poc/examples/nmap-{streaming,callback}.pow: minor cleanup

* Update comments.
* Add Content-Type: text/xml header (nmap-streaming.pow) only.
* Wrap the Nmap output in XML comment delimiters, *after* the XML header.
* Write to /response/body (preferred) instead of /response/stream (legacy).
* Use suffix .xml for temp files.
* Move possibly noise-generating calls outside of the block
  that is sent to the /request/body.
This commit is contained in:
pancho horrillo
2019-10-24 17:05:54 +02:00
parent b0c16ca684
commit 2fc18b76e3
2 changed files with 35 additions and 29 deletions
+17 -15
View File
@@ -17,8 +17,10 @@
#
#
# Nmap execution with callback. When processes finishes call the CALLBACK site
# and send a POST with the XML results
# Nmap execution with callback.
#
# When the Nmap processes finishes it will call the CALLBACK site
# and POST the XML results
#
# Call example:
@@ -27,19 +29,19 @@
#
kapow route add -X POST /nmap-callback - <<-'EOF'
PORTS=$(kapow get /request/form/ports)
: ${PORTS:=9000}
IP=$(kapow get /request/form/ip)
: ${IP:=127.0.0.1}
CALLBACK=$(kapow get /request/params/callback)
: ${CALLBACK:=127.0.0.1:9999}
tmpfile="$(mktemp --suffix=.xml)"
trap "{ rm -f \"$tmpfile\"; }" EXIT
{
PORTS=$(kapow get /request/form/ports)
: ${PORTS:=9000}
IP=$(kapow get /request/form/ip)
: ${IP:=127.0.0.1}
CALLBACK=$(kapow get /request/params/callback)
: ${CALLBACK:=127.0.0.1:9999}
tmpfile="$(mktemp --suffix=.nmap)"
trap "{ rm -f \"$tmpfile\"; }" EXIT
nmap \
-Pn \
-n \
@@ -55,5 +57,5 @@ kapow route add -X POST /nmap-callback - <<-'EOF'
-F "data=@$tmpfile" \
"$CALLBACK"
} | kapow set /response/stream
} | kapow set /response/body
EOF
+18 -14
View File
@@ -17,8 +17,10 @@
#
#
# Streams nmap execution. When processes finishes print the value ##########"
# as separator and then print the Nmap XML report
# Streams nmap execution.
#
# The output from Nmap is wrapped in XML comment delimiters
# and then follows the Nmap XML report proper
#
# Call example:
@@ -27,16 +29,19 @@
#
kapow route add -X POST /nmap-stream - <<-'EOF'
PORTS=$(kapow get /request/form/ports)
: ${PORTS:=9000}
IP=$(kapow get /request/form/ip)
: ${IP:=127.0.0.1}
tmpfile="$(mktemp --suffix=.xml)"
trap "{ rm -f \"$tmpfile\"; }" EXIT
kapow set /response/headers/Content-Type text/xml
{
PORTS=$(kapow get /request/form/ports)
: ${PORTS:=9000}
IP=$(kapow get /request/form/ip)
: ${IP:=127.0.0.1}
tmpfile="$(mktemp --suffix=.nmap)"
trap "{ rm -f \"$tmpfile\"; }" EXIT
echo '<?xml version="1.0" encoding="UTF-8"?>'
echo '<!--'
nmap \
-Pn \
@@ -45,8 +50,7 @@ kapow route add -X POST /nmap-stream - <<-'EOF'
-oX "$tmpfile" \
"$IP"
echo '-->'
tail --lines=+2 "$tmpfile"
cat "$tmpfile"
} | kapow set /response/stream
} | kapow set /response/body
EOF