关联漏洞
描述
Vulnerability Scanner for CVE-2022-42889 (Text4Shell)
介绍
# Scanner for CVE-2022-42889 (Text4Shell)
## Description
This is a scanner for CVE-2022-42889 (Text4Shell) vulnerability
## Usage
### Step
1. Download jar file (jar file is on `preparedJar/text4shell-scanner.jar`)
2. Check java version on your system
3. Run jar file with args (refer to the following example)
### Sample command
```cmd
> java -jar text4shell-scanner.jar /Path/you/want/to/scan
```
Sample Result
```
Scanner for CVE-2022-42889
User Name : ian
OS Name : Mac OS X
Target paths : [/Users]
Exclude paths : [/.Trash, /Dropbox, /Library]
Critical! Found vulnerability(CVE-2022-42889)! Path : /Path/~~/org.apache.commons/commons-text/1.9/~~/commons-text-1.9.jar, Version : 1.9
Critical! Found vulnerability(CVE-2022-42889)! Path : /Path/~~/org.apache.commons/commons-text/1.9/~~/commons-text-1.9-sources.jar, Version : 1.9
### Result ###
Vulnerable Files are 2 exists
```
### Args
- `--charset`
- `--exclude-prefix`
- `--exclude-pattern`
- `--help`
## Environment
JDK - OpenJDK 11.0.12
## CheckList
- OS
- [x] Mac
- [x] Linux
- [ ] Windows(Not supported)
## License
MIT License
文件快照
[4.0K] /data/pocs/acefb1cc62b69535ce424630942e112629fec29a
├── [ 664] build.gradle
├── [ 138] Dockerfile
├── [4.0K] gradle
│ └── [4.0K] wrapper
│ ├── [ 59K] gradle-wrapper.jar
│ └── [ 202] gradle-wrapper.properties
├── [8.0K] gradlew
├── [2.8K] gradlew.bat
├── [1.1K] LICENSE
├── [4.0K] preparedJar
│ └── [1.1M] text4shell-scanner.jar
├── [1.1K] README.md
├── [ 32] settings.gradle
└── [4.0K] src
├── [4.0K] main
│ └── [4.0K] java
│ └── [4.0K] com
│ └── [4.0K] vulcheck
│ └── [4.0K] text4shell
│ ├── [4.0K] entity
│ │ ├── [ 766] Version.java
│ │ └── [ 252] VulState.java
│ ├── [4.0K] scanner
│ │ ├── [3.8K] Config.java
│ │ ├── [6.5K] Detector.java
│ │ └── [4.1K] Scanner.java
│ └── [4.0K] utils
│ ├── [ 596] CustomUtils.java
│ ├── [1.2K] DummyInputStream.java
│ └── [2.3K] ZipFileParser.java
└── [4.0K] test
└── [4.0K] java
└── [4.0K] com
└── [4.0K] vulcheck
└── [4.0K] text4shell
└── [ 405] Text4ShellScannerTests.java
17 directories, 19 files
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。