al0ne / Vxscan

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。
Apache License 2.0
1.74k stars 441 forks source link

继续来提BUG 7-1号的代码 #11

Closed strengthen8 closed 5 years ago

strengthen8 commented 5 years ago

202.101.164.75 is not alive

124.160.116.204 is not alive

PortScan: [+] http:80 [+] http:443

Vuln: [+] https://tj.dianping.com | 页面不存在 | 美团点评 OS: [+] None

running 82.314 seconds... root@qiang-year:~/Vxscan# ls db error.log hosts.txt lib LICENSE logo2.jpg logo.jpg README.md README.zh-CN.md report requirements.txt script Vxscan.py root@qiang-year:~/Vxscan# tail -500f error.log 2019-07-01 13:01:00,873 - /usr/lib/python3/dist-packages/urllib3/connection.py[line:360] - ERROR: Certificate did not match expected hostname: tj.dianping.com. Certificate: {'subject': ((('organizationalUnitName', 'Domain Control Validated'),), (('commonName', '.sankuai.com'),)), 'issuer': ((('countryName', 'US'),), (('stateOrProvinceName', 'Arizona'),), (('localityName', 'Scottsdale'),), (('organizationName', 'GoDaddy.com, Inc.'),), (('organizationalUnitName', 'http://certs.godaddy.com/repository/'),), (('commonName', 'Go Daddy Secure Certificate Authority - G2'),)), 'version': 3, 'serialNumber': '9292B75E6D7D9B3A', 'notBefore': 'Jun 18 03:12:13 2019 GMT', 'notAfter': 'Jul 11 02:56:01 2020 GMT', 'subjectAltName': (('DNS', '.sankuai.com'), ('DNS', 'sankuai.com')), 'OCSP': ('http://ocsp.godaddy.com/',), 'caIssuers': ('http://certificates.godaddy.com/repository/gdig2.crt',), 'crlDistributionPoints': ('http://crl.godaddy.com/gdig2s1-1180.crl',)} 2019-07-01 13:01:00,975 - /usr/lib/python3/dist-packages/urllib3/connection.py[line:360] - ERROR: Certificate did not match expected hostname: tj.dianping.com. Certificate: {'subject': ((('organizationalUnitName', 'Domain Control Validated'),), (('commonName', '.sankuai.com'),)), 'issuer': ((('countryName', 'US'),), (('stateOrProvinceName', 'Arizona'),), (('localityName', 'Scottsdale'),), (('organizationName', 'GoDaddy.com, Inc.'),), (('organizationalUnitName', 'http://certs.godaddy.com/repository/'),), (('commonName', 'Go Daddy Secure Certificate Authority - G2'),)), 'version': 3, 'serialNumber': '9292B75E6D7D9B3A', 'notBefore': 'Jun 18 03:12:13 2019 GMT', 'notAfter': 'Jul 11 02:56:01 2020 GMT', 'subjectAltName': (('DNS', '.sankuai.com'), ('DNS', 'sankuai.com')), 'OCSP': ('http://ocsp.godaddy.com/',), 'caIssuers': ('http://certificates.godaddy.com/repository/gdig2.crt',), 'crlDistributionPoints': ('http://crl.godaddy.com/gdig2s1-1180.crl',)} 2019-07-01 13:01:00,978 - /usr/lib/python3/dist-packages/urllib3/connection.py[line:360] - ERROR: Certificate did not match expected hostname: tj.dianping.com. Certificate: {'subject': ((('organizationalUnitName', 'Domain Control Validated'),), (('commonName', '.sankuai.com'),)), 'issuer': ((('countryName', 'US'),), (('stateOrProvinceName', 'Arizona'),), (('localityName', 'Scottsdale'),), (('organizationName', 'GoDaddy.com, Inc.'),), (('organizationalUnitName', 'http://certs.godaddy.com/repository/'),), (('commonName', 'Go Daddy Secure Certificate Authority - G2'),)), 'version': 3, 'serialNumber': '9292B75E6D7D9B3A', 'notBefore': 'Jun 18 03:12:13 2019 GMT', 'notAfter': 'Jul 11 02:56:01 2020 GMT', 'subjectAltName': (('DNS', '.sankuai.com'), ('DNS', 'sankuai.com')), 'OCSP': ('http://ocsp.godaddy.com/',), 'caIssuers': ('http://certificates.godaddy.com/repository/gdig2.crt',), 'crlDistributionPoints': ('http://crl.godaddy.com/gdig2s1-1180.crl',)} 2019-07-01 13:01:01,213 - /usr/lib/python3/dist-packages/urllib3/connection.py[line:360] - ERROR: Certificate did not match expected hostname: tj.dianping.com. Certificate: {'subject': ((('organizationalUnitName', 'Domain Control Validated'),), (('commonName', '.sankuai.com'),)), 'issuer': ((('countryName', 'US'),), (('stateOrProvinceName', 'Arizona'),), (('localityName', 'Scottsdale'),), (('organizationName', 'GoDaddy.com, Inc.'),), (('organizationalUnitName', 'http://certs.godaddy.com/repository/'),), (('commonName', 'Go Daddy Secure Certificate Authority - G2'),)), 'version': 3, 'serialNumber': '9292B75E6D7D9B3A', 'notBefore': 'Jun 18 03:12:13 2019 GMT', 'notAfter': 'Jul 11 02:56:01 2020 GMT', 'subjectAltName': (('DNS', '.sankuai.com'), ('DNS', 'sankuai.com')), 'OCSP': ('http://ocsp.godaddy.com/',), 'caIssuers': ('http://certificates.godaddy.com/repository/gdig2.crt',), 'crlDistributionPoints': ('http://crl.godaddy.com/gdig2s1-1180.crl',)} 2019-07-01 13:01:02,768 - /usr/lib/python3/dist-packages/urllib3/connection.py[line:360] - ERROR: Certificate did not match expected hostname: tj.dianping.com. Certificate: {'subject': ((('organizationalUnitName', 'Domain Control Validated'),), (('commonName', '.sankuai.com'),)), 'issuer': ((('countryName', 'US'),), (('stateOrProvinceName', 'Arizona'),), (('localityName', 'Scottsdale'),), (('organizationName', 'GoDaddy.com, Inc.'),), (('organizationalUnitName', 'http://certs.godaddy.com/repository/'),), (('commonName', 'Go Daddy Secure Certificate Authority - G2'),)), 'version': 3, 'serialNumber': '9292B75E6D7D9B3A', 'notBefore': 'Jun 18 03:12:13 2019 GMT', 'notAfter': 'Jul 11 02:56:01 2020 GMT', 'subjectAltName': (('DNS', '.sankuai.com'), ('DNS', 'sankuai.com')), 'OCSP': ('http://ocsp.godaddy.com/',), 'caIssuers': ('http://certificates.godaddy.com/repository/gdig2.crt',), 'crlDistributionPoints': ('http://crl.godaddy.com/gdig2s1-1180.crl',)} 2019-07-01 13:01:29,696 - Vxscan.py[line:338] - ERROR: local variable 'address' referenced before assignment Traceback (most recent call last): File "Vxscan.py", line 324, in pool name, wafresult = start(host) File "/root/Vxscan/lib/common.py", line 213, in start 'Address': address, UnboundLocalError: local variable 'address' referenced before assignment