lot of stuff
This commit is contained in:
parent
8a9b822cf6
commit
97a4c5801b
@ -10,102 +10,109 @@ $name = filter_input(INPUT_GET, 'name', FILTER_VALIDATE_REGEXP, [
|
||||
'options' => ['regexp' => '/^[^<>:"\/|?]+$/'],
|
||||
]);
|
||||
|
||||
$hostsListRegex = "/^[\da-zA-Z-.,:\/]+$/";
|
||||
$compareWith = filter_input(INPUT_GET, 'compareWith', FILTER_VALIDATE_REGEXP, [
|
||||
'flags' => FILTER_NULL_ON_FAILURE,
|
||||
'options' => ['regexp' => '/^[^<>:"\/|?]+$/'],
|
||||
]);
|
||||
|
||||
$hostsListRegex = "/^[\da-zA-Z-.,:\/]+$/";
|
||||
$protocolePortsListRegex = "/^(([TU]:)?[0-9\-]+|[a-z\-]+)(,([TU]:)?[0-9\-]+|,[a-z\-]+)*$/";
|
||||
$portsListRegex = "/^([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*$/";
|
||||
$tempoRegex = "/^\d+[smh]?$/";
|
||||
$portsListRegex = "/^([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*$/";
|
||||
$tempoRegex = "/^\d+[smh]?$/";
|
||||
|
||||
$inputs = filter_input_array(INPUT_GET, [
|
||||
'iR' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-exclude' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]],
|
||||
'iR' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'exclude' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]],
|
||||
|
||||
'sL' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]],
|
||||
'sP' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'P0' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'Pn' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PS' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]],
|
||||
'PA' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]],
|
||||
'PU' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]],
|
||||
'PE' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PP' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PO' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 255]],
|
||||
'n' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'R' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-dns-servers' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]],
|
||||
|
||||
'sS' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sT' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sA' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sW' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sF' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sN' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sX' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PU' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sL' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]],
|
||||
'sP' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'P0' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'Pn' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PS' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]],
|
||||
'PA' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]],
|
||||
'PU' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]],
|
||||
'PE' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PP' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-scanflags' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^([URG|ACK|PSH|RST|SYN|FIN]+)$|^([0-2]?\d?\d)$/"]],
|
||||
'sI' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^[a-zA-Z\d:.-]+(:\d+)?$/"]],
|
||||
'sO' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'b' => FILTER_VALIDATE_DOMAIN,
|
||||
'-traceroute' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-reason' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PO' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 255]],
|
||||
'PR' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'send-ip' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'n' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'R' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'dns-servers' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]],
|
||||
|
||||
'p' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]],
|
||||
'F' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'r' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-top-ports' => FILTER_VALIDATE_INT,
|
||||
'-port-ratio' => ['filter' => FILTER_VALIDATE_FLOAT, 'options' => ['min_range' => 0, 'max_range' => 1]],
|
||||
'sS' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sT' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sA' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sW' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sF' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sN' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sX' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PU' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'scanflags' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^([URG|ACK|PSH|RST|SYN|FIN]+)$|^([0-2]?\d?\d)$/"]],
|
||||
'sI' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^[a-zA-Z\d:.-]+(:\d+)?$/"]],
|
||||
'sO' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'b' => FILTER_VALIDATE_DOMAIN,
|
||||
'traceroute' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'reason' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
|
||||
'sV' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-version-light' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-version-intensity' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 9]],
|
||||
'-version-all' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-version-trace' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'p' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]],
|
||||
'F' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'r' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'top-ports' => FILTER_VALIDATE_INT,
|
||||
'port-ratio' => ['filter' => FILTER_VALIDATE_FLOAT, 'options' => ['min_range' => 0, 'max_range' => 1]],
|
||||
|
||||
'O' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-osscan-limit' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-osscan-guess' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'sV' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'version-light' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'version-intensity' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 9]],
|
||||
'version-all' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'version-trace' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
|
||||
'T0' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T1' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T2' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T3' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T4' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T5' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-min-hostgroup' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-max-hostgroup' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-min-parallelism' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-max-parallelism' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-min-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'-max-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'-initial-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'-max-retries' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-host-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'-scan-delay' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'-max-scan-delay' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'O' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'osscan-limit' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'osscan-guess' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
|
||||
'f' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'mtu' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'D' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]],
|
||||
'S' => ['filter' => FILTER_VALIDATE_IP],
|
||||
'e' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^[a-z\d]+$/"]],
|
||||
'g' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-source-port' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-data-length' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'-ip-options' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^\"(R|T|U|L [\da-zA-Z-.: ]+|S [\da-zA-Z-.: ]+|\\\\x[\da-fA-F]{1,2}(\*[\d]+)?|\\\\[0-2]?[\d]{1,2}(\*[\d]+)?)\"$/"]],
|
||||
'ttl' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 255]],
|
||||
'-spoof-mac' => ['filter' => FILTER_VALIDATE_MAC],
|
||||
'-badsum' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T0' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T1' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T2' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T3' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T4' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'T5' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'min-hostgroup' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'max-hostgroup' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'min-parallelism' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'max-parallelism' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'min-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'max-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'initial-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'max-retries' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'host-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'scan-delay' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
'max-scan-delay' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]],
|
||||
|
||||
//'6' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'A' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-send-eth' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-send-ip' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-privileged' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'V' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'-unprivileged' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'h' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'f' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'mtu' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'D' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]],
|
||||
'S' => ['filter' => FILTER_VALIDATE_IP],
|
||||
'e' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^[a-z\d]+$/"]],
|
||||
'g' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'source-port' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'data-length' => ['filter' => FILTER_VALIDATE_INT],
|
||||
'ip-options' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^\"(R|T|U|L [\da-zA-Z-.: ]+|S [\da-zA-Z-.: ]+|\\\\x[\da-fA-F]{1,2}(\*[\d]+)?|\\\\[0-2]?[\d]{1,2}(\*[\d]+)?)\"$/"]],
|
||||
'ttl' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 255]],
|
||||
'spoof-mac' => ['filter' => FILTER_VALIDATE_MAC],
|
||||
'badsum' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
|
||||
//'6' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'A' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'send-eth' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'send-ip' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'privileged' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'V' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'unprivileged' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
'h' => ['filter' => FILTER_VALIDATE_BOOLEAN],
|
||||
], false) ?: $DEFAULT_ARGS;
|
||||
|
55
index.php
55
index.php
@ -25,40 +25,41 @@ include_once 'filter_inputs.php';
|
||||
</a>
|
||||
<div class="right menu">
|
||||
<form class="ui category search item" onsubmit="targetsInputDiv.classList.add('loading')">
|
||||
<div id="targetsInputDiv" class="ui icon input">
|
||||
<input class="prompt" type="text" id="targetsInput" name="targets" required="" oninput="hiddenInput.value=this.value"
|
||||
pattern="[a-zA-Z0-9._\/ \-]+" value="<?= $targets; ?>" placeholder="Scanner un réseau..."
|
||||
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
|
||||
Exemples: <?= $_SERVER['REMOTE_ADDR']; ?>/24 <?= $_SERVER['SERVER_NAME']; ?> 10.0-255.0-255.1-254" />
|
||||
<i class="satellite dish icon"></i>
|
||||
<button style="display:none" type="submit" formaction="scan.php" formmethod="get"></button>
|
||||
<div class="fiels">
|
||||
<div id="targetsInputDiv" class="ui icon input">
|
||||
<input class="prompt" type="text" id="targetsInput" name="targets" oninput="hiddenInput.value=this.value" required
|
||||
pattern="[a-zA-Z0-9._\/ \-]+" value="<?= $targets; ?>" placeholder="Scanner un réseau..."
|
||||
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
|
||||
Exemples: <?= $_SERVER['REMOTE_ADDR']; ?>/24 <?= $_SERVER['SERVER_NAME']; ?> 10.0-255.0-255.1-254" />
|
||||
<i class="satellite dish icon"></i>
|
||||
</div>
|
||||
<button style="display: none;" type="submit" formmethod="get" formaction="scan.php"></button>
|
||||
<button class="ui teal icon submit button" type="submit" formmethod="get" formaction="options.php" onclick="targetsInput.required=false">
|
||||
<i class="sliders horizontal icon"></i>
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
<form class="item" method="get" action="scan-options.php">
|
||||
<input id="hiddenInput" type="hidden" name="targets" value="<?= $targets; ?>" />
|
||||
<input id="hiddenInput" type="hidden" name="name" value="<?= $name; ?>" />
|
||||
<?= '<input type="hidden" name="' . str_replace('=', '" value="', http_build_query($inputs, '', '/><input type="hidden" name="')) . '"/>'; ?>
|
||||
<button class="ui teal submit button" type="submit">Options</button>
|
||||
</form>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<main class="ui main container">
|
||||
<div class="ui large relaxed card">
|
||||
<div class="content">
|
||||
<div class="header">Précédents scans</div>
|
||||
<div class="ui divided link list">
|
||||
<?php
|
||||
if (!file_exists($SCANS_DIR)) {
|
||||
mkdir($SCANS_DIR);
|
||||
}
|
||||
foreach (scandir($SCANS_DIR) as $scan) {
|
||||
if (substr($scan, -4) == '.xml') {
|
||||
$targets = str_replace('!', '/', substr_replace($scan, '', -4));
|
||||
echo "<a class='item' href='scan.php?targets=" . urlencode($targets) . "'>$targets</a>\n";
|
||||
<div class="ui middle aligned center aligned grid">
|
||||
<div class="ui large relaxed card">
|
||||
<div class="content">
|
||||
<div class="header">Précédents scans</div>
|
||||
<div class="ui divided link list">
|
||||
<?php
|
||||
if (!file_exists($SCANS_DIR)) {
|
||||
mkdir($SCANS_DIR);
|
||||
}
|
||||
}
|
||||
?>
|
||||
foreach (scandir($SCANS_DIR) as $scan) {
|
||||
if (substr($scan, -4) == '.xml') {
|
||||
$targets = str_replace('!', '/', substr_replace($scan, '', -4));
|
||||
echo "<a class='item' href='scan.php?targets=" . urlencode($targets) . "'>$targets</a>\n";
|
||||
}
|
||||
}
|
||||
?>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
307
options.php
Executable file
307
options.php
Executable file
@ -0,0 +1,307 @@
|
||||
<?php
|
||||
include_once 'config.php';
|
||||
include_once 'filter_inputs.php';
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
<html lang="fr">
|
||||
|
||||
<head>
|
||||
<meta charset="utf-8" />
|
||||
<title>lanScan</title>
|
||||
<link rel="icon" href="favicon.ico" />
|
||||
<script src="https://cdn.jsdelivr.net/npm/jquery@3.7.1/dist/jquery.min.js"></script>
|
||||
<script src="https://cdn.jsdelivr.net/npm/fomantic-ui@2.9.3/dist/semantic.min.js"></script>
|
||||
<link rel="stylesheet" type="text/css"
|
||||
href="https://cdn.jsdelivr.net/npm/fomantic-ui@2.9.3/dist/semantic.min.css" />
|
||||
<script src="https://cdn.jsdelivr.net/npm/@yaireo/tagify"></script>
|
||||
<script src="https://cdn.jsdelivr.net/npm/@yaireo/tagify/dist/tagify.polyfills.min.js"></script>
|
||||
<link href="https://cdn.jsdelivr.net/npm/@yaireo/tagify/dist/tagify.css" rel="stylesheet" type="text/css" />
|
||||
<link href="style.css" rel="stylesheet" type="text/css" />
|
||||
</head>
|
||||
|
||||
<body>
|
||||
<nav class="ui inverted teal fixed menu">
|
||||
<a class="header item" href=".">
|
||||
lan<?php include 'logo.svg'; ?>can
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<main class="ui main container">
|
||||
<h1 class="header">Scanner un réseau avec Nmap</h1>
|
||||
|
||||
<form id="newScanForm" class="ui form" method="get" action="scan.php">
|
||||
<div class="required field">
|
||||
<label for="targetsInput" title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
|
||||
Exemples: <?= $_SERVER['REMOTE_ADDR']; ?>/24 <?= $_SERVER['SERVER_NAME']; ?> 10.0-255.0-255.1-254">Cibles</label>
|
||||
<input id="targetsInput" type="text" name="targets" placeholder="Cibles" required
|
||||
