Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

能否增加目录绕过字典 #14

Closed
weujieytt opened this issue Aug 23, 2022 · 7 comments
Closed

能否增加目录绕过字典 #14

weujieytt opened this issue Aug 23, 2022 · 7 comments

Comments

@weujieytt
Copy link

例如:
/;/actuator/env
//actuator/..;/env

@yuligesec
Copy link
Contributor

后续考虑加入鉴权绕过功能。

@weujieytt
Copy link
Author

后续考虑加入鉴权绕过功能。

遇到/api-docs?group=openapi这种情况就扫不出来了

@yuligesec
Copy link
Contributor

这是哪个框架的?有没有外网url。

@weujieytt
Copy link
Author

这是哪个框架的?有没有外网url。

这也是springboot的,只是平常项目上遇到了不少,不加group=xxx访问不到,https://blog.csdn.net/weixin_42425967/article/details/113044573

@yuligesec
Copy link
Contributor

fofa找的Knife4j是没有问题的,你用最新版再试试吧,和不加group=xxx没有关系,默认获取到API文档地址就是带group的。

@F6JO
Copy link

F6JO commented Aug 30, 2023

+1 有的目标不加group请求不到目录比如访问"/v3/api-docs?group=系统模块"是正常,访问/v3/api-docs就是404了

@yuligesec
Copy link
Contributor

https://github.com/API-Security/APIKit/releases/tag/v1.5.1 可以解决该问题。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants