feat: complete basic functions

Support http,dns and mysql connection. Support custom http, dns response. Support dns rebinding.
Support mysql load local files and jdbc deserialize exploit.
This commit is contained in:
Li4n0
2021-04-21 18:55:16 +08:00
parent e9db8ddb24
commit 3559894acc
114 changed files with 41617 additions and 0 deletions
+59
View File
@@ -0,0 +1,59 @@
package notice
import (
"encoding/json"
"fmt"
"io/ioutil"
"net/http"
"strings"
"github.com/li4n0/revsuit/internal/record"
)
var _ Bot = (*Weixin)(nil)
type Weixin struct {
URL string
}
type weixinMarkdown struct {
Content string `json:"content"`
}
type weixinPayload struct {
ToUser string `json:"touser"`
MsgType string `json:"msgtype"`
Markdown weixinMarkdown `json:"markdown"`
}
func (w *Weixin) buildPayload(r record.Record) string {
payload := weixinPayload{
ToUser: "@all",
MsgType: "markdown",
Markdown: weixinMarkdown{
Content: "<font color=\"#e96900\" face=\"Fira Code\" size=3>New Connection</font>\n" +
formatRecordField(r, `> **<font color="#e96900" face="Fira Code">%s: </font>**<font color="#e96900" face="Fira Code">%v</font>`),
},
}
p, err := json.Marshal(&payload)
if err != nil {
return ""
}
return string(p)
}
func (w *Weixin) notice(r record.Record) error {
resp, err := http.DefaultClient.Post(w.URL, "application/json", strings.NewReader(w.buildPayload(r)))
if err != nil {
return fmt.Errorf("HTTP request: %v", err)
}
defer resp.Body.Close()
if resp.StatusCode/100 != 2 {
data, err := ioutil.ReadAll(resp.Body)
if err != nil {
return fmt.Errorf("read HTTP response body: %v", err)
}
return fmt.Errorf("non-success response status code %d with body: %s", resp.StatusCode, data)
}
return nil
}