pattern="[a-zA-Z0-9._\/ \-]+" value="<?= $targets; ?>" list="targetsList"
|
||||
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
|
||||
Exemples: <?= $_SERVER['REMOTE_ADDR']; ?>/24 <?= $_SERVER['SERVER_NAME']; ?> 10.0-255.0-255.1-254" />
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label for="nameInput">Enregistrer sous le nom</label>
|
||||
<input id="nameInput" type="text" name="name" placeholder="Réseau local" pattern='[^<>:"\\\/\|@?]+'
|
||||
title='Caractères interdits : <>:"\/|@?'
|
||||
value="<?= htmlspecialchars($name); ?>">
|
||||
</div>
|
||||
|
||||
<div class="ui styled fluid accordion field">
|
||||
<div class="title">
|
||||
<i class="icon dropdown"></i>
|
||||
Découverte des hôtes actifs
|
||||
</div>
|
||||
<div class="content">
|
||||
<div class="inline field" title="-Pn">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PnCheckbox" name="Pn" <?= $inputs['Pn'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PnCheckbox">Sauter cette étape (considérer tous les hôtes comme actifs)</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="fields">
|
||||
<div class="field" title="-PS">
|
||||
<label for="PSInput">TCP SYN</label>
|
||||
<input type="text" id="PSInput" name="-PS" placeholder="Ports" list="servicesList"
|
||||
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?= $inputs['PS'] ?? "" ?>"
|
||||
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
|
||||
</div>
|
||||
<div class="field" title="-PA">
|
||||
<label for="PAInput">TCP ACK</label>
|
||||
<input type="text" id="PAInput" name="-PA" placeholder="Ports" list="servicesList"
|
||||
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?= $inputs['PA'] ?? "" ?>"
|
||||
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
|
||||
</div>
|
||||
<div class="field" title="-PU">
|
||||
<label for="PUInput">UDP</label>
|
||||
<input type="text" id="PUInput" name="-PU" placeholder="Ports" list="servicesList"
|
||||
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?= $inputs['PU'] ?? "" ?>"
|
||||
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label>ICMP</label>
|
||||
<div class="inline fields">
|
||||
<div class="field" title="-PE">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PECheckbox" name="-PE" <?= $inputs['PE'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PECheckbox">Echo request</label>
|
||||
</div>
|
||||
</div>
|
||||
<div class="field" title="-PP">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PPCheckbox" name="PP" <?= $inputs['PP'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PPCheckbox">Timestamp request</label>
|
||||
</div>
|
||||
</div>
|
||||
<div class="field" title="-PM">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PMCheckbox" name="PM" <?= $inputs['PM'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PMCheckbox">Mask request</label>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field" title="--exclude">
|
||||
<label for="excludeInput">Exclure les hôtes ou réseaux</label>
|
||||
<input type="text" id="excludeInput" name="exclude" placeholder="Hôte/réseau" list="targetsList"
|
||||
pattern="[a-zA-Z0-9._\/,\-]*" value="<?= $inputs['exclude'] ?? "" ?>">
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field" title="-PO">
|
||||
<label for="POInput" title="PO">Protocole IP (par type)</label>
|
||||
<input type="text" id="POInput" name="P0" placeholder="Protocole"
|
||||
pattern="[0-9,\-]+" value="<?= $inputs['PO'] ?? "" ?>"
|
||||
title="[num de protocole]">
|
||||
</div>
|
||||
|
||||
<div class="fields">
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PRCheckbox" name="PR" <?= $inputs['PR'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PRCheckbox" title="PR">Ping ARP</label>
|
||||
</div>
|
||||
</div>
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="sendIPCheckbox" name="send-ip" <?= $inputs['send-ip'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="sendIPCheckbox" title="send-ip">Pas de scan ARP</label>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="fields">
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="nCheckbox" name="n" <?= $inputs['n'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="nCheckbox" title="n">Ne jamais résoudre les noms DNS</label>
|
||||
</div>
|
||||
</div>
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="RCheckbox" name="R" <?= $inputs['R'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="nCheckbox" title="R">Toujours résoudre les noms DNS<br />(par défault seuls les hôtes actifs sont résolus)</label>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label for="dnsServersInput" title="dns-servers">Utiliser les serveurs DNS</label>
|
||||
<input type="text" id="dnsServersInput" name="dns-servers" placeholder="serveur"
|
||||
pattern="[a-zA-Z0-9._,\-]*" value="<?= $inputs['dns-servers'] ?? "" ?>"
|
||||
title="serv1[,serv2],...">
|
||||
</div>
|
||||
|
||||
<div class="field" title="--exclude">
|
||||
<label for="excludeInput">Exclure les hôtes ou réseaux</label>
|
||||
<input type="text" id="excludeInput" name="exclude" placeholder="Hôte/réseau" list="targetsList"
|
||||
pattern="[a-zA-Z0-9._\/,\-]*" value="<?= $inputs['exclude'] ?? "" ?>">
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="title">
|
||||
<i class="icon dropdown"></i>
|
||||
Techniques de scan
|
||||
</div>
|
||||
<div class="content">
|
||||
<div class="inline field" title="-sP">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="sPCheckbox" name="sP" <?= $inputs['sP'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="sPCheckbox">Sauter cette étape</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="FCheckbox" name="F" <?= $inputs['F'] ?? false ? 'checked' : ''; ?>
|
||||
onchange="pInput.disabled = FCheckbox.checked" />
|
||||
<label for="FCheckbox" title="F">Scanner les ports connus</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label for="pInput" title="p">Scanner les ports</label>
|
||||
<input type="text" id="pInput" name="p" placeholder="Ports" list="servicesList" <?= $inputs['F'] ?? false ? 'disabled' : ''; ?>
|
||||
pattern="(([TU]:)?[0-9\-]+|[a-z\-]+)(,([TU]:)?[0-9\-]+|,[a-z\-]+)*" value="<?= $inputs['p'] ?? "" ?>"
|
||||
title="Liste de ports ex: ssh,ftp,U:53,111,137,T:21-25,80,139,8080">
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="rCheckbox" name="r" <?= $inputs['r'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="rCheckbox" title="r">Ne pas mélanger les ports</label>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="title">
|
||||
<i class="icon dropdown"></i>
|
||||
Divers
|
||||
</div>
|
||||
<div class="content">
|
||||
<div class="field">
|
||||
<label for="compareWithSelect">Comparer avec un précédent scan</label>
|
||||
<select class="ui dropdown" id="compareWithSelect" name="compareWith" value="<?= $compareWith ?>">
|
||||
<option value="">Précédent scan</option>
|
||||
<?php
|
||||
if (!file_exists($SCANS_DIR)) mkdir($SCANS_DIR);
|
||||
foreach (scandir($SCANS_DIR) as $filename) {
|
||||
if (substr($filename, -4) === '.xml') {
|
||||
$name = substr($filename, 0, -4);
|
||||
if ($name == $compareWith) {
|
||||
echo " <option value='$name' selected>$name</option>\n";
|
||||
} else {
|
||||
echo " <option value='$name'>$name</option>\n";
|
||||
}
|
||||
}
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<button type="submit" class="ui teal submit button">Démarrer</button>
|
||||
</form>
|
||||
|
||||
<h2 class="ui header">Précédents scans</h2>
|
||||
<div class="ui fluid relaxed card">
|
||||
<div class="content">
|
||||
<div class="ui divided link list">
|
||||
<?php
|
||||
if (!file_exists($SCANS_DIR)) {
|
||||
mkdir($SCANS_DIR);
|
||||
}
|
||||
foreach (scandir($SCANS_DIR) as $scan) {
|
||||
if (substr($scan, -4) == '.xml') {
|
||||
$targets = str_replace('!', '/', substr_replace($scan, '', -4));
|
||||
echo "<a class='item' href='scan.php?targets=" . urlencode($targets) . "'>$targets</a>\n";
|
||||
}
|
||||
}
|
||||
?>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</main>
|
||||
|
||||
<datalist id='targetsList'>
|
||||
<option value="<?= $_SERVER['REMOTE_ADDR']; ?>/24"></option>
|
||||
<option value="<?= $_SERVER['SERVER_NAME']; ?>"></option>
|
||||
</datalist>
|
||||
<datalist id='servicesList'>
|
||||
<?php
|
||||
$nmap_services = file("$NMAP_DATADIR/nmap-services");
|
||||
$services = [];
|
||||
foreach ($nmap_services as $service) {
|
||||
if (0 !== strpos($service, '#')) {
|
||||
[$name, $port] = explode("\t", $service);
|
||||
$services[$name] = explode("/", $port);
|
||||
}
|
||||
}
|
||||
foreach ($services as $name => [$portid, $protocol]) {
|
||||
echo " <option value='$name'></option>\n";
|
||||
}
|
||||
?>
|
||||
</datalist>
|
||||
|
||||
<script>
|
||||
class TagsInput extends Tagify {
|
||||
constructor(input, originalInputValueDelimiter = ",") {
|
||||
super(input, {
|
||||
delimiters: " |,",
|
||||
originalInputValueFormat: tags => tags.map(tag => tag.value).join(originalInputValueDelimiter),
|
||||
})
|
||||
if (!this.whitelist.length && input.list) this.whitelist = Array.from(input.list.options).map(option => option.value)
|
||||
}
|
||||
}
|
||||
|
||||
$(".ui.accordion").accordion()
|
||||
|
||||
$("#compareWithSelect").dropdown({
|
||||
clearable: true
|
||||
})
|
||||
|
||||
new TagsInput(targetsInput, " ")
|
||||
new TagsInput(excludeInput)
|
||||
new TagsInput(PSInput)
|
||||
new TagsInput(PAInput)
|
||||
new TagsInput(PUInput)
|
||||
new TagsInput(POInput)
|
||||
new TagsInput(pInput)
