v1.24 大版本更新-Cross-version update
EN:
0:Thanks to user @wuha0926 for reporting the issue of template validation failing with the response_time function.
1:Added the function stop_scan: true/false (This means that the process will stop immediately as soon as one path matches, and no further requests will be sent.)
2:Added functions aes_cbc, java_class_cmd, aes_cbc_decrypt, shiro_cookie, jndi_payload, jndi_wrapper, jndi_rmi, etc., for deserialization scanning.
3: Added three built-in variables: {{username}}, {{password}}, and {{email}}. These variables are read by default if referenced in the template and are located in the wordlists directory.
4:The matcher/extractor no longer extracts information based on context; it is now optimized for precise information extraction.
5:Optimized the removal of output vulnerability URL information; now only the vulnerability URL is output.
6:Optimized the matcher priority and accuracy issues.
7:Optimized the output report format for -o.
8:Updated the latest version of POCs to 3233.
https://github.com/hack007x/veil_poc
9:POC writing manual v1.2.3
@https://github.com/hack007x/veil/wiki/veil-Poc-%E8%AF%AD%E6%B3%95%E6%80%BB%E8%A7%88v1.2.3
ZH:
0:感谢用户@wuha0926 反馈提出的问题,模板验证response_time 函数不通过问题
1:新增函数:stop_scan: true/false (这意味着,只要其中一条路径匹配,该过程就会立即停止,并且不会发送任何进一步的请求。)
2:新增函数aes_cbc、java_class_cmd、aes_cbc_decrypt、shiro_cookie、jndi_payload、jndi_wrapper、jndi_rmi 等等用于反序列化扫描
3:新增内置变量 {{username}} {{password}} {{email}}3个内置变量,如果模板有引用到默认读读取,wordlists目录下。
4:匹配器-提取器 不再上下文延申提取信息,优化为精准提取信息。
5:优化删除输出漏洞URL信息,目前只输出漏洞的URL即可
6:优化匹配器优先级问题以及匹配器精准度问题。
7:优化-o 输出报告格式
8:最新版本 POC更新至3233个
https://github.com/hack007x/veil_poc
9:poc编写手册 v1.2.3
https://github.com/hack007x/veil/wiki/veil-Poc-%E8%AF%AD%E6%B3%95%E6%80%BB%E8%A7%88v1.2.3