
Una utilidad para producir una base de datos de caché HTTP para usar con go-exploit
go-exploit-cache construye una base de datos SQLite de caché HTTP utilizada por el framework go-exploit para permitir el uso compartido entre exploits y la verificación de objetivos sin escaneo. En lugar de conectarse activamente a los objetivos, go-exploit puede consultar la caché para ejecutar comprobaciones de versión y otros escaneos utilizando datos HTTP recopilados previamente (Shodan, Censys, PCAP, RunZero, etc.).
Proyecto:
vulncheck-oss/go-exploit
Esta herramienta genera la caché SQLite quego-exploitlee.
http_cache SQLite que go-exploit utiliza para verificación sin escaneo y comprobaciones de versión..json.gz, RunZero JSONL (y RunZero JSON1 limitado), PCAP/pcapng, y Censys JSONL (mediante script auxiliar)..json.gzcensys/censys_v3_dump.py para preparar)go-exploitConsulte USAGE.md para más detalles.
./build/go-exploit-cache \
-type shodan-gzip \
-in ~/Downloads/734342e9-56b8-4299-a072-9d1d28f66434.json.gz \
-out confluence.db
Salida típica:
Decompressing the Shodan GZIP... this can be slow
Decompressed file written to .tmp/shodan.json
Generating database entries...
Cleaning up .tmp directory
Inspeccionar la base de datos:
sqlite3 confluence.db
sqlite> select rhost, rport from http_cache limit 1;
52.200.210.54|80
Puede verificar un objetivo utilizando únicamente datos en caché. El ejemplo usa unshare -n para bloquear el acceso a la red (solo para la demo — unshare no es necesario):
sudo unshare -n ./build/cve-2023-22527_linux-arm64 \
-c -v -rhost 52.200.210.54 -rport 80 \
-db ~/go-exploit-cache/confluence.db
Salida de ejemplo:
time=... level=STATUS msg="Starting target" host=52.200.210.54 port=80
time=... level=STATUS msg="Validating Confluence target"
time=... level=SUCCESS msg="Target verification succeeded!"
time=... level=VERSION msg="The reported version is 7.19.17"
time=... level=STATUS msg="The target appears to be a patched version." vulnerable=no
shodan-gzip — exportación .json.gz de Shodanrunzero-jsonl — RunZero JSONL (soporte limitado de JSON1)pcap / pcapng — archivos PCAP (extrae tráfico HTTP)censys-jsonl — Censys JSONL (use el script auxiliar en censys/)Consulte test/testdata para ver archivos de ejemplo.
censys_v3_dump.py para obtener los datos. Comienza aceptando una consulta de búsqueda de Censys Platform y luego descarga los hosts individuales para acceder a las cabeceras HTTP y al cuerpo HTTP completo. Use censys/censys_v3_dump.py para recopilar y formatear los resultados de Censys en JSONL adecuado para su ingesta.http_cache — tabla principal (tabla generada por la caché)
| column | type | description |
|---|---|---|
| id | INTEGER | primary key |
| created | INTEGER | date |
| rhost | TEXT | remote host (IP) |
| rport | INT | remote port |
| uri | TEXT | the cached path |
| data | BLOB | HTTP headers + body |
verified — tabla de descripción de software (tabla poblada por go-exploit)
| column | type | description |
|---|---|---|
| id | INTEGER | primary key |
| created | INTEGER | date |
| software name | TEXT | Name of software |
| installed | INT | 0 or 1 |
| version | TEXT | The software version |
| rhost | TEXT | remote host (IP) |
| rport | INT | remote port |
En Ubuntu:
sudo apt install libpcap-dev
make
(Requiere una cadena de herramientas de Go — consulte https://go.dev/doc/install.)