SSI-Scan [SSI injection scanner]

poqun

Carder
Carder
Joined
11 yrs. 7 mth. 14 days
Messages
2,772
Reaction score
2,095
Wallet
0$
SSI-Scan is a basic PoC tool that helps facilitate the discovery of SSI injection vulnerabilities, a fairly rare and underdocumented code injection vulnerability where Server Side Includes directives are executed without proper validation and may lead to a system compromise or complete server enumeration.

At this point, SSI-Scan tests for injection by sending a POST request encapsulated with a hardcoded payload or through injecting forms specified by the user with a payload and looking for environment variable matches in the page source.

SSI-Scan requires BeautifulSoup4 and mechanize.

Example usage:
Code:
Please, Log in or Register to view codes content!

For more information on SSI injection:
Please, Log in or Register to view URLs content!

Please, Log in or Register to view URLs content!


SSI-Scan will be receiving more updates to its functionality.

TnX && Credit: fnordbg

Download
Please, Log in or Register to view URLs content!
 
Paid adv. expire in 2 months
CLICK to buy Advertisement !
westernunion carding Verified & Trusted WesternUnion | MoneyGram | Bank - Transferring [299$ BTC for 2000$ WU]
electronics carding Verified & Trusted Electronics Carding, Carding iPhone, Samsung Carding, MacBook Carding, Laptops Carding
Top Bottom