ekultek
|
3bced94e70
|
minor update for a privately reported issue, where the HTML would display the site in a small scroll box, will not display as the full site
|
2017-11-02 09:24:23 -05:00 |
|
ekultek
|
bc335fa2d3
|
created a clickjacking scanner that will test a page for an X-Frame-Options header, if the header is not there, then it will create a basic HTML page with that URL as an iframe
|
2017-11-01 21:48:58 -05:00 |
|
ekultek
|
d1adbcdc10
|
forgot to bump the version number
|
2017-11-01 10:08:22 -05:00 |
|
ekultek
|
b26d29108c
|
fixes an issue where the geckodriver will not connect, usually means something happened during the installation of it, will now attempt to re-install the geckodriver (issue #132)
|
2017-11-01 10:07:15 -05:00 |
|
ekultek
|
e85c13b2b8
|
minor update to the search.py file, X-Forwarded instead of X-Forward
|
2017-10-31 14:11:05 -05:00 |
|
ekultek
|
51db83833b
|
patch for a reported issue where it would fail with from a website with Unicode
|
2017-10-31 13:18:40 -05:00 |
|
ekultek
|
29b2ad69e2
|
update to tamper scripts, using kwargs instead of warning
|
2017-10-31 13:17:33 -05:00 |
|
ekultek
|
fec7935d42
|
forgot to update the version number
|
2017-10-31 09:49:35 -05:00 |
|
ekultek
|
99575425f1
|
fixes an issue where if you run in verbose mode with whois lookup it will error out if certain information is not found (issue #128), it will now display the JSON data if you run in verbose mode
|
2017-10-31 09:47:49 -05:00 |
|
ekultek
|
04cd49e722
|
added some new URL's to the skip schema, edited the DDG link to the HTML link, made sure that the URL is not just a protocol before adding to the file
|
2017-10-29 11:46:36 -05:00 |
|
ekultek
|
6030774303
|
a patch for a reported issue (private) where if the found sitemap already exists, it would error out. will not just write as plain text and warn you that it probably already exists, also fixes an issue where found admin pages where not saved to a log file, and finally moved the sitemap.xml and robots.txt searches to a single function
|
2017-10-29 11:00:28 -05:00 |
|
ekultek
|
182e588774
|
patched a privately reported issue that would not allow you to run the blackwidow crawler behind a proxy, forgot a space in the README file
|
2017-10-28 16:53:13 -05:00 |
|
ekultek
|
f75cabb876
|
added a new requirement BeautifulSoup, fixed the crawler will pull all links with an 'a' tag and descriptor of 'href', bumped version number
|
2017-10-28 16:28:18 -05:00 |
|
ekultek
|
0c8d4f9bf7
|
edited the default user agent so it will reflect the best practices of user agent strings (reference https://docs.developer.amazonservices.com/en_US/dev_guide/DG_UserAgentHeader.html)
|
2017-10-28 15:49:10 -05:00 |
|
ekultek
|
cf2cc59022
|
fix for the intel AMT exploit checker (messed it up without realizing it)
|
2017-10-28 08:26:47 -05:00 |
|
ekultek
|
46fc2372c9
|
created a sitemap parser, will check for a page sitemap and save it if it is found, otherwise will just continue processing
|
2017-10-28 08:25:58 -05:00 |
|
ekultek
|
073361339b
|
bumped the version number and edited the checksums to match the new updates
|
2017-10-28 08:25:13 -05:00 |
|
ekultek
|
ecf067b6bb
|
patch for unicode errors, it appears that selenium isn't formatted to handle unicode errors (as far as I can tell) so the dork that causes the error will be skipped (issue #125)
|
2017-10-27 17:14:08 -05:00 |
|
ekultek
|
6c46fd7523
|
splitting the shell commands via shlex will make the commands more secure, and able to avoid most shell injection instances
|
2017-10-25 16:32:55 -05:00 |
|
ekultek
|
6ba7231e82
|
splitting the shell commands via shlex will make the commands more secure, and able to avoid most shell injection instances
|
2017-10-25 16:32:27 -05:00 |
|
ekultek
|
bdcc28b412
|
you are now successfully able to launch the sqlmap API automatically using the --auto flag (issue #58)
|
2017-10-25 13:26:20 -05:00 |
|
ekultek
|
c7fedc0165
|
fixed the nmap issues, it will run now it will also install itself if it's not there. working on sqlmap autostart (still). moved the function to create sqlmap and nmap arguments to settings.py. created two new scripts (one is still a work in progess)
|
2017-10-24 01:22:21 -05:00 |
|
ekultek
|
f6888b59af
|
moved the find running opts function to settings, cleaning out the zeus.py file
|
2017-10-23 22:26:16 -05:00 |
|
ekultek
|
9cc673a05b
|
some minor changes to the WhoIs lookup, trying to prevent it from displaying empty lists and dicts
|
2017-10-23 22:25:37 -05:00 |
|
ekultek
|
a06371aa72
|
fixes an issue with unicode errors from XSS payloads (issue #124)
|
2017-10-23 14:11:03 -05:00 |
|
ekultek
|
242219ac8f
|
moved the search engine configuration to the settings file
|
2017-10-23 13:41:43 -05:00 |
|
ekultek
|
977564ae62
|
minor update where running through a file or dork would not allow you to parse webcache or pull all URLs, also updated some whois lookup info
|
2017-10-21 16:59:43 -05:00 |
|
ekultek
|
e2287391c3
|
created a whois lookup search. Will either display it in human readable form with the correct flags, or save the found information to a log file
|
2017-10-21 10:16:16 -05:00 |
|
ekultek
|
d813e70ac1
|
edited the way that the patch ID is displayed, will now pull the ID from origin/master
|
2017-10-21 08:45:19 -05:00 |
|
ekultek
|
b2ff3da457
|
the auto fix for program install error was in the wrong spot (issue #115), moved to correct spot. should work fine now
|
2017-10-19 18:30:17 -05:00 |
|
ekultek
|
a1426ea0a1
|
had some time so making some compatibility updates (issue #7). Also edited the auto issue, you'll have your own unique ID number now
|
2017-10-19 07:14:51 -05:00 |
|
ekultek
|
02a9f54544
|
created two new flags, one for parsing webcache, another for pulling all URLs. This will also produce more results per search.
|
2017-10-18 13:04:09 -05:00 |
|
ekultek
|
fddeb7b774
|
patches issue where zeus will only install one geckodriver version if your version is under 54 (issue #108)
|
2017-10-18 10:01:33 -05:00 |
|
ekultek
|
a17b2745d9
|
must pass a checksum verification before you can create a github issue
|
2017-10-17 15:12:32 -05:00 |
|
ekultek
|
c7071d3f18
|
adding a checksum for a verification that will be taking place in the next push
|
2017-10-17 14:51:39 -05:00 |
|
ekultek
|
1c24a4b4af
|
some minor edits done to the prorgam, grammar fixes, moved some functions, edited some things, nothing to major or important
|
2017-10-17 13:33:40 -05:00 |
|
ekultek
|
ea884a8138
|
some updates that include a script to re-install a dependency that tends to fail, and fix a proxy configuration issue
|
2017-10-17 09:05:10 -05:00 |
|
ekultek
|
a909ac6c74
|
updating some doc strings, will be updating them more in time. just wanted to go ahead and start on them for now
|
2017-10-16 10:03:35 -05:00 |
|
ekultek
|
fc782c71fb
|
patches an issue where zeus would only install one geckodriver version (issue #103)
|
2017-10-16 09:39:52 -05:00 |
|
ekultek
|
5375c15b9e
|
patches an issue where Zeus will always install the same geckodriver version (issue #102)
|
2017-10-15 09:10:51 -05:00 |
|
ekultek
|
65716493e7
|
added new geckodriver versions for different firefox versions, hoping this will help some what with issue #99 (at least until I can figure out a solid fix). will also now extract the gecko version installed for the auto-issues
|
2017-10-14 14:56:45 -05:00 |
|
ekultek
|
f3a5621d86
|
updated the auto issue to provide the firefox browser version as well
|
2017-10-14 09:26:33 -05:00 |
|
ekultek
|
21398eaf8a
|
patches an issue where the target refuses the connection (issue #97), also creates a way to run against the IP addresses of the hostname instead
|
2017-10-14 07:47:50 -05:00 |
|
ekultek
|
37f1669596
|
update to the geckodriver versions, it will extract the one that is correct for your system
|
2017-10-13 13:39:09 -05:00 |
|
ekultek
|
24cdc14e9e
|
minor patch to catch the geckodriver error, happens when firefox is not compatible (issue #94)
|
2017-10-13 13:15:46 -05:00 |
|
ekultek
|
bef138e4a8
|
patch for an issue where there HTML could not be parsed due to fake div classes (issue #91)
|
2017-10-13 10:10:20 -05:00 |
|
ekultek
|
6383abf69a
|
patch for an issue where to many sessions would be open, will now auto clean the sessions (issue #92)
|
2017-10-13 10:06:57 -05:00 |
|
ekultek
|
b380c6e7c4
|
added a catch for the max retries error, along with how to bypass it, good luck
|
2017-10-12 18:55:29 -05:00 |
|
ekultek
|
a05c26e376
|
patch for an issue where you could not run the enumerate file flag (-f)
|
2017-10-12 18:05:19 -05:00 |
|
ekultek
|
307751e14f
|
patch for an issue where the current URL could not be pulled due to a present alert (issue #81)
|
2017-10-12 17:53:45 -05:00 |
|
ekultek
|
c35fddb4ce
|
just cleaning up the parameters a little bit, not as messy now
|
2017-10-12 11:59:59 -05:00 |
|
ekultek
|
c008f93d16
|
multi-threading is broken, working on a fix, for now DO NOT use it
|
2017-10-12 10:43:13 -05:00 |
|
ekultek
|
799b6baba0
|
created some new extenstions and a threading flag for the admin panel finder
|
2017-10-11 17:47:18 -05:00 |
|
ekultek
|
859ea19c44
|
minor update to the initial fix for issue #58, supressing help until that part is done
|
2017-10-11 14:39:01 -05:00 |
|
ekultek
|
e9f5b82d05
|
initial push for an issue (#58) where it would not auto start sqlmap, lots more work to be done so make sure you start the sqlmap server before the process
|
2017-10-11 14:36:34 -05:00 |
|
ekultek
|
92a5b44548
|
patch for using Bing as the search engine, Bing apparently was not implemented, sorry
|
2017-10-10 19:41:17 -05:00 |
|
ekultek
|
f8614dc883
|
minor update to randomcase script, will now truly be random case
|
2017-10-10 18:16:49 -05:00 |
|
ekultek
|
9d97a6765a
|
created five new tamper scripts for XSS payloads
|
2017-10-10 17:59:01 -05:00 |
|
ekultek
|
80d9565585
|
files edited to reflect the move of the settings, errors, and tamper scripts folders
|
2017-10-10 17:01:13 -05:00 |
|
ekultek
|
269a27f886
|
moved tamper scripts outside of attacks folder
|
2017-10-10 17:00:18 -05:00 |
|
ekultek
|
a8d81d28ce
|
moved errors and settings to core folder
|
2017-10-10 16:59:51 -05:00 |
|
ekultek
|
5767f2e974
|
successfully extracts the URL from Google ban URL (issue #13)
|
2017-10-10 14:59:23 -05:00 |
|
ekultek
|
37cc3862a8
|
minor changes to the extraction schema
|
2017-10-09 16:45:37 -05:00 |
|
ekultek
|
e43ee8a0ca
|
skips google play and google maps, also extracts correctly from webcache with out error (issue #55)
|
2017-10-09 16:09:50 -05:00 |
|
ekultek
|
a10d8d5825
|
minor edit to search.py removed sqlmap_api_directions.txt
|
2017-10-09 10:56:25 -05:00 |
|
ekultek
|
f9577d0365
|
edited so that the file to be read from depends on the command you use instead of defaulting to URL_LOG
|
2017-10-08 08:21:17 -05:00 |
|
ekultek
|
4188c2c37c
|
fixes issue where it tries to run the attacks no matter what happens (issue #54)
|
2017-10-08 07:47:01 -05:00 |
|
ekultek
|
2937e9c759
|
patch for an error that occurs when firefox is not found (issue #52)
|
2017-10-08 07:39:05 -05:00 |
|
ekultek
|
b52f301358
|
branch issue fix #1
|
2017-10-07 09:34:03 -05:00 |
|
ekultek
|
671e77b984
|
patch for issue #49, bo longer need to restart the sqlmap API each iteration
|
2017-10-07 08:09:16 -05:00 |
|
ekultek
|
97b620aef4
|
initial fix for issue #49, still more work to be done
|
2017-10-05 21:21:51 -05:00 |
|
ekultek
|
3004ca5595
|
can now extract from google webcache URL's
|
2017-10-04 14:15:54 -05:00 |
|
ekultek
|
1e71aaa5f5
|
gave write_to_file function ability to write list, tuple, set to files (issue #40)
|
2017-10-04 07:07:43 -05:00 |
|
ekultek
|
7cf2d26e89
|
bumped version number
|
2017-10-03 14:54:04 -05:00 |
|
ekultek
|
94dac1c2bc
|
added the ability to search multiple pages of Google (issue #4)
|
2017-10-03 11:19:16 -05:00 |
|
ekultek
|
008ee37362
|
minor edit to skip safe characters in encoding
|
2017-10-03 11:18:13 -05:00 |
|
ekultek
|
d813942c55
|
created three new tamper scripts and added warnings to other ones
|
2017-10-02 12:10:34 -05:00 |
|
ekultek
|
c618647eeb
|
created three new tamper scripts and added warnings to other ones
|
2017-10-02 12:10:15 -05:00 |
|
ekultek
|
67a1738278
|
minor change to sqlmap scan, will not output '{}' if there are no arguments passed
|
2017-10-01 08:28:14 -05:00 |
|
ekultek
|
4cf72fc97b
|
patch for issue #22, will not shutdown if the provided URL is not valid with an error message instead of throwing an exception
|
2017-10-01 08:06:03 -05:00 |
|
ekultek
|
f87f63d3b0
|
added a file for those that don't know how to use sqlmap, also minor fix to extract your log file.
|
2017-09-30 08:26:36 -05:00 |
|
ekultek
|
ceca62c4b4
|
auto issue creation, also caught an error, apparently it's really hard to understand tHAT SQLMAP NEEDS TO BE STARTED IN ORDER TO WORK
|
2017-09-30 08:01:40 -05:00 |
|
ekultek
|
daca2ac1a2
|
patch for file logging issue (issue #10)
|
2017-09-29 17:46:54 -05:00 |
|
ekultek
|
f38ec5f65f
|
adding support for python 3 (issue #7) if you find any issues with python3 please make an issue there
|
2017-09-29 14:28:53 -05:00 |
|
ekultek
|
3e4e37042a
|
complete re-write of intel AMT bypass, proxy and user agent configuration added for issue #9
|
2017-09-29 13:58:46 -05:00 |
|
ekultek
|
024e660853
|
created a tamper script for URL encoding, created tamper warnings, minor update to search.py, bumped version number
|
2017-09-29 10:21:26 -05:00 |
|
ekultek
|
9de772204e
|
creating tamper scripts for the XSS payloads
|
2017-09-28 11:16:48 -05:00 |
|
ekultek
|
bf922eeb7c
|
fixed the blackwidow log file issue #14
|
2017-09-28 11:16:21 -05:00 |
|
ekultek
|
83e0a5a436
|
updates to the XSS scanner, will successfully output if possible sqli is present or not, and only display the information once
|
2017-09-27 18:02:55 -05:00 |
|
ekultek
|
09d3bf1067
|
created a flag for you to pass a file to try attacks with, this way you can just attack the targets found after searching
|
2017-09-27 14:14:08 -05:00 |
|
ekultek
|
166e918223
|
patched the XSS scanner, should work better now
|
2017-09-27 10:35:39 -05:00 |
|
ekultek
|
4ba8a8a0f4
|
close the display and browser after exception has been caught
|
2017-09-26 18:30:50 -05:00 |
|
ekultek
|
526807c7ff
|
basic implement of Google IP bypass done (more work to be done)
|
2017-09-26 18:20:43 -05:00 |
|
ekultek
|
90d3798a93
|
created an XSS scanner for issue #8
|
2017-09-26 12:56:35 -05:00 |
|
Thomas Perkins
|
ed4820b8ee
|
Merge pull request #12 from cclauss/modernize-python2-code
Fix urllib imports for Python 3
|
2017-09-25 14:14:37 -05:00 |
|
cclauss
|
b708f5627f
|
Modernize Python 2 code to get ready for Python 3
|
2017-09-25 21:06:02 +02:00 |
|
ekultek
|
0b07d367e4
|
created a disclaimer that you have to accept to run the program. this will be shown once during the first run of the program.
|
2017-09-25 12:06:07 -05:00 |
|
ekultek
|
759a8d47c1
|
added a flag for nmap arguments, will also display a reference to sqlmap and nmap option man page if you have any questions
|
2017-09-25 11:27:56 -05:00 |
|
ekultek
|
6875605c98
|
patch for issue #2 install xvfb if it isn't there, also added it to the README requirements.
|
2017-09-25 11:08:32 -05:00 |
|
cclauss
|
73486352ec
|
Simplify with dict comprehension
https://docs.python.org/2/tutorial/datastructures.html#dictionaries
|
2017-09-25 17:19:46 +02:00 |
|
cclauss
|
5186a0e533
|
Define raw_input() for Python 3
__raw_input()__ is called on lines 276 and 283 but it was removed from Python 3 in favor of __input()__.
|
2017-09-25 13:55:43 +02:00 |
|
ekultek
|
97ff5610c1
|
minor update to the spider, and errors thrown by it
|
2017-09-21 10:29:25 -05:00 |
|
ekultek
|
d0a0a8b9c5
|
patch for issue #1. Way to be the firstgit add --all
|
2017-09-21 10:14:42 -05:00 |
|
ekultek
|
909c817b6e
|
patched an issue where the selenium proxy was not working
|
2017-09-20 17:36:19 -05:00 |
|
ekultek
|
36259f3a12
|
created an admin page finder for the found URL's
|
2017-09-20 17:19:20 -05:00 |
|
ekultek
|
47561c3aab
|
added the ability to create arguments for nmap
|
2017-09-18 15:25:42 -05:00 |
|
ekultek
|
98e0c6b8b6
|
minor update so that if no hosts are found it will not default to the last log file
|
2017-09-14 13:42:04 -05:00 |
|
ekultek
|
3042b2e24c
|
created a scan for Intel ME exploit
|
2017-09-13 16:38:54 -05:00 |
|
ekultek
|
6b4cc87e9d
|
minor update when skipping a URL during sqlmap API scan
|
2017-09-11 11:48:56 -05:00 |
|
ekultek
|
2987f13021
|
created a website spider, will pull all useable URL's from a given webpage
|
2017-09-11 11:43:53 -05:00 |
|
ekultek
|
9900109a25
|
bumped version number
|
2017-09-11 09:46:03 -05:00 |
|
ekultek
|
ac89b9fc97
|
removed unused import 'time'
|
2017-09-11 09:45:39 -05:00 |
|
ekultek
|
729e9ee6dc
|
bumped version number
|
2017-09-10 08:51:49 -05:00 |
|
ekultek
|
5aa3b19ec7
|
increased scanning time, sqlmap will scan faster now and not sleep as long
|
2017-09-10 08:51:36 -05:00 |
|
ekultek
|
bc02651e78
|
edited so that the type in the output won't be messed up
|
2017-09-10 08:50:41 -05:00 |
|
ekultek
|
7dc6d9b510
|
minor fix
|
2017-09-09 15:43:03 -05:00 |
|
ekultek
|
83f639f70d
|
created random dork function and bumped version number
|
2017-09-09 08:37:32 -05:00 |
|
ekultek
|
118c0f1d2d
|
edited the warning message to tell people they need to restart the sqlmap API server each iteration
|
2017-09-09 08:36:47 -05:00 |
|
ekultek
|
6023e1628c
|
bumped version number, edited saying
|
2017-09-08 14:26:57 -05:00 |
|
ekultek
|
a5e204731f
|
edited the nmap scan, it will work successfully and skip if nothing is found
|
2017-09-08 14:26:29 -05:00 |
|
ekultek
|
92baed3a9f
|
edited the get_urls function to obfuscate user-agent changes
|
2017-09-08 10:12:24 -05:00 |
|
ekultek
|
b22180a82d
|
minor change to output the current URL before sqlmap scan
|
2017-09-07 20:55:06 -05:00 |
|
ekultek
|
5432fdd15b
|
initial release of Zeus - Advanced dork scanner
|
2017-09-07 12:54:16 -05:00 |
|