nuclei/pkg/requests/http-request.go

166 lines
5.0 KiB
Go
Raw Normal View History

package requests
import (
2020-04-28 23:02:07 +02:00
"bufio"
2020-04-29 02:57:18 +02:00
"fmt"
2020-04-04 02:50:32 +05:30
"io/ioutil"
"net/http"
2020-04-04 03:26:11 +05:30
"net/url"
2020-04-04 02:50:32 +05:30
"strings"
"github.com/projectdiscovery/nuclei/pkg/extractors"
"github.com/projectdiscovery/nuclei/pkg/matchers"
2020-04-04 17:12:29 +05:30
retryablehttp "github.com/projectdiscovery/retryablehttp-go"
)
2020-04-22 22:45:02 +02:00
// HTTPRequest contains a request to be made from a template
type HTTPRequest struct {
// Method is the request method, whether GET, POST, PUT, etc
Method string `yaml:"method"`
// Path contains the path/s for the request
Path []string `yaml:"path"`
// Headers contains headers to send with the request
Headers map[string]string `yaml:"headers,omitempty"`
// Body is an optional parameter which contains the request body for POST methods, etc
Body string `yaml:"body,omitempty"`
// Matchers contains the detection mechanism for the request to identify
// whether the request was successful
Matchers []*matchers.Matcher `yaml:"matchers,omitempty"`
2020-04-26 05:50:33 +05:30
// MatchersCondition is the condition of the matchers
// whether to use AND or OR. Default is OR.
MatchersCondition string `yaml:"matchers-condition,omitempty"`
// matchersCondition is internal condition for the matchers.
matchersCondition matchers.ConditionType
// Extractors contains the extraction mechanism for the request to identify
// and extract parts of the response.
Extractors []*extractors.Extractor `yaml:"extractors,omitempty"`
// Redirects specifies whether redirects should be followed.
Redirects bool `yaml:"redirects,omitempty"`
// MaxRedirects is the maximum number of redirects that should be followed.
MaxRedirects int `yaml:"max-redirects,omitempty"`
// Raw contains raw requests
Raw []string `yaml:"raw,omitempty"`
}
2020-04-04 02:50:32 +05:30
// GetMatchersCondition returns the condition for the matcher
func (r *HTTPRequest) GetMatchersCondition() matchers.ConditionType {
return r.matchersCondition
}
// SetMatchersCondition sets the condition for the matcher
func (r *HTTPRequest) SetMatchersCondition(condition matchers.ConditionType) {
r.matchersCondition = condition
}
2020-04-29 02:57:18 +02:00
// MakeHTTPRequest creates a *http.Request from a request configuration
2020-04-22 22:45:02 +02:00
func (r *HTTPRequest) MakeHTTPRequest(baseURL string) ([]*retryablehttp.Request, error) {
2020-04-04 03:26:11 +05:30
parsed, err := url.Parse(baseURL)
if err != nil {
return nil, err
}
hostname := parsed.Hostname()
2020-04-04 02:50:32 +05:30
2020-04-29 02:57:18 +02:00
values := map[string]interface{}{
"BaseURL": baseURL,
"Hostname": hostname,
}
if len(r.Raw) > 0 {
2020-04-29 02:57:18 +02:00
return r.makeHTTPRequestFromRaw(baseURL, values)
}
return r.makeHTTPRequestFromModel(baseURL, values)
}
// MakeHTTPRequestFromModel creates a *http.Request from a request template
func (r *HTTPRequest) makeHTTPRequestFromModel(baseURL string, values map[string]interface{}) (requests []*retryablehttp.Request, err error) {
2020-04-30 17:39:33 +02:00
replacer := newReplacer(values)
2020-04-04 02:50:32 +05:30
for _, path := range r.Path {
2020-04-04 03:26:11 +05:30
// Replace the dynamic variables in the URL if any
2020-04-30 17:39:33 +02:00
URL := replacer.Replace(path)
2020-04-04 02:50:32 +05:30
2020-04-04 03:26:11 +05:30
// Build a request on the specified URL
2020-04-30 17:39:33 +02:00
req, err := http.NewRequest(r.Method, URL, nil)
2020-04-04 02:50:32 +05:30
if err != nil {
return nil, err
}
2020-04-29 02:57:18 +02:00
request, err := r.fillRequest(req, values)
2020-04-04 17:12:29 +05:30
if err != nil {
return nil, err
}
requests = append(requests, request)
2020-04-04 02:50:32 +05:30
}
2020-04-29 02:57:18 +02:00
return
2020-04-04 02:50:32 +05:30
}
2020-04-28 23:02:07 +02:00
// makeHTTPRequestFromRaw creates a *http.Request from a raw request
func (r *HTTPRequest) makeHTTPRequestFromRaw(baseURL string, values map[string]interface{}) (requests []*retryablehttp.Request, err error) {
2020-04-30 17:39:33 +02:00
replacer := newReplacer(values)
for _, raw := range r.Raw {
// Add trailing line
raw += "\n"
2020-04-29 02:57:18 +02:00
// Replace the dynamic variables in the URL if any
2020-04-30 17:39:33 +02:00
raw = replacer.Replace(raw)
2020-04-28 23:02:07 +02:00
// Build a parsed request from raw
parsedReq, err := http.ReadRequest(bufio.NewReader(strings.NewReader(raw)))
if err != nil {
return nil, err
}
// requests generated from http.ReadRequest have incorrect RequestURI, so they
// cannot be used to perform another request directly, we need to generate a new one
// with the new target url
finalURL := fmt.Sprintf("%s%s", baseURL, parsedReq.URL)
req, err := http.NewRequest(r.Method, finalURL, parsedReq.Body)
if err != nil {
return nil, err
}
2020-04-28 23:02:07 +02:00
// copy headers
2020-04-29 23:07:19 +02:00
req.Header = parsedReq.Header.Clone()
2020-04-28 23:02:07 +02:00
request, err := r.fillRequest(req, values)
if err != nil {
return nil, err
}
requests = append(requests, request)
2020-04-29 02:57:18 +02:00
}
2020-04-28 23:02:07 +02:00
return requests, nil
2020-04-29 02:57:18 +02:00
}
2020-04-28 23:02:07 +02:00
2020-04-29 02:57:18 +02:00
func (r *HTTPRequest) fillRequest(req *http.Request, values map[string]interface{}) (*retryablehttp.Request, error) {
2020-04-30 17:39:33 +02:00
replacer := newReplacer(values)
2020-04-29 02:57:18 +02:00
// Check if the user requested a request body
if r.Body != "" {
req.Body = ioutil.NopCloser(strings.NewReader(r.Body))
}
2020-04-28 23:02:07 +02:00
2020-04-29 02:57:18 +02:00
// Set the header values requested
for header, value := range r.Headers {
2020-04-30 17:39:33 +02:00
req.Header.Set(header, replacer.Replace(value))
2020-04-29 02:57:18 +02:00
}
2020-04-28 23:02:07 +02:00
2020-04-29 02:57:18 +02:00
// Set some headers only if the header wasn't supplied by the user
2020-04-29 23:07:19 +02:00
if _, ok := req.Header["User-Agent"]; !ok {
2020-04-29 02:57:18 +02:00
req.Header.Set("User-Agent", "Nuclei (@pdiscoveryio)")
}
2020-04-29 23:07:19 +02:00
if _, ok := req.Header["Accept"]; !ok {
2020-04-29 02:57:18 +02:00
req.Header.Set("Accept", "*/*")
}
2020-04-29 23:07:19 +02:00
if _, ok := req.Header["Accept-Language"]; !ok {
2020-04-29 02:57:18 +02:00
req.Header.Set("Accept-Language", "en")
2020-04-28 23:02:07 +02:00
}
2020-04-29 02:57:18 +02:00
req.Header.Set("Connection", "close")
req.Close = true
2020-04-28 23:02:07 +02:00
2020-04-29 02:57:18 +02:00
return retryablehttp.FromRequest(req)
2020-04-28 23:02:07 +02:00
}