* Update comments. * Add Content-Type: text/xml header (nmap-streaming.pow) only. * Wrap the Nmap output in XML comment delimiters, *after* the XML header. * Write to /response/body (preferred) instead of /response/stream (legacy). * Use suffix .xml for temp files. * Move possibly noise-generating calls outside of the block that is sent to the /request/body.
57 lines
1.3 KiB
Bash
Executable File
57 lines
1.3 KiB
Bash
Executable File
#!/bin/bash
|
|
|
|
#
|
|
# Copyright 2019 Banco Bilbao Vizcaya Argentaria, S.A.
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
#
|
|
|
|
#
|
|
# Streams nmap execution.
|
|
#
|
|
# The output from Nmap is wrapped in XML comment delimiters
|
|
# and then follows the Nmap XML report proper
|
|
#
|
|
|
|
# Call example:
|
|
#
|
|
# $ curl -v http://localhost:8080/nmap-stream -d 'ip=127.0.0.1&ports=9000'
|
|
#
|
|
|
|
kapow route add -X POST /nmap-stream - <<-'EOF'
|
|
PORTS=$(kapow get /request/form/ports)
|
|
: ${PORTS:=9000}
|
|
|
|
IP=$(kapow get /request/form/ip)
|
|
: ${IP:=127.0.0.1}
|
|
|
|
tmpfile="$(mktemp --suffix=.xml)"
|
|
trap "{ rm -f \"$tmpfile\"; }" EXIT
|
|
|
|
kapow set /response/headers/Content-Type text/xml
|
|
|
|
{
|
|
echo '<?xml version="1.0" encoding="UTF-8"?>'
|
|
echo '<!--'
|
|
nmap \
|
|
-Pn \
|
|
-n \
|
|
-p "$PORTS" \
|
|
-oX "$tmpfile" \
|
|
"$IP"
|
|
echo '-->'
|
|
tail --lines=+2 "$tmpfile"
|
|
|
|
} | kapow set /response/body
|
|
EOF
|