mirror of
https://github.com/Ekultek/Zeus-Scanner.git
synced 2026-03-11 08:55:51 +00:00
created a whois lookup search. Will either display it in human readable form with the correct flags, or save the found information to a log file
This commit is contained in:
parent
d813e70ac1
commit
e2287391c3
11 changed files with 103212 additions and 11 deletions
4
.gitignore
vendored
4
.gitignore
vendored
|
|
@ -5,4 +5,6 @@ geckodriver.log
|
|||
bin/executed.txt
|
||||
bin/paths
|
||||
bin/version_info
|
||||
checksum.txt
|
||||
checksum.txt
|
||||
etc/ip_resolvers.txt
|
||||
etc/sub_names.txt
|
||||
1
etc/auths/git_auth
Normal file
1
etc/auths/git_auth
Normal file
|
|
@ -0,0 +1 @@
|
|||
Vm0wd2VHUXhTWGxTV0d4V1YwZG9jRlZ0TVc5V1JteHlWMjVrVmxKc2NEQlVWbU0xVmpBeFYySkVUbHBXVmxwUVZteFZlRll5VGtsaApSbHBYWld4YVRWWnJaRFJaVjAxNFZHNVdhZ3BTYldodlZGWmFjMDB4WkZkWGJVWmFWbXh3V0ZZeU5VdFhRWEJwVWpKb1dsWlVRbGRUCk1WWlhWMjVPVjJKVldsVlpiRnBIVGtaWmVXVkdaRlprTTBKd1ZXcEtiMWRXWkZoa1JtUnJDazFYVWxoWGExcHZZVEZLYzJOR1FsZGkKV0ZJelZqRmFWbVZYVWtoUFYyaHJUVEJLVlZadGRHdE9SbHBYVjJ4b2JGSnRVbkpEYXpGelYydG9WMDF1VW5aV1IzaHJVMFpXZFZGcwpjR2tLVW01Q1NWWkdVa2RWTWsxNFZtNVNVMkpJUWxkV01GWkxWbFphUjFWcmRHbE5WbHBJVjJ0YWExbFdTa2RUYlVaRVlrWnNNMVJzCldtOVdNVm8yVm10NFdGWnNjRXhhUmxwSFkyczVWd3BYYld0TFZXMTBkMU5XV25OVmEyUlhUVlZzTkZadGVITlpWa3B6VTI1S1ZWWXoKUW5WVWJGcEdaVlpzTm1KR1JsWldlbWMxVVRKak9WQlJiejBLCg==:9
|
||||
1
etc/auths/whois_auth
Normal file
1
etc/auths/whois_auth
Normal file
|
|
@ -0,0 +1 @@
|
|||
Vm0wd2QyUXlWa1pOVldScFVtMVNWRll3WkZOVlJscHpWMjVrVlUxV2NEQlVWbU0xWVdzeFYxWnFUbGRpVkVaSVZteFZlRll5VGtWU2JIQk9VakpvVVZadGVHdFRNVTVJVm10a2FsSnVRazlWYlRWRFZWWmtWMVp0UmxSaVZrWTFWVEp3WVZaSFNraGhSemxWVm14YU0xVnNXbUZqVms1WllVWlNUbFpZUWpaV1ZFa3hVakZXZEZOc1dsaGlSa3BoV1ZSR2QwMHhXbGRYYlhScVRWWndNRlZ0ZUd0VWJGcHpZMFJhVjFadFVUQldha1pUWXpGT2NsWnNTbGRTTTAwMQ==:9
|
||||
|
|
@ -1,13 +1,23 @@
|
|||
d41d8cd98f00b204e9800998ecf8427e ./checksum.txt
|
||||
caa0444d437bc23ae47436e87e868e3e ./README.md
|
||||
e6c13a69a5290cdb1a8e5e1c4dd19b7d ./requirements.txt
|
||||
bce3c2e4bac9bf712125e758364cc65c ./zeus.py
|
||||
29799e62b65dc912792ba7ac4f3cdeb2 ./zeus.py
|
||||
6ad5f22ec4a6f8324bfb1b01ab6d51ec ./etc/scripts/cleanup.sh
|
||||
155c9482f690f1482f324a7ffd8b8098 ./etc/scripts/fix_pie.sh
|
||||
642a77905d8bb4e5533e0e9c2137c0fa ./etc/agents.txt
|
||||
66b11aa388ea909de7b212341259a318 ./etc/auths/git_auth
|
||||
8f686b05c5c5dfc02f0fcaa7ebc8677c ./etc/auths/whois_auth
|
||||
82cc68f46539d0255f7ce14cd86cd49b ./etc/link_ext.txt
|
||||
75b485c7a5c6daa22a65794da4109ddc ./etc/dorks.txt
|
||||
8fc2e244d69f0a38c2d7cee8da211cbf ./etc/xss_payloads.txt
|
||||
d41d8cd98f00b204e9800998ecf8427e ./bin/__init__.py
|
||||
f2f852c1d73ac75f3caff2c9fcd36ac5 ./bin/unzip_gecko.py
|
||||
a19ac607db04a68fdbfc81d6c5a000d1 ./bin/unzip_gecko.py
|
||||
dc1eb4ebe0f372af48b5a9c107ebc68d ./bin/drivers/geckodriver-v0.18.0-linux32.tar.gz
|
||||
be18faeea6e7db9db6990d8667e2298f ./bin/drivers/geckodriver-v0.17.0-linux64.tar.gz
|
||||
79b1a158f96d29942a111c0905f1c807 ./bin/drivers/geckodriver-v0.17.0-linux32.tar.gz
|
||||
ca6935a72fd0527d15a78a17a35e56e8 ./bin/drivers/geckodriver-v0.19.0-linux64.tar.gz
|
||||
4ccb56fb3700005c9f9188f84152f21a ./bin/drivers/geckodriver-v0.18.0-linux64.tar.gz
|
||||
07cd383c8aef8ea5ef194a506141afd6 ./bin/drivers/geckodriver-v0.19.0-linux32.tar.gz
|
||||
9a3eea24ffb08eaa221eb3e951e9e7c2 ./lib/tamper_scripts/obfuscateordinal_encode.py
|
||||
10bf1bc4ef0287d31633148fab557e8a ./lib/tamper_scripts/uppercase_encode.py
|
||||
99f284510464fcec513b60cb8f47f8f0 ./lib/tamper_scripts/hex_encode.py
|
||||
|
|
@ -25,6 +35,9 @@ d41d8cd98f00b204e9800998ecf8427e ./lib/__init__.py
|
|||
d41d8cd98f00b204e9800998ecf8427e ./lib/attacks/__init__.py
|
||||
6eddc0714ba922d750ab080f33b5bfd2 ./lib/attacks/sqlmap_scan/__init__.py
|
||||
5e5bb575014ebe613db6bf671d008cf8 ./lib/attacks/sqlmap_scan/sqlmap_opts.py
|
||||
d41d8cd98f00b204e9800998ecf8427e ./lib/attacks/whois_lookup/__init__.py
|
||||
9931efff89b0a4af28249c5937b29b26 ./lib/attacks/whois_lookup/whois.py
|
||||
f90f0aacbaba8a21011e68657e187ea4 ./lib/attacks/whois_lookup/__init__.pyc
|
||||
fc11145007c1c3f47cbda44ced93e73f ./lib/attacks/admin_panel_finder/__init__.py
|
||||
23c1e5e934029f9acc89d2c95e7748e7 ./lib/attacks/xss_scan/__init__.py
|
||||
7870fc3ce4808b5c57dc32e9b84a90b3 ./lib/attacks/nmap_scan/__init__.py
|
||||
|
|
@ -32,11 +45,16 @@ fc11145007c1c3f47cbda44ced93e73f ./lib/attacks/admin_panel_finder/__init__.py
|
|||
c5ebb0c56c9ae3b9a72a14e3f05afa16 ./lib/attacks/intel_me/__init__.py
|
||||
1faa2b5dfad6eb538bbfe42942d2a9da ./lib/core/errors.py
|
||||
d41d8cd98f00b204e9800998ecf8427e ./lib/core/__init__.py
|
||||
28df692d6ecc5d0888e8a63466666c5b ./lib/core/settings.py
|
||||
3384f68bbef53c38a0444508604acba9 ./lib/core/settings.py
|
||||
d41d8cd98f00b204e9800998ecf8427e ./var/google_search/__init__.py
|
||||
d28b1b648539106a488067b951a9dd7c ./var/google_search/search.py
|
||||
