Skip to content

Instantly share code, notes, and snippets.

@AndrHacK
Created December 28, 2017 18:50
Show Gist options
  • Save AndrHacK/4f2ed1ef9985201e65ee823a3fddc4fd to your computer and use it in GitHub Desktop.
Save AndrHacK/4f2ed1ef9985201e65ee823a3fddc4fd to your computer and use it in GitHub Desktop.
Server Deki Siteleri SQL Taraması Yapma Aracı
#Cretor: cp1254
#Edit By B0RU70 -Update (TR)
import urllib
import os
import re
from time import sleep
def sqlihunt(dork , filename ):
dork= 'IP:'+dork+" php?id= "
file2 =open(filename+'.txt','w')
start=0
end=200
sleep(3)
print "[info]Taramaya Basliyor... "
while start<=end :
try:
con = urllib.urlretrieve('http://www.bing.com/search?q='+dork+"&first="+str(start))
#con = con = urllib.urlretrieve('http://www.bing.com/search?q=ip%3A41.203.11.42+%22php%3Fid%3D%22&go=&qs=ds&form=QBLH&filt=all')
conf = open(con[0])
readd=conf.read()
find=re.findall('<h2><a href="(.*?)"',readd)
start = start+10
#return find
except IOError:
print "[ERROR]Baglanti Hatasi "
print "[Info]Yeniden Deneniyor... "
sleep(10)
print "[Info]Tekrar Baslatiliyor.. "
try :
for i in range(len(find)):
rez=find[i]+"'"
tst = urllib.urlretrieve(rez)
tstf = open(tst[0])
tstdd= tstf.read()
tstfind=re.findall('/error in your SQL syntax|SQL syntax|mysql_fetch_array()|execute query|mysql_fetch_object()|mysql_num_rows()|mysql_fetch_assoc()|mysql_fetch_row()|SELECT * FROM|supplied argument is not a valid MySQL|Syntax error|Fatal error/i|You have an error in your SQL syntax|Microsoft VBScript runtime error',tstdd)
if(tstfind):
print "[SQL Bulundu] : "+ rez
file2.write(rez + '\n')
else:
print "[SQL Bulunamadi ] : " + rez
except IOError:
print "[ERROR]Birsey Bulunamadi"
#B0RU70 http://www.zone-h.org/archive/notifier=Kirito1337 And http://www.zone-h.org/archive/notifier=B0RU70
print """
--[ B0RU70 Security / https://b0ru70.blogspot.com ]--
"""
param1 = raw_input("Hedef Ip Adress : ")
param2 = raw_input("Kayit Edilcek Dosya Adi : ")
sqlihunt(param1 , param2 )
print " ./Tamamlandi "
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment