jsinfo-scan简单改版,增加了swagger、druid目录扫描和手机号、身份证号敏感信息匹配
#匹配敏感信息
'Swagger UI': r'((swagger-ui.html)|("swagger":)|(Swagger UI)|(swaggerUi))',
'Druid': r'((Druid Stat Index)|(druid monitor))',
'Spring Boot': r'((local.server.port)|(:{"mappings":{")|({"_links":{"self":))',
'IDCard': '^0-9[^0-9]',
'Phone': '^0-9A-Za-z[^0-9A-Za-z]'
#敏感目录
vul_path = r"""
druid/index.html
system/index.html
webpage/system/druid/index.html
api
swagger-ui.html
swagger/ui/index
api/swagger-ui.html
swagger/index.html
env
trace
actuator
api/env
api/trace
actuator/env
actuator/trace
monitor/env
gateway/actuator/env
"""