable components such as weblogic, tomcat, apache, jboss, nginx, struct2, thinkphp2x3x5x, spring, redis, jenkins, PHP language vulnerabilities, shiro, Fanwei OA, Zhiyuan OA, Tongda OA, etc. It supports calling dnslog platforms to detect RCE without echo (including log4j2 detection), supports single-target detection and batch detection. The program uses a high-concurrency thread pool, supports custom import of POCs/EXPs, and can generate vulnerability reports.
POC bomber uses verification mode by default to validate POCs. If the attack value in the returned result is True, you can add the parameter (--attack) to enter attack mode and directly call the EXP for exploitation (you need to specify the POC file name), achieving one-click getshell.
The v3.0.0 version of POC-bomber features faster scanning efficiency, fixes lag caused by a single POC and various bugs, adds colored output and progress display, supports specifying a POC directory, and is suitable for the fast pace of HVV. It also adds some publicly disclosed POCs from 2022. It supports self-hosted dnslog servers. After configuring your own domain, you can use POCbomber to start a dnslog platform on a VPS for DNS out-of-band detection of certain vulnerabilities.
python3 pocbomber.py -u http://xxx.xxx
image image

python3 pocbomber.py -u http://xxx.xxx --poc="thinkphp2_rce.py" --attack

git clone https://github.com/tr0uble-mAker/POC-bomber.git
cd POC-bomber
pip install -r requirements.txt
View usage: python3 pocbomber.py
Modes:
Get POC/EXP info: python3 pocbomber.py --show
Single-target detection: python3 pocbomber.py -u http://xxx.xxx.xx
Batch detection: python3 pocbomber.py -f url.txt -o report.txt
Specify POC detection: python3 pocbomber.py -f url.txt --poc="thinkphp2_rce.py"
EXP attack mode: python3 pocbomber.py -u target_url --poc="specified_poc_file" --attack
Parameters:
-u --url Target URL
-f --file Specify the target URL file
-o --output Specify the report output file (no report generated by default)
-p --poc Specify one or multiple POCs for detection, pass the POC file name directly, separate multiple POCs with (,)
-t --thread Specify the maximum number of concurrent threads in the thread pool (30 by default)
--show Display detailed POC/EXP information
--attack Use the EXP in the POC file to attack
--dnslog Use the dnslog platform to detect vulnerabilities without echo (dnslog is disabled by default, can be enabled in the configuration file)
/inc/config.py
+--------- poc_bomber.py (Launches POC-bomber)
|
+--------- inc (Contains core files supporting the POC-bomber framework)
|
\--------- pocs(POC storage list)----------- framework(Contains framework vulnerability POCs)
|
|------ middleware(Contains middleware vulnerability POCs)
|
|------ ports(Contains common port vulnerability and host service vulnerability POCs)
|
\----- webs(Contains common web page vulnerability POCs)