Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
exploit-writing-for-oswe — 编写漏洞利用脚本的技巧(更快!) | Kitploit
工具/GitHubGitHub/rizemon/exploit-writing-for-oswe
脚本与自动化Web应用程序漏洞利用Web安全渗透测试学习与教育精选资源Payload 开发
GitHubrizemon/exploit-writing-for-oswe

exploit-writing-for-oswe

编写漏洞利用脚本的技巧(更快!)

查看仓库
591112162年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

OSWE 漏洞利用编写

背景

是什么

本仓库包含一系列与在 OSWE 实验室和认证考试中编写漏洞利用脚本相关的实用代码片段和技巧。

这里的一些示例可能违背某些编码实践,但我们的最终目标是快速且正确地编写漏洞利用脚本。

如果你对使用 requests 库不熟悉,或者刚刚接触 Python,那么 代码片段 部分是一个很好的起点。否则,可以直接跳到 可复用代码 部分或 技巧 部分。

为什么

  • 虽然关于该认证有很多 write-up、评测和笔记,但专门关注漏洞利用编写过程的资源却很少。
  • 编写漏洞利用脚本可能令人生畏,尤其是对于 Python 新手或缺乏通过代码与 Web 应用交互经验的人来说。
  • 识别漏洞和撰写考试报告所花费的时间可能会有很大波动,但如果掌握得当,开发漏洞利用脚本的时间可以最小化并保持稳定。

目录

  • OSWE 漏洞利用编写
    • 背景
      • 是什么
      • 为什么
    • 目录
    • 代码片段
      • 起始模板
      • 有用的导入
      • 使用 requests 库
        • 发送最简单的 HTTP 请求
        • 指定不同的 HTTP 方法
        • 读取 HTTP 响应
        • 在 URL 中以查询字符串形式发送数据(使用 params 参数)
        • 在请求体中以查询字符串形式发送数据(使用 data 参数)
        • 在请求体中发送 JSON 数据(使用 json 参数)
        • 在请求体中发送文件(使用 files 参数)
        • 设置 HTTP 请求头(使用 headers 参数)
        • 设置 HTTP Cookie(使用 cookies 参数)
        • 禁用跟随 3XX 重定向(使用 allow_redirects 参数)
        • 与未验证的 HTTPS 服务器交互(使用 verify 参数)
        • 通过 HTTP 代理发送请求(使用 proxies 参数)
        • 创建 Session
        • 设置持久化 Cookie
        • 设置持久化请求头
      • 故障排除
        • 使用 Wireshark 并过滤 HTTP 请求
        • 打印 HTTP 请求的内容
        • 通过 Burp Suite 代理 HTTP 请求并检查
      • 可复用代码
        • 通过 HTTP 提供文件服务
        • 窃取 HTTP Cookie
        • 加速 SQL 注入
    • 技巧
      • 使用 assert 在每个 HTTP 请求后执行健全性检查
      • 在每个步骤后打印有意义的信息
      • 将每个漏洞利用步骤拆分为单独的函数
      • 创建一个全局的 Session 对象,这样它就不需要显式地传递给每个函数调用
      • 创建一个全局的 BASE_URL 字符串并从它构造所需的 URL
      • 要强制所有 HTTP 请求都通过 Burp Suite,而无需使用 proxies 参数,请在运行时设置 HTTP_PROXY / HTTPS_PROXY 环境变量
      • 应用编码/解码方案以安全地传输 Payload
      • 当 Payload 同时包含单引号(')和双引号(")时,使用 """ 创建 Payload 字符串
      • 使用多线程加速 SQL 注入
      • 在开发针对需要认证功能的漏洞利用时,硬编码已认证用户的 Cookie
      • 如果 Payload 包含太多花括号({}),避免使用 f-string(f"")或 str.format

代码片段

起始模板

import requests

def main():
    print("Hello World!")

if __name__ == __main__:
    main()

有用的导入

# For sending HTTP requests
import requests

# For Base64 encoding/decoding
from base64 import b64encode, b64decode, urlsafe_b64encode, urlsafe_b64decode

# For getting current time or for calculating time delays
from time import time

# For regular expressions
import re

# For running shell commands
import subprocess

# For multithreading
from concurrent.futures import ThreadPoolExecutor

# For running a HTTP server in the background
import threading
from http.server import HTTPServer, BaseHTTPRequestHandler

# For parsing HTTP cookies
from http import cookies

# For getting command-line arguments
import sys

使用 requests 库

发送最简单的 HTTP 请求

resp_obj = requests.get("https://github.com")

指定不同的 HTTP 方法

# GET method
requests.get("https://github.com")

# POST method
requests.post("https://github.com")

# PUT method
requests.put("https://github.com")

# PATCH method
requests.patch("https://github.com")

# DELETE method
requests.delete("https://github.com")

读取 HTTP 响应

resp_obj = requests.get("https://github.com")

# HTTP status code (e.g 404, 500, 301)
resp_obj.status_code

# HTTP response headers (e.g Location, Content-Disposition)
resp_obj.headers["Location"]

# Body as bytes
resp_obj.content

# Body as a string
resp_obj.text

# Body as a dictionary (if body is a JSON)
resp_obj.json()

在 URL 中以查询字符串形式发送数据(使用 params 参数)

params = {
    "foo": "bar"
}

requests.get("https://github.com", params=params)

在请求体中以查询字符串形式发送数据(使用 data 参数)

data = {
    "foo": "bar"
}

requests.post("https://github.com", data=data)

在请求体中发送 JSON 数据(使用 json 参数)

data = {
    "foo": "bar"
}

requests.post("https://github.com", json=data)

在请求体中发送文件(使用 files 参数)

files = {
    #                (FILE_NAME, FILE_CONTENTS, FILE_MIMETYPE)
    "uploaded_file": ("phpinfo.php", b"<?php phpinfo() ?>", "application/x-httpd-php")
}

requests.post("https://github.com", files=files)

设置 HTTP 请求头(使用 headers 参数)

headers = {
    "X-Forwarded-For": "127.0.0.1"
}

requests.get("https://github.com", headers=headers)

设置 HTTP Cookie(使用 cookies 参数)

cookies = {
    "PHPSESSID": "fakesession"
}

requests.get("https://github.com", cookies=cookies)

禁用跟随 3XX 重定向(使用 allow_redirects 参数)

requests.post("https://github.com/login", allow_redirects=False)

与未验证的 HTTPS 服务器交互(使用 verify 参数)

# Supresses InsecureRequestWarning messages
requests.packages.urllib3.disable_warnings(requests.packages.urllib3.exceptions.InsecureRequestWarning)

requests.get("https://github.com", verify=False)

通过 HTTP 代理发送请求(使用 proxies 参数)

proxies = {
    "HTTP": "http://127.0.0.1:8080",
    "HTTPS": "http://127.0.0.1:8080"
}

requests.get("https://github.com", proxies=proxies)

创建 Session

下载工具