
Un'utilità per produrre un database di cache HTTP da utilizzare con go-exploit
go-exploit-cache crea un database SQLite di cache HTTP utilizzato dal framework go-exploit per abilitare la condivisione tra exploit e la verifica scanless dei target. Invece di connettersi attivamente ai target, go-exploit può consultare la cache per eseguire controlli di versione e altre scansioni utilizzando dati HTTP raccolti in precedenza (Shodan, Censys, PCAP, RunZero, ecc.).
Progetto:
vulncheck-oss/go-exploit
Questo strumento genera la cache SQLite chego-exploitlegge.
http_cache che go-exploit utilizza per la verifica scanless e i controlli di versione..json.gz, RunZero JSONL (e RunZero JSON1 con supporto limitato), PCAP/pcapng e Censys JSONL (tramite script di supporto)..json.gzcensys/censys_v3_dump.py per preparare)go-exploitVedi USAGE.md per maggiori dettagli.
./build/go-exploit-cache \
-type shodan-gzip \
-in ~/Downloads/734342e9-56b8-4299-a072-9d1d28f66434.json.gz \
-out confluence.db
Output tipico:
Decompressing the Shodan GZIP... this can be slow
Decompressed file written to .tmp/shodan.json
Generating database entries...
Cleaning up .tmp directory
Ispeziona il DB:
sqlite3 confluence.db
sqlite> select rhost, rport from http_cache limit 1;
52.200.210.54|80
Puoi verificare un target utilizzando solo i dati in cache. L'esempio usa unshare -n per bloccare l'accesso alla rete (solo per demo — unshare non è richiesto):
sudo unshare -n ./build/cve-2023-22527_linux-arm64 \
-c -v -rhost 52.200.210.54 -rport 80 \
-db ~/go-exploit-cache/confluence.db
Output di esempio:
time=... level=STATUS msg="Starting target" host=52.200.210.54 port=80
time=... level=STATUS msg="Validating Confluence target"
time=... level=SUCCESS msg="Target verification succeeded!"
time=... level=VERSION msg="The reported version is 7.19.17"
time=... level=STATUS msg="The target appears to be a patched version." vulnerable=no
shodan-gzip — export Shodan .json.gzrunzero-jsonl — RunZero JSONL (supporto JSON1 limitato)pcap / pcapng — file PCAP (estrae traffico HTTP)censys-jsonl — Censys JSONL (usa lo script di supporto in censys/)Vedi test/testdata per file di esempio.
censys_v3_dump.py per recuperare i dati. Inizia accettando una query di ricerca di Censys Platform e poi scarica i singoli host per accedere agli header HTTP e al body HTTP completo. Usa censys/censys_v3_dump.py per raccogliere e formattare i risultati Censys in JSONL adatto all'acquisizione.http_cache — tabella principale (tabella generata dalla cache)
| column | type | description |
|---|---|---|
| id | INTEGER | primary key |
| created | INTEGER | date |
| rhost | TEXT | remote host (IP) |
| rport | INT | remote port |
| uri | TEXT | the cached path |
| data | BLOB | HTTP headers + body |
verified — tabella di descrizione del software (tabella popolata da go-exploit)
| column | type | description |
|---|---|---|
| id | INTEGER | primary key |
| created | INTEGER | date |
| software name | TEXT | Name of software |
| installed | INT | 0 or 1 |
| version | TEXT | The software version |
| rhost | TEXT | remote host (IP) |
| rport | INT | remote port |
Su Ubuntu:
sudo apt install libpcap-dev
make
(Richiede una toolchain Go — vedi https://go.dev/doc/install.)