2022-09-08 15:57:17 +08:00
|
|
|
package internal
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
2022-11-10 21:03:07 +08:00
|
|
|
"fmt"
|
2022-11-21 20:44:02 +08:00
|
|
|
"github.com/antonmedv/expr"
|
|
|
|
"github.com/antonmedv/expr/vm"
|
2022-09-20 04:01:38 +08:00
|
|
|
"github.com/chainreactors/logs"
|
2022-09-08 17:04:41 +08:00
|
|
|
"github.com/chainreactors/spray/pkg"
|
2022-10-26 18:28:40 +08:00
|
|
|
"github.com/chainreactors/spray/pkg/ihttp"
|
2022-09-15 19:27:07 +08:00
|
|
|
"github.com/chainreactors/words"
|
2022-09-08 15:57:17 +08:00
|
|
|
"github.com/panjf2000/ants/v2"
|
2022-09-23 01:20:01 +08:00
|
|
|
"github.com/valyala/fasthttp"
|
2022-11-29 20:50:00 +08:00
|
|
|
"net/url"
|
2022-11-21 20:44:02 +08:00
|
|
|
"strconv"
|
2022-11-29 20:50:00 +08:00
|
|
|
"strings"
|
2022-09-08 15:57:17 +08:00
|
|
|
"sync"
|
2022-12-11 04:21:42 +08:00
|
|
|
"sync/atomic"
|
2022-09-15 19:27:07 +08:00
|
|
|
"time"
|
2022-09-08 15:57:17 +08:00
|
|
|
)
|
|
|
|
|
|
|
|
var (
|
2022-11-17 17:09:37 +08:00
|
|
|
CheckRedirect func(string) bool
|
2022-09-08 15:57:17 +08:00
|
|
|
)
|
2022-11-17 16:27:44 +08:00
|
|
|
|
2022-11-17 05:40:02 +08:00
|
|
|
var max = 2147483647
|
2022-11-29 21:55:27 +08:00
|
|
|
var maxRedirect = 3
|
2022-12-11 00:24:28 +08:00
|
|
|
var maxRecuDepth = 0
|
2022-09-23 01:47:24 +08:00
|
|
|
|
2022-11-10 21:03:07 +08:00
|
|
|
func NewPool(ctx context.Context, config *pkg.Config) (*Pool, error) {
|
2022-09-19 14:42:29 +08:00
|
|
|
pctx, cancel := context.WithCancel(ctx)
|
2022-09-08 15:57:17 +08:00
|
|
|
pool := &Pool{
|
2022-09-23 01:39:00 +08:00
|
|
|
Config: config,
|
|
|
|
ctx: pctx,
|
2022-09-23 01:47:24 +08:00
|
|
|
cancel: cancel,
|
2022-10-26 18:28:40 +08:00
|
|
|
client: ihttp.NewClient(config.Thread, 2, config.ClientType),
|
2022-11-10 21:03:07 +08:00
|
|
|
baselines: make(map[int]*pkg.Baseline),
|
|
|
|
tempCh: make(chan *pkg.Baseline, config.Thread),
|
2022-12-11 04:21:42 +08:00
|
|
|
checkCh: make(chan *Unit),
|
2022-09-23 11:20:41 +08:00
|
|
|
wg: sync.WaitGroup{},
|
|
|
|
initwg: sync.WaitGroup{},
|
2022-11-10 17:19:05 +08:00
|
|
|
reqCount: 1,
|
|
|
|
failedCount: 1,
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
p, _ := ants.NewPoolWithFunc(config.Thread, func(i interface{}) {
|
2022-12-11 04:21:42 +08:00
|
|
|
atomic.AddInt32(&pool.Statistor.ReqTotal, 1)
|
2022-09-08 15:57:17 +08:00
|
|
|
unit := i.(*Unit)
|
2022-09-20 04:01:38 +08:00
|
|
|
req, err := pool.genReq(unit.path)
|
|
|
|
if err != nil {
|
|
|
|
logs.Log.Error(err.Error())
|
2022-12-02 15:21:17 +08:00
|
|
|
return
|
2022-09-20 04:01:38 +08:00
|
|
|
}
|
2022-12-02 18:29:26 +08:00
|
|
|
start := time.Now()
|
2022-09-23 11:20:41 +08:00
|
|
|
resp, reqerr := pool.client.Do(pctx, req)
|
2022-10-26 18:28:40 +08:00
|
|
|
if pool.ClientType == ihttp.FAST {
|
|
|
|
defer fasthttp.ReleaseResponse(resp.FastResponse)
|
|
|
|
defer fasthttp.ReleaseRequest(req.FastRequest)
|
|
|
|
}
|
|
|
|
|
2022-12-11 00:24:28 +08:00
|
|
|
// compare与各种错误处理
|
2022-12-02 18:05:33 +08:00
|
|
|
var bl *pkg.Baseline
|
2022-09-23 11:20:41 +08:00
|
|
|
if reqerr != nil && reqerr != fasthttp.ErrBodyTooLarge {
|
2022-10-19 16:38:23 +08:00
|
|
|
pool.failedCount++
|
2022-12-11 04:21:42 +08:00
|
|
|
atomic.AddInt32(&pool.Statistor.FailedNumber, 1)
|
2022-11-29 20:50:00 +08:00
|
|
|
bl = &pkg.Baseline{UrlString: pool.BaseURL + unit.path, IsValid: false, ErrString: reqerr.Error(), Reason: ErrRequestFailed.Error()}
|
2022-11-10 17:19:05 +08:00
|
|
|
pool.failedBaselines = append(pool.failedBaselines, bl)
|
2022-09-08 15:57:17 +08:00
|
|
|
} else {
|
2022-11-29 21:55:27 +08:00
|
|
|
if unit.source != WordSource && unit.source != RedirectSource {
|
2022-11-10 21:03:07 +08:00
|
|
|
bl = pkg.NewBaseline(req.URI(), req.Host(), resp)
|
2022-09-08 15:57:17 +08:00
|
|
|
} else {
|
2022-11-29 21:55:27 +08:00
|
|
|
if pool.MatchExpr != nil {
|
2022-11-21 20:44:02 +08:00
|
|
|
// 如果非wordsource, 或自定义了match函数, 则所有数据送入tempch中
|
|
|
|
bl = pkg.NewBaseline(req.URI(), req.Host(), resp)
|
|
|
|
} else if err = pool.PreCompare(resp); err == nil {
|
|
|
|
// 通过预对比跳过一些无用数据, 减少性能消耗
|
|
|
|
bl = pkg.NewBaseline(req.URI(), req.Host(), resp)
|
2022-11-29 21:55:27 +08:00
|
|
|
if err != ErrRedirect && bl.RedirectURL != "" {
|
|
|
|
if bl.RedirectURL != "" && !strings.HasPrefix(bl.RedirectURL, "http") {
|
|
|
|
bl.RedirectURL = "/" + strings.TrimLeft(bl.RedirectURL, "/")
|
|
|
|
bl.RedirectURL = pool.BaseURL + bl.RedirectURL
|
|
|
|
}
|
|
|
|
pool.addRedirect(bl, unit.reCount)
|
|
|
|
}
|
2022-11-21 20:44:02 +08:00
|
|
|
pool.addFuzzyBaseline(bl)
|
|
|
|
} else {
|
|
|
|
bl = pkg.NewInvalidBaseline(req.URI(), req.Host(), resp, err.Error())
|
|
|
|
}
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-12-02 18:29:26 +08:00
|
|
|
bl.Spended = time.Since(start).Milliseconds()
|
2022-09-08 15:57:17 +08:00
|
|
|
switch unit.source {
|
2022-11-17 05:48:46 +08:00
|
|
|
case InitRandomSource:
|
2022-12-11 00:24:28 +08:00
|
|
|
pool.random = bl
|
2022-11-10 21:03:07 +08:00
|
|
|
pool.addFuzzyBaseline(bl)
|
2022-10-27 23:40:15 +08:00
|
|
|
pool.initwg.Done()
|
2022-11-17 05:48:46 +08:00
|
|
|
case InitIndexSource:
|
|
|
|
pool.index = bl
|
|
|
|
pool.initwg.Done()
|
2022-09-20 18:09:06 +08:00
|
|
|
case CheckSource:
|
2022-11-21 20:44:02 +08:00
|
|
|
if bl.ErrString != "" {
|
2022-12-11 00:50:03 +08:00
|
|
|
logs.Log.Warnf("[check.error] %s maybe ip had banned, break (%d/%d), error: %s", pool.BaseURL, pool.failedCount, pool.BreakThreshold, bl.ErrString)
|
2022-12-11 00:24:28 +08:00
|
|
|
} else if i := pool.random.Compare(bl); i < 1 {
|
2022-11-10 17:32:58 +08:00
|
|
|
if i == 0 {
|
2022-12-11 03:52:06 +08:00
|
|
|
if pool.Fuzzy {
|
|
|
|
logs.Log.Warn("[check.fuzzy] maybe trigger risk control, " + bl.String())
|
|
|
|
}
|
2022-11-10 17:32:58 +08:00
|
|
|
} else {
|
2022-12-11 04:37:56 +08:00
|
|
|
pool.failedCount++
|
2022-11-10 17:32:58 +08:00
|
|
|
logs.Log.Warn("[check.failed] maybe trigger risk control, " + bl.String())
|
2022-12-11 04:37:56 +08:00
|
|
|
pool.failedBaselines = append(pool.failedBaselines, bl)
|
2022-11-10 17:32:58 +08:00
|
|
|
}
|
2022-11-10 15:43:25 +08:00
|
|
|
} else {
|
2022-11-10 21:03:07 +08:00
|
|
|
pool.resetFailed() // 如果后续访问正常, 重置错误次数
|
2022-11-10 15:43:25 +08:00
|
|
|
logs.Log.Debug("[check.pass] " + bl.String())
|
2022-09-23 01:39:00 +08:00
|
|
|
}
|
|
|
|
|
2022-09-08 15:57:17 +08:00
|
|
|
case WordSource:
|
2022-09-23 01:20:01 +08:00
|
|
|
// 异步进行性能消耗较大的深度对比
|
|
|
|
pool.tempCh <- bl
|
2022-11-11 10:37:30 +08:00
|
|
|
pool.reqCount++
|
2022-11-17 05:40:02 +08:00
|
|
|
if pool.reqCount%pool.CheckPeriod == 0 {
|
2022-11-11 10:20:32 +08:00
|
|
|
pool.reqCount++
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.check()
|
2022-11-17 05:40:02 +08:00
|
|
|
} else if pool.failedCount%pool.ErrPeriod == 0 {
|
2022-11-11 10:20:32 +08:00
|
|
|
pool.failedCount++
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.check()
|
2022-09-23 11:20:41 +08:00
|
|
|
}
|
2022-11-10 15:43:25 +08:00
|
|
|
pool.bar.Done()
|
2022-11-29 21:55:27 +08:00
|
|
|
case RedirectSource:
|
|
|
|
bl.FrontURL = unit.frontUrl
|
|
|
|
pool.tempCh <- bl
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
2022-10-19 16:38:23 +08:00
|
|
|
|
2022-09-08 15:57:17 +08:00
|
|
|
})
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.reqPool = p
|
2022-12-11 00:24:28 +08:00
|
|
|
// 挂起一个异步的处理结果线程, 不干扰主线程的请求并发
|
2022-11-11 10:20:32 +08:00
|
|
|
go func() {
|
|
|
|
for bl := range pool.tempCh {
|
2022-11-23 10:59:15 +08:00
|
|
|
if _, ok := pool.Statistor.Counts[bl.Status]; ok {
|
|
|
|
pool.Statistor.Counts[bl.Status]++
|
|
|
|
} else {
|
|
|
|
pool.Statistor.Counts[bl.Status] = 1
|
|
|
|
}
|
2022-12-14 14:20:45 +08:00
|
|
|
|
|
|
|
var params map[string]interface{}
|
|
|
|
if pool.MatchExpr != nil || pool.FilterExpr != nil || pool.RecuExpr != nil {
|
|
|
|
params = map[string]interface{}{
|
|
|
|
"index": pool.index,
|
|
|
|
"random": pool.random,
|
|
|
|
"current": bl,
|
|
|
|
}
|
|
|
|
for _, status := range FuzzyStatus {
|
|
|
|
if bl, ok := pool.baselines[status]; ok {
|
|
|
|
params["bl"+strconv.Itoa(status)] = bl
|
|
|
|
} else {
|
|
|
|
params["bl"+strconv.Itoa(status)] = &pkg.Baseline{}
|
|
|
|
}
|
2022-12-11 00:24:28 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-11-21 20:44:02 +08:00
|
|
|
var status bool
|
|
|
|
if pool.MatchExpr != nil {
|
2022-12-11 00:24:28 +08:00
|
|
|
if CompareWithExpr(pool.MatchExpr, params) {
|
2022-11-21 20:44:02 +08:00
|
|
|
status = true
|
2022-11-11 10:20:32 +08:00
|
|
|
}
|
|
|
|
} else {
|
2022-11-21 20:44:02 +08:00
|
|
|
if pool.BaseCompare(bl) {
|
|
|
|
status = true
|
|
|
|
}
|
2022-11-11 10:20:32 +08:00
|
|
|
}
|
2022-11-21 20:44:02 +08:00
|
|
|
|
|
|
|
if status {
|
2022-11-21 23:56:27 +08:00
|
|
|
pool.Statistor.FoundNumber++
|
2022-12-11 00:24:28 +08:00
|
|
|
if pool.FilterExpr != nil && CompareWithExpr(pool.FilterExpr, params) {
|
2022-11-21 23:56:27 +08:00
|
|
|
pool.Statistor.FilteredNumber++
|
2022-11-21 20:44:02 +08:00
|
|
|
bl.Reason = ErrCustomFilter.Error()
|
|
|
|
bl.IsValid = false
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
bl.IsValid = false
|
|
|
|
}
|
2022-12-11 00:24:28 +08:00
|
|
|
|
|
|
|
// 如果要进行递归判断, 要满足 bl有效, mod为path-spray, 当前深度小于最大递归深度
|
|
|
|
if bl.IsValid && pool.Mod == pkg.PathSpray && bl.RecuDepth < maxRecuDepth {
|
|
|
|
if CompareWithExpr(pool.RecuExpr, params) {
|
|
|
|
bl.Recu = true
|
|
|
|
}
|
|
|
|
}
|
2022-11-21 20:44:02 +08:00
|
|
|
pool.OutputCh <- bl
|
|
|
|
pool.wg.Done()
|
2022-11-11 10:20:32 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
pool.analyzeDone = true
|
|
|
|
}()
|
2022-09-08 15:57:17 +08:00
|
|
|
return pool, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
type Pool struct {
|
|
|
|
*pkg.Config
|
2022-11-21 23:56:27 +08:00
|
|
|
Statistor *pkg.Statistor
|
2022-11-10 21:03:07 +08:00
|
|
|
client *ihttp.Client
|
2022-12-11 03:52:06 +08:00
|
|
|
reqPool *ants.PoolWithFunc
|
2022-11-10 21:03:07 +08:00
|
|
|
bar *pkg.Bar
|
|
|
|
ctx context.Context
|
|
|
|
cancel context.CancelFunc
|
|
|
|
tempCh chan *pkg.Baseline // 待处理的baseline
|
2022-12-11 03:52:06 +08:00
|
|
|
checkCh chan *Unit
|
2022-11-10 15:43:25 +08:00
|
|
|
reqCount int
|
|
|
|
failedCount int
|
2022-11-10 21:03:07 +08:00
|
|
|
failedBaselines []*pkg.Baseline
|
2022-12-11 00:24:28 +08:00
|
|
|
random *pkg.Baseline
|
2022-11-17 05:48:46 +08:00
|
|
|
index *pkg.Baseline
|
2022-11-10 21:03:07 +08:00
|
|
|
baselines map[int]*pkg.Baseline
|
2022-11-10 15:43:25 +08:00
|
|
|
analyzeDone bool
|
|
|
|
worder *words.Worder
|
2022-12-11 00:24:28 +08:00
|
|
|
locker sync.Mutex
|
2022-11-10 15:43:25 +08:00
|
|
|
wg sync.WaitGroup
|
|
|
|
initwg sync.WaitGroup // 初始化用, 之后改成锁
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) Init() error {
|
2022-12-09 19:30:12 +08:00
|
|
|
// 分成两步是为了避免闭包的线程安全问题
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.initwg.Add(1)
|
|
|
|
pool.reqPool.Invoke(newUnit("/", InitIndexSource))
|
|
|
|
pool.initwg.Wait()
|
|
|
|
if pool.index.ErrString != "" {
|
|
|
|
return fmt.Errorf(pool.index.String())
|
2022-12-02 18:05:33 +08:00
|
|
|
}
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.index.Collect()
|
2022-12-15 00:19:06 +08:00
|
|
|
logs.Log.Info("[baseline.index] " + pool.index.String())
|
2022-12-09 19:30:12 +08:00
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.initwg.Add(1)
|
|
|
|
pool.reqPool.Invoke(newUnit(pkg.RandPath(), InitRandomSource))
|
|
|
|
pool.initwg.Wait()
|
2022-09-08 15:57:17 +08:00
|
|
|
// 检测基本访问能力
|
2022-12-11 03:52:06 +08:00
|
|
|
if pool.random.ErrString != "" {
|
|
|
|
return fmt.Errorf(pool.random.String())
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.random.Collect()
|
2022-12-15 00:19:06 +08:00
|
|
|
logs.Log.Info("[baseline.random] " + pool.random.String())
|
2022-11-17 05:48:46 +08:00
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
if pool.random.RedirectURL != "" {
|
2022-11-29 20:50:00 +08:00
|
|
|
// 自定协议升级
|
|
|
|
// 某些网站http会重定向到https, 如果发现随机目录出现这种情况, 则自定将baseurl升级为https
|
2022-12-11 03:52:06 +08:00
|
|
|
rurl, err := url.Parse(pool.random.RedirectURL)
|
|
|
|
if err == nil && rurl.Hostname() == pool.random.Url.Hostname() && pool.random.Url.Scheme == "http" && rurl.Scheme == "https" {
|
2022-12-15 00:19:06 +08:00
|
|
|
logs.Log.Infof("baseurl %s upgrade http to https", pool.BaseURL)
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.BaseURL = strings.Replace(pool.BaseURL, "http", "https", 1)
|
2022-11-29 20:50:00 +08:00
|
|
|
}
|
|
|
|
}
|
2022-11-17 05:48:46 +08:00
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
if pool.random.RedirectURL != "" {
|
2022-09-23 01:20:01 +08:00
|
|
|
CheckRedirect = func(redirectURL string) bool {
|
2022-12-11 03:52:06 +08:00
|
|
|
if redirectURL == pool.random.RedirectURL {
|
2022-09-08 15:57:17 +08:00
|
|
|
// 相同的RedirectURL将被认为是无效数据
|
|
|
|
return false
|
2022-09-23 01:20:01 +08:00
|
|
|
} else {
|
|
|
|
// path为3xx, 且与baseline中的RedirectURL不同时, 为有效数据
|
|
|
|
return true
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) addRedirect(bl *pkg.Baseline, reCount int) {
|
2022-11-29 21:55:27 +08:00
|
|
|
if reCount >= maxRedirect {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
if uu, err := url.Parse(bl.RedirectURL); err == nil && uu.Hostname() == pool.index.Url.Hostname() {
|
|
|
|
pool.wg.Add(1)
|
|
|
|
_ = pool.reqPool.Invoke(&Unit{
|
2022-11-29 21:55:27 +08:00
|
|
|
path: uu.Path,
|
|
|
|
source: RedirectSource,
|
|
|
|
frontUrl: bl.UrlString,
|
|
|
|
reCount: reCount + 1,
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) check() {
|
|
|
|
if pool.failedCount > pool.BreakThreshold {
|
|
|
|
// 当报错次数超过上限是, 结束任务
|
|
|
|
pool.recover()
|
|
|
|
pool.cancel()
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if pool.Mod == pkg.HostSpray {
|
|
|
|
pool.checkCh <- newUnit(pkg.RandHost(), CheckSource)
|
|
|
|
} else if pool.Mod == pkg.PathSpray {
|
|
|
|
pool.checkCh <- newUnit(pkg.RandPath(), CheckSource)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (pool *Pool) genReq(s string) (*ihttp.Request, error) {
|
|
|
|
if pool.Mod == pkg.HostSpray {
|
|
|
|
return ihttp.BuildHostRequest(pool.ClientType, pool.BaseURL, s)
|
|
|
|
} else if pool.Mod == pkg.PathSpray {
|
|
|
|
return ihttp.BuildPathRequest(pool.ClientType, pool.BaseURL, s)
|
|
|
|
}
|
|
|
|
return nil, fmt.Errorf("unknown mod")
|
|
|
|
}
|
|
|
|
func (pool *Pool) Run(ctx context.Context, offset, limit int) {
|
2022-12-12 17:05:44 +08:00
|
|
|
pool.worder.RunWithRules()
|
2022-09-15 19:27:07 +08:00
|
|
|
Loop:
|
|
|
|
for {
|
|
|
|
select {
|
2022-12-11 03:52:06 +08:00
|
|
|
case u, ok := <-pool.worder.C:
|
2022-09-15 19:27:07 +08:00
|
|
|
if !ok {
|
|
|
|
break Loop
|
|
|
|
}
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.Statistor.End++
|
2022-12-11 04:21:42 +08:00
|
|
|
if int(pool.reqCount) < offset {
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.reqCount++
|
2022-11-10 15:48:38 +08:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
if pool.Statistor.End > limit {
|
2022-11-10 15:48:38 +08:00
|
|
|
break Loop
|
|
|
|
}
|
|
|
|
|
2022-11-10 04:48:07 +08:00
|
|
|
if u == "" {
|
|
|
|
continue
|
|
|
|
}
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.wg.Add(1)
|
|
|
|
_ = pool.reqPool.Invoke(newUnit(u, WordSource))
|
|
|
|
case unit := <-pool.checkCh:
|
|
|
|
pool.Statistor.CheckNumber++
|
|
|
|
pool.reqPool.Invoke(unit)
|
2022-09-15 19:27:07 +08:00
|
|
|
case <-ctx.Done():
|
|
|
|
break Loop
|
2022-12-11 03:52:06 +08:00
|
|
|
case <-pool.ctx.Done():
|
2022-09-19 14:42:29 +08:00
|
|
|
break Loop
|
2022-09-15 19:27:07 +08:00
|
|
|
}
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.wg.Wait()
|
|
|
|
pool.Statistor.EndTime = time.Now().Unix()
|
|
|
|
pool.Close()
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) PreCompare(resp *ihttp.Response) error {
|
2022-11-17 16:27:44 +08:00
|
|
|
status := resp.StatusCode()
|
2022-11-17 17:09:37 +08:00
|
|
|
if IntsContains(WhiteStatus, status) {
