Giter Site home page Giter Site logo

aabysszg / springboot-scan Goto Github PK

View Code? Open in Web Editor NEW
1.3K 1.3K 123.0 3.2 MB

针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具

Home Page: https://blog.zgsec.cn/archives/129.html

License: MIT License

Python 100.00%
cve-2018-1273 cve-2021-21234 cve-2022-22947 cve-2022-22963 cve-2022-22965 exploit exploits security security-tools spring spring-boot spring-vulnerability springboot vul

springboot-scan's Introduction

About Me

  • 👋 Hi, My ID is AabyssZG, 你可以叫我曾哥
  • 👀 I'm good at 云安全、红蓝攻防和渗透测试
  • 🌱 I'm currently learning 区块链、DevSecOps
  • 📫 日常活跃于各大平台, 推特ID @AabyssZG
  • 👋 My Blog: https://blog.zgsec.cn
  • 🌱 JetBrains OSS Developer(使用JetBrains开源许可证)
  • 💞️ 感谢Github开源社区,感谢JetBrains对 Open source code 做出的贡献

My Skills

About MyWork

现在我在国际云安全联盟(CSA)渗透测试工作组做云安全方面的研究

云安全联盟大中华区官网:https://www.c-csa.cn

About MyTeam

我是渊龙Sec安全团队的负责人,团队英文名:AabyssTeam

My Future

🥰恭喜您成为第 位访客,感谢您的关注和支持~😍
  • 👀 会尝试上传我自己整理的一些笔记, 以及我自己做的一些安全相关的工具
  • 🌱 维护好团队项目, 开发出更多的优质项目
  • 👋 分享优质渗透测试的骚姿势,欢迎师傅们和我交流~

springboot-scan's People

Contributors

aabysszg avatar ffr66 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

springboot-scan's Issues

缺少代理

可以把延迟、和代理开发以下么 我看 使用的requests包 应该可以实现 有时候会卡
image

SpringBoot-Scan的一些建议

你好,作者!
我觉得这个脚本是不是可以添加一些爬虫功能 而不是只爆破字典中的内容 比如一些spring未授权环境下 访问/actuator/ 里面会有一些非字典中的内容如 /actuator/nacosconfig 、/actuator/nacosdiscovery等 这种情况下感觉加上爬虫爬取/actuator/会好一些

扫描报错

在扫描时发生错误,实际上应该存在这个目录,用其他扫描工具是正常的
111

安装库后,还是报错

Traceback (most recent call last):
File "E:\Tools\SpringBoot-Scan-main\SpringBoot-Scan.py", line 7, in
from inc import output, console, run ,proxycheck
File "E:\Tools\SpringBoot-Scan-main\inc\console.py", line 4, in
from inc import output,run,vul,springcheck
File "E:\ools\SpringBoot-Scan-main\inc\springcheck.py", line 4, in
from inc import output,run,vul,console
ImportError: cannot import name 'vul' from 'inc' (unknown location)

error

requests.exceptions.ConnectionError: HTTPConnectionPool(host='spring-dev-vab.apps.grv.scbs.ch', port=80): Max retries exceeded with url: /actuator (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7fc216eb1160>: Failed to establish a new connection: [Errno 111] Connection refused'))

I think you have to wait for 10 second if not response then you have to move other target

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.