mirror of
https://github.com/cisagov/snafflepy
synced 2026-09-24 18:22:23 +00:00
+31
-12
@@ -51,23 +51,42 @@ class Rules:
|
||||
|
||||
def is_interest_file(file:RemoteFile, rules: Rules, smb_client: SMBClient, share):
|
||||
backup_ext_list = [".bak", ".mdf", ".sqldump", ".sdf"]
|
||||
cred_list = ["creds", "password", "passw", "credentials"]
|
||||
cred_list = ["creds", "password", "passw", "credentials", "login", "secret", "account", "pass",
|
||||
".kdb",".psafe3",".kwallet",".keychain",".agilekeychain",".cred"]
|
||||
|
||||
file_text = termcolor.colored(f"[File]", "green")
|
||||
ssn_regex = str("^\d{{3}}-\d{{2}}-\d{{4}}$")
|
||||
for ext in backup_ext_list:
|
||||
if re.search(str(ext), str(file.name).lower()):
|
||||
file_triage = termcolor.colored(f"{{Yellow}}\\\\{file.target}\\{share}\\{file.name} <KeepBackupFiles>", "light_yellow", "on_white")
|
||||
try:
|
||||
|
||||
# Non-file shares
|
||||
if str(share).lower().find("ipc") or str(share).lower().find("print"):
|
||||
pass
|
||||
else:
|
||||
file_data = ""
|
||||
file.get(smb_client)
|
||||
|
||||
# MVP Build only, check for SSN in files
|
||||
with open(str(file.tmp_filename)) as f:
|
||||
file_data = f.read(10000)
|
||||
if re.search(ssn_regex, file_text):
|
||||
file_triage = termcolor.colored(f"{{Red}}\\\\{file.target}\\{share}\\{file.name} <SsnRegexFound>", "light_yellow", "on_white")
|
||||
print(file_text, file_triage)
|
||||
|
||||
# MVP Build only, check for backup files
|
||||
for ext in backup_ext_list:
|
||||
if re.search(str(ext), str(file.name).lower()):
|
||||
file_triage = termcolor.colored(f"{{Yellow}}\\\\{file.target}\\{share}\\{file.name} <KeepBackupFiles>", "light_yellow", "on_white")
|
||||
try:
|
||||
file.get(smb_client)
|
||||
print(file_text, file_triage)
|
||||
except FileRetrievalError as e:
|
||||
smb_client.handle_download_error(share, file.name, e)
|
||||
|
||||
# MVP Build only, check for files with possible passwords contained inside
|
||||
for cred in cred_list:
|
||||
if re.search(str(cred), str(file.name).lower()):
|
||||
file_triage = termcolor.colored(f"{{Black}}\\\\{file.target}\\{share}\\{file.name} <KeepFilesWithInterestName>", "black", "on_white")
|
||||
file.get(smb_client)
|
||||
print(file_text, file_triage)
|
||||
except FileRetrievalError as e:
|
||||
smb_client.handle_download_error(share, file.name, e)
|
||||
for cred in cred_list:
|
||||
if re.search(str(cred), str(file.name).lower()):
|
||||
file_triage = termcolor.colored(f"{{Black}}\\\\{file.target}\\{share}\\{file.name} <KeepFilesWithInterestName>", "black", "on_white")
|
||||
file.get(smb_client)
|
||||
print(file_text, file_triage)
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -31,7 +31,7 @@ def begin_snaffle(options):
|
||||
options.targets[0], options.username, options.password)
|
||||
domain_names = list_computers(login, options.domain)
|
||||
for target in domain_names:
|
||||
log.debug(
|
||||
log.info(
|
||||
f"Found{target}, adding to targets to snaffle...")
|
||||
try:
|
||||
options.targets.append(target)
|
||||
|
||||
+1
-1
@@ -192,7 +192,7 @@ class SMBClient:
|
||||
file_text = termcolor.colored("[File]", 'green')
|
||||
print(file_text, f"\\\\{self.server}\\{share}\\{sub_name}")
|
||||
|
||||
yield subfile
|
||||
|
||||
# self.handle_download_error(share, sub_name, err)
|
||||
except Exception as e:
|
||||
if str(err).find("STATUS_FILE_IS_A_DIRECTORY"):
|
||||
|
||||
+2
-2
@@ -34,8 +34,8 @@ def parse_arguments():
|
||||
|
||||
parser.add_argument("-m", "--max-file-snaffle", metavar="size", type=int, default=10000, help="Max filesize to snaffle in bytes (any files over this size will be dropped)")
|
||||
# TODO
|
||||
parser.add_argument("-i", "--no-share-discovery", action='store_true',
|
||||
help="Disables share discovery (more stealthy)")
|
||||
# parser.add_argument("-i", "--no-share-discovery", action='store_true',
|
||||
# help="Disables share discovery (more stealthy)")
|
||||
parser.add_argument("-n", "--disable-computer-discovery", action='store_true',
|
||||
help="Disable computer discovery, requires a list of hosts to do discovery on")
|
||||
|
||||
|
||||
Reference in New Issue
Block a user