removed failing queries from the dorks.txt file

This commit is contained in:
ekultek 2017-12-15 09:44:46 -06:00
parent 31c530cc9f
commit f0056a0133
3 changed files with 1 additions and 206 deletions

View file

@ -9,7 +9,7 @@ c3ef86ef033a88aa00d016465eeeb339 ./zeus.py
d3ad89703575a712a0aeead2b176d8c5 ./etc/html/clickjacking_test_page.html
642a77905d8bb4e5533e0e9c2137c0fa ./etc/text_files/agents.txt
82cc68f46539d0255f7ce14cd86cd49b ./etc/text_files/link_ext.txt
0f2c29a4bab9f626a4747b0fb3a388bb ./etc/text_files/dorks.txt
c57ac34fe965961917ac8a207df256d5 ./etc/text_files/dorks.txt
cf85d83da34d70720193d83950c31fdc ./etc/text_files/xss_payloads.txt
6cabeb9919d2301efc4ba3d8869282d6 ./etc/checksum/md5sum.md5
5250f0aa13b8af4775efa506e77de1ce ./etc/xml/headers.xml
@ -92,7 +92,6 @@ c4ac50a3f3550c62219e7e4f38d4b496 ./lib/plugins/1024.py
76a1d1decfb872bfafdf510c656f113a ./lib/plugins/rssfeed.py
320f0db977c85b477ba1ea78b140cb8a ./lib/plugins/4images.py
35dc8b7da4becb60662aab3c48a9210b ./lib/plugins/openxchange.py
637f2ba9a198c64452335abd3fd9df3d ./lib/attacks/gist_lookup/__init__.py
bdb7ff546787d38bbbd0aac9d4a4cdf8 ./lib/attacks/clickjacking_scan/__init__.py
d41d8cd98f00b204e9800998ecf8427e ./lib/attacks/__init__.py
6e9e0a9e2c72e00d8690c0177b695d56 ./lib/attacks/sqlmap_scan/__init__.py

