Documentation
¶
Overview ¶
- Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: cert.go @Date: 2025/9/1 下午4:00*
- Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: eval.go @Date: 2025/2/21 下午3:01*
- Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: icon.go @Date: 2025/2/21 下午3:06*
- Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: req.go @Date: 2025/2/21 下午3:06*
- Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: runner.go @Date: 2025/2/20 下午3:37*
- Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: server.go @Date: 2025/4/3 上午10:10*
- Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: title.go @Date: 2025/4/3 上午9:47*
- Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: yaml.go @Date: 2025/2/21 下午2:36*
Index ¶
- Constants
- func BuildBaseProtoResponseOwned(ctx context.Context, resp *http.Response, body []byte, latency int64, ...) *proto.Response
- func BuildProtoRequest(resp *http.Response, method, body, path string) *proto.Request
- func BuildProtoResponseOwned(ctx context.Context, resp *http.Response, body []byte, latency int64, ...) *proto.Response
- func CleanServerString(server string) string
- func EvaluateOutput(args yaml.MapSlice, variables map[string]any, lib *gcel.CustomLib) map[string]string
- func ExtractICPRecord(body string) string
- func ExtractICPRecordFromBody(body []byte) string
- func ExtractServerInfo(header http.Header) (string, string)
- func ExtractVersion(server string) string
- func FormatServerResult(originalServer, cleanedServer, version string) string
- func GetCertInfos(resp *http.Response) []*types.CertInfo
- func GetIconURL(pageURL, body string) string
- func GetIconURLFromBody(pageURL string, body []byte) string
- func GetPageIconHash(ctx context.Context, client *network.HTTPClient, pageURL string, body []byte, ...) string
- func GetServerInfoFromResponse(resp *http.Response) *types.ServerInfo
- func GetServerInfoFromTCP(address, hostType string) *types.ServerInfo
- func GetTitle(urlStr string, resp *http.Response) string
- func GetTitleFromBody(ctx context.Context, urlStr string, resp *http.Response, bodyBytes []byte, ...) string
- func IsFuzzSet(args yaml.MapSlice, variableMap map[string]any, customLib *celPkg.CustomLib)
- func Select(pocPath string, pocName string) (string, error)
- func SendRequest(parentCtx context.Context, client *network.HTTPClient, target string, ...) (map[string]any, error)
- func SetVariableMap(find string, variableMap map[string]any) string
- func StandBase64(raw []byte) []byte
- type Classification
- type DetectionRule
- type Finger
- type GetIconHash
- type Info
- type Metadata
- type Payloads
- type Rule
- type RuleMap
- type RuleMapSlice
- type RuleRequest
- type Source
Constants ¶
const ( HttpType = "http" TcpType = "tcp" UdpType = "udp" SslType = "ssl" GoType = "go" )
const FingerFile = "fingerYaml"
FingerFile 配置poc文件目录
Variables ¶
This section is empty.
Functions ¶
func BuildBaseProtoResponseOwned ¶
func BuildBaseProtoResponseOwned(ctx context.Context, resp *http.Response, body []byte, latency int64, client *network.HTTPClient, options network.OptionsRequest, pageURL string) *proto.Response
BuildBaseProtoResponseOwned 构造扫描入口响应。pageURL 为最终页面地址, 仅用于资源解析;规则缓存和 proto.Response.Url 继续使用目标地址。
func BuildProtoRequest ¶
BuildProtoRequest 构造proto.Request结构体 (公开版本)
func BuildProtoResponseOwned ¶
func BuildProtoResponseOwned(ctx context.Context, resp *http.Response, body []byte, latency int64, client *network.HTTPClient, options network.OptionsRequest) *proto.Response
BuildProtoResponseOwned 接管独占正文,UTF-8 输入直接作为只读消息正文。 调用后不得修改输入;GB18030 回退与字符串入口一致。Raw 与 Body 仍使用 各自的数组,消息发布后可由同次扫描中的规则共享读取。
func CleanServerString ¶
CleanServerString 移除服务器信息中没有用的内容
func EvaluateOutput ¶ added in v1.2.0
func EvaluateOutput(args yaml.MapSlice, variables map[string]any, lib *gcel.CustomLib) map[string]string
EvaluateOutput 仅保存成功求值的输出。失败的提取表达式不作为产品版本或证据回传。 执行变量保留完整值,公开结果中的单项输出限制为 512 字节。
func ExtractICPRecord ¶
ExtractICPRecord 支持 HTML 与纯文本;优先采用备案官网链接中的有效号码。
func ExtractICPRecordFromBody ¶
ExtractICPRecordFromBody 从只读正文提取备案号,不保留整页引用。
func ExtractServerInfo ¶
ExtractServerInfo 从HTTP响应头中提取server信息
func FormatServerResult ¶
FormatServerResult 格式化显示服务器信息结果
func GetCertInfos ¶
GetCertInfos 返回完整证书信息数组,用于结构化输出
func GetIconURLFromBody ¶
GetIconURLFromBody 直接读取只读正文,避免整页字符串副本。
func GetPageIconHash ¶
func GetPageIconHash(ctx context.Context, client *network.HTTPClient, pageURL string, body []byte, options network.OptionsRequest) string
GetPageIconHash 依次验证页面候选,最后回退根路径。所有请求共享一个 时间预算;失败不写长期缓存,签名参数不同的地址保持独立。
func GetServerInfoFromResponse ¶
func GetServerInfoFromResponse(resp *http.Response) *types.ServerInfo
GetServerInfoFromResponse 从HTTP响应中获取并格式化服务器信息 返回ServerInfo结构体指针
func GetServerInfoFromTCP ¶
func GetServerInfoFromTCP(address, hostType string) *types.ServerInfo
GetServerInfoFromTCP 从TCP/UDP响应中获取并格式化服务器信息 返回ServerInfo结构体指针
func GetTitleFromBody ¶
func GetTitleFromBody(ctx context.Context, urlStr string, resp *http.Response, bodyBytes []byte, client *network.HTTPClient, options network.OptionsRequest) string
GetTitleFromBody 消费已限长的正文,附加资源继承同一次扫描的请求策略。
func SendRequest ¶
func SendRequest(parentCtx context.Context, client *network.HTTPClient, target string, req RuleRequest, rule Rule, variableMap map[string]any, options network.OptionsRequest) (map[string]any, error)
SendRequest 使用指定 HTTP 客户端发送 yaml poc 请求。 parentCtx 取消或超时后,请求会尽快结束(与 Scan(ctx) 语义一致)。
func SetVariableMap ¶
SetVariableMap 处理解析set中变量 跳过 proto.Request/Response/Reverse 等不可能出现在模板中的大对象, 避免 fmt.Sprintf("%v") 触发 protobuf 文本序列化(单次数百KB,占总分配64%)
Types ¶
type Classification ¶
type DetectionRule ¶ added in v1.2.0
type Finger ¶
type Finger struct {
Id string `yaml:"id"` // 脚本名称
Transport string `yaml:"transport"` // 传输方式,该字段用于指定发送数据包的协议,该字段用于指定发送数据包的协议:①tcp ②udp ③http
Set yaml.MapSlice `yaml:"set"` // 全局变量定义,该字段用于定义全局变量。比如随机数,反连平台等
Payloads Payloads `yaml:"payloads"`
Rules RuleMapSlice `yaml:"rules"`
Expression string `yaml:"expression"`
Info Info `yaml:"info"`
Gopoc string `yaml:"gopoc"` // Gopoc 脚本名称
Source Source `yaml:"-"`
}
type GetIconHash ¶
type GetIconHash struct {
// contains filtered or unexported fields
}
GetIconHash 获取 icon hash。
func NewGetIconHash ¶
func NewGetIconHash(iconURL string, proxy string) *GetIconHash
NewGetIconHash 初始化 GetIconHash
func (*GetIconHash) Run ¶
func (g *GetIconHash) Run(ctx context.Context) string
Run 运行获取 icon hash 的流程。
func (*GetIconHash) WithHTTPClient ¶
func (g *GetIconHash) WithHTTPClient(client *network.HTTPClient) *GetIconHash
WithHTTPClient 绑定 Runner/Engine 持有的 HTTP 客户端(nil 时回退 DefaultHTTPClient)。
func (*GetIconHash) WithHeaders ¶
func (g *GetIconHash) WithHeaders(headers map[string]string) *GetIconHash
WithHeaders 复制页面请求头,支持需要认证或 Referer 的图标资源。
func (*GetIconHash) WithTimeout ¶
func (g *GetIconHash) WithTimeout(timeout time.Duration) *GetIconHash
WithTimeout 设置 favicon 请求超时。
type Info ¶
type Info struct {
Name string `yaml:"name"`
Author string `yaml:"author"`
Severity string `yaml:"severity"`
Verified bool `yaml:"verified"`
VerifiedDeclared bool `yaml:"-"`
Description string `yaml:"description"`
Reference []string `yaml:"reference"`
Affected string `yaml:"affected"` // 影响版本
Solutions string `yaml:"solutions"` // 解决方案
Tags string `yaml:"tags"` // 标签
Classification Classification `yaml:"classification"`
Created string `yaml:"created"` // create time
}
Info 以下开始是 信息部分
type Metadata ¶ added in v1.2.0
type Metadata struct {
ID string
Info Info
Source Source
Transport string
Expression string
Detection []DetectionRule
}
Metadata 展示规则来源和检测依据,不暴露表达式树及执行状态。
type Rule ¶
type Rule struct {
Request RuleRequest `yaml:"request"`
Expression string `yaml:"expression"`
Output yaml.MapSlice `yaml:"output"`
}
type RuleMapSlice ¶
type RuleMapSlice []RuleMap
RuleMapSlice 用于帮助yaml解析,保证Rule有序
func (*RuleMapSlice) UnmarshalYAML ¶
func (m *RuleMapSlice) UnmarshalYAML(unmarshal func(any) error) error
UnmarshalYAML 保持规则在源文件中的顺序,重复名称采用最后一次定义。 所有解析状态属于当前调用;并发加载规则不需要共享计数器或全局锁。
type RuleRequest ¶
type RuleRequest struct {
Type string `yaml:"type"` // 传输方式,默认 http,可选:tcp,udp,ssl,go 等任意扩展
Host string `yaml:"host"` // tcp/udp 请求的主机名
Data string `yaml:"data"` // tcp/udp 发送的内容
DataType string `yaml:"data-type"` // tcp/udp 发送的数据类型,默认字符串
ReadSize int `yaml:"read-size"` // tcp/udp 读取内容的长度
ReadTimeout int `yaml:"read-timeout"` // tcp/udp专用
Raw string `yaml:"raw"` // raw 专用
Method string `yaml:"method"`
Path string `yaml:"path"`
Headers map[string]string `yaml:"headers"`
Body string `yaml:"body"`
FollowRedirects bool `yaml:"follow_redirects"` // 是否跟随重定向,默认跟随重定向
}