
.NET 패딩 오라클 평가 도구의 Python 구현
.NET 웹 애플리케이션이 패딩 오라클(Padding Oracle) 취약점에 노출되어 있는지 확인하는 작은 스크립트입니다. 이 스크립트는 패치가 설치되었는지 여부만 확인하는 것이 아니라, 오라클이 실제로 존재하고 악용 가능한지 검증합니다.
dotnetpaddingoracle.py [-h] [-t] [-b] [-d] [-s] [-p PARAMETER] Burp request file
Perform the padding Oracle attack on .NET web application
positional arguments:
Burp request file Request sample from Burp
optional arguments:
-h, --help show this help message and exit
-t, --test-vuln Test for the padding Oracle vulnerability
-b, --no-burp Disable Burp proxying
-d, --decrypt Decrypt
-s, --ssl use ssl transport
-p PARAMETER, --parameter PARAMETER
Parameter to use as Oracle