Coder Social home page Coder Social logo

5l1v3r1 / pocbox Goto Github PK

View Code? Open in Web Editor NEW

This project forked from 0versp4ce/pocbox

0.0 0.0 0.0 42 MB

PoCBox - 赏金猎人的脆弱性测试辅助平台(破300star写重构版本,400star免费线上版本开放【在线食用地址:由于经常被DDOS导致服务器资源恶意被占用 费用过大决定关闭服务 】,1000star开源重构全新版本!)

HTML 2.70% PHP 23.63% CSS 30.41% JavaScript 43.25%

pocbox's Introduction

PoCBox - 漏洞测试验证辅助平台

开发这个平台的初衷是帮助自己在漏洞挖掘测试中更加方便快捷的辅助自己进行漏洞验证。

一开始的想法是框架化、模块化,但是开发着开发着就发现有点累,于是采用了原始的方法去开发:原生JavaScript+PHP。

PoCBox功能: 生成漏洞验证代码(便于撰写报告)、在线测试(便于快速手工测试)

作者:Vulkey_Chen 博客:gh0st.cn

团队:米斯特安全团队 Www.Hi-OurLife.Com

注意:平台不关注安全漏洞问题,也建议各位搭建的时候选好服务和域名!!!

400Star Flag

地址:http://pocbox.pwnhoo.com:68/

Docker

拉镜像

docker pull registry.cn-hangzhou.aliyuncs.com/pocbox/pocbox:1.0

运行

docker container run -d -p 本地端口:80 registry.cn-hangzhou.aliyuncs.com/pocbox/pocbox:1.0

PoCBox 版本更迭

关于PoCBox的版本更迭记录如下。

PoCBox V1 Beta

  1. 增加漏洞模块(JSONP劫持、CORS跨域资源读取、Flash跨域资源读取)
  2. 平台使用原生JS+PHP开发搭建

PoCBox V2 Beta

  1. 增加Fuzz类模块(URL)
  2. 增加其他类模块(Google Hack、Caimima)
  3. 平台由原生JS转向jQuery

PoCBox V2.0.1 Beta

  1. 修复JSONP劫持无法在线测试的问题(感谢:dogboy)
  2. 修复交互类攻击PoC的目标带有&符号无法正常在线测试(将URL地址进行URL编码再传输 感谢:Vulkey_Chen)
  3. 增加漏洞测试模块:点击劫持(按钮)、JavaScript URL跳转、302 URL跳转

PoCBox V3.0.0 Beta

  1. 增加漏洞测试模块:XXE for xls|xlsx|doc、文件上传、
  2. 增加其他类模块:搜索引擎SITE语法生成

PoCBox V3.0.1 Beta

  1. 修复XXE漏洞测试模块造成的RCE漏洞(感谢:Vulkey_Chen)

PoCBox 开源

开发出来不少时间了,也内测了一段时间,现在放出开源版本,如下图所示:

pocbox

搭建平台所需环境: PHP

开源功能:

  • 测试:JSONP劫持、CORS、Flash跨域资源读取、Google Hack语法生成、URL测试字典生成、JavaScript URL跳转、302 URL跳转
  • 中英文语言切换(默认为英文)

结合DoraBox靶场演示测试

Youtube:https://youtu.be/1Q5Q_8gObwU

pocbox

开源地址:https://github.com/gh0stkey/PoCBox

最后

感谢米斯特安全所有核心成员的协助内测。祝各位新年快乐!

pocbox's People

Contributors

gh0stkey avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.