ice-doom / EyeJo

EyeJo是一款自动化资产风险评估平台,可以协助甲方安全人员或乙方安全人员对授权的资产中进行排查,快速发现存在的薄弱点和攻击面。
454 stars 80 forks source link

关于新任务域名的问题 #10

Closed aguai778 closed 3 years ago

aguai778 commented 3 years ago

为什么需要加http前缀? 另外如果一次执行过多域名 shodan&fofa 会很慢,我等待了10个小时左右还在执行shodan&fofa,大约900子域名

ice-doom commented 3 years ago

由于是支持带上路径的url,如果不必须带上http前缀,如http://a.a.a.a/?src=http://b.b.b.b&cmd=1这种会导致获取的url产生错误。 目前shodan和fofa是循环查询api获取数据,没有并发去查询。 可以进去容器查看下日志,目前是什么原因卡在这里,docker exec -it eyejo_worker tail -50 celery.log

aguai778 commented 3 years ago

09:59:59,751 [ALERT] utils:272 - GET https://freeapi.robtex.com/pdns/reverse/184.30.162.93 429 - Too Many Requests 24

09:59:59,751 [ALERT] utils:281 - {'status': 'ratelimited'}

aguai778 commented 3 years ago

09:59:18,176 [INFOR] brute:496 - Finished Brute module to brute lenovo.com.cn

09:59:18,186 [ERROR] database:40 - ('This result object does not return rows. It has been closed automatically.',)

09:59:18,199 [ERROR] database:40 - ('This result object does not return rows. It has been closed automatically.',)

ice-doom commented 3 years ago

可以截图解全点,打码去掉敏感信息,这么看,看不出来