mirror of
https://github.com/shmilylty/OneForAll.git
synced 2026-08-26 12:57:50 +08:00
完善cname黑名单过滤机制
This commit is contained in:
@@ -157,7 +157,7 @@ def gen_subdomains(expression, path):
|
|||||||
"""
|
"""
|
||||||
Generate subdomains
|
Generate subdomains
|
||||||
|
|
||||||
:param str expression: generate subdomains's expression
|
:param str expression: generate subdomains expression
|
||||||
:param str path: path of wordlist
|
:param str path: path of wordlist
|
||||||
:return set subdomains: list of subdomains
|
:return set subdomains: list of subdomains
|
||||||
"""
|
"""
|
||||||
@@ -188,7 +188,7 @@ def gen_fuzz_subdomains(expression, rule, fuzzlist):
|
|||||||
"""
|
"""
|
||||||
Generate subdomains based on fuzz mode
|
Generate subdomains based on fuzz mode
|
||||||
|
|
||||||
:param str expression: generate subdomains's expression
|
:param str expression: generate subdomains expression
|
||||||
:param str rule: regexp rule
|
:param str rule: regexp rule
|
||||||
:param str fuzzlist: fuzz dictionary
|
:param str fuzzlist: fuzz dictionary
|
||||||
:return set subdomains: list of subdomains
|
:return set subdomains: list of subdomains
|
||||||
@@ -217,7 +217,7 @@ def gen_word_subdomains(expression, path):
|
|||||||
"""
|
"""
|
||||||
Generate subdomains based on word mode
|
Generate subdomains based on word mode
|
||||||
|
|
||||||
:param str expression: generate subdomains's expression
|
:param str expression: generate subdomains expression
|
||||||
:param str path: path of wordlist
|
:param str path: path of wordlist
|
||||||
:return set subdomains: list of subdomains
|
:return set subdomains: list of subdomains
|
||||||
"""
|
"""
|
||||||
@@ -375,14 +375,14 @@ def check_dict():
|
|||||||
exit(0)
|
exit(0)
|
||||||
|
|
||||||
|
|
||||||
def gen_result_infos(items, infos, subdomains, ip_times, wc_ips, wc_ttl, bk_cname):
|
def gen_result_infos(items, infos, subdomains, ip_times, wc_ips, wc_ttl):
|
||||||
qname = items.get('name')[:-1] # 去除最右边的`.`点号
|
qname = items.get('name')[:-1] # 去除最右边的`.`点号
|
||||||
reason = items.get('status')
|
reason = items.get('status')
|
||||||
resolver = items.get('resolver')
|
resolver = items.get('resolver')
|
||||||
data = items.get('data')
|
data = items.get('data')
|
||||||
answers = data.get('answers')
|
answers = data.get('answers')
|
||||||
info = dict()
|
info = dict()
|
||||||
cname = list()
|
cnames = list()
|
||||||
ips = list()
|
ips = list()
|
||||||
public = list()
|
public = list()
|
||||||
times = list()
|
times = list()
|
||||||
@@ -397,13 +397,14 @@ def gen_result_infos(items, infos, subdomains, ip_times, wc_ips, wc_ttl, bk_cnam
|
|||||||
have_a_record = True
|
have_a_record = True
|
||||||
ttl = answer.get('ttl')
|
ttl = answer.get('ttl')
|
||||||
ttls.append(ttl)
|
ttls.append(ttl)
|
||||||
cname.append(answer.get('name')[:-1]) # 去除最右边的`.`点号
|
cname = answer.get('name')[:-1]
|
||||||
|
cnames.append(cname) # 去除最右边的`.`点号
|
||||||
ip = answer.get('data')
|
ip = answer.get('data')
|
||||||
ips.append(ip)
|
ips.append(ip)
|
||||||
public.append(utils.ip_is_public(ip))
|
public.append(utils.ip_is_public(ip))
|
||||||
num = ip_times.get(ip)
|
num = ip_times.get(ip)
|
||||||
times.append(num)
|
times.append(num)
|
||||||
isvalid, reason = is_valid_subdomain(ip, ttl, num, wc_ips, wc_ttl, cname, bk_cname)
|
isvalid, reason = is_valid_subdomain(ip, ttl, num, wc_ips, wc_ttl, cname)
|
||||||
logger.log('TRACE', f'{ip} effective: {isvalid} reason: {reason}')
|
logger.log('TRACE', f'{ip} effective: {isvalid} reason: {reason}')
|
||||||
is_valid_flags.append(isvalid)
|
is_valid_flags.append(isvalid)
|
||||||
if not have_a_record:
|
if not have_a_record:
|
||||||
@@ -413,7 +414,7 @@ def gen_result_infos(items, infos, subdomains, ip_times, wc_ips, wc_ttl, bk_cnam
|
|||||||
info['resolve'] = 1
|
info['resolve'] = 1
|
||||||
info['reason'] = reason
|
info['reason'] = reason
|
||||||
info['ttl'] = ttls
|
info['ttl'] = ttls
|
||||||
info['cname'] = cname
|
info['cname'] = cnames
|
||||||
info['ip'] = ips
|
info['ip'] = ips
|
||||||
info['public'] = public
|
info['public'] = public
|
||||||
info['times'] = times
|
info['times'] = times
|
||||||
@@ -454,7 +455,7 @@ def stat_ip_times(result_paths):
|
|||||||
return times
|
return times
|
||||||
|
|
||||||
|
|
||||||
def deal_output(output_paths, ip_times, wildcard_ips, wildcard_ttl, bk_cname):
|
def deal_output(output_paths, ip_times, wildcard_ips, wildcard_ttl):
|
||||||
logger.log('INFOR', f'Processing result')
|
logger.log('INFOR', f'Processing result')
|
||||||
infos = dict() # 用来记录所有域名有关信息
|
infos = dict() # 用来记录所有域名有关信息
|
||||||
subdomains = list() # 用来保存所有通过有效性检查的子域
|
subdomains = list() # 用来保存所有通过有效性检查的子域
|
||||||
@@ -480,8 +481,7 @@ def deal_output(output_paths, ip_times, wildcard_ips, wildcard_ttl, bk_cname):
|
|||||||
logger.log('TRACE', f'Processing {line}, {qname} no response')
|
logger.log('TRACE', f'Processing {line}, {qname} no response')
|
||||||
continue
|
continue
|
||||||
infos, subdomains = gen_result_infos(items, infos, subdomains,
|
infos, subdomains = gen_result_infos(items, infos, subdomains,
|
||||||
ip_times, wildcard_ips,
|
ip_times, wildcard_ips, wildcard_ttl)
|
||||||
wildcard_ttl, bk_cname)
|
|
||||||
return infos, subdomains
|
return infos, subdomains
|
||||||
|
|
||||||
|
|
||||||
@@ -515,10 +515,11 @@ def check_ip_times(times):
|
|||||||
return False
|
return False
|
||||||
|
|
||||||
|
|
||||||
def is_valid_subdomain(ip, ttl, times, wc_ips, wc_ttl, cname, bk_cname):
|
def is_valid_subdomain(ip, ttl, times, wc_ips, wc_ttl, cname):
|
||||||
ip_blacklist = settings.brute_ip_blacklist
|
ip_blacklist = settings.brute_ip_blacklist
|
||||||
if cname in bk_cname:
|
cname_blacklist = settings.brute_cname_blacklist
|
||||||
return 0, 'cname blacklist' # 有些泛解析会统一解析到一个cname上
|
if cname in cname_blacklist:
|
||||||
|
return 0, 'cname blacklist' # 有些泛解析会统一解析到一个cname上
|
||||||
if ip in ip_blacklist: # 解析ip在黑名单ip则为非法子域
|
if ip in ip_blacklist: # 解析ip在黑名单ip则为非法子域
|
||||||
return 0, 'IP blacklist'
|
return 0, 'IP blacklist'
|
||||||
if all([wc_ips, wc_ttl]): # 有泛解析记录才进行对比
|
if all([wc_ips, wc_ttl]): # 有泛解析记录才进行对比
|
||||||
@@ -583,11 +584,10 @@ class Brute(Module):
|
|||||||
def __init__(self, target=None, targets=None, process=None, concurrent=None,
|
def __init__(self, target=None, targets=None, process=None, concurrent=None,
|
||||||
word=False, wordlist=None, recursive=False, depth=None, nextlist=None,
|
word=False, wordlist=None, recursive=False, depth=None, nextlist=None,
|
||||||
fuzz=False, place=None, rule=None, fuzzlist=None, export=True,
|
fuzz=False, place=None, rule=None, fuzzlist=None, export=True,
|
||||||
alive=True, format='csv', path=None, bk_cname=[]):
|
alive=True, format='csv', path=None):
|
||||||
Module.__init__(self)
