mirror of
https://github.com/vanhauser-thc/thc-hydra.git
synced 2025-07-05 12:36:09 -07:00
Fix unauthenticated memcached server detection
This commit is contained in:
parent
1ad374b6a1
commit
6575bf964d
1 changed files with 44 additions and 55 deletions
|
@ -16,7 +16,6 @@ void dummy_mcached() {
|
|||
extern int32_t hydra_data_ready_timed(int32_t socket, long sec, long usec);
|
||||
|
||||
extern char *HYDRA_EXIT;
|
||||
char *buf;
|
||||
|
||||
int mcached_send_com_quit(int32_t sock) {
|
||||
char *com_quit = "quit\r\n";
|
||||
|
@ -56,7 +55,7 @@ int32_t start_mcached(int32_t s, char *ip, int32_t port, unsigned char options,
|
|||
if (verbose)
|
||||
hydra_report(stderr, "[ERROR] Couldn't setup SASL auth: %s\n", memcached_strerror(cache, rc));
|
||||
memcached_free(cache);
|
||||
return 4;
|
||||
return 3;
|
||||
}
|
||||
|
||||
rc = memcached_behavior_set(cache, MEMCACHED_BEHAVIOR_BINARY_PROTOCOL, 1);
|
||||
|
@ -65,7 +64,7 @@ int32_t start_mcached(int32_t s, char *ip, int32_t port, unsigned char options,
|
|||
hydra_report(stderr, "[ERROR] Couldn't use the binary protocol: %s\n", memcached_strerror(cache, rc));
|
||||
memcached_destroy_sasl_auth_data(cache);
|
||||
memcached_free(cache);
|
||||
return 4;
|
||||
return 3;
|
||||
}
|
||||
rc = memcached_behavior_set(cache, MEMCACHED_BEHAVIOR_CONNECT_TIMEOUT, 10000);
|
||||
if (rc != MEMCACHED_SUCCESS) {
|
||||
|
@ -73,7 +72,7 @@ int32_t start_mcached(int32_t s, char *ip, int32_t port, unsigned char options,
|
|||
hydra_report(stderr, "[ERROR] Couldn't set the connect timeout: %s\n", memcached_strerror(cache, rc));
|
||||
memcached_destroy_sasl_auth_data(cache);
|
||||
memcached_free(cache);
|
||||
return 4;
|
||||
return 3;
|
||||
}
|
||||
|
||||
servers = memcached_server_list_append(servers, hydra_address2string(ip), port, &rc);
|
||||
|
@ -83,7 +82,7 @@ int32_t start_mcached(int32_t s, char *ip, int32_t port, unsigned char options,
|
|||
hydra_report(stderr, "[ERROR] Couldn't add server: %s\n", memcached_strerror(cache, rc));
|
||||
memcached_destroy_sasl_auth_data(cache);
|
||||
memcached_free(cache);
|
||||
return 4;
|
||||
return 3;
|
||||
}
|
||||
|
||||
rc = memcached_stat_execute(cache, "", NULL, NULL);
|
||||
|
@ -94,9 +93,9 @@ int32_t start_mcached(int32_t s, char *ip, int32_t port, unsigned char options,
|
|||
memcached_free(cache);
|
||||
hydra_completed_pair_skip();
|
||||
if (memcmp(hydra_get_next_pair(), &HYDRA_EXIT, sizeof(HYDRA_EXIT)) == 0) {
|
||||
return 4;
|
||||
return 3;
|
||||
}
|
||||
return 3;
|
||||
return 2;
|
||||
}
|
||||
|
||||
memcached_destroy_sasl_auth_data(cache);
|
||||
|
@ -105,14 +104,13 @@ int32_t start_mcached(int32_t s, char *ip, int32_t port, unsigned char options,
|
|||
hydra_report_found_host(port, ip, "memcached", fp);
|
||||
hydra_completed_pair_found();
|
||||
if (memcmp(hydra_get_next_pair(), &HYDRA_EXIT, sizeof(HYDRA_EXIT)) == 0)
|
||||
return 4;
|
||||
return 3;
|
||||
|
||||
return 3;
|
||||
return 2;
|
||||
}
|
||||
|
||||
void service_mcached(char *ip, int32_t sp, unsigned char options, char *miscptr, FILE * fp, int32_t port, char *hostname) {
|
||||
int32_t run = 1, next_run = 1, sock = -1;
