Security test method, related device, script file transmission method and related device

By managing the address library in the tunnel proxy plug-in, dynamically selecting the address of the dynamic script file to ensure the success of data transmission, the security test interruption problem caused by the loss of contact between the client and the dynamic script file is solved, and the continuity of security test is achieved.

CN119995793APending Publication Date: 2025-05-13BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311508884.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When performing security testing, the client is prone to losing contact with the dynamic script file, resulting in interruption of security testing.

Method used

By implementing address library management in the client's tunnel proxy plug-in, the addresses of dynamic script files are randomly crawled in the address library or determined according to the frequency of use, ensuring that the data transmission instructions can be successfully sent.

Benefits of technology

It effectively avoids interruption between the client and dynamic script files, ensuring the continuity and stability of security testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995793A_ABST
    Figure CN119995793A_ABST
Patent Text Reader

Abstract

The invention discloses a security test method, a related device, a script file transmission method and a related device, which are applied to a tunnel proxy plug-in of a client, the client is configured with an address library, and the address library comprises addresses of a plurality of dynamic script files. The address of each dynamic script file corresponds to a unique dynamic script file, the dynamic script files are located in a controlled host, the controlled host is controlled by a client, and the security test method comprises the following steps: receiving a data instruction; if the data instruction is a data transmission instruction, determining an address of a target dynamic script file in an address library; according to the address of the target dynamic script file, sending the data transmission instruction to the target dynamic script file; and if the data transmission instruction fails to be sent, re-determining the address of the target dynamic script file until the data transmission instruction is successfully sent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of big data, and in particular to a security testing method and related devices, a script file transmission method and related devices. Background Art

[0002] With the advancement of Internet technology, network security is becoming more and more important. In order to avoid losses from attacks, many companies, units and institutions will conduct security tests. At present, in the process of security testing with the help of HTTP tunnel, it is necessary to first place a dynamic script file in the controlled host. When the command is transmitted, it is necessary to rely on the dynamic script file for communication. However, during the test, the client can easily lose contact with the dynamic script file, resulting in the loss of contact between the client and the controlled host, the controlled host loses control, and the security test is forced to be interrupted. Summary of the invention

[0003] The embodiments of the present application provide a security testing method and related devices, a script file transmission method and related devices, which can solve the problem that the client easily loses contact with the dynamic script file, resulting in the forced interruption of the security test.

[0004] In the first aspect, an embodiment of the present application provides a security testing method, which is applied to a tunnel proxy plug-in of a client, wherein the client is configured with an address library, wherein the address library contains addresses of multiple dynamic script files, wherein the address of each dynamic script file corresponds to a unique dynamic script file, and the dynamic script file is located in a controlled host, and the controlled host is controlled by the client. The security testing method includes: receiving a data instruction; if the data instruction is a data transmission instruction, determining the address of a target dynamic script file in the address library; sending the data transmission instruction to the target dynamic script file according to the address of the target dynamic script file; if the data transmission instruction fails to be sent, re-determining the address of the target dynamic script file until it is sent successfully.

[0005] In a possible implementation, determining the address of the target dynamic script file in the address library specifically includes: randomly grabbing the address of a dynamic script file in the address library; and determining the address of the dynamic script file as the address of the target dynamic script file.

[0006] In a possible implementation, there are multiple controlled hosts, and the addresses of the controlled hosts and the addresses of the corresponding dynamic script files are stored in association in the address library, the address of the corresponding dynamic script file is the address of the dynamic script file located on the controlled host, the data transmission instruction includes the address of the target controlled host, and randomly grabbing the address of a dynamic script file in the address library through a random algorithm includes: determining the address of the dynamic script file stored in association with the address of the target controlled host according to the address of the target controlled host; and randomly grabbing the address of a dynamic script file from the addresses of the dynamic script file stored in association with the address of the target controlled host.

[0007] In a possible implementation, after receiving the data instruction, the method further includes: if the data instruction is an address deletion instruction, reading the address to be deleted contained in the address deletion instruction, the address to be deleted being the address of the dynamic script file to be deleted; and deleting the address to be deleted in the address library.

[0008] In a possible implementation, after receiving the data instruction, the method further includes: if the data instruction is an address increase instruction, reading the address to be added contained in the address increase instruction, the address to be added is the address of the dynamic script file to be added; and adding the address to be added in the address library.

[0009] In the second aspect, an embodiment of the present application provides a script file transmission method, which is applied to a vulnerability management plug-in of a client, wherein the client is configured with an address library, and the address library contains addresses of multiple dynamic script files, and the address of each dynamic script file corresponds to a unique dynamic script file. The script file transmission method includes: determining the vulnerability of a controlled host; utilizing the vulnerability of the controlled host to upload multiple dynamic script files to the controlled host; forming an address addition instruction based on the address of each dynamic script file; and sending the address addition instruction to the tunnel proxy plug-in of the client, so that the tunnel proxy plug-in of the client adds the address of the dynamic script file in the address library according to the address addition instruction.

[0010] In a possible implementation, the method of uploading multiple dynamic script files to the controlled host by exploiting the vulnerability of the controlled host specifically includes: determining whether the controlled host meets a preset condition; if the preset condition is met, uploading multiple dynamic script files to the controlled host by exploiting the vulnerability of the controlled host.

[0011] In a possible implementation, determining whether the controlled host meets the preset conditions specifically includes: if the number of dynamic script files in the controlled host is less than a preset number threshold, determining that the controlled host meets the preset conditions; if the number of dynamic script files in the controlled host is not less than the preset number threshold, determining whether the time from the last upload of a dynamic script file exceeds a preset time threshold; if the time from the last upload of a dynamic script file exceeds the preset time threshold, determining that the controlled host meets the preset conditions.

[0012] In a third aspect, an embodiment of the present application provides a security testing device, which is a tunnel proxy plug-in for a client, wherein an address library is configured in the client, wherein the address library contains addresses of multiple dynamic script files, wherein the address of each dynamic script file corresponds to a unique dynamic script file, and the dynamic script file is located in a controlled host, and the controlled host is controlled by the client. The security testing device includes: an instruction receiving module, which is used to receive data instructions; an address determination module, which is used to determine the address of a target dynamic script file in the address library if the data instruction is a data transmission instruction, wherein the target dynamic script file is a dynamic script file to be sent and is located in the target controlled host; an instruction sending module, which is used to send the data transmission instruction to the target dynamic script file according to the address of the target dynamic script file; and a file reconnection module, which is used to re-determine the address of the target dynamic script file if the data transmission instruction fails to be sent until it is successfully sent.

[0013] In a possible implementation, the address determination module specifically includes: an address capture submodule, used to randomly capture the address of a dynamic script file in the address library; and an address determination submodule, used to determine the address of the dynamic script file as the address of the target dynamic script file.

[0014] In a possible implementation, there are multiple controlled hosts, and the addresses of the controlled hosts and the addresses of the corresponding dynamic script files are stored in association in the address library, the address of the corresponding dynamic script file is the address of the dynamic script file located on the controlled host, and the data transmission instruction includes the address of the target controlled host. The address capture submodule specifically includes: an associated address unit, which is used to determine the address of the dynamic script file stored in association with the address of the target controlled host according to the address of the target controlled host; and a random address unit, which is used to randomly capture the address of a dynamic script file from the addresses of the dynamic script file stored in association with the address of the target controlled host.

[0015] In a possible implementation, the security testing device further includes: if the data instruction is an address deletion instruction, reading the address to be deleted contained in the address deletion instruction, the address to be deleted being the address of the dynamic script file to be deleted; and deleting the address to be deleted in the address library.

[0016] In a possible implementation, the security testing device further includes: if the data instruction is an address increase instruction, reading the address to be added contained in the address increase instruction, the address to be added is the address of the dynamic script file to be added; and adding the address to be added in the address library.

[0017] In a fourth aspect, an embodiment of the present application provides a script file transmission device, which is applied to a vulnerability management plug-in of a client, wherein an address library is configured in the client, and the address library contains addresses of multiple dynamic script files, and the address of each dynamic script file corresponds to a unique dynamic script file. The security testing device includes: a vulnerability determination module, which is used to determine the vulnerability of the controlled host; a file upload module, which is used to upload multiple dynamic script files to the controlled host by exploiting the vulnerability of the controlled host; an instruction formation module, which is used to form an address addition instruction according to the address of each dynamic script file; and an instruction sending module, which is used to send the address addition instruction to the tunnel proxy plug-in of the client, so that the tunnel proxy plug-in of the client adds the address of the dynamic script file in the address library according to the address addition instruction.

[0018] In a possible implementation, the file upload module specifically includes: a condition determination submodule, used to determine whether the controlled host meets preset conditions; and a file upload submodule, used to exploit the vulnerability of the controlled host and upload multiple dynamic script files to the controlled host if the preset conditions are met.

[0019] In a possible implementation, the condition determination submodule specifically includes: a first judgment unit, used to determine that the controlled host meets the preset condition if the number of dynamic script files in the controlled host is less than a preset number threshold; a second judgment unit, used to determine whether the time from the last upload of a dynamic script file exceeds a preset time threshold if the number of dynamic script files in the controlled host is not less than the preset number threshold; a third judgment unit, used to determine that the controlled host meets the preset condition if the time from the last upload of a dynamic script file exceeds a preset time threshold.

[0020] In a fifth aspect, an embodiment of the present application provides a client, which includes: a security testing device and a script file transmission device; wherein the security testing device is the security testing device as described above, and the script file transmission device is the script file transmission device as described above.

[0021] In a sixth aspect, an embodiment of the present application provides a client, comprising: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded and executed by the processor: receiving a data instruction; if the data instruction is a data transmission instruction, determining the address of a target dynamic script file in an address library; according to the address of the target dynamic script file, sending the data transmission instruction to the target dynamic script file; if the data transmission instruction fails to be sent, re-determining the address of the target dynamic script file until it is sent successfully.

[0022] In a possible implementation, when the processor determines the address of the target dynamic script file in the address library, the processor specifically executes: randomly grabbing the address of a dynamic script file in the address library; and determining the address of the dynamic script file as the address of the target dynamic script file.

[0023] In a possible implementation, there are multiple controlled hosts, and the addresses of the controlled hosts and the addresses of the corresponding dynamic script files are stored in association in the address library, the address of the corresponding dynamic script file is the address of the dynamic script file located on the controlled host, and the data transmission instruction includes the address of the target controlled host. When the processor randomly grabs the address of a dynamic script file in the address library, it specifically executes: according to the address of the target controlled host, determine the address of the dynamic script file stored in association with the address of the target controlled host; and randomly grab the address of a dynamic script file from the addresses of the dynamic script file stored in association with the address of the target controlled host.

[0024] In a possible implementation, after receiving the data instruction, the processor is further used to execute: if the data instruction is an address deletion instruction, read the address to be deleted contained in the address deletion instruction, where the address to be deleted is the address of the dynamic script file to be deleted; and delete the address to be deleted in the address library.

[0025] In a possible implementation, after receiving the data instruction, the processor is further used to execute: if the data instruction is an address increase instruction, read the address to be added contained in the address increase instruction, and the address to be added is the address of the dynamic script file to be added; and add the address to be added in the address library.

[0026] In one possible implementation, the processor is also used to execute: determining a vulnerability of a controlled host; utilizing the vulnerability of the controlled host to upload multiple dynamic script files to the controlled host; forming an address increase instruction based on the address of each of the dynamic script files; and sending the address increase instruction to the tunnel proxy plug-in of the client, so that the tunnel proxy plug-in of the client adds the address of the dynamic script file in the address library according to the address increase instruction.

[0027] In a possible implementation, when the processor exploits a vulnerability of the controlled host to upload multiple dynamic script files to the controlled host, the processor specifically performs: determining whether the controlled host meets a preset condition; if the preset condition is met, exploiting the vulnerability of the controlled host to upload multiple dynamic script files to the controlled host.

[0028] In one possible implementation, when the processor determines whether the controlled host meets the preset conditions, it specifically performs the following steps: if the number of dynamic script files in the controlled host is less than a preset number threshold, it determines that the controlled host meets the preset conditions; if the number of dynamic script files in the controlled host is not less than the preset number threshold, it determines whether the time since the last upload of a dynamic script file exceeds a preset time threshold; if the time since the last upload of a dynamic script file exceeds the preset time threshold, it determines that the controlled host meets the preset conditions.

