Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/bash
- # ===================================================================
- # Vulnerability extractor script
- # by Joseph Burger
- # 2015 - 3 - 17
- # This shell script takes the url to the vulnerabilities XML file,
- # packaged as a .gz file, from http://static.vbd.nist.gov/downloads.cfm
- # and then downloads it, unzips it, extracts the vulnerability id and score
- # using an awk script, and then further refines the output of that awk script
- # using a sed script. The finished product is a text file with two columns, the
- # first column being the vulnerability id, and the second column having the
- # vulnerability's severity score, or in the case that there's no severity score,
- # "TBD". This output file is saved as "condensedVulns.txt"
- # ===================================================================
- # ===================================================================
- # Get the xml file.
- # User input method is commented out, in favor of
- # automatically getting it using curl with some egrep
- # ===================================================================
- echo Please enter the download URL of the vulnerability.xml.gz file
- read xmlURL
- #xmlURL=`curl https://nvd.nist.gov/download.cfm | \
- #egrep feeds/xml.*.gz | tail -n 1 | sed -r "s/.*a href='(.*?)' .*$/\1/"`;
- # ===================================================================
- # This command extracts the awk script from this shell script and
- # stores it inside the file "awkScript"
- # ===================================================================
- tail -n 22 getVulns.sh | tr '\#' ' ' > awkScript
- wget $xmlURL && \
- gzip -d *.xml.gz && \
- awk -f awkScript *.xml | sed -rn '/<entry id/N; s/^.*<entry id*."(.*)".*cvss:score>(.*)<.*$/\1\t\2/w condensedVulns.txt' && \
- rm *.xml awkScript
- echo $myURL
- echo The vulnerabilities are listed in "condensedVulns.txt"
- # ===================================================================
- # Store the awk script inside this shell script to save space
- # ===================================================================
- # This script goes through an xml file containing vulnerabilities
- # and extracts the id, as well as the score. If there is no score
- # it substitutes "TBD".
- #BEGIN{
- # num=0;
- # }
- #{
- # if( /entry id/ ) {
- # print $0;
- # arr[num++] = $0
- # while ( ! /cvss:score/ && ! /entry>/ ){
- # getline < FILENAME
- # }
- # if ( /cvss:score/ ) {
- # arr[num] = arr[num] $0
- # } else {
- # arr[num] = arr[num] "\t<cvss:score>TBD</cvss:score>"
- # }
- # while ( ! /entry>/ ) {
- # getline < FILENAME
- # }
- # print arr[num]
- # }
- #}
- #END{}
Advertisement
Add Comment
Please, Sign In to add comment