该工具将帮助你识别系统中的远程代码执行漏洞 (log4j)。
你需要安装 httpx、subfinder、assetfinder、curl 和 amass 才能运行该 bash 脚本。
git clone https://github.com/shamo0/CVE-2021-44228.gitchmod +x log4j_scanner.sh./log4j_scanner.sh./log4j_scanner.sh -l subdomains.txt -i c6wvp482vtc10xx5bhnggdqp5neyyyyyb.interact.sh
./log4j_scanner.sh -d vulnsite.com -i c6wvp482vtc10xx5bhnggdqp5neyyyyyb.interact.sh
-h, --help 帮助菜单
-l, --url-list 用于扫描的域名/子域名/IP 列表。
-d, --domain 域名,其所有子域名和自身将通过 Subfinder 和 Assetfinder 检查。
-i, --inteactshdomain interactsh 域名地址。
但同时也请注意