|
||||
int32_t myport = PORT_MCACHED;
|
||||
|
||||
hydra_register_socket(sp);
|
||||
|
||||
|
@ -121,47 +119,10 @@ void service_mcached(char *ip, int32_t sp, unsigned char options, char *miscptr,
|
|||
return;
|
||||
|
||||
switch (run) {
|
||||
case 1: /* connect and service init function */
|
||||
if (sock >= 0)
|
||||
sock = hydra_disconnect(sock);
|
||||
|
||||
if (port != 0)
|
||||
myport = port;
|
||||
|
||||
sock = hydra_connect_tcp(ip, myport);
|
||||
port = myport;
|
||||
|
||||
if (sock < 0) {
|
||||
if (verbose || debug)
|
||||
hydra_report(stderr, "[ERROR] Child with pid %d terminating, can not connect\n", (int32_t) getpid());
|
||||
hydra_child_exit(1);
|
||||
}
|
||||
|
||||
if (mcached_send_com_version(sock)) {
|
||||
return;
|
||||
}
|
||||
if (hydra_data_ready_timed(sock, 0, 1000) > 0) {
|
||||
buf = hydra_receive_line(sock);
|
||||
if (strstr(buf, "VERSION ")) {
|
||||
hydra_report_found_host(port, ip, "memcached", fp);
|
||||
free(buf);
|
||||
mcached_send_com_quit(sock);
|
||||
if (sock >= 0)
|
||||
sock = hydra_disconnect(sock);
|
||||
hydra_report(stderr, "[ERROR] Memcached server does not require any authentication\n");
|
||||
next_run = 3;
|
||||
break;
|
||||
}
|
||||
free(buf);
|
||||
}
|
||||
sock = hydra_disconnect(sock);
|
||||
//authentication is required, let's use libmemcached
|
||||
next_run = 2;
|
||||
break;
|
||||
case 2:
|
||||
case 1:
|
||||
next_run = start_mcached(sock, ip, port, options, miscptr, fp);
|
||||
break;
|
||||
case 3:
|
||||
case 2:
|
||||
hydra_child_exit(0);
|
||||
return;
|
||||
default:
|
||||
|
@ -179,12 +140,40 @@ int32_t service_mcached_init(char *ip, int32_t sp, unsigned char options, char *
|
|||
// called before the childrens are forked off, so this is the function
|
||||
// which should be filled if initial connections and service setup has to be
|
||||
// performed once only.
|
||||
//
|
||||
// fill if needed.
|
||||
//
|
||||
// return codes:
|
||||
// 0 all OK
|
||||
// -1 error, hydra will exit, so print a good error message here
|
||||
|
||||
int32_t sock = -1;
|
||||
int32_t myport = PORT_MCACHED;
|
||||
char *buf;
|
||||
|
||||
if (port != 0)
|
||||
myport = port;
|
||||
|
||||
sock = hydra_connect_tcp(ip, myport);
|
||||
if (sock < 0) {
|
||||
if (verbose || debug)
|
||||
hydra_report(stderr, "[ERROR] Can not connect\n");
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (mcached_send_com_version(sock)) {
|
||||
if (verbose || debug)
|
||||
hydra_report(stderr, "[ERROR] Can not send request\n");
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (hydra_data_ready_timed(sock, 0, 1000) > 0) {
|
||||
buf = hydra_receive_line(sock);
|
||||
if (strstr(buf, "VERSION ")) {
|
||||
hydra_report_found_host(port, ip, "memcached", fp);
|
||||
mcached_send_com_quit(sock);
|
||||
if (sock >= 0)
|
||||
sock = hydra_disconnect(sock);
|
||||
hydra_report(stderr, "[ERROR] Memcached server does not require any authentication\n");
|
||||
}
|
||||
free(buf);
|
||||
return -1;
|
||||
}
|
||||
if (sock >= 0)
|
||||
sock = hydra_disconnect(sock);
|
||||
return 0;
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue