Sign inSign up

cyrinux/jok3r

By cyrinux

•Updated about 7 years ago

This is a POC, don't use me, archlinux fork from koutto/jok3r

Image
0

1.0K

cyrinux/jok3r repository overview

.. raw:: html

⁠

.. image:: ./pictures/logo.png

.. raw:: html


Jok3r v3 beta

.. image:: https://img.shields.io/badge/python-3.6-blue.svg⁠ :target: https://www.python.org/downloads/release/python-366/⁠ :alt: Python 3.6

.. image:: https://readthedocs.org/projects/jok3r/badge/?version=latest⁠ :target: https://jok3r.readthedocs.io/en/latest/⁠ :alt: Documentation ReadTheDocs

.. image:: https://img.shields.io/microbadger/image-size/koutto/jok3r.svg⁠ :target: https://hub.docker.com/r/koutto/jok3r/⁠ :alt: Docker Size

.. image:: https://img.shields.io/docker/cloud/build/koutto/jok3r.svg⁠ :alt: Docker Build Status

.. raw:: html

⁠Network & Web Pentest Automation Framework

www.jok3r-framework.com⁠

WARNING: Project is still in version 3 BETA. It is still under active development and bugs might be present.

Many tests are going on: see https://github.com/koutto/jok3r/blob/master/tests/TESTS.rst⁠. Ideas, bug reports, contributions are welcome !

.. contents:: :local: :depth: 1

⁠============= Overview

Jok3r is a Python3 CLI application which is aimed at helping penetration testers for network infrastructure and web black-box security tests.

The goal is to save as much time as possible during network/web pentests by automating as many security tests as possible in order to quickly identify low-hanging fruits vulnerabilities, and then spend more time on more interesting and tricky stuff !

It is based upon the observation that there are many hacking open-source tools/scripts (from various sources) targeting common network services available out there, that allow to perform various tasks from fingerprinting to exploitation. Therefore, the idea of Jok3r is to combine those open-source tools in a smart way to get the more relevant results.

⁠============= Features

⁠Pentest Toolbox management

  • Selection of Tools: Compilation of 50+ open-source tools & scripts, from various sources.
  • Docker-based: Application packaged in a Docker image running Kali OS, available on Docker Hub.
  • Ready-to-use: All tools and dependencies installed, just pull the Docker image and run a fresh container.
  • Updates made easy: Easily keep the whole toolbox up-to-date by running only one command.
  • Easy Customization: Easily add/remove tools from a simple configuration file.

⁠Network Infrastructure Security Assessment

  • Many supported Services: Target most common TCP/UDP services (HTTP, FTP, SSH, SMB, Oracle, MS-SQL, MySQL, PostgreSQL, VNC, etc.).
  • Combine Power of Tools: Each security check is performed by a tool from the toolbox. Attacks are performed by chaining security checks.
  • Context Awareness: Security checks to run are selected and adapted according to the context of the target (i.e. detected technologies, credentials, vulnerabilities, etc.).
  • Reconnaissance: Automatic fingerprinting (product detection) of targeted services is performed.
  • CVE Lookup: When product names and their versions are detected, a vulnerability lookup is performed on online CVE databases (using Vulners & CVE Details).
  • Vulnerability Scanning: Automatically check for common vulnerabilities and attempt to perform some exploitations (auto-pwn).
  • Brute-force Attack: Automatically check for default/common credentials on the service and perform dictionnary attack if necessary. Wordlists are optimized according to the targeted services.
  • Post-authentication Testing: Automatically perform some post-exploitation checks when valid credentials have been found.

⁠Web Security Assessment

  • Large Focus on HTTP: More than 60 different security checks targeting HTTP supported for now.
  • Web Technologies Detection: Fingerprinting engine based on Wappalyzer is run prior to security checks, allowing to detect: Programming language, Framework, JS library, CMS, Web & Application Server.
  • Server Exploitation: Automatically scan and/or exploit most critical vulnerabilities (e.g. RCE) on web and application servers (e.g. JBoss, Tomcat, Weblogic, Websphere, Jenkins, etc.).
  • CMS Vulnerability Scanning: Automatically run vulnerability scanners on most common CMS (Wordpress, Drupal, Joomla, etc.).

