mirror of
https://github.com/shadow1ng/fscan.git
synced 2026-09-25 04:31:52 +08:00
1. buildTargetURL 对 443/8443 等已知 TLS 端口默认使用 https scheme, webtitle 触发 POC 扫描前将检测到的协议写回 info.URL, 避免对 HTTPS 服务发送 HTTP 请求导致 EOF 2. GetInfo 添加 probe nil 检查,防止探针初始化失败时空指针 panic 3. 删除 test-nuclei-example.yaml 测试模板,避免 robots.txt 误报
This commit is contained in:
+14
-1
@@ -97,7 +97,11 @@ func WebScan(ctx context.Context, info *common.HostInfo, cfg *common.Config, ses
|
||||
func buildTargetURL(info *common.HostInfo) (string, error) {
|
||||
// 自动构建URL
|
||||
if info.URL == "" {
|
||||
info.URL = protocolHTTP + net.JoinHostPort(info.Host, fmt.Sprint(info.Port))
|
||||
protocol := protocolHTTP
|
||||
if isTLSPort(info.Port) {
|
||||
protocol = protocolHTTPS
|
||||
}
|
||||
info.URL = protocol + net.JoinHostPort(info.Host, fmt.Sprint(info.Port))
|
||||
} else if !hasProtocolPrefix(info.URL) {
|
||||
info.URL = protocolHTTP + normalizeSchemelessWebTarget(info.URL)
|
||||
}
|
||||
@@ -132,6 +136,15 @@ func hasProtocolPrefix(urlStr string) bool {
|
||||
return strings.HasPrefix(urlStr, protocolHTTP) || strings.HasPrefix(urlStr, protocolHTTPS)
|
||||
}
|
||||
|
||||
func isTLSPort(port int) bool {
|
||||
switch port {
|
||||
case 443, 8443, 4443, 9443:
|
||||
return true
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
func normalizeSchemelessWebTarget(rawURL string) string {
|
||||
authority := rawURL
|
||||
suffix := ""
|
||||
|
||||
Reference in New Issue
Block a user