OXIESEC PANEL
- Current Dir:
/
/
usr
/
share
/
nmap
/
nselib
Server IP: 139.59.38.164
Upload:
Create Dir:
Name
Size
Modified
Perms
📁
..
-
08/07/2020 12:36:00 PM
rwxr-xr-x
📄
afp.lua
71.92 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ajp.lua
16.69 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
amqp.lua
10.5 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
anyconnect.lua
4.45 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
asn1.lua
14.57 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
base32.lua
7.33 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
base64.lua
5.67 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
bin.lua
12.89 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
bit.lua
2.43 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
bitcoin.lua
16.99 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
bits.lua
1.82 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
bittorrent.lua
40.77 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
bjnp.lua
9.45 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
brute.lua
50.04 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
cassandra.lua
5.78 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
citrixxml.lua
16 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
coap.lua
76.24 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
comm.lua
10.75 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
creds.lua
18.22 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
cvs.lua
3.13 KB
04/16/2018 01:11:39 AM
rw-r--r--
📁
data
-
08/07/2020 12:36:00 PM
rwxr-xr-x
📄
datafiles.lua
11.05 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
datetime.lua
1.16 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
dhcp.lua
29.17 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
dhcp6.lua
19.87 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
dns.lua
51.44 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
dnsbl.lua
19.02 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
dnssd.lua
12.57 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
drda.lua
24.2 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
eap.lua
7.64 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
eigrp.lua
14.47 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
formulas.lua
5.35 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ftp.lua
9.03 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
geoip.lua
1.71 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
giop.lua
18.44 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
gps.lua
3.05 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
http.lua
105.81 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
httpspider.lua
36.15 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
iax2.lua
9.6 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ike.lua
15.02 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
imap.lua
9.59 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
informix.lua
39.76 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ipOps.lua
26.92 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ipmi.lua
10.02 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ipp.lua
12.54 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
irc.lua
757 bytes
04/16/2018 01:11:39 AM
rw-r--r--
📄
iscsi.lua
21.45 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
isns.lua
15.34 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
jdwp.lua
43.57 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
json.lua
11.65 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ldap.lua
31.86 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
lfs.luadoc
1.68 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
libssh2-utility.lua
4.39 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
libssh2.luadoc
4.75 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
listop.lua
4.66 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
lpeg-utility.lua
5.64 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
lpeg.luadoc
351 bytes
04/16/2018 01:11:39 AM
rw-r--r--
📄
ls.lua
10.96 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
match.lua
2.05 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
membase.lua
9.88 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
mobileme.lua
8.46 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
mongodb.lua
21.29 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
mqtt.lua
28.95 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
msrpc.lua
179.93 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
msrpcperformance.lua
29.72 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
msrpctypes.lua
167.61 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
mssql.lua
110.87 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
multicast.lua
6.1 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
mysql.lua
17.09 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
natpmp.lua
5.04 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ncp.lua
36 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ndmp.lua
11.58 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
netbios.lua
13.9 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
nmap.luadoc
40.34 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
nrpc.lua
4.42 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
nsedebug.lua
3.49 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
omp2.lua
4.77 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
openssl.luadoc
7.08 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ospf.lua
15.29 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
packet.lua
36.65 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
pcre.luadoc
6.79 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
pgsql.lua
20.61 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
pop3.lua
5.7 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
pppoe.lua
29.95 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
proxy.lua
12.04 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
rdp.lua
11.05 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
re.lua
8.22 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
redis.lua
3.59 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
rmi.lua
47.89 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
rpc.lua
106.22 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
rpcap.lua
11.19 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
rsync.lua
5.19 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
rtsp.lua
8.67 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
sasl.lua
16.38 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
shortport.lua
8.01 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
sip.lua
30.56 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
slaxml.lua
17.9 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
smb.lua
175.85 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
smb2.lua
16.32 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
smbauth.lua
37.53 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
smtp.lua
19.81 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
snmp.lua
15.99 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
socks.lua
8.26 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
srvloc.lua
12.25 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ssh1.lua
8.88 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
ssh2.lua
11.88 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
sslcert.lua
33.34 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
sslv2.lua
9.63 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
stdnse.lua
45.93 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
strbuf.lua
4.52 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
strict.lua
2.53 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
stun.lua
11.51 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
tab.lua
3.35 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
target.lua
3.93 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
tftp.lua
9.38 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
tls.lua
56.16 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
tn3270.lua
43.75 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
tns.lua
64.17 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
unicode.lua
14.32 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
unittest.lua
12.33 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
unpwdb.lua
10.08 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
upnp.lua
11.18 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
url.lua
12.09 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
versant.lua
8.6 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
vnc.lua
23.3 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
vulns.lua
76.29 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
vuzedht.lua
16.62 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
wsdd.lua
12.03 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
xdmcp.lua
11.9 KB
04/16/2018 01:11:39 AM
rw-r--r--
📄
xmpp.lua
15.88 KB
04/16/2018 01:11:39 AM
rw-r--r--
Editing: unpwdb.lua
Close
--- -- Username/password database library. -- -- The <code>usernames</code> and <code>passwords</code> functions return -- multiple values for use with exception handling via -- <code>nmap.new_try</code>. The first value is the Boolean success -- indicator, the second value is the closure. -- -- The closures can take an argument of <code>"reset"</code> to rewind the list -- to the beginning. -- -- To avoid taking a long time against slow services, the closures will -- stop returning values (start returning <code>nil</code>) after a -- certain time. The time depends on the timing template level, and is -- * <code>-T3</code> or less: 10 minutes -- * <code>-T4</code>: 5 minutes -- * <code>-T5</code>: 3 minutes -- Time limits are increased by 50% if a custom username or password -- database is used with the <code>userdb</code> or <code>passdb</code> -- script arguments. You can control the time limit directly with the -- <code>unpwdb.timelimit</code> script argument. Use -- <code>unpwdb.timelimit=0</code> to disable the time limit. -- -- You can select your own username and/or password database to read from with -- the script arguments <code>userdb</code> and <code>passdb</code>, -- respectively. Comments are allowed in these files, prefixed with -- <code>"#!comment:"</code>. Comments cannot be on the same line as a -- username or password because this leaves too much ambiguity, e.g. does the -- password in <code>"mypass #!comment: blah"</code> contain a space, two -- spaces, or do they just separate the password from the comment? -- -- @usage -- require("unpwdb") -- -- local usernames, passwords -- local try = nmap.new_try() -- -- usernames = try(unpwdb.usernames()) -- passwords = try(unpwdb.passwords()) -- -- for password in passwords do -- for username in usernames do -- -- Do something with username and password. -- end -- usernames("reset") -- end -- -- @usage -- nmap --script-args userdb=/tmp/user.lst -- nmap --script-args unpwdb.timelimit=10m -- -- @args userdb The filename of an alternate username database. Default: nselib/data/usernames.lst -- @args passdb The filename of an alternate password database. Default: nselib/data/passwords.lst -- @args unpwdb.userlimit The maximum number of usernames -- <code>usernames</code> will return (default unlimited). -- @args unpwdb.passlimit The maximum number of passwords -- <code>passwords</code> will return (default unlimited). -- @args unpwdb.timelimit The maximum amount of time that any iterator will run -- before stopping. The value is in seconds by default and you can follow it -- with <code>ms</code>, <code>s</code>, <code>m</code>, or <code>h</code> for -- milliseconds, seconds, minutes, or hours. For example, -- <code>unpwdb.timelimit=30m</code> or <code>unpwdb.timelimit=.5h</code> for -- 30 minutes. The default depends on the timing template level (see the module -- description). Use the value <code>0</code> to disable the time limit. -- @author Kris Katterjohn 06/2008 -- @copyright Same as Nmap--See https://nmap.org/book/man-legal.html local io = require "io" local nmap = require "nmap" local os = require "os" local stdnse = require "stdnse" _ENV = stdnse.module("unpwdb", stdnse.seeall) local usertable = {} local passtable = {} local customdata = false -- So I don't have to type as much :) local args = nmap.registry.args local userfile = function() if args.userdb then customdata = true return args.userdb end return nmap.fetchfile("nselib/data/usernames.lst") end local passfile = function() if args.passdb then customdata = true return args.passdb end return nmap.fetchfile("nselib/data/passwords.lst") end local filltable = function(filename, table) if #table ~= 0 then return true end local file = io.open(filename, "r") if not file then return false end for l in file:lines() do -- Comments takes up a whole line if not l:match("#!comment:") then table[#table + 1] = l end end file:close() return true end table_iterator = function(table) local i = 1 return function(cmd) if cmd == "reset" then i = 1 return end local elem = table[i] if elem then i = i + 1 end return elem end end --- Returns the suggested number of seconds to attempt a brute force attack -- -- Based on the <code>unpwdb.timelimit</code> script argument, Nmap's timing -- values (<code>-T4</code> etc.) and whether or not a user-defined list is -- used. -- -- You can use the script argument <code>notimelimit</code> to make this -- function return <code>nil</code>, which means the brute-force should run -- until the list is empty. If <code>notimelimit</code> is not used, be sure to -- still check for <code>nil</code> return values on the above two functions in -- case you finish before the time limit is up. timelimit = function() -- If we're reading from a user-defined username or password list, -- we'll give them a timeout 1.5x the default. If the "notimelimit" -- script argument is used, we return nil. local t = nmap.timing_level() -- Easy enough if args.notimelimit then return nil end if args["unpwdb.timelimit"] then local limit, err = stdnse.parse_timespec(args["unpwdb.timelimit"]) if not limit then error(err) end return limit end if t <= 3 then return (customdata and 900) or 600 elseif t == 4 then return (customdata and 450) or 300 elseif t == 5 then return (customdata and 270) or 180 end end --- Returns a function closure which returns a new username with every call -- until the username list is exhausted (in which case it returns -- <code>nil</code>). -- @return boolean Status. -- @return function The usernames iterator. local usernames_raw = function() local path = userfile() if not path then return false, "Cannot find username list" end if not filltable(path, usertable) then return false, "Error parsing username list" end return true, table_iterator(usertable) end --- Returns a function closure which returns a new password with every call -- until the password list is exhausted (in which case it returns -- <code>nil</code>). -- @return boolean Status. -- @return function The passwords iterator. local passwords_raw = function() local path = passfile() if not path then return false, "Cannot find password list" end if not filltable(path, passtable) then return false, "Error parsing password list" end return true, table_iterator(passtable) end --- Wraps time and count limits around an iterator. -- -- When either limit expires, starts returning <code>nil</code>. Calling the -- iterator with an argument of "reset" resets the count. -- @param time_limit Time limit in seconds. Use 0 or <code>nil</code> for no limit. -- @param count_limit Count limit in seconds. Use 0 or <code>nil</code> for no limit. -- @return boolean Status. -- @return function The wrapped iterator. limited_iterator = function(iterator, time_limit, count_limit) local start, count, elem time_limit = (time_limit and time_limit > 0) and time_limit count_limit = (count_limit and count_limit > 0) and count_limit start = os.time() count = 0 return function(cmd) if cmd == "reset" then count = 0 else count = count + 1 end if count_limit and count > count_limit then return end if time_limit and os.time() - start >= time_limit then return end return iterator(cmd) end end --- Returns a function closure which returns a new password with every call -- until the username list is exhausted or either limit expires (in which cases -- it returns <code>nil</code>). -- @param time_limit Time limit in seconds. Use 0 for no limit. -- @param count_limit Count limit in seconds. Use 0 for no limit. -- @return boolean Status. -- @return function The usernames iterator. usernames = function(time_limit, count_limit) local status, iterator status, iterator = usernames_raw() if not status then return false, iterator end time_limit = time_limit or timelimit() if not count_limit and args["unpwdb.userlimit"] then count_limit = tonumber(args["unpwdb.userlimit"]) end return true, limited_iterator(iterator, time_limit, count_limit) end --- Returns a function closure which returns a new password with every call -- until the password list is exhausted or either limit expires (in which cases -- it returns <code>nil</code>). -- @param time_limit Time limit in seconds. Use 0 for no limit. -- @param count_limit Count limit in seconds. Use 0 for no limit. -- @return boolean Status. -- @return function The passwords iterator. passwords = function(time_limit, count_limit) local status, iterator status, iterator = passwords_raw() if not status then return false, iterator end time_limit = time_limit or timelimit() if not count_limit and args["unpwdb.passlimit"] then count_limit = tonumber(args["unpwdb.passlimit"]) end return true, limited_iterator(iterator, time_limit, count_limit) end --- Returns a new iterator that iterates through its consecutive iterators, -- basically concatenating them. -- @param iter1 First iterator to concatenate. -- @param iter2 Second iterator to concatenate. -- @return function The concatenated iterators. function concat_iterators (iter1, iter2) local function helper (next_iterator, command, first, ...) if first ~= nil then return first, ... elseif next_iterator ~= nil then return helper(nil, command, next_iterator(command)) end end local function iterator (command) if command == "reset" then iter1 "reset" iter2 "reset" else return helper(iter2, command, iter1(command)) end end return iterator end --- Returns a new iterator that filters its results based on the filter. -- @param iterator Iterator that needs to be filtered -- @param filter Function that returns bool, which serves as a filter -- @return function The filtered iterator. function filter_iterator (iterator, filter) return function (command) if command == "reset" then iterator "reset" else local val = iterator(command) while val and not filter(val) do val = iterator(command) end return val end end end return _ENV;