Compare commits

..

No commits in common. "664bee12493e1cc30a68028fed9915e92c97c610" and "eae12a8e4ef74862a1830befe557021c2573c127" have entirely different histories.

9 changed files with 27721 additions and 322 deletions

1
.gitignore vendored
View File

@ -1,3 +1,2 @@
scans/ scans/
server.php server.php
test.php

View File

@ -2,8 +2,8 @@
$SCANS_DIR = 'scans'; $SCANS_DIR = 'scans';
$DEFAULT_ARGS = [ $DEFAULT_ARGS = [
'PS' => 'ssh,http,https,msrpc,microsoft-ds', '-PS' => 'ssh,http,https,msrpc,microsoft-ds',
'F' => true, '-F' => true,
'T5' => true, '-T5' => true,
]; ];
$NMAP_DATADIR = '/usr/share/nmap'; $NMAP_DATADIR = '/usr/share/nmap';

View File

@ -15,97 +15,97 @@ $protocolePortsListRegex = "/^(([TU]:)?[0-9\-]+|[a-z\-]+)(,([TU]:)?[0-9\-]+|,[a-
$portsListRegex = "/^([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*$/"; $portsListRegex = "/^([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*$/";
$tempoRegex = "/^\d+[smh]?$/"; $tempoRegex = "/^\d+[smh]?$/";
$options = filter_input_array(INPUT_GET, [ $input_args = filter_input_array(INPUT_GET, [
'iR' => ['filter' => FILTER_VALIDATE_INT], '-iR' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-exclude' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]], '--exclude' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $hostsListRegex]],
'sL' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]], '-sL' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $hostsListRegex]],
'sP' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sP' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'P0' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-P0' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'Pn' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-PN' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'PS' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]], '-PS' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $portsListRegex]],
'PA' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]], '-PA' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $portsListRegex]],
'PU' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]], '-PU' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $portsListRegex]],
'PE' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-PE' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'PP' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-PP' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-PM' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'PO' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 255]], '-PO' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['min_range' => 0, 'max_range' => 255]],
'n' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-n' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'R' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-R' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-dns-servers' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]], '--dns-servers' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $hostsListRegex]],
'sS' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sS' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'sT' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sT' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'sA' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sA' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'sW' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sW' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'sM' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sM' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'sF' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sF' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'sN' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sN' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'sX' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sX' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'PU' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-PU' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-PM' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-PM' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'PM' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-PM' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-scanflags' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^([URG|ACK|PSH|RST|SYN|FIN]+)$|^([0-2]?\d?\d)$/"]], '--scanflags' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => "/^([URG|ACK|PSH|RST|SYN|FIN]+)$|^([0-2]?\d?\d)$/"]],
'sI' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^[a-zA-Z\d:.-]+(:\d+)?$/"]], '-sI' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => "/^[a-zA-Z\d:.-]+(:\d+)?$/"]],
'sO' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sO' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'b' => FILTER_VALIDATE_DOMAIN, '-b' => FILTER_VALIDATE_DOMAIN,
'-traceroute' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--traceroute' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-reason' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--reason' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'p' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $portsListRegex]], '-p' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $portsListRegex]],
'F' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-F' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'r' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-r' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-top-ports' => FILTER_VALIDATE_INT, '--top-ports' => FILTER_VALIDATE_INT,
'-port-ratio' => ['filter' => FILTER_VALIDATE_FLOAT, 'options' => ['min_range' => 0, 'max_range' => 1]], '--port-ratio' => ['filter' => FILTER_VALIDATE_FLOAT, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['min_range' => 0, 'max_range' => 1]],
'sV' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-sV' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-version-light' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--version-light' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-version-intensity' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 9]], '--version-intensity' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['min_range' => 0, 'max_range' => 9]],
'-version-all' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--version-all' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-version-trace' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--version-trace' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'O' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-O' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-osscan-limit' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--osscan-limit' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-osscan-guess' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--osscan-guess' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'T0' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-T0' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'T1' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-T1' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'T2' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-T2' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'T3' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-T3' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'T4' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-T4' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'T5' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-T5' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-min-hostgroup' => ['filter' => FILTER_VALIDATE_INT], '--min-hostgroup' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-max-hostgroup' => ['filter' => FILTER_VALIDATE_INT], '--max-hostgroup' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-min-parallelism' => ['filter' => FILTER_VALIDATE_INT], '--min-parallelism' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-max-parallelism' => ['filter' => FILTER_VALIDATE_INT], '--max-parallelism' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-min-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]], '--min-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $tempoRegex]],
'-max-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]], '--max-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $tempoRegex]],
'-initial-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]], '--initial-rtt-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $tempoRegex]],
'-max-retries' => ['filter' => FILTER_VALIDATE_INT], '--max-retries' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-host-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]], '--host-timeout' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $tempoRegex]],
'-scan-delay' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]], '--scan-delay' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $tempoRegex]],
'-max-scan-delay' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $tempoRegex]], '--max-scan-delay' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $tempoRegex]],
'f' => ['filter' => FILTER_VALIDATE_INT], '-f' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'mtu' => ['filter' => FILTER_VALIDATE_INT], '-mtu' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'D' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => $hostsListRegex]], '-D' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => $hostsListRegex]],
'S' => ['filter' => FILTER_VALIDATE_IP], '-S' => ['filter' => FILTER_VALIDATE_IP, 'flags' => FILTER_NULL_ON_FAILURE],
'e' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^[a-z\d]+$/"]], '-e' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => "/^[a-z\d]+$/"]],
'g' => ['filter' => FILTER_VALIDATE_INT], '-g' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-source-port' => ['filter' => FILTER_VALIDATE_INT], '--source-port' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-data-length' => ['filter' => FILTER_VALIDATE_INT], '--data-length' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE],
'-ip-options' => ['filter' => FILTER_VALIDATE_REGEXP, 'options' => ['regexp' => "/^\"(R|T|U|L [\da-zA-Z-.: ]+|S [\da-zA-Z-.: ]+|\\\\x[\da-fA-F]{1,2}(\*[\d]+)?|\\\\[0-2]?[\d]{1,2}(\*[\d]+)?)\"$/"]], '--ip-options' => ['filter' => FILTER_VALIDATE_REGEXP, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['regexp' => "/^\"(R|T|U|L [\da-zA-Z-.: ]+|S [\da-zA-Z-.: ]+|\\\\x[\da-fA-F]{1,2}(\*[\d]+)?|\\\\[0-2]?[\d]{1,2}(\*[\d]+)?)\"$/"]],
'ttl' => ['filter' => FILTER_VALIDATE_INT, 'options' => ['min_range' => 0, 'max_range' => 255]], '-ttl' => ['filter' => FILTER_VALIDATE_INT, 'flags' => FILTER_NULL_ON_FAILURE, 'options' => ['min_range' => 0, 'max_range' => 255]],
'-spoof-mac' => ['filter' => FILTER_VALIDATE_MAC], '--spoof-mac' => ['filter' => FILTER_VALIDATE_MAC, 'flags' => FILTER_NULL_ON_FAILURE],
'-badsum' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--badsum' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
//'6' => ['filter' => FILTER_VALIDATE_BOOLEAN], //'-6' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'A' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-A' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-send-eth' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--send-eth' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-send-ip' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--send-ip' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-privileged' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--privileged' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'V' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-V' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'-unprivileged' => ['filter' => FILTER_VALIDATE_BOOLEAN], '--unprivileged' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
'h' => ['filter' => FILTER_VALIDATE_BOOLEAN], '-h' => ['filter' => FILTER_VALIDATE_BOOLEAN, 'flags' => FILTER_NULL_ON_FAILURE],
], false) ?: $DEFAULT_ARGS; ], false) ?: $DEFAULT_ARGS;

View File

@ -37,7 +37,7 @@ Exemples: <?=$_SERVER['REMOTE_ADDR']; ?>/24 <?=$_SERVER['SERVER_NAME']; ?> 10.0-
<form class="item" method="get" action="scan-options.php"> <form class="item" method="get" action="scan-options.php">
<input id="hiddenInput" type="hidden" name="targets" value="<?=$targets; ?>"/> <input id="hiddenInput" type="hidden" name="targets" value="<?=$targets; ?>"/>
<input id="hiddenInput" type="hidden" name="name" value="<?=$name; ?>"/> <input id="hiddenInput" type="hidden" name="name" value="<?=$name; ?>"/>
<?='<input type="hidden" name="'.str_replace('=', '" value="', http_build_query($options, '', '/><input type="hidden" name="')).'"/>'; ?> <?='<input type="hidden" name="'.str_replace('=', '" value="', http_build_query($input_args, '', '/><input type="hidden" name="')).'"/>'; ?>
<button class="ui teal submit button" type="submit">Options</button> <button class="ui teal submit button" type="submit">Options</button>
</form> </form>
</div> </div>

