
Utility a riga di comando per verificare se un host è vulnerabile a CVE-2019-19781 (Citrix ADC/NetScaler). Scansiona un singolo host e riporta lo stato di vulnerabilità con tentativi e timeout configurabili.
Questa utility determina se un host sembra essere suscettibile a CVE-2019-19781.
Versioni Python 3.6 e superiori. Si noti che Python 2 non è supportato.
Da una release:
pip install https://github.com/cisagov/check-cve-2019-19781/releases/download/v1.0.1/cve_2019_19781-1.0.1-py3-none-any.whl
Da sorgente:
git clone https://github.com/cisagov/check-cve-2019-19781.git
cd check-cve-2019-19781
pip install -r requirements.txt
Per scansionare un host:
❱ cve-2019-19781 citrix.example.org
2020-01-10 22:11:46,312 WARNING citrix.example.org appears to be vulnerable.
Le informazioni dettagliate sull'utilizzo possono essere visualizzate con:
❱ cve-2019-19781 --help
Check for the existence of CVE-2019-19781 on a host machine.
EXIT STATUS
This utility exits with one of the following values:
0 The host does not seem vulnerable
1 Command was invoked incorrectly
2 The host appears to be vulnerable
>2 An error occurred.
For more information about this vulnerability see:
https://nvd.nist.gov/vuln/detail/CVE-2019-19781
Usage:
cve-2019-19781 [options] <host>
cve-2019-19781 (-h | --help)
Options:
-h --help Show this message.
--log-level=LEVEL If specified, then the log level will be set to
the specified value. Valid values are "debug", "info",
"warning", "error", and "critical". [default: info]
-r --retries=count Number of times to retry a failed connection attempt before
giving up. [default: 2]
-t --timeout=seconds Number of seconds to wait during each connection attempt.
[default: 10]
Accogliamo con favore i contributi! Si prega di vedere qui per i dettagli.
Questo progetto è nel pubblico dominio mondiale.
Questo progetto è di pubblico dominio negli Stati Uniti, e i diritti d'autore e i diritti correlati sull'opera in tutto il mondo sono rinunciati tramite la dedica al pubblico dominio CC0 1.0 Universale.
Tutti i contributi a questo progetto saranno rilasciati sotto la dedica CC0. Inviando una pull request, accetti di rispettare questa rinuncia agli interessi di copyright.