Webãµã€ãããã«ã¹ã¿ã ã¯ãŒããªã¹ããçæããããŒã«
CeWLïŒãã¯ãŒã«ããšçºé³ããŸãïŒã¯ãæå®ãããURLãæ¢çŽ¢ïŒã¹ãã€ããªã³ã°ïŒãããµã€ãå ã§äœ¿çšãããŠããåèªãåéããŠãªã¹ãåããRuby補ã®ã¢ããªã±ãŒã·ã§ã³ã§ããäž»ã«ãããã¬ãŒã·ã§ã³ãã¹ããã»ãã¥ãªãã£ç£æ»ã®æèã§ãã¿ãŒã²ããåºæã®ãã¹ã¯ãŒãèŸæžãäœæããç®çã§äœ¿çšãããŸããäŸãã°ãäŒæ¥ã®Webãµã€ãããåéããåèªãªã¹ãã¯ããã®äŒæ¥ã«é¢é£ãããã¹ã¯ãŒããæšæž¬ããéã®èŸæžæ»æã«å©çšãããããšããããŸããããã«ãããäžè¬çãªèŸæžãã¡ã€ã«ãããå¹æçãªæ»æãå¯èœã«ãªãå ŽåããããŸããð€
CeWLã¯ãRubyã¢ããªãšããŠéçºãããŠãããRobin Woodæ°ã«ãã£ãŠäœæã»ã¡ã³ããã³ã¹ãããŠããŸãã PaulDotComã®ããããã£ã¹ãïŒãšããœãŒã129ïŒã§ãã¿ãŒã²ããã®Webãµã€ããã¹ãã€ããªã³ã°ããŠç¬èªã®åèªãªã¹ããäœæãããšããè°è«ããã£ããã«éçºãããŸããã
çæãããã¯ãŒããªã¹ãã¯ãJohn the RipperãHashcatãHydraãMedusaãšãã£ããã¹ã¯ãŒãã¯ã©ããã³ã°ããŒã«ãšçµã¿åãããŠäœ¿çšãããããšãæ³å®ãããŠããŸãã
CeWLã®äž»ãªæ©èœ âïž
- Webãµã€ãã®ã¯ããŒã«: æå®ãããURLãããªã³ã¯ã蟿ããWebããŒãžãåéããŸããã¯ããŒã«ããæ·±ãïŒéå±€ïŒãæå®ã§ããŸãã
- åèªã®æœåº: HTMLã³ã³ãã³ãããåèªãæœåºãããªã¹ãåããŸãã
- åèªé·ã®ãã£ã«ã¿ãªã³ã°: æœåºããåèªã®æå°é·ïŒããã©ã«ãã¯3æåïŒãæ倧é·ãæå®ã§ããŸãã
- å€éšãµã€ããžã®ã¯ããŒã«: ãªãã·ã§ã³ã§ããªã³ã¯å ã®å€éšãµã€ããã¯ããŒã«å¯Ÿè±¡ã«å«ããããšãã§ããŸãã
- ã¡ã¿ããŒã¿ã®æœåº: PDFãOfficeããã¥ã¡ã³ããªã©ã®ãã¡ã€ã«ãããäœæè æ å ±ãªã©ã®ã¡ã¿ããŒã¿ãæœåºã§ããŸãã
- ã¡ãŒã«ã¢ãã¬ã¹ã®æœåº:
mailto:
ãªã³ã¯ãªã©ããã¡ãŒã«ã¢ãã¬ã¹ãæœåºãããªã¹ãåã§ããŸããããã¯ãŠãŒã¶ãŒåã®ãªã¹ããšããŠãå©çšå¯èœã§ãã - åºåãªãã·ã§ã³: æœåºããåèªãªã¹ããã¡ã¿ããŒã¿ãã¡ãŒã«ã¢ãã¬ã¹ããããããã¡ã€ã«ã«åºåã§ããŸãã
- èªèšŒã»ãããã·å¯Ÿå¿: BasicèªèšŒãDigestèªèšŒãå¿ èŠãªãµã€ãããããã·çµç±ã§ã®ã¢ã¯ã»ã¹ã«ã察å¿ããŠããŸãã
- 倧æå/å°æåã®æ±ã: æœåºããåèªããã¹ãŠå°æåã«å€æãããªãã·ã§ã³ããããŸãã
- æ°åãå«ãåèª: æ°åãå«ãåèªãæœåºå¯Ÿè±¡ã«å«ãããã©ããã®ãªãã·ã§ã³ããããŸãã
- åèªã®åºçŸåæ°è¡šç€º: ååèªãäœååºçŸãããã衚瀺ãããªãã·ã§ã³ããããŸãã
CeWLã«ã¯ãé¢é£ããŒã«ãšã㊠FAB (Files Already Bagged) ãå«ãŸããŠããŸããFABã¯ãããŠã³ããŒãæžã¿ã®ãã¡ã€ã«ïŒOfficeææžãPDFãªã©ïŒããã¡ã¿ããŒã¿ïŒäœæè æ å ±ãªã©ïŒãæœåºãããŠãŒã¶ãŒåã®åè£ãªã¹ããäœæããããã®ããŒã«ã§ããCeWLãçæãããã¹ã¯ãŒãåè£ãªã¹ããšçµã¿åãããŠå©çšãããããšããããŸãã
ã€ã³ã¹ããŒã«æ¹æ³ ð»
CeWLã¯å€ãã®ãããã¬ãŒã·ã§ã³ãã¹ãçšLinuxãã£ã¹ããªãã¥ãŒã·ã§ã³ãç¹ã«Kali Linuxã«ã¯ããã©ã«ãã§ã€ã³ã¹ããŒã«ãããŠããŸãã
ãããã䜿ãã®ç°å¢ã«CeWLãã€ã³ã¹ããŒã«ãããŠããªãå Žåããä»ã®OSïŒUbuntu, macOS, Windowsäžã®WSLãªã©ïŒã§å©çšãããå Žåã¯ã以äžã®æé ã§ã€ã³ã¹ããŒã«ã§ããŸããCeWLã¯Rubyã§æžãããŠãããããRubyããã³RubyGemsãäºåã«ã€ã³ã¹ããŒã«ãããŠããå¿ èŠããããŸãã
äŸåé¢ä¿
CeWLã®å®è¡ã«ã¯ã以äžã®Rubyã©ã€ãã©ãªïŒgemïŒãå¿ èŠã§ã:
ããã«ãmini_exiftool
gemã¯ãã·ã¹ãã ã«exiftool
ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ãããŠããå¿
èŠããããŸããããã¯éåžžãåOSã®ããã±ãŒãžãããŒãžã£ã§ã€ã³ã¹ããŒã«ã§ããŸãã
# Debian/Ubuntuç³»ã®å Žå
sudo apt update
sudo apt install ruby ruby-dev build-essential libgmp-dev zlib1g-dev liblzma-dev patch libcurl4-openssl-dev libxml2-dev libxslt1-dev pkg-config exiftool -y
ã€ã³ã¹ããŒã«æé
RubyGemsã䜿ã£ãŠã€ã³ã¹ããŒã«ããã®ãäžè¬çã§ã:
sudo gem install cewl
ãããã¯ãGitHubãªããžããªãããœãŒã¹ã³ãŒããã¯ããŒã³ããBundlerã䜿ã£ãŠäŸåé¢ä¿ãã€ã³ã¹ããŒã«ããããšãå¯èœã§ãã
git clone https://github.com/digininja/CeWL.git
cd CeWL
gem install bundler
bundle install
Kali Linuxã§ããã±ãŒãžãšããŠã€ã³ã¹ããŒã«ããå Žå:
sudo apt update
sudo apt install cewl
Dockerã§ã®å©çš
Dockerãã€ã³ã¹ããŒã«ãããŠããã°ãã³ã³ããã䜿ã£ãŠCeWLãå®è¡ããããšãã§ããŸãã
# Dockerã€ã¡ãŒãžã®ãã«ã
git clone https://github.com/digininja/CeWL.git
cd CeWL
docker build -t cewl .
# ã³ã³ããã®å®è¡ (ããŒã«ã«ãã¡ã€ã«ã¢ã¯ã»ã¹ãªã)
docker run -it --rm cewl [ãªãã·ã§ã³] ... <url>
# ã³ã³ããã®å®è¡ (ããŒã«ã«ãã¡ã€ã«ã¢ã¯ã»ã¹ãã - ã«ã¬ã³ããã£ã¬ã¯ããªãããŠã³ã)
docker run -it --rm -v "${PWD}:/host" cewl [ãªãã·ã§ã³] ... <url>
åºæ¬çãªäœ¿ãæ¹ ð
æãåºæ¬çãªäœ¿ãæ¹ã¯ãcewl
ã³ãã³ãã®åŸã«å¯Ÿè±¡ã®URLãæå®ããã ãã§ããããã«ãããæå®ããURLã®WebããŒãžããåèªãæœåºãããæšæºåºåã«è¡šç€ºãããŸããããã©ã«ãã§ã¯ã深床2ïŒæå®ããããŒãžãšããããã1åãªã³ã¯ã蟿ã£ãããŒãžïŒãŸã§ã¯ããŒã«ãã3æå以äžã®åèªãæœåºããŸãã
cewl http://example.com
äžèšã®ã³ãã³ããå®è¡ãããšãhttp://example.com
ãšãã®ãµã€ãå
ã®ãªã³ã¯å
ïŒæ·±åºŠ2ãŸã§ïŒããåéãããåèªã®ãªã¹ããã¿ãŒããã«ã«åºåãããŸãã
ãã¡ã€ã«ãžã®åºå
å€ãã®å Žåãçæãããã¯ãŒããªã¹ãããã¡ã€ã«ã«ä¿åããŠãä»ã®ããŒã«ã§å©çšãããã§ãããã-w
ãŸã㯠--write
ãªãã·ã§ã³ã䜿çšããŸãã
cewl http://example.com -w wordlist.txt
ãã®ã³ãã³ãã¯ãæœåºããåèªãªã¹ãã wordlist.txt
ãšããååã®ãã¡ã€ã«ã«ä¿åããŸãã
äž»èŠãªãªãã·ã§ã³è§£èª¬ ð§
CeWLã«ã¯å€ãã®ãªãã·ã§ã³ããããæåã现ããå¶åŸ¡ã§ããŸãã以äžã«äž»èŠãªãªãã·ã§ã³ã説æããŸãã
ãªãã·ã§ã³ | çç¥åœ¢ | 説æ | ããã©ã«ãå€ |
---|---|---|---|
--help |
-h |
ãã«ãã¡ãã»ãŒãžã衚瀺ããŸãã | – |
--depth <x> |
-d <x> |
ã¹ãã€ããŒã蟿ããªã³ã¯ã®æ·±ãïŒéå±€ïŒãæå®ããŸãã | 2 |
--min_word_length <x> |
-m <x> |
æœåºããåèªã®æå°æåæ°ãæå®ããŸãã | 3 |
--max_word_length <x> |
-x <x> |
æœåºããåèªã®æ倧æåæ°ãæå®ããŸãã | æå®ãªã |
--offsite |
-o |
æå®ããURL以å€ã®å€éšãµã€ããžã®ãªã³ã¯ã蟿ãããã«ããŸããâ ïž æ³šæ: æå³ããåºç¯å²ãªã¯ããŒã«ã«ãªãå¯èœæ§ããããŸãã | ç¡å¹ |
--write <file> |
-w <file> |
æœåºããåèªãªã¹ããæå®ãããã¡ã€ã«ã«æžã蟌ã¿ãŸãã | æšæºåºå |
--ua <agent> |
-u <agent> |
HTTPãªã¯ãšã¹ãæã«éä¿¡ããUser-Agentæååãæå®ããŸãã | CeWLã®ããã©ã«ãå€ |
--no-words |
-n |
åèªãªã¹ããåºåããŸããïŒã¡ã¿ããŒã¿ãã¡ãŒã«ã¢ãã¬ã¹ã®ã¿æœåºããå Žåãªã©ã«äœ¿çšïŒã | åèªãªã¹ããåºå |
