|
11 | 11 |
|
12 | 12 | version: 2.1 |
13 | 13 | plugins: |
| 14 | + max_parallel: 10 |
14 | 15 | xss: |
15 | 16 | enabled: true |
16 | 17 | ie_feature: false |
@@ -58,86 +59,7 @@ plugins: |
58 | 59 | phantasm: |
59 | 60 | enabled: true |
60 | 61 | depth: 1 |
61 | | - poc: |
62 | | - - poc-yaml-activemq-cve-2016-3088 |
63 | | - - poc-yaml-bash-cve-2014-6271 |
64 | | - - poc-yaml-cacti-weathermap-file-write |
65 | | - - poc-yaml-coldfusion-cve-2010-2861-lfi |
66 | | - - poc-yaml-confluence-cve-2015-8399 |
67 | | - - poc-yaml-confluence-cve-2019-3396-lfi |
68 | | - - poc-yaml-coremail-cnvd-2019-16798 |
69 | | - - poc-yaml-couchdb-cve-2017-12635 |
70 | | - - poc-yaml-couchdb-unauth |
71 | | - - poc-yaml-dedecms-url-redirection |
72 | | - - poc-yaml-discuz-wooyun-2010-080723 |
73 | | - - poc-yaml-discuz-v72-sqli |
74 | | - - poc-yaml-discuz-wechat-plugins-unauth |
75 | | - - poc-yaml-dlink-850l-info-leak |
76 | | - - poc-yaml-dlink-cve-2019-16920-rce |
77 | | - - poc-yaml-docker-api-unauthorized-rce |
78 | | - - poc-yaml-docker-registry-api-unauth |
79 | | - - poc-yaml-drupal-drupalgeddon2-rce |
80 | | - - poc-yaml-drupalgeddon-cve-2014-3704-sqli |
81 | | - - poc-yaml-ecology-javabeanshell-rce |
82 | | - - poc-yaml-ecology-workflowcentertreedata-sqli |
83 | | - - poc-yaml-ecshop-360-rce |
84 | | - - poc-yaml-elasticsearch-cve-2015-1427 |
85 | | - - poc-yaml-elasticsearch-unauth |
86 | | - - poc-yaml-etouch-v2-sqli |
87 | | - - poc-yaml-finereport-directory-traversal |
88 | | - - poc-yaml-glassfish-cve-2010-2861-lfi |
89 | | - - poc-yaml-hadoop-yarn-unauth |
90 | | - - poc-yaml-ifw8-router-cve-2019-16313 |
91 | | - - poc-yaml-influxdb-unauth |
92 | | - - poc-yaml-jboss-unauth |
93 | | - - poc-yaml-jenkins-cve-2018-1000861-rce |
94 | | - - poc-yaml-joomla-cve-2015-7297-sqli |
95 | | - - poc-yaml-joomla-cve-2017-8917-sqli |
96 | | - - poc-yaml-joomla-ext-zhbaidumap-cve-2018-6605-sqli |
97 | | - - poc-yaml-maccmsv10-backdoor |
98 | | - - poc-yaml-metinfo-cve-2019-16996-sqli |
99 | | - - poc-yaml-metinfo-cve-2019-16997-sqli |
100 | | - - poc-yaml-metinfo-cve-2019-17418-sqli |
101 | | - - poc-yaml-metinfo-lfi-cnvd-2018-13393 |
102 | | - - poc-yaml-nextjs-cve-2017-16877 |
103 | | - - poc-yaml-nhttpd-cve-2019-16278 |
104 | | - - poc-yaml-nuuo-file-inclusion |
105 | | - - poc-yaml-php-cgi-cve-2012-1823 |
106 | | - - poc-yaml-phpmyadmin-cve-2018-12613-file-inclusion |
107 | | - - poc-yaml-phpmyadmin-setup-deserialization |
108 | | - - poc-yaml-phpstudy-backdoor-rce |
109 | | - - poc-yaml-phpunit-cve-2017-9841-rce |
110 | | - - poc-yaml-joomla-cnvd-2019-34135-rce |
111 | | - - poc-yaml-springcloud-cve-2019-3799 |
112 | | - - poc-yaml-tomcat-cve-2018-11759 |
113 | | - - poc-yaml-pulse-cve-2019-11510 |
114 | | - - poc-yaml-rails-cve-2018-3760-rce |
115 | | - - poc-yaml-resin-cnnvd-200705-315 |
116 | | - - poc-yaml-resin-inputfile-fileread-or-ssrf |
117 | | - - poc-yaml-resin-viewfile-fileread |
118 | | - - poc-yaml-seacms-v654-rce |
119 | | - - poc-yaml-apache-solr-cve-2017-12629-xxe |
120 | | - - poc-yaml-solr-cve-2019-0193 |
121 | | - - poc-yaml-supervisord-cve-2017-11610 |
122 | | - - poc-yaml-tensorboard-unauth |
123 | | - - poc-yaml-thinkphp5-controller-rce |
124 | | - - poc-yaml-thinkphp5023-method-rce |
125 | | - - poc-yaml-tomcat-cve-2017-12615-rce |
126 | | - - poc-yaml-uwsgi-cve-2018-7490 |
127 | | - - poc-yaml-vbulletin-cve-2019-16759 |
128 | | - - poc-yaml-weblogic-cve-2017-10271-reverse |
129 | | - - poc-yaml-weblogic-cve-2019-2729-1 |
130 | | - - poc-yaml-weblogic-cve-2019-2729-2 |
131 | | - - poc-yaml-weblogic-ssrf |
132 | | - - poc-yaml-weblogic-cve-2017-10271 |
133 | | - - poc-yaml-weblogic-cve-2019-2725 |
134 | | - - poc-yaml-webmin-cve-2019-15107-rce |
135 | | - - poc-yaml-wuzhicms-v410-sqli |
136 | | - - poc-yaml-yungoucms-sqli |
137 | | - - poc-yaml-zabbix-authentication-bypass |
138 | | - - poc-yaml-zabbix-cve-2016-10134-sqli |
139 | | - - poc-yaml-zimbra-cve-2019-9670-xxe |
140 | | - - poc-go-tomcat-put |
| 62 | + poc: [] |
141 | 63 |
|
142 | 64 | log: |
143 | 65 | level: info # 支持 debug, info, warn, error, fatal |
@@ -221,4 +143,18 @@ http: |
221 | 143 | - PROPFIND |
222 | 144 | - MOVE |
223 | 145 | tls_skip_verify: true # 是否验证目标网站的 https 证书。 |
| 146 | + |
| 147 | +subdomain: |
| 148 | + modes: # 使用哪些方式获取子域名 |
| 149 | + - brute # 字典爆破模式 |
| 150 | + - api # 使用各大 api 获取 |
| 151 | + - zone_transfer # 尝试使用域传送漏洞获取 |
| 152 | + worker_count: 100 # 决定同时允许多少个 DNS 查询 |
| 153 | + dns_servers: # 查询使用的 DNS server |
| 154 | + - 1.1.1.1 |
| 155 | + - 8.8.8.8 |
| 156 | + allow_recursive: false # 是否允许递归扫描,开了后如果发现 a.example.com 将继续扫描 a.example.com 的子域名 |
| 157 | + max_depth: 5 # 最大允许的子域名深度 |
| 158 | + main_dictionary: "" # 一级子域名字典, 绝对路径 |
| 159 | + sub_dictionary: "" # 其它层级子域名字典, 绝对路径 |
224 | 160 | ``` |
0 commit comments