首先运行 docker run --rm -p 8000:80 siwecos/infoleak-scanner。
打开浏览器使用扫描器:http://localhost/?url=<URL>
安装 php5、curl 和网络服务器:
sudo apt-get install apache2 php5 php5-curl
将应用程序复制到网络服务器目录:
cp -R . /var/www/html/
搜索检测到的 CMS 的插件。最大的列表(wordpress)包含 980 个不同的插件。
搜索存在漏洞且最常用的 JavaScript 库。
搜索邮件地址。对垃圾邮件和/或社会工程学攻击有价值。
搜索电话号码。对社会工程学攻击和/或诈骗有价值。
| 发现项 | 评分 (0-100) |
|---------------------+---------------|
| CMS_ONLY | 100 |
| CMS_VERSION | 96 |
| CMS_VERSION_VULN | 见下方说明 |
| PLUGIN_ONLY | 99 |
| PLUGIN_VERSION | 96 |
| PLUGIN_VERSION_VULN | 见下方说明 |
| JS_LIB_ONLY | 99 |
| JS_LIB_VERSION | 96 |
| JS_LIB_VULN_VERSION | 见下方说明 |
| EMAIL_FOUND | 96 |
| NUMBER_FOUND | 98 |
如果发现以下类型:
CMS_VERSION_VULN
PLUGIN_VERSION_VULN
JS_LIB_VULN_VERSION
则总分将上限为 20 分,并且每多一个漏洞将扣减 10 分。这意味着,如果同时返回
CMS_VERSION_VULN、PLUGIN_VERSION_VULN 和 JS_LIB_VULN_VERSION,总分将为 0 分。
此外,在 Wordpress 网站上发现 jQuery v1.12.4 时,不会像普通易受攻击库那样评分。
此类发现将导致 90 分的评分,但占位符仍为 JS_LIB_VULN_VERSION,因为它是一个易受攻击的库。
您可以通过 POST 和 GET 请求运行扫描器。
如果您希望通过 POST 请求运行扫描器,必须以 JSON 编码格式发送参数:
{
"url": "string",
"dangerLevel": 0,
"callbackurls": [
"string"
],
"userAgent": "string"
}
url 定义要扫描的 URL。
dangerLevel 不相关,只需设置为 0。
callbackurls 是一个 URL 数组。这些 URL 将接收扫描结果(通过 POST 发送)。
userAgent 定义您希望在扫描时发送的自定义用户代理。
通过 GET 请求运行扫描器更简单。您只需提供一个 URL 即可运行应用程序:
http://localhost/?url=<URL>
所有扫描均未发现结果:
{
"name": "InfoLeak-Scanner",
"version": "1.0.0",
"hasError": false,
"errorMessage": null,
"score": 100,
"tests": [
{
"name": "CMS",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "info",
"testDetails": null
},
{
"name": "CMS_PLUGINS",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "warning",
"testDetails": null
},
{
"name": "JS_LIB",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "warning",
"testDetails": null
},
{
"name": "EMAIL_ADDRESS",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "info",
"testDetails": null
},
{
"name": "PHONE_NUMBER",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "info",
"testDetails": null
}
]
}
每次扫描至少发现一个问题:
{
"name": "InfoLeak-Scanner",
"version": "1.0.0",
"hasError": false,
"errorMessage": null,
"score": 20,
"tests": [
{
"name": "CMS",
"hasError": false,
"errorMessage": null,
"score": 96,
"scoreType": "info",
"testDetails": [
{
"placeholder": "CMS_VERSION",
"values": {
"cms": "wordpress",
"version": "4.9.6",
"node": "meta",
"node_content": "WordPress 4.9.6"
}
}
]
},
{
"name": "CMS_PLUGINS",
"hasError": false,
"errorMessage": null,
"score": 99,
"scoreType": "warning",
"testDetails": [
{
"placeholder": "PLUGIN_ONLY",
"values": {
"plugin": "contact-form-7",
"node": "href",
"node_content": "https://[...]/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.0.2"
}
}
]
},
{
"name": "JS_LIB",
"hasError": false,
"errorMessage": null,
"score": 0,
"scoreType": "warning",
"testDetails": [
{
"placeholder": "JS_LIB_VULN_VERSION",
"values": {
"js_lib_name": "jquery",
"js_lib_version": "1.12.4",
"node": "src",
"node_content": "https://[...]/wp-includes/js/jquery/jquery.js?ver=1.12.4"
}
}
]
},
{
"name": "EMAIL_ADDRESS",
"hasError": false,
"errorMessage": null,
"score": 96,
"scoreType": "info",
"testDetails": [
{
"placeholder": "EMAIL_FOUND",
"values": {
"email_adress": [
[
"[email protected]"
]
]
}
}
]
},
{
"name": "PHONE_NUMBER",
"hasError": false,
"errorMessage": null,
"score": 98,
"scoreType": "info",
"testDetails": [
{
"placeholder": "NUMBER_FOUND",
"values": {
"number": [
"1234-12 11 22-3",
"123-11 22 333-4"
]
}
}
]
}
]
}