![]() |
|
Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: Python (https://sinister.li/Forum-Python) +--- Thread: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | (/Thread-Vulnerability-Record-Database-BETA-Keep-Track-of-Your-Vulnerabilities) |
RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - Ex094 - 04-04-2013 (04-04-2013, 06:59 PM)Linuxephus Wrote:I'll get Linux soon, Don't you worry! A Promise is a Promise and I shall fulfill it(04-04-2013, 06:49 PM)Ex094 Wrote: @Linuxephus Yes it's for the community and it's open source
RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - noize - 04-04-2013 Alright, I've tried to make a few (or maybe a lot, I've lost acquaintance) edits in the code. Code: ####################################################################################
# Vulnerability Record Database BETA v.2
# Read the Change Log
# Coded By Ex094
# BETA Tester: noize(A huge thanks to this guy)
# Thanks to Deque for the Output Formatting
# Thanks to Hackcommunity for the Support
####################################################################################
# If you want to learn, copy-pasting this code won't do a shit! #
# Understand the code line by line and edit it on your own. #
## ##
### ---> Just give credits <--- ###
## ##
####################################################################################
vals = [' Vulnerability name: ', ' Vulnerability ID: ', ' Exposure level: ', ' Discoverer: ', ' Exploited on: ', ' Vulnerability type: ', ' Discovered the ']
import sqlite3
import os
color = lambda: os.system('color 0a')
color()
clear = lambda: os.system('cls')
wait = lambda: os.system('timeout /t 1 /nobreak > nul')
############################################
## Insert new vulnerability into database ##
############################################
def insert():
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""SELECT * FROM VRDrec""")
info = cur.fetchall()
########################################
## Values to insert into the database ##
########################################
clear()
Vulname = input('Vulnerability name: ')
Vulid = input('Vulnerability ID: ')
#####################################################
## Check if vulnerability name or ID already exist ##
#####################################################
for i in range(len(info)):
if Vulname in info[i][0]:
print('Vulnerability name already exists.')
print('Please, choose a different name.')
input('Press any key...')
insert()
elif Vulid in info[i][1]:
print('Vulnerability ID already exists.')
print('Please, enter a different ID.')
input('Press any key...')
insert()
Explevel = input('Exposure level (high/medium/low): ')
Disname = input('Vulnerability discoverer: ')
ask = input('Exploit type (software/OS/web/other): ').strip()
if ask == 'software':
Appvuln = input(' Software name: ')
Mainvuln = Appvuln
elif ask == 'os':
Osvuln = input(' Operating system name: ')
Mainvuln = Osvuln
elif ask == 'web':
Webvuln = input(' Website URL: ').strip()
Mainvuln = Webvuln
elif ask == 'other':
Othvuln = input(' Vulnerability type: ')
Mainvuln = Othvuln
elif ask == 'else':
Othvuln = input(' Vulnerability type: ')
Mainvuln = Othvuln
else:
Mainvuln = Othvuln
Vultype = input('Exploit subcategory (code injection/CSRF/SQLi/XSS/else): ')
Datedisc = input('0-day (dd/mm/yy): ')
########################
## Database injection ##
########################
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""INSERT INTO VRDrec (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc) VALUES (?,?,?,?,?,?,?)""", (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc))
con.commit()
cur.close()
cur.close()
print('Vulnerability successfully recorded.')
input('Press any key to go back to the menu...')
#############################################
## View all records stored in the database ##
#############################################
def view_db():
clear()
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""SELECT * FROM VRDrec""")
getall = cur.fetchall()
for items in getall:
print('***********************')
for i in range(len(vals)):
print(vals[i], items[i])
print('***********************')
print(' ')
input('Press any key to go back to the menu...')
#####################
## Delete a record ##
#####################
def del_rec():
clear()
print('Enter the vulnerability ID for the record you want to delete:')
print('(Enter "view" to see all stored vulnerabilities)')
ask = input('')
if ask == 'view':
view_db()
else:
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""DELETE FROM VRDrec WHERE Vulid LIKE ?""", (ask,))
con.commit()
cur.close()
cur.close()
clear()
print('Record successfully removed from database.')
input('Press any key to go back to the menu...')
###################
## Search engine ##
###################
def search_db():
clear()
item = input('Search for vulnerability name: ')
try:
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
item = '%' + item + '%'
cur.execute("""SELECT * FROM VRDrec WHERE Vulname LIKE ?""", (item,))
find = cur.fetchall()
con.commit()
cur.close()
cur.close()
## Result ##
row = 0
print('Query returned the following item(s): ')
for items in find:
print(' ')
print('****************************')
for i in range(len(vals)):
print(vals[i], items[i])
print('****************************')
if items == '':
print('No matches found in the database.')
except:
print('No matches found in the database.')
######################
## Report generator ##
######################
def report():
clear()
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""SELECT * FROM VRDrec""")
getall = cur.fetchall()
sql = 0
xss = 0
lfi = 0
sqli = 0
other = 0
low = 0
high = 0
med = 0
sql_d = ['sql', 'SQL', 'Sql', 'SQl']
xss_d = ['xss', 'XSS', 'Xss']
lfi_d = ['lfi', 'LFI', 'LFi']
sqli_d = ['SQLi' , 'sqli', 'SQLI', 'sqlI']
warns_h = ['High', 'high']
warns_l = ['low', 'Low']
warns_m = ['Medium', 'medium']
for i in range(len(getall)):
for dorks in sql_d:
if dorks in getall[i][5]:
sql += 1
for dorks_t in xss_d:
if dorks_t in getall[i][5]:
xss += 1
for dorks_th in lfi_d:
if dorks_th in getall[i][5]:
lfi += 1
for dorks_f in sqli_d:
if dorks_f in getall[i][5]:
sqli += 1
sql -= 1
for l in warns_l:
if l in getall[i][2]:
low += 1
for h in warns_h:
if h in getall[i][2]:
high += 1
for m in warns_m:
if m in getall[i][2]:
med += 1
print('#################')
print(' ')
print('## Report: ##')
print(' ')
print('#################')
print(' ')
print(('''%d SQL, %d SQLi, %d XSS, %d LFI web vulnerabilites;''') % (sql, sqli, xss, lfi))
print('%d high level, %d medium level and %d low level vulnerabilities;' % (high, med, low))
print('There is a total of %d vulnerabilities in the database.' % (len(getall)))
print(' ')
wait()
wait()
print('All vulnerabilities stored in the database are to follow: ')
print(' ')
for items in getall:
print(items[0])
print(' ')
wait()
input('Press any key to go back to the menu...')
###############
## Main menu ##
###############
def main():
clear()
print('''
####################################################################
# #
# Welcome to Vulnerability Record Database #
# Made for Pen-Testers #
# #
####################################################################
''')
print('''
What would you like to do?
1) Record a new vulnerability
2) View all stored vulnerabilites
3) Search for a vulnerability in the database
4) Delete a stored vulnerability
5) Generate report
6) Credits
0) Quit
''')
try:
with open('data/database.sql'): pass
except IOError:
print ('Creating database...')
con = sqlite3.connect('data/database.sql')
cur = con.cursor()
cur.execute("""CREATE TABLE VRDrec (Vulname, Vulid, Explevel, Disname, Mainvuln, Vultype, Datedisc BOOL)""")
cur.close()
cur.close()
main()
try:
choice = input('Enter your choice: ').strip()
if choice == '1':
insert()
main()
elif choice == '2':
view_db()
main()
elif choice == '3':
search_db()
main()
elif choice == '4':
del_rec()
main()
elif choice == '5':
report()
main()
elif choice == '6':
clear()
print('''
Vulnerability Record Database
Coded by: Ex094
Output formatting: Deque
BETA tester: noize (From HC)
Inspirated by Hackcommunity.com and its members
''')
input('Press any key to go back to the menu...')
main()
elif choice == '0':
os.system('exit')
elif choice == 'exit':
os.system('exit')
elif choice == 'quit':
os.system('exit')
else:
print(' ')
print('Invalid choice.')
input('Press any key...')
main()
except:
print('Unexpected error!')
main()
if '___name___' == '___main___': main()I'm sorry but now I've really got to go. As I come back I'll provide a detailed change log. I haven't still looked to what Deque improved, if I didn't touch that things you could mash these up together (or if you liked better your version, I'm not gonna offend). You may give it a shot in this while. RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - Ex094 - 04-04-2013 @noize No Problem mate I've already posted the fixed one
RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - noize - 04-04-2013 (04-04-2013, 07:19 PM)Ex094 Wrote: @noize No Problem mate Oh, I actually edited much of the source before even running it. Anyhow, a change log: Spoiler:
- I've edited mainly syntax ('cause this looks better to me, maybe you prefered it the way you made it); - I changed font color to the one I like the most; - I set it to check if username or id are used just after having entered 'em, so the user won't have to re-enter all info but just those, also it recalls insert() and not main() if they are already used now; - I changed some other things in the code for insert() function; - I call clear() in the function, so that it won't be: Code: clear()
function()Code: clear()
main()Code: main()- I've added a sleep function for report output (not a big thing, just looked better to me); - Fixed 1 or 2 typo errors; - Most edits in layout/ouput/syntax (comments layout, centered "Welcome" message, substituted terms, etc...); - Made it able to handle different options from the ones suggested (high/medium/low), though still suggests. I can remember many other changes in the source but I couldn't tell right now. Of course, this is how it looks best to me; you may disagree. Please, don't hit me too hard as I've never studied Python before and this is the first time ever I try to edit a Python source code, so it's understandable that I'm not gonna do big things. RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - Ex094 - 04-05-2013 Update: Linux users can now use VRD, another bug has been found and a fix will be released later! RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - DaPaus - 04-05-2013 When I look at this code I see that I have still a lot to learn Nice work Ex094!Its awesome! RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - Ex094 - 04-06-2013 (04-05-2013, 10:24 PM)Dapaus Wrote: When I look at this code I see that I have still a lot to learnGlad you like it mate ![]() I'll be adding more features soon. RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - Exploits - 04-06-2013 This is an incredibly impressive and useful tool, thanks alot @Ex094 and everyone who helped, great job!!! God i need to learn how to code lol one of these days :lol: RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - 3r3bus - 04-07-2013 Pretty awesome stuff, nice one. RE: Vulnerability Record Database BETA | Keep Track of Your Vulnerabilities | - h3r0 - 07-15-2014 I hope I'm not necromancing too much but I feel like this needs to be said (Please excuse the fact that I'm a new user). I think this would do well to be hosted on GitHub (I see that some people have already suggested changes). To learn github see the link (I would like to just write a tutorial but I'm too new to create threads) External GitHub Tutorial |