mirror of
https://github.com/Ekultek/Zeus-Scanner.git
synced 2026-03-11 08:55:51 +00:00
moved the command line parsing to it's own class
This commit is contained in:
parent
2a1aaa6965
commit
3a24e0545d
1 changed files with 11 additions and 190 deletions
201
zeus.py
201
zeus.py
|
|
@ -1,10 +1,8 @@
|
|||
#!/usr/bin/env python
|
||||
|
||||
import os
|
||||
import io
|
||||
import time
|
||||
import shlex
|
||||
import optparse
|
||||
import warnings
|
||||
import subprocess
|
||||
|
||||
|
|
@ -12,9 +10,8 @@ from var import blackwidow
|
|||
from var.search import selenium_search
|
||||
from var.auto_issue.github import request_issue_creation
|
||||
from lib.header_check import main_header_check
|
||||
from lib.attacks.nmap_scan.nmap_opts import NMAP_API_OPTS
|
||||
from lib.attacks.sqlmap_scan.sqlmap_opts import SQLMAP_API_OPTIONS
|
||||
|
||||
from lib.core.parse import ZeusParser
|
||||
from lib.core.errors import (
|
||||
InvalidInputProvided,
|
||||
InvalidProxyType
|
||||
|
|
@ -30,7 +27,6 @@ from lib.core.settings import (
|
|||
set_color,
|
||||
get_latest_log_file,
|
||||
get_random_dork,
|
||||
update_zeus,
|
||||
fix_log_file,
|
||||
config_headers,
|
||||
config_search_engine,
|
||||
|
|
@ -38,10 +34,7 @@ from lib.core.settings import (
|
|||
run_attacks,
|
||||
CURRENT_LOG_FILE_PATH,
|
||||
SPIDER_LOG_PATH,
|
||||
VERSION_STRING,
|
||||
URL_REGEX, URL_QUERY_REGEX,
|
||||
NMAP_MAN_PAGE_URL,
|
||||
SQLMAP_MAN_PAGE_URL,
|
||||
URL_LOG_PATH,
|
||||
BANNER
|
||||
)
|
||||
|
|
@ -50,134 +43,9 @@ warnings.simplefilter("ignore")
|
|||
|
||||
if __name__ == "__main__":
|
||||
|
||||
parser = optparse.OptionParser(usage="{} -d|r|l|f|b| DORK|FILE|URL [ATTACKS] [--OPTS]".format(
|
||||
os.path.basename(__file__)
|
||||
))
|
||||
opt = ZeusParser.cmd_parser()
|
||||
|
||||
# mandatory options
|
||||
mandatory = optparse.OptionGroup(parser, "Mandatory Options",
|
||||
"These options have to be used in order for Zeus to run")
|
||||
mandatory.add_option("-d", "--dork", dest="dorkToUse", metavar="DORK",
|
||||
help="Specify a singular Google dork to use for queries")
|
||||
mandatory.add_option("-l", "--dork-list", dest="dorkFileToUse", metavar="FILE-PATH",
|
||||
help="Specify a file full of dorks to run through"),
|
||||
mandatory.add_option("-r", "--rand-dork", dest="useRandomDork", action="store_true",
|
||||
help="Use a random dork from the etc/dorks.txt file to perform the scan")
|
||||
mandatory.add_option("-b", "--blackwidow", dest="spiderWebSite", metavar="URL",
|
||||
help="Spider a single webpage for all available URL's")
|
||||
mandatory.add_option("-f", "--url-file", dest="fileToEnumerate", metavar="FILE-PATH",
|
||||
help="Run an attack on URL's in a given file")
|
||||
|
||||
# attack options
|
||||
attacks = optparse.OptionGroup(parser, "Attack arguments",
|
||||
"These arguments will give you the choice on how you want to check the websites")
|
||||
attacks.add_option("-s", "--sqli", dest="runSqliScan", action="store_true",
|
||||
help="Run a Sqlmap SQLi scan on the discovered URL's")
|
||||
attacks.add_option("-p", "--port-scan", dest="runPortScan", action="store_true",
|
||||
help="Run a Nmap port scan on the discovered URL's")
|
||||
attacks.add_option("-a", "--admin-panel", dest="adminPanelFinder", action="store_true",
|
||||
help="Search for the websites admin panel")
|
||||
attacks.add_option("-x", "--xss-scan", dest="runXssScan", action="store_true",
|
||||
help="Run an XSS scan on the found URL's")
|
||||
attacks.add_option("-w", "--whois-lookup", dest="performWhoisLookup", action="store_true",
|
||||
help="Perform a WhoIs lookup on the provided domain")
|
||||
attacks.add_option("-c", "--clickjacking", dest="performClickjackingScan", action="store_true",
|
||||
help="Perform a clickjacking scan on a provided URL")
|
||||
attacks.add_option("-g", "--github-search", dest="searchGithub", action="store_true",
|
||||
help="Perform a Github Gist search for any information on the found websites")
|
||||
attacks.add_option("-P", "--pgp", dest="pgpLookup", action="store_true",
|
||||
help="Perform a PGP public key lookup on the found URLs")
|
||||
attacks.add_option("--sqlmap-args", dest="sqlmapArguments", metavar="SQLMAP-ARGS",
|
||||
help="Pass the arguments to send to the sqlmap API within quotes & "
|
||||
"separated by a comma. IE 'dbms mysql, verbose 3, level 5'")
|
||||
attacks.add_option("--sqlmap-conf", dest="sqlmapConfigFile", metavar="CONFIG-FILE-PATH",
|
||||
help="Pass a configuration file that contains the sqlmap arguments")
|
||||
attacks.add_option("--nmap-args", dest="nmapArguments", metavar="NMAP-ARGS",
|
||||
help="Pass the arguments to send to the nmap API within quotes & "
|
||||
"separated by a pipe. IE '-O|-p 445, 1080'")
|
||||
attacks.add_option("--show-sqlmap", dest="showSqlmapArguments", action="store_true",
|
||||
help="Show the arguments that the sqlmap API understands")
|
||||
attacks.add_option("--show-nmap", dest="showNmapArgs", action="store_true",
|
||||
help="Show the arguments that nmap understands")
|
||||
attacks.add_option("--show-possibles", dest="showAllConnections", action="store_true",
|
||||
help="Show all connections made during the admin panel search")
|
||||
attacks.add_option("--tamper", dest="tamperXssPayloads", metavar="TAMPER-SCRIPT",
|
||||
help="Send the XSS payloads through tampering before sending to the target")
|
||||
attacks.add_option("--thread", dest="threadPanels", action="store_true",
|
||||
help="Run multiple threads on functions that support multi-threading")
|
||||
attacks.add_option("--auto", dest="autoStartSqlmap", action="store_true",
|
||||
help="Automatically start the sqlmap API (or at least try to)")
|
||||
|
||||
# search engine options
|
||||
engines = optparse.OptionGroup(parser, "Search engine arguments",
|
||||
"Arguments to change the search engine used (default is Google)")
|
||||
engines.add_option("-D", "--search-engine-ddg", dest="useDDG", action="store_true",
|
||||
help="Use DuckDuckGo as the search engine")
|
||||
engines.add_option("-B", "--search-engine-bing", dest="useBing", action="store_true",
|
||||
help="Use Bing as the search engine")
|
||||
engines.add_option("-A", "--search-engine-aol", dest="useAOL", action="store_true",
|
||||
help="Use AOL as the search engine")
|
||||
|
||||
# arguments to edit your search patterns
|
||||
search_items = optparse.OptionGroup(parser, "Search options",
|
||||
"Arguments that will control the search criteria")
|
||||
search_items.add_option("-L", "--links", dest="amountToSearch", type=int, metavar="HOW-MANY-LINKS",
|
||||
help="Specify how many links to try and search on Google")
|
||||
search_items.add_option("-M", "--multi", dest="searchMultiplePages", action="store_true",
|
||||
help="Search multiple pages of Google")
|
||||
search_items.add_option("-E", "--exclude-none", dest="noExclude", action="store_true",
|
||||
help="Do not exclude URLs because they do not have a GET(query) parameter in them")
|
||||
search_items.add_option("-W", "--webcache", dest="parseWebcache", action="store_true",
|
||||
help="Parse webcache URLs for the redirect in them")
|
||||
search_items.add_option("--x-forward", dest="forwardedForRandomIP", action="store_true",
|
||||
help="Add a header called 'X-Forwarded-For' with three random IP addresses")
|
||||
search_items.add_option("--time-sec", dest="controlTimeout", metavar="SECONDS", type=int,
|
||||
help="Control the sleep and timeout times in relevant situations")
|
||||
|
||||
# obfuscation options
|
||||
anon = optparse.OptionGroup(parser, "Anonymity arguments",
|
||||
"Arguments that help with anonymity and hiding identity")
|
||||
anon.add_option("--proxy", dest="proxyConfig", metavar="PROXY-STRING",
|
||||
help="Use a proxy to do the scraping, will not auto configure to the API's")
|
||||
anon.add_option("--proxy-file", dest="proxyFileRand", metavar="FILE-PATH",
|
||||
help="Grab a random proxy from a given file of proxies")
|
||||
anon.add_option("--random-agent", dest="useRandomAgent", action="store_true",
|
||||
help="Use a random user-agent from the etc/agents.txt file")
|
||||
anon.add_option("--agent", dest="usePersonalAgent", metavar="USER-AGENT",
|
||||
help="Use your own personal user-agent"),
|
||||
anon.add_option("--tor", dest="useTor", action="store_true",
|
||||
help="Use Tor connection as the proxy and set the firefox browser settings to mimic Tor")
|
||||
|
||||
# miscellaneous options
|
||||
misc = optparse.OptionGroup(parser, "Misc Options",
|
||||
"These options affect how the program will run")
|
||||
misc.add_option("--verbose", dest="runInVerbose", action="store_true",
|
||||
help="Run the application in verbose mode (more output)")
|
||||
misc.add_option("--batch", dest="runInBatch", action="store_true",
|
||||
help="Skip the questions and run in default batch mode")
|
||||
misc.add_option("--update", dest="updateZeus", action="store_true",
|
||||
help="Update to the latest development version")
|
||||
misc.add_option("--hide", dest="hideBanner", action="store_true",
|
||||
help="Hide the banner during running")
|
||||
misc.add_option("--version", dest="showCurrentVersion", action="store_true",
|
||||
help="Show the current version and exit")
|
||||
misc.add_option("-T", "--x-threads", dest="amountOfThreads", metavar="THREAD-AMOUNT", type=int,
|
||||
help="Specify how many threads you want to pass")
|
||||
misc.add_option("--show-success", dest="showSuccessRate", action="store_true",
|
||||
help="Calculate the dorks success rate and output the calculation in human readable form")
|
||||
|
||||
parser.add_option_group(mandatory)
|
||||
parser.add_option_group(attacks)
|
||||
parser.add_option_group(search_items)
|
||||
parser.add_option_group(anon)
|
||||
parser.add_option_group(engines)
|
||||
parser.add_option_group(misc)
|
||||
|
||||
opt, _ = parser.parse_args()
|
||||
|
||||
if opt.showCurrentVersion:
|
||||
print(VERSION_STRING)
|
||||
exit(0)
|
||||
ZeusParser().single_show_args(opt)
|
||||
|
||||
# run the setup on the program
|
||||
setup(verbose=opt.runInVerbose)
|
||||
|
|
@ -187,51 +55,6 @@ if __name__ == "__main__":
|
|||
|
||||
start_up()
|
||||
|
||||
if opt.showSqlmapArguments:
|
||||
logger.info(set_color(
|
||||
"there are a total of {} arguments understood by sqlmap API, "
|
||||
"they include:".format(len(SQLMAP_API_OPTIONS))
|
||||
))
|
||||
print("\n")
|
||||
for arg in SQLMAP_API_OPTIONS:
|
||||
print(
|
||||
"[*] {}".format(arg)
|
||||
)
|
||||
print("\n")
|
||||
logger.info(set_color(
|
||||
"for more information about sqlmap arguments, see here '{}'...".format(
|
||||
SQLMAP_MAN_PAGE_URL
|
||||
)
|
||||
))
|
||||
shutdown()
|
||||
|
||||
if opt.showNmapArgs:
|
||||
logger.info(set_color(
|
||||
"there are a total of {} arguments understood by nmap, they include:".format(
|
||||
len(NMAP_API_OPTS)
|
||||
)
|
||||
))
|
||||
print("\n")
|
||||
for arg in NMAP_API_OPTS:
|
||||
print(
|
||||
"[*] {}".format(arg)
|
||||
)
|
||||
print("\n")
|
||||
logger.info(set_color(
|
||||
"for more information on what the arguments do please see here '{}'...".format(
|
||||
NMAP_MAN_PAGE_URL
|
||||
)
|
||||
))
|
||||
shutdown()
|
||||
|
||||
# update the program
|
||||
if opt.updateZeus:
|
||||
logger.info(set_color(
|
||||
"update in progress..."
|
||||
))
|
||||
update_zeus()
|
||||
shutdown()
|
||||
|
||||
if opt.runInVerbose:
|
||||
being_run = find_running_opts(opt)
|
||||
logger.debug(set_color(
|
||||
|
|
@ -285,11 +108,13 @@ if __name__ == "__main__":
|
|||
), level=25
|
||||
))
|
||||
logger.info(set_color(
|
||||
"checking for HTTP headers..."
|
||||
"fetching target meta-data..."
|
||||
))
|
||||
main_header_check(
|
||||
url, verbose=opt.runInVerbose, agent=agent_to_use,
|
||||
proxy=proxy_to_use, xforward=opt.forwardedForRandomIP
|
||||
proxy=proxy_to_use, xforward=opt.forwardedForRandomIP,
|
||||
identify_plugins=opt.identifyPlugin, identify_waf=opt.identifyProtection,
|
||||
show_description=opt.showPluginDescription
|
||||
)
|
||||
run_attacks(
|
||||
url.strip(),
|
||||
|
|
@ -331,16 +156,17 @@ if __name__ == "__main__":
|
|||
show_success=opt.showSuccessRate
|
||||
)
|
||||
except InvalidProxyType:
|
||||
supported_proxy_types = ["socks5", "socks4", "https", "http"]
|
||||
supported_proxy_types = ("socks5", "socks4", "https", "http")
|
||||
logger.fatal(set_color(
|
||||
"the provided proxy is not valid, specify the protocol and try again, supported "
|
||||
"proxy protocols are {} (IE socks5://127.0.0.1:9050)...".format(", ".join(supported_proxy_types)), level=50
|
||||
"proxy protocols are {} (IE socks5://127.0.0.1:9050)...".format(
|
||||
", ".join(list(supported_proxy_types))), level=50
|
||||
))
|
||||
except Exception as e:
|
||||
if "Permission denied:" in str(e):
|
||||
logger.fatal(set_color(
|
||||
"your permissions are not allowing Zeus to run, "
|
||||
"try running me with sudo...", level=50
|
||||
"try running Zeus with sudo...", level=50
|
||||
))
|
||||
shutdown()
|
||||
else:
|
||||
|
|
@ -394,11 +220,6 @@ if __name__ == "__main__":
|
|||
logger.fatal(set_color(
|
||||
"failed to connect to search engine...".format(e), level=50
|
||||
))
|
||||
elif "Error 503" in str(e):
|
||||
logger.fatal(set_color(
|
||||
"Google has blocked your IP address from doing anymore searches via API, "
|
||||
"you can still search using headless browsers (-d <DORK>)...", level=50
|
||||
))
|
||||
else:
|
||||
logger.exception(set_color(
|
||||
"failed with unexpected error '{}'...".format(e), level=50
|
||||
|
|
|
|||
Loading…
Reference in a new issue