Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

未添加关键字检测 #2

Open
Funhity opened this issue Sep 19, 2019 · 6 comments
Open

未添加关键字检测 #2

Funhity opened this issue Sep 19, 2019 · 6 comments

Comments

@Funhity
Copy link

Funhity commented Sep 19, 2019

发现在ssrf还有CVE-2018-2894中只做了状态码200的判断,导致误报,建议添加下关键判断。

@rabbitmask
Copy link
Owner

感谢反馈,这里确实偷了个小懒,在目标网站根本就不是weblogic站点的情况下确实会产生这种误报,然而确实是weblogic的情况下,并不影响检测结果。

@1154322699
Copy link

1154322699 commented Sep 23, 2019 via email

@Funhity
Copy link
Author

Funhity commented Sep 23, 2019

因为我测试的时候发现网站存在waf,当被waf拦截跳转到其他页面时,也会提示漏洞存在

@rabbitmask
Copy link
Owner

十分感谢,waf拦截导致返回200确实有可能,这就说得通了,我会在下一版本同时正则返回内容,而不是只判断状态码,再次感谢,鞠躬~

@1154322699
Copy link

1154322699 commented Sep 23, 2019 via email

@Funhity
Copy link
Author

Funhity commented Sep 24, 2019

^_^

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants