AIL-framework/bin/CreditCards.py

86 lines
3.1 KiB
Python
Raw Normal View History

2018-05-04 13:53:29 +02:00
#!/usr/bin/env python3
# -*-coding:UTF-8 -*
"""
The CreditCards Module
======================
This module is consuming the Redis-list created by the Categ module.
It apply credit card regexes on paste content and warn if above a threshold.
"""
2014-08-14 17:55:18 +02:00
import pprint
import time
from packages import Paste
from packages import lib_refine
from pubsublogger import publisher
2014-09-05 17:05:45 +02:00
import re
2018-04-16 14:50:04 +02:00
import sys
2014-09-05 17:05:45 +02:00
from Helper import Process
2014-08-20 15:14:57 +02:00
if __name__ == "__main__":
publisher.port = 6380
2014-08-20 15:14:57 +02:00
publisher.channel = "Script"
config_section = 'CreditCards'
2014-08-14 17:55:18 +02:00
p = Process(config_section)
# FUNCTIONS #
publisher.info("CreditCards script started")
creditcard_regex = "4[0-9]{12}(?:[0-9]{3})?"
2014-09-05 17:05:45 +02:00
# Source: http://www.richardsramblings.com/regex/credit-card-numbers/
cards = [
r'\b4\d{3}(?:[\ \-]?)\d{4}(?:[\ \-]?)\d{4}(?:[\ \-]?)\d{4}\b', # 16-digit VISA, with separators
r'\b5[1-5]\d{2}(?:[\ \-]?)\d{4}(?:[\ \-]?)\d{4}(?:[\ \-]?)\d{4}\b', # 16 digits MasterCard
r'\b6(?:011|22(?:(?=[\ \-]?(?:2[6-9]|[3-9]))|[2-8]|9(?=[\ \-]?(?:[01]|2[0-5])))|4[4-9]\d|5\d\d)(?:[\ \-]?)\d{4}(?:[\ \-]?)\d{4}(?:[\ \-]?)\d{4}\b', # Discover Card
r'\b35(?:2[89]|[3-8]\d)(?:[\ \-]?)\d{4}(?:[\ \-]?)\d{4}(?:[\ \-]?)\d{4}\b', # Japan Credit Bureau (JCB)
r'\b3[47]\d\d(?:[\ \-]?)\d{6}(?:[\ \-]?)\d{5}\b', # American Express
r'\b(?:5[0678]\d\d|6304|6390|67\d\d)\d{8,15}\b', # Maestro
2014-09-05 17:05:45 +02:00
]
regex = re.compile('|'.join(cards))
while True:
2014-09-05 17:05:45 +02:00
message = p.get_from_set()
2014-08-14 17:55:18 +02:00
if message is not None:
2014-09-05 17:05:45 +02:00
filename, score = message.split()
paste = Paste.Paste(filename)
content = paste.get_p_content()
all_cards = re.findall(regex, content)
if len(all_cards) > 0:
2018-04-16 14:50:04 +02:00
print('All matching', all_cards)
2014-08-14 17:55:18 +02:00
creditcard_set = set([])
2014-09-05 17:05:45 +02:00
for card in all_cards:
clean_card = re.sub('[^0-9]', '', card)
2018-04-16 14:50:04 +02:00
clean_card = clean_card
2014-09-05 17:05:45 +02:00
if lib_refine.is_luhn_valid(clean_card):
2018-04-16 14:50:04 +02:00
print(clean_card, 'is valid')
2014-09-05 17:05:45 +02:00
creditcard_set.add(clean_card)
2014-08-14 17:55:18 +02:00
pprint.pprint(creditcard_set)
2014-08-20 15:14:57 +02:00
to_print = 'CreditCard;{};{};{};'.format(
2014-09-05 17:05:45 +02:00
paste.p_source, paste.p_date, paste.p_name)
2014-08-14 17:55:18 +02:00
if (len(creditcard_set) > 0):
publisher.warning('{}Checked {} valid number(s);{}'.format(
2018-11-02 16:07:27 +01:00
to_print, len(creditcard_set), paste.p_rel_path))
2018-04-16 14:50:04 +02:00
print('{}Checked {} valid number(s);{}'.format(
2018-11-02 16:07:27 +01:00
to_print, len(creditcard_set), paste.p_rel_path))
#Send to duplicate
p.populate_set_out(filename, 'Duplicate')
2018-05-16 14:39:01 +02:00
msg = 'infoleak:automatic-detection="credit-card";{}'.format(filename)
p.populate_set_out(msg, 'Tags')
else:
2018-11-02 16:07:27 +01:00
publisher.info('{}CreditCard related;{}'.format(to_print, paste.p_rel_path))
else:
publisher.debug("Script creditcard is idling 1m")
2014-09-05 17:05:45 +02:00
time.sleep(10)