基於Python3的漏洞檢測工具 ( Python3 插件式框架 )
阿新 • • 發佈:2018-07-18
lang gin detection print shel load nec list auto [TOC]
Python3 漏洞檢測工具 -- lance
lance, a simple version of the vulnerability detection framework based on Python3.
基於Python3的簡單版漏洞檢測框架 -- lance
可以自定義poc或exp插件,可以指定要加載的poc或exp。
代碼已經上傳到Github : https://github.com/b4zinga/lance
screenshot
requirements
python3
關鍵代碼
def loadPlugin(url, poc=None): """load all plugins. """ if "://" not in url: url = "http://" + url url = url.strip("/") print("[*] Target url: %s" % url) plugin_path = os.path.join(os.path.dirname(os.path.dirname(os.path.realpath(__file__))),"plugins") if not os.path.isdir(plugin_path): print("[!] %s is not a directory! " % plugin_path) raise EnvironmentError print("[*] Plugin path: %s " % plugin_path) items = os.listdir(plugin_path) if poc: print("[*] Loading %s plugins." % poc) for item in items: if item.endswith(".py") and not item.startswith(‘__‘): plugin_name = item[:-3] if poc in plugin_name: print("[*] Loading plugin: %s" % plugin_name) module = importlib.import_module("plugins." + plugin_name) try: result = module.run(url) if result: print("[+] " + result) else: print("[-] Not Vulnerable %s " % plugin_name) except: print("[!] ConnectionError ") else: continue else: for item in items: if item.endswith(".py") and not item.startswith(‘__‘): plugin_name = item[:-3] print("[*] Loading plugin: %s" % plugin_name) module = importlib.import_module("plugins." + plugin_name) try: result = module.run(url) if result: print("[+] " + result) else: print("[-] Not Vulnerable %s " % plugin_name) except: print("[!] ConnectionError ") print("[*] Finished")
usage
please run python3 lance.py -h
for help.
root@kali:~/lance# python3 lance.py usage: python lance.py lance. By [email protected] optional arguments: -h, --help show this help message and exit Target: -u URL target url. Module: -m module poc or exp to be loaded. defaul is all.
documents
說明文檔 : https://github.com/b4zinga/lance/blob/master/README.md
Guide : https://github.com/b4zinga/lance/blob/master/docs/Guide.md
ChangeLog : https://github.com/b4zinga/lance/blob/master/docs/ChangeLog.md
TODOList : https://github.com/b4zinga/lance/blob/master/docs/TODOList.md
Any advice or sugggestions
Please mail to [email protected]
代碼已經上傳到Github : https://github.com/b4zinga/lance
基於Python3的漏洞檢測工具 ( Python3 插件式框架 )