
PyJFuzz - Fuzzer de JSON en Python

PyJFuzz es un framework pequeño, extensible y listo para usar que se utiliza para fuzzear entradas JSON, como API REST de endpoints móviles, implementación JSON, navegadores, ejecutables de línea de comandos y mucho más.
| Versión | 1.1.0 |
|---|---|
| Página principal | http://www.mseclab.com/ |
| GitHub | https://github.com/mseclab/PyJFuzz |
| Autor | Daniele Linguaglossa (@dzonerzy) |
| Licencia | MIT - (ver archivo LICENSE) |
Dependencias
Para funcionar, PyJFuzz necesita algunas dependencias: bottle, netifaces, GitPython y gramfuzz. Puede instalarlas desde la instalación automática de setup.py.
Instalación
Puede instalar PyJFuzz con el siguiente comando
git clone https://github.com/mseclab/PyJFuzz.git && cd PyJFuzz && sudo python setup.py install
Herramienta CLI
Una vez instalado, PyJFuzz creará tanto una librería de Python como una utilidad de línea de comandos llamada pjf (captura de pantalla a continuación)
Librería
PyJFuzz también puede funcionar como una librería. Puede importarlo en su proyecto de la siguiente manera
from pyjfuzz.lib import *
Clases
Los objetos/clases disponibles son los siguientes:
Ejemplos
A continuación, algunos ejemplos triviales de cómo implementar un programa impulsado por PyJFuzz
simple_fuzzer.py
from argparse import Namespace
from pyjfuzz.lib import *
config = PJFConfiguration(Namespace(json={"test": ["1", 2, True]}, nologo=True, level=6))
fuzzer = PJFFactory(config)
while True:
print fuzzer.fuzzed
custom_techniques.py
from argparse import Namespace
from pyjfuzz.lib import *
# Techniques may be defined by group , or by technique number
# groups are CHTPRSX , to understand what they are , please run pyjfuzz with -h switch or look at the command line screenshot
# This below will initalizate a config object which use only the P group attacks where P stay for Path Traversal
config = PJFConfiguration(Namespace(json={"test": ["1", 2, True]}, nologo=True, level=6, techniques="P"))
# once a config object is defined you can access to config.techniques to view the selected techniques for your group
print("Techniques IDs: {0}".format(str(config.techniques)))
# you can eventually modify them!
config.techniques = [2]
# This way only attack number 2 (LFI Attack) will be performed!
fuzzer = PJFFactory(config)
while True:
print fuzzer.fuzzed
simple_server.py
from argparse import Namespace
from pyjfuzz.lib import *
config = PJFConfiguration(Namespace(json={"test": ["1", 2, True]}, nologo=True, level=6, debug=True, indent=True))
PJFServer(config).run()
A veces, es posible que necesite modificar configuraciones estándar no personalizables, como el puerto del servidor HTTPS o HTTP. Esto se puede hacer de la siguiente manera
from argparse import Namespace
from pyjfuzz.lib import *
config = PJFConfiguration(Namespace(json={"test": ["1", 2, True]}, nologo=True, level=6, indent=True))
print config.ports["servers"]["HTTP_PORT"] # 8080
print config.ports["servers"]["HTTPS_PORT"] # 8443
print config.ports["servers"]["TCASE_PORT"] # 8888
config.ports["servers"]["HTTPS_PORT"] = 443 # Change HTTPS port to 443
Recuerde: Al cambiar los puertos predeterminados, siempre debe manejar las excepciones debido a los privilegios necesarios.
A continuación, una lista completa de todas las configuraciones/personalizaciones disponibles del objeto PJFConfiguration:
Tabla de configuración