srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/proxy/intrude.go
blob: 933a3098ed63a5a4ea42f62d58209607f468150f (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
// Intruder-equivalent: mark positions in a raw request template with §
// (Burp's own marker character, so anyone who's used Burp already knows
// the syntax), and Sniper-attack them - one position fuzzed at a time
// through a shared payload set, every other marked position holding its
// base value. Battering ram / pitchfork / cluster bomb are not
// implemented; Sniper covers the large majority of real Intruder usage
// and this whole feature is explicitly optional in the build order.
package proxy

import (
	"bytes"
	"context"
	"fmt"

	"mitmux/internal/store"
)

const marker = "§"

// maxIntrudeRequests caps positions × payloads for one attack - a safety
// limit against an accidental huge wordlist times several positions
// turning into an unbounded flood, not a tuned production value.
const maxIntrudeRequests = 1000

// IntrudePosition is one marked, resolved insertion point.
type IntrudePosition struct {
	Index int    // 0-based, in order of appearance
	Base  string // the text between its markers
}

// ParseMarkers finds every §base§ pair in template and returns the
// resolved positions plus template with the markers stripped out (the
// form actually used as the base request when no position is being
// fuzzed). An odd number of § markers is a user error - unterminated
// marker - reported rather than guessed at.
func ParseMarkers(template []byte) (positions []IntrudePosition, stripped []byte, err error) {
	parts := bytes.Split(template, []byte(marker))
	if len(parts)%2 != 1 {
		return nil, nil, fmt.Errorf("unterminated %s marker - markers must come in pairs", marker)
	}
	if len(parts) == 1 {
		return nil, template, nil
	}

	var buf bytes.Buffer
	for i, part := range parts {
		if i%2 == 1 {
			positions = append(positions, IntrudePosition{Index: len(positions), Base: string(part)})
		}
		buf.Write(part)
	}
	return positions, buf.Bytes(), nil
}

// buildRequest re-inserts each position's base value into stripped
// (computed relative to the ORIGINAL template's marker layout, so this
// re-derives offsets rather than operating on the already-stripped
// bytes) except for `active`, which gets payload instead.
func buildRequest(template []byte, active int, payload string) ([]byte, error) {
	parts := bytes.Split(template, []byte(marker))
	if len(parts)%2 != 1 {
		return nil, fmt.Errorf("unterminated %s marker", marker)
	}
	var buf bytes.Buffer
	pos := 0
	for i, part := range parts {
		if i%2 == 1 {
			if pos == active {
				buf.WriteString(payload)
			} else {
				buf.Write(part)
			}
			pos++
			continue
		}
		buf.Write(part)
	}
	return buf.Bytes(), nil
}

// Intrude runs a Sniper attack: template must contain at least one
// §marked§ position. For each position, in order, every payload is sent
// with that position replaced by the payload and all others at their
// base value; onResult is called synchronously after each request
// completes - with the position index, the payload used, the resulting
// entry (nil if sendErr is set), and any send error - so a caller can
// stream progress, and stops the attack early if it returns false.
func (s *Server) Intrude(ctx context.Context, scheme, host string, template []byte, payloads []string,
	onResult func(position int, payload string, entry *store.Entry, sendErr error) bool) error {
	positions, _, err := ParseMarkers(template)
	if err != nil {
		return err
	}
	if len(positions) == 0 {
		return fmt.Errorf("no %s-marked positions in the request template", marker)
	}
	if len(payloads) == 0 {
		return fmt.Errorf("no payloads")
	}
	if total := len(positions) * len(payloads); total > maxIntrudeRequests {
		return fmt.Errorf("attack would send %d requests (%d positions × %d payloads), over the %d limit",
			total, len(positions), len(payloads), maxIntrudeRequests)
	}

	for _, pos := range positions {
		for _, payload := range payloads {
			raw, err := buildRequest(template, pos.Index, payload)
			if err != nil {
				return err
			}

			// sendRaw is already self-bounding (dialForRepeat's own dial
			// timeout, then conn.SetDeadline for the rest), so ctx here
			// only needs to carry cancellation - e.g. the IPC connection
			// driving this attack closing mid-run.
			e, sendErr := s.sendRaw(ctx, scheme, host, raw, "intruder")

			if !onResult(pos.Index, payload, e, sendErr) {
				return nil
			}
		}
	}
	return nil
}