该仓库包含一个用于自动化利用 CVE-2024-4956 的 Python 工具,能够从输入文件中批量测试文件路径,并自动将存在的文件路径内容保存到磁盘以供分析。漏洞详情可参见此处。
usage: cve-2024-4956.py [-h] [-f FILE] [-p PROXY] -u URL [--test] [-r RELATIVE_PATH]
CVE-2024-4956 Path Traversal Exploit Script
options:
-h, --help show this help message and exit
-f FILE, --file FILE Path to the text file containing a list of relative file paths to test based on the Nexus server installation path
-p PROXY, --proxy PROXY
HTTP proxy string to use for requests (e.g. http://localhost:8080)
-u URL, --url URL Base URL of the target server
--test Run the program in test mode to check for directory traversal vulnerability, then exit
-r RELATIVE_PATH, --relative-path RELATIVE_PATH
Relative path for traversal tests (paths in the file provided to -f will be underneath this path)
用于从 OrientDB .pcl 文件中自动化提取 Apache Shiro 1 哈希值的脚本可在此处获取,用于提取/收集哈希值以供 Hashcat 模块使用。
我开发了一个自定义的 Apache Shiro 1 hashcat 模块,而官方项目尚未支持该算法。该模块位于我的 hashcat 分支此处。你可以使用此程序提取的哈希值,并直接将其用于该模块。使用步骤如下:
12150 访问我已向官方 Hashcat 项目提交了拉取请求,希望它能被合并,使该模块可通过官方 Hashcat 仓库获取!有关创建 Hashcat 模块的博客文章已发布此处。
该仓库包含创建 Apache Shiro 1 Hashcat 模块时使用的实用工具,例如一个使用 OpenSSL 破解 Apache Shiro 1 哈希值的独立 C 程序,以及一个生成 Apache Shiro 1 哈希值的 Java 应用程序。
本程序仅用于合法及授权目的。作者不对该项目的滥用承担任何责任。