Commit 33db74cf by 钱炳权

Merge branch 'master' into 'dev'

Master

See merge request !2
parents 970ef118 0745a33d
...@@ -16,3 +16,12 @@ ...@@ -16,3 +16,12 @@
2024-04-01 14:46:12.978 [main] INFO o.s.b.w.s.c.ServletWebServerApplicationContext - Root WebApplicationContext: initialization completed in 461 ms 2024-04-01 14:46:12.978 [main] INFO o.s.b.w.s.c.ServletWebServerApplicationContext - Root WebApplicationContext: initialization completed in 461 ms
2024-04-01 14:46:13.162 [main] INFO o.s.boot.web.embedded.tomcat.TomcatWebServer - Tomcat started on port(s): 8100 (http) with context path '' 2024-04-01 14:46:13.162 [main] INFO o.s.boot.web.embedded.tomcat.TomcatWebServer - Tomcat started on port(s): 8100 (http) with context path ''
2024-04-01 14:46:13.169 [main] INFO com.example.fuzzControll.FuzzControlApplication - Started FuzzControlApplication in 0.849 seconds (JVM running for 1.322) 2024-04-01 14:46:13.169 [main] INFO com.example.fuzzControll.FuzzControlApplication - Started FuzzControlApplication in 0.849 seconds (JVM running for 1.322)
2024-04-08 14:12:55.975 [main] INFO com.example.fuzzControll.FuzzControlApplication - Starting FuzzControlApplication using Java 11.0.6 on DESKTOP-GDSKRB2 with PID 27760 (D:\code\company\fuzz-backend\fuzz-backend\fuzzbackend\target\classes started by qian in D:\code\company\fuzz-backend\fuzz-backend\fuzzbackend)
2024-04-08 14:12:55.989 [main] INFO com.example.fuzzControll.FuzzControlApplication - The following 1 profile is active: "dev"
2024-04-08 14:12:56.567 [main] INFO o.s.boot.web.embedded.tomcat.TomcatWebServer - Tomcat initialized with port(s): 8100 (http)
2024-04-08 14:12:56.573 [main] INFO org.apache.catalina.core.StandardService - Starting service [Tomcat]
2024-04-08 14:12:56.573 [main] INFO org.apache.catalina.core.StandardEngine - Starting Servlet engine: [Apache Tomcat/9.0.68]
2024-04-08 14:12:56.793 [main] INFO o.a.c.core.ContainerBase.[Tomcat].[localhost].[/] - Initializing Spring embedded WebApplicationContext
2024-04-08 14:12:56.793 [main] INFO o.s.b.w.s.c.ServletWebServerApplicationContext - Root WebApplicationContext: initialization completed in 779 ms
2024-04-08 14:12:56.972 [main] INFO o.s.boot.web.embedded.tomcat.TomcatWebServer - Tomcat started on port(s): 8100 (http) with context path ''
2024-04-08 14:12:56.991 [main] INFO com.example.fuzzControll.FuzzControlApplication - Started FuzzControlApplication in 1.299 seconds (JVM running for 2.308)
...@@ -22,6 +22,7 @@ ...@@ -22,6 +22,7 @@
<dependency> <dependency>
<groupId>org.springframework.boot</groupId> <groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter</artifactId> <artifactId>spring-boot-starter</artifactId>
<version>2.5.3</version>
</dependency> </dependency>
<dependency> <dependency>
<groupId>org.springframework.boot</groupId> <groupId>org.springframework.boot</groupId>
...@@ -51,11 +52,6 @@ ...@@ -51,11 +52,6 @@
<dependency> <dependency>
<groupId>com.alibaba</groupId> <groupId>com.alibaba</groupId>
<artifactId>fastjson</artifactId> <artifactId>fastjson</artifactId>
<version>1.2.47</version>
</dependency>
<dependency>
<groupId>com.alibaba</groupId>
<artifactId>fastjson</artifactId>
<version>2.0.31</version> <version>2.0.31</version>
</dependency> </dependency>
<dependency> <dependency>
...@@ -86,31 +82,35 @@ ...@@ -86,31 +82,35 @@
<plugins> <plugins>
<plugin> <plugin>
<groupId>org.apache.maven.plugins</groupId> <groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-compiler-plugin</artifactId> <artifactId>maven-surefire-plugin</artifactId>
<version>3.8.1</version> <version>2.22.2</version>
<configuration> <configuration>
<source>11</source> <skipTests>true</skipTests>
<target>11</target>
<encoding>UTF-8</encoding>
</configuration> </configuration>
</plugin> </plugin>
<plugin> <plugin>
<groupId>org.springframework.boot</groupId> <groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-maven-plugin</artifactId> <artifactId>spring-boot-maven-plugin</artifactId>
<version>${spring-boot.version}</version> <version>2.6.13</version>
<configuration>
<mainClass>com.example.fuzzControll.AflnetControlApplication</mainClass>
<skip>true</skip>
</configuration>
<executions> <executions>
<execution> <execution>
<id>repackage</id>
<goals> <goals>
<goal>repackage</goal> <goal>repackage</goal>
</goals> </goals>
</execution> </execution>
</executions> </executions>
</plugin> </plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-compiler-plugin</artifactId>
<configuration>
<source>7</source>
<target>7</target>
</configuration>
</plugin>
</plugins> </plugins>
</build> </build>
......
...@@ -5,7 +5,7 @@ import org.springframework.stereotype.Component; ...@@ -5,7 +5,7 @@ import org.springframework.stereotype.Component;
@Component("kittyProperties") @Component("kittyProperties")
@ConfigurationProperties(prefix = "kitty") @ConfigurationProperties(prefix = "kitty")
public class kittyProperties { public class KittyProperties {
String path; String path;
String venvPath; String venvPath;
String methodPath; String methodPath;
...@@ -15,6 +15,15 @@ public class kittyProperties { ...@@ -15,6 +15,15 @@ public class kittyProperties {
String stagesHttp; String stagesHttp;
String reportHttp; String reportHttp;
String mutationPath; String mutationPath;
String aflnetPath;
public String getAflnetPath() {
return aflnetPath;
}
public void setAflnetPath(String aflnetPath) {
this.aflnetPath = aflnetPath;
}
public String getMutationPath() { public String getMutationPath() {
return mutationPath; return mutationPath;
......
...@@ -5,7 +5,7 @@ import org.springframework.stereotype.Component; ...@@ -5,7 +5,7 @@ import org.springframework.stereotype.Component;
@Component("seedProperties") @Component("seedProperties")
@ConfigurationProperties(prefix = "filepath") @ConfigurationProperties(prefix = "filepath")
public class seedProperties { public class SeedProperties {
String seedPath; String seedPath;
public String getSeedPath() { public String getSeedPath() {
......
package com.example.fuzzControll.constents;
import com.example.fuzzControll.conf.SpringContextUtil;
import com.example.fuzzControll.conf.KittyProperties;
public class CmdConstent {
static KittyProperties kittyProperties = (KittyProperties)SpringContextUtil.getBean("kittyProperties");
public static final String GET_FILE_NAME = "ls -h ";
public static final String DELETE_FILE = "sudo rm -r ";
public static final String COUNT_FILE = "ls -l | grep \"^-\" | wc -l";
public static final String COUNT_DIR = "ls -l | grep \"^d\" | wc -l";
public static final String RUN_AFLNET = "afl-fuzz -d -i "+kittyProperties.getAflnetPath()+"aflnet/tutorials/live555/in-rtsp -o out-live8 " +
"-x "+kittyProperties.getAflnetPath()+"aflnet/tutorials/live555/rtsp.dict ";
public static final String RUN_PING = "ping www.baidu.com";
}
package com.example.fuzzControll.constents; package com.example.fuzzControll.constents;
public class mutationConstent { public class MutationConstent {
public static final String TEST_GRANULARITY_BIT_BYTE = "test_granularity_bit_byte.py "; public static final String TEST_GRANULARITY_BIT_BYTE = "test_granularity_bit_byte.py ";
public static final String TEST_MUTATED_LIBS = "test_mutated_libs.py "; public static final String TEST_MUTATED_LIBS = "test_mutated_libs.py ";
public static final String TEST_MUTATION_STRATEGY = "test_mutation_strategy.py "; public static final String TEST_MUTATION_STRATEGY = "test_mutation_strategy.py ";
......
package com.example.fuzzControll.constents; package com.example.fuzzControll.constents;
public class protocolConstent { public class ProtocolConstent {
public static final String ARP = "arp_raw.py "; public static final String ARP = "arp_raw.py ";
public static final String BGP = "bgp_tcp.py "; public static final String BGP = "bgp_tcp.py ";
public static final String DHCP = "dhcp_scapy.py "; public static final String DHCP = "dhcp_scapy.py ";
......
package com.example.fuzzControll.constents;
public class cmdConstent {
public static final String GET_FILE_NAME = "ls -h ";
public static final String DELETE_FILE = "sudo rm -r ";
public static final String RUN_AFLNET = "afl-fuzz -d -i /home/qbq/aflnet/tutorials/live555/in-rtsp -o out-live8 " +
"-x /home/qbq/aflnet/tutorials/live555/rtsp.dict ";
public static final String RUN_PING = "ping www.baidu.com";
}
package com.example.fuzzControll.controller; package com.example.fuzzControll.controller;
import com.example.fuzzControll.pojo.vo.AjaxResult; import com.example.fuzzControll.pojo.vo.AjaxResult;
import com.example.fuzzControll.service.getServerMessageService; import com.example.fuzzControll.service.GetServerMessageService;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.web.bind.annotation.RequestMapping; import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestMethod; import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController; import org.springframework.web.bind.annotation.RestController;
import java.util.Arrays;
/** /**
* kitty服务器信息 * kitty服务器信息
*/ */
@RestController @RestController
@RequestMapping("/kittyServer") @RequestMapping("/kittyServer")
public class kittyServerMessageController { @Slf4j
public class KittyServerMessageController {
@Autowired @Autowired
getServerMessageService getServerMessageService; GetServerMessageService getServerMessageService;
/** /**
* 获取服务器stats信息 * 获取服务器stats信息
*/ */
...@@ -23,6 +27,7 @@ public class kittyServerMessageController { ...@@ -23,6 +27,7 @@ public class kittyServerMessageController {
try { try {
return AjaxResult.success(getServerMessageService.getStats()); return AjaxResult.success(getServerMessageService.getStats());
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("stats信息获取失败!"); return AjaxResult.error("stats信息获取失败!");
} }
} }
...@@ -34,6 +39,7 @@ public class kittyServerMessageController { ...@@ -34,6 +39,7 @@ public class kittyServerMessageController {
try { try {
return AjaxResult.success(getServerMessageService.getTemplateInfo()); return AjaxResult.success(getServerMessageService.getTemplateInfo());
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("templateInfo信息获取失败!"); return AjaxResult.error("templateInfo信息获取失败!");
} }
} }
...@@ -45,7 +51,8 @@ public class kittyServerMessageController { ...@@ -45,7 +51,8 @@ public class kittyServerMessageController {
try { try {
return AjaxResult.success(getServerMessageService.getStages()); return AjaxResult.success(getServerMessageService.getStages());
} catch (Exception e) { } catch (Exception e) {
return AjaxResult.error("stats信息获取失败!"); log.error(e.getMessage());
return AjaxResult.error("stages信息获取失败!");
} }
} }
/** /**
...@@ -56,7 +63,8 @@ public class kittyServerMessageController { ...@@ -56,7 +63,8 @@ public class kittyServerMessageController {
try { try {
return AjaxResult.success(getServerMessageService.getReport()); return AjaxResult.success(getServerMessageService.getReport());
} catch (Exception e) { } catch (Exception e) {
return AjaxResult.error("stats信息获取失败!"); log.error(e.getMessage());
return AjaxResult.error("report信息获取失败!");
} }
} }
} }
package com.example.fuzzControll.controller; package com.example.fuzzControll.controller;
import com.example.fuzzControll.pojo.vo.AjaxResult; import com.example.fuzzControll.pojo.vo.AjaxResult;
import com.example.fuzzControll.service.seedFileService; import com.example.fuzzControll.service.SeedFileService;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.web.bind.annotation.PathVariable; import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.RequestMapping; import org.springframework.web.bind.annotation.RequestMapping;
...@@ -9,17 +10,19 @@ import org.springframework.web.bind.annotation.RequestMethod; ...@@ -9,17 +10,19 @@ import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController; import org.springframework.web.bind.annotation.RestController;
import org.springframework.web.multipart.MultipartFile; import org.springframework.web.multipart.MultipartFile;
import java.util.Arrays;
import java.util.List; import java.util.List;
/** /**
* aflnet种子文件 * aflnet种子文件
*/ */
@Slf4j
@RestController @RestController
@RequestMapping("/seedFile") @RequestMapping("/seedFile")
public class seedFileController { public class SeedFileController {
@Autowired @Autowired
seedFileService service; SeedFileService service;
/** /**
* 种子文件查询接口 * 种子文件查询接口
...@@ -30,6 +33,7 @@ public class seedFileController { ...@@ -30,6 +33,7 @@ public class seedFileController {
try { try {
files = service.getSeedFiles(); files = service.getSeedFiles();
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("种子文件获取失败!"); return AjaxResult.error("种子文件获取失败!");
} }
return AjaxResult.success(files); return AjaxResult.success(files);
...@@ -43,6 +47,7 @@ public class seedFileController { ...@@ -43,6 +47,7 @@ public class seedFileController {
try { try {
service.delFile(fileName); service.delFile(fileName);
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("种子文件删除失败!"); return AjaxResult.error("种子文件删除失败!");
} }
return AjaxResult.success("种子文件删除成功!"); return AjaxResult.success("种子文件删除成功!");
...@@ -55,6 +60,7 @@ public class seedFileController { ...@@ -55,6 +60,7 @@ public class seedFileController {
try { try {
service.upload(file); service.upload(file);
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("种子文件upload失败!"); return AjaxResult.error("种子文件upload失败!");
} }
return AjaxResult.success("种子文件upload成功!"); return AjaxResult.success("种子文件upload成功!");
......
package com.example.fuzzControll.controller; package com.example.fuzzControll.controller;
import com.example.fuzzControll.pojo.vo.AjaxResult; import com.example.fuzzControll.pojo.vo.AjaxResult;
import com.example.fuzzControll.pojo.vo.testEntity; import com.example.fuzzControll.pojo.vo.TestEntity;
import com.example.fuzzControll.service.generateMethodService; import com.example.fuzzControll.service.GenerateMethodService;
import com.example.fuzzControll.service.mutationService; import com.example.fuzzControll.service.MutationService;
import com.example.fuzzControll.service.protocolTemplateService; import com.example.fuzzControll.service.ProtocolTemplateService;
import com.example.fuzzControll.service.vulnerabilityTypeService; import com.example.fuzzControll.service.VulnerabilityTypeService;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.web.bind.annotation.RequestBody; import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestMapping; import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestMethod; import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController; import org.springframework.web.bind.annotation.RestController;
import java.util.Arrays;
import java.util.List; import java.util.List;
import java.util.Map; import java.util.Map;
/** /**
* 不同类型的测试方法 * 不同类型的测试方法
*/ */
@Slf4j
@RestController @RestController
@RequestMapping("/testClass") @RequestMapping("/testClass")
public class testClassController { public class TestClassController {
@Autowired @Autowired
generateMethodService generateMethodService; GenerateMethodService generateMethodService;
@Autowired @Autowired
mutationService mutationService; MutationService mutationService;
@Autowired @Autowired
protocolTemplateService protocolTemplateService; ProtocolTemplateService protocolTemplateService;
@Autowired @Autowired
vulnerabilityTypeService vulnerabilityTypeService; VulnerabilityTypeService vulnerabilityTypeService;
/** /**
* 模板 * 模板
*/ */
@RequestMapping(value = "/protocolTemplate", method = RequestMethod.POST) @RequestMapping(value = "/protocolTemplate", method = RequestMethod.POST)
public AjaxResult protocolTemplate(@RequestBody testEntity testEntity) { public AjaxResult protocolTemplate(@RequestBody TestEntity testEntity) {
try { try {
Map<String, List<String>> result = protocolTemplateService.generation(testEntity); Map<String, List<String>> result = protocolTemplateService.generation(testEntity);
return AjaxResult.success(result==null?"模板文件生成未成功运行":result); return AjaxResult.success(result==null?"模板文件生成未成功运行":result);
} catch (Exception e) { } catch (Exception e) {
return AjaxResult.error("模板文件生成失败!"); log.error(e.getMessage());
return AjaxResult.error(e.getMessage());
} }
} }
...@@ -46,11 +50,12 @@ public class testClassController { ...@@ -46,11 +50,12 @@ public class testClassController {
*生成方法 *生成方法
*/ */
@RequestMapping(value = "/generate", method = RequestMethod.POST) @RequestMapping(value = "/generate", method = RequestMethod.POST)
public AjaxResult generate(@RequestBody testEntity testEntity) { public AjaxResult generate(@RequestBody TestEntity testEntity) {
try { try {
Map<String, List<String>> result = generateMethodService.generation(testEntity); Map<String, List<String>> result = generateMethodService.generation(testEntity);
return AjaxResult.success(result==null?"生成方法未成功运行":result); return AjaxResult.success(result==null?"生成方法未成功运行":result);
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("生成方法使用失败!"); return AjaxResult.error("生成方法使用失败!");
} }
} }
...@@ -59,11 +64,12 @@ public class testClassController { ...@@ -59,11 +64,12 @@ public class testClassController {
*变异方法 *变异方法
*/ */
@RequestMapping(value = "/mutation", method = RequestMethod.POST) @RequestMapping(value = "/mutation", method = RequestMethod.POST)
public AjaxResult mutation(@RequestBody testEntity testEntity) { public AjaxResult mutation(@RequestBody TestEntity testEntity) {
try { try {
Map<String, List<String>> result = mutationService.generation(testEntity); Map<String, List<String>> result = mutationService.generation(testEntity);
return AjaxResult.success(result==null?"mutationTest未成功运行":result); return AjaxResult.success(result==null?"mutationTest未成功运行":result);
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("mutationTest失败!"); return AjaxResult.error("mutationTest失败!");
} }
} }
...@@ -72,11 +78,12 @@ public class testClassController { ...@@ -72,11 +78,12 @@ public class testClassController {
*漏洞类型 *漏洞类型
*/ */
@RequestMapping(value = "/vulnerabilityType", method = RequestMethod.POST) @RequestMapping(value = "/vulnerabilityType", method = RequestMethod.POST)
public AjaxResult upload(@RequestBody testEntity testEntity) { public AjaxResult upload(@RequestBody TestEntity testEntity) {
try { try {
Map<String, List<String>> result = vulnerabilityTypeService.generation(testEntity); Map<String, List<String>> result = vulnerabilityTypeService.generation(testEntity);
return AjaxResult.success(result==null?"漏洞类型未成功运行":result); return AjaxResult.success(result==null?"漏洞类型未成功运行":result);
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("漏洞类型测试失败!"); return AjaxResult.error("漏洞类型测试失败!");
} }
} }
......