⁠Local Database & Reporting

  • Local Database: Data related to targets is organized by missions (workspaces) into a local Sqlite database that is kept updated during security testings.
  • Metasploit-like Interactive Shell: Access the database through an interactive shell with several built-in commands.
  • Import Targets from Nmap: Add targets to a mission either manually or by loading Nmap results.
  • Access all Results: All outputs from security checks, detected credentials and vulnerabilities are stored into the database and can be accessed easily.
  • Reporting: Generate full HTML reports with targets summary, web screenshots and all results from security testing.

⁠============ Demos

  • Example 1: Scan a JAVA-RMI (JMX) service:

.. image:: pictures/video-01.png :target: https://www.youtube.com/watch?v=FlbeBj5FPtI⁠

  • Example 2: Scan a Joomla website:

.. image:: pictures/video-02.png :target: https://www.youtube.com/watch?v=z4cf_8EQ59Q⁠

⁠============ Architecture

.. image:: ./pictures/visio/architecture/jok3r-architecture.png :alt: Jok3r architecture

.. image:: ./pictures/visio/flowchart/jok3r-flow-chart.svg :width: 700px :alt: Jok3r flowchart

⁠============ Installation

IMPORTANT: The recommended way to use Jok3r is by pulling the Docker Image so you will not have to worry about dependencies issues and installing the various hacking tools of the toolbox. Everything is tested from the Docker container available on Docker Hub !

.. image:: https://raw.githubusercontent.com/koutto/jok3r/master/pictures/docker-logo.png⁠

A Docker image is available on Docker Hub and automatically re-built at each update: https://hub.docker.com/r/koutto/jok3r/⁠. It is initially based on official Kali Linux Docker image (kalilinux/kali-linux-docker).

.. image:: https://images.microbadger.com/badges/image/koutto/jok3r.svg⁠ :target: https://microbadger.com/images/koutto/jok3r⁠ :alt: Docker Image size

  1. Pull Jok3r Docker Image:

    .. code-block:: console

     sudo docker pull koutto/jok3r
    
  2. Run fresh Docker container:

    .. code-block:: console

     sudo docker run -i -t --name jok3r-container -w /root/jok3r -e DISPLAY=$DISPLAY -v /tmp/.X11-unix:/tmp/.X11-unix --shm-size 2g --net=host koutto/jok3r
    

Notes:

  • -e DISPLAY=$DISPLAY -v /tmp/.X11-unix:/tmp/.X11-unix is required in order to be able to start GUI applicationfrom the Docker container (e.g. open web browser to read reports). It requires running xhost +local:root on the host.

  • --shm-size 2g is used to increase the size of the shared memory, it is required to avoid crashs of web browser when reading reports from the Docker container.

  • --net=host is required to share host's interface. It is needed for reverse connections (e.g. Ping to container when testing for RCE, Getting a reverse shell)

  1. To re-run a stopped container:

    .. code-block:: console

     sudo docker start -i jok3r-container
    
  2. To open multiple shells inside the container:

    .. code-block:: console

     sudo docker exec -it jok3r-container bash
    

⁠============ Update

In order to update, just pull the latest Docker Image from Docker Hub and run a fresh container from this new image:

.. code-block:: console

sudo docker pull koutto/jok3r
sudo docker run -i -t --name jok3r-container-updated -w /root/jok3r -e DISPLAY=$DISPLAY -v /tmp/.X11-unix:/tmp/.X11-unix --shm-size 2g --net=host koutto/jok3r

Note: Of course, you can retrieve your local database local.db (with your saved missions, targets...) from an old container by using the command sudo docker cp.

⁠==================== Quick usage examples

⁠Pentest Toolbox management

  • Show all the tools in the toolbox:

.. code-block:: console

python3 jok3r.py toolbox --show-all
  • Install all the tools in the toolbox (already done in Docker container):

.. code-block:: console

python3 jok3r.py toolbox --install-all --fast
  • Update all the tools in the toolbox and prompt each time to check update:

.. code-block:: console

python3 jok3r.py toolbox --update-all
  • Update all the tools in the toolbox without any prompt:

.. code-block:: console

python3 jok3r.py toolbox --update-all --fast

⁠Information

  • List supported services:

.. code-block:: console

python3 jok3r.py info --services
  • Show security checks for a given service:

.. code-block:: console

python3 jok3r.py info --checks <service>
  • Show supported attack profiles for a given service:

.. code-block:: console

python3 jok3r.py info --attack-profiles <service>
  • Show supported products for all services:

.. code-block:: console

python3 jok3r.py info --products

⁠Security Testing

Create a new mission in local database:

.. code-block:: console

python3 jok3r.py db

jok3rdb[default]> mission -a mayhem

[+] Mission "mayhem" successfully added
[*] Selected mission is now mayhem

jok3rdb[mayhem]> 

Single target:

  • Run all security checks against an URL in interactive mode and add results to the "mayhem" mission:

.. code-block:: console

python3 jok3r.py attack -t https://www.example.com/ --add2db mayhem
  • Run security checks against a MS-SQL service (without user-interaction) and add results to the mission:

.. code-block:: console

python3 jok3r.py attack -t 192.168.1.42:1433 -s mssql --add2db mayhem --fast
  • Run only "recon" and "vulnscan" security checks against an FTP service and add results to the mission:

.. code-block:: console

python3 jok3r.py attack -t 192.168.1.142:21 -s ftp --cat-only recon,vulnscan --add2db mayhem

Multiple targets:

  • Search only for "easy wins" (critical vulns & easy to exploit) on all services registered in mission "mayhem":

.. code-block:: console

python3 jok3r.py attack -m mayhem --profile red-team --fast
  • Run all security checks against all services in the given mission and store results in the database:

.. code-block:: console

python3 jok3r.py attack -m mayhem --fast
  • Run security checks against only FTP services running on ports 21/tcp and 2121/tcp from the mission:

.. code-block:: console

python3 jok3r.py attack -m mayhem -f "port=21,2121;service=ftp" --fast
  • Run security checks against only FTP services running on ports 2121/tcp and all HTTP services on 192.168.1.42 from the mission:

.. code-block:: console

python3 jok3r.py attack -m mayhem -f "port=2121;service=ftp" -f "ip=192.168.1.42;service=http"

⁠Database Access & Reporting

  • Select a mission:

.. code-block:: console

python3 jok3r.py db

jok3rdb[default]> mission mayhem

[*] Selected mission is now mayhem
  • Import hosts/services from Nmap results (XML) into the mission scope:

.. code-block:: console

jok3rdb[mayhem]> nmap results.xml
  • Display services, hosts, detected products & credentials registered in selected mission:

.. code-block:: console

jok3rdb[mayhem]> services
jok3rdb[mayhem]> hosts
jok3rdb[mayhem]> products
jok3rdb[mayhem]> creds
  • Search for string in checks results in selected mission:

.. code-block:: console

jok3rdb[mayhem]> results --search '<search_string>'
  • Display vulnerabilities automatically detected from checks outputs in selected mission (experimental):

.. code-block:: console

jok3rdb[mayhem]> vulns
  • Generate HTML report for the selected mission:

.. code-block:: console

jok3rdb[mayhem]> report

⁠====================== Typical usage example

You begin a pentest with several servers in the scope. Here is a typical example of usage of JoK3r:

  1. You run Nmap scan on the servers in the scope.

  2. You create a new mission (let's say "mayhem") in the local database:

.. code-block:: console

python3 jok3r.py db

jok3rdb[default]> mission -a mayhem

[+] Mission "mayhem" successfully added
[*] Selected mission is now mayhem

jok3rdb[mayhem]> 

3. You import your results from Nmap scan in the database:

.. code-block:: console

jok3rdb[mayhem]> nmap results.xml

4. You can then have a quick overview of all services and hosts in the scope, add some comments, add some credentials if you already have some knowledge about the targets (grey box pentest), and so on.

.. code-block:: console

jok3rdb[mayhem]> hosts

[...]

jok3rdb[mayhem]> services

[...]

5. Now, you can run security checks against some targets in the scope. For example, if you want to run checks against all Java-RMI services in the scope, you can run the following command:

.. code-block:: console

python3 jok3r.py attack -m mayhem -f "service=java-rmi" --fast

6. You can view the full results from the security checks either in live when the tools are executed or later from the database using the following command:

.. code-block:: console

jok3rdb[mayhem]> results

7. At any moment, it is possible to display data automatically extracted from security checks outputs, i.e. detected products, credentials & vulnerabilities.

