mirror of
https://github.com/Ekultek/Zeus-Scanner.git
synced 2026-03-11 08:55:51 +00:00
removed failing queries from the dorks.txt file
This commit is contained in:
parent
31c530cc9f
commit
f0056a0133
3 changed files with 1 additions and 206 deletions
|
|
@ -9,7 +9,7 @@ c3ef86ef033a88aa00d016465eeeb339 ./zeus.py
|
|||
d3ad89703575a712a0aeead2b176d8c5 ./etc/html/clickjacking_test_page.html
|
||||
642a77905d8bb4e5533e0e9c2137c0fa ./etc/text_files/agents.txt
|
||||
82cc68f46539d0255f7ce14cd86cd49b ./etc/text_files/link_ext.txt
|
||||
0f2c29a4bab9f626a4747b0fb3a388bb ./etc/text_files/dorks.txt
|
||||
c57ac34fe965961917ac8a207df256d5 ./etc/text_files/dorks.txt
|
||||
cf85d83da34d70720193d83950c31fdc ./etc/text_files/xss_payloads.txt
|
||||
6cabeb9919d2301efc4ba3d8869282d6 ./etc/checksum/md5sum.md5
|
||||
5250f0aa13b8af4775efa506e77de1ce ./etc/xml/headers.xml
|
||||
|
|
@ -92,7 +92,6 @@ c4ac50a3f3550c62219e7e4f38d4b496 ./lib/plugins/1024.py
|
|||
76a1d1decfb872bfafdf510c656f113a ./lib/plugins/rssfeed.py
|
||||
320f0db977c85b477ba1ea78b140cb8a ./lib/plugins/4images.py
|
||||
35dc8b7da4becb60662aab3c48a9210b ./lib/plugins/openxchange.py
|
||||
637f2ba9a198c64452335abd3fd9df3d ./lib/attacks/gist_lookup/__init__.py
|
||||
bdb7ff546787d38bbbd0aac9d4a4cdf8 ./lib/attacks/clickjacking_scan/__init__.py
|
||||
d41d8cd98f00b204e9800998ecf8427e ./lib/attacks/__init__.py
|
||||
6e9e0a9e2c72e00d8690c0177b695d56 ./lib/attacks/sqlmap_scan/__init__.py
|
||||
|
|
|
|||
|
|
@ -9,11 +9,8 @@ inurl:"nacional.php?id="
|
|||
inurl:head.php?choix=
|
||||
inurl:"group.php?gid="
|
||||
inurl:/cgi-bin/wwwadmin.pl
|
||||
intitle:Novell intitle:WebAccess "Copyright *-* Novell, Inc"
|
||||
inurl:m2f/m2f_phpbb204.php?m2f_root_path=
|
||||
inurl:page.php?base_dir=
|
||||
inurl:main.php?mod=
|
||||
intitle:"PhpMyExplorer" inurl:"index.php" -cvs
|
||||
intitle:"Remote Desktop Web Connection"
|
||||
filetype:cfg ks intext:rootpw -sample -test -howto
|
||||
inurl:blank.php?oldal=
|
||||
|
|
@ -22,7 +19,6 @@ inurl:enter.php?link=
|
|||
inurl:\"/axs/ax-admin.pl\" -script
|
||||
inurl:/index.php?babInstallPath=
|
||||
inurl:press.php?dir=
|
||||
inurl:profiles filetype:mdb
|
||||
inurl:info.php?op=
|
||||
inurl:"products.asp?ID="
|
||||
inurl:general.php?menu=
|
||||
|
|
@ -40,22 +36,17 @@ inurl:mod*.php?dir=
|
|||
intext:"The following report contains confidential information" vulnerability -search
|
||||
ext:nsf nsf -gov -mil
|
||||
inurl:chap-secrets -cvs
|
||||
inurl:akocomments.php?mosConfig_absolute_path=
|
||||
inurl:press.php?path=
|
||||
inurl:index.php?sub=index.php?id=index.php?t=
|
||||
inurl:msadcs.dll
|
||||
inurl:print.php?pre=
|
||||
intext:"You have an error in your SQL syntax near"
|
||||
filetype:cgi inurl:"fileman.cgi"
|
||||
intitle:"OnLine Recruitment Program - Login"
|
||||
inurl:pagina.php?ref=
|
||||
inurl:default.php?loader=
|
||||
inurl:print.php?module=
|
||||
inurl:blank.php?corpo=
|
||||
inurl:index2.php?f=
|
||||
inurl:/scripts/tools/getdrvrs.exe
|
||||
inurl:index1.php?pg=
|
||||
filetype:mdb inurl:users.mdb
|
||||
inurl:nota.php?eval=
|
||||
inurl:gallery.php?sivu=
|
||||
inurl:template.php?opcion=
|
||||
|
|
@ -63,8 +54,6 @@ inurl:path.php?category=
|
|||
inurl:news_display.php?getid=
|
||||
inurl:index.php?link=
|
||||
intitle:"welcome.to.squeezebox"
|
||||
inurl:components/com_forum/download.php?phpbb_root_path=
|
||||
intitle:\"Web Data Administrator - Login\"
|
||||
inurl:index1.php?tipo=
|
||||
inurl:/class.mysql.php?path_to_bt_dir=
|
||||
inurl:/jaf/index.php?show=
|
||||
|
|
@ -72,7 +61,6 @@ inurl:home.php?redirect=
|
|||
inurl:blank.php?mod=
|
||||
inurl:"faq_list.asp?id="
|
||||
inurl:"informacion.php?id="
|
||||
inurl:"checkout_confirmed.asp?order_id="
|
||||
inurl:modules/My_eGallery/index.php?basepath=
|
||||
inurl:newsitem.php?num=
|
||||
inurl:search.pl
|
||||
|
|
@ -89,22 +77,16 @@ inurl:page.php?ev=
|
|||
inurl:browser.inc
|
||||
inurl:include.php?x=
|
||||
intext:"liveice configuration file" ext:cfg
|
||||
inurl:components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=
|
||||
inurl:"details.asp?Product_ID="
|
||||
filetype:ini ServUDaemon
|
||||
inurl:include.php?play=
|
||||
inurl:"search.asp?CartID="
|
||||
inurl:print.php?cont=
|
||||
intext:"A syntax error has occurred" filetype:ihtml
|
||||
inurl:test.bat
|
||||
inurl:main.php?tipo=
|
||||
inurl:info2www
|
||||
inurl:index2.php?doshow=
|
||||
inurl:start.php?pageweb=
|
||||
inurl:press.php?abre=
|
||||
inurl:padrao.php?seccion=
|
||||
inurl:head.php?pageweb=
|
||||
inurl:principal.php?basepath=
|
||||
inurl:"cardinfo.asp?card="
|
||||
inurl:file.php?seccion=
|
||||
inurl:shop
|
||||
|
|
@ -117,36 +99,24 @@ inurl:/content.php?page=
|
|||
inurl:file.php?cmd=
|
||||
inurl:padrao.php?body=
|
||||
inurl:mod*.php?ev=
|
||||
inurl:webmail./index.pl "Interface"
|
||||
inurl:page.php?adresa=
|
||||
inurl:/include/write.php?dir=
|
||||
inurl:sub*.php?g=
|
||||
inurl:file.php?disp=
|
||||
inurl:ids5web
|
||||
filetype:log intext:"ConnectionManager2″
|
||||
inurl:include/new-visitor.inc.php?lvc_include_dir=
|
||||
inurl:"quem_somos.php?id="
|
||||
inurl:vbstats.php "page generated"
|
||||
inurl:index3.php?x=
|
||||
inurl:index.php?pg=
|
||||
inurl:/mcf.php?content=
|
||||
inurl:"shprodde.asp?SKU="
|
||||
inurl:info.php?pagina=
|
||||
inurl:"storefronts.asp?title="
|
||||
inurl:sitio.php?abre=
|
||||
intext:"mySQL error with query"
|
||||
inurl:php
|
||||
inurl:historialeer.php?num=
|
||||
inurl:pagina.php?numero=
|
||||
intitle:"inc. vpn 3000 concentrator" intitle:asterisk.management.portal web-access
|
||||
inurl:print.php?basepath=
|
||||
inurl:/library/lib.php?root=
|
||||
|
||||
inurl:layout.php?sekce=
|
||||
htpasswd / htgroup
|
||||
inurl:standard.php?pre=
|
||||
inurl:info.php?o=
|
||||
filetype:reg reg HKEY_ Windows Registry exports can reveal
|
||||
inurl:vtund.conf intext:pass -cvs s
|
||||
inurl:page.php?e=
|
||||
inurl:default.php?opcion=
|
||||
|
|
@ -161,8 +131,6 @@ intext:"Mecury Version" "Infastructure Group"
