You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GTFOBins二进制查询Bash函数问题排查及优化问询

高效提取GTFOBins利用代码的Bash实现

核心优化思路

直接用正则匹配HTML容易出错且维护性差,推荐用**HTML解析工具(如pup)**精准定位元素,比纯正则/awk组合更高效可靠。如果环境受限,也可以用curl+awk的轻量方案,但优先级还是专用解析工具更高。

实现代码(基于pup)

gtfobins() {
    local bin=$1
    local url="https://gtfobins.github.io/gtfobins/$bin/"
    
    # 检查二进制是否存在(HEAD请求,避免下载整个页面)
    if ! curl --head --silent --fail "$url" > /dev/null; then
        echo "Error: Binary '$bin' not found in GTFOBins"
        return 1
    fi

    # 提取功能列表
    local functions
    functions=$(curl --silent "$url" | pup '.function-name text{}')
    
    echo "Available functions for $bin:"
    # 给功能编号,方便选择
    local i=1
    local func_list=()
    while read -r func; do
        echo "$i. $func"
        func_list[$i]="$func"
        ((i++))
    done <<< "$functions"

    # 让用户选择功能
    read -p "Enter function number: " num
    if [[ ! "$num" =~ ^[0-9]+$ ]] || (( num < 1 || num >= i )); then
        echo "Invalid selection"
        return 1
    fi

    local target_func=${func_list[$num]}
    # 提取对应功能的利用代码(精准定位section下的code块)
    curl --silent "$url" | pup "section:has(.function-name:contains(\"$target_func\")) code text{}"
}

轻量替代方案(无pup,用awk)

如果环境没法安装pup,可以用正则结合awk提取(注意:该方案对GTFOBins页面结构变化敏感):

gtfobins_light() {
    local bin=$1
    local url="https://gtfobins.github.io/gtfobins/$bin/"
    
    if ! curl --head --silent --fail "$url" > /dev/null; then
        echo "Error: Binary '$bin' not found in GTFOBins"
        return 1
    fi

    local page=$(curl --silent "$url")
    # 提取功能列表
    echo "Available functions for $bin:"
    echo "$page" | awk -F'<h3 class="function-name"' 'NR>1 {split($2,a, /<\/h3>/); print NR-1". "a[1]}'
    
    read -p "Enter function number: " num
    # 提取对应功能的代码块
    echo "$page" | awk -v num="$num" '
        BEGIN {count=0; in_code=0}
        /<h3 class="function-name"/ {count++}
        count == num && /<code/ {in_code=1; next}
        count == num && /<\/code/ {in_code=0; exit}
        in_code == 1 {print $0}
    ' | sed 's/^[[:space:]]*//; s/[[:space:]]*$//' # 清理多余空格
}

优化点说明

  • 存在性检查用HEAD请求:比GET请求快很多,只验证页面是否存在,不下载完整内容。
  • 用pup解析HTML:避免正则匹配HTML的各种边缘情况,代码更简洁可靠。
  • 功能编号存储数组:避免二次解析页面查找目标功能,提升执行效率。

内容的提问来源于stack exchange,提问作者Psiber_Syn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 14:24:56