mirror of
https://github.com/shadow1ng/fscan.git
synced 2026-09-25 12:41:53 +08:00
fix: 修复 Web Stop 信号等待阻塞和 SMB 响应解析越界 panic
- scanner.go: 长驻插件等待信号时同时监听 ctx.Done(),Web Stop 可正常返回 - smb_protocol.go: 响应长度检查修正为 47,远端偏移量全部做边界校验
This commit is contained in:
+6
-3
@@ -109,11 +109,14 @@ func RunScan(ctx context.Context, info common.HostInfo, config *common.Config, s
|
|||||||
}
|
}
|
||||||
common.LogInfo(i18n.GetText("press_ctrl_c_exit"))
|
common.LogInfo(i18n.GetText("press_ctrl_c_exit"))
|
||||||
|
|
||||||
// 优雅等待信号
|
// 优雅等待信号或 context 取消(Web Stop)
|
||||||
sigChan := make(chan os.Signal, 1)
|
sigChan := make(chan os.Signal, 1)
|
||||||
signal.Notify(sigChan, os.Interrupt, syscall.SIGTERM)
|
signal.Notify(sigChan, os.Interrupt, syscall.SIGTERM)
|
||||||
<-sigChan
|
select {
|
||||||
common.LogInfo(i18n.GetText("received_exit_signal"))
|
case <-sigChan:
|
||||||
|
common.LogInfo(i18n.GetText("received_exit_signal"))
|
||||||
|
case <-ctx.Done():
|
||||||
|
}
|
||||||
cancel()
|
cancel()
|
||||||
time.Sleep(500 * time.Millisecond)
|
time.Sleep(500 * time.Millisecond)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -242,7 +242,7 @@ func probeSMBv1(conn net.Conn, target string, timeout time.Duration) (*SMBTarget
|
|||||||
}
|
}
|
||||||
|
|
||||||
ret, err := readSMBMessage(conn)
|
ret, err := readSMBMessage(conn)
|
||||||
if err != nil || len(ret) < 45 {
|
if err != nil || len(ret) < 47 {
|
||||||
return nil, fmt.Errorf("读取SMBv1 Session Setup响应失败: %w", err)
|
return nil, fmt.Errorf("读取SMBv1 Session Setup响应失败: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -251,21 +251,24 @@ func probeSMBv1(conn net.Conn, target string, timeout time.Duration) (*SMBTarget
|
|||||||
}
|
}
|
||||||
|
|
||||||
// 解析blob信息
|
// 解析blob信息
|
||||||
blobLength := bytesToUint16(ret[43:45])
|
blobLength := int(bytesToUint16(ret[43:45]))
|
||||||
blobCount := bytesToUint16(ret[45:47])
|
blobCount := int(bytesToUint16(ret[45:47]))
|
||||||
|
|
||||||
if int(blobCount) > len(ret) {
|
gssNative := ret[47:]
|
||||||
|
gssLen := len(gssNative)
|
||||||
|
|
||||||
|
// 校验远端返回的偏移量
|
||||||
|
if blobLength > gssLen || blobCount > gssLen || blobLength > blobCount {
|
||||||
return info, nil
|
return info, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
gssNative := ret[47:]
|
|
||||||
offNTLM := bytes.Index(gssNative, []byte("NTLMSSP"))
|
offNTLM := bytes.Index(gssNative, []byte("NTLMSSP"))
|
||||||
if offNTLM == -1 {
|
if offNTLM == -1 {
|
||||||
return info, nil
|
return info, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// 提取native OS和LM信息
|
// 提取native OS和LM信息
|
||||||
native := gssNative[int(blobLength):blobCount]
|
native := gssNative[blobLength:blobCount]
|
||||||
ss := strings.Split(string(native), "\x00\x00")
|
ss := strings.Split(string(native), "\x00\x00")
|
||||||
|
|
||||||
if len(ss) > 0 {
|
if len(ss) > 0 {
|
||||||
@@ -276,8 +279,10 @@ func probeSMBv1(conn net.Conn, target string, timeout time.Duration) (*SMBTarget
|
|||||||
}
|
}
|
||||||
|
|
||||||
// 解析NTLM信息
|
// 解析NTLM信息
|
||||||
bs := gssNative[offNTLM:blobLength]
|
if offNTLM <= blobLength {
|
||||||
parseNTLMChallenge(bs, info)
|
bs := gssNative[offNTLM:blobLength]
|
||||||
|
parseNTLMChallenge(bs, info)
|
||||||
|
}
|
||||||
|
|
||||||
return info, nil
|
return info, nil
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user