Coder Social home page Coder Social logo

opensec-cn / vtest Goto Github PK

View Code? Open in Web Editor NEW
873.0 873.0 191.0 400 KB

用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。

License: Apache License 2.0

Python 98.04% Dockerfile 1.96%

vtest's People

Contributors

explorer1092 avatar l3m0n avatar neargle avatar ywolf avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

vtest's Issues

配置完dns访问测试httplog的时候显示1016 Origin DNS error

你好,请问一下,我在godaddy买的域名,然后按照vtest的domain.md说明做的dns设置,然后配置完成后,可以登录,但是在测试httplog的时候总是显示Error 1016 Origin DNS error这个页面
image
下面这个是我的dns配置:
image

偶尔能访问成功一次,但是大部分时候还是显示Error 1016 Origin DNS error

关于接收请求刷新

建议增加刷新按钮或者切换每个选项卡的时候自动刷新,不然每次都要自己右键刷新网页记录才会出来~~~~

关于TOKEN硬编码

看了下,貌似目前API_TOKEN是硬编码的,PASSWORD写死了。

PASSWORD = 'admin'
API_TOKEN = md5("ded08972cead38d6ed8f485e5b65b4b6" + PASSWORD)

关于https的支持

目前想的方案是nginx加上https,然后反代到vtest,不知道还有其他便捷点的没。

i.example.com解析不生效

399行是不是应该改成这样才能生效?直接用没有解析,改完就可以了

pre_data = domain.replace('.' + 'i' + '.' + ROOT_DOMAIN, '')

xss + sql injection

26331556080339_ pic_hd
xss
26341556080344_ pic_hd

注入
body参数
26351556080349_ pic_hd
body参数直接获取,没有过滤,并入查询,导致注入
image

为什么解析结果固定为 1.1.1.1 ?

def dns():
    d = DNSServer()
    d.add_record('httplog', LOCAL_IP)
    d.add_record('x', LOCAL_IP)
    d.add_record('mock', LOCAL_IP)
    d.start()

只有 httplog 、x 、mock解析的结果为LOCAL_IP,其余的解析结果为1.1.1.1

为什么其他的解析结果不是LOCAL_IP呢?这么做的用意是什么?

blind ssrf时,利用 http://xx.x.baidu.com/ 作为payload,可以一次性判断此ssrf漏洞多种的可能性。比如域名是否解析,http请求是否能正常发出。

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.