Giter VIP home page Giter VIP logo

thinkphpgui's Introduction

ThinkPHPGUI

  • Thinkphp(GUI)漏洞利用工具,支持各版本TP漏洞检测,命令执行,getshell。 (如果感觉对您有帮助,感觉不错的话,请您给个大大的 ⭐️❗️)
  • JFormDesigner可视化编写,没有javafx可视化好用(建议学javafx)。
  • 检测不到的payload欢迎提交payload至issues。

V1.3

新增:ThinkPHP 6.x 日志泄漏。

修复:ThinkPHP 3.x,5.x日志泄漏识别准确度。

V1.2

新增:刚爆出的 ThinkPHP 3.x 日志包含RCE,getshell,命令执行

截屏2021-07-22 上午12 45 51

V1.1

新增:ThinkPHP5.x,ThinkPHP3.x日志泄露

截屏2021-06-27 下午6 34 29

V1.0

  • 支持版本:

    截屏2021-06-23 上午2 23 51
  1. 检测单个版本漏洞

检查单个

  1. 检测多个版本漏洞

检查多个

  1. 命令执行

命令执行

  1. GetShell

getshell_1

getshell_2

  1. 批量检查单个版本漏洞

批量检查单个

  1. 批量检测多个版本漏洞

批量检查多个

免责声明

本工具仅能在取得足够合法授权的企业安全建设中使用,在使用本工具过程中,您应确保自己所有行为符合当地的法律法规。

如您在使用本工具的过程中存在任何非法行为,您将自行承担所有后果,本工具所有开发者和所有贡献者不承担任何法律及连带责任。

除非您已充分阅读、完全理解并接受本协议所有条款,否则,请您不要安装并使用本工具。

您的使用行为或者您以其他任何明示或者默示方式表示接受本协议的,即视为您已阅读并同意本协议的约束。

thinkphpgui's People

Contributors

ljn26 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

thinkphpgui's Issues

功能建议

设置代理
一键 getshell 显示详细数据包

thinkphp5.0.5RCE

thinkphp5.0.5RCE
Payload:_method=__construct&filter=system&method=get&get[]=whoami

您好,这个漏洞的发现您这个工具没有,一直在用您写的这个工具。

5.x 数据库信息泄露问题

[+] 存在ThinkPHP 5.x 数据库信息泄露
Payload: username: hostname: password: database:
你好,请问一下这个怎么利用,网上未搜到相关利用过程

闪退

配置了java环境,为啥还是闪退呀?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.