[0029] In the seventh aspect, an embodiment of the present application provides a computer storage medium, which stores multiple instructions, and the instructions are suitable for being loaded by a processor and executing the method steps provided by the first aspect of the embodiment of the present application or any one of the implementations of the first aspect.

[0030] In an eighth aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when executed on a computer or a processor, enables the above-mentioned computer or processor to execute the encoding method provided by the first aspect of the embodiment of the present application or any possible implementation of the first aspect.

[0031] In the embodiment of the present application, by establishing a connection with multiple dynamic script files in the controlled host, when transmitting data to the controlled host, an address of a dynamic script file is selected in the address library, and then the data is transmitted to the dynamic script file. If the transmission fails, the address of the dynamic script file is reselected in the address library, and the dynamic script file is transmitted to it until the transmission is successful, so as to ensure that even if a dynamic script file loses contact, it can still contact the controlled device, thereby solving the problem that the client can easily lose contact with the dynamic script file, resulting in the forced interruption of the security test.

[0032] It can be understood that the script file transmission method provided in the second aspect and the script file transmission device provided in the fourth aspect are method items of another execution subject corresponding to the security testing method provided in the first aspect. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the security testing method provided in the first aspect, and will not be repeated here.

[0033] The security testing device provided in the third aspect, the client provided in the fifth aspect, the client provided in the sixth aspect, the computer storage medium provided in the seventh aspect, and the computer program product provided in the eighth aspect are all used to execute the security testing method provided in the first aspect. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the security testing method provided in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0035] Figure 1 An exemplary implementation environment diagram is shown to which the technical solution of the embodiments of the present application can be applied.

[0036] Figure 2 A flow chart of a safety testing method provided in an embodiment of the present application is shown.

[0037] Figure 3 A structural diagram of a data transmission instruction provided in an embodiment of the present application is shown.

[0038] Figure 4 A schematic diagram of the structure of an address increase instruction provided in an embodiment of the present application is shown.

[0039] Figure 5 A schematic diagram of the structure of an address deletion instruction provided in an embodiment of the present application is shown.

[0040] Figure 6 Shown according to Figure 2 A specific implementation flow chart of step S200 in the safety testing method shown in the corresponding embodiment.

[0041] Figure 7 A flow chart of a script file transmission method provided in an embodiment of the present application is shown.

[0042] Figure 8 Shown according to Figure 7A specific implementation flow chart of step S600 in the script file transmission method shown in the corresponding embodiment.

[0043] Fig. 9 A schematic structural diagram of a safety testing device provided in an embodiment of the present application is shown.

[0044] Fig.10 A schematic diagram of the structure of a script file transmission device provided in an embodiment of the present application is shown.

[0045] Fig.11 A schematic diagram of the structure of a client provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0046] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.

[0047] The terms "first", "second", "third", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices.

[0048] Figure 1 FIG. 1 is an implementation environment diagram of a file audit method provided in an embodiment, such as Figure 1 As shown, in this implementation environment, a client 100 and a controlled host 200 are included.

[0049] The client 100 is a client used by the user to control the controlled host 200, such as a personal computer, a mobile phone, and a tablet computer. The controlled host 200 is a host device controlled by the client 100. The controlled host 200 stores multiple dynamic script files, which are uploaded to the controlled host by the client 100. The client 100 is configured with an address library, which contains addresses of multiple dynamic script files, and the address of each dynamic script file corresponds to a unique dynamic script file located in the controlled host 200. The client 100 is installed with a tunnel proxy plug-in 110 and a vulnerability management plug-in 120.

[0050] After the user determines the vulnerability of the controlled host 200 through the vulnerability management plug-in 120, the user uses the vulnerability of the controlled host 200 to upload multiple dynamic script files to the controlled host 200, and then generates an address addition instruction based on the address of each dynamic script file and sends it to the tunnel proxy plug-in 110. The tunnel proxy plug-in 110 adds the address of the above dynamic script file to the address library according to the address addition instruction.

[0051] The user also sends data instructions to the tunnel proxy plug-in 110 through the vulnerability management plug-in 120. The tunnel proxy plug-in 110 first determines the type of the data instruction. If it is a data transmission instruction, it determines the address of the target dynamic script file in the address library, and then sends the data transmission instruction to the target dynamic script file located on the controlled host 200 based on the address of the target dynamic script file. If the data transmission instruction fails to be sent this time, the address of the target dynamic script file is re-determined and the instruction is sent until it is sent successfully.

[0052] It should be noted that the client 100 and the controlled host 200 can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc., but are not limited thereto. The client 100 and the controlled host 200 can be connected via Bluetooth, USB (Universal Serial Bus) or other communication connection methods, and the present invention does not limit this.

[0053] The implementation details of the technical solution of the embodiment of the present application are described in detail below:

[0054] Figure 2 A flowchart of a security testing method according to an embodiment of the present application is shown. The security testing method can be performed by a tunnel proxy plug-in. The tunnel proxy plug-in can be Figure 1 The tunnel proxy plug-in 110 of the client 100 shown in FIG. Figure 2 As shown, the safety testing method at least includes:

[0055] Step S100, receiving a data instruction.

[0056] Step S200: If the data instruction is a data transmission instruction, the address of the target dynamic script file is determined in the address library.

[0057] Step S300: sending the data transmission instruction to the target dynamic script file according to the address of the target dynamic script file.

[0058] Step S400: If the data transmission instruction fails to be sent, the address of the target dynamic script file is re-determined until it is sent successfully.

[0059] In an embodiment of the present application, during the test process, the user can control the tunnel proxy plug-in by sending various data instructions to the tunnel proxy plug-in 110 in the client 100. When it is necessary to control the controlled host 200 for security testing, a data transmission instruction can be sent to the tunnel proxy plug-in 110. After the tunnel proxy plug-in 110 receives the data instruction and determines that the data instruction is a data transmission instruction, it determines the address of the target dynamic script file in the address library, and then sends the data transmission instruction to the target dynamic script file according to the address of the target dynamic script file. If the sending fails, it proves that the target dynamic script file has lost contact. At this time, a new target dynamic script file is determined, and the address of the new target dynamic script file is determined in the address library. The data transmission instruction is sent to the new target dynamic script file until the sending is successful, so as to ensure that even if a dynamic script file loses contact, it can still contact the controlled device, thereby solving the problem that the client can easily lose contact with the dynamic script file. The problem of forced interruption of security testing is caused.

