- Perform a POST request to the
/ssl-vpn/hipreport.esp
endpoint. - Perform a GET request to
/global-protect/portal/images/sxy.txt
to check if the exploitation allows access to the file, which would typically be forbidden (403 Forbidden status).
You need Python 3.6 or newer and aiohttp
. Ensure you have the latest version of Python and pip installed.
python check.py -host 192.168.1.1
python check.py -list ips.txt