
sj v2.8.2
एक्सपोज़्ड (Swagger/OpenAPI) परिभाषा फ़ाइलों में परिभाषित एंडपॉइंट्स के ऑडिटिंग के लिए एक उपकरण।
sj (Swagger Jacker)

sj एक कमांड लाइन टूल है जिसे उजागर Swagger/OpenAPI परिभाषा फ़ाइलों का ऑडिट करने में सहायता के लिए डिज़ाइन किया गया है, जो संबंधित API एंडपॉइंट्स की कमजोर प्रमाणीकरण के लिए जाँच करता है। यह मैन्युअल भेद्यता परीक्षण के लिए कमांड टेम्पलेट्स भी प्रदान करता है।
यह परिभाषा फ़ाइल से पथ, पैरामीटर और स्वीकृत विधियों को पार्स करके ऐसा करता है, फिर परिणामों का उपयोग पाँच उप-कमांड्स में से एक के साथ करता है:
automate- अनुरोधों की एक श्रृंखला तैयार करता है और प्रतिक्रिया के स्टेटस कोड का विश्लेषण करता है।prepare- मैन्युअल परीक्षण के लिए उपयोग किए जाने वाले कमांड्स की सूची उत्पन्न करता है।endpoints- कच्चे API रूट्स की सूची उत्पन्न करता है। पथ मानों को परीक्षण डेटा से प्रतिस्थापित नहीं किया जाएगा।brute- सामान्यतः उपयोग किए जाने वाले फ़ाइल पथों के आधार पर ऑपरेशन परिभाषाओं को खोजने के लिए लक्ष्य पर अनुरोधों की एक श्रृंखला भेजता है।convert- एक परिभाषा फ़ाइल को v2 से v3 में परिवर्तित करता है।
Build
स्रोत से संकलित करने के लिए, सुनिश्चित करें कि आपके पास Go संस्करण >= 1.22.5 स्थापित है और रिपॉजिटरी के भीतर से go build चलाएँ:
$ git clone https://github.com/BishopFox/sj.git
$ cd sj/
$ go build .
Install
टूल का नवीनतम संस्करण स्थापित करने के लिए, चलाएँ:
$ go install github.com/BishopFox/sj@latest
# Note: you may also need to place the path to your Go binaries within your PATH environment variable:
$ export PATH=$PATH:~/go/bin
Usage
प्रत्येक परिभाषित एंडपॉइंट पर अनुरोधों की एक श्रृंखला भेजने और प्रत्येक प्रतिक्रिया के स्टेटस कोड का विश्लेषण करने के लिए
automateकमांड का उपयोग करें।
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080
Gathering API details.
⚠ POST 500 /v2/pet
⚠ PUT 500 /v2/pet
✓ GET 200 /v2/pet/findByStatus
✓ GET 200 /v2/pet/findByTags
✓ GET 200 /v2/pet/1
✓ POST 200 /v2/pet/1
⚠ POST N/A /v2/pet/1/uploadImage
✓ GET 200 /v2/store/inventory
⚠ POST N/A /v2/store/order
⚠ GET N/A /v2/store/order/1
✓ POST 200 /v2/user
⚠ POST N/A /v2/user/createWithArray
⚠ POST N/A /v2/user/createWithList
✓ GET 200 /v2/user/login
✓ GET 200 /v2/user/logout
✓ GET 200 /v2/user/bishopfox
✓ PUT 200 /v2/user/bishopfox
आप मिलान किए गए अनुरोधों को एक अलग प्रॉक्सी (जैसे, Burp Suite) के माध्यम से रीप्ले करने के लिए --replay-proxy फ़्लैग का उपयोग कर सकते हैं। यह आपको सभी ट्रैफ़िक को एक प्रॉक्सी (या सीधे) के माध्यम से रूट करने की सुविधा देता है, जबकि केवल रुचिकर परिणाम आपके इंटरसेप्शन प्रॉक्सी को भेजता है:
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi --replay-proxy http://127.0.0.1:8080
आप इसे --proxy के साथ भी जोड़ सकते हैं ताकि स्कैनिंग ट्रैफ़िक को एक अलग प्रॉक्सी के माध्यम से रूट किया जा सके, जबकि मिलानों को Burp पर रीप्ले किया जा सके:
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://proxy:9090 --replay-proxy http://127.0.0.1:8080
आप आंशिक (या पूर्ण) प्रतिक्रिया देखने के लिए वर्बोज़ आउटपुट का अनुरोध भी कर सकते हैं:
$ sj automate -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080 -v
Gathering API details.
⚠ POST 500 /v2/pet
{"code":500,"type":"unknown","message":"something
⚠ PUT 500 /v2/pet
{"code":500,"type":"unknown","message":"something
✓ GET 200 /v2/pet/findByStatus
[]
✓ GET 200 /v2/pet/findByTags
[]
✓ GET 200 /v2/pet/1
{"id":1,"category":{"id":1,"name":"cat"},"name":"d
✓ POST 200 /v2/pet/1
{"code":200,"type":"unknown","message":"1"}
⚠ POST N/A /v2/pet/1/uploadImage
✓ GET 200 /v2/store/inventory
{"sold":115,"bishopfox":1,"SOLD":1,"string":224,"d
⚠ POST N/A /v2/store/order
⚠ GET N/A /v2/store/order/1
✓ POST 200 /v2/user
{"code":200,"type":"unknown","message":"1"}
⚠ POST N/A /v2/user/createWithArray
⚠ POST N/A /v2/user/createWithList
✓ GET 200 /v2/user/login
{"code":200,"type":"unknown","message":"logged in
✓ GET 200 /v2/user/logout
{"code":200,"type":"unknown","message":"ok"}
✓ GET 200 /v2/user/bishopfox
{"id":1,"username":"bishopfox","firstName":"bishop
✓ PUT 200 /v2/user/bishopfox
{"code":200,"type":"unknown","message":"1"}
मैन्युअल परीक्षण के लिए कमांड्स की सूची तैयार करने के लिए
prepareकमांड का उपयोग करें। वर्तमान मेंcurlऔरsqlmapदोनों का समर्थन करता है। आपको संभवतः इन्हें थोड़ा संशोधित करना होगा।
$ sj prepare -u https://petstore.swagger.io/v2/swagger.json -qi -p http://127.0.0.1:8080
$ curl -X POST "https://petstore.swagger.io/v2/pet" -H 'Content-Type: application/json' -d '{"category":{"id":1,"name":"bishopfox"},"id":1,"name":"doggie","photoUrls":"https://bishopfox.com","status":"available","tags":[{"id":1,"name":"bishopfox"}]}'
$ curl -X PUT "https://petstore.swagger.io/v2/pet" -H 'Content-Type: application/json' -d '{"category":{"id":1,"name":"bishopfox"},"id":1,"name":"doggie","photoUrls":"https://bishopfox.com","status":"available","tags":[{"id":1,"name":"bishopfox"}]}'
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByStatus?status=1"
$ curl -X GET "https://petstore.swagger.io/v2/pet/findByTags?tags=1"
$ curl -X GET "https://petstore.swagger.io/v2/pet/1"
$ curl -X POST "https://petstore.swagger.io/v2/pet/1" -H 'Content-Type: application/x-www-form-urlencoded' -d 'name=bishopfox&status=bishopfox'
$ curl -X POST "https://petstore.swagger.io/v2/pet/1/uploadImage" -H 'Content-Type: application/x-www-form-urlencoded' -d 'additionalMetadata=bishopfox&file=1'
$ curl -X GET "https://petstore.swagger.io/v2/store/inventory"
$ curl -X POST "https://petstore.swagger.io/v2/store/order" -H 'Content-Type: application/json' -d '{"complete":true,"id":1,"petId":1,"quantity":1,"shipDate":"1990-01-01","status":"placed"}'
$ curl -X GET "https://petstore.swagger.io/v2/store/order/1"
$ curl -X POST "https://petstore.swagger.io/v2/user" -H 'Content-Type: application/json' -d '{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}'
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithArray" -H 'Content-Type: application/json' -d '[{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}]'
$ curl -X POST "https://petstore.swagger.io/v2/user/createWithList" -H 'Content-Type: application/json' -d '[{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}]'
$ curl -X GET "https://petstore.swagger.io/v2/user/login?username=bishopfox&password=bishopfox"
$ curl -X GET "https://petstore.swagger.io/v2/user/logout"
$ curl -X GET "https://petstore.swagger.io/v2/user/bishopfox"
$ curl -X PUT "https://petstore.swagger.io/v2/user/bishopfox" -H 'Content-Type: application/json' -d '{"email":"[email protected]","firstName":"bishopfox","id":1,"lastName":"bishopfox","password":"bishopfox","phone":"bishopfox","userStatus":1,"username":"bishopfox"}'
Multiple request body content types
एक ऑपरेशन अक्सर कई कंटेंट प्रकारों के अंतर्गत एक ही बॉडी घोषित करता है। डिफ़ॉल्ट रूप से sj वह भेजता है जो स्वीकार किए जाने की सबसे अधिक संभावना है, पहले application/json, फिर application/x-www-form-urlencoded, फिर multipart/form-data, फिर XML को प्राथमिकता देता है। चयन नियतात्मक है, इसलिए बार-बार चलाने पर समान कमांड उत्पन्न होते हैं।
चूँकि JSON पार्सर और XML पार्सर अलग-अलग हमले की सतह हैं, --all-content-types केवल पसंदीदा के बजाय प्रत्येक घोषित प्रकार भेजता है: