diff --git a/lib/attacks/admin_panel_finder/__init__.py b/lib/attacks/admin_panel_finder/__init__.py index 88a9858..1611834 100644 --- a/lib/attacks/admin_panel_finder/__init__.py +++ b/lib/attacks/admin_panel_finder/__init__.py @@ -1,5 +1,4 @@ import os -import time import multiprocessing try: # Python 2 @@ -10,18 +9,8 @@ except ImportError: # Python 3 import requests +import lib.core.settings from var.auto_issue.github import request_issue_creation -from lib.core.settings import ( - logger, - replace_http, - set_color, - create_tree, - prompt, - write_to_log_file, - ROBOTS_PAGE_PATH, - SITEMAP_FILE_LOG_PATH, - ADMIN_PAGE_FILE_PATH -) def check_for_externals(url, data_sep="-" * 30, **kwargs): @@ -40,16 +29,16 @@ def check_for_externals(url, data_sep="-" * 30, **kwargs): } currently_searching = ext[robots if robots else sitemap] if verbose: - logger.debug(set_color( + lib.core.settings.logger.debug(lib.core.settings.set_color( "currently searching for a '{}'...".format(currently_searching), level=10 )) - url = replace_http(url) + url = lib.core.settings.replace_http(url) full_url = "{}{}{}".format("http://", url, currently_searching) conn = requests.get(full_url) data = conn.content code = conn.status_code if code == 404: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "unable to connect to '{}', assuming does not exist and continuing...".format( full_url ), level=40 @@ -61,10 +50,10 @@ def check_for_externals(url, data_sep="-" * 30, **kwargs): if "Allow" in line: interesting.add(line.strip()) if len(interesting) > 0: - create_tree(full_url, list(interesting)) + lib.core.settings.create_tree(full_url, list(interesting)) else: if not batch: - to_display = prompt( + to_display = lib.core.settings.prompt( "nothing interesting found in robots.txt would you like to display the entire page", opts="yN" ) if to_display.lower().startswith("y"): @@ -73,15 +62,18 @@ def check_for_externals(url, data_sep="-" * 30, **kwargs): data_sep, data, data_sep ) ) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "robots.txt page will be saved into a file...", level=25 )) - return write_to_log_file(data, ROBOTS_PAGE_PATH, "robots-{}.log".format(url)) + return lib.core.settings.write_to_log_file(data, lib.core.settings.ROBOTS_PAGE_PATH, "robots-{}.log".format(url)) elif sitemap: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "found a sitemap, saving to file...", level=25 )) - return write_to_log_file(data, SITEMAP_FILE_LOG_PATH, "{}-sitemap.xml".format(replace_http(url))) + return lib.core.settings.write_to_log_file(data, lib.core.settings.SITEMAP_FILE_LOG_PATH, + "{}-sitemap.xml".format( + lib.core.settings.replace_http(url)) + ) def check_for_admin_page(url, exts, protocol="http://", **kwargs): @@ -91,7 +83,7 @@ def check_for_admin_page(url, exts, protocol="http://", **kwargs): verbose = kwargs.get("verbose", False) show_possibles = kwargs.get("show_possibles", False) possible_connections, connections = set(), set() - stripped_url = replace_http(str(url).strip()) + stripped_url = lib.core.settings.replace_http(str(url).strip()) for ext in exts: # each extension is loaded before this process begins to save time # while running this process. @@ -99,12 +91,12 @@ def check_for_admin_page(url, exts, protocol="http://", **kwargs): ext = ext.strip() true_url = "{}{}{}".format(protocol, stripped_url, ext) if verbose: - logger.debug(set_color( + lib.core.settings.logger.debug(lib.core.settings.set_color( "trying '{}'...".format(true_url), level=10 )) try: urlopen(true_url, timeout=5) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "connected successfully to '{}'...".format(true_url), level=25 )) connections.add(true_url) @@ -112,7 +104,7 @@ def check_for_admin_page(url, exts, protocol="http://", **kwargs): data = str(e).split(" ") if verbose: if "Access Denied" in str(e): - logger.warning(set_color( + lib.core.settings.logger.warning(lib.core.settings.set_color( "got access denied, possible control panel found without external access on '{}'...".format( true_url ), @@ -120,7 +112,7 @@ def check_for_admin_page(url, exts, protocol="http://", **kwargs): )) possible_connections.add(true_url) else: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "failed to connect got error code {}...".format( data[2] ), level=40 @@ -128,46 +120,46 @@ def check_for_admin_page(url, exts, protocol="http://", **kwargs): except Exception as e: if verbose: if "" or "timeout: timed out" in str(e): - logger.warning(set_color( + lib.core.settings.logger.warning(lib.core.settings.set_color( "connection timed out assuming won't connect and skipping...", level=30 )) else: - logger.exception(set_color( + lib.core.settings.logger.exception(lib.core.settings.set_color( "failed to connect with unexpected error '{}'...".format(str(e)), level=50 )) request_issue_creation() possible_connections, connections = list(possible_connections), list(connections) data_msg = "found {} possible connections(s) and {} successful connection(s)..." - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( data_msg.format(len(possible_connections), len(connections)) )) if len(connections) > 0: # create the connection tree if we got some connections - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "creating connection tree..." )) - create_tree(url, connections) + lib.core.settings.create_tree(url, connections) else: - logger.fatal(set_color( + lib.core.settings.logger.fatal(lib.core.settings.set_color( "did not receive any successful connections to the admin page of " "{}...".format(url), level=50 )) if show_possibles: if len(possible_connections) > 0: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "creating possible connection tree..." )) - create_tree(url, possible_connections) + lib.core.settings.create_tree(url, possible_connections) else: - logger.fatal(set_color( + lib.core.settings.logger.fatal(lib.core.settings.set_color( "did not find any possible connections to {}'s " "admin page".format(url), level=50 )) - logger.warning(set_color( + lib.core.settings.logger.warning(lib.core.settings.set_color( "only writing successful connections to log file..." )) - write_to_log_file(list(connections), ADMIN_PAGE_FILE_PATH, "{}-admin-page.log".format( - replace_http(url) + lib.core.settings.write_to_log_file(list(connections), lib.core.settings.ADMIN_PAGE_FILE_PATH, "{}-admin-page.log".format( + lib.core.settings.replace_http(url) )) @@ -187,31 +179,31 @@ def main(url, show=False, verbose=False, **kwargs): do_threading = kwargs.get("do_threading", False) proc_num = kwargs.get("proc_num", 3) batch = kwargs.get("batch", False) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "parsing robots.txt..." )) results = check_for_externals(url, robots=True, batch=batch) if not results: - logger.warning(set_color( + lib.core.settings.logger.warning(lib.core.settings.set_color( "seems like this page is either blocking access to robots.txt or it does not exist...", level=30 )) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "checking for a sitemap..." )) check_for_externals(url, sitemap=True) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "loading extensions..." )) extensions = __load_extensions() if verbose: - logger.debug(set_color( + lib.core.settings.logger.debug(lib.core.settings.set_color( "loaded a total of {} extensions...".format(len(extensions)), level=10 )) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "attempting to bruteforce admin panel..." )) if do_threading: - logger.warning(set_color( + lib.core.settings.logger.warning(lib.core.settings.set_color( "starting parallel processing with {} processes, this " "will depend on your GPU speed...".format(proc_num), level=30 )) diff --git a/lib/attacks/intel_me/__init__.py b/lib/attacks/intel_me/__init__.py index 66d2bc9..1c5ba77 100644 --- a/lib/attacks/intel_me/__init__.py +++ b/lib/attacks/intel_me/__init__.py @@ -4,12 +4,8 @@ import socket import requests -from lib.core.settings import ( - proxy_string_to_dict, - logger, set_color, - DEFAULT_USER_AGENT, - replace_http -) +import lib.core.settings + from lxml import html from var.auto_issue.github import request_issue_creation @@ -21,7 +17,7 @@ def __get_auth_headers(target, port, **kwargs): source = kwargs.get("source", None) proxy, agent, verbose = kwargs.get("proxy", None), kwargs.get("agent", None), kwargs.get("verbose", False) if not source or 'WWW-Authenticate' not in source.headers['WWW-Authenticate']: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "header value not established, attempting to get bypass..." )) source = requests.get("http://{0}:{1}/index.htm".format(target, port), timeout=10, headers={ @@ -30,7 +26,7 @@ def __get_auth_headers(target, port, **kwargs): return source # Get digest and nonce and return the new header elif 'WWW-Authenticate' in source.headers: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "header value established successfully, attempting authentication..." )) data = re.compile('Digest realm="Digest:(.*)", nonce="(.*)",stale="false",qop="auth"').search( @@ -42,7 +38,7 @@ def __get_auth_headers(target, port, **kwargs): 'uri="/index.htm", response="", qop=auth, ' \ 'nc=00000001, cnonce="deadbeef"'.format(digest, nonce) else: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "nothing found, will skip URL..." )) return None @@ -53,7 +49,7 @@ def __get_raw_data(target, page, port, agent=None, proxy=None, **kwargs): collect all the information from an exploitable target """ verbose = kwargs.get("verbose", False) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "attempting to get raw hardware information..." )) return requests.get("http://{0}:{1}/{2}.htm".format(target, port, page), @@ -71,7 +67,7 @@ def __get_hardware(target, port, agent=None, proxy=None, verbose=False): req = __get_raw_data(target, 'hw-sys', port, agent=agent, proxy=proxy, verbose=verbose) if not req.status_code == 200: return None - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "connected successfully getting hardware info..." )) tree = html.fromstring(req.content) @@ -112,40 +108,40 @@ def main_intel_amt(url, agent=None, proxy=None, **kwargs): """ do_ip_address = kwargs.get("do_ip", False) verbose = kwargs.get("verbose", False) - proxy = proxy_string_to_dict(proxy) or None - agent = agent or DEFAULT_USER_AGENT + proxy = lib.core.settings.proxy_string_to_dict(proxy) or None + agent = agent or lib.core.settings.DEFAULT_USER_AGENT port_list = (16993, 16992, 693, 692) if do_ip_address: - logger.warning(set_color( + lib.core.settings.logger.warning(lib.core.settings.set_color( "running against IP addresses may result in the targets refusing the connection...", level=30 )) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "will run against IP address instead of hostname..." )) try: - url = replace_http(url) + url = lib.core.settings.replace_http(url) url = "http://{}".format(socket.gethostbyname(url)) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "discovered IP address {}...".format(url) )) except Exception as e: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "failed to gather IP address from hostname '{}', received an error '{}'. " "will just run against hostname...".format(url, e), level=40 )) url = url - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "attempting to connect to '{}' and get hardware info...".format(url) )) for port in list(port_list): if verbose: - logger.debug(set_color( + lib.core.settings.logger.debug(lib.core.settings.set_color( "trying on port {}...".format(port), level=10 )) try: json_data = __get_hardware(url, port, agent=agent, proxy=proxy, verbose=verbose) if json_data is None: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "unable to get any information, skipping...", level=40 )) pass @@ -158,23 +154,23 @@ def main_intel_amt(url, agent=None, proxy=None, **kwargs): print("-" * 40) except requests.exceptions.ConnectionError as e: if "Max retries exceeded with url" in str(e): - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "failed connection, target machine is actively refusing the connection, skipping...", level=40 )) pass else: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "failed connection with '{}', skipping...", level=40 )) pass except Exception as e: if "Temporary failure in name resolution" in str(e): - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "failed to connect on '{}', skipping...".format(url), level=40 )) pass else: - logger.exception(set_color( + lib.core.settings.logger.exception(lib.core.settings.set_color( "ran into exception '{}', cannot continue...".format(e), level=50 )) request_issue_creation() diff --git a/lib/attacks/whois_lookup/whois.py b/lib/attacks/whois_lookup/whois.py index 2e58425..9a14476 100644 --- a/lib/attacks/whois_lookup/whois.py +++ b/lib/attacks/whois_lookup/whois.py @@ -5,13 +5,7 @@ import urllib2 from base64 import b64decode -from lib.core.settings import ( - WHOIS_JSON_LINK, - write_to_log_file, - WHOIS_RESULTS_LOG_PATH, - logger, set_color, - replace_http -) +import lib.core.settings def __get_encoded_string(path="{}/etc/auths/whois_auth"): @@ -46,7 +40,7 @@ def gather_raw_whois_info(domain): "Authorization": "Token {}".format(__get_token()), } request = urllib2.Request( - WHOIS_JSON_LINK.format(domain), headers=auth_headers + lib.core.settings.WHOIS_JSON_LINK.format(domain), headers=auth_headers ) data = urllib2.urlopen(request).read() _json_data = json.loads(data) @@ -101,17 +95,17 @@ def whois_lookup_main(domain, **kwargs): # sleep a little bit so that WhoIs doesn't stop us from making requests verbose = kwargs.get("verbose", False) timeout = kwargs.get("timeout", None) - domain = replace_http(domain) - logger.info(set_color( + domain = lib.core.settings.replace_http(domain) + lib.core.settings.logger.info(lib.core.settings.set_color( "performing WhoIs lookup on given domain '{}'...".format(domain) )) if timeout is not None: time.sleep(timeout) raw_information = gather_raw_whois_info(domain) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "discovered raw information...", level=25 )) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "gathering interesting information..." )) interesting_data = get_interesting(raw_information) @@ -119,7 +113,10 @@ def whois_lookup_main(domain, **kwargs): try: human_readable_display(domain, interesting_data) except (ValueError, Exception): - logger.fatal(set_color( + lib.core.settings.logger.fatal(lib.core.settings.set_color( "unable to display any information from WhoIs lookup on domain '{}'...".format(domain), level=50 )) - write_to_log_file(raw_information, WHOIS_RESULTS_LOG_PATH, "{}-whois.json".format(domain)) \ No newline at end of file + lib.core.settings.write_to_log_file( + raw_information, lib.core.settings.WHOIS_RESULTS_LOG_PATH, + "{}-whois.json".format(domain) + ) \ No newline at end of file diff --git a/lib/attacks/xss_scan/__init__.py b/lib/attacks/xss_scan/__init__.py index 9f29d60..1d4bfe8 100644 --- a/lib/attacks/xss_scan/__init__.py +++ b/lib/attacks/xss_scan/__init__.py @@ -9,17 +9,8 @@ import importlib import requests +import lib.core.settings from lib.core.errors import InvalidTamperProvided -from lib.core.settings import ( - logger, - set_color, - DEFAULT_USER_AGENT, - proxy_string_to_dict, - DBMS_ERRORS, - create_tree, - prompt, - shutdown, -) def list_tamper_scripts(path="{}/lib/tamper_scripts"): @@ -71,12 +62,12 @@ def create_urls(url, payload_list, tamper=None): else: payload = __tamper_payload(payload, tamper_type=tamper, warning=False) except InvalidTamperProvided: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "you provided and invalid tamper script, acceptable tamper scripts are: {}...".format( " | ".join(list_tamper_scripts()), level=40 ) )) - shutdown() + lib.core.settings.shutdown() loaded_url = "{}{}\n".format(url.strip(), payload.strip()) tmp.write(loaded_url) return tf_name @@ -107,14 +98,14 @@ def scan_xss(url, agent=None, proxy=None): chance that the URL is vulnerable to XSS attacks. Usually what will happen is the payload will be tampered or encoded if the site is not vulnerable """ - user_agent = agent or DEFAULT_USER_AGENT - config_proxy = proxy_string_to_dict(proxy) + user_agent = agent or lib.core.settings.DEFAULT_USER_AGENT + config_proxy = lib.core.settings.proxy_string_to_dict(proxy) config_headers = {"connection": "close", "user-agent": user_agent} xss_request = requests.get(url, proxies=config_proxy, headers=config_headers) html_data = xss_request.content query = find_xss_script(url) - for db in DBMS_ERRORS.keys(): - for item in DBMS_ERRORS[db]: + for db in lib.core.settings.DBMS_ERRORS.keys(): + for item in lib.core.settings.DBMS_ERRORS[db]: if re.findall(item, html_data): return "sqli", db if query in html_data: @@ -127,30 +118,30 @@ def main_xss(start_url, verbose=False, proxy=None, agent=None, tamper=None, batc main attack method to be called """ if tamper: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "tampering payloads with '{}'...".format(tamper) )) find_xss_script(start_url) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "loading payloads..." )) payloads = __load_payloads() if verbose: - logger.debug(set_color( + lib.core.settings.logger.debug(lib.core.settings.set_color( "a total of {} payloads loaded...".format(len(payloads)), level=10 )) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "payloads will be written to a temporary file and read from there..." )) filename = create_urls(start_url, payloads, tamper=tamper) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "loaded URL's have been saved to '{}'...".format(filename), level=25 )) - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "testing for XSS vulnerabilities on host '{}'...".format(start_url) )) if proxy is not None: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "using proxy '{}'...".format(proxy) )) success = set() @@ -160,18 +151,18 @@ def main_xss(start_url, verbose=False, proxy=None, agent=None, tamper=None, batc result = scan_xss(url, proxy=proxy, agent=agent) payload = find_xss_script(url) if verbose: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "trying payload '{}'...".format(payload) )) if result[0] != "sqli" and result[0] is True: success.add(url) if verbose: - logger.debug(set_color( + lib.core.settings.logger.debug(lib.core.settings.set_color( "payload '{}' appears to be usable...".format(payload), level=10 )) elif result[0] is "sqli": if i <= 1: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "loaded URL '{}' threw a DBMS error and appears to be injectable, test for SQL injection, " "backend DBMS appears to be '{}'...".format( url, result[1] @@ -179,27 +170,27 @@ def main_xss(start_url, verbose=False, proxy=None, agent=None, tamper=None, batc )) else: if verbose: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "SQL error discovered...", level=40 )) else: if verbose: - logger.debug(set_color( + lib.core.settings.logger.debug(lib.core.settings.set_color( "host '{}' does not appear to be vulnerable to XSS attacks with payload '{}'...".format( start_url, payload ), level=10 )) if len(success) != 0: - logger.info(set_color( + lib.core.settings.logger.info(lib.core.settings.set_color( "possible XSS scripts to be used:", level=25 )) - create_tree(start_url, list(success)) + lib.core.settings.create_tree(start_url, list(success)) else: - logger.error(set_color( + lib.core.settings.logger.error(lib.core.settings.set_color( "host '{}' does not appear to be vulnerable to XSS attacks...".format(start_url) )) if not batch: - save = prompt( + save = lib.core.settings.prompt( "would you like to keep the URL's saved for further testing", opts="yN" ) if save.lower().startswith("n"):