Files
XSStrike/core/checker.py

28 lines
1.1 KiB
Python
Raw Normal View History

2018-10-27 18:58:52 +05:30
import re
import copy
from fuzzywuzzy import fuzz
from core.config import xsschecker
from urllib.parse import quote_plus
from core.requester import requester
from core.utils import replacer, fillHoles
2018-10-27 18:58:52 +05:30
def checker(url, params, headers, GET, delay, payload, positions):
checkString = 'st4r7s' + payload
2018-10-27 18:58:52 +05:30
paramsCopy = copy.deepcopy(params)
response = requester(url, replacer(paramsCopy, xsschecker, checkString), headers, GET, delay).text.lower()
reflectedPositions = []
for match in re.finditer('st4r7s', response):
reflectedPositions.append(match.start())
filledPositions = fillHoles(positions, reflectedPositions)
2018-10-27 18:58:52 +05:30
# Itretating over the reflections
efficiencies = []
for position in reflectedPositions:
if position:
reflected = response[position:position+len(checkString)]
efficiency = fuzz.partial_ratio(reflected, checkString.lower())
if reflected[-1] == '\\':
efficiency += 1
efficiencies.append(efficiency)
else:
efficiencies.append(0)
2018-10-27 18:58:52 +05:30
return efficiencies