Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-21974 PoC — 威睿 VMware ESXi 缓冲区错误漏洞

Source
Associated Vulnerability
Title: 威睿 VMware ESXi 缓冲区错误漏洞 (CVE-2021-21974)
Description:OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
Description
ESXi EZ - A custom scanner that takes list of IPs either in JSON, CSV or individually  and checks for infection CVE-2021-21974
Readme
# ESXi_ransomware_scanner
A program that scans IP addresses for signs of ESXi compromise by grabbing the ransom note from an html page and comparing the strings.

## Requirements
- python 3.x
- requests
- BeautifulSoup
- tqdm
- colorama

## Installation
Use the package manager pip to install the required packages.

```python
    pip install requests
    pip install bs4
    pip install tqdm
    pip install colorama
```
## Usage
Run the program with Python 3:

```python
python ESXi_EZ_Scanner.py
```
## Menu
The program will display the following menu:

## Scanning a single IP address
Select option 1 from the menu and enter the IP address you wish to scan. The program will then display a message indicating whether the IP address is infected or not.

## Scanning IP addresses from a CSV file
Select option 2 from the menu and enter the name of the CSV file. The file should contain a list of IP addresses, with one IP address per row. The program will then scan each IP address and display a message indicating whether each IP address is infected or not.

## Scanning IP addresses from a JSON file
Select option 3 from the menu and enter the name of the JSON file. The file should contain a list of IP addresses, with each IP address represented as a string in the list. The program will then scan each IP address and display a message indicating whether each IP address is infected or not.

## Contributing
Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →