你可以使用以下 Shodan 搜索语法来查找公开目标。
http.favicon.hash:362091310http.favicon.hash:545827989path=/mifs你可以使用以下命令将 Shodan API 返回的数据转换为适合检测脚本的格式:
jq -cr 'select(.http.favicon.hash == 362091310) | [ if .ssl? then "https://" else "http://" end , (.ip_str) + ":" + (.port|tostring)] | add' example.json > your_data_file.txt
./CVE-2023-35078.sh http[s]://your.target:port(同时指定协议和目标端口)如果你想测试多个目标,可以简单地用一个循环来包装:
while read line; do ./CVE-2023-35078.sh $line; done < your_data_file.txt
此漏洞影响所有受支持的版本 – 11.4 版本的 11.10、11.9 和 11.8 版本。更早的版本/发布也存在风险。
你可以通过升级到 EPMM 版本 11.8.1.1、11.9.1.1 和 11.10.0.2 来修复漏洞。这些修复版本还覆盖了低于 11.8.1.0 的不受支持和生命周期结束(EoL)的软件版本。