From 3a24e0545d1923126a11d97edfb0669d133aa81a Mon Sep 17 00:00:00 2001 From: ekultek Date: Wed, 6 Dec 2017 09:38:41 -0600 Subject: [PATCH] moved the command line parsing to it's own class --- zeus.py | 201 ++++---------------------------------------------------- 1 file changed, 11 insertions(+), 190 deletions(-) diff --git a/zeus.py b/zeus.py index c432f33..5b38245 100755 --- a/zeus.py +++ b/zeus.py @@ -1,10 +1,8 @@ #!/usr/bin/env python -import os import io import time import shlex -import optparse import warnings import subprocess @@ -12,9 +10,8 @@ from var import blackwidow from var.search import selenium_search from var.auto_issue.github import request_issue_creation from lib.header_check import main_header_check -from lib.attacks.nmap_scan.nmap_opts import NMAP_API_OPTS -from lib.attacks.sqlmap_scan.sqlmap_opts import SQLMAP_API_OPTIONS +from lib.core.parse import ZeusParser from lib.core.errors import ( InvalidInputProvided, InvalidProxyType @@ -30,7 +27,6 @@ from lib.core.settings import ( set_color, get_latest_log_file, get_random_dork, - update_zeus, fix_log_file, config_headers, config_search_engine, @@ -38,10 +34,7 @@ from lib.core.settings import ( run_attacks, CURRENT_LOG_FILE_PATH, SPIDER_LOG_PATH, - VERSION_STRING, URL_REGEX, URL_QUERY_REGEX, - NMAP_MAN_PAGE_URL, - SQLMAP_MAN_PAGE_URL, URL_LOG_PATH, BANNER ) @@ -50,134 +43,9 @@ warnings.simplefilter("ignore") if __name__ == "__main__": - parser = optparse.OptionParser(usage="{} -d|r|l|f|b| DORK|FILE|URL [ATTACKS] [--OPTS]".format( - os.path.basename(__file__) - )) + opt = ZeusParser.cmd_parser() - # mandatory options - mandatory = optparse.OptionGroup(parser, "Mandatory Options", - "These options have to be used in order for Zeus to run") - mandatory.add_option("-d", "--dork", dest="dorkToUse", metavar="DORK", - help="Specify a singular Google dork to use for queries") - mandatory.add_option("-l", "--dork-list", dest="dorkFileToUse", metavar="FILE-PATH", - help="Specify a file full of dorks to run through"), - mandatory.add_option("-r", "--rand-dork", dest="useRandomDork", action="store_true", - help="Use a random dork from the etc/dorks.txt file to perform the scan") - mandatory.add_option("-b", "--blackwidow", dest="spiderWebSite", metavar="URL", - help="Spider a single webpage for all available URL's") - mandatory.add_option("-f", "--url-file", dest="fileToEnumerate", metavar="FILE-PATH", - help="Run an attack on URL's in a given file") - - # attack options - attacks = optparse.OptionGroup(parser, "Attack arguments", - "These arguments will give you the choice on how you want to check the websites") - attacks.add_option("-s", "--sqli", dest="runSqliScan", action="store_true", - help="Run a Sqlmap SQLi scan on the discovered URL's") - attacks.add_option("-p", "--port-scan", dest="runPortScan", action="store_true", - help="Run a Nmap port scan on the discovered URL's") - attacks.add_option("-a", "--admin-panel", dest="adminPanelFinder", action="store_true", - help="Search for the websites admin panel") - attacks.add_option("-x", "--xss-scan", dest="runXssScan", action="store_true", - help="Run an XSS scan on the found URL's") - attacks.add_option("-w", "--whois-lookup", dest="performWhoisLookup", action="store_true", - help="Perform a WhoIs lookup on the provided domain") - attacks.add_option("-c", "--clickjacking", dest="performClickjackingScan", action="store_true", - help="Perform a clickjacking scan on a provided URL") - attacks.add_option("-g", "--github-search", dest="searchGithub", action="store_true", - help="Perform a Github Gist search for any information on the found websites") - attacks.add_option("-P", "--pgp", dest="pgpLookup", action="store_true", - help="Perform a PGP public key lookup on the found URLs") - attacks.add_option("--sqlmap-args", dest="sqlmapArguments", metavar="SQLMAP-ARGS", - help="Pass the arguments to send to the sqlmap API within quotes & " - "separated by a comma. IE 'dbms mysql, verbose 3, level 