27407
nmap/nmap-services Normal file

File diff suppressed because it is too large Load Diff

View File

@ -22,15 +22,14 @@ include_once 'filter_inputs.php';
<body> <body>
<nav class="ui inverted teal fixed menu"> <nav class="ui inverted teal fixed menu">
<a class="header item" href="."> <a class="header item" href=".">
lan<?php include 'logo.svg'; ?>can lan
<?php include 'logo.svg'; ?>can
</a> </a>
</nav> </nav>
<main class="ui main container"> <main class="ui main container">
<h1 class="header">Scanner un réseau avec Nmap</h1>
<form id="newScanForm" class="ui form" method="get" action="scan.php"> <form id="newScanForm" class="ui form" method="get" action="scan.php">
<h1 class="header">Scanner un réseau avec Nmap</h1>
<!--<div class="field"> <!--<div class="field">
<label for="nameInput">Nom</label> <label for="nameInput">Nom</label>
<input id="nameInput" type="text" name="name" placeholder="Réseau local" pattern='[^&lt;&gt;:&quot;\\\/\|@?]+' <input id="nameInput" type="text" name="name" placeholder="Réseau local" pattern='[^&lt;&gt;:&quot;\\\/\|@?]+'
@ -39,8 +38,8 @@ include_once 'filter_inputs.php';
</div>--> </div>-->
<div class="required field"> <div class="required field">
<label for="targetsInput">Cibles</label> <label for="targetsInput">Cibles</label>
<input id="targetsInput" type="text" name="targets" placeholder="Cibles" required <input id="targetsInput" type="text" name="targets" placeholder="Cibles" required=""
pattern="[a-zA-Z0-9._\/ \-]+" value="<?= $targets; ?>" list="targetsList" pattern="[a-zA-Z0-9._\/ \-]+" value="<?= htmlspecialchars($targets); ?>" list="targetsList"
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc. title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
Exemples: <?=$_SERVER['REMOTE_ADDR']; ?>/24 <?=$_SERVER['SERVER_NAME']; ?> 10.0-255.0-255.1-254" /> Exemples: <?=$_SERVER['REMOTE_ADDR']; ?>/24 <?=$_SERVER['SERVER_NAME']; ?> 10.0-255.0-255.1-254" />
</div> </div>
@ -49,109 +48,117 @@ Exemples: <?=$_SERVER['REMOTE_ADDR']; ?>/24 <?=$_SERVER['SERVER_NAME']; ?> 10.0-
<div class="title"><i class="icon dropdown"></i>Spécification des cibles</div> <div class="title"><i class="icon dropdown"></i>Spécification des cibles</div>
<div class="content"> <div class="content">
<div class="field"> <div class="field">
<label for="excludeInput">Exclure les hôtes ou réseaux</label> <label class="inline field">
<input type="text" id="excludeInput" name="-exclude" placeholder="Hôte/réseau" list="targetsList" <div class="ui checkbox">
pattern="[a-zA-Z0-9._\/,\-]*" value="<?=$options['-exclude']?? "" ?>" <input type="checkbox" id="excludeCheckbox" onchange="excludeInput.disabled = !this.checked"/>
<label for="excludeCheckbox">Exclure les hôtes ou réseaux</label>
</div>
</label>
<input type="text" id="excludeInput" name="--exclude" placeholder="Hôte/réseau" list="targetsList" disabled
pattern="[a-zA-Z0-9._\/,\-]*" value=""
title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc. title="Les cibles peuvent être spécifiées par des noms d'hôtes, des adresses IP, des adresses de réseaux, etc.
Exemples: <?=$_SERVER['REMOTE_ADDR']; ?>/24,<?=$_SERVER['SERVER_NAME']; ?>,10.0-255.0-255.1-254"> Exemples: <?=$_SERVER['REMOTE_ADDR']; ?>/24,<?=$_SERVER['SERVER_NAME']; ?>,10.0-255.0-255.1-254">
</div> </div>
</div> </div>
<div class="title"><i class="icon dropdown"></i>Découverte des hôtes actifs</div> <div class="title"><i class="icon dropdown"></i>Découverte des hôtes</div>
<div class="content"> <div class="content">
<div class="inline field"> <div class="inline field">
<div class="ui toggle checkbox"> <div class="ui checkbox">
<input type="checkbox" id="sPCheckbox" name="sP" <?=$options['sP']?? false? 'checked' : ''; ?>/> <input type="checkbox" id="sPCheckbox" name="-sP"/>
<label for="sPCheckbox">N'effectuer que l'étape de découverte des hôtes actifs</label> <label for="sPCheckbox">N'effectuer que la découverte des hôtes actifs</label>
</div> </div>
</div> </div>
<div class="inline field"> <div class="inline field">
<div class="ui toggle checkbox"> <div class="ui checkbox">
<input type="checkbox" id="PnCheckbox" name="Pn" <?=$options['Pn']?? false? 'checked' : ''; ?>/> <input type="checkbox" id="PECheckbox" name="-PE"/>
<label for="PnCheckbox">Considérer tous les hôtes comme actifs (saute la découverte des hôtes)</label> <label for="PECheckbox">Considérer tous les hôtes comme actifs</label>
</div> </div>
</div> </div>
<div class="fields">
<div class="field">
<label for="PSInput">Ping TCP SYN</label>
<input type="text" id="PSInput" name="PS" placeholder="Ports" list="servicesList"
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?=$options['PS']?? "" ?>"
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
</div>
<div class="field"> <div class="field">
<label for="PAInput">Ping TCP ACK</label> <label class="inline field">
<input type="text" id="PAInput" name="PA" placeholder="Ports" list="servicesList" <div class="ui checkbox">
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?=$options['PA']?? "" ?>" <input type="checkbox" id="PSCheckbox" onchange="PSInput.disabled = !this.checked"/>
title="Liste de ports ex: 22,23,25,80,200-1024,60000-"> <label for="PSCheckbox">Ping TCP SYN</label>
</div>
</label>
<input type="text" id="PSInput" name="-PS" placeholder="Ports" list="servicesList" disabled
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="80"
title="Liste de ports ex: 22,23,25,80,113,1050,35000">
</div> </div>
<div class="field"> <div class="field">
<label for="PUInput">Ping UDP</label> <label>
<input type="text" id="PUInput" name="PU" placeholder="Ports" list="servicesList" <div class="ui checkbox">
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="<?=$options['PU']?? "" ?>" <input type="checkbox" id="PACheckbox" onchange="PAInput.disabled = !this.checked"/>
title="Liste de ports ex: 22,23,25,80,200-1024,60000-"> <label for="PACheckbox">Ping TCP ACK</label>
</div> </div>
</label>
<input type="text" id="PAInput" name="-PA" placeholder="Ports" list="servicesList" disabled
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="80"
title="Liste de ports ex: 22,23,25,80,113,1050,35000">
</div> </div>
<div class="field"> <div class="field">
<label>Ping ICMP</label> <label>
<div class="ui checkbox">
<input type="checkbox" id="PUCheckbox" onchange="PUInput.disabled = !this.checked"/>
<label for="PUCheckbox">Ping UDP</label>
</div>
</label>
<input type="text" id="PUInput" name="-PU" placeholder="Ports" list="servicesList" disabled
pattern="([0-9\-]+|[a-z\-]+)(,[0-9\-]+|,[a-z\-]+)*" value="31338"
title="Liste de ports ex: 22,23,25,80,113,1050,35000">
</div>
<div class="inline fields"> <div class="inline fields">
<label>Ping ICMP</label>
<div class="field"> <div class="field">
<div class="ui toggle checkbox"> <div class="ui checkbox">
<input type="checkbox" id="PECheckbox" name="PE" <?=$options['PE']?? false? 'checked' : ''; ?>/> <input type="checkbox" id="PECheckbox" name="-PE"/>
<label for="PECheckbox">Echo request</label> <label for="PECheckbox">Echo request</label>
</div> </div>
</div> </div>
<div class="field"> <div class="field">
