google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

add Apache ActiveMQ RCE CVE-2023-46604 Detector #370

Open hh-hunter opened 5 months ago

hh-hunter commented 5 months ago

@tooryx ,hi this is issue #364 merge pull request,please check this.

hh-hunter commented 5 months ago

The range environment is in https://github.com/google/security-testbeds/pull/17

hh-hunter commented 5 months ago

@tooryx Please review

hh-hunter commented 1 month ago

@lokiuox I have finished the repair, please check it.

hh-hunter commented 1 month ago

I've finished modifying the problem you mentioned (including the oobSleep part),and I've used google-java-format to format the code,for the payload generation part I have not modified, because I see the situation is not included http protocol, if you are sure to include, I can also change to remove the manual addition of the protocol section, please review it! @lokiuox

hh-hunter commented 1 month ago

@lokiuox All problems have been fixed, please review it again

hh-hunter commented 1 month ago

Regarding the bonus of the last plug-in, there has been no progress from January to now. Can you tell me what's going on? https://issuetracker.google.com/issues/319331887 @lokiuox @tooryx

lokiuox commented 1 month ago

Regarding the bonus of the last plug-in, there has been no progress from January to now. Can you tell me what's going on? https://issuetracker.google.com/issues/319331887 @lokiuox @tooryx

Hey @hh-hunter, I work for Doyensec and we're helping with plugin reviews, but we're not part of the Tsunami team, so I cannot help you with that or even see the ticket, sorry.

hh-hunter commented 3 weeks ago

@lokiuox please review.