d41d8cd98f00b204e9800998ecf8427e ./var/__init__.py
|
||||
66b11aa388ea909de7b212341259a318 ./var/auto_issue/oauth
|
||||
d41d8cd98f00b204e9800998ecf8427e ./var/auto_issue/__init__.py
|
||||
5048edbe9ca4a281bc9b9fe27a4539a4 ./var/auto_issue/github.py
|
||||
4506850a02aa18e12bef4efeb760ad9e ./var/auto_issue/github.py
|
||||
a83bf6c450035a733fa81a46c16fdd2b ./var/blackwidow/__init__.py
|
||||
3bd1097ac6645f6fbb3a8fa6b07002b3 ./.github/CONTRIBUTING.md
|
||||
1d4d81f6661524558d4f9f3d517fa7fc ./.github/LICENSE.md
|
||||
50570f0932047fa6b567c46df374ec90 ./.github/CODE_OF_CONDUCT.md
|
||||
3b80f55a0b161769c07292bbec686641 ./.github/ISSUE_TEMPLATE.md
|
||||
baae8bbef0dec71131f5fd4e468ef2d8 ./.gitignore
|
||||
2014
etc/ip_resolvers.txt
Normal file
2014
etc/ip_resolvers.txt
Normal file
File diff suppressed because it is too large
Load diff
101010
etc/sub_names.txt
Normal file
101010
etc/sub_names.txt
Normal file
File diff suppressed because it is too large
Load diff
0
lib/attacks/whois_lookup/__init__.py
Normal file
0
lib/attacks/whois_lookup/__init__.py
Normal file
133
lib/attacks/whois_lookup/whois.py
Normal file
133
lib/attacks/whois_lookup/whois.py
Normal file
|
|
@ -0,0 +1,133 @@
|
|||
import os
|
||||
import json
|
||||
import urllib2
|
||||
|
||||
from base64 import b64decode
|
||||
|
||||
from lib.core.settings import (
|
||||
WHOIS_JSON_LINK,
|
||||
write_to_log_file,
|
||||
WHOIS_RESULTS_LOG_PATH,
|
||||
logger, set_color,
|
||||
replace_http
|
||||
)
|
||||
|
||||
|
||||
def __get_encoded_string(path="{}/etc/auths/whois_auth"):
|
||||
with open(path.format(os.getcwd())) as log:
|
||||
return log.read()
|
||||
|
||||
|
||||
def __get_n(encoded):
|
||||
return encoded.split(":")[-1]
|
||||
|
||||
|
||||
def __decode(encoded, n):
|
||||
token = encoded.split(":")[0]
|
||||
for _ in range(0, n):
|
||||
token = b64decode(token)
|
||||
return token
|
||||
|
||||
|
||||
def __get_token():
|
||||
encoded = __get_encoded_string()
|
||||
n = __get_n(encoded)
|
||||
token = __decode(encoded, int(n))
|
||||
return token
|
||||
|
||||
|
||||
def gather_raw_whois_info(domain):
|
||||
"""
|
||||
get the raw JSON data for from the whois API
|
||||
"""
|
||||
auth_headers = {
|
||||
"Content-Type": "application/json",
|
||||
"Authorization": "Token {}".format(__get_token()),
|
||||
}
|
||||
request = urllib2.Request(
|
||||
WHOIS_JSON_LINK.format(domain), headers=auth_headers
|
||||
)
|
||||
data = urllib2.urlopen(request).read()
