2016-02-05 16:15:09 +01:00
|
|
|
#!/usr/bin/env python2
|
|
|
|
# -*-coding:UTF-8 -*
|
|
|
|
import time
|
2016-07-26 10:45:02 +02:00
|
|
|
import sys
|
2016-02-05 16:15:09 +01:00
|
|
|
from packages import Paste
|
2016-02-10 16:39:06 +01:00
|
|
|
from pubsublogger import publisher
|
2016-02-05 16:15:09 +01:00
|
|
|
from Helper import Process
|
|
|
|
import re
|
2016-07-26 10:45:02 +02:00
|
|
|
from pyfaup.faup import Faup
|
2016-02-05 16:15:09 +01:00
|
|
|
|
2016-02-10 16:39:06 +01:00
|
|
|
if __name__ == "__main__":
|
|
|
|
publisher.port = 6380
|
|
|
|
publisher.channel = "Script"
|
|
|
|
config_section = "Credential"
|
|
|
|
p = Process(config_section)
|
|
|
|
publisher.info("Find credentials")
|
|
|
|
|
2016-08-08 09:17:44 +02:00
|
|
|
faup = Faup()
|
|
|
|
|
2016-02-10 17:31:52 +01:00
|
|
|
critical = 8
|
2016-02-10 16:39:06 +01:00
|
|
|
|
2016-02-11 12:19:03 +01:00
|
|
|
regex_web = "((?:https?:\/\/)[-_0-9a-zA-Z]+\.[0-9a-zA-Z]+)"
|
2016-02-10 16:39:06 +01:00
|
|
|
regex_cred = "[a-zA-Z0-9._-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,6}:[a-zA-Z0-9\_\-]+"
|
2016-07-25 16:38:57 +02:00
|
|
|
regex_site_for_stats = "@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,6}:"
|
2016-02-10 16:39:06 +01:00
|
|
|
while True:
|
2016-02-10 17:31:52 +01:00
|
|
|
message = p.get_from_set()
|
|
|
|
if message is None:
|
2016-02-10 16:39:06 +01:00
|
|
|
publisher.debug("Script Credential is Idling 10s")
|
|
|
|
time.sleep(10)
|
|
|
|
continue
|
|
|
|
|
2016-02-10 17:31:52 +01:00
|
|
|
filepath, count = message.split()
|
|
|
|
|
|
|
|
if count < 5:
|
|
|
|
# Less than 5 matches from the top password list, false positive.
|
|
|
|
continue
|
|
|
|
|
2016-02-10 16:39:06 +01:00
|
|
|
paste = Paste.Paste(filepath)
|
|
|
|
content = paste.get_p_content()
|
|
|
|
creds = set(re.findall(regex_cred, content))
|
|
|
|
if len(creds) == 0:
|
|
|
|
continue
|
|
|
|
|
2016-07-26 10:45:02 +02:00
|
|
|
sites= re.findall(regex_web, content) #Use to count occurences
|
|
|
|
sites_set = set(re.findall(regex_web, content))
|
2016-02-10 16:39:06 +01:00
|
|
|
|
2016-02-11 12:19:03 +01:00
|
|
|
message = 'Checked {} credentials found.'.format(len(creds))
|
2016-07-26 10:45:02 +02:00
|
|
|
if sites_set:
|
|
|
|
message += ' Related websites: {}'.format(', '.join(sites_set))
|
2016-02-10 16:39:06 +01:00
|
|
|
|
2016-10-27 11:50:24 +02:00
|
|
|
to_print = 'Credential;{};{};{};{};{}'.format(paste.p_source, paste.p_date, paste.p_name, message, paste.p_path)
|
2016-02-10 16:39:06 +01:00
|
|
|
|
|
|
|
print('\n '.join(creds))
|
|
|
|
|
|
|
|
if len(creds) > critical:
|
2016-02-10 17:31:52 +01:00
|
|
|
print("========> Found more than 10 credentials in this file : {}".format(filepath))
|
2016-02-10 16:39:06 +01:00
|
|
|
publisher.warning(to_print)
|
2016-07-18 16:22:33 +02:00
|
|
|
#Send to duplicate
|
2016-07-25 16:38:57 +02:00
|
|
|
p.populate_set_out(filepath, 'Duplicate')
|
2016-08-08 11:37:18 +02:00
|
|
|
#Send to BrowseWarningPaste
|
2016-08-08 09:17:44 +02:00
|
|
|
p.populate_set_out('credential;{}'.format(filepath), 'BrowseWarningPaste')
|
2016-07-25 16:38:57 +02:00
|
|
|
|
2016-07-26 10:45:02 +02:00
|
|
|
#Put in form, count occurences, then send to moduleStats
|
2016-07-25 16:38:57 +02:00
|
|
|
creds_sites = {}
|
2016-08-08 11:37:18 +02:00
|
|
|
site_occurence = re.findall(regex_site_for_stats, content)
|
|
|
|
for site in site_occurence:
|
|
|
|
site_domain = site[1:-1]
|
|
|
|
if site_domain in creds_sites.keys():
|
|
|
|
creds_sites[site_domain] += 1
|
|
|
|
else:
|
|
|
|
creds_sites[site_domain] = 1
|
|
|
|
|
2016-07-26 10:45:02 +02:00
|
|
|
for url in sites:
|
|
|
|
faup.decode(url)
|
|
|
|
domain = faup.get()['domain']
|
|
|
|
if domain in creds_sites.keys():
|
|
|
|
creds_sites[domain] += 1
|
|
|
|
else:
|
|
|
|
creds_sites[domain] = 1
|
|
|
|
|
2016-07-25 16:38:57 +02:00
|
|
|
for site, num in creds_sites.iteritems(): # Send for each different site to moduleStats
|
2016-08-08 11:37:18 +02:00
|
|
|
print 'credential;{};{};{}'.format(num, site, paste.p_date)
|
|
|
|
p.populate_set_out('credential;{};{};{}'.format(num, site, paste.p_date), 'ModuleStats')
|
2016-07-25 16:38:57 +02:00
|
|
|
|
2016-07-26 10:45:02 +02:00
|
|
|
if sites_set:
|
|
|
|
print("=======> Probably on : {}".format(', '.join(sites_set)))
|
2016-02-10 16:39:06 +01:00
|
|
|
else:
|
|
|
|
publisher.info(to_print)
|