Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add xxl job rce and Optimize shiro detection script #128

Merged
merged 6 commits into from
Oct 9, 2023

Conversation

QdghJ
Copy link
Contributor

@QdghJ QdghJ commented Oct 7, 2023

add xxl job rce and Optimize shiro detection script

refer:
https://github.com/vulhub/vulhub/blob/master/xxl-job/unacc/README.md

Copy link
Collaborator

@PortSwiggerWiener PortSwiggerWiener left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the new BCheck and also improving the others!

The new one looks very interesting, but I wonder if it would be better as a per host check (given host) rather than a per request check? Currently this will issue a request to /run per audit item.

@QdghJ
Copy link
Contributor Author

QdghJ commented Oct 9, 2023

Thanks for your correction, it would be better to send requests to each host

change to give host
Copy link
Contributor Author

@QdghJ QdghJ left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Modified to send one request per host

Copy link
Collaborator

@PortSwiggerWiener PortSwiggerWiener left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for making the update. Looks good 👍

@PortSwiggerWiener PortSwiggerWiener merged commit b8df51f into PortSwigger:main Oct 9, 2023
@michael-eaton-portswigger

@QdghJ As a contributor to our GitHub repository, we would like to invite you to our closed Discord community.

It is a place where passionate Burp users, including people who directly work on building and developing Burp here at PortSwigger, can talk about the tooling and web security in general.

If you would like to join, please email us at [email protected] and we will send over an invite link.

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

4 participants