|
||||
_json_data = json.loads(data)
|
||||
return _json_data
|
||||
|
||||
|
||||
def get_interesting(raw_json):
|
||||
"""
|
||||
return the interesting aspects of the whois lookup from the raw JSON data
|
||||
"""
|
||||
nameservers = raw_json["nameservers"]
|
||||
user_contact = raw_json["contacts"]
|
||||
admin_info = raw_json["contacts"]["admin"]
|
||||
reg_info = raw_json["registrar"]
|
||||
return nameservers, user_contact, admin_info, reg_info
|
||||
|
||||
|
||||
def human_readable_display(domain, interesting, raw, show_readable=False):
|
||||
if show_readable:
|
||||
contact_dict = dict(interesting[1])
|
||||
print(" |--[!] Domain: {} (organization '{}')".format(domain, contact_dict["owner"][0]["organization"]))
|
||||
print(" | |--[x] Found nameservers (total {})".format(len(interesting[0])))
|
||||
if len(interesting[0]) > 1:
|
||||
for i, server in enumerate(interesting[0], start=1):
|
||||
print(" | | |--[{}]--- {}".format(i, server))
|
||||
else:
|
||||
print(" | | |--{}".format("".join(interesting[0])))
|
||||
if contact_dict["owner"][0]["name"] is not None or "":
|
||||
print(" | |--[x] Contact name found: {}".format(contact_dict["owner"][0]["name"]))
|
||||
if contact_dict["owner"][0]["phone"] != "" or None:
|
||||
print(" | | |-- Phone number: {}".format(contact_dict["owner"][0]["phone"]))
|
||||
else:
|
||||
print(" | | |-- No phone number revealed")
|
||||
else:
|
||||
print(" [x] No contact owner revealed")
|
||||
if len(contact_dict["admin"]) > 0:
|
||||
print(" | |--[x] Total admins found {}".format(len(contact_dict["admin"])))
|
||||
for i, admin in enumerate(contact_dict["admin"]):
|
||||
print(" | | |--[{}]--- {}".format(i, admin))
|
||||
else:
|
||||
print(" | |--[x] No administrators revealed")
|
||||
return write_to_log_file(raw, WHOIS_RESULTS_LOG_PATH, "whois-log-{}.json")
|
||||
else:
|
||||
return write_to_log_file(raw, WHOIS_RESULTS_LOG_PATH, "whois-log-{}.json")
|
||||
|
||||
|
||||
def whois_lookup_main(domain, **kwargs):
|
||||
readable = kwargs.get("readable", False)
|
||||
verbose = kwargs.get("verbose", False)
|
||||
domain = replace_http(domain)
|
||||
logger.info(set_color(
|
||||
"performing WhoIs lookup on given domain '{}'...".format(domain)
|
||||
))
|
||||
raw_information = gather_raw_whois_info(domain)
|
||||
logger.info(set_color(
|
||||
"discovered raw information..."
|
||||
))
|
||||
logger.info(set_color(
|
||||
"gathering interesting information..."
|
||||
))
|
||||
interesting_data = get_interesting(raw_information)
|
||||
if readable:
|
||||
if verbose:
|
||||
for data in interesting_data:
|
||||
logger.debug(set_color(
|
||||
"found '{}'...".format(data), level=10
|
||||
))
|
||||
try:
|
||||
return human_readable_display(domain, interesting_data, raw_information, show_readable=True)
|
||||
except:
|
||||
logger.fatal(set_color(
|
||||
"unable to display any information from WhoIs lookup on domain '{}'...".format(domain), level=50
|
||||
))
|
||||
else:
|
||||
if verbose:
|
||||
for data in interesting_data:
|
||||
logger.debug(set_color(
|
||||
"found '{}'...".format(data), level=10
|
||||
))
|
||||
try:
|
||||
return human_readable_display(domain, interesting_data, raw_information)
|
||||
except:
|
||||
logger.fatal(set_color(
|
||||
"unable to find any information on '{}' from WhoIs lookup...".format(domain), level=50
|
||||
))
|
||||
|
|
@ -3,6 +3,7 @@ import io
|
|||
import re
|
||||
import sys
|
||||
import glob
|
||||
import json
|
||||
import time
|
||||
import difflib
|
||||
import logging
|
||||
|
|
@ -25,12 +26,13 @@ try:
|
|||
except NameError:
|
||||
raw_input = input # Python 3
|
||||
|
||||
|
||||
# get the master patch ID when a patch is pushed to the program
|
||||
PATCH_ID = str(subprocess.check_output(["git", "rev-parse", "origin/master"]))[:6]
|
||||
# clone link
|
||||
CLONE = "https://github.com/ekultek/zeus-scanner.git"
|
||||
# current version <major.minor.commit.patch ID>
|
||||
VERSION = "1.0.56.{}".format(PATCH_ID)
|
||||
VERSION = "1.0.57"
|
||||
# colors to output depending on the version
|
||||
VERSION_TYPE_COLORS = {"dev": 33, "stable": 92, "other": 30}
|
||||
# version string formatting
|
||||
|
|
@ -69,6 +71,7 @@ FIX_PROGRAM_INSTALL_PATH = "{}/etc/scripts/fix_pie.sh".format(os.getcwd())
|
|||
CLEANUP_TOOL_PATH = "{}/etc/scripts/cleanup.sh".format(os.getcwd())
|
||||
# paths to sqlmap and nmap
|
||||
TOOL_PATHS = "{}/bin/paths/path_config.ini".format(os.getcwd())
|
||||
WHOIS_RESULTS_LOG_PATH = "{}/log/whois".format(os.getcwd())
|
||||
# path to store robot.txt page in
|
||||
ROBOTS_PAGE_PATH = "{}/log/robots".format(os.getcwd())
|
||||
# URL's that are extracted from Google's ban URL
|
||||
|
|
@ -85,6 +88,8 @@ CURRENT_LOG_FILE_PATH = "{}/log".format(os.getcwd())
|
|||
NMAP_MAN_PAGE_URL = "https://nmap.org/book/man-briefoptions.html"
|
||||
# sqlmap's manual page for their options
|
||||
SQLMAP_MAN_PAGE_URL = "https://github.com/sqlmapproject/sqlmap/wiki/Usage"
|
||||
# whois API link
|
||||
WHOIS_JSON_LINK = "https://jsonwhoisapi.com/api/v1/whois?identifier={}"
|
||||
# holder for sqlmap API ID hashes, makes it so that they are all unique
|
||||
ALREADY_USED = set()
|
||||
# search engines that the application can use
|
||||
|
|
@ -423,6 +428,8 @@ def write_to_log_file(data_to_write, path, filename):
|
|||
for item in list(data_to_write):
|
||||
item = item.strip()
|
||||
log.write(str(item) + "\n")
|
||||
elif isinstance(data_to_write, dict):
|
||||
json.dump(data_to_write, log, sort_keys=True, indent=4)
|
||||
else:
|
||||
log.write(data_to_write + "\n")
|
||||
logger.info(set_color(
|
||||
|
|
@ -507,6 +514,9 @@ def get_md5sum(url="https://raw.githubusercontent.com/Ekultek/Zeus-Scanner/maste
|
|||
|
||||
|
||||
def create_identifier(chars=string.ascii_letters):
|
||||
"""
|
||||
create the identifier for your Github issue
|
||||
"""
|
||||
retval = []