package com.example.fuzzControll.controller; package com.example.fuzzControll.controller;
import com.example.fuzzControll.pojo.vo.AjaxResult; import com.example.fuzzControll.pojo.vo.AjaxResult;
import com.example.fuzzControll.pojo.vo.cmdStartParams; import com.example.fuzzControll.pojo.vo.CmdStartParams;
import com.example.fuzzControll.service.testService; import com.example.fuzzControll.service.TestService;
import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.web.bind.annotation.RequestBody; import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestMapping; import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestMethod; import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController; import org.springframework.web.bind.annotation.RestController;
import java.util.Arrays;
/** /**
* aflnet测试控制 * aflnet测试控制
*/ */
@Slf4j
@RestController @RestController
@RequestMapping("/test") @RequestMapping("/test")
public class testControler { public class TestControler {
@Autowired @Autowired
testService service; TestService service;
/** /**
* 测试启动 * 测试启动
*/ */
@RequestMapping(value = "/testStart", method = RequestMethod.POST) @RequestMapping(value = "/testStart", method = RequestMethod.POST)
public AjaxResult list(@RequestBody cmdStartParams cmdStartParams) { public AjaxResult list(@RequestBody final CmdStartParams cmdStartParams) {
try { try {
new Thread(new Runnable() { new Thread(new Runnable() {
@Override @Override
public void run() { public void run() {
log.info("aflnet start!");
service.testStart(cmdStartParams); service.testStart(cmdStartParams);
} }
}).start(); }).start();
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("测试启动失败!"); return AjaxResult.error("测试启动失败!");
} }
return AjaxResult.success("测试启动成功!"); return AjaxResult.success("测试启动成功!");
...@@ -44,6 +50,7 @@ public class testControler { ...@@ -44,6 +50,7 @@ public class testControler {
try { try {
service.testStop(); service.testStop();
} catch (Exception e) { } catch (Exception e) {
log.error(e.getMessage());
return AjaxResult.error("测试停止失败!"); return AjaxResult.error("测试停止失败!");
} }
return AjaxResult.success("测试停止成功!"); return AjaxResult.success("测试停止成功!");
......
package com.example.fuzzControll.controller; package com.example.fuzzControll.controller;
import lombok.extern.slf4j.Slf4j;
import org.springframework.stereotype.Component; import org.springframework.stereotype.Component;
import javax.websocket.*; import javax.websocket.*;
...@@ -14,17 +15,18 @@ import java.util.concurrent.ConcurrentHashMap; ...@@ -14,17 +15,18 @@ import java.util.concurrent.ConcurrentHashMap;
*/ */
@Component("WebSocket") @Component("WebSocket")
@ServerEndpoint("/websocket/testResult/{name}") @ServerEndpoint("/websocket/testResult/{name}")
@Slf4j
public class WebSocket { public class WebSocket {
private Session session; //与某个客户端连接对话,通过此对客户端发送消息 private Session session; //与某个客户端连接对话,通过此对客户端发送消息
private static final ConcurrentHashMap<String, WebSocket> WEBSOCKET_CONCURRENTHASHMAP = new ConcurrentHashMap<>(); //存放所有连接的客户端 private static final ConcurrentHashMap<String, WebSocket> WEBSOCKET_CONCURRENTHASHMAP = new ConcurrentHashMap<String, WebSocket>(); //存放所有连接的客户端
@OnOpen @OnOpen
public void onOpen(Session session, @PathParam(value = "name") String name) { public void onOpen(Session session, @PathParam(value = "name") String name) {
this.session = session; //默认客户端,没有重名 this.session = session; //默认客户端,没有重名
WEBSOCKET_CONCURRENTHASHMAP.put(name, this); WEBSOCKET_CONCURRENTHASHMAP.put(name, this);
System.out.println("【webSocket连接成功】当前连接人数为:" + WEBSOCKET_CONCURRENTHASHMAP.size() + ",此人为:" + name); log.info("Websocket is connected! The man is {}.There are {} people in the connection ",name,WEBSOCKET_CONCURRENTHASHMAP.size());
} }
...@@ -40,8 +42,7 @@ public class WebSocket { ...@@ -40,8 +42,7 @@ public class WebSocket {
} }
} }
log.info("Websocket is closed! There are {} people in the connection ",WEBSOCKET_CONCURRENTHASHMAP.size());
System.out.println("【webSocket退出成功】当前连接人数为:" + WEBSOCKET_CONCURRENTHASHMAP.size());
} }
@OnError @OnError
...@@ -93,7 +94,6 @@ public class WebSocket { ...@@ -93,7 +94,6 @@ public class WebSocket {
public void appointSending(String sender, String name, String message) { public void appointSending(String sender, String name, String message) {
try { try {
// WEBSOCKET_CONCURRENTHASHMAP.get(name).session.getBasicRemote().sendText(sender + ":" + message); // WEBSOCKET_CONCURRENTHASHMAP.get(name).session.getBasicRemote().sendText(sender + ":" + message);
WEBSOCKET_CONCURRENTHASHMAP.get(name).session.getBasicRemote().sendText(message); WEBSOCKET_CONCURRENTHASHMAP.get(name).session.getBasicRemote().sendText(message);
......
package com.example.fuzzControll.exception;
public class AflnetException extends BaseException{
private static final long serialVersionUID = 1L;
public AflnetException(String defaultMessage) {
super(defaultMessage, "aflnet");
}
}
package com.example.fuzzControll.exception;
/**
* 基础异常
*/
public class BaseException extends RuntimeException{
private static final long serialVersionUID = 1L;
/**
* 错误消息
*/
private String defaultMessage;
/**
* 所属模块
*/
private String module;
public BaseException() {
}
public BaseException(String defaultMessage, String module) {
this.defaultMessage = defaultMessage;
this.module = module;
}
}
package com.example.fuzzControll.exception;
/**
* cmd运行异常
*/
public class CmdException extends BaseException {
private static final long serialVersionUID = 1L;
public CmdException() {
}
public CmdException(String defaultMessage) {
super(defaultMessage, "cmd");
}
}
package com.example.fuzzControll.exception;
/**
* 文件操作异常
*/
public class FileException extends BaseException{
private static final long serialVersionUID = 1L;
public FileException(String defaultMessage) {
super(defaultMessage, "file");
}
}
package com.example.fuzzControll.exception;
public class FuzzException extends BaseException{
private static final long serialVersionUID = 1L;
public FuzzException(String defaultMessage) {
super(defaultMessage, "fuzz");
}
}
package com.example.fuzzControll.exception;
public class ServerException extends BaseException{
private static final long serialVersionUID = 1L;
public ServerException(String defaultMessage) {
super(defaultMessage, "server");
}
}
...@@ -7,7 +7,7 @@ import lombok.Setter; ...@@ -7,7 +7,7 @@ import lombok.Setter;
@Data @Data
@Getter @Getter
@Setter @Setter
public class cmdStartParams { public class CmdStartParams {
String netinfo; //netInfo String netinfo; //netInfo
String protopcol; //protocol String protopcol; //protocol
int waiting; //usec int waiting; //usec
......
...@@ -7,7 +7,7 @@ import lombok.Setter; ...@@ -7,7 +7,7 @@ import lombok.Setter;
@Data @Data
@Getter @Getter
@Setter @Setter
public class testEntity { public class TestEntity {
String testClassName; String testClassName;
String[] paramJson; String[] paramJson;
} }
...@@ -3,7 +3,7 @@ package com.example.fuzzControll.pojo.vo; ...@@ -3,7 +3,7 @@ package com.example.fuzzControll.pojo.vo;
import lombok.Data; import lombok.Data;
@Data @Data
public class testReturnEntity { public class TestReturnEntity {
String run_time; String run_time;
String cycles_done; String cycles_done;
String last_new_path; String last_new_path;
......
package com.example.fuzzControll.service; package com.example.fuzzControll.service;
import com.example.fuzzControll.pojo.vo.testEntity; import com.example.fuzzControll.pojo.vo.TestEntity;
import java.util.List; import java.util.List;
import java.util.Map; import java.util.Map;
public interface generateMethodService { public interface GenerateMethodService {
Map<String,List<String>> generation(testEntity testEntity); Map<String,List<String>> generation(TestEntity testEntity);
} }
package com.example.fuzzControll.service; package com.example.fuzzControll.service;
import java.util.List; public interface GetServerMessageService {
import java.util.Map;
public interface getServerMessageService {
String getStats(); String getStats();
String getTemplateInfo(); String getTemplateInfo();
......
package com.example.fuzzControll.service; package com.example.fuzzControll.service;
import com.example.fuzzControll.pojo.vo.testEntity; import com.example.fuzzControll.pojo.vo.TestEntity;
import java.util.List; import java.util.List;
import java.util.Map; import java.util.Map;
public interface mutationService { public interface MutationService {
Map<String, List<String>> generation(testEntity testEntity); Map<String, List<String>> generation(TestEntity testEntity);
} }
package com.example.fuzzControll.service; package com.example.fuzzControll.service;
import com.example.fuzzControll.pojo.vo.testEntity; import com.example.fuzzControll.pojo.vo.TestEntity;
import java.util.List; import java.util.List;
import java.util.Map; import java.util.Map;
public interface protocolTemplateService { public interface ProtocolTemplateService {
Map<String,List<String>> generation(testEntity testEntity); Map<String,List<String>> generation(TestEntity testEntity);
} }
...@@ -4,10 +4,11 @@ import org.springframework.web.multipart.MultipartFile; ...@@ -4,10 +4,11 @@ import org.springframework.web.multipart.MultipartFile;
import java.util.List; import java.util.List;
public interface seedFileService { public interface SeedFileService {
public List<String> getSeedFiles(); public List<String> getSeedFiles();
void delFile(String fileName); void delFile(String fileName);
void upload(MultipartFile file); void upload(MultipartFile file);
int getSeedFileCount(String msg);
} }
package com.example.fuzzControll.service; package com.example.fuzzControll.service;
import com.example.fuzzControll.pojo.vo.cmdStartParams; import com.example.fuzzControll.pojo.vo.CmdStartParams;
public interface testService { public interface TestService {
void testStart(cmdStartParams cmdStartParams); void testStart(CmdStartParams cmdStartParams);
void testStop(); void testStop();
......
package com.example.fuzzControll.service; package com.example.fuzzControll.service;
import com.example.fuzzControll.pojo.vo.testEntity; import com.example.fuzzControll.pojo.vo.TestEntity;
import java.util.List; import java.util.List;
import java.util.Map; import java.util.Map;
public interface vulnerabilityTypeService { public interface VulnerabilityTypeService {
Map<String, List<String>> generation(testEntity testEntity); Map<String, List<String>> generation(TestEntity testEntity);
} }
package com.example.fuzzControll.service.impl; package com.example.fuzzControll.service.impl;
import com.example.fuzzControll.conf.kittyProperties; import com.example.fuzzControll.conf.KittyProperties;
import com.example.fuzzControll.pojo.vo.testEntity; import com.example.fuzzControll.exception.FuzzException;
import com.example.fuzzControll.service.generateMethodService; import com.example.fuzzControll.pojo.vo.TestEntity;
import com.example.fuzzControll.tools.cmdTools; import com.example.fuzzControll.service.GenerateMethodService;
import com.example.fuzzControll.tools.testTools; import com.example.fuzzControll.tools.CmdTools;
import com.example.fuzzControll.tools.TestTools;
import lombok.extern.slf4j.Slf4j; import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service; import org.springframework.stereotype.Service;
...@@ -14,13 +15,13 @@ import java.util.Map; ...@@ -14,13 +15,13 @@ import java.util.Map;
@Service @Service
@Slf4j @Slf4j
public class generateMethodServiceImpl implements generateMethodService { public class GenerateMethodServiceImpl implements GenerateMethodService {
cmdTools cmdTools = new cmdTools(); CmdTools cmdTools = new CmdTools();
@Autowired @Autowired
kittyProperties kitty; KittyProperties kitty;
@Override @Override
public Map<String, List<String>> generation(testEntity testEntity) { public Map<String, List<String>> generation(TestEntity testEntity) throws FuzzException {
String cmd = parseParameters(testEntity); String cmd = parseParameters(testEntity);
if (cmd.isEmpty()) { if (cmd.isEmpty()) {
return null; return null;
...@@ -28,7 +29,7 @@ public class generateMethodServiceImpl implements generateMethodService { ...@@ -28,7 +29,7 @@ public class generateMethodServiceImpl implements generateMethodService {
return cmdTools.runProgramCmdAndResult(cmd); return cmdTools.runProgramCmdAndResult(cmd);
} }
public String parseParameters(testEntity testEntity) { public String parseParameters(TestEntity testEntity) {
switch (testEntity.getTestClassName().toLowerCase()) { switch (testEntity.getTestClassName().toLowerCase()) {
case "foreach": case "foreach":
return cmd(testEntity, "-f"); return cmd(testEntity, "-f");
...@@ -56,8 +57,8 @@ public class generateMethodServiceImpl implements generateMethodService { ...@@ -56,8 +57,8 @@ public class generateMethodServiceImpl implements generateMethodService {
} }
} }
private String cmd(testEntity testEntity, String cmd) { private String cmd(TestEntity testEntity, String cmd) {
if (!testTools.paramsLenghtTest(testEntity.getParamJson().length, 5, "generationMethod")) if (!TestTools.paramsLenghtTest(testEntity.getParamJson().length, 5, "generationMethod"))
return ""; return "";
String target_host = null; String target_host = null;
String target_port = null; String target_port = null;
......
