
このツールは、お使いのシステムにおけるリモートコード実行の脆弱性(log4j)を特定するのに役立ちます。
bash スクリプトを実行するには、httpx、subfinder、assetfinder、curl、amass をインストールする必要があります。
git clone https://github.com/shamo0/CVE-2021-44228.gitchmod +x log4j_scanner.sh./log4j_scanner.sh./log4j_scanner.sh -l subdomains.txt -i c6wvp482vtc10xx5bhnggdqp5neyyyyyb.interact.sh
./log4j_scanner.sh -d vulnsite.com -i c6wvp482vtc10xx5bhnggdqp5neyyyyyb.interact.sh
-h, --help Help menu
-l, --url-list List of domain/subdomain/ip to be used for scanning.
-d, --domain The domain name to which all subdomains and itself will be checked with Subfinder & Assetfinder.
-i, --inteactshdomain interactsh domain address.
ただし、以下の点にもご注意ください。