HTML 报告 — 发现项概览,含严重性徽章和 OWASP 映射 |
发现项表格 — PYTHIA-SQL 代码、DBMS 检测、CWE-89 映射 |
Pythia 是一款生产级 SQL 注入检测扫描器,将伦理置于首位。专为渗透测试人员、安全研究员和 DevSecOps 工程师设计,通过 6 种检测方法识别 SQL 注入漏洞,并可直接集成到 CI/CD 流水线中。
--fail-on、--sarif、--diff 标志用于流水线集成~/.argos/argos.db)| 检测方法 | 描述 | 所需模式 |
|---|---|---|
| 基于错误 | 响应中的 SQL 错误(MySQL、PostgreSQL、MSSQL、Oracle、SQLite) | 安全 |
| 布尔盲注 | 来自 TRUE/FALSE 条件的响应差异 | 安全 |
| 时间盲注 | 来自 SLEEP/WAITFOR 负载的响应延迟 | 激进 |
| UNION 查询注入 | 通过 UNION SELECT 提取数据 | 激进 |
| 二阶注入 | 存储→检索注入模式(POST→GET 链) | 激进 |
| ORDER BY 注入 | 数字排序参数注入 | 激进 |
python -m pyth --target http://example.com/products?id=1 --html
- **14种发现代码**:DBMS专用(MySQL、PostgreSQL、MSSQL、Oracle、SQLite)+ 技术专用
- **DBMS指纹识别**:自动检测数据库类型和版本
- **WAF绕过**:激进模式下170+绕过载荷(十六进制、URL编码、内联注释、大小写变体)
- **会话变量检测**:针对DVWA-high风格认证模式的POST→GET链
- **智能爬虫**:BFS爬取,支持弹窗/onclick提取(`--js`)、站点地图、robots.txt
- **误报加固**:SequenceMatcher相似度评分 + 多载荷确认
### CI/CD集成```bash
# Pipeline-friendly: exit 10 if high+ findings found
python -m pyth --target https://staging.app.com --aggressive --fail-on high
echo $? # 0=clean, 10=findings found, 1=error
# SARIF for GitHub Security / GitLab SAST
python -m pyth --target https://app.com --aggressive --sarif > results.sarif
# Compare vs last scan — show what's new, what's fixed
python -m pyth --target https://app.com --aggressive --diff last --html
python -m pyth --target https://api.example.com/v1/users
--auth-header "Authorization: Bearer eyJhbGc..."
--auth-header "X-API-Key: sk-prod-xxx"
--aggressive --html
多次传递 `--auth-header` 以设置多个请求头。
### AI 驱动分析
从命令行选择你的 AI 提供商:
| 提供商 | 最佳用途 | 速度 | 成本 | 隐私 |
| ------------------------------------ | ------------------------------- | ---------- | ------------- | ----------- |
| **OpenAI gpt-4o-mini**(默认) | 生产质量,低成本 | 快速 | ~$0.02/次扫描 | 标准 |
| **Anthropic Claude** | 注重隐私,代码修复 | 快速 | ~$0.06/次扫描 | 增强 |
| **Ollama(本地)** | 完全隐私 | 慢(CPU) | 免费 | 100% 离线 |```bash
# Standard analysis
python -m pyth --target http://example.com --use-ai --ai-tone technical --html
# Agent mode: AI queries NVD for real CVEs (no API key for NVD)
python -m pyth --target http://example.com --use-ai --ai-agent --html
# Multi-provider comparison
python -m pyth --target http://example.com --use-ai \
--ai-compare "openai:gpt-4o-mini,anthropic:claude-3-5-haiku-20241022" --html
# With budget cap
python -m pyth --target http://example.com --use-ai --ai-budget 0.05 --html
JSON 报告(机器可读,v0.2.0 schema)```json { "tool": "pythia", "version": "0.2.0", "target": "http://localhost:8081", "mode": "aggressive", "summary": { "total": 26, "critical": 18, "high": 6, "medium": 2 }, "findings": [ { "id": "PYTHIA-SQL-001", "title": "Error-Based SQL Injection (MySQL/MariaDB)", "severity": "critical", "confidence": "high", "parameter": "id", "vector": "GET", "dbms": "MySQL 8.0.32", "cvss": 9.8, "contextual_score": 9.9, "risk_factors": ["no_ssl", "pii_detected"], "payload": "' OR '1'='1' --", "owasp": { "id": "A03", "name": "Injection" }, "cwe": { "id": "CWE-89", "name": "SQL Injection" }, "detection_method": "error-based" } ], "notes": { "scan_duration_seconds": 87.3, "requests_sent": 342, "rate_limit_applied": "5.0 req/s", "false_positive_disclaimer": "..." }, "diff": null }
**HTML 报告**(友好可读)
- 过滤栏:严重级别、OWASP 分类、检测方法、数据库管理系统
- 每个发现项的 OWASP/CWE/CVE 徽章(可点击跳转至外部参考)
- CVSS 基础分数 + 上下文分数(带颜色标识)
- 可展开的证据部分,附带载荷可视化
- AI 分析标签页(标准/代理/对比)
- 差异部分(新增/已修复/持续存在的发现项)
- Oracle 主题(紫色 `#6a11cb`)— 可直接交付客户,无需修改
### 发现代码
所有代码 → **OWASP A03 注入** / **CWE-89 SQL 注入**