[0060] In step S100 , the data instructions include three types: data transmission instructions, address deletion instructions, and address addition instructions.

[0061] After receiving the data transmission instruction, the tunnel proxy plug-in 110 analyzes and determines the data instruction. If the data instruction is a data transmission instruction, step S200 is executed; if the data instruction is an address deletion instruction, the corresponding address deletion step is executed; if the data instruction is an address addition instruction, the corresponding address addition step is executed.

[0062] The specific steps of analyzing and judging the data instructions may include:

[0063] If the instruction indicator bit of the data instruction is the first indicator value, the indicator bit is a data transmission instruction.

[0064] If the instruction indicator bit of the data instruction is the second indicator value, the indicator bit is an address deletion instruction.

[0065] If the instruction indicator bit of the data instruction is the third indicator value, the indicator bit is an address increase instruction.

[0066] In this embodiment, if Figures 3 to 5 As shown, the data instruction includes an instruction indicator 101 located at the end of the instruction and data content 102 following the indicator.

[0067] The instruction indication bits 101 of the data transmission instruction, the address deletion instruction, and the address increase instruction are all different. The tunnel proxy plug-in 110 can determine the specific type of the data instruction through the instruction indication bit 101. For example, in one embodiment, the instruction indication bit 101 of the data transmission instruction is \x05, the instruction indication bit 101 of the address deletion instruction is \x67, and the instruction indication bit 101 of the address increase instruction is \x66.

[0068] The data content 102 following the indicator bit includes a data bit 103 and a content value 104. In this embodiment, the data bit 103 is located between the instruction indicator bit 101 and the content value 104. The data bit 103 of the data transmission instruction is used to indicate how many methods can be used, and the content value 104 is the specific method value. The data bit 103 of the address deletion instruction and the address addition instruction is used to indicate the address length of the dynamic script file to be added or deleted, and the content value 104 is the specific dynamic script file to be added or deleted.

[0069] In some embodiments, after step S100, the method further includes:

[0070] If the data instruction is an address deletion instruction, the address to be deleted contained in the address deletion instruction is read, and the address to be deleted is the address of the dynamic script file to be deleted.

[0071] The address to be deleted is deleted from the address database.

[0072] In this embodiment, the data instruction is an address deletion instruction. At this time, the address deletion step is executed. The address of the dynamic script file to be deleted contained in the address deletion instruction, that is, the address to be deleted, is first read, and then the address to be deleted is deleted from the address library.

[0073] When a user deletes a dynamic script file located in a controlled host through the vulnerability management plug-in 120, or when the user completes testing of a dynamic script file located in a controlled host, the vulnerability management plug-in 120 will package the address of the dynamic script file and send the address addition instruction to the tunnel proxy plug-in 120, so that the tunnel proxy plug-in 120 can perform the above-mentioned address deletion step and delete the address of the dynamic script file from the address library to ensure real-time updating of the address library and avoid selecting the address of the corresponding dynamic script file in step S200, thereby improving data processing efficiency.

[0074] In some embodiments, after step S100, the method further includes:

[0075] If the data instruction is an address adding instruction, the address to be added contained in the address adding instruction is read, and the address to be added is the address of the dynamic script file to be added.

[0076] Add the address to be added to the address library.

[0077] In this embodiment, the data instruction is an address increase instruction. At this time, the address increase step is executed. The address of the dynamic script file to be added contained in the address increase instruction, that is, the address to be added, is first read, and then the address to be added is added to the address library.

[0078] Whenever the vulnerability management plug-in 120 exploits a vulnerability to upload a dynamic script file to the controlled host 200, the address of the dynamic script file is packaged into an address addition instruction and sent to the tunnel proxy plug-in 120 so that the tunnel proxy plug-in 120 executes the above-mentioned address addition step and adds the address of the dynamic script file to the address library.

[0079] In step S200, an address library is configured in the client 100, which includes addresses of multiple dynamic script files, each address of a dynamic script file corresponds to a unique dynamic script file. Each dynamic script file is located in the controlled host 200, and the controlled host 200 is controlled by the client.

[0080] There are many specific ways to determine the address of the target dynamic script file in the address library, such as randomly grabbing the address, sequentially grabbing the address, and determining the address according to the frequency of use.

[0081] Specifically, in some embodiments, the specific implementation of step S200 can be found in Figure 6 . Figure 6 is based on Figure 2 The detailed description of step S200 in the safety testing method shown in the corresponding embodiment, in the safety testing method, step S200 may include the following steps:

[0082] Step S210, randomly grabbing the address of a dynamic script file in the address library.

[0083] Step S220: determining the address of the dynamic script file as the address of the target dynamic script file.

[0084] In the embodiment of the present application, the address of the target dynamic script file is determined by randomly grabbing the address. Specifically, the address of a dynamic script file is first randomly grabbed in the address library, and then the address of the dynamic script file is determined as the address of the target dynamic script file.

[0085] In step S210, there are many ways to randomly grab the address of the dynamic script file, and the details can be referred to the following embodiments.

[0086] Specifically, in some embodiments, the specific implementation of step S210 can refer to this embodiment. Figure 6 Detailed description of step S210 in the security testing method shown in the corresponding embodiment. In the security testing method, there are multiple controlled hosts, the addresses of the controlled hosts in the address library are associated with the addresses of the corresponding dynamic script files and stored, the addresses of the corresponding dynamic script files are the addresses of the dynamic script files located on the controlled hosts, and the data transmission instruction includes the address of the target controlled host. Step S210 may include the following steps:

[0087] According to the address of the target controlled host, the address of the dynamic script file stored in association with the address of the target controlled host is determined.

[0088] The address of a dynamic script file is randomly captured from the addresses of the dynamic script files stored in association with the address of the target controlled host.

[0089] In this embodiment, there are multiple controlled hosts, so in addition to the address of the dynamic script file, the address library also stores the address of each controlled host. The address of each controlled host is managed and stored in the address library separately from the address of the dynamic script file located on the controlled host. The data transmission instruction sent by the vulnerability management module includes the address of the target controlled host. At this time, before random capture, it is necessary to first capture the address of the dynamic script file located on the target controlled host according to the address of the target controlled host, that is, the address of the dynamic script file stored in association with the address of the target controlled host, to form a pre-selected address set, and then randomly capture the address of a dynamic script file in the pre-selected address set.

