
go-exploit과 함께 사용할 HTTP 캐시 데이터베이스를 생성하는 유틸리티
go-exploit-cache는 go-exploit 프레임워크에서 사용하는 HTTP 캐시 SQLite 데이터베이스를 빌드하여 익스플로잇 간 공유와 스캔 없는(scanless) 대상 검증을 가능하게 합니다. 대상에 능동적으로 연결하는 대신, go-exploit은 캐시를 조회하여 이전에 수집된 HTTP 데이터(Shodan, Censys, PCAP, RunZero 등)를 사용해 버전 확인 및 기타 스캔을 실행할 수 있습니다.
프로젝트:
vulncheck-oss/go-exploit
이 도구는go-exploit이 읽는 SQLite 캐시를 생성합니다.
go-exploit이 스캔 없는 검증 및 버전 확인에 사용하는 SQLite http_cache를 생성합니다..json.gz, RunZero JSONL (제한적 RunZero JSON1), PCAP/pcapng, Censys JSONL (헬퍼 스크립트 사용)..json.gzcensys/censys_v3_dump.py로 준비)go-exploit이 사용할 수 있는 SQLite DB를 생성합니다.자세한 내용은 USAGE.md를 참조하세요.
./build/go-exploit-cache \
-type shodan-gzip \
-in ~/Downloads/734342e9-56b8-4299-a072-9d1d28f66434.json.gz \
-out confluence.db
일반적인 출력:
Decompressing the Shodan GZIP... this can be slow
Decompressed file written to .tmp/shodan.json
Generating database entries...
Cleaning up .tmp directory
DB 검사:
sqlite3 confluence.db
sqlite> select rhost, rport from http_cache limit 1;
52.200.210.54|80
캐시된 데이터만 사용하여 대상을 검증할 수 있습니다. 예제에서는 unshare -n을 사용하여 네트워크 접근을 차단합니다 (데모 전용 — unshare는 필수가 아닙니다):
sudo unshare -n ./build/cve-2023-22527_linux-arm64 \
-c -v -rhost 52.200.210.54 -rport 80 \
-db ~/go-exploit-cache/confluence.db
출력 예시:
time=... level=STATUS msg="Starting target" host=52.200.210.54 port=80
time=... level=STATUS msg="Validating Confluence target"
time=... level=SUCCESS msg="Target verification succeeded!"
time=... level=VERSION msg="The reported version is 7.19.17"
time=... level=STATUS msg="The target appears to be a patched version." vulnerable=no
shodan-gzip — Shodan .json.gz 내보내기runzero-jsonl — RunZero JSONL (제한적 JSON1 지원)pcap / pcapng — PCAP 파일 (HTTP 트래픽 추출)censys-jsonl — Censys JSONL (censys/의 헬퍼 스크립트 사용)예제 파일은 test/testdata를 참조하세요.
censys_v3_dump.py를 만들었습니다. 이 스크립트는 Censys Platform 검색 쿼리를 받아들여 시작한 다음, HTTP 헤더와 전체 HTTP 본문에 접근하기 위해 개별 호스트를 다운로드합니다. censys/censys_v3_dump.py를 사용하여 Censys 결과를 수집하고 수집에 적합한 JSONL로 포맷하세요.http_cache — 메인 테이블 (캐시 생성 테이블)
| column | type | description |
|---|---|---|
| id | INTEGER | primary key |
| created | INTEGER | date |
| rhost | TEXT | remote host (IP) |
| rport | INT | remote port |
| uri | TEXT | the cached path |
| data | BLOB | HTTP headers + body |
verified — 소프트웨어 설명 테이블 (go-exploit이 채우는 테이블)
| column | type | description |
|---|---|---|
| id | INTEGER | primary key |
| created | INTEGER | date |
| software name | TEXT | Name of software |
| installed | INT | 0 or 1 |
| version | TEXT | The software version |
| rhost | TEXT | remote host (IP) |
| rport | INT | remote port |
Ubuntu에서:
sudo apt install libpcap-dev
make
(Go 툴체인이 필요합니다 — https://go.dev/doc/install 참조.)