Alright, I've tried to make a few (or maybe a lot, I've lost acquaintance) edits in the code.
Code:
####################################################################################
# Vulnerability Record Database BETA v.2
# Read the Change Log
# Coded By Ex094
# BETA Tester: noize(A huge thanks to this guy)
# Thanks to Deque for the Output Formatting
# Thanks to Hackcommunity for the Support
####################################################################################
# If you want to learn, copy-pasting this code won't do a shit! #
# Understand the code line by line and edit it on your own. #
## ##
### ---> Just give credits <--- ###
## ##
####################################################################################
vals = [' Vulnerability name: ', ' Vulnerability ID: ', ' Exposure level: ', ' Discoverer: ', ' Exploited on: ', ' Vulnerability type: ', ' Discovered the ']
import sqlite3
import os
color = lambda: os.system('color 0a')
color()
clear = lambda: os.system('cls')
wait = lambda: os.system('timeout /t 1 /nobreak > nul')
############################################
## Insert new vulnerability into database ##
############################################
def insert():
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""SELECT * FROM VRDrec""")
info = cur.fetchall()
########################################
## Values to insert into the database ##
########################################
clear()
Vulname = input('Vulnerability name: ')
Vulid = input('Vulnerability ID: ')
#####################################################
## Check if vulnerability name or ID already exist ##
#####################################################
for i in range(len(info)):
if Vulname in info[i][0]:
print('Vulnerability name already exists.')
print('Please, choose a different name.')
input('Press any key...')
insert()
elif Vulid in info[i][1]:
print('Vulnerability ID already exists.')
print('Please, enter a different ID.')
input('Press any key...')
insert()
Explevel = input('Exposure level (high/medium/low): ')
Disname = input('Vulnerability discoverer: ')
ask = input('Exploit type (software/OS/web/other): ').strip()
if ask == 'software':
Appvuln = input(' Software name: ')
Mainvuln = Appvuln
elif ask == 'os':
Osvuln = input(' Operating system name: ')
Mainvuln = Osvuln
elif ask == 'web':
Webvuln = input(' Website URL: ').strip()
Mainvuln = Webvuln
elif ask == 'other':
Othvuln = input(' Vulnerability type: ')
Mainvuln = Othvuln
elif ask == 'else':
Othvuln = input(' Vulnerability type: ')
Mainvuln = Othvuln
else:
Mainvuln = Othvuln
Vultype = input('Exploit subcategory (code injection/CSRF/SQLi/XSS/else): ')
Datedisc = input('0-day (dd/mm/yy): ')
########################
## Database injection ##
########################
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""INSERT INTO VRDrec (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc) VALUES (?,?,?,?,?,?,?)""", (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc))
con.commit()
cur.close()
cur.close()
print('Vulnerability successfully recorded.')
input('Press any key to go back to the menu...')
#############################################
## View all records stored in the database ##
#############################################
def view_db():
clear()
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""SELECT * FROM VRDrec""")
getall = cur.fetchall()
for items in getall:
print('***********************')
for i in range(len(vals)):
print(vals[i], items[i])
print('***********************')
print(' ')
input('Press any key to go back to the menu...')
#####################
## Delete a record ##
#####################
def del_rec():
clear()
print('Enter the vulnerability ID for the record you want to delete:')
print('(Enter "view" to see all stored vulnerabilities)')
ask = input('')
if ask == 'view':
view_db()
else:
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""DELETE FROM VRDrec WHERE Vulid LIKE ?""", (ask,))
con.commit()
cur.close()
cur.close()
clear()
print('Record successfully removed from database.')
input('Press any key to go back to the menu...')
###################
## Search engine ##
###################
def search_db():
clear()
item = input('Search for vulnerability name: ')
try:
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
item = '%' + item + '%'
cur.execute("""SELECT * FROM VRDrec WHERE Vulname LIKE ?""", (item,))
find = cur.fetchall()
con.commit()
cur.close()
cur.close()
## Result ##
row = 0
print('Query returned the following item(s): ')
for items in find:
print(' ')
print('****************************')
for i in range(len(vals)):
print(vals[i], items[i])
print('****************************')
if items == '':
print('No matches found in the database.')
except:
print('No matches found in the database.')
######################
## Report generator ##
######################
def report():
clear()
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""SELECT * FROM VRDrec""")
getall = cur.fetchall()
sql = 0
xss = 0
lfi = 0
sqli = 0
other = 0
low = 0
high = 0
med = 0
sql_d = ['sql', 'SQL', 'Sql', 'SQl']
xss_d = ['xss', 'XSS', 'Xss']
lfi_d = ['lfi', 'LFI', 'LFi']
sqli_d = ['SQLi' , 'sqli', 'SQLI', 'sqlI']
warns_h = ['High', 'high']
warns_l = ['low', 'Low']
warns_m = ['Medium', 'medium']
for i in range(len(getall)):
for dorks in sql_d:
if dorks in getall[i][5]:
sql += 1
for dorks_t in xss_d:
if dorks_t in getall[i][5]:
xss += 1
for dorks_th in lfi_d:
if dorks_th in getall[i][5]:
lfi += 1
for dorks_f in sqli_d:
if dorks_f in getall[i][5]:
sqli += 1
sql -= 1
for l in warns_l:
if l in getall[i][2]:
low += 1
for h in warns_h:
if h in getall[i][2]:
high += 1
for m in warns_m:
if m in getall[i][2]:
med += 1
print('#################')
print(' ')
print('## Report: ##')
print(' ')
print('#################')
print(' ')
print(('''%d SQL, %d SQLi, %d XSS, %d LFI web vulnerabilites;''') % (sql, sqli, xss, lfi))
print('%d high level, %d medium level and %d low level vulnerabilities;' % (high, med, low))
print('There is a total of %d vulnerabilities in the database.' % (len(getall)))
print(' ')
wait()
wait()
print('All vulnerabilities stored in the database are to follow: ')
print(' ')
for items in getall:
print(items[0])
print(' ')
wait()
input('Press any key to go back to the menu...')
###############
## Main menu ##
###############
def main():
clear()
print('''
####################################################################
# #
# Welcome to Vulnerability Record Database #
# Made for Pen-Testers #
# #
####################################################################
''')
print('''
What would you like to do?
1) Record a new vulnerability
2) View all stored vulnerabilites
3) Search for a vulnerability in the database
4) Delete a stored vulnerability
5) Generate report
6) Credits
0) Quit
''')
try:
with open('data/database.sql'): pass
except IOError:
print ('Creating database...')
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""CREATE TABLE VRDrec (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc BOOL)""")
cur.close()
cur.close()
main()
try:
choice = input('Enter your choice: ').strip()
if choice == '1':
insert()
main()
elif choice == '2':
view_db()
main()
elif choice == '3':
search_db()
main()
elif choice == '4':
del_rec()
main()
elif choice == '5':
report()
main()
elif choice == '6':
clear()
print('''
Vulnerability Record Database
Coded by: Ex094
Output formatting: Deque
BETA tester: noize (From HC)
Inspirated by Hackcommunity.com and its members
''')
input('Press any key to go back to the menu...')
main()
elif choice == '0':
os.system('exit')
elif choice == 'exit':
os.system('exit')
elif choice == 'quit':
os.system('exit')
else:
print(' ')
print('Invalid choice.')
input('Press any key...')
main()
except:
print('Unexpected error!')
main()
if '___name___' == '___main___': main()
I'm sorry but now I've really got to go.
As I come back I'll provide a detailed change log.
I haven't still looked to what Deque improved, if I didn't touch that things you could mash these up together (or if you liked better your version, I'm not gonna offend).
You may give it a shot in this while.