
エクスプロイトスクリプトを(より速く!)書くためのヒント
このリポジトリには、OSWEのラボおよび認定試験でエクスプロイトスクリプトを作成する際に役立つ、便利なスニペットとヒントの一覧が含まれています。
ここに示す例の一部は、特定のコーディング慣行に反するかもしれませんが、最終的な目標はエクスプロイトスクリプトを迅速かつ正確に書くことです。
requestsライブラリの使用に慣れていない場合や、Pythonに不慣れな場合は、コードスニペットセクションが最適な出発点です。それ以外の場合は、再利用可能なコードセクションまたはヒントセクションに進んでください。
requestsライブラリの使用
params引数を使用)data引数を使用)json引数を使用)files引数を使用)headers引数を使用)cookies引数を使用)3XXリダイレクトの追跡を無効にする(allow_redirects引数を使用)verify引数を使用)proxies引数を使用)Sessionを作成するassertを使用して健全性チェックを実行するSessionオブジェクトを作成するBASE_URL文字列を作成し、そこから必要なURLを構築するproxies引数を使用せずにすべてのHTTPリクエストをBurp Suite経由で送信するには、実行時にHTTP_PROXY / HTTPS_PROXY環境変数を設定する')とダブルクォート(")の両方が含まれる場合は、"""を使用して作成する{})が多すぎる場合は、f-strings(f"")やstr.formatの使用を避けるimport requests
def main():
print("Hello World!")
if __name__ == __main__:
main()
# For sending HTTP requests
import requests
# For Base64 encoding/decoding
from base64 import b64encode, b64decode, urlsafe_b64encode, urlsafe_b64decode
# For getting current time or for calculating time delays
from time import time
# For regular expressions
import re
# For running shell commands
import subprocess
# For multithreading
from concurrent.futures import ThreadPoolExecutor
# For running a HTTP server in the background
import threading
from http.server import HTTPServer, BaseHTTPRequestHandler
# For parsing HTTP cookies
from http import cookies
# For getting command-line arguments
import sys
requestsライブラリの使用resp_obj = requests.get("https://github.com")
# GET method
requests.get("https://github.com")
# POST method
requests.post("https://github.com")
# PUT method
requests.put("https://github.com")
# PATCH method
requests.patch("https://github.com")
# DELETE method
requests.delete("https://github.com")
resp_obj = requests.get("https://github.com")
# HTTP status code (e.g 404, 500, 301)
resp_obj.status_code
# HTTP response headers (e.g Location, Content-Disposition)
resp_obj.headers["Location"]
# Body as bytes
resp_obj.content
# Body as a string
resp_obj.text
# Body as a dictionary (if body is a JSON)
resp_obj.json()
params引数を使用)params = {
"foo": "bar"
}
requests.get("https://github.com", params=params)
data引数を使用)data = {
"foo": "bar"
}
requests.post("https://github.com", data=data)
json引数を使用)data = {
"foo": "bar"
}
requests.post("https://github.com", json=data)
files引数を使用)files = {
# (FILE_NAME, FILE_CONTENTS, FILE_MIMETYPE)
"uploaded_file": ("phpinfo.php", b"<?php phpinfo() ?>", "application/x-httpd-php")
}
requests.post("https://github.com", files=files)
headers引数を使用)headers = {
"X-Forwarded-For": "127.0.0.1"
}
requests.get("https://github.com", headers=headers)
cookies引数を使用)cookies = {
"PHPSESSID": "fakesession"
}
requests.get("https://github.com", cookies=cookies)
3XXリダイレクトの追跡を無効にする(allow_redirects引数を使用)requests.post("https://github.com/login", allow_redirects=False)
verify引数を使用)