Skip to content

Scanner Remote Code Execution yang rentan di web berbasis PHP seperti Laravel, ThinkPHP, FCKeditor, dll. Dibuat dengan Python, cocok untuk pentest & bug bounty.

Notifications You must be signed in to change notification settings

kafyasfngl/rce-scanner

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

7 Commits
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ” RCE Scanner Made By Next Project

RCE Scanner adalah tool scanning otomatis berbasis Python yang dirancang untuk mendeteksi keberadaan beberapa vulnerable endpoints atau file yang sering ditemukan dalam aplikasi web berbasis PHP seperti Laravel, ThinkPHP, dan lainnya.

Script ini sudah dilengkapi dengan pengecekan redirect, pengecekan string khusus, dan metode aman untuk mendeteksi kerentanan tanpa melakukan eksploitasi berbahaya.

Scanner Banner Python Version License


πŸ’‘ Fitur Utama

  • πŸš€ Multi-threaded fast scanning
  • πŸ›‘οΈ Bypass redirect detection
  • πŸ“‘ Mendukung berbagai payload populer seperti:
    • PHPUnit RCE
    • ThinkPHP RCE
    • Laravel Ignition RCE
    • FCKeditor file upload
    • elFinder exposure
    • PHPFileManager detection
  • πŸ”„ Deteksi otomatis protokol (http/https)
  • πŸ“ Simpan hasil scan ke results.txt

πŸ“‚ Struktur Payload yang Dicek

Nama Vulnerability Path yang Diserang Metode Deteksi
PHPUnit /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php POST ShellOK di response
ThinkPHP 5.0.x /index.php?s=/index/\think\app/invokefunction GET phpinfo
Laravel Ignition /_ignition/execute-solution POST viewFile di response
FCKeditor Upload /fckeditor/editor/filemanager/connectors/php/upload.php POST shell.php response check
elFinder /elfinder/php/connector.minimal.php GET JSON {"api":"2.1"}
PHPFileManager /phpfilemanager.php GET File Manager

βš™οΈ Cara Penggunaan

  1. Installasi
git clone https://github.com/username/next-project-scanner.git
cd next-project-scanner
pip install -r requirements.txt
  1. Persiapkan list target
    Buat file berisi daftar URL target (list.txt) contoh:
example.com
http://targetsite.org
https://another-site.net
  1. Jalankan script
python scanner.py

Masukkan List

[?] Masukkan nama file target (contoh: list.txt):
>> list.txt

Credit : Next Project

About

Scanner Remote Code Execution yang rentan di web berbasis PHP seperti Laravel, ThinkPHP, FCKeditor, dll. Dibuat dengan Python, cocok untuk pentest & bug bounty.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages