Commit graph

273 commits

Author SHA1 Message Date
ekultek
3bced94e70 minor update for a privately reported issue, where the HTML would display the site in a small scroll box, will not display as the full site 2017-11-02 09:24:23 -05:00
ekultek
bc335fa2d3 created a clickjacking scanner that will test a page for an X-Frame-Options header, if the header is not there, then it will create a basic HTML page with that URL as an iframe 2017-11-01 21:48:58 -05:00
ekultek
d1adbcdc10 forgot to bump the version number 2017-11-01 10:08:22 -05:00
ekultek
b26d29108c fixes an issue where the geckodriver will not connect, usually means something happened during the installation of it, will now attempt to re-install the geckodriver (issue #132) 2017-11-01 10:07:15 -05:00
ekultek
e85c13b2b8 minor update to the search.py file, X-Forwarded instead of X-Forward 2017-10-31 14:11:05 -05:00
ekultek
51db83833b patch for a reported issue where it would fail with from a website with Unicode 2017-10-31 13:18:40 -05:00
ekultek
29b2ad69e2 update to tamper scripts, using kwargs instead of warning 2017-10-31 13:17:33 -05:00
ekultek
fec7935d42 forgot to update the version number 2017-10-31 09:49:35 -05:00
ekultek
99575425f1 fixes an issue where if you run in verbose mode with whois lookup it will error out if certain information is not found (issue #128), it will now display the JSON data if you run in verbose mode 2017-10-31 09:47:49 -05:00
ekultek
04cd49e722 added some new URL's to the skip schema, edited the DDG link to the HTML link, made sure that the URL is not just a protocol before adding to the file 2017-10-29 11:46:36 -05:00
ekultek
6030774303 a patch for a reported issue (private) where if the found sitemap already exists, it would error out. will not just write as plain text and warn you that it probably already exists, also fixes an issue where found admin pages where not saved to a log file, and finally moved the sitemap.xml and robots.txt searches to a single function 2017-10-29 11:00:28 -05:00
ekultek
182e588774 patched a privately reported issue that would not allow you to run the blackwidow crawler behind a proxy, forgot a space in the README file 2017-10-28 16:53:13 -05:00
ekultek
f75cabb876 added a new requirement BeautifulSoup, fixed the crawler will pull all links with an 'a' tag and descriptor of 'href', bumped version number 2017-10-28 16:28:18 -05:00
ekultek
0c8d4f9bf7 edited the default user agent so it will reflect the best practices of user agent strings (reference https://docs.developer.amazonservices.com/en_US/dev_guide/DG_UserAgentHeader.html) 2017-10-28 15:49:10 -05:00
ekultek
cf2cc59022 fix for the intel AMT exploit checker (messed it up without realizing it) 2017-10-28 08:26:47 -05:00
ekultek
46fc2372c9 created a sitemap parser, will check for a page sitemap and save it if it is found, otherwise will just continue processing 2017-10-28 08:25:58 -05:00
ekultek
073361339b bumped the version number and edited the checksums to match the new updates 2017-10-28 08:25:13 -05:00
ekultek
ecf067b6bb patch for unicode errors, it appears that selenium isn't formatted to handle unicode errors (as far as I can tell) so the dork that causes the error will be skipped (issue #125) 2017-10-27 17:14:08 -05:00
ekultek
6c46fd7523 splitting the shell commands via shlex will make the commands more secure, and able to avoid most shell injection instances 2017-10-25 16:32:55 -05:00
ekultek
6ba7231e82 splitting the shell commands via shlex will make the commands more secure, and able to avoid most shell injection instances 2017-10-25 16:32:27 -05:00
ekultek
bdcc28b412 you are now successfully able to launch the sqlmap API automatically using the --auto flag (issue #58) 2017-10-25 13:26:20 -05:00
ekultek
c7fedc0165 fixed the nmap issues, it will run now it will also install itself if it's not there. working on sqlmap autostart (still). moved the function to create sqlmap and nmap arguments to settings.py. created two new scripts (one is still a work in progess) 2017-10-24 01:22:21 -05:00
ekultek
f6888b59af moved the find running opts function to settings, cleaning out the zeus.py file 2017-10-23 22:26:16 -05:00
ekultek
9cc673a05b some minor changes to the WhoIs lookup, trying to prevent it from displaying empty lists and dicts 2017-10-23 22:25:37 -05:00
ekultek
a06371aa72 fixes an issue with unicode errors from XSS payloads (issue #124) 2017-10-23 14:11:03 -05:00
ekultek
242219ac8f moved the search engine configuration to the settings file 2017-10-23 13:41:43 -05:00
ekultek
977564ae62 minor update where running through a file or dork would not allow you to parse webcache or pull all URLs, also updated some whois lookup info 2017-10-21 16:59:43 -05:00
ekultek
e2287391c3 created a whois lookup search. Will either display it in human readable form with the correct flags, or save the found information to a log file 2017-10-21 10:16:16 -05:00
ekultek
d813e70ac1 edited the way that the patch ID is displayed, will now pull the ID from origin/master 2017-10-21 08:45:19 -05:00
ekultek
b2ff3da457 the auto fix for program install error was in the wrong spot (issue #115), moved to correct spot. should work fine now 2017-10-19 18:30:17 -05:00
ekultek
a1426ea0a1 had some time so making some compatibility updates (issue #7). Also edited the auto issue, you'll have your own unique ID number now 2017-10-19 07:14:51 -05:00
ekultek
02a9f54544 created two new flags, one for parsing webcache, another for pulling all URLs. This will also produce more results per search. 2017-10-18 13:04:09 -05:00
ekultek
fddeb7b774 patches issue where zeus will only install one geckodriver version if your version is under 54 (issue #108) 2017-10-18 10:01:33 -05:00
ekultek
a17b2745d9 must pass a checksum verification before you can create a github issue 2017-10-17 15:12:32 -05:00
ekultek
c7071d3f18 adding a checksum for a verification that will be taking place in the next push 2017-10-17 14:51:39 -05:00
ekultek
1c24a4b4af some minor edits done to the prorgam, grammar fixes, moved some functions, edited some things, nothing to major or important 2017-10-17 13:33:40 -05:00
ekultek
ea884a8138 some updates that include a script to re-install a dependency that tends to fail, and fix a proxy configuration issue 2017-10-17 09:05:10 -05:00
ekultek
a909ac6c74 updating some doc strings, will be updating them more in time. just wanted to go ahead and start on them for now 2017-10-16 10:03:35 -05:00
ekultek
fc782c71fb patches an issue where zeus would only install one geckodriver version (issue #103) 2017-10-16 09:39:52 -05:00
ekultek
5375c15b9e patches an issue where Zeus will always install the same geckodriver version (issue #102) 2017-10-15 09:10:51 -05:00
ekultek
65716493e7 added new geckodriver versions for different firefox versions, hoping this will help some what with issue #99 (at least until I can figure out a solid fix). will also now extract the gecko version installed for the auto-issues 2017-10-14 14:56:45 -05:00
ekultek
f3a5621d86 updated the auto issue to provide the firefox browser version as well 2017-10-14 09:26:33 -05:00
ekultek
21398eaf8a patches an issue where the target refuses the connection (issue #97), also creates a way to run against the IP addresses of the hostname instead 2017-10-14 07:47:50 -05:00
ekultek
37f1669596 update to the geckodriver versions, it will extract the one that is correct for your system 2017-10-13 13:39:09 -05:00
ekultek
24cdc14e9e minor patch to catch the geckodriver error, happens when firefox is not compatible (issue #94) 2017-10-13 13:15:46 -05:00
ekultek
bef138e4a8 patch for an issue where there HTML could not be parsed due to fake div classes (issue #91) 2017-10-13 10:10:20 -05:00
ekultek
6383abf69a patch for an issue where to many sessions would be open, will now auto clean the sessions (issue #92) 2017-10-13 10:06:57 -05:00
ekultek
b380c6e7c4 added a catch for the max retries error, along with how to bypass it, good luck 2017-10-12 18:55:29 -05:00
ekultek
a05c26e376 patch for an issue where you could not run the enumerate file flag (-f) 2017-10-12 18:05:19 -05:00
ekultek
307751e14f patch for an issue where the current URL could not be pulled due to a present alert (issue #81) 2017-10-12 17:53:45 -05:00
ekultek
c35fddb4ce just cleaning up the parameters a little bit, not as messy now 2017-10-12 11:59:59 -05:00
ekultek
c008f93d16 multi-threading is broken, working on a fix, for now DO NOT use it 2017-10-12 10:43:13 -05:00
ekultek
799b6baba0 created some new extenstions and a threading flag for the admin panel finder 2017-10-11 17:47:18 -05:00
ekultek
859ea19c44 minor update to the initial fix for issue #58, supressing help until that part is done 2017-10-11 14:39:01 -05:00
ekultek
e9f5b82d05 initial push for an issue (#58) where it would not auto start sqlmap, lots more work to be done so make sure you start the sqlmap server before the process 2017-10-11 14:36:34 -05:00
ekultek
92a5b44548 patch for using Bing as the search engine, Bing apparently was not implemented, sorry 2017-10-10 19:41:17 -05:00
ekultek
f8614dc883 minor update to randomcase script, will now truly be random case 2017-10-10 18:16:49 -05:00
ekultek
9d97a6765a created five new tamper scripts for XSS payloads 2017-10-10 17:59:01 -05:00
ekultek
80d9565585 files edited to reflect the move of the settings, errors, and tamper scripts folders 2017-10-10 17:01:13 -05:00
ekultek
269a27f886 moved tamper scripts outside of attacks folder 2017-10-10 17:00:18 -05:00
ekultek
a8d81d28ce moved errors and settings to core folder 2017-10-10 16:59:51 -05:00
ekultek
5767f2e974 successfully extracts the URL from Google ban URL (issue #13) 2017-10-10 14:59:23 -05:00
ekultek
37cc3862a8 minor changes to the extraction schema 2017-10-09 16:45:37 -05:00
ekultek
e43ee8a0ca skips google play and google maps, also extracts correctly from webcache with out error (issue #55) 2017-10-09 16:09:50 -05:00
ekultek
a10d8d5825 minor edit to search.py removed sqlmap_api_directions.txt 2017-10-09 10:56:25 -05:00
ekultek
f9577d0365 edited so that the file to be read from depends on the command you use instead of defaulting to URL_LOG 2017-10-08 08:21:17 -05:00
ekultek
4188c2c37c fixes issue where it tries to run the attacks no matter what happens (issue #54) 2017-10-08 07:47:01 -05:00
ekultek
2937e9c759 patch for an error that occurs when firefox is not found (issue #52) 2017-10-08 07:39:05 -05:00
ekultek
b52f301358 branch issue fix #1 2017-10-07 09:34:03 -05:00
ekultek
671e77b984 patch for issue #49, bo longer need to restart the sqlmap API each iteration 2017-10-07 08:09:16 -05:00
ekultek
97b620aef4 initial fix for issue #49, still more work to be done 2017-10-05 21:21:51 -05:00
ekultek
3004ca5595 can now extract from google webcache URL's 2017-10-04 14:15:54 -05:00
ekultek
1e71aaa5f5 gave write_to_file function ability to write list, tuple, set to files (issue #40) 2017-10-04 07:07:43 -05:00
ekultek
7cf2d26e89 bumped version number 2017-10-03 14:54:04 -05:00
ekultek
94dac1c2bc added the ability to search multiple pages of Google (issue #4) 2017-10-03 11:19:16 -05:00
ekultek
008ee37362 minor edit to skip safe characters in encoding 2017-10-03 11:18:13 -05:00
ekultek
d813942c55 created three new tamper scripts and added warnings to other ones 2017-10-02 12:10:34 -05:00
ekultek
c618647eeb created three new tamper scripts and added warnings to other ones 2017-10-02 12:10:15 -05:00
ekultek
67a1738278 minor change to sqlmap scan, will not output '{}' if there are no arguments passed 2017-10-01 08:28:14 -05:00
ekultek
4cf72fc97b patch for issue #22, will not shutdown if the provided URL is not valid with an error message instead of throwing an exception 2017-10-01 08:06:03 -05:00
ekultek
f87f63d3b0 added a file for those that don't know how to use sqlmap, also minor fix to extract your log file. 2017-09-30 08:26:36 -05:00
ekultek
ceca62c4b4 auto issue creation, also caught an error, apparently it's really hard to understand tHAT SQLMAP NEEDS TO BE STARTED IN ORDER TO WORK 2017-09-30 08:01:40 -05:00
ekultek
daca2ac1a2 patch for file logging issue (issue #10) 2017-09-29 17:46:54 -05:00
ekultek
f38ec5f65f adding support for python 3 (issue #7) if you find any issues with python3 please make an issue there 2017-09-29 14:28:53 -05:00
ekultek
3e4e37042a complete re-write of intel AMT bypass, proxy and user agent configuration added for issue #9 2017-09-29 13:58:46 -05:00
ekultek
024e660853 created a tamper script for URL encoding, created tamper warnings, minor update to search.py, bumped version number 2017-09-29 10:21:26 -05:00
ekultek
9de772204e creating tamper scripts for the XSS payloads 2017-09-28 11:16:48 -05:00
ekultek
bf922eeb7c fixed the blackwidow log file issue #14 2017-09-28 11:16:21 -05:00
ekultek
83e0a5a436 updates to the XSS scanner, will successfully output if possible sqli is present or not, and only display the information once 2017-09-27 18:02:55 -05:00
ekultek
09d3bf1067 created a flag for you to pass a file to try attacks with, this way you can just attack the targets found after searching 2017-09-27 14:14:08 -05:00
ekultek
166e918223 patched the XSS scanner, should work better now 2017-09-27 10:35:39 -05:00
ekultek
4ba8a8a0f4 close the display and browser after exception has been caught 2017-09-26 18:30:50 -05:00
ekultek
526807c7ff basic implement of Google IP bypass done (more work to be done) 2017-09-26 18:20:43 -05:00
ekultek
90d3798a93 created an XSS scanner for issue #8 2017-09-26 12:56:35 -05:00
Thomas Perkins
ed4820b8ee Merge pull request #12 from cclauss/modernize-python2-code
Fix urllib imports for Python 3
2017-09-25 14:14:37 -05:00
cclauss
b708f5627f Modernize Python 2 code to get ready for Python 3 2017-09-25 21:06:02 +02:00
ekultek
0b07d367e4 created a disclaimer that you have to accept to run the program. this will be shown once during the first run of the program. 2017-09-25 12:06:07 -05:00
ekultek
759a8d47c1 added a flag for nmap arguments, will also display a reference to sqlmap and nmap option man page if you have any questions 2017-09-25 11:27:56 -05:00
ekultek
6875605c98 patch for issue #2 install xvfb if it isn't there, also added it to the README requirements. 2017-09-25 11:08:32 -05:00
cclauss
73486352ec Simplify with dict comprehension
https://docs.python.org/2/tutorial/datastructures.html#dictionaries
2017-09-25 17:19:46 +02:00
cclauss
5186a0e533 Define raw_input() for Python 3
__raw_input()__ is called on lines 276 and 283 but it was removed from Python 3 in favor of __input()__.
2017-09-25 13:55:43 +02:00
ekultek
97ff5610c1 minor update to the spider, and errors thrown by it 2017-09-21 10:29:25 -05:00
ekultek
d0a0a8b9c5 patch for issue #1. Way to be the firstgit add --all 2017-09-21 10:14:42 -05:00
ekultek
909c817b6e patched an issue where the selenium proxy was not working 2017-09-20 17:36:19 -05:00
ekultek
36259f3a12 created an admin page finder for the found URL's 2017-09-20 17:19:20 -05:00
ekultek
47561c3aab added the ability to create arguments for nmap 2017-09-18 15:25:42 -05:00
ekultek
98e0c6b8b6 minor update so that if no hosts are found it will not default to the last log file 2017-09-14 13:42:04 -05:00
ekultek
3042b2e24c created a scan for Intel ME exploit 2017-09-13 16:38:54 -05:00
ekultek
6b4cc87e9d minor update when skipping a URL during sqlmap API scan 2017-09-11 11:48:56 -05:00
ekultek
2987f13021 created a website spider, will pull all useable URL's from a given webpage 2017-09-11 11:43:53 -05:00
ekultek
9900109a25 bumped version number 2017-09-11 09:46:03 -05:00
ekultek
ac89b9fc97 removed unused import 'time' 2017-09-11 09:45:39 -05:00
ekultek
729e9ee6dc bumped version number 2017-09-10 08:51:49 -05:00
ekultek
5aa3b19ec7 increased scanning time, sqlmap will scan faster now and not sleep as long 2017-09-10 08:51:36 -05:00
ekultek
bc02651e78 edited so that the type in the output won't be messed up 2017-09-10 08:50:41 -05:00
ekultek
7dc6d9b510 minor fix 2017-09-09 15:43:03 -05:00
ekultek
83f639f70d created random dork function and bumped version number 2017-09-09 08:37:32 -05:00
ekultek
118c0f1d2d edited the warning message to tell people they need to restart the sqlmap API server each iteration 2017-09-09 08:36:47 -05:00
ekultek
6023e1628c bumped version number, edited saying 2017-09-08 14:26:57 -05:00
ekultek
a5e204731f edited the nmap scan, it will work successfully and skip if nothing is found 2017-09-08 14:26:29 -05:00
ekultek
92baed3a9f edited the get_urls function to obfuscate user-agent changes 2017-09-08 10:12:24 -05:00
ekultek
b22180a82d minor change to output the current URL before sqlmap scan 2017-09-07 20:55:06 -05:00
ekultek
5432fdd15b initial release of Zeus - Advanced dork scanner 2017-09-07 12:54:16 -05:00