Skip to content

Latest commit

 

History

39 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CredzCheckr

Testing default web credentials

v.1.8

News v1.X

  • pma bf
  • top 300 passwd
  • "rd" option
  • News default usernames, passwords, inputs endpoints
  • fix any bugs

News v1.8

  • Fixed cross-module NameErrors (globals that were never shared between modules)
  • Fixed argument-order bugs in the bf_top_password() calls (bruteforce now receives the right params)
  • Fixed malformed ANSI escape codes in the live status lines
  • Fixed -U: -u is now correctly treated as a URLs file, and a hit on one URL no longer aborts the whole batch
  • Fixed time.sleep() on rate-limit (was passing a string), KeyErrors on unknown templates, and the broken input-detection parser
  • Fixed the bruteforce progress counter (it now resets per username and shows user (i/N) | pass i/N)
  • Python 3.12 compatible; requirements.txt now lists mmh3 (needed by the favicon fingerprint)
  • Content/header/cookie fingerprint in addition to the favicon hash (Django, Grafana, Jenkins, GitLab, WordPress, Joomla, phpMyAdmin, Tomcat)
  • Form-aware login submission: the tool now parses the real login form, carries over its hidden fields (CSRF tokens, framework markers like Django's this_is_the_login_form) and persists cookies (sessionid, csrftoken) through a session, and sets Referer — so CSRF-protected apps (Django & co.) can actually be tested
  • --rb raw request replay: feed a raw HTTP request copied from Burp/ZAP and bruteforce it directly (auto-detects the username/password fields, replays cookies + hidden fields + headers verbatim)
  • -T/--techno force the technology: skip fingerprinting and go straight to a known techno's default creds + form template (--list-techno prints the supported names)
  • Expanded default-credentials DB to 90 technologies / 200+ credentials (Django, Grafana, Jenkins, GitLab, Nexus, JBoss, WebLogic, Zabbix, Nagios, Proxmox, iDRAC, iLO, Cisco, Fortinet, Citrix, Confluence, Jira, RabbitMQ, MinIO, Hikvision, and many more), with content/header/cookie fingerprints for each

Install

git clone https://github.com/c0dejump/CredzCheckr.git
cd CredzCheckr
pip3 install -r requirements.txt

Usage

usage: credzcheckr.py [-h] [-u URL] [-U] [-w] [-b] [-i INPUTS] [-k [KEY_WORDS ...]] [-d DOMAIN]
                      [-X POST_REQUEST] [-uap] [-T TECHNO] [--list-techno] [--user USER_KNOWN] [--cookie COOKIE_] [--onlypass]
                      [--rf REQ_FILE] [--rd REQ_DATA] [--rb REQ_BURP] [--nomessage NOMESSAGE]

 optional arguments:
  -h, --help            show this help message and exit
  -u URL                URL login to test [required]
  -U, --urls_file       Treat -u as a file containing one URL per line.
  -w                    list of your passwords to test Default:
                        credz/wordlists/top_300_default_passwd.txt
  -b, --bruteforce      Bruteforce username/password
  -i INPUTS, --inputs INPUTS
                        if that not found inputs during the scan, this option add auto in inputs.txt
                        file. Ex: -i "user:passwd" 
  -k [KEY_WORDS ...], --key_words [KEY_WORDS ...]
                        if you want add personal password in list
  -d DOMAIN, --domain DOMAIN
                        Add domain to test all combinaison like domain@2019, domain2021...
  -X POST_REQUEST       POST requests URL Ex: credzcheckr -u toto.com/login -X
                        toto.com/login_check
  -uap, --user-as-pass  test user-as-pass
  -T TECHNO, --techno TECHNO
                        Force the technology instead of fingerprinting it (e.g. -T django)
  --list-techno         List the supported technologies and exit
  --user USER_KNOWN     If you want test just a known username
  --cookie COOKIE_      To add cookie
  --onlypass            If there is just only password to test
  --rf REQ_FILE         Json file containing the indications to carry out for a request
  --rd REQ_DATA         TXT file containing the data of the requests with 'BFU' for username & 'BFP' for password params (exemple in config/request_data.txt)
  --rb REQ_BURP         TXT file containing a raw HTTP request (Burp/ZAP). Creds auto-detected or marked with BFU/BFP
  --nomessage NOMESSAGE
                        if the value of this option is not found in the source code of the page it
                        will be considered as potentially found


Examples

	//Basic
	python3 credzcheckr.py -u URL/login.php 

	// With particular inputs
	python3 credzcheckr.py -u URL/login.php -i "user_input:password_input"

	// With a domain name
	python3 credzcheckr.py -u facebook.com/login.php -d facebook

	// BF default username/password
	python3 credzcheckr.py -u URL/login.php -b

	// Force the technology (skip fingerprinting)
	python3 credzcheckr.py -u URL/admin/ -T django -b
	python3 credzcheckr.py --list-techno

	// With specific format requests file
	python3 credzcheckr.py --rf config/request_json.json

	// Replay a raw Burp/ZAP request and bruteforce it (creds auto-detected)
	python3 credzcheckr.py --rb request.txt -b
	//   -> paste the raw request into request.txt; mark the fields with BFU/BFP
	//      if auto-detection misses them, e.g. username=BFU&password=BFP

	// With nomessage option
	python3 credzcheckr.py -u URL/login.php -b --nomessage "incorrect"

	// With POST redirect URL
	python3 credzcheckr.py -u URL/login.php -X URL/login_check.php 

alt tag alt tag

TODO

  • [IP] Different credentials forms
  • Get (nmap) file to scan
  • Captcha bypass
  • Selenium when javascript do enable
  • Bruteforce with user@domain.(fr/en...)
  • MF'er BF (bf as a dirty all possible combinations (have a good cpu) )

Credits

About

Testing default web credentials

Resources

Stars

35 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages