
Testa centenas de técnicas de bypass de URL contra páginas protegidas por 40X usando requisições curl brutas, com varredura em múltiplos modos, spoofing de cabeçalhos e exportação de resultados em JSON/HTML para avaliação de controle de acesso.
Ferramenta que testa MUITOS bypasses de URL para acessar uma página protegida 40X.
Se você está se perguntando por que este código é nada mais que um wrapper curl sujo, aqui está o motivo:
Isso é surpreendentemente difícil de alcançar em Python sem perder todas as vantagens da biblioteca, como análise, encapsulamento SSL/TLS e assim por diante.
Então, seja como eu, use curl como backend, vai ficar tudo bem.
Além disso, esta ferramenta pode ser usada como biblioteca, veja lib_sample_usage.py
Recomendamos usar pipx para instalar esta ferramenta:```bash
pipx install bypass-url-parser
pipx install git+https://github.com/laluka/bypass-url-parser
Alternativamente, você pode usar `pip`:```bash
pip install bypass-url-parser
Bypass Url Parser, made with love by @TheLaluka A tool that tests MANY url bypasses to reach a 40X protected page.
Usage: bypass-url-parser (-u | -R ) [-m ] [-o ] [-S ] [ (-H
)...] [-r ] [-s ] [--spoofip-replace] [-p ] [--spoofport-replace] [-t ] [-T ] [--request-tls] [--jsonl] [--dump-payloads] [-x <proxy_url>] [-v | -d | -dd]Program options: -u, --url URL (path is optional) to run bypasses against -R, --request Load HTTP raw request from a file -H, --header
Header(s) to use, format: "Cookie: can_i_haz=fire" -m, --mode Bypass modes. See 'Bypasser.BYPASS_MODES' in code [Default: all] -o, --outdir Output directory for results -x, --proxy <proxy_url> Set a proxy in the format http://proxy_ip:port. -S, --save-level Save results level. From 0 (DISABLE) to 3 (FULL) [Default: 2] -s, --spoofip IP(s) to inject in ip-specific headers -p, --spoofport Port(s) to inject in port-specific headers -r, --retry Retry attempts of failed requests. Set 0 to disable all retry tentatives [Default: 1] -t, --threads Scan with N parallel threads [Default: 1] -T, --timeout Request times out after N seconds [Default: 5]General options: -h, --help Show help, you are here :) -v, --verbose Verbose output -d, --debug Show more details like curl commands generated by this tool -dd, --debug Print Debug level 2 (with all classes debug_class output) -V, --version Show version info
Misc options: --spoofip-replace Disable list of default internal IPs in 'http_headers_ip' bypass mode --spoofport-replace Disable list of default internal ports in 'http_headers_port' bypass mode --request-tls Force usage of TLS/HTTPS for the request load with the '-R, --request' option --dump-payloads Print all payloads (curls) generated by this tool. --jsonl Print results in JSON lines format (pipe command output)
Examples: bypass-url-parser -u "http://127.0.0.1/juicy_403_endpoint/" -s 8.8.8.8 -d bypass-url-parser -u /path/urls -t 30 -T 5 -H "Cookie: me_iz=admin" -H "User-agent: test" bypass-url-parser -R /path/request_file --request-tls -m "mid_paths, end_paths"
## Resultado esperado```bash
bypass-url-parser -u http://127.0.0.1:8000/foo/bar
2022-08-09 14:52:40 lalu-perso bup[361559] WARNING Trying to bypass 'http://127.0.0.1:8000/foo/bar' url (3213 payloads)...
2022-08-09 14:52:40 lalu-perso bup[361559] INFO Doing: 50 / 3213
[...]
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Doing: 3200 / 3213
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (1/3) the '16' failed curl commands with 10 threads and 10s timeout
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (2/3) the '16' failed curl commands with 5 threads and 20s timeout
2022-08-09 14:52:54 lalu-perso bup[361559] INFO Retry (3/3) the '16' failed curl commands with 1 threads and 30s timeout
2022-08-09 14:52:55 lalu-perso bup[361559] INFO
[#####] [bypass_method] [payload] => [status_code] [content_type] [content_length] [lines_count] [word_counts] [title] [server] [redirect_url]
[GROUP (1587)] [original_request] [http://127.0.0.1:8000/foo/bar] => [404] [text/html] [469] [14] [95] [Error response] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (10)] [http_methods] [-X CONNECT http://127.0.0.1:8000/foo/bar] => [501] [text/html] [500] [14] [96] [Error response] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000/???foo/bar] => [200] [text/html] [913] [26] [27] [Directory listing for /???foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//???foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/???foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000/??foo/bar] => [200] [text/html] [911] [26] [27] [Directory listing for /??foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//??foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/??foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000/?foo/bar] => [200] [text/html] [909] [26] [27] [Directory listing for /?foo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000//?foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/?foo/bar]
[SINGLE] [mid_paths] [http://127.0.0.1:8000///?anythingfoo/bar] => [200] [text/html] [929] [26] [27] [Directory listing for ///?anythingfoo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[SINGLE] [mid_paths] [http://127.0.0.1:8000////?anythingfoo/bar] => [200] [text/html] [931] [26] [27] [Directory listing for ////?anythingfoo/bar] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (2)] [mid_paths] [http://127.0.0.1:8000/#?foo/bar] => [200] [text/html] [893] [26] [27] [Directory listing for /] [SimpleHTTP/0.6 Python/3.8.10] []
[GROUP (2)] [mid_paths] [http://127.0.0.1:8000//#?foo/bar] => [301] [] [] [0] [0] [] [SimpleHTTP/0.6 Python/3.8.10] [/]
sudo apt install -y bat curl virtualenv python3
virtualenv -p python3 .py3 source .py3/bin/activate PDM_BUILD_SCM_VERSION="$(git describe --abbrev=0)-dev" pip install .
python src/bypass_url_parser/init.py -u https://thinkloveshare.com/juicy_403_endpoint/
bypass-url-parser -u https://thinkloveshare.com/juicy_403_endpoint/ cat /tmp/tmpRANDOM-bypass-url-parser/triaged-bypass.json | jq -r '.results[].request_curl_cmd' cat /tmp/tmpRANDOM-bypass-url-parser/triaged-bypass.json | jq -r '.results[].response_data'
### DOCKER```bash
docker run --rm -it -v "$PWD:/host" -w /host ghcr.io/laluka/bypass-url-parser:latest bash -il
# Then bup -h, keep the docker open as the output is saved by default in /tmp
# Or specify the output to the current directory, and consult them later! :)
O Bypass_url_parser permite definir alguns argumentos de várias maneiras:
-m, --mode, -s, --spoofip e -p, --spoofport podem ser um nome de arquivo, uma string, uma lista de strings separadas por vírgula ou uma lista (quando Bypasser é usado como biblioteca);-u, --url pode ser um nome de arquivo, uma string ou uma lista (quando Bypasser é usado como biblioteca);stdin (com -) é suportado para todos esses argumentos.Por exemplo, se você deseja definir várias URLs alvo (-u, --url), todos os comandos a seguir produzem o mesmo resultado:```bash
bypass-url-parser -u http://thinkloveshare.com/test
bypass-url-parser -u /path/urls
cat /path/urls | bypass-url-parser -u -
echo 'http://thinkloveshare.com/test' | bypass-url-parser -u -
### Definição do alvo
Um alvo deve ser definido para a ferramenta funcionar. 2 opções:
- `-u, --url`: URL(s), em GET
- `-R, --request`: Arquivo de requisição. O protocolo não pode ser adivinhado a partir do arquivo, então `http` por padrão ou `https` se a opção `--request-tls` estiver presente.
### Modo de bypass
Se `-m, --mode` for especificado, você pode selecionar o modo de bypass desejado para executar um teste (ou testes) específico(s) e reduzir o número de requisições enviadas pela ferramenta.
Por enquanto, o(s) seguinte(s) modo(s) de bypass são suportados:```
all, mid_paths, end_paths, case_substitution, char_encode, http_methods, http_versions, http_headers_method, http_headers_scheme, http_headers_ip, http_headers_port, http_headers_url, user_agent
Exemplo:```bash bypass-url-parser -u /path/urls -m "case_substitution, char_encode, http_headers_scheme"
### Spoofip / Spoofport
Para personalizar os endereços IP e portas usados nas tentativas de bypass, a ferramenta suporta as seguintes opções:
- Com `-s, --spoofip` você pode definir alguns IP(s) para injetar em cabeçalhos `ip-specific` (`X-Forwarded-For`, `X-Real-Ip`, etc.)
- Com `-p, --spoofport` você pode definir algumas portas para injetar em cabeçalhos `port-specific` (`X-Forwarded-Port`)
Por padrão, essas entradas personalizadas são adicionadas às listas internas de IP/porta. Se você quiser usar apenas seus IP(s)/porta(s), pode usar os argumentos `--spoofip-replace` e/ou `--spoofport-replace`.
Exemplo:```bash
bypass-url-parser -u /path/urls -s /path/custom_ip --spoofip-replace
bypass-url-parser -u /path/urls -p "3000, 9443, 10443"
Com a opção --jsonl, é possível imprimir os resultados no stdout no formato JSON-Lines. A saída padrão da ferramenta e os resultados são exibidos com um logger no stderr, por isso é possível encadear o formato de saída JSON-Lines com outras ferramentas:```bash
bypass-url-parser -u "https://thinkloveshare.com/juicy_403_endpoint/" -t 20 -S 0 -m case_substitution,char_encode --jsonl | jq
***Notas:** Com `-S 2` ou `-S 3`, a saída JSON-Lines também inclui o caminho e o nome dos arquivos html salvos.*
### Salvamento de resultados
Por padrão, se a url alvo for única, a ferramenta salva uma cópia dos resultados no diretório `/tmp/tmpXXX-bypass-url-parser/`.
***Notas:** Se múltiplas urls alvo forem passadas para `-u`, os resultados são prefixados com a url como diretório (`/tmp/tmpXXX-bypass-url-parser/http-target-com-8080-api-users/`).*
Existem dois argumentos para personalizar esse comportamento:
- `-o, --outdir` para definir um diretório de saída personalizado
- `-S, --save-level` para escolher um nível de salvamento
Os níveis de salvamento são:
- `0` (NONE): Desabilitar o salvamento de saída e a criação do diretório de saída;
- `1` (MÍNIMO): Salvar apenas o arquivo de log do programa que contém os resultados: `triaged-bypass.log`;
- `2` (PERTINENTE): Salvar o arquivo de log do programa `triaged-bypass.log` e as respostas curl **pertinentes (resultados)** no arquivo `triaged-bypass.json` e arquivos html separados (Padrão);
- `3` (COMPLETO): Salvar o arquivo de log do programa `triaged-bypass.log` e **todas** as respostas curl no arquivo `triaged-bypass.json` e arquivos html separados.
#### Exemplo```bash
bypass-url-parser -S 0
bypass-url-parser -S 1 -o /tmp/bypass-res
bypass-url-parser -S 2 -o /tmp/bypass-res2 -H "User-Agent: curl 7.74.0" -u http://thinkloveshare.com/juicy_403_endpoint/
tree /tmp/bypass-res2/
├── bypass-2469eecf6c38b5817d2248e911ad4382.html
├── bypass-6f7cce7caf0a0a4b440859fa189d496d.html
├── bypass-80f4ab5d32b4e74c20630c7e67f2e42f.html
├── bypass-93079abffe63d34f79ac4a511cd6b5e6.html
├── bypass-945822230d58d1ad4680d5dfbc470ecb.html
├── bypass-e6118c315eea0e5b2ebc4fcafe0559c0.html
├── triaged-bypass.json
└── triaged-bypass.log
0 directories, 8 files
A partir do nível MINIMAL, os resultados exibidos pelo programa são salvos no arquivo triaged-bypass.log.
Com os níveis de salvamento PERTINENT e FULL, o programa exporta adicionalmente todos os resultados no arquivo triaged-bypass.json:```json
{
"url": "http://thinkloveshare.com/juicy_403_endpoint/",
"bypass_modes": "all",
"results": [
{
"request_curl_cmd": "/usr/bin/curl -sS -kgi -H 'User-Agent: curl 7.74.0' --path-as-is -H 'X-BlueCoat-Via: localhos[...SNIP...]",
"request_curl_payload": "-H X-BlueCoat-Via: localhost http://thinkloveshare.com/juicy_403_endpoint/",
"response_headers": "HTTP/1.1 301 Moved Permanently\nConnection: keep-alive\nContent-Length: 162\nServer: GitHub.c[...SNIP...]",
"response_data": "\n301 Moved Permanently\n\n
Tornando-os mais fáceis de manusear com `jq`:```bash
$ jq -r '.results[] | [.request_curl_payload, .response_status_code, .response_content_type, .response_content_length] | join("|")' /tmp/bypass-res2/triaged-bypass.json
-H X-BlueCoat-Via: localhost http://thinkloveshare.com/juicy_403_endpoint/|301|text/html|162
-X PROPFIND http://thinkloveshare.com/juicy_403_endpoint/|405||131
http://thinkloveshare.com/%3b%2f%2e%2e%2f%2e%2e%2f%2fjuicy_403_endpoint/|400|text/html|9121
-H Host: 8.8.8.8 http://thinkloveshare.com/juicy_403_endpoint/|404|text/html|9115
-X CONNECT http://thinkloveshare.com/juicy_403_endpoint/|400|text/plain|15
http://thinkloveshare.com/juicy_403_endpoint/°//|400|text/html|90
Com os níveis de salvamento PERTINENT e FULL, os comandos curl e respostas HTTP completas também são armazenados em pseudo arquivos .html:```bash
$ echo /tmp/bypass-res2/*.html | xargs batcat
───────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
│ File: /tmp/bypass-res2/bypass-2469eecf6c38b5817d2248e911ad4382.html
───────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
1 │ /usr/bin/curl -sS -kgi -H 'User-Agent: curl 7.74.0' --path-as-is 'http://thinkloveshare.com/juicy_403_endpoint/°//'
2 │
3 │ HTTP/1.1 400 Bad request
4 │ Connection: keep-alive
5 │ Content-Length: 90
6 │ Cache-Control: no-cache
7 │ Content-Type: text/html
8 │ Accept-Ranges: bytes
9 │ Date: Tue, 25 Apr 2023 23:51:38 GMT
10 │ Via: 1.1 varnish
11 │ X-Served-By: cache-par-lfpg1960025-PAR
12 │ X-Cache: MISS
13 │ X-Cache-Hits: 0
14 │ X-Timer: S1682466698.230664,VS0,VE10
15 │ Vary: Accept-Encoding
16 │ X-Fastly-Request-ID: b6bbb82302420db4f101a316dca39cc283a4fd44
17 │
18 │
## Contribuidores
- Lançamento inicial por [@TheLaluka](https://twitter.com/TheLaluka)
- Grande refatoração & lib-mode com agradecimentos a [@jtop_fap](https://twitter.com/jtop_fap)
- Suporte para builds `Docker` & `Pypi` com o gentil trabalho de [@DugnyG](https://twitter.com/DugnyG)
## Licença
Copyright (C) 2022 Laluka
Este programa é um software livre: você pode redistribuí-lo e/ou modificá-lo sob os termos da Licença Pública Geral Affero GNU, conforme publicada pela Free Software Foundation, seja a versão 3 da Licença, ou (a seu critério) qualquer versão posterior.
Este programa é distribuído na esperança de que seja útil, mas SEM QUALQUER GARANTIA; sem a garantia implícita de COMERCIALIZAÇÃO ou ADEQUAÇÃO A UM PROPÓSITO ESPECÍFICO. Consulte a Licença Pública Geral Affero GNU para obter mais detalhes.
Você deve ter recebido uma cópia da Licença Pública Geral Affero GNU junto com este programa. Caso contrário, consulte <https://www.gnu.org/licenses/>.