|
Module.__init__(self)
|
||||||
self.module = 'Brute'
|
self.module = 'Brute'
|
||||||
self.source = 'Brute'
|
self.source = 'Brute'
|
||||||
self.bk_cname = bk_cname
|
|
||||||
self.target = target
|
self.target = target
|
||||||
self.targets = targets
|
self.targets = targets
|
||||||
self.process_num = process or utils.get_process_num()
|
self.process_num = process or utils.get_process_num()
|
||||||
@@ -716,7 +716,7 @@ class Brute(Module):
|
|||||||
output_paths.append(output_path)
|
output_paths.append(output_path)
|
||||||
ip_times = stat_ip_times(output_paths)
|
ip_times = stat_ip_times(output_paths)
|
||||||
self.infos, self.subdomains = deal_output(output_paths, ip_times,
|
self.infos, self.subdomains = deal_output(output_paths, ip_times,
|
||||||
wildcard_ips, wildcard_ttl, self.bk_cname)
|
wildcard_ips, wildcard_ttl)
|
||||||
delete_file(dict_path, output_paths)
|
delete_file(dict_path, output_paths)
|
||||||
end = time.time()
|
end = time.time()
|
||||||
self.elapse = round(end - start, 1)
|
self.elapse = round(end - start, 1)
|
||||||
|
|||||||
@@ -60,6 +60,8 @@ enable_fuzz = False # 是否使用fuzz模式枚举域名
|
|||||||
fuzz_place = None # 指定爆破的位置 指定的位置用`*`表示 示例:www.*.example.com
|
fuzz_place = None # 指定爆破的位置 指定的位置用`*`表示 示例:www.*.example.com
|
||||||
fuzz_rule = None # fuzz域名的正则 示例:'[a-z][0-9]' 表示第一位是字母 第二位是数字
|
fuzz_rule = None # fuzz域名的正则 示例:'[a-z][0-9]' 表示第一位是字母 第二位是数字
|
||||||
brute_ip_blacklist = {'0.0.0.0', '0.0.0.1'} # IP黑名单 子域解析到IP黑名单则标记为非法子域
|
brute_ip_blacklist = {'0.0.0.0', '0.0.0.1'} # IP黑名单 子域解析到IP黑名单则标记为非法子域
|
||||||
|
# CNAME黑名单 子域解析到CNAME黑名单则标记为非法子域
|
||||||
|
brute_cname_blacklist = {'nonexist.sdo.com', 'shop.taobao.com'}
|
||||||
ip_appear_maximum = 100 # 多个子域解析到同一IP次数超过100次则标记为非法(泛解析)子域
|
ip_appear_maximum = 100 # 多个子域解析到同一IP次数超过100次则标记为非法(泛解析)子域
|
||||||
|
|
||||||
# 代理设置
|
# 代理设置
|
||||||
|
|||||||
+2
-3
@@ -83,11 +83,10 @@ class OneForAll(object):
|
|||||||
:param bool takeover: Scan subdomain takeover (default False)
|
:param bool takeover: Scan subdomain takeover (default False)
|
||||||
"""
|
"""
|
||||||
def __init__(self, target=None, targets=None, brute=None, dns=None, req=None,
|
def __init__(self, target=None, targets=None, brute=None, dns=None, req=None,
|
||||||
port=None, alive=None, format=None, path=None, takeover=None, bk_cname=[]):
|
port=None, alive=None, format=None, path=None, takeover=None):
|
||||||
self.target = target
|
self.target = target
|
||||||
self.targets = targets
|
self.targets = targets
|
||||||
self.brute = brute
|
self.brute = brute
|
||||||
self.bk_cname = bk_cname
|
|
||||||
self.dns = dns
|
self.dns = dns
|
||||||
self.req = req
|
self.req = req
|
||||||
self.port = port
|
self.port = port
|
||||||
@@ -198,7 +197,7 @@ class OneForAll(object):
|
|||||||
if self.brute:
|
if self.brute:
|
||||||
# Due to there will be a large number of dns resolution requests,
|
# Due to there will be a large number of dns resolution requests,
|
||||||
# may cause other network tasks to be error
|
# may cause other network tasks to be error
|
||||||
brute = Brute(self.domain, word=True, export=False, bk_cname=self.bk_cname)
|
brute = Brute(self.domain, word=True, export=False)
|
||||||
brute.check_env = False
|
brute.check_env = False
|
||||||
brute.quite = True
|
brute.quite = True
|
||||||
brute.run()
|
brute.run()
|
||||||
|
|||||||
Reference in New Issue
Block a user