
此Python3脚本利用本地文件包含(LFI)漏洞,通过日志投毒技术实现远程代码执行(RCE)。专为Artica Proxy(CVE-2024-2053)设计,但也适用于其他LFI场景。
/etc/passwd、/proc/self/environ)git clone https://github.com/yourusername/artica-lfi-rce.git
cd artica-lfi-rce
pip3 install -r requirements.txt
python3 artica.py <target_url> <endpoint> [options]基本用法: python3 artica.py http://vulnerable.com /images.listener.php
使用代理: python3 artica.py https://target.com:9000 /vuln.php -p http://127.0.0.1:8080
详细模式: python3 artica.py http://victim.com /endpoint.php -v
忽略SSL错误: python3 artica.py https://self-signed.com /path.php --no-verify
| 组件 | 描述 |
|---|---|
| 载荷 |
|
| 注入点 | User-Agent、Referer、Cookies、GET参数 |
| Webshell | 随机文件名(shell_[TIMESTAMP].php) |
本工具仅供教育目的和授权渗透测试使用。开发者不承担任何责任,也不对因使用本程序造成的任何误用或损害负责。
MIT许可证 - 版权所有 (c) 2024