
Uma ferramenta simples para interagir com shells web e vulnerabilidades de injeção de comandos
Cliente de Web Shell
O Wshlient é um cliente de web shell projetado para ser bastante simples e versátil. Basta criar um arquivo de texto contendo uma requisição HTTP e informar onde o Wshlient injeta os comandos, então você pode aproveitar um shell.
https://github.com/user-attachments/assets/eafcf666-4c52-4e28-a341-a03bba93fe89
Caso o vídeo acima não funcione para você:
Além das baterias incluídas do Python, o Wshlient usa apenas o requests. Basta instalá-lo diretamente ou usando o requirements.txt:
$ git clone https://github.com/gildasio/wshlient
$ cd wshlient
$ pip install -r requirements.txt
$ ./wshlient.py -h
Alternativamente, você também pode criar um link simbólico no seu $PATH para usá-lo diretamente em qualquer lugar do sistema:
$ ln -s $PWD/wshlient.py /usr/local/bin/wshlient
$ ./wshlient.py -h
usage: wshlient.py [-h] [-d] [-i] [-ne] [-it INJECTION_TOKEN] [-st START_TOKEN] [-et END_TOKEN] req
positional arguments:
req File containing raw http request
options:
-h, --help show this help message and exit
-d, --debug Enable debug output
-i, --ifs Replaces whitespaces with $IFS
-ne, --no-url-encode Disable command URL encode
-it INJECTION_TOKEN, --injection-token INJECTION_TOKEN
Token to be replaced by commands (default: INJECT)
-st START_TOKEN, --start-token START_TOKEN
Token that marks the output beginning
-et END_TOKEN, --end-token END_TOKEN
Token that marks the output ending
Você pode contribuir para o Wshlient:
Sinta-se à vontade para fazê-lo, mas lembre-se de manter a simplicidade.