
ماسح ضوئي قائم على الإضافات يساعد الباحثين في مجال الأمن على تحديد المشكلات في العديد من أنظمة إدارة المحتوى، خاصة دروبال وسيلفرسترايب.
ماسح ضوئي قائم على الإضافات يساعد باحثي الأمن في تحديد المشكلات المتعلقة بعدة أنظمة إدارة محتوى (CMS).
استخدام droopescan لمهاجمة أهداف دون موافقة مسبقة متبادلة غير قانوني. تقع على عاتق المستخدم النهائي مسؤولية الامتثال لجميع القوانين المحلية والولائية والفيدرالية المعمول بها. لا يتحمل المطورون أي مسؤولية ولا يتحملون مسؤولية أي إساءة استخدام أو ضرر يسببه هذا البرنامج. يرجى ملاحظة أنه على الرغم من أن droopescan يخرج الإصدار الأكثر احتمالاً لنظام إدارة المحتوى المثبت على المضيف البعيد، إلا أن أي ارتباط بين أرقام الإصدارات والثغرات الأمنية يجب أن يتم يدويًا بواسطة المستخدم.
أنظمة إدارة المحتوى المدعومة هي:
وظائف جزئية لـ:
computer:~/droopescan$ droopescan scan drupal -u http://example.org/ -t 32
[+] No themes found.
[+] Possible interesting urls found:
Default changelog file - https://www.example.org/CHANGELOG.txt
Default admin - https://www.example.org/user/login
[+] Possible version(s):
7.34
[+] Plugins found:
views https://www.example.org/sites/all/modules/views/
https://www.example.org/sites/all/modules/views/README.txt
https://www.example.org/sites/all/modules/views/LICENSE.txt
token https://www.example.org/sites/all/modules/token/
https://www.example.org/sites/all/modules/token/README.txt
https://www.example.org/sites/all/modules/token/LICENSE.txt
pathauto https://www.example.org/sites/all/modules/pathauto/
https://www.example.org/sites/all/modules/pathauto/README.txt
https://www.example.org/sites/all/modules/pathauto/LICENSE.txt
https://www.example.org/sites/all/modules/pathauto/API.txt
libraries https://www.example.org/sites/all/modules/libraries/
https://www.example.org/sites/all/modules/libraries/CHANGELOG.txt
https://www.example.org/sites/all/modules/libraries/README.txt
https://www.example.org/sites/all/modules/libraries/LICENSE.txt
entity https://www.example.org/sites/all/modules/entity/
https://www.example.org/sites/all/modules/entity/README.txt
https://www.example.org/sites/all/modules/entity/LICENSE.txt
google_analytics https://www.example.org/sites/all/modules/google_analytics/
https://www.example.org/sites/all/modules/google_analytics/README.txt
https://www.example.org/sites/all/modules/google_analytics/LICENSE.txt
ctools https://www.example.org/sites/all/modules/ctools/
https://www.example.org/sites/all/modules/ctools/CHANGELOG.txt
https://www.example.org/sites/all/modules/ctools/LICENSE.txt
https://www.example.org/sites/all/modules/ctools/API.txt
features https://www.example.org/sites/all/modules/features/
https://www.example.org/sites/all/modules/features/CHANGELOG.txt
https://www.example.org/sites/all/modules/features/README.txt
https://www.example.org/sites/all/modules/features/LICENSE.txt
https://www.example.org/sites/all/modules/features/API.txt
[... snip for README ...]
[+] Scan finished (0:04:59.502427 elapsed)
يمكنك الحصول على قائمة كاملة بالخيارات عن طريق تشغيل:
droopescan --help
droopescan scan --help
لأن droopescan:
التثبيت سهل باستخدام pip:
apt-get install python-pip
pip install droopescan
التثبيت اليدوي كالتالي:
git clone https://github.com/droope/droopescan.git
cd droopescan
pip install -r requirements.txt
./droopescan scan --help
فرع master يتوافق مع أحدث إصدار (ما هو موجود في pypi). فرع development غير مستقر ويجب توجيه جميع طلبات السحب ضده.
تثبيت حزمة BlackArch package (يتم صيانتها بواسطة طرف ثالث):
sudo pacman -S droopescan
يمكنك بناء صورة docker وتشغيل droopescan من Docker:
git clone https://github.com/droope/droopescan.git
cd droopescan
docker build -t droope/droopescan .
# عرض المساعدة
docker run --rm droope/droopescan
# مثال لمسح موقع drupal
docker run --rm droope/droopescan scan drupal -u https://drupal.example.com
يهدف Droopescan إلى أن يكون الأكثر دقة افتراضيًا، مع عدم تحميل الخادم الهدف بسبب الطلبات المتزامنة المفرطة. لهذا السبب، افتراضيًا، سيتم إجراء عدد كبير من الطلبات بأربعة خيوط؛ قم بتغيير هذه الإعدادات باستخدام الوسيطات --number و --threads على التوالي.
هذه الأداة قادرة على إجراء أربعة أنواع من الاختبارات. افتراضيًا، يتم تشغيل جميع الاختبارات، ولكن يمكنك تحديد أحد الاختبارات التالية باستخدام العلم -e أو --enumerate:
يمكنك تحديد مضيف معين لمسحه عن طريق تمرير المعامل -u أو --url:
droopescan scan drupal -u example.org
يمكنك أيضًا حذف الوسيطة drupal. سيؤدي هذا إلى تشغيل "تحديد CMS"، مثل:
droopescan scan -u example.org
يمكن مسح عناوين URL متعددة باستخدام المعامل -U أو --url-file. يجب تعيين هذا المعامل إلى مسار ملف يحتوي على قائمة عناوين URL.
droopescan scan drupal -U list_of_urls.txt
يمكن أيضًا حذف المعامل drupal في هذا المثال. لكل موقع، سيقوم بعدة طلبات GET لتحديد CMS، وإذا تم اعتبار الموقع CMS مدعومًا، يتم مسحه وإضافته إلى قائمة الإخراج. يمكن أن يكون هذا مفيدًا، على سبيل المثال، لتشغيل droopescan عبر جميع مواقع مؤسستك.
droopescan scan -U list_of_urls.txt
يحتوي كتلة الكود أدناه على مثال لقائمة عناوين URL، واحد لكل سطر:
http://localhost/drupal/6.0/
http://localhost/drupal/6.1/
http://localhost/drupal/6.10/
http://localhost/drupal/6.11/
http://localhost/drupal/6.12/
ملف يحتوي على عناوين URL وقيمة لتجاوز رأس المضيف الافتراضي مفصولة بعلامات تبويب أو مسافات مقبول أيضًا لملفات URL. يمكن أن يكون هذا مفيدًا عند إجراء مسح عبر نطاق كبير من المضيفات وتريد منع استعلامات DNS غير الضرورية. للتوضيح، مثال أدناه:
192.168.1.1 example.org
http://192.168.1.1/ example.org
http://192.168.1.2/drupal/ example.org
من المغري جدًا اختبار ما إذا كان الماسح يعمل مع CMS معين عن طريق مسح الموقع الرسمي (على سبيل المثال wordpress.org لـ wordpress)، لكن المواقع الرسمية نادرًا ما تعمل بتثبيتات عادية لأنظمة إدارة المحتوى الخاصة بها أو تقوم بأشياء غير تقليدية. على سبيل المثال، يعمل wordpress.org على الإصدار الأحدث من wordpress، والذي لن يتم التعرف عليه على أنه wordpress بواسطة droopescan على الإطلاق لأن المجاميع الاختبارية لا تتطابق مع أي إصدار معروف من wordpress.
يدعم التطبيق بالكامل ملفات .netrc ومتغيرات البيئة http_proxy.
استخدم ملف .netrc للمصادقة الأساسية. مثال لملف netrc (ملف باسم .netrc موضوع في دليل المنزل الرئيسي الخاص بك) يمكن أن يبدو كالتالي:
machine secret.google.com
login [email protected]
password Winter01
يمكنك تعيين متغيرات http_proxy و https_proxy. تسمح لك هذه بتعيين وكيل HTTP رئيسي، حيث يمكنك التعامل مع أنواع أكثر تعقيدًا من المصادقة (مثل Fiddler، ZAP، Burp)