Compare commits

...

10 Commits
2.0 ... 2.0.5

Author SHA1 Message Date
AnonymousUser
43fbc46b65 Version: 2.0.5 Fixed Bug 2021-07-06 18:33:11 +08:00
AnonymousUser
00a4a835b2 Update 2021-06-25 12:41:25 +08:00
AnonymousUser
f872dadf46 Version: 2.0.4 Fixed Bug 2021-06-14 23:06:03 +08:00
0chen
15bbb9f1a0 修复一处bug
close #18
感谢#18 问题已经修复
2021-06-14 15:33:22 +08:00
AnonymousUser
89f3f6cf09 Version 2.0.3 Fixed Match Scope Bug 2021-06-12 15:24:19 +08:00
AnonymousUser
cf9f434ff8 Version 2.0.3 Fixed Match Scope Bug 2021-06-12 15:19:39 +08:00
AnonymousUser
37a907d6df Version: 2.0.2 Fixed UI BUG 2021-06-11 18:27:14 +08:00
AnonymousUser
83e5da2f7e Version: 2.0.2 Fixed UI BUG 2021-06-11 18:25:36 +08:00
AnonymousUser
e43a96b8ad Version: 2.0.1 Fixed bug 2021-06-11 12:36:30 +08:00
AnonymousUser
a7112ad297 Version: 2.0 Update 2021-06-11 08:22:45 +08:00
9 changed files with 95 additions and 78 deletions

View File

@@ -25,8 +25,6 @@ https://gh0st.cn/HaE/
初次装载`HaE`会初始化配置文件,默认配置文件内置一个正则: `Email`,初始化的配置文件会放在与`BurpSuite Jar`包同级目录下。 初次装载`HaE`会初始化配置文件,默认配置文件内置一个正则: `Email`,初始化的配置文件会放在与`BurpSuite Jar`包同级目录下。
![-w330](images/16000708493657.jpg)
除了初始化的配置文件外,还有`Setting.yml`,该文件用于存储配置文件路径;`HaE`支持自定义配置文件路径,你可以通过点击`Select File`按钮进行选择自定义配置文件。 除了初始化的配置文件外,还有`Setting.yml`,该文件用于存储配置文件路径;`HaE`支持自定义配置文件路径,你可以通过点击`Select File`按钮进行选择自定义配置文件。
![-w477](images/16000710069404.jpg) ![-w477](images/16000710069404.jpg)
@@ -82,13 +80,16 @@ https://gh0st.cn/HaE/
...还有诸多使用方法等待大家去发掘。 ...还有诸多使用方法等待大家去发掘。
## 使用视频
123
## 文末 ## 文末
随笔: 正义感是一个不可丢失的东西。 随笔: 正义感是一个不可丢失的东西。
Github项目地址BUG、需求、正则欢迎提交: https://github.com/gh0stkey/HaE Github项目地址BUG、需求、正则欢迎提交: https://github.com/gh0stkey/HaE
## 404StarLink 2.0 - Galaxy
![404StarLink Logo](https://github.com/knownsec/404StarLink-Project/raw/master/logo.png)
`HaE` 是 404Team [星链计划2.0](https://github.com/knownsec/404StarLink2.0-Galaxy) 中的一环,如果对 `HaE` 有任何疑问又或是想要找小伙伴交流,可以参考星链计划的加群方式。
- [https://github.com/knownsec/404StarLink2.0-Galaxy#community](https://github.com/knownsec/404StarLink2.0-Galaxy#community)

View File

@@ -33,7 +33,7 @@ public class BurpExtender implements IBurpExtender, IHttpListener, IMessageEdito
this.callbacks = callbacks; this.callbacks = callbacks;
BurpExtender.helpers = callbacks.getHelpers(); BurpExtender.helpers = callbacks.getHelpers();
String version = "2.0"; String version = "2.0.5";
callbacks.setExtensionName(String.format("HaE (%s) - Highlighter and Extractor", version)); callbacks.setExtensionName(String.format("HaE (%s) - Highlighter and Extractor", version));
// 定义输出 // 定义输出
stdout = new PrintWriter(callbacks.getStdout(), true); stdout = new PrintWriter(callbacks.getStdout(), true);
@@ -74,15 +74,6 @@ public class BurpExtender implements IBurpExtender, IHttpListener, IMessageEdito
if (toolFlag == 64 || toolFlag == 32 || toolFlag == 4) { if (toolFlag == 64 || toolFlag == 32 || toolFlag == 4) {
Map<String, Map<String, Object>> obj; Map<String, Map<String, Object>> obj;
byte[] content = messageInfo.getRequest(); byte[] content = messageInfo.getRequest();
// 获取报文头
List<String> tmpHeaders = helpers.analyzeRequest(messageInfo.getHttpService(), content).getHeaders();
String headers = String.join("\n", tmpHeaders);
// 获取报文主体
int bodyOffset = helpers.analyzeRequest(messageInfo.getHttpService(), content).getBodyOffset();
byte[] byteRequest = messageInfo.getRequest();
byte[] body = Arrays.copyOfRange(byteRequest, bodyOffset, byteRequest.length);
// 流量清洗 // 流量清洗
String urlString = helpers.analyzeRequest(messageInfo.getHttpService(), content).getUrl().toString(); String urlString = helpers.analyzeRequest(messageInfo.getHttpService(), content).getUrl().toString();
urlString = urlString.indexOf("?") > 0 ? urlString.substring(0, urlString.indexOf("?")) : urlString; urlString = urlString.indexOf("?") > 0 ? urlString.substring(0, urlString.indexOf("?")) : urlString;
@@ -93,10 +84,28 @@ public class BurpExtender implements IBurpExtender, IHttpListener, IMessageEdito
} }
if (messageIsRequest) { if (messageIsRequest) {
obj = ec.matchRegex(content, headers, body, "request"); // 获取报文头
List<String> requestTmpHeaders = helpers.analyzeRequest(messageInfo.getHttpService(), content).getHeaders();
String requestHeaders = String.join("\n", requestTmpHeaders);
// 获取报文主体
int requestBodyOffset = helpers.analyzeRequest(messageInfo.getHttpService(), content).getBodyOffset();
byte[] byteRequest = messageInfo.getRequest();
byte[] requestBody = Arrays.copyOfRange(byteRequest, requestBodyOffset, byteRequest.length);
obj = ec.matchRegex(content, requestHeaders, requestBody, "request");
} else { } else {
// 获取报文头
List<String> responseTmpHeaders = helpers.analyzeRequest(messageInfo.getHttpService(), content).getHeaders();
String responseHeaders = String.join("\n", responseTmpHeaders);
// 获取报文主体
int responseBodyOffset = helpers.analyzeResponse(content).getBodyOffset();
byte[] byteResponse = messageInfo.getResponse();
byte[] responseBody = Arrays.copyOfRange(byteResponse, responseBodyOffset, byteResponse.length);
content = messageInfo.getResponse(); content = messageInfo.getResponse();
obj = ec.matchRegex(content, headers, body, "response"); obj = ec.matchRegex(content, responseHeaders, responseBody, "response");
} }
List<String> colorList = da.highlightList(obj); List<String> colorList = da.highlightList(obj);
@@ -133,37 +142,47 @@ public class BurpExtender implements IBurpExtender, IHttpListener, IMessageEdito
@Override @Override
public boolean isEnabled(byte[] content, boolean isRequest) { public boolean isEnabled(byte[] content, boolean isRequest) {
try { Map<String, Map<String, Object>> obj;
// 流量清洗
String urlString = helpers.analyzeRequest(controller.getHttpService(), controller.getRequest()).getUrl().toString(); if (isRequest) {
urlString = urlString.indexOf("?") > 0 ? urlString.substring(0, urlString.indexOf("?")) : urlString; try {
// 正则判断 // 流量清洗
if (mh.matchSuffix(urlString)) { String urlString = helpers.analyzeRequest(controller.getHttpService(), controller.getRequest()).getUrl().toString();
urlString = urlString.indexOf("?") > 0 ? urlString.substring(0, urlString.indexOf("?")) : urlString;
// 正则判断
if (mh.matchSuffix(urlString)) {
return false;
}
} catch (Exception e) {
return false; return false;
} }
} catch (Exception e) {
return false;
}
// 获取报文头 // 获取报文头
List<String> tmpHeaders = helpers.analyzeRequest(controller.getHttpService(), content).getHeaders(); List<String> requestTmpHeaders = helpers.analyzeRequest(controller.getHttpService(), content).getHeaders();
String headers = String.join("\n", tmpHeaders); String requestHeaders = String.join("\n", requestTmpHeaders);
// 获取报文主体 // 获取报文主体
int bodyOffset = helpers.analyzeRequest(controller.getHttpService(), content).getBodyOffset(); int requestBodyOffset = helpers.analyzeRequest(controller.getHttpService(), content).getBodyOffset();
byte[] byteRequest = controller.getRequest(); byte[] byteRequest = controller.getRequest();
byte[] body = Arrays.copyOfRange(byteRequest, bodyOffset, byteRequest.length); byte[] requestBody = Arrays.copyOfRange(byteRequest, requestBodyOffset, byteRequest.length);
Map<String, Map<String, Object>> obj; obj = ec.matchRegex(content, requestHeaders, requestBody, "request");
if (isRequest) { if (obj.size() > 0) {
obj = ec.matchRegex(content, headers, body, "request");
if (obj.size() != 0) {
String result = da.extractString(obj); String result = da.extractString(obj);
extractRequestContent = result.getBytes(); extractRequestContent = result.getBytes();
return true; return true;
} }
} else { } else {
obj = ec.matchRegex(content, headers, body, "response");
if (obj.size() != 0) { // 获取报文头
List<String> responseTmpHeaders = helpers.analyzeResponse(content).getHeaders();
String responseHeaders = String.join("\n", responseTmpHeaders);
// 获取报文主体
int responseBodyOffset = helpers.analyzeResponse(content).getBodyOffset();
byte[] byteResponse = controller.getResponse();
byte[] responseBody = Arrays.copyOfRange(byteResponse, responseBodyOffset, byteResponse.length);
obj = ec.matchRegex(content, responseHeaders, responseBody, "response");
if (obj.size() > 0) {
String result = da.extractString(obj); String result = da.extractString(obj);
extractResponseContent = result.getBytes(); extractResponseContent = result.getBytes();
return true; return true;

