
Uno strumento semplice per interagire con web shell e vulnerabilità di command injection.
Client Web Shell
Wshlient è un client web shell progettato per essere piuttosto semplice ma versatile. Basta creare un file di testo contenente una richiesta HTTP e indicare dove Wshlient deve iniettare i comandi, e potrai usufruire di una shell.
https://github.com/user-attachments/assets/eafcf666-4c52-4e28-a341-a03bba93fe89
Nel caso in cui il video sopra non funzioni per te:
Delle batterie incluse di Python, Wshclient usa solo requests. Basta installarlo direttamente o usando requirements.txt:
$ git clone https://github.com/gildasio/wshlient
$ cd wshlient
$ pip install -r requirements.txt
$ ./wshlient.py -h
In alternativa puoi creare un link simbolico nel tuo $PATH per usarlo direttamente ovunque nel sistema:
$ ln -s $PWD/wshlient.py /usr/local/bin/wshlient
$ ./wshlient.py -h
usage: wshlient.py [-h] [-d] [-i] [-ne] [-it INJECTION_TOKEN] [-st START_TOKEN] [-et END_TOKEN] req
positional arguments:
req File containing raw http request
options:
-h, --help show this help message and exit
-d, --debug Enable debug output
-i, --ifs Replaces whitespaces with $IFS
-ne, --no-url-encode Disable command URL encode
-it INJECTION_TOKEN, --injection-token INJECTION_TOKEN
Token to be replaced by commands (default: INJECT)
-st START_TOKEN, --start-token START_TOKEN
Token that marks the output beginning
-et END_TOKEN, --end-token END_TOKEN
Token that marks the output ending
Puoi contribuire a Wshlient:
Sentiti libero di farlo, ma tieni presente di mantenere le cose semplici.