資源簡介
監控的腳本,看別人怎么攻擊你的 然后你抓到他的流量去攻擊別人
代碼片段和文件信息
#!/usr/bin/env?python
#?encoding:utf-8
import?sys
import?pyinotify
import?os
import?time
def?detect_waf(pathname):
????try:
????????with?open(pathname)?as?f:
????????????content?=?f.read()
????????????black_list?=?[““?“<%“]
????????????black_list?+=?[‘eval‘?‘assert‘]
????????????black_list?+=?[‘passthru‘?‘exec‘?‘system‘?‘shell_exec‘?‘popen‘?‘proc_open‘]
????????????black_list?+=?[‘hightlight_file‘?‘show_source‘?‘php_strip_whitespace‘?‘file_get_contents‘?‘readfile‘?‘file‘?‘fopen‘?‘fread‘?‘include‘?‘include_once‘?‘require‘?‘require_once‘?‘fread‘?‘fgets‘?‘fpassthru‘?‘fgetcsv‘?‘fgetss‘?‘fscanf‘?‘parse_ini_file‘]
????????????black_list?+=?[‘glob‘?‘opendir‘?‘dir‘?‘readdir‘?‘scandir‘]
????????????FLAG?=?False
????????????for?black?in?black_list:
????????????????if
評論
共有 條評論