<div class="ui toggle checkbox"> <div class="ui checkbox">
<input type="checkbox" id="PPCheckbox" name="PP" <?=$options['PP']?? false? 'checked' : ''; ?>/> <input type="checkbox" id="PPCheckbox" name="-PP"/>
<label for="PPCheckbox">Timestamp request</label> <label for="PPCheckbox">Timestamp request</label>
</div> </div>
</div> </div>
<div class="field"> <div class="field">
<div class="ui toggle checkbox"> <div class="ui checkbox">
<input type="checkbox" id="PMCheckbox" name="PM" <?=$options['PM']?? false? 'checked' : ''; ?>/> <input type="checkbox" id="PMCheckbox" name="-PM"/>
<label for="PMCheckbox">Mask request</label> <label for="PMCheckbox">Mask request</label>
</div> </div>
</div> </div>
</div> </div>
</div>
<div class="field"> <div class="field">
<div class="ui toggle checkbox"> <div class="ui checkbox">
<input type="checkbox" id="PRCheckbox" name="PR" <?=$options['PR']?? false? 'checked' : ''; ?>/> <input type="checkbox" id="PRCheckbox" name="-PR"/>
<label for="PRCheckbox">Ping ARP</label> <label for="PRCheckbox">Ping ARP</label>
</div> </div>
</div> </div>
<div class="field">
<label for="P0Input">Ping IP Protocol</label>
<input type="text" id="P0Input" name="P0" placeholder="Ports"
pattern="[0-9\-]+" value="<?=$options['P0']?? "" ?>"
title="Liste de ports ex: 22,23,25,80,200-1024,60000-">
</div>
</div> </div>
<div class="title"><i class="icon dropdown"></i>Techniques de scan</div> <div class="title"><i class="icon dropdown"></i>Techniques de scan</div>
<div class="content"> <div class="content">
<div class="field"> <div class="field">
<div class="ui toggle checkbox"> <label>
<input type="checkbox" id="FCheckbox" name="F" <?=$options['F']?? false? 'checked' : ''; ?>/> <div class="ui checkbox">
<label for="FCheckbox">Scanner que les ports connus</label> <input type="checkbox" id="pCheckbox" onchange="pInput.disabled = !this.checked"/>
<label for="pCheckbox">Scanner les ports</label>
</div> </div>
</div> </label>
<input type="text" id="pInput" name="-p" placeholder="Ports" list="servicesList" disabled
<div class="field"> pattern="(([TU]:)?[0-9\-]+|[a-z\-]+)(,([TU]:)?[0-9\-]+|,[a-z\-]+)*" value="1-1024"
<label for="pInput">Scanner que les ports</label>
<input type="text" id="pInput" name="p" placeholder="Ports" list="servicesList"
pattern="(([TU]:)?[0-9\-]+|[a-z\-]+)(,([TU]:)?[0-9\-]+|,[a-z\-]+)*" value="<?=$options['p']?? "" ?>"
title="Liste de ports ex: ssh,ftp,U:53,111,137,T:21-25,80,139,8080"> title="Liste de ports ex: ssh,ftp,U:53,111,137,T:21-25,80,139,8080">
</div> </div>
<div class="field"> <div class="field">
<div class="ui toggle checkbox"> <div class="ui checkbox">
<input type="checkbox" id="rCheckbox" name="r" <?=$options['r']?? false? 'checked' : ''; ?>/> <input type="checkbox" id="FCheckbox" name="-F"/>
<label for="FCheckbox">Scanner les ports connus</label>
</div>
</div>
<div class="field">
<div class="ui checkbox">
<input type="checkbox" id="rCheckbox" name="-r"/>
<label for="rCheckbox">Ne pas mélanger les ports</label> <label for="rCheckbox">Ne pas mélanger les ports</label>
</div> </div>
</div> </div>
@ -159,7 +166,7 @@ Exemples: <?=$_SERVER['REMOTE_ADDR']; ?>/24,<?=$_SERVER['SERVER_NAME']; ?>,10.0-
</div> </div>
<button type="submit" class="ui teal submit button">Démarrer</button> <button type="submit" class="ui fluid teal submit button">Démarrer</button>
</form> </form>
<datalist id='targetsList'> <datalist id='targetsList'>
@ -171,7 +178,7 @@ if (!file_exists($SCANS_DIR)) {
mkdir($SCANS_DIR); mkdir($SCANS_DIR);
} }