View file

@ -9,11 +9,8 @@ inurl:"nacional.php?id="
inurl:head.php?choix=
inurl:"group.php?gid="
inurl:/cgi-bin/wwwadmin.pl
intitle:Novell intitle:WebAccess "Copyright *-* Novell, Inc"
inurl:m2f/m2f_phpbb204.php?m2f_root_path=
inurl:page.php?base_dir=
inurl:main.php?mod=
intitle:"PhpMyExplorer" inurl:"index.php" -cvs
intitle:"Remote Desktop Web Connection"
filetype:cfg ks intext:rootpw -sample -test -howto
inurl:blank.php?oldal=
@ -22,7 +19,6 @@ inurl:enter.php?link=
inurl:\"/axs/ax-admin.pl\" -script
inurl:/index.php?babInstallPath=
inurl:press.php?dir=
inurl:profiles filetype:mdb
inurl:info.php?op=
inurl:"products.asp?ID="
inurl:general.php?menu=
@ -40,22 +36,17 @@ inurl:mod*.php?dir=
intext:"The following report contains confidential information" vulnerability -search
ext:nsf nsf -gov -mil
inurl:chap-secrets -cvs
inurl:akocomments.php?mosConfig_absolute_path=
inurl:press.php?path=
inurl:index.php?sub=index.php?id=index.php?t=
inurl:msadcs.dll
inurl:print.php?pre=
intext:"You have an error in your SQL syntax near"
filetype:cgi inurl:"fileman.cgi"
intitle:"OnLine Recruitment Program - Login"
inurl:pagina.php?ref=
inurl:default.php?loader=
inurl:print.php?module=
inurl:blank.php?corpo=
inurl:index2.php?f=
inurl:/scripts/tools/getdrvrs.exe
inurl:index1.php?pg=
filetype:mdb inurl:users.mdb
inurl:nota.php?eval=
inurl:gallery.php?sivu=
inurl:template.php?opcion=
@ -63,8 +54,6 @@ inurl:path.php?category=
inurl:news_display.php?getid=
inurl:index.php?link=
intitle:"welcome.to.squeezebox"
inurl:components/com_forum/download.php?phpbb_root_path=
intitle:\"Web Data Administrator - Login\"
inurl:index1.php?tipo=
inurl:/class.mysql.php?path_to_bt_dir=
inurl:/jaf/index.php?show=
@ -72,7 +61,6 @@ inurl:home.php?redirect=
inurl:blank.php?mod=
inurl:"faq_list.asp?id="
inurl:"informacion.php?id="
inurl:"checkout_confirmed.asp?order_id="
inurl:modules/My_eGallery/index.php?basepath=
inurl:newsitem.php?num=
inurl:search.pl
@ -89,22 +77,16 @@ inurl:page.php?ev=
inurl:browser.inc
inurl:include.php?x=
intext:"liveice configuration file" ext:cfg
inurl:components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=
inurl:"details.asp?Product_ID="
filetype:ini ServUDaemon
inurl:include.php?play=
inurl:"search.asp?CartID="
inurl:print.php?cont=
intext:"A syntax error has occurred" filetype:ihtml
inurl:test.bat
inurl:main.php?tipo=
inurl:info2www
inurl:index2.php?doshow=
inurl:start.php?pageweb=
inurl:press.php?abre=
inurl:padrao.php?seccion=
inurl:head.php?pageweb=
inurl:principal.php?basepath=
inurl:"cardinfo.asp?card="
inurl:file.php?seccion=
inurl:shop
@ -117,36 +99,24 @@ inurl:/content.php?page=
inurl:file.php?cmd=
inurl:padrao.php?body=
inurl:mod*.php?ev=
inurl:webmail./index.pl "Interface"
inurl:page.php?adresa=
inurl:/include/write.php?dir=
inurl:sub*.php?g=
inurl:file.php?disp=
inurl:ids5web
filetype:log intext:"ConnectionManager2″
inurl:include/new-visitor.inc.php?lvc_include_dir=
inurl:"quem_somos.php?id="
inurl:vbstats.php "page generated"
inurl:index3.php?x=
inurl:index.php?pg=
inurl:/mcf.php?content=
inurl:"shprodde.asp?SKU="
inurl:info.php?pagina=
inurl:"storefronts.asp?title="
inurl:sitio.php?abre=
intext:"mySQL error with query"
inurl:php
inurl:historialeer.php?num=
inurl:pagina.php?numero=
intitle:"inc. vpn 3000 concentrator" intitle:asterisk.management.portal web-access
inurl:print.php?basepath=
inurl:/library/lib.php?root=
inurl:layout.php?sekce=
htpasswd / htgroup
inurl:standard.php?pre=
inurl:info.php?o=
filetype:reg reg HKEY_ Windows Registry exports can reveal
inurl:vtund.conf intext:pass -cvs s
inurl:page.php?e=
inurl:default.php?opcion=
@ -161,8 +131,6 @@ intext:"Mecury Version" "Infastructure Group"
inurl:padrao.php?path=
inurl:index.php?op=
inurl:padrao.php?a=
inurl:sitio.php?secao=
inurl:/cgi-bin/tcsh
inurl:show.php?d=
inurl:finger
filetype:wab wab
@ -176,7 +144,6 @@ inurl:/cgi-bin/sendform.cgi
inurl:print.php?pag=
inurl:padrao.php?menue=
inurl:"aktuelles.php?id="
inurl:components/com_performs/performs.php?mosConfig_absolute_path=
inurl:"template.php?pag="
intitle:\"Index of\" cfide
inurl:home.php?tipo=
@ -185,16 +152,12 @@ filetype:sql "insert into" (pass|passwd|password)
inurl:include.php?goFile=
inurl:"agenda.php?o="
inurl:/index.php?TWC=
filetype:dat "password.dat"
inurl:pagina.php?ir=
inurl:pagina.php?secao=
inurl:path.php?pname=
filetypera orafiletypedb pdb backup (Pilot | Pluckerdb)
inurl:include.php?left=
inurl:"shopwelcome.asp?title="
inurl:pagina.php?recipe=
inurl:/cgi-bin/dbmlparser.exe
inurl:path.php?addr=
inurl:sub*.php?load=
inurl:home.php?body=
inurl:base.php?*[*]*=
@ -204,13 +167,10 @@ inurl:*db filetype:mdb
inurl:show.php?redirect=
inurl:/header.php?abspath=
inurl:art.php?idm=
inurl:/includes/functions_portal.php?phpbb_root_path=
inurl:head.php?dir=
inurl:big.php?pathtotemplate=
inurl:"promo.asp?id="
inurl:"index.php?KID="
inurl:show.php?disp=
intitle:Index.of etc shadow site:passwd
inurl:blank.php?url=
inurl:/cgi-bin/files.pl
inurl:blank.php?link=
@ -225,15 +185,12 @@ intitle:"Login to @Mail" (ext:pl | inurl:"index") -dwaffleman
inurl:standard.php?secc=
inurl:path.php?id=
intitle:\"index of\" inurl:ftp (pub | incoming)
inurl:"add-to-cart.asp?ID="
intitle:"ITS System Information" "Please log on to the SAP System"
inurl:forward filetype:forward -cvs
inurl:/cgi-bin/www-sql
intext:"Welcome to PHP-Nuke" congratulations
inurl:general.php?body=
inurl:mod*.php?goFile=
inurl:nota.php?OpenPage=
inurl:/modules/agendax/addevent.inc.php?agendax_path=
filetype:sql password
inurl:newsid=
intext:"Web Wiz Journal"
@ -1396,7 +1353,6 @@ inurl:home.php?menu=
inurl:sitio.php?middlePart=
inurl:main.php?goto=
filetype:ctt Contact
inurl:backup filetype:mdb
intitle:"site administration: please log in" "site designed by emarketsouth"
inurl:head.php?incl=
inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man
@ -3230,7 +3186,6 @@ inurl:print.php?opcion=
inurl:index.php?u=administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path=
inurl:path.php?sp=
inurl:news.php?id=
inurl:"/axs/ax-admin.pl" -script
inurl:"store-details.asp?id="
intitle:"Virtual Server Administration System"
inurl:padrao.php?texto=

