You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自定义Nuclei模板报context deadline exceeded错误的排查与解决

关于Nuclei模板出现“context deadline exceeded”错误的排查与修复

问题描述

我编写了一个检测WordPress站点是否启用目录列表的Nuclei模板,通过请求/wp-content/uploads/端点并匹配“Index of”字符串判断结果,但一直出现“context deadline exceeded”错误。已尝试切换请求类型为raw再切回basic,问题未解决,且Project Discovery仓库中其他模板可正常运行。原模板内容如下:

id: wordpress-directory-listing
info:
  name: /wp-content/uploads - Directory Listing Enabled
  author: winteri3coming
  severity: high
  description: detects if directory listing is enabled at /wp-content/uploads/.
  tags: wordpress

requests:
  - method: GET
    path:
      - "{{BaseURL}}/wp-content/uploads/"
    unsafe: true
    matchers:
      - type: regex
        regex:
          - "[Ii]ndex of"

错误原因分析

  1. 缺失自定义超时配置:Nuclei默认超时时间较短,若目标站点响应缓慢、网络延迟高,会触发超时错误。
  2. 无请求重试机制:单次请求遇到网络波动或临时故障时,直接返回超时,没有重试逻辑。
  3. 不必要的unsafe参数:unsafe: true用于标记有风险的修改类请求(如POST/PUT),GET请求为只读操作,该参数不仅无效,还可能干扰请求处理逻辑。

修复方案与模板优化

针对以上问题,对模板做如下修改:

  1. 添加自定义超时配置,延长请求等待时间
  2. 增加重试机制,提升请求成功率
  3. 移除无用的unsafe参数
  4. 优化正则匹配(可选,统一匹配大小写或更精准的规则)

修改后的完整模板:

id: wordpress-directory-listing
info:
  name: /wp-content/uploads - Directory Listing Enabled
  author: winteri3coming
  severity: high
  description: Detects if directory listing is enabled at /wp-content/uploads/.
  tags: wordpress

requests:
  - method: GET
    path:
      - "{{BaseURL}}/wp-content/uploads/"
    # 自定义超时时间,根据实际情况调整
    timeout: 15s
    # 重试次数与间隔
    retry: 2
    retry-delay: 1s
    matchers:
      - type: regex
        regex:
          - "(?i)index of"
        # 明确指定匹配位置为响应体,避免误匹配响应头
        part: body

额外说明

  • 超时时间可根据目标网络环境调整,建议在10-20s区间内选择
  • 重试次数不宜过多,避免给目标站点造成额外负载
  • 正则中(?i)标记可实现大小写不敏感匹配,比[Ii]写法更简洁

内容的提问来源于stack exchange,提问作者B.Djo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 10:10:49