.. code-block:: console

jok3rdb[mayhem]> products

[...]

jok3rdb[mayhem]> creds

[...]

jok3rdb[mayhem]> vulns

[...]

8. At any moment, you can generate an HTML report with a summary of all targets in the mission scope, screenshots of web pages for HTTP services and full outputs of all security checks that have been run:

.. code-block:: console

jok3rdb[mayhem]> report

⁠================== Full Documentation

Documentation writing in progress...

⁠===================================== Supported Services & Security Checks

Updated on: 12/07/2019

Lots of checks remain to be implemented and services must be added !! Work in progress ...

  • AJP (default 8009/tcp)_
  • FTP (default 21/tcp)_
  • HTTP (default 80/tcp)_
  • Java-RMI (default 1099/tcp)_
  • JDWP (default 9000/tcp)_
  • MSSQL (default 1433/tcp)_
  • MySQL (default 3306/tcp)_
  • Oracle (default 1521/tcp)_
  • PostgreSQL (default 5432/tcp)_
  • RDP (default 3389/tcp)_
  • SMB (default 445/tcp)_
  • SMTP (default 25/tcp)_
  • SNMP (default 161/udp)_
  • SSH (default 22/tcp)_
  • Telnet (default 21/tcp)_
  • VNC (default 5900/tcp)_

⁠AJP (default 8009/tcp)

.. code-block:: console

+------------------------+--------------+--------------------------------------------------------------------------+-------------------+
| Name                   | Category     | Description                                                              | Tool used         |
+------------------------+--------------+--------------------------------------------------------------------------+-------------------+
| nmap-recon             | recon        | Recon using Nmap AJP scripts                                             | nmap              |
| tomcat-version         | recon        | Fingerprint Tomcat version through AJP                                   | ajpy              |
| vulners-lookup         | vulnlookup   | Vulnerabilities lookup on Vulners.com (requires product name+version)    | vulners-lookup    |
| cvedetails-lookup      | vulnlookup   | Vulnerabilities lookup on Cvedetails.com (requires product name+version) | cvedetails-lookup |
| default-creds-tomcat   | defaultcreds | Check default credentials for Tomcat Application Manager through AJP     | ajpy              |
| deploy-webshell-tomcat | exploit      | Deploy a webshell on Tomcat through AJP and list applications            | ajpy              |
+------------------------+--------------+--------------------------------------------------------------------------+-------------------+

⁠FTP (default 21/tcp)

.. code-block:: console

+-------------------+--------------+--------------------------------------------------------------------------+-------------------+
| Name              | Category     | Description                                                              | Tool used         |
+-------------------+--------------+--------------------------------------------------------------------------+-------------------+
| nmap-recon        | recon        | Recon using Nmap FTP scripts                                             | nmap              |
| ftpmap-scan       | vulnscan     | Identify FTP server soft/version and check for known vulns               | ftpmap            |
| vulners-lookup    | vulnlookup   | Vulnerabilities lookup on Vulners.com (requires product name+version)    | vulners-lookup    |
| cvedetails-lookup | vulnlookup   | Vulnerabilities lookup on Cvedetails.com (requires product name+version) | cvedetails-lookup |
| default-creds     | defaultcreds | Check default/common credentials on FTP server                           | hydra             |
| bruteforce-creds  | bruteforce   | Bruteforce FTP accounts                                                  | hydra             |
| ftp-dirlisting    | postexploit  | List directories/files on FTP server (maxdepth=4)                        | lftp              |
+-------------------+--------------+--------------------------------------------------------------------------+-------------------+

⁠HTTP (default 80/tcp)

