From 9c5552905707fff51e8fae9c1f75152925c88259 Mon Sep 17 00:00:00 2001 From: NotoriousRebel Date: Wed, 8 Jul 2020 23:30:24 -0400 Subject: [PATCH] Readded certifi to requirements.txt and added certifi to screenshot.py when fetching urls. --- README.md | 2 +- requirements/base.txt | 2 -- theHarvester/__main__.py | 2 +- theHarvester/discovery/dnssearch.py | 2 +- theHarvester/screenshot/screenshot.py | 10 +++++++--- 5 files changed, 10 insertions(+), 8 deletions(-) diff --git a/README.md b/README.md index 778d8813..eb691035 100644 --- a/README.md +++ b/README.md @@ -87,7 +87,7 @@ Passive: Active: ------- * DNS brute force: dictionary brute force enumeration - +* Screenshots: Take screenshots of subdomains that were found Modules that require an API key: -------------------------------- diff --git a/requirements/base.txt b/requirements/base.txt index aab2d431..e153cb03 100644 --- a/requirements/base.txt +++ b/requirements/base.txt @@ -5,7 +5,6 @@ aiosqlite==0.13.0 beautifulsoup4==4.9.1 certifi==2020.6.20 dnspython==1.16.0 -fastapi==0.58.1 netaddr==0.8.0 plotly==4.8.2 pyppeteer==0.2.2 @@ -15,5 +14,4 @@ retrying==1.3.3 shodan==1.23.0 texttable==1.6.2 lxml==4.5.1 -uvicorn==0.11.5 uvloop==0.14.0; platform_system != "Windows" \ No newline at end of file diff --git a/theHarvester/__main__.py b/theHarvester/__main__.py index c9994eff..97cea8db 100644 --- a/theHarvester/__main__.py +++ b/theHarvester/__main__.py @@ -597,7 +597,7 @@ async def start(): # Verify path exists if not create it or if user does not create it skip screenshot if path_exists: await screen_shotter.verify_installation() - print(f'\nScreenshots can be found: {screen_shotter.output}{screen_shotter.slash}') + print(f'\nScreenshots can be found in: {screen_shotter.output}{screen_shotter.slash}') start = time.perf_counter() print('Filtering domains for ones we can reach') unique_resolved_domains = {url.split(':')[0]for url in full if ':' in url and 'www.' not in url} diff --git a/theHarvester/discovery/dnssearch.py b/theHarvester/discovery/dnssearch.py index fdb328be..64cd0eab 100644 --- a/theHarvester/discovery/dnssearch.py +++ b/theHarvester/discovery/dnssearch.py @@ -40,7 +40,7 @@ class DnsForce: self.list = [f'{word.strip()}.{self.domain}' for word in self.list] async def run(self): - print(f'Created checker with this many words {len(self.list)}') + print(f'Starting DNS brute forcing with {len(self.list)} words') checker = hostchecker.Checker( self.list) if self.dnsserver == [] or self.dnsserver == "" or self.dnsserver is None \ else hostchecker.Checker(self.list, nameserver=self.dnsserver) diff --git a/theHarvester/screenshot/screenshot.py b/theHarvester/screenshot/screenshot.py index f302dc2f..f838ae71 100644 --- a/theHarvester/screenshot/screenshot.py +++ b/theHarvester/screenshot/screenshot.py @@ -6,8 +6,10 @@ take screenshots from pyppeteer import launch import aiohttp import asyncio +import certifi from datetime import datetime import os +import ssl import sys @@ -21,7 +23,8 @@ class ScreenShotter: def verify_path(self): try: if not os.path.isdir(self.output): - answer = input('[+] The output path you have entered does not exist would you like to create it (y/n): ') + answer = input( + '[+] The output path you have entered does not exist would you like to create it (y/n): ') if answer.lower() == 'yes' or answer.lower() == 'y': os.mkdir(self.output) return True @@ -53,9 +56,10 @@ class ScreenShotter: 'Chrome/83.0.4103.106 Safari/537.36'} url = f'http://{url}' if ('http' not in url and 'https' not in url) else url url = url.replace('www.', '') + sslcontext = ssl.create_default_context(cafile=certifi.where()) async with aiohttp.ClientSession(timeout=timeout, headers=headers, - connector=aiohttp.TCPConnector(verify_ssl=False)) as session: - async with session.get(url) as resp: + connector=aiohttp.TCPConnector(ssl=sslcontext)) as session: + async with session.get(url, verify_ssl=False) as resp: # TODO fix with origin url, should be there somewhere text = await resp.text("UTF-8") return f'http://{url}' if ('http' not in url and 'https' not in url) else url, text