TideSec / TideSec/TscanPlus

JsMap泄露检测问题

Open
#1,688 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
4.4k
Forks
248
PR merge metrics
No merged PRs in 30d

Description

📝 问题描述

清晰简洁地描述您遇到的问题(例如:扫描结果错误、模块崩溃、功能异常等)

漏洞检测——DumpAll——JsMap泄露检测不到问题

🕹 复现步骤

请按照实际操作步骤填写,确保可复现(示例格式):

  1. 使用环境

    • 目标系统:Windows 11 专业版
    • 无影版本:v3.4.3
    • 网络环境: 公网目标
  2. 功能配置

    • 功能模块:漏洞检测——DumpAll
    • 防护设备:
    • 配置截图:
Image
  1. 异常描述

漏洞检测——DumpAll——JsMap泄露——.js.map检测不到问题,实际目标是存在js.map文件泄露的
希望能够优化一下检测逻辑。

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the issue in the DumpAll vulnerability-detection module against a target known to expose a .js.map file. Trace why the JsMap leak check does not report it, then verify that the same target is detected after the detection logic is adjusted.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.