|
||||
new TagsInput(dnsServersInput)
|
||||
|
||||
newScanForm.onsubmit = function(event) {
|
||||
if (this.checkValidity()) {
|
||||
newScanForm.classList.add("loading")
|
||||
return true
|
||||
} else {
|
||||
event.preventDefault()
|
||||
this.reportValidity()
|
||||
}
|
||||
}
|
||||
</script>
|
||||
</body>
|
||||
|
||||
</html>
|
259
scan-options.php
259
scan-options.php
@ -1,259 +0,0 @@
|
||||
<?php
|
||||
include_once 'config.php';
|
||||
include_once 'filter_inputs.php';
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
<html lang="fr">
|
||||
|
||||
<head>
|
||||
<meta charset="utf-8" />
|
||||
<title>lanScan</title>
|
||||
<link rel="icon" href="favicon.ico" />
|
||||
<script src="https://cdn.jsdelivr.net/npm/jquery@3.7.1/dist/jquery.min.js"></script>
|
||||
<script src="https://cdn.jsdelivr.net/npm/fomantic-ui@2.9.3/dist/semantic.min.js"></script>
|
||||
<link rel="stylesheet" type="text/css"
|
||||
href="https://cdn.jsdelivr.net/npm/fomantic-ui@2.9.3/dist/semantic.min.css" />
|
||||
<script src="https://cdn.jsdelivr.net/npm/@yaireo/tagify"></script>
|
||||
<script src="https://cdn.jsdelivr.net/npm/@yaireo/tagify/dist/tagify.polyfills.min.js"></script>
|
||||
<link href="https://cdn.jsdelivr.net/npm/@yaireo/tagify/dist/tagify.css" rel="stylesheet" type="text/css" />
|
||||
<link href="style.css" rel="stylesheet" type="text/css" />
|
||||
</head>
|
||||
|
||||
<body>
|
||||
<nav class="ui inverted teal fixed menu">
|
||||
<a class="header item" href=".">
|
||||
lan<?php include 'logo.svg'; ?>can
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<main class="ui main container">
|
||||
<h1 class="header">Scanner un réseau avec Nmap</h1>
|
||||
|
||||
<form id="newScanForm" class="ui form" method="get" action="scan.php">
|
||||
|
||||
<!--<div class="field">
|
||||
<label for="nameInput">Nom</label>
|
||||
<input id="nameInput" type="text" name="name" placeholder="Réseau local" pattern='[^<>:"\\\/\|@?]+'
|
||||
title='Nom de fichier valide (ne contenant pas les caractères <>:"\/|@?)'
|
||||
value="<?= htmlspecialchars($name); ?>">
|
||||
</div>-->
|
||||
<div class="required field">
|
||||
<label for="targetsInput">Cibles</label>
|
||||
<input id="targetsInput" type="text" name="targets" placeholder="Cibles" required
|
||||
pattern="[a-zA-Z0-9._\/ \-]+" value="<?= $targets; ?>" list="targetsList"
|
||||
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
|
||||
Exemples: <?= $_SERVER['REMOTE_ADDR']; ?>/24 <?= $_SERVER['SERVER_NAME']; ?> 10.0-255.0-255.1-254" />
|
||||
</div>
|
||||
|
||||
<div class="ui styled fluid accordion field">
|
||||
<div class="title"><i class="icon dropdown"></i>Spécification des cibles</div>
|
||||
<div class="content">
|
||||
<div class="field">
|
||||
<label for="excludeInput">Exclure les hôtes ou réseaux</label>
|
||||
<input type="text" id="excludeInput" name="-exclude" placeholder="Hôte/réseau" list="targetsList"
|
||||
pattern="[a-zA-Z0-9._\/,\-]*" value="<?= $inputs['-exclude'] ?? "" ?>"
|
||||
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
|
||||
Exemples: <?= $_SERVER['REMOTE_ADDR']; ?>/24,<?= $_SERVER['SERVER_NAME']; ?>,10.0-255.0-255.1-254">
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="title"><i class="icon dropdown"></i>Découverte des hôtes actifs</div>
|
||||
<div class="content">
|
||||
<div class="inline field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="sPCheckbox" name="sP" <?= $inputs['sP'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="sPCheckbox">N'effectuer que l'étape de découverte des hôtes actifs</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="inline field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PnCheckbox" name="Pn" <?= $inputs['Pn'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PnCheckbox">Considérer tous les hôtes comme actifs (saute la découverte des hôtes)</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="fields">
|
||||
<div class="field">
|
||||
<label for="PSInput">Ping TCP SYN</label>
|
||||
<input type="text" id="PSInput" name="PS" placeholder="Ports" list="servicesList"
|
||||
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?= $inputs['PS'] ?? "" ?>"
|
||||
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
|
||||
</div>
|
||||
<div class="field">
|
||||
<label for="PAInput">Ping TCP ACK</label>
|
||||
<input type="text" id="PAInput" name="PA" placeholder="Ports" list="servicesList"
|
||||
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?= $inputs['PA'] ?? "" ?>"
|
||||
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
|
||||
</div>
|
||||
<div class="field">
|
||||
<label for="PUInput">Ping UDP</label>
|
||||
<input type="text" id="PUInput" name="PU" placeholder="Ports" list="servicesList"
