參考:https://github.com/sethsec/PyCodeInjection
PyCodeInjection項(xiàng)目包含兩個(gè)主要組件:
PyCodeInjectionShell - 一種利用基于Web應(yīng)用程序的Python代碼注入的工具
PyCodeInjectionApp - 一種易受Python代碼注入攻擊的Web應(yīng)用程序
安裝:
git clone https://github.com/sethsec/PyCodeInjection.git /opt/PythonCodeInjection
cd /opt/PythonCodeInjection/VulnApp
./install_requirements.sh
使用案例:
root@playground:/opt/PyCodeInjection/VulnApp# python PyCodeInjectionApp.py
http://0.0.0.0:8080/
192.168.81.1:12637 - - [02/Nov/2016 22:02:28] "HTTP/1.1 POST /pyinject" - 200 OK
192.168.81.1:12639 - - [02/Nov/2016 22:02:37] "HTTP/1.1 POST /pyinject" - 200 OK
192.168.81.1:12640 - - [02/Nov/2016 22:02:38] "HTTP/1.1 POST /pyinject" - 200 OK
192.168.81.1:12641 - - [02/Nov/2016 22:02:39] "HTTP/1.1 POST /pyinject" - 200 OK
192.168.81.1:12642 - - [02/Nov/2016 22:02:39] "HTTP/1.1 POST /pyinject" - 200 OK