2021-07-15 10:41:41 +00:00
|
|
|
package parsers
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
2021-08-31 13:57:26 +00:00
|
|
|
"regexp"
|
2021-10-20 20:24:11 +00:00
|
|
|
"strings"
|
2021-07-19 18:04:08 +00:00
|
|
|
|
|
|
|
"gopkg.in/yaml.v2"
|
|
|
|
|
2021-08-31 13:57:26 +00:00
|
|
|
"github.com/projectdiscovery/gologger"
|
2021-07-15 10:41:41 +00:00
|
|
|
"github.com/projectdiscovery/nuclei/v2/pkg/catalog/loader/filter"
|
|
|
|
"github.com/projectdiscovery/nuclei/v2/pkg/model"
|
|
|
|
"github.com/projectdiscovery/nuclei/v2/pkg/templates"
|
2021-08-27 18:45:28 +00:00
|
|
|
"github.com/projectdiscovery/nuclei/v2/pkg/templates/cache"
|
2021-11-03 11:48:35 +00:00
|
|
|
"github.com/projectdiscovery/nuclei/v2/pkg/templates/types"
|
2021-07-15 10:41:41 +00:00
|
|
|
"github.com/projectdiscovery/nuclei/v2/pkg/utils"
|
2021-08-31 13:57:26 +00:00
|
|
|
"github.com/projectdiscovery/nuclei/v2/pkg/utils/stats"
|
2021-07-15 10:41:41 +00:00
|
|
|
)
|
|
|
|
|
2021-10-19 22:31:38 +00:00
|
|
|
const (
|
|
|
|
mandatoryFieldMissingTemplate = "mandatory '%s' field is missing"
|
|
|
|
invalidFieldFormatTemplate = "invalid field format for '%s' (allowed format is %s)"
|
|
|
|
)
|
2021-07-15 10:41:41 +00:00
|
|
|
|
2021-08-19 12:17:25 +00:00
|
|
|
// LoadTemplate returns true if the template is valid and matches the filtering criteria.
|
|
|
|
func LoadTemplate(templatePath string, tagFilter *filter.TagFilter, extraTags []string) (bool, error) {
|
|
|
|
template, templateParseError := ParseTemplate(templatePath)
|
2021-07-15 10:41:41 +00:00
|
|
|
if templateParseError != nil {
|
|
|
|
return false, templateParseError
|
|
|
|
}
|
2021-08-19 12:17:25 +00:00
|
|
|
|
|
|
|
if len(template.Workflows) > 0 {
|
2021-08-18 20:28:54 +00:00
|
|
|
return false, nil
|
|
|
|
}
|
2021-07-15 10:41:41 +00:00
|
|
|
|
2021-10-19 22:31:38 +00:00
|
|
|
if validationError := validateTemplateFields(template); validationError != nil {
|
2021-10-25 12:12:01 +00:00
|
|
|
stats.Increment(SyntaxErrorStats)
|
2021-07-15 10:41:41 +00:00
|
|
|
return false, validationError
|
|
|
|
}
|
|
|
|
|
2022-01-07 12:00:20 +00:00
|
|
|
templateId := strings.ToLower(template.ID)
|
|
|
|
|
|
|
|
return isTemplateInfoMetadataMatch(tagFilter, &template.Info, extraTags, template.Type(), templateId)
|
2021-08-19 12:17:25 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// LoadWorkflow returns true if the workflow is valid and matches the filtering criteria.
|
2021-08-31 10:21:15 +00:00
|
|
|
func LoadWorkflow(templatePath string) (bool, error) {
|
2021-08-19 12:17:25 +00:00
|
|
|
template, templateParseError := ParseTemplate(templatePath)
|
|
|
|
if templateParseError != nil {
|
|
|
|
return false, templateParseError
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(template.Workflows) > 0 {
|
2021-10-19 22:31:38 +00:00
|
|
|
if validationError := validateTemplateFields(template); validationError != nil {
|
2021-08-19 12:17:25 +00:00
|
|
|
return false, validationError
|
|
|
|
}
|
2021-08-27 18:49:05 +00:00
|
|
|
return true, nil
|
2021-07-15 10:41:41 +00:00
|
|
|
}
|
2021-08-19 12:17:25 +00:00
|
|
|
|
|
|
|
return false, nil
|
2021-07-15 10:41:41 +00:00
|
|
|
}
|
|
|
|
|
2022-01-07 12:00:20 +00:00
|
|
|
func isTemplateInfoMetadataMatch(tagFilter *filter.TagFilter, templateInfo *model.Info, extraTags []string, templateType types.ProtocolType, templateId string) (bool, error) {
|
2021-07-15 10:41:41 +00:00
|
|
|
templateTags := templateInfo.Tags.ToSlice()
|
|
|
|
templateAuthors := templateInfo.Authors.ToSlice()
|
|
|
|
templateSeverity := templateInfo.SeverityHolder.Severity
|
|
|
|
|
2022-01-07 12:00:20 +00:00
|
|
|
match, err := tagFilter.Match(templateTags, templateAuthors, templateSeverity, extraTags, templateType, templateId)
|
2021-08-19 12:17:25 +00:00
|
|
|
|
2021-07-15 10:41:41 +00:00
|
|
|
if err == filter.ErrExcluded {
|
|
|
|
return false, filter.ErrExcluded
|
|
|
|
}
|
|
|
|
|
2021-08-19 12:17:25 +00:00
|
|
|
return match, err
|
2021-07-15 10:41:41 +00:00
|
|
|
}
|
|
|
|
|
2021-10-19 22:31:38 +00:00
