mirror of
https://github.com/projectdiscovery/nuclei.git
synced 2025-12-25 12:45:28 +00:00
* feat: added initial live DAST server implementation * feat: more logging + misc additions * feat: auth file support enhancements for more complex scenarios + misc * feat: added io.Reader support to input providers for http * feat: added stats db to fuzzing + use sdk for dast server + misc * feat: more additions and enhancements * misc changes to live server * misc * use utils pprof server * feat: added simpler stats tracking system * feat: fixed analyzer timeout issue + missing case fix * misc changes fix * feat: changed the logics a bit + misc changes and additions * feat: re-added slope checks + misc * feat: added baseline measurements for time based checks * chore(server): fix typos Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * fix(templates): potential DOM XSS Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * fix(authx): potential NIL deref Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * feat: misc review changes * removed debug logging * feat: remove existing cookies only * feat: lint fixes * misc * misc text update * request endpoint update * feat: added tracking for status code, waf-detection & grouped errors (#6028) * feat: added tracking for status code, waf-detection & grouped errors * lint error fixes * feat: review changes + moving to package + misc --------- Co-authored-by: sandeep <8293321+ehsandeep@users.noreply.github.com> * fix var dump (#5921) * fix var dump * fix dump test * Added filename length restriction for debug mode (-srd flag) (#5931) Co-authored-by: Andrey Matveenko <an.matveenko@vkteam.ru> * more updates * Update pkg/output/stats/waf/waf.go Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> --------- Co-authored-by: sandeep <8293321+ehsandeep@users.noreply.github.com> Co-authored-by: Dwi Siswanto <25837540+dwisiswant0@users.noreply.github.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Dogan Can Bakir <65292895+dogancanbakir@users.noreply.github.com> Co-authored-by: 9flowers <51699499+Lercas@users.noreply.github.com> Co-authored-by: Andrey Matveenko <an.matveenko@vkteam.ru> Co-authored-by: Sandeep Singh <sandeep@projectdiscovery.io>
107 lines
2.2 KiB
Go
107 lines
2.2 KiB
Go
// Package stats implements a statistics recording module for
|
|
// nuclei fuzzing.
|
|
package stats
|
|
|
|
import (
|
|
"fmt"
|
|
"log"
|
|
"net/url"
|
|
|
|
"github.com/pkg/errors"
|
|
)
|
|
|
|
// Tracker is a stats tracker module for fuzzing server
|
|
type Tracker struct {
|
|
database *simpleStats
|
|
}
|
|
|
|
// NewTracker creates a new tracker instance
|
|
func NewTracker() (*Tracker, error) {
|
|
db, err := NewSimpleStats()
|
|
if err != nil {
|
|
return nil, errors.Wrap(err, "could not create new tracker")
|
|
}
|
|
|
|
tracker := &Tracker{
|
|
database: db,
|
|
}
|
|
return tracker, nil
|
|
}
|
|
|
|
func (t *Tracker) GetStats() SimpleStatsResponse {
|
|
return t.database.GetStatistics()
|
|
}
|
|
|
|
// Close closes the tracker
|
|
func (t *Tracker) Close() {
|
|
t.database.Close()
|
|
}
|
|
|
|
// FuzzingEvent is a fuzzing event
|
|
type FuzzingEvent struct {
|
|
URL string
|
|
ComponentType string
|
|
ComponentName string
|
|
TemplateID string
|
|
PayloadSent string
|
|
StatusCode int
|
|
Matched bool
|
|
RawRequest string
|
|
RawResponse string
|
|
Severity string
|
|
|
|
siteName string
|
|
}
|
|
|
|
func (t *Tracker) RecordResultEvent(event FuzzingEvent) {
|
|
event.siteName = getCorrectSiteName(event.URL)
|
|
if err := t.database.InsertMatchedRecord(event); err != nil {
|
|
log.Printf("could not insert matched record: %s", err)
|
|
}
|
|
}
|
|
|
|
type ComponentEvent struct {
|
|
URL string
|
|
ComponentType string
|
|
ComponentName string
|
|
|
|
siteName string
|
|
}
|
|
|
|
func (t *Tracker) RecordComponentEvent(event ComponentEvent) {
|
|
event.siteName = getCorrectSiteName(event.URL)
|
|
if err := t.database.InsertComponent(event); err != nil {
|
|
log.Printf("could not insert component record: %s", err)
|
|
}
|
|
}
|
|
|
|
type ErrorEvent struct {
|
|
TemplateID string
|
|
URL string
|
|
Error string
|
|
}
|
|
|
|
func (t *Tracker) RecordErrorEvent(event ErrorEvent) {
|
|
if err := t.database.InsertError(event); err != nil {
|
|
log.Printf("could not insert error record: %s", err)
|
|
}
|
|
}
|
|
|
|
func getCorrectSiteName(originalURL string) string {
|
|
parsed, err := url.Parse(originalURL)
|
|
if err != nil {
|
|
return ""
|
|
}
|
|
|
|
// Site is the host:port combo
|
|
siteName := parsed.Host
|
|
if parsed.Port() == "" {
|
|
if parsed.Scheme == "https" {
|
|
siteName = fmt.Sprintf("%s:443", siteName)
|
|
} else if parsed.Scheme == "http" {
|
|
siteName = fmt.Sprintf("%s:80", siteName)
|
|
}
|
|
}
|
|
return siteName
|
|
}
|