From f0056a01333465b81e09d8954a9e206a9406e4f8 Mon Sep 17 00:00:00 2001 From: ekultek Date: Fri, 15 Dec 2017 09:44:46 -0600 Subject: [PATCH] removed failing queries from the dorks.txt file --- etc/checksum/md5sum.md5 | 3 +- etc/text_files/dorks.txt | 45 -------- lib/attacks/gist_lookup/__init__.py | 159 ---------------------------- 3 files changed, 1 insertion(+), 206 deletions(-) delete mode 100644 lib/attacks/gist_lookup/__init__.py diff --git a/etc/checksum/md5sum.md5 b/etc/checksum/md5sum.md5 index e28bf39..5b0e19d 100644 --- a/etc/checksum/md5sum.md5 +++ b/etc/checksum/md5sum.md5 @@ -9,7 +9,7 @@ c3ef86ef033a88aa00d016465eeeb339 ./zeus.py d3ad89703575a712a0aeead2b176d8c5 ./etc/html/clickjacking_test_page.html 642a77905d8bb4e5533e0e9c2137c0fa ./etc/text_files/agents.txt 82cc68f46539d0255f7ce14cd86cd49b ./etc/text_files/link_ext.txt -0f2c29a4bab9f626a4747b0fb3a388bb ./etc/text_files/dorks.txt +c57ac34fe965961917ac8a207df256d5 ./etc/text_files/dorks.txt cf85d83da34d70720193d83950c31fdc ./etc/text_files/xss_payloads.txt 6cabeb9919d2301efc4ba3d8869282d6 ./etc/checksum/md5sum.md5 5250f0aa13b8af4775efa506e77de1ce ./etc/xml/headers.xml @@ -92,7 +92,6 @@ c4ac50a3f3550c62219e7e4f38d4b496 ./lib/plugins/1024.py 76a1d1decfb872bfafdf510c656f113a ./lib/plugins/rssfeed.py 320f0db977c85b477ba1ea78b140cb8a ./lib/plugins/4images.py 35dc8b7da4becb60662aab3c48a9210b ./lib/plugins/openxchange.py -637f2ba9a198c64452335abd3fd9df3d ./lib/attacks/gist_lookup/__init__.py bdb7ff546787d38bbbd0aac9d4a4cdf8 ./lib/attacks/clickjacking_scan/__init__.py d41d8cd98f00b204e9800998ecf8427e ./lib/attacks/__init__.py 6e9e0a9e2c72e00d8690c0177b695d56 ./lib/attacks/sqlmap_scan/__init__.py diff --git a/etc/text_files/dorks.txt b/etc/text_files/dorks.txt index 132efd3..3e983c3 100644 --- a/etc/text_files/dorks.txt +++ b/etc/text_files/dorks.txt @@ -9,11 +9,8 @@ inurl:"nacional.php?id=" inurl:head.php?choix= inurl:"group.php?gid=" inurl:/cgi-bin/wwwadmin.pl -intitle:Novell intitle:WebAccess "Copyright *-* Novell, Inc" -inurl:m2f/m2f_phpbb204.php?m2f_root_path= inurl:page.php?base_dir= inurl:main.php?mod= -intitle:"PhpMyExplorer" inurl:"index.php" -cvs intitle:"Remote Desktop Web Connection" filetype:cfg ks intext:rootpw -sample -test -howto inurl:blank.php?oldal= @@ -22,7 +19,6 @@ inurl:enter.php?link= inurl:\"/axs/ax-admin.pl\" -script inurl:/index.php?babInstallPath= inurl:press.php?dir= -inurl:profiles filetype:mdb inurl:info.php?op= inurl:"products.asp?ID=" inurl:general.php?menu= @@ -40,22 +36,17 @@ inurl:mod*.php?dir= intext:"The following report contains confidential information" vulnerability -search ext:nsf nsf -gov -mil inurl:chap-secrets -cvs -inurl:akocomments.php?mosConfig_absolute_path= inurl:press.php?path= -inurl:index.php?sub=index.php?id=index.php?t= inurl:msadcs.dll inurl:print.php?pre= intext:"You have an error in your SQL syntax near" filetype:cgi inurl:"fileman.cgi" -intitle:"OnLine Recruitment Program - Login" inurl:pagina.php?ref= inurl:default.php?loader= inurl:print.php?module= inurl:blank.php?corpo= inurl:index2.php?f= -inurl:/scripts/tools/getdrvrs.exe inurl:index1.php?pg= -filetype:mdb inurl:users.mdb inurl:nota.php?eval= inurl:gallery.php?sivu= inurl:template.php?opcion= @@ -63,8 +54,6 @@ inurl:path.php?category= inurl:news_display.php?getid= inurl:index.php?link= intitle:"welcome.to.squeezebox" -inurl:components/com_forum/download.php?phpbb_root_path= -intitle:\"Web Data Administrator - Login\" inurl:index1.php?tipo= inurl:/class.mysql.php?path_to_bt_dir= inurl:/jaf/index.php?show= @@ -72,7 +61,6 @@ inurl:home.php?redirect= inurl:blank.php?mod= inurl:"faq_list.asp?id=" inurl:"informacion.php?id=" -inurl:"checkout_confirmed.asp?order_id=" inurl:modules/My_eGallery/index.php?basepath= inurl:newsitem.php?num= inurl:search.pl @@ -89,22 +77,16 @@ inurl:page.php?ev= inurl:browser.inc inurl:include.php?x= intext:"liveice configuration file" ext:cfg -inurl:components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path= inurl:"details.asp?Product_ID=" -filetype:ini ServUDaemon inurl:include.php?play= -inurl:"search.asp?CartID=" inurl:print.php?cont= -intext:"A syntax error has occurred" filetype:ihtml inurl:test.bat inurl:main.php?tipo= inurl:info2www inurl:index2.php?doshow= inurl:start.php?pageweb= inurl:press.php?abre= -inurl:padrao.php?seccion= inurl:head.php?pageweb= -inurl:principal.php?basepath= inurl:"cardinfo.asp?card=" inurl:file.php?seccion= inurl:shop @@ -117,36 +99,24 @@ inurl:/content.php?page= inurl:file.php?cmd= inurl:padrao.php?body= inurl:mod*.php?ev= -inurl:webmail./index.pl "Interface" inurl:page.php?adresa= -inurl:/include/write.php?dir= inurl:sub*.php?g= inurl:file.php?disp= -inurl:ids5web -filetype:log intext:"ConnectionManager2″ -inurl:include/new-visitor.inc.php?lvc_include_dir= inurl:"quem_somos.php?id=" -inurl:vbstats.php "page generated" inurl:index3.php?x= inurl:index.php?pg= inurl:/mcf.php?content= inurl:"shprodde.asp?SKU=" inurl:info.php?pagina= -inurl:"storefronts.asp?title=" inurl:sitio.php?abre= intext:"mySQL error with query" inurl:php -inurl:historialeer.php?num= inurl:pagina.php?numero= -intitle:"inc. vpn 3000 concentrator" intitle:asterisk.management.portal web-access inurl:print.php?basepath= -inurl:/library/lib.php?root= - inurl:layout.php?sekce= htpasswd / htgroup inurl:standard.php?pre= inurl:info.php?o= -filetype:reg reg HKEY_ Windows Registry exports can reveal inurl:vtund.conf intext:pass -cvs s inurl:page.php?e= inurl:default.php?opcion= @@ -161,8 +131,6 @@ intext:"Mecury Version" "Infastructure Group" inurl:padrao.php?path= inurl:index.php?op= inurl:padrao.php?a= -inurl:sitio.php?secao= -inurl:/cgi-bin/tcsh inurl:show.php?d= inurl:finger filetype:wab wab @@ -176,7 +144,6 @@ inurl:/cgi-bin/sendform.cgi inurl:print.php?pag= inurl:padrao.php?menue= inurl:"aktuelles.php?id=" -inurl:components/com_performs/performs.php?mosConfig_absolute_path= inurl:"template.php?pag=" intitle:\"Index of\" cfide inurl:home.php?tipo= @@ -185,16 +152,12 @@ filetype:sql "insert into" (pass|passwd|password) inurl:include.php?goFile= inurl:"agenda.php?o=" inurl:/index.php?TWC= -filetype:dat "password.dat" inurl:pagina.php?ir= inurl:pagina.php?secao= inurl:path.php?pname= filetypera orafiletypedb pdb backup (Pilot | Pluckerdb) inurl:include.php?left= -inurl:"shopwelcome.asp?title=" inurl:pagina.php?recipe= -inurl:/cgi-bin/dbmlparser.exe -inurl:path.php?addr= inurl:sub*.php?load= inurl:home.php?body= inurl:base.php?*[*]*= @@ -204,13 +167,10 @@ inurl:*db filetype:mdb inurl:show.php?redirect= inurl:/header.php?abspath= inurl:art.php?idm= -inurl:/includes/functions_portal.php?phpbb_root_path= inurl:head.php?dir= -inurl:big.php?pathtotemplate= inurl:"promo.asp?id=" inurl:"index.php?KID=" inurl:show.php?disp= -intitle:Index.of etc shadow site:passwd inurl:blank.php?url= inurl:/cgi-bin/files.pl inurl:blank.php?link= @@ -225,15 +185,12 @@ intitle:"Login to @Mail" (ext:pl | inurl:"index") -dwaffleman inurl:standard.php?secc= inurl:path.php?id= intitle:\"index of\" inurl:ftp (pub | incoming) -inurl:"add-to-cart.asp?ID=" -intitle:"ITS System Information" "Please log on to the SAP System" inurl:forward filetype:forward -cvs inurl:/cgi-bin/www-sql intext:"Welcome to PHP-Nuke" congratulations inurl:general.php?body= inurl:mod*.php?goFile= inurl:nota.php?OpenPage= -inurl:/modules/agendax/addevent.inc.php?agendax_path= filetype:sql password inurl:newsid= intext:"Web Wiz Journal" @@ -1396,7 +1353,6 @@ inurl:home.php?menu= inurl:sitio.php?middlePart= inurl:main.php?goto= filetype:ctt Contact -inurl:backup filetype:mdb intitle:"site administration: please log in" "site designed by emarketsouth" inurl:head.php?incl= inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man @@ -3230,7 +3186,6 @@ inurl:print.php?opcion= inurl:index.php?u=administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path= inurl:path.php?sp= inurl:news.php?id= -inurl:"/axs/ax-admin.pl" -script inurl:"store-details.asp?id=" intitle:"Virtual Server Administration System" inurl:padrao.php?texto= diff --git a/lib/attacks/gist_lookup/__init__.py b/lib/attacks/gist_lookup/__init__.py deleted file mode 100644 index ca0c498..0000000 --- a/lib/attacks/gist_lookup/__init__.py +++ /dev/null @@ -1,159 +0,0 @@ -import re - -from bs4 import BeautifulSoup - -import lib.core.common -import lib.core.settings -import var.auto_issue.github - - -def __create_url(redirect, template="https://gist.github.com{}"): - """ - create the URL for the Gists - """ - return template.format(redirect) - - -def get_raw_html(redirect, verbose=False): - """ - get the raw HTML of the Gist plus the URL for it - """ - tag, descriptor = "a", "href" - raw_gist_regex = re.compile(r".raw.[a-z0-9]{40}", re.I) - _, status, html, _ = lib.core.common.get_page(redirect) - - if status == 200: - soup = BeautifulSoup(html, "html.parser") - for link in soup.findAll(tag): - raw_gist_redirect = link.get(descriptor) - if raw_gist_regex.search(str(raw_gist_redirect)) is not None: - url = __create_url(raw_gist_redirect) - if verbose: - lib.core.settings.logger.debug(lib.core.settings.set_color( - "found raw Gist URL '{}'".format(url), level=10 - )) - try: - _, _, html, _ = lib.core.common.get_page(url) - raw_soup = BeautifulSoup(html, "html.parser") - return raw_soup, url - except Exception: - return None, None - else: - return None, None - - -def get_links(page_set, proxy=None, agent=None): - """ - parse 10 pages of Github gists and use them - """ - redirects, retval = set(), set() - gist_search_url = "https://gist.github.com/discover?page={}" - tag, descriptor = "a", "href" - gist_regex = re.compile(r"[a-f0-9]{32}", re.I) - gist_skip_schema = ("stargazers", "forks", "#comments") - - for i in range(page_set): - lib.core.settings.logger.info(lib.core.settings.set_color( - "fetching all Gists on page #{}".format(i+1) - )) - _, status, html, _ = lib.core.common.get_page( - gist_search_url.format(i+1), proxy=proxy, agent=agent - ) - if status == 200: - soup = BeautifulSoup(html, "html.parser") - for link in soup.findAll(tag): - redirect = link.get(descriptor) - if not any(s in redirect for s in gist_skip_schema): - if gist_regex.search(redirect) is not None: - if not any(protocol in redirect for protocol in ["https://", "http://"]): - redirects.add(__create_url(redirect)) - else: - redirects.add(redirect) - else: - lib.core.settings.logger.warning(lib.core.settings.set_color( - "page #{} failed to load with status code {} (reason '{}')".format( - i+1, status, lib.core.common.STATUS_CODES[int(status)] - ), level=30 - )) - continue - return redirects - - -def check_files_for_information(data_to_search, query): - """ - check the files to see if they contain any of the information that was specified - """ - # create multiple regex types to ensure that we cover all our - # bases while we do the searching. - # this will make it so that if there is a match anywhere - # in anything, we'll find it. - data_to_search = str(data_to_search) - data_regex_schema = ( - # match a URL with or without www - re.compile(r"(http(s)?)?(.//)?(www.)?{}".format(query), re.I), - # match our string and any random character around it (I like to call it the tittyex) - re.compile(r"(.)?{}(.)?".format(query), re.I), - # single boundary match, checks if it's inside of something else - re.compile(r"\b{}".format(query), re.I), - # double boundary, same as above but with another boundary - re.compile(r"\b{}\b".format(query), re.I), - # wildcard match - re.compile(r"{}*".format(query), re.I), - # normal match - re.compile(r"{}".format(query), re.I) - ) - for regex in list(data_regex_schema): - if regex.search(data_to_search) is not None: - lib.core.settings.logger.info(lib.core.settings.set_color( - "found match with given specifics ('{}'), saving Gist to file".format( - regex.pattern - ), level=25 - )) - lib.core.common.write_to_log_file( - data_to_search, - lib.core.settings.GIST_MATCH_LOG, - lib.core.settings.GIST_FILENAME.format(query) - ) - - -def github_gist_search_main(query, **kwargs): - """ - main function for searching Gists - """ - proxy = kwargs.get("proxy", None) - agent = kwargs.get("agent", None) - verbose = kwargs.get("verbose", False) - page_set = kwargs.get("page_set", 5) - - try: - lib.core.settings.logger.info(lib.core.settings.set_color( - "searching a total of {} pages of Gists for '{}'".format( - page_set, query - ) - )) - - if "www." in query: - query = query.split(".")[1] - - links = get_links(page_set, proxy=proxy, agent=agent) - if verbose: - lib.core.settings.logger.debug(lib.core.settings.set_color( - "found a total of {} links to search, attempting all of them".format( - len(links) - ), level=15 - )) - for link in list(links): - if link is not None: - try: - gist, gist_link = get_raw_html(link, verbose=verbose) - check_files_for_information(gist, query) - except TypeError: - pass - except KeyboardInterrupt: - if not lib.core.common.pause(): - lib.core.common.shutdown() - except Exception as e: - lib.core.settings.logger.exception(lib.core.settings.set_color( - "Gist search has failed with error '{}'".format(str(e)), level=50 - )) - var.auto_issue.github.request_issue_creation()