|
||||
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?= $inputs['PU'] ?? "" ?>"
|
||||
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label>Ping ICMP</label>
|
||||
<div class="inline fields">
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PECheckbox" name="PE" <?= $inputs['PE'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PECheckbox">Echo request</label>
|
||||
</div>
|
||||
</div>
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PPCheckbox" name="PP" <?= $inputs['PP'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PPCheckbox">Timestamp request</label>
|
||||
</div>
|
||||
</div>
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PMCheckbox" name="PM" <?= $inputs['PM'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PMCheckbox">Mask request</label>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="PRCheckbox" name="PR" <?= $inputs['PR'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="PRCheckbox">Ping ARP</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label for="P0Input">Ping IP Protocol</label>
|
||||
<input type="text" id="P0Input" name="P0" placeholder="Ports"
|
||||
pattern="[0-9\-]+" value="<?= $inputs['P0'] ?? "" ?>"
|
||||
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="title"><i class="icon dropdown"></i>Techniques de scan</div>
|
||||
<div class="content">
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="FCheckbox" name="F" <?= $inputs['F'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="FCheckbox">Scanner que les ports connus</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label for="pInput">Scanner que les ports</label>
|
||||
<input type="text" id="pInput" name="p" placeholder="Ports" list="servicesList"
|
||||
pattern="(([TU]:)?[0-9\-]+|[a-z\-]+)(,([TU]:)?[0-9\-]+|,[a-z\-]+)*" value="<?= $inputs['p'] ?? "" ?>"
|
||||
title="Liste de ports ex: ssh,ftp,U:53,111,137,T:21-25,80,139,8080">
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<div class="ui toggle checkbox">
|
||||
<input type="checkbox" id="rCheckbox" name="r" <?= $inputs['r'] ?? false ? 'checked' : ''; ?> />
|
||||
<label for="rCheckbox">Ne pas mélanger les ports</label>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
|
||||
<button type="submit" class="ui teal submit button">Démarrer</button>
|
||||
</form>
|
||||
|
||||
<datalist id='targetsList'>
|
||||
<option value="<?= $_SERVER['REMOTE_ADDR']; ?>"></option>
|
||||
<option value="192.168.1.0/24"></option>
|
||||
<option value="<?= $_SERVER['SERVER_NAME']; ?>"></option>
|
||||
<?php
|
||||
if (!file_exists($SCANS_DIR)) {
|
||||
mkdir($SCANS_DIR);
|
||||
}
|
||||
foreach (scandir($SCANS_DIR) as $scan) {
|
||||
if ('.xml' == substr($scan, -4)) {
|
||||
$targets = str_replace('!', '/', substr_replace($scan, '', -4));
|
||||
echo " <option value='$targets'></option>\n";
|
||||
}
|
||||
}
|
||||
?>
|
||||
</datalist>
|
||||
<datalist id='servicesList'>
|
||||
<?php
|
||||
$nmap_services = file("$NMAP_DATADIR/nmap-services");
|
||||
$services = [];
|
||||
foreach ($nmap_services as $service) {
|
||||
if (0 !== strpos($service, '#')) {
|
||||
[$name, $port] = explode("\t", $service);
|
||||
$services[$name] = explode("/", $port);
|
||||
}
|
||||
}
|
||||
foreach ($services as $name => [$portid, $protocol]) {
|
||||
echo " <option value='$name'></option>\n";
|
||||
}
|
||||
?>
|
||||
</datalist>
|
||||
</main>
|
||||
<script>
|
||||
class TagsInput extends Tagify {
|
||||
constructor(input, options) {
|
||||
super(input, options)
|
||||
if (!this.whitelist.length && input.list) this.whitelist = Array.from(input.list.options).map(option => option.value)
|
||||
console.log(this.whitelist, input.list)
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
const joinWithSpaces = tags => tags.map(tag => tag.value).join(' ')
|
||||
const joinWithCommas = tags => tags.map(tag => tag.value).join(',')
|
||||
|
||||
$('.ui.accordion').accordion()
|
||||
|
||||
new TagsInput(targetsInput, {
|
||||
delimiters: " |,",
|
||||
originalInputValueFormat: joinWithSpaces,
|
||||
})
|
||||
|
||||
new TagsInput(excludeInput, {
|
||||
delimiters: " |,",
|
||||
originalInputValueFormat: joinWithCommas,
|
||||
})
|
||||
|
||||
new TagsInput(PSInput, {
|
||||
delimiters: " |,",
|
||||
originalInputValueFormat: joinWithCommas,
|
||||
})
|
||||
|
||||
new TagsInput(PAInput, {
|
||||
delimiters: " |,",
|
||||
originalInputValueFormat: joinWithCommas,
|
||||
})
|
||||
|
||||
new TagsInput(PUInput, {
|
||||
delimiters: " |,",
|
||||
originalInputValueFormat: joinWithCommas,
|
||||
})
|
||||
|
||||
new TagsInput(P0Input, {
|
||||
delimiters: " |,",
|
||||
originalInputValueFormat: joinWithCommas
|
||||
})
|
||||
|
||||
new TagsInput(pInput, {
|
||||
delimiters: " |,",
