// 红队渗透 · 2024-12-01

掌握 gobuster 的 completion 子命令:红队打靶的“作弊器”

在渗透测试和网络安全领域,自动补全功能可以极大地提升效率和体验。尤其是在命令行环境下,手动输入复杂命令和参数可能导致频繁出错或效率低下。幸运的是,gobuster 提供了一个名为 completion 的子命令,可为不同的 shell 环境生成自动补全配置文件。在本教程中,我们将重点介绍 completion 子命令的用法,并详细讲解如何在 Zsh 环境中启用自动补全,让你的操作更快、更精准!


一、completion 子命令的作用

completion 子命令的主要功能是为 gobuster 生成适合当前 shell 环境的自动补全脚本。通过加载这些脚本,可以实现以下功能:

  • 参数补全:自动补全 gobuster 的所有子命令和选项。
  • 动态补全:根据当前上下文动态生成可用参数或路径。
  • 减少错误:避免手动输入时出现拼写或格式错误。

支持的 Shell 环境包括:

  • Bash
  • Zsh
  • Fish

二、在 Zsh 中启用 gobuster 自动补全

下面是一步步在 Zsh 环境中配置 gobuster 自动补全的流程:

1. 生成自动补全脚本

运行以下命令生成 Zsh 的自动补全脚本:

sudo gobuster completion zsh

输出的内容类似如下:

#compdef gobuster
compdef _gobuster gobuster

# zsh completion for gobuster                             -*- shell-script -*-

__gobuster_debug()
{
    local file="$BASH_COMP_DEBUG_FILE"
    if [[ -n ${file} ]]; then
        echo "$*" >> "${file}"
    fi
}

_gobuster()
{
    local shellCompDirectiveError=1
    local shellCompDirectiveNoSpace=2
    local shellCompDirectiveNoFileComp=4
    local shellCompDirectiveFilterFileExt=8
    local shellCompDirectiveFilterDirs=16
    local shellCompDirectiveKeepOrder=32

    local lastParam lastChar flagPrefix requestComp out directive comp lastComp noSpace keepOrder
    local -a completions

    __gobuster_debug "\n========= starting completion logic =========="
    __gobuster_debug "CURRENT: ${CURRENT}, words[*]: ${words[*]}"

    # The user could have moved the cursor backwards on the command-line.
    # We need to trigger completion from the $CURRENT location, so we need
    # to truncate the command-line ($words) up to the $CURRENT location.
    # (We cannot use $CURSOR as its value does not work when a command is an alias.)
    words=("${=words[1,CURRENT]}")
    __gobuster_debug "Truncated words[*]: ${words[*]},"

    lastParam=${words[-1]}
    lastChar=${lastParam[-1]}
    __gobuster_debug "lastParam: ${lastParam}, lastChar: ${lastChar}"

    # For zsh, when completing a flag with an = (e.g., gobuster -n=<TAB>)
    # completions must be prefixed with the flag
    setopt local_options BASH_REMATCH
    if [[ "${lastParam}" =~ '-.*=' ]]; then
        # We are dealing with a flag with an =
        flagPrefix="-P ${BASH_REMATCH}"
    fi

    # Prepare the command to obtain completions
    requestComp="${words[1]} __complete ${words[2,-1]}"
    if [ "${lastChar}" = "" ]; then
        # If the last parameter is complete (there is a space following it)
        # We add an extra empty parameter so we can indicate this to the go completion code.
        __gobuster_debug "Adding extra empty parameter"
        requestComp="${requestComp} \"\""
    fi

    __gobuster_debug "About to call: eval ${requestComp}"

    # Use eval to handle any environment variables and such
    out=$(eval ${requestComp} 2>/dev/null)
    __gobuster_debug "completion output: ${out}"

    # Extract the directive integer following a : from the last line
    local lastLine
    while IFS='\n' read -r line; do
        lastLine=${line}
    done < <(printf "%s\n" "${out[@]}")
    __gobuster_debug "last line: ${lastLine}"

    if [ "${lastLine[1]}" = : ]; then
        directive=${lastLine[2,-1]}
        # Remove the directive including the : and the newline
        local suffix
        (( suffix=${#lastLine}+2))
        out=${out[1,-$suffix]}
    else
        # There is no directive specified.  Leave $out as is.
        __gobuster_debug "No directive found.  Setting do default"
        directive=0
    fi

    __gobuster_debug "directive: ${directive}"
    __gobuster_debug "completions: ${out}"
    __gobuster_debug "flagPrefix: ${flagPrefix}"

    if [ $((directive & shellCompDirectiveError)) -ne 0 ]; then
        __gobuster_debug "Completion received error. Ignoring completions."
        return
    fi

    local activeHelpMarker="_activeHelp_ "
    local endIndex=${#activeHelpMarker}
    local startIndex=$((${#activeHelpMarker}+1))
    local hasActiveHelp=0
    while IFS='\n' read -r comp; do
        # Check if this is an activeHelp statement (i.e., prefixed with $activeHelpMarker)
        if [ "${comp[1,$endIndex]}" = "$activeHelpMarker" ];then
            __gobuster_debug "ActiveHelp found: $comp"
            comp="${comp[$startIndex,-1]}"
            if [ -n "$comp" ]; then
                compadd -x "${comp}"
                __gobuster_debug "ActiveHelp will need delimiter"
                hasActiveHelp=1
            fi

            continue
        fi

        if [ -n "$comp" ]; then
            # If requested, completions are returned with a description.
            # The description is preceded by a TAB character.
            # For zsh's _describe, we need to use a : instead of a TAB.
            # We first need to escape any : as part of the completion itself.
            comp=${comp//:/\\:}

            local tab="$(printf '\t')"
            comp=${comp//$tab/:}

            __gobuster_debug "Adding completion: ${comp}"
            completions+=${comp}
            lastComp=$comp
        fi
    done < <(printf "%s\n" "${out[@]}")

    # Add a delimiter after the activeHelp statements, but only if:
    # - there are completions following the activeHelp statements, or
    # - file completion will be performed (so there will be choices after the activeHelp)
    if [ $hasActiveHelp -eq 1 ]; then
        if [ ${#completions} -ne 0 ] || [ $((directive & shellCompDirectiveNoFileComp)) -eq 0 ]; then
            __gobuster_debug "Adding activeHelp delimiter"
            compadd -x "--"
            hasActiveHelp=0
        fi
    fi

    if [ $((directive & shellCompDirectiveNoSpace)) -ne 0 ]; then
        __gobuster_debug "Activating nospace."
        noSpace="-S ''"
    fi

    if [ $((directive & shellCompDirectiveKeepOrder)) -ne 0 ]; then
        __gobuster_debug "Activating keep order."
        keepOrder="-V"
    fi

    if [ $((directive & shellCompDirectiveFilterFileExt)) -ne 0 ]; then
        # File extension filtering
        local filteringCmd
        filteringCmd='_files'
        for filter in ${completions[@]}; do
            if [ ${filter[1]} != '*' ]; then
                # zsh requires a glob pattern to do file filtering
                filter="\*.$filter"
            fi
            filteringCmd+=" -g $filter"
        done
        filteringCmd+=" ${flagPrefix}"

        __gobuster_debug "File filtering command: $filteringCmd"
        _arguments '*:filename:'"$filteringCmd"
    elif [ $((directive & shellCompDirectiveFilterDirs)) -ne 0 ]; then
        # File completion for directories only
        local subdir
        subdir="${completions[1]}"
        if [ -n "$subdir" ]; then
            __gobuster_debug "Listing directories in $subdir"
            pushd "${subdir}" >/dev/null 2>&1
        else
            __gobuster_debug "Listing directories in ."
        fi

        local result
        _arguments '*:dirname:_files -/'" ${flagPrefix}"
        result=$?
        if [ -n "$subdir" ]; then
            popd >/dev/null 2>&1
        fi
        return $result
    else
        __gobuster_debug "Calling _describe"
        if eval _describe $keepOrder "completions" completions $flagPrefix $noSpace; then
            __gobuster_debug "_describe found some completions"

            # Return the success of having called _describe
            return 0
        else
            __gobuster_debug "_describe did not find completions."
            __gobuster_debug "Checking if we should do file completion."
            if [ $((directive & shellCompDirectiveNoFileComp)) -ne 0 ]; then
                __gobuster_debug "deactivating file completion"

                # We must return an error code here to let zsh know that there were no
                # completions found by _describe; this is what will trigger other
                # matching algorithms to attempt to find completions.
                # For example zsh can match letters in the middle of words.
                return 1
            else
                # Perform file completion
                __gobuster_debug "Activating file completion"

                # We must return the result of this command, so it must be the
                # last command, or else we must store its result to return it.
                _arguments '*:filename:_files'" ${flagPrefix}"
            fi
        fi
    fi
}

# don't run the completion function when being source-ed or eval-ed
if [ "$funcstack[1]" = "_gobuster" ]; then
    _gobuster
fi

}

这些脚本定义了如何补全命令和参数,例如子命令、选项(如 -u、-w)以及自定义值。


2. 将脚本添加到 Zsh 配置文件

为了让 Zsh 每次启动时都加载补全脚本,可以将生成的内容追加到 Zsh 的配置文件(~/.zshrc)中。直接执行以下命令:

sudo gobuster completion zsh >> ~/.zshrc

3. 重新加载 Zsh 配置文件

执行以下命令,使新的配置立即生效:

source ~/.zshrc

三、验证自动补全功能

配置完成后,在命令行中尝试输入以下命令并按下 Tab 键,验证补全功能是否正常:

1. 补全子命令

gobuster [Tab]

会提示可用的子命令,如下图: 在这里插入图片描述

2. 补全选项

gobuster dir [Tab]

会提示可用的选项,如下图: 在这里插入图片描述


四、总结

启用 gobuster 自动补全功能后,你将获得以下显著优势:

  1. 提升效率:无需记忆复杂的命令或选项名称,大幅缩短输入时间。
  2. 降低错误率:避免输入拼写错误或漏掉必需的参数。
  3. 动态提示:根据当前上下文提供精确的补全建议,操作更直观。

打靶时,掌握这一工具并将其融入日常工作流,能帮助你快人一步!

快速回顾:

  1. 生成自动补全脚本:
    sudo gobuster completion zsh
  2. 添加脚本到配置文件:
    sudo gobuster completion zsh >> ~/.zshrc
  3. 重新加载配置:
    source ~/.zshrc

附录

Gobuster命令学习可参考下面文章:https://cloud.tencent.com/developer/article/2331391

原文 https://blog.csdn.net/2301_79518550/article/details/144177783