Compare commits
10 Commits
8437465f1b
...
ff1c4d8720
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ff1c4d8720 | ||
|
|
6fadf24cca | ||
|
|
723c15baa3 | ||
|
|
9b923400de | ||
|
|
aaa48dc29e | ||
|
|
06dae382f0 | ||
|
|
09d752d237 | ||
|
|
2632cb1cc1 | ||
|
|
752e038dbb | ||
|
|
110c3738f6 |
21
README.md
21
README.md
@@ -1,21 +1,31 @@
|
||||
# Superset_auth_bypass_check
|
||||
Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具
|
||||
|
||||
**本工具仅用于教育和研究目的,以提高安全意识和改进软件开发实践。在使用本工具之前,请确保您遵守了相关法律法规和道德准则。**
|
||||
---
|
||||
|
||||
修复时间:2023.8.3
|
||||
* 修复由于硬编码session时间过期导致的session失效,引用<a href="https://github.com/noraj/flask-session-cookie-manager">flask_session_cookie_manager</a>工具生成实时session进行检测。
|
||||
* 修复由于未禁用重定向导致跳转/login/匹配状态码为200的bug
|
||||
|
||||
感谢nplookges师傅的反馈
|
||||
|
||||
---
|
||||
|
||||
开发环境:
|
||||
python3
|
||||
|
||||
**避免python环境命名导致运行失败,可将python运行程序改为python3添加到环境变量中**
|
||||
|
||||
```python
|
||||
使用方式(支持单个URL检测和批量检测)://url做了合规处理,支持输入ip、ip:port样式
|
||||
|
||||
单个检测:python superset_auth_bypass_check.py -u
|
||||
单个检测:python3 superset_auth_bypass_check.py -u
|
||||
|
||||
示例:python superset_auth_bypass_check.py -u http://192.168.1.1/
|
||||
示例:python3 superset_auth_bypass_check.py -u http://192.168.1.1/
|
||||
|
||||
批量检测:python superset_auth_bypass_check.py -f
|
||||
批量检测:python3 superset_auth_bypass_check.py -f
|
||||
|
||||
示例:python superset_auth_bypass_check.py -f url.txt
|
||||
示例:python3 superset_auth_bypass_check.py -f url.txt
|
||||
|
||||
```
|
||||
|
||||
@@ -27,6 +37,7 @@ python3
|
||||
批量检测:
|
||||

|
||||
|
||||
---
|
||||
|
||||
**免责声明**
|
||||
|
||||
|
||||
@@ -88,9 +88,11 @@ def main():
|
||||
for thread in threads_queue:
|
||||
thread.join()
|
||||
|
||||
print("\n存在漏洞列表:")
|
||||
for url in vulurl:
|
||||
print(url+" [+]漏洞存在!!!")
|
||||
if vulurl:
|
||||
print("\n存在漏洞列表:")
|
||||
for url in vulurl:
|
||||
print(url+" [+]漏洞存在!!!")
|
||||
print("\ncookie: session="+sessionout)
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
|
||||
Reference in New Issue
Block a user