#!/bin/bash
# Stage 4: 深度验证 .git 暴露 + 抓 robots.txt 里的隐藏路径
set -e
OUT="/root/pentest_reports/oppo_V-001"
TARGET="https://www.coloros.com"

echo "===[4.1] 验证 .git 暴露 (用 HEAD/HEAD~1 / 不同 User-Agent 绕过) ==="
# 测试 412 是什么 filter 导致的
for ua in "Mozilla/5.0" "git/2.40.0" "curl/8.0" "" "Git-Proxy"; do
    code=$(curl -sk -o /dev/null -w "%{http_code}" "$TARGET/.git/config" -H "User-Agent: $ua" --max-time 8)
    echo "  UA='$ua'  HTTP $code"
done

echo ""
echo "===[4.2] 用 GET 加不同 method 试探 (.git/) ==="
for method in GET HEAD OPTIONS PROPFIND TRACE; do
    code=$(curl -sk -o /dev/null -w "%{http_code}" -X "$method" "$TARGET/.git/" --max-time 8)
    echo "  $method  HTTP $code"
done

echo ""
echo "===[4.3] robots.txt 里 Disallow 路径一一探 ==="
for p in article-preview list-preview topics-preview feature/coloros11 feature/coloros12; do
    code=$(curl -sk -o /dev/null -w "%{http_code}" "$TARGET/$p" --max-time 8)
    size=$(curl -sk -o /dev/null -w "%{size_download}" "$TARGET/$p" --max-time 8)
    [ "$code" != "404" ] && echo "  HTTP $code  ${size}B  /$p"
done

echo ""
echo "===[4.4] .well-known/security.txt (RFC 9116) ==="
curl -sk "$TARGET/.well-known/security.txt" --max-time 8 2>&1 | head -10

echo ""
echo "===[4.5] API 路径探测 (常见 SPA API) ==="
for p in api api/v1 api/v2 _api _next/data nuxt-axios graphql api/graphql; do
    code=$(curl -sk -o /dev/null -w "%{http_code}" "$TARGET/$p" --max-time 8)
    [ "$code" != "404" ] && [ "$code" != "302" ] && echo "  HTTP $code  /$p"
done

echo ""
echo "===[4.6] GET /article-preview 看返回内容 ==="
curl -sk -i "$TARGET/article-preview" --max-time 8 2>&1 | head -15
echo "---"
curl -sk -i "$TARGET/list-preview" --max-time 8 2>&1 | head -15