
Jok3r - Network and Web Pentest Framework
.. raw:: html
.. image:: ./pictures/logo.png
.. raw:: html
.. image:: https://img.shields.io/badge/python-3.6-blue.svg :target: https://www.python.org/downloads/release/python-366/ :alt: Python 3.6
.. image:: https://readthedocs.org/projects/jok3r/badge/?version=latest :target: https://jok3r.readthedocs.io/en/latest/ :alt: Documentation ReadTheDocs
.. image:: https://img.shields.io/docker/automated/koutto/jok3r.svg :target: https://hub.docker.com/r/koutto/jok3r/ :alt: Docker Automated build
.. image:: https://img.shields.io/docker/build/koutto/jok3r.svg :alt: Docker Build Status
.. raw:: html
Jok3r is a Python3 CLI application aimed at helping penetration testers with network infrastructure and black-box web security testing.
Its main goal is to save time on everything that can be automated in the network/web to be audited, so you can spend more time on more interesting and challenging things.
To achieve this, I have combined open source auditing tools to run various security checks on all common network services.
Tool management:
Attack automation:
Mission / Local Database Management:
Jok3r has been built with the ambition of being easy and quickly customizable: Tools, security checks, supported network services... can be easily added/edited/removed by editing configuration files with an easy-to-understand syntax.
The recommended way to use Jok3r is inside a Docker container, no worries about dependency issues when installing the various auditing tools.
.. image:: https://raw.githubusercontent.com/koutto/jok3r/master/pictures/docker-logo.png
A Docker image is available on Docker Hub and is automatically rebuilt on each update: https://hub.docker.com/r/koutto/jok3r/. Initially based on official Kali / Debian Linux Docker image (kalilinux/kali-linux-docker).
.. image:: https://images.microbadger.com/badges/image/koutto/jok3r.svg :target: https://microbadger.com/images/koutto/jok3r :alt: Docker Image size
Pull Jok3r Docker image:
.. code-block:: console
sudo docker pull koutto/jok3r
Run updated Docker container:
.. code-block:: console
sudo docker run -i -t --name jok3r-container -w /root/jok3r --net=host koutto/jok3r
Important: --net=host option required to share the host interface. It is needed for reverse connections (e.g., to ping the container when testing RCE, get a reverse shell))
Jok3r toolbox is ready to use!
.. code-block:: console
sudo docker start -i jok3r-container
.. code-block:: console
sudo docker exec -it jok3r-container bash
Show all tools
.. code-block:: console
python3 jok3r.py toolbox --show-all
Install all tools
.. code-block:: console
python3 jok3r.py toolbox --install-all --fast
Update all tools
.. code-block:: console
python3 jok3r.py toolbox --update-all --fast
List supported services
.. code-block:: console
python3 jok3r.py info --services
Show security checks for HTTP
.. code-block:: console
python3 jok3r.py info --checks http
Create a new mission in the local database
.. code-block:: console
python3 jok3r.py db
jok3rdb[default]> mission -a MyAudit
[+] Mission "MyAudit" added successfully
[*] Selected mission is MyAudit
jok3rdb[MyAudit]>
Run security checks on a URL and add results to the mission
.. code-block:: console
python3 jok3r.py attack -t https://www.frogs.com/webapp/ --add MyAudit
Run security checks on MSSQL service (without user interaction) and add results to the mission
.. code-block:: console
python3 jok3r.py attack -t 190.212.190.133:1433 -s mssql --add MyAudit --fast
Import hosts/services from Nmap results into the mission scope
.. code-block:: console
python3 jok3r.py db
jok3rdb[default]> mission MyAudit
[*] Selected mission is now MyAudit
jok3rdb[MyAudit]> nmap results.xml
Run security checks on services in the given mission and store results in the database
.. code-block:: console
python3 jok3r.py attack -m MyAudit --fast
Run security checks only on FTP services on ports 21/tcp and 2121/tcp of the mission
.. code-block:: console
python3 jok3r.py attack -m MyAudit -f "port=21,2121;service=ftp" --fast
Run security checks only on FTP services on port 2121/tcp and all HTTP services on 190.212.190.133 of the mission
.. code-block:: console
python3 jok3r.py attack -m MyAudit -f "port=2121;service=ftp" -f "ip=190.212.190.133;service=http"
You start an audit with multiple servers. Here is a common example in JoK3r:
Run Nmap scan on the target servers
Create a new mission (say "MyAudit") in the local database:
.. code-block:: console
python3 jok3r.py db
jok3rdb[default]> mission -a MyAudit
[+] Mission "MyAudit" successfully added
[*] Selected mission is MyAudit
jok3rdb[MyAudit]>
3. Import your Nmap scan results:
.. code-block:: console
jok3rdb[MyAudit]> nmap results.xml
4. You can get a quick overview of all services and hosts, add some comments, add some credentials if you already have some knowledge about the targets (grey box pentest) and so on
.. code-block:: console
jok3rdb[MyAudit]> hosts
[...]
jok3rdb[MyAudit]> services
[...]
5. Now, run security checks against some targets. For example, to run checks for Java-RMI services, you can run the following command:
.. code-block:: console
python3 jok3r.py attack -m MyAudit -f "service=java-rmi" --fast
6. You can view the results of the security checks live while tools are running or later from the database using the following command:
.. code-block:: console
jok3rdb[MayhemProject]> results
Documentation is available at: coming soon...
Many checks are still to be implemented and services need to be added! Work in progress ...
AJP (default 8009/tcp)_FTP (default 21/tcp)_HTTP (default 80/tcp)_Java-RMI (default 1099/tcp)_JDWP (default 9000/tcp)_MSSQL (default 1433/tcp)_MySQL (default 3306/tcp)_Oracle (default 1521/tcp)_PostgreSQL (default 5432/tcp)_RDP (default 3389/tcp)_SMB (default 445/tcp)_SMTP (default 25/tcp)_SNMP (default 161/udp)_SSH (default 22/tcp)_Telnet (default 21/tcp)_VNC (default 5900/tcp)_.. code-block:: console