View file

@ -1,159 +0,0 @@
import re
from bs4 import BeautifulSoup
import lib.core.common
import lib.core.settings
import var.auto_issue.github
def __create_url(redirect, template="https://gist.github.com{}"):
"""
create the URL for the Gists
"""
return template.format(redirect)
def get_raw_html(redirect, verbose=False):
"""
get the raw HTML of the Gist plus the URL for it
"""
tag, descriptor = "a", "href"
raw_gist_regex = re.compile(r".raw.[a-z0-9]{40}", re.I)
_, status, html, _ = lib.core.common.get_page(redirect)
if status == 200:
soup = BeautifulSoup(html, "html.parser")
for link in soup.findAll(tag):
raw_gist_redirect = link.get(descriptor)
if raw_gist_regex.search(str(raw_gist_redirect)) is not None:
url = __create_url(raw_gist_redirect)
if verbose:
lib.core.settings.logger.debug(lib.core.settings.set_color(
"found raw Gist URL '{}'".format(url), level=10
))
try:
_, _, html, _ = lib.core.common.get_page(url)
raw_soup = BeautifulSoup(html, "html.parser")
return raw_soup, url
except Exception:
return None, None
else:
return None, None
def get_links(page_set, proxy=None, agent=None):
"""
parse 10 pages of Github gists and use them
"""
redirects, retval = set(), set()
gist_search_url = "https://gist.github.com/discover?page={}"
tag, descriptor = "a", "href"
gist_regex = re.compile(r"[a-f0-9]{32}", re.I)
gist_skip_schema = ("stargazers", "forks", "#comments")
for i in range(page_set):
lib.core.settings.logger.info(lib.core.settings.set_color(
"fetching all Gists on page #{}".format(i+1)
))
_, status, html, _ = lib.core.common.get_page(
gist_search_url.format(i+1), proxy=proxy, agent=agent
)
if status == 200:
soup = BeautifulSoup(html, "html.parser")
for link in soup.findAll(tag):
redirect = link.get(descriptor)
if not any(s in redirect for s in gist_skip_schema):
if gist_regex.search(redirect) is not None:
if not any(protocol in redirect for protocol in ["https://", "http://"]):
redirects.add(__create_url(redirect))
else:
redirects.add(redirect)
else:
lib.core.settings.logger.warning(lib.core.settings.set_color(
"page #{} failed to load with status code {} (reason '{}')".format(
i+1, status, lib.core.common.STATUS_CODES[int(status)]
), level=30
))
continue
return redirects
def check_files_for_information(data_to_search, query):
"""
check the files to see if they contain any of the information that was specified
"""
# create multiple regex types to ensure that we cover all our
# bases while we do the searching.
# this will make it so that if there is a match anywhere
# in anything, we'll find it.
data_to_search = str(data_to_search)
data_regex_schema = (
# match a URL with or without www
re.compile(r"(http(s)?)?(.//)?(www.)?{}".format(query), re.I),
# match our string and any random character around it (I like to call it the tittyex)
re.compile(r"(.)?{}(.)?".format(query), re.I),
# single boundary match, checks if it's inside of something else
re.compile(r"\b{}".format(query), re.I),
# double boundary, same as above but with another boundary
re.compile(r"\b{}\b".format(query), re.I),
# wildcard match
re.compile(r"{}*".format(query), re.I),
# normal match
re.compile(r"{}".format(query), re.I)
)
for regex in list(data_regex_schema):
if regex.search(data_to_search) is not None:
lib.core.settings.logger.info(lib.core.settings.set_color(
"found match with given specifics ('{}'), saving Gist to file".format(
regex.pattern
), level=25
))
lib.core.common.write_to_log_file(
data_to_search,
lib.core.settings.GIST_MATCH_LOG,
lib.core.settings.GIST_FILENAME.format(query)
)
def github_gist_search_main(query, **kwargs):
"""
main function for searching Gists
"""
proxy = kwargs.get("proxy", None)
agent = kwargs.get("agent", None)
verbose = kwargs.get("verbose", False)
page_set = kwargs.get("page_set", 5)
try:
lib.core.settings.logger.info(lib.core.settings.set_color(
"searching a total of {} pages of Gists for '{}'".format(
page_set, query
)
))
if "www." in query:
query = query.split(".")[1]
links = get_links(page_set, proxy=proxy, agent=agent)
if verbose:
lib.core.settings.logger.debug(lib.core.settings.set_color(
"found a total of {} links to search, attempting all of them".format(
len(links)
), level=15
))
for link in list(links):
if link is not None:
try:
gist, gist_link = get_raw_html(link, verbose=verbose)
check_files_for_information(gist, query)
except TypeError:
pass
except KeyboardInterrupt:
if not lib.core.common.pause():
lib.core.common.shutdown()
except Exception as e:
lib.core.settings.logger.exception(lib.core.settings.set_color(
"Gist search has failed with error '{}'".format(str(e)), level=50
))
var.auto_issue.github.request_issue_creation()