Pengujian Penetrasi Python: Membuat Alat Multi-Opsi

Mar 10 2023
R. Eric Kiser Selama uji penetrasi, mungkin ada saat-saat di mana Anda perlu mengembangkan alat yang ringan dan tidak berisik.

R.Eric Kiser

Selama uji penetrasi, mungkin ada saat-saat di mana Anda perlu mengembangkan alat yang ringan dan senyap. Setelah melakukan pengintaian pada sistem, Anda dapat memperoleh pemahaman yang lebih jelas tentang bagaimana sistem jaringan disusun. Berbekal pengetahuan ini, Anda dapat membuat alat yang melakukan banyak tugas berdampak rendah. Pada artikel ini saya akan mendemonstrasikan cara membuat skrip Python yang menyertakan utilitas baris perintah yang mengelola sistem Linux melalui penggunaan Ansible.

Kita perlu mengimpor modul osdan subprocess untuk berinteraksi dengan sistem operasi dan menjalankan perintah.

import os
import subprocess

Fungsi pertama memberikan opsi untuk menginstal Ansible pada sistem menggunakan fungsi subprocess.rununtuk menjalankan perintah yang diperlukan.

def install_ansible():
    subprocess.run(["sudo", "apt", "update"])
    subprocess.run(["sudo", "apt", "install", "software-properties-common"])
    subprocess.run(["sudo", "apt-add-repository", "--yes", "--update", "ppa:ansible/ansible"])
    subprocess.run(["sudo", "apt", "install", "ansible"])

def add_ssh_key():
    ip = input("Enter the IP address of the remote server: ")
    username = input("Enter the username on the remote server: ")
    ssh_key_path = input("Enter the path to the SSH key: ")
    subprocess.run(["ssh-copy-id", f"{username}@{ip}", "-i", ssh_key_path])

def download_files():
    ips = input("Enter the IP addresses of the systems to download files from (comma-separated): ")
    files = input("Enter the files to download (comma-separated): ")
    dest = input("Enter the destination folder to save the files: ")
    for ip in ips.split(","):
        for file in files.split(","):
            subprocess.run(["ansible", f"{ip}", "-m", "fetch", "-a", f"src={file} dest={os.path.join(dest, ip)}"])

def download_files():
    ips = input("Enter the IP addresses of the systems to download files from (comma-separated): ")
    files = input("Enter the files to download (comma-separated): ")
    dest = input("Enter the destination folder to save the files: ")
    for ip in ips.split(","):
        for file in files.split(","):
            subprocess.run(["ansible", f"{ip}", "-m", "fetch", "-a", f"src={file} dest={os.path.join(dest, ip)}"])

def transfer_files():
    source_ip = input("Enter the IP address of the source server: ")
    dest_ip = input("Enter the IP address of the destination server: ")
    files = input("Enter the files to transfer (comma-separated): ")
    for file in files.split(","):
        subprocess.run(["ansible", f"{source_ip}", "-m", "copy", "-a", f"src={file} dest={dest_ip}:"])

choice = input("Enter your choice: ")
        if choice == "1":
            install_ansible()
        elif choice == "2":
            add_ssh_key()
        elif choice == "3":
            scan_files()
        elif choice == "4":
            download_files()
        elif choice == "5":
            transfer_files()
        elif choice == "0":
            break
        else:
            print("Invalid choice")

if __name__ == "__main__":
    main()

Itu dia. Anda sekarang memiliki kemampuan untuk membuat alat apa pun yang Anda inginkan! Tepuk tangan, ikuti, dan bagikan jika Anda menyukai artikel ini dan Selamat Berburu!