tr0uble-mAker / POC-bomber

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点
GNU General Public License v3.0
2.24k stars 375 forks source link

为什么工具中requests.post发出的http版本为1.0呢? #13

Open zy696 opened 2 years ago

zy696 commented 2 years ago

BP捕获的数据包中http协议版本为1.0,没有host头,导致在漏洞探测时,回显404,加上host头正常。大家有遇到这种问题吗?怎么把HTTP版本设置为1.1呢? POST / HTTP/1.0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0 Accept-Encoding: gzip, deflate Accept: / Connection: close

tr0uble-mAker commented 2 years ago

已修复