Foro de elhacker.net

Programación => Scripting => Mensaje iniciado por: The_Mushrr00m en 4 Julio 2013, 07:34 am



Título: [Python] mushi_admin_finder.py [Admin-Finder]
Publicado por: The_Mushrr00m en 4 Julio 2013, 07:34 am
Bueno, primero que nada un saludo para todos los que lleguen a leer esta entrada. :P

Se que en el foro he estado algo ausente desde hace un tiempo, pero aquí esta el inicio de posiblemente una larga serie de “scripts” que publicare, codeados con mi “navaja suiza” Python…

Este es un admin_finder algo básico, pero es el que utilizare en una mini-suit que estoy preparando, con varios scripts que son necesarios a la hora del pentesting.

EDITO: 28/07/2013

Les dejo el code...

Código
  1. #Created for @The_Mushrr00m
  2. #For suggestions or bugs, contact me on Twitter:
  3. #@Mushrr00m_Funji @The_Mushrr00m
  4.  
  5. #Greets...
  6.  
  7. #cd directory/to/code
  8. #direcory/to/code>python mushi_admin_finder.py
  9. #Follow the instructions xD
  10.  
  11.  
  12.  
  13. import httplib
  14. import socket
  15. import sys
  16.  
  17. def header():
  18.    print """\t
  19.    ##################################################################################################################################################
  20.    #                                                                                                                                                #
  21.    #  coded by:                                                                                                                                     #
  22.    #                                                                                                                                                #
  23.    #     /$$$$$$$$ /$$                        /$$      /$$                     /$$                            /$$$$$$   /$$$$$$                     #
  24.    #    |__  $$__/| $$                       | $$$    /$$$                    | $$                           /$$$_  $$ /$$$_  $$                    #
  25.    #       | $$   | $$$$$$$   /$$$$$$        | $$$$  /$$$$ /$$   /$$  /$$$$$$$| $$$$$$$   /$$$$$$   /$$$$$$ | $$$$\ $$| $$$$\ $$ /$$$$$$/$$$$       #
  26.    #       | $$   | $$__  $$ /$$__  $$       | $$ $$/$$ $$| $$  | $$ /$$_____/| $$__  $$ /$$__  $$ /$$__  $$| $$ $$ $$| $$ $$ $$| $$_  $$_  $$      #
  27.    #       | $$   | $$  | $$| $$_____/       | $$\ $ | $$| $$  | $$ \____  $$| $$  | $$| $$      | $$      | $$ \ $$$| $$ \ $$$| $$ | $$ | $$      #
  28.    #       | $$   | $$  | $$|  $$$$$$$       | $$ \/  | $$|  $$$$$$/ /$$$$$$$/| $$  | $$| $$      | $$      |  $$$$$$/|  $$$$$$/| $$ | $$ | $$      #
  29.    #       |__/   |__/  |__/ \_______//$$$$$$|__/     |__/ \______/ |_______/ |__/  |__/|__/      |__/       \______/  \______/ |__/ |__/ |__/      #
  30.    #                                                                                                                                          v1.0  #
  31.    ##################################################################################################################################################\n"""
  32.  
  33. header()
  34.  
  35. try:
  36.    var1=0
  37.    var2=0
  38.  
  39.    php = ['Flogin/','admin/','administrador/','admin1/','admin2/','admin3/','admin4/','admin5/','usuarios/','usuario/','administrator/','moderator/','webadmin/','adminarea/','bb-admin/','adminLogin/','admin_area/','panel-administracion/','instadmin/',
  40. 'memberadmin/','administratorlogin/','adm/','admin/account.php','admin/index.php','admin/login.php','admin/admin.php','admin/account.php',
  41. 'admin_area/admin.php','admin_area/login.php','siteadmin/login.php','siteadmin/index.php','siteadmin/login.html','admin/account.html','admin/index.html','admin/login.html','admin/admin.html',
  42. 'admin_area/index.php','bb-admin/index.php','bb-admin/login.php','bb-admin/admin.php','admin/home.php','admin_area/login.html','admin_area/index.html',
  43. 'admin/controlpanel.php','admin.php','admincp/index.asp','admincp/login.asp','admincp/index.html','admin/account.html','adminpanel.html','webadmin.html',
  44. 'webadmin/index.html','webadmin/admin.html','webadmin/login.html','admin/admin_login.html','admin_login.html','panel-administracion/login.html',
  45. 'admin/cp.php','cp.php','administrator/index.php','administrator/login.php','nsw/admin/login.php','webadmin/login.php','admin/admin_login.php','admin_login.php',
  46. 'administrator/account.php','administrator.php','admin_area/admin.html','pages/admin/admin-login.php','admin/admin-login.php','admin-login.php',
  47. 'bb-admin/index.html','bb-admin/login.html','acceso.php','bb-admin/admin.html','admin/home.html','login.php','modelsearch/login.php','moderator.php','moderator/login.php',
  48. 'moderator/admin.php','account.php','pages/admin/admin-login.html','admin/admin-login.html','admin-login.html','controlpanel.php','admincontrol.php',
  49. 'admin/adminLogin.html','adminLogin.html','admin/adminLogin.html','home.html','rcjakar/admin/login.php','adminarea/index.html','adminarea/admin.html',
  50. 'webadmin.php','webadmin/index.php','webadmin/admin.php','admin/controlpanel.html','admin.html','admin/cp.html','cp.html','adminpanel.php','moderator.html',
  51. 'administrator/index.html','administrator/login.html','user.html','administrator/account.html','administrator.html','login.html','modelsearch/login.html',
  52. 'moderator/login.html','adminarea/login.html','panel-administracion/index.html','panel-administracion/admin.html','modelsearch/index.html','modelsearch/admin.html',
  53. 'admincontrol/login.html','adm/index.html','adm.html','moderator/admin.html','user.php','account.html','controlpanel.html','admincontrol.html',
  54. 'panel-administracion/login.php','wp-login.php','adminLogin.php','admin/adminLogin.php','home.php','admin.php','adminarea/index.php',
  55. 'adminarea/admin.php','adminarea/login.php','panel-administracion/index.php','panel-administracion/admin.php','modelsearch/index.php',
  56. 'modelsearch/admin.php','admincontrol/login.php','adm/admloginuser.php','admloginuser.php','admin2.php','admin2/login.php','admin2/index.php','usuarios/login.php',
  57. 'adm/index.php','adm.php','affiliate.php','adm_auth.php','memberadmin.php','administratorlogin.php']
  58.  
  59.    asp = ['admin/','administrador/','admin1/','admin2/','admin3/','admin4/','admin5/','moderator/','webadmin/','adminarea/','bb-admin/','adminLogin/','admin_area/','panel-administracion/','instadmin/',
  60. 'memberadmin/','administratorlogin/','adm/','account.asp','admin/account.asp','admin/index.asp','admin/login.asp','admin/admin.asp',
  61. 'admin_area/admin.asp','admin_area/login.asp','admin/account.html','admin/index.html','admin/login.html','admin/admin.html',
  62. 'admin_area/admin.html','admin_area/login.html','admin_area/index.html','admin_area/index.asp','bb-admin/index.asp','bb-admin/login.asp','bb-admin/admin.asp',
  63. 'bb-admin/index.html','bb-admin/login.html','bb-admin/admin.html','admin/home.html','admin/controlpanel.html','admin.html','admin/cp.html','cp.html',
  64. 'administrator/index.html','administrator/login.html','administrator/account.html','administrator.html','login.html','modelsearch/login.html','moderator.html',
  65. 'moderator/login.html','moderator/admin.html','account.html','controlpanel.html','admincontrol.html','admin_login.html','panel-administracion/login.html',
  66. 'admin/home.asp','admin/controlpanel.asp','admin.asp','pages/admin/admin-login.asp','admin/admin-login.asp','admin-login.asp','admin/cp.asp','cp.asp',
  67. 'administrator/account.asp','administrator.asp','acceso.asp','login.asp','modelsearch/login.asp','moderator.asp','moderator/login.asp','administrator/login.asp',
  68. 'moderator/admin.asp','controlpanel.asp','admin/account.html','adminpanel.html','webadmin.html','pages/admin/admin-login.html','admin/admin-login.html',
