• Stars
    star
    1,495
  • Rank 31,403 (Top 0.7 %)
  • Language
    Python
  • Created almost 8 years ago
  • Updated over 1 year ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively.

ds_store_exp

A .DS_Store file disclosure exploit.

It parses .DS_Store file and downloads files recursively.

่ฟ™ๆ˜ฏไธ€ไธช .DS_Store ๆ–‡ไปถๆณ„ๆผๅˆฉ็”จ่„šๆœฌ๏ผŒๅฎƒ่งฃๆž.DS_Storeๆ–‡ไปถๅนถ้€’ๅฝ’ๅœฐไธ‹่ฝฝๆ–‡ไปถๅˆฐๆœฌๅœฐใ€‚

Usage: python ds_store_exp.py http://www.example.com/.DS_Store

Install

pip install ds-store requests

Example

ds_store_exp.py http://hd.zj.qq.com/themes/galaxyw/.DS_Store

hd.zj.qq.com/
โ””โ”€โ”€ themes
    โ””โ”€โ”€ galaxyw
        โ”œโ”€โ”€ app
        โ”‚ย ย  โ””โ”€โ”€ css
        โ”‚ย ย      โ””โ”€โ”€ style.min.css
        โ”œโ”€โ”€ cityData.min.js
        โ”œโ”€โ”€ images
        โ”‚ย ย  โ””โ”€โ”€ img
        โ”‚ย ย      โ”œโ”€โ”€ bg-hd.png
        โ”‚ย ย      โ”œโ”€โ”€ bg-item-activity.png
        โ”‚ย ย      โ”œโ”€โ”€ bg-masker-pop.png
        โ”‚ย ย      โ”œโ”€โ”€ btn-bm.png
        โ”‚ย ย      โ”œโ”€โ”€ btn-login-qq.png
        โ”‚ย ย      โ”œโ”€โ”€ btn-login-wx.png
        โ”‚ย ย      โ”œโ”€โ”€ ico-add-pic.png
        โ”‚ย ย      โ”œโ”€โ”€ ico-address.png
        โ”‚ย ย      โ”œโ”€โ”€ ico-bm.png
        โ”‚ย ย      โ”œโ”€โ”€ ico-duration-time.png
        โ”‚ย ย      โ”œโ”€โ”€ ico-pop-close.png
        โ”‚ย ย      โ”œโ”€โ”€ ico-right-top-delete.png
        โ”‚ย ย      โ”œโ”€โ”€ page-login-hd.png
        โ”‚ย ย      โ”œโ”€โ”€ pic-masker.png
        โ”‚ย ย      โ””โ”€โ”€ ticket-selected.png
        โ””โ”€โ”€ member
            โ”œโ”€โ”€ assets
            โ”‚ย ย  โ”œโ”€โ”€ css
            โ”‚ย ย  โ”‚ย ย  โ”œโ”€โ”€ ace-reset.css
            โ”‚ย ย  โ”‚ย ย  โ””โ”€โ”€ antd.css
            โ”‚ย ย  โ””โ”€โ”€ lib
            โ”‚ย ย      โ”œโ”€โ”€ cityData.min.js
            โ”‚ย ย      โ””โ”€โ”€ ueditor
            โ”‚ย ย          โ”œโ”€โ”€ index.html
            โ”‚ย ย          โ”œโ”€โ”€ lang
            โ”‚ย ย          โ”‚ย ย  โ””โ”€โ”€ zh-cn
            โ”‚ย ย          โ”‚ย ย      โ”œโ”€โ”€ images
            โ”‚ย ย          โ”‚ย ย      โ”‚ย ย  โ”œโ”€โ”€ copy.png
            โ”‚ย ย          โ”‚ย ย      โ”‚ย ย  โ”œโ”€โ”€ localimage.png
            โ”‚ย ย          โ”‚ย ย      โ”‚ย ย  โ”œโ”€โ”€ music.png
            โ”‚ย ย          โ”‚ย ย      โ”‚ย ย  โ””โ”€โ”€ upload.png
            โ”‚ย ย          โ”‚ย ย      โ””โ”€โ”€ zh-cn.js
            โ”‚ย ย          โ”œโ”€โ”€ php
            โ”‚ย ย          โ”‚ย ย  โ”œโ”€โ”€ action_crawler.php
            โ”‚ย ย          โ”‚ย ย  โ”œโ”€โ”€ action_list.php
            โ”‚ย ย          โ”‚ย ย  โ”œโ”€โ”€ action_upload.php
            โ”‚ย ย          โ”‚ย ย  โ”œโ”€โ”€ config.json
            โ”‚ย ย          โ”‚ย ย  โ”œโ”€โ”€ controller.php
            โ”‚ย ย          โ”‚ย ย  โ””โ”€โ”€ Uploader.class.php
            โ”‚ย ย          โ”œโ”€โ”€ ueditor.all.js
            โ”‚ย ย          โ”œโ”€โ”€ ueditor.all.min.js
            โ”‚ย ย          โ”œโ”€โ”€ ueditor.config.js
            โ”‚ย ย          โ”œโ”€โ”€ ueditor.parse.js
            โ”‚ย ย          โ””โ”€โ”€ ueditor.parse.min.js
            โ””โ”€โ”€ static
                โ”œโ”€โ”€ css
                โ”‚ย ย  โ””โ”€โ”€ page.css
                โ”œโ”€โ”€ img
                โ”‚ย ย  โ”œโ”€โ”€ bg-table-title.png
                โ”‚ย ย  โ”œโ”€โ”€ bg-tab-say.png
                โ”‚ย ย  โ”œโ”€โ”€ ico-black-disabled.png
                โ”‚ย ย  โ”œโ”€โ”€ ico-black-enabled.png
                โ”‚ย ย  โ”œโ”€โ”€ ico-coorption-person.png
                โ”‚ย ย  โ”œโ”€โ”€ ico-miss-person.png
                โ”‚ย ย  โ”œโ”€โ”€ ico-mr-person.png
                โ”‚ย ย  โ”œโ”€โ”€ ico-white-disabled.png
                โ”‚ย ย  โ””โ”€โ”€ ico-white-enabled.png
                โ””โ”€โ”€ scripts
                    โ”œโ”€โ”€ js
                    โ””โ”€โ”€ lib
                        โ””โ”€โ”€ jquery.min.js

