Giter Club home page Giter Club logo

charvulflow's Introduction

CharVulFlow_V1.0.1【补天 | 雷神 | 360众包】

```
_________ .__                ____   ____    .__  ___________.__                 
\_   ___ \|  |__ _____ ______\   \ /   /_ __|  | \_   _____/|  |   ______  _  __
/    \  \/|  |  \\__  \\_  __ \   Y   /  |  \  |  |    __)  |  |  /  _ \ \/ \/ /
\     \___|   Y  \/ __ \|  | \/\     /|  |  /  |__|     \   |  |_(  <_> )     / 
 \______  /___|  (____  /__|    \___/ |____/|____/\___  /   |____/\____/ \/\_/  
        \/     \/     \/                              \/
```

0x00、项目说明

  1. 需求:满足公益漏洞大批量提交需要(尤其针对零权活动),减少人工时间成本;
  2. 支持漏洞类型:GET类型请求,结果可直接回显浏览器(未授权访问、信息泄露、弱口令等);
  3. 支持个性化制:自定义需要截图证明,建议提前与审核商量好提交。
  4. 后续计划加入:权重检测模块,满足日常不参加活动公益漏洞提交。

0x01、配置文件

  1. 在module.get_shoot修改适合你电脑的webdrive配置,参考:

    • Edge浏览器配置Selenium
    • Chrome浏览器配置Selenium需修改部分代码
    • 第17行代码需要修改为自己的电脑用户名,否则截图浏览器出现弹窗。
  2. 在module.config填写需要的cookie以及apikey:

    [config]    # API:站长ICP|滑动验证
    chinaz = eaxxxxxxxxxxxxxxxxxxxxxxxxxxx43b 
    appkey = d2xxxxxxxxxxxxxxxxxxxxxxxxxxx52e
    
    [but]       # 补天
    cookie = wzws_sessionid=xxxxxx; PHPSESSID=xxxxxx; __btu__=xxxxxx; __btc__=xxxxxx; __btuc__=xxxxxx
    
    [thor]      # 雷神
    cookie = 25xxxxxx-d1b7-4277-a79d-xxxxxxxxxx35
    
    [bugcloud]   # 360众包
    cookie = sessionID=xxxxxx; Q_UDID=xxxxxx
    
  3. 在url.txt填写能回显的所有url,选择注释main函数 补天 is_but | 雷神 is_thor | 360众包 is_bugcloud 选择平台运行。

0x02、使用效果

  • jshERP-boot未授权访问为例:直接访问/jshERP-boot/user/getAllList;.ico即可获取所有用户账户密码。 img_1.png

  • 程序运行截图

      0%|          | 0/3 [00:00<?, ?it/s]成功提交金华市xxxxx有限公司
     33%|███▎      | 1/3 [01:05<02:11, 65.51s/it]成功提交苏州xxxxx有限公司
     67%|██████▋   | 2/3 [02:08<01:04, 64.25s/it]成功提交广州xxxxx有限公司
    100%|██████████| 3/3 [03:23<00:00, 67.71s/it]
    
  • 提交成功列表 img_2.png img_3.png

  • 漏洞详细 img_4.png

0x03、项目逻辑

  • 运行流程结构 img.png

charvulflow's People

Contributors

iamhufei avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.