package com.it_jaros.jscanner; import java.io.IOException; import java.io.InputStream; import java.net.*; import java.nio.charset.StandardCharsets; import java.time.Duration; import java.util.*; import java.util.concurrent.*; import java.util.concurrent.atomic.AtomicBoolean; import java.util.concurrent.atomic.AtomicInteger; import java.util.concurrent.atomic.AtomicLong; import java.util.function.Consumer; import java.util.function.Function; public class Scanner implements AutoCloseable { private static final int READ_BUFFER_SIZE = 1024; private volatile boolean cancelled = false; private final ExecutorService executor = Executors.newVirtualThreadPerTaskExecutor(); private final Semaphore socketLimit; private final boolean bannerRecognition; private final boolean disableOnlineCheck; private final int maxHostsLimit; private final int maxWorkersPerHost; private final int timeoutInMillis; private final long delayInNanos; public Scanner( int socketLimit, int timeoutInMillis, int delayInMillis, int maxWorkersPerHost, int maxHostsLimit, boolean disableOnlineCheck, boolean bannerRecognition ) { this.delayInNanos = TimeUnit.MILLISECONDS.toNanos(Math.max(0, delayInMillis)); this.bannerRecognition = bannerRecognition; this.disableOnlineCheck = disableOnlineCheck; this.maxHostsLimit = maxHostsLimit; this.maxWorkersPerHost = maxWorkersPerHost; this.socketLimit = new Semaphore(socketLimit); this.timeoutInMillis = timeoutInMillis; } public Scanner(ScanOptions options) { this(options.socketLimit(), options.timeoutInMillis(), options.delayInMillis(), options.maxWorkersPerHost(), options.maxHostsLimit(), options.disableOnlineCheck(), options.bannerRecognition()); } /** * Starts a given scan. * * @param scan */ public void runScan(final Scan scan, final Consumer consumer) { if (scan == null) { throw new IllegalArgumentException("Scan argument cannot be null"); } scan.start(); // start producer thread final ProducerState state = startProducer( scan.getHosts().iterator(), maxHostsLimit, host -> new ScanHostTask(scan, host), scan.getThreadCounter() ); // the main thread is the consumer // Let the consumer run as long as the producer runs // or if still tasks are pending in pipeline // we do not listen to canceled here because we want // all results (also partial) collected for the consumer // with whatever is there already while (state.running().get() || state.inPipeline().get() > 0) { try { ScanResult result = getHostResult(state); if (result == null) { continue; } consumer.accept(result); } catch (InterruptedException e) { Thread.currentThread().interrupt(); } } scan.stop(); } private ScanResult getHostResult(ProducerState state) throws InterruptedException { // let's check for results and give add them to our scan data holder object Future finishedHost = state.completionService().poll(10, TimeUnit.MILLISECONDS); if (finishedHost == null) { return null; } ScanResult result = null; try { result = finishedHost.get(); } catch (ExecutionException e) { System.err.printf("%s -> %s%n", e.getClass().getSimpleName(), e.getMessage()); } finally { // No matter what happens we have to free the resources after getting ScanResult state.activeWorkers().release(); state.inPipeline().decrementAndGet(); } return result; } /** * This method helps to cleanup the code a bit and remove redundancy * The producer for providing hosts and the one for providing ports * are similar and the small differences can be handled using a function * * @param queue * @param maxWorkers * @param taskFactory * @param * @param * @return */ private ProducerState startProducer(Iterator queue, int maxWorkers, Function> taskFactory, Counter threadCounter) { final AtomicInteger inPipeline = new AtomicInteger(0); final AtomicBoolean running = new AtomicBoolean(true); final Semaphore activeWorkers = new Semaphore(maxWorkers); CompletionService completionService = new ExecutorCompletionService<>(executor); executor.submit(() -> { try { threadCounter.inc(); while (!cancelled && queue.hasNext()) { activeWorkers.acquire(); // remember if we submitted anything // so we can release the semaphore boolean submitted = false; try { // just in case something changed while waiting // for the semaphore if (cancelled) { break; } // get next item and create callable // using lambda expression final INPUT item = queue.next(); Callable task = taskFactory.apply(item); inPipeline.incrementAndGet(); try { // here we are filling the completion service // host <-> virtual thread completionService.submit(task); submitted = true; } catch (Throwable e) { inPipeline.decrementAndGet(); throw e; } } finally { if (!submitted) { activeWorkers.release(); } } } } catch (InterruptedException e) { Thread.currentThread().interrupt(); } finally { threadCounter.dec(); running.set(false); } }); return new ProducerState<>(running, inPipeline, activeWorkers, completionService); } public boolean awaitTermination(Duration duration) throws InterruptedException { return executor.awaitTermination(duration.toMillis(), TimeUnit.MILLISECONDS); } public void cancel() { if (!cancelled) { cancelled = true; } executor.shutdown(); } public void cancelNow() { if (!cancelled) { cancelled = true; } executor.shutdownNow(); } @Override public void close() throws Exception { cancel(); } private final class ScanHostTask implements Callable { private final Scan scan; private final String host; // input parameter ScanHostTask(Scan scan, String host) { this.scan = scan; this.host = host; } @Override public ScanResult call() { try { scan.getThreadCounter().inc(); scan.getHostCounter().inc(); scan.getHostTotalCounter().inc(); if (cancelled) { return null; } return scanHostPorts(host, scan); } finally { scan.getThreadCounter().dec(); scan.getHostCounter().dec(); } } /** * Scans the ports of a given host * * @param host * @param scan * @return */ private ScanResult scanHostPorts(final String host, final Scan scan) { if (!disableOnlineCheck && !checkHostOnline(host)) { // Unreachable host return new ScanResult( host, new BitSet(PortRange.MAX_PORT), new BitSet(PortRange.MAX_PORT), new HashMap<>(), List.of() ); } final PortRange portRange = new PortRange(scan.getPorts()); final AtomicLong portSlotFactory = new AtomicLong(System.nanoTime()); // producer thread ProducerState state = startProducer( portRange.iterator(), maxWorkersPerHost, port -> new ScanPortTask(host, port, scan, portSlotFactory), scan.getThreadCounter() ); // consumer is the main thread // we run as long as the producer is running or as long as things are in pipeline to be processed // only exception is when cancelled is set final PortResultAccumulator accumulator = new PortResultAccumulator(host); while (!cancelled && (state.running().get() || state.inPipeline().get() > 0)) { try { PortResult portResult = getPortResult(state); if (portResult == null) { continue; } accumulator.add(portResult); } catch (InterruptedException ignored) { Thread.currentThread().interrupt(); } } return accumulator.build(); } private boolean checkHostOnline(String host) { try { return InetAddress.getByName(host).isReachable(timeoutInMillis); } catch (IOException e) { // something went wrong } return false; } private PortResult getPortResult(ProducerState state) throws InterruptedException { Future portResultFuture = state.completionService().poll(10, TimeUnit.MILLISECONDS); if (portResultFuture == null) { return null; } PortResult portResult = null; try { portResult = portResultFuture.get(); } catch (ExecutionException e) { // something more serious did not work System.err.printf("%s -> %s%n", e.getClass().getSimpleName(), e.getMessage()); } finally { state.activeWorkers().release(); state.inPipeline().decrementAndGet(); } return portResult; } } private final class ScanPortTask implements Callable { private final Scan scan; private final String host; private final int port; private final AtomicLong portSlotFactory; private ScanPortTask(String host, int port, Scan scan, AtomicLong portSlotFactory) { this.scan = scan; this.host = host; this.port = port; this.portSlotFactory = portSlotFactory; } @Override public PortResult call() throws Exception { try { scan.getThreadCounter().inc(); waitForSlot(portSlotFactory); if (cancelled) { return null; } return checkPort(host, port, scan); } finally { scan.getThreadCounter().dec(); } } private void waitForSlot(AtomicLong scanSlotFactory) throws InterruptedException { if (delayInNanos > 0) { long slot = scanSlotFactory.getAndAdd(delayInNanos); long wait = slot - System.nanoTime(); if (wait > 0) Thread.sleep(Duration.ofNanos(wait)); } } private PortResult checkPort(String host, int port, Scan scan) throws InterruptedException { PortResult result = new PortResult(); result.setPort(port); result.setState(PortState.UNKNOWN); // don't allow more sockets then specified socketLimit.acquire(); // count how many ports are concurrently checked // todo object/data asymmetry scan.getSocketCounter().inc(); try (Socket socket = new Socket()) { socket.connect(new InetSocketAddress(host, port), timeoutInMillis); result.setState(PortState.OPEN); if (bannerRecognition) { result.setBanner(getBanner(socket)); } } catch (SocketTimeoutException ignored) { result.setState(PortState.FILTERED); } catch (ConnectException ignored) { result.setState(PortState.CLOSED); } catch (NoRouteToHostException ignored) { // NoRouteToHostException: this can be safely ignored because the port is closed if a host is unreachable // Will happen a lot when scanning for open ports, so not needed } catch (IOException e) { result.setException(e); } finally { scan.getSocketCounter().dec(); socketLimit.release(); } return result; } private String getBanner(Socket socket) { byte[] buffer = new byte[READ_BUFFER_SIZE]; try (InputStream input = socket.getInputStream()) { socket.setSoTimeout(timeoutInMillis); int bytesRead = input.read(buffer); if (bytesRead <= 0) { return null; } return new String(buffer, 0, bytesRead, StandardCharsets.UTF_8).trim(); } catch (IOException e) { // we ignore this failure } return null; } } private final class PortResultAccumulator { private final String host; private final BitSet openPorts = new BitSet(PortRange.MAX_PORT); private final BitSet filteredPorts = new BitSet(PortRange.MAX_PORT); private final Map serviceTypes = new HashMap<>(); private final List scanFailures = new ArrayList<>(); private PortResultAccumulator(String host) { this.host = host; } void add(PortResult portResult) { switch (portResult.getState()) { case OPEN -> { // bitset is not thread-safe, so it is set // outside the other virtual threads that update progress openPorts.set(portResult.getPort()); serviceTypes.put(portResult.getPort(), ServiceDetector.detect(portResult.getBanner())); } case FILTERED -> { filteredPorts.set(portResult.getPort()); } default -> { // sonarcube glücklich machen } } Exception e = portResult.getException(); if (e != null) { scanFailures.add(new ScanFailure(portResult.getPort(), ExceptionInfo.from(e))); } } ScanResult build() { return new ScanResult(host, openPorts, filteredPorts, serviceTypes, scanFailures); } } }