|
|
|
|
// 如果为白名单状态码则直接返回
|
|
|
|
return nil
|
|
|
|
}
|
2022-12-11 03:52:06 +08:00
|
|
|
if pool.random != nil && pool.random.Status != 200 && pool.random.Status == status {
|
2022-11-10 21:03:07 +08:00
|
|
|
return ErrSameStatus
|
|
|
|
}
|
|
|
|
|
2022-11-17 17:09:37 +08:00
|
|
|
if IntsContains(BlackStatus, status) {
|
2022-09-15 19:27:07 +08:00
|
|
|
return ErrBadStatus
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
|
|
|
|
2022-11-17 17:09:37 +08:00
|
|
|
if IntsContains(WAFStatus, status) {
|
2022-11-17 16:27:44 +08:00
|
|
|
return ErrWaf
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
|
|
|
|
2022-11-29 21:55:27 +08:00
|
|
|
if CheckRedirect != nil && !CheckRedirect(resp.GetHeader("Location")) {
|
2022-11-17 16:27:44 +08:00
|
|
|
return ErrRedirect
|
2022-09-26 17:19:08 +08:00
|
|
|
}
|
2022-09-08 15:57:17 +08:00
|
|
|
|
2022-09-15 19:27:07 +08:00
|
|
|
return nil
|
2022-09-08 15:57:17 +08:00
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) BaseCompare(bl *pkg.Baseline) bool {
|
2022-11-11 10:20:32 +08:00
|
|
|
if !bl.IsValid {
|
2022-11-21 20:44:02 +08:00
|
|
|
return false
|
2022-11-11 10:20:32 +08:00
|
|
|
}
|
2022-11-11 11:55:49 +08:00
|
|
|
var status = -1
|
2022-12-11 03:52:06 +08:00
|
|
|
base, ok := pool.baselines[bl.Status] // 挑选对应状态码的baseline进行compare
|
2022-11-17 05:48:46 +08:00
|
|
|
if !ok {
|
2022-12-11 03:52:06 +08:00
|
|
|
if pool.random.Status == bl.Status {
|
2022-11-17 05:48:46 +08:00
|
|
|
// 当other的状态码与base相同时, 会使用base
|
|
|
|
ok = true
|
2022-12-11 03:52:06 +08:00
|
|
|
base = pool.random
|
|
|
|
} else if pool.index.Status == bl.Status {
|
2022-11-17 05:48:46 +08:00
|
|
|
// 当other的状态码与index相同时, 会使用index
|
|
|
|
ok = true
|
2022-12-11 03:52:06 +08:00
|
|
|
base = pool.index
|
2022-11-17 05:48:46 +08:00
|
|
|
}
|
2022-11-11 11:40:53 +08:00
|
|
|
}
|
|
|
|
|
2022-11-11 11:55:49 +08:00
|
|
|
if ok {
|
|
|
|
if status = base.Compare(bl); status == 1 {
|
2022-11-21 20:44:02 +08:00
|
|
|
bl.Reason = ErrCompareFailed.Error()
|
|
|
|
return false
|
2022-09-23 01:20:01 +08:00
|
|
|
}
|
2022-11-11 10:20:32 +08:00
|
|
|
}
|
2022-09-23 01:20:01 +08:00
|
|
|
|
2022-11-11 14:50:59 +08:00
|
|
|
bl.Collect()
|
2022-12-12 18:01:14 +08:00
|
|
|
//if !pool.IgnoreWaf {
|
|
|
|
// // 部分情况下waf的特征可能是全局, 指定了--ignore-waf则不会进行waf的指纹检测
|
|
|
|
// for _, f := range bl.Frameworks {
|
|
|
|
// if f.HasTag("waf") {
|
|
|
|
// pool.Statistor.WafedNumber++
|
|
|
|
// bl.Reason = ErrWaf.Error()
|
|
|
|
// return false
|
|
|
|
// }
|
|
|
|
// }
|
|
|
|
//}
|
2022-09-23 11:20:41 +08:00
|
|
|
|
2022-11-11 14:50:59 +08:00
|
|
|
if ok && status == 0 && base.FuzzyCompare(bl) {
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.Statistor.FuzzyNumber++
|
2022-11-21 20:44:02 +08:00
|
|
|
bl.Reason = ErrFuzzyCompareFailed.Error()
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.PutToFuzzy(bl)
|
2022-11-21 20:44:02 +08:00
|
|
|
return false
|
2022-11-11 14:50:59 +08:00
|
|
|
}
|
|
|
|
|
2022-11-21 20:44:02 +08:00
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
2022-12-11 00:24:28 +08:00
|
|
|
func CompareWithExpr(exp *vm.Program, params map[string]interface{}) bool {
|
2022-11-21 20:44:02 +08:00
|
|
|
res, err := expr.Run(exp, params)
|
|
|
|
if err != nil {
|
|
|
|
logs.Log.Warn(err.Error())
|
|
|
|
}
|
|
|
|
|
|
|
|
if res == true {
|
|
|
|
return true
|
|
|
|
} else {
|
|
|
|
return false
|
|
|
|
}
|
2022-09-23 01:20:01 +08:00
|
|
|
}
|
2022-09-26 17:19:08 +08:00
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) addFuzzyBaseline(bl *pkg.Baseline) {
|
|
|
|
if _, ok := pool.baselines[bl.Status]; !ok && IntsContains(FuzzyStatus, bl.Status) {
|
2022-11-10 21:03:07 +08:00
|
|
|
bl.Collect()
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.locker.Lock()
|
|
|
|
pool.baselines[bl.Status] = bl
|
|
|
|
pool.locker.Unlock()
|
2022-12-15 00:19:06 +08:00
|
|
|
logs.Log.Infof("[baseline.%dinit] %s", bl.Status, bl.String())
|
2022-11-10 21:03:07 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) PutToInvalid(bl *pkg.Baseline, reason string) {
|
2022-11-10 21:18:26 +08:00
|
|
|
bl.IsValid = false
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.OutputCh <- bl
|
2022-11-10 21:18:26 +08:00
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) PutToFuzzy(bl *pkg.Baseline) {
|
2022-11-10 21:18:26 +08:00
|
|
|
bl.IsFuzzy = true
|
2022-12-11 03:52:06 +08:00
|
|
|
pool.FuzzyCh <- bl
|
2022-11-10 21:18:26 +08:00
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) resetFailed() {
|
|
|
|
pool.failedCount = 1
|
|
|
|
pool.failedBaselines = nil
|
2022-11-10 15:43:25 +08:00
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) recover() {
|
|
|
|
logs.Log.Errorf("%s ,failed request exceeds the threshold , task will exit. Breakpoint %d", pool.BaseURL, pool.reqCount)
|
|
|
|
for i, bl := range pool.failedBaselines {
|
2022-11-10 17:19:05 +08:00
|
|
|
logs.Log.Errorf("[failed.%d] %s", i, bl.String())
|
2022-11-10 15:43:25 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-12-11 03:52:06 +08:00
|
|
|
func (pool *Pool) Close() {
|
|
|
|
for pool.analyzeDone {
|
2022-09-23 11:20:41 +08:00
|
|
|
time.Sleep(time.Duration(100) * time.Millisecond)
|
|
|
|
}
|
2022-12-11 03:52:06 +08:00
|
|
|
close(pool.tempCh)
|
|
|
|
pool.bar.Close()
|
2022-09-23 11:20:41 +08:00
|
|
|
}
|