foreach (scandir($SCANS_DIR) as $scan) { foreach (scandir($SCANS_DIR) as $scan) {
if ('.xml' == substr($scan, -4)) { if (substr($scan, -4) == '.xml') {
$targets = str_replace('!', '/', substr_replace($scan, '', -4)); $targets = str_replace('!', '/', substr_replace($scan, '', -4));
echo " <option value='$targets'></option>\n"; echo " <option value='$targets'></option>\n";
} }
@ -183,12 +190,12 @@ foreach (scandir($SCANS_DIR) as $scan) {
$nmap_services = file("$NMAP_DATADIR/nmap-services"); $nmap_services = file("$NMAP_DATADIR/nmap-services");
$services = []; $services = [];
foreach ($nmap_services as $service) { foreach ($nmap_services as $service) {
if (0 !== strpos($service, '#')) { if (strpos($service, '#') !== 0) {
[$name, $port] = explode("\t", $service); [$name, $port] = explode("\t", $service);
$services[$name] = explode("/", $port); $services[$name] = $port;
} }
} }
foreach ($services as $name => [$portid, $protocol]) { foreach ($services as $name => $port) {
echo " <option value='$name'></option>\n"; echo " <option value='$name'></option>\n";
} }
?> ?>
@ -202,46 +209,61 @@ const joinWithCommas = tags => tags.map(tag => tag.value).join(',')
$('.ui.accordion').accordion() $('.ui.accordion').accordion()
new Tagify(targetsInput, { var targetsTagify = new Tagify(targetsInput, {
delimiters: " |,", delimiters: " |,",
originalInputValueFormat: joinWithSpaces, originalInputValueFormat: joinWithSpaces,
whitelist: targetsWhitelist, whitelist: targetsWhitelist,
}) })
new Tagify(excludeInput, { var excludeTagify = new Tagify(excludeInput, {
delimiters: " |,", delimiters: " |,",
originalInputValueFormat: joinWithCommas, originalInputValueFormat: joinWithCommas,
whitelist: targetsWhitelist, whitelist: targetsWhitelist,
}) })
excludeCheckbox.onchange = (event) => {
excludeInput.disabled = !excludeCheckbox.checked
excludeTagify.setDisabled(!excludeCheckbox.checked)
}
new Tagify(PSInput, { var PSTagify = new Tagify(PSInput, {
delimiters: " |,", delimiters: " |,",
originalInputValueFormat: joinWithCommas, originalInputValueFormat: joinWithCommas,
whitelist: servicesWhitelist, whitelist: servicesWhitelist,
}) })
PSCheckbox.onchange = () => {
PSInput.disabled = !PSCheckbox.checked
PSTagify.setDisabled(!PSCheckbox.checked)
}
new Tagify(PAInput, { var PATagify = new Tagify(PAInput, {
delimiters: " |,", delimiters: " |,",
originalInputValueFormat: joinWithCommas, originalInputValueFormat: joinWithCommas,
whitelist: servicesWhitelist, whitelist: servicesWhitelist,
}) })
PACheckbox.onchange = () => {
PAInput.disabled = !PACheckbox.checked
PATagify.setDisabled(!PACheckbox.checked)
}
new Tagify(PUInput, { var PUTagify = new Tagify(PUInput, {
delimiters: " |,", delimiters: " |,",
originalInputValueFormat: joinWithCommas, originalInputValueFormat: joinWithCommas,
whitelist: servicesWhitelist, whitelist: servicesWhitelist,
}) })
PUCheckbox.onchange = () => {
PUInput.disabled = !PUCheckbox.checked
PUTagify.setDisabled(!PUCheckbox.checked)
}
new Tagify(P0Input, { var pTagify = new Tagify(pInput, {
delimiters: " |,",
originalInputValueFormat: joinWithCommas
})
new Tagify(pInput, {
delimiters: " |,", delimiters: " |,",
originalInputValueFormat: joinWithCommas, originalInputValueFormat: joinWithCommas,
whitelist: servicesWhitelist, whitelist: servicesWhitelist,
}) })
pCheckbox.onchange = () => {
pInput.disabled = !pCheckbox.checked
pTagify.setDisabled(!pCheckbox.checked)
}
newScanForm.onsubmit = function (event) { newScanForm.onsubmit = function (event) {
if (this.checkValidity()) { if (this.checkValidity()) {

