예제 #1
0
        // public CheckResult retCheck;
        /// <summary>
        /// コンストラクタ
        /// </summary>
        /// <param name="checker">コピーコンストラクタ(ライトコピー)</param>
        public Checker(Checker checker)
        {
            //retCheck = new CheckResult();
            loginUrl = checker._loginUrl;
            homeUrl = checker._homeUrl;
            getOnlyUrl = checker._getOnlyUrl;
            formdata = checker._formdata;

            //参照渡し
            formdatas = checker.formdatas;
            checkResult = checker.checkResult;
            firstResponse = checker.firstResponse;
        }
예제 #2
0
        /// <summary>
        /// 実際にチェックを行うメソッド
        /// </summary>
        public void checkSessions()
        {
            //LoginURL Test
            //ログイン前に振ってる物のチェック
            //CheckerWebResponse firstResponse = getResponse(loginUrl, null, null);

            //HomeURL Test
            //ログイン前に振った物をそのまま利用してるもの
            String formText = "";

            foreach (KeyValuePair <string, FormInput> pair in formdata.table)
            {
                if (pair.Key != null && !pair.Key.Equals(""))
                {
                    formText += Uri.EscapeDataString(pair.Key) + "=" + Uri.EscapeDataString(pair.Value.value) + "&";
                }
            }
            formText = formText.Substring(0, formText.Length - 1);
            CheckerWebResponse secondResponse = getResponse(homeUrl, formText, firstResponse.cookieContainer, loginUrl);

            //セッションアダプション用
            //振るタイミングは、ログイン画面を開いた後から、ログインをクリックする前までの間
            CookieContainer cookieCont         = copyContainer(secondResponse.cookieContainer, homeUrl);
            Hashtable       randomSessiontable = new Hashtable();
            bool            checkRand          = false;
            Hashtable       mergeTable         = new Hashtable();

            foreach (DictionaryEntry dic in firstResponse.cookietable)
            {
                mergeTable[dic.Key] = dic.Value;
            }
            foreach (DictionaryEntry dic in secondResponse.cookietable)
            {
                mergeTable[dic.Key] = dic.Value;
            }
            foreach (DictionaryEntry dic in mergeTable)
            {
                CookieData tmp = (CookieData)dic.Value;
                if (isSession(tmp))
                {
                    checkRand = true;
                    Random rand     = new Random();
                    String randst   = "";
                    char[] randchar = new char[tmp.value.Length];
                    for (int i = 0; i < tmp.value.Length; ++i)
                    {
                        randst += rand.Next(9);
                    }
                    cookieCont.GetCookies(new Uri(homeUrl))[tmp.name].Value = randst;
                    randomSessiontable.Add(tmp.name, randst);
                }
            }
            CheckerWebResponse secondRandomSessionResponse = null;

            if (checkRand)
            {
                secondRandomSessionResponse = getResponse(homeUrl, formText, cookieCont, loginUrl);
            }
            else
            {
                secondRandomSessionResponse      = new CheckerWebResponse();
                secondRandomSessionResponse.body = null;
            }

            //セッションが一画面ごとに変わっていないかチェックするためのもの
            CheckerWebResponse secondResponseFixedCheckResult = null;

            if (secondResponse.statusCode >= 300 && secondResponse.statusCode <= 399)
            {
                secondResponseFixedCheckResult = getResponse(secondResponse.location, null, secondResponse.cookieContainer, loginUrl);
            }
            else if (getOnlyUrl != null)
            {
                secondResponseFixedCheckResult = getResponse(getOnlyUrl, null, secondResponse.cookieContainer, loginUrl);
            }

            //Check
            Hashtable firstCookietable              = firstResponse.cookietable;
            Hashtable secondCookietable             = secondResponse.cookietable;
            Hashtable secondResponseFixedChecktable = null;
            Hashtable secondRandomCookietable       = secondRandomSessionResponse.cookietable;

            //ログイン前に割り振ったセッションをそのまま利用していないかのチェック
            fixChecker(firstCookietable, secondCookietable);

            //ログイン後にセッションを毎回変えているかのチェック
            if (secondResponseFixedCheckResult != null)
            {
                secondResponseFixedChecktable = secondResponseFixedCheckResult.cookietable;
                fixChecker(secondCookietable, secondResponseFixedChecktable);
            }

            //ログイン直前に割り振られた偽セッションをそのまま利用していないかのチェック
            foreach (DictionaryEntry dic in randomSessiontable)
            {
                String key = (String)dic.Key;
                if (secondRandomCookietable.ContainsKey(key))
                {
                    if ((String)randomSessiontable[key] == ((CookieData)secondRandomCookietable[key]).value)
                    {
                        ((CookieData)secondRandomCookietable[key]).fix = true;
                    }
                }
                else
                {
                    secondRandomCookietable.Add(key, new CookieData(key, (String)randomSessiontable[key], null, null, null, false, false));
                    ((CookieData)secondRandomCookietable[key]).fix = true;
                }
            }

            //レスポンス生成
            CheckResult retCheck = new CheckResult();

            //Set body
            retCheck.firstBody  = firstResponse.body;
            retCheck.secondBody = secondResponse.body;
            if (secondResponseFixedCheckResult != null)
            {
                retCheck.secondResponseFixedCheckBody = secondResponseFixedCheckResult.body;
            }
            retCheck.secondRandomBody = secondRandomSessionResponse.body;

