mirror of
https://github.com/shadow1ng/fscan.git
synced 2026-09-22 03:10:42 +08:00
isolate session network checks
This commit is contained in:
+5
-5
@@ -176,7 +176,7 @@ func EnhancedPortScan(ctx context.Context, hosts []string, ports string, timeout
|
||||
}
|
||||
|
||||
// 检查代理可靠性,如果存在全回显问题则警告
|
||||
if common.IsProxyEnabled() && !common.IsProxyReliable() {
|
||||
if session.ProxyEnabled() && !session.ProxyReliable() {
|
||||
session.LogError("检测到代理存在全回显问题,端口扫描结果可能不准确")
|
||||
}
|
||||
|
||||
@@ -465,7 +465,7 @@ func scanSinglePort(ctx context.Context, host string, port int, addr string, ada
|
||||
adaptiveTO.Record(time.Since(start))
|
||||
|
||||
// 步骤1.5:代理连接深度验证(防止透明代理/全回显代理的假连接问题)
|
||||
valid, verifyMethod := verifyProxyConnectionDeep(conn, addr)
|
||||
valid, verifyMethod := verifyProxyConnectionDeep(conn, addr, session)
|
||||
if !valid {
|
||||
session.LogDebug(fmt.Sprintf("代理验证失败 %s: %s", addr, verifyMethod))
|
||||
_ = conn.Close()
|
||||
@@ -474,7 +474,7 @@ func scanSinglePort(ctx context.Context, host string, port int, addr string, ada
|
||||
|
||||
// 步骤1.6:如果使用了代理且进行了数据交互,需要重建连接
|
||||
// 因为验证阶段可能读取了Banner或发送了HTTP GET探测,污染了连接状态
|
||||
if common.IsProxyEnabled() && verifyMethod != "direct" {
|
||||
if session.ProxyEnabled() && verifyMethod != "direct" {
|
||||
_ = conn.Close()
|
||||
// 重新建立干净的连接用于服务识别
|
||||
conn, err = connectWithRetry(ctx, session, addr, timeout, 2)
|
||||
@@ -523,10 +523,10 @@ func handleConnectionFailure(err error, host string, port int, addr string, fail
|
||||
// 1. 快速 Banner 检测 (100ms) - 大部分服务会主动发送数据
|
||||
// 2. 轻量探测 (发送 \r\n) - 触发某些服务响应,同时不污染协议状态
|
||||
// 3. 短超时等待 (500ms) - 平衡准确性和性能
|
||||
func verifyProxyConnectionDeep(conn net.Conn, addr string) (bool, string) {
|
||||
func verifyProxyConnectionDeep(conn net.Conn, addr string, session *common.ScanSession) (bool, string) {
|
||||
// 无代理或SOCKS5代理:跳过深度验证
|
||||
// SOCKS5协议层已验证连接可达性,连接成功即端口开放
|
||||
if !common.IsProxyEnabled() || common.IsSOCKS5Proxy() {
|
||||
if !session.ProxyEnabled() || session.IsSOCKS5Proxy() {
|
||||
return true, "direct"
|
||||
}
|
||||
|
||||
|
||||
+4
-5
@@ -136,12 +136,12 @@ func (w *WebPortDetector) DetectHTTPServiceOnly(host string, port int, config *c
|
||||
client := createHTTPClient(config, session)
|
||||
|
||||
// 尝试HTTP
|
||||
if w.tryHTTP(client, host, port, "http") {
|
||||
if w.tryHTTP(client, session, host, port, "http") {
|
||||
return true
|
||||
}
|
||||
|
||||
// 尝试HTTPS
|
||||
if w.tryHTTP(client, host, port, "https") {
|
||||
if w.tryHTTP(client, session, host, port, "https") {
|
||||
return true
|
||||
}
|
||||
|
||||
@@ -163,7 +163,7 @@ func isPortReachable(host string, port int, config *common.Config, session *comm
|
||||
}
|
||||
|
||||
// tryHTTP 尝试HTTP请求 - 简化的核心逻辑
|
||||
func (w *WebPortDetector) tryHTTP(client *http.Client, host string, port int, protocol string) bool {
|
||||
func (w *WebPortDetector) tryHTTP(client *http.Client, session *common.ScanSession, host string, port int, protocol string) bool {
|
||||
// 构造URL
|
||||
var url string
|
||||
if (port == 80 && protocol == "http") || (port == 443 && protocol == "https") {
|
||||
@@ -181,8 +181,7 @@ func (w *WebPortDetector) tryHTTP(client *http.Client, host string, port int, pr
|
||||
req.Header.Set("User-Agent", "fscan-web-detector/2.1")
|
||||
req.Header.Set("Accept", "*/*")
|
||||
|
||||
// 使用统一的SafeHTTPDo以确保遵循限速策略和代理设置
|
||||
resp, err := common.SafeHTTPDo(client, req)
|
||||
resp, err := session.HTTPDo(client, req)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user