Login Register






Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | filter_list
Author
Message
RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #11
(04-04-2013, 06:59 PM)Linuxephus Wrote:
(04-04-2013, 06:49 PM)Ex094 Wrote: @Linuxephus Yes it's for the community and it's open source Smile

New links have been added for the V.2.1 Fixed version after @Deque bugs report, I've fixed em. Should support Linux now! Someone test it and tell whether it works or not because I don't have Linux ATM.

What?!
No Linux for you?
Shame shame.:nono:
I'll get Linux soon, Don't you worry! A Promise is a Promise and I shall fulfill it Smile
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #12
Alright, I've tried to make a few (or maybe a lot, I've lost acquaintance) edits in the code.

Code:
#################################################################################### # Vulnerability Record Database BETA v.2 # Read the Change Log # Coded By Ex094 # BETA Tester: noize(A huge thanks to this guy) # Thanks to Deque for the Output Formatting # Thanks to Hackcommunity for the Support #################################################################################### # If you want to learn, copy-pasting this code won't do a shit! # # Understand the code line by line and edit it on your own. # ## ## ### ---> Just give credits <--- ### ## ## #################################################################################### vals = [' Vulnerability name: ', ' Vulnerability ID: ', ' Exposure level: ', ' Discoverer: ', ' Exploited on: ', ' Vulnerability type: ', ' Discovered the '] import sqlite3 import os color = lambda: os.system('color 0a') color() clear = lambda: os.system('cls') wait = lambda: os.system('timeout /t 1 /nobreak > nul') ############################################ ## Insert new vulnerability into database ## ############################################ def insert(): con = sqlite3.connect('data/database.sql') cur = con.cursor() cur.execute("""SELECT * FROM VRDrec""") info = cur.fetchall() ######################################## ## Values to insert into the database ## ######################################## clear() Vulname = input('Vulnerability name: ') Vulid = input('Vulnerability ID: ') ##################################################### ## Check if vulnerability name or ID already exist ## ##################################################### for i in range(len(info)): if Vulname in info[i][0]: print('Vulnerability name already exists.') print('Please, choose a different name.') input('Press any key...') insert() elif Vulid in info[i][1]: print('Vulnerability ID already exists.') print('Please, enter a different ID.') input('Press any key...') insert() Explevel = input('Exposure level (high/medium/low): ') Disname = input('Vulnerability discoverer: ') ask = input('Exploit type (software/OS/web/other): ').strip() if ask == 'software': Appvuln = input(' Software name: ') Mainvuln = Appvuln elif ask == 'os': Osvuln = input(' Operating system name: ') Mainvuln = Osvuln elif ask == 'web': Webvuln = input(' Website URL: ').strip() Mainvuln = Webvuln elif ask == 'other': Othvuln = input(' Vulnerability type: ') Mainvuln = Othvuln elif ask == 'else': Othvuln = input(' Vulnerability type: ') Mainvuln = Othvuln else: Mainvuln = Othvuln Vultype = input('Exploit subcategory (code injection/CSRF/SQLi/XSS/else): ') Datedisc = input('0-day (dd/mm/yy): ') ######################## ## Database injection ## ######################## con = sqlite3.connect('data/database.sql') cur = con.cursor() cur.execute("""INSERT INTO VRDrec (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc) VALUES (?,?,?,?,?,?,?)""", (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc)) con.commit() cur.close() cur.close() print('Vulnerability successfully recorded.') input('Press any key to go back to the menu...') ############################################# ## View all records stored in the database ## ############################################# def view_db(): clear() con = sqlite3.connect('data/database.sql') cur = con.cursor() cur.execute("""SELECT * FROM VRDrec""") getall = cur.fetchall() for items in getall: print('***********************') for i in range(len(vals)): print(vals[i], items[i]) print('***********************') print(' ') input('Press any key to go back to the menu...') ##################### ## Delete a record ## ##################### def del_rec(): clear() print('Enter the vulnerability ID for the record you want to delete:') print('(Enter "view" to see all stored vulnerabilities)') ask = input('') if ask == 'view': view_db() else: con = sqlite3.connect('data/database.sql') cur = con.cursor() cur.execute("""DELETE FROM VRDrec WHERE Vulid LIKE ?""", (ask,)) con.commit() cur.close() cur.close() clear() print('Record successfully removed from database.') input('Press any key to go back to the menu...') ################### ## Search engine ## ################### def search_db(): clear() item = input('Search for vulnerability name: ') try: con = sqlite3.connect('data/database.sql') cur = con.cursor() item = '%' + item + '%' cur.execute("""SELECT * FROM VRDrec WHERE Vulname LIKE ?""", (item,)) find = cur.fetchall() con.commit() cur.close() cur.close() ## Result ## row = 0 print('Query returned the following item(s): ') for items in find: print(' ') print('****************************') for i in range(len(vals)): print(vals[i], items[i]) print('****************************') if items == '': print('No matches found in the database.') except: print('No matches found in the database.') ###################### ## Report generator ## ###################### def report(): clear() con = sqlite3.connect('data/database.sql') cur = con.cursor() cur.execute("""SELECT * FROM VRDrec""") getall = cur.fetchall() sql = 0 xss = 0 lfi = 0 sqli = 0 other = 0 low = 0 high = 0 med = 0 sql_d = ['sql', 'SQL', 'Sql', 'SQl'] xss_d = ['xss', 'XSS', 'Xss'] lfi_d = ['lfi', 'LFI', 'LFi'] sqli_d = ['SQLi' , 'sqli', 'SQLI', 'sqlI'] warns_h = ['High', 'high'] warns_l = ['low', 'Low'] warns_m = ['Medium', 'medium'] for i in range(len(getall)): for dorks in sql_d: if dorks in getall[i][5]: sql += 1 for dorks_t in xss_d: if dorks_t in getall[i][5]: xss += 1 for dorks_th in lfi_d: if dorks_th in getall[i][5]: lfi += 1 for dorks_f in sqli_d: if dorks_f in getall[i][5]: sqli += 1 sql -= 1 for l in warns_l: if l in getall[i][2]: low += 1 for h in warns_h: if h in getall[i][2]: high += 1 for m in warns_m: if m in getall[i][2]: med += 1 print('#################') print(' ') print('## Report: ##') print(' ') print('#################') print(' ') print(('''%d SQL, %d SQLi, %d XSS, %d LFI web vulnerabilites;''') % (sql, sqli, xss, lfi)) print('%d high level, %d medium level and %d low level vulnerabilities;' % (high, med, low)) print('There is a total of %d vulnerabilities in the database.' % (len(getall))) print(' ') wait() wait() print('All vulnerabilities stored in the database are to follow: ') print(' ') for items in getall: print(items[0]) print(' ') wait() input('Press any key to go back to the menu...') ############### ## Main menu ## ############### def main(): clear() print(''' #################################################################### # # # Welcome to Vulnerability Record Database # # Made for Pen-Testers # # # #################################################################### ''') print(''' What would you like to do? 1) Record a new vulnerability 2) View all stored vulnerabilites 3) Search for a vulnerability in the database 4) Delete a stored vulnerability 5) Generate report 6) Credits 0) Quit ''') try: with open('data/database.sql'): pass except IOError: print ('Creating database...') con = sqlite3.connect('data/database.sql') cur = con.cursor() cur.execute("""CREATE TABLE VRDrec (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc BOOL)""") cur.close() cur.close() main() try: choice = input('Enter your choice: ').strip() if choice == '1': insert() main() elif choice == '2': view_db() main() elif choice == '3': search_db() main() elif choice == '4': del_rec() main() elif choice == '5': report() main() elif choice == '6': clear() print(''' Vulnerability Record Database Coded by: Ex094 Output formatting: Deque BETA tester: noize (From HC) Inspirated by Hackcommunity.com and its members ''') input('Press any key to go back to the menu...') main() elif choice == '0': os.system('exit') elif choice == 'exit': os.system('exit') elif choice == 'quit': os.system('exit') else: print(' ') print('Invalid choice.') input('Press any key...') main() except: print('Unexpected error!') main() if '___name___' == '___main___': main()

I'm sorry but now I've really got to go.
As I come back I'll provide a detailed change log.
I haven't still looked to what Deque improved, if I didn't touch that things you could mash these up together (or if you liked better your version, I'm not gonna offend).
You may give it a shot in this while.
My Bitcoin address: 1AtxVsSSG2Z8JfjNy9KNFDUN6haeKr7LiP
Give me money by visiting www.google.com here: http://coin-ads.com/6Ol83U

If you want a Bitcoin URL shortener/advertiser, please, use this referral: http://coin-ads.com/register.php?refid=noize


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #13
@noize No Problem mate Smile I've already posted the fixed one
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #14
(04-04-2013, 07:19 PM)Ex094 Wrote: @noize No Problem mate Smile I've already posted the fixed one

Oh, I actually edited much of the source before even running it.
Anyhow, a change log:
Spoiler:
- I've edited mainly syntax ('cause this looks better to me, maybe you prefered it the way you made it);
- I changed font color to the one I like the most;
- I set it to check if username or id are used just after having entered 'em, so the user won't have to re-enter all info but just those, also it recalls insert() and not main() if they are already used now;
- I changed some other things in the code for insert() function;
- I call clear() in the function, so that it won't be:
Code:
clear() function()
but just function(), as in function() I already call it, for e.g., all
Code:
clear() main()
become just
Code:
main()
as in main() is already called a clear() function.
- I've added a sleep function for report output (not a big thing, just looked better to me);
- Fixed 1 or 2 typo errors;
- Most edits in layout/ouput/syntax (comments layout, centered "Welcome" message, substituted terms, etc...);
- Made it able to handle different options from the ones suggested (high/medium/low), though still suggests.

I can remember many other changes in the source but I couldn't tell right now. Of course, this is how it looks best to me; you may disagree.
Please, don't hit me too hard as I've never studied Python before and this is the first time ever I try to edit a Python source code, so it's understandable that I'm not gonna do big things.
My Bitcoin address: 1AtxVsSSG2Z8JfjNy9KNFDUN6haeKr7LiP
Give me money by visiting www.google.com here: http://coin-ads.com/6Ol83U

If you want a Bitcoin URL shortener/advertiser, please, use this referral: http://coin-ads.com/register.php?refid=noize


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #15
Update: Linux users can now use VRD, another bug has been found and a fix will be released later!
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #16
When I look at this code I see that I have still a lot to learn Sad Nice work Ex094!
Its awesome!
[Image: Signature.png]

Chek Out My Tutorials
| Set Up A Pentest Lab | How To Make Bitcoins |


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #17
(04-05-2013, 10:24 PM)Dapaus Wrote: When I look at this code I see that I have still a lot to learn Sad Nice work Ex094!
Its awesome!
Glad you like it mate Smile
I'll be adding more features soon.
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #18
This is an incredibly impressive and useful tool, thanks alot @Ex094 and everyone who helped, great job!!!
God i need to learn how to code lol one of these days :lol:
[Image: HChelpers_zps3210ab3a.png]


RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #19
Pretty awesome stuff, nice one.




RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | #20
I hope I'm not necromancing too much but I feel like this needs to be said (Please excuse the fact that I'm a new user).

I think this would do well to be hosted on GitHub (I see that some people have already suggested changes).

To learn github see the link (I would like to just write a tutorial but I'm too new to create threads)

External GitHub Tutorial
[Image: iQ3pcQu.png]
BTC Address: 1DCKgDaWcmc9dxBkhe9qrTQtrQpoFUzXdn