package services import ( "context" "fmt" "io" "net/http" "strings" "time" "github.com/shadow1ng/fscan/common" "github.com/shadow1ng/fscan/plugins" ) type RabbitMQPlugin struct { plugins.BasePlugin } func NewRabbitMQPlugin() *RabbitMQPlugin { return &RabbitMQPlugin{ BasePlugin: plugins.NewBasePlugin("rabbitmq"), } } func (p *RabbitMQPlugin) Scan(ctx context.Context, info *common.HostInfo) *ScanResult { target := fmt.Sprintf("%s:%s", info.Host, info.Ports) if common.DisableBrute { return p.identifyService(ctx, info) } if info.Ports == "5672" || info.Ports == "5671" { return p.testAMQPProtocol(ctx, info) } credentials := GenerateCredentials("rabbitmq") if len(credentials) == 0 { return &ScanResult{ Success: false, Service: "rabbitmq", Error: fmt.Errorf("没有可用的测试凭据"), } } for _, cred := range credentials { if p.testCredential(ctx, info, cred) { common.LogSuccess(fmt.Sprintf("RabbitMQ %s %s:%s", target, cred.Username, cred.Password)) return &ScanResult{ Success: true, Service: "rabbitmq", Username: cred.Username, Password: cred.Password, } } } return &ScanResult{ Success: false, Service: "rabbitmq", Error: fmt.Errorf("未发现弱密码"), } } func (p *RabbitMQPlugin) testAMQPProtocol(ctx context.Context, info *common.HostInfo) *ScanResult { return &ScanResult{ Success: true, Service: "rabbitmq", Banner: "RabbitMQ AMQP", } } func (p *RabbitMQPlugin) testCredential(ctx context.Context, info *common.HostInfo, cred Credential) bool { baseURL := fmt.Sprintf("http://%s:%s", info.Host, info.Ports) client := &http.Client{ Timeout: time.Duration(common.Timeout) * time.Second, } req, err := http.NewRequestWithContext(ctx, "GET", baseURL+"/api/overview", nil) if err != nil { return false } req.SetBasicAuth(cred.Username, cred.Password) req.Header.Set("Content-Type", "application/json") resp, err := client.Do(req) if err != nil { return false } defer resp.Body.Close() return resp.StatusCode == 200 } func (p *RabbitMQPlugin) identifyService(ctx context.Context, info *common.HostInfo) *ScanResult { target := fmt.Sprintf("%s:%s", info.Host, info.Ports) if info.Ports == "5672" || info.Ports == "5671" { return &ScanResult{ Success: true, Service: "rabbitmq", Banner: "RabbitMQ AMQP", } } baseURL := fmt.Sprintf("http://%s:%s", info.Host, info.Ports) client := &http.Client{ Timeout: time.Duration(common.Timeout) * time.Second, } req, err := http.NewRequestWithContext(ctx, "GET", baseURL, nil) if err != nil { return &ScanResult{ Success: false, Service: "rabbitmq", Error: err, } } resp, err := client.Do(req) if err != nil { return &ScanResult{ Success: false, Service: "rabbitmq", Error: err, } } defer resp.Body.Close() var banner string if resp.StatusCode == 200 || resp.StatusCode == 401 { body, _ := io.ReadAll(resp.Body) bodyStr := strings.ToLower(string(body)) if strings.Contains(bodyStr, "rabbitmq") { banner = "RabbitMQ" } else if strings.Contains(bodyStr, "management") { banner = "RabbitMQ" } else { banner = "RabbitMQ" } } else { return &ScanResult{ Success: false, Service: "rabbitmq", Error: fmt.Errorf("无法识别为RabbitMQ服务"), } } common.LogSuccess(fmt.Sprintf("RabbitMQ %s %s", target, banner)) return &ScanResult{ Success: true, Service: "rabbitmq", Banner: banner, } } // init 自动注册插件 func init() { // 使用高效注册方式:直接传递端口信息,避免实例创建 RegisterPluginWithPorts("rabbitmq", func() Plugin { return NewRabbitMQPlugin() }, []int{5672, 15672, 5671}) }