diff --git a/oneforall/config.py b/oneforall/config.py index 61ca99b..1f1a0be 100644 --- a/oneforall/config.py +++ b/oneforall/config.py @@ -37,8 +37,8 @@ ips_appear_maximum = 10 # 同一IP集合出现次数超过10认为是泛解析 # 代理设置 enable_proxy = True # 是否使用代理 全局开关 proxy_all_module = False # 代理所有模块 -proxy_partial_module = ['GoogleQuery', 'AskSearch', 'DuckDuckGoSearch', 'GoogleAPISearch', - 'GoogleSearch', 'YahooSearch', 'YandexSearch'] # 代理自定义的模块 +proxy_partial_module = ['GoogleQuery', 'AskSearch', 'DuckDuckGoSearch', 'GoogleAPISearch', 'GoogleSearch', + 'YahooSearch', 'YandexSearch', 'CrossDomainXml', 'ContentSecurityPolicy'] # 代理自定义的模块 proxy_pool = [{'http': 'http://127.0.0.1:1080', 'https': 'https://127.0.0.1:1080'}] # 代理池 # proxy_pool = [{'http': 'socks5://127.0.0.1:10808', 'https': 'socks5://127.0.0.1:10808'}] # 代理池 diff --git a/oneforall/modules/check/cdx.py b/oneforall/modules/check/cdx.py index f4318a2..c3875e8 100644 --- a/oneforall/modules/check/cdx.py +++ b/oneforall/modules/check/cdx.py @@ -26,12 +26,18 @@ class CheckCDX(Module): :return: """ url = f'http://{self.domain}/crossdomain.xml' - self.header = self.get_header() - self.proxy = self.get_proxy(self.source) - resp = self.get(url) - if not resp: + urls = [f'http://{self.domain}/crossdomain.xml', f'https://{self.domain}/crossdomain.xml', + f'http://www.{self.domain}/crossdomain.xml', f'https://www.{self.domain}/crossdomain.xml'] + response = None + for url in urls: + self.header = self.get_header() + self.proxy = self.get_proxy(self.source) + response = self.get(url) + if response: + break + if not response: return - self.subdomains = match_subdomain(self.domain, resp.text) + self.subdomains = match_subdomain(self.domain, response.text) def run(self, rx_queue): """ diff --git a/oneforall/modules/check/csp.py b/oneforall/modules/check/csp.py index 916db3a..7d47a38 100644 --- a/oneforall/modules/check/csp.py +++ b/oneforall/modules/check/csp.py @@ -18,7 +18,7 @@ class CheckCSP(Module): Module.__init__(self) self.domain = self.register(domain) self.module = 'Check' - self.source = 'Content-Security-Policy' + self.source = 'ContentSecurityPolicy' self.header = header def check(self): @@ -26,11 +26,18 @@ class CheckCSP(Module): 正则匹配响应头中的内容安全策略字段以发现子域名 """ if not self.header: - url = f'http://www.{self.domain}' - resp = self.get(url) - if not resp: + urls = [f'http://{self.domain}', f'https://{self.domain}', + f'http://www.{self.domain}', f'https://www.{self.domain}'] + response = None + for url in urls: + self.header = self.get_header() + self.proxy = self.get_proxy(self.source) + response = self.get(url) + if response: + break + if not response: return - self.header = resp.headers + self.header = response.headers csp = self.header.get('Content-Security-Policy') if not csp: logger.log('DEBUG', f'{self.domain}域的响应头不存在内容安全策略字段')