[0090] In other embodiments, the address of the target dynamic script file may also be determined according to the usage frequency of the dynamic script file. In this embodiment, the steps of step S200 may specifically include:

[0091] The score of each dynamic script file is determined according to the usage frequency of each dynamic script file.

[0092] The address of the dynamic script file with the highest score is captured in the address library as the address of the target dynamic script file.

[0093] Specifically, the way to determine the score of each dynamic script file may be that if the usage frequency of the dynamic script file is greater than a first predetermined frequency threshold, the dynamic script file is assigned a first score; if the usage frequency of the dynamic script file is less than a second predetermined frequency threshold, the dynamic script file is assigned a second score; if the usage frequency of the dynamic script file is between the first predetermined frequency threshold and the second predetermined frequency threshold, the dynamic script file is assigned a third score. Wherein, the first predetermined frequency threshold is greater than the second predetermined frequency threshold, the first score is less than the second score, and the second score is less than the third score.

[0094] In other embodiments, the way to determine the score of each dynamic script file may also be that if the usage frequency of the dynamic script file is greater than the first predetermined frequency threshold, the first score is assigned to the dynamic script file; if the usage frequency of the dynamic script file is less than the second predetermined frequency threshold, the number of dynamic script files within the range is counted to obtain a first number; if the usage frequency of the dynamic script file is within the first predetermined frequency threshold and the second predetermined frequency threshold, the number of dynamic script files within the range is counted to obtain a second number; if the first number is less than the second number, the second score is assigned to the dynamic script file whose usage frequency is less than the second predetermined frequency threshold, and the third score is assigned to the dynamic script file whose usage frequency is between the first predetermined frequency threshold and the second predetermined frequency threshold; if the first number is greater than the second number, the third score is assigned to the dynamic script file whose usage frequency is less than the second predetermined frequency threshold, and the second score is assigned to the dynamic script file whose usage frequency is between the first predetermined frequency threshold and the second predetermined frequency threshold. Wherein, the first predetermined frequency threshold is greater than the second predetermined frequency threshold, the first score is less than the second score, and the second score is less than the third score.

[0095] In step S300, after determining the address of the target dynamic script file, the data transmission instruction can be sent to the target dynamic script file located in the controlled host 200 according to the address of the target dynamic script file. If the instruction is sent successfully, wait for the next instruction, if the instruction fails to send, execute step S400.

[0096] In step S400, when the data transmission instruction fails to be sent, the address of the target dynamic script file is re-determined, and the data transmission instruction is sent according to the new address of the target dynamic script file until it is successfully sent. At the same time, the address of the dynamic script file that failed to be sent is deleted from the address library to avoid being determined as the address of the target dynamic script file during subsequent instruction transmission, which prolongs the data transmission cycle and reduces the data transmission efficiency.

[0097] Figure 7 A flowchart of a script file transmission method according to an embodiment of the present application is shown. The script file transmission method can be executed by a vulnerability management plug-in. The vulnerability management plug-in can be Figure 7 The vulnerability management plug-in 120 of the client 100 shown in FIG. Figure 2 As shown, the safety testing method at least includes:

[0098] Step S500, determining the vulnerability of the controlled host.

[0099] Step S600, utilizing the vulnerability of the controlled host to upload multiple dynamic script files to the controlled host.

[0100] Step S700: generating an address adding instruction according to the address of each of the dynamic script files.

[0101] Step S800: Send the address adding instruction to the tunnel proxy plug-in of the client, so that the tunnel proxy plug-in of the client adds the address of the dynamic script file in the address library according to the address adding instruction.

[0102] In an embodiment of the present application, the vulnerability management plug-in 120 first determines the vulnerability of the controlled host 200, and then uses the vulnerability to upload multiple dynamic script files to the controlled host 200, and then forms an address increase instruction according to the address of each of the dynamic script files, and an address increase instruction only contains the address of one dynamic script file. Finally, the address increase instruction is sent to the tunnel proxy plug-in 110, so that the tunnel proxy plug-in 110 increases the address of the dynamic script file in the address library according to the address increase instruction. Upload multiple dynamic script files to the controlled host 200 and record the address correspondence in the database, so that during the data transmission process, the client 100 can transmit information with the client through multiple dynamic script files, reduce the risk of disconnection between it and the controlled host 200, and improve the stability of the connection.

[0103] In step S500, the controlled host is scanned to determine the vulnerability of the controlled host. After the vulnerability of the controlled host is obtained, step S600 is executed.

[0104] In step S600, there are many ways to upload multiple dynamic script files to the controlled host by taking advantage of the vulnerability of the controlled host. For details, please refer to the following embodiments.

[0105] Specifically, in some embodiments, the specific implementation of step S600 can be found in Figure 8 . Figure 8 is based on Figure 7 The detailed description of step S600 in the script file transmission method shown in the corresponding embodiment, in the security testing method, step S600 may include the following steps:

[0106] Step S610, determining whether the controlled host meets a preset condition.

[0107] Step S620: if the preset conditions are met, a vulnerability of the controlled host is exploited to upload multiple dynamic script files to the controlled host.

[0108] In the embodiment of the present application, it is first determined whether the controlled host 200 meets the preset conditions, and if the preset conditions are met, multiple dynamic script files are uploaded to the controlled host 200. That is, in this embodiment, the uploading of dynamic script files is not one-time, and a batch of dynamic script files can be uploaded at intervals to avoid the situation where the first batch of dynamic script files uploaded are all lost.

[0109] In step S610, the preset condition setting may have multiple situations. For example, in one embodiment, the preset condition may be that after the address of a dynamic script file in the address library is deleted, that is, whenever the address of a dynamic script file in the address library is deleted, a new dynamic script file is added to the controlled host 200 to ensure that there is a dynamic script file that can be contacted. Further, in step S200, the address of the newly uploaded dynamic script file may be used as the target script file address to save time in determining the target script file address and improve data transmission efficiency.

