justview
JustView is a multi-threaded web vulnerability scanner first released in 2015 by the Chinese researcher known as "LuckyCat". It is an open-source tool hosted on GitHub at github.com/luckycat/JustView, and while intended for legitimate security testing, it is frequently abused by malicious actors for unauthorized scanning and exploitation.
JustView performs automated scans for SQL injection, cross-site scripting (XSS), remote and local file inclusion (RFI/LFI), directory traversal, and server-side request forgery (SSRF). It includes a built-in dictionary for brute-forcing directories and files, and can detect outdated software versions by analyzing HTTP response headers. The scanner supports HTTP/HTTPS proxies, multi-threading for speed, and WAF detection with evasion techniques such as parameter pollution and payload encoding. It also features a plugin system for extending capabilities and can generate detailed reports in HTML format.
In 2018, JustView was implicated in a series of attacks against Chinese e-commerce platforms, where it was used to extract customer data via SQL injection. Analysis of the source code revealed hardcoded C2 server credentials, indicating a potential backdoor. The tool has been referenced in multiple security advisories by Chinese CERTs. No CVEs are directly associated with the scanner itself, but it has been used to exploit known vulnerabilities.
The primary indicator is the user-agent string "JustView/1.0" or "JustView/2.0". Behavioral fingerprints include rapid sequential requests to paths like /admin, /login, /cgi-bin, /wp-admin with SQL keywords in query parameters, high request rate from a single IP, and absence of Referer headers. The scanner often sends requests with unusual Accept headers such as "text/html,application/xhtml+xml".
JustView can lead to complete compromise of vulnerable web applications, including unauthorized database access, data exfiltration, website defacement, and lateral movement within internal networks through LFI/RFI. It is often used as a reconnaissance tool to identify further attack vectors.
Immediate blocking of requests containing the JustView user-agent or matching its behavioral patterns is critical. Web application firewalls (WAFs) and intrusion prevention systems (IPS) should be configured to detect and drop such traffic at the perimeter.
Similar Threats
Free Bot Analysis
Find out exactly how much of your traffic is automated — and which bots are draining your bandwidth and skewing your analytics.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.