package com.example.fuzzControll.service.impl; package com.example.fuzzControll.service.impl;
import com.example.fuzzControll.conf.kittyProperties; import com.example.fuzzControll.conf.KittyProperties;
import com.example.fuzzControll.service.getServerMessageService; import com.example.fuzzControll.exception.ServerException;
import com.example.fuzzControll.service.GetServerMessageService;
import lombok.extern.slf4j.Slf4j; import lombok.extern.slf4j.Slf4j;
import org.apache.http.HttpStatus;
import org.apache.http.client.methods.CloseableHttpResponse; import org.apache.http.client.methods.CloseableHttpResponse;
import org.apache.http.client.methods.HttpGet; import org.apache.http.client.methods.HttpGet;
import org.apache.http.impl.client.CloseableHttpClient; import org.apache.http.impl.client.CloseableHttpClient;
...@@ -12,16 +12,11 @@ import org.apache.http.util.EntityUtils; ...@@ -12,16 +12,11 @@ import org.apache.http.util.EntityUtils;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service; import org.springframework.stereotype.Service;
import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
@Slf4j @Slf4j
@Service("getServerMessageService") @Service("getServerMessageService")
public class getServerMessageImpl implements getServerMessageService { public class GetServerMessageImpl implements GetServerMessageService {
@Autowired @Autowired
kittyProperties kitty; KittyProperties kitty;
public String getServerMsg(String messageName) { public String getServerMsg(String messageName) {
switch (messageName) { switch (messageName) {
...@@ -31,7 +26,7 @@ public class getServerMessageImpl implements getServerMessageService { ...@@ -31,7 +26,7 @@ public class getServerMessageImpl implements getServerMessageService {
CloseableHttpResponse templateInfoResponse = httpClient.execute(httpGetTemplateInfo);) { CloseableHttpResponse templateInfoResponse = httpClient.execute(httpGetTemplateInfo);) {
return EntityUtils.toString(templateInfoResponse.getEntity(), "utf-8"); return EntityUtils.toString(templateInfoResponse.getEntity(), "utf-8");
} catch (Exception e) { } catch (Exception e) {
log.error("templateInfo http error!"); throw new ServerException("get server templateInfo error !");
} }
} }
case "stats": { case "stats": {
...@@ -40,7 +35,7 @@ public class getServerMessageImpl implements getServerMessageService { ...@@ -40,7 +35,7 @@ public class getServerMessageImpl implements getServerMessageService {
CloseableHttpResponse statsResponse = httpClient.execute(httpGetStats);) { CloseableHttpResponse statsResponse = httpClient.execute(httpGetStats);) {
return EntityUtils.toString(statsResponse.getEntity(), "utf-8"); return EntityUtils.toString(statsResponse.getEntity(), "utf-8");
} catch (Exception e) { } catch (Exception e) {
log.error("stats http error!"); throw new ServerException("get server stats error !");
} }
} }
case "report": { case "report": {
...@@ -49,7 +44,8 @@ public class getServerMessageImpl implements getServerMessageService { ...@@ -49,7 +44,8 @@ public class getServerMessageImpl implements getServerMessageService {
CloseableHttpResponse reportResponse = httpClient.execute(httpGetStats);) { CloseableHttpResponse reportResponse = httpClient.execute(httpGetStats);) {
return EntityUtils.toString(reportResponse.getEntity(), "utf-8"); return EntityUtils.toString(reportResponse.getEntity(), "utf-8");
} catch (Exception e) { } catch (Exception e) {
log.error("report http error!"); throw new ServerException("get server report error !");
} }
} }
case "stages": { case "stages": {
...@@ -58,7 +54,7 @@ public class getServerMessageImpl implements getServerMessageService { ...@@ -58,7 +54,7 @@ public class getServerMessageImpl implements getServerMessageService {
CloseableHttpResponse stagesResponse = httpClient.execute(httpGetStats);) { CloseableHttpResponse stagesResponse = httpClient.execute(httpGetStats);) {
return EntityUtils.toString(stagesResponse.getEntity(), "utf-8"); return EntityUtils.toString(stagesResponse.getEntity(), "utf-8");
} catch (Exception e) { } catch (Exception e) {
log.error("stages http error!"); throw new ServerException("get server stages error !");
} }
} }
default: default:
...@@ -72,17 +68,17 @@ public class getServerMessageImpl implements getServerMessageService { ...@@ -72,17 +68,17 @@ public class getServerMessageImpl implements getServerMessageService {
} }
@Override @Override
public String getTemplateInfo() { public String getTemplateInfo() throws ServerException{
return getServerMsg("templateInfo"); return getServerMsg("templateInfo");
} }
@Override @Override
public String getStages() { public String getStages() throws ServerException{
return getServerMsg("report"); return getServerMsg("stages");
} }
@Override @Override
public String getReport() { public String getReport() throws ServerException{
return getServerMsg("stages"); return getServerMsg("report");
} }
} }
package com.example.fuzzControll.service.impl; package com.example.fuzzControll.service.impl;
import com.example.fuzzControll.conf.kittyProperties; import com.example.fuzzControll.conf.KittyProperties;
import com.example.fuzzControll.constents.mutationConstent; import com.example.fuzzControll.constents.MutationConstent;
import com.example.fuzzControll.pojo.vo.testEntity; import com.example.fuzzControll.exception.FuzzException;
import com.example.fuzzControll.service.mutationService; import com.example.fuzzControll.pojo.vo.TestEntity;
import com.example.fuzzControll.tools.cmdTools; import com.example.fuzzControll.service.MutationService;
import com.example.fuzzControll.tools.testTools; import com.example.fuzzControll.tools.CmdTools;
import com.example.fuzzControll.tools.TestTools;
import lombok.extern.slf4j.Slf4j; import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service; import org.springframework.stereotype.Service;
...@@ -15,14 +16,14 @@ import java.util.Map; ...@@ -15,14 +16,14 @@ import java.util.Map;
@Service("mutationService") @Service("mutationService")
@Slf4j @Slf4j
class mutationServiceImpl implements mutationService { class MutationServiceImpl implements MutationService {
cmdTools cmdTools = new cmdTools(); CmdTools cmdTools = new CmdTools();
@Autowired @Autowired
kittyProperties kitty; KittyProperties kitty;
@Override @Override
public Map<String, List<String>> generation(testEntity testEntity) { public Map<String, List<String>> generation(TestEntity testEntity) throws FuzzException {
String cmd = parseParameters(testEntity); String cmd = parseParameters(testEntity);
if (cmd.isEmpty()) { if (cmd.isEmpty()) {
return null; return null;
...@@ -30,7 +31,7 @@ class mutationServiceImpl implements mutationService { ...@@ -30,7 +31,7 @@ class mutationServiceImpl implements mutationService {
return cmdTools.runProgramCmdAndResult(cmd); return cmdTools.runProgramCmdAndResult(cmd);
} }
public String parseParameters(testEntity testEntity) { public String parseParameters(TestEntity testEntity) {
switch (testEntity.getTestClassName().toLowerCase()) { switch (testEntity.getTestClassName().toLowerCase()) {
case "bit": case "bit":
return variationGranularityCmd(testEntity, 1); return variationGranularityCmd(testEntity, 1);
...@@ -96,8 +97,8 @@ class mutationServiceImpl implements mutationService { ...@@ -96,8 +97,8 @@ class mutationServiceImpl implements mutationService {
} }
} }
private String distortionLibCmd(testEntity testEntity, int methodNum) { private String distortionLibCmd(TestEntity testEntity, int methodNum) {
if (!testTools.paramsLenghtTest(testEntity.getParamJson().length, 2, "distortionLib" + methodNum)) if (!TestTools.paramsLenghtTest(testEntity.getParamJson().length, 2, "distortionLib" + methodNum))
return ""; return "";
String dst_ip = null; String dst_ip = null;
String dst_port = null; String dst_port = null;
...@@ -107,12 +108,12 @@ class mutationServiceImpl implements mutationService { ...@@ -107,12 +108,12 @@ class mutationServiceImpl implements mutationService {
} catch (Exception e) { } catch (Exception e) {
log.error("distortionLib [{}] 参数解析失败!", methodNum); log.error("distortionLib [{}] 参数解析失败!", methodNum);
} }
return kitty.getVenvPath() + " " + kitty.getMutationPath() + mutationConstent.TEST_MUTATED_LIBS + " -g " + methodNum + " -d " + dst_ip + " -p " + dst_port; return kitty.getVenvPath() + " " + kitty.getMutationPath() + MutationConstent.TEST_MUTATED_LIBS + " -g " + methodNum + " -d " + dst_ip + " -p " + dst_port;
} }
private String variationGranularityCmd(testEntity testEntity, int methodNum) { private String variationGranularityCmd(TestEntity testEntity, int methodNum) {
if (!testTools.paramsLenghtTest(testEntity.getParamJson().length, 2, "variationGranularity" + methodNum)) if (!TestTools.paramsLenghtTest(testEntity.getParamJson().length, 2, "variationGranularity" + methodNum))
return ""; return "";
String dst_ip = null; String dst_ip = null;
String dst_port = null; String dst_port = null;
...@@ -122,10 +123,10 @@ class mutationServiceImpl implements mutationService { ...@@ -122,10 +123,10 @@ class mutationServiceImpl implements mutationService {
} catch (Exception e) { } catch (Exception e) {
log.error("variationGranularity [{}] 参数解析失败!", methodNum); log.error("variationGranularity [{}] 参数解析失败!", methodNum);
} }
return kitty.getVenvPath() + " " + kitty.getMutationPath() + mutationConstent.TEST_GRANULARITY_BIT_BYTE + " -g " + methodNum + " -d " + dst_ip + " -p " + dst_port; return kitty.getVenvPath() + " " + kitty.getMutationPath() + MutationConstent.TEST_GRANULARITY_BIT_BYTE + " -g " + methodNum + " -d " + dst_ip + " -p " + dst_port;
} }
private String mutationStrategyCmd(testEntity testEntity, int methodNum) { private String mutationStrategyCmd(TestEntity testEntity, int methodNum) {
if (!testTools.paramsLenghtTest(testEntity.getParamJson().length, 2, "mutationStrategy" + methodNum)) if (!TestTools.paramsLenghtTest(testEntity.getParamJson().length, 2, "mutationStrategy" + methodNum))
return ""; return "";
String dst_ip = null; String dst_ip = null;
String dst_port = null; String dst_port = null;
...@@ -135,7 +136,7 @@ class mutationServiceImpl implements mutationService { ...@@ -135,7 +136,7 @@ class mutationServiceImpl implements mutationService {
} catch (Exception e) { } catch (Exception e) {
log.error("mutationStrategy [{}] 参数解析失败!", methodNum); log.error("mutationStrategy [{}] 参数解析失败!", methodNum);
} }
return kitty.getVenvPath() + " " + kitty.getMutationPath() + mutationConstent.TEST_MUTATION_STRATEGY + " -g " + methodNum + " -d " + dst_ip + " -p " + dst_port; return kitty.getVenvPath() + " " + kitty.getMutationPath() + MutationConstent.TEST_MUTATION_STRATEGY + " -g " + methodNum + " -d " + dst_ip + " -p " + dst_port;
} }
} }
\ No newline at end of file
package com.example.fuzzControll.service.impl;
import com.example.fuzzControll.conf.SeedProperties;
import com.example.fuzzControll.constents.CmdConstent;
import com.example.fuzzControll.exception.CmdException;
import com.example.fuzzControll.exception.FileException;
import com.example.fuzzControll.service.SeedFileService;
import com.example.fuzzControll.tools.CmdTools;
import com.example.fuzzControll.tools.FileTools;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service;
import org.springframework.web.multipart.MultipartFile;
import java.util.ArrayList;
import java.util.List;
@Service
public class SeedFileServiceImpl implements SeedFileService {
CmdTools cmdTools = new CmdTools();
FileTools fileTools = new FileTools();
@Autowired
SeedProperties properties;
@Override
public List<String> getSeedFiles() throws CmdException{
return cmdTools.runCmd(CmdConstent.GET_FILE_NAME + properties.getSeedPath(),"getSeedFiles");
}
//todo 同步修改可能会出现问题
@Override
public void delFile(String fileName) throws CmdException {
int fileCountBefore = 0;
int fileCountAfter = 0;
try {
fileCountBefore = getSeedFileCount("delFile before.");
cmdTools.runCmd(CmdConstent.DELETE_FILE + properties.getSeedPath() + "/" + fileName,"delFile");
fileCountAfter = getSeedFileCount("delFile after.");
} catch (CmdException e) {
throw new CmdException(e.getMessage());
}
if(fileCountAfter==fileCountBefore){
throw new CmdException("Delete unsuccess ! The file has not changed .Attempt to change permissions.");
}
}
@Override
public void upload(MultipartFile file) throws FileException,CmdException {
int fileCountBefore = 0;
int fileCountAfter = 0;
try {
fileCountBefore = getSeedFileCount("upload before.");
fileTools.load(file);
fileCountAfter = getSeedFileCount("upload after.");
} catch (CmdException e) {
throw new CmdException(e.getMessage());
} catch (FileException e){
throw new FileException(e.getMessage());
}
if(fileCountAfter==fileCountBefore){
throw new FileException("upload file error !The file failed to be submitted.Attempt to change permissions.");
}
}
/**
*
* 获取种子文件目录下文件数量
*/
@Override
public int getSeedFileCount(String msg) throws CmdException {
int count = 0;
try {
List<String> files = cmdTools.runCmd(CmdConstent.GET_FILE_NAME+ properties.getSeedPath(),"getSeedFileCount");
count = files.size();
} catch (CmdException e) {
throw new CmdException(e.getMessage()+" when "+msg);
}
return count;
}
}
package com.example.fuzzControll.service.impl;
import com.example.fuzzControll.conf.SpringContextUtil;
import com.example.fuzzControll.conf.KittyProperties;
import com.example.fuzzControll.constents.CmdConstent;
import com.example.fuzzControll.exception.AflnetException;
import com.example.fuzzControll.exception.CmdException;
import com.example.fuzzControll.pojo.vo.CmdStartParams;
import com.example.fuzzControll.service.TestService;
import com.example.fuzzControll.tools.CmdTools;
import com.example.fuzzControll.tools.TestControlTools;
import org.springframework.stereotype.Service;
@Service("testService")
public class TestServiceImpl implements TestService {
KittyProperties kittyProperties = (KittyProperties) SpringContextUtil.getBean("kittyProperties");
CmdTools cmdTools = new CmdTools();
//todo 不同服务不同端口
@Override
public void testStart(CmdStartParams cmdStartParams) throws AflnetException {
TestControlTools.setIsRunning(true);
String cmd = cmdTools.parse(cmdStartParams);
String finalCmd = CmdConstent.RUN_AFLNET + cmd + kittyProperties.getAflnetPath()+"live555/testProgs/testOnDemandRTSPServer 8554";
cmdTools.runProgramCmd(finalCmd);
}
@Override
public void testStop() {
TestControlTools.setIsRunning(false);
}
}
package com.example.fuzzControll.service.impl; package com.example.fuzzControll.service.impl;
import com.example.fuzzControll.conf.kittyProperties; import com.example.fuzzControll.conf.KittyProperties;
import com.example.fuzzControll.pojo.vo.testEntity; import com.example.fuzzControll.exception.FuzzException;
import com.example.fuzzControll.service.vulnerabilityTypeService; import com.example.fuzzControll.pojo.vo.TestEntity;
import com.example.fuzzControll.tools.cmdTools; import com.example.fuzzControll.service.VulnerabilityTypeService;
import com.example.fuzzControll.tools.CmdTools;
import lombok.extern.slf4j.Slf4j; import lombok.extern.slf4j.Slf4j;
import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service; import org.springframework.stereotype.Service;
...@@ -13,18 +14,18 @@ import java.util.Map; ...@@ -13,18 +14,18 @@ import java.util.Map;
@Slf4j @Slf4j
@Service("vulnerabilityTypeService") @Service("vulnerabilityTypeService")
public class vulnerabilityTypeServiceImpl implements vulnerabilityTypeService { public class VulnerabilityTypeServiceImpl implements VulnerabilityTypeService {
cmdTools cmdTools = new cmdTools(); CmdTools cmdTools = new CmdTools();
@Autowired @Autowired
kittyProperties kitty; KittyProperties kitty;
@Override @Override
public Map<String, List<String>> generation(testEntity testEntity) { public Map<String, List<String>> generation(TestEntity testEntity) throws FuzzException {
String cmd = parseParameters(testEntity); String cmd = parseParameters(testEntity);
return cmdTools.runProgramCmdAndResult(cmd); return cmdTools.runProgramCmdAndResult(cmd);
} }
public String parseParameters(testEntity testEntity) { public String parseParameters(TestEntity testEntity) {
switch (testEntity.getTestClassName().toLowerCase()) { switch (testEntity.getTestClassName().toLowerCase()) {
case "array_index_out_of_bounds_vulnerabilit"://have error case "array_index_out_of_bounds_vulnerabilit"://have error
return cmd(testEntity, 0); return cmd(testEntity, 0);
...@@ -56,7 +57,7 @@ public class vulnerabilityTypeServiceImpl implements vulnerabilityTypeService { ...@@ -56,7 +57,7 @@ public class vulnerabilityTypeServiceImpl implements vulnerabilityTypeService {
} }
} }
private String cmd(testEntity testEntity, int kindNum) { private String cmd(TestEntity testEntity, int kindNum) {
return kitty.getVenvPath() + " " + kitty.getVulnerabilityTypePath() + "vul_types_test.py " + kindNum; return kitty.getVenvPath() + " " + kitty.getVulnerabilityTypePath() + "vul_types_test.py " + kindNum;
} }
//todo 还有很多类型要写 //todo 还有很多类型要写
......
package com.example.fuzzControll.service.impl;
import com.example.fuzzControll.conf.seedProperties;
import com.example.fuzzControll.constents.cmdConstent;
import com.example.fuzzControll.service.seedFileService;
import com.example.fuzzControll.tools.cmdTools;
import com.example.fuzzControll.tools.fileTools;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service;
import org.springframework.web.multipart.MultipartFile;
import java.util.List;
@Service
public class seedFileServiceImpl implements seedFileService {
cmdTools cmdTools = new cmdTools();
fileTools fileTools = new fileTools();
@Autowired
seedProperties properties;
@Override
public List<String> getSeedFiles() {
return cmdTools.runCmd(cmdConstent.GET_FILE_NAME+properties.getSeedPath());
}
//todo 没有执行结果提示,
@Override
public void delFile(String fileName) {
cmdTools.runCmd(cmdConstent.DELETE_FILE+properties.getSeedPath()+"/"+fileName);
}
@Override
public void upload(MultipartFile file) {
fileTools.load(file);
}
}
package com.example.fuzzControll.service.impl;
import com.example.fuzzControll.constents.cmdConstent;
import com.example.fuzzControll.pojo.vo.cmdStartParams;
import com.example.fuzzControll.service.testService;
import com.example.fuzzControll.tools.cmdTools;
import com.example.fuzzControll.tools.testControlTools;
import org.springframework.stereotype.Service;
@Service("testService")
public class testServiceImpl implements testService {
cmdTools cmdTools = new cmdTools();
//todo 不同服务不同端口
@Override
public void testStart(cmdStartParams cmdStartParams) {
testControlTools.setIsRunning(true);
String cmd = cmdTools.parse(cmdStartParams);
String finalCmd = cmdConstent.RUN_AFLNET+cmd+"/home/qbq/live555/testProgs/testOnDemandRTSPServer 8554";
System.out.println(finalCmd);
cmdTools.runProgramCmd(finalCmd);
}
@Override
public void testStop() {
testControlTools.setIsRunning(false);
}
}
...@@ -3,8 +3,12 @@ package com.example.fuzzControll.tools; ...@@ -3,8 +3,12 @@ package com.example.fuzzControll.tools;
import com.alibaba.fastjson.JSONObject; import com.alibaba.fastjson.JSONObject;
import com.example.fuzzControll.conf.SpringContextUtil; import com.example.fuzzControll.conf.SpringContextUtil;
import com.example.fuzzControll.controller.WebSocket; import com.example.fuzzControll.controller.WebSocket;
import com.example.fuzzControll.pojo.vo.cmdStartParams; import com.example.fuzzControll.exception.AflnetException;
import com.example.fuzzControll.pojo.vo.testReturnEntity; import com.example.fuzzControll.exception.CmdException;
import com.example.fuzzControll.exception.FuzzException;
import com.example.fuzzControll.pojo.vo.CmdStartParams;
import com.example.fuzzControll.pojo.vo.TestReturnEntity;
import lombok.extern.slf4j.Slf4j;
import java.io.*; import java.io.*;
...@@ -12,22 +16,23 @@ import java.util.*; ...@@ -12,22 +16,23 @@ import java.util.*;
//todo need modify //todo need modify
public class cmdTools { @Slf4j
public class CmdTools {
Boolean send = false; Boolean send = false;
WebSocket socket = (WebSocket) SpringContextUtil.getBean("WebSocket"); WebSocket socket = (WebSocket) SpringContextUtil.getBean("WebSocket");
/** /**
* 运行不需要后台运行cmd * 运行不需要后台运行cmd
*/ */
public List<String> runCmd(String cmd) { public List<String> runCmd(String cmd,String caller) throws CmdException {
List<String> result = new ArrayList<>(); List<String> result = new ArrayList<String>();
try { try {
Process process = Runtime.getRuntime().exec(cmd); Process process = Runtime.getRuntime().exec(cmd);
printMessage(process.getInputStream(), result); printMessage(process.getInputStream(), result);
printMessage(process.getErrorStream(), new ArrayList<>()); printMessage(process.getErrorStream(), new ArrayList<String>());
process.waitFor(); process.waitFor();
} catch (Exception e) { } catch (Exception e) {
e.printStackTrace(); throw new CmdException(caller+" run cmd failed!");
} }
return result; return result;
...@@ -43,7 +48,7 @@ public class cmdTools { ...@@ -43,7 +48,7 @@ public class cmdTools {
try { try {
Process process = Runtime.getRuntime().exec(cmd); Process process = Runtime.getRuntime().exec(cmd);
printMessageToWeb(process.getInputStream(), process); printMessageToWeb(process.getInputStream(), process);
printMessage(process.getErrorStream(), new ArrayList<>()); printMessage(process.getErrorStream(), new ArrayList<String>());
process.waitFor(); process.waitFor();
} catch (Exception e) { } catch (Exception e) {
e.printStackTrace(); e.printStackTrace();
...@@ -54,24 +59,25 @@ public class cmdTools { ...@@ -54,24 +59,25 @@ public class cmdTools {
* 运行需要后台运行cmd * 运行需要后台运行cmd
* 将数据存入文件中 * 将数据存入文件中
*/ */
public Map<String, List<String>> runProgramCmdAndResult(String cmd) { public Map<String, List<String>> runProgramCmdAndResult(String cmd) throws FuzzException {
Map<String, List<String>> result = new HashMap(); Map<String, List<String>> result = new HashMap();
List<String> out = Collections.synchronizedList(new ArrayList<>()); List<String> out = Collections.synchronizedList(new ArrayList<String>());
List<String> error = Collections.synchronizedList(new ArrayList<>()); List<String> error = Collections.synchronizedList(new ArrayList<String>());
try { try {
Process process = Runtime.getRuntime().exec(cmd); Process process = Runtime.getRuntime().exec(cmd);
printMessageByProgramCmd(process.getInputStream(), out); printMessageByProgramCmd(process.getInputStream(), out);
printMessageByProgramCmd(process.getErrorStream(), error); printMessageByProgramCmd(process.getErrorStream(), error);
process.waitFor(); process.waitFor();
} catch (Exception e) { } catch (Exception e) {
e.printStackTrace(); log.error("aflnet run error!");
throw new FuzzException("run fuzz error !");
} }
result.put("out", out); result.put("out", out);
result.put("error", error); result.put("error", error);
return result; return result;
} }
private List<String> printMessageByProgramCmd(InputStream input, List<String> result) throws InterruptedException { private List<String> printMessageByProgramCmd(final InputStream input, final List<String> result) throws InterruptedException {
new Thread(new Runnable() { new Thread(new Runnable() {
@Override @Override
public void run() { public void run() {
...@@ -91,7 +97,7 @@ public class cmdTools { ...@@ -91,7 +97,7 @@ public class cmdTools {
return result; return result;
} }
private List<String> printMessage(final InputStream input, List<String> result) { private List<String> printMessage(final InputStream input, final List<String> result) {
new Thread(new Runnable() { new Thread(new Runnable() {
@Override @Override
public void run() { public void run() {
...@@ -115,19 +121,17 @@ public class cmdTools { ...@@ -115,19 +121,17 @@ public class cmdTools {
Reader reader = new InputStreamReader(input); Reader reader = new InputStreamReader(input);
BufferedReader bf = new BufferedReader(reader); BufferedReader bf = new BufferedReader(reader);
String line = null; String line = null;
testReturnEntity returnEntity = new testReturnEntity(); TestReturnEntity returnEntity = new TestReturnEntity();
while ((line = bf.readLine()) != null && testControlTools.getIsRunning()) { while ((line = bf.readLine()) != null && TestControlTools.getIsRunning()) {
makeReturnEntity(line, returnEntity); makeReturnEntity(line, returnEntity);
if (send) { if (send) {
String data = JSONObject.toJSONString(returnEntity); String data = JSONObject.toJSONString(returnEntity);
socket.appointSending("backend100", "web100", data); socket.appointSending("backend", "web", data);
System.out.println(returnEntity + "*");
} }
} }
} }
private testReturnEntity makeReturnEntity(String line, testReturnEntity returnEntity) { private TestReturnEntity makeReturnEntity(String line, TestReturnEntity returnEntity) {
System.out.println(line);
if (line.contains("run time")) { if (line.contains("run time")) {
send = false; send = false;
int run_time = line.indexOf(":"); int run_time = line.indexOf(":");
...@@ -217,7 +221,10 @@ public class cmdTools { ...@@ -217,7 +221,10 @@ public class cmdTools {
return returnEntity; return returnEntity;
} }
public String parse(cmdStartParams cmdStartParams) { public String parse(CmdStartParams cmdStartParams) throws AflnetException{
if(cmdStartParams==null){
throw new AflnetException("CmdStartParams is null!");
}
StringBuilder cmd = new StringBuilder(); StringBuilder cmd = new StringBuilder();
if (cmdStartParams.getNetinfo() != "") { if (cmdStartParams.getNetinfo() != "") {
cmd.append(" -N " + cmdStartParams.getNetinfo()); cmd.append(" -N " + cmdStartParams.getNetinfo());
......
package com.example.fuzzControll.tools; package com.example.fuzzControll.tools;
import com.example.fuzzControll.conf.SpringContextUtil; import com.example.fuzzControll.conf.SpringContextUtil;
import com.example.fuzzControll.conf.seedProperties; import com.example.fuzzControll.conf.SeedProperties;
import com.example.fuzzControll.exception.FileException;
import lombok.extern.slf4j.Slf4j;
import org.springframework.web.multipart.MultipartFile; import org.springframework.web.multipart.MultipartFile;
import java.io.BufferedInputStream; import java.io.BufferedInputStream;
...@@ -9,15 +11,18 @@ import java.io.BufferedOutputStream; ...@@ -9,15 +11,18 @@ import java.io.BufferedOutputStream;
import java.io.FileOutputStream; import java.io.FileOutputStream;
import java.io.InputStream; import java.io.InputStream;
public class fileTools { @Slf4j
seedProperties properties = (seedProperties) SpringContextUtil.getBean("seedProperties"); public class FileTools {
SeedProperties properties = (SeedProperties) SpringContextUtil.getBean("seedProperties");
public void load(MultipartFile file) { public void load(MultipartFile file) throws FileException {
if (file == null) {
throw new FileException("upload file is null !");
}
try (InputStream inputStream = file.getInputStream(); try (InputStream inputStream = file.getInputStream();
FileOutputStream outputStream = new FileOutputStream(properties.getSeedPath() + "/" + file.getOriginalFilename());) { FileOutputStream outputStream = new FileOutputStream(properties.getSeedPath() + "/" + file.getOriginalFilename());) {
BufferedInputStream bufferedInputStream = new BufferedInputStream(inputStream); BufferedInputStream bufferedInputStream = new BufferedInputStream(inputStream);
BufferedOutputStream bufferedOutputStream = new BufferedOutputStream(outputStream); BufferedOutputStream bufferedOutputStream = new BufferedOutputStream(outputStream);
byte[] buffer = new byte[1024]; byte[] buffer = new byte[1024];
int bytesRead; int bytesRead;
while ((bytesRead = bufferedInputStream.read(buffer)) != -1) { while ((bytesRead = bufferedInputStream.read(buffer)) != -1) {
...@@ -25,6 +30,7 @@ public class fileTools { ...@@ -25,6 +30,7 @@ public class fileTools {
} }
} catch (Exception e) { } catch (Exception e) {
e.printStackTrace(); e.printStackTrace();
throw new FileException("write file error !");
} }
} }
......
package com.example.fuzzControll.tools; package com.example.fuzzControll.tools;
//todo 对ip等增加正则判断 //todo 对ip等增加正则判断
public class regularTools { public class RegularTools {
} }
package com.example.fuzzControll.tools; package com.example.fuzzControll.tools;
public class testControlTools { public class TestControlTools {
private static Boolean isRunning; private static Boolean isRunning;
public static Boolean getIsRunning() { public static Boolean getIsRunning() {
...@@ -8,6 +8,6 @@ public class testControlTools { ...@@ -8,6 +8,6 @@ public class testControlTools {
} }
public static void setIsRunning(Boolean isRunning) { public static void setIsRunning(Boolean isRunning) {
testControlTools.isRunning = isRunning; TestControlTools.isRunning = isRunning;
} }
} }
...@@ -3,7 +3,7 @@ package com.example.fuzzControll.tools; ...@@ -3,7 +3,7 @@ package com.example.fuzzControll.tools;
import lombok.extern.slf4j.Slf4j; import lombok.extern.slf4j.Slf4j;
@Slf4j @Slf4j
public class testTools { public class TestTools {
public static boolean paramsLenghtTest(int paramsLen,int needParamsLen,String name){ public static boolean paramsLenghtTest(int paramsLen,int needParamsLen,String name){
Boolean isOk = paramsLen==needParamsLen; Boolean isOk = paramsLen==needParamsLen;
if(!isOk){ if(!isOk){
......
...@@ -14,14 +14,15 @@ logging: ...@@ -14,14 +14,15 @@ logging:
max-file-size: 10MB max-file-size: 10MB
filepath: filepath:
seedPath: "/home/qbq/aflnet/tutorials/live555/in-rtsp" seedPath: "/home/aflnet/tutorials/live555/in-rtsp"
kitty: kitty:
path: "/home/qbq/fuzz50/kitty/renix/" #kitty项目下的各协议生成模板python文件路径 aflnetPath: "/home/"
venvPath: "/home/qbq/fuzz50/kitty/venv/bin/python" path: "/home/fuzz50/kitty/renix/" #kitty项目下的各协议生成模板python文件路径
methodPath: "/home/qbq/fuzz50/kitty/2020test/"#kitty下变异方法路径 venvPath: "/home/fuzz50/kitty/venv/bin/python"
vulnerabilityTypePath: "/home/qbq/fuzz50/kitty/2020test/"#kitty下漏洞类型python路径 methodPath: "/home/fuzz50/kitty/2020test/"#kitty下变异方法路径
mutationPath: "/home/qbq/fuzz50/kitty/2020test/" vulnerabilityTypePath: "/home/fuzz50/kitty/2020test/"#kitty下漏洞类型python路径
mutationPath: "/home/fuzz50/kitty/2020test/"
templateInfoHttp: "http://127.0.0.1:26001/api/template_info.json"#模板信息请求链接 templateInfoHttp: "http://127.0.0.1:26001/api/template_info.json"#模板信息请求链接
statsHttp: "http://127.0.0.1:26001/api/stats.json"#运行时数据 statsHttp: "http://127.0.0.1:26001/api/stats.json"#运行时数据
stagesHttp: "http://127.0.0.1:26001/api/stages.json"# stagesHttp: "http://127.0.0.1:26001/api/stages.json"#
......
__ ___ _ __ _
/ _|_ _ ________ / __\ __ _ ___| | __ /__\ __ __| |
,--, ___ ,-. | |_| | | |_ /_ //__\/// _` |/ __| |/ //_\| '_ \ / _` |
.--., ,--.'| ,--.'|_ ,---, ,--/ /| ,---, | _| |_| |/ / / // \/ \ (_| | (__| <//__| | | | (_| |
,--.' \ | | : ,---, | | :,' ,---,.,---.'| ,--. :/ | ,---, ,---.'| |_| \__,_/___/___\_____/\__,_|\___|_|\_\__/|_| |_|\__,_|
| | /\/ : : ' ,-+-. / | : : ' : ,' .' || | : : : ' / ,-+-. / | | | :
,--.--. : : : ,---. | ' | ,--.'|' | ,---. .;__,' / ,---.' ,: : : ,--.--. ,---. | ' / ,---. ,--.'|' | | | | \ No newline at end of file
/ \ : | |-, / \ ' | | | | ,"' | / \ | | | | | |: |,-. / \ / \ ' | : / \| | ,"' | ,--.__| |
.--. .-. || : :/| / / || | : | | / | | / / |:__,'| : : : .' | : ' | .--. .-. | / / ' | | \ / / | | / | | / ,' |
\__\/: . .| | .'. ' / |' : |__ | | | | |. ' / | ' : |__ : |.' | | / : \__\/: . .. ' / ' : |. \ . ' / | | | | |. ' / |
," .--.; |' : ' ' ; /|| | '.'|| | | |/ ' ; /| | | '.'|`---' ' : |: | ," .--.; |' ; :__ | | ' \ \' ; /| | | |/ ' ; |: |
/ / ,. || | | ' | / |; : ;| | |--' ' | / | ; : ; | | '/ : / / ,. |' | '.'|' : |--' ' | / | | |--' | | '/ '
; : .' \ : \ | : || , / | |/ | : | | , / | : |; : .' \ : :; |,' | : | |/ | : :|
| , .-./ |,' \ \ / ---`-' '---' \ \ / ---`-' / \ / | , .-./\ \ / '--' \ \ /'---' \ \ /
`--`---' `--' `----' `----' `-'----' `--`---' `----' `----' `----'
...@@ -8,7 +8,7 @@ ...@@ -8,7 +8,7 @@
var ws1 = null; var ws1 = null;
var ws2 = null; var ws2 = null;
function myFunction() { function myFunction() {
ws1 = new WebSocket("ws://192.168.37.149:8100/websocket/testResult/" + "web"); ws1 = new WebSocket("ws://localhost:8100/websocket/testResult/" + "web");
ws1.onmessage = function (evt) { ws1.onmessage = function (evt) {
console.log(evt); console.log(evt);
var received_msg =JSON.parse(evt.data) ; var received_msg =JSON.parse(evt.data) ;
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment