Class: CMSScanner::Finders::InterestingFile::XMLRPC
- Inherits:
-
Finder
- Object
- Finder
- CMSScanner::Finders::InterestingFile::XMLRPC
show all
- Defined in:
- app/finders/interesting_files/xml_rpc.rb
Overview
Constant Summary
Constants inherited
from Finder
Finder::DIRECT_FILE_ACCESS
Instance Attribute Summary
Attributes inherited from Finder
#target
Instance Method Summary
collapse
Methods inherited from Finder
#found_by, #initialize
Instance Method Details
#aggressive(_opts = {}) ⇒ XMLRPC
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
|
# File 'app/finders/interesting_files/xml_rpc.rb', line 43
def aggressive(_opts = {})
potential_urls << target.url('xmlrpc.php')
potential_urls.uniq.each do |potential_url|
next unless target.in_scope?(potential_url)
res = NS::Browser.get(potential_url)
next unless res && res.body =~ /XML-RPC server accepts POST requests only/i
return NS::XMLRPC.new(potential_url,
confidence: 100,
found_by: DIRECT_FILE_ACCESS)
end
nil
end
|
#passive(opts = {}) ⇒ Array<XMLRPC>
12
13
14
|
# File 'app/finders/interesting_files/xml_rpc.rb', line 12
def passive(opts = {})
[(opts), passive_body(opts)].compact
end
|
#passive_body(_opts = {}) ⇒ XMLRPC
27
28
29
30
31
32
33
34
35
36
37
38
39
40
|
# File 'app/finders/interesting_files/xml_rpc.rb', line 27
def passive_body(_opts = {})
page = Nokogiri::HTML(NS::Browser.get(target.url).body)
page.css('link[rel="pingback"]').each do |tag|
url = tag.attribute('href').to_s
next unless target.in_scope?(url)
potential_urls << url
return NS::XMLRPC.new(url, confidence: 30,
found_by: 'Link Tag (passive detection)')
end
nil
end
|
17
18
19
20
21
22
23
24
|
# File 'app/finders/interesting_files/xml_rpc.rb', line 17
def (_opts = {})
url = NS::Browser.get(target.url).['X-Pingback']
return unless target.in_scope?(url)
potential_urls << url
NS::XMLRPC.new(url, confidence: 30, found_by: 'Headers (passive detection)')
end
|
#potential_urls ⇒ Array<String>
Returns The potential urls to the XMl RPC file.
7
8
9
|
# File 'app/finders/interesting_files/xml_rpc.rb', line 7
def potential_urls
@potential_urls ||= []
end
|