--lowercase |
æœåºããåèªããã¹ãŠå°æåã«å€æããŸãã | å€æããªã | |
--with-numbers |
æ°åãå«ãåèªãæœåºå¯Ÿè±¡ãšããŸãïŒäŸ: “product123″ïŒã | æ°åãå«ãŸãªãåèªã®ã¿ | |
--convert-umlauts |
ãŠã ã©ãŠããªã©ã®ç¹å®ã®ISO-8859-1æåãASCIIçžåœã®æåã«å€æããŸã (Àâae, öâoe, ÃŒâue, Ãâss)ã | å€æããªã | |
--meta |
-a |
ããã¥ã¡ã³ããã¡ã€ã«ïŒPDF, Officeãªã©ïŒããã¡ã¿ããŒã¿ïŒäœæè
æ
å ±ãªã©ïŒãæœåºããŸããexiftool ãå¿
èŠã§ãã |
æœåºããªã |
--meta_file <file> |
æœåºããã¡ã¿ããŒã¿ãæå®ãããã¡ã€ã«ã«æžã蟌ã¿ãŸãã | æšæºåºå (--meta æå®æ) |
|
--email |
-e |
ããŒãžå ããã¡ãŒã«ã¢ãã¬ã¹ãæœåºããŸãã | æœåºããªã |
--email_file <file> |
æœåºããã¡ãŒã«ã¢ãã¬ã¹ãæå®ãããã¡ã€ã«ã«æžã蟌ã¿ãŸãã | æšæºåºå (--email æå®æ) |
|
--count |
-c |
ååèªã®åºçŸåæ°ã衚瀺ããŸãããªã¹ãã¯åæ°é ã«ãœãŒããããŸãã | 衚瀺ããªã |
--verbose |
-v |
詳现ãªåŠçæ å ±ã衚瀺ããŸãããããã°ã«åœ¹ç«ã¡ãŸãã | ç¡å¹ |
--debug |
ããã«è©³çŽ°ãªãããã°æ å ±ã衚瀺ããŸãã | ç¡å¹ | |
--auth_type <type> |
èªèšŒã¿ã€ããæå®ããŸã (basic ãŸã㯠digest )ã |
– | |
--auth_user <user> |
èªèšŒã«äœ¿çšãããŠãŒã¶ãŒåãæå®ããŸãã | – | |
--auth_pass <pass> |
èªèšŒã«äœ¿çšãããã¹ã¯ãŒããæå®ããŸãã | – | |
--proxy_host <host> |
ãããã·ãµãŒããŒã®ãã¹ãåãæå®ããŸãã | – | |
--proxy_port <port> |
ãããã·ãµãŒããŒã®ããŒãçªå·ãæå®ããŸãã | 8080 |
|
--proxy_username <user> |
ãããã·èªèšŒãå¿ èŠãªå Žåã®ãŠãŒã¶ãŒåãæå®ããŸãã | – | |
--proxy_password <pass> |
ãããã·èªèšŒãå¿ èŠãªå Žåã®ãã¹ã¯ãŒããæå®ããŸãã | – | |
--header, -H <header:value> |
-H |
ã«ã¹ã¿ã HTTPããããŒãè¿œå ããŸã (äŸ: -H "Cookie: sessionid=123" )ãè€æ°æå®å¯èœã§ãã |
– |
--keep |
-k |
ããŠã³ããŒããããã¡ã€ã«ãä¿æããŸãã | ä¿æããªã |
--exclude <file> |
ã¯ããŒã«å¯Ÿè±¡ããé€å€ãããã¹ã®ãªã¹ããå«ããã¡ã€ã«ãæå®ããŸãã | – | |
--allowed <regex> |
