go-exploit-cache 构建一个由 go-exploit 框架使用的 HTTP 缓存 SQLite 数据库,以实现跨漏洞利用共享和无扫描目标验证。go-exploit 无需主动连接目标,而是可以查询缓存,利用先前收集的 HTTP 数据(Shodan、Censys、PCAP、RunZero 等)来运行版本检查和其他扫描。
项目:
vulncheck-oss/go-exploit
此工具生成go-exploit读取的 SQLite 缓存。
go-exploit 用于无扫描验证和版本检查的 SQLite http_cache。.json.gz、RunZero JSONL(以及有限的 RunZero JSON1)、PCAP/pcapng,以及 Censys JSONL(通过辅助脚本)。.json.gzcensys/censys_v3_dump.py 进行准备)go-exploit 使用的 SQLite 数据库更多详情请参见 USAGE.md。
./build/go-exploit-cache \
-type shodan-gzip \
-in ~/Downloads/734342e9-56b8-4299-a072-9d1d28f66434.json.gz \
-out confluence.db
典型输出:
Decompressing the Shodan GZIP... this can be slow
Decompressed file written to .tmp/shodan.json
Generating database entries...
Cleaning up .tmp directory
检查数据库:
sqlite3 confluence.db
sqlite> select rhost, rport from http_cache limit 1;
52.200.210.54|80
您可以仅使用缓存数据验证目标。示例使用 unshare -n 来阻止网络访问(仅用于演示——并非必须使用 unshare):
sudo unshare -n ./build/cve-2023-22527_linux-arm64 \
-c -v -rhost 52.200.210.54 -rport 80 \
-db ~/go-exploit-cache/confluence.db
示例输出:
time=... level=STATUS msg="Starting target" host=52.200.210.54 port=80
time=... level=STATUS msg="Validating Confluence target"
time=... level=SUCCESS msg="Target verification succeeded!"
time=... level=VERSION msg="The reported version is 7.19.17"
time=... level=STATUS msg="The target appears to be a patched version." vulnerable=no
shodan-gzip — Shodan .json.gz 导出runzero-jsonl — RunZero JSONL(有限的 JSON1 支持)pcap / pcapng — PCAP 文件(提取 HTTP 流量)censys-jsonl — Censys JSONL(使用 censys/ 中的辅助脚本)示例文件请参见 test/testdata。
censys_v3_dump.py 来抓取数据。它首先接受一个 Censys Platform 搜索查询,然后下载各个主机以访问 HTTP 标头和完整的 HTTP 正文。使用 censys/censys_v3_dump.py 收集 Censys 结果并将其格式化为适合摄取的 JSONL。http_cache — 主表(缓存生成表)
| column | type | description |
|---|---|---|
| id | INTEGER | primary key |
| created | INTEGER | date |
| rhost | TEXT | remote host (IP) |
| rport | INT | remote port |
| uri | TEXT | the cached path |
| data | BLOB | HTTP headers + body |
verified — 软件描述表(go-exploit 填充表)
| column | type | description |
|---|---|---|
| id | INTEGER | primary key |
| created | INTEGER | date |
| software name | TEXT | Name of software |
| installed | INT | 0 or 1 |
| version | TEXT | The software version |
| rhost | TEXT | remote host (IP) |
| rport | INT | remote port |
在 Ubuntu 上:
sudo apt install libpcap-dev
make
(需要 Go 工具链——参见 https://go.dev/doc/install。)