[0110] Specifically, in other embodiments, the specific implementation of step S610 can refer to this embodiment. Figure 8 The detailed description of step S610 in the script file transmission method shown in the corresponding embodiment, in the security testing method, step S610 may include the following steps:

[0111] If the number of dynamic script files in the controlled host is less than a preset number threshold, determining that the controlled host meets the preset condition;

[0112] If the number of dynamic script files in the controlled host is not less than a preset number threshold, determining whether the time since the last upload of a dynamic script file exceeds a preset time threshold;

[0113] If the time from the last upload of the dynamic script file exceeds the predetermined time threshold, it is determined that the controlled host meets the preset condition.

[0114] In the present embodiment, the preset condition is whether the number of dynamic script files in the controlled host 200 is less than the preset number threshold and whether the time of uploading the dynamic script file exceeds the predetermined time threshold. When the number of dynamic script files in the controlled host 200 is less than the preset number threshold, it is proved that the dynamic script files in the controlled host 200 are insufficient, and the client 100 and the controlled host 200 have the risk of disconnection. At this time, the dynamic script file should be uploaded to avoid the failure of the safety test termination. After the dynamic script file has not been uploaded for a long time, the risk of all dynamic script files being disconnected is relatively large. At this time, it is necessary to upload the dynamic script file. Because the risk of disconnection caused by the small number of dynamic script files is greater than that of not uploading the dynamic script file for a long time, it is more conducive to avoiding risks and ensuring the security of data transmission to first judge the number of dynamic script files.

[0115] In other embodiments, it may also be possible to first determine whether no dynamic script files have been uploaded for a long time, and then determine the number of dynamic script files.

[0116] In step S620, after the preset conditions are met, the vulnerability of the controlled host 200 is exploited to upload multiple dynamic script files to the controlled host 200. Confirming whether the upload conditions are met before uploading is conducive to improving the success rate of uploading.

[0117] In step S700, each time a dynamic script file is uploaded to the controlled host 200, an address adding instruction is generated, and the address adding instruction includes the address of the dynamic script file. Then, step S800 is executed to send the address adding instruction to the tunnel proxy plug-in 110, and the tunnel proxy plug-in 110 adds the address of the dynamic script file in the address library according to the address adding instruction.

[0118] Fig. 9 The following is a schematic diagram showing the structure of a safety testing device provided in an embodiment of the present application. Fig. 9 As shown, the security testing device 900 is used for a tunnel proxy plug-in of a client, the client is configured with an address library, the address library contains addresses of multiple dynamic script files, each address of a dynamic script file corresponds to a unique dynamic script file, the dynamic script file is located in a controlled host, the controlled host is controlled by the client, and the security testing device 900 includes:

[0119] The instruction receiving module 910 is used to receive data instructions.

[0120] The address determination module 920 is used to determine the address of the target dynamic script file in the address library if the data instruction is a data transmission instruction. The target dynamic script file is a dynamic script file to be sent to and is located in the target controlled host.

[0121] The instruction sending module 930 is used to send the data transmission instruction to the target dynamic script file according to the address of the target dynamic script file.

[0122] The file reconnection module 940 is used to re-determine the address of the target dynamic script file if the data transmission instruction fails to be sent, until the sending is successful.

[0123] In a possible implementation, the address determination module 920 specifically includes: an address capture submodule, used to randomly capture the address of a dynamic script file in the address library; and an address determination submodule, used to determine the address of the dynamic script file as the address of the target dynamic script file.

[0124] In a possible implementation, there are multiple controlled hosts, and the addresses of the controlled hosts and the addresses of the corresponding dynamic script files are stored in association in the address library, the address of the corresponding dynamic script file is the address of the dynamic script file located on the controlled host, and the data transmission instruction includes the address of the target controlled host. The address capture submodule specifically includes: an associated address unit, which is used to determine the address of the dynamic script file stored in association with the address of the target controlled host according to the address of the target controlled host; and a random address unit, which is used to randomly capture the address of a dynamic script file from the addresses of the dynamic script file stored in association with the address of the target controlled host.

[0125] In a possible implementation, the security testing device 900 further includes: if the data instruction is an address deletion instruction, reading the address to be deleted contained in the address deletion instruction, where the address to be deleted is the address of the dynamic script file to be deleted; and deleting the address to be deleted in the address library.

[0126] In a possible implementation, the security testing device 900 further includes: if the data instruction is an address increase instruction, reading the address to be added contained in the address increase instruction, wherein the address to be added is the address of the dynamic script file to be added; and adding the address to be added in the address library.

[0127] In the embodiment of the present application, by establishing a connection with multiple dynamic script files in the controlled host, when transmitting data to the controlled host, an address of a dynamic script file is selected in the address library, and then the data is transmitted to the dynamic script file. If the transmission fails, the address of the dynamic script file is reselected in the address library, and the dynamic script file is transmitted to it until the transmission is successful, so as to ensure that even if a dynamic script file loses contact, it can still contact the controlled device, thereby solving the problem that the client can easily lose contact with the dynamic script file, resulting in the forced interruption of the security test.

[0128] Fig.10 The following is a schematic diagram showing the structure of a script file transmission device provided in an embodiment of the present application. Fig.10 As shown, the script file transmission device 1000 is applied to the vulnerability management plug-in 120 of the client 100. The client 100 is configured with an address library, which contains addresses of multiple dynamic script files. The address of each dynamic script file corresponds to a unique dynamic script file. The security testing device 1000 includes:

[0129] The vulnerability determination module 1010 is used to determine the vulnerabilities of the controlled host.

[0130] The file upload module 1020 is used to upload multiple dynamic script files to the controlled host by taking advantage of the vulnerability of the controlled host.

[0131] The instruction forming module 1030 is used to form an address adding instruction according to the address of each dynamic script file.

[0132] The instruction sending module 1040 is used to send the address adding instruction to the tunnel proxy plug-in of the client, so that the tunnel proxy plug-in of the client adds the address of the dynamic script file in the address library according to the address adding instruction.

[0133] In a possible implementation, the file upload module 1020 specifically includes: a condition determination submodule, used to determine whether the controlled host meets the preset conditions; and a file upload submodule, used to exploit the vulnerability of the controlled host and upload multiple dynamic script files to the controlled host if the preset conditions are met.

[0134] In a possible implementation, the condition determination submodule specifically includes: a first judgment unit, used to determine that the controlled host meets the preset condition if the number of dynamic script files in the controlled host is less than a preset number threshold; a second judgment unit, used to determine whether the time from the last upload of a dynamic script file exceeds a preset time threshold if the number of dynamic script files in the controlled host is not less than the preset number threshold; a third judgment unit, used to determine that the controlled host meets the preset condition if the time from the last upload of a dynamic script file exceeds a preset time threshold.

[0135] In an embodiment of the present application, the vulnerability management plug-in 120 first determines the vulnerability of the controlled host 200, and then uses the vulnerability to upload multiple dynamic script files to the controlled host 200, and then forms an address increase instruction according to the address of each of the dynamic script files, and an address increase instruction only contains the address of one dynamic script file. Finally, the address increase instruction is sent to the tunnel proxy plug-in 110, so that the tunnel proxy plug-in 110 increases the address of the dynamic script file in the address library according to the address increase instruction. Upload multiple dynamic script files to the controlled host 200 and record the address correspondence in the database, so that during the data transmission process, the client 100 can transmit information with the client through multiple dynamic script files, reduce the risk of disconnection between it and the controlled host 200, and improve the stability of the connection.

[0136] In some embodiments of the present application, the client 100 includes the above-mentioned security testing device 900 and the script file transmission device 1000.

[0137] It should be noted that when the security testing device provided in the above embodiment executes the security testing method and the script file transmission device provided in the above embodiment executes the script file transmission method, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the wireless screen projection connection device and the wireless screen projection connection method embodiment provided in the above embodiment belong to the same concept, and the implementation process thereof is detailed in the method embodiment, which will not be repeated here.

[0138] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0139] See also Fig.11 , is a schematic diagram of the structure of a safety testing device provided in an embodiment of the present application. Fig.11 As shown, the client 1100 may include: at least one processor 1101 , at least one network interface 1104 , a user interface 1103 , a memory 1105 , and at least one communication bus 1102 .

[0140] The communication bus 1102 is used to realize the connection and communication between these components.

[0141] The user interface 1103 may include a display screen (Display) and a camera (Camera), and the optional user interface 1103 may also include a standard wired interface and a wireless interface.

[0142] The network interface 1104 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).

[0143] Among them, the processor 1101 may include one or more processing cores. The processor 1101 uses various interfaces and lines to connect various parts within the entire client 1100, and executes various functions and processes data of the electronic device 110 by running or executing instructions, programs, code sets or instruction sets stored in the memory 1105, and calling data stored in the memory 1105. Optionally, the processor 1101 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 1101 can integrate one or a combination of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU) and a modem. Among them, the CPU mainly processes the operating system, user interface and application programs; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 1101, and it can be implemented separately through a chip.

[0144] Among them, the memory 1105 may include a random access memory (Random Access Memory, RAM) and may also include a read-only memory (Read-Only Memory). Optionally, the memory 1105 includes a non-transitory computer-readable storage medium. The memory 1105 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 1105 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 1105 may also be optionally at least one storage device located away from the aforementioned processor 1101. As Fig.11 As shown, the memory 1105 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a security testing application.

[0145] exist Fig.11In the client 1100 shown, the user interface 1103 is mainly used to provide an input interface for the user and obtain the data input by the user; and the processor 1101 can be used to call the security testing application stored in the memory 1105, and perform the following operations: receive a data instruction; if the data instruction is a data transmission instruction, determine the address of the target dynamic script file in the address library; according to the address of the target dynamic script file, send the data transmission instruction to the target dynamic script file; if the data transmission instruction fails to be sent, redetermine the address of the target dynamic script file until it is sent successfully.

[0146] In a possible implementation, when the processor determines the address of the target dynamic script file in the address library, the processor specifically executes: randomly grabbing the address of a dynamic script file in the address library; and determining the address of the dynamic script file as the address of the target dynamic script file.

[0147] In a possible implementation, there are multiple controlled hosts, and the addresses of the controlled hosts and the addresses of the corresponding dynamic script files are stored in association in the address library, the address of the corresponding dynamic script file is the address of the dynamic script file located on the controlled host, and the data transmission instruction includes the address of the target controlled host. When the processor randomly grabs the address of a dynamic script file in the address library, it specifically executes: according to the address of the target controlled host, determine the address of the dynamic script file stored in association with the address of the target controlled host; and randomly grab the address of a dynamic script file from the addresses of the dynamic script file stored in association with the address of the target controlled host.

[0148] In a possible implementation, after receiving the data instruction, the processor is further used to execute: if the data instruction is an address deletion instruction, read the address to be deleted contained in the address deletion instruction, where the address to be deleted is the address of the dynamic script file to be deleted; and delete the address to be deleted in the address library.

[0149] In a possible implementation, after receiving the data instruction, the processor is further used to execute: if the data instruction is an address increase instruction, read the address to be added contained in the address increase instruction, and the address to be added is the address of the dynamic script file to be added; and add the address to be added in the address library.

[0150] In one possible implementation, the processor is also used to execute: determining a vulnerability of a controlled host; utilizing the vulnerability of the controlled host to upload multiple dynamic script files to the controlled host; forming an address increase instruction based on the address of each of the dynamic script files; and sending the address increase instruction to the tunnel proxy plug-in of the client, so that the tunnel proxy plug-in of the client adds the address of the dynamic script file in the address library according to the address increase instruction.

[0151] In a possible implementation, when the processor exploits a vulnerability of the controlled host to upload multiple dynamic script files to the controlled host, the processor specifically performs: determining whether the controlled host meets a preset condition; if the preset condition is met, exploiting the vulnerability of the controlled host to upload multiple dynamic script files to the controlled host.

[0152] In one possible implementation, when the processor determines whether the controlled host meets the preset conditions, it specifically performs the following steps: if the number of dynamic script files in the controlled host is less than a preset number threshold, it determines that the controlled host meets the preset conditions; if the number of dynamic script files in the controlled host is not less than the preset number threshold, it determines whether the time since the last upload of a dynamic script file exceeds a preset time threshold; if the time since the last upload of a dynamic script file exceeds the preset time threshold, it determines that the controlled host meets the preset conditions.