|
||||
originalInputValueFormat: joinWithCommas,
|
||||
})
|
||||
|
||||
newScanForm.onsubmit = function(event) {
|
||||
if (this.checkValidity()) {
|
||||
newScanForm.classList.add("loading")
|
||||
return true
|
||||
} else {
|
||||
event.preventDefault()
|
||||
this.reportValidity()
|
||||
}
|
||||
}
|
||||
</script>
|
||||
</body>
|
||||
|
||||
</html>
|
42
scan.php
42
scan.php
@ -15,40 +15,42 @@ if (!file_exists($SCANS_DIR)) {
|
||||
$basedir = "{$_SERVER['REQUEST_SCHEME']}://{$_SERVER['SERVER_NAME']}:{$_SERVER['SERVER_PORT']}" . dirname($_SERVER['REQUEST_URI']);
|
||||
|
||||
$args = '';
|
||||
foreach ($inputs as $name => $value) {
|
||||
foreach ($inputs as $arg => $value) {
|
||||
if (is_null($value)) {
|
||||
http_response_code(400);
|
||||
exit("Valeur incorecte pour le paramètre $option : " . filter_input(INPUT_GET, $option, FILTER_SANITIZE_FULL_SPECIAL_CHARS));
|
||||
die("Valeur incorecte pour le paramètre $arg : " . filter_input(INPUT_GET, $arg, FILTER_SANITIZE_FULL_SPECIAL_CHARS));
|
||||
} else if ($value) {
|
||||
if ($value === true) {
|
||||
$args .= " -$name";
|
||||
if (strlen($arg)<=2) $args .= " -$arg";
|
||||
else $arg = "--$arg";
|
||||
} else {
|
||||
$args .= " -$name " . ($value);
|
||||
if (strlen($arg)<=2) $args .= " -$arg" . ($value);
|
||||
else $arg = "--$arg " . ($value);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
$result = `nmap$args --stylesheet $basedir/stylesheet.xsl -oX - $targets`;
|
||||
if (!$result) {
|
||||
exec("nmap$args --stylesheet $basedir/stylesheet.xsl -oX - $targets 2>&1", $result, $code);
|
||||
if ($code) {
|
||||
http_response_code(500);
|
||||
exit();
|
||||
die(implode("<br/>\n", $result));
|
||||
}
|
||||
|
||||
$xml = new DOMDocument();
|
||||
$xml->loadXML($result);
|
||||
$xml->loadXML(implode("\n", $result));
|
||||
|
||||
$dir = $SCANS_DIR;
|
||||
if (!file_exists($SCANS_DIR)) {
|
||||
mkdir($SCANS_DIR);
|
||||
}
|
||||
$xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='name' value='$name'"), $xml->documentElement);
|
||||
$xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='scansDir' value='$SCANS_DIR'"), $xml->documentElement);
|
||||
$xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='compareWith' value='$compareWith'"), $xml->documentElement);
|
||||
|
||||
$path = "$SCANS_DIR/" . str_replace('/', '!', $targets) . '.xml';
|
||||
if (!file_exists($path)) {
|
||||
$xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='compareWith' value=''"), $xml->documentElement);
|
||||
if ($name) {
|
||||
if (!file_exists($SCANS_DIR)) mkdir($SCANS_DIR);
|
||||
$path = "$SCANS_DIR/$name.xml";
|
||||
$xml->save($path);
|
||||
} else {
|
||||
$xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='compareWith' value='$path'"), $xml->documentElement);
|
||||
}
|
||||
|
||||
header('Content-type: text/xml');
|
||||
exit($xml->saveXML());
|
||||
header("Location: $path");
|
||||
exit();
|
||||
} else {
|
||||
header('Content-type: text/xml');
|
||||
exit($xml->saveXML());
|
||||
}
|
||||
|
@ -27,6 +27,10 @@
|
||||
margin-left: .3em;
|
||||
}
|
||||
|
||||
.ui.form .fields > .field {
|
||||
width: 100%;
|
||||
}
|
||||
|
||||
.ui.ui.form .field .fields .field:not(:only-child) .ui.checkbox {
|
||||
margin-top: 0;
|
||||
}
|
||||
|
@ -8,24 +8,40 @@
|
||||
<xsl:output indent="yes"/>
|
||||
<xsl:strip-space elements='*'/>
|
||||
|
||||
<xsl:param name="name"/>
|
||||
<xsl:param name="scansDir"/>
|
||||
<xsl:param name="compareWith"/>
|
||||
<xsl:variable name="nameOrCompareWith">
|
||||
<xsl:choose>
|
||||
<xsl:when test="$name"><xsl:value-of select="$name"/></xsl:when>
|
||||
<xsl:when test="$compareWith"><xsl:value-of select="$compareWith"/></xsl:when>
|
||||
</xsl:choose>
|
||||
</xsl:variable>
|
||||
<xsl:variable name="current" select="./nmaprun"/>
|
||||
<xsl:variable name="init" select="document(string($compareWith))/nmaprun"/>
|
||||
<xsl:variable name="basedir" select="substring-before(substring-after(processing-instruction('xml-stylesheet'),'href="'),'/stylesheet.xsl"')"/>
|
||||
<xsl:variable name="init" select="document(concat($scansDir, '/', $compareWith, '.xml'))/nmaprun"/>
|
||||
|
||||
<xsl:template match="nmaprun">
|
||||
<xsl:variable name="targets" select="substring-after(./@args, '-oX - ')"/>
|
||||
<xsl:variable name="basedir" select="substring-before(substring-after(./@args, '--stylesheet '), '/stylesheet.xsl')"/>
|
||||
<xsl:variable name="targets" select="substring-after(@args, '-oX - ')"/>
|
||||
<xsl:variable name="PS" select="substring-before(substring-after(@args, '-PS'), ' -')"/>
|
||||
<xsl:variable name="F" select="contains(@args, '-F')"/>
|
||||
|
||||
<html lang="fr">
|
||||
<head>
|
||||
<meta charset="utf-8"/>
|
||||
<meta http-equiv="refresh" content="60"/>
|
||||
<title>lanScan - <xsl:value-of select="$targets"/>
|
||||
<title>
|
||||
<xsl:text>lanScan - </xsl:text>
|
||||
<xsl:choose>
|
||||
<xsl:when test="string-length($nameOrCompareWith)"><xsl:value-of select="$nameOrCompareWith"/></xsl:when>
|
||||
<xsl:otherwise><xsl:value-of select="$targets"/></xsl:otherwise>
|
||||
</xsl:choose>
|
||||
</title>
|
||||
<link rel="icon" href="favicon.ico"/>
|
||||
<link rel="icon" href="{$basedir}/favicon.ico"/>
|
||||
<link rel="stylesheet" type="text/css" href="https://cdn.jsdelivr.net/npm/fomantic-ui@2.9.3/dist/semantic.min.css"/>
|
||||
<link href="https://cdn.jsdelivr.net/npm/@yaireo/tagify/dist/tagify.css" rel="stylesheet" type="text/css"/>
|
||||
<link href="https://cdn.datatables.net/v/dt/jszip-3.10.1/dt-2.1.8/b-3.1.2/b-html5-3.1.2/b-print-3.1.2/fh-4.0.1/r-3.0.3/datatables.css" rel="stylesheet"/>
|
||||
<link href="style.css" rel="stylesheet" type="text/css"/>
|
||||
<link href="{$basedir}/style.css" rel="stylesheet" type="text/css"/>
|
||||
<script src="https://code.jquery.com/jquery-3.7.1.js"></script>
|
||||
<script src="https://cdnjs.cloudflare.com/ajax/libs/fomantic-ui/2.9.2/semantic.min.js"></script>
|
||||
<script src="https://cdn.jsdelivr.net/npm/@yaireo/tagify"></script>
|
||||
@ -90,23 +106,37 @@
|
||||
</a>
|
||||
<div class="right menu">
|
||||
<form class="ui category search item" onsubmit="targetsInputDiv.classList.add('loading')">
|
||||
<div id="targetsInputDiv" class="ui icon input">
|
||||
<input class="prompt" type="text" id="targetsInput" name="targets" required="" oninput="hiddenInput.value=this.value"
|
||||
pattern="[a-zA-Z0-9._\/ \-]+" value="{$targets}" placeholder="Scanner un réseau..."
|
||||
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
|
||||
<div class="fiels">
|
||||
<div id="targetsInputDiv" class="ui icon input">
|
||||
<input class="prompt" type="text" id="targetsInput" name="targets" oninput="hiddenInput.value=this.value" required=""
|
||||
pattern="[a-zA-Z0-9._\/ \-]+" value="{$targets}" placeholder="Scanner un réseau..."
|
||||
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
|
||||
Exemples: 192.168.1.0/24 scanme.nmap.org 10.0-255.0-255.1-254"/>
|
||||
<i class="satellite dish icon"></i>
|
||||
<button style="display:none" type="submit" formaction="scan.php" formmethod="get"></button>
|
||||
<i class="satellite dish icon"></i>
|
||||
</div>
|
||||
<xsl:if test="$PS"><input type="hidden" name="PS" value="{$PS}"/></xsl:if>
|
||||
<xsl:if test="$F"><input type="hidden" name="F" value="on"/></xsl:if>
|
||||
<xsl:if test="string-length($nameOrCompareWith)"><input type="hidden" name="compareWith" value="{$nameOrCompareWith}"/></xsl:if>
|
||||
<button style="display: none;" type="submit" formmethod="get" formaction="{$basedir}/scan.php"></button>
|
||||
<button class="ui teal icon submit button" type="submit" formmethod="get" formaction="{$basedir}/options.php" onclick="targetsInput.required=false">
|
||||
<i class="sliders horizontal icon"></i>
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
<form class="item" method="get" action="scan-options.php">
|
||||
<input id="hiddenInput" type="hidden" name="targets" value="{$targets}"/>
|
||||
<button class="ui teal submit button" type="submit">Options</button>
|
||||
</form>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<main class="ui main container">
|
||||
<h1 class="ui header">
|
||||
<xsl:choose>
|
||||
<xsl:when test="string-length($nameOrCompareWith)">
|
||||
<xsl:value-of select="$nameOrCompareWith"/>
|
||||
<div class="sub header"><xsl:value-of select="$targets"/></div>
|
||||
</xsl:when>
|
||||
<xsl:otherwise><xsl:value-of select="$targets"/></xsl:otherwise>
|
||||
</xsl:choose>
|
||||
</h1>
|
||||
|
||||
<table id="scanResultsTable" style="width:100%" role="grid" class="ui sortable small table">
|
||||
<thead>
|
||||
<tr>
|
||||
@ -153,6 +183,7 @@ $.toast({
|
||||
showIcon: 'satellite dish',
|
||||
displayTime: 'auto',
|
||||
closeIcon: true,
|
||||
position: 'bottom right',
|
||||
})
|
||||
</xsl:if>
|
||||
<xsl:if test="runstats/finished/@errormsg">
|
||||
@ -163,15 +194,18 @@ $.toast({
|
||||
class: 'error',
|
||||
displayTime: 'auto',
|
||||
closeIcon: true,
|
||||
position: 'bottom right',
|
||||
})
|
||||
</xsl:if>
|
||||
<xsl:if test="$init">
|
||||
$.toast({
|
||||
title: '<xsl:value-of select="$compareWith"/>',
|
||||
message: 'Comparaison avec les résultats du <xsl:value-of select="$init/runstats/finished/@timestr"/>',
|
||||
class: 'info',
|
||||
showIcon: 'calendar',
|
||||
displayTime: 10000,
|
||||
closeIcon: true,
|
||||
position: 'bottom right',
|
||||
})
|
||||
</xsl:if>
|
||||
</script>
|
||||
|
Loading…
x
Reference in New Issue
Block a user