fix: 修复 #591 POC 对 HTTPS 端口误用 HTTP + #592 空指针 panic

1. buildTargetURL 对 443/8443 等已知 TLS 端口默认使用 https scheme,
   webtitle 触发 POC 扫描前将检测到的协议写回 info.URL,
   避免对 HTTPS 服务发送 HTTP 请求导致 EOF
2. GetInfo 添加 probe nil 检查,防止探针初始化失败时空指针 panic
3. 删除 test-nuclei-example.yaml 测试模板,避免 robots.txt 误报
This commit is contained in:
ZacharyZcR
2026-06-27 16:23:52 +08:00
parent 4976cb1f6b
commit 4922122530
4 changed files with 19 additions and 27 deletions
+1
View File
@@ -270,6 +270,7 @@ func (p *WebTitlePlugin) identifyFingerprintsMulti(ctx context.Context, info *co
// 非全量模式下,基于指纹触发POC扫描
if !config.POC.Full && !config.POC.Disabled {
info.URL = baseURL
p.triggerPocScan(ctx, info, fingerprints, config, session)
}