finger

package
v1.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: MIT Imports: 35 Imported by: 0

Documentation

Overview

  • Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: cert.go @Date: 2025/9/1 下午4:00*
  • Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: eval.go @Date: 2025/2/21 下午3:01*
  • Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: icon.go @Date: 2025/2/21 下午3:06*
  • Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: req.go @Date: 2025/2/21 下午3:06*
  • Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: runner.go @Date: 2025/2/20 下午3:37*
  • Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: server.go @Date: 2025/4/3 上午10:10*
  • Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: title.go @Date: 2025/4/3 上午9:47*
  • Package fingerYaml @Author: zhizhuo @IDE:GoLand @File: yaml.go @Date: 2025/2/21 下午2:36*

Index

Constants

View Source
const (
	HttpType = "http"
	TcpType  = "tcp"
	UdpType  = "udp"
	SslType  = "ssl"
	GoType   = "go"
)
View Source
const FingerFile = "fingerYaml"

FingerFile 配置poc文件目录

Variables

This section is empty.

Functions

func BuildBaseProtoResponseOwned

func BuildBaseProtoResponseOwned(ctx context.Context, resp *http.Response, body []byte, latency int64, client *network.HTTPClient, options network.OptionsRequest, pageURL string) *proto.Response

BuildBaseProtoResponseOwned 构造扫描入口响应。pageURL 为最终页面地址, 仅用于资源解析;规则缓存和 proto.Response.Url 继续使用目标地址。

func BuildProtoRequest

func BuildProtoRequest(resp *http.Response, method, body, path string) *proto.Request

BuildProtoRequest 构造proto.Request结构体 (公开版本)

func BuildProtoResponseOwned

func BuildProtoResponseOwned(ctx context.Context, resp *http.Response, body []byte, latency int64, client *network.HTTPClient, options network.OptionsRequest) *proto.Response

BuildProtoResponseOwned 接管独占正文,UTF-8 输入直接作为只读消息正文。 调用后不得修改输入;GB18030 回退与字符串入口一致。Raw 与 Body 仍使用 各自的数组,消息发布后可由同次扫描中的规则共享读取。

func CleanServerString

func CleanServerString(server string) string

CleanServerString 移除服务器信息中没有用的内容

func EvaluateOutput added in v1.2.0

func EvaluateOutput(args yaml.MapSlice, variables map[string]any, lib *gcel.CustomLib) map[string]string

EvaluateOutput 仅保存成功求值的输出。失败的提取表达式不作为产品版本或证据回传。 执行变量保留完整值,公开结果中的单项输出限制为 512 字节。

func ExtractICPRecord

func ExtractICPRecord(body string) string

ExtractICPRecord 支持 HTML 与纯文本;优先采用备案官网链接中的有效号码。

func ExtractICPRecordFromBody

func ExtractICPRecordFromBody(body []byte) string

ExtractICPRecordFromBody 从只读正文提取备案号,不保留整页引用。

func ExtractServerInfo

func ExtractServerInfo(header http.Header) (string, string)

ExtractServerInfo 从HTTP响应头中提取server信息

func ExtractVersion

func ExtractVersion(server string) string

ExtractVersion 从服务器字符串中提取版本信息

func FormatServerResult

func FormatServerResult(originalServer, cleanedServer, version string) string

FormatServerResult 格式化显示服务器信息结果

func GetCertInfos

func GetCertInfos(resp *http.Response) []*types.CertInfo

GetCertInfos 返回完整证书信息数组,用于结构化输出

func GetIconURL

func GetIconURL(pageURL, body string) string

GetIconURL 返回优先级最高的图标地址;同级候选保持文档顺序。

func GetIconURLFromBody

func GetIconURLFromBody(pageURL string, body []byte) string

GetIconURLFromBody 直接读取只读正文,避免整页字符串副本。

func GetPageIconHash

func GetPageIconHash(ctx context.Context, client *network.HTTPClient, pageURL string, body []byte, options network.OptionsRequest) string

GetPageIconHash 依次验证页面候选,最后回退根路径。所有请求共享一个 时间预算;失败不写长期缓存,签名参数不同的地址保持独立。

func GetServerInfoFromResponse

func GetServerInfoFromResponse(resp *http.Response) *types.ServerInfo

GetServerInfoFromResponse 从HTTP响应中获取并格式化服务器信息 返回ServerInfo结构体指针

func GetServerInfoFromTCP

func GetServerInfoFromTCP(address, hostType string) *types.ServerInfo

GetServerInfoFromTCP 从TCP/UDP响应中获取并格式化服务器信息 返回ServerInfo结构体指针

func GetTitle

func GetTitle(urlStr string, resp *http.Response) string

GetTitle 从网页中提取标题

func GetTitleFromBody

func GetTitleFromBody(ctx context.Context, urlStr string, resp *http.Response, bodyBytes []byte, client *network.HTTPClient, options network.OptionsRequest) string

GetTitleFromBody 消费已限长的正文,附加资源继承同一次扫描的请求策略。

func IsFuzzSet

func IsFuzzSet(args yaml.MapSlice, variableMap map[string]any, customLib *celPkg.CustomLib)

IsFuzzSet 解析Set中的定义变量

func Select

func Select(pocPath string, pocName string) (string, error)

Select 获取指定名字的yaml文件位置

func SendRequest

func SendRequest(parentCtx context.Context, client *network.HTTPClient, target string, req RuleRequest, rule Rule, variableMap map[string]any, options network.OptionsRequest) (map[string]any, error)

SendRequest 使用指定 HTTP 客户端发送 yaml poc 请求。 parentCtx 取消或超时后,请求会尽快结束(与 Scan(ctx) 语义一致)。

func SetVariableMap

func SetVariableMap(find string, variableMap map[string]any) string

SetVariableMap 处理解析set中变量 跳过 proto.Request/Response/Reverse 等不可能出现在模板中的大对象, 避免 fmt.Sprintf("%v") 触发 protobuf 文本序列化(单次数百KB,占总分配64%)

func StandBase64

func StandBase64(raw []byte) []byte

StandBase64 标准化Base64编码

Types

type Classification

type Classification struct {
	CvssMetrics string  `yaml:"cvss-metrics"`
	CvssScore   float64 `yaml:"cvss-score"`
	CveId       string  `yaml:"cve-id"`
	CweId       string  `yaml:"cwe-id"`
}

type DetectionRule added in v1.2.0

type DetectionRule struct {
	Key        string
	Transport  string
	Method     string
	Path       string
	Expression string
	Output     map[string]string
}

type Finger

type Finger struct {
	Id         string        `yaml:"id"`        //  脚本名称
	Transport  string        `yaml:"transport"` // 传输方式,该字段用于指定发送数据包的协议,该字段用于指定发送数据包的协议:①tcp ②udp ③http
	Set        yaml.MapSlice `yaml:"set"`       // 全局变量定义,该字段用于定义全局变量。比如随机数,反连平台等
	Payloads   Payloads      `yaml:"payloads"`
	Rules      RuleMapSlice  `yaml:"rules"`
	Expression string        `yaml:"expression"`
	Info       Info          `yaml:"info"`
	Gopoc      string        `yaml:"gopoc"` // Gopoc 脚本名称
	Source     Source        `yaml:"-"`
}

func Load

func Load(fileName string, Fingers embed.FS) (*Finger, error)

Load 加载yaml文件

func Read

func Read(fileName string) (*Finger, error)

Read 获取yaml文件内容

func (*Finger) IsHTTPType

func (finger *Finger) IsHTTPType() bool

IsHTTPType 判断是否是http请求

type GetIconHash

type GetIconHash struct {
	// contains filtered or unexported fields
}

GetIconHash 获取 icon hash。

func NewGetIconHash

func NewGetIconHash(iconURL string, proxy string) *GetIconHash

NewGetIconHash 初始化 GetIconHash

func (*GetIconHash) Run

func (g *GetIconHash) Run(ctx context.Context) string

Run 运行获取 icon hash 的流程。

func (*GetIconHash) WithHTTPClient

func (g *GetIconHash) WithHTTPClient(client *network.HTTPClient) *GetIconHash

WithHTTPClient 绑定 Runner/Engine 持有的 HTTP 客户端(nil 时回退 DefaultHTTPClient)。

func (*GetIconHash) WithHeaders

func (g *GetIconHash) WithHeaders(headers map[string]string) *GetIconHash

WithHeaders 复制页面请求头,支持需要认证或 Referer 的图标资源。

func (*GetIconHash) WithTimeout

func (g *GetIconHash) WithTimeout(timeout time.Duration) *GetIconHash

WithTimeout 设置 favicon 请求超时。

type Info

type Info struct {
	Name             string         `yaml:"name"`
	Author           string         `yaml:"author"`
	Severity         string         `yaml:"severity"`
	Verified         bool           `yaml:"verified"`
	VerifiedDeclared bool           `yaml:"-"`
	Description      string         `yaml:"description"`
	Reference        []string       `yaml:"reference"`
	Affected         string         `yaml:"affected"`  // 影响版本
	Solutions        string         `yaml:"solutions"` // 解决方案
	Tags             string         `yaml:"tags"`      // 标签
	Classification   Classification `yaml:"classification"`
	Created          string         `yaml:"created"` // create time
}

Info 以下开始是 信息部分

func (*Info) UnmarshalYAML added in v1.2.0

func (i *Info) UnmarshalYAML(unmarshal func(any) error) error

UnmarshalYAML 区分未填写 verified 与明确的 false,保留原始声明。

type Metadata added in v1.2.0

type Metadata struct {
	ID         string
	Info       Info
	Source     Source
	Transport  string
	Expression string
	Detection  []DetectionRule
}

Metadata 展示规则来源和检测依据,不暴露表达式树及执行状态。

type Payloads

type Payloads struct {
	Continue bool          `yaml:"continue"`
	Payloads yaml.MapSlice `yaml:"payloads"`
}

type Rule

type Rule struct {
	Request    RuleRequest   `yaml:"request"`
	Expression string        `yaml:"expression"`
	Output     yaml.MapSlice `yaml:"output"`
}

type RuleMap

type RuleMap struct {
	Key   string
	Value Rule
}

RuleMap 用于帮助yaml解析,保证Rule有序

type RuleMapSlice

type RuleMapSlice []RuleMap

RuleMapSlice 用于帮助yaml解析,保证Rule有序

func (*RuleMapSlice) UnmarshalYAML

func (m *RuleMapSlice) UnmarshalYAML(unmarshal func(any) error) error

UnmarshalYAML 保持规则在源文件中的顺序,重复名称采用最后一次定义。 所有解析状态属于当前调用;并发加载规则不需要共享计数器或全局锁。

type RuleRequest

type RuleRequest struct {
	Type            string            `yaml:"type"`         // 传输方式,默认 http,可选:tcp,udp,ssl,go 等任意扩展
	Host            string            `yaml:"host"`         // tcp/udp 请求的主机名
	Data            string            `yaml:"data"`         // tcp/udp 发送的内容
	DataType        string            `yaml:"data-type"`    // tcp/udp 发送的数据类型,默认字符串
	ReadSize        int               `yaml:"read-size"`    // tcp/udp 读取内容的长度
	ReadTimeout     int               `yaml:"read-timeout"` // tcp/udp专用
	Raw             string            `yaml:"raw"`          // raw 专用
	Method          string            `yaml:"method"`
	Path            string            `yaml:"path"`
	Headers         map[string]string `yaml:"headers"`
	Body            string            `yaml:"body"`
	FollowRedirects bool              `yaml:"follow_redirects"` // 是否跟随重定向,默认跟随重定向
}

type Source added in v1.2.0

type Source struct {
	Path    string
	SHA256  string
	Builtin bool
}

Source 记录实际加载的规则文件;摘要只在加载时计算。

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL