Closed 0xPugal closed 10 months ago
Have you tried increasing delay for blind injection detection?
Have you tried increasing delay for blind injection detection?
For blind injection, instead of time delay, I suggest do more step such as perform curl/wget/ping to Attacker. How does that sound?
@alasalamont These solutions require a lot of conditions to be met in order to succeed. Attacker must be accessible from the internet on some custom port and the target must be able to create connections as well as have the required tool installed. This is fine for advanced exploitation (reverse shell or OOB exfiltration), but not for initial detection.
A better solution would be making more tests with increased delay after the initial detection in order to verify the vulnerability.
Should be fixed in 1.2.0 Can you verify?
Closing for now, as the fix was provided in 1.2.0, but no confirmation was given
1st time
python3 sstimap.py -u https://target.com/path?country=mc
2nd time
python3 sstimap.py -u https://target.com/path?country=mc --os-shell