yhy0 / Jie

Jie stands out as a comprehensive security assessment and exploitation tool meticulously crafted for web applications. Its robust suite of features encompasses vulnerability scanning, information gathering, and exploitation, elevating it to an indispensable toolkit for both security professionals and penetration testers. 挖洞辅助工具(漏洞扫描、信息收集)
https://jie.fireline.fun/
GNU Affero General Public License v3.0
563 stars 116 forks source link

老哥,你xss的js语义分析的地方有点问题 #2

Closed sairson closed 1 year ago

sairson commented 1 year ago

image 这点你是不是还没写完😂,glint项目中的html语法树有点问题(我已经给提issues了),多层的节点,它解析不出来,其次glint中的语法树部分不会生成BlockComment这些,w13scan和glint结合的话需要对这一部分改改

yhy0 commented 1 year ago

感谢,我瞅瞅看看怎么写,刚学

sairson commented 1 year ago

glint中的Byte2Str存在内存覆盖问题,在解析html语法树的时候,建议使用string函数,虽然效率会慢,但是不会出现转换问题,可以注意一下

yhy0 commented 1 year ago

感谢,大佬太强了