
SeleniumベースのWebスクレイパーでパスワードリストを生成する
Selenium ベースのウェブスクレイパーで、パスワードリストを生成します。
# Download Firefox webdriver from https://github.com/mozilla/geckodriver/releases
$ tar xzf geckodriver-v{VERSION-HERE}.tar.gz
$ sudo mv geckodriver /usr/local/bin # Make sure it is in your PATH
$ geckodriver --version # Make sure webdriver is properly installed
$ git clone https://github.com/dariusztytko/words-scraper
$ sudo pip3 install -r words-scraper/requirements.txt
$ python3 words-scraper.py -o words.txt https://www.example.com https://blog.example.com
このように生成された単語リストは、オンラインブルートフォース攻撃やパスワードハッシュのクラックに使用できます:
$ hashcat -m 0 hashes.txt words.txt
--depth オプションを使用すると、リンク先のページからも単語をスクレイピングします。 オプションの --show-gui スイッチを使用すると、進捗を追跡し、ページをすばやく表示できます:
$ python3 words-scraper.py -o words.txt --depth 1 --show-gui https://www.example.com
生成された単語リストは、words-converter.py スクリプトを使用して拡張できます。 このスクリプトは特殊文字とアクセント記号を削除します。 例えば、ポーランド語の単語 źdźbło! は以下の単語に変換されます:
$ cat words.txt | python3 words-converter.py | sort -u > words2.txt
Twitter ページはスクロール中に動的に読み込まれます。 --max-scrolls オプションを使用して単語をスクレイピング:
$ python3 words-scraper.py -o words.txt --max-scrolls 300 --show-gui https://twitter.com/example.com
$ ssh -D 1080 -Nf {USER-HERE}@{IP-HERE} >/dev/null 2>&
$ python3 words-scraper.py -o words.txt --socks-proxy 127.0.0.1:1080 https://www.example.com
usage: words-scraper.py [-h] [--depth DEPTH] [--max-scrolls MAX_SCROLLS]
[--min-word-length MIN_WORD_LENGTH]
[--page-load-delay PAGE_LOAD_DELAY]
[--page-scroll-delay PAGE_SCROLL_DELAY] [--show-gui]
[--socks-proxy SOCKS_PROXY] -o OUTPUT_FILE
url [url ...]
Words scraper (version: 1.0)
positional arguments:
url URL to scrape
optional arguments:
-h, --help show this help message and exit
--depth DEPTH scraping depth, default: 0
--max-scrolls MAX_SCROLLS
maximum number of the page scrolls, default: 0
--min-word-length MIN_WORD_LENGTH
default: 3
--page-load-delay PAGE_LOAD_DELAY
page loading delay, default: 3.0
--page-scroll-delay PAGE_SCROLL_DELAY
page scrolling delay, default: 1.0
--show-gui show browser GUI
--socks-proxy SOCKS_PROXY
socks proxy e.g. 127.0.0.1:1080
-o OUTPUT_FILE, --output-file OUTPUT_FILE
save words to file
CHANGELOG を参照してください。