21 directories, 48 files

More Repositories

1

subDomainsBrute

A fast sub domain brute tool for pentesters
Python
3,444
star
2

GitHack

A `.git` folder disclosure exploit
Python
3,050
star
3

BBScan

A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers
Python
2,166
star
4

swagger-exp

A Swagger API Exploit
JavaScript
1,136
star
5

htpwdScan

HTTP weak pass scanner
Python
900
star
6

EasyPen

EasyPen is a GUI program which helps pentesters do target discovery, vulnerability scan and exploitation
JavaScript
606
star
7

IIS_shortname_Scanner

an IIS shortname Scanner
Python
522
star
8

eyes.sh

Optimized DNS/HTTP Log Tool for pentesters, faster and easy to use.
HTML
378
star
9

idea_exploit

Gather sensitive information from (.idea) folder for pentesters
Python
357
star
10

MisConfig_HTTP_Proxy_Scanner

The scanner helps to scan misconfigured reverse proxy servers and misconfigured forward proxy servers
Python
170
star
11

edu-dns-zone-transfer

script to scan edu.cn DNS Servers
Python
89
star
12

log4j2_vul_local_scanner

Log4j ๆผๆดžๆœฌๅœฐๆฃ€ๆต‹่„šๆœฌใ€‚ Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)
Python
85
star
13

struts2_045_scan

Struts2-045 Scanner
Python
73
star
14

OutLook_WebAPP_Brute

Microsoft Outlook WebAPP Brute
Python
64
star
15

WIFIpass

decrypt all saved WIFI passwords on your PC
Python
61
star
16

chromePass

Decrypt all saved Chrome passwords
Python
41
star
17

NPUcat

NPUcat one click proxy
Python
9
star
18

DNS_AXFR_Client

A python DNS Transfer Client
Python
8
star
19

lijiejie

1
star