734 Commits

Author SHA1 Message Date
dependabot[bot]
c97eac958b Bump libsqlite3-sys from 0.22.2 to 0.25.1
Bumps [libsqlite3-sys](https://github.com/rusqlite/rusqlite) from 0.22.2 to 0.25.1.
- [Release notes](https://github.com/rusqlite/rusqlite/releases)
- [Changelog](https://github.com/rusqlite/rusqlite/blob/master/Changelog.md)
- [Commits](https://github.com/rusqlite/rusqlite/commits/v0.25.1)

---
updated-dependencies:
- dependency-name: libsqlite3-sys
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-02-15 15:45:10 +00:00
kpcyrd
844a40e929 Release v0.25.0 2023-01-28 19:51:02 +01:00
kpcyrd
2238285c16 Merge pull request #239 from kpcyrd/update
Update dependencies, fix #238
2023-01-28 18:42:38 +00:00
kpcyrd
e397edb4f4 Refactor MQTT client integration, integrate automatic keep-alive 2023-01-28 17:58:11 +01:00
kpcyrd
70b5039d50 Fix some clippy warnings, remove base64 crate 2023-01-27 19:31:48 +01:00
kpcyrd
326c868699 Update dependencies 2023-01-27 19:15:24 +01:00
kpcyrd
1be1967d6f Release v0.24.3 2022-11-13 03:22:10 +01:00
kpcyrd
5364328e2a Merge pull request #236 from kpcyrd/bump
Fix clone3 sandbox crash, improve sandbox crash error message
2022-11-13 02:19:54 +00:00
kpcyrd
01bcb10833 Fix chrono deprecation warnings 2022-11-13 03:01:07 +01:00
kpcyrd
56f7b1c646 Fix winkekatze-sub.lua example module 2022-11-12 21:47:15 +01:00
kpcyrd
dc26c14da4 Allow clone3 syscall in sandbox (#235) 2022-11-12 21:46:47 +01:00
kpcyrd
a2c70e43de Replace EOF while parsing a value at line 1 column 0 error with Sandbox child has crashed 2022-11-12 21:37:05 +01:00
kpcyrd
b28276c42e Update dependencies 2022-11-12 21:24:19 +01:00
kpcyrd
aa3311bfab Merge pull request #234 from SpriteOvO/riscv64
Support compiling for RISC-V 64-bit
2022-09-29 16:43:42 +00:00
Sprite
edb5b4bf25 Support compiling for RISC-V 64-bit 2022-09-28 21:18:02 +08:00
kpcyrd
231d3293fe Merge pull request #229 from kpcyrd/bump
Update dependencies
2022-07-17 17:02:38 +00:00
kpcyrd
febb39ab03 Update dependencies 2022-07-17 18:49:21 +02:00
kpcyrd
ebc1fa791d Fix clippy warnings, reduce heap allocations 2022-07-14 00:04:38 +02:00
kpcyrd
3ea88d9bd5 Merge pull request #227 from stoeckmann/paths
Fix error messages in paths.rs
2022-04-13 22:49:41 +00:00
Tobias Stoeckmann
006e3618fb Unify function bodies 2022-04-13 22:29:38 +02:00
Tobias Stoeckmann
c4b74aa6fc Adjust error messages to show target directory 2022-04-13 22:29:36 +02:00
kpcyrd
6cd97d980d Release v0.24.2 2022-03-29 02:38:09 +02:00
kpcyrd
b4f2591378 Merge pull request #225 from kpcyrd/bump
Update dependencies
2022-03-29 00:27:34 +00:00
kpcyrd
3a204a92a5 Add docker release github action 2022-03-29 01:16:52 +02:00
kpcyrd
b65c72d090 Update Dockerfile to alpine 3.15 and buildkit 2022-03-28 20:40:15 +02:00
kpcyrd
035ef9aa76 Add missing seccomp syscall (rseq) 2022-03-28 19:25:22 +02:00
kpcyrd
35c6501623 Update dependencies 2022-03-28 18:44:32 +02:00
kpcyrd
c0cb5840cc Merge pull request #224 from ysf/patch-1
Fixed typo
2022-03-21 17:57:30 +00:00
ysf
bba152d560 Fixed typo 2022-03-21 09:18:52 +01:00
kpcyrd
53a39d54bc Merge pull request #223 from definitepotato/issue-222
Adding syscall to seccomp sandbox.
2022-01-19 11:19:33 +00:00
definitepotato
455403baaf Adding syscall to seccomp sandbox. 2022-01-15 13:14:16 -05:00
kpcyrd
ec07344a0b Merge pull request #221 from kpcyrd/clippy
Fix clippy warnings
2022-01-14 15:56:14 +00:00
kpcyrd
c2d95659dc Fix clippy warnings 2022-01-13 20:05:34 +01:00
kpcyrd
cd99ac3911 Release v0.24.1 2021-12-05 16:17:51 +01:00
kpcyrd
f2a5dbc60c Merge pull request #219 from kpcyrd/seccomp
seccomp: Allow fstat call
2021-12-05 12:05:12 +00:00
kpcyrd
6425483c2b seccomp: Allow fstat call 2021-12-05 12:37:20 +01:00
kpcyrd
25f940788f Release v0.24.0 2021-12-05 01:15:41 +01:00
kpcyrd
c232b23b1e Merge pull request #217 from kpcyrd/rescope
Add rescope command to run autonoscope rules on existing db
2021-12-04 23:40:51 +00:00
kpcyrd
5b19c8c4b3 Add basic completions for interactive shell 2021-12-03 18:38:36 +01:00
kpcyrd
aeba3f4574 Allow statx and lseek syscalls 2021-12-03 18:38:36 +01:00
kpcyrd
1f5ea402ea Support rescoping with filters 2021-12-03 14:27:06 +01:00
kpcyrd
d54ffd1eba Add advanced interactive mode for rescope 2021-12-03 13:49:03 +01:00
kpcyrd
5bca5677b6 Add rescope command to run autonoscope rules on existing db 2021-12-03 04:11:53 +01:00
kpcyrd
af021cb6be Allow invoking sn0int autonoscope and sn0int autoscope from cli 2021-12-03 01:05:25 +01:00
kpcyrd
52891cf6b1 Fix compile warning about dead code 2021-12-03 00:52:29 +01:00
kpcyrd
6e76c035df Bump dependencies 2021-12-03 00:43:41 +01:00
kpcyrd
850d628a93 Release v0.23.0 2021-10-23 20:02:24 +02:00
kpcyrd
5bb03d39bc Merge pull request #215 from kpcyrd/user-agent
Allow setting a different default user agent
2021-10-23 12:23:24 +00:00
kpcyrd
f5660570d2 Update dependencies 2021-10-23 14:03:12 +02:00
kpcyrd
f1b0608daa Allow setting a different default user agent 2021-10-23 13:50:32 +02:00
kpcyrd
c775ae1dee Add patreon link 2021-10-23 13:15:50 +02:00
kpcyrd
36b5219008 Update readme 2021-10-02 15:03:25 +02:00
kpcyrd
79982fd5f0 Merge pull request #214 from kpcyrd/img-hash
Add perceptual image hashing
2021-09-22 01:58:21 +00:00
kpcyrd
5fe71feec3 Fix regression for sn0int run -f ./foo.lua 2021-09-22 01:21:03 +02:00
kpcyrd
b8d4eb0f51 Add functions for perceptual image hashing 2021-09-22 01:19:59 +02:00
kpcyrd
e6444db009 Merge pull request #213 from kpcyrd/cli-proxy
Allow setting a proxy with `run -X <proxy>`
2021-09-13 10:19:38 +00:00
kpcyrd
7dcb6b81dc Allow setting a proxy with run -X <proxy> 2021-09-13 11:51:32 +02:00
kpcyrd
4fb56d91c2 Allow using run <module> interactively 2021-09-13 11:29:13 +02:00
kpcyrd
8c486b7e6e Release v0.22.0 2021-09-08 18:44:54 +02:00
kpcyrd
e939a28469 Merge pull request #210 from kpcyrd/bump
Update dependencies
2021-09-08 12:12:28 +00:00
kpcyrd
2dec9dd28c Update dependencies 2021-09-08 13:50:57 +02:00
kpcyrd
06459098b1 Merge pull request #209 from kpcyrd/update
Update dependencies, fix clippy warnings
2021-09-06 15:07:53 +00:00
kpcyrd
fc0447725c Fix clippy warnings 2021-09-06 16:26:45 +02:00
kpcyrd
8312695e46 Update dependencies 2021-09-06 15:44:45 +02:00
kpcyrd
6c8e2df632 Update to nom7 2021-08-21 13:31:09 +02:00
kpcyrd
b1ee2d4ce7 Merge pull request #208 from kpcyrd/update
Update dependencies
2021-08-17 20:48:13 +00:00
kpcyrd
4cbb72e4c8 Update dependencies 2021-08-17 21:22:48 +02:00
kpcyrd
9e76935f55 Merge pull request #207 from kpcyrd/readline-exec
Support invoking shell commands with `!` from readline
2021-08-01 17:00:10 +00:00
kpcyrd
8b5ad635fa Support invoking shell commands with ! from readline 2021-07-29 14:15:00 +02:00
kpcyrd
9f4914f419 Release v0.21.2 2021-06-23 23:12:19 +02:00
kpcyrd
f24b1b2b9b Update dockerfile baseimage 2021-06-23 23:07:37 +02:00
kpcyrd
735e2dbaf8 Merge pull request #205 from kpcyrd/update
Update dependencies, fix seccomp issue on x86_64 musl
2021-06-23 21:03:19 +00:00
kpcyrd
5409ed8cdb Fix integration tests 2021-06-23 17:33:09 +02:00
kpcyrd
d0a36be95a Update dependencies 2021-06-23 17:00:11 +02:00
kpcyrd
0ab8aace70 Fix seccomp segfault with open on x86_64 musl 2021-06-23 17:00:11 +02:00
kpcyrd
699ebad23a registry: Set user agent when authenticating with github 2021-06-23 16:22:31 +02:00
kpcyrd
84e0e62753 Release v0.21.1 2021-05-18 00:49:10 +02:00
kpcyrd
dc8aac1b0f Merge pull request #202 from kpcyrd/aarch64
Update dependencies to fix aarch64 on musl
2021-05-17 22:46:55 +00:00
kpcyrd
7b4d599951 Update dependencies to fix aarch64 on musl 2021-05-18 00:30:39 +02:00
kpcyrd
d88c722a4b Release v0.21.0 2021-05-12 19:19:30 +02:00
kpcyrd
d70fc8f4c0 Merge pull request #200 from kpcyrd/update
Update dependencies
2021-05-12 16:54:46 +00:00
kpcyrd
da08f3a4bb Update dependencies 2021-05-12 18:27:44 +02:00
kpcyrd
892fa0d3e4 Merge pull request #199 from kpcyrd/stats
Improve stats command
2021-04-07 01:03:21 +00:00
kpcyrd
605d691b28 Add select --values as shorthand for jq -r .value 2021-04-07 02:34:41 +02:00
kpcyrd
efb458a725 Allow deleting multiple workspaces at once 2021-04-07 02:25:58 +02:00
kpcyrd
84e147f709 Add stats -q for more compact output 2021-04-07 02:11:29 +02:00
kpcyrd
1876e9ac8d Add stats --all to show stats for all workspaces 2021-04-07 01:51:57 +02:00
kpcyrd
8525883b91 README: Add packaging status 2021-03-23 01:29:53 +00:00
kpcyrd
02c537c253 Merge pull request #197 from kpcyrd/stats
Add sn0int stats
2021-03-20 13:38:12 +00:00
kpcyrd
d84038dcc3 Add irc notifications for github actions 2021-03-18 03:31:07 +01:00
kpcyrd
becb44a5d7 Update dependencies 2021-03-18 02:38:47 +01:00
kpcyrd
6e1904eaf9 Extend interactive completions for pkg list 2021-03-14 19:38:44 +01:00
kpcyrd
d493857011 Add stats --json output 2021-03-14 18:40:47 +01:00
kpcyrd
3af9abde1b Add stats command 2021-03-14 01:34:42 +01:00
kpcyrd
0ea8c46578 Release v0.20.1 2021-03-07 16:07:34 +01:00
kpcyrd
2e231da60c Merge pull request #196 from kpcyrd/update
Speedup initial database setup
2021-03-07 14:58:12 +00:00
kpcyrd
a97a7c6a4c Speedup docker build on github actions 2021-03-07 15:40:02 +01:00
kpcyrd
2b09ca997c Introduce github actions 2021-03-07 14:44:09 +01:00
kpcyrd
66fa77d16e Speedup initial database setup 2021-03-07 14:11:37 +01:00
kpcyrd
23e06ede3b Update dependencies 2021-03-07 14:11:25 +01:00
kpcyrd
7b994d7cae Merge pull request #195 from steev/master
Mention pkg-config being needed.
2021-01-03 20:06:05 +00:00
Steev Klimaszewski
59b591d0e8 Mention pkg-config being needed.
Not all installations have build tools installed, and libsodium requires
calling out to pkg-config so add it to the build instructions on Debian
so that the build doesn't fail.
2021-01-03 10:54:13 -06:00
kpcyrd
309be4b22f Release v0.20.0 2020-12-28 20:47:45 +01:00
kpcyrd
02d0ccce64 Merge pull request #194 from kpcyrd/bump
Bump dependencies
2020-12-28 19:03:23 +00:00
kpcyrd
a15d8167b9 Fix clippy warnings 2020-12-28 18:12:45 +01:00
kpcyrd
d125d91f0d Update dependencies 2020-12-28 17:13:40 +01:00
kpcyrd
01e4f87420 Update dependencies 2020-12-28 15:58:10 +01:00
kpcyrd
037189ec57 Merge pull request #189 from kpcyrd/redirects
Add option to follow redirects
2020-12-28 13:17:22 +00:00
kpcyrd
0d77c06a95 Fix default user agent 2020-11-01 23:20:28 +01:00
kpcyrd
247648aff8 Add redirect support 2020-11-01 23:04:06 +01:00
kpcyrd
f73c375d12 Merge pull request #187 from kpcyrd/add-stdin
Allow streaming some structs from stdin into db
2020-11-01 20:11:59 +00:00
kpcyrd
484507e033 Merge pull request #188 from kpcyrd/inverse-rules
Add inverse rules
2020-11-01 20:04:42 +00:00
kpcyrd
27588f5319 Allow streaming some structs from stdin into db 2020-11-01 19:28:50 +01:00
kpcyrd
c2b535eeed Merge pull request #186 from kpcyrd/bump
Bump dependencies
2020-11-01 16:33:44 +00:00
kpcyrd
410a381643 Update kali install instructions 2020-11-01 03:46:56 +01:00
kpcyrd
f702f48708 Update dependencies 2020-10-27 00:56:26 +01:00
kpcyrd
031a269de0 Update cert parser 2020-10-27 00:49:34 +01:00
kpcyrd
c1b38c8fa6 Add inverse rules 2020-10-27 00:07:00 +01:00
kpcyrd
afe302c101 Update dependencies 2020-10-02 21:23:28 +02:00
kpcyrd
b09c820a11 Merge pull request #183 from kpcyrd/stealth
Add support to track module stealth in metadata
2020-09-25 21:20:32 +00:00
kpcyrd
301ad3cf44 Show possible stealth values in help 2020-09-25 22:51:03 +02:00
kpcyrd
53b1e9fd1a Align pkg-search style with pkg-list 2020-09-25 22:41:33 +02:00
kpcyrd
5c447d259f Update dependencies 2020-09-25 20:50:14 +02:00
kpcyrd
67082a1002 Allow filtering by stealth level in pkg list 2020-09-13 22:40:42 +02:00
kpcyrd
152dd82848 Show stealth status in pkg list 2020-09-13 22:19:01 +02:00
kpcyrd
21c70aaf58 Add author and repository meta fields 2020-09-13 21:36:33 +02:00
kpcyrd
a93d9ddbe2 Add -- Stealth metadata option 2020-09-13 21:24:17 +02:00
kpcyrd
1de7f1a2d2 Highlight weekends in cal time/hour view 2020-07-08 02:21:41 +02:00
kpcyrd
4a82171ca1 Correctly clear terminal after worker::spawn_multi 2020-06-26 03:18:11 +02:00
kpcyrd
1828b67509 Release v0.19.1 2020-06-24 00:46:45 +02:00
kpcyrd
8f2d71e631 Merge pull request #181 from kpcyrd/notify-fix
Fix early exit on notification and make ratelimiter more global
2020-06-23 23:11:59 +02:00
kpcyrd
2277089bda Share the ratelimit state between main modules and all notifications 2020-06-23 05:41:24 +02:00
kpcyrd
63f226f68f Prevent notifications from interfering with ctrl-c register 2020-06-23 04:55:16 +02:00
kpcyrd
da0e6aa482 Release v0.19.0 2020-06-18 21:06:11 +02:00
kpcyrd
82a2bb1bd0 Merge pull request #180 from kpcyrd/exit
Make sn0int more forgiving with accidential ^C
2020-06-18 18:46:29 +02:00
kpcyrd
b96eea97ee Add exit and quit to completion, remove quickstart 2020-06-18 03:38:16 +02:00
kpcyrd
fd420f4107 Make sn0int more forgiving with accidential ^C 2020-06-18 03:38:16 +02:00
kpcyrd
c5a23a5929 Merge pull request #179 from kpcyrd/notify
Trigger events on database insert/update/delete
2020-06-13 16:06:22 +02:00
kpcyrd
eb2e6203be Trigger notification on ttl expire 2020-06-13 00:48:11 +02:00
kpcyrd
b838dc5b31 Refactor db add/update logging code 2020-06-12 23:24:24 +02:00
kpcyrd
983df4a12e Trigger events on database inserts and updates 2020-06-12 21:32:15 +02:00
kpcyrd
9825bad1fe Merge pull request #178 from kpcyrd/notify
Add basic notification system
2020-06-12 04:13:09 +02:00
kpcyrd
0183e5dbcf Document signal notifications 2020-06-12 03:21:46 +02:00
kpcyrd
dacc28e2f1 Document discord notifications 2020-06-12 00:02:22 +02:00
kpcyrd
90b3abc471 Allow access to debug logs in notify scripts 2020-06-11 23:57:53 +02:00
kpcyrd
09333ebd0d Fix timer description 2020-06-11 04:10:11 +02:00
kpcyrd
e8b1b1ac87 Document notifications with pushover 2020-06-11 03:43:51 +02:00
kpcyrd
eb56a66b20 Include example code to write scripts with options 2020-06-11 03:23:37 +02:00
kpcyrd
fbd9909fef Document new notification system 2020-06-11 03:15:24 +02:00
kpcyrd
51e76b4c89 Connect db_activity to notification system 2020-06-11 01:51:59 +02:00
kpcyrd
484a426834 Fix workspace filter 2020-06-10 03:25:40 +02:00
kpcyrd
31b8840f8c Implement glob patterns for topics 2020-06-10 03:11:25 +02:00
kpcyrd
dfc13be9cc Add notify system 2020-06-10 01:53:43 +02:00
kpcyrd
d6bb6a9a1f Merge pull request #176 from kpcyrd/seccomp
Fix seccomp issues on arm
2020-06-09 13:51:39 +02:00
kpcyrd
bfbe8f2c1a Merge pull request #177 from kpcyrd/cal
Implement calendar function
2020-06-09 13:51:31 +02:00
kpcyrd
289b0edbb3 Fix seccomp issues on arm 2020-06-09 01:26:33 +02:00
kpcyrd
b69e5f879b Merge pull request #175 from kpcyrd/bump-deps
Bump dependencies
2020-06-08 14:40:12 +02:00
kpcyrd
d8810a449c Implement an hourly-view 2020-06-08 03:24:26 +02:00
kpcyrd
bdcd052500 Add time view with 12min slices 2020-06-08 03:24:26 +02:00
kpcyrd
26aa17bf4d Fix crash with low activity 2020-06-08 03:24:26 +02:00
kpcyrd
7a6d6cf2d5 Integrate activity into calendar 2020-06-08 03:24:26 +02:00
kpcyrd
e9cdc40821 Implement activity annotation with dummy data 2020-06-08 03:24:26 +02:00
kpcyrd
c4c7b420ce Implement calendar function 2020-06-08 03:24:26 +02:00
kpcyrd
3d304f13bc Bump dependencies 2020-06-08 03:21:22 +02:00
kpcyrd
6ee61c189e Merge pull request #174 from kpcyrd/cargo-deb
Add cargo-deb metadata
2020-06-08 03:19:17 +02:00
kpcyrd
5ad5666caf Merge pull request #173 from kpcyrd/docs
Update install instructions
2020-06-08 01:46:47 +02:00
kpcyrd
e057f8e6be Merge pull request #172 from kpcyrd/seccomp
Fix seccomp issue: clock_nanosleep
2020-06-08 01:45:31 +02:00
kpcyrd
baf44b4882 Add cargo-deb metadata 2020-06-08 01:43:51 +02:00
kpcyrd
f7fda8de4c Fix typo in sandbox docs 2020-06-07 23:59:39 +02:00
kpcyrd
43154cf841 Update install instructions 2020-06-07 23:59:39 +02:00
kpcyrd
49f082875d Update syscallz dependency 2020-06-07 23:13:48 +02:00
kpcyrd
1e575e0dbe Fix seccomp issue: clock_nanosleep 2020-06-07 23:13:48 +02:00
kpcyrd
d741020ff8 Merge pull request #168 from 0x646e78/fedora-install-notes
Add install details for Fedora/RH based systems
2020-06-06 14:33:11 +02:00
DNX
33dca47b38 Add install details for Fedora/RH based systems 2020-05-25 10:20:49 +10:00
kpcyrd
33bd4f9e94 Merge pull request #167 from kpcyrd/agent
Improve `pkg quickstart`, deprecate `mod`
2020-05-09 03:07:35 +02:00
kpcyrd
7a75a7a255 Prevent insertion of domains/subdomains with asterisks 2020-05-05 14:09:34 +02:00
kpcyrd
1c23995c86 Bump dependencies 2020-04-19 15:59:37 +02:00
kpcyrd
23ae7491e3 Make pkg quickstart skip already installed modules 2020-04-01 00:30:07 +02:00
kpcyrd
487578f974 Add deprecation notice for mod command 2020-03-31 23:44:03 +02:00
kpcyrd
4dec06843f Include os version into api useragent 2020-03-24 02:26:52 +01:00
kpcyrd
5f31289430 Release v0.18.2 2020-03-23 19:03:45 +01:00
kpcyrd
b519619324 Fix incomplete osx 10.13 dns bugfix 2020-03-23 19:01:15 +01:00
kpcyrd
5ff78297e4 Release v0.18.1 2020-03-23 15:52:32 +01:00
kpcyrd
c36e0e9a60 Bump dependencies 2020-03-23 15:40:57 +01:00
kpcyrd
6e5a41fa34 Merge pull request #164 from kpcyrd/count
Add select --count
2020-03-23 15:39:58 +01:00
kpcyrd
896e13373e Work around issue with ipv6 dns resolvers 2020-03-21 18:23:53 +01:00
kpcyrd
baeb200a1c Improve error messages 2020-03-20 21:52:09 +01:00
kpcyrd
6648a35f17 Add select --count 2020-03-20 21:52:09 +01:00
kpcyrd
62204e2f31 Merge pull request #162 from kpcyrd/travis
Fix misc issues
2020-03-16 01:50:00 +01:00
kpcyrd
98c1272874 Merge pull request #161 from kpcyrd/oauth
Use new github oauth endpoint
2020-03-16 01:18:13 +01:00
kpcyrd
27df923256 Use new github oauth endpoint 2020-03-16 00:13:35 +01:00
kpcyrd
872d279c49 Support patterns in pkg list 2020-03-15 15:39:41 +01:00
kpcyrd
b548446759 Fix display of netblocks in detailed view 2020-03-15 15:36:18 +01:00
kpcyrd
d5ec02b3d7 Include target triple in sn0int registry requests 2020-03-08 16:25:32 +01:00
kpcyrd
b60de4547f Update travis irc notifications 2020-03-08 15:13:44 +01:00
kpcyrd
7ab4cbd745 Release v0.18.0 2020-03-07 17:30:36 +01:00
kpcyrd
51fa7a02ae Merge pull request #160 from kpcyrd/url-none-bytes
Properly support inserting urls with no body
2020-03-07 16:26:21 +01:00
kpcyrd
39bcc40f55 Document new crypto functions 2020-03-07 15:34:19 +01:00
kpcyrd
38c16d62ee Document mqtt functions 2020-03-07 15:19:02 +01:00
kpcyrd
ecd843c74f docs: extract autonoscope section 2020-03-07 14:59:05 +01:00
kpcyrd
5611d54131 Switch docker container to alpine 2020-03-07 14:49:00 +01:00
kpcyrd
bd5aaaedcd Properly support inserting urls with no body 2020-03-07 03:40:16 +01:00
kpcyrd
c50b770b1e Merge pull request #159 from kpcyrd/mqtt
Add mqtt and libsodium functions
2020-03-05 19:50:45 +01:00
kpcyrd
80f794b521 Fully disable flaky mqtt test 2020-03-05 16:56:17 +01:00
kpcyrd
e22c346537 Allow more direct access to mqtt pkts 2020-03-05 15:51:20 +01:00
kpcyrd
eed2da40b4 Fix flaky test 2020-03-05 10:51:20 +01:00
kpcyrd
b5ba669d10 Do not error for read timeouts in sock_recvline 2020-03-05 03:06:27 +01:00
kpcyrd
832a2608f4 Support geoipupdate path 2020-03-05 03:03:30 +01:00
kpcyrd
ef4b3226ea Add libsodium on osx 2020-03-05 02:29:16 +01:00
kpcyrd
54f2e60695 Add binary support to http_request/http_send 2020-03-05 01:58:45 +01:00
kpcyrd
6f1125516c Add libsodium support for decryption 2020-03-03 16:34:06 +01:00
kpcyrd
76042da044 Add mqtt functions 2020-03-03 01:35:16 +01:00
kpcyrd
193d855f69 Suggest a smaller number of concurrency 2020-02-29 01:39:00 +01:00
kpcyrd
65f282ac4c Update install instructions on sn0int.com 2020-02-29 01:38:24 +01:00
kpcyrd
5fc97140f3 Point to online docs on first start 2020-02-29 01:36:38 +01:00
kpcyrd
0ce8b70f09 Replace quickstart with pkg quickstart 2020-02-29 01:31:01 +01:00
kpcyrd
b4fbca4e0d Merge pull request #158 from kpcyrd/update
Update dependencies
2020-02-28 17:39:05 +01:00
kpcyrd
621bd9304c Document strval and intval 2020-02-28 16:48:00 +01:00
kpcyrd
1ab5972f90 Add more advanced time references 2020-02-28 16:45:36 +01:00
kpcyrd
8aaa5bd167 Update pledge 2020-02-28 15:35:11 +01:00
kpcyrd
4c89888a67 Change update check interval 2020-02-28 15:32:44 +01:00
kpcyrd
fc4d076113 Update x509-parser 2020-02-23 23:37:40 +01:00
kpcyrd
798bd56e75 Release v0.17.1 2020-02-22 19:38:23 +01:00
kpcyrd
5359d1cb95 Merge pull request #157 from kpcyrd/sandbox
seccomp: whitelist ppoll instead of poll on aarch64
2020-02-22 19:34:17 +01:00
kpcyrd
ff7fe3936b Refactor ipc parent/child code 2020-02-22 18:28:33 +01:00
kpcyrd
d1d221f81e Improve child process logging 2020-02-22 17:46:36 +01:00
kpcyrd
e2acdf53a4 Downgrade from broken x509-parser release
https://github.com/rusticata/x509-parser/pull/27
2020-02-22 17:12:09 +01:00
kpcyrd
749d7efab5 Add sn0int run --dump-sandbox-init-msg for debugging 2020-02-22 16:52:36 +01:00
kpcyrd
d96a967fa9 Fix integration test 2020-02-22 16:04:35 +01:00
kpcyrd
3dddd0b041 Add exit and quit commands 2020-02-22 15:19:46 +01:00
kpcyrd
33f02bb832 seccomp: whitelist ppoll instead of poll on aarch64 2020-02-22 15:17:17 +01:00
kpcyrd
28a73e9399 Release v0.17.0 2020-02-20 23:59:30 +01:00
kpcyrd
040db1ecfe Merge pull request #155 from kpcyrd/str
Add two string functions, fix seccomp issue
2020-02-20 23:31:53 +01:00
kpcyrd
9212f5dbdd Add strval 2020-02-20 21:35:46 +01:00
kpcyrd
32c430c768 Merge pull request #156 from kpcyrd/db-activity
Return true if uniq activity event is already known
2020-02-20 21:05:24 +01:00
kpcyrd
f3d72cf482 Add missing documentation for db functions 2020-02-20 13:32:19 +01:00
kpcyrd
978df56ec4 Return true if uniq activity event is already known 2020-02-20 00:11:04 +01:00
kpcyrd
699695e20f Add additional labels to sn0int select output 2020-02-19 18:27:11 +01:00
kpcyrd
948a4a59cb Add subcommand to show sn0int filesystem paths 2020-02-16 20:49:45 +01:00
kpcyrd
dbb594d5da Add str_find and str_replace 2020-02-16 02:42:41 +01:00
kpcyrd
4f8a5da351 Fix seccomp: poll 2020-02-16 02:42:41 +01:00
kpcyrd
4d0d4fc992 Merge pull request #154 from kpcyrd/split
Split codebase into sn0int and sn0int-std
2020-02-16 02:42:03 +01:00
kpcyrd
31aa5cb6c0 travis: re-enable registry build 2020-02-16 01:10:11 +01:00
kpcyrd
a4c7894b9a Move sn0int-common location 2020-02-16 00:33:25 +01:00
kpcyrd
51fcffe1c3 Update dependencies 2020-02-16 00:33:25 +01:00
kpcyrd
1fc3b8aa86 Split into sn0int and sn0int-std 2020-02-16 00:33:25 +01:00
kpcyrd
c93f19c02a Merge pull request #153 from kpcyrd/geo
Add geo_polygon_contains
2020-02-04 06:48:23 +01:00
kpcyrd
2f7fbe199f Fix completions for pkg 2020-02-04 05:26:32 +01:00
kpcyrd
5f3361828b Add geo_polygon_contains 2020-02-03 20:19:14 +01:00
kpcyrd
910dd6f7c6 Rename Engine to Library 2020-02-03 20:19:14 +01:00
kpcyrd
f7819d87c0 Merge pull request #152 from kpcyrd/workspaces
Migrate to new workspace format
2020-02-03 20:18:16 +01:00
kpcyrd
52ce2f9d6e Migrate to new workspace format 2020-02-01 21:32:21 +01:00
kpcyrd
91c73f88f6 Merge pull request #151 from kpcyrd/pkg
sn0int pkg
2020-02-01 20:38:44 +01:00
kpcyrd
419293ec00 Do not init a shell for sn0int workspace 2020-02-01 18:21:28 +01:00
kpcyrd
361ea8a5d3 Add sn0int pkg subcommand 2020-02-01 17:40:30 +01:00
kpcyrd
e0074faaad Add new pkg command to replace mod 2020-02-01 17:18:44 +01:00
kpcyrd
12fcfbd6e8 Release v0.16.0 2020-01-30 04:16:17 +01:00
kpcyrd
ba82a880ed Rename ws_{read,write}_* to ws_{recv,send}_* 2020-01-30 04:11:39 +01:00
kpcyrd
87a3b0a683 Merge pull request #150 from kpcyrd/misc
Misc corrections
2020-01-28 03:02:10 +01:00
kpcyrd
48e0d4109a Add ipaddr to http responses 2020-01-28 01:24:50 +01:00
kpcyrd
eba4da0e77 Set PRAGMA synchronous = NORMAL 2020-01-24 21:11:24 +01:00
kpcyrd
d42d1fe3bc Merge pull request #149 from kpcyrd/websockets
Add websocket support
2020-01-24 03:29:13 +01:00
kpcyrd
e6fb92539a Document new websocket functions 2020-01-23 21:54:43 +01:00
kpcyrd
691a3b0350 Add read timeout support to websockets 2020-01-23 19:21:31 +01:00
kpcyrd
e45a0289e9 Allow updating read timeout of connections 2020-01-23 19:21:31 +01:00
kpcyrd
8adfb8f4a1 Show passwords when inserting new breach-email 2020-01-22 01:24:15 +01:00
kpcyrd
76a71e1121 Add ws_{read,write}_json shorthands 2020-01-20 04:40:41 +01:00
kpcyrd
95b43a7855 Add test module for tls functions 2020-01-20 04:06:58 +01:00
kpcyrd
84b7b1aade Improve websocket test scripts 2020-01-20 02:19:44 +01:00
kpcyrd
a11414b76c Improve error handling 2020-01-20 00:45:31 +01:00
kpcyrd
c80c7d3831 Add websocket support 2020-01-20 00:33:12 +01:00
kpcyrd
d0308e80c8 Release v0.15.0 2020-01-18 21:26:03 +01:00
kpcyrd
5183d1fea5 Merge pull request #148 from kpcyrd/repl-completion
Add tab completion to sn0int repl
2020-01-18 21:16:43 +01:00
kpcyrd
37a92566a1 Disable broken registry test due to rustc regression 2020-01-18 18:19:18 +01:00
kpcyrd
2755a6968c Fix typos in docs 2020-01-18 04:04:14 +01:00
kpcyrd
ebcbb0bf55 Add tab completion to sn0int repl 2020-01-17 02:57:22 +01:00
kpcyrd
d7e0282cea Merge pull request #147 from kpcyrd/activity
Add support for activity events
2020-01-16 23:33:22 +01:00
kpcyrd
9ad4177828 Document new activity interface 2020-01-16 03:42:14 +01:00
kpcyrd
d29f13830d Add radius to events 2020-01-16 02:26:49 +01:00
kpcyrd
af3e46da5a Create activity unique index over topic+uniq 2020-01-14 23:57:23 +01:00
kpcyrd
16054d4145 Allow fetching one previous event as initial state with --initial 2020-01-14 19:21:24 +01:00
kpcyrd
4d26c746ff Add option to query only events tied to a location 2020-01-14 18:11:19 +01:00
kpcyrd
dd9bc3c4fa Add missing activity indexes 2020-01-14 05:01:35 +01:00
kpcyrd
43c95a779e Add basic interface to query activity 2020-01-14 04:37:17 +01:00
kpcyrd
12dd58ba43 Add support for certs valid for emails 2020-01-14 02:49:53 +01:00
kpcyrd
6797187fc7 Add command to insert ports into database 2020-01-13 04:19:58 +01:00
kpcyrd
a3c5fb687e Add support for activity events 2020-01-13 04:19:58 +01:00
kpcyrd
aab8a52861 Merge pull request #145 from kpcyrd/ratelimits
Add ratelimit_throttle
2020-01-12 13:07:46 +01:00
kpcyrd
bb1feaf9a7 Add ratelimit_throttle 2020-01-07 03:39:56 +01:00
kpcyrd
f4a305ddd1 Merge pull request #146 from kpcyrd/geoip
Make geoip optional due to CCPA fallout
2020-01-07 03:33:02 +01:00
kpcyrd
0d96f66cf9 Make geoip optional due to CCPA fallout 2020-01-06 21:47:30 +01:00
kpcyrd
a75b28effa Merge pull request #142 from kpcyrd/prompts
Use readline for prompts
2020-01-04 15:49:48 +01:00
kpcyrd
1c147baafa Disable windows tests 2020-01-04 04:34:03 +01:00
kpcyrd
1073464923 Use readline for prompts 2020-01-04 04:34:03 +01:00
kpcyrd
038e082ca2 Update kamadak-exif 2020-01-04 04:02:23 +01:00
kpcyrd
aa296e2996 Fix netblock output 2020-01-03 23:44:13 +01:00
kpcyrd
ad700d0893 Release v0.14.0 2019-11-23 21:09:20 +01:00
kpcyrd
88da9ad0ad Merge pull request #141 from kpcyrd/misc
Misc fixes
2019-11-23 20:54:04 +01:00
kpcyrd
501387f402 Automatically clear redirect when publishing a new version 2019-11-21 17:12:12 +01:00
kpcyrd
3fdd49d138 Update registry dependencies 2019-11-21 16:07:53 +01:00
kpcyrd
2898fac7c5 Avoid conflict with modules folder and explicitly configured namespaces 2019-11-21 15:58:56 +01:00
kpcyrd
cc2eee254f Change cryptoaddr balance to BigInt 2019-11-21 15:58:16 +01:00
kpcyrd
98f0abf9fb Update dependencies 2019-11-21 15:57:58 +01:00
kpcyrd
ee14e4fb31 Merge pull request #140 from kpcyrd/redirects
Support module redirects
2019-11-21 15:14:31 +01:00
kpcyrd
b0a4651652 Add uninstall command 2019-11-21 06:04:23 +01:00
kpcyrd
a79cf5b9bf Support module redirects 2019-11-21 06:04:23 +01:00
kpcyrd
4af1f3462d Add redirect support to database 2019-11-21 06:04:23 +01:00
kpcyrd
36cd52fa7c Merge pull request #139 from kpcyrd/cryptoaddrs
Support cryptocurrency addresses
2019-11-21 06:04:09 +01:00
kpcyrd
d1e76f75d4 Add first_seen field 2019-11-20 20:01:19 +01:00
kpcyrd
11d8d783f4 Add 64 bit support for crypto currency balance 2019-11-20 19:56:55 +01:00
kpcyrd
3468d62710 Add intval function 2019-11-20 19:39:47 +01:00
kpcyrd
617e2e1e06 Support cryptocurrency addresses 2019-11-20 16:49:09 +01:00
kpcyrd
d8dc71a079 Merge pull request #138 from kpcyrd/add-urls
Add missing `add url` command
2019-11-18 03:22:06 +01:00
kpcyrd
f1c761b26f Add social preview to registry 2019-11-18 01:36:29 +01:00
kpcyrd
f3e794cc51 Automatically normalize redirects for urls 2019-11-17 17:14:18 +01:00
kpcyrd
3b037f0b7a Add missing add url command 2019-11-16 05:06:51 +01:00
kpcyrd
aa90f26136 Merge branch 'reg-html' 2019-11-11 03:47:31 +01:00
kpcyrd
7602e238c4 Fix registry docker image 2019-11-11 03:02:24 +01:00
kpcyrd
134c691984 Add details page 2019-10-29 19:27:04 +01:00
kpcyrd
9b5e0d90ad Add copy-to-clipboard button 2019-10-29 13:36:32 +01:00
kpcyrd
1b3401e355 Merge pull request #137 from kpcyrd/cli
Improve cli interface (add/run)
2019-10-27 03:19:57 +01:00
kpcyrd
cb04edc638 Add support for sn0int run -t 'where id=1' foo 2019-10-27 02:06:54 +01:00
kpcyrd
839ba732a0 Improve add account 2019-10-27 01:57:16 +02:00
kpcyrd
525b5c1deb Update dependencies 2019-10-27 01:56:56 +02:00
kpcyrd
0980cbfbb8 Create FUNDING.yml 2019-10-24 12:48:18 +02:00
kpcyrd
16233f7c84 Merge pull request #133 from kpcyrd/docs
Update scripting documentation
2019-09-29 10:16:56 +02:00
kpcyrd
b4888631b1 Document module repo template 2019-09-29 09:26:58 +02:00
kpcyrd
1da35e4e88 Move modules to github.com/kpcyrd/sn0int-modules 2019-09-29 09:12:33 +02:00
kpcyrd
ebd517b168 Merge pull request #132 from kpcyrd/export
Add export command
2019-09-29 08:31:58 +02:00
kpcyrd
f1ecdeb3bd Add export command 2019-09-29 05:01:02 +02:00
kpcyrd
50533f3acb Update scripting docs 2019-09-22 03:24:42 +02:00
kpcyrd
ebb5c53781 Merge pull request #130 from kpcyrd/misc
Add steam module and misc fixes
2019-09-20 20:06:30 +02:00
kpcyrd
3d22268e5a Add chefkoch module, rework date functions 2019-09-20 18:52:16 +02:00
kpcyrd
fe87c4d6e4 Add steam module 2019-09-20 18:49:29 +02:00
kpcyrd
399716e504 Fix warning 2019-09-20 18:49:18 +02:00
kpcyrd
2d45eda880 Bump dependencies 2019-09-20 11:36:57 +02:00
kpcyrd
42717e9c2e Merge pull request #129 from kpcyrd/onions
Allow modules to set a proxy
2019-09-20 11:36:30 +02:00
kpcyrd
41ff8f8c87 Merge pull request #127 from kpcyrd/repl
Add basic lua repl
2019-09-20 05:39:45 +02:00
kpcyrd
c2bf35fe44 Allow modules to set a proxy 2019-09-20 05:37:53 +02:00
kpcyrd
eb00849871 Merge pull request #128 from kpcyrd/pgp-fixes
Solve pgp issues
2019-09-15 17:53:38 +02:00
kpcyrd
9057fd666f Fix pgp uid decoding issue 2019-09-14 23:39:21 +02:00
kpcyrd
a89cefc48f Add stdin_read_to_end 2019-09-14 23:24:39 +02:00
kpcyrd
65eff0aca7 Refactor readline code 2019-09-13 07:03:25 +02:00
kpcyrd
d441bc9436 Add basic repl 2019-09-10 07:47:09 +02:00
kpcyrd
4d2f5532f1 Merge pull request #125 from kpcyrd/wip
Various modules
2019-09-09 01:30:08 +02:00
kpcyrd
3fd54053e3 Add clear_if_lower_or_equal logic 2019-09-08 23:28:44 +02:00
kpcyrd
c4dd03dcc5 Refactor twitch module 2019-09-08 23:05:18 +02:00
kpcyrd
1d69fbb9aa Add soundcloud module 2019-09-08 23:05:18 +02:00
kpcyrd
344e262104 Add virustotal module 2019-09-05 17:09:41 +02:00
kpcyrd
14d31b0311 Add very basic tiktok module 2019-09-02 01:39:17 +02:00
kpcyrd
678b36674b Update dependencies 2019-09-01 20:44:23 +02:00
kpcyrd
cce0a818aa Update modules 2019-08-28 12:21:13 +02:00
kpcyrd
c67b559dc4 Release v0.13.0 2019-08-26 14:46:30 +02:00
kpcyrd
dee17117bf Merge pull request #124 from kpcyrd/bugfixes
Bugfixes
2019-08-26 14:39:16 +02:00
kpcyrd
95bdc8d483 Reduce number of dns lookups in UpdateTask 2019-08-26 12:52:49 +02:00
kpcyrd
5f4a166974 Bump dependencies 2019-08-26 01:24:57 +02:00
kpcyrd
4ef80240cd Reduce number of dns lookups in InstallTask 2019-08-25 22:51:00 +02:00
kpcyrd
6214d3a7c7 More verbose update errors 2019-08-25 22:14:55 +02:00
kpcyrd
8f95ff2747 Fix Box<dyn _> warnings 2019-08-25 20:09:27 +02:00
kpcyrd
6c3f77581d Merge pull request #122 from kpcyrd/bugfixes
Various bugfixes
2019-08-12 09:17:11 +02:00
kpcyrd
b016d42641 Update dependencies 2019-08-12 07:34:15 +02:00
kpcyrd
64b3be68a0 Add misc fields 2019-08-11 10:17:38 +02:00
kpcyrd
d877c4346c Add pronunciation to readme 2019-08-10 19:47:52 +02:00
kpcyrd
d5a53a5468 Add autonoscope docs 2019-08-10 19:32:19 +02:00
kpcyrd
872d82d07d Automatically lowercase some fields 2019-08-10 16:17:38 +02:00
kpcyrd
e44196cf6f Add mx scripts 2019-08-09 19:06:35 +02:00
kpcyrd
f6237ffb1e Add twitter to README 2019-08-08 13:55:25 +02:00
kpcyrd
b6f383f122 Add tab completion for keyring 2019-08-08 13:52:07 +02:00
kpcyrd
5e0d0ff160 Merge pull request #120 from kpcyrd/bugfixes
Various bugfixes
2019-08-07 16:51:56 +02:00
kpcyrd
942b3e9d1b Add shodan-certs.lua 2019-08-07 11:38:17 +02:00
kpcyrd
b421e96ebb Add http_fetch 2019-08-07 10:45:00 +02:00
kpcyrd
341674d7ac Add telefonbuch-reverse.lua 2019-08-06 10:26:23 +02:00
kpcyrd
46d162de91 Add dasoertliche-reverse.lua 2019-08-06 10:05:56 +02:00
kpcyrd
1d831cb011 Refactor object family enums 2019-08-06 09:24:23 +02:00
kpcyrd
57e4c1d06f Update to nom 5 2019-08-06 05:54:14 +02:00
kpcyrd
8f70f50129 Update and install modules concurrently
Resolves #118
2019-07-29 06:27:47 +02:00
kpcyrd
4fa2f68cf9 Refactor outdated mechanism
Resolves #104
2019-07-28 07:35:04 +02:00
kpcyrd
fd9b1d6abb List modules with no source on registry index
Resolves #105
2019-07-28 06:50:33 +02:00
kpcyrd
d111cd0888 Merge pull request #107 from HerrSpace/360_no_scope
Add netblocks
2019-07-28 00:38:31 +02:00
kpcyrd
d9bbd6721f Add netblocks docs 2019-07-27 23:57:03 +02:00
kpcyrd
c249795c57 Add autonoscope support to netblocks 2019-07-27 23:45:31 +02:00
Patrick Meyer
77c6c69a11 Add netblock struct 2019-07-27 23:45:17 +02:00
kpcyrd
3674063594 Merge pull request #114 from kpcyrd/tls
Add tls support for sock_connect
2019-07-27 15:18:39 +02:00
kpcyrd
95f935a109 Add option to disable tls verification in sock_connect 2019-07-26 20:00:52 +02:00
kpcyrd
c8d0d0d610 Include certificates in tls data 2019-07-26 17:17:49 +02:00
kpcyrd
555f2074ae Update socket documentation with tls 2019-07-26 16:35:14 +02:00
kpcyrd
6c76559833 Add tls support for sock_connect 2019-07-26 16:27:36 +02:00
kpcyrd
9cb4af8176 Merge pull request #113 from kpcyrd/refactor
Refactor psl code
2019-07-25 17:52:28 +02:00
kpcyrd
e57b4d806a Add missing semver_match docs 2019-07-24 17:29:01 +02:00
kpcyrd
fb9ad06129 Add set_err function 2019-07-24 17:19:53 +02:00
kpcyrd
bae012afd7 Add http_fetch_json 2019-07-24 17:12:19 +02:00
kpcyrd
1bbe862eb8 Handle private domains on the public suffix list correctly 2019-07-23 19:06:34 +02:00
kpcyrd
6e432b3595 Update rocket_failure 2019-07-22 05:23:54 +02:00
kpcyrd
e5decd2210 Remove unused dependencies 2019-07-22 04:31:39 +02:00
kpcyrd
7b92149aa0 Merge pull request #111 from kpcyrd/lazy
Lazy load some files
2019-07-22 03:58:00 +02:00
kpcyrd
63f23af690 Update chaturbate module description 2019-07-22 03:01:24 +02:00
kpcyrd
fd6dec602e Add twitch module 2019-07-22 01:44:40 +02:00
kpcyrd
9150410124 Update dependencies 2019-07-22 01:32:21 +02:00
kpcyrd
f100c967c8 Fix autonoscope bug in add subdomain 2019-07-22 01:07:06 +02:00
kpcyrd
053f3ae19e Add forward/backward word navigation 2019-07-20 06:59:48 +02:00
kpcyrd
b30a1dc4fb Add chaturbate module 2019-07-18 07:10:54 +02:00
kpcyrd
5ed3913a37 Expose scope and noscope subcommands 2019-07-18 07:08:03 +02:00
kpcyrd
35784f426e Add venmo script 2019-07-16 07:57:16 +02:00
kpcyrd
eb102df4e1 Enforce specific alphabets for encoding functions 2019-07-16 07:55:20 +02:00
kpcyrd
5e970ac09c Add subdomain import script 2019-07-16 07:55:20 +02:00
kpcyrd
9fa2ac6939 Add base64 and base32 functions 2019-07-16 07:55:20 +02:00
kpcyrd
2a86d7f1d0 Update dependencies 2019-07-16 07:55:20 +02:00
kpcyrd
3d4dbf8bb9 Add wigle-ssid-location module 2019-07-16 07:55:20 +02:00
kpcyrd
abc7357feb Lazy load geoip/asndb from reader 2019-07-16 07:55:20 +02:00
kpcyrd
52107caeb6 Lazy load psl from reader 2019-07-16 07:55:20 +02:00
kpcyrd
52538cc913 Merge pull request #109 from kpcyrd/autonoscope
Implement autonoscope
2019-07-16 07:31:55 +02:00
kpcyrd
6606b2d922 Fix docker images 2019-07-16 06:17:07 +02:00
kpcyrd
222aad5c36 Fix "missing unscoped field" bug 2019-07-15 03:28:09 +02:00
kpcyrd
ed46d60b00 Automatically set autonoscope status at insert 2019-07-06 04:16:35 +02:00
kpcyrd
31c904dd13 Automatically overwrite autonoscope rules on conflict 2019-07-06 03:36:13 +02:00
kpcyrd
5665503526 Add autonoscope engine 2019-07-06 03:30:55 +02:00
kpcyrd
7277b3ea0a Update dependencies 2019-07-05 01:35:05 +02:00
kpcyrd
cb3fcc5dfd Merge pull request #106 from kpcyrd/search
Add additional module filter flags
2019-07-05 01:33:59 +02:00
kpcyrd
8e5e931130 Update install instructions 2019-07-02 06:06:20 +02:00
kpcyrd
7ffeb3d9c8 Add "build from source" documentation 2019-07-02 05:56:45 +02:00
kpcyrd
00977e0ff6 Add search --new to filter already installed modules 2019-06-30 21:39:26 +02:00
kpcyrd
2c348637e2 Add [installed] to mod search output 2019-06-30 21:30:42 +02:00
kpcyrd
90f06c1e5c Allow listing modules by input source 2019-06-30 21:06:13 +02:00
kpcyrd
6f65631c83 Add spyse subdomains module 2019-06-30 20:43:30 +02:00
kpcyrd
595ea363b2 Update modules 2019-06-23 17:46:44 +02:00
kpcyrd
53ca4c115e Add pgp-vks module 2019-06-23 17:10:29 +02:00
kpcyrd
763e0098f3 Merge pull request #103 from kpcyrd/pgp-sigs
Add pgp signature to pgp_pubkey result
2019-06-23 15:12:18 +02:00
kpcyrd
11e3e008fd Update pgp_pubkey_armored docs 2019-06-23 05:31:13 +02:00
kpcyrd
cac2644969 Return primary key fingerprint in pgp_pubkey 2019-06-23 05:28:32 +02:00
kpcyrd
c4bfb8e21b Deduplicate issuers and add test 2019-06-22 21:23:56 +02:00
kpcyrd
0c20b851b0 Add pgp signature to pgp_pubkey result 2019-06-22 21:10:56 +02:00
kpcyrd
bf9ad46c28 Merge pull request #101 from kpcyrd/windows-sqlite
Introduce sqlite-bundled feature for windows
2019-06-22 20:40:59 +02:00
kpcyrd
ad2ff10604 Update rustyline 2019-06-22 18:05:53 +02:00
kpcyrd
a8ba73ba14 Introduce sqlite-bundled feature for windows 2019-06-21 19:37:11 +02:00
kpcyrd
b64a956192 Release v0.12.0 2019-06-19 18:57:31 +02:00
kpcyrd
cd4d224a7b Simplify debian/ubuntu/kali install instructions 2019-06-18 12:15:59 +02:00
kpcyrd
e74198c1c9 Bump dependencies 2019-06-16 17:02:36 +02:00
kpcyrd
13335d91eb Merge pull request #100 from kpcyrd/ports
Add ports to database
2019-06-16 16:35:09 +02:00
kpcyrd
e369bf5c10 pgp-keyserver: lowercase all emails 2019-06-15 22:13:21 +02:00
kpcyrd
e2a6f9dab6 Add warn and warn_once 2019-06-09 14:50:32 +02:00
kpcyrd
5b6ef4c13a Merge pull request #99 from hovman/patch-1
Correcting typo
2019-06-09 12:04:39 +02:00
hovman
c7913faa10 Correcting typo 2019-06-09 01:37:24 -07:00
kpcyrd
9ed6cf8993 Fix bugs in pgp-keyserver.lua 2019-06-09 01:36:04 +02:00
kpcyrd
2b7026f8d5 Add protocol field to port model 2019-06-06 12:03:32 +02:00
kpcyrd
625dff3375 Deprecate family field in ipaddr 2019-06-06 11:24:40 +02:00
kpcyrd
119b9a0d27 Add command to insert ipaddr 2019-06-06 11:24:20 +02:00
kpcyrd
5467eba157 Update dependencies 2019-06-02 21:01:10 +02:00
kpcyrd
b34f750996 Merge pull request #98 from kpcyrd/seccomp
seccomp: whitelist membarrier
2019-06-02 15:41:48 +02:00
kpcyrd
b08358a872 seccomp: whitelist membarrier 2019-06-02 14:47:58 +02:00
kpcyrd
5898426ea4 Update detailed representation of ports 2019-05-31 16:06:30 +02:00
Georg Semmler
29867963a8 Fix models 2019-05-31 15:58:37 +02:00
kpcyrd
2ac0a6d3d4 Add ports to database 2019-05-31 13:02:00 +02:00
kpcyrd
4eed460cf9 Merge pull request #96 from kpcyrd/registry
List uploaded modules on the registry website
2019-05-30 16:18:58 +02:00
kpcyrd
b3777cabdb List uploaded modules on the registry website 2019-05-28 05:45:58 +02:00
kpcyrd
470fce422f Merge pull request #95 from kpcyrd/hmac
Add hmac, strftime/strptime, xml_decode
2019-05-28 05:12:17 +02:00
kpcyrd
2af6d1d9da Add workspace --delete 2019-05-27 13:34:01 +02:00
kpcyrd
6eec3278e0 Bump dependencies 2019-05-27 03:43:22 +02:00
kpcyrd
76bc93d73b Add a function to get a named xml element 2019-05-24 17:18:21 +02:00
kpcyrd
366f864317 Replace xml parser 2019-05-24 07:45:19 +02:00
kpcyrd
cd1026560d Merge pull request #90 from kpcyrd/lto
Reenable lto
2019-05-23 07:36:31 +02:00
kpcyrd
3e4a72c484 Add xml parser 2019-05-23 07:34:37 +02:00
kpcyrd
b170145b03 Add strftime/strptime 2019-05-23 06:49:03 +02:00
kpcyrd
dc3f0f7cd0 Add hmac functions 2019-05-23 05:49:32 +02:00
kpcyrd
e177a8c029 seccomp: whitelist gettimeofday 2019-05-23 04:26:11 +02:00
kpcyrd
a5c4a07114 Add cve-2014-8244.lua for linksys JNAP 2019-05-18 11:03:16 +02:00
kpcyrd
37b1d0e067 Release v0.11.2 2019-05-13 06:33:11 +02:00
kpcyrd
056499fb64 Merge pull request #92 from kpcyrd/current_exe
Fix current_exe path issue on openbsd
2019-05-13 06:11:24 +02:00
kpcyrd
231eba3a37 Update nude-rs dependency 2019-05-13 05:23:13 +02:00
kpcyrd
c205df63a8 Fix current_exe path issue on openbsd 2019-05-13 04:58:26 +02:00
kpcyrd
9a12ea8e6a Update dependencies and remove workspace workaround 2019-05-13 04:51:18 +02:00
kpcyrd
c81fdde5f9 Add new dns modules 2019-04-30 15:32:48 +02:00
kpcyrd
0dcf5f4d28 Update openbsd install instructions 2019-04-26 09:13:08 +02:00
kpcyrd
2dfef8d9a3 Release v0.11.1 2019-04-25 17:23:52 +02:00
kpcyrd
3810b7c87e Merge pull request #91 from kpcyrd/openbsd
Fix build for openbsd
2019-04-25 17:11:18 +02:00
kpcyrd
da85aa2eb3 Unveil /dev/urandom 2019-04-25 08:14:00 +02:00
kpcyrd
ea70815589 Fix build for openbsd 2019-04-25 07:37:09 +02:00
kpcyrd
16a233ebdf Reenable lto 2019-04-24 18:09:10 +02:00
kpcyrd
3c2386ff48 Revert rocket workaround again
https://github.com/SergioBenitez/Rocket/issues/905
2019-04-24 13:47:39 +02:00
kpcyrd
1068fccf0f Bump module versions 2019-04-24 13:42:54 +02:00
kpcyrd
eb885b06ab Release v0.11.0 2019-04-22 03:10:17 +02:00
kpcyrd
8e2b430396 Update readme text 2019-04-22 02:45:30 +02:00
kpcyrd
d3bd38ce6e Bump dependencies 2019-04-22 02:28:40 +02:00
kpcyrd
e9f7cd667f Document into_blob 2019-04-22 02:10:56 +02:00
kpcyrd
cb86f21a95 Merge remote-tracking branch 'origin/docs' 2019-04-22 00:14:27 +02:00
kpcyrd
eb7f38b9ed Update docs 2019-04-17 19:19:32 +02:00
kpcyrd
7c50200e7e Merge pull request #86 from kpcyrd/imgs
Add image forensics support
2019-04-16 13:48:41 +02:00
kpcyrd
d77800b6fd Docker: Switch back to debian 2019-04-16 12:05:02 +02:00
kpcyrd
e3be152a98 Add --paths flag to select command 2019-04-15 17:12:02 +02:00
kpcyrd
c8ccfa0cfc Change padding direction 2019-04-15 16:08:20 +02:00
kpcyrd
724bcdc344 Use nude-rs from crates.io 2019-04-15 15:39:46 +02:00
kpcyrd
0e9bcaf82e Pad blob ids to uniform length 2019-04-15 01:15:42 +02:00
kpcyrd
1e6ee04a36 Use base58 instead of hex for blobs 2019-04-14 18:54:31 +02:00
kpcyrd
5df39f758e Add img_load and img_nudity 2019-04-14 17:39:28 +02:00
kpcyrd
72bdc83fd3 Update dependencies 2019-04-14 15:46:10 +02:00
kpcyrd
657dc35fda Bump dependencies 2019-04-03 17:10:05 +02:00
kpcyrd
90ea945f79 Add gpg importer to github module
Shout out to @anthraxx for the hint
2019-04-03 17:09:29 +02:00
kpcyrd
0f7ad254ec Add endpoint for badges 2019-03-25 16:16:32 +01:00
kpcyrd
96e539fdbc Fix update terminal output 2019-03-25 10:43:30 +01:00
kpcyrd
2ef48dd830 Add more badges 2019-03-25 10:32:24 +01:00
kpcyrd
a5c92a5e3a Clear outdated counter after successful update 2019-03-25 08:03:51 +01:00
kpcyrd
f4f785f888 Add a name field to emails 2019-03-25 07:37:00 +01:00
kpcyrd
1904133294 Refactor script for-loops 2019-03-24 20:41:09 +01:00
kpcyrd
e3f4d1f837 Add image downloader to instagram module 2019-03-24 11:21:27 +01:00
kpcyrd
703d1814d0 Add cryptographic hash functions 2019-03-18 07:31:28 +01:00
kpcyrd
dd26c49739 Add fsck subcommand 2019-03-18 03:09:20 +01:00
kpcyrd
62d1b9aa06 Add image decoder 2019-03-18 01:50:27 +01:00
kpcyrd
c033f08e64 Support importing images from disk 2019-03-17 06:50:31 +01:00
kpcyrd
d11e7bb009 Restructure argument handling 2019-03-17 05:45:24 +01:00
kpcyrd
c42783c338 Refactor struct enums 2019-03-17 01:51:01 +01:00
kpcyrd
3a787f647b Add exif parser 2019-03-17 01:30:27 +01:00
kpcyrd
c88801af82 Add home assistant script 2019-03-12 16:58:47 +01:00
kpcyrd
7abde1374d Send blobs to child process 2019-03-12 16:05:52 +01:00
kpcyrd
e715a7d7c1 Add blob storage 2019-03-12 15:42:47 +01:00
kpcyrd
812a2f4d27 Add image model to database 2019-03-08 19:02:36 +01:00
kpcyrd
8025418e2f Document config file locations 2019-03-08 06:11:49 +01:00
kpcyrd
edff6eda43 Add keybase modules 2019-03-05 14:16:11 +01:00
kpcyrd
bdd46eb9be Fix docker-registry build 2019-03-04 18:41:58 +01:00
kpcyrd
c4d0cfd0d7 Improve sn0int run interface 2019-03-04 07:17:08 +01:00
kpcyrd
30f848bcf7 Merge pull request #81 from kpcyrd/registry
Registry and update improvements
2019-03-03 05:17:00 +01:00
kpcyrd
66c2007a16 Allow setting private modules in the config file 2019-03-03 04:13:54 +01:00
kpcyrd
ee691942f4 Try detecting private modules and skip update 2019-03-03 00:41:38 +01:00
kpcyrd
7bc4dc4c6a Automatically check for new modules 2019-03-02 16:23:58 +01:00
kpcyrd
e9a4323f52 Add endpoint to query latest publish 2019-03-02 16:16:49 +01:00
kpcyrd
f54b4d8c99 Add health endpoint to registry 2019-03-01 04:55:00 +01:00
kpcyrd
8951147b9a Release v0.10.0 2019-02-28 17:20:24 +01:00
kpcyrd
2886596893 Add tests for json functions 2019-02-28 16:29:00 +01:00
kpcyrd
e896e11d7c Add ddwrt script 2019-02-28 16:29:00 +01:00
kpcyrd
cbb6a87ca2 Merge pull request #80 from kpcyrd/ring
Bump ring for aarch64 support
2019-02-28 16:26:10 +01:00
kpcyrd
09e1514391 Bump ring 2019-02-27 18:10:46 +01:00
kpcyrd
8a6f8aaca0 Merge pull request #79 from kpcyrd/docs
Document structs
2019-02-27 16:36:01 +01:00
kpcyrd
a22caa4ef4 Skip lto to avoid compiler bug 2019-02-27 14:40:19 +01:00
kpcyrd
e3a84dfe89 Document structs 2019-02-24 20:50:03 +01:00
kpcyrd
b938d9c7f5 Refactor structs 2019-02-24 17:08:18 +01:00
kpcyrd
454a769f84 Merge pull request #78 from kpcyrd/breaches
Add breaches
2019-02-23 22:03:29 +01:00
kpcyrd
8150ad9483 Support multiple passwords per breach
Also update password-less links to a breach if we insert a 2nd link that
contains a password between the same breach and email.
2019-02-21 16:22:09 +01:00
kpcyrd
b9fddedbb5 Fix <= and >= in db queries 2019-02-19 16:58:54 +01:00
kpcyrd
b48c8728fd Add breaches to database 2019-02-19 16:43:36 +01:00
kpcyrd
af9087b80b Merge pull request #75 from kpcyrd/accounts
Add accounts
2019-02-19 16:30:10 +01:00
kpcyrd
b8b535c19a Disable docker test because of max build time 2019-02-15 18:39:10 +01:00
kpcyrd
344d28ec56 Add function to test sn0int semver 2019-02-15 14:29:07 +01:00
kpcyrd
30d3c1ac56 Set useragent for api client correctly 2019-02-15 14:24:14 +01:00
kpcyrd
0748297a42 Improve namechk error handling 2019-02-15 14:20:06 +01:00
kpcyrd
e9d9e9925a Add first attempt on namechk script 2019-02-14 17:14:36 +01:00
kpcyrd
c0c2c31b65 Add displayname field 2019-02-14 16:07:39 +01:00
kpcyrd
17f4682476 Add accounts to database 2019-02-12 16:38:07 +01:00
kpcyrd
4ce8f00ad8 Add additional context to download failures 2019-02-12 15:13:06 +01:00
kpcyrd
e5a9f4cfba Document optional dependencies on debian 2019-02-12 15:01:12 +01:00
kpcyrd
fcc6509a69 Make unknown script metadata non-fatal 2019-02-10 07:00:23 +01:00
kpcyrd
14339dea2f Fix mremap seccomp filter 2019-02-09 19:00:44 +01:00
kpcyrd
c849c57435 Release v0.9.1 2019-02-03 03:46:28 +01:00
kpcyrd
e4254bec17 Update docs 2019-02-03 03:45:23 +01:00
kpcyrd
980e6b55f4 Merge pull request #71 from kpcyrd/seccomp-i686
Adjust sandbox for i686
2019-02-03 03:43:08 +01:00
kpcyrd
2712bdaeea Update boxxy commands 2019-02-02 23:37:47 +01:00
kpcyrd
c0a63b0620 Don't kill the process at open, return error 2019-02-02 22:49:21 +01:00
kpcyrd
12754d1c7a Add integration test script 2019-02-02 16:57:39 +01:00
kpcyrd
0ae36e4976 Adjust sandbox for i686 2019-02-02 15:33:42 +01:00
kpcyrd
2972aa2480 Whitelist missing writev and readv syscalls 2019-01-31 23:59:31 +01:00
kpcyrd
874b317c95 Fix broken rst links 2019-01-31 17:24:07 +01:00
kpcyrd
ca66674f33 Split install instructions into debian and ubuntu 2019-01-31 17:19:24 +01:00
kpcyrd
6c81fe72b0 Add github issue template 2019-01-30 23:34:57 +01:00
kpcyrd
89402fe6e8 Bump module versions 2019-01-30 22:32:19 +01:00
kpcyrd
745cd01419 Update osx install instructions 2019-01-30 22:12:13 +01:00
kpcyrd
e3105165e0 Release v0.9.0 2019-01-29 02:40:32 +01:00
kpcyrd
a37fc3e0b3 Merge pull request #67 from kpcyrd/bump
Bump dependencies
2019-01-29 02:36:24 +01:00
kpcyrd
cbb8ca675e Fix cargo install instructions 2019-01-29 01:11:17 +01:00
kpcyrd
7f622a8c24 Bump dependencies 2019-01-29 01:11:02 +01:00
kpcyrd
b9d990caae Merge pull request #63 from kpcyrd/datetime
Add datetime function
2019-01-28 02:33:43 +01:00
kpcyrd
6856f3333f Fix datetime format for deserialize 2019-01-28 01:04:14 +01:00
kpcyrd
653651555f Add function to get current datetime 2019-01-23 21:09:39 +01:00
kpcyrd
d973bcc796 Merge pull request #62 from kpcyrd/db-add-ttl
Add db_add_ttl function
2019-01-21 20:50:30 +01:00
kpcyrd
d772d82d57 Relax workspace name rules 2019-01-21 19:57:57 +01:00
kpcyrd
0d722837db Workaround travis-cache inactitiy bug 2019-01-21 14:11:19 +01:00
kpcyrd
8695d4490d Enable Write-Ahead logging to resolve locking issue 2019-01-21 14:09:52 +01:00
kpcyrd
3b7b78ed4d Automatically clear expired entities from db 2019-01-21 08:11:20 +01:00
kpcyrd
c6ac0ede23 Update dependencies 2019-01-21 07:28:57 +01:00
kpcyrd
bfb06499c9 Add function to add to db with ttl until expiry 2019-01-21 01:07:51 +01:00
kpcyrd
9a8830fa53 Add passive arp scanner 2019-01-19 15:46:04 +01:00
kpcyrd
f00c1250f1 Merge branch 'sockets' 2019-01-19 15:38:04 +01:00
kpcyrd
9247d0fded Add module thunderbird-autoconfig 2019-01-19 03:06:11 +01:00
kpcyrd
83ad8c355f Add well-known urls scanner 2019-01-19 02:53:08 +01:00
kpcyrd
98bfee2778 Merge pull request #61 from kpcyrd/json
Add json output for select
2019-01-19 02:50:57 +01:00
kpcyrd
dd0966883d Don't display progress indicator in some cases 2019-01-19 01:11:10 +01:00
kpcyrd
3b9fe5ba6c Add json option to select 2019-01-19 00:28:18 +01:00
kpcyrd
8f38f80ac6 Document sock_* functions 2019-01-18 02:53:51 +01:00
kpcyrd
df7c3b69f4 Add subcommand to create new module 2019-01-18 02:44:46 +01:00
kpcyrd
cf7eb20d95 Use socks5 if set and automatically resolve dns 2019-01-17 18:21:08 +01:00
kpcyrd
8a4b8be0e7 Add socket functions and smtp-check script 2019-01-16 22:17:53 +01:00
kpcyrd
b97aeda086 Improve sn0int publish output 2019-01-14 18:19:21 +01:00
kpcyrd
064b3d7c01 Bump module versions 2019-01-13 01:29:23 +01:00
kpcyrd
3d2f80c9bb Update install instruction link 2019-01-13 01:23:25 +01:00
kpcyrd
686e1e5119 Release v0.8.1 2019-01-13 01:04:03 +01:00
kpcyrd
913e9a9f4f Update feature list format 2019-01-13 01:02:55 +01:00
kpcyrd
7a1cf34646 Update readme table of contents 2019-01-12 11:42:49 +01:00
kpcyrd
ed5e913275 Merge pull request #58 from kpcyrd/dns-cache
Add a dns-cache
2019-01-12 11:37:52 +01:00
kpcyrd
be2e859efd Merge some examples 2019-01-12 09:58:30 +01:00
kpcyrd
ef711c4fae Bump dependencies 2019-01-12 09:30:50 +01:00
kpcyrd
e8a8072349 Travis: skip sqlite install on osx 2019-01-12 08:58:32 +01:00
kpcyrd
592d697888 Remove some unused code 2019-01-12 05:04:11 +01:00
kpcyrd
f8807b7a60 Use chrootable-https dns cache 2019-01-12 04:35:05 +01:00
kpcyrd
40b97d74b4 Fix san extension parser bug 2019-01-10 21:08:54 +01:00
kpcyrd
4b8cc88871 Document sandbox 2019-01-10 08:04:34 +01:00
kpcyrd
3136ed522e Update module versions 2019-01-10 01:07:09 +01:00
kpcyrd
5cb3460ef4 Release v0.8.0 2019-01-07 03:28:39 +01:00
kpcyrd
bfe589e5a0 Use x509 parser in ctlogs module 2019-01-07 02:41:30 +01:00
kpcyrd
a29d3b1739 Use alpine dockerfile again 2019-01-07 01:16:34 +01:00
kpcyrd
f01f299e02 Connect iwdump module to database 2019-01-06 21:33:46 +01:00
kpcyrd
b0f25110a3 Expose select to non-interactive mode 2019-01-06 21:24:00 +01:00
kpcyrd
494e503d84 Add CONTRIBUTING.md 2019-01-06 18:36:05 +01:00
kpcyrd
27608f9bdd Suggest running help on unknown command 2019-01-06 16:37:28 +01:00
kpcyrd
b429355a46 Add git webroot scanner 2019-01-06 16:32:42 +01:00
kpcyrd
0b9474fdbd Link to webirc 2019-01-04 01:30:26 +01:00
kpcyrd
97ea7daef8 Connect dhcpd parser to database 2019-01-02 04:18:00 +01:00
kpcyrd
a39c901b2f Merge pull request #57 from kpcyrd/options
Introduce an option system
2019-01-01 22:30:17 +01:00
kpcyrd
8ccccea367 Introduce an option system 2019-01-01 20:25:54 +01:00
kpcyrd
5df4f180e5 Add dhcpd and iw station dump parser 2019-01-01 06:43:59 +01:00
kpcyrd
b49d97e55c Merge pull request #53 from kpcyrd/networks
Add networks and devices
2019-01-01 05:52:49 +01:00
kpcyrd
570c6b4225 Generate readme toc from docs/ 2019-01-01 02:27:07 +01:00
kpcyrd
6fbebd8544 Document proxy config 2019-01-01 01:57:13 +01:00
kpcyrd
86c2b91c73 Exclude unneeded open syscall 2019-01-01 01:38:51 +01:00
kpcyrd
db2203b286 Merge pull request #56 from kpcyrd/socks5
Add socks5 support
2019-01-01 01:37:02 +01:00
kpcyrd
1772d8b9e3 Fix docker hub 2018-12-31 18:20:33 +01:00
kpcyrd
9814167212 Add docker usage instructions 2018-12-31 04:01:29 +01:00
kpcyrd
5b039fe0eb Add socks5 support 2018-12-31 03:49:50 +01:00
kpcyrd
9d414da7d4 Merge pull request #54 from kpcyrd/selftest
Add features to support selftest
2018-12-31 03:44:55 +01:00
kpcyrd
b828f2d6f0 Update description 2018-12-29 16:11:34 +01:00
kpcyrd
06ae0958ec Introduce help command
Resolve #55
2018-12-28 05:00:45 +01:00
kpcyrd
2747e5a1c5 Add table of contents to readme 2018-12-28 04:14:44 +01:00
kpcyrd
6e210acc90 Add features to support selftest 2018-12-26 14:37:18 +01:00
kpcyrd
653b1bd340 Add ipaddr to device table 2018-12-26 00:19:26 +01:00
kpcyrd
0b719b832c Add devices and networks 2018-12-25 14:55:11 +01:00
kpcyrd
7dcb950899 Add ieee iab and oui to repo 2018-12-25 13:10:48 +01:00
kpcyrd
41e8b4f047 Release v0.7.0 2018-12-24 02:43:39 +01:00
kpcyrd
145b6dfa9a Add reverse dns and description for ips 2018-12-24 01:14:02 +01:00
kpcyrd
5368ef3e52 Allow keyring as source argument 2018-12-23 23:44:48 +01:00
kpcyrd
a95ba52e97 Add phpmyadmin url bruteforce 2018-12-23 19:45:55 +01:00
kpcyrd
e578b4eea7 Merge pull request #50 from kpcyrd/phone
Support phonenumbers
2018-12-23 19:41:06 +01:00
kpcyrd
b9e920d890 Fix tests 2018-12-23 18:41:19 +01:00
kpcyrd
765a9d161c Refactor entity formatting 2018-12-23 17:17:25 +01:00
kpcyrd
fcd8867a15 clippy fixes 2018-12-23 17:17:25 +01:00
kpcyrd
0928ea12c6 Ask the user to grant access to credentials 2018-12-23 17:17:25 +01:00
kpcyrd
641f46892b Connect keyring to modules 2018-12-23 17:17:25 +01:00
kpcyrd
776d02e8cc Automatically encode input in log functions 2018-12-23 17:17:25 +01:00
kpcyrd
0db0dd263e Add twilio lookup prototype 2018-12-23 17:17:25 +01:00
kpcyrd
73ac953ee4 Rename and document accesskey command to keyring 2018-12-23 17:17:25 +01:00
kpcyrd
3b4381cf3b Add accesskey manager 2018-12-23 17:17:25 +01:00
kpcyrd
3c853b83d4 Add more fields to phonenumber table 2018-12-23 17:17:25 +01:00
kpcyrd
93d6fb12a7 Add phonenumbers to database 2018-12-23 17:17:25 +01:00
kpcyrd
2f4fa798c1 Refactor module loader 2018-12-21 03:07:09 +01:00
kpcyrd
426ec77eb3 Remove obsolete update command 2018-12-21 02:49:35 +01:00
kpcyrd
40efb237d7 Replace dockerfile with debian for now 2018-12-20 23:42:10 +01:00
kpcyrd
ffc8ce6a3c Bump some module versions 2018-12-20 20:43:33 +01:00
kpcyrd
8f16948443 Merge pull request #49 from kpcyrd/async-chrootable
Port to async chrootable-https
2018-12-12 01:59:02 +01:00
kpcyrd
3a84395551 Port to async chrootable-https 2018-12-12 00:25:40 +01:00
kpcyrd
d8923f4b46 Bump dependencies 2018-12-10 14:53:47 +01:00
kpcyrd
699c242136 Merge pull request #48 from kpcyrd/rocket-4
Port to rocket 0.4
2018-12-10 14:50:51 +01:00
kpcyrd
347da4825c Remove custom_derive feature 2018-12-10 03:43:43 +01:00
kpcyrd
55cba1e04d Improve error messages 2018-12-10 02:08:55 +01:00
kpcyrd
f6559668c2 Improve error handling 2018-12-10 02:08:55 +01:00
kpcyrd
b42323d63c Move cache-control headers to registry code 2018-12-10 02:08:55 +01:00
kpcyrd
e3ee1a7f20 Move security headers to registry code 2018-12-10 02:08:55 +01:00
kpcyrd
75c888c473 Port to latest rocket version 2018-12-10 02:08:55 +01:00
kpcyrd
5735af29b2 Merge pull request #47 from kpcyrd/2018
Port to rust 2018 edition
2018-12-10 02:07:05 +01:00
kpcyrd
212aa9601e Port sn0int-registry to 2018 edition 2018-12-09 15:27:42 +01:00
kpcyrd
5582892763 Port sn0int-common to 2018 edition 2018-12-09 15:19:27 +01:00
kpcyrd
7b91e6f872 Port to 2018 edition 2018-12-09 15:17:50 +01:00
kpcyrd
d77b2b39e0 cargo fix --edition 2018-12-09 15:17:50 +01:00
kpcyrd
22aaf3c0b1 Release v0.6.0 2018-12-08 22:04:29 +01:00
kpcyrd
1099b061bb Merge pull request #46 from kpcyrd/stdin
Allow reading from stdin in scripts
2018-12-08 21:59:09 +01:00
kpcyrd
795688ecc9 Add poc arp-scan parser 2018-12-07 18:13:52 +01:00
kpcyrd
aafa53c66b Document stdin_readline 2018-12-07 18:13:32 +01:00
kpcyrd
316b0e1cd2 Allow reading from stdin in scripts 2018-12-07 18:00:55 +01:00
kpcyrd
f6bc1b2c08 Add asciicast to readme 2018-12-06 04:09:48 +01:00
kpcyrd
93c6c45e28 Bypass a regression in sqlite 2018-12-06 03:49:12 +01:00
kpcyrd
facd5290e0 Report publish as successful if code didn't change 2018-12-05 17:16:36 +01:00
kpcyrd
72354066b0 Merge pull request #44 from kpcyrd/automatic-fields
Introduce automatic fields based on other fields
2018-12-04 02:07:19 +01:00
kpcyrd
41270f6611 Introduce automatic fields based on other fields 2018-12-04 00:52:16 +01:00
kpcyrd
52db46c340 Adjust sandbox for arm 2018-12-03 04:25:50 +01:00
kpcyrd
a1fb2932e2 Refactor detailed output to trait 2018-12-03 04:22:16 +01:00
kpcyrd
39c1e9b8c6 List subdomains when listing domains 2018-12-02 19:00:19 +01:00
kpcyrd
9ffdbef805 Bump dependencies 2018-12-02 15:04:20 +01:00
kpcyrd
c80f2a1ed2 Merge pull request #40 from kpcyrd/axfr
Refactor dns function to support axfr
2018-12-02 15:02:26 +01:00
kpcyrd
3b83fc0075 Improve ResolveOptions processing 2018-11-30 04:55:21 +01:00
kpcyrd
891e7a1ec5 Introduce debug output and verbose runs 2018-11-30 01:43:04 +01:00
kpcyrd
4c61df7638 Fix more script regressions 2018-11-30 01:02:53 +01:00
kpcyrd
ccf32813fd Change zero indexing to proper lua indexing 2018-11-29 02:46:06 +01:00
kpcyrd
ff3295f08e Add axfr module 2018-11-29 02:29:09 +01:00
kpcyrd
d0e3ff0a0f Update docs and scripts to new dns function 2018-11-29 00:21:32 +01:00
kpcyrd
4b3fc76f0c Refactor dns function to support axfr 2018-11-28 18:04:52 +01:00
kpcyrd
a9d092cede Release v0.5.2 2018-11-26 23:03:50 +01:00
kpcyrd
56b914be88 Add cname harvester 2018-11-26 22:28:09 +01:00
kpcyrd
d495fc4d19 psl: use correct list path 2018-11-26 22:23:48 +01:00
kpcyrd
1618f777d7 Update archlinux install instructions 2018-11-22 23:35:02 +01:00
kpcyrd
cb97809ca1 Release v0.5.1 2018-11-22 20:54:41 +01:00
kpcyrd
4c8b14a788 Merge pull request #37 from kpcyrd/skip-dl
Skip download on archlinux if desired packages are installed
2018-11-22 20:49:41 +01:00
kpcyrd
bda14a9a7b Use publicsuffix-list on archlinux 2018-11-22 18:23:59 +01:00
kpcyrd
53b37120f8 Use geoip2-database on archlinux 2018-11-22 18:14:35 +01:00
kpcyrd
3860d752f9 Update description 2018-11-22 17:59:31 +01:00
kpcyrd
00ec57ac24 Merge pull request #36 from stoeckmann/typo
Fixed typos.
2018-11-21 22:52:53 +01:00
Tobias Stoeckmann
068462c2aa One more typo occurrence.
As spotted and requested by kpcyrd, fixed this one as well.

Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
2018-11-21 22:10:52 +01:00
Tobias Stoeckmann
73f4fc0bb4 Fixed typos.
Just a typo in it's vs its in two places.

Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
2018-11-21 22:02:14 +01:00
kpcyrd
ce1d1b3652 Add docs badge 2018-11-20 17:29:46 +01:00
kpcyrd
2acdea73f1 Release v0.5.0 2018-11-20 17:19:06 +01:00
kpcyrd
fe2dae484e Merge pull request #34 from kpcyrd/docs
Add docs
2018-11-20 17:03:05 +01:00
kpcyrd
9cf37f3d5f Add function reference 2018-11-20 15:49:53 +01:00
kpcyrd
c513c06a85 Enforce valid workspace names 2018-11-19 19:19:29 +01:00
kpcyrd
af0244b9f7 Link to irc channel 2018-11-19 12:49:07 +01:00
kpcyrd
71cad5045b Update output in usage.rst 2018-11-19 12:23:53 +01:00
kpcyrd
90e3986815 docs: Explain scripting 2018-11-19 11:40:11 +01:00
kpcyrd
772cd79612 Add database docs 2018-11-18 12:00:51 +01:00
kpcyrd
4dbd84d196 Add usage instructions 2018-11-18 12:00:51 +01:00
kpcyrd
2fc28900c4 Add readthedocs files 2018-11-18 12:00:41 +01:00
kpcyrd
bf481757b7 threatminer-ipaddr: Don't error on unscoped domains 2018-11-18 10:29:27 +01:00
kpcyrd
638eb0e436 Flesh out workspace command and add completion 2018-11-18 10:29:01 +01:00
kpcyrd
bf2a4afb19 Merge pull request #32 from kpcyrd/x509
Add x509_parse_pem
2018-11-18 10:26:51 +01:00
kpcyrd
23331bdad8 Improve processing of certs with ipaddrs 2018-11-18 10:09:26 +01:00
kpcyrd
7bc7030e5c Accept ip addresses in san extension parser 2018-11-18 08:33:45 +01:00
kpcyrd
90b0c1c3eb Add x509_parse_pem to lua engine 2018-11-16 19:17:03 +01:00
kpcyrd
70624e7a79 Add certificate parser 2018-11-16 18:30:56 +01:00
kpcyrd
4313f6d102 db_add returns nil if entity is out of scope 2018-11-16 14:37:31 +01:00
kpcyrd
813f0b0457 travis: send notifications to irc 2018-11-16 11:01:57 +01:00
kpcyrd
adc49c3238 Mute error! calls by default 2018-11-16 10:27:47 +01:00
kpcyrd
f89c1bae9e Don't send psl through stdio 2018-11-15 11:10:27 +01:00
kpcyrd
50af0057aa Merge pull request #30 from kpcyrd/threaded
Add multi threading
2018-11-15 01:36:48 +01:00
kpcyrd
a6db483479 Allow adjusting threads 2018-11-14 20:38:51 +01:00
kpcyrd
97f2ac0ae8 Prefix log lines with entity 2018-11-14 13:33:35 +01:00
kpcyrd
0dd2fd08b8 Fix infinite hang if target list is empty 2018-11-14 12:57:04 +01:00
kpcyrd
d871fbafb2 Add multi threading 2018-11-14 09:20:16 +01:00
kpcyrd
d2a2e22ef4 Reduce event loop complexity 2018-11-14 09:20:16 +01:00
kpcyrd
70275885fe Simplify event channels 2018-11-14 09:20:16 +01:00
kpcyrd
9b4dfb0f62 Cleanly remove spinners from stacked spinners 2018-11-14 09:20:16 +01:00
kpcyrd
b0800939a1 Add stacked spinners 2018-11-14 09:20:09 +01:00
kpcyrd
b9aa341e98 Make passive spider more intelligent 2018-11-13 20:10:44 +01:00
kpcyrd
241b52d63d Add script to benchmark db_add speed 2018-11-13 11:05:07 +01:00
kpcyrd
a9e07a2c12 Add OpenBSD support 2018-11-11 08:29:42 +01:00
346 changed files with 73591 additions and 6219 deletions

View File

@@ -1,6 +1,10 @@
target
Dockerfile
.dockerignore
docker-compose.yml
docker
docs
ci
.git
.gitignore
*.sw[op]

2
.github/FUNDING.yml vendored Normal file
View File

@@ -0,0 +1,2 @@
github: [kpcyrd]
patreon: kpcyrd

58
.github/workflows/docker-release.yml vendored Normal file
View File

@@ -0,0 +1,58 @@
name: Publish Docker image
on:
release:
types: [ published ]
jobs:
push_to_registry:
name: Push Docker image to GitHub Registry
runs-on: ubuntu-latest
steps:
-
name: Checkout
uses: actions/checkout@v2
-
name: Docker meta
id: meta
uses: docker/metadata-action@v3
with:
images: |
ghcr.io/kpcyrd/sn0int
tags: |
type=semver,pattern={{raw}}
-
name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
-
name: Cache Docker layers
uses: actions/cache@v2
with:
path: /tmp/.buildx-cache
key: ${{ runner.os }}-buildx-${{ github.sha }}
restore-keys: |
${{ runner.os }}-buildx-
-
name: Login to Registry
uses: docker/login-action@v1
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GITHUB_TOKEN }}
-
name: Build and push Docker images
uses: docker/build-push-action@v2
with:
push: true
tags: ${{ steps.meta.outputs.tags }}
file: Dockerfile
cache-from: type=local,src=/tmp/.buildx-cache
cache-to: type=local,dest=/tmp/.buildx-cache-new
-
# Temp fix
# https://github.com/docker/build-push-action/issues/252
# https://github.com/moby/buildkit/issues/1896
name: Move cache
run: |
rm -rf /tmp/.buildx-cache
mv /tmp/.buildx-cache-new /tmp/.buildx-cache

30
.github/workflows/docker.yml vendored Normal file
View File

@@ -0,0 +1,30 @@
name: Docker
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
jobs:
build:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
build:
- name: sn0int
file: Dockerfile
- name: registry
file: sn0int-registry/Dockerfile
steps:
- uses: actions/checkout@v2
- name: Build the Docker image
run: DOCKER_BUILDKIT=1 docker build -t ${{ matrix.build.name }} -f ${{ matrix.build.file }} .
- name: Test the Docker image
run: docker run --rm ${{ matrix.build.name }} --help
- name: Show Docker images
run: docker images

69
.github/workflows/rust.yml vendored Normal file
View File

@@ -0,0 +1,69 @@
name: Rust
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
schedule:
- cron: '0 9 * * 1'
env:
CARGO_TERM_COLOR: always
jobs:
build:
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [macos-latest, ubuntu-latest]
steps:
- uses: actions/checkout@v2
- name: Install dependencies (apt)
if: matrix.os == 'ubuntu-latest'
run: sudo apt-get install libsqlite3-dev libseccomp-dev libsodium-dev
- name: Install dependencies (brew)
if: matrix.os == 'macos-latest'
run: brew install pkg-config libsodium
- name: Build (sn0int)
run: cargo build --verbose
- name: Build (common)
run: cd sn0int-common && cargo build --verbose
- name: Build (std)
run: cd sn0int-std && cargo build --verbose
- name: Build (examples)
run: cargo build --verbose --examples
- name: Run tests (sn0int)
run: cargo test --verbose
- name: Run tests (sn0int, --ignored)
run: cargo test --verbose -- --ignored
- name: Run tests (common)
run: cd sn0int-common && cargo test --verbose
- name: Run tests (common, --ignored)
run: cd sn0int-common && cargo test --verbose -- --ignored
- name: Run tests (std)
run: cd sn0int-std && cargo test --verbose
- name: Run tests (std, --ignored)
run: cd sn0int-std && cargo test --verbose -- --ignored
notify:
# forks shouldn't notify
if: github.repository == 'kpcyrd/sn0int'
runs-on: ubuntu-latest
needs:
- build
steps:
- name: irc notify
uses: rectalogic/notify-irc@v1
with:
server: irc.hackint.org
channel: "#sn0int"
nickname: github-ci
message: '${{ github.repository }}#${{ github.run_id }}(${{ github.event_name }}): ${{ github.ref }}: tests completed: ${{ needs.build.result }} (https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }})'

View File

@@ -1,49 +0,0 @@
language: rust
cache: cargo
matrix:
include:
- os: linux
rust: stable
env:
- BUILD_MODE=test
- os: linux
rust: stable
env:
- BUILD_MODE=common
- os: linux
rust: stable
env:
- BUILD_MODE=boxxy
- os: linux
rust: stable
env:
- BUILD_MODE=docker
- os: linux
rust: stable
env:
- BUILD_MODE=docker-registry
- os: osx
rust: stable
env:
- BUILD_MODE=test
- os: osx
rust: stable
env:
- BUILD_MODE=common
#- os: windows
# rust: stable
# env:
# - BUILD_MODE="windows test"
- os: windows
rust: stable
env:
- BUILD_MODE="windows common"
before_install:
- ci/setup.sh "$TRAVIS_OS_NAME"
script:
- df -h
- ci/run.sh $BUILD_MODE
- df -h

32
CONTRIBUTING.md Normal file
View File

@@ -0,0 +1,32 @@
# How to contribute
To contribute to sn0int, clone the repository and make sure both the build and
tests pass for you:
git clone https://github.com/kpcyrd/sn0int.git
cd sn0int
# build the project
cargo build
# run regular tests
cargo test
# run tests depending on the network
# these might fail if a service is down
cargo test -- --ignored
The project is loosely structured into a few folders:
- `src/models/` - database models
- `src/runtime/` - the stdlib that's exposed to lua
- `src/engine/` - code related to lua
- `src/sandbox/` - code related to sandboxing
- `src/cmd/` - cli commands
- `src/` - misc modules
After you're done, make sure the build completes without any warnings and both
tests pass successfully:
cargo test
cargo test -- --ignored
If you want to introduce a new feature feel free to open an issue first to make
sure your feature is a good fit for the project before implementing it.

5604
Cargo.lock generated

File diff suppressed because it is too large Load Diff

View File

@@ -1,61 +1,104 @@
[package]
name = "sn0int"
version = "0.4.0"
description = "OSINT framework and package manager"
version = "0.25.0"
description = "Semi-automatic OSINT framework and package manager"
authors = ["kpcyrd <git@rxv.cc>"]
license = "GPL-3.0"
repository = "https://github.com/kpcyrd/sn0int"
categories = ["command-line-utilities"]
readme = "README.md"
[badges]
travis-ci = { repository = "kpcyrd/sn0int" }
edition = "2021"
[workspace]
members = ["sn0int-registry/sn0int-common",
"sn0int-registry"]
members = ["sn0int-common",
"sn0int-registry",
"sn0int-std"]
[package.metadata.deb]
extended-description = """\
sn0int (pronounced /snoɪnt/) is a semi-automatic OSINT framework and package
manager. It was built for IT security professionals and bug hunters to gather
intelligence about a given target or about yourself. sn0int is enumerating
attack surface by semi-automatically processing public information and mapping
the results in a unified format for followup investigations."""
section = "utils"
priority = "optional"
depends = "$auto, publicsuffix"
assets = [
["target/release/sn0int", "usr/bin/", "755"],
]
[features]
sqlite-bundled = ["libsqlite3-sys/bundled"]
[dependencies]
sn0int-common = { version="0.3.0", path="sn0int-registry/sn0int-common" }
rustyline = "2"
sn0int-common = { version="0.13.0", path="sn0int-common" }
sn0int-std = { version="=0.25.0", path="sn0int-std" }
rustyline = "10.0"
log = "0.4"
env_logger = "0.5"
env_logger = "0.9"
hlua-badtouch = "0.4"
structopt = "0.2"
structopt = "0.3"
failure = "0.1"
rand = "0.5"
colored = "1.6"
rand = "0.8"
colored = "2"
lazy_static = "1.0"
shellwords = "1.0"
publicsuffix = { version="1.5", default-features=false }
diesel = { version = "1.0.0", features = ["sqlite"] }
diesel = { version = "1.0.0", features = ["sqlite", "chrono"] }
diesel_migrations = { version = "1.3.0", features = ["sqlite"] }
dirs = "1.0"
url = "1.7"
nix = "0.11"
chrootable-https = "0.3.4"
trust-dns-proto = "0.5.0"
base64 = "0.10"
kuchiki = "0.7.2"
serde_urlencoded = "0.5"
serde = "1.0"
serde_derive = "1.0"
libsqlite3-sys = { version = "0.25.1", features = ["bundled-windows"] }
chrono = { version = "0.4", features = ["serde"] }
dirs-next = "2.0"
url = "2.0"
percent-encoding = "2.1"
#chrootable-https = { path = "../chrootable-https" }
chrootable-https = "0.16"
data-encoding = "2.3.3"
serde = { version = "1.0", features = ["derive"] }
serde_urlencoded = "0.7"
serde_json = "1.0"
crossbeam-channel = "0.3"
crossbeam-channel = "0.5"
ctrlc = "3.1"
opener = "0.3.0"
separator = "0.3.1"
opener = "0.5"
separator = "0.4"
maplit = "1.0.1"
sloppy-rfc4880 = "0.1.2"
sloppy-rfc4880 = "0.2"
regex = "1.0"
toml = "0.4"
maxminddb = "0.10.0"
tar = "0.4.17"
libflate = "0.1.14"
toml = "0.5"
threadpool = "1.7"
atty = "0.2"
semver = "1"
bytes = "0.4"
bytesize = "1.0"
ipnetwork = "0.18"
strum = "0.24"
strum_macros = "0.24"
embedded-triple = "0.1.0"
humansize = "1.1.0"
digest = "0.10"
md-5 = "0.10"
sha-1 = "0.10"
sha2 = "0.10"
sha3 = "0.10"
hmac = "0.12"
walkdir = "2.2"
nude = "0.3"
glob = "0.3.0"
os-version = "0.2"
[target.'cfg(target_os="linux")'.dependencies]
caps = "0.3"
syscallz = "0.7"
caps = "0.5"
#syscallz = { path="../syscallz-rs" }
syscallz = "0.16"
nix = "0.24"
[target.'cfg(target_os="openbsd")'.dependencies]
pledge = "0.4"
unveil = "0.3"
[dev-dependencies]
boxxy = "0.8"
#boxxy = { path = "../boxxy-rs" }
boxxy = "0.13"
tempfile = "3.0"

View File

@@ -1,14 +1,18 @@
FROM alpine:edge
RUN apk add --no-cache sqlite-dev libseccomp-dev
RUN apk add --no-cache --virtual .build-rust rust cargo
FROM rust:alpine3.15
ENV RUSTFLAGS="-C target-feature=-crt-static"
RUN apk add --no-cache musl-dev sqlite-dev libseccomp-dev libsodium-dev
WORKDIR /usr/src/sn0int
COPY . .
RUN cargo build --release --verbose
RUN strip target/release/sn0int
RUN --mount=type=cache,target=/var/cache/buildkit \
CARGO_HOME=/var/cache/buildkit/cargo \
CARGO_TARGET_DIR=/var/cache/buildkit/target \
cargo build --release --locked --verbose && \
cp -v /var/cache/buildkit/target/release/sn0int /
RUN strip /sn0int
FROM alpine:edge
RUN apk add --no-cache libgcc sqlite-libs libseccomp
COPY --from=0 /usr/src/sn0int/target/release/sn0int /usr/local/bin/sn0int
FROM alpine:3.15
RUN apk add --no-cache libgcc sqlite-libs libseccomp libsodium
COPY --from=0 /sn0int /usr/local/bin/sn0int
VOLUME ["/data", "/cache"]
ENV XDG_DATA_HOME=/data \
XDG_CACHE_HOME=/cache

29
ISSUE_TEMPLATE.md Normal file
View File

@@ -0,0 +1,29 @@
<!--
Hello!
If you want to report a bug we added some common questions below that help us analyse your issue faster.
All of these are optional so feel free to remove anything that doesn't apply.
-->
please describe your issue here
---
## Versions
- **rustc --version:**
- **cargo --version:**
- **sn0int --version:**
- **uname -a:**
## Environment
- **Operating System/Distro:**
- **Installed from (source/apt/pacman/brew/docker):**
<!--
Thank you!
We'll try to respond as quickly as possible.
-->

View File

@@ -1,16 +1,32 @@
check:
(cd sn0int-registry/sn0int-common; cargo check)
(cd sn0int-common; cargo check)
(cd sn0int-registry; cargo check)
(cd sn0int-std; cargo check)
cargo check
force-check:
(cd sn0int-registry/sn0int-common; touch src/lib.rs; cargo check)
(cd sn0int-common; touch src/lib.rs; cargo check)
(cd sn0int-registry; touch src/main.rs; cargo check)
(cd sn0int-std; touch src/lib.rs; cargo check)
touch src/lib.rs
cargo check
test:
(cd sn0int-registry/sn0int-common; cargo test)
(cd sn0int-common; cargo test)
(cd sn0int-registry; cargo test)
cargo test
cargo test -- --ignored
(cd sn0int-std; cargo test)
(cd sn0int-std; cargo test -- --ignored)
cargo test --lib
cargo test --lib -- --ignored
update:
get-oui -v -u http://standards-oui.ieee.org/oui/oui.txt -f data/ieee-oui.txt
get-iab -v -u http://standards-oui.ieee.org/iab/iab.txt -f data/ieee-iab.txt
rm -f data/ieee-*.txt.bak
docs:
$(MAKE) -C docs html
contrib/html-toc2md.pl README.md docs/_build/html/index.html > README2.md
mv README2.md README.md
.PHONY: check force-check test update docs

333
README.md
View File

@@ -1,29 +1,328 @@
# sn0int [![Build Status][travis-img]][travis] [![Crates.io][crates-img]][crates]
# sn0int [![crates.io][crates-img]][crates] [![Documentation Status][docs-img]][docs] [![irc.hackint.org:6697/#sn0int][irc-img]][irc] [![@sn0int][twitter-img]][twitter] [![@sn0int@chaos.social][mastodon-img]][mastodon] [![registry status][registry-img]][registry]
[travis-img]: https://travis-ci.org/kpcyrd/sn0int.svg?branch=master
[travis]: https://travis-ci.org/kpcyrd/sn0int
[crates-img]: https://img.shields.io/crates/v/sn0int.svg
[crates]: https://crates.io/crates/sn0int
[docs-img]: https://readthedocs.org/projects/sn0int/badge/?version=latest
[docs]: https://sn0int.readthedocs.io/en/latest/?badge=latest
[irc-img]: https://img.shields.io/badge/hackint-%23sn0int-blue.svg
[irc]: https://webirc.hackint.org/#irc://irc.hackint.org/#sn0int
[twitter-img]: https://img.shields.io/badge/twitter-@sn0int-blue.svg
[twitter]: https://twitter.com/sn0int
[mastodon-img]: https://img.shields.io/badge/mastodon-chaos.social-blue.svg
[mastodon]: https://chaos.social/@sn0int
[registry-img]: https://img.shields.io/website/https/sn0int.com.svg?label=registry
[registry]: https://sn0int.com/
sn0int is an OSINT framework and package manager. It's purpose is
semi-automatically processing public information to enumerate attack surface.
sn0int itself is only providing an engine that can be extended with scripts.
sn0int (pronounced [`/snoɪnt/`][ipa]) is a semi-automatic OSINT framework and
package manager. It's used by IT security professionals, bug bounty hunters,
law enforcement agencies and in security awareness trainings to gather
intelligence about a given target or about yourself. sn0int is enumerating
attack surface by semi-automatically processing public information and mapping
the results in a unified format for followup investigations.
sn0int is heavily inspired by recon-ng, but takes a few different design
approaches. We've tried to correct some limitations in the database design and
also addressed the modularity problem:
[ipa]: http://ipa-reader.xyz/?text=sno%C9%AAnt
Instead of downloading and reviewing python scripts that have full access to
your system, sn0int is executing modules in a lua sandbox. Modules can be
published to the sn0int registry and then installed by users. This means that
you don't have to send pull requests to sn0int to add a module and updates can
be shipped much faster.
Among other things, sn0int is currently able to:
- Harvest subdomains from certificate transparency logs and passive dns
- Mass resolve collected subdomains and scan for http or https services
- Enrich ip addresses with asn and geoip info
- Harvest emails from pgp keyservers and whois
- Discover compromised logins in breaches
- Find somebody's profiles across the internet
- Enumerate local networks with unique techniques like passive arp
- Gather information about phonenumbers
- Harvest activity and images from social media profiles
- Basic image processing
sn0int is heavily inspired by recon-ng and maltego, but remains more flexible
and is fully opensource. None of the investigations listed above are hardcoded
in the source, instead they are provided by modules that are executed in a
sandbox. You can easily extend sn0int by writing your own modules and share
them with other users by publishing them to the sn0int registry. This allows
you to ship updates for your modules on your own instead of pull-requesting
them into the sn0int codebase.
For questions and support join us on IRC: [irc.hackint.org:6697/#sn0int](https://webirc.hackint.org/#irc://irc.hackint.org/#sn0int)
[![asciicast](https://asciinema.org/a/shZ3TVY1o0opGFln3Oi2DAMCB.svg)](https://asciinema.org/a/shZ3TVY1o0opGFln3Oi2DAMCB)
## Installation
- Archlinux: `yaourt -S sn0int`
- Alpine: `apk add --no-cache sqlite-dev libseccomp-dev cargo` + build from source
- Debian: `apt install libsqlite3-dev libseccomp-dev` + build from source
<a href="https://repology.org/project/sn0int/versions"><img align="right" src="https://repology.org/badge/vertical-allrepos/sn0int.svg" alt="Packaging status"></a>
Archlinux
pacman -S sn0int
Mac OSX
brew install sn0int
Debian/Ubuntu/Kali
There are prebuilt packages signed by a debian maintainer. We can import the
key for this repository out of the debian keyring.
apt install debian-keyring
gpg -a --export --keyring /usr/share/keyrings/debian-maintainers.gpg git@rxv.cc | apt-key add -
apt-key adv --keyserver keyserver.ubuntu.com --refresh-keys git@rxv.cc
echo deb http://apt.vulns.sexy stable main > /etc/apt/sources.list.d/apt-vulns-sexy.list
apt update
apt install sn0int
Docker
docker run --rm --init -it -v "$PWD/.cache:/cache" -v "$PWD/.data:/data" kpcyrd/sn0int
Alpine
apk add sn0int
OpenBSD
pkg_add sn0int
Gentoo
layman -a pentoo
emerge --ask net-analyzer/sn0int
NixOS
nix-env -i sn0int
For everything else please have a look at the [detailed list][1].
[1]: https://sn0int.readthedocs.io/en/latest/install.html
## Getting started
- [Installation](https://sn0int.readthedocs.io/en/latest/install.html)
- [Archlinux](https://sn0int.readthedocs.io/en/latest/install.html#archlinux)
- [Mac OSX](https://sn0int.readthedocs.io/en/latest/install.html#mac-osx)
- [Debian &gt;= bullseye, Ubuntu &gt;= 20.04, Kali](https://sn0int.readthedocs.io/en/latest/install.html#debian-bullseye-ubuntu-20-04-kali)
- [Debian &lt;= buster, Ubuntu &lt;= 19.10](https://sn0int.readthedocs.io/en/latest/install.html#debian-buster-ubuntu-19-10)
- [Fedora/CentOS/Redhat](https://sn0int.readthedocs.io/en/latest/install.html#fedora-centos-redhat)
- [Docker](https://sn0int.readthedocs.io/en/latest/install.html#docker)
- [Alpine](https://sn0int.readthedocs.io/en/latest/install.html#alpine)
- [OpenBSD](https://sn0int.readthedocs.io/en/latest/install.html#openbsd)
- [Gentoo](https://sn0int.readthedocs.io/en/latest/install.html#gentoo)
- [NixOS](https://sn0int.readthedocs.io/en/latest/install.html#nixos)
- [Windows](https://sn0int.readthedocs.io/en/latest/install.html#windows)
- [Build from source](https://sn0int.readthedocs.io/en/latest/build.html)
- [Install dependencies](https://sn0int.readthedocs.io/en/latest/build.html#install-dependencies)
- [Archlinux](https://sn0int.readthedocs.io/en/latest/build.html#archlinux)
- [Mac OSX](https://sn0int.readthedocs.io/en/latest/build.html#mac-osx)
- [Debian/Ubuntu/Kali](https://sn0int.readthedocs.io/en/latest/build.html#debian-ubuntu-kali)
- [Alpine](https://sn0int.readthedocs.io/en/latest/build.html#alpine)
- [OpenBSD](https://sn0int.readthedocs.io/en/latest/build.html#openbsd)
- [Gentoo](https://sn0int.readthedocs.io/en/latest/build.html#gentoo)
- [Windows](https://sn0int.readthedocs.io/en/latest/build.html#windows)
- [Building](https://sn0int.readthedocs.io/en/latest/build.html#building)
- [Running your first investigation](https://sn0int.readthedocs.io/en/latest/usage.html)
- [Installing the default modules](https://sn0int.readthedocs.io/en/latest/usage.html#installing-the-default-modules)
- [Adding something to scope](https://sn0int.readthedocs.io/en/latest/usage.html#adding-something-to-scope)
- [Running a module](https://sn0int.readthedocs.io/en/latest/usage.html#running-a-module)
- [Running followup modules on the results](https://sn0int.readthedocs.io/en/latest/usage.html#running-followup-modules-on-the-results)
- [Unscoping entities](https://sn0int.readthedocs.io/en/latest/usage.html#unscoping-entities)
- [Autonoscope](https://sn0int.readthedocs.io/en/latest/autonoscope.html)
- [Domains](https://sn0int.readthedocs.io/en/latest/autonoscope.html#domains)
- [IPs](https://sn0int.readthedocs.io/en/latest/autonoscope.html#ips)
- [URLs](https://sn0int.readthedocs.io/en/latest/autonoscope.html#urls)
- [Writing your first module](https://sn0int.readthedocs.io/en/latest/scripting.html)
- [Creating a repository](https://sn0int.readthedocs.io/en/latest/scripting.html#creating-a-repository)
- [Publish your module](https://sn0int.readthedocs.io/en/latest/scripting.html#publish-your-module)
- [Publish your repo](https://sn0int.readthedocs.io/en/latest/scripting.html#publish-your-repo)
- [Reading data from stdin](https://sn0int.readthedocs.io/en/latest/scripting.html#reading-data-from-stdin)
- [Database](https://sn0int.readthedocs.io/en/latest/database.html)
- [db_add](https://sn0int.readthedocs.io/en/latest/database.html#db-add)
- [db_add_ttl](https://sn0int.readthedocs.io/en/latest/database.html#db-add-ttl)
- [db_activity](https://sn0int.readthedocs.io/en/latest/database.html#db-activity)
- [db_update](https://sn0int.readthedocs.io/en/latest/database.html#db-update)
- [db_select](https://sn0int.readthedocs.io/en/latest/database.html#db-select)
- [Structs](https://sn0int.readthedocs.io/en/latest/structs.html)
- [Domains](https://sn0int.readthedocs.io/en/latest/structs.html#domains)
- [Subdomains](https://sn0int.readthedocs.io/en/latest/structs.html#subdomains)
- [IpAddrs](https://sn0int.readthedocs.io/en/latest/structs.html#ipaddrs)
- [URLs](https://sn0int.readthedocs.io/en/latest/structs.html#urls)
- [Emails](https://sn0int.readthedocs.io/en/latest/structs.html#emails)
- [Phonenumbers](https://sn0int.readthedocs.io/en/latest/structs.html#phonenumbers)
- [Devices](https://sn0int.readthedocs.io/en/latest/structs.html#devices)
- [Networks](https://sn0int.readthedocs.io/en/latest/structs.html#networks)
- [Accounts](https://sn0int.readthedocs.io/en/latest/structs.html#accounts)
- [Breaches](https://sn0int.readthedocs.io/en/latest/structs.html#breaches)
- [Images](https://sn0int.readthedocs.io/en/latest/structs.html#images)
- [Ports](https://sn0int.readthedocs.io/en/latest/structs.html#ports)
- [Netblocks](https://sn0int.readthedocs.io/en/latest/structs.html#netblocks)
- [CryptoAddrs](https://sn0int.readthedocs.io/en/latest/structs.html#cryptoaddrs)
- [Activity](https://sn0int.readthedocs.io/en/latest/structs.html#activity)
- [Relations](https://sn0int.readthedocs.io/en/latest/structs.html#relations)
- [subdomain_ipaddr](https://sn0int.readthedocs.io/en/latest/structs.html#subdomain-ipaddr)
- [network_device](https://sn0int.readthedocs.io/en/latest/structs.html#network-device)
- [breach_email](https://sn0int.readthedocs.io/en/latest/structs.html#breach-email)
- [Activity](https://sn0int.readthedocs.io/en/latest/activity.html)
- [Anatomy of an event](https://sn0int.readthedocs.io/en/latest/activity.html#anatomy-of-an-event)
- [Logging events](https://sn0int.readthedocs.io/en/latest/activity.html#logging-events)
- [Querying events](https://sn0int.readthedocs.io/en/latest/activity.html#querying-events)
- [Visualization](https://sn0int.readthedocs.io/en/latest/activity.html#visualization)
- [Notifications](https://sn0int.readthedocs.io/en/latest/notifications.html)
- [Receiving notifications](https://sn0int.readthedocs.io/en/latest/notifications.html#receiving-notifications)
- [Telegram](https://sn0int.readthedocs.io/en/latest/notifications.html#telegram)
- [Pushover](https://sn0int.readthedocs.io/en/latest/notifications.html#pushover)
- [Discord](https://sn0int.readthedocs.io/en/latest/notifications.html#discord)
- [Signal](https://sn0int.readthedocs.io/en/latest/notifications.html#signal)
- [Writing your own module](https://sn0int.readthedocs.io/en/latest/notifications.html#writing-your-own-module)
- [Setting up notification rules](https://sn0int.readthedocs.io/en/latest/notifications.html#setting-up-notification-rules)
- [Testing notifications](https://sn0int.readthedocs.io/en/latest/notifications.html#testing-notifications)
- [Running sn0int automatically](https://sn0int.readthedocs.io/en/latest/notifications.html#running-sn0int-automatically)
- [Monitors](https://sn0int.readthedocs.io/en/latest/notifications.html#monitors)
- [Timers](https://sn0int.readthedocs.io/en/latest/notifications.html#timers)
- [Keyring](https://sn0int.readthedocs.io/en/latest/keyring.html)
- [Managing the keyring](https://sn0int.readthedocs.io/en/latest/keyring.html#managing-the-keyring)
- [Using access keys in scripts](https://sn0int.readthedocs.io/en/latest/keyring.html#using-access-keys-in-scripts)
- [Using access keys as source argument](https://sn0int.readthedocs.io/en/latest/keyring.html#using-access-keys-as-source-argument)
- [Configuration](https://sn0int.readthedocs.io/en/latest/config.html)
- [\[core\]](https://sn0int.readthedocs.io/en/latest/config.html#core)
- [\[namespaces\]](https://sn0int.readthedocs.io/en/latest/config.html#namespaces)
- [\[network\]](https://sn0int.readthedocs.io/en/latest/config.html#network)
- [Sandbox](https://sn0int.readthedocs.io/en/latest/sandbox.html)
- [Linux](https://sn0int.readthedocs.io/en/latest/sandbox.html#linux)
- [OpenBSD](https://sn0int.readthedocs.io/en/latest/sandbox.html#openbsd)
- [IPC Protocol](https://sn0int.readthedocs.io/en/latest/sandbox.html#ipc-protocol)
- [Limitations](https://sn0int.readthedocs.io/en/latest/sandbox.html#limitations)
- [Diagnosing a sandbox failure](https://sn0int.readthedocs.io/en/latest/sandbox.html#diagnosing-a-sandbox-failure)
- [Function reference](https://sn0int.readthedocs.io/en/latest/reference.html)
- [asn_lookup](https://sn0int.readthedocs.io/en/latest/reference.html#asn-lookup)
- [base64_decode](https://sn0int.readthedocs.io/en/latest/reference.html#base64-decode)
- [base64_encode](https://sn0int.readthedocs.io/en/latest/reference.html#base64-encode)
- [base64_custom_decode](https://sn0int.readthedocs.io/en/latest/reference.html#base64-custom-decode)
- [base64_custom_encode](https://sn0int.readthedocs.io/en/latest/reference.html#base64-custom-encode)
- [base32_custom_decode](https://sn0int.readthedocs.io/en/latest/reference.html#base32-custom-decode)
- [base32_custom_encode](https://sn0int.readthedocs.io/en/latest/reference.html#base32-custom-encode)
- [clear_err](https://sn0int.readthedocs.io/en/latest/reference.html#clear-err)
- [create_blob](https://sn0int.readthedocs.io/en/latest/reference.html#create-blob)
- [datetime](https://sn0int.readthedocs.io/en/latest/reference.html#datetime)
- [db_add](https://sn0int.readthedocs.io/en/latest/reference.html#db-add)
- [db_add_ttl](https://sn0int.readthedocs.io/en/latest/reference.html#db-add-ttl)
- [db_activity](https://sn0int.readthedocs.io/en/latest/reference.html#db-activity)
- [db_select](https://sn0int.readthedocs.io/en/latest/reference.html#db-select)
- [db_update](https://sn0int.readthedocs.io/en/latest/reference.html#db-update)
- [dns](https://sn0int.readthedocs.io/en/latest/reference.html#dns)
- [error](https://sn0int.readthedocs.io/en/latest/reference.html#error)
- [geoip_lookup](https://sn0int.readthedocs.io/en/latest/reference.html#geoip-lookup)
- [hex](https://sn0int.readthedocs.io/en/latest/reference.html#hex)
- [hmac_md5](https://sn0int.readthedocs.io/en/latest/reference.html#hmac-md5)
- [hmac_sha1](https://sn0int.readthedocs.io/en/latest/reference.html#hmac-sha1)
- [hmac_sha2_256](https://sn0int.readthedocs.io/en/latest/reference.html#hmac-sha2-256)
- [hmac_sha2_512](https://sn0int.readthedocs.io/en/latest/reference.html#hmac-sha2-512)
- [hmac_sha3_256](https://sn0int.readthedocs.io/en/latest/reference.html#hmac-sha3-256)
- [hmac_sha3_512](https://sn0int.readthedocs.io/en/latest/reference.html#hmac-sha3-512)
- [html_select](https://sn0int.readthedocs.io/en/latest/reference.html#html-select)
- [html_select_list](https://sn0int.readthedocs.io/en/latest/reference.html#html-select-list)
- [http_mksession](https://sn0int.readthedocs.io/en/latest/reference.html#http-mksession)
- [http_request](https://sn0int.readthedocs.io/en/latest/reference.html#http-request)
- [http_send](https://sn0int.readthedocs.io/en/latest/reference.html#http-send)
- [http_fetch](https://sn0int.readthedocs.io/en/latest/reference.html#http-fetch)
- [http_fetch_json](https://sn0int.readthedocs.io/en/latest/reference.html#http-fetch-json)
- [img_load](https://sn0int.readthedocs.io/en/latest/reference.html#img-load)
- [img_exif](https://sn0int.readthedocs.io/en/latest/reference.html#img-exif)
- [img_ahash](https://sn0int.readthedocs.io/en/latest/reference.html#img-ahash)
- [img_dhash](https://sn0int.readthedocs.io/en/latest/reference.html#img-dhash)
- [img_phash](https://sn0int.readthedocs.io/en/latest/reference.html#img-phash)
- [img_nudity](https://sn0int.readthedocs.io/en/latest/reference.html#img-nudity)
- [info](https://sn0int.readthedocs.io/en/latest/reference.html#info)
- [intval](https://sn0int.readthedocs.io/en/latest/reference.html#intval)
- [json_decode](https://sn0int.readthedocs.io/en/latest/reference.html#json-decode)
- [json_decode_stream](https://sn0int.readthedocs.io/en/latest/reference.html#json-decode-stream)
- [json_encode](https://sn0int.readthedocs.io/en/latest/reference.html#json-encode)
- [key_trunc_pad](https://sn0int.readthedocs.io/en/latest/reference.html#key-trunc-pad)
- [keyring](https://sn0int.readthedocs.io/en/latest/reference.html#keyring)
- [last_err](https://sn0int.readthedocs.io/en/latest/reference.html#last-err)
- [md5](https://sn0int.readthedocs.io/en/latest/reference.html#md5)
- [mqtt_connect](https://sn0int.readthedocs.io/en/latest/reference.html#mqtt-connect)
- [mqtt_subscribe](https://sn0int.readthedocs.io/en/latest/reference.html#mqtt-subscribe)
- [mqtt_recv](https://sn0int.readthedocs.io/en/latest/reference.html#mqtt-recv)
- [mqtt_ping](https://sn0int.readthedocs.io/en/latest/reference.html#mqtt-ping)
- [pgp_pubkey](https://sn0int.readthedocs.io/en/latest/reference.html#pgp-pubkey)
- [pgp_pubkey_armored](https://sn0int.readthedocs.io/en/latest/reference.html#pgp-pubkey-armored)
- [print](https://sn0int.readthedocs.io/en/latest/reference.html#print)
- [psl_domain_from_dns_name](https://sn0int.readthedocs.io/en/latest/reference.html#psl-domain-from-dns-name)
- [ratelimit_throttle](https://sn0int.readthedocs.io/en/latest/reference.html#ratelimit-throttle)
- [regex_find](https://sn0int.readthedocs.io/en/latest/reference.html#regex-find)
- [regex_find_all](https://sn0int.readthedocs.io/en/latest/reference.html#regex-find-all)
- [semver_match](https://sn0int.readthedocs.io/en/latest/reference.html#semver-match)
- [set_err](https://sn0int.readthedocs.io/en/latest/reference.html#set-err)
- [sha1](https://sn0int.readthedocs.io/en/latest/reference.html#sha1)
- [sha2_256](https://sn0int.readthedocs.io/en/latest/reference.html#sha2-256)
- [sha2_512](https://sn0int.readthedocs.io/en/latest/reference.html#sha2-512)
- [sha3_256](https://sn0int.readthedocs.io/en/latest/reference.html#sha3-256)
- [sha3_512](https://sn0int.readthedocs.io/en/latest/reference.html#sha3-512)
- [sleep](https://sn0int.readthedocs.io/en/latest/reference.html#sleep)
- [sn0int_time](https://sn0int.readthedocs.io/en/latest/reference.html#sn0int-time)
- [sn0int_time_from](https://sn0int.readthedocs.io/en/latest/reference.html#sn0int-time-from)
- [sn0int_version](https://sn0int.readthedocs.io/en/latest/reference.html#sn0int-version)
- [sock_connect](https://sn0int.readthedocs.io/en/latest/reference.html#sock-connect)
- [sock_upgrade_tls](https://sn0int.readthedocs.io/en/latest/reference.html#sock-upgrade-tls)
- [sock_options](https://sn0int.readthedocs.io/en/latest/reference.html#sock-options)
- [sock_send](https://sn0int.readthedocs.io/en/latest/reference.html#sock-send)
- [sock_recv](https://sn0int.readthedocs.io/en/latest/reference.html#sock-recv)
- [sock_sendline](https://sn0int.readthedocs.io/en/latest/reference.html#sock-sendline)
- [sock_recvline](https://sn0int.readthedocs.io/en/latest/reference.html#sock-recvline)
- [sock_recvall](https://sn0int.readthedocs.io/en/latest/reference.html#sock-recvall)
- [sock_recvline_contains](https://sn0int.readthedocs.io/en/latest/reference.html#sock-recvline-contains)
- [sock_recvline_regex](https://sn0int.readthedocs.io/en/latest/reference.html#sock-recvline-regex)
- [sock_recvn](https://sn0int.readthedocs.io/en/latest/reference.html#sock-recvn)
- [sock_recvuntil](https://sn0int.readthedocs.io/en/latest/reference.html#sock-recvuntil)
- [sock_sendafter](https://sn0int.readthedocs.io/en/latest/reference.html#sock-sendafter)
- [sock_newline](https://sn0int.readthedocs.io/en/latest/reference.html#sock-newline)
- [sodium_secretbox_open](https://sn0int.readthedocs.io/en/latest/reference.html#sodium-secretbox-open)
- [status](https://sn0int.readthedocs.io/en/latest/reference.html#status)
- [stdin_readline](https://sn0int.readthedocs.io/en/latest/reference.html#stdin-readline)
- [stdin_read_to_end](https://sn0int.readthedocs.io/en/latest/reference.html#stdin-read-to-end)
- [str_find](https://sn0int.readthedocs.io/en/latest/reference.html#str-find)
- [str_replace](https://sn0int.readthedocs.io/en/latest/reference.html#str-replace)
- [strftime](https://sn0int.readthedocs.io/en/latest/reference.html#strftime)
- [strptime](https://sn0int.readthedocs.io/en/latest/reference.html#strptime)
- [strval](https://sn0int.readthedocs.io/en/latest/reference.html#strval)
- [time_unix](https://sn0int.readthedocs.io/en/latest/reference.html#time-unix)
- [url_decode](https://sn0int.readthedocs.io/en/latest/reference.html#url-decode)
- [url_encode](https://sn0int.readthedocs.io/en/latest/reference.html#url-encode)
- [url_escape](https://sn0int.readthedocs.io/en/latest/reference.html#url-escape)
- [url_join](https://sn0int.readthedocs.io/en/latest/reference.html#url-join)
- [url_parse](https://sn0int.readthedocs.io/en/latest/reference.html#url-parse)
- [url_unescape](https://sn0int.readthedocs.io/en/latest/reference.html#url-unescape)
- [utf8_decode](https://sn0int.readthedocs.io/en/latest/reference.html#utf8-decode)
- [warn](https://sn0int.readthedocs.io/en/latest/reference.html#warn)
- [warn_once](https://sn0int.readthedocs.io/en/latest/reference.html#warn-once)
- [ws_connect](https://sn0int.readthedocs.io/en/latest/reference.html#ws-connect)
- [ws_options](https://sn0int.readthedocs.io/en/latest/reference.html#ws-options)
- [ws_recv_text](https://sn0int.readthedocs.io/en/latest/reference.html#ws-recv-text)
- [ws_recv_binary](https://sn0int.readthedocs.io/en/latest/reference.html#ws-recv-binary)
- [ws_recv_json](https://sn0int.readthedocs.io/en/latest/reference.html#ws-recv-json)
- [ws_send_text](https://sn0int.readthedocs.io/en/latest/reference.html#ws-send-text)
- [ws_send_binary](https://sn0int.readthedocs.io/en/latest/reference.html#ws-send-binary)
- [ws_send_json](https://sn0int.readthedocs.io/en/latest/reference.html#ws-send-json)
- [x509_parse_pem](https://sn0int.readthedocs.io/en/latest/reference.html#x509-parse-pem)
- [xml_decode](https://sn0int.readthedocs.io/en/latest/reference.html#xml-decode)
- [xml_named](https://sn0int.readthedocs.io/en/latest/reference.html#xml-named)
## Rationale
This tool was written for companies to help them understand their attack
surface from a blackbox point of view. It's often difficult to understand that
something is easier to discover than some people assume, putting them at risk
of false security.
It's also designed to be useful for red team assessments and bug bounties,
which also help companies to identify weaknesses that could result in a
compromise.
Some functionality was written to do the same thing for individuals to raise
awareness about personal attack surface, privacy and how much data is publicly
available. These issues are often out of scope in bug bounties and sometimes by
design. We believe that blaming the user is the wrong approach and these issues
should be addressed at the root cause by the people designing those systems.
## License

34
ci/bench.sh Executable file
View File

@@ -0,0 +1,34 @@
#!/bin/sh
set -eu
X=$(mktemp -d)
cd "$X"
mkdir -p "$X/.cache"
cp -r "$HOME/.cache/sn0int" "$X/.cache/"
#export CARGO_HOME="${CARGO_HOME:-$HOME/.cargo}"
#export RUSTUP_HOME="${RUSTUP_HOME:-$HOME/.rustup}"
export HOME="$X"
cat > 1k.lua <<EOF
-- Description: Insert 1k random subdomains
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
for i=1,1000 do
x = 'foo' .. i .. '.example.com'
db_add('subdomain', {
domain_id=arg['id'],
value=x,
})
end
end
EOF
echo '[*] Setting up workspace'
echo 'add domain example.com' | "$@" > /dev/null
echo '[*] Running 1k inserts'
time "$@" run -f ./1k.lua

View File

@@ -1,3 +1,5 @@
stage1
ls
echo checkpoint1
id
echo sandbox fail

133
ci/integration.py Executable file
View File

@@ -0,0 +1,133 @@
#!/usr/bin/env python3
import subprocess
from subprocess import DEVNULL, PIPE
import shutil
from pathlib import Path
import tempfile
import json
import sys
def _sn0int(tempdir, binary, args, piped_stdout=False):
return subprocess.Popen(
['/usr/bin/env', 'HOME='+tempdir, binary] + args,
stdin=PIPE,
stdout=PIPE if piped_stdout else None,
)
def sn0int(tempdir, binary, cmds):
p = _sn0int(tempdir, binary, [])
for cmd in cmds:
p.stdin.write((cmd + '\n').encode('utf-8'))
p.communicate()
if p.returncode != 0:
raise Exception('process failed')
def sn0int_select(tempdir, binary, query):
p = _sn0int(tempdir, binary, ['select', '--json'] + query, piped_stdout=True)
stdout, _ = p.communicate()
lines = filter(None, stdout.decode('utf-8').split('\n'))
return [json.loads(x) for x in lines]
def main(tempdir, binary):
print('[*] setting up workspace')
sn0int(tempdir, binary, [])
print('[*] adding domain')
sn0int(tempdir, binary, [
'add domain',
'example.com',
'select domains',
])
print('[*] testing db for domain')
domains = sn0int_select(tempdir, binary, ['domains'])
assert domains == [{'id': 1, 'value': 'example.com', 'unscoped': False}]
print('[*] installing modules')
sn0int(tempdir, binary, [
'pkg install kpcyrd/ctlogs',
'pkg install kpcyrd/dns-resolve',
'pkg install kpcyrd/url-scan',
'pkg install kpcyrd/geoip',
])
print('[*] running ctlogs')
sn0int(tempdir, binary, [
'use ctlogs',
'run',
'select subdomains',
])
print('[*] testing db for subdomains')
subdomains = sn0int_select(tempdir, binary, ['subdomains'])
assert {x['value'] for x in subdomains} == {
'example.com',
'www.example.com',
'm.example.com',
'dev.example.com',
'products.example.com',
'support.example.com',
}
print('[*] running dns-resolve')
sn0int(tempdir, binary, [
'use dns-resolve',
'run',
'select ipaddrs',
])
print('[*] testing db for ipaddrs')
ipaddrs = sn0int_select(tempdir, binary, ['ipaddrs'])
assert len(ipaddrs) >= 1
print('[*] running url-scan')
sn0int(tempdir, binary, [
'use url-scan',
'run',
'select urls',
])
print('[*] testing db for urls')
urls = sn0int_select(tempdir, binary, ['urls'])
assert {(x['value'], x['status']) for x in urls} == {
('http://example.com/', 200),
('https://example.com/', 200),
('http://www.example.com/', 200),
('https://www.example.com/', 200),
}
cache = Path.home() / '.cache' / 'sn0int'
if cache.exists():
print('[*] copying geoip files')
shutil.copytree(cache, tempdir + '/.cache/sn0int', dirs_exist_ok=True)
print('[*] running geoip')
sn0int(tempdir, binary, [
'use geoip',
'run',
'select ipaddrs',
])
print('[*] testing db for ipaddrs again')
ipaddrs2 = sn0int_select(tempdir, binary, ['ipaddrs'])
assert ipaddrs != ipaddrs2
print('')
print('\t###########')
print('\t# SUCCESS #')
print('\t###########')
print('')
if __name__ == '__main__':
try:
binary = sys.argv[1]
except IndexError:
print('Usage: %s target/release/sn0int' % sys.argv[0])
else:
with tempfile.TemporaryDirectory(prefix='sn0int-') as tempdir:
main(tempdir, binary)

View File

@@ -1,41 +0,0 @@
#!/bin/sh
set -exu
case "$1" in
build)
cargo build --verbose
cargo build --verbose --examples
;;
test)
ci/run.sh build
wget https://geolite.maxmind.com/download/geoip/database/GeoLite2-City.tar.gz \
https://geolite.maxmind.com/download/geoip/database/GeoLite2-ASN.tar.gz
cargo run --example maxmind-dl -- -e GeoLite2-City.tar.gz GeoLite2-City.mmdb GeoLite2-City.mmdb
cargo run --example maxmind-dl -- -e GeoLite2-ASN.tar.gz GeoLite2-ASN.mmdb GeoLite2-ASN.mmdb
cargo test --verbose
cargo test --verbose -- --ignored
;;
common)
cd sn0int-registry/sn0int-common
cargo test --verbose
;;
windows)
export SQLITE3_LIB_DIR="$TRAVIS_BUILD_DIR"
ci/run.sh "$2"
;;
boxxy)
cargo build --verbose --examples
if cat ci/boxxy_stage1.txt | RUST_LOG=boxxy cargo run --example boxxy; then
echo "SANDOX ERROR: should've crashed"
exit 1
fi
;;
docker)
docker build -t sn0int .
docker images
docker run --rm sn0int --help
;;
docker-registry)
docker build -t sn0int-registry sn0int-registry/
docker images
;;
esac

View File

@@ -1,16 +0,0 @@
#!/bin/sh
set -exu
case "$1" in
linux)
sudo apt update
sudo apt install libsqlite3-dev libseccomp-dev
;;
osx)
brew install sqlite3
;;
windows)
curl -fsS --retry 3 --retry-connrefused -o sqlite3.zip https://sqlite.org/2017/sqlite-dll-win64-x64-3160200.zip
7z e sqlite3.zip -y
"C:\\Program Files (x86)\\Microsoft Visual Studio 14.0\\VC\\bin\\lib.exe" /def:sqlite3.def /OUT:sqlite3.lib /machine:x64
;;
esac

View File

@@ -0,0 +1,15 @@
FROM rust:alpine3.11
ENV RUSTFLAGS="-C target-feature=-crt-static"
RUN apk add --no-cache musl-dev sqlite-dev libseccomp-dev libsodium-dev
WORKDIR /usr/src/sn0int
COPY . .
RUN cargo build --release --verbose
RUN strip target/release/sn0int
FROM alpine:3.11
RUN apk add --no-cache libgcc sqlite-libs libseccomp libsodium
COPY --from=0 /usr/src/sn0int/target/release/sn0int /usr/local/bin/sn0int
VOLUME ["/data", "/cache"]
ENV XDG_DATA_HOME=/data \
XDG_CACHE_HOME=/cache
ENTRYPOINT ["sn0int"]

View File

@@ -0,0 +1,16 @@
FROM rust:buster
RUN apt-get update -q && apt-get install -yq libsqlite3-dev libseccomp-dev libsodium-dev \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /usr/src/sn0int
COPY . .
RUN cargo build --release --verbose
RUN strip target/release/sn0int
FROM debian:buster
RUN apt-get update -q && apt-get install -yq libsqlite3-dev libseccomp-dev libsodium-dev \
&& rm -rf /var/lib/apt/lists/*
COPY --from=0 /usr/src/sn0int/target/release/sn0int /usr/local/bin/sn0int
VOLUME ["/data", "/cache"]
ENV XDG_DATA_HOME=/data \
XDG_CACHE_HOME=/cache
ENTRYPOINT ["sn0int"]

39
contrib/html-toc2md.pl Executable file
View File

@@ -0,0 +1,39 @@
#!/usr/bin/env perl
use strict; use warnings;
my ($readme, $toc) = @ARGV;
defined $readme or die 'missing readme path';
defined $toc or die 'missing toc path';
open(my $r, "<$readme") or die 'failed to open readme';
open(my $t, "<$toc") or die 'failed to open toc';
my $re = qr/^\s*- \[.+\]\(https:\/\/sn0int.readthedocs.io\/en\/.+\)$/;
# pass through start of readme
while (<$r>) {
last if ($_ =~ $re);
print $_;
}
# skip toc
while (<$r>) {
last unless ($_ =~ $re);
}
# generate new toc
while (my $line = <$t>) {
if ($line =~ /toctree-l(\d).*href="([^"]+)">(.+)<\/a/) {
my $space = int($1)-1;
my $section = $2;
my $label = $3;
$label =~ s/([\[\]])/\\$1/g;
print " " x ($space*2), "- [$label](https://sn0int.readthedocs.io/en/latest/$section)\n";
}
}
print;
# pass through end of readme
while (<$r>) {
print $_;
}

0
data/.gitkeep Normal file
View File

4595
data/ieee-iab.txt Normal file

File diff suppressed because it is too large Load Diff

25800
data/ieee-oui.txt Normal file

File diff suppressed because it is too large Load Diff

1
docs/.gitignore vendored Normal file
View File

@@ -0,0 +1 @@
/_build/

19
docs/Makefile Normal file
View File

@@ -0,0 +1,19 @@
# Minimal makefile for Sphinx documentation
#
# You can set these variables from the command line.
SPHINXOPTS =
SPHINXBUILD = sphinx-build
SOURCEDIR = .
BUILDDIR = _build
# Put it first so that "make" without argument is like "make help".
help:
@$(SPHINXBUILD) -M help "$(SOURCEDIR)" "$(BUILDDIR)" $(SPHINXOPTS) $(O)
.PHONY: help Makefile
# Catch-all target: route all unknown targets to Sphinx using the new
# "make mode" option. $(O) is meant as a shortcut for $(SPHINXOPTS).
%: Makefile
@$(SPHINXBUILD) -M $@ "$(SOURCEDIR)" "$(BUILDDIR)" $(SPHINXOPTS) $(O)

166
docs/activity.rst Normal file
View File

@@ -0,0 +1,166 @@
Activity
========
So far we've learned about regular `structs <structs.html>`_, but activity is
special.
Activity is an event tied to a specific time and topic and has a small amount
of data piggybacked to it.
Anatomy of an event
-------------------
``topic``
This is some freestyle text used to group events to a specific topic. This
must not conflict with other modules unless there's a very good reason.
The topic should look like ``kpcyrd/example:something``, with ``something``
being a meaningful unique identifier for whatever is generating these
events, like a mac address or an account name/id.
The rules around this might become stricter in the future.
``time``
The most important part of the event: The time and date it happened.
``initial``
This value can not be set but might be present in sn0int output. See `Querying events`_.
``uniq`` (optional)
This is an optional feature to deduplicate events. Assuming you're
importing posts by an account, you wouldn't want to store a new event for
each post you already imported. If you set this field to the technical post
id then sn0int would skip the event if it already has an event with the
same ``topic`` and ``uniq`` combination to avoid inserting duplicates.
``latitude`` (optional)
Latitude - if you can tie the event to a specific location.
``longitude`` (optional)
Longitude - if you can tie the event to a specific location.
``radius`` (optional)
The location radius in meters. If the position you got has a precision of
100 meters set this value to ``100``.
``content``
Arbitrary data that you want to attach to the event. This doesn't need to
be a string and can be an arbitrary object that is then stored as json
string.
Logging events
--------------
An ``activity`` event can be logged with ``db_activity``:
.. code-block:: lua
db_activity({
topic='harness/activity-ping:dummy',
time=sn0int_time(),
content={
a='b',
foo={
bar=1337,
},
msg='ohai',
},
})
Logging an event that has a location attached could look like this:
.. code-block:: lua
db_activity({
topic='harness/activity-ping:dummy',
time=sn0int_time(),
latitude=40.726662,
longitude=-74.036677,
radius=50,
content={
a='b',
foo={
bar=1337,
},
msg='ohai',
},
})
Making sure an event is not logged twice can be done with ``uniq``:
.. code-block:: lua
-- create the first event
db_activity({
topic='harness/activity-ping:dummy',
time=sn0int_time(),
uniq='12345',
content='ohai',
})
-- this does nothing because we already have an event with this topic+uniq combination
db_activity({
topic='harness/activity-ping:dummy',
time=sn0int_time(),
uniq='12345',
content='ohai',
})
-- this creates a new event because uniq is different
db_activity({
topic='harness/activity-ping:dummy',
time=sn0int_time(),
uniq='6789',
content='ohai',
})
-- this also creates a new event because topic is different
db_activity({
topic='harness/activity-ping:something-else',
time=sn0int_time(),
uniq='6789',
content='ohai',
})
Querying events
---------------
There is a commandline interface that can be used to query all events we've
logged. To get everything (sorted by time)::
sn0int activity
To limit the output to a specific topic::
sn0int activity -t harness/activity-ping:dummy
To limit it to a specific time frame::
# everything since
sn0int activity --since 2020-01-13T04:20:00
# everything until
sn0int activity --until 2020-01-13T04:20:00
# both
sn0int activity --since yesterday --until today
When using ``--since`` you might also want to know the previous state and use
it as an initial value. Consider this example::
2020-01-13 14:30:00 # user goes offline
2020-01-13 23:59:00 # user goes online
2020-01-14 09:30:00 # user goes idle
2020-01-14 14:20:00 # user goes offline
If we're running a query like ``sn0int activity --since 2020-01-14T00:00:00``
the program consuming the output wouldn't know that the user is initially
online because we're only getting this data::
{"id":8,"topic":"foo/bar:asdf","time":"2020-01-14T09:30:00","content":{"state":"idle"}}
{"id":9,"topic":"foo/bar:asdf","time":"2020-01-14T14:20:00","content":{"state":"offline"}}
We can tweak this with ``sn0int activity --initial --since
2020-01-14T00:00:00`` to include one more event that we only use to populate
the intial state::
{"id":7,"initial":true,"topic":"foo/bar:asdf","time":"2020-01-13T23:59:00","content":{"state":"online"}}
{"id":8,"topic":"foo/bar:asdf","time":"2020-01-14T09:30:00","content":{"state":"idle"}}
{"id":9,"topic":"foo/bar:asdf","time":"2020-01-14T14:20:00","content":{"state":"offline"}}
Visualization
-------------
There is no visualization built in, there may be external frontends for this in
the future. You're very welcome to write one!

81
docs/autonoscope.rst Normal file
View File

@@ -0,0 +1,81 @@
Autonoscope
===========
Instead of manually unscoping everything you can also define so called
autonoscope rules. Those are executed from most specific to least specific and
the first match wins. If no rule matches, the default is in-scope::
[sn0int][demo] > # add the domain first
[sn0int][demo] > # this is necessary because we only want to partially unscope example.com
[sn0int][demo] > add domain example.com
[sn0int][demo] >
[sn0int][demo] > # automatically noscope all subdomains
[sn0int][demo] > autonoscope add domain example.com
[sn0int][demo] > # except subdomains of prod.example.com
[sn0int][demo] > autoscope add domain prod.example.com
[sn0int][demo] >
[sn0int][demo] > autonoscope list
scope domain "prod.example.com"
noscope domain "example.com"
[sn0int][demo] >
[sn0int][demo] > # this is going to be out-of-scope
[sn0int][demo] > add subdomain www.example.com
[sn0int][demo] > # this is going to be in-scope
[sn0int][demo] > add subdomain db.prod.example.com
[sn0int][demo] >
[sn0int][demo] > select subdomains
#1, "www.example.com"
#2, "db.prod.example.com"
[sn0int][demo] > select subdomains where unscoped=0
#2, "db.prod.example.com"
[sn0int][demo] > select subdomains where unscoped=1
#1, "www.example.com"
[sn0int][demo] >
Domains
-------
Autonoscope rules for domains are applied to the following structs:
- domains
- subdomains
- urls
Example rules::
autonoscope add domain example.com
autonoscope add domain staging.example.com
autonoscope add domain com
autonoscope add domain .
IPs
---
Autonoscope rules for IPs are applied to the following structs:
- ipaddrs
- netblocks
- ports
Example rules::
autonoscope add ip 0.0.0.0/0
autonoscope add ip ::/0
autonoscope add ip 192.168.0.0/16
autonoscope add ip 10.13.33.37/32
URLs
----
Autonoscope rules for urls are applied to the following structs:
- urls
Note that these rules are specific to a certain origin (like
``https://example.com``) and are used to filter paths.
Example rules::
autonoscope add url https://example.com/
autonoscope add url https://example.com/admin/
autonoscope add url https://example.com/a/b/c/d

83
docs/build.rst Normal file
View File

@@ -0,0 +1,83 @@
Build from source
=================
It's generally recommended to `install a package <install.html>`_ if available.
This section is about building the binary from git.
Install dependencies
--------------------
You need a recent rust compiler. It's usually recommended to install a rust
compiler with `rustup <https://rustup.rs/>`_, but if you're system ships the
most recent compiler in a package that works too. Note that some systems aren't
fully supported by rustup (like OpenBSD and alpine) and you need to install
rust from a package in that case.
Archlinux
~~~~~~~~~
.. code-block:: bash
$ pacman -S geoip2-database libseccomp libsodium publicsuffix-list sqlite
Mac OSX
~~~~~~~
.. code-block:: bash
$ brew install libsodium
Debian/Ubuntu/Kali
~~~~~~~~~~~~~~~~~~
.. code-block:: bash
$ apt install build-essential libsqlite3-dev libseccomp-dev libsodium-dev publicsuffix pkg-config
.. warning::
On a debian based system make sure you've installed rust with rustup.
Alpine
~~~~~~
.. code-block:: bash
$ apk add sqlite-dev libseccomp-dev libsodium-dev
Docker
~~~~~~
.. code-block:: bash
$ DOCKER_BUILDKIT=1 docker build -t kpcyrd/sn0int .
OpenBSD
~~~~~~~
.. code-block:: bash
$ pkg_add sqlite3 geolite2-city geolite2-asn libsodium
Gentoo
~~~~~~
.. code-block:: bash
emerge --ask sys-libs/libseccomp dev-db/sqlite dev-libs/libsodium
Windows
~~~~~~~
You don't need to install any dependencies on windows, but you need to use a
different build command in the next section.
Building
--------
After all dependencies have been installed, simply build the binary:
.. code-block:: bash
$ cargo build --release
After the build finished the binary is located at ``target/release/sn0int``.

173
docs/conf.py Normal file
View File

@@ -0,0 +1,173 @@
# -*- coding: utf-8 -*-
#
# Configuration file for the Sphinx documentation builder.
#
# This file does only contain a selection of the most common options. For a
# full list see the documentation:
# http://www.sphinx-doc.org/en/master/config
# -- Path setup --------------------------------------------------------------
# If extensions (or modules to document with autodoc) are in another directory,
# add these directories to sys.path here. If the directory is relative to the
# documentation root, use os.path.abspath to make it absolute, like shown here.
#
# import os
# import sys
# sys.path.insert(0, os.path.abspath('.'))
# -- Project information -----------------------------------------------------
project = 'sn0int'
copyright = '2018-2020, kpcyrd'
author = 'kpcyrd'
# The short X.Y version
version = ''
# The full version, including alpha/beta/rc tags
release = ''
# -- General configuration ---------------------------------------------------
# If your documentation needs a minimal Sphinx version, state it here.
#
# needs_sphinx = '1.0'
# Add any Sphinx extension module names here, as strings. They can be
# extensions coming with Sphinx (named 'sphinx.ext.*') or your custom
# ones.
extensions = [
]
# Add any paths that contain templates here, relative to this directory.
templates_path = ['_templates']
# The suffix(es) of source filenames.
# You can specify multiple suffix as a list of string:
#
# source_suffix = ['.rst', '.md']
source_suffix = '.rst'
# The master toctree document.
master_doc = 'index'
# The language for content autogenerated by Sphinx. Refer to documentation
# for a list of supported languages.
#
# This is also used if you do content translation via gettext catalogs.
# Usually you set "language" from the command line for these cases.
language = None
# List of patterns, relative to source directory, that match files and
# directories to ignore when looking for source files.
# This pattern also affects html_static_path and html_extra_path.
exclude_patterns = ['_build', 'Thumbs.db', '.DS_Store']
# The name of the Pygments (syntax highlighting) style to use.
pygments_style = None
# -- Options for HTML output -------------------------------------------------
# The theme to use for HTML and HTML Help pages. See the documentation for
# a list of builtin themes.
#
html_theme = 'default'
# Theme options are theme-specific and customize the look and feel of a theme
# further. For a list of options available for each theme, see the
# documentation.
#
# html_theme_options = {}
# Add any paths that contain custom static files (such as style sheets) here,
# relative to this directory. They are copied after the builtin static files,
# so a file named "default.css" will overwrite the builtin "default.css".
html_static_path = ['_static']
# Custom sidebar templates, must be a dictionary that maps document names
# to template names.
#
# The default sidebars (for documents that don't match any pattern) are
# defined by theme itself. Builtin themes are using these templates by
# default: ``['localtoc.html', 'relations.html', 'sourcelink.html',
# 'searchbox.html']``.
#
# html_sidebars = {}
# -- Options for HTMLHelp output ---------------------------------------------
# Output file base name for HTML help builder.
htmlhelp_basename = 'sn0intdoc'
# -- Options for LaTeX output ------------------------------------------------
latex_elements = {
# The paper size ('letterpaper' or 'a4paper').
#
# 'papersize': 'letterpaper',
# The font size ('10pt', '11pt' or '12pt').
#
# 'pointsize': '10pt',
# Additional stuff for the LaTeX preamble.
#
# 'preamble': '',
# Latex figure (float) alignment
#
# 'figure_align': 'htbp',
}
# Grouping the document tree into LaTeX files. List of tuples
# (source start file, target name, title,
# author, documentclass [howto, manual, or own class]).
latex_documents = [
(master_doc, 'sn0int.tex', 'sn0int Documentation',
'kpcyrd', 'manual'),
]
# -- Options for manual page output ------------------------------------------
# One entry per manual page. List of tuples
# (source start file, name, description, authors, manual section).
man_pages = [
('man', 'sn0int', 'Semi-automatic OSINT framework and package manager',
[author], 1)
]
# -- Options for Texinfo output ----------------------------------------------
# Grouping the document tree into Texinfo files. List of tuples
# (source start file, target name, title, author,
# dir menu entry, description, category)
texinfo_documents = [
(master_doc, 'sn0int', 'sn0int Documentation',
author, 'sn0int', 'One line description of project.',
'Miscellaneous'),
]
# -- Options for Epub output -------------------------------------------------
# Bibliographic Dublin Core info.
epub_title = project
# The unique identifier of the text. This can be a ISBN number
# or the project homepage.
#
# epub_identifier = ''
# A unique identification for the text.
#
# epub_uid = ''
# A list of files that should not be packed into the epub file.
epub_exclude_files = ['search.html']

54
docs/config.rst Normal file
View File

@@ -0,0 +1,54 @@
Configuration
=============
This section documents the config file. By default this file does not exist and
a default configuration is used instead.
Linux/BSD
``~/.config/sn0int.toml``
OSX
``~/Library/Preferences/sn0int.toml``
Windows
``%APPDATA%/sn0int.toml``
[core]
------
``registry``
Configure the registry you want to use. Defaults to ``https://sn0int.com``.
``no-autoupdate``
sn0int is going to check if your modules are outdated during startout once
a week. Set this option to ``true`` to disable this.
[namespaces]
------------------
By default sn0int modules are assumed to be installed from the registry. You
may want to keep a local directory with private modules, especially during
development. You can configure a folder that contains modules that aren't
managed by sn0int by adding a namespace section to the config file::
[namespaces]
foo = "/opt/sn0int/foo"
bar = "~/repos/a/b/c/sn0int-modules"
This is going to load modules from these two folders and register them in the
``foo`` and ``bar`` namespace.
Note that sn0int is also going to assume that symlinks in
``~/.local/share/sn0int/modules`` and folders containing a ``.git`` folder are
externally managed.
[network]
---------
To enable a proxy, add the following to your config file::
[network]
proxy = "127.0.0.1:9050"
This forces everything through tor (or any other socks5 proxy) and restricts
all other functions that depend on the network. For example the ``dns``
function is fully disabled if a proxy is configured.

123
docs/database.rst Normal file
View File

@@ -0,0 +1,123 @@
Database
========
There are a few things you need to understand how the database works to use it
efficiently.
The database that is backing sn0int is sqlite, but the api that is exposed to
the user and scripts is an nosql-ish object store. The query language that is
exposed to the user is still very similar to sql, except that it lacks a column
statement::
select subdomains where value like %.example.com
^ ^ ^ ^ ^
| | | | this value is going to be quoted automatically
| | | |
| | | this triggers automatic quoting
| | |
| | apply a filter, this translates to sql quite literally
| |
| the entity we want to select is a subdomain.
| this affects the table and the deserializer
|
select entities
This is how almost all user facing functions work that operate on the database.
The functions that are available for scripting are a bit more object based and
described below.
db_add
------
This operation is somewhat straight forward. It adds an entity to the
database:
.. code-block:: lua
domain_id = db_add('domain', {
value='example.com',
})
If this entity conflicts with an entity that already exists, an upsert is
triggered and an db_update is performed instead.
.. note::
This function may return ``nil`` if the entity already exists, but has been
removed from scope with ``noscope``. Everytime you use ``db_add`` you need
to make sure that the ID that has been returned is not ``nil``.
db_add_ttl
----------
Add a temporary entity to the database. This is commonly used to insert
temporary links that automatically expire over time. If the entity already
exists and is also marked as temporary the new ttl is going to replace the old
ttl. If the entity already exists but never expires we are not going to add a
ttl.
.. code-block:: lua
-- this link is valid for 2min
domain_id = db_add_ttl('network-device', {
network_id=1,
device_id=13,
}, 120)
db_activity
-----------
Log an activity event. A basic event looks like this:
.. code-block:: lua
db_activity({
topic='harness/activity-ping:dummy',
time=sn0int_time(),
content={
a='b',
foo={
bar=1337,
},
msg='ohai',
},
})
This function is explained in detail in the `activity <activity.html>`_
section.
db_update
---------
Update some mutable fields of an entity:
.. code-block:: lua
db_update('ipaddr', arg, {
asn=lookup['asn'],
as_org=lookup['as_org'],
})
The first parameter is usually the same arg that your script was called with.
Usually you can use db_add instead of db_update due to the upsert feature, but
db_update is still slightly faster.
.. note::
Some fields are immutable and can not be updated.
db_select
---------
This function is used to check if something is in scope. If the entity has been
added to the database and has not been removed from scope, this function
returns that entities id. This is somewhat similar to ``db_add``, except that
``db_select`` never adds anything to the database.
.. code-block:: lua
domain_id = db_select('domain', 'example.com')
if domain_id ~= nil then
-- do something
end
This function only accepts a string instead of a lua table. This string is used
to filter on the ``value`` column.

50
docs/index.rst Normal file
View File

@@ -0,0 +1,50 @@
sn0int
======
sn0int is a semi-automatic OSINT framework and package manager. It was built
for IT security professionals and bug hunters to gather intelligence about a
given target or about yourself. sn0int is enumerating attack surface by
semi-automatically processing public information and mapping the results in a
unified format for followup investigations.
Among other things, sn0int is currently able to:
- Harvest subdomains from certificate transparency logs
- Harvest subdomains from various passive dns logs
- Sift through subdomain results for publicly accessible websites
- Harvest emails from pgp keyservers
- Enrich ip addresses with ASN and geoip info
- Harvest subdomains from the wayback machine
- Gather information about phonenumbers
- Bruteforce interesting urls
sn0int is heavily inspired by recon-ng and maltego, but remains more flexible
and is fully opensource. None of the investigations listed above are hardcoded
in the source, instead those are provided by modules that are executed in a
sandbox. You can easily extend sn0int by writing your own modules and share
them with other users by publishing them to the sn0int registry. This allows
you to ship updates for your modules on your own since you don't need to send a
pull request.
Join us on IRC: `irc.hackint.org:6697/#sn0int <https://webirc.hackint.org/#irc://irc.hackint.org/#sn0int>`_
Getting Started
---------------
.. toctree::
:maxdepth: 3
:glob:
install
build
usage
autonoscope
scripting
database
structs
activity
notifications
keyring
config
sandbox
reference

113
docs/install.rst Normal file
View File

@@ -0,0 +1,113 @@
Installation
============
If available, please prefer the package shipped by operating system. If your
operating system has a package but you're running on older version, please use
the `build from source <build.html>`_ instructions instead.
Archlinux
---------
.. code-block:: bash
$ pacman -S sn0int
Mac OSX
-------
.. code-block:: bash
$ brew install sn0int
Debian >= bullseye, Ubuntu >= 20.04, Kali
-----------------------------------------
There are prebuilt packages signed by a debian maintainer. We can import the
key for this repository out of the debian keyring.
.. code-block:: bash
$ sudo apt install debian-keyring
$ gpg -a --export --keyring /usr/share/keyrings/debian-maintainers.gpg kpcyrd@archlinux.org | sudo tee /etc/apt/trusted.gpg.d/apt-vulns-sexy.gpg
$ echo deb http://apt.vulns.sexy stable main | sudo tee /etc/apt/sources.list.d/apt-vulns-sexy.list
$ sudo apt update
$ sudo apt install sn0int
Debian <= buster, Ubuntu <= 19.10
---------------------------------
There are prebuilt packages signed by a debian maintainer. We can import the
key for this repository out of the debian keyring.
.. code-block:: bash
$ sudo apt install debian-keyring
$ gpg -a --export --keyring /usr/share/keyrings/debian-maintainers.gpg git@rxv.cc | sudo apt-key add -
$ sudo apt-key adv --keyserver keyserver.ubuntu.com --refresh-keys git@rxv.cc
$ echo deb http://apt.vulns.sexy stable main | sudo tee /etc/apt/sources.list.d/apt-vulns-sexy.list
$ sudo apt update
$ sudo apt install sn0int
Fedora/CentOS/Redhat
--------------------
Using rust+cargo from the repos might work for you, but we only officially
support rust+cargo installed with `rustup <https://rustup.rs/>`_. Have a look
at the docker image as an alternative.
.. code-block:: bash
$ dnf install @development-tools libsq3-devel libseccomp-devel libsodium-devel publicsuffix-list
$ git clone https://github.com/kpcyrd/sn0int.git
$ cd sn0int
$ cargo install -f --path .
Docker
------
.. code-block:: bash
$ docker run --rm --init -it -v "$PWD/.cache:/cache" -v "$PWD/.data:/data" kpcyrd/sn0int
Alpine
------
.. code-block:: bash
$ apk add sn0int
OpenBSD
-------
.. code-block:: bash
$ pkg_add sn0int
Gentoo
------
.. code-block:: bash
$ layman -a pentoo
$ emerge --ask net-analyzer/sn0int
NixOS
-----
.. code-block:: bash
$ nix-env -i sn0int
Windows
-------
This is not recommended and only passively maintained. Please prefer linux in a
virtual machine if needed.
Make sure rust is installed and setup.
.. code-block:: bash
$ git clone https://github.com/kpcyrd/sn0int.git
$ cd sn0int
$ cargo install -f --path .

77
docs/keyring.rst Normal file
View File

@@ -0,0 +1,77 @@
Keyring
=======
A common problem is that you need either an api key or a username/password
combination. Instead of hardcoding it in the script you should request them
from the keyring. In order to do this you need to request permissions to those
credentials.
Managing the keyring
--------------------
The keyring is a simple namespaced key-value store::
[sn0int][default] > keyring add aws:AKIAIOSFODNN7EXAMPLE
Secretkey: keep-this-secret
[sn0int][default] > keyring list
aws:AKIAIOSFODNN7EXAMPLE
[sn0int][default] >
[sn0int][default] > keyring list aws
aws:AKIAIOSFODNN7EXAMPLE
[sn0int][default] > keyring list instagram
[sn0int][default] >
[sn0int][default] > keyring get aws:AKIAIOSFODNN7EXAMPLE
Namespace: "aws"
Access Key: "AKIAIOSFODNN7EXAMPLE"
Secret: "keep-this-secret"
[sn0int][default] >
If the service uses a username-password combination, set the username as the
access key and the password as the secret.
If the service uses only a secret key for the api, set the secret key as the
access key and leave the secret blank.
A script doesn't automatically get access to requested keyring namespaces.
Instead the user is asked to confirm those requests to limit abusive scripts.
Using access keys in scripts
----------------------------
We can request all keys of a certain namespace in our script metadata. This is
going to prompt the user to grant the script access. This can be done for
multiple namespaces in the same script:
.. code-block:: lua
-- Keyring-Access: aws
-- Keyring-Access: asdf
If the user granted us access to those keys we can read them with ``keyring``:
.. code-block:: lua
creds = keyring('aws')
debug(creds[1]['access_key'])
debug(creds[1]['secret_key'])
This returns a list of all keys in that namespace. Any empty list is returned
if the user doesn't have any keys in that namespace.
If you want to allow the user to select a specific script you can introduce an
option that is set by the user and then filter ``creds`` until the
``access_key`` matches.
Using access keys as source argument
------------------------------------
We can also use the access keys as source argument. This is useful if each
account has access to different things and we want to read through all of them.
Since access key permissions are granted per namespace we need to specify which
credentials we want to use.
.. code-block:: lua
-- Keyring-Access: aws
-- Source: keyring:aws

35
docs/make.bat Normal file
View File

@@ -0,0 +1,35 @@
@ECHO OFF
pushd %~dp0
REM Command file for Sphinx documentation
if "%SPHINXBUILD%" == "" (
set SPHINXBUILD=sphinx-build
)
set SOURCEDIR=.
set BUILDDIR=_build
if "%1" == "" goto help
%SPHINXBUILD% >NUL 2>NUL
if errorlevel 9009 (
echo.
echo.The 'sphinx-build' command was not found. Make sure you have Sphinx
echo.installed, then set the SPHINXBUILD environment variable to point
echo.to the full path of the 'sphinx-build' executable. Alternatively you
echo.may add the Sphinx directory to PATH.
echo.
echo.If you don't have Sphinx installed, grab it from
echo.http://sphinx-doc.org/
exit /b 1
)
%SPHINXBUILD% -M %1 %SOURCEDIR% %BUILDDIR% %SPHINXOPTS%
goto end
:help
%SPHINXBUILD% -M help %SOURCEDIR% %BUILDDIR% %SPHINXOPTS%
:end
popd

14
docs/man.rst Normal file
View File

@@ -0,0 +1,14 @@
:orphan:
sn0int
======
todo
.. toctree::
:maxdepth: 3
:glob:
usage
config
reference

311
docs/notifications.rst Normal file
View File

@@ -0,0 +1,311 @@
Notifications
=============
If you run sn0int unattended nobody might see the sn0int output. For cases like
this you can configure notifications to send you a push notification in case
something interesting happens. This is also especially useful if you have
sn0int setup to run automatically.
Receiving notifications
-----------------------
Notifications are just regular sn0int modules. You can install them just like
any other module or write your own. This section contains walkthroughs on how
to setup common integrations.
Telegram
~~~~~~~~
Install the telegram notification module from the registry:
.. code-block:: bash
sn0int pkg install kpcyrd/notify-telegram
Open your telegram app and open a chat with ``@botfather``. Send ``/newbot``
and answer the questions. Copy ``bot_token`` and open this url in your browser:
.. code-block::
https://api.telegram.org/bot**your_bot_token**/getUpdates
Back on your app, open the t.me link to start a new chat with your bot, then
send ``/start``. Reload the page in your browser, you should see the new
message you sent. Copy the ``chat_id``.
Test your tokens are working correctly by sending yourself a notification:
.. code-block:: bash
sn0int notify exec kpcyrd/notify-telegram -o bot_token=1337:foobar -o chat_id=1337 'hello world'
You should receive ``hello world`` from your bot on Telegram.
Pushover
~~~~~~~~
Install the pushover notification module from the registry:
.. code-block:: bash
sn0int pkg install kpcyrd/notify-pushover
Signup for pushover and configure the app on your device. Copy th user key
visible on the pushover dashboard. Click "Create an Application/API Token". Set
"sn0int" as name and set an icon if you want to. Copy the api token.
Test your tokens are working correctly by sending yourself a notification:
.. code-block:: bash
sn0int notify exec kpcyrd/notify-pushover -o user_key=asdf1337 -o api_token=asdf1337 'hello world'
You should receive ``hello world`` as a push notification.
Discord
~~~~~~~
Install the discord notification module from the registry:
.. code-block:: bash
sn0int pkg install kpcyrd/notify-discord
Decide which channel should receive notifications (or create a new one). Open
the "Server Settings" of your discord server. Click on "Webhooks". Click
"Create Webhook". Configure the Name and Channel. Copy the Webhook URL.
Test your tokens are working correctly by sending yourself a notification:
.. code-block:: bash
sn0int notify exec kpcyrd/notify-discord -o url=https://discord.com/api/webhooks/1337/asdf 'hello world'
You should receive ``hello world`` in your discord channel.
Signal
~~~~~~
Install the sn0int notification module from the registry:
.. code-block:: bash
sn0int pkg install kpcyrd/notify-signal
This module allows end-to-end encrypted notifications, but it's also difficult
to setup. You need a second phone number and install both `signal-cli
<https://github.com/AsamK/signal-cli>`_ and `sn0int-signal
<https://github.com/kpcyrd/sn0int-signal>`_.
After you've registered your second phone number with signal-cli, you can use
sn0int-signal to expose a minimal api for notify-signal. For more detailed
instructions and how to start the api at boot, see the `sn0int-signal README
<https://github.com/kpcyrd/sn0int-signal>`_.
Read the secret key generated at ``/etc/sn0int-signal.key`` and send a
notification to the signal phone number:
.. code-block:: bash
sn0int notify exec kpcyrd/notify-signal -o to=+31337 -o secret=asdf 'hello world'
You should receive ``hello world`` from the number signed up with signal-cli.
Writing your own module
~~~~~~~~~~~~~~~~~~~~~~~
Make sure you've read the detailed instructions on how to get setup with
`module development <scripting.html>`_.
Create a new sn0int module like this:
.. code-block:: bash
sn0int new ~/repos/sn0int-modules/notify-custom.lua
Edit the ``-- Source:`` so it takes notifications as input:
.. code-block:: lua
-- Description: TODO your description here
-- Version: 0.1.0
-- License: GPL-3.0
-- Source: notifications
function run(arg)
-- TODO your code here
-- https://sn0int.readthedocs.io/en/stable/reference.html
debug(arg)
info(arg['subject'])
info(arg['body'])
end
Execute your script:
.. code-block:: bash
sn0int notify exec notify-custom 'hello world'
You most likely need to pass options to avoid hard-coding keys into your
script. Options can be fetched like this:
.. code-block:: lua
-- Description: TODO your description here
-- Version: 0.1.0
-- License: GPL-3.0
-- Source: notifications
function run(arg)
-- TODO your code here
-- https://sn0int.readthedocs.io/en/stable/reference.html
local foo = getopt('foo')
if not foo then return 'Missing -o foo= option' end
info('foo: ' .. foo)
info('subject: ' .. arg['subject'])
end
And passed like this:
.. code-block:: bash
sn0int notify exec notify-custom -o "foo=hello world" 'ohai'
Setting up notification rules
-----------------------------
We now know how to trigger notifications manually, but we would rather trigger
notifications if a module runs into something interesting.
You can setup subscriptions on specific topics and then have a notification
script execute automatically.
Lookup the location of your sn0int config file:
.. code-block:: bash
sn0int paths
And open it in an editor of your choice:
.. code-block:: bash
vim /home/user/.config/sn0int.toml
A basic configuration could look like this:
.. code-block:: toml
# You can have multiple notification sections, this one is named
# `demo-telegram-integration`
# The label can be set to whatever you want, but you may need to add
# double-quotes to use some characters.
[notifications.demo-telegram-integration]
# If this option is present, the notification must originate from one of
# the following workspaces.
workspaces = ["default", "some-workspace"]
# If this option is present, the notification must match one of the
# filters. You can use `*` as a wildcard to match everything except `:`.
topics = ["activity:harness/activity-ping:*"]
# Mandatory: the module to execute.
script = "kpcyrd/notify-telegram"
# The options to pass to the module, if any.
# Can be accessed with `getopt`
options = [
"bot_token=1337:foobar",
"chat_id=1337",
]
All options except ``script`` are optional, but setting filters is highly
recommended.
Testing notifications
---------------------
To test if your configuration works correctly you can create an event manually:
.. code-block:: bash
sn0int -w some-workspace notify send activity:harness/activity-ping:dummy "hello world"
If it matches any of your rules you should receive a push notifications.
.. note::
If you want to test just the routing without actually sending something, add ``--dry-run``.
Running sn0int automatically
----------------------------
Support for this is going to improve in the future, but you can already set
this up if you're ok with a slightly buggy experience.
Monitors
~~~~~~~~
Some modules are long-running and either wait for an event from a server or
have custom polling built in that's usually configurable with an ``-o
interval=`` option. If your module has a non-trivial setup phase, an author may
take this approach.
.. code-block::
# /etc/systemd/system/sn0int-your-new-service.service
[Unit]
Description=sn0int: run example/changeme
[Service]
User=your-user
ExecStart=/usr/bin/sn0int run -w your-workspace example/changeme
Restart=always
RestartSec=0
[Install]
WantedBy=multi-user.target
Enable the service to run on boot:
.. code-block:: bash
systemctl enable --now sn0int-your-new-service.service
Timers
~~~~~~
If the module is only one-shot you can set it up to run with a timer:
.. code-block::
# /etc/systemd/system/sn0int-your-other-service.service
[Unit]
Description=sn0int: run example/changeme
[Service]
User=your-user
ExecStart=/usr/bin/sn0int run -w your-workspace example/changeme
Setup the timer like this:
.. code-block::
# /etc/systemd/system/sn0int-your-other-service.timer
[Unit]
Description=sn0int: run example/changeme
[Timer]
OnBootSec=1min
OnUnitActiveSec=1h
[Install]
WantedBy=timers.target
.. code-block:: bash
systemctl enable --now sn0int-your-other-service.timer

1531
docs/reference.rst Normal file

File diff suppressed because it is too large Load Diff

147
docs/sandbox.rst Normal file
View File

@@ -0,0 +1,147 @@
Sandbox
=======
Scripts are generally considered to be untrusted and executed exclusively in a
child process. It's important to note that there's a basic sandbox that's
active on every operating system, and there's a second line of defense on
supported operating systems.
The first line of defense is the restrictive stdlib. It's assumed that an
attacker gains full control over the lua code and is able to call any function
with arbitrary arguments. The stdlib only provides functions that are
considered safe, so for example it's not possible to start a process or open a
file.
The second line of defense is supposed to make sure the system isn't
compromised even if the first layer is fully broken and an attacker gains full
control over the child process.
Right now this is only supported on linux and openbsd.
Linux
-----
On linux we use seccomp to filter all syscalls that we don't need. We also use
chroot to disable filesystem access. It's recommended to install the sn0int
binary with ``cap_sys_chroot`` to make sure unprivileged users can use chroot.
The chroot location is hard coded and all capabilities are removed after the
chroot is done or if no chroot is going to happen.
OpenBSD
-------
On openbsd we're using ``pledge`` to restrict syscalls and ``unveil`` to
restrict filesystem access.
IPC Protocol
------------
The parent process and the child process communicate using an IPC protocol that
is line-based json.
For a simple hello world the parent process is only going to send a single line
to the child process. This line contains:
- The function argument
- The dns config
- Keys that the module has been given access to
- The module metadata and code
- Options, if any
- A socks5 proxy, if any
- The log level
.. code-block:: json
{"arg":null,"dns_config":{"ns":["1.1.1.1:53","1.0.0.1:53"],"tcp":false,"timeout":{"nanos":0,"secs":3}},"keyring":[],"module":{"author":"anonymous","description":"basic selftest","keyring_access":[],"name":"selftest","script":{"code":"-- Description: basic selftest\n-- Version: 0.1.0\n-- License: GPL-3.0\n\nfunction run()\n -- nothing to do here\nend\n"},"source":null,"version":"0.1.0"},"options":{},"proxy":null,"verbose":2}
Saving this line in a file called ``start.json`` and sending it to a sandbox
process should result in the following output::
$ sn0int sandbox foobar < start.json
{"Exit":"Ok"}
$
This line tells us that the script terminated successfully.
There are some functions that cause a notification to the parent process. We
are going to add a call to the ``info()`` function to our module:
.. code-block:: json
{"arg":null,"dns_config":{"ns":["1.1.1.1:53","1.0.0.1:53"],"tcp":false,"timeout":{"nanos":0,"secs":3}},"keyring":[],"module":{"author":"anonymous","description":"basic selftest","keyring_access":[],"name":"selftest","script":{"code":"-- Description: basic selftest\n-- Version: 0.1.0\n-- License: GPL-3.0\n\nfunction run()\n info('ohai')\nend\n"},"source":null,"version":"0.1.0"},"options":{},"proxy":null,"verbose":2}
This is going to print an additional event::
$ sn0int sandbox foobar < start2.json
{"Log":{"Info":"\"ohai\""}}
{"Exit":"Ok"}
$
There are some functions that block the child process until the parent process
sent a reply. These functions are mostly database related functions, since the
child doesn't have direct database access. To demonstrate this, we're going to
write two lines to our file this time, one is the init line and the second one
is the reply for the database event:
.. code-block:: json
{"arg":null,"dns_config":{"ns":["1.1.1.1:53","1.0.0.1:53"],"tcp":false,"timeout":{"nanos":0,"secs":3}},"keyring":[],"module":{"author":"anonymous","description":"basic selftest","keyring_access":[],"name":"selftest","script":{"code":"-- Description: basic selftest\n-- Version: 0.1.0\n-- License: GPL-3.0\n\nfunction run()\n x = db_add('domain', {value=\"example.com\"})\n info(x)\nend\n"},"source":null,"version":"0.1.0"},"options":{},"proxy":null,"verbose":2}
{"Ok":1337}
Results in the following output::
$ target/release/sn0int sandbox foobar < start3.json
{"Database":{"Insert":{"Domain":{"value":"example.com"}}}}
{"Log":{"Info":"1337.0"}}
{"Exit":"Ok"}
$
The first line is a database event and indicates that the child wants to insert
data. After printing this line the child tries to read a line from stdin, this
is why we needed to write two lines to our json file this time. In the second
line the child learns if the insert was successful and which id was assigned to
that entity.
Limitations
-----------
There are some limitations that you should be aware:
- Network access is available and network namespaces aren't isolated. This
means scripts have access to your local network, the internet and also your
localhost loopback interface.
- If chroot is unavailable an attacker could connect to unix domain sockets.
Diagnosing a sandbox failure
----------------------------
You might experience a sandbox failure, especially on architectures that are
less popular. This usually looks like this::
[sn0int][example][kpcyrd/ctlogs] > run
[-] Failed "example.com": Sandbox child has crashed
[+] Finished kpcyrd/ctlogs (1 errors)
A module that never finishes could also mean an IO thread inside the worker got
killed by the sandbox.
You can try to diagnose this yourself with strace::
strace -f sn0int run -vv ctlogs 2>&1 | tee strace.log
Open ``strace.log``, look out for syscalls that didn't return by searching for
``= ?`` and ignore calls to exit and similar. You are looking for something
like this::
seccomp(SECCOMP_SET_MODE_FILTER, 0, {len=48, filter=0xdd59094e490}) = 0
write(1, "[+] activated!\n", 15[+] activated!
) = 15
getresuid( <unfinished ...>) = ?
+++ killed by SIGSYS (core dumped) +++
This would indicate a call to ``getresuid`` which was not allowed by the
seccomp filter.
If you don't want to diagnose this yourself open a new bug report with as much
information as possible, specifically which distro, which release and which
architecture you're using.

262
docs/scripting.rst Normal file
View File

@@ -0,0 +1,262 @@
Writing your first module
=========================
Scripting is the core feature in sn0int. It's not strictly required, but if you
want to write your own modules, this section is for you.
Creating a repository
---------------------
It's highly recommended to use a VCS for development, so let's start by setting
that up. We're going to assume you store your repos in ``~/repos`` but you're
free to change that to something else::
$ git init ~/repos/sn0int-modules
$ cd ~/repos/sn0int-modules
.. note::
If you're using github you can also create a repo from the `module repo
template`_.
.. _module repo template: https://github.com/sn0int/sn0int-modules
We need to add this folder to the sn0int config file so it's correctly detected
when starting sn0int. Open the `config file <config.html>`_ in your prefered
editor. Note that the file does not exist by default and the path is different
depending on your operating system. On linux you would open the config file
with::
$ vim ~/.config/sn0int.toml
Add the following::
[namespaces]
your_github_name = "~/repos/sn0int-modules"
Every module we're adding to ``~/repos/sn0int-modules`` is now going to be
picked up by sn0int.
Make sure you're still in the right folder and add your first module::
sn0int new first.lua
This is going to generate some boilerplate for you that every module needs to
load successfully. Afterwards we can edit it like this:
.. code-block:: lua
-- Description: ohai wurld
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
-- TODO: do something here
end
``Description`` (mandatory)
This should be a short text that describes what your module is doing.
``Version`` (mandatory)
Every module requires a semver_ version. You can just set it to ``0.1.0``
during development, but you need to increase it every time you publish your
module. If you don't care about that one, just keep increasing ``0.X.0``.
.. _semver: https://semver.org/
``Source`` (mandatory)
This is going to specify what kind of entities we're interested in. If we
specify ``domains`` our module is going to be called with all domains that
are targeted.
- ``domains``
- ``subdomains``
- ``ipaddrs``
- ``urls``
- ``emails``
``License`` (mandatory)
This is somewhat special. We require that every module is licensed under an
open source license. Pick one of the following licenses.
- ``MIT`` - https://opensource.org/licenses/MIT
- ``GPL-3.0`` - https://opensource.org/licenses/gpl-license
- ``LGPL-3.0`` - https://opensource.org/licenses/lgpl-license
- ``BSD-2-Clause`` - https://opensource.org/licenses/BSD-2-Clause
- ``BSD-3-Clause`` - https://opensource.org/licenses/BSD-3-Clause
- ``WTFPL`` - https://spdx.org/licenses/WTFPL.html
``function run(arg)`` (mandatory)
This is where the actual magic of our module happens. Our function is going
to be called in a loop for each entity that is targeted by the user.
Let's continue. For the sake of an hello world we're going to take some
``domains``, check if a ``www`` subdomain exists and if it does, add it to the
database.
.. code-block:: lua
-- Description: Scan for www. subdomains
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
subdomain = 'www.' .. arg['value']
info(subdomain)
end
This is already enough to execute it. Make sure you've added a domain to scope
with ``add domain example.com``, save your file and run it like this::
sn0int run -f ./first.lua
We should see some output by our info function.
.. note::
``info`` is useful for development but you usually want your module to run
quietly, so before publishing either remove it or replace it with ``debug``.
Next, we want to actually resolve that name, we're going to use the ``dns``
function for that. This function takes a name and a query type and returns a
result. Note that this function might fail, in which case we want to abort our
function. We do that by checking if the return value of ``last_err()`` is
truth-y.
.. code-block:: lua
-- Description: Scan for www. subdomains
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
subdomain = 'www.' .. arg['value']
records = dns(subdomain, {
record='A'
})
if last_err() then return end
info(records)
end
If you run your module again you're going to see some output, either
``{"answers":[somedata],"error":null}`` or
``{"answers":[],"error":"NXDomain"}``. If the dns reply doesn't indicate an
error this means the subdomain exists and we can add it to our database with
``resolvable`` being set to ``true``.
.. code-block:: lua
-- Description: Scan for www. subdomains
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
subdomain = 'www.' .. arg['value']
records = dns(subdomain, {
record='A'
})
if last_err() then return end
if records['error'] == nil then
db_add('subdomain', {
domain_id=arg['id'],
value=subdomain,
resolvable=true,
})
end
end
.. hint::
See the database section to understand how the database works in detail.
If we execute our finished module one more time it's going to log that it
discovered a subdomain, if it doesn't, try adding more domains to scope. Note
that this only happens the first time. Modules that don't discover anything or
don't discover anything new exit silently.
There's still some room for improvement, for example, since we already resolved
that record, we could also add the ip address to the scope and link it to the
subdomain we added.
.. hint::
For debugging purposes you can increase the verbosity with ``sn0int run -v``
so database operations are logged even if nothing was changed, or with
``sn0int run -vv`` to enable ``debug()`` output.
Publish your module
-------------------
The public registry uses github usernames to namespace the registry. This means
you need to authenticate to the registry using your github username. This can
be done using::
sn0int login
sn0int is going to open a new tab in your browser, if you are already signed
into your github account you only need to confirm an authorization request. The
application doesn't need any of your data, so it's only asking you to confirm
your identity.
Afterwards publish your module with::
sn0int publish ./first.lua
Please also make sure you publish your repository to github so other people can
submit pull requests. The recommended repository location is::
https://github.com/<your-username>/sn0int-modules
Publish your repo
-----------------
It is highly recommended to publish your repository on github so people can
file issues and pull requests for your module. If you've been following along
with the github template you can simply commit your changes and push them.
Your repository would look like one of these:
- https://github.com/kpcyrd/sn0int-modules
- https://github.com/ysf/sn0int-modules
- https://github.com/cybiere/sn0int-modules
Reading data from stdin
-----------------------
Sometimes you need to read data that can't be easily accessed from within the
sandbox, like output of other programms or file content. In that case you can
write a module that reads from stdin:
.. code-block:: lua
-- Description: Read from stdin
-- Version: 0.1.0
-- License: GPL-3.0
function run()
while true do
x = stdin_readline()
if x == nil then
break
end
info(x)
end
end
Write it to a file and run it like this::
% echo hello | sn0int run --stdin -vvf stdin.lua
[*] anonymous/stdin : "hello\n"
[+] Finished anonymous/stdin
%
This is going to read one line at a time and allows you to process it with
regular expressions and add data to the database.
.. note::
If you get an error like ``Failed to read stdin: "stdin is unavailable"``
make sure the ``--stdin`` flag is set.

335
docs/structs.rst Normal file
View File

@@ -0,0 +1,335 @@
Structs
=======
This section describes all supported structs in depth. Please refer to this
section if in doubt about the correct usage of fields to ensure
interoperability between modules.
Domains
-------
Represents a registerable domain as defined by the `public suffix list
<https://publicsuffix.org/>`_. If in doubt check `psl_domain_from_dns_name
<reference.html#psl-domain-from-dns-name>`_.
``value``
The domain name, like ``example.co.uk``.
Subdomains
----------
A subdomain of a `domain <#domains>`_. The depth is arbitrary, so
``foo.example.co.uk`` and ``foo.bar.example.co.uk`` are both valid subdomains
of ``example.co.uk``.
``value``
The subdomain, like ``foo.bar.example.co.uk``.
``domain_id``
The numeric id of a domain struct.
``resolvable``
Whether the subdomain can be resolved to a A/AAAA record. nil if unknown.
IpAddrs
-------
An ip address. Note that most of these fields are geoip related and an
approximation instead of an actual location.
``value``
The ip address.
``family``
The address family of the ip address, either ``4`` or ``6``.
``continent``
The continent associated with this ip address.
``continent_code``
The continent code of the ``continent`` field, eg ``NA``.
``country``
The country associated with this ip address.
``country_code``
The country code of the ``country`` field, eg ``US``.
``city``
The city associated with this ip address.
``latitude``
Latitude associated with this ip address.
``longitude``
Longitude associated with this ip address.
``asn``
The number of the autonomous system this ip belongs to.
``as_org``
The organization of the autonomous system this ip belongs to.
``description``
This field is sn0int internal if we have additional information about this
ip address, for example technical identifiers from aws.
``reverse_dns``
The reverse dns name setup for this ip address.
URLs
----
``subdomain_id``
The numeric id of a subdomain struct.
``value``
The url, including a schema, hostname and path.
``status``
The http status code, like ``200``.
``body``
The raw response body. This can be any mime type.
``online``
Whether or not the url gives a http response (even if it's an error).
``title``
The parsed ``<title>`` of the page, if available.
``redirect``
If the server replied with a redirect, this is the url it redirected to.
Emails
------
``value``
The email address.
``displayname``
The display name of a given email address: ``this is the name <foo@example.com>``.
``valid``
Whether that email address is valid or has been disabled.
Phonenumbers
------------
``value``
The phone number in E.164 format (+491234567)
``name``
An alias we can assign to this phone number. This alias is sn0int internal.
``valid``
Whether the number is assigned to a customer.
``last_online``
The last time this number has been online.
``country``
The country this number is associated with.
``carrier``
The name of the carrier this numer is registered with.
``line``
The type of the phone number, can be ``landline``, ``mobile`` or ``voip``.
``is_ported``
Whether this number has been ported to a different carrier.
``last_ported``
The last time this number has been ported.
``caller_name``
The name of the owner of the phone number.
``caller_type``
The type of caller, eg ``business`` or ``consumer``.
Devices
-------
``value``
The devices mac address or another identifier if needed.
``name``
An alias we can assign to this device. This alias is sn0int internal.
``hostname``
The hostname configured on the device.
``vendor``
The hardware vendor of the device. This is usually derived from the mac
address.
``last_seen``
The last time we've observed the device somewhere.
Networks
--------
A wired or wireless network at a specific location that a device could be
connected to.
``value``
The network name. This can be an ssid or any other identifier but should be
unique.
``latitude``
Latitude of the networks location.
``longitude``
Longitude of the networks location.
``description``
A human readable description in case the value is a technical identifier.
Accounts
--------
A users account or profile on a webservice, like github or instagram.
``service``
The identifier of the service/website. It's recommended to use the websites
domain for this as defined in `Domains`_.
``username``
The users unique identifier, like the login name. If the login name is not
known or the system doesn't use login names, use the email address instead.
``displayname``
The users display name. This name is often not unique and may contain the
users real name.
``email``
The email address associated with the account.
``url``
The url of the public profile if available.
``last_seen``
The last time this account has been active/online.
``birthday``
The users birthday set on the account.
``phonenumber``
The phonenumber associated with the account.
``profile_pic``
The blob identifier of the users current profile picture.
Breaches
--------
Either a breach of a specific website, a breach compilation or a breach
notification service.
``value``
The name of the breach, breach compilation or notification service.
Images
------
``value``
The id that identifies the blob. This id is deterministic based on file
content.
``filename``
This field is used if we have a well known filename for the content.
``mime``
The image mimetype, like ``image/png`` or ``image/jpeg``.
``width``
The width of the image.
``height``
The height of the image.
``created``
The date and time this image has been taken.
``latitude``
Latitude this picture has been taken.
``longitude``
Longitude this picture has been taken.
``nudity``
A score that classifies nudity in this picture. The score goes from 0 to 2
and is commonly calculated with ``img_nudity``. A score above 1 means
nudity has been detected.
``ahash``
The Mean (aHash) perceptual hash.
``dhash``
The Gradient (dHash) perceptual hash.
``phash``
The DCT (pHash) perceptual hash.
Ports
-----
The status of a port on an ip address.
``ip_addr_id``
The numeric id of an ipaddr struct.
``ip_addr``
The actual ipaddr.
``port``
The port number.
``status``
The status of the port, either ``open`` or ``closed``.
``banner``
The service banner we discovered on this port.
``service``
The service that is running on this port.
``version``
The version of the service running on this port.
Netblocks
---------
A netblock is a network address range that has been allocated to an individual,
organization or company. Those are commonly found when running whois lookups on
an ip address.
Consider the following example: Running a whois lookup on ``140.82.118.4`` (one
of the addresses currently in use by github) returns that this address belongs
to the netrange ``140.82.112.0 - 140.82.127.255``, so the netblock in this case
is ``140.82.112.0/20``.
``family``
This is either ``4`` or ``6`` and populated automatically.
``value``
This is the network range in CIDR notation.
``asn``
The number of the autonomous system this network belongs to.
``as_org``
The organization of the autonomous system this network belongs to.
``description``
This field isn't strictly defined and meant to be used as a human
meaningful name if available.
CryptoAddrs
-----------
A cryptoaddr is any cryptocurrency address and not tied to a specific currency.
``value``
The address string. This looks like ``1BvBMSEYstWetqTFn5Au4m4GFg7xJaNVN2``.
``currency``
The identifier for a specific currency. This is usually the ticker symbols,
like ``xbt``, ``zec`` or ``xmr``.
``denominator``
Balance is tracked internally using 64 bit integers (signed, for technical reasons). Balance is supposed to be the lowest unit, so in case of bitcoin you'd write ``100,000,000`` satoshi instead of ``1`` bitcoin. Since this value is inconvinient to work with we're using the denominator to display values. In case of bitcoin you'd set it to ``8``.
``balance``
The current balance of the address, in the lowest possible unit. In case of bitcoin this would be satoshis.
``received``
The total amount of currency received by this address.
``first_seen``
The first time currency was sent to this address.
``last_withdrawal``
The last time a transaction signed by this address was observed.
``description``
A human readable note for this address.
Activity
--------
Activity is different from all other structs, have a look at the `Activity
Section <activity.html>`_.
Relations
---------
Relations are linking two structs together. The link may contain additional information.
subdomain_ipaddr
~~~~~~~~~~~~~~~~
Links an ip address to a subdomain.
``subdomain_id``
The numeric id of a subdomain struct.
``ip_addr_id``
The numeric id of an ip addr struct.
network_device
~~~~~~~~~~~~~~
Links a device to a network. This is commonly used with ``db_add_ttl`` so the
link automatically expires. This is frequently used to monitor networks for
known and unknown devices.
``network_id``
The numeric id of a network struct.
``device_id``
The numeric id of a device struct.
``ipaddr``
The ip address assigned to the device.
``last_seen``
The last time we've seen the device on that network.
breach_email
~~~~~~~~~~~~
Links an email to a breach. If we know the password as well we can add it to
the link. If we don't know the password we can leave it blank and fill it
later. An email can be linked to a breach multiple times with different
passwords. There is a special upserting logic in place to support this.
``breach_id``
The numeric id of a breach struct.
``email_id``
The numeric id of an email struct.
``password``
The password for that email in the breach.

258
docs/usage.rst Normal file
View File

@@ -0,0 +1,258 @@
Running your first investigation
================================
This page is going to guide you through the process of setting up your
environment and running your first investigation.
Installing the default modules
------------------------------
By default, sn0int doesn't have any modules installed. If you start up sn0int
it's going to download some files that it needs and then suggests to install a
number of recommended modules::
$ sn0int
___/ .
____ , __ .' /\ ` , __ _/_
( |' `. | / | | |' `. |
`--. | | |,' | | | | |
\___.' / | /`---' / / | \__/
osint | recon | security
irc.hackint.org:6697/#sn0int
[+] Connecting to database
[+] Downloading public suffix list
[+] Downloading "GeoLite2-City.mmdb"
[+] Downloading "GeoLite2-ASN.mmdb"
[+] Loaded 0 modules
[*] No modules found, run pkg quickstart to install default modules
[sn0int][default] >
Typing ``pkg quickstart`` is going to get you a fair number of featured modules::
[sn0int][default] > pkg quickstart
[+] Installing kpcyrd/asn
[+] Installing kpcyrd/ctlogs
[+] Installing kpcyrd/dns-resolve
[+] Installing kpcyrd/geoip
[+] Installing kpcyrd/hackertarget-subdomains
[+] Installing kpcyrd/otx-subdomains
[+] Installing kpcyrd/passive-spider
[+] Installing kpcyrd/pgp-keyserver
[+] Installing kpcyrd/threatminer-ipaddr
[+] Installing kpcyrd/threatminer-subdomains
[+] Installing kpcyrd/url-scan
[+] Installing kpcyrd/waybackurls
[+] Loaded 12 modules
[sn0int][default] >
Adding something to scope
-------------------------
You probably want to separate your investigations so you should select a
workspace where your results should go::
[sn0int][default] > workspace demo
[+] Connecting to database
[sn0int][demo] >
Next, we have to start somewhere and add the first entity to our scope::
[sn0int][demo] > add domain
Domain: example.com
[sn0int][demo] >
.. note::
There is a concept of a domain vs a subdomain. We are referring to a domain
as everything that is a subdomain of a `public suffix`_. For example, .com
is a public suffix, which makes example.com a domain in sn0int terms. Every
subdomain of that, like www.example.com, is referred to as a subdomain.
Note that example.com can be added as a subdomain as well since it can hold
records. In that case, example.com is both the name of the dns zone, while
also being an entity in that zone.
.. _public suffix: https://publicsuffix.org/
You can confirm this by running a select on the domains we now have::
[sn0int][demo] > select domains
#1, "example.com"
[sn0int][demo] >
Something we don't need right now, but is going to be useful later on is the
ability to filter your entities::
[sn0int][demo] > select domains where id=1
#1, "example.com"
[sn0int][demo] >
[sn0int][demo] > select domains where value like %.com
#1, "example.com"
[sn0int][demo] >
[sn0int][demo] > select domains where ( value like e% and value like %m ) or false
#1, "example.com"
[sn0int][demo] >
.. note::
Almost all entities have a ``value`` column that holds the primary value of
the entity.
Running a module
----------------
Now that we have something to get started with, we can run our first module.
First lets list all modules we have::
[sn0int][demo] > pkg list
kpcyrd/asn (0.1.0)
Run a asn lookup for an ip address
kpcyrd/ctlogs (0.1.0)
Query certificate transparency logs to discover subdomains
kpcyrd/dns-resolve (0.1.0)
Query subdomains to discovery ip addresses and verify the record is visible
kpcyrd/geoip (0.1.0)
Run a geoip lookup for an ip address
kpcyrd/hackertarget-subdomains (0.1.0)
Query hackertarget for subdomains of a domain
kpcyrd/otx-subdomains (0.1.0)
Query alienvault otx passive dns for subdomains of a domain
kpcyrd/passive-spider (0.1.0)
Scrape known http responses for urls
kpcyrd/pgp-keyserver (0.1.0)
Query pgp keyserver for email addresses
kpcyrd/threatminer-ipaddr (0.1.0)
Query ThreatMiner passive dns for subdomains of an ip address
kpcyrd/threatminer-subdomains (0.1.0)
Query ThreatMiner passive dns for subdomains of a domain
kpcyrd/url-scan (0.1.0)
Scan subdomains for websites
kpcyrd/waybackurls (0.1.0)
Discover subdomains from wayback machine
[sn0int][demo] >
Let's start by querying certificate transparency logs::
[sn0int][demo] > use ctlogs
[sn0int][demo][kpcyrd/ctlogs] > run
[*] "example.com" : Subdomain: "www.example.com"
[*] "example.com" : Subdomain: "m.example.com"
[*] "example.com" : Subdomain: "dev.example.com"
[*] "example.com" : Subdomain: "products.example.com"
[*] "example.com" : Subdomain: "support.example.com"
[+] Finished kpcyrd/ctlogs
[sn0int][demo][kpcyrd/ctlogs] >
Looks like we've discovered some subdomains here. It might be tempting to throw
some of them in a browser but hold on, there's a more efficient way to approach
this.
.. hint::
You can run the modules concurrently with ``run -j3``.
Running followup modules on the results
---------------------------------------
A lot of time has been spent on the database part. While it sort of feels like
a no-sql database we are actually enforcing a schema for a reason instead of
just using generic dictionaries and calling it a day.
It's crucial that entities created by one module can be picked up by another
module, like LEGOs. Let's continue with a module to query the dns records::
[sn0int][demo][kpcyrd/ctlogs] > use dns-resolve
[sn0int][demo][kpcyrd/dns-resolve] > run
[*] "www.example.com" : Updating "www.example.com" (resolvable => true)
[*] "www.example.com" : IpAddr: 93.184.216.34
[*] "www.example.com" : "www.example.com" -> 93.184.216.34
[*] "m.example.com" : Updating "m.example.com" (resolvable => false)
[*] "dev.example.com" : Updating "dev.example.com" (resolvable => false)
[*] "products.example.com" : Updating "products.example.com" (resolvable => false)
[*] "support.example.com" : Updating "support.example.com" (resolvable => false)
[+] Finished kpcyrd/dns-resolve
[sn0int][demo][kpcyrd/dns-resolve] >
.. TODO: mention https://github.com/kpcyrd/sn0int/issues/27
Two things happened here: We've discovered some IP addresses and added them to
scope, and we also updated our subdomain entities with new information, since
we now know which of them are resolvable and which aren't.
Let's run the next module, which is actually going to check for websites on
them, but let's only target subdomains that we know are resolvable::
[sn0int][demo][kpcyrd/dns-resolve] > use url-scan
[sn0int][demo][kpcyrd/url-scan] > target
#1, "www.example.com"
93.184.216.34
#2, "m.example.com"
#3, "dev.example.com"
#4, "products.example.com"
#5, "support.example.com"
[sn0int][demo][kpcyrd/url-scan] > target where resolvable
[+] 1 entities selected
[sn0int][demo][kpcyrd/url-scan] > target
#1, "www.example.com"
93.184.216.34
[sn0int][demo][kpcyrd/url-scan] >
We can both preview and limit the targets that are going to be passed to the
module with the target command. Once we are satisfied with our selection we can
run this module::
[sn0int][demo][kpcyrd/url-scan] > run
[*] "www.example.com" : Url: "http://www.example.com/" (200)
[*] "www.example.com" : Url: "https://www.example.com/" (200)
[+] Finished kpcyrd/url-scan
[sn0int][demo][kpcyrd/url-scan] >
We've now probed both port 80 and port 443 for each subdomain and found two
http responses this way. If you want a list of urls you may want to visit in
your browser can now query them::
[sn0int][demo][kpcyrd/url-scan] > select urls
#1, "http://www.example.com/" (200)
#2, "https://www.example.com/" (200)
[sn0int][demo][kpcyrd/url-scan] >
Unscoping entities
------------------
Something you are going to run into is that modules are too greedy and add
things to the scope we are not interested in. You can delete them using the
delete command, but those are likely picked up by a module again.
What you can do instead is setting a flag on an entity that removes it from
our scope. This is done using the noscope command::
[sn0int][demo] > use ctlogs
[sn0int][demo][kpcyrd/ctlogs] > target
#1, "example.com"
[sn0int][demo][kpcyrd/ctlogs] > add domain
Domain: google.com
[sn0int][demo][kpcyrd/ctlogs] > target
#1, "example.com"
#2, "google.com"
[sn0int][demo][kpcyrd/ctlogs] > noscope domains where value=google.com
[+] Updated 1 rows
[sn0int][demo][kpcyrd/ctlogs] > target
#1, "example.com"
[sn0int][demo][kpcyrd/ctlogs] >
Entities that are unscoped are automatically ignored by all modules.
You can reverse this using the scope command::
[sn0int][demo][kpcyrd/ctlogs] > target
#1, "example.com"
[sn0int][demo][kpcyrd/ctlogs] > scope domains where true
[+] Updated 2 rows
[sn0int][demo][kpcyrd/ctlogs] > target
#1, "example.com"
#2, "google.com"
[sn0int][demo][kpcyrd/ctlogs] >
.. hint::
All entities have this field, you can refer to it in queries using
``unscoped=1``.

View File

@@ -1,32 +0,0 @@
extern crate sn0int;
extern crate env_logger;
extern crate maxminddb;
use std::env;
use sn0int::errors::*;
use sn0int::geoip::{AsnDB, Maxmind};
fn run() -> Result<()> {
let asndb = AsnDB::open_or_download()?;
for arg in env::args().skip(1) {
let ip = arg.parse()?;
let asn = asndb.lookup(ip)?;
println!("{:#?}", asn);
}
Ok(())
}
fn main() {
env_logger::init();
if let Err(err) = run() {
eprintln!("Error: {}", err);
for cause in err.iter_chain().skip(1) {
eprintln!("Because: {}", cause);
}
std::process::exit(1);
}
}

View File

@@ -1,31 +0,0 @@
extern crate sn0int;
extern crate env_logger;
use std::env;
use sn0int::errors::*;
use sn0int::geoip::{GeoIP, Maxmind};
fn run() -> Result<()> {
let geoip = GeoIP::open_or_download()?;
for arg in env::args().skip(1) {
let ip = arg.parse()?;
let lookup = geoip.lookup(ip)?;
println!("{:#?}", lookup);
}
Ok(())
}
fn main() {
env_logger::init();
if let Err(err) = run() {
eprintln!("Error: {}", err);
for cause in err.iter_chain().skip(1) {
eprintln!("Because: {}", cause);
}
std::process::exit(1);
}
}

View File

@@ -1,45 +0,0 @@
extern crate sn0int;
extern crate env_logger;
extern crate chrootable_https;
#[macro_use] extern crate log;
extern crate structopt;
use sn0int::errors::*;
use sn0int::geoip::{GeoIP, Maxmind};
use sn0int::paths;
use std::fs;
use structopt::StructOpt;
#[derive(Debug, StructOpt)]
pub struct Args {
url: String,
filter: String,
target: String,
#[structopt(short="e", long="extract-only")]
extract_only: bool,
}
fn run() -> Result<()> {
let args = Args::from_args();
debug!("{:?}", args);
let path = paths::cache_dir()?.join(&args.target);
if args.extract_only {
let body = fs::read(&args.url)?;
sn0int::archive::extract(&mut &body[..], &args.filter, path)?;
} else {
GeoIP::download(path, &args.filter, &args.url)?;
}
Ok(())
}
fn main() {
env_logger::init();
if let Err(err) = run() {
eprintln!("Error: {}", err);
for cause in err.iter_chain().skip(1) {
eprintln!("Because: {}", cause);
}
std::process::exit(1);
}
}

71
examples/maxmind.rs Normal file
View File

@@ -0,0 +1,71 @@
use sn0int::errors::*;
use sn0int::geoip::{AsnDB, GeoIP, Maxmind};
use sn0int::paths;
use std::net::IpAddr;
use std::path::Path;
use structopt::StructOpt;
#[derive(Debug, StructOpt)]
pub enum Args {
#[structopt(name="asn")]
Asn(AsnArgs),
#[structopt(name="geoip")]
GeoIP(GeoIPArgs),
}
#[derive(Debug, StructOpt)]
pub struct AsnArgs {
ip: IpAddr,
}
impl AsnArgs {
fn run(&self, cache_dir: &Path) -> Result<()> {
let path = AsnDB::cache_path(cache_dir)?;
let asndb = AsnDB::open(&path)?;
let asn = asndb.lookup(self.ip)?;
println!("{:#?}", asn);
Ok(())
}
}
#[derive(Debug, StructOpt)]
pub struct GeoIPArgs {
ip: IpAddr,
}
impl GeoIPArgs {
fn run(&self, cache_dir: &Path) -> Result<()> {
let path = GeoIP::cache_path(cache_dir)?;
let geoip = GeoIP::open(&path)?;
let lookup = geoip.lookup(self.ip)?;
println!("{:#?}", lookup);
Ok(())
}
}
fn run() -> Result<()> {
let args = Args::from_args();
debug!("{:?}", args);
let cache_dir = paths::cache_dir()?;
match args {
Args::Asn(args) => args.run(&cache_dir),
Args::GeoIP(args) => args.run(&cache_dir),
}
}
fn main() {
env_logger::init();
if let Err(err) = run() {
eprintln!("Error: {}", err);
for cause in err.iter_chain().skip(1) {
eprintln!("Because: {}", cause);
}
std::process::exit(1);
}
}

View File

@@ -1,20 +1,67 @@
extern crate sn0int;
use std::env;
use std::thread;
use std::time::Duration;
use sn0int::term::{SPINNERS, Spinner};
use sn0int::term::{SPINNERS, Spinner, StackedSpinners};
use structopt::StructOpt;
#[derive(Debug, StructOpt)]
pub enum Args {
#[structopt(name="single")]
Single(Single),
#[structopt(name="stacked")]
Stacked(Stacked),
}
#[derive(Debug, StructOpt)]
pub struct Single {
idx: usize,
#[structopt(long="ticks", default_value="100")]
ticks: usize,
}
impl Single {
fn run(&self) {
let mut s = Spinner::new(SPINNERS[self.idx], "Demo".to_string());
for _ in 0..self.ticks {
thread::sleep(Duration::from_millis(100));
s.tick();
}
s.finish("Done".to_string());
}
}
#[derive(Debug, StructOpt)]
pub struct Stacked {
}
impl Stacked {
fn run(&self) {
let mut stack = StackedSpinners::new();
stack.add("1".into(), String::from("spinner1"));
stack.add("2".into(), String::from("spinner2"));
stack.add("3".into(), String::from("spinner3"));
for x in 1..=3 {
for _ in 0..50 {
thread::sleep(Duration::from_millis(100));
stack.tick();
}
// stack.log("ohai");
stack.remove(&x.to_string());
}
stack.clear();
// stack.finish("Done".to_string());
}
}
fn main() {
let idx = env::args().skip(1).next().expect("Expected argv[1]");
let idx = idx.parse::<usize>().expect("argv[1] is not a number");
let mut s = Spinner::new(SPINNERS[idx], "Demo".to_string());
for _ in 0..100 {
thread::sleep(Duration::from_millis(100));
s.tick();
let args = Args::from_args();
match args {
Args::Single(args) => args.run(),
Args::Stacked(args) => args.run(),
}
s.finish("Done".to_string());
}

View File

@@ -37,25 +37,6 @@ INSERT INTO subdomains (id, domain_id, value, unscoped, resolvable)
DROP TABLE _subdomains_old;
-- subdomain_ipaddrs
ALTER TABLE subdomain_ipaddrs RENAME TO _subdomain_ipaddrs_old;
CREATE TABLE subdomain_ipaddrs (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
subdomain_id INTEGER NOT NULL,
ip_addr_id INTEGER NOT NULL,
FOREIGN KEY(subdomain_id) REFERENCES subdomains(id) ON DELETE CASCADE,
FOREIGN KEY(ip_addr_id) REFERENCES ipaddrs(id) ON DELETE CASCADE,
CONSTRAINT subdomain_ipaddr_unique UNIQUE (subdomain_id, ip_addr_id)
);
INSERT INTO subdomain_ipaddrs (id, subdomain_id, ip_addr_id)
SELECT id, subdomain_id, ip_addr_id
FROM _subdomain_ipaddrs_old;
DROP TABLE _subdomain_ipaddrs_old;
-- urls
ALTER TABLE urls RENAME TO _urls_old;
@@ -123,4 +104,23 @@ INSERT INTO ipaddrs (id, family, value, unscoped, continent, continent_code, cou
DROP TABLE _ipaddrs_old;
-- subdomain_ipaddrs
ALTER TABLE subdomain_ipaddrs RENAME TO _subdomain_ipaddrs_old;
CREATE TABLE subdomain_ipaddrs (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
subdomain_id INTEGER NOT NULL,
ip_addr_id INTEGER NOT NULL,
FOREIGN KEY(subdomain_id) REFERENCES subdomains(id) ON DELETE CASCADE,
FOREIGN KEY(ip_addr_id) REFERENCES ipaddrs(id) ON DELETE CASCADE,
CONSTRAINT subdomain_ipaddr_unique UNIQUE (subdomain_id, ip_addr_id)
);
INSERT INTO subdomain_ipaddrs (id, subdomain_id, ip_addr_id)
SELECT id, subdomain_id, ip_addr_id
FROM _subdomain_ipaddrs_old;
DROP TABLE _subdomain_ipaddrs_old;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1,25 @@
PRAGMA foreign_keys=off;
ALTER TABLE urls RENAME TO _urls_old;
CREATE TABLE urls (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
subdomain_id INTEGER NOT NULL,
value VARCHAR NOT NULL,
status INTEGER,
body BLOB,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
online BOOLEAN,
title VARCHAR,
redirect VARCHAR,
FOREIGN KEY(subdomain_id) REFERENCES subdomains(id) ON DELETE CASCADE,
CONSTRAINT url_unique UNIQUE (value)
);
INSERT INTO urls (id, subdomain_id, value, status, body, unscoped, online, title, redirect)
SELECT id, subdomain_id, value, status, body, unscoped, online, title, redirect
FROM _urls_old;
DROP TABLE _urls_old;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1,26 @@
PRAGMA foreign_keys=off;
ALTER TABLE urls RENAME TO _urls_old;
CREATE TABLE urls (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
subdomain_id INTEGER NOT NULL,
value VARCHAR NOT NULL,
path VARCHAR NOT NULL,
status INTEGER,
body BLOB,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
online BOOLEAN,
title VARCHAR,
redirect VARCHAR,
FOREIGN KEY(subdomain_id) REFERENCES subdomains(id) ON DELETE CASCADE,
CONSTRAINT url_unique UNIQUE (value)
);
INSERT INTO urls (id, subdomain_id, value, path, status, body, unscoped, online, title, redirect)
SELECT id, subdomain_id, value, '/', status, body, unscoped, online, title, redirect
FROM _urls_old;
DROP TABLE _urls_old;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1 @@
DROP TABLE phonenumbers;

View File

@@ -0,0 +1,16 @@
CREATE TABLE phonenumbers (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
name VARCHAR,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
valid BOOLEAN,
last_online DATETIME,
country VARCHAR,
carrier VARCHAR,
line VARCHAR,
is_ported BOOLEAN,
last_ported DATETIME,
caller_name VARCHAR,
caller_type VARCHAR,
CONSTRAINT phonenumber_unique UNIQUE (value)
);

View File

@@ -0,0 +1,27 @@
PRAGMA foreign_keys=off;
CREATE TABLE _ipaddrs_new (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
family VARCHAR NOT NULL,
value VARCHAR NOT NULL,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
continent VARCHAR,
continent_code VARCHAR,
country VARCHAR,
country_code VARCHAR,
city VARCHAR,
latitude FLOAT,
longitude FLOAT,
asn INTEGER,
as_org VARCHAR,
CONSTRAINT ipaddr_unique UNIQUE (value)
);
INSERT INTO _ipaddrs_new (id, family, value, unscoped, continent, continent_code, city, latitude, longitude, asn, as_org)
SELECT id, family, value, unscoped, continent, continent_code, city, latitude, longitude, asn, as_org
FROM ipaddrs;
DROP TABLE ipaddrs;
ALTER TABLE _ipaddrs_new RENAME TO ipaddrs;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1,2 @@
ALTER TABLE ipaddrs ADD COLUMN description VARCHAR;
ALTER TABLE ipaddrs ADD COLUMN reverse_dns VARCHAR;

View File

@@ -0,0 +1,3 @@
DROP TABLE network_devices;
DROP TABLE networks;
DROP TABLE devices;

View File

@@ -0,0 +1,30 @@
CREATE TABLE networks (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
latitude FLOAT,
longitude FLOAT,
CONSTRAINT network_unique UNIQUE (value)
);
CREATE TABLE devices (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
name VARCHAR,
hostname VARCHAR,
vendor VARCHAR,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
last_seen DATETIME,
CONSTRAINT device_unique UNIQUE (value)
);
CREATE TABLE network_devices (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
network_id INTEGER NOT NULL,
device_id INTEGER NOT NULL,
ipaddr VARCHAR,
last_seen DATETIME,
FOREIGN KEY(network_id) REFERENCES networks(id) ON DELETE CASCADE,
FOREIGN KEY(device_id) REFERENCES devices(id) ON DELETE CASCADE,
CONSTRAINT network_device_unique UNIQUE (network_id, device_id)
);

View File

@@ -0,0 +1 @@
DROP TABLE ttls;

View File

@@ -0,0 +1,7 @@
CREATE TABLE ttls (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
family VARCHAR NOT NULL,
key INTEGER NOT NULL,
expire DATETIME NOT NULL,
CONSTRAINT ttl_unique UNIQUE (family, key)
);

View File

@@ -0,0 +1 @@
DROP TABLE accounts;

View File

@@ -0,0 +1,12 @@
CREATE TABLE accounts (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
service VARCHAR NOT NULL,
username VARCHAR NOT NULL,
displayname VARCHAR,
email VARCHAR,
url VARCHAR,
last_seen DATETIME,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
CONSTRAINT account_unique UNIQUE (value)
);

View File

@@ -0,0 +1,2 @@
DROP TABLE breach_emails;
DROP TABLE breaches;

View File

@@ -0,0 +1,16 @@
CREATE TABLE breaches (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
CONSTRAINT breach_unique UNIQUE (value)
);
CREATE TABLE breach_emails (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
breach_id INTEGER NOT NULL,
email_id INTEGER NOT NULL,
password VARCHAR,
FOREIGN KEY(breach_id) REFERENCES breaches(id) ON DELETE CASCADE,
FOREIGN KEY(email_id) REFERENCES emails(id) ON DELETE CASCADE,
CONSTRAINT breach_emails_unique UNIQUE (breach_id, email_id, password)
);

View File

@@ -0,0 +1 @@
DROP TABLE images;

View File

@@ -0,0 +1,21 @@
CREATE TABLE images (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
filename VARCHAR,
mime VARCHAR,
width INT,
height INT,
created DATETIME,
latitude FLOAT,
longitude FLOAT,
nudity FLOAT,
ahash VARCHAR,
dhash VARCHAR,
phash VARCHAR,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
CONSTRAINT image_unique UNIQUE (value)
);

View File

@@ -0,0 +1,18 @@
PRAGMA foreign_keys=off;
CREATE TABLE _emails_new (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
valid BOOLEAN,
CONSTRAINT email_unique UNIQUE (value)
);
INSERT INTO _emails_new (id, value, unscoped, valid)
SELECT id, value, unscoped, valid
FROM emails;
DROP TABLE emails;
ALTER TABLE _emails_new RENAME TO emails;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1,2 @@
-- Your SQL goes here
ALTER TABLE emails ADD COLUMN displayname VARCHAR;

View File

@@ -0,0 +1 @@
DROP TABLE ports;

View File

@@ -0,0 +1,17 @@
CREATE TABLE ports (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
ip_addr_id INTEGER NOT NULL,
value VARCHAR NOT NULL,
ip_addr VARCHAR NOT NULL,
port INTEGER NOT NULL,
protocol VARCHAR NOT NULL,
status VARCHAR NOT NULL,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
banner VARCHAR,
service VARCHAR,
version VARCHAR,
FOREIGN KEY(ip_addr_id) REFERENCES ipaddrs(id) ON DELETE CASCADE,
CONSTRAINT port_unique UNIQUE (value)
);

View File

@@ -0,0 +1,2 @@
-- This file should undo anything in `up.sql`
DROP TABLE autonoscope;

View File

@@ -0,0 +1,8 @@
-- Your SQL goes here
CREATE TABLE autonoscope (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
object VARCHAR NOT NULL,
value VARCHAR NOT NULL,
scoped BOOLEAN NOT NULL,
CONSTRAINT autonoscope_unique UNIQUE (object, value)
);

View File

@@ -0,0 +1 @@
DROP TABLE netblocks;

View File

@@ -0,0 +1,10 @@
CREATE TABLE netblocks (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
family VARCHAR NOT NULL,
value VARCHAR NOT NULL,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
asn INTEGER,
as_org VARCHAR,
description VARCHAR,
CONSTRAINT netblock_unique UNIQUE (value)
);

View File

@@ -0,0 +1,41 @@
PRAGMA foreign_keys=off;
-- accounts
CREATE TABLE _accounts_new (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
service VARCHAR NOT NULL,
username VARCHAR NOT NULL,
displayname VARCHAR,
email VARCHAR,
url VARCHAR,
last_seen DATETIME,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
CONSTRAINT account_unique UNIQUE (value)
);
INSERT INTO _accounts_new (id, value, service, username, displayname, email, url, last_seen, unscoped)
SELECT id, value, service, username, displayname, email, url, last_seen, unscoped
FROM accounts;
DROP TABLE accounts;
ALTER TABLE _accounts_new RENAME TO accounts;
-- networks
CREATE TABLE _networks_new (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
latitude FLOAT,
longitude FLOAT,
CONSTRAINT network_unique UNIQUE (value)
);
INSERT INTO _networks_new (id, value, unscoped, latitude, longitude)
SELECT id, value, unscoped, latitude, longitude
FROM networks;
DROP TABLE networks;
ALTER TABLE _networks_new RENAME TO networks;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1,4 @@
ALTER TABLE accounts ADD COLUMN phonenumber VARCHAR;
ALTER TABLE accounts ADD COLUMN profile_pic VARCHAR;
ALTER TABLE accounts ADD COLUMN birthday VARCHAR;
ALTER TABLE networks ADD COLUMN description VARCHAR;

View File

@@ -0,0 +1 @@
DROP TABLE cryptoaddrs;

View File

@@ -0,0 +1,13 @@
CREATE TABLE cryptoaddrs (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
value VARCHAR NOT NULL,
currency VARCHAR,
denominator INTEGER,
balance BIGINT,
received BIGINT,
first_seen DATETIME,
last_withdrawal DATETIME,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
description VARCHAR,
CONSTRAINT netblock_unique UNIQUE (value)
);

View File

@@ -0,0 +1,31 @@
DROP TABLE activity;
PRAGMA foreign_keys=off;
-- ports
CREATE TABLE _ports_new (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
ip_addr_id INTEGER NOT NULL,
value VARCHAR NOT NULL,
ip_addr VARCHAR NOT NULL,
port INTEGER NOT NULL,
protocol VARCHAR NOT NULL,
status VARCHAR NOT NULL,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
banner VARCHAR,
service VARCHAR,
version VARCHAR,
FOREIGN KEY(ip_addr_id) REFERENCES ipaddrs(id) ON DELETE CASCADE,
CONSTRAINT port_unique UNIQUE (value)
);
INSERT INTO _ports_new (id, ip_addr_id, value, ip_addr, port, protocol, status, unscoped, banner, service, version)
SELECT id, ip_addr_id, value, ip_addr, port, protocol, status, unscoped, banner, service, version
FROM ports;
DROP TABLE ports;
ALTER TABLE _ports_new RENAME TO ports;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1,44 @@
CREATE TABLE activity (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
topic VARCHAR NOT NULL,
time DATETIME NOT NULL,
uniq VARCHAR,
latitude FLOAT,
longitude FLOAT,
radius INTEGER,
content VARCHAR NOT NULL
);
CREATE UNIQUE INDEX activity_uniq ON activity(topic, uniq);
CREATE INDEX activity_topic ON activity(topic);
CREATE INDEX activity_time ON activity(time);
CREATE INDEX activity_topic_time ON activity(topic, time);
PRAGMA foreign_keys=off;
-- ports
CREATE TABLE _ports_new (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
ip_addr_id INTEGER NOT NULL,
value VARCHAR NOT NULL,
ip_addr VARCHAR NOT NULL,
port INTEGER NOT NULL,
protocol VARCHAR NOT NULL,
status VARCHAR,
unscoped BOOLEAN DEFAULT 0 NOT NULL,
banner VARCHAR,
service VARCHAR,
version VARCHAR,
FOREIGN KEY(ip_addr_id) REFERENCES ipaddrs(id) ON DELETE CASCADE,
CONSTRAINT port_unique UNIQUE (value)
);
INSERT INTO _ports_new (id, ip_addr_id, value, ip_addr, port, protocol, status, unscoped, banner, service, version)
SELECT id, ip_addr_id, value, ip_addr, port, protocol, status, unscoped, banner, service, version
FROM ports;
DROP TABLE ports;
ALTER TABLE _ports_new RENAME TO ports;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1,18 @@
PRAGMA foreign_keys=off;
CREATE TABLE _ttls_new (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
family VARCHAR NOT NULL,
key INTEGER NOT NULL,
expire DATETIME NOT NULL,
CONSTRAINT ttl_unique UNIQUE (family, key)
);
INSERT INTO _ttls_new (id, family, key, expire)
SELECT id, family, key, expire
FROM ttls;
DROP TABLE ttls;
ALTER TABLE _ttls_new RENAME TO ttls;
PRAGMA foreign_keys=on;

View File

@@ -0,0 +1,19 @@
PRAGMA foreign_keys=off;
CREATE TABLE _ttls_new (
id INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,
family VARCHAR NOT NULL,
key INTEGER NOT NULL,
value VARCHAR NOT NULL,
expire DATETIME NOT NULL,
CONSTRAINT ttl_unique UNIQUE (family, key)
);
INSERT INTO _ttls_new (id, family, key, value, expire)
SELECT id, family, key, "unknown", expire
FROM ttls;
DROP TABLE ttls;
ALTER TABLE _ttls_new RENAME TO ttls;
PRAGMA foreign_keys=on;

View File

@@ -1,16 +0,0 @@
-- Description: Run a asn lookup for an ip address
-- Version: 0.1.0
-- Source: ipaddrs
-- License: GPL-3.0
function run(arg)
lookup = asn_lookup(arg['value'])
if last_err() then return end
if arg['asn'] ~= lookup['asn'] or arg['as_org'] ~= lookup['as_org'] then
db_update('ipaddr', arg, {
asn=lookup['asn'],
as_org=lookup['as_org'],
})
end
end

View File

@@ -1,48 +0,0 @@
-- Description: Query certificate transparency logs to discover subdomains
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
session = http_mksession()
req = http_request(session, 'GET', 'https://crt.sh/', {
query={
q='%.' .. arg['value'],
output='json'
}
})
resp = http_send(req)
if last_err() then return end
if resp['status'] ~= 200 then return 'http error: ' .. resp['status'] end
certs = json_decode_stream(resp['text'])
if last_err() then return end
seen = {}
i = 1
while i <= #certs do
c = certs[i]
-- print(c)
name = c['name_value']
if name:find("*.") == 1 then
-- ignore wildcard domains
seen[name] = 1
end
if seen[name] == nil then
-- info(name)
db_add('subdomain', {
domain_id=arg['id'],
value=name,
})
seen[name] = 1
end
i = i+1
end
end

View File

@@ -1,46 +0,0 @@
-- Description: Query subdomains to discovery ip addresses and verify the record is visible
-- Version: 0.1.0
-- Source: subdomains
-- License: GPL-3.0
function run(arg)
records = dns(arg['value'], 'A')
if last_err() then return end
-- update subdomain
resolvable = records['success'] ~= nil
if arg['resolvable'] ~= resolvable then
-- TODO: pass arg to function as well
db_update('subdomain', arg, {
resolvable=resolvable
})
end
if not resolvable then
return
end
records = records['success']
-- there is a bug in struct -> lua that causes tables to be zero indexed
-- this checks if there's something at index 0 but uses index 1 if this is fixed
i = 0
if records[i] == nil then i = 1 end
while records[i] ~= nil do
r = records[i]
if r['A'] ~= nil then
ipaddr_id = db_add('ipaddr', {
family='4',
value=r['A'],
})
if last_err() then return end
db_add('subdomain-ipaddr', {
subdomain_id=arg['id'],
ip_addr_id=ipaddr_id,
})
end
i = i+1
end
end

View File

@@ -1,10 +0,0 @@
-- Description: Run a geoip lookup for an ip address
-- Version: 0.1.0
-- Source: ipaddrs
-- License: GPL-3.0
function run(arg)
lookup = geoip_lookup(arg['value'])
if last_err() then return end
db_update('ipaddr', arg, lookup)
end

View File

@@ -1,30 +0,0 @@
-- Description: Query hackertarget for subdomains of a domain
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
session = http_mksession()
req = http_request(session, 'GET', 'https://api.hackertarget.com/hostsearch/', {
query={
q=arg['value']
}
})
resp = http_send(req)
if last_err() then return end
if resp['status'] ~= 200 then return 'http error: ' .. resp['status'] end
m = regex_find_all("([^,]+),.+\\n?", resp['text'])
i = 1
while i <= #m do
db_add('subdomain', {
domain_id=arg['id'],
value=m[i][2]
})
i = i+1
end
end

View File

@@ -1,32 +0,0 @@
-- Description: Query alienvault otx passive dns for subdomains of a domain
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
session = http_mksession()
url = 'https://otx.alienvault.com/api/v1/indicators/domain/' .. arg['value'] .. '/passive_dns'
req = http_request(session, 'GET', url, {})
resp = http_send(req)
if last_err() then return end
if resp['status'] ~= 200 then return 'http error: ' .. resp['status'] end
o = json_decode(resp['text'])
if last_err() then return end
o = o['passive_dns']
i = 0
while o[i] do
x = o[i]
db_add('subdomain', {
domain_id=arg['id'],
value=x['hostname'],
})
i = i+1
end
end

View File

@@ -1,72 +0,0 @@
-- Description: Scrape known http responses for urls
-- Version: 0.1.0
-- Source: urls
-- License: GPL-3.0
function entry(target, parent, href)
-- TODO: parse mailto:foo@example.com?subject=asdf
-- TODO: parse tel:+4912345
-- TODO: allow discovering 3rd-party domains
-- TODO: maybe record urls as well
local psl, parts, url, host
if href == nil then
return
end
url = url_join(parent, href)
if url:match('^https?://') == nil then
return
end
parts = url_parse(url)
if last_err() then return end
host = parts['host']
psl = psl_domain_from_dns_name(host)
if psl ~= target then
-- TODO: this doesn't match the current target, but might match a different target in scope
-- if we can check an entry exists in the db we could make this more intelligent
return
end
domain_id = db_add('domain', {
value=psl,
})
db_add('subdomain', {
domain_id=domain_id,
value=host,
})
end
function run(arg)
if arg['body'] == nil or #arg['body'] == 0 then
return
end
body = utf8_decode(arg['body'])
if last_err() then return end
links = html_select_list(body, 'a')
if last_err() then return end
if #links == 0 then
return
end
-- get public suffix
url = url_parse(arg['value'])
if last_err() then return end
psl = psl_domain_from_dns_name(url['host'])
-- process html links
i = 1
while i <= #links do
href = links[i]['attrs']['href']
entry(psl, arg['value'], href)
i = i+1
end
end

View File

@@ -1,58 +0,0 @@
-- Description: Query pgp keyserver for email addresses
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
session = http_mksession()
--lookup_url = 'https://pgp.mit.edu/pks/lookup'
lookup_url = 'https://sks-keyservers.net/pks/lookup'
req = http_request(session, 'GET', lookup_url, {
query={
search=arg['value'],
}
})
resp = http_send(req)
if last_err() then return end
if resp['status'] ~= 200 then return 'http error: ' .. resp['status'] end
links = html_select_list(resp['text'], 'a')
i = 1
while i <= #links do
href = links[i]['attrs']['href']
if href:find('/pks/lookup%?op=get&search=') == 1 then
url = url_join(lookup_url, href)
req = http_request(session, 'GET', url, {})
resp = http_send(req)
-- TODO: do not abort script if one attempt fails
if last_err() then return end
if resp['status'] ~= 200 then return 'http error: ' .. resp['status'] end
pubkey = pgp_pubkey_armored(resp['text'])
-- print(pubkey)
-- TODO: ensure at least one email matches our target domain
if pubkey['uids'] then
j = 1
while j <= #pubkey['uids'] do
m = regex_find("<([^< ]+@[^< ]+)>$", pubkey['uids'][j])
if m then
db_add('email', {
value=m[2],
})
end
j = j+1
end
end
end
i = i+1
end
end

View File

@@ -1,50 +0,0 @@
-- Description: Query ThreatMiner passive dns for subdomains of an ip address
-- Version: 0.1.0
-- Source: ipaddrs
-- License: GPL-3.0
function run(arg)
session = http_mksession()
-- TODO: add option to filter old entries based on last_seen
req = http_request(session, 'GET', 'https://api.threatminer.org/v2/host.php', {
query={
rt='2',
q=arg['value']
}
})
resp = http_send(req)
if last_err() then return end
if resp['status'] ~= 200 then return 'http error: ' .. resp['status'] end
o = json_decode(resp['text'])
if last_err() then return end
o = o['results']
i = 0
while o[i] do
x = o[i]
domain = psl_domain_from_dns_name(x['domain'])
-- TODO: if this fails, skip this entry instead
if last_err() then return end
domain_id = db_add('domain', {
value=domain,
})
subdomain_id = db_add('subdomain', {
domain_id=domain_id,
value=x['domain'],
})
db_add('subdomain-ipaddr', {
subdomain_id=subdomain_id,
ip_addr_id=arg['id'],
})
i = i+1
end
end

View File

@@ -1,35 +0,0 @@
-- Description: Query ThreatMiner passive dns for subdomains of a domain
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
session = http_mksession()
req = http_request(session, 'GET', 'https://api.threatminer.org/v2/domain.php', {
query={
rt='5',
q=arg['value']
}
})
resp = http_send(req)
if last_err() then return end
if resp['status'] ~= 200 then return 'http error: ' .. resp['status'] end
o = json_decode(resp['text'])
if last_err() then return end
o = o['results']
i = 0
while o[i] do
x = o[i]
db_add('subdomain', {
domain_id=arg['id'],
value=x,
})
i = i+1
end
end

View File

@@ -1,46 +0,0 @@
-- Description: Scan subdomains for websites
-- Version: 0.1.0
-- Source: subdomains
-- License: GPL-3.0
function request(subdomain_id, url)
req = http_request(session, 'GET', url, {
timeout=5000
})
reply = http_send(req)
if last_err() then
clear_err()
return
end
obj = {
subdomain_id=subdomain_id,
value=url,
status=reply['status'],
body=reply['text'],
redirect=reply['headers']['location'],
}
redirect = reply['headers']['location']
if redirect then
obj['redirect'] = url_join(url, redirect)
end
db_add('url', obj)
-- info(json_encode(reply['status']))
-- info(json_encode(reply['headers']['location']))
-- info(json_encode(reply['text']))
end
function run(arg)
domain = arg['value']
session = http_mksession()
request(arg['id'], 'http://' .. domain .. '/')
if last_err() then return end
request(arg['id'], 'https://' .. domain .. '/')
if last_err() then return end
end

View File

@@ -1,56 +0,0 @@
-- Description: Discover subdomains from wayback machine
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run(arg)
domain = arg['value']
url = 'https://web.archive.org/cdx/search/cdx?url=*.' .. domain .. '/*&output=json&collapse=urlkey'
session = http_mksession()
req = http_request(session, 'GET', url, {})
resp = http_send(req)
if last_err() then return end
if resp['status'] ~= 200 then return 'http error: ' .. resp['status'] end
o = json_decode(resp['text'])
if last_err() then return end
-- no known urls
if o[0] == nil then
return
end
-- ensure the api response is still what we expect
if o[0][2] == nil then
return 'api returned unexpected json format'
end
seen = {}
i = 1
while o[i] do
url = o[i][2]
parts = url_parse(url)
if last_err() then
clear_err()
error("Failed to parse url: " .. json_encode(url))
else
subdomain = parts['host']
if seen[subdomain] == nil then
db_add('subdomain', {
domain_id=arg['id'],
value=parts['host'],
})
if last_err() then return end
seen[subdomain] = 1
end
end
i = i+1
end
end

View File

@@ -0,0 +1,26 @@
-- Description: Log some dummy activity
-- Version: 0.1.0
-- License: GPL-3.0
function run()
local uniq = getopt('uniq')
local topic = getopt('topic') or 'harness/activity-ping:dummy'
if getopt('gps') then
lat=1.23
lon=4.56
radius=100
end
db_activity({
topic=topic,
time=sn0int_time(),
uniq=uniq,
latitude=lat,
longitude=lon,
radius=radius,
content={
msg='ohai',
},
})
end

View File

@@ -0,0 +1,29 @@
-- Description: Log some dummy activity
-- Version: 0.1.0
-- License: GPL-3.0
function run()
local uniq = getopt('uniq')
local topic = getopt('topic') or 'harness/activity-ping:dummy'
if getopt('gps') then
lat=1.23
lon=4.56
radius=100
end
while true do
db_activity({
topic=topic,
time=sn0int_time(),
uniq=uniq,
latitude=lat,
longitude=lon,
radius=radius,
content={
msg='ohai',
},
})
sleep(5)
end
end

107
modules/harness/add-all.lua Normal file
View File

@@ -0,0 +1,107 @@
-- Description: TODO your description here
-- Version: 0.1.0
-- License: GPL-3.0
function run()
info('adding domain')
domain_id = db_add('domain', {
value='example.com',
})
if last_err() then return end
info('adding subdomain')
subdomain_id = db_add('subdomain', {
domain_id=domain_id,
value='example.com',
})
if last_err() then return end
info('adding ipaddr')
ipaddr_id = db_add('ipaddr', {
value='192.0.2.1',
})
if last_err() then return end
info('adding device')
device_id = db_add('device', {
value='ff:ff:ff:ff:ff:ff',
})
if last_err() then return end
info('adding network')
network_id = db_add('network', {
value='myssid',
})
if last_err() then return end
info('adding email')
email_id = db_add('email', {
value='foo@example.com',
})
if last_err() then return end
info('adding phonenumber')
phonenumber_id = db_add('phonenumber', {
value='+4912345678',
})
if last_err() then return end
info('adding breach')
breach_id = db_add('breach', {
value='hack the planet',
})
if last_err() then return end
info('adding account')
account_id = db_add('account', {
service='github.com',
username='kpcyrd',
})
if last_err() then return end
info('adding image')
blob = create_blob('abc')
image_id = db_add('image', {
value=blob,
})
if last_err() then return end
info('adding port')
port_id = db_add('port', {
ip_addr_id=ipaddr_id,
ip_addr='192.0.2.1',
port=443,
protocol='tcp',
status='open',
})
if last_err() then return end
info('adding url')
url_id = db_add('url', {
subdomain_id=subdomain_id,
value='https://www.example.com/a/b',
body='<html></html>',
})
if last_err() then return end
info('adding breach_email')
db_add('breach-email', {
breach_id=breach_id,
email_id=email_id,
})
if last_err() then return end
info('adding network_device')
db_add('network-device', {
network_id=network_id,
device_id=device_id,
})
if last_err() then return end
info('adding subdomain_ipaddr')
db_add('subdomain-ipaddr', {
subdomain_id=subdomain_id,
ip_addr_id=ipaddr_id,
})
if last_err() then return end
end

View File

@@ -0,0 +1,26 @@
-- Description: TODO your description here
-- Version: 0.1.0
-- License: GPL-3.0
-- git log -s --format='%H %ci'
function run()
while true do
local x = stdin_readline()
if x == nil then
break
end
local m = regex_find('^(\\S+) (.+)', x)
if m then
time = strptime('%Y-%m-%d %T %z', m[3])
time = sn0int_time_from(time)
db_activity({
topic='harness/sn0int-commit:dummy',
time=time,
uniq=m[2],
content={},
})
end
end
end

View File

@@ -0,0 +1,10 @@
-- Description: TODO your description here
-- Version: 0.1.0
-- License: GPL-3.0
-- Source: subdomains
function run(arg)
db_update('subdomain', arg, {
resolvable=true,
})
end

View File

@@ -0,0 +1,13 @@
-- Description: TODO your description here
-- Version: 0.1.0
-- License: GPL-3.0
-- Source: domains
function run(arg)
for i=1, 20 do
db_add('subdomain', {
domain_id=arg['id'],
value=http_mksession() .. '.' .. arg['value'],
})
end
end

View File

@@ -1,6 +1,5 @@
-- Description: Test error handling
-- Version: 0.1.0
-- Source: domains
-- License: GPL-3.0
function run()

Some files were not shown because too many files have changed in this diff Show More