            //レスポンスにセット
            retCheck.firstCookieCheck        = firstCookietable;
            retCheck.secondCookieCheck       = secondCookietable;
            retCheck.secondRandomCookieCheck = secondRandomCookietable;
            if (secondResponseFixedCheckResult != null)
            {
                retCheck.secondResponseFixedCheck = secondResponseFixedChecktable;
            }
            checkResult = retCheck;
        }
예제 #3
0
        /// <summary>
        /// 実際にチェックを行うメソッド
        /// </summary>
        public void checkSessions()
        {
            //LoginURL Test
            //ログイン前に振ってる物のチェック
            //CheckerWebResponse firstResponse = getResponse(loginUrl, null, null);

            //HomeURL Test
            //ログイン前に振った物をそのまま利用してるもの
            String formText = "";
            foreach (KeyValuePair<string, FormInput> pair in formdata.table)
            {
                if (pair.Key != null && !pair.Key.Equals(""))
                {
                    formText += Uri.EscapeDataString(pair.Key) + "=" + Uri.EscapeDataString(pair.Value.value) + "&";
                }
            }
            formText = formText.Substring(0, formText.Length - 1);
            CheckerWebResponse secondResponse = getResponse(homeUrl, formText, firstResponse.cookieContainer,loginUrl);

            //セッションアダプション用
            //振るタイミングは、ログイン画面を開いた後から、ログインをクリックする前までの間
            CookieContainer cookieCont = copyContainer(secondResponse.cookieContainer, homeUrl);
            Hashtable randomSessiontable = new Hashtable();
            bool checkRand = false;
            Hashtable mergeTable = new Hashtable();
            foreach (DictionaryEntry dic in firstResponse.cookietable)
            {
                mergeTable[dic.Key] = dic.Value;
            }
            foreach (DictionaryEntry dic in secondResponse.cookietable)
            {
                mergeTable[dic.Key] = dic.Value;
            }
            foreach (DictionaryEntry dic in mergeTable)
            {
                CookieData tmp = (CookieData)dic.Value;
                if (isSession(tmp))
                {
                    checkRand = true;
                    Random rand = new Random();
                    String randst = "";
                    char[] randchar = new char[tmp.value.Length];
                    for (int i = 0; i < tmp.value.Length; ++i)
                    {
                        randst += rand.Next(9);
                    }
                    cookieCont.GetCookies(new Uri(homeUrl))[tmp.name].Value = randst;
                    randomSessiontable.Add(tmp.name, randst);
                }
            }
            CheckerWebResponse secondRandomSessionResponse = null;
            if (checkRand)
            {
                secondRandomSessionResponse = getResponse(homeUrl, formText, cookieCont,loginUrl);
            }
            else
            {
                secondRandomSessionResponse = new CheckerWebResponse();
                secondRandomSessionResponse.body = null;
            }

            //セッションが一画面ごとに変わっていないかチェックするためのもの
            CheckerWebResponse secondResponseFixedCheckResult = null;
            if (secondResponse.statusCode >= 300 && secondResponse.statusCode <= 399)
            {
                secondResponseFixedCheckResult = getResponse(secondResponse.location, null, secondResponse.cookieContainer,loginUrl);
            }
            else if (getOnlyUrl != null)
            {
                secondResponseFixedCheckResult = getResponse(getOnlyUrl, null, secondResponse.cookieContainer,loginUrl);
            }

            //Check
            Hashtable firstCookietable = firstResponse.cookietable;
            Hashtable secondCookietable = secondResponse.cookietable;
            Hashtable secondResponseFixedChecktable = null;
            Hashtable secondRandomCookietable = secondRandomSessionResponse.cookietable;

            //ログイン前に割り振ったセッションをそのまま利用していないかのチェック
            fixChecker(firstCookietable, secondCookietable);

            //ログイン後にセッションを毎回変えているかのチェック
            if (secondResponseFixedCheckResult != null)
            {
                secondResponseFixedChecktable = secondResponseFixedCheckResult.cookietable;
                fixChecker(secondCookietable, secondResponseFixedChecktable);
            }

            //ログイン直前に割り振られた偽セッションをそのまま利用していないかのチェック
            foreach (DictionaryEntry dic in randomSessiontable)
            {
                String key = (String)dic.Key;
                if (secondRandomCookietable.ContainsKey(key))
                {
                    if ((String)randomSessiontable[key] == ((CookieData)secondRandomCookietable[key]).value)
                    {
                        ((CookieData)secondRandomCookietable[key]).fix = true;
                    }
                }
                else
                {
                    secondRandomCookietable.Add(key, new CookieData(key, (String)randomSessiontable[key], null, null, null, false, false));
                    ((CookieData)secondRandomCookietable[key]).fix = true;
                }
            }

            //レスポンス生成
            CheckResult retCheck = new CheckResult();

            //Set body
            retCheck.firstBody = firstResponse.body;
            retCheck.secondBody = secondResponse.body;
            if (secondResponseFixedCheckResult != null) retCheck.secondResponseFixedCheckBody = secondResponseFixedCheckResult.body;
            retCheck.secondRandomBody = secondRandomSessionResponse.body;

            //レスポンスにセット
            retCheck.firstCookieCheck = firstCookietable;
            retCheck.secondCookieCheck = secondCookietable;
            retCheck.secondRandomCookieCheck = secondRandomCookietable;
            if (secondResponseFixedCheckResult != null) retCheck.secondResponseFixedCheck = secondResponseFixedChecktable;
            checkResult = retCheck;
        }