
编写漏洞利用脚本的技巧(更快!)
本仓库包含一系列与在 OSWE 实验室和认证考试中编写漏洞利用脚本相关的实用代码片段和技巧。
这里的一些示例可能违背某些编码实践,但我们的最终目标是快速且正确地编写漏洞利用脚本。
如果你对使用
requests库不熟悉,或者刚刚接触 Python,那么 代码片段 部分是一个很好的起点。否则,可以直接跳到 可复用代码 部分或 技巧 部分。
requests 库
params 参数)data 参数)json 参数)files 参数)headers 参数)cookies 参数)3XX 重定向(使用 allow_redirects 参数)verify 参数)proxies 参数)Sessionassert 在每个 HTTP 请求后执行健全性检查Session 对象,这样它就不需要显式地传递给每个函数调用BASE_URL 字符串并从它构造所需的 URLproxies 参数,请在运行时设置 HTTP_PROXY / HTTPS_PROXY 环境变量')和双引号(")时,使用 """ 创建 Payload 字符串{}),避免使用 f-string(f"")或 str.formatimport requests
def main():
print("Hello World!")
if __name__ == __main__:
main()
# For sending HTTP requests
import requests
# For Base64 encoding/decoding
from base64 import b64encode, b64decode, urlsafe_b64encode, urlsafe_b64decode
# For getting current time or for calculating time delays
from time import time
# For regular expressions
import re
# For running shell commands
import subprocess
# For multithreading
from concurrent.futures import ThreadPoolExecutor
# For running a HTTP server in the background
import threading
from http.server import HTTPServer, BaseHTTPRequestHandler
# For parsing HTTP cookies
from http import cookies
# For getting command-line arguments
import sys
requests 库resp_obj = requests.get("https://github.com")
# GET method
requests.get("https://github.com")
# POST method
requests.post("https://github.com")
# PUT method
requests.put("https://github.com")
# PATCH method
requests.patch("https://github.com")
# DELETE method
requests.delete("https://github.com")
resp_obj = requests.get("https://github.com")
# HTTP status code (e.g 404, 500, 301)
resp_obj.status_code
# HTTP response headers (e.g Location, Content-Disposition)
resp_obj.headers["Location"]
# Body as bytes
resp_obj.content
# Body as a string
resp_obj.text
# Body as a dictionary (if body is a JSON)
resp_obj.json()
params 参数)params = {
"foo": "bar"
}
requests.get("https://github.com", params=params)
data 参数)data = {
"foo": "bar"
}
requests.post("https://github.com", data=data)
json 参数)data = {
"foo": "bar"
}
requests.post("https://github.com", json=data)
files 参数)files = {
# (FILE_NAME, FILE_CONTENTS, FILE_MIMETYPE)
"uploaded_file": ("phpinfo.php", b"<?php phpinfo() ?>", "application/x-httpd-php")
}
requests.post("https://github.com", files=files)
headers 参数)headers = {
"X-Forwarded-For": "127.0.0.1"
}
requests.get("https://github.com", headers=headers)
cookies 参数)cookies = {
"PHPSESSID": "fakesession"
}
requests.get("https://github.com", cookies=cookies)
3XX 重定向(使用 allow_redirects 参数)requests.post("https://github.com/login", allow_redirects=False)
verify 参数)# Supresses InsecureRequestWarning messages
requests.packages.urllib3.disable_warnings(requests.packages.urllib3.exceptions.InsecureRequestWarning)
requests.get("https://github.com", verify=False)
proxies 参数)proxies = {
"HTTP": "http://127.0.0.1:8080",
"HTTPS": "http://127.0.0.1:8080"
}
requests.get("https://github.com", proxies=proxies)
Session