-
Hi,
In the EvilPot system, it goes to sleep if it matches the `sleep` or `waitfor` function.
https://github.com/chaitin/xray/blob/e0e361a596566a996f0fb4558900e981f40bbf8f/tests/evilpot/evil/evil…
-
Due to below webscan finding:
We need to add below security header `Content-Security-Policy: default-src https: ; script-src blob: https: ;frame-ancestors 'self'; style-src https:`, but **s…
-
## 问题1:连接逻辑
Xray webscan listen模式启动时,若webhook端口还未开放或者 reverse的端口还未开放,则整个扫描过程中webhook和reverse功能都是失效的。
这样就严格要求了启动顺序,对于使用而言体验并不太好,建议可以改成定期检查,或者就算检查不通过,依然向webhook吐输出。
## 问题2:阻塞
当在Retry Reverse的Warni…
-
http://k8gege.org/p/c5430395.html
### 前言
Ladon 6.2支持Cobalt Strike 4.0,内置58个功能
加载脚本Ladon.cna,通过Beacon命令或右键使用
### 应用场景
CS命令行下扫描目标内网,无需代理转发扫描收集信息、密码爆破等
跳板扫描外网资产(即无需代理直接通过在控机器扫描其它目标资产)
### La…
-
xray发的包,headers里的“suffix”、“c1”、“c2”,最终没有写入jsp文件中;
xray发的包用burpsuit发,headers里的“suffix”、“c1”、“c2”,成功写入jsp文件中。
![image](https://user-images.githubusercontent.com/90889983/205299498-73ac2962-46a9-4a20-a…
-
![image](https://user-images.githubusercontent.com/55070619/177667088-ba26d28c-029f-4c9e-8a43-f05ce60d837b.png)
-
```
webscan ************.io
✓ Advanced scan of DNS complete.
✓ (4/4) Scan of IPs complete.
✓ (132/132) Scan of open ports completed.
✓ (4/4) Scan of enabled tls versions completed.
…
-
My webstie has the Cross-Origin Embedder Policy (COEP) enable, so it block iframe. i can' using streamsaver. is there any way to solve this problem?
-
用xray爬虫扫描spring应用的漏洞是发现,没有带上原始的Accept头,导致页面类型显示错误,无法判断出漏洞
`xray webscan --plugins cmd-injection,sqldet --browser-crawler http://127.0.0.1:8090/springboot-spel-rce/`
爬虫到的原始请求是
```
GE…
-
In [`44025e0`](https://github.com/blaineam/statussi/commit/44025e0f10f08cddbf8e83d1ee66982c0fdf0f01
), Miller WebScan (https://webscan.wemiller.com) was **down**:
- HTTP code: 530
- Response time: 78 …