[0153] In the embodiment of the present application, by establishing a connection with multiple dynamic script files in the controlled host, when transmitting data to the controlled host, an address of a dynamic script file is selected in the address library, and then the data is transmitted to the dynamic script file. If the transmission fails, the address of the dynamic script file is reselected in the address library, and the dynamic script file is transmitted to it until the transmission is successful, so as to ensure that even if a dynamic script file loses contact, it can still contact the controlled device, thereby solving the problem that the client can easily lose contact with the dynamic script file, resulting in the forced interruption of the security test.

[0154] In an embodiment of the present application, the vulnerability management plug-in 120 first determines the vulnerability of the controlled host 200, and then uses the vulnerability to upload multiple dynamic script files to the controlled host 200, and then forms an address increase instruction according to the address of each of the dynamic script files, and an address increase instruction only contains the address of one dynamic script file. Finally, the address increase instruction is sent to the tunnel proxy plug-in 110, so that the tunnel proxy plug-in 110 increases the address of the dynamic script file in the address library according to the address increase instruction. Upload multiple dynamic script files to the controlled host 200 and record the address correspondence in the database, so that during the data transmission process, the client 100 can transmit information with the client through multiple dynamic script files, reduce the risk of disconnection between it and the controlled host 200, and improve the stability of the connection.

[0155] The embodiment of the present application also provides a computer-readable storage medium, in which instructions are stored. When the instructions are executed on a computer or a processor, the computer or the processor executes the above-mentioned Figure 2 , Figure 6-Figure 8 One or more steps in the illustrated embodiment. If the various components of the above safety testing device are implemented in the form of software functional units and sold or used as independent products, they can be stored in the computer-readable storage medium.

[0156] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted by the computer-readable storage medium. The computer instructions can be transmitted from a website site, a computer, a server or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server, a data center, etc. that contains one or more available media integrated. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital versatile disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).

[0157] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The aforementioned storage medium includes: various media that can store program codes, such as system memory (Read Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk. In the absence of conflict, the technical features in this embodiment and the implementation scheme can be combined arbitrarily.

[0158] The embodiments described above are merely preferred embodiments of the present application and are not intended to limit the scope of the present application. Without departing from the design spirit of the present application, various modifications and improvements made to the technical solutions of the present application by ordinary technicians in this field should fall within the protection scope determined by the claims of the present application.

Claims

1. A safety testing method, characterized in that: In a tunnel proxy plug-in applied to a client, the client is configured with an address library, the address library contains addresses of multiple dynamic script files, each address of a dynamic script file corresponds to a unique dynamic script file, the dynamic script file is located in a controlled host, and the controlled host is controlled by the client. The security testing method includes: Receive data instructions; If the data instruction is a data transmission instruction, then determining the address of the target dynamic script file in the address library; According to the address of the target dynamic script file, the data transmission instruction is sent to the target dynamic script file; If the data transmission instruction fails to be sent, the address of the target dynamic script file is re-determined until it is sent successfully.

2. The method according to claim 1, characterized in that Determining the address of the target dynamic script file in the address library specifically includes: Randomly grab an address of a dynamic script file in the address library; The address of the dynamic script file is determined as the address of the target dynamic script file.

3. The method according to claim 2, characterized in that There are multiple controlled hosts, the addresses of the controlled hosts and the addresses of the corresponding dynamic script files are stored in association in the address library, the address of the corresponding dynamic script file is the address of the dynamic script file located on the controlled host, the data transmission instruction includes the address of the target controlled host, and the address of a dynamic script file is randomly captured in the address library, specifically including: According to the address of the target controlled host, determining the address of the dynamic script file stored in association with the address of the target controlled host; The address of a dynamic script file is randomly captured from the addresses of the dynamic script files stored in association with the address of the target controlled host.

4. A script file transmission method, characterized in that: In a vulnerability management plug-in applied to a client, the client is configured with an address library, the address library contains addresses of multiple dynamic script files, each address of a dynamic script file corresponds to a unique dynamic script file, and the script file transmission method includes: Identify vulnerabilities of controlled hosts; Exploiting the vulnerability of the controlled host, uploading multiple dynamic script files to the controlled host; According to the address of each of the dynamic script files, an address adding instruction is formed; The address adding instruction is sent to the tunnel proxy plug-in of the client, so that the tunnel proxy plug-in of the client adds the address of the dynamic script file in the address library according to the address adding instruction.

5. The method according to claim 4, characterized in that The method of taking advantage of the vulnerability of the controlled host to upload multiple dynamic script files to the controlled host specifically includes: Determining whether the controlled host meets a preset condition; If the preset conditions are met, the vulnerability of the controlled host is exploited to upload multiple dynamic script files to the controlled host.

6. A safety testing device, characterized in that: A tunnel proxy plug-in applied to a client, wherein the client is configured with an address library, wherein the address library contains addresses of multiple dynamic script files, wherein the address of each dynamic script file corresponds to a unique dynamic script file, wherein the dynamic script file is located in a controlled host, wherein the controlled host is controlled by the client, and wherein the security testing device comprises: An instruction receiving module, used for receiving data instructions; An address determination module, used for determining the address of a target dynamic script file in an address library if the data instruction is a data transmission instruction; An instruction sending module, used for sending the data transmission instruction to the target dynamic script file according to the address of the target dynamic script file; The file reconnection module is used to re-determine the address of the target dynamic script file if the data transmission instruction fails to be sent, until the sending is successful.

7. A script file transmission device, characterized in that: In a vulnerability management plug-in applied to a client, the client is configured with an address library, the address library contains addresses of multiple dynamic script files, each address of a dynamic script file corresponds to a unique dynamic script file, and the security testing device includes: A vulnerability determination module, used to determine the vulnerabilities of the controlled host; A file upload module, used to upload multiple dynamic script files to the controlled host by exploiting the vulnerability of the controlled host; An instruction forming module, used for forming an address adding instruction according to the address of each of the dynamic script files; The instruction sending module is used to send the address adding instruction to the tunnel proxy plug-in of the client, so that the tunnel proxy plug-in of the client adds the address of the dynamic script file in the address library according to the address adding instruction.

8. A client, characterized in that: The client comprises: a security testing device and a script file transmission device; wherein the security testing device is the security testing device described in claim 6, and the script file transmission device is the script file transmission device described in claim 7.

9. A client, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the method steps as claimed in any one of claims 1 to 5.

10. A computer storage medium, characterized in that: The computer storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 5.