|
|
|
func validateTemplateFields(template *templates.Template) error {
|
|
|
|
info := template.Info
|
2021-07-15 10:41:41 +00:00
|
|
|
|
2021-10-20 20:24:11 +00:00
|
|
|
var errors []string
|
|
|
|
|
2021-08-03 11:51:34 +00:00
|
|
|
if utils.IsBlank(info.Name) {
|
2021-10-20 20:24:11 +00:00
|
|
|
errors = append(errors, fmt.Sprintf(mandatoryFieldMissingTemplate, "name"))
|
2021-07-15 10:41:41 +00:00
|
|
|
}
|
|
|
|
|
2021-08-03 11:51:34 +00:00
|
|
|
if info.Authors.IsEmpty() {
|
2021-10-20 20:24:11 +00:00
|
|
|
errors = append(errors, fmt.Sprintf(mandatoryFieldMissingTemplate, "author"))
|
2021-07-15 10:41:41 +00:00
|
|
|
}
|
2021-10-19 22:31:38 +00:00
|
|
|
|
|
|
|
if template.ID == "" {
|
2021-10-20 20:24:11 +00:00
|
|
|
errors = append(errors, fmt.Sprintf(mandatoryFieldMissingTemplate, "id"))
|
|
|
|
} else if !templateIDRegexp.MatchString(template.ID) {
|
|
|
|
errors = append(errors, fmt.Sprintf(invalidFieldFormatTemplate, "id", templateIDRegexp.String()))
|
2021-10-19 22:31:38 +00:00
|
|
|
}
|
|
|
|
|
2021-10-20 20:24:11 +00:00
|
|
|
if len(errors) > 0 {
|
|
|
|
return fmt.Errorf(strings.Join(errors, ", "))
|
2021-10-19 22:31:38 +00:00
|
|
|
}
|
|
|
|
|
2021-07-15 10:41:41 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2021-08-31 14:23:53 +00:00
|
|
|
var (
|
|
|
|
parsedTemplatesCache *cache.Templates
|
|
|
|
ShouldValidate bool
|
|
|
|
fieldErrorRegexp = regexp.MustCompile(`not found in`)
|
2021-10-20 19:58:36 +00:00
|
|
|
templateIDRegexp = regexp.MustCompile(`^([a-zA-Z0-9]+[-_])*[a-zA-Z0-9]+$`)
|
2021-08-31 14:23:53 +00:00
|
|
|
)
|
2021-08-31 13:57:26 +00:00
|
|
|
|
2021-08-31 16:09:20 +00:00
|
|
|
const (
|
2021-12-05 14:11:14 +00:00
|
|
|
SyntaxWarningStats = "syntax-warnings"
|
|
|
|
SyntaxErrorStats = "syntax-errors"
|
|
|
|
RuntimeWarningsStats = "runtime-warnings"
|
2021-08-31 16:09:20 +00:00
|
|
|
)
|
2021-08-27 18:57:37 +00:00
|
|
|
|
|
|
|
func init() {
|
2021-08-31 14:23:53 +00:00
|
|
|
|
2021-08-27 18:57:37 +00:00
|
|
|
parsedTemplatesCache = cache.New()
|
2021-08-31 13:57:26 +00:00
|
|
|
|
2021-08-31 20:31:55 +00:00
|
|
|
stats.NewEntry(SyntaxWarningStats, "Found %d templates with syntax warning (use -validate flag for further examination)")
|
|
|
|
stats.NewEntry(SyntaxErrorStats, "Found %d templates with syntax error (use -validate flag for further examination)")
|
2021-12-05 14:11:14 +00:00
|
|
|
stats.NewEntry(RuntimeWarningsStats, "Found %d templates with runtime error (use -validate flag for further examination)")
|
2021-08-27 18:57:37 +00:00
|
|
|
}
|
2021-08-27 14:06:06 +00:00
|
|
|
|
2021-08-18 20:40:36 +00:00
|
|
|
// ParseTemplate parses a template and returns a *templates.Template structure
|
|
|
|
func ParseTemplate(templatePath string) (*templates.Template, error) {
|
2021-08-27 18:45:28 +00:00
|
|
|
if value, err := parsedTemplatesCache.Has(templatePath); value != nil {
|
|
|
|
return value.(*templates.Template), err
|
2021-08-27 14:06:06 +00:00
|
|
|
}
|
2022-01-24 11:18:12 +00:00
|
|
|
data, err := utils.ReadFromPathOrURL(templatePath)
|
2021-07-15 10:41:41 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
template := &templates.Template{}
|
2021-09-01 14:41:42 +00:00
|
|
|
if err := yaml.UnmarshalStrict(data, template); err != nil {
|
2021-08-31 13:57:26 +00:00
|
|
|
errString := err.Error()
|
|
|
|
if !fieldErrorRegexp.MatchString(errString) {
|
2021-08-31 16:09:20 +00:00
|
|
|
stats.Increment(SyntaxErrorStats)
|
2021-08-31 13:57:26 +00:00
|
|
|
return nil, err
|
|
|
|
}
|
2021-08-31 16:09:20 +00:00
|
|
|
stats.Increment(SyntaxWarningStats)
|
2021-08-31 14:23:53 +00:00
|
|
|
if ShouldValidate {
|
|
|
|
gologger.Error().Msgf("Syntax warnings for template %s: %s", templatePath, err)
|
|
|
|
} else {
|
|
|
|
gologger.Warning().Msgf("Syntax warnings for template %s: %s", templatePath, err)
|
|
|
|
}
|
2021-07-15 10:41:41 +00:00
|
|
|
}
|
2021-08-27 18:45:28 +00:00
|
|
|
parsedTemplatesCache.Store(templatePath, template, nil)
|
2021-07-15 10:41:41 +00:00
|
|
|
return template, nil
|
|
|
|
}
|