View File

@@ -28,7 +28,7 @@ public class ExtractContent {
String matchContent = ""; String matchContent = "";
for (Object[] objects : rules.get(i)) { for (Object[] objects : rules.get(i)) {
// 遍历获取规则 // 遍历获取规则
List<String> result = new ArrayList<String>(); List<String> result = new ArrayList<>();
Map<String, Object> tmpMap = new HashMap<>(); Map<String, Object> tmpMap = new HashMap<>();
String name = objects[1].toString(); String name = objects[1].toString();
@@ -38,7 +38,7 @@ public class ExtractContent {
String scope = objects[4].toString(); String scope = objects[4].toString();
String engine = objects[5].toString(); String engine = objects[5].toString();
// 判断规则是否开启与作用域 // 判断规则是否开启与作用域
if (loaded && (scopeString.contains(scope) || scope.equals("any"))) { if (loaded && (scope.contains(scopeString) || scope.equals("any"))) {
switch (scope) { switch (scope) {
case "any": case "any":
case "request": case "request":

View File

@@ -221,7 +221,7 @@ class TabTitleEditListener extends MouseAdapter implements ChangeListener, Docum
protected Boolean isRenamesucc = false; protected Boolean isRenamesucc = false;
protected LoadConfigFile loadfile = new LoadConfigFile(); protected LoadConfigFile loadfile = new LoadConfigFile();
protected LoadRule lr = new LoadRule(loadfile.getConfigPath()); protected LoadRule lr = new LoadRule(loadfile.getConfigPath());
protected SetRuleConfig setruleconfig = new SetRuleConfig(); protected SetRuleConfig setRuleConfig = new SetRuleConfig();
protected final Action startEditing = new AbstractAction() { protected final Action startEditing = new AbstractAction() {
@Override public void actionPerformed(ActionEvent e) { @Override public void actionPerformed(ActionEvent e) {
editingIdx = tabbedPane.getSelectedIndex(); editingIdx = tabbedPane.getSelectedIndex();
@@ -243,7 +243,7 @@ class TabTitleEditListener extends MouseAdapter implements ChangeListener, Docum
if (editingIdx >= 0 && !title.isEmpty()) { if (editingIdx >= 0 && !title.isEmpty()) {
String oldname = tabbedPane.getTitleAt(editingIdx); String oldname = tabbedPane.getTitleAt(editingIdx);
tabbedPane.setTitleAt(editingIdx, title); tabbedPane.setTitleAt(editingIdx, title);
setruleconfig.rename(oldname,title); setRuleConfig.rename(oldname,title);
} }
cancelEditing.actionPerformed(null); cancelEditing.actionPerformed(null);
} }
@@ -298,7 +298,7 @@ class TabTitleEditListener extends MouseAdapter implements ChangeListener, Docum
} }
public void newTab(){ public void newTab(){
Object[][] data = new Object[][]{{false, "New Name", "(New Regex)", "gray", "any", "nfa"}}; Object[][] data = new Object[][]{{false, "New Name", "(New Regex)", "gray", "any", "nfa"}};
insertTab(tabbedPane,setruleconfig.newRules(),data); insertTab(tabbedPane,setRuleConfig.newRules(),data);
} }
public void insertTab(@NotNull JTabbedPane pane,String title,Object[][] data){ public void insertTab(@NotNull JTabbedPane pane,String title,Object[][] data){
pane.addTab(title,new RulePane(data,pane)); pane.addTab(title,new RulePane(data,pane));

