Skip to content

Script to check vulnerability status of redis instances running on synology.me domains

Notifications You must be signed in to change notification settings

zipponnova/synology-me-poc

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 

Repository files navigation

Redis Vulnerability Scanner

Overview

Redis Vulnerability Scanner is a powerful and efficient script designed to scan Redis instances across multiple IP addresses and ports to identify potential vulnerabilities.

Features

  • Scans multiple IP addresses and ports concurrently.
  • Identifies vulnerable Redis instances.
  • Optionally fetches keyvalue pairs from the database and displays proof of concept (PoC) data from vulnerable instances.
  • Provides detailed output including counts of vulnerable, non-vulnerable, and unreachable IPs.
  • Offers options to display only vulnerable IPs or only the IP addresses of vulnerable instances.

Installation

  1. Clone the repository:

    git clone https://github.com/zipponnova/redis-vulnerability-scanner.git
    cd redis-vulnerability-scanner
  2. Install dependencies:

    pip3 install redis termcolor

Usage

Command-Line Options

  • --ips: List of IP addresses to scan (space/comma separated).
  • --ips-file: File containing IP addresses (line/space/comma separated).
  • --ports: List of ports to scan.
  • --max-workers: Maximum number of worker threads (default is 10).
  • --poc: Fetch proof of concept data from Redis.
  • --only-vulnerable: Print only vulnerable IPs and their details.
  • --only-ips: Print only IP addresses of vulnerable instances.

Examples

Scan IPs from a file and print only vulnerable IP addresses

python3 redis-vulnerability-scanner.py --ips-file ips.txt --ports 6379 --only-ips

About

Script to check vulnerability status of redis instances running on synology.me domains

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages