Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

同时使用以下 --common和 --append-rule filebak 生成的扫描字典惨不忍睹 #40

Open
SuperXiaoxiong opened this issue Jun 12, 2024 · 5 comments
Labels
enhancement New feature or request

Comments

@SuperXiaoxiong
Copy link

生成了很多如下扫描目录

files.2/README.md~/README.md~/README.txtbak
files.1/README.md.bak/README.md.old
files~/readme.txt~/README.md.old/README.md
files/LICENSE.txt~/readme.mdbak
files.1/README.md~/README.md~/readme.mdbak/README.md
@M09Ic
Copy link
Contributor

M09Ic commented Jun 23, 2024

和过滤策略设置的有问题, 看来是默认的过滤设置没有过滤掉很多无效页面。 导致append-rule生效于无效页面。

是否可以提供测试站点

@M09Ic M09Ic added the enhancement New feature or request label Jun 24, 2024
@SuperXiaoxiong
Copy link
Author

SuperXiaoxiong commented Jul 16, 2024

网上找的在野站点,不太好提供
可以模拟一下输出,最后结果中会输出 这两个,这个是预期之类的,特异性404 和 403

[rule]          404     153     1076ms  https://host/files~ [404 Not Found] [nginx]
[redirect]      403     153     1199ms  https://host/files --> https://ids.nuctech.com/files/ [403 Forbidden] [nginx]

但是途中标圈的不清楚是 这么生成出来的

image

@M09Ic
Copy link
Contributor

M09Ic commented Jul 19, 2024

因为没看到提供的命令输入, 所以我猜测应该是 内置的rule规则与common/bak功能交叉生成的字典

@SuperXiaoxiong
Copy link
Author

同时使用了 --common --append-rule filebak
这两个参数

@M09Ic
Copy link
Contributor

M09Ic commented Aug 22, 2024

那就是过滤算法出了问题. 因为append-rule是根据有效目录生成的. 如果过滤算法正常, append-rule不会爆炸式派生. 可以提供更多上下文, 提升spray默认的过滤算法

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants