From a17b2745d97843d9e693bba0647d61a634bff4b6 Mon Sep 17 00:00:00 2001 From: ekultek Date: Tue, 17 Oct 2017 15:12:32 -0500 Subject: [PATCH] must pass a checksum verification before you can create a github issue --- etc/checksum/md5sum.md5 | 36 ++---------------------------------- lib/core/settings.py | 14 +++++++++++++- var/auto_issue/github.py | 7 +++++++ 3 files changed, 22 insertions(+), 35 deletions(-) diff --git a/etc/checksum/md5sum.md5 b/etc/checksum/md5sum.md5 index dfa85aa..d192a1b 100644 --- a/etc/checksum/md5sum.md5 +++ b/etc/checksum/md5sum.md5 @@ -1,4 +1,3 @@ -caa0444d437bc23ae47436e87e868e3e ./README.md e6c13a69a5290cdb1a8e5e1c4dd19b7d ./requirements.txt 5a7b2d95ee736b8781ada9782598ba60 ./zeus.py 6ad5f22ec4a6f8324bfb1b01ab6d51ec ./etc/scripts/cleanup.sh @@ -8,15 +7,7 @@ e6c13a69a5290cdb1a8e5e1c4dd19b7d ./requirements.txt b0e9a64654947e53b8631a9b84f1df97 ./etc/dorks.txt 8fc2e244d69f0a38c2d7cee8da211cbf ./etc/xss_payloads.txt d41d8cd98f00b204e9800998ecf8427e ./bin/__init__.py -41a2765efe9b3537feacbb7fe9d17029 ./bin/unzip_gecko.pyc feea6218ad0b502f050542378d63cc65 ./bin/unzip_gecko.py -183c08e232bf29fad8cc59578e82799a ./bin/__init__.pyc -dc1eb4ebe0f372af48b5a9c107ebc68d ./bin/drivers/geckodriver-v0.18.0-linux32.tar.gz -be18faeea6e7db9db6990d8667e2298f ./bin/drivers/geckodriver-v0.17.0-linux64.tar.gz -79b1a158f96d29942a111c0905f1c807 ./bin/drivers/geckodriver-v0.17.0-linux32.tar.gz -ca6935a72fd0527d15a78a17a35e56e8 ./bin/drivers/geckodriver-v0.19.0-linux64.tar.gz -4ccb56fb3700005c9f9188f84152f21a ./bin/drivers/geckodriver-v0.18.0-linux64.tar.gz -07cd383c8aef8ea5ef194a506141afd6 ./bin/drivers/geckodriver-v0.19.0-linux32.tar.gz 9a3eea24ffb08eaa221eb3e951e9e7c2 ./lib/tamper_scripts/obfuscateordinal_encode.py 10bf1bc4ef0287d31633148fab557e8a ./lib/tamper_scripts/uppercase_encode.py 99f284510464fcec513b60cb8f47f8f0 ./lib/tamper_scripts/hex_encode.py @@ -34,41 +25,18 @@ d41d8cd98f00b204e9800998ecf8427e ./lib/__init__.py d41d8cd98f00b204e9800998ecf8427e ./lib/attacks/__init__.py 6eddc0714ba922d750ab080f33b5bfd2 ./lib/attacks/sqlmap_scan/__init__.py 5e5bb575014ebe613db6bf671d008cf8 ./lib/attacks/sqlmap_scan/sqlmap_opts.py -a9abaae1f2172605a876c0e05e765f04 ./lib/attacks/sqlmap_scan/__init__.pyc -acdf89d7a72e77aba459c3cee54b620b ./lib/attacks/sqlmap_scan/sqlmap_opts.pyc fc11145007c1c3f47cbda44ced93e73f ./lib/attacks/admin_panel_finder/__init__.py -bcd962f2e4370370c94ce75d4e2ca995 ./lib/attacks/admin_panel_finder/__init__.pyc -9fe469347a594e19bd31b8101bfb6e20 ./lib/attacks/__init__.pyc 23c1e5e934029f9acc89d2c95e7748e7 ./lib/attacks/xss_scan/__init__.py -9e8f845b442b6ba6e339ee8c898c1cd9 ./lib/attacks/xss_scan/__init__.pyc 7870fc3ce4808b5c57dc32e9b84a90b3 ./lib/attacks/nmap_scan/__init__.py 216999fa0e84866d5c1d96d5676034e4 ./lib/attacks/nmap_scan/nmap_opts.py -d61985cd8a65348dc111ee1d07eaecec ./lib/attacks/nmap_scan/__init__.pyc -f1b62adcf20f295b463527aae2d2d722 ./lib/attacks/nmap_scan/nmap_opts.pyc c5ebb0c56c9ae3b9a72a14e3f05afa16 ./lib/attacks/intel_me/__init__.py -180eadad41b985abd727184843048a40 ./lib/attacks/intel_me/__init__.pyc -6e2342c26745e1b678f8691288803a24 ./lib/__init__.pyc 1faa2b5dfad6eb538bbfe42942d2a9da ./lib/core/errors.py d41d8cd98f00b204e9800998ecf8427e ./lib/core/__init__.py -14e6c06c3fef11117fa5e754b94e879a ./lib/core/settings.py -d2f5a36327e30cb3b63ef49988fa8f99 ./lib/core/errors.pyc -7c228436b888452938928b660348564e ./lib/core/settings.pyc -967a3b60306f9cd602ccb5dfce49030a ./lib/core/__init__.pyc -ddae89d6734be3518a80d09db0c02868 ./var/google_search/search.pyc +41698674b4f695db0dd7db61abf1161c ./lib/core/settings.py d41d8cd98f00b204e9800998ecf8427e ./var/google_search/__init__.py e5457ee2e54bb4f4f823367818694596 ./var/google_search/search.py -7b6e69a65f83df2b7a485133c132f986 ./var/google_search/__init__.pyc d41d8cd98f00b204e9800998ecf8427e ./var/__init__.py 66b11aa388ea909de7b212341259a318 ./var/auto_issue/oauth d41d8cd98f00b204e9800998ecf8427e ./var/auto_issue/__init__.py -2ae9dbc7ddf3cff3ecc348be3ba5b8b6 ./var/auto_issue/github.pyc -1636f4a832c924f25d323689e119612e ./var/auto_issue/__init__.pyc -f388ba77f53551e1a4ff9dbe45e3cf27 ./var/auto_issue/github.py +5048edbe9ca4a281bc9b9fe27a4539a4 ./var/auto_issue/github.py a83bf6c450035a733fa81a46c16fdd2b ./var/blackwidow/__init__.py -029dd130b270bdcc43918f2643064e63 ./var/blackwidow/__init__.pyc -1e06bed60866af1c5ede80d77e21c56d ./var/__init__.pyc -3bd1097ac6645f6fbb3a8fa6b07002b3 ./.github/CONTRIBUTING.md -1d4d81f6661524558d4f9f3d517fa7fc ./.github/LICENSE.md -50570f0932047fa6b567c46df374ec90 ./.github/CODE_OF_CONDUCT.md -3b80f55a0b161769c07292bbec686641 ./.github/ISSUE_TEMPLATE.md -096eda44c0f2e503f347b64a5f300d67 ./.gitignore diff --git a/lib/core/settings.py b/lib/core/settings.py index cd626e2..9a4db12 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -24,7 +24,7 @@ except NameError: # clone link CLONE = "https://github.com/ekultek/zeus-scanner.git" # current version -VERSION = "1.0.52" +VERSION = "1.0.53" # colors to output depending on the version VERSION_TYPE_COLORS = {"dev": 33, "stable": 92, "other": 30} # version string formatting @@ -53,6 +53,8 @@ DEFAULT_USER_AGENT = "Zeus-Scanner(v{})::Python->v{}.{}".format( URL_QUERY_REGEX = re.compile(r"(.*)[?|#](.*){1}\=(.*)") # regex to recognize a URL URL_REGEX = re.compile(r"((https?):((//)|(\\\\))+([\w\d:#@%/;$()~_?\+-=\\\.&](#!)?)*)") +# path to the checksum +CHECKSUM_PATH = "{}/etc/checksum/md5sum.md5".format(os.getcwd()) # geckodriver version information path, grabs the file that was installed on your system GECKO_VERSION_INFO_PATH = "{}/bin/version_info".format(os.getcwd()) # attempt to fix the program install error @@ -484,3 +486,13 @@ def config_headers(**kwargs): else: agent = DEFAULT_USER_AGENT return proxy_retval, agent + + +def get_md5sum(url="https://raw.githubusercontent.com/Ekultek/Zeus-Scanner/master/etc/checksum/md5sum.md5"): + """ + compare the checksums to post an issue + """ + current_checksum = open(CHECKSUM_PATH).read() + posted_checksum = requests.get(url).content + if current_checksum == posted_checksum: + return True diff --git a/var/auto_issue/github.py b/var/auto_issue/github.py index 8b1270b..83f7264 100644 --- a/var/auto_issue/github.py +++ b/var/auto_issue/github.py @@ -29,6 +29,13 @@ def decode(n, token): def request_issue_creation(): + if not lib.core.settings.get_md5sum(): + lib.core.settings.logger.fatal(lib.core.settings.set_color( + "it appears that your checksums did not match, therefore it is assumed " + "that you have edited some of the code, issue request denied...", level=50 + )) + lib.core.settings.shutdown() + question = lib.core.settings.prompt( "would you like to create an anonymous issue and post it to Zeus's Github", opts="yN" )