#!/bin/bash
# 批量出 13 个"缺失安全响应头"报告
set +e
TOOL="E:/hexstrike-ai/tools/gen_report.py"
OUT_BASE="E:/hexstrike-ai/reports"
mkdir -p "$OUT_BASE/V-001-OPPO" "$OUT_BASE/V-002-vivo" "$OUT_BASE/V-003-PayPal" \
         "$OUT_BASE/V-004-齐治" "$OUT_BASE/V-005-度小满" "$OUT_BASE/V-006-金蝶" \
         "$OUT_BASE/V-007-乐信" "$OUT_BASE/V-008-翼支付" "$OUT_BASE/V-009-值得买" \
         "$OUT_BASE/V-010-太平洋保险" "$OUT_BASE/V-011-千寻位置" "$OUT_BASE/V-012-阶跃星辰" \
         "$OUT_BASE/V-013-T3出行"

declare -A TARGETS=(
    ["V-001"]="heytap.com|欢太科技|https://www.heytap.com"
    ["V-002"]="passport.vivo.com.cn|维沃移动通信|https://passport.vivo.com.cn"
    ["V-003"]="paypal.cn|贝宝支付|https://www.paypal.cn"
    ["V-004"]="qzsec.com|齐治科技|https://www.qzsec.com"
    ["V-005"]="duxiaoman.com|度小满金融|https://www.duxiaoman.com"
    ["V-006"]="kingdee.com|金蝶软件|https://www.kingdee.com"
    ["V-007"]="lexin.com|乐信科技|https://www.lexin.com"
    ["V-008"]="bestpay.com.cn|翼支付|https://www.bestpay.com.cn"
    ["V-009"]="smzdm.com|值得买科技|https://www.smzdm.com"
    ["V-010"]="s.3001.net|太平洋保险|https://s.3001.net"
    ["V-011"]="qxwz.com|千寻位置|https://www.qxwz.com"
    ["V-012"]="stepfun.com|阶跃星辰|https://www.stepfun.com"
    ["V-013"]="t3go.cn|T3出行|https://www.t3go.cn"
)

for tid in V-001 V-002 V-003 V-004 V-005 V-006 V-007 V-008 V-009 V-010 V-011 V-012 V-013; do
    IFS='|' read -r dom brand url <<< "${TARGETS[$tid]}"
    proj_dir=$(ls -d $OUT_BASE/${tid}-* 2>/dev/null | head -1)
    out="${proj_dir}/${tid}_01_security_headers.md"

    python3.exe "$TOOL" "$tid" "$brand $dom 缺失关键 HTTP 安全响应头" medium \
        --vuln-url "$url" \
        --vuln-type "缺失安全响应头" \
        --desc "$brand ($url) 缺失多个关键 HTTP 安全响应头，包括 Strict-Transport-Security、Content-Security-Policy、X-Frame-Options、Referrer-Policy、X-Content-Type-Options、Permissions-Policy。攻击者可利用此缺陷实施点击劫持、中间人攻击、跨站脚本攻击等。影响范围涉及所有访问该站点的用户。" \
        --reproduce-html "1. 打开命令行终端<br>2. 执行命令：<code>curl -sI $url</code><br>3. 观察响应头：<br>&nbsp;&nbsp;- <strong>Strict-Transport-Security</strong>: 未设置<br>&nbsp;&nbsp;- <strong>Content-Security-Policy</strong>: 未设置<br>&nbsp;&nbsp;- <strong>X-Frame-Options</strong>: 未设置<br>&nbsp;&nbsp;- <strong>Referrer-Policy</strong>: 未设置<br>&nbsp;&nbsp;- <strong>X-Content-Type-Options</strong>: 未设置<br>&nbsp;&nbsp;- <strong>Permissions-Policy</strong>: 未设置<br>4. 使用浏览器开发者工具 (F12 → Network → Headers) 可获得同样结果<br>5. 验证: 在另一台机器通过中间人代理抓包可看到所有响应均无以上安全头" \
        --fix-html "1. <strong>添加 HSTS</strong>: Nginx 配置 <code>add_header Strict-Transport-Security \"max-age=31536000; includeSubDomains; preload\" always;</code><br>2. <strong>添加 CSP</strong>: <code>add_header Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:;\" always;</code><br>3. <strong>防点击劫持</strong>: <code>add_header X-Frame-Options \"SAMEORIGIN\" always;</code> 或使用 CSP 的 frame-ancestors<br>4. <strong>Referrer 控制</strong>: <code>add_header Referrer-Policy \"strict-origin-when-cross-origin\" always;</code><br>5. <strong>MIME 嗅探防护</strong>: <code>add_header X-Content-Type-Options \"nosniff\" always;</code><br>6. <strong>特性策略</strong>: <code>add_header Permissions-Policy \"geolocation=(), microphone=(), camera=()\" always;</code><br>7. 配置完成后使用 <a href='https://securityheaders.com/'>https://securityheaders.com/</a> 验证评分 A+" \
        --output "$out" 2>&1 | tail -2

    if [ -f "$out" ]; then
        echo "[$tid] ✓ $out ($(stat -c %s "$out")B)"
    else
        echo "[$tid] ❌ 失败"
    fi
done