
익스플로잇 스크립트 작성 팁 (더 빠르게!)
이 저장소에는 OSWE 랩 및 자격증 시험에서 익스플로잇 스크립트를 작성하는 데 유용한 스니펫과 팁 목록이 포함되어 있습니다.
여기 있는 일부 예제는 특정 코딩 관행에 어긋날 수 있지만, 우리의 최종 목표는 익스플로잇 스크립트를 빠르고 정확하게 작성하는 것입니다.
requests라이브러리 사용에 익숙하지 않거나 Python이 처음이라면 코드 스니펫 섹션에서 시작하는 것이 좋습니다. 그렇지 않다면 재사용 가능한 코드 섹션이나 팁 섹션으로 건너뛰어도 됩니다.
requests 라이브러리 사용하기
params 인자 사용)data 인자 사용)json 인자 사용)files 인자 사용)headers 인자 사용)cookies 인자 사용)3XX 리다이렉트 따라가기 비활성화 (allow_redirects 인자 사용)verify 인자 사용)proxies 인자 사용)Session 생성하기assert로 sanity check 수행하기Session 객체 생성하기BASE_URL 문자열을 생성하고 이로부터 필요한 URL 구성하기proxies 인자를 사용하지 않고 모든 HTTP 요청이 Burp Suite를 통과하도록 하려면, 실행 시 HTTP_PROXY / HTTPS_PROXY 환경 변수를 설정하세요')와 큰따옴표(")가 모두 포함된 경우 """를 사용하여 생성하기{})가 너무 많이 포함된 경우 f-strings(f"")이나 str.format 사용 피하기import requests
def main():
print("Hello World!")
if __name__ == __main__:
main()
# For sending HTTP requests
import requests
# For Base64 encoding/decoding
from base64 import b64encode, b64decode, urlsafe_b64encode, urlsafe_b64decode
# For getting current time or for calculating time delays
from time import time
# For regular expressions
import re
# For running shell commands
import subprocess
# For multithreading
from concurrent.futures import ThreadPoolExecutor
# For running a HTTP server in the background
import threading
from http.server import HTTPServer, BaseHTTPRequestHandler
# For parsing HTTP cookies
from http import cookies
# For getting command-line arguments
import sys
requests 라이브러리 사용하기resp_obj = requests.get("https://github.com")
# GET method
requests.get("https://github.com")
# POST method
requests.post("https://github.com")
# PUT method
requests.put("https://github.com")
# PATCH method
requests.patch("https://github.com")
# DELETE method
requests.delete("https://github.com")
resp_obj = requests.get("https://github.com")
# HTTP status code (e.g 404, 500, 301)
resp_obj.status_code
# HTTP response headers (e.g Location, Content-Disposition)
resp_obj.headers["Location"]
# Body as bytes
resp_obj.content
# Body as a string
resp_obj.text
# Body as a dictionary (if body is a JSON)
resp_obj.json()
params 인자 사용)params = {
"foo": "bar"
}
requests.get("https://github.com", params=params)
data 인자 사용)data = {
"foo": "bar"
}
requests.post("https://github.com", data=data)
json 인자 사용)data = {
"foo": "bar"
}
requests.post("https://github.com", json=data)
files 인자 사용)files = {
# (FILE_NAME, FILE_CONTENTS, FILE_MIMETYPE)
"uploaded_file": ("phpinfo.php", b"<?php phpinfo() ?>", "application/x-httpd-php")
}
requests.post("https://github.com", files=files)
headers 인자 사용)headers = {
"X-Forwarded-For": "127.0.0.1"
}
requests.get("https://github.com", headers=headers)
cookies 인자 사용)cookies = {
"PHPSESSID": "fakesession"
}
requests.get("https://github.com", cookies=cookies)
3XX 리다이렉트 따라가기 비활성화 (allow_redirects 인자 사용)requests.post("https://github.com/login", allow_redirects=False)
verify 인자 사용)# Supresses InsecureRequestWarning messages
requests.packages.urllib3.disable_warnings(requests.packages.urllib3.exceptions.InsecureRequestWarning)