{"id":696,"date":"2022-08-07T22:57:01","date_gmt":"2022-08-07T14:57:01","guid":{"rendered":"https:\/\/www.langsasec.cn\/?p=696"},"modified":"2022-11-13T23:46:06","modified_gmt":"2022-11-13T15:46:06","slug":"serein","status":"publish","type":"post","link":"https:\/\/blog.langsasec.cn\/index.php\/2022\/08\/07\/serein\/","title":{"rendered":"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%e5%89%8d%e8%a8%80\"><\/span>\u524d\u8a00<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e00\u6b3e\u56fe\u5f62\u5316\u3001\u6279\u91cf\u91c7\u96c6url\u3001\u6279\u91cf\u5bf9\u91c7\u96c6\u7684url\u8fdb\u884c\u5404\u79cdnday\u68c0\u6d4b\u7684\u5de5\u5177\u3002\u53ef\u7528\u4e8esrc\u6316\u6398\u3001cnvd\u6316\u6398\u30010day\u5229\u7528\u3001\u6253\u9020\u81ea\u5df1\u7684\u6b66\u5668\u5e93\u7b49\u573a\u666f\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%e9%a1%b9%e7%9b%ae%e5%9c%b0%e5%9d%80\"><\/span>\u9879\u76ee\u5730\u5740<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><a href=\"https:\/\/github.com\/W01fh4cker\/Serein\">https:\/\/github.com\/W01fh4cker\/Serein<\/a><\/p><p>\u5173\u6ce8\u6d6a\u98d2sec\u56de\u590dSerein\u83b7\u53d6\u5feb\u901f\u4e0b\u8f7d\u5730\u5740<\/p><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"latest-interface-display-%e6%9c%80%e6%96%b0%e7%89%88%e9%a1%b5%e9%9d%a2%e5%b1%95%e7%a4%ba\"><\/span>Latest-Interface-Display | \u6700\u65b0\u7248\u9875\u9762\u5c55\u793a<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/img-blog.csdnimg.cn\/img_convert\/a2c3c25deb37d0ff709b6df329aae13f.png\" title=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe\" alt=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"exploit-example-%e5%88%a9%e7%94%a8%e7%a4%ba%e4%be%8b\"><\/span>Exploit-Example | \u5229\u7528\u793a\u4f8b<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>\u6211\u4eec\u60f3\u6279\u91cf\u5229\u7528<code>\u5411\u65e5\u8475RCE<\/code>\u6f0f\u6d1e\uff0c\u4e8e\u662f\u6211\u4eec<code>base64\u52a0\u5bc6<\/code>\u8bed\u53e5<code>body=\"Verification failure\"<\/code>\uff0c\u5f97\u5230\uff1a<code>Ym9keT0iVmVyaWZpY2F0aW9uIGZhaWx1cmUi<\/code>\u3002<\/li><li>\u6211\u4eec\u9009\u53d6\u83b7\u53d6\u524d<code>2000<\/code>\u6761\uff08\u5177\u4f53\u6761\u6570\u9700\u8981\u6839\u636e\u81ea\u5df1\u7684\u4f1a\u5458\u60c5\u51b5\u6765\u586b\u5199\uff09\uff1a<img decoding=\"async\" alt=\"0\" src=\"https:\/\/img-blog.csdnimg.cn\/img_convert\/381122c606d91096dd537cccdec0cf82.png\" title=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe1\" \/><img decoding=\"async\" alt=\"1\" src=\"https:\/\/img-blog.csdnimg.cn\/img_convert\/c74bf8ee061cb174ddfec4274cad997a.png\" title=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe2\" \/><img decoding=\"async\" alt=\"2\" src=\"https:\/\/img-blog.csdnimg.cn\/img_convert\/29358d692d2f826b0f427e3a3bc9150d.png\" title=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe3\" \/><\/li><li>\u76f4\u63a5\u70b9\u51fb<code>\u5411\u65e5\u8475RCE\u4e00\u628a\u68ad<\/code>\uff1a<img decoding=\"async\" alt=\"4\" src=\"https:\/\/img-blog.csdnimg.cn\/img_convert\/db3090e7bf7f474dc0dbc126f962227f.png\" title=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe4\" \/><\/li><li>\u53ef\u4ee5\u770b\u5230\u8f6f\u4ef6\u5f00\u59cb\u6279\u91cf\u68c0\u6d4b\u4e86\uff08\u53ef\u80fd\u4f1a\u51fa\u73b0\u77ed\u65f6\u95f4\u7684\u7a7a\u767d\uff0c\u8bf7\u8010\u5fc3\u7b49\u5f85\u7a0b\u5e8f\u8fd0\u884c\uff09\uff1a<img decoding=\"async\" alt=\"5\" src=\"https:\/\/img-blog.csdnimg.cn\/img_convert\/03c0fa7938ed9eeb86b0e8beffa06446.png\" title=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe5\" \/>\u8f6f\u4ef6\u7684\u7ebf\u7a0b\u6570\u662f<code>100<\/code>\uff0c\u53ef\u4ee5\u81ea\u5df1\u5bf9<code>exp<\/code>\u6587\u4ef6\u4e0b\u7684<code>xrk_rce.py<\/code>\u7684\u7b2c<code>58<\/code>\u884c\u8fdb\u884c\u8c03\u6574\u3002\uff08\u901f\u5ea6\u8fd8\u662f\u5f88\u5feb\u7684\uff09<\/li><li><strong>\u5220\u9664\u6587\u4ef6\u5939\u4e0b<code>urls.txt<\/code>\u3001<code>\u4fee\u6b63\u540e\u7684url.txt<\/code>\u3001<code>host.txt<\/code>\u8fd9\u4e09\u4e2a\u6587\u4ef6\uff0c\u51c6\u5907\u4f7f\u7528\u5176\u4ed6\u4e00\u952e\u68ad\u54c8\u6a21\u5757\uff1a<\/strong><img