|
|||
inurl:padrao.php?path=
|
||||
inurl:index.php?op=
|
||||
inurl:padrao.php?a=
|
||||
inurl:sitio.php?secao=
|
||||
inurl:/cgi-bin/tcsh
|
||||
inurl:show.php?d=
|
||||
inurl:finger
|
||||
filetype:wab wab
|
||||
|
|
@ -176,7 +144,6 @@ inurl:/cgi-bin/sendform.cgi
|
|||
inurl:print.php?pag=
|
||||
inurl:padrao.php?menue=
|
||||
inurl:"aktuelles.php?id="
|
||||
inurl:components/com_performs/performs.php?mosConfig_absolute_path=
|
||||
inurl:"template.php?pag="
|
||||
intitle:\"Index of\" cfide
|
||||
inurl:home.php?tipo=
|
||||
|
|
@ -185,16 +152,12 @@ filetype:sql "insert into" (pass|passwd|password)
|
|||
inurl:include.php?goFile=
|
||||
inurl:"agenda.php?o="
|
||||
inurl:/index.php?TWC=
|
||||
filetype:dat "password.dat"
|
||||
inurl:pagina.php?ir=
|
||||
inurl:pagina.php?secao=
|
||||
inurl:path.php?pname=
|
||||
filetypera orafiletypedb pdb backup (Pilot | Pluckerdb)
|
||||
inurl:include.php?left=
|
||||
inurl:"shopwelcome.asp?title="
|
||||
inurl:pagina.php?recipe=
|
||||
inurl:/cgi-bin/dbmlparser.exe
|
||||
inurl:path.php?addr=
|
||||
inurl:sub*.php?load=
|
||||
inurl:home.php?body=
|
||||
inurl:base.php?*[*]*=
|
||||
|
|
@ -204,13 +167,10 @@ inurl:*db filetype:mdb
|
|||
inurl:show.php?redirect=
|
||||
inurl:/header.php?abspath=
|
||||
inurl:art.php?idm=
|
||||
inurl:/includes/functions_portal.php?phpbb_root_path=
|
||||
inurl:head.php?dir=
|
||||
inurl:big.php?pathtotemplate=
|
||||
inurl:"promo.asp?id="
|
||||
inurl:"index.php?KID="
|
||||
inurl:show.php?disp=
|
||||
intitle:Index.of etc shadow site:passwd
|
||||
inurl:blank.php?url=
|
||||
inurl:/cgi-bin/files.pl
|
||||
inurl:blank.php?link=
|
||||
|
|
@ -225,15 +185,12 @@ intitle:"Login to @Mail" (ext:pl | inurl:"index") -dwaffleman
|
|||
inurl:standard.php?secc=
|
||||
inurl:path.php?id=
|
||||
intitle:\"index of\" inurl:ftp (pub | incoming)
|
||||
inurl:"add-to-cart.asp?ID="
|
||||
intitle:"ITS System Information" "Please log on to the SAP System"
|
||||
inurl:forward filetype:forward -cvs
|
||||
inurl:/cgi-bin/www-sql
|
||||
intext:"Welcome to PHP-Nuke" congratulations
|
||||
inurl:general.php?body=
|
||||
inurl:mod*.php?goFile=
|
||||
inurl:nota.php?OpenPage=
|
||||
inurl:/modules/agendax/addevent.inc.php?agendax_path=
|
||||
filetype:sql password
|
||||
inurl:newsid=
|
||||
intext:"Web Wiz Journal"
|
||||
|
|
@ -1396,7 +1353,6 @@ inurl:home.php?menu=
|
|||
inurl:sitio.php?middlePart=
|
||||
inurl:main.php?goto=
|
||||
filetype:ctt Contact
|
||||
inurl:backup filetype:mdb
|
||||
intitle:"site administration: please log in" "site designed by emarketsouth"
|
||||
inurl:head.php?incl=
|
||||
inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man
|
||||
|
|
@ -3230,7 +3186,6 @@ inurl:print.php?opcion=
|
|||
inurl:index.php?u=administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path=
|
||||
inurl:path.php?sp=
|
||||
inurl:news.php?id=
|
||||
inurl:"/axs/ax-admin.pl" -script
|
||||
inurl:"store-details.asp?id="
|
||||
intitle:"Virtual Server Administration System"
|
||||
inurl:padrao.php?texto=
|
||||
|
|
|
|||
|
|
@ -1,159 +0,0 @@
|
|||
import re
|
||||
|
||||
from bs4 import BeautifulSoup
|
||||
|
||||
import lib.core.common
|
||||
import lib.core.settings
|
||||
import var.auto_issue.github
|
||||
|
||||
|
||||
def __create_url(redirect, template="https://gist.github.com{}"):
|
||||
"""
|
||||
create the URL for the Gists
|
||||
"""
|
||||
return template.format(redirect)
|
||||
|
||||
|
||||
def get_raw_html(redirect, verbose=False):
|
||||
"""
|
||||
get the raw HTML of the Gist plus the URL for it
|
||||
"""
|
||||
tag, descriptor = "a", "href"
|
||||
raw_gist_regex = re.compile(r".raw.[a-z0-9]{40}", re.I)
|
||||
_, status, html, _ = lib.core.common.get_page(redirect)
|
||||
|
||||
if status == 200:
|
||||
soup = BeautifulSoup(html, "html.parser")
|
||||
for link in soup.findAll(tag):
|
||||
raw_gist_redirect = link.get(descriptor)
|
||||
if raw_gist_regex.search(str(raw_gist_redirect)) is not None:
|
||||
url = __create_url(raw_gist_redirect)
|
||||
if verbose:
|
||||
lib.core.settings.logger.debug(lib.core.settings.set_color(
|
||||
"found raw Gist URL '{}'".format(url), level=10
|
||||
))
|
||||
try:
|
||||
_, _, html, _ = lib.core.common.get_page(url)
|
||||
raw_soup = BeautifulSoup(html, "html.parser")
|
||||
return raw_soup, url
|
||||
except Exception:
|
||||
return None, None
|
||||
else:
|
||||
return None, None
|
||||
|
||||
|
||||
def get_links(page_set, proxy=None, agent=None):
|
||||
"""
|
||||
parse 10 pages of Github gists and use them
|
||||
"""
|
||||
redirects, retval = set(), set()
|
||||
gist_search_url = "https://gist.github.com/discover?page={}"
|
||||
tag, descriptor = "a", "href"
|
||||
gist_regex = re.compile(r"[a-f0-9]{32}", re.I)
|
||||
gist_skip_schema = ("stargazers", "forks", "#comments")
|
||||
|
||||
for i in range(page_set):
|
||||
lib.core.settings.logger.info(lib.core.settings.set_color(
|
||||
"fetching all Gists on page #{}".format(i+1)
|
||||
))
|
||||
_, status, html, _ = lib.core.common.get_page(
|
||||
gist_search_url.format(i+1), proxy=proxy, agent=agent
|
||||
)
|
||||
if status == 200:
|
||||
soup = BeautifulSoup(html, "html.parser")
|
||||
for link in soup.findAll(tag):
|
||||
redirect = link.get(descriptor)
|
||||
if not any(s in redirect for s in gist_skip_schema):
|
||||
if gist_regex.search(redirect) is not None:
|
||||
if not any(protocol in redirect for protocol in ["https://", "http://"]):
|
||||
redirects.add(__create_url(redirect))
|
||||
else:
|
||||
redirects.add(redirect)
|
||||
else:
|
||||
lib.core.settings.logger.warning(lib.core.settings.set_color(
|
||||
"page #{} failed to load with status code {} (reason '{}')".format(
|
||||
i+1, status, lib.core.common.STATUS_CODES[int(status)]
|
||||
), level=30
|
||||
))
|
||||
continue
|
||||
return redirects
|
||||
|
||||
|
||||
def check_files_for_information(data_to_search, query):
|
||||
"""
|
||||
check the files to see if they contain any of the information that was specified
|
||||
"""