5'") - attacks.add_option("--sqlmap-conf", dest="sqlmapConfigFile", metavar="CONFIG-FILE-PATH", - help="Pass a configuration file that contains the sqlmap arguments") - attacks.add_option("--nmap-args", dest="nmapArguments", metavar="NMAP-ARGS", - help="Pass the arguments to send to the nmap API within quotes & " - "separated by a pipe. IE '-O|-p 445, 1080'") - attacks.add_option("--show-sqlmap", dest="showSqlmapArguments", action="store_true", - help="Show the arguments that the sqlmap API understands") - attacks.add_option("--show-nmap", dest="showNmapArgs", action="store_true", - help="Show the arguments that nmap understands") - attacks.add_option("--show-possibles", dest="showAllConnections", action="store_true", - help="Show all connections made during the admin panel search") - attacks.add_option("--tamper", dest="tamperXssPayloads", metavar="TAMPER-SCRIPT", - help="Send the XSS payloads through tampering before sending to the target") - attacks.add_option("--thread", dest="threadPanels", action="store_true", - help="Run multiple threads on functions that support multi-threading") - attacks.add_option("--auto", dest="autoStartSqlmap", action="store_true", - help="Automatically start the sqlmap API (or at least try to)") - - # search engine options - engines = optparse.OptionGroup(parser, "Search engine arguments", - "Arguments to change the search engine used (default is Google)") - engines.add_option("-D", "--search-engine-ddg", dest="useDDG", action="store_true", - help="Use DuckDuckGo as the search engine") - engines.add_option("-B", "--search-engine-bing", dest="useBing", action="store_true", - help="Use Bing as the search engine") - engines.add_option("-A", "--search-engine-aol", dest="useAOL", action="store_true", - help="Use AOL as the search engine") - - # arguments to edit your search patterns - search_items = optparse.OptionGroup(parser, "Search options", - "Arguments that will control the search criteria") - search_items.add_option("-L", "--links", dest="amountToSearch", type=int, metavar="HOW-MANY-LINKS", - help="Specify how many links to try and search on Google") - search_items.add_option("-M", "--multi", dest="searchMultiplePages", action="store_true", - help="Search multiple pages of Google") - search_items.add_option("-E", "--exclude-none", dest="noExclude", action="store_true", - help="Do not exclude URLs because they do not have a GET(query) parameter in them") - search_items.add_option("-W", "--webcache", dest="parseWebcache", action="store_true", - help="Parse webcache URLs for the redirect in them") - search_items.add_option("--x-forward", dest="forwardedForRandomIP", action="store_true", - help="Add a header called 'X-Forwarded-For' with three random IP addresses") - search_items.add_option("--time-sec", dest="controlTimeout", metavar="SECONDS", type=int, - help="Control the sleep and timeout times in relevant situations") - - # obfuscation options - anon = optparse.OptionGroup(parser, "Anonymity arguments", - "Arguments that help with anonymity and hiding identity") - anon.add_option("--proxy", dest="proxyConfig", metavar="PROXY-STRING", - help="Use a proxy to do the scraping, will not auto configure to the API's") - anon.add_option("--proxy-file", dest="proxyFileRand", metavar="FILE-PATH", - help="Grab a random proxy from a given file of proxies") - anon.add_option("--random-agent", dest="useRandomAgent", action="store_true", - help="Use a random user-agent from the etc/agents.txt file") - anon.add_option("--agent", dest="usePersonalAgent", metavar="USER-AGENT", - help="Use your own personal user-agent"), - anon.add_option("--tor", dest="useTor", action="store_true", - help="Use Tor connection as the proxy and set the firefox browser settings to mimic Tor") - - # miscellaneous options - misc = optparse.OptionGroup(parser, "Misc Options", - "These options affect how the program will run") - misc.add_option("--verbose", dest="runInVerbose", action="store_true", - help="Run the application in verbose mode (more output)") - misc.add_option("--batch", dest="runInBatch", action="store_true", - help="Skip the questions and run in default batch mode") - misc.add_option("--update", dest="updateZeus", action="store_true", - help="Update to the latest development version") - misc.add_option("--hide", dest="hideBanner", action="store_true", - help="Hide the banner during running") - misc.add_option("--version", dest="showCurrentVersion", action="store_true", - help="Show the current version and exit") - misc.add_option("-T", "--x-threads", dest="amountOfThreads", metavar="THREAD-AMOUNT", type=int, - help="Specify how many threads you want to pass") - misc.add_option("--show-success", dest="showSuccessRate", action="store_true", - help="Calculate the dorks success rate and output the calculation in human readable form") - - parser.add_option_group(mandatory) - parser.add_option_group(attacks) - parser.add_option_group(search_items) - parser.add_option_group(anon) - parser.add_option_group(engines) - parser.add_option_group(misc) - - opt, _ = parser.parse_args() - - if opt.showCurrentVersion: - print(VERSION_STRING) - exit(0) + ZeusParser().single_show_args(opt) # run the setup on the program setup(verbose=opt.runInVerbose) @@ -187,51 +55,6 @@ if __name__ == "__main__": start_up() - if opt.showSqlmapArguments: - logger.info(set_color( - "there are a total of {} arguments understood by sqlmap API, " - "they include:".format(len(SQLMAP_API_OPTIONS)) - )) - print("\n") - for arg in SQLMAP_API_OPTIONS: - print( - "[*] {}".format(arg) - ) - print("\n") - logger.info(set_color( - "for more information about sqlmap arguments, see here '{}'...".format( - SQLMAP_MAN_PAGE_URL - ) - )) - shutdown() - - if opt.showNmapArgs: - logger.info(set_color( - "there are a total of {} arguments understood by nmap, they include:".format( - len(NMAP_API_OPTS) - ) - )) - print("\n") - for arg in NMAP_API_OPTS: - print( - "[*] {}".format(arg) - ) - print("\n") - logger.info(set_color( - "for more information on what the arguments do please see here '{}'...".format( - NMAP_MAN_PAGE_URL - ) - )) - shutdown() - - # update the program - if opt.updateZeus: - logger.info(set_color( - "update in progress..." - )) - update_zeus() - shutdown() - if opt.runInVerbose: being_run = find_running_opts(opt) logger.debug(set_color( @@ -285,11 +108,13 @@ if __name__ == "__main__": ), level=25 )) logger.info(set_color( - "checking for HTTP headers..." + "fetching target meta-data..." )) main_header_check( url, verbose=opt.runInVerbose, agent=agent_to_use, - proxy=proxy_to_use, xforward=opt.forwardedForRandomIP + proxy=proxy_to_use, xforward=opt.forwardedForRandomIP, + identify_plugins=opt.identifyPlugin, identify_waf=opt.identifyProtection, + show_description=opt.showPluginDescription ) run_attacks( url.strip(), @@ -331,16 +156,17 @@ if __name__ == "__main__": show_success=opt.showSuccessRate ) except InvalidProxyType: - supported_proxy_types = ["socks5", "socks4", "https", "http"] + supported_proxy_types = ("socks5", "socks4", "https", "http") logger.fatal(set_color( "the provided proxy is not valid, specify the protocol and try again, supported " - "proxy protocols are {} (IE socks5://127.0.0.1:9050)...".format(", ".join(supported_proxy_types)), level=50 + "proxy protocols are {} (IE socks5://127.0.0.1:9050)...".format( + ", ".join(list(supported_proxy_types))), level=50 )) except Exception as e: if "Permission denied:" in str(e): logger.fatal(set_color( "your permissions are not allowing Zeus to run, " - "try running me with sudo...", level=50 + "try running Zeus with sudo...", level=50 )) shutdown() else: @@ -394,11 +220,6 @@ if __name__ == "__main__": logger.fatal(set_color( "failed to connect to search engine...".format(e), level=50 )) - elif "Error 503" in str(e): - logger.fatal(set_color( - "Google has blocked your IP address from doing anymore searches via API, " - "you can still search using headless browsers (-d )...", level=50 - )) else: logger.exception(set_color( "failed with unexpected error '{}'...".format(e), level=50