
A library for detecting known secrets across many web frameworks
mkdir -p ~/ctools/
cd ~/ctools/
git clone https://github.com/irsdl/crapsecrets/
cd ~/ctools/crapsecrets
pip3 install -r requirements.txt
export PYTHONPATH=$(pwd):$PYTHONPATH
python3 ./crapsecrets/examples/cli.py -u http://update.microsoft.com/ -r
python3 ./crapsecrets/examples/cli.py -u http://update.microsoft.com/ -mrd 5
python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -u http://update.microsoft.com/
python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -mkf ./local/aspnet_machinekeys_local.txt -u http://192.168.6.22:8080/
python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -mkf ./local/aspnet_machinekeys_local.txt -mkf ./crapsecrets/resources/aspnet_machinekeys.txt -u http://192.168.6.22:8080/a1/b/c1/
-mrd 5 to allow analysis of long redirect responses.--allviewstatekeys or -avsk in order to try all the key combinations as validation and encryption keys--findviewstatepage or -fvsp in order to try a set of default pages when .aspx is missing from the URL--max-redirect-depth argument for manual redirects).--timeout or -t argument--allviewstatekeys flag, the tool attempts to find all Potential EncryptionKeys and tries each one in a random order to decrypt the data. Because so many keys are tested, there is a chance of hitting an invalid key on any single run. However, the tool will list every possible key it detects. By running the tool twice, you significantly increase the likelihood of finding a valid encryption key, since seeing the same key appear in both runs is nearly a 100% guarantee that it is correct.["default.aspx", "index.aspx", "main.aspx", "home.aspx" , "start.aspx", "welcome.aspx", "default2.aspx"] - This increases the testing time significantly but can potentially lead to more findings-mkf or --machinekeyfile as a resource file for machinekeys so we can use a local version if it contains sensitive keys-evsd or --enable-viewstate-decryption argument to check for the decryption key even when the validation key has not been found. This can be useful when the validation key is slightly different from the original one in the list.__VIEWSTATEGENERATOR by identifying its hash code. It also tries to find the actual path and app path early if __VIEWSTATEGENERATOR and URL have been provided. This can potentially increase performance, especially when an identifiable default ASPX page is missing from the URL.-nt or --num-threads option (only applicable for the viewstate module). The default is 1 which is surprisingly faster than 10 in most cases!-dap or --disable-active-path-check/WebResource.axd?d= or /ScriptResource.axd?d= under a new module called "aspnet_resource.py". It also supports IsolateApps feature there too. This is useful when __VIEWSTATE and __EVENTVALIDATION are missing.pytest in the root of the project. Although some of them have been fixed, there are still some errors in the tests that need addressing in the future. I also need to run pytest on the original repo to compare!FAILED tests/all_modules_test.py::test_carve_all_cookies - AssertionError: assert 2 == 7
FAILED tests/examples_blacklist3r_test.py::test_examples_blacklist3r_offline - AssertionError: assert 'Did not find viewstate in repsonse from URL' in 'Did not find viewstate in response...
FAILED tests/examples_cli_test.py::test_example_cli_hashcat_telerikhashkey - AssertionError: assert 'Module: [Te...ture Command' not in '\x1b[32m\n ...y_file>]\n\n'
FAILED tests/examples_cli_test.py::test_example_cli_hashcat_telerikhashkey_invalid2 - AssertionError: assert 'Known Secret Found!' in '\x1b[32m\n __ ) | ...
FAILED tests/examples_symfony_signedurl_test.py::test_symfony_brute_success - AssertionError: assert 'Found Symfony Secret! [50c8215b436ebfcc1d568effb624a40e]' in 'Target appears to be ...
FAILED tests/examples_telerik_knownkey_test.py::test_fullrun_PBKDF2 - KeyError: "'additional_matcher' is not a valid Pattern"
FAILED tests/examples_telerik_knownkey_test.py::test_badoutput_PBKDF1_MS - KeyError: "'additional_matcher' is not a valid Pattern"
FAILED tests/examples_telerik_knownkey_test.py::test_fullrun_asyncupload_earlydetection - KeyError: "'additional_matcher' is not a valid Pattern"
FAILED tests/examples_telerik_knownkey_test.py::test_fullrun_asyncupload_success - KeyError: "'additional_matcher' is not a valid Pattern"
FAILED tests/examples_telerik_knownkey_test.py::test_fullrun_asyncupload_PBKDF1_MS - KeyError: "'additional_matcher' is not a valid Pattern"
This software has been created purely for the purposes of academic research and for the development of effective defensive techniques, and is not intended to be used to attack systems except where explicitly authorized. Project maintainers are not responsible or liable for misuse of the software. Use responsibly.