mirror of
https://github.com/shadow1ng/fscan.git
synced 2026-09-22 03:10:42 +08:00
- eval_random: randomInt参数max<=min时不再panic,返回CEL错误 - scanner: 长驻插件nil/panic时兜底发送ready通道,消除死锁 - poc_executor: Ceye API密钥改为环境变量CEYE_API/CEYE_DOMAIN - Eval: ParseResponse加入oResp.Request nil检查 - Eval: reverseCheck中http.NewRequest错误不再忽略 - poc_executor: clusterpoc中CEL表达式求值错误记录日志 - winwmi: PowerShell执行失败完整记录错误信息 - sshkey: authorized_keys读取失败处理错误 - minidump: Scan结束后释放系统DLL句柄 - Windows插件: PE文件错误消息改用i18n
89 lines
2.6 KiB
Go
89 lines
2.6 KiB
Go
package lib
|
|
|
|
import (
|
|
"math/rand" //nolint:gosec // G404: math/rand用于生成POC测试数据,非加密用途
|
|
|
|
"github.com/google/cel-go/checker/decls"
|
|
"github.com/google/cel-go/common/types"
|
|
"github.com/google/cel-go/common/types/ref"
|
|
"github.com/google/cel-go/interpreter/functions"
|
|
exprpb "google.golang.org/genproto/googleapis/api/expr/v1alpha1"
|
|
)
|
|
|
|
// registerRandomDeclarations 注册随机函数的CEL声明
|
|
func registerRandomDeclarations() []*exprpb.Decl {
|
|
return []*exprpb.Decl{
|
|
decls.NewFunction("randomInt",
|
|
decls.NewOverload("randomInt_int_int",
|
|
[]*exprpb.Type{decls.Int, decls.Int},
|
|
decls.Int)),
|
|
decls.NewFunction("randomLowercase",
|
|
decls.NewOverload("randomLowercase_int",
|
|
[]*exprpb.Type{decls.Int},
|
|
decls.String)),
|
|
decls.NewFunction("randomUppercase",
|
|
decls.NewOverload("randomUppercase_int",
|
|
[]*exprpb.Type{decls.Int},
|
|
decls.String)),
|
|
decls.NewFunction("randomString",
|
|
decls.NewOverload("randomString_int",
|
|
[]*exprpb.Type{decls.Int},
|
|
decls.String)),
|
|
}
|
|
}
|
|
|
|
// registerRandomImplementations 注册随机函数的CEL实现
|
|
func registerRandomImplementations() []*functions.Overload {
|
|
return []*functions.Overload{
|
|
{
|
|
Operator: "randomInt_int_int",
|
|
Binary: func(lhs ref.Val, rhs ref.Val) ref.Val {
|
|
from, ok := lhs.(types.Int)
|
|
if !ok {
|
|
return types.ValOrErr(lhs, "unexpected type '%v' passed to randomInt", lhs.Type())
|
|
}
|
|
to, ok := rhs.(types.Int)
|
|
if !ok {
|
|
return types.ValOrErr(rhs, "unexpected type '%v' passed to randomInt", rhs.Type())
|
|
}
|
|
min, max := int(from), int(to)
|
|
if max <= min {
|
|
return types.NewErr("randomInt: max(%d) must be greater than min(%d)", max, min)
|
|
}
|
|
//nolint:gosec // G404: 用于生成POC测试随机数,非加密用途
|
|
return types.Int(rand.Intn(max-min) + min)
|
|
},
|
|
},
|
|
{
|
|
Operator: "randomLowercase_int",
|
|
Unary: func(value ref.Val) ref.Val {
|
|
n, ok := value.(types.Int)
|
|
if !ok {
|
|
return types.ValOrErr(value, "unexpected type '%v' passed to randomLowercase", value.Type())
|
|
}
|
|
return types.String(randomLowercase(int(n)))
|
|
},
|
|
},
|
|
{
|
|
Operator: "randomUppercase_int",
|
|
Unary: func(value ref.Val) ref.Val {
|
|
n, ok := value.(types.Int)
|
|
if !ok {
|
|
return types.ValOrErr(value, "unexpected type '%v' passed to randomUppercase", value.Type())
|
|
}
|
|
return types.String(randomUppercase(int(n)))
|
|
},
|
|
},
|
|
{
|
|
Operator: "randomString_int",
|
|
Unary: func(value ref.Val) ref.Val {
|
|
n, ok := value.(types.Int)
|
|
if !ok {
|
|
return types.ValOrErr(value, "unexpected type '%v' passed to randomString", value.Type())
|
|
}
|
|
return types.String(randomString(int(n)))
|
|
},
|
|
},
|
|
}
|
|
}
|