View File

@ -5,7 +5,7 @@ include_once 'filter_inputs.php';
if (!$targets) { if (!$targets) {
http_response_code(400); http_response_code(400);
die('Paramètre manquant : targets'); exit('Paramètre manquant : targets');
} }
if (!file_exists($SCANS_DIR)) { if (!file_exists($SCANS_DIR)) {
@ -14,19 +14,7 @@ if (!file_exists($SCANS_DIR)) {
$basedir = "{$_SERVER['REQUEST_SCHEME']}://{$_SERVER['SERVER_NAME']}:{$_SERVER['SERVER_PORT']}".dirname($_SERVER['REQUEST_URI']); $basedir = "{$_SERVER['REQUEST_SCHEME']}://{$_SERVER['SERVER_NAME']}:{$_SERVER['SERVER_PORT']}".dirname($_SERVER['REQUEST_URI']);
$args = ''; $args = str_replace('=', ' ', http_build_query($input_args, '', ' '));
foreach ($options as $arg => $value) {
if (is_null($value)) {
http_response_code(400);
exit("Valeur incorecte pour le paramètre $option : ".filter_input(INPUT_GET, $option, FILTER_SANITIZE_FULL_SPECIAL_CHARS));
} else if ($value) {
if ($value === true) {
$args .= " -$arg";
} else {
$arg .= " -$arg ".escapeshellarg($value);
}
}
}
$result = `nmap $args --stylesheet $basedir/stylesheet.xsl -oX - $targets`; $result = `nmap $args --stylesheet $basedir/stylesheet.xsl -oX - $targets`;
if (!$result) { if (!$result) {
@ -45,9 +33,7 @@ if (!file_exists($SCANS_DIR)) {
$path = "$SCANS_DIR/".str_replace('/', '!', $targets).'.xml'; $path = "$SCANS_DIR/".str_replace('/', '!', $targets).'.xml';
if (!file_exists($path)) { if (!file_exists($path)) {
$xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='compareWith' value=''"), $xml->documentElement); $xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='compareWith' value=''"), $xml->documentElement);
$xml-> $xml->save($path);
save($path);
} else { } else {
$xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='compareWith' value='$path'"), $xml->documentElement); $xml->insertBefore($xml->createProcessingInstruction('xslt-param', "name='compareWith' value='$path'"), $xml->documentElement);
} }

