mirror of
https://github.com/byt3bl33d3r/SprayingToolkit
synced 2026-06-08 13:24:39 +00:00
Added spindrift.py, updated readme and vaporizer.py
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
emails.txt
|
||||
names.txt
|
||||
lync_valid_accounts.txt
|
||||
owa_valid_accounts.txt
|
||||
# Byte-compiled / optimized / DLL files
|
||||
|
||||
@@ -48,6 +48,24 @@ Options:
|
||||
--pass-row-name NAME password row title in CSV file [default: Password]
|
||||
```
|
||||
|
||||
#### Examples
|
||||
|
||||
```bash
|
||||
python atomizer.py owa contoso.com 'Fall2018' --userfile emails.txt
|
||||
```
|
||||
|
||||
```bash
|
||||
python atomizer.py lync contoso.com 'Fall2018' --userfile emails.txt
|
||||
```
|
||||
|
||||
```bash
|
||||
python atomizer lync contoso.com --csvfile accounts.csv
|
||||
```
|
||||
|
||||
```bash
|
||||
python atomizer owa 'https://owa.contoso.com/autodiscover/autodiscover.xml' --recon
|
||||
```
|
||||
|
||||
### Vaporizer
|
||||
|
||||
A port of [@OrOneEqualsOne](https://twitter.com/OrOneEqualsOne)'s [GatherContacts](https://github.com/clr2of8/GatherContacts) Burp extension to [mitmproxy](https://mitmproxy.org/) with some improvements.
|
||||
@@ -56,9 +74,9 @@ Scrapes Google and Bing for LinkedIn profiles, automatically generates emails fr
|
||||
|
||||
(Built on top of Atomizer)
|
||||
|
||||
#### Usage
|
||||
#### Examples
|
||||
|
||||
```
|
||||
```bash
|
||||
mitmdump -s vaporizer.py --set sprayer=(lync|owa) --set domain=domain.com --set target=<domain or url to spray> --set password=password --set email_format='{f}.{last}'
|
||||
```
|
||||
|
||||
@@ -81,6 +99,39 @@ Scrapes all text from the target website and sends it to [AWS Comprehend](https:
|
||||
|
||||
#### Usage
|
||||
|
||||
```
|
||||
```bash
|
||||
mitmdump -s aerosol.py --set domain=domain.com
|
||||
```
|
||||
|
||||
### Spindrift
|
||||
|
||||
Converts names to active directory usernames (e.g `Alice Eve` => `CONTOSO\aeve`)
|
||||
|
||||
#### Usage
|
||||
|
||||
```
|
||||
Usage:
|
||||
spindrift [<file>] (--target TARGET | --domain DOMAIN) [--format FORMAT]
|
||||
|
||||
Arguments:
|
||||
file file containing names, can also read from stdin
|
||||
|
||||
Options:
|
||||
--target TARGET optional domain or url to retrieve the internal domain name from OWA
|
||||
--domain DOMAIN manually specify the domain to append to each username
|
||||
--format FORMAT username format [default: {f}{last}]
|
||||
```
|
||||
|
||||
#### Examples
|
||||
|
||||
Reads names from STDIN, `--domain` is used to specify the domain manually:
|
||||
|
||||
```bash
|
||||
cat names.txt | ./spindrift --domain CONTOSO
|
||||
```
|
||||
|
||||
Reads names from `names.txt`, `--target` dynamically grabs the internal domain name from OWA (you can give it a domain or url)
|
||||
|
||||
```bash
|
||||
python spindrift.py names.txt --target contoso.com
|
||||
```
|
||||
|
||||
Regular → Executable
Regular → Executable
Executable
+40
@@ -0,0 +1,40 @@
|
||||
#! /usr/bin/env python3
|
||||
|
||||
"""
|
||||
Usage:
|
||||
spindrift [<file>] (--target TARGET | --domain DOMAIN) [--format FORMAT]
|
||||
|
||||
Arguments:
|
||||
file file containing names, can also read from stdin
|
||||
|
||||
Options:
|
||||
--target TARGET optional domain or url to retrieve the internal domain name from OWA
|
||||
--domain DOMAIN manually specify the domain to append to each username
|
||||
--format FORMAT username format [default: {f}{last}]
|
||||
"""
|
||||
|
||||
import sys
|
||||
from docopt import docopt
|
||||
from core.sprayers.owa import OWA
|
||||
|
||||
|
||||
def convert_to_ad_username(name, username_format, domain):
|
||||
first, last = name.strip().split()
|
||||
username = username_format.format(first=first, last=last, f=first[:1], l=last[:1]).lower()
|
||||
print(f"{domain.upper()}\\{username.lower()}")
|
||||
|
||||
|
||||
if __name__ == '__main__':
|
||||
|
||||
args = docopt(__doc__)
|
||||
contents = open(args['<file>']) if args['<file>'] else sys.stdin
|
||||
|
||||
if args['--target']:
|
||||
owa = OWA(args['--target'])
|
||||
domain = owa.netbios_domain
|
||||
|
||||
elif args['--domain']:
|
||||
domain = args['--domain']
|
||||
|
||||
for line in contents:
|
||||
convert_to_ad_username(line, args['--format'], domain)
|
||||
Regular → Executable
+6
@@ -11,6 +11,7 @@ class Vaporizer:
|
||||
|
||||
def __init__(self):
|
||||
self.emails = set()
|
||||
self.names = set()
|
||||
self.atomizer = None
|
||||
|
||||
self.loop = asyncio.get_event_loop()
|
||||
@@ -91,6 +92,7 @@ class Vaporizer:
|
||||
for name in names:
|
||||
first, last, full_text = name
|
||||
ctx.log.info(colored(f"{full_text} => {first} {last}", "yellow"))
|
||||
self.names.add(f"{first} {last}")
|
||||
|
||||
email = f"{ctx.options.email_format.format(first=first, last=last, f=first[:1], l=last[:1])}@{ctx.options.domain}".lower()
|
||||
emails.append(email)
|
||||
@@ -114,6 +116,10 @@ class Vaporizer:
|
||||
for email in self.emails:
|
||||
email_file.write(email + '\n')
|
||||
|
||||
with open("names.txt", "a+") as name_file:
|
||||
for name in self.names:
|
||||
name_file.write(name + '\n')
|
||||
|
||||
ctx.log.info(print_good(f"Dumped {len(self.emails)} email(s) to emails.txt"))
|
||||
|
||||
if self.atomizer:
|
||||
|
||||
Reference in New Issue
Block a user