candyapplecorn

NIST Vulnerability Extractor for Mac

Jun 16th, 2015
312
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 3.21 KB | None | 0 0
  1. #!/bin/bash
  2.  
  3. # ===================================================================
  4. #     Vulnerability extractor script
  5. #    by Joseph Burger
  6. #    2015 - 3 - 17
  7.  
  8. #    This shell script takes the url to the vulnerabilities XML file,
  9. #    packaged as a .gz file, from http://static.vbd.nist.gov/downloads.cfm
  10. #    and then downloads it, unzips it, extracts the vulnerability id and score
  11. #    using an awk script, and then further refines the output of that awk script
  12. #    using a sed script. The finished product is a text file with two columns, the
  13. #    first column being the vulnerability id, and the second column having the
  14. #    vulnerability's severity score, or in the case that there's no severity score,
  15. #    "TBD". This output file is saved as "condensedVulns.txt"
  16. # ===================================================================
  17.  
  18. #Change directories
  19. clear
  20. cd /Users/fredburger/Documents/VulnFind/SCRIPTS/
  21.  
  22. # ===================================================================
  23. #    Get the xml file.
  24. #    User input method is commented out, in favor of
  25. #     automatically getting it using curl with some egrep
  26. # ===================================================================
  27.  
  28. echo -n "Please enter the year for the XML file "
  29. read xmlURL
  30.  
  31. curl -o xmlFile$xmlURL.xml.zip $(egrep $xmlURL XMLGZURLS)
  32. unzip xmlFile$xmlURL.xml.zip
  33.  
  34. #download=`curl https://nvd.nist.gov/download.cfm | \
  35. #egrep feeds/xml.*$xmlURL.*gz | tail -n 1 | sed -r "s/.*a href='(.*?)' .*$/\1/"`;
  36.  
  37. #curl -o xmlFile $download
  38. #echo Please enter the name of the xml.gz file
  39. #read xmlFile
  40.  
  41. # ===================================================================
  42. #    This command extracts the awk script from this shell script and
  43. #    stores it inside the file "awkScript"
  44. # ===================================================================
  45. tail -n 22 getVulns.sh | tr '\#' ' ' > awkScript;
  46. chmod 777 awkScript
  47.  
  48. #wget $xmlURL && \
  49. #gzip -d $xmlFile && \
  50. #sedCmd="'/<entry id/N; s/^.*<entry id*."(.*)".*cvss:score>(.*)<.*$/\1    \2/w condensedVulnsTest.txt'"
  51. awk -f awkScript *.xml | sed -nE '/<entry id/N; s/^.*<entry id*."(.*)".*cvss:score>(.*)<.*$/\1    \2/w condensedVulnsTest.txt' && \
  52. rm *.xml *.zip awkScript
  53. mv condensedVulnsTest.txt ../vulns$xmlURL.txt
  54. open /Users/Fredburger/Documents/VulnFind
  55. #echo $myURL
  56. echo The vulnerabilities are listed in "vulns$xmlURL.txt"
  57. killall Terminal
  58.  
  59. # ===================================================================
  60. #    Store the awk script inside this shell script to save space
  61. # ===================================================================
  62.  
  63. # This script goes through an xml file containing vulnerabilities
  64. # and extracts the id, as well as the score. If there is no score
  65. # it substitutes "TBD".
  66. #BEGIN{
  67. #    num=0;
  68. #    }
  69. #{
  70. #    if( /entry id/ ) {
  71. #        print $0;
  72. #        arr[num++] = $0
  73. #        while ( ! /cvss:score/ && ! /entry>/ ){
  74. #            getline < FILENAME
  75. #        }
  76. #        if ( /cvss:score/ ) {
  77. #            arr[num] = arr[num] $0
  78. #        } else {
  79. #            arr[num] = arr[num] "\t<cvss:score>TBD</cvss:score>"
  80. #        }
  81. #        while ( ! /entry>/ ) {
  82. #            getline < FILENAME
  83. #        }
  84. #        print arr[num]
  85. #    }
  86. #}
  87. #END{}
Advertisement
Add Comment
Please, Sign In to add comment