decoding=\"async\" src=\"https:\/\/img-blog.csdnimg.cn\/img_convert\/06b8019b7d4d60b1e718f70af470fb97.png\" title=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe6\" alt=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe6\" \/><img decoding=\"async\" src=\"https:\/\/img-blog.csdnimg.cn\/img_convert\/f7f5c7efe3b203c54e6fdbd2d1662297.png\" title=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe7\" alt=\"\u5de5\u5177\u63a8\u8350\u2014\u2014Serein (SRC\u6316\u6398\u795e\u5668)\u63d2\u56fe7\" \/><\/li><\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"how-to-use-%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8\"><\/span>How-To-Use | \u5982\u4f55\u4f7f\u7528<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>B\u7ad9\uff1a<a href=\"https:\/\/www.bilibili.com\/video\/bv1Dv4y137Lu\">https:\/\/www.bilibili.com\/video\/bv1Dv4y137Lu<\/a><\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>\u9700\u8981<code>python3.7~3.9<\/code><\/strong>&nbsp;git clone <a href=\"https:\/\/github.com\/W01fh4cker\/Serein.git\" rel=\"nofollow\">https:\/\/github.com\/W01fh4cker\/Serein.git<\/a><br>&nbsp;cd Serein<br>&nbsp;pip3 install -r requirements.txt<br>&nbsp;python3 Serein.py<\/li><li>\u70b9\u51fb\u5de6\u4e0a\u89d2\u7684<code>\u8f6f\u4ef6\u914d\u7f6e<\/code>\u914d\u7f6e<code>fofa<\/code>\u7684<code>email<\/code>\u548c<code>key<\/code>\uff08\u6ce8\u610f\u4e0d\u662f\u5bc6\u7801\uff0c\u800c\u662f<code>https:\/\/fofa.info\/personalData<\/code>\u4e0b\u65b9\u7684<code>API KEY<\/code>\uff09\uff0c\u7136\u540e\u5c31\u53ef\u4ee5\u6109\u5feb\u5730\u4f7f\u7528<code>fofa\u641c\u7d22<\/code>\u5566\u3002 <strong>\u6ce8\u610f\uff1a\u5fc5\u987b\u662f<code>fofa<\/code>\u666e\u901a\/\u9ad8\u7ea7\/\u4f01\u4e1a\u8d26\u53f7\uff0c\u56e0\u4e3a<code>fofa<\/code>\u6ce8\u518c\u4f1a\u5458\u8c03\u7528<code>api<\/code>\u9700\u8981\u6d88\u8017<code>f<\/code>\u5e01\uff0c\u5982\u679c\u60a8\u662f\u6ce8\u518c\u4f1a\u5458\u8bf7\u786e\u4fdd\u60a8\u6709<code>f<\/code>\u5e01\uff0c\u5426\u5219\u65e0\u6cd5\u67e5\u8be2\uff01<\/strong><\/li><li>\u641c\u96c6\u5b8c\u6210\u4e4b\u540e\uff0c\u8f6f\u4ef6\u7684\u540c\u7ea7\u76ee\u5f55\u4e0b\u4f1a\u751f\u6210<code>urls.txt<\/code>\u3001<code>\u4fee\u6b63\u540e\u7684url.txt<\/code>\u3001<code>host.txt<\/code>\uff0c\u5206\u522b\u4fdd\u5b58<code>\u91c7\u96c6\u7684\u539f\u59cburl<\/code>\u3001\u6dfb\u52a0\u4e86<code>http\/https\u5934\u7684url<\/code>\u3001<code>\u4ec5\u7f51\u7ad9IP<\/code>\u3002<\/li><li>\u5b8c\u6210\u4e00\u6b21\u626b\u63cf\u4efb\u52a1\u540e\uff0c\u82e5\u8981\u5f00\u542f\u4e0b\u4e00\u6b21\u626b\u63cf\uff0c\u8bf7\u5220\u9664\u6587\u4ef6\u5939\u4e0b<code>urls.txt<\/code>\u3001<code>\u4fee\u6b63\u540e\u7684url.txt<\/code>\u3001<code>host.txt<\/code>\u8fd9\u4e09\u4e2a\u6587\u4ef6\u3002<\/li><\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%e5%85%8d%e8%b4%a3%e5%a3%b0%e6%98%8e\"><\/span>\u514d\u8d23\u58f0\u660e<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u672c\u516c\u4f17\u53f7\u63d0\u4f9b\u7684\u5de5\u5177\u4ec5\u4f9b\u5b66\u4e60\u4f7f\u7528, \u5982\u82e5\u4f7f\u7528\u5de5\u5177\u8fdb\u884c\u975e\u6cd5\u884c\u4e3a\u7686\u4e0e\u672c\u516c\u4f17\u53f7\u65e0\u5173<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u8a00 \u4e00\u6b3e\u56fe\u5f62\u5316\u3001\u6279\u91cf\u91c7\u96c6url\u3001\u6279\u91cf\u5bf9\u91c7\u96c6\u7684url\u8fdb\u884c\u5404\u79cdnday\u68c0\u6d4b\u7684\u5de5\u5177\u3002\u53ef\u7528\u4e8esrc\u6316\u6398\u3001cnvd\u6316\u6398 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36],"tags":[],"class_list":["post-696","post","type-post","status-publish","format-standard","hentry","category-tools"],"_links":{"self":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/696","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/comments?post=696"}],"version-history":[{"count":1,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/696\/revisions"}],"predecessor-version":[{"id":697,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/696\/revisions\/697"}],"wp:attachment":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/media?parent=696"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/categories?post=696"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/tags?post=696"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}