Giter VIP home page Giter VIP logo

gatherburp's Introduction

Hi there 👋

This is kN6jq Github!

Github

Welcome to my Github page! I am kN6jq!

img

🌱 Things I am currently working on:

  • Java
  • Golang

gatherburp's People

Contributors

kn6jq avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar

gatherburp's Issues

db文件错误。

public class DbUtils
中的写法,会判定.gather目录是不是判定。如果目录不存在,就会创造数据库失败。
要修改create()

sql模块发送json数据包是批量同时发送

sql模块发送普通的post数据包就会一个一个参数的去打payload,碰到json数据包,就直接所有参数都一次性打上去了。碰到某些参数又会跳过不测试例如 regiongrade ,mouduleTYpe

fastjson回显payload不全

尝试使用了一下fastjson回显模块,只看到有spring的回显payload,辛苦大佬有空添加一下其他方式的回显

【建议】routescan和log4jscan增强

  1. routescan希望能集成RouteVulScan或者APIKit的指纹
  2. log4jscan希望能加入Log4j2Scan一样的fuzz功能,扩展可选选型,增加bypass能力

现有功能进过配置都能达到,但是最好预集成进初始配置中,增加开包即用,且个人配置不会随着未来版本迭代重新配置
(就是懒

格式问题

插件的格式有点小问题,一旦路径输入过长,就不能正常保存配置了。
也不能拖动
image

Routescan模块缺少初始配置

用的release里的gatherBurp-gatherBurp-1.0.7-SNAPSHOT-jar-with-dependencies

Routescan初始配置只有xxl-job的poc。

【建议】

  1. Routescan扫描路径的poc加入导入导出功能
  2. Sqlcheck模块能根据报错或变化直观提示注入点
  3. 各模块的白名单域名可多行或正则检查
  4. 加入各shiro检查模块 :D

UI小bug和log4j域名问题

image

sql注入模块的UI 被动检测怎么对不齐呀.

image

dnslog的这个域名是什么情况,能不能自动加载bp的域名进行检测。还是必须手动配置一个dns服务器,然后人工查看

提几个问题

1、重复的url似乎会重复进行扫描
2、sql注入模块,如果出现报错的话,可以增加一个提示,就不用每个url都点进去看,像xia_sql那个插件那样

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.