Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"关于xray sql检测模块问题反馈” #1765

Open
Zoneygit opened this issue Nov 24, 2023 · 2 comments
Open

"关于xray sql检测模块问题反馈” #1765

Zoneygit opened this issue Nov 24, 2023 · 2 comments

Comments

@Zoneygit
Copy link

Zoneygit commented Nov 24, 2023

我用xray一共检测了12473个网站 awvs出来了100个sql注入 能复现出来70个左右
xray出来51个 能复现出来30个
是同一批域名
我发现awvs会针对referer头和x-Forwarded-For检测
他会针对referer植入一个网址 一般是谷歌网址加一堆参数测试 xray我暂时并没有发现针对referer头和x-Forwarded-For检测出来的注入 所以特此留言 也希望更新一下sql注入的负载 有些已经被waf精准识别了 出漏洞率也大大降低了。
感谢长亭提供如此优秀漏扫的软件 !

@Zoneygit
Copy link
Author

new

@Jarcis-cy
Copy link
Collaborator

感谢反馈!我们会记录优化的,后续关于dast相关的能力,比如sql注入等,会优化在xray2.0的xscan中

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants