Class: Wmap::WpTracker

Inherits:
Object
  • Object
show all
Includes:
Utils
Defined in:
lib/wmap/wp_tracker.rb

Overview

Main class to automatically track the site inventory

Constant Summary collapse

Max_http_timeout =

set hard stop limit of http time-out to 8 seconds, in order to avoid severe performance penalty for certain ‘weird’ site(s)

8000

Constants included from Utils::DomainRoot

Utils::DomainRoot::File_ccsld, Utils::DomainRoot::File_cctld, Utils::DomainRoot::File_gtld, Utils::DomainRoot::File_tld

Instance Attribute Summary collapse

Instance Method Summary collapse

Methods included from Utils

#cidr_2_ips, #file_2_hash, #file_2_list, #get_nameserver, #get_nameservers, #host_2_ip, #host_2_ips, #is_cidr?, #is_fqdn?, #is_ip?, #list_2_file, #reverse_dns_lookup, #sort_ips, #valid_dns_record?, #zone_transferable?

Methods included from Utils::Logger

#wlog

Methods included from Utils::UrlMagic

#create_absolute_url_from_base, #create_absolute_url_from_context, #host_2_url, #is_site?, #is_ssl?, #is_url?, #make_absolute, #normalize_url, #url_2_host, #url_2_path, #url_2_port, #url_2_site, #urls_on_same_domain?

Methods included from Utils::DomainRoot

#get_domain_root, #get_sub_domain, #is_domain_root?, #print_ccsld, #print_cctld, #print_gtld

Constructor Details

#initialize(params = {}) ⇒ WpTracker

WordPress checker instance default variables



27
28
29
30
31
32
33
34
35
36
37
38
# File 'lib/wmap/wp_tracker.rb', line 27

def initialize (params = {})
	@verbose=params.fetch(:verbose, false)
	@data_dir=params.fetch(:data_dir, File.dirname(__FILE__)+'/../../data/')
	Dir.mkdir(@data_dir) unless Dir.exist?(@data_dir)
   wp_sites=@data_dir+'wp_sites'
   @file_wps=params.fetch(:sites_wp, wp_sites)
	@http_timeout=params.fetch(:http_timeout, 5000)
	@max_parallel=params.fetch(:max_parallel, 40)
	Dir.mkdir(@data_dir) unless Dir.exist?(@data_dir)
	@log_file=@data_dir + "wp_checker.log"
   @known_wp_sites=load_from_file(@file_wps)
end

Instance Attribute Details

#data_dirObject

include Singleton



21
22
23
# File 'lib/wmap/wp_tracker.rb', line 21

def data_dir
  @data_dir
end

#http_timeoutObject

include Singleton



21
22
23
# File 'lib/wmap/wp_tracker.rb', line 21

def http_timeout
  @http_timeout
end

#known_wp_sitesObject (readonly)

Returns the value of attribute known_wp_sites.



22
23
24
# File 'lib/wmap/wp_tracker.rb', line 22

def known_wp_sites
  @known_wp_sites
end

#max_parallelObject

include Singleton



21
22
23
# File 'lib/wmap/wp_tracker.rb', line 21

def max_parallel
  @max_parallel
end

#sites_wpObject

include Singleton



21
22
23
# File 'lib/wmap/wp_tracker.rb', line 21

def sites_wp
  @sites_wp
end

#verboseObject

include Singleton



21
22
23
# File 'lib/wmap/wp_tracker.rb', line 21

def verbose
  @verbose
end

Instance Method Details

#add(url) ⇒ Object

‘setter’ to add wordpress entry to the cache one at a time



98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
# File 'lib/wmap/wp_tracker.rb', line 98

def add(url)
   begin
	  puts "Add entry to the local cache table: #{url}" if @verbose
     site=url_2_site(url)
		if @known_wp_sites.key?(site)
			puts "Site is already exist. Skipping: #{site}"
		else
			record=Hash.new
			if is_wp?(site)
         record[site]=true
       else
         record[site]=false
       end
			puts "Entry loaded: #{record}"
		end
     @known_wp_sites.merge!(record)
     return record
	rescue => ee
		puts "Exception on method #{__method__}: #{ee}: #{url}" if @verbose
	end
end

#is_wp?(url) ⇒ Boolean

logic to determin if it’s a wordpress site

Returns:

  • (Boolean)


121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
# File 'lib/wmap/wp_tracker.rb', line 121

def is_wp?(url)
	#begin
		site=url_2_site(url)
		if wp_readme?(site)
			found=true
		elsif wp_css?(site)
			found=true
		elsif wp_meta?(site)
			found=true
		elsif wp_login?(site)
			found=true
		elsif wp_rpc?(site)
			found=true
		else
			found=false
		end
		return found
	#rescue => ee
	#	puts "Exception on method #{__method__}: #{ee}: #{url}" if @verbose
	#end
end

#load_from_file(file = @file_stores, lc = true) ⇒ Object

‘setter’ to load the known wordpress sites into an instance variable



42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
# File 'lib/wmap/wp_tracker.rb', line 42

def load_from_file (file=@file_stores, lc=true)
	puts "Loading trusted file: #{file}"	if @verbose
	begin
		known_wp_sites=Hash.new
		f_wp_sites=File.open(file, 'r')
		f_wp_sites.each_line do |line|
			puts "Processing line: #{line}" if @verbose
			line=line.chomp.strip
			next if line.nil?
			next if line.empty?
			next if line =~ /^\s*#/
			line=line.downcase if lc==true
			entry=line.split(',')
			if known_wp_sites.key?(entry[0])
				next
			else
				if entry[1] =~ /yes/i
					known_wp_sites[entry[0]]=true
				else
					known_wp_sites[entry[0]]=false
				end
			end

		end
		f_wp_sites.close
		return known_wp_sites
	rescue => ee
		puts "Exception on method #{__method__}: #{ee}" if @verbose
		return nil
	end
end

#open_url(url) ⇒ Object

Wrapper for the OpenURI open method - create an open_uri object and return the reference upon success



188
189
190
191
192
193
194
195
196
197
198
199
200
# File 'lib/wmap/wp_tracker.rb', line 188

def open_url(url)
#url_object = nil
puts "Open url #{url} by creating an open_uri object. Return the reference upon success." if @verbose
if url =~ /http\:/i
	# patch for allow the 'un-safe' URL redirection i.e. https://www.example.com -> http://www.example.com
	url_object = open(url, :allow_redirections=>:safe, :read_timeout=>Max_http_timeout/1000)
elsif url =~ /https\:/i
	url_object = open(url,:ssl_verify_mode => 0, :allow_redirections =>:safe, :read_timeout=>Max_http_timeout/1000)
else
	raise "Invalid URL format - please specify the protocol prefix http(s) in the URL: #{url}"
end
return url_object
end

#read_url(url) ⇒ Object

Wrapper to use OpenURI method ‘read’ to return url body contents



174
175
176
177
178
179
180
181
182
183
184
185
# File 'lib/wmap/wp_tracker.rb', line 174

def read_url(url)
   begin
     puts "Wrapper to return the OpenURI object for url: #{url}" if @verbose
		url_object=open_url(url)
		html_body=url_object.read
     doc = Nokogiri::HTML(html_body)
     return doc
   rescue => ee
     puts "Exception on method #{__method__}: #{ee}" if @verbose
     return nil
   end
end

#refresh(num = @max_parallel) ⇒ Object

add wordpress site entries (from a sitetracker list)



144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
# File 'lib/wmap/wp_tracker.rb', line 144

def refresh (num=@max_parallel)
   #begin
	  puts "Add entries to the local cache table from site tracker: " if @verbose
		results=Hash.new
		wps=Wmap::SiteTracker.instance.known_sites.keys
		if wps.size > 0
			Parallel.map(wps, :in_processes => num) { |target|
				add(target)
			}.each do |process|
				if process.nil?
					next
				elsif process.empty?
					#do nothing
				else
					results.merge!(process)
				end
			end
			@known_wp_sites.merge!(results)
			puts "Done loading entries."
			return results
		else
			puts "Error: no entry is loaded. Please check your list and try again."
		end
		return results
	#rescue => ee
	#	puts "Exception on method #{__method__}: #{ee}" if @verbose
	#end
end

#save_to_file!(file_wps = @file_wps, wps = @known_wp_sites) ⇒ Object Also known as: save!

Save the current domain hash table into a file



75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
# File 'lib/wmap/wp_tracker.rb', line 75

def save_to_file!(file_wps=@file_wps, wps=@known_wp_sites)
	puts "Saving the current wordpress site table from memory to file: #{file_wps} ..." if @verbose
	begin
		timestamp=Time.now
		f=File.open(file_wps, 'w')
		f.write "# Local wps file created by class #{self.class} method #{__method__} at: #{timestamp}\n"
		f.write "# domain name, free zone transfer detected?\n"
		wps.keys.sort.map do |key|
			if wps[key]
				f.write "#{key}, yes\n"
			else
				f.write "#{key}, no\n"
			end
		end
		f.close
		puts "WordPress site cache table is successfully saved: #{file_wps}"
	rescue => ee
		puts "Exception on method #{__method__}: #{ee}" if @verbose
	end
end

#wp_css?(site) ⇒ Boolean

Wordpress detection checkpoint - install.css

Returns:

  • (Boolean)


222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
# File 'lib/wmap/wp_tracker.rb', line 222

def wp_css?(site)
  css_url=site + "wp-admin/css/install.css"
  k=Wmap::UrlChecker.new
  if k.response_code(css_url) == 200
    k=nil
    parser = CssParser::Parser.new
    parser.load_uri!(css_url)
    rule = parser.find_by_selector('#logo a')
    if rule.length >0
      if rule[0] =~ /wordpress/i
        return true
      end
    end
  else
    k=nil
    return false
  end
  return false
end

