补全JS匹配正则,并修复JS匹配URL路径丢失的问题#20
Merged
lemonlove7 merged 1 commit intolemonlove7:mainfrom Jan 27, 2024
mewhz:main
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
使用 fofa 搜索 app="用友-U8CRM"





正常访问时:http://ip/login/login.php
使用完整路径运行 ehole_magic 可以正常识别出指纹
仅使用:http://ip 无法识别出指纹
查看请求包发现请求中的 JavaScript 未出现在正则中,于是在 jsjump.go 的 20 - 27 行中添加新正则,并添加等号两边无空格正则
后发现原本 finger/finger.go 中拼接路径后,会覆盖原本的 data 变量,在 finger/finger.go 的 1588 - 1598 行中,把 data.jsurl 放入队列中。
修改后再次运行