
log4shell (CVE-2021-44228) herramienta de escaneo
Esta herramienta te ayudará a identificar la vulnerabilidad de ejecución remota de código (log4j) en tus sistemas.
Necesitarás instalar httpx, subfinder, assetfinder, curl y amass para ejecutar el script bash.
git clone https://github.com/shamo0/CVE-2021-44228.gitchmod +x log4j_scanner.sh./log4j_scanner.sh./log4j_scanner.sh -l subdomains.txt -i c6wvp482vtc10xx5bhnggdqp5neyyyyyb.interact.sh
./log4j_scanner.sh -d vulnsite.com -i c6wvp482vtc10xx5bhnggdqp5neyyyyyb.interact.sh
-h, --help Menú de ayuda
-l, --url-list Lista de dominios/subdominios/ip para usar en el escaneo.
-d, --domain El nombre de dominio sobre el cual se comprobarán todos los subdominios y él mismo con Subfinder & Assetfinder.
-i, --inteactshdomain Dirección del dominio interactsh.
Pero también ten en cuenta que