2017-10-16 13:50:49 +08:00
|
|
|
|
# VulApps [http://vulapps.evalbug.com/](http://vulapps.evalbug.com/)
|
2016-06-16 16:18:17 +08:00
|
|
|
|
|
2016-12-24 14:21:47 +08:00
|
|
|
|
收集各种漏洞环境,为方便使用,统一采用 Dockerfile 形式。同时也收集了安全工具环境。
|
2016-06-16 16:18:17 +08:00
|
|
|
|
|
2016-06-16 19:30:19 +08:00
|
|
|
|
> 喜欢请点 Star,如果不打算贡献,千万别 Fork
|
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
本项目 GitHub 地址: [https://github.com/Medicean/VulApps](https://github.com/Medicean/VulApps)
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-06-18 11:57:07 +08:00
|
|
|
|
[DockerHub 在线镜像地址](https://hub.docker.com/r/medicean/vulapps/)
|
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
## 获取并使用相关镜像
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-12-24 14:21:47 +08:00
|
|
|
|
> 直接使用 docker 命令拉取相关镜像,并启动。
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-12-24 14:21:47 +08:00
|
|
|
|
**需要查看相关环境的 tag 在Github具体的漏洞目录下查看 README 文件**
|
|
|
|
|
|
|
|
|
|
### 以 Struts2 S2-037 漏洞环境为例:
|
|
|
|
|
|
|
|
|
|
通过 S2-037漏洞环境的 [README文件](./s/struts2/s2-037/README.md) 得知 tag 为 `s_struts2_s2-037`
|
2016-06-18 00:18:49 +08:00
|
|
|
|
|
|
|
|
|
1. 获取镜像:
|
|
|
|
|
|
|
|
|
|
```
|
2016-06-16 19:30:19 +08:00
|
|
|
|
docker pull medicean/vulapps:s_struts2_s2-037
|
2016-06-18 00:18:49 +08:00
|
|
|
|
```
|
|
|
|
|
|
2017-01-12 21:50:33 +08:00
|
|
|
|
> 如果获取速度慢,推荐使用 [中科大 Docker Mirrors](https://lug.ustc.edu.cn/wiki/mirrors/help/docker) 或者使用 [阿里云 Mirrors(加速器)](https://cr.console.aliyun.com/#/accelerator)
|
2016-06-18 11:57:07 +08:00
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
2. 创建并启动容器
|
|
|
|
|
|
|
|
|
|
```
|
|
|
|
|
docker run -d -p 80:8080 medicean/vulapps:s_struts2_s2-037
|
|
|
|
|
```
|
|
|
|
|
|
2016-12-24 14:21:47 +08:00
|
|
|
|
访问 `http://127.0.0.1/` 即可访问启动好的 s2-037 环境,快拿出 exp 工具尝试一下吧。
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
|
|
|
|
## 组件首字母
|
|
|
|
|
|
2016-06-30 02:35:30 +08:00
|
|
|
|
* [B](#b)
|
2016-09-08 16:48:51 +08:00
|
|
|
|
* [C](#c)
|
2017-06-29 22:32:22 +08:00
|
|
|
|
* [D](#d)
|
2017-06-28 22:15:32 +08:00
|
|
|
|
* [F](#f)
|
2016-08-25 14:34:45 +08:00
|
|
|
|
* [I](#i)
|
2016-10-05 19:20:39 +08:00
|
|
|
|
* [J](#j)
|
2017-03-10 00:15:07 +08:00
|
|
|
|
* [M](#m)
|
2016-12-16 21:21:32 +08:00
|
|
|
|
* [N](#n)
|
2016-07-02 00:40:26 +08:00
|
|
|
|
* [O](#o)
|
2017-05-08 01:42:24 +08:00
|
|
|
|
* [P](#p)
|
2016-10-28 15:25:08 +08:00
|
|
|
|
* [R](#r)
|
2016-06-16 19:30:19 +08:00
|
|
|
|
* [S](#s)
|
2017-09-21 00:47:08 +08:00
|
|
|
|
* [T](#t)
|
2016-08-14 12:45:21 +08:00
|
|
|
|
* [W](#w)
|
2016-08-18 15:50:33 +08:00
|
|
|
|
* [Z](#z)
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-12-24 14:21:47 +08:00
|
|
|
|
## 安全工具环境
|
|
|
|
|
|
2017-02-14 21:46:26 +08:00
|
|
|
|
* [巡风](./tools/xunfeng/)
|
2017-02-16 10:25:03 +08:00
|
|
|
|
* [Ant(蚁逅)](./tools/ant/)
|
2017-07-18 12:19:34 +08:00
|
|
|
|
* [Hawkeye](./tools/hawkeye)
|
2016-12-24 14:21:47 +08:00
|
|
|
|
|
2016-06-16 19:30:19 +08:00
|
|
|
|
## 漏洞环境
|
|
|
|
|
|
2016-06-30 02:35:30 +08:00
|
|
|
|
### [B](./b/)<div id="b"></div>
|
|
|
|
|
|
2016-06-30 03:23:01 +08:00
|
|
|
|
* [Bash](./b/bash/)
|
2016-06-30 02:35:30 +08:00
|
|
|
|
|
2016-09-08 16:48:51 +08:00
|
|
|
|
### [C](./c/)<div id="c"></div>
|
|
|
|
|
|
|
|
|
|
* [Cisco](./c/cisco/)
|
2016-12-14 11:54:08 +08:00
|
|
|
|
* [CmsEasy](./c/cmseasy/)
|
2016-09-08 16:48:51 +08:00
|
|
|
|
|
2017-06-29 22:32:22 +08:00
|
|
|
|
### [D](./d/)<div id="d"></div>
|
|
|
|
|
|
|
|
|
|
* [Drupal](./d/drupal/)
|
|
|
|
|
|
2017-06-28 22:15:32 +08:00
|
|
|
|
### [F](./f/)<div id="f"></div>
|
|
|
|
|
|
|
|
|
|
* [FFmpeg](./i/ffmpeg/)
|
|
|
|
|
|
2018-06-01 16:24:53 +08:00
|
|
|
|
### [G](./g/)<div id="g"></div>
|
|
|
|
|
|
|
|
|
|
* [Git](./g/git/)
|
|
|
|
|
|
2016-08-25 14:34:45 +08:00
|
|
|
|
### [I](./i/)<div id="i"></div>
|
|
|
|
|
|
|
|
|
|
* [ImageMagick](./i/imagemagick/)
|
|
|
|
|
|
2016-10-05 19:20:39 +08:00
|
|
|
|
### [J](./j/)<div id="j"></div>
|
|
|
|
|
|
2017-09-12 11:20:39 +08:00
|
|
|
|
* [JBoss](./j/jboss/)
|
2016-10-05 19:20:39 +08:00
|
|
|
|
* [Jenkins](./j/jenkins/)
|
2016-10-31 00:58:50 +08:00
|
|
|
|
* [Joomla!](./j/joomla/)
|
2016-10-05 19:20:39 +08:00
|
|
|
|
|
2017-03-10 00:15:07 +08:00
|
|
|
|
### [M](./m/)<div id="m"></div>
|
2016-12-16 21:21:32 +08:00
|
|
|
|
|
2017-03-10 00:15:07 +08:00
|
|
|
|
* [Memcached](./m/memcached/)
|
|
|
|
|
|
|
|
|
|
### [N](./n/)<div id="n"></div>
|
|
|
|
|
|
|
|
|
|
* [Nagios](./n/nagios/)
|
|
|
|
|
* [Node.js](./n/nodejs/)
|
2017-07-14 11:03:29 +08:00
|
|
|
|
* [Nginx](./n/nginx/)
|
2016-12-16 21:21:32 +08:00
|
|
|
|
|
2016-07-02 00:40:26 +08:00
|
|
|
|
### [O](./o/)<div id="o"></div>
|
|
|
|
|
|
|
|
|
|
* [OpenSSL](./o/openssl/)
|
|
|
|
|
|
2017-05-08 01:42:24 +08:00
|
|
|
|
### [P](./p/)<div id="p"></div>
|
|
|
|
|
|
|
|
|
|
* [PHPMailer](./p/phpmailer/)
|
|
|
|
|
|
2016-10-28 15:25:08 +08:00
|
|
|
|
### [R](./r/)<div id="r"></div>
|
|
|
|
|
|
|
|
|
|
* [Redis](./r/redis/)
|
|
|
|
|
|
2016-06-16 19:30:19 +08:00
|
|
|
|
### [S](./s/)<div id="s"></div>
|
2016-06-16 16:18:17 +08:00
|
|
|
|
|
2017-05-25 13:29:51 +08:00
|
|
|
|
* [Samba](./s/samba/)
|
2017-01-10 16:46:40 +08:00
|
|
|
|
* [Shiro](./s/shiro/)
|
2017-08-13 02:54:47 +08:00
|
|
|
|
* [SSH](./s/ssh/)
|
2017-09-29 03:18:17 +08:00
|
|
|
|
* [Spring](./s/spring/)
|
2017-01-18 22:09:27 +08:00
|
|
|
|
* [Spring Boot](./s/springboot/)
|
|
|
|
|
* [Struts2](./s/struts2/)
|
2017-06-18 02:26:53 +08:00
|
|
|
|
* [Spring WebFlow](./s/springwebflow/)
|
2017-07-28 00:41:04 +08:00
|
|
|
|
* [Supervisor](./s/supervisor/)
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2017-09-21 00:47:08 +08:00
|
|
|
|
### [T](./t/)<div id="t"></div>
|
|
|
|
|
|
|
|
|
|
* [Tomcat](./t/tomcat/)
|
|
|
|
|
|
2016-08-14 12:45:21 +08:00
|
|
|
|
### [W](./w/)<div id="w"></div>
|
|
|
|
|
|
|
|
|
|
* [WordPress](./w/wordpress/)
|
2016-08-18 15:50:33 +08:00
|
|
|
|
|
|
|
|
|
### [Z](./z/)<div id="z"></div>
|
|
|
|
|
|
|
|
|
|
* [Zabbix](./z/zabbix/)
|
2016-11-13 15:05:07 +08:00
|
|
|
|
|
|
|
|
|
---
|
|
|
|
|
|
2017-05-08 01:42:24 +08:00
|
|
|
|
## 同类项目
|
|
|
|
|
|
|
|
|
|
* [phith0n/vulhub](https://github.com/phith0n/vulhub)
|
|
|
|
|
|
2016-11-13 15:05:07 +08:00
|
|
|
|
## 相关链接
|
|
|
|
|
|
|
|
|
|
* [如何参与VulApps](./.github/CONTRIBUTING.md)
|
|
|
|
|
* [致谢列表](./THANKS.md)
|