ã¯ããŒã«ãèš±å¯ãããã¹ã®æ£èŠè¡šçŸãã¿ãŒã³ãæå®ããŸãã | – | |
--meta-temp-dir <dir> |
ã¡ã¿ããŒã¿æœåºæã«exiftoolã䜿çšããäžæãã£ã¬ã¯ããªãæå®ããŸãã | /tmp |
å®è·µçãªå©çšäŸð¡
äŸ1: åºæ¬çãªã¯ããŒã«ãšãã¡ã€ã«ä¿å
æå®ãããµã€ãã深床2ãæå°åèªé·5æåã§ã¯ããŒã«ããçµæã docs.txt
ã«ä¿åããŸãã
cewl -d 2 -m 5 -w docs.txt https://example.com
äŸ2: ã¡ã¢ããšã¡ã¿ããŒã¿ã®æœåº
深床1ã§ã¯ããŒã«ããåèªãªã¹ãã¯åºåãããã¡ãŒã«ã¢ãã¬ã¹ãšã¡ã¿ããŒã¿ãæœåºããããããå¥ã®ãã¡ã€ã«ã«ä¿åããŸãã
cewl https://target-site.com -d 1 -n -e --email_file emails.txt -a --meta_file metadata.txt
äŸ3: BasicèªèšŒãå¿ èŠãªãµã€ããžã®ã¢ã¯ã»ã¹
BasicèªèšŒãå¿ èŠãªãµã€ãã«å¯ŸããŠããŠãŒã¶ãŒåãšãã¹ã¯ãŒããæå®ããŠã¯ããŒã«ããŸãã
cewl --auth_type basic --auth_user admin --auth_pass password123 -w auth_words.txt https://secure.example.com
äŸ4: ãããã·çµç±ã§ã®ã¢ã¯ã»ã¹
ãããã·ãµãŒã㌠proxy.local:8080
ãçµç±ããŠãµã€ãã«ã¢ã¯ã»ã¹ããŸãã
cewl --proxy_host proxy.local --proxy_port 8080 -w proxy_words.txt https://internal.example.com
äŸ5: 詳现衚瀺ãšåèªã«ãŠã³ã
ã¯ããŒã«ããã»ã¹ã詳现ã«è¡šç€ºããååèªã®åºçŸåæ°ãã«ãŠã³ãããŠãã¡ã€ã«ã«åºåããŸãã
cewl -v -c -w counted_words.txt https://blog.example.com
äŸ6: æ°åãå«ãåèªãšå°æåå
æ°åãå«ãåèªãæœåºãããã¹ãŠå°æåã«å€æããŠã¯ãŒããªã¹ããäœæããŸãã
cewl --with-numbers --lowercase -w alphanumeric_lower.txt https://techforum.example.com
é«åºŠãªäœ¿ãæ¹ãšæ³šæç¹ â ïž
å¹æçãªã¿ãŒã²ããéžå®
CeWLã®å¹æã¯ãã¿ãŒã²ãããšããWebãµã€ãã®éžå®ã«å€§ããäŸåããŸããåŸæ¥å¡ã®ããã°ãäŒç€Ÿã®ãäŒç€ŸæŠèŠããã補åæ å ±ãããŒãžãæè¡ããã¥ã¡ã³ãããã©ãŒã©ã ãªã©ãã¿ãŒã²ããçµç¹ã«é¢é£ããåºæã®åèªãå€ãå«ãŸããŠããããªããŒãžãéžã¶ããšãéèŠã§ãã
ä»ã®ããŒã«ãšã®é£æº