View File

@@ -27,18 +27,19 @@ public class RulePane extends JPanel {
RuleSetting add = new RuleSetting(); RuleSetting add = new RuleSetting();
int isOk = JOptionPane.showConfirmDialog(null,add,"RuleSetting - Add Rule",JOptionPane.OK_OPTION); int isOk = JOptionPane.showConfirmDialog(null,add,"RuleSetting - Add Rule",JOptionPane.OK_OPTION);
if(isOk == 0){ if(isOk == 0){
model.addRow(new Object[0]); Vector data = new Vector();
model.setValueAt(false,(model.getRowCount()-1),0); data.add(false);
model.setValueAt(add.Name.getText(),(model.getRowCount()-1),1); data.add(add.Name.getText());
model.setValueAt(add.Regex.getText(),(model.getRowCount()-1),2); data.add(add.Regex.getText());
model.setValueAt(add.ColorSelect.getSelectedItem().toString(),(model.getRowCount()-1),3); data.add(add.ColorSelect.getSelectedItem().toString());
model.setValueAt(add.ScopeSelect.getSelectedItem().toString(),(model.getRowCount()-1),4); data.add(add.ScopeSelect.getSelectedItem().toString());
model.setValueAt(add.EngineSelect.getSelectedItem().toString(),(model.getRowCount()-1),5); data.add(add.EngineSelect.getSelectedItem().toString());
model.insertRow(model.getRowCount(),data);
model = (DefaultTableModel) table.getModel(); model = (DefaultTableModel) table.getModel();
int select = table.convertRowIndexToModel(table.getSelectedRow()); setruleconfig.add(data,pane.getTitleAt(pane.getSelectedIndex()));
setruleconfig.add((Vector) model.getDataVector().get(select),pane.getTitleAt(pane.getSelectedIndex()));
} }
} }
private void RuleEditMouseClicked(MouseEvent e,JTabbedPane pane){ private void RuleEditMouseClicked(MouseEvent e,JTabbedPane pane){
if (table.getSelectedRowCount()>=1){ if (table.getSelectedRowCount()>=1){
RuleSetting edit = new RuleSetting(); RuleSetting edit = new RuleSetting();
@@ -60,18 +61,19 @@ public class RulePane extends JPanel {
} }
} }
} }
private void RuleRemoveMouseClicked(MouseEvent e,JTabbedPane pane){ private void RuleRemoveMouseClicked(MouseEvent e,JTabbedPane pane){
if (table.getSelectedRowCount()>=1){ if (table.getSelectedRowCount()>=1){
int isOk = JOptionPane.showConfirmDialog(null,"Are your sure?","RuleSetting - Delete Rule",JOptionPane.OK_OPTION); int isOk = JOptionPane.showConfirmDialog(null,"Are your sure?","RuleSetting - Delete Rule",JOptionPane.OK_OPTION);
if (isOk==0){ if (isOk==0){
model.removeRow(table.convertRowIndexToModel(table.getSelectedRow()));
table.remove(table.getSelectedRow());
model = (DefaultTableModel) table.getModel();
int select = table.convertRowIndexToModel(table.getSelectedRow()); int select = table.convertRowIndexToModel(table.getSelectedRow());
model.removeRow(select);
model = (DefaultTableModel) table.getModel();
setruleconfig.remove(select,pane.getTitleAt(pane.getSelectedIndex())); setruleconfig.remove(select,pane.getTitleAt(pane.getSelectedIndex()));
} }
} }
} }
private void RuleTableChange(TableModelEvent e,JTabbedPane pane) { private void RuleTableChange(TableModelEvent e,JTabbedPane pane) {
if (e.getColumn()==0&&table.getSelectedRow()!=-1&&!isEdit){ if (e.getColumn()==0&&table.getSelectedRow()!=-1&&!isEdit){
model = (DefaultTableModel) table.getModel(); model = (DefaultTableModel) table.getModel();

View File

@@ -23,7 +23,7 @@ public class RuleSetting extends JPanel {
Name = new JTextField(); Name = new JTextField();
ScopeSelect = new JComboBox<>(); ScopeSelect = new JComboBox<>();
EngineSelect = new JComboBox<>(); EngineSelect = new JComboBox<>();
label7 = new JLabel(); label6 = new JLabel();
ColorSelect = new JComboBox<>(); ColorSelect = new JComboBox<>();
//======== this ======== //======== this ========
@@ -32,24 +32,24 @@ public class RuleSetting extends JPanel {
//---- label5 ---- //---- label5 ----
label5.setText("Engine:"); label5.setText("Engine:");
add(label5); add(label5);
label5.setBounds(10, 175, 50, 17); label5.setBounds(new Rectangle(new Point(10, 175), label5.getPreferredSize()));
//---- label4 ---- //---- label4 ----
label4.setText("Scope:"); label4.setText("Scope:");
add(label4); add(label4);
label4.setBounds(10, 135, 50, 17); label4.setBounds(new Rectangle(new Point(10, 135), label4.getPreferredSize()));
add(Regex); add(Regex);
Regex.setBounds(70, 50, 265, 30); Regex.setBounds(70, 50, 265, 30);
//---- label3 ---- //---- label3 ----
label3.setText("Regex:"); label3.setText("Regex:");
add(label3); add(label3);
label3.setBounds(10, 55, 50, 17); label3.setBounds(new Rectangle(new Point(10, 55), label3.getPreferredSize()));
//---- label2 ---- //---- label2 ----
label2.setText("Name:"); label2.setText("Name:");
add(label2); add(label2);
label2.setBounds(10, 15, 50, 17); label2.setBounds(new Rectangle(new Point(10, 15), label2.getPreferredSize()));
add(Name); add(Name);
Name.setBounds(70, 10, 265, 30); Name.setBounds(70, 10, 265, 30);
@@ -64,9 +64,9 @@ public class RuleSetting extends JPanel {
EngineSelect.setBounds(70, 170, 265, EngineSelect.getPreferredSize().height); EngineSelect.setBounds(70, 170, 265, EngineSelect.getPreferredSize().height);
//---- label7 ---- //---- label7 ----
label7.setText("Color:"); label6.setText("Color:");
add(label7); add(label6);
label7.setBounds(new Rectangle(new Point(10, 95), label7.getPreferredSize())); label6.setBounds(new Rectangle(new Point(10, 95), label6.getPreferredSize()));
//---- ColorSelect ---- //---- ColorSelect ----
ColorSelect.setModel(new DefaultComboBoxModel<>(Config.colorArray)); ColorSelect.setModel(new DefaultComboBoxModel<>(Config.colorArray));
@@ -99,7 +99,7 @@ public class RuleSetting extends JPanel {
public JTextField Name; public JTextField Name;
public JComboBox<String> ScopeSelect; public JComboBox<String> ScopeSelect;
public JComboBox<String> EngineSelect; public JComboBox<String> EngineSelect;
private JLabel label7; private JLabel label6;
public JComboBox<String> ColorSelect; public JComboBox<String> ColorSelect;
// JFormDesigner - End of variables declaration //GEN-END:variables // JFormDesigner - End of variables declaration //GEN-END:variables
} }

View File

@@ -18,8 +18,8 @@ import java.util.Map;
public class LoadRule { public class LoadRule {
private static String filePath = "Config.yml"; private static String filePath = "Config.yml";
public LoadRule(String configfile){ public LoadRule(String configfile){
init();
filePath = configfile; filePath = configfile;
init();
} }
// 初始化配置 // 初始化配置

View File

@@ -14,20 +14,10 @@ public class Rule {
private String Color; private String Color;
private String Engine; private String Engine;
private String Scope; private String Scope;
private String Action;
public Boolean getLoaded() { public Boolean getLoaded() {
return Loaded; return Loaded;
} }
public void setLoaded(Boolean loaded) {
this.Loaded = loaded;
}
public String getAction() {
return Action;
}
public String getColor() { public String getColor() {
return Color; return Color;
} }
@@ -48,6 +38,11 @@ public class Rule {
return Scope; return Scope;
} }
public void setLoaded(Boolean loaded) {
this.Loaded = loaded;
}
public void setColor(String color) { public void setColor(String color) {
this.Color = color; this.Color = color;
} }

View File

@@ -98,7 +98,7 @@ public class SetRuleConfig {
lr = new LoadRule(loadfile.getConfigPath()); lr = new LoadRule(loadfile.getConfigPath());
config = lr.getConfig(); config = lr.getConfig();
String name = "New "; String name = "New ";
Object[][] data = new Object[][]{{false,"newName","newRegex","gray","any","nfa"}}; Object[][] data = new Object[][]{{false, "New Name", "(New Regex)", "gray", "any", "nfa"}};
while (config.containsKey(name+i)){ while (config.containsKey(name+i)){
i++; i++;
} }