-
Notifications
You must be signed in to change notification settings - Fork 2
/
main.go
82 lines (74 loc) · 1.32 KB
/
main.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
package main
import (
"log"
"net"
"net/http"
"net/url"
"sort"
"sync"
"time"
)
var history = struct {
*sync.Mutex
records map[string][]string
}{
&sync.Mutex{},
make(map[string][]string),
}
func keys(query url.Values) []string {
result := make([]string, 0, len(query))
for key := range query {
result = append(result, key)
}
return result
}
func equal(a []string, b []string) bool {
if len(a) != len(b) {
return false
}
for index, value := range a {
if value != b[index] {
return false
}
}
return true
}
func scanURL(rawurl string) {
u, err := url.Parse(rawurl)
if err != nil || len(u.RawQuery) == 0 {
return
}
history.Lock()
path := u.Host + u.Path
params := keys(u.Query())
sort.Strings(params)
if equal(params, history.records[path]) {
history.Unlock()
return
} else {
history.records[path] = params
history.Unlock()
}
var t SQLmapTask
t.create("")
t.start(SQLmapTaskInfo{Url: rawurl})
for {
if t.status() == "running" {
time.Sleep(5 * time.Minute)
continue
}
result := t.result().([]interface{})
if len(result) != 0 {
log.Printf("\033[0;31mHIT!\033[0m URL: %v, Result: %v\n", rawurl, t.result())
}
t.delete()
break
}
}
func main() {
ln, err := net.Listen("tcp", ":1017")
if err != nil {
log.Fatal(err)
}
http.Serve(ln, http.HandlerFunc(handleRequest))
}