
Web scanner that detects CMS versions, plugins, vulnerable JavaScript libraries, email addresses, and phone numbers on target websites, scoring information leakage risk.
First run docker run --rm -p 8000:80 siwecos/infoleak-scanner.
Open your browser and use the scanner: http://localhost/?url=<URL>
Get php5, curl and a webserver:
sudo apt-get install apache2 php5 php5-curl
Copy application into webserver:
cp -R . /var/www/html/
Searches plugins for the detected CMS. Biggest list (wordpress) contains 980 different plugins.
Searches for vulnerable and most used JavaScript libraries.
Searches for mail adresses. Interesting for spam and/or social engineering attacks.
Searches for phone numbers. Interesting for social engineering attacks and/or scam.
| Finding | Score (0-100) |
|---------------------+---------------|
| CMS_ONLY | 100 |
| CMS_VERSION | 96 |
| CMS_VERSION_VULN | see below |
| PLUGIN_ONLY | 99 |
| PLUGIN_VERSION | 96 |
| PLUGIN_VERSION_VULN | see below |
| JS_LIB_ONLY | 99 |
| JS_LIB_VERSION | 96 |
| JS_LIB_VULN_VERSION | see below |
| EMAIL_FOUND | 96 |
| NUMBER_FOUND | 98 |
If there was a finding like:
CMS_VERSION_VULN
PLUGIN_VERSION_VULN
JS_LIB_VULN_VERSION
then the overall score will capped to 20 and every additional vulnerability
will decrease the overall score by 10. Which means, that if
CMS_VERSION_VULN and PLUGIN_VERSION_VULN and JS_LIB_VULN_VERSION is returned, the
overall score will be 0.
Also a finding of jQuery v1.12.4 on a Wordpress website won't be rated like a usual vulnerable library.
This finding will result in a score of 90, but the placeholder will still be JS_LIB_VULN_VERSION as it is a vulnerable library.
You can run the scanner via POST and GET requests.
If you want to run the scanner with a POST request you have to send the parameters in a JSON encoded format:
{
"url": "string",
"dangerLevel": 0,
"callbackurls": [
"string"
],
"userAgent": "string"
}
url defines the URL which should be scanned.
dangerLevel is not relevant, simply define it to 0.
callbackurls is an array of URLs. These URLs will get the result of the
scanner (sent via POST).
userAgent defines your individual user agent which you want to be sent when scanning.
Running the scanner with a GET request is much simpler. All you have to do is to run the application with a given URL:
http://localhost/?url=<URL>
No findings in any scans:
{
"name": "InfoLeak-Scanner",
"version": "1.0.0",
"hasError": false,
"errorMessage": null,
"score": 100,
"tests": [
{
"name": "CMS",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "info",
"testDetails": null
},
{
"name": "CMS_PLUGINS",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "warning",
"testDetails": null
},
{
"name": "JS_LIB",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "warning",
"testDetails": null
},
{
"name": "EMAIL_ADDRESS",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "info",
"testDetails": null
},
{
"name": "PHONE_NUMBER",
"hasError": false,
"errorMessage": null,
"score": 100,
"scoreType": "info",
"testDetails": null
}
]
}
At least one finding in every scan:
{
"name": "InfoLeak-Scanner",
"version": "1.0.0",
"hasError": false,
"errorMessage": null,
"score": 20,
"tests": [
{
"name": "CMS",
"hasError": false,
"errorMessage": null,
"score": 96,
"scoreType": "info",
"testDetails": [
{
"placeholder": "CMS_VERSION",
"values": {
"cms": "wordpress",
"version": "4.9.6",
"node": "meta",
"node_content": "WordPress 4.9.6"
}
}
]
},
{
"name": "CMS_PLUGINS",
"hasError": false,
"errorMessage": null,
"score": 99,
"scoreType": "warning",
"testDetails": [
{
"placeholder": "PLUGIN_ONLY",
"values": {
"plugin": "contact-form-7",
"node": "href",
"node_content": "https://[...]/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.0.2"
}
}
]
},
{
"name": "JS_LIB",
"hasError": false,
"errorMessage": null,
"score": 0,
"scoreType": "warning",
"testDetails": [
{
"placeholder": "JS_LIB_VULN_VERSION",
"values": {
"js_lib_name": "jquery",
"js_lib_version": "1.12.4",
"node": "src",
"node_content": "https://[...]/wp-includes/js/jquery/jquery.js?ver=1.12.4"
}
}
]
},
{
"name": "EMAIL_ADDRESS",
"hasError": false,
"errorMessage": null,
"score": 96,
"scoreType": "info",
"testDetails": [
{
"placeholder": "EMAIL_FOUND",
"values": {
"email_adress": [
[
"[email protected]"
]
]
}
}
]
},
{
"name": "PHONE_NUMBER",
"hasError": false,
"errorMessage": null,
"score": 98,
"scoreType": "info",
"testDetails": [
{
"placeholder": "NUMBER_FOUND",
"values": {
"number": [
"1234-12 11 22-3",
"123-11 22 333-4"
]
}
}
]
}
]
}