nuclei/v2/pkg/protocols/file/request.go

241 lines
8.4 KiB
Go
Raw Normal View History

2021-01-01 15:28:28 +05:30
package file
import (
"bufio"
"encoding/hex"
"io"
2021-01-01 15:28:28 +05:30
"os"
"strings"
2022-02-25 01:49:14 +01:00
"time"
2021-01-01 15:28:28 +05:30
"github.com/docker/go-units"
2021-01-01 15:28:28 +05:30
"github.com/pkg/errors"
"github.com/remeh/sizedwaitgroup"
2021-01-01 15:28:28 +05:30
"github.com/projectdiscovery/gologger"
2022-02-25 01:49:14 +01:00
"github.com/projectdiscovery/nuclei/v2/pkg/model"
"github.com/projectdiscovery/nuclei/v2/pkg/operators"
2021-01-01 15:28:28 +05:30
"github.com/projectdiscovery/nuclei/v2/pkg/output"
"github.com/projectdiscovery/nuclei/v2/pkg/protocols"
"github.com/projectdiscovery/nuclei/v2/pkg/protocols/common/helpers/responsehighlighter"
templateTypes "github.com/projectdiscovery/nuclei/v2/pkg/templates/types"
2022-02-25 01:49:14 +01:00
"github.com/projectdiscovery/nuclei/v2/pkg/types"
2021-01-01 15:28:28 +05:30
)
var _ protocols.Request = &Request{}
// Type returns the type of the protocol request
func (request *Request) Type() templateTypes.ProtocolType {
return templateTypes.FileProtocol
}
2022-02-25 00:55:05 +01:00
type FileMatch struct {
Data string
Line int
ByteIndex int
Match bool
Extract bool
Expr string
2022-02-25 08:59:10 +01:00
Raw string
2022-02-25 00:55:05 +01:00
}
2021-01-01 15:28:28 +05:30
// ExecuteWithResults executes the protocol requests and returns results instead of writing them.
func (request *Request) ExecuteWithResults(input string, metadata, previous output.InternalEvent, callback protocols.OutputEventCallback) error {
wg := sizedwaitgroup.New(request.options.Options.BulkSize)
2021-01-14 22:43:08 +05:30
err := request.getInputPaths(input, func(data string) {
request.options.Progress.AddToTotal(1)
2021-01-14 22:43:08 +05:30
wg.Add()
go func(filePath string) {
2021-01-14 22:43:08 +05:30
defer wg.Done()
file, err := os.Open(filePath)
2021-01-14 22:43:08 +05:30
if err != nil {
gologger.Error().Msgf("Could not open file path %s: %s\n", filePath, err)
2021-01-14 22:43:08 +05:30
return
}
defer file.Close()
2021-01-01 15:28:28 +05:30
2021-01-14 22:43:08 +05:30
stat, err := file.Stat()
if err != nil {
gologger.Error().Msgf("Could not stat file path %s: %s\n", filePath, err)
2021-01-14 22:43:08 +05:30
return
}
if stat.Size() >= request.maxSize {
gologger.Verbose().Msgf("Limiting %s processed data to %s bytes: exceeded max size\n", filePath, units.HumanSize(float64(request.maxSize)))
2021-01-16 14:10:24 +05:30
}
totalBytes := units.BytesSize(float64(stat.Size()))
fileReader := io.LimitReader(file, request.maxSize)
var bytesCount, linesCount, wordsCount int
isResponseDebug := request.options.Options.Debug || request.options.Options.DebugResponse
scanner := bufio.NewScanner(fileReader)
buffer := []byte{}
scanner.Buffer(buffer, int(chunkSize))
2022-02-25 00:55:05 +01:00
var fileMatches []FileMatch
2022-02-25 01:49:14 +01:00
exprLines := make(map[string][]int)
exprBytes := make(map[string][]int)
for scanner.Scan() {
2022-02-25 08:59:10 +01:00
lineContent := scanner.Text()
n := len(lineContent)
// update counters
currentBytes := bytesCount + n
processedBytes := units.BytesSize(float64(currentBytes))
gologger.Verbose().Msgf("[%s] Processing file %s chunk %s/%s", request.options.TemplateID, filePath, processedBytes, totalBytes)
2022-02-25 00:55:05 +01:00
dslMap := request.responseToDSLMap(&fileStatus{
2022-02-25 08:59:10 +01:00
raw: lineContent,
inputFilePath: input,
matchedFileName: filePath,
lines: linesCount,
words: wordsCount,
bytes: bytesCount,
})
2021-01-01 15:28:28 +05:30
2022-02-25 00:55:05 +01:00
if parts, ok := request.CompiledOperators.Execute(dslMap, request.Match, request.Extract, isResponseDebug); parts != nil && ok {
if parts.Extracts != nil {
for expr, extracts := range parts.Extracts {
for _, extract := range extracts {
fileMatches = append(fileMatches, FileMatch{
Data: extract,
Extract: true,
Line: linesCount + 1,
ByteIndex: bytesCount,
Expr: expr,
2022-02-25 08:59:10 +01:00
Raw: lineContent,
2022-02-25 00:55:05 +01:00
})
}
}
}
if parts.Matches != nil {
for expr, matches := range parts.Matches {
for _, match := range matches {
fileMatches = append(fileMatches, FileMatch{
Data: match,
Match: true,
Line: linesCount + 1,
ByteIndex: bytesCount,
Expr: expr,
2022-02-25 08:59:10 +01:00
Raw: lineContent,
2022-02-25 00:55:05 +01:00
})
}
}
}
}
2022-02-25 08:59:10 +01:00
currentLinesCount := 1 + strings.Count(lineContent, "\n")
linesCount += currentLinesCount
2022-02-25 08:59:10 +01:00
wordsCount += strings.Count(lineContent, " ")
bytesCount = currentBytes
}
2022-02-25 00:55:05 +01:00
2022-02-25 08:59:10 +01:00
// build event structure to interface with internal logic
2022-02-25 01:49:14 +01:00
internalEvent := request.responseToDSLMap(&fileStatus{
inputFilePath: input,
matchedFileName: filePath,
})
operatorResult := &operators.Result{}
for _, fileMatch := range fileMatches {
operatorResult.Matched = operatorResult.Matched || fileMatch.Match
operatorResult.Extracted = operatorResult.Extracted || fileMatch.Extract
switch {
case fileMatch.Extract:
if operatorResult.Extracts == nil {
operatorResult.Extracts = make(map[string][]string)
}
if _, ok := operatorResult.Extracts[fileMatch.Expr]; !ok {
operatorResult.Extracts[fileMatch.Expr] = []string{fileMatch.Data}
} else {
operatorResult.Extracts[fileMatch.Expr] = append(operatorResult.Extracts[fileMatch.Expr], fileMatch.Data)
}
operatorResult.OutputExtracts = append(operatorResult.OutputExtracts, fileMatch.Data)
operatorResult.OutputUnique = map[string]struct{}{}
case fileMatch.Match:
if operatorResult.Matches == nil {
operatorResult.Matches = make(map[string][]string)
}
if _, ok := operatorResult.Matches[fileMatch.Expr]; !ok {
operatorResult.Matches[fileMatch.Expr] = []string{fileMatch.Data}
} else {
operatorResult.Matches[fileMatch.Expr] = append(operatorResult.Matches[fileMatch.Expr], fileMatch.Data)
}
}
exprLines[fileMatch.Expr] = append(exprLines[fileMatch.Expr], fileMatch.Line)
exprBytes[fileMatch.Expr] = append(exprBytes[fileMatch.Expr], fileMatch.ByteIndex)
}
2022-02-25 00:55:05 +01:00
2022-02-25 01:49:14 +01:00
// build results
var results []*output.ResultEvent
for expr, items := range operatorResult.Matches {
results = append(results, &output.ResultEvent{
MatcherStatus: true,
TemplateID: types.ToString(internalEvent["template-id"]),
TemplatePath: types.ToString(internalEvent["template-path"]),
Info: internalEvent["template-info"].(model.Info),
Type: types.ToString(internalEvent["type"]),
Path: types.ToString(internalEvent["path"]),
Matched: types.ToString(internalEvent["path"]),
2022-02-25 01:49:14 +01:00
Host: types.ToString(internalEvent["host"]),
ExtractedResults: items,
// Response: types.ToString(wrapped.InternalEvent["raw"]),
2022-02-25 08:59:10 +01:00
Timestamp: time.Now(),
Lines: exprLines[expr],
MatcherName: expr,
2022-02-25 01:49:14 +01:00
})
}
for expr, items := range operatorResult.Extracts {
results = append(results, &output.ResultEvent{
MatcherStatus: true,
TemplateID: types.ToString(internalEvent["template-id"]),
TemplatePath: types.ToString(internalEvent["template-path"]),
Info: internalEvent["template-info"].(model.Info),
Type: types.ToString(internalEvent["type"]),
Path: types.ToString(internalEvent["path"]),
Matched: types.ToString(internalEvent["matched"]),
2022-02-25 01:49:14 +01:00
Host: types.ToString(internalEvent["host"]),
ExtractedResults: items,
Lines: exprLines[expr],
ExtractorName: expr,
2022-02-25 01:49:14 +01:00
// FileToIndexPosition: exprBytes,
Timestamp: time.Now(),
})
}
event := &output.InternalWrappedEvent{
InternalEvent: internalEvent,
Results: results,
OperatorsResult: operatorResult,
}
2022-02-25 08:59:10 +01:00
dumpResponse(event, request.options, fileMatches, filePath)
2022-02-25 01:49:14 +01:00
callback(event)
request.options.Progress.IncrementRequests()
2021-01-14 22:43:08 +05:30
}(data)
2021-01-01 15:28:28 +05:30
})
2021-01-14 22:43:08 +05:30
wg.Wait()
2021-01-01 15:28:28 +05:30
if err != nil {
request.options.Output.Request(request.options.TemplatePath, input, request.Type().String(), err)
request.options.Progress.IncrementFailedRequestsBy(1)
return errors.Wrap(err, "could not send file request")
2021-01-01 15:28:28 +05:30
}
return nil
2021-01-01 15:28:28 +05:30
}
2022-02-25 08:59:10 +01:00
func dumpResponse(event *output.InternalWrappedEvent, requestOptions *protocols.ExecuterOptions, filematches []FileMatch, filePath string) {
cliOptions := requestOptions.Options
if cliOptions.Debug || cliOptions.DebugResponse {
2022-02-25 00:55:05 +01:00
for _, fileMatch := range filematches {
2022-02-25 08:59:10 +01:00
lineContent := fileMatch.Raw
2022-02-25 00:55:05 +01:00
hexDump := false
2022-02-25 08:59:10 +01:00
if responsehighlighter.HasBinaryContent(lineContent) {
2022-02-25 00:55:05 +01:00
hexDump = true
2022-02-25 08:59:10 +01:00
lineContent = hex.Dump([]byte(lineContent))
2022-02-25 00:55:05 +01:00
}
2022-02-25 08:59:10 +01:00
highlightedResponse := responsehighlighter.Highlight(event.OperatorsResult, lineContent, cliOptions.NoColor, hexDump)
2022-02-25 00:55:05 +01:00
gologger.Debug().Msgf("[%s] Dumped match/extract file snippet for %s at line %d\n\n%s", requestOptions.TemplateID, filePath, fileMatch.Line, highlightedResponse)
}
}
}