|
||||
for _ in range(0, 7):
|
||||
retval.append(random.choice(chars))
|
||||
|
|
|
|||
|
|
@ -12,7 +12,7 @@ from base64 import b64decode
|
|||
import lib.core.settings
|
||||
|
||||
|
||||
def __get_encoded_string(filename="{}/var/auto_issue/oauth"):
|
||||
def __get_encoded_string(filename="{}/etc/auths/git_auth"):
|
||||
with open(filename.format(os.getcwd())) as data:
|
||||
return data.read()
|
||||
|
||||
|
|
|
|||
20
zeus.py
20
zeus.py
|
|
@ -18,6 +18,7 @@ from lib.attacks.admin_panel_finder import main
|
|||
from lib.attacks.xss_scan import main_xss
|
||||
from lib.attacks.nmap_scan.nmap_opts import NMAP_API_OPTS
|
||||
from lib.attacks.sqlmap_scan.sqlmap_opts import SQLMAP_API_OPTIONS
|
||||
from lib.attacks.whois_lookup.whois import whois_lookup_main
|
||||
|
||||
from lib.attacks import (
|
||||
nmap_scan,
|
||||
|
|
@ -82,6 +83,10 @@ if __name__ == "__main__":
|
|||
help="Search for the websites admin panel")
|
||||
attacks.add_option("-x", "--xss-scan", dest="runXssScan", action="store_true",
|
||||
help="Run an XSS scan on the found URL's")
|
||||
attacks.add_option("-w", "--whois-lookup", dest="performWhoisLookup", action="store_true",
|
||||
help="Perform a WhoIs lookup on the provided domain")
|
||||
attacks.add_option("--show-readable", dest="showReadableOutput", action="store_true",
|
||||
help="Show human readable output from the WhoIs lookup")
|
||||
attacks.add_option("--sqlmap-args", dest="sqlmapArguments", metavar="SQLMAP-ARGS",
|
||||
help="Pass the arguments to send to the sqlmap API within quotes & "
|
||||
"separated by a comma. IE 'dbms mysql, verbose 3, level 5'")
|
||||
|
|
@ -363,6 +368,7 @@ if __name__ == "__main__":
|
|||
xss = kwargs.get("xss", False)
|
||||
admin = kwargs.get("admin", False)
|
||||
verbose = kwargs.get("verbose", False)
|
||||
whois = kwargs.get("whois", False)
|
||||
batch = kwargs.get("batch", False)
|
||||
auto_start = kwargs.get("auto_start", False)
|
||||
|
||||
|
|
@ -371,7 +377,8 @@ if __name__ == "__main__":
|
|||
"port": opt.runPortScan,
|
||||
"xss": opt.runXssScan,
|
||||
"admin": opt.adminPanelFinder,
|
||||
"intel": opt.intelCheck
|
||||
"intel": opt.intelCheck,
|
||||
"whois": opt.performWhoisLookup
|
||||
}
|
||||
|
||||
enabled = set()
|
||||
|
|
@ -421,6 +428,10 @@ if __name__ == "__main__":
|
|||
url, verbose=verbose, proxy=proxy_to_use,
|
||||
agent=agent_to_use, tamper=opt.tamperXssPayloads
|
||||
)
|
||||
elif whois:
|
||||
whois_lookup_main(
|
||||
url, verbose=opt.runInVerbose, readable=opt.showReadableOutput
|
||||
)
|
||||
else:
|
||||
pass
|
||||
else:
|
||||
|
|
@ -453,7 +464,7 @@ if __name__ == "__main__":
|
|||
options = [
|
||||
opt.runSqliScan, opt.runPortScan,
|
||||
opt.intelCheck, opt.adminPanelFinder,
|
||||
opt.runXssScan
|
||||
opt.runXssScan, opt.performWhoisLookup
|
||||
]
|
||||
if any(options):
|
||||
with open(urls_to_use) as urls:
|
||||
|
|
@ -462,8 +473,9 @@ if __name__ == "__main__":
|
|||
url.strip(),
|
||||
sqlmap=opt.runSqliScan, nmap=opt.runPortScan,
|
||||
intel=opt.intelCheck, xss=opt.runXssScan,
|
||||
admin=opt.adminPanelFinder, verbose=opt.runInVerbose,
|
||||
batch=opt.runInBatch, auto_start=opt.autoStartSqlmap
|
||||
whois=opt.performWhoisLookup, admin=opt.adminPanelFinder,
|
||||
verbose=opt.runInVerbose, batch=opt.runInBatch,
|
||||
auto_start=opt.autoStartSqlmap
|
||||
)
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue