package file import ( "bufio" "strings" "time" "github.com/projectdiscovery/nuclei/v2/pkg/model" "github.com/projectdiscovery/nuclei/v2/pkg/operators/extractors" "github.com/projectdiscovery/nuclei/v2/pkg/operators/matchers" "github.com/projectdiscovery/nuclei/v2/pkg/output" "github.com/projectdiscovery/nuclei/v2/pkg/types" ) // Match matches a generic data response again a given matcher func (r *Request) Match(data map[string]interface{}, matcher *matchers.Matcher) (bool, []string) { partString := matcher.Part switch partString { case "body", "all", "data", "": partString = "raw" } item, ok := data[partString] if !ok { return false, []string{} } itemStr := types.ToString(item) switch matcher.GetType() { case matchers.SizeMatcher: return matcher.Result(matcher.MatchSize(len(itemStr))), []string{} case matchers.WordsMatcher: return matcher.ResultWithMatchedSnippet(matcher.MatchWords(itemStr, nil)) case matchers.RegexMatcher: return matcher.ResultWithMatchedSnippet(matcher.MatchRegex(itemStr)) case matchers.BinaryMatcher: return matcher.ResultWithMatchedSnippet(matcher.MatchBinary(itemStr)) case matchers.DSLMatcher: return matcher.Result(matcher.MatchDSL(data)), []string{} } return false, []string{} } // Extract performs extracting operation for an extractor on model and returns true or false. func (r *Request) Extract(data map[string]interface{}, extractor *extractors.Extractor) map[string]struct{} { partString := extractor.Part switch partString { case "body", "all", "data", "": partString = "raw" } item, ok := data[partString] if !ok { return nil } itemStr := types.ToString(item) switch extractor.GetType() { case extractors.RegexExtractor: return extractor.ExtractRegex(itemStr) case extractors.KValExtractor: return extractor.ExtractKval(data) } return nil } // responseToDSLMap converts a DNS response to a map for use in DSL matching func (r *Request) responseToDSLMap(raw, host, matched string) output.InternalEvent { data := make(output.InternalEvent, 5) // Some data regarding the request metadata data["path"] = host data["matched"] = matched data["raw"] = raw data["template-id"] = r.options.TemplateID data["template-info"] = r.options.TemplateInfo data["template-path"] = r.options.TemplatePath return data } // MakeResultEvent creates a result event from internal wrapped event func (r *Request) MakeResultEvent(wrapped *output.InternalWrappedEvent) []*output.ResultEvent { if len(wrapped.OperatorsResult.DynamicValues) > 0 { return nil } results := make([]*output.ResultEvent, 0, len(wrapped.OperatorsResult.Matches)+1) // If we have multiple matchers with names, write each of them separately. if len(wrapped.OperatorsResult.Matches) > 0 { for k := range wrapped.OperatorsResult.Matches { data := r.makeResultEventItem(wrapped) data.MatcherName = k results = append(results, data) } } else if len(wrapped.OperatorsResult.Extracts) > 0 { for k, v := range wrapped.OperatorsResult.Extracts { data := r.makeResultEventItem(wrapped) data.ExtractedResults = v data.ExtractorName = k results = append(results, data) } } else { data := r.makeResultEventItem(wrapped) results = append(results, data) } raw, ok := wrapped.InternalEvent["raw"] if !ok { return results } rawStr, ok := raw.(string) if !ok { return results } // Identify the position of match in file using a dirty hack. for _, result := range results { for _, extraction := range result.ExtractedResults { scanner := bufio.NewScanner(strings.NewReader(rawStr)) line := 1 for scanner.Scan() { if strings.Contains(scanner.Text(), extraction) { if result.FileToIndexPosition == nil { result.FileToIndexPosition = make(map[string]int) } result.FileToIndexPosition[result.Matched] = line continue } line++ } } } return results } func (r *Request) makeResultEventItem(wrapped *output.InternalWrappedEvent) *output.ResultEvent { data := &output.ResultEvent{ TemplateID: types.ToString(wrapped.InternalEvent["template-id"]), TemplatePath: types.ToString(wrapped.InternalEvent["template-path"]), Info: wrapped.InternalEvent["template-info"].(model.Info), Type: "file", Path: types.ToString(wrapped.InternalEvent["path"]), Matched: types.ToString(wrapped.InternalEvent["matched"]), Host: types.ToString(wrapped.InternalEvent["matched"]), ExtractedResults: wrapped.OperatorsResult.OutputExtracts, Response: types.ToString(wrapped.InternalEvent["raw"]), Timestamp: time.Now(), } return data }