2016-06-16 16:18:17 +08:00
|
|
|
|
# VulApps
|
|
|
|
|
|
2016-06-16 19:30:19 +08:00
|
|
|
|
收集各种漏洞环境,为方便使用,统一采用 Dockerfile 形式。
|
2016-06-16 16:18:17 +08:00
|
|
|
|
|
2016-06-16 19:30:19 +08:00
|
|
|
|
> 喜欢请点 Star,如果不打算贡献,千万别 Fork
|
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
本项目 GitHub 地址: [https://github.com/Medicean/VulApps](https://github.com/Medicean/VulApps)
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-06-18 11:57:07 +08:00
|
|
|
|
[DockerHub 在线镜像地址](https://hub.docker.com/r/medicean/vulapps/)
|
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
## 获取并使用相关镜像
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-09-09 16:07:22 +08:00
|
|
|
|
> 直接使用 docker 命令拉取相关镜像,并启动。需要查看相关环境的 tag 可以直接在 dockerhub 查看或在具体的漏洞目录下查看 ReadME 文件。
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
以 Struts2 S2-037 漏洞环境为例:
|
|
|
|
|
|
|
|
|
|
1. 获取镜像:
|
|
|
|
|
|
|
|
|
|
```
|
2016-06-16 19:30:19 +08:00
|
|
|
|
docker pull medicean/vulapps:s_struts2_s2-037
|
2016-06-18 00:18:49 +08:00
|
|
|
|
```
|
|
|
|
|
|
2016-08-14 12:45:21 +08:00
|
|
|
|
> 如果获取速度慢,推荐使用 [中科大 Docker Mirrors](https://lug.ustc.edu.cn/wiki/mirrors/help/docker)
|
2016-06-18 11:57:07 +08:00
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
2. 创建并启动容器
|
|
|
|
|
|
|
|
|
|
```
|
|
|
|
|
docker run -d -p 80:8080 medicean/vulapps:s_struts2_s2-037
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
> 说明:
|
|
|
|
|
>
|
|
|
|
|
> -d 表示守护形式后台一直运行该容器
|
|
|
|
|
>
|
|
|
|
|
> -p 80:8080 Dockerfile 中暴露了容器的 8080 端口,将其映射到本机的 80 端口
|
|
|
|
|
>
|
|
|
|
|
> 其它选项请根据自己实际情况运行。
|
|
|
|
|
|
|
|
|
|
## 镜像 Tag 及路径命名规则
|
|
|
|
|
|
|
|
|
|
1. 路径
|
|
|
|
|
|
|
|
|
|
`/组件首字母/组件名/具体漏洞名`
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
2. Tag
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
**路径名全小写,路径分割符一率替换为下划线**
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
**例如:**
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-06-18 00:18:49 +08:00
|
|
|
|
Struts2 S2-037 漏洞环境,路径为 [/s/struts2/s2-037](./s/struts2/s2-037) , 所以 Tag 为:`s_struts2_s2-037`
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
|
|
|
|
## 组件首字母
|
|
|
|
|
|
2016-06-30 02:35:30 +08:00
|
|
|
|
* [B](#b)
|
2016-09-08 16:48:51 +08:00
|
|
|
|
* [C](#c)
|
2016-08-25 14:34:45 +08:00
|
|
|
|
* [I](#i)
|
2016-10-05 19:20:39 +08:00
|
|
|
|
* [J](#j)
|
2016-07-02 00:40:26 +08:00
|
|
|
|
* [O](#o)
|
2016-10-28 15:25:08 +08:00
|
|
|
|
* [R](#r)
|
2016-06-16 19:30:19 +08:00
|
|
|
|
* [S](#s)
|
2016-08-14 12:45:21 +08:00
|
|
|
|
* [W](#w)
|
2016-08-18 15:50:33 +08:00
|
|
|
|
* [Z](#z)
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
|
|
|
|
## 漏洞环境
|
|
|
|
|
|
2016-06-30 02:35:30 +08:00
|
|
|
|
### [B](./b/)<div id="b"></div>
|
|
|
|
|
|
2016-06-30 03:23:01 +08:00
|
|
|
|
* [Bash](./b/bash/)
|
2016-06-30 02:35:30 +08:00
|
|
|
|
|
2016-09-08 16:48:51 +08:00
|
|
|
|
### [C](./c/)<div id="c"></div>
|
|
|
|
|
|
|
|
|
|
* [Cisco](./c/cisco/)
|
|
|
|
|
|
2016-08-25 14:34:45 +08:00
|
|
|
|
### [I](./i/)<div id="i"></div>
|
|
|
|
|
|
|
|
|
|
* [ImageMagick](./i/imagemagick/)
|
|
|
|
|
|
2016-10-05 19:20:39 +08:00
|
|
|
|
### [J](./j/)<div id="j"></div>
|
|
|
|
|
|
|
|
|
|
* [Jenkins](./j/jenkins/)
|
2016-10-31 00:58:50 +08:00
|
|
|
|
* [Joomla!](./j/joomla/)
|
2016-10-05 19:20:39 +08:00
|
|
|
|
|
2016-07-02 00:40:26 +08:00
|
|
|
|
### [O](./o/)<div id="o"></div>
|
|
|
|
|
|
|
|
|
|
* [OpenSSL](./o/openssl/)
|
|
|
|
|
|
2016-10-28 15:25:08 +08:00
|
|
|
|
### [R](./r/)<div id="r"></div>
|
|
|
|
|
|
|
|
|
|
* [Redis](./r/redis/)
|
|
|
|
|
|
2016-06-16 19:30:19 +08:00
|
|
|
|
### [S](./s/)<div id="s"></div>
|
2016-06-16 16:18:17 +08:00
|
|
|
|
|
2016-06-16 16:23:42 +08:00
|
|
|
|
* [Struts2](./s/struts2/)
|
2016-06-16 19:30:19 +08:00
|
|
|
|
|
2016-08-14 12:45:21 +08:00
|
|
|
|
### [W](./w/)<div id="w"></div>
|
|
|
|
|
|
|
|
|
|
* [WordPress](./w/wordpress/)
|
2016-08-18 15:50:33 +08:00
|
|
|
|
|
|
|
|
|
### [Z](./z/)<div id="z"></div>
|
|
|
|
|
|
|
|
|
|
* [Zabbix](./z/zabbix/)
|
2016-11-13 15:05:07 +08:00
|
|
|
|
|
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
## 相关链接
|
|
|
|
|
|
|
|
|
|
* [如何参与VulApps](./.github/CONTRIBUTING.md)
|
|
|
|
|
* [致谢列表](./THANKS.md)
|