检测格式化字符串攻击脚本

'''
#------------------------   used for inspect_formatstring_flaw      -------------------------
def inspect_format_attack():
    print "detecting format attack..........................."
    for index in range(0, len(content)):
        needoutput = False
        if content[index].count("%") > 4:
            #find quotes contains char '%'
            line = content[index]
            pos1 = line.index('%')
            begin = pos1
            end = pos1
            while begin >= 0 and line[begin] != '"':
                begin = begin - 1
            while end < len(line) and line[end] != '"':
                end = end + 1
            if begin != -1 and end > begin:
                formatstring = line[begin + 1 : end]
                formatnum = formatstring.count("%")
                formatnum = formatnum - formatstring.count("%%")
                formatnum = formatnum + formatstring.count("%ld")
                #tranverse the params and validate them, first find the next ','
                begin = line[end :].find(',')
                if begin == -1:
                    needoutput = True
                else:
                    line = line[begin + end :]
                    nindex = index + 1
                    #if seperated in several lines
                    while line.count(";") == 0:
                        line = line + content[nindex]
                        nindex = nindex + 1
                    pos1 = line.find(';')
                    line = line[: pos1]
                    if line.count(',') < formatnum:
                        needoutput = True
                        #IDA failed to recognize more arguments means there may be a format-string attack
        if needoutput:
            print "\t%d %s"%(index, content[index])
'''
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值