Spaces:
Running on CPU Upgrade
Running on CPU Upgrade
| ############################################################################### | |
| # SPDX-License-Identifier: GPL-3.0-only | |
| # PURPOSE: Run dictionary tests | |
| ############################################################################### | |
| sub nikto_dictionary_attack_init { | |
| my $id = { name => "dictionary", | |
| full_name => "Dictionary attack", | |
| author => "Tautology", | |
| description => "Attempts to dictionary attack commonly known directories/files", | |
| hooks => { | |
| recon => { method => \&nikto_dictionary_attack, | |
| weight => 20, | |
| }, | |
| }, | |
| options => { dictionary => "Dictionary of paths to look for.", | |
| method => "Method to use to enumerate.", | |
| }, | |
| copyright => "2009 Chris Sullo" | |
| }; | |
| return $id; | |
| } | |
| sub nikto_dictionary_attack { | |
| my ($mark, $parameters) = @_; | |
| return if $mark->{'terminate'}; | |
| my $method = "HEAD"; | |
| my $dictfile = ""; | |
| if ( defined $parameters | |
| && defined $parameters->{'dictionary'}) { | |
| $dictfile = $parameters->{'dictionary'}; | |
| } | |
| elsif (defined($CLI{'mutate-options'})) { | |
| $dictfile = $CLI{'mutate-options'}; | |
| } | |
| else { | |
| nprint("- No dictionary file given in plugin options, skipping check", "v", "dictionary"); | |
| return; | |
| } | |
| if ( defined $parameters | |
| && defined $parameters->{'method'}) { | |
| $method = $parameters->{'method'}; | |
| } | |
| my $ctr = 0; | |
| if (!defined $dictfile) { | |
| nprint("- No dictionary file given in mutate-options, skipping check."); | |
| return; | |
| } | |
| # Record the host for future use | |
| my $host = $mark->{'hostname'}; | |
| nprint("- Guessing directories/files (using dictionary $dictfile).", "v", "dictionary"); | |
| my $fh; | |
| unless (open($fh, "<", $dictfile)) { | |
| nprint("+ ERROR: Unable to open dictionary file $dictfile: $!."); | |
| return; | |
| } | |
| # Now attempt on each entry | |
| while (<$fh>) { | |
| return if $mark->{'terminate'}; | |
| chomp; | |
| s/\#.*$//; | |
| next if ($_ eq ""); | |
| my $dir = $_; | |
| if (($ctr % 100) == 0) { | |
| nprint("- File enumeration guess $ctr ($dir): /$dir/", "v", "dictionary"); | |
| } | |
| my ($code, $content, $error, $request, $response) = | |
| nfetch($mark, "/$dir", "${method}", "", "", "", "dictionary_attack"); | |
| foreach my $found (split(/ /, $VARIABLES{"\@HTTPFOUND"})) { | |
| if ($code eq $found) { | |
| add_vulnerability($mark, "/$dir: Found a file", | |
| 999969, "", $method, "/$dir", $request, $response); | |
| } | |
| } | |
| $ctr++; | |
| } | |
| close($fh); | |
| } # End sub | |
| 1; | |