0799bfbae8
Sanitized version of red team infrastructure automation platform. Operational content (implant pipelines, lures, credential capture) replaced with documented stubs. Architecture and infrastructure automation code intact.
231 lines
7.9 KiB
Bash
Executable File
231 lines
7.9 KiB
Bash
Executable File
#!/bin/bash
|
|
# Web Application Enumeration Script for Attack Box
|
|
# Usage: ./web_enum_automation.sh <target_url>
|
|
|
|
set -e
|
|
|
|
if [ $# -eq 0 ]; then
|
|
echo "Usage: $0 <target_url>"
|
|
echo "Example: $0 https://example.com"
|
|
echo " $0 http://10.0.0.100:8080"
|
|
exit 1
|
|
fi
|
|
|
|
TARGET_URL="$1"
|
|
# Extract domain/IP for workspace naming
|
|
TARGET_CLEAN=$(echo "$TARGET_URL" | sed 's|https\?://||g' | sed 's|/.*||g' | tr ':' '_')
|
|
WORKSPACE="/root/operator/scans/web/$TARGET_CLEAN"
|
|
DATE=$(date +%Y%m%d_%H%M%S)
|
|
|
|
# Colors for output
|
|
RED='\033[0;31m'
|
|
GREEN='\033[0;32m'
|
|
YELLOW='\033[1;33m'
|
|
BLUE='\033[0;34m'
|
|
NC='\033[0m' # No Color
|
|
|
|
echo -e "${GREEN}[+] Starting web enumeration for: $TARGET_URL${NC}"
|
|
|
|
# Create workspace
|
|
mkdir -p "$WORKSPACE"
|
|
cd "$WORKSPACE"
|
|
|
|
# Create log file
|
|
LOG_FILE="web_enum_$DATE.log"
|
|
echo "Web enumeration started at $(date)" > "$LOG_FILE"
|
|
|
|
# Function to log and execute
|
|
log_and_run() {
|
|
echo -e "${YELLOW}[*] $1${NC}"
|
|
echo "[$(date)] $1" >> "$LOG_FILE"
|
|
eval "$2" 2>&1 | tee -a "$LOG_FILE"
|
|
}
|
|
|
|
# Basic web info gathering
|
|
echo -e "${GREEN}[+] Phase 1: Basic Information Gathering${NC}"
|
|
log_and_run "Getting HTTP headers" "curl -I $TARGET_URL"
|
|
log_and_run "Checking robots.txt" "curl -s $TARGET_URL/robots.txt"
|
|
log_and_run "Checking sitemap.xml" "curl -s $TARGET_URL/sitemap.xml"
|
|
|
|
# Technology detection
|
|
echo -e "${GREEN}[+] Phase 2: Technology Detection${NC}"
|
|
log_and_run "Running whatweb" "whatweb -a 3 $TARGET_URL"
|
|
if command -v wappalyzer &> /dev/null; then
|
|
log_and_run "Running Wappalyzer" "wappalyzer $TARGET_URL"
|
|
fi
|
|
|
|
# Directory and file enumeration
|
|
echo -e "${GREEN}[+] Phase 3: Directory and File Enumeration${NC}"
|
|
|
|
# Gobuster with common wordlist
|
|
log_and_run "Gobuster directory enumeration (common)" "gobuster dir -u $TARGET_URL -w /usr/share/wordlists/dirb/common.txt -o gobuster_common.txt -q"
|
|
|
|
# Gobuster with bigger wordlist
|
|
if [ -f "/usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt" ]; then
|
|
log_and_run "Gobuster directory enumeration (medium)" "gobuster dir -u $TARGET_URL -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -o gobuster_medium.txt -q --timeout 10s"
|
|
fi
|
|
|
|
# File extension enumeration
|
|
log_and_run "Gobuster file enumeration" "gobuster dir -u $TARGET_URL -w /usr/share/wordlists/dirb/common.txt -x txt,php,html,js,xml,json,bak,old -o gobuster_files.txt -q"
|
|
|
|
# Alternative directory tools
|
|
if command -v dirb &> /dev/null; then
|
|
log_and_run "Dirb enumeration" "dirb $TARGET_URL -o dirb_results.txt"
|
|
fi
|
|
|
|
if command -v ffuf &> /dev/null; then
|
|
log_and_run "FFUF enumeration" "ffuf -w /usr/share/wordlists/dirb/common.txt -u $TARGET_URL/FUZZ -o ffuf_results.json -of json -s"
|
|
fi
|
|
|
|
# Subdomain enumeration (if it's a domain)
|
|
if [[ $TARGET_URL == *"."* ]] && [[ $TARGET_URL != *[0-9]* ]]; then
|
|
echo -e "${GREEN}[+] Phase 4: Subdomain Enumeration${NC}"
|
|
DOMAIN=$(echo "$TARGET_URL" | sed 's|https\?://||g' | sed 's|/.*||g' | cut -d':' -f1)
|
|
log_and_run "Gobuster subdomain enumeration" "gobuster dns -d $DOMAIN -w /usr/share/wordlists/dirb/common.txt -o gobuster_subdomains.txt -q"
|
|
fi
|
|
|
|
# Web vulnerability scanning
|
|
echo -e "${GREEN}[+] Phase 5: Vulnerability Scanning${NC}"
|
|
log_and_run "Nikto scan" "nikto -h $TARGET_URL -o nikto_results.txt"
|
|
|
|
# Nuclei web templates
|
|
if command -v nuclei &> /dev/null; then
|
|
log_and_run "Nuclei web vulnerability scan" "nuclei -u $TARGET_URL -t ~/nuclei-templates/http/ -o nuclei_web_results.txt"
|
|
fi
|
|
|
|
# SSL/TLS testing (for HTTPS)
|
|
if [[ $TARGET_URL == https* ]]; then
|
|
echo -e "${GREEN}[+] Phase 6: SSL/TLS Testing${NC}"
|
|
DOMAIN=$(echo "$TARGET_URL" | sed 's|https://||g' | sed 's|/.*||g')
|
|
log_and_run "SSL certificate information" "openssl s_client -connect $DOMAIN:443 -servername $DOMAIN < /dev/null 2>/dev/null | openssl x509 -text -noout"
|
|
|
|
if command -v sslscan &> /dev/null; then
|
|
log_and_run "SSLScan" "sslscan $DOMAIN"
|
|
fi
|
|
|
|
if command -v testssl.sh &> /dev/null; then
|
|
log_and_run "TestSSL" "testssl.sh $TARGET_URL"
|
|
fi
|
|
fi
|
|
|
|
# Web application firewall detection
|
|
echo -e "${GREEN}[+] Phase 7: WAF Detection${NC}"
|
|
if command -v wafw00f &> /dev/null; then
|
|
log_and_run "WAF detection" "wafw00f $TARGET_URL"
|
|
fi
|
|
|
|
# Content discovery and analysis
|
|
echo -e "${GREEN}[+] Phase 8: Content Analysis${NC}"
|
|
|
|
# Find interesting files and directories
|
|
echo -e "${BLUE}[*] Analyzing discovered content...${NC}"
|
|
if [ -f "gobuster_common.txt" ]; then
|
|
echo "Interesting directories found:" >> content_analysis.txt
|
|
grep -E "(admin|login|api|config|backup|test|dev)" gobuster_common.txt >> content_analysis.txt 2>/dev/null || echo "No interesting directories found" >> content_analysis.txt
|
|
fi
|
|
|
|
# Parameter discovery
|
|
if command -v arjun &> /dev/null; then
|
|
log_and_run "Parameter discovery with Arjun" "arjun -u $TARGET_URL -o arjun_params.txt"
|
|
fi
|
|
|
|
# JavaScript analysis
|
|
log_and_run "Finding JavaScript files" "curl -s $TARGET_URL | grep -oP '(?<=src=\")[^\"]*\.js(?=\")' | head -10 > js_files.txt"
|
|
|
|
# Generate summary report
|
|
echo -e "${GREEN}[+] Web Enumeration Complete!${NC}"
|
|
echo -e "${BLUE}[*] Results saved in: $WORKSPACE${NC}"
|
|
echo -e "${BLUE}[*] Log file: $LOG_FILE${NC}"
|
|
|
|
# Count discovered items
|
|
DIRS_FOUND=0
|
|
FILES_FOUND=0
|
|
if [ -f "gobuster_common.txt" ]; then
|
|
DIRS_FOUND=$(wc -l < gobuster_common.txt)
|
|
fi
|
|
if [ -f "gobuster_files.txt" ]; then
|
|
FILES_FOUND=$(wc -l < gobuster_files.txt)
|
|
fi
|
|
|
|
echo -e "${BLUE}[*] Directories found: $DIRS_FOUND${NC}"
|
|
echo -e "${BLUE}[*] Files found: $FILES_FOUND${NC}"
|
|
|
|
# Generate HTML report
|
|
cat > "web_enum_report.html" << EOF
|
|
<!DOCTYPE html>
|
|
<html>
|
|
<head>
|
|
<title>Web Enumeration Report - $TARGET_URL</title>
|
|
<style>
|
|
body { font-family: Arial, sans-serif; margin: 40px; }
|
|
h1 { color: #333; }
|
|
h2 { color: #666; }
|
|
.stats { background: #f0f0f0; padding: 10px; margin: 10px 0; }
|
|
pre { background: #f8f8f8; padding: 10px; overflow-x: auto; }
|
|
.finding { background: #ffffcc; padding: 5px; margin: 5px 0; }
|
|
</style>
|
|
</head>
|
|
<body>
|
|
<h1>Web Enumeration Report</h1>
|
|
<p><strong>Target:</strong> $TARGET_URL</p>
|
|
|
|
<div class="stats">
|
|
<h2>Statistics</h2>
|
|
<p>Directories Found: $DIRS_FOUND</p>
|
|
<p>Files Found: $FILES_FOUND</p>
|
|
<p>Scan Date: $(date)</p>
|
|
</div>
|
|
|
|
<h2>Discovered Directories</h2>
|
|
<pre>$(cat gobuster_common.txt 2>/dev/null | head -20 || echo "No directories file found")</pre>
|
|
|
|
<h2>Discovered Files</h2>
|
|
<pre>$(cat gobuster_files.txt 2>/dev/null | head -20 || echo "No files found")</pre>
|
|
|
|
<h2>Technology Stack</h2>
|
|
<pre>$(grep -A 10 "Running whatweb" $LOG_FILE 2>/dev/null | tail -n +2 | head -10 || echo "Technology detection results not available")</pre>
|
|
|
|
<h2>Security Findings</h2>
|
|
<pre>$(cat nikto_results.txt 2>/dev/null | head -20 || echo "Nikto results not available")</pre>
|
|
</body>
|
|
</html>
|
|
EOF
|
|
|
|
echo -e "${GREEN}[+] HTML report generated: web_enum_report.html${NC}"
|
|
|
|
# Next steps suggestions
|
|
cat > "next_steps.txt" << EOF
|
|
Next Steps for $TARGET_URL:
|
|
===========================
|
|
|
|
1. Manual Testing:
|
|
- Browse discovered directories manually
|
|
- Test for authentication bypasses
|
|
- Look for file upload functionality
|
|
- Check for SQL injection points
|
|
|
|
2. Focused Scanning:
|
|
- Run OWASP ZAP or Burp Suite
|
|
- Test for XSS vulnerabilities
|
|
- Check for CSRF tokens
|
|
- Test API endpoints if found
|
|
|
|
3. Exploitation:
|
|
- Research CVEs for identified technologies
|
|
- Test default credentials
|
|
- Look for configuration files with sensitive data
|
|
- Check for local file inclusion vulnerabilities
|
|
|
|
4. Further Enumeration:
|
|
- Use custom wordlists for your target
|
|
- Check for backup files (.bak, .old, .swp)
|
|
- Look for version control directories (.git, .svn)
|
|
- Test for subdomain takeover
|
|
|
|
Files to review:
|
|
$(ls -la *.txt *.html *.json 2>/dev/null || echo "No additional files found")
|
|
EOF
|
|
|
|
echo -e "${GREEN}[+] Next steps guide generated: next_steps.txt${NC}"
|
|
echo "Web enumeration completed at $(date)" >> "$LOG_FILE"
|