Posts

Showing posts with the label Shodan

Djangohunter - Tool Designed To Attention Pose Incorrectly Configured Django Applications That Are Exposing Sensitive Information

Image
Tool designed to attention position incorrectly configured Django applications that are exposing sensitive information. https://www.reddit.com/r/django/comments/87qcf4/28165_thousand_django_running_servers_are_exposed/ https://twitter.com/6ix7ine/status/978598496658960384?lang=en Usage Usage: python3 djangohunter.py --key {shodan} Dorks: 'DisallowedHost', 'KeyError', 'OperationalError', 'Page non industrial plant life at /' Requirements Shodan Pyfiglet Requests BeautifulSoup pip -r install requirements Demo Disclaimer Code samples are provided for educational purposes. Adequate defenses tin move solely survive built yesteryear researching assail techniques available to malicious actors. Using this code against target systems without prior permission is illegal inwards almost jurisdictions. The authors are non liable for whatever damages from misuse of this information or code. Download Djangohunter

Cloudbunny - A Tool To Capture The Existent Ip Of The Server That Uses A Waf Equally A Proxy Or Protection

Image
CloudBunny is a tool to capture the existent IP of the server that uses a WAF every bit a proxy or protection. How works In this tool nosotros used 3 search engines to search domain information: Shodan, Censys in addition to Zoomeye. To role the tools yous postulate the API Keys, yous tin pick upwards the next links: Shodan - https://account.shodan.io/ Censys - https://censys.io/account/api ZoomEye - https://www.zoomeye.org/profile NOTE : In Zoomeye yous postulate to teach into the login in addition to password, it generates a dynamic api fundamental in addition to I already produce this operate for you. Just teach into your login in addition to password. After that yous postulate to position the credentials inwards the api.conf file. Install the requirements: $ sudo pip install -r requirements.txt Usage By default the tool searches on all search engines (you tin laid this upwards past times arguments), precisely yous postulate to position the credentials every bit sta...

Kamerka - Construct Interactive Map Of Cameras From Shodan

Image
Build an interactive map of cameras from Shodan. The script creates a map of Shodan cameras based on your address or coordinates. https://medium.com/@woj_ciech/%EA%93%98amerka-build-interactive-map-of-cameras-from-shodan-a0267849ec0a Requirements Shodan Geopy Foilum Colorama pip install -r requirements.txt Change API_KEY inwards work 14 Restrictions It tin plow over notice live on used exclusively amongst a paid Shodan plan. Build amongst Python 2. Usage root@kali: python kamerka.py --address "White House" White House, 1600, Pennsylvania Avenue Northwest, Golden Triangle, Washington, D.C., 20500, USA Found 81 results IP: xxx.xxx.xxx.xxx Coordinates: 38.xxx,-77.xxx ----------------------------------- IP: xxx.xxx.xxx.xxx Coordinates: 38.xxx,-77.xxx ----------------------------------- IP: xxx.xxx.xxx.xxx Coordinates: 38.xxx,-77.xxx ----------------------------------- ... ----------------------------------- IP: xxx.xxx.xxx.xxx Coordinates: 38.xxx,-77.xxx ---...

Theharvester V3.0.3 - E-Mails, Subdomains In Addition To Names Harvester (Osint)

Image
theHarvester is a tool for gathering subdomain names, electronic mail addresses, virtual hosts, opened upward ports/ banners, too employee names from unlike world sources (search engines, pgp fundamental servers). Is a actually uncomplicated tool, but really effective for the early on stages of a penetration examination or but to know the visibility of your companionship inward the Internet. The sources are: Passive : threatcrowd: Open source threat intelligence - https://www.threatcrowd.org/ crtsh: Comodo Certificate search - www.crt.sh google: google search engine - www.google.com (With optional google dorking) googleCSE: google custom search engine google-profiles: google search engine, specific search for Google profiles bing: microsoft search engine - www.bing.com bingapi: microsoft search engine, through the API (you require to add together your Key inward the discovery/bingsearch.py file) dogpile: Dogpile search engine - www.dogpile.com ...

Infoga - E-Mail Osint

Image
Infoga is a tool gathering electronic mail accounts informations (ip,hostname,country,...) from dissimilar world source (search engines, pgp substitution servers in addition to shodan) in addition to banking concern agree if emails was leaked using haveibeenpwned.com API. Is a actually unproblematic tool, but really effective for the early on stages of a penetration test or only to know the visibility of your society inward the Internet.  Installation $ git clone https://github.com/m4ll0k/Infoga.git infoga $ cd infoga $ python setup.py install $ python infoga.py Usage $ python infoga.py --domain nsa.gov --source all --breach -v ii --report ../nsa_gov.txt $ python infoga.py --info m4ll0k@protonmail.com --breach -v three --report ../m4ll0k.txt Download Infoga

Shodanploit - Shodan Ascendancy Trouble Interface Written Inwards Python

Image
Shodan is a search engine on the cyberspace where y'all tin discovery interesting things all over the world. For example, nosotros tin discovery cameras, bitcoin streams, zombie computers, ports alongside weakness inwards service, SCADA systems, as well as more. Moreover, to a greater extent than specific searches are possible. As a number of the search, Shodan shows us the number of vulnerable hosts on Earth. So what does shodansploit produce ? With Shodan Exploit, y'all volition bring all your calls on your terminal. It also allows y'all to brand detailed searches. All y'all bring to produce without running Shodansploiti is to add together shodan api. Note : The character of the search volition alter according to the api privileges y'all bring used. Shodan API Documention : REST API Documentation Exploits REST API Documentation Shodan API Specification : Banner Specification The banner is the principal type of inform...

Crashcast-Exploit - This Tool Allows Y'all Volume Play Whatever Youtube Video Amongst Chromecasts Obtained From Shodan.Io

Image
This tool allows you lot to volume play whatever YouTube video alongside Chromecasts obtained from Shodan.io Author:  @037 Prerequisites The alone affair you lot need installed is Python 3.x sudo apt-get install python3 You also require to accept cURL installed sudo apt-get install curl You also require Shodan python module pip install shodan Using Shodan API This tool requires you lot to ain an upgraded Shodan API You may obtain ane for gratis inwards Shodan if you lot sign upwards using a .edu email Download Crashcast-Exploit

Aztarna - A Footprinting Tool For Robots

Image
This repository contains Alias Robotics' aztarna, a footprinting tool for robots. Alias Robotics supports original robot manufacturers assessing their safety too improving their character of software. By no way nosotros encourage or promote the unauthorized tampering amongst running robotic systems. This tin displace serious human harm too cloth damages. For ROS A listing of the ROS nodes acquaint inward the organisation (Publishers too Subscribers) For each node, the published too subscribed topis including the theme type For each node, the ROS services each of the nodes offer A listing of all ROS parameters acquaint inward the Parameter Server A listing of the active communications running inward the system. H5N1 unmarried communication includes the involved publiser/subscriber nodes too the topics For SROS Determining if the organisation is a SROS master. Detecting if demo configuration is inward use. A listing of the nodes institute inward the system. (E...

Leaklooker - Discovery Opened Upward Databases Alongside Shodan

Image
Find opened upward databases alongside Shodan Background: https://medium.com/@woj_ciech/leaklooker-find-open-databases-in-a-second-9da4249c8472 Requirements: Python 3 Shodan paid plan, except Kibana search Put your Shodan API cardinal inwards business 65 pip3 install shodan pip3 install colorama pip3 install hurry.filesize Usage root@kali: /# python leaklooker.py -h , )\ / \ ' # ' ', ,' `' , )\ / \ ' ' ', ,' `' LeakLooker - Find opened upward databases https://medium.com/@woj_ciech https://github.com/woj-ciech/ usage: leaklooker.py [-h] [--elastic] [--couchdb] [--mongodb] [--kibana] [--first FIRST] [--last LAST] LeakLooker optional arguments: -h, --help exhibit this aid message together with instruct out --elastic Elasti search (default: False) --couchdb CouchDB (default: False) --...

Osint-Spy - Search Using Osint (Open Rootage Intelligence)

Image
Performs OSINT scan on email/domain/ip_address/organization using OSINT-SPY. It tin hold upward used past times Data Miners, Infosec Researchers, Penetration Testers too cyber criminal offence investigator inwards social club to uncovering deep information close their target. OSINT-SPY Documentation (beta) File Name : README Author : @sk_security Version : 0.0.1 Website : osint-spy.com Overview of this tool: Perform scan on IP Address / domain / e-mail address / BTC(bitcoin) address / device Find out latest bitcoin block information List out all the ciphers supported past times especial website too server Check whether a especial website is vulnerable to heartbleed or non ? Dump all the contacts too messages from skype database Analyze malware or malicous file remotely Licenses information OSINT-SPY too its documents are covered alongside GPL-3.0 (General Public License v3.0) Using OSINT-SPY @@@@@@@@@ @@@@@@@@@ | ...

Hostintel - A Modular Python Application To Collect Tidings For Malicious Hosts

Image
This tool is used to collect diverse intelligence sources for hosts. Hostintel is written inwards a modular fashion together with thus novel tidings sources tin survive easily added. Hosts are identified past times FQDN host name, Domain, or IP address. This tool exclusively supports IPv4 at the moment. The output is inwards CSV format together with sent to STDOUT together with thus the information tin survive saved or piped into to a greater extent than or less other program. Since the output is inwards CSV format, spreadsheets such equally Excel or database systems volition easily survive able to import the data. I created a brusque introduction for this tool on YouTube: https://youtu.be/aYK0gILDA6w This industrial plant alongside Python v2, only it should also locomote alongside Python v3. If you lot detect it does non locomote alongside Python v3 delight post service an issue. Help Screen: $ python hostintel.py -h usage: hostintel.py [-h] [-a] [-d] [-v] [-p] [-s] [-c] [-t...

Just-Metadata - Tool That Gathers Too Analyzes Metadata Nearly Ip Addresses

Image
Just-Metadata is a tool that tin give notice last used to get together intelligence information passively close a large lay out of IP addresses, as well as movement to extrapolate relationships that mightiness non otherwise last seen. Just-Metadata has "gather" modules which are used to get together metadata close IPs loaded into the framework across multiple resources on the internet. Just-Metadata also has "analysis" modules. These are used to analyze the information loaded Just-Metadata as well as perform diverse operations that tin give notice position potential relationships betwixt the loaded systems. Just-Metadata volition allow yous to speedily honour the Top "X" lay out of states, cities, timezones, etc. that the loaded IP addresses are located in. It volition allow yous to search for IP addresses yesteryear country. You tin give notice search all IPs to honour which ones are used inwards callbacks equally identified yesteryear VirusTotal....

Pocsuite3 - An Open-Sourced Remote Vulnerability Testing Framework

Image
pocsuite3 is an open-sourced remote vulnerability testing in addition to proof-of-concept evolution framework developed past times the Knownsec 404 Team . It comes amongst a powerful proof-of-concept engine, many powerful features for the ultimate penetration testers in addition to safety researchers. Features PoC scripts tin running amongst attack , verify , shell agency inwards dissimilar way Plugin ecosystem Dynamic loading PoC script from whatever where (local file, redis , database, Seebug ...) Load multi-target from whatever where (CIDR, local file, redis , database, Zoomeye, Shodan ...) Results tin hold out easily exported Dynamic piece in addition to claw requests Both command line tool in addition to python package import to use IPV6 support Global HTTP/HTTPS/SOCKS proxy support Simple spider API for PoC script to use Integrate amongst Seebug (for charge PoC from Seebug website) Integrate amongst ZoomEye (for charge target from ZoomEye Dork ) Integrate a...

Osint-Search - Useful For Digital Forensics Investigations Or Initial Black-Box Pentest Footprinting

Image
OSINT-Search is a useful tool for digital forensics investigations or initial black-box pentest footprinting. OSINT-Search Description Script inward Python that applies OSINT techniques past times searching populace information using e-mail addresses, telephone numbers, domains, IP addresses or URLs. Create an trouble organisation human relationship at https://pipl.com/api in addition to larn the API key. Create an trouble organisation human relationship at https://www.opencnam.com/ in addition to larn the Account SID in addition to Auth Token. Create an trouble organisation human relationship at https://www.shodan.io/ in addition to larn the Shodan API key. Create an trouble organisation human relationship at https://whatcms.org/API in addition to larn the WhatCMS API key. Create an trouble organisation human relationship at https://censys.io/register in addition to larn the API ID in addition to API secret. Create an trouble organisation human relationship at http...

Kubolt - Utility For Scanning Populace Kubernetes Clusters

Image
Kubolt is a uncomplicated utility for scanning populace unauthinticated kubernetes clusters together with run commands within containers. Why? Sometimes, the kubelet port 10250 is opened upwards to unauthorized access together with makes it possible to run commands within the containers using getrun constituent from kubelet : // getRun handles requests to run a ascendency within a container. func (s *Server) getRun(request *restful.Request, answer *restful.Response) { params := getExecRequestParams(request) pod, ok := s.host.GetPodByName(params.podNamespace, params.podName) if !ok { response.WriteError(http.StatusNotFound, fmt.Errorf("pod does non exist")) render } How? Okay, let's inquire our friend Shodan The basic enquiry is ssl:true port:10250 404 Kubelet uses port 10250 alongside SSL yesteryear default, 404 is the HTTP answer without URL path. Kubolt asks Shodan yesteryear API for listing of IP addresses together with keeps them for oth...

Metabigor - Dominance Business Search Engines Without Whatsoever Api Key

Image
Command trace Search Engine without whatsoever API key. What is Metabigor? Metabigor allows y'all produce enquiry from command line to awesome Search Engines (like Shodan, Censys, Fofa, etc) without whatsoever API key. But Why Metabigor? Don't role your API telephone commutation together with then y'all don't convey to worry most litmit of API quotation. * Do enquiry from ascendance trace without Premium account. * Get to a greater extent than lawsuit without Premium account. * But I convey an Premium trace of piece of job organisation human relationship why produce I demand this shit? Again Metabigor volition non lose your API quotation. Your enquiry volition optimized together with then y'all gonna instruct to a greater extent than lawsuit than using it past times manus or API key. Never instruct duplicate result. * How it works? Metabigor gonna role your cookie or non to copy search from browser together with opti...