  69. 'webadmin/index.html','webadmin/admin.html','webadmin/login.html','user.asp','user.html','admincp/index.asp','admincp/login.asp','admincp/index.html',
  70. 'admin/adminLogin.html','adminLogin.html','admin/adminLogin.html','home.html','adminarea/index.html','adminarea/admin.html','adminarea/login.html',
  71. 'panel-administracion/index.html','panel-administracion/admin.html','modelsearch/index.html','modelsearch/admin.html','admin/admin_login.html',
  72. 'admincontrol/login.html','adm/index.html','adm.html','admincontrol.asp','admin/account.asp','adminpanel.asp','webadmin.asp','webadmin/index.asp',
  73. 'webadmin/admin.asp','webadmin/login.asp','admin/admin_login.asp','admin_login.asp','panel-administracion/login.asp','adminLogin.asp',
  74. 'admin/adminLogin.asp','home.asp','admin.asp','adminarea/index.asp','adminarea/admin.asp','adminarea/login.asp','admin-login.html',
  75. 'panel-administracion/index.asp','panel-administracion/admin.asp','modelsearch/index.asp','modelsearch/admin.asp','administrator/index.asp',
  76. 'admincontrol/login.asp','adm/admloginuser.asp','admloginuser.asp','admin2.asp','admin2/login.asp','admin2/index.asp','adm/index.asp',
  77. 'adm.asp','affiliate.asp','adm_auth.asp','memberadmin.asp','administratorlogin.asp','siteadmin/login.asp','siteadmin/index.asp','siteadmin/login.html']
  78.  
  79.    cfm = ['admin/','administrator/','admin1/','admin2/','admin3/','admin4/','admin5/','usuarios/','usuario/','administrator/','moderator/','webadmin/','adminarea/','bb-admin/','adminLogin/','admin_area/','panel-administracion/','instadmin/',
  80. 'memberadmin/','administratorlogin/','adm/','admin/account.cfm','admin/index.cfm','admin/login.cfm','admin/admin.cfm','admin/account.cfm',
  81. 'admin_area/admin.cfm','admin_area/login.cfm','siteadmin/login.cfm','siteadmin/index.cfm','siteadmin/login.html','admin/account.html','admin/index.html','admin/login.html','admin/admin.html',
  82. 'admin_area/index.cfm','bb-admin/index.cfm','bb-admin/login.cfm','bb-admin/admin.cfm','admin/home.cfm','admin_area/login.html','admin_area/index.html',
  83. 'admin/controlpanel.cfm','admin.cfm','admincp/index.asp','admincp/login.asp','admincp/index.html','admin/account.html','adminpanel.html','webadmin.html',
  84. 'webadmin/index.html','webadmin/admin.html','webadmin/login.html','admin/admin_login.html','admin_login.html','panel-administracion/login.html',
  85. 'admin/cp.cfm','cp.cfm','administrator/index.cfm','administrator/login.cfm','nsw/admin/login.cfm','webadmin/login.cfm','admin/admin_login.cfm','admin_login.cfm',
  86. 'administrator/account.cfm','administrator.cfm','admin_area/admin.html','pages/admin/admin-login.cfm','admin/admin-login.cfm','admin-login.cfm',
  87. 'bb-admin/index.html','bb-admin/login.html','bb-admin/admin.html','admin/home.html','login.cfm','modelsearch/login.cfm','moderator.cfm','moderator/login.cfm',
  88. 'moderator/admin.cfm','account.cfm','pages/admin/admin-login.html','admin/admin-login.html','admin-login.html','controlpanel.cfm','admincontrol.cfm',
  89. 'admin/adminLogin.html','acceso.cfm','adminLogin.html','admin/adminLogin.html','home.html','rcjakar/admin/login.cfm','adminarea/index.html','adminarea/admin.html',
  90. 'webadmin.cfm','webadmin/index.cfm','webadmin/admin.cfm','admin/controlpanel.html','admin.html','admin/cp.html','cp.html','adminpanel.cfm','moderator.html',
  91. 'administrator/index.html','administrator/login.html','user.html','administrator/account.html','administrator.html','login.html','modelsearch/login.html',
  92. 'moderator/login.html','adminarea/login.html','panel-administracion/index.html','panel-administracion/admin.html','modelsearch/index.html','modelsearch/admin.html',
  93. 'admincontrol/login.html','adm/index.html','adm.html','moderator/admin.html','user.cfm','account.html','controlpanel.html','admincontrol.html',
  94. 'panel-administracion/login.cfm','wp-login.cfm','adminLogin.cfm','admin/adminLogin.cfm','home.cfm','admin.cfm','adminarea/index.cfm',
  95. 'adminarea/admin.cfm','adminarea/login.cfm','panel-administracion/index.cfm','panel-administracion/admin.cfm','modelsearch/index.cfm',
  96. 'modelsearch/admin.cfm','admincontrol/login.cfm','adm/admloginuser.cfm','admloginuser.cfm','admin2.cfm','admin2/login.cfm','admin2/index.cfm','usuarios/login.cfm',
  97. 'adm/index.cfm','adm.cfm','affiliate.cfm','adm_auth.cfm','memberadmin.cfm','administratorlogin.cfm']
  98.  
  99.    js = ['admin/','administrator/','admin1/','admin2/','admin3/','admin4/','admin5/','usuarios/','usuario/','administrator/','moderator/','webadmin/','adminarea/','bb-admin/','adminLogin/','admin_area/','panel-administracion/','instadmin/',
  100. 'memberadmin/','administratorlogin/','adm/','admin/account.js','admin/index.js','admin/login.js','admin/admin.js','admin/account.js',
  101. 'admin_area/admin.js','admin_area/login.js','siteadmin/login.js','siteadmin/index.js','siteadmin/login.html','admin/account.html','admin/index.html','admin/login.html','admin/admin.html',
  102. 'admin_area/index.js','bb-admin/index.js','bb-admin/login.js','bb-admin/admin.js','admin/home.js','admin_area/login.html','admin_area/index.html',
  103. 'admin/controlpanel.js','admin.js','admincp/index.asp','admincp/login.asp','admincp/index.html','admin/account.html','adminpanel.html','webadmin.html',
  104. 'webadmin/index.html','webadmin/admin.html','webadmin/login.html','admin/admin_login.html','admin_login.html','panel-administracion/login.html',
  105. 'admin/cp.js','cp.js','administrator/index.js','administrator/login.js','nsw/admin/login.js','webadmin/login.js','admin/admin_login.js','admin_login.js',
  106. 'administrator/account.js','administrator.js','admin_area/admin.html','pages/admin/admin-login.js','admin/admin-login.js','admin-login.js',
  107. 'bb-admin/index.html','bb-admin/login.html','bb-admin/admin.html','admin/home.html','login.js','modelsearch/login.js','moderator.js','moderator/login.js',
  108. 'moderator/admin.js','account.js','pages/admin/admin-login.html','admin/admin-login.html','admin-login.html','controlpanel.js','admincontrol.js',
  109. 'admin/adminLogin.html','adminLogin.html','admin/adminLogin.html','home.html','rcjakar/admin/login.js','adminarea/index.html','adminarea/admin.html',
  110. 'webadmin.js','webadmin/index.js','acceso.js','webadmin/admin.js','admin/controlpanel.html','admin.html','admin/cp.html','cp.html','adminpanel.js','moderator.html',
  111. 'administrator/index.html','administrator/login.html','user.html','administrator/account.html','administrator.html','login.html','modelsearch/login.html',
  112. 'moderator/login.html','adminarea/login.html','panel-administracion/index.html','panel-administracion/admin.html','modelsearch/index.html','modelsearch/admin.html',
  113. 'admincontrol/login.html','adm/index.html','adm.html','moderator/admin.html','user.js','account.html','controlpanel.html','admincontrol.html',
  114. 'panel-administracion/login.js','wp-login.js','adminLogin.js','admin/adminLogin.js','home.js','admin.js','adminarea/index.js',
  115. 'adminarea/admin.js','adminarea/login.js','panel-administracion/index.js','panel-administracion/admin.js','modelsearch/index.js',
  116. 'modelsearch/admin.js','admincontrol/login.js','adm/admloginuser.js','admloginuser.js','admin2.js','admin2/login.js','admin2/index.js','usuarios/login.js',
  117. 'adm/index.js','adm.js','affiliate.js','adm_auth.js','memberadmin.js','administratorlogin.js']
  118.  
  119.    cgi = ['admin/','administrator/','admin1/','admin2/','admin3/','admin4/','admin5/','usuarios/','usuario/','administrator/','moderator/','webadmin/','adminarea/','bb-admin/','adminLogin/','admin_area/','panel-administracion/','instadmin/',
  120. 'memberadmin/','administratorlogin/','adm/','admin/account.cgi','admin/index.cgi','admin/login.cgi','admin/admin.cgi','admin/account.cgi',
  121. 'admin_area/admin.cgi','admin_area/login.cgi','siteadmin/login.cgi','siteadmin/index.cgi','siteadmin/login.html','admin/account.html','admin/index.html','admin/login.html','admin/admin.html',
  122. 'admin_area/index.cgi','bb-admin/index.cgi','bb-admin/login.cgi','bb-admin/admin.cgi','admin/home.cgi','admin_area/login.html','admin_area/index.html',
  123. 'admin/controlpanel.cgi','admin.cgi','admincp/index.asp','admincp/login.asp','admincp/index.html','admin/account.html','adminpanel.html','webadmin.html',
  124. 'webadmin/index.html','webadmin/admin.html','webadmin/login.html','admin/admin_login.html','admin_login.html','panel-administracion/login.html',
  125. 'admin/cp.cgi','cp.cgi','administrator/index.cgi','administrator/login.cgi','nsw/admin/login.cgi','webadmin/login.cgi','admin/admin_login.cgi','admin_login.cgi',
  126. 'administrator/account.cgi','administrator.cgi','admin_area/admin.html','pages/admin/admin-login.cgi','admin/admin-login.cgi','admin-login.cgi',
  127. 'bb-admin/index.html','bb-admin/login.html','bb-admin/admin.html','admin/home.html','login.cgi','modelsearch/login.cgi','moderator.cgi','moderator/login.cgi',
  128. 'moderator/admin.cgi','account.cgi','pages/admin/admin-login.html','admin/admin-login.html','admin-login.html','controlpanel.cgi','admincontrol.cgi',
  129. 'admin/adminLogin.html','adminLogin.html','admin/adminLogin.html','home.html','rcjakar/admin/login.cgi','adminarea/index.html','adminarea/admin.html',
  130. 'webadmin.cgi','webadmin/index.cgi','acceso.cgi','webadmin/admin.cgi','admin/controlpanel.html','admin.html','admin/cp.html','cp.html','adminpanel.cgi','moderator.html',
  131. 'administrator/index.html','administrator/login.html','user.html','administrator/account.html','administrator.html','login.html','modelsearch/login.html',
  132. 'moderator/login.html','adminarea/login.html','panel-administracion/index.html','panel-administracion/admin.html','modelsearch/index.html','modelsearch/admin.html',
  133. 'admincontrol/login.html','adm/index.html','adm.html','moderator/admin.html','user.cgi','account.html','controlpanel.html','admincontrol.html',
  134. 'panel-administracion/login.cgi','wp-login.cgi','adminLogin.cgi','admin/adminLogin.cgi','home.cgi','admin.cgi','adminarea/index.cgi',
  135. 'adminarea/admin.cgi','adminarea/login.cgi','panel-administracion/index.cgi','panel-administracion/admin.cgi','modelsearch/index.cgi',
  136. 'modelsearch/admin.cgi','admincontrol/login.cgi','adm/admloginuser.cgi','admloginuser.cgi','admin2.cgi','admin2/login.cgi','admin2/index.cgi','usuarios/login.cgi',
  137. 'adm/index.cgi','adm.cgi','affiliate.cgi','adm_auth.cgi','memberadmin.cgi','administratorlogin.cgi']
  138.  
  139.  
  140.    try:
  141.        site = raw_input("Que sitio quieres escanear?: ")
  142.        site = site.replace("http://","")
  143.        print ("\tChecando el sitio " + site + "...")
  144.        conn = httplib.HTTPConnection(site)
  145.        conn.connect()
  146.        print "\t[$] Siiii.....el servidor esta funcionando :P"
  147.    except (httplib.HTTPResponse, socket.error) as Exit:
  148.        raw_input("\t [!] Oops :( Error occured, Server offline or invalid URL :(")
  149.        exit()
  150.    print "Ingresa el numero del tipo de sitio escaneado:"
  151.    print "1 PHP"
  152.    print "2 ASP"
  153.    print "3 CFM"
  154.    print "4 JS"
  155.    print "5 CGI"
  156.    print "\nEjemplo: Presiona 1 y la tecla enter para seleccionar PHP\n"
  157.    code=input("> ")
  158.  
  159.    if code==1:
  160.        print("\t [+] Escaneando " + site + "...\n\n")
  161.        for admin in php:
  162.            admin = admin.replace("\n","")
  163.            admin = "/" + admin
  164.            host = site + admin
  165.            print ("\t [#] Checando " + host + "...")
  166.            connection = httplib.HTTPConnection(site)
  167.            connection.request("GET",admin)
  168.            response = connection.getresponse()
  169.            var2 = var2 + 1
  170.            if response.status == 200:
  171.                var1 = var1 + 1
  172.                print "%s %s" % ( "\n\n>>>" + host, "Pagina de Administrador encontrada! *--* ")
  173.                raw_input("Presiona la tecla enter para continuar.\n")
  174.            elif response.status == 404:
  175.                var2 = var2
  176.            elif response.status == 302:
  177.                print "%s %s" % ("\n>>>" + host, "Posible pagina de Administrador encontrada (302 - Redirect)")
  178.            else:
  179.                print "%s %s %s" % (host, " Interesantes respuestas:", response.status)
  180.            connection.close()
  181.        print("\n\nCompletado \n")
  182.        print "Paginas de Administrador encontradas: " , var1
  183.        print var2, " Total de paginas escaneadas"
  184.        raw_input("[/] Este juego se acabo...): Presiona la tecla enter para salir...")
  185.  
  186.  
  187.    if code==2:
  188.        print("\t [+] Escaneando " + site + "...\n\n")
  189.        for admin in asp:
  190.            admin = admin.replace("\n","")
  191.            admin = "/" + admin
  192.            host = site + admin
  193.            print ("\t [#] Checando " + host + "...")
  194.            connection = httplib.HTTPConnection(site)
  195.            connection.request("GET",admin)
  196.            response = connection.getresponse()
  197.            var2 = var2 + 1
  198.            if response.status == 200:
  199.                var1 = var1 + 1
  200.                print "%s %s" % ( "\n\n>>>" + host, "Pagina de Administrador encontrada! *--* ")
  201.                raw_input("Presiona la tecla enter para continuar.\n")
  202.            elif response.status == 404:
  203.                var2 = var2
  204.            elif response.status == 302:
  205.                print "%s %s" % ("\n>>>" + host, "Posible pagina de Administrador encontrada (302 - Redirect)")
  206.            else:
  207.                print "%s %s %s" % (host, " Interesantes respuestas:", response.status)
  208.            connection.close()
  209.        print("\n\nCompletado \n")
  210.        print var1, " Paginas de Administrador encontradas"
  211.        print var2, " Total de paginas escaneadas"
  212.        raw_input("[/] Este juego se acabo...): Presiona la tecla enter para salir...")
  213.  
  214.  
  215.    if code==3:
  216.        print("\t [+] Escaneando " + site + "...\n\n")
  217.        for admin in cfm:
  218.            admin = admin.replace("\n","")
  219.            admin = "/" + admin
  220.            host = site + admin
  221.            print ("\t [#] Checando " + host + "...")
  222.            connection = httplib.HTTPConnection(site)
  223.            connection.request("GET",admin)
  224.            response = connection.getresponse()
  225.            var2 = var2 + 1
  226.            if response.status == 200:
  227.                var1 = var1 + 1
  228.                print "%s %s" % ( "\n\n>>>" + host, "Pagina de Administrador encontrada! *--* ")
  229.                raw_input("Presiona la tecla enter para continuar.\n")
  230.            elif response.status == 404:
  231.                var2 = var2
  232.            elif response.status == 302:
  233.                print "%s %s" % ("\n>>>" + host, "Posible pagina de Administrador encontrada (302 - Redirect)")
  234.            else:
  235.                print "%s %s %s" % (host, " Interesantes respuestas:", response.status)
  236.            connection.close()
  237.        print("\n\nCompletado \n")
  238.        print var1, " Paginas de Administrador encontradas"
  239.        print var2, " Total de paginas escaneadas"
  240.        raw_input("[/] Este juego se acabo...): Presiona la tecla enter para salir...")
  241.  
  242.    if code==4:
  243.        print("\t [+] Escaneando " + site + "...\n\n")
  244.        for admin in js:
  245.            admin = admin.replace("\n","")
  246.            admin = "/" + admin
  247.            host = site + admin
  248.            print ("\t [#] Checando " + host + "...")
  249.            connection = httplib.HTTPConnection(site)
  250.            connection.request("GET",admin)
  251.            response = connection.getresponse()
  252.            var2 = var2 + 1
  253.            if response.status == 200:
  254.                var1 = var1 + 1
  255.                print "%s %s" % ( "\n\n>>>" + host, "Pagina de Administrador encontrada! *--* ")
  256.                raw_input("Presiona la tecla enter para continuar.\n")
  257.            elif response.status == 404:
  258.                var2 = var2
  259.            elif response.status == 302:
  260.                print "%s %s" % ("\n>>>" + host, "Posible pagina de Administrador encontrada (302 - Redirect)")
  261.            else:
  262.                print "%s %s %s" % (host, " Interesantes respuestas:", response.status)
  263.            connection.close()
  264.        print("\n\nCompletado \n")
  265.        print var1, " Paginas de Administrador encontradas"
  266.        print var2, " Total de paginas escaneadas"
  267.        raw_input("[/] Este juego se acabo...): Presiona la tecla enter para salir...")
  268.  
  269.    if code==5:
  270.       print("\t [+] Escaneando " + site + "...\n\n")
  271.       for admin in cgi:
  272.            admin = admin.replace("\n","")
  273.            admin = "/" + admin
  274.            host = site + admin
  275.            print ("\t [#] Checando " + host + "...")
  276.            connection = httplib.HTTPConnection(site)
  277.            connection.request("GET",admin)
  278.            response = connection.getresponse()
  279.            var2 = var2 + 1
  280.            if response.status == 200:
  281.                var1 = var1 + 1
  282.                print "%s %s" % ( "\n\n>>>" + host, "Pagina de Administrador encontrada! *--* ")
  283.                raw_input("Presiona la tecla enter para continuar.\n")
  284.            elif response.status == 404:
  285.                var2 = var2
  286.            elif response.status == 302:
  287.                print "%s %s" % ("\n>>>" + host, "Posible pagina de Administrador encontrada (302 - Redirect)")
  288.            else:
  289.                print "%s %s %s" % (host, " Interesantes respuestas:", response.status)
  290.                connection.close()
  291.    print("\n\nCompletado \n")
  292.    print var1, " Paginas de Administrador encontradas"
  293.    print var2, " Total de paginas escaneadas"
  294.    raw_input(" Este juego se acabo...): Presiona la tecla enter para salir...")
  295.  
  296. except (httplib.HTTPResponse, socket.error):
  297.    print "\n\t[!] Sesion Cancelada ; Ocurrio un error. Revisa tus ajustes de internet :("
  298. except (KeyboardInterrupt, SystemExit):
  299.    print "\n\t[!] Sesion Cancelada"
  300.  

(http://www.d4rksh3ll.tk/wp-content/uploads/2013/03/pick.jpg)


Follow me on Twitter...

@The_Mushrr00m (http://www.twitter.com/The_Mushrr00m)
@Mushrr00m_ACIS (http://www.twitter.com/Mushrr00m_ACIS)

FUENTE...mi blog xD (http://code-funji.blogspot.mx/)

  ;-)


Título: Re: [Python] mushi_admin_finder.py [Admin-Finder]
Publicado por: The_Mushrr00m en 4 Julio 2013, 07:35 am
No se porque se publico 2 veces .__. favor de que algun admin borre la otra entrada...


Título: Re: [Python] mushi_admin_finder.py [Admin-Finder]
Publicado por: BigBear en 5 Julio 2013, 02:23 am
buen aporte , podrias tambien poner el codigo en el post para no tener que descargarlo para verlo.


Título: Re: [Python] mushi_admin_finder.py [Admin-Finder]
Publicado por: The_Mushrr00m en 29 Julio 2013, 01:24 am
Tienes razon xD eso de alejarme del foro me afecto  :( ya lo edito

Saludos..!