CeWLã§çæããã¯ãŒããªã¹ãã¯ããã®ãŸãŸãã¹ã¯ãŒãã¯ã©ããã³ã°ããŒã«ïŒJohn the Ripper, Hashcatãªã©ïŒããã«ãŒããã©ãŒã¹ããŒã«ïŒHydra, Medusaãªã©ïŒã®èŸæžãã¡ã€ã«ãšããŠå©çšã§ããŸããããå¹æçãªãã¹ã¯ãŒãã¯ã©ãã¯ã®ããã«ã¯ãCeWLã§çæãããªã¹ãã«ãäžè¬çãªèŸæžãªã¹ãïŒäŸ: RockYouïŒããä»ã®ã«ãŒã«ããŒã¹ã®åèªçæïŒäŸ: CrunchïŒãçµã¿åãããããšãæå¹ã§ãã
# CeWLã§ãªã¹ãçæ
cewl -d 3 -m 6 -w cewl_list.txt https://target.example.com
# Hashcatã§CeWLãªã¹ãã䜿ã£ãŠã¯ã©ãã¯è©Šè¡
hashcat -m 0 -a 0 hashfile.txt cewl_list.txt
# Hydraã§CeWLãªã¹ãã䜿ã£ãŠãã°ã€ã³è©Šè¡
hydra -L users.txt -P cewl_list.txt target.example.com http-post-form "/login.php:user=^USER^&pass=^PASS^:F=Login Failed"
ã¯ããŒã«æ·±åºŠãšç¯å²ã®æ³šæ
-d
(深床)ãªãã·ã§ã³ã倧ããèšå®ãããã-o
(å€éšãµã€ãèš±å¯)ãªãã·ã§ã³ã䜿çšãããšãã¯ããŒã«ç¯å²ãéåžžã«åºããªããæéãšãªãœãŒã¹ã倧éã«æ¶è²»ããå¯èœæ§ããããŸãããŸããæå³ããªããµã€ããžå€§éã®ãªã¯ãšã¹ããéãããšã«ãªããããŸããããããã®ãªãã·ã§ã³ã¯æ
éã«äœ¿çšããŠãã ããã--exclude
ã --allowed
ãªãã·ã§ã³ã§ã¯ããŒã«ç¯å²ãé©åã«å¶éããããšãæ€èšããŸãããã
æ³çã»å«ççãªåŽé¢
CeWLãå«ãããããã»ãã¥ãªãã£ããŒã«ã¯ãå¿ ãèš±å¯ãããç°å¢ããŸãã¯èªèº«ã®ç®¡çäžã«ããç°å¢ã«å¯ŸããŠã®ã¿äœ¿çšããŠãã ãããèš±å¯ãªã第äžè ã®Webãµã€ããã¯ããŒã«ããããååŸããæ å ±ã§äžæ£ã¢ã¯ã»ã¹ãè©Šã¿ãããšã¯ãæ³åŸã§çŠæ¢ãããŠãããé倧ãªçµæãæãå¯èœæ§ããããŸãã
ãŸãšã âš
CeWLã¯ãç¹å®ã®ã¿ãŒã²ããã«åãããã«ã¹ã¿ã ã¯ãŒããªã¹ããå¹ççã«çæããããã®éåžžã«åŒ·åãªããŒã«ã§ããWebãµã€ãã®ã³ã³ãã³ãããé¢é£æ§ã®é«ãåèªãæœåºããããšã§ãäžè¬çãªèŸæžæ»æãããæåçã®é«ããã¹ã¯ãŒãã¯ã©ãã¯ããã«ãŒããã©ãŒã¹æ»æãå¯èœã«ããŸãã
è±å¯ãªãªãã·ã§ã³ã«ãããã¯ããŒã«ç¯å²ãåèªã®ãã£ã«ã¿ãªã³ã°ãã¡ã¿ããŒã¿ãã¡ãŒã«ã¢ãã¬ã¹ã®æœåºãªã©ãæ§ã ãªããŒãºã«å¯Ÿå¿ã§ããŸãããããã¬ãŒã·ã§ã³ãã¹ããã»ãã¥ãªãã£è©äŸ¡ã«ãããŠãã¿ãŒã²ããã«é¢ããæ å ±ã掻çšãããã¹ã¯ãŒãæšæž¬ã¯éèŠãªææ³ã®äžã€ã§ãããCeWLã¯ãã®ããã»ã¹ãèªååããå¹çåããäžã§å€§ããªå©ããšãªããŸãã
ãã ãããã®åŒ·åãããã«ã䜿çšã«ã¯æ³çã»å«ççãªé æ ®ãäžå¯æ¬ ã§ããåžžã«èš±å¯ãããç¯å²å ã§ã責任ãã䜿ãæ¹ãå¿ãããŸããããð
ã³ã¡ã³ã