
PyJFuzz - Python JSON Fuzzer

PyJFuzz ist ein kleines, erweiterbares und sofort einsatzbereites Framework zum Fuzzing von JSON-Eingaben, wie z.B. mobile REST-API-Endpoints, JSON-Implementierungen, Browser, CLI-Anwendungen und vieles mehr.
| Version | 1.1.0 |
|---|---|
| Startseite | http://www.mseclab.com/ |
| GitHub | https://github.com/mseclab/PyJFuzz |
| Autor | Daniele Linguaglossa (@dzonerzy) |
| Lizenz | MIT - (siehe LICENSE-Datei) |
Abhängigkeiten
Damit PyJFuzz funktioniert, benötigt es einige Abhängigkeiten: bottle, netifaces, GitPython und gramfuzz. Diese können über die automatische setup.py-Installation installiert werden.
Installation
Sie können PyJFuzz mit folgendem Befehl installieren:
git clone https://github.com/mseclab/PyJFuzz.git && cd PyJFuzz && sudo python setup.py install
CLI-Tool
Nach der Installation erstellt PyJFuzz sowohl eine Python-Bibliothek als auch ein Befehlszeilenprogramm namens pjf (siehe Screenshot unten)
Bibliothek
PyJFuzz kann auch als Bibliothek arbeiten. Sie können sie wie folgt in Ihr Projekt importieren:
from pyjfuzz.lib import *
Klassen
Die verfügbaren Objekte/Klassen sind die folgenden:
Beispiele
Im Folgenden finden Sie einige triviale Beispiele für die Implementierung eines PyJFuzz-gestützten Programms.
simple_fuzzer.py
from argparse import Namespace
from pyjfuzz.lib import *
config = PJFConfiguration(Namespace(json={"test": ["1", 2, True]}, nologo=True, level=6))
fuzzer = PJFFactory(config)
while True:
print fuzzer.fuzzed
custom_techniques.py
from argparse import Namespace
from pyjfuzz.lib import *
# Techniques may be defined by group , or by technique number
# groups are CHTPRSX , to understand what they are , please run pyjfuzz with -h switch or look at the command line screenshot
# This below will initalizate a config object which use only the P group attacks where P stay for Path Traversal
config = PJFConfiguration(Namespace(json={"test": ["1", 2, True]}, nologo=True, level=6, techniques="P"))
# once a config object is defined you can access to config.techniques to view the selected techniques for your group
print("Techniques IDs: {0}".format(str(config.techniques)))
# you can eventually modify them!
config.techniques = [2]
# This way only attack number 2 (LFI Attack) will be performed!
fuzzer = PJFFactory(config)
while True:
print fuzzer.fuzzed
simple_server.py
from argparse import Namespace
from pyjfuzz.lib import *
config = PJFConfiguration(Namespace(json={"test": ["1", 2, True]}, nologo=True, level=6, debug=True, indent=True))
PJFServer(config).run()
Manchmal müssen Sie standardmäßige, nicht anpassbare Einstellungen wie HTTPS- oder HTTP-Server-Port ändern. Dies kann auf folgende Weise erfolgen:
from argparse import Namespace
from pyjfuzz.lib import *
config = PJFConfiguration(Namespace(json={"test": ["1", 2, True]}, nologo=True, level=6, indent=True))
print config.ports["servers"]["HTTP_PORT"] # 8080
print config.ports["servers"]["HTTPS_PORT"] # 8443
print config.ports["servers"]["TCASE_PORT"] # 8888
config.ports["servers"]["HTTPS_PORT"] = 443 # Change HTTPS port to 443
Denken Sie daran: Beim Ändern der Standard-Ports sollten Sie immer Ausnahmen behandeln, da Berechtigungen erforderlich sind!
Nachfolgend finden Sie eine umfassende Liste aller verfügbaren Einstellungen/Anpassungen des PJFConfiguration-Objekts:
Konfigurationstabelle