Skip to content
This repository has been archived by the owner on Apr 7, 2023. It is now read-only.

扫描插件误报 #10

Open
MagicZer0 opened this issue May 24, 2019 · 0 comments
Open

扫描插件误报 #10

MagicZer0 opened this issue May 24, 2019 · 0 comments

Comments

@MagicZer0
Copy link

插件位置:
scanner/plugins/cms/zfsoft/zfsoft_database_control.py

该漏洞检测插件判断原理是拆分用户提交的主机和端口,然后socket直接连接,连接成功就认为存在该漏洞。这是绝对不严谨的。比如127.0.0.1:8080开着就存在这个漏洞。

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant