[10286] 2016-07-10_FlashXSS检测脚本的简单实现

文档创建者:s7ckTeam
浏览次数:4
最后更新:2025-01-18
2016-07-10_FlashXSS检测脚本的简单实现 F l a s h   X S S w h o a m i s b   F r e e B u f   2 0 1 6 - 0 7 - 1 0 f l a s h         x s s f l a s h z e r o c l i p b o a r d . s w f s w f u p l o a d . s w f   1 z e r o c l i p b o a r d . s w f f l a s h 使 f l a s h x s s   p o c Z e r o C l i p b o a r d . s w f ? i d = % 2 2 ) ) } c a t c h ( e ) { ( a l e r t ) ( / X S S / . s o u r c e ) ; } / / & w i d t h = 5 0 0 & h e i g h t = 5 0 0 E x t e r n a l i n t e r f a c e . c a l l i d x s s         i d   =   f l a s h v a r s . i d ;
i d   =   i d . s p l i t ( " " ) . j o i n ( " " ) ; 使 s p l i t ( ) j o i n ( ) i d x s s [ ]   X S S     1 6 .   F l a s h   X s s   [ E x t e r n a l I n t e r f a c e . c a l l ] Z e r o C l i p b o a r d . s w f p a y l o a d / Z e r o C l i p b o a r d . s w f / f l a s h / Z e r o C l i p b o a r d . s w f / j s / Z e r o C l i p b o a r d . s w f / s w f / Z e r o C l i p b o a r d . s w f 2 s w f u p l o a d . s w f w e b p o c s w f u p l o a d . s w f ? m o v i e N a m e = a a a % 2 2 ] ) } c a t c h ( e ) { ( a l e r t ) ( 1 ) } ; / / [ ]   X S S     1 5 .   F l a s h   X s s   [ E x t e r n a l I n t e r f a c e . c a l l ] s w f u p l o a d . s w f g i t h u b F i x e s   a   X S S   i s s u e   i n   E x t e r n a l C a l l s . t h i s . m o v i e N a m e   =   t h i s . m o v i e N a m e . r e p l a c e ( / [ ^ a - z A - Z 0 - 9 _ . - ] / g ,   " " ) ;   g , ^ ' a - z A - Z 0 - 9 _ ' . ' - ' m o v i e N a m e s w f u p l o a d . s w f p a y l o a d / s w f u p l o a d . s w f [ ^ a - z A - Z 0 - 9 _ . - ]
/ s w f u p l o a d / s w f u p l o a d . s w f / u p l o a d / s w f u p l o a d . s w f / i m a g e s / s w f u p l o a d . s w f / s t a t i c / s w f u p l o a d . s w f / c o m m o n / s w f u p l o a d . s w f s w f s e a y l a y e r l i j i j i e s u b D o m a i n s B r u t e t x t s w f w e b 1 h t t p s w e b h t t p h t t p s , d o u b l e h o m e _ p a g e   =   " h t t p : / / " + d o m a i n _ n a m e 2 访 访 j s c s s i m a g e p a y l o a d 访 j s r   =   r e q u e s t s . g e t ( h o m e _ p a g e ) 3 h r e f s r c a c t i o n j s u r l 访 P h a n t o m j s l i n k _ l i s t   = r e . f i n d a l l ( r " ( ? < = h r e f = " ) . + ? ( ? = " ) | ( ? < = h r e f = ' ) . + ? ( ? = ' ) | ( ? < = s r c = " ) . + ? ( ? = " ) | ( ? < = s r c = ' ) . + ? ( ? = ' ) | ( ? < = a c t i o n = " ) . + ? ( ? = " ) | ( ? < = a c t i o n = ' ) . + ? ( ? = ' ) "   , d a t a ) 4 访 访 访 3 s 线 3 s t i m e o u t = 3        
       
        1 s w f f l a s h 2 0 0 r e q u e s t s 访 a l l o w _ r e d i r e c t s F a l s e 2 0 0 s w f s w f c w s f w s c w s f w s i f   r . s t a t u s _ c o d e   = =   2 0 0 :         i f   b 2 a _ h e x ( r . c o n t e n t [ : 3 ] )   = =   " 4 3 5 7 5 3 "   o r   b 2 a _ h e x ( r . c o n t e n t [ : 3 ] )   = =   " 4 6 5 7 5 3 " : # C W S F W S             r e t u r n   T r u e 2 线 1 0 0 1 1 0 p a y l o a d p a y l o a d 访 0 - 3 s w e b 1 0 0 s 线 p y t h o n 线 p o o l   =   T h r e a d P o o l ( 5 0 ) r e s u l t s   =   p o o l . m a p ( g e t _ u r l _ c o d e ,   n e w _ u r l _ l i s t ) # g e t _ u r l _ c o d e r e q u e s t s . g e t p o o l . c l o s e ( ) p o o l . j o i n ( ) 3 H T T P S C o n n e c t i o n P o o l ( h o s t = ' x x x . x x x . x x x ' ,   p o r t = x x x ) :   M a x   r e t r i e s   e x c e e d e d   w i t h   u r l :   / x x x / x x x   ( C a u s e d   b y   N e w C o n n e c t i o n E r r o r ( ' :   F a i l e d   t o e s t a b l i s h   a   n e w   c o n n e c t i o n :   [ E r r n o   1 1 0 0 4 ]   g e t a d d r i n f o   f a i l e d ' , ) ) h t t p g o o g l e r e q u e s t s 使 u r l l i b 3 h t t p   c o n n e c t i o n k e e p - a l i v e r e q u e s t s . g e t ( " h t t p : / / . . . " ,   h e a d e r s = { ' C o n n e c t i o n ' : ' c l o s e ' } ) r e q u e s t s . p o s t ( " h t t p : / / . . . " ,   h e a d e r s = { ' C o n n e c t i o n ' : ' c l o s e ' } ) 1 0 0 p y t h o n
h t t p : / / w e i b o . c o m / w h o a m i s b *   w h o a m i s b F r e e B u f
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则