
sj v2.7.0
एक्सपोज़्ड (Swagger/OpenAPI) परिभाषा फ़ाइलों में परिभाषित एंडपॉइंट्स के ऑडिटिंग के लिए एक उपकरण।
sj (Swagger Jacker)

sj एक कमांड लाइन उपकरण है जिसे एक्सपोज़ किए गए Swagger/OpenAPI परिभाषा फ़ाइलों के ऑडिटिंग में सहायता के लिए डिज़ाइन किया गया है। यह संबंधित API एंडपॉइंट्स पर कमजोर प्रमाणीकरण की जाँच करता है। यह मैन्युअल भेद्यता परीक्षण के लिए कमांड टेम्पलेट भी प्रदान करता है।
यह परिभाषा फ़ाइल को पार्स करके पथ, पैरामीटर और स्वीकृत विधियों का पता लगाता है, फिर परिणामों का उपयोग पाँच उप-कमांडों में से एक के साथ करता है:
automate- अनुरोधों की एक श्रृंखला तैयार करता है और प्रतिक्रिया की स्थिति कोड का विश्लेषण करता है।prepare- मैन्युअल परीक्षण के लिए उपयोग करने के लिए कमांड की एक सूची उत्पन्न करता है।endpoints- कच्चे API मार्गों की एक सूची उत्पन्न करता है। पथ मानों को परीक्षण डेटा से प्रतिस्थापित नहीं किया जाएगा।brute- सामान्य रूप से उपयोग किए जाने वाले फ़ाइल पथों के आधार पर ऑपरेशन परिभाषाएँ खोजने के लिए लक्ष्य पर अनुरोधों की एक श्रृंखला भेजता है।convert- एक परिभाषा फ़ाइल को v2 से v3 में परिवर्तित करता है।
बिल्ड
स्रोत से संकलित करने के लिए, सुनिश्चित करें कि आपके पास Go संस्करण >= 1.22.5 स्थापित है और रिपॉजिटरी के अंदर go build चलाएँ:
$ git clone https://github.com/BishopFox/sj.git
$ cd sj/
$ go build .
इंस्टॉल करना
टूल का नवीनतम संस्करण स्थापित करने के लिए, चलाएँ:
$ go install github.com/BishopFox/sj@latest
# नोट: आपको अपने Go बाइनरी के पथ को अपने PATH एनवायरनमेंट वेरिएबल में रखने की भी आवश्यकता हो सकती है:
$ export PATH=$PATH:~/go/bin
उपयोग
प्रत्येक परिभाषित एंडपॉइंट पर अनुरोधों की एक श्रृंखला भेजने और प्रत्येक प्रतिक्रिया की स्थिति कोड का विश्लेषण करने के लिए
automateकमांड का उपयोग करें।
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080
Gathering API details.
Title: Swagger Petstore
Description: This is a sample server Petstore server. You can find out more about Swagger at [http://swagger.io](http://swagger.io) or on [irc.freenode.net, #swagger](http://swagger.io/irc/). For this sample, you can use the api key `special-key` to test the authorization filters.
✓ GET 200 /v2/pet/findByStatus
✓ GET 200 /v2/user/logout
⚠ POST 400 /v2/user/createWithArray
⚠ POST 400 /v2/store/order
✗ GET 404 /v2/store/order/1
⚠ POST 400 /v2/pet
⚠ PUT 415 /v2/pet
⚠ POST 400 /v2/user/createWithList
✗ GET 404 /v2/user/bishopfox
⚠ PUT 415 /v2/user/bishopfox
⚠ POST 400 /v2/user
⚠ POST 415 /v2/pet/1/uploadImage
✓ GET 200 /v2/pet/findByTags
✗ GET 404 /v2/pet/1
⚠ POST 415 /v2/pet/1
✓ GET 200 /v2/store/inventory
✓ GET 200 /v2/user/login
आप मिलान किए गए अनुरोधों को एक अलग प्रॉक्सी (जैसे, Burp Suite) के माध्यम से पुनः चलाने के लिए --replay-proxy ध्वज का उपयोग कर सकते हैं। इससे आप एक प्रॉक्सी (या सीधे) के माध्यम से सभी ट्रैफ़िक को रूट कर सकते हैं जबकि केवल दिलचस्प परिणाम अपने इंटरसेप्शन प्रॉक्सी को भेज सकते हैं:
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi --replay-proxy http://127.0.0.1:8080
आप इसे --proxy के साथ भी जोड़ सकते हैं ताकि स्कैनिंग ट्रैफ़िक को एक अलग प्रॉक्सी के माध्यम से रूट किया जा सके जबकि मैचों को Burp पर पुनः चलाया जा सके:
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://proxy:9090 --replay-proxy http://127.0.0.1:8080
आप आंशिक (या पूर्ण) प्रतिक्रिया देखने के लिए विस्तृत आउटपुट का अनुरोध भी कर सकते हैं:
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080 -v
Gathering API details.
Title: Swagger Petstore
Description: This is a sample server Petstore server. You can find out more about Swagger at [http://swagger.io](http://swagger.io) or on [irc.freenode.net, #swagger](http://swagger.io/irc/). For this sample, you can use the api key `special-key` to test the authorization filters.
✗ GET 404 /v2/user/bishopfox
{"code":1,"type":"error","message":"User not found
⚠ PUT 415 /v2/user/bishopfox
{"code":415,"type":"unknown","message":"com.sun.je
✓ GET 200 /v2/user/logout
{"code":200,"type":"unknown","message":"ok"}
⚠ POST 400 /v2/user/createWithArray
{"code":400,"type":"unknown","message":"bad input"
⚠ POST 400 /v2/user/createWithList
{"code":400,"type":"unknown","message":"bad input"
✗ GET 404 /v2/pet/1
{"code":1,"type":"error","message":"Pet not found"
⚠ POST 415 /v2/pet/1
{"code":415,"type":"unknown"}
✓ GET 200 /v2/store/inventory
{"sold":117,"string":26,"invalidStatus":1,"-1":1,"
⚠ POST 400 /v2/store/order
{"code":400,"type":"unknown","message":"bad input"
✓ GET 200 /v2/user/login
{"code":200,"type":"unknown","message":"logged in
⚠ POST 400 /v2/pet
{"code":400,"type":"unknown","message":"bad input"
⚠ PUT 415 /v2/pet
{"code":415,"type":"unknown","message":"com.sun.je
✓ GET 200 /v2/pet/findByStatus
[]
✓ GET 200 /v2/pet/findByTags
[]
✗ GET 404 /v2/store/order/1
{"code":1,"type":"error","message":"Order not foun
⚠ POST 400 /v2/user
{"code":400,"type":"unknown","message":"bad input"
⚠ POST 415 /v2/pet/1/uploadImage
{"code":415,"type":"unknown"}
मैन्युअल परीक्षण के लिए कमांड की एक सूची तैयार करने के लिए
prepareकमांड का उपयोग करें। वर्तमान मेंcurlऔरsqlmapदोनों का समर्थन करता है। आपको संभवतः इनमें थोड़ा बदलाव करना होगा।
$ sj prepare -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080
INFO[0000] Gathering API details.
Title: Swagger Petstore
Description: This is a sample server Petstore server. You can find out more about Swagger at [http://swagger.io](http://swagger.io) or on [irc.freenode.net, #swagger](http://swagger.io/irc/). For this sample, you can use the api key `special-key` to test the authorization filters.
$ curl -X POST "https://petstore.swagger.io/v2/pet/{petId}"
$ curl -X GET "https://petstore.swagger.io/v2/pet/{petId}"
$ curl -X GET "https://petstore.swagger.io/v2/store/inventory"
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithList" -d 'body=1'
$ curl -X GET "https://petstore.swagger.io/v2/user/logout"
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithArray" -d 'body=1'
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByStatus"
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByTags"
$ curl -X POST "https://petstore.swagger.io/v2/store/order" -d 'petId=1&quantity=1&shipDate=bishopfox&status=bishopfox&complete=1&id=1&body='
$ curl -X POST "https://petstore.swagger.io/v2/pet/{petId}/uploadImage"
$ curl -X POST "https://petstore.swagger.io/v2/pet" -d 'photoUrls=1&tags=1&status=bishopfox&id=1&category=&name=doggie&body='
$ curl -X PUT "https://petstore.swagger.io/v2/pet" -d 'id=1&category=&name=doggie&photoUrls=1&tags=1&status=bishopfox&body='
$ curl -X GET "https://petstore.swagger.io/v2/user/{username}"
$ curl -X PUT "https://petstore.swagger.io/v2/user/{username}" -d 'email=bishopfox&password=bishopfox&phone=bishopfox&userStatus=1&id=1&username=bishopfox&firstName=bishopfox&lastName=bishopfox&body='
$ curl -X GET "https://petstore.swagger.io/v2/user/login"
$ curl -X POST "https://petstore.swagger.io/v2/user" -d 'phone=bishopfox&userStatus=1&id=1&username=bishopfox&firstName=bishopfox&lastName=bishopfox&email=bishopfox&password=bishopfox&body='
$ curl -X GET "https://petstore.swagger.io/v2/store/order/{orderId}"
प्रदान की गई परिभाषा फ़ाइल से कच्चे एंडपॉइंट की सूची उत्पन्न करने के लिए
endpointsकमांड का उपयोग करें।
$ sj endpoints -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080