View File

@ -1,13 +1,9 @@
<?xml version="1.0" encoding="utf-8"?> <?xml version="1.0" encoding="utf-8"?>
<xsl:stylesheet <xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:xs="http://www.w3.org/2001/XMLSchema" version="2.0">
xmlns:xs="http://www.w3.org/2001/XMLSchema"
version="1.1">
<xsl:output method="html" encoding="UTF-8" /> <xsl:output method="html" encoding="UTF-8" />
<xsl:output indent="yes" /> <xsl:output indent="yes" />
<xsl:strip-space elements='*' /> <xsl:strip-space elements='*' />
<xsl:param name="compareWith" /> <xsl:param name="compareWith" />
<xsl:variable name="current" select="./nmaprun" /> <xsl:variable name="current" select="./nmaprun" />
<xsl:variable name="init" select="document(string($compareWith))/nmaprun" /> <xsl:variable name="init" select="document(string($compareWith))/nmaprun" />
@ -121,6 +117,14 @@ Exemples: 192.168.1.0/24 scanme.nmap.org 10.0-255.0-255.1-254"/>
</div> </div>
</xsl:if> </xsl:if>
<xsl:if test="$init">
<div class="ui info message">
<i class="calendar icon"></i>
<xsl:text>Comparaison avec le scan de </xsl:text>
<xsl:value-of select="$init/runstats/finished/@timestr" />
</div>
</xsl:if>
<table id="scanResultsTable" style="width:100%" role="grid" class="ui sortable small table"> <table id="scanResultsTable" style="width:100%" role="grid" class="ui sortable small table">
<thead> <thead>
<tr> <tr>
@ -133,6 +137,9 @@ Exemples: 192.168.1.0/24 scanme.nmap.org 10.0-255.0-255.1-254"/>
<tbody> <tbody>
<xsl:apply-templates select="host | $init/host[not(address/@addr = $current/host/address/@addr)]" /> <xsl:apply-templates select="host | $init/host[not(address/@addr = $current/host/address/@addr)]" />
</tbody> </tbody>
<caption>
<xsl:value-of select="runstats/finished/@summary" />
</caption>
</table> </table>
</main> </main>
<script> <script>
@ -143,7 +150,7 @@ DataTable.ext.type.detect.unshift(function (d) {
}); });
DataTable.ext.type.order['ipv4-address-pre'] = function (ipAddress) { DataTable.ext.type.order['ipv4-address-pre'] = function (ipAddress) {
[a, b, c, d] = ipAddress.split(".").map(Number) [a, b, c, d] = ipAddress.split(".").map(s => Number(s))
return 16777216*a + 65536*b + 256*c + d; return 16777216*a + 65536*b + 256*c + d;
}; };
@ -159,35 +166,6 @@ var table = $('#scanResultsTable').DataTable({
table.order([1, 'asc']).draw() table.order([1, 'asc']).draw()
$('.ui.dropdown').dropdown() $('.ui.dropdown').dropdown()
<xsl:if test="$init">
$.toast({
message: 'Comparaison avec les résultats du <xsl:value-of select="$init/runstats/finished/@timestr"/>',
class: 'info',
showIcon: 'calendar',
displayTime: 10000,
closeIcon: true,
})
</xsl:if>
<xsl:if test="runstats/finished/@summary">
$.toast({
title: '<xsl:value-of select="runstats/finished/@exit"/>',
message: '<xsl:value-of select="runstats/finished/@summary"/>',
showIcon: 'satellite dish',
displayTime: 'auto',
closeIcon: true,
})
</xsl:if>
<xsl:if test="runstats/finished/@errormsg">
$.toast({
title: '<xsl:value-of select="runstats/finished/@exit"/>',
message: '<xsl:value-of select="runstats/finished/@errormsg"/>',
showIcon: 'exclamation triangle',
class: 'error',
displayTime: 'auto',
closeIcon: true,
})
</xsl:if>
</script> </script>
</body> </body>
</html> </html>
@ -276,14 +254,6 @@ $.toast({
&amp;p=<xsl:value-of select="@portid" /> &amp;p=<xsl:value-of select="@portid" />
</xsl:attribute> </xsl:attribute>
</xsl:if> </xsl:if>
<xsl:value-of select="service/@name"/>
<div class="detail">
<xsl:choose>
<xsl:when test="@protocol='udp'">U:</xsl:when>
<xsl:otherwise>:</xsl:otherwise>
</xsl:choose>
<xsl:value-of select="@portid"/>
</div>
<xsl:if test="(service/@name='microsoft-ds' or service/@name='netbios-ssn') and ../../hostscript/script[@id='smb-shares-size']/table"> <xsl:if test="(service/@name='microsoft-ds' or service/@name='netbios-ssn') and ../../hostscript/script[@id='smb-shares-size']/table">
<xsl:attribute name="style"> <xsl:attribute name="style">
<xsl:for-each select="$currentHost/hostscript/script[@id='smb-shares-size']/table"> <xsl:for-each select="$currentHost/hostscript/script[@id='smb-shares-size']/table">
@ -296,6 +266,16 @@ $.toast({
</xsl:if> </xsl:if>
</xsl:for-each> </xsl:for-each>
</xsl:attribute> </xsl:attribute>
</xsl:if>
<xsl:value-of select="service/@name" />
<div class="detail">
<xsl:choose>
<xsl:when test="@protocol='udp'">U:</xsl:when>
<xsl:otherwise>:</xsl:otherwise>
</xsl:choose>
<xsl:value-of select="@portid" />
</div>
<xsl:if test="(service/@name='microsoft-ds' or service/@name='netbios-ssn') and ../../hostscript/script[@id='smb-shares-size']/table">
<i class="dropdown icon"></i> <i class="dropdown icon"></i>
<div class="menu"> <div class="menu">
<xsl:apply-templates select="$currentHost/hostscript/script[@id='smb-shares-size']/table"> <xsl:apply-templates select="$currentHost/hostscript/script[@id='smb-shares-size']/table">

5
test.php Normal file
View File

@ -0,0 +1,5 @@
<?php
include_once 'filter_inputs.php';
var_dump($input_args);