/
postgres.go
110 lines (102 loc) · 3.03 KB
/
postgres.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
package bruteutils
import (
"fmt"
"github.com/go-pg/pg/v10"
"github.com/yaklang/yaklang/common/log"
"github.com/yaklang/yaklang/common/netx"
"github.com/yaklang/yaklang/common/utils"
"strings"
"time"
)
func postgresqlUnAuthCheck(Host string, Port int) (bool, error) {
sendData := []byte{58, 0, 0, 0, 167, 65, 0, 0, 0, 0, 0, 0, 212, 7, 0, 0, 0, 0, 0, 0, 97, 100, 109, 105, 110, 46, 36, 99, 109, 100, 0, 0, 0, 0, 0, 255, 255, 255, 255, 19, 0, 0, 0, 16, 105, 115, 109, 97, 115, 116, 101, 114, 0, 1, 0, 0, 0, 0}
getlogData := []byte{72, 0, 0, 0, 2, 0, 0, 0, 0, 0, 0, 0, 212, 7, 0, 0, 0, 0, 0, 0, 97, 100, 109, 105, 110, 46, 36, 99, 109, 100, 0, 0, 0, 0, 0, 1, 0, 0, 0, 33, 0, 0, 0, 2, 103, 101, 116, 76, 111, 103, 0, 16, 0, 0, 0, 115, 116, 97, 114, 116, 117, 112, 87, 97, 114, 110, 105, 110, 103, 115, 0, 0}
conn, err := netx.DialTimeout(5*time.Second, "tcp", fmt.Sprintf("%s:%v", Host, Port))
if err != nil {
return false, err
}
defer conn.Close()
err = conn.SetReadDeadline(time.Now().Add(5 * time.Second))
if err != nil {
return false, err
}
_, err = conn.Write(sendData)
if err != nil {
return false, err
}
buf := make([]byte, 1024)
count, err := conn.Read(buf)
if err != nil {
return false, err
}
text := string(buf[0:count])
if strings.Contains(text, "ismaster") == false {
return false, err
}
_, err = conn.Write(getlogData)
if err != nil {
return false, err
}
count, err = conn.Read(buf)
if err != nil {
return false, err
}
text = string(buf[0:count])
if strings.Contains(text, "totalLinesWritten") == false {
return false, err
}
return true, err
}
var postgresAuth = &DefaultServiceAuthInfo{
ServiceName: "postgres",
DefaultPorts: "5432",
DefaultUsernames: append([]string{"postgres"}, CommonUsernames...),
DefaultPasswords: CommonPasswords,
UnAuthVerify: func(i *BruteItem) *BruteItemResult {
i.Target = appendDefaultPort(i.Target, 5432)
result := i.Result()
conn, err := netx.DialTCPTimeout(defaultTimeout, i.Target)
if err != nil {
result.Finished = true
return result
}
conn.Close()
host, port, _ := utils.ParseStringToHostPort(i.Target)
r, _ := postgresqlUnAuthCheck(host, port)
if r {
result.Ok = true
return result
}
return result
},
BrutePass: func(item *BruteItem) *BruteItemResult {
// 173.254.29.192/24
item.Target = appendDefaultPort(item.Target, 5432)
result := item.Result()
db := pg.Connect(&pg.Options{
Addr: item.Target,
User: item.Username,
Password: item.Password,
Database: "postgres",
})
_, err := db.Exec("select 1")
if err != nil {
result.Ok = false
switch true {
case strings.Contains(err.Error(), "connect: connection refused"):
fallthrough
case strings.Contains(err.Error(), "no pg_hba.conf entry for host"):
fallthrough
case strings.Contains(err.Error(), "network unreachable"):
fallthrough
case strings.Contains(err.Error(), "i/o timeout"):
result.Finished = true
return result
}
log.Errorf("exec select 1 failed: %v", err)
return result
}
result.Ok = true
return result
},
}