.. code-block:: console

+------------------------------------------+--------------+------------------------------------------------------------------------------------------------+-------------------------------+
| Name                                     | Category     | Description                                                                                    | Tool used                     |
+------------------------------------------+--------------+------------------------------------------------------------------------------------------------+-------------------------------+
| nmap-recon                               | recon        | Recon using Nmap HTTP scripts                                                                  | nmap                          |
| load-balancing-detection                 | recon        | HTTP load balancer detection                                                                   | halberd                       |
| waf-detection                            | recon        | Identify and fingerprint WAF products protecting website                                       | wafw00f                       |
| waf-detection2                           | recon        | Identify and fingerprint WAF products protecting website                                       | identifywaf                   |
| cloudmare-recon                          | recon        | CloudFlare real IP catcher                                                                     | cloudmare                     |
| fingerprinting-multi-whatweb             | recon        | Identify CMS, blogging platforms, JS libraries, Web servers                                    | whatweb                       |
| fingerprinting-appserver                 | recon        | Fingerprint application server (JBoss, ColdFusion, Weblogic, Tomcat, Railo, Axis2, Glassfish)  | clusterd                      |
| webdav-detection-msf                     | recon        | Detect WebDAV on webserver                                                                     | metasploit                    |
| fingerprinting-multi-wig                 | recon        | Fingerprint several CMS and web/application servers                                            | wig                           |
| fingerprinting-cms-cmseek                | recon        | Detect CMS (130+ supported), detect version on Drupal, advanced scan on Wordpress/Joomla       | cmseek                        |
| fingerprinting-cms-fingerprinter         | recon        | Fingerprint precisely CMS versions (based on files checksums)                                  | fingerprinter                 |
| fingerprinting-drupal                    | recon        | Fingerprint Drupal 7/8: users, nodes, default files, modules, themes enumeration               | drupwn                        |
| fingerprinting-domino                    | recon        | Fingerprint IBM/Lotus Domino software                                                          | domiowned                     |
| crawling-fast                            | recon        | Crawl website quickly, analyze interesting files/directories                                   | dirhunt                       |
| crawling-fast2                           | recon        | Crawl website and extract URLs, files, intel & endpoints                                       | photon                        |
| vulners-lookup                           | vulnlookup   | Vulnerabilities lookup (language, framework, jslib, cms, server, appserver) on Vulners.com     | vulners-lookup                |
| cvedetails-lookup                        | vulnlookup   | Vulnerabilities lookup (language, framework, jslib, cms, server, appserver) on Cvedetails.com  | cvedetails-lookup             |
| default-creds-web-multi                  | defaultcreds | Check for default credentials on various web interfaces                                        | changeme                      |
| default-creds-appserver                  | defaultcreds | Check for default/common credentials on appservers                                             | web-brutator                  |
| ssl-check                                | vulnscan     | Check for SSL/TLS configuration                                                                | testssl                       |
| headers-analysis                         | vulnscan     | Check HTTP headers                                                                             | h2t                           |
| vulnscan-multi-nikto                     | vulnscan     | Check for multiple web vulnerabilities/misconfigurations                                       | nikto                         |
| webdav-scan-davscan                      | vulnscan     | Scan HTTP WebDAV                                                                               | davscan                       |
| webdav-internal-ip-disclosure            | vulnscan     | Check for WebDAV internal IP disclosure                                                        | metasploit                    |
| webdav-website-content                   | vulnscan     | Detect webservers disclosing its content through WebDAV                                        | metasploit                    |
| http-put-check                           | vulnscan     | Detect the support of dangerous HTTP PUT method                                                | metasploit                    |
| apache-optionsbleed-check                | vulnscan     | Test for the Optionsbleed bug in Apache httpd (CVE-2017-9798)                                  | optionsbleed                  |
| shellshock-scan                          | vulnscan     | Detect if web server is vulnerable to Shellshock (CVE-2014-6271)                               | shocker                       |
| iis-shortname-scan                       | vulnscan     | Scan for IIS short filename (8.3) disclosure vulnerability                                     | iis-shortname-scanner         |
| iis-internal-ip-disclosure               | vulnscan     | Check for IIS internal IP disclosure                                                           | metasploit                    |
| tomcat-user-enum                         | vulnscan     | Enumerate users on Tomcat 4.1.0-4.1.39, 5.5.0-5.5.27 and 6.0.0-6.0.18                          | metasploit                    |
| jboss-vulnscan-multi                     | vulnscan     | Scan JBoss application server for multiple vulnerabilities                                     | metasploit                    |
| jboss-status-infoleak                    | vulnscan     | Queries JBoss status servlet to collect sensitive information 

Tag summary

Content type

Image

Digest

Size

2.7 GB

Last updated

about 7 years ago

docker pull cyrinux/jok3r