#wp_login?(url) ⇒ Boolean

Wordpress detection checkpoint - wp-login

Returns:

  • (Boolean)


260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
# File 'lib/wmap/wp_tracker.rb', line 260

def wp_login?(url)
site=url_2_site(url)
=site + "wp-login.php"
  k=Wmap::UrlChecker.new
  if k.response_code() == 200
    k=nil
    doc=read_url()
    links=doc.css('link')
    if links.to_s =~ /login.min.css/i
      return true
    else
      return false
    end
  end
return false
end

#wp_meta?(url) ⇒ Boolean

Wordpress detection checkpoint - meta generator

Returns:

  • (Boolean)


243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
# File 'lib/wmap/wp_tracker.rb', line 243

def wp_meta?(url)
site=url_2_site(url)
  k=Wmap::UrlChecker.new
  if k.response_code(site) == 200
    k=nil
    doc=read_url(site)
    meta=doc.css('meta')
    if meta.to_s =~ /wordpress/i
      return true
    else
      return false
    end
  end
return false
end

#wp_readme?(site) ⇒ Boolean

Wordpress detection checkpoint - readme.html

Returns:

  • (Boolean)


203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
# File 'lib/wmap/wp_tracker.rb', line 203

def wp_readme?(site)
  readme_url=site + "readme.html"
  k=Wmap::UrlChecker.new
  if k.response_code(readme_url) == 200
    k=nil
    doc=read_url(readme_url)
    title=doc.css('title')
    if title.to_s =~ /wordpress/i
      return true
    else
      return false
    end
  else
    k=nil
    return false
  end
end

#wp_rpc?(url) ⇒ Boolean

Wordpress detection checkpoint - xml-rpc

Returns:

  • (Boolean)


278
279
280
281
282
283
284
285
286
287
288
# File 'lib/wmap/wp_tracker.rb', line 278

def wp_rpc?(url)
site=url_2_site(url)
rpc_url=site + "xmlrpc.php"
  k=Wmap::UrlChecker.new
#puts "res code", k.response_code(rpc_url)
  if k.response_code(rpc_url) == 405 # method not allowed
    k=nil
    return true
  end
return false
end

#wp_ver(url) ⇒ Object

Extract the WordPress version



291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
# File 'lib/wmap/wp_tracker.rb', line 291

def wp_ver(url)
	if !wp_ver_readme(url).nil?
		return wp_ver_readme(url)
	elsif !wp_ver_meta(url).nil?
		return wp_ver_meta(url)
	elsif !(url,"login.min.css").nil?
		return (url,"login.min.css")
	elsif !(url,"buttons.min.css").nil?
		return (url,"buttons.min.css")
	elsif !(url,"wp-admin.min.css").nil?
		return (url,"wp-admin.min.css")
	else
		return nil
	end
end

#wp_ver_login(url, pattern) ⇒ Object

Identify wordpress version through the login page



308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
# File 'lib/wmap/wp_tracker.rb', line 308

def (url,pattern)
puts "Check for #{pattern}" if @verbose
site=url_2_site(url)
=site + "wp-login.php"
  k=Wmap::UrlChecker.new
#puts "Res code: #{k.response_code(login_url)}" if @verbose
  if k.response_code() == 200
    doc=read_url()
	#puts doc.inspect
    links=doc.css('link')
	#puts links.inspect if @verbose
	links.each do |tag|
     if tag.to_s.include?(pattern)
			puts tag.to_s if @verbose
			k=nil
       return tag.to_s.scan(/[\d+\.]+\d+/).first
     end
	end
  end
  k=nil
  return nil
end

#wp_ver_meta(url) ⇒ Object

Identify wordpress version through the meta link



332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
# File 'lib/wmap/wp_tracker.rb', line 332

def wp_ver_meta(url)
site=url_2_site(url)
  k=Wmap::UrlChecker.new
  if k.response_code(site) == 200
    doc=read_url(site)
	#puts doc.inspect
    meta=doc.css('meta')
	#puts meta.inspect
	meta.each do |tag|
     if tag.to_s =~ /wordpress/i
			#puts tag.to_s
			k=nil
       return tag.to_s.scan(/[\d+\.]+\d+/).first
     end
	end
  end
  k=nil
  return nil
end

#wp_ver_readme(url) ⇒ Object

Wordpress version detection via - readme.html



353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
# File 'lib/wmap/wp_tracker.rb', line 353

def wp_ver_readme(url)
	site=url_2_site(url)
   readme_url=site + "readme.html"
   k=Wmap::UrlChecker.new
	puts "Res code: #{k.response_code(readme_url)}" if @verbose
   if k.response_code(readme_url) == 200
     k=nil
     doc=read_url(readme_url)
		puts doc if @verbose
     =doc.css('h1#logo')[0]
     puts .inspect if @verbose
		return .to_s.scan(/[\d+\.]+\d+/).first
   end
   k=nil
   return nil
end