mirror of
https://github.com/shmilylty/OneForAll.git
synced 2026-08-26 12:57:50 +08:00
重构
This commit is contained in:
+10
-5
@@ -213,6 +213,8 @@ class AIOBrute(Module):
|
|||||||
self.nameservers = config.resolver_nameservers
|
self.nameservers = config.resolver_nameservers
|
||||||
self.ips_times = dict() # IP集合出现次数
|
self.ips_times = dict() # IP集合出现次数
|
||||||
self.enable_wildcard = False # 当前域名是否使用泛解析
|
self.enable_wildcard = False # 当前域名是否使用泛解析
|
||||||
|
self.wildcard_check = config.enable_wildcard_check
|
||||||
|
self.wildcard_deal = config.enable_wildcard_deal
|
||||||
self.wildcard_ips = set() # 泛解析IP集合
|
self.wildcard_ips = set() # 泛解析IP集合
|
||||||
self.wildcard_ttl = int() # 泛解析TTL整型值
|
self.wildcard_ttl = int() # 泛解析TTL整型值
|
||||||
|
|
||||||
@@ -239,16 +241,18 @@ class AIOBrute(Module):
|
|||||||
# logger.log('DEBUG', f'爆破{subdomain}时出错 {str(answers)}')
|
# logger.log('DEBUG', f'爆破{subdomain}时出错 {str(answers)}')
|
||||||
continue
|
continue
|
||||||
name, alias, ips = answer
|
name, alias, ips = answer
|
||||||
|
if name.endswith('.'):
|
||||||
|
name = name[0:-1]
|
||||||
# 取值 如果是首次出现的IP集合 出现次数先赋值0
|
# 取值 如果是首次出现的IP集合 出现次数先赋值0
|
||||||
value = self.ips_times.setdefault(str(ips), 0)
|
value = self.ips_times.setdefault(str(ips), 0)
|
||||||
self.ips_times[str(ips)] = value + 1
|
self.ips_times[str(ips)] = value + 1
|
||||||
# 目前域名开启了泛解析
|
# 目前域名开启了泛解析
|
||||||
if self.enable_wildcard:
|
if self.enable_wildcard and self.wildcard_deal:
|
||||||
# 通过对比查询的子域和响应的子域来判断真实子域
|
# 通过对比查询的子域和响应的子域来判断真实子域
|
||||||
# 去掉解析到CDN的情况
|
# 去掉解析到CDN的情况
|
||||||
if 'cdn' in name:
|
if 'cdn' or 'waf' in name:
|
||||||
continue
|
continue
|
||||||
if not name.endswith(self.domain + '.'):
|
if not name.endswith(self.domain):
|
||||||
continue
|
continue
|
||||||
# 通过对比解析到的IP集合的次数来判断真实子域
|
# 通过对比解析到的IP集合的次数来判断真实子域
|
||||||
if wildcard_by_times(ips, self.ips_times):
|
if wildcard_by_times(ips, self.ips_times):
|
||||||
@@ -262,8 +266,9 @@ class AIOBrute(Module):
|
|||||||
|
|
||||||
async def main(self, domain, rx_queue):
|
async def main(self, domain, rx_queue):
|
||||||
if not self.fuzz: # fuzz模式不探测域名是否使用泛解析
|
if not self.fuzz: # fuzz模式不探测域名是否使用泛解析
|
||||||
self.enable_wildcard, self.wildcard_ips, self.wildcard_ttl \
|
if self.wildcard_check:
|
||||||
= detect_wildcard(domain)
|
self.enable_wildcard, self.wildcard_ips, self.wildcard_ttl \
|
||||||
|
= detect_wildcard(domain)
|
||||||
tasks = self.gen_tasks(domain)
|
tasks = self.gen_tasks(domain)
|
||||||
logger.log('INFOR', f'正在爆破{domain}的域名')
|
logger.log('INFOR', f'正在爆破{domain}的域名')
|
||||||
# for task in tqdm.tqdm(tasks, total=len(tasks),
|
# for task in tqdm.tqdm(tasks, total=len(tasks),
|
||||||
|
|||||||
+3
-2
@@ -30,10 +30,11 @@ enable_partial_module = [] # 启用部分模块 必须禁用enable_all_module
|
|||||||
module_thread_timeout = 360.0 # 每个收集模块线程超时时间(默认6分钟)
|
module_thread_timeout = 360.0 # 每个收集模块线程超时时间(默认6分钟)
|
||||||
|
|
||||||
# 爆破模块设置
|
# 爆破模块设置
|
||||||
enable_brute_module = False # 使用爆破模块(默认禁用)
|
enable_brute_module = False # 使用爆破模块(默认False)
|
||||||
enable_dns_resolve = True # DNS解析子域(默认True)
|
enable_dns_resolve = True # DNS解析子域(默认True)
|
||||||
enable_http_request = True # HTTP请求子域(默认True)
|
enable_http_request = True # HTTP请求子域(默认True)
|
||||||
enable_wildcard_check = True # 开启泛解析检测 会去掉泛解析的子域
|
enable_wildcard_check = True # 开启泛解析检测(默认True)
|
||||||
|
enable_wildcard_deal = True # 开启泛解析处理(默认True)
|
||||||
# 爆破时使用的进程数(根据系统中CPU数量情况设置 不宜大于CPU数量 默认为系统中的CPU数量)
|
# 爆破时使用的进程数(根据系统中CPU数量情况设置 不宜大于CPU数量 默认为系统中的CPU数量)
|
||||||
brute_process_num = os.cpu_count()
|
brute_process_num = os.cpu_count()
|
||||||
brute_coroutine_num = 1024 # 爆破时每个进程下的协程数
|
brute_coroutine_num = 1024 # 爆破时每个进程下的协程数
|
||||||
|
|||||||
Reference in New Issue
Block a user