|
||||
# create multiple regex types to ensure that we cover all our
|
||||
# bases while we do the searching.
|
||||
# this will make it so that if there is a match anywhere
|
||||
# in anything, we'll find it.
|
||||
data_to_search = str(data_to_search)
|
||||
data_regex_schema = (
|
||||
# match a URL with or without www
|
||||
re.compile(r"(http(s)?)?(.//)?(www.)?{}".format(query), re.I),
|
||||
# match our string and any random character around it (I like to call it the tittyex)
|
||||
re.compile(r"(.)?{}(.)?".format(query), re.I),
|
||||
# single boundary match, checks if it's inside of something else
|
||||
re.compile(r"\b{}".format(query), re.I),
|
||||
# double boundary, same as above but with another boundary
|
||||
re.compile(r"\b{}\b".format(query), re.I),
|
||||
# wildcard match
|
||||
re.compile(r"{}*".format(query), re.I),
|
||||
# normal match
|
||||
re.compile(r"{}".format(query), re.I)
|
||||
)
|
||||
for regex in list(data_regex_schema):
|
||||
if regex.search(data_to_search) is not None:
|
||||
lib.core.settings.logger.info(lib.core.settings.set_color(
|
||||
"found match with given specifics ('{}'), saving Gist to file".format(
|
||||
regex.pattern
|
||||
), level=25
|
||||
))
|
||||
lib.core.common.write_to_log_file(
|
||||
data_to_search,
|
||||
lib.core.settings.GIST_MATCH_LOG,
|
||||
lib.core.settings.GIST_FILENAME.format(query)
|
||||
)
|
||||
|
||||
|
||||
def github_gist_search_main(query, **kwargs):
|
||||
"""
|
||||
main function for searching Gists
|
||||
"""
|
||||
proxy = kwargs.get("proxy", None)
|
||||
agent = kwargs.get("agent", None)
|
||||
verbose = kwargs.get("verbose", False)
|
||||
page_set = kwargs.get("page_set", 5)
|
||||
|
||||
try:
|
||||
lib.core.settings.logger.info(lib.core.settings.set_color(
|
||||
"searching a total of {} pages of Gists for '{}'".format(
|
||||
page_set, query
|
||||
)
|
||||
))
|
||||
|
||||
if "www." in query:
|
||||
query = query.split(".")[1]
|
||||
|
||||
links = get_links(page_set, proxy=proxy, agent=agent)
|
||||
if verbose:
|
||||
lib.core.settings.logger.debug(lib.core.settings.set_color(
|
||||
"found a total of {} links to search, attempting all of them".format(
|
||||
len(links)
|
||||
), level=15
|
||||
))
|
||||
for link in list(links):
|
||||
if link is not None:
|
||||
try:
|
||||
gist, gist_link = get_raw_html(link, verbose=verbose)
|
||||
check_files_for_information(gist, query)
|
||||
except TypeError:
|
||||
pass
|
||||
except KeyboardInterrupt:
|
||||
if not lib.core.common.pause():
|
||||
lib.core.common.shutdown()
|
||||
except Exception as e:
|
||||
lib.core.settings.logger.exception(lib.core.settings.set_color(
|
||||
"Gist search has failed with error '{}'".format(str(e)), level=50
|
||||
))
|
||||
var.auto_issue.github.request_issue_creation()
|
||||
Loading…
Reference in a new issue