Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2017-12637_SAP-NetWeaver-URL-Traversal — Scanner LFI Preuve de concept : Détection automatisée des expositions de /etc/passwd via directory traversal et correspondance regex. | Kitploit
Outils/GitHubGitHub/abrewer251/cve-2017-12637_sap-netweaver-url-traversal
ReconnaissanceScanners de VulnérabilitésExploitationExploitation d'Applications WebCollecte d'InformationsTests d'Intrusion
GitHubabrewer251/cve-2017-12637_sap-netweaver-url-traversal

CVE-2017-12637_SAP-NetWeaver-URL-Traversal

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →

Scanner LFI Preuve de concept : Détection automatisée des expositions de /etc/passwd via directory traversal et correspondance regex.

Voir le dépôt
9il y a 1 anPas encore vérifié
Partager

CVE-2017-12637_SAP-NetWeaver-URL-Traversal

Scanner LFI de preuve de concept : Détection automatisée de l'exposition de /etc/passwd via traversal de répertoire et correspondance regex.

# LFI Scanner

A lightweight Python proof-of-concept to scan target hosts for Local File Inclusion (LFI) vulnerabilities by attempting to retrieve `/etc/passwd` and detecting its presence with a regex check. :contentReference[oaicite:0]{index=0}

## Features

- **Batch scanning** of hostnames or host:port targets from an input file  
- **Directory traversal payload** to reach `/etc/passwd`  
- **Regex detection** of the `root` entry to confirm LFI  
- **Progress bar** powered by `tqdm` for real-time feedback  
- **Structured reporting**: outputs findings and previews to a results file  

## Prerequisites

- Python 3.6 or newer  
- [`tqdm`](https://pypi.org/project/tqdm/) (`pip install tqdm`)  
- `curl` CLI available in your PATH  

## Installation

```bash
git clone https://github.com/yourusername/lfi-scanner.git
cd lfi-scanner
pip install tqdm

Usage

python poc.py <input_file> [-o OUTPUT_FILE]
  • <input_file>: Path to a file containing one target per line (hostname or hostname:port).
  • -o, --output: (Optional) Path to write results (default: results.txt).

Example

Given targets.txt:

example.com
192.168.0.1:8443

Run the scanner:

python poc.py targets.txt -o scan_results.txt

You’ll see output like:

[+] https://example.com:443/... → /etc/passwd FOUND
[-] https://192.168.0.1:8443/... → Response received, no match

And scan_results.txt will contain a summary and previews.

Script Breakdown

  • poc.py:

    • Uses argparse to parse --input and --output.
    • Iterates targets and constructs the URL with a deep traversal payload.
    • Calls curl --insecure -s for each target.
    • Searches for root:.*?:0:0: to confirm /etc/passwd exposure.
    • Prints status per host and writes detailed results to the output file.

Disclaimer

Use this tool responsibly and only on assets you own or have explicit permission to test. Unauthorized scanning may violate laws and terms of service.

License

Released under the MIT License.

Télécharger l’outil