26 August 2020

The Pillager 0.7 Release

I spent the last couple days recoding the Pillager, getting rid of bugs, optimizing code, making it more extendable and more solid overall. So this post is to release the new code.  However, with that being said, the Pillager is in mass revision right now and I added some more developers to the team to add a whole host of new database attacking features as well as moving past databases and into other areas of post exploitation pillaging. Soon to be released..  As usual this tool and any tool i create is based on my issues when performing penetration tests and solves those problems.. If you have any insight or comments i will certainly take them into consideration for future releases.

For now check out Version 0.7.. Named searches and Data searches via external config files are now functioning properly as well as other bugs fixed along the way... Drop this in a BT5 VM and make sure you have your DB python stuff installed per the help docs and you should be good to go.  If you are looking to use oracle you are going to have to install all the oracle nonsense from oracle or use a BT4r2 vm which has most of the needed drivers minus cxoracle which will need to be installed.

http://consolecowboys.org/pillager/pillage_0.7.zip



Ficti0n$ python pillager.py
 
[---] The Database Pillager (DBPillage) [---]
[---] CcLabs Release [---]
[---] Authors: Ficti0n, [---]
[---] Contributors: Steponequit [---]
[---] Version: 0.7 [---]
[---] Find Me On Twitter: ficti0n [---]
[---] Homepage: http://console-cowboys.blogspot.com [---]

Release Notes:
 --Fixed bugs and optimized code
 --Added Docstrings
 --Fixed Named and Data searches from config files                 

About:
The Database Pillager is a multiplatform database tool for searching and browsing common
database platforms encountered while penetration testing. DBPillage can be used to search
for PCI/HIPAA data automatically or use DBPillage to browse databases,display data.
and search for specified tables/data instances.
DBpillage was designed as a post exploitation pillaging tool with a goal of targeted
extraction of data without the use of database platform specific GUI based tools that
are difficult to use and make my job harder.

Supported Platforms:
        --------------------
-Oracle
-MSSQL
-MYSQL
        -PostGreSQL
     

        Usage Examples:
        ************************************************************************
        
        For Mysql Postgres and MsSQL pillaging:
        ---------------------------------------
        python dbPillage -a [address] -d [dbType] -u [username] -p [password]
        
        
        For Oracle pillaging you need a SID connection string:
        ------------------------------------------------------
        python dbPillage-a [address]/[sid] -d [dbType] -u [username] -p [password]
        

        Grab some hashes and Hipaa specific:(Default is PCI)
        ------------------------------------
        python dbPillage -a [address] -d [dbType] -u [username] -p [password] --hashes -s hipaa


Drop into a SQL CMDShell:
-------------------------
        python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -q

Config file specified searches:
-------------------------------
Search for data Items from inputFiles/data.txt:
        python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -D

Search for specific table names from inputFiles/tables.txt:
python dbpillage.py -a [address] -d [dbType] -u [username] -p [password] -N

     
     
        Switch Options:
        ---------------------
        -# --hashes = grab database password hashes
        -l --limit  = limit the amount of rows that are searched or when displaying data (options = any number)
        -s --searchType = Type of data search you want to perform (options:pci, hipaa, all)(PCI default)
        -u --user = Database servers username
        -p --pass = Password for the database server
        -a --address = Ipaddress of the database server
        -d --database = The database type you are pillageing (options: mssql,mysql,oracle,postgres)
        -r --report = report format (HTML, XML, screen(default))
        -N --nameSearch = Search via inputFiles/tables.txt
        -D --dataSearch = Targeted data searches per inputFiles/data.txt
-q --queryShell = Drop into a SQL CMDshell in mysql or mssql
     
     
        Prerequisites:
        -------------
        python v2  (Tested on Python 2.5.2 BT4 R2 and BT5 R3 - Oracle stuff on BT4r2 only unless you install the drivers from oracle)
        cx_oracle (cx-oracle.sourceforge.net)
        psycopg2  (initd.org/psycopg/download/)
        MySQLdb   (should be on BT by default)
        pymssql   (should be on BT by default)
     

More info

  1. Hack Tools For Games
  2. Pentest Tools Nmap
  3. Hacking Tools
  4. Hacking Tools Kit
  5. Hacker Tools Hardware
  6. Hack Tools For Windows
  7. Nsa Hacker Tools
  8. Physical Pentest Tools
  9. Hacking Tools Mac
  10. Hacking Tools Hardware
  11. Hacking Tools For Pc
  12. Hack Rom Tools
  13. Hacking Tools Name
  14. Hacking Tools Hardware
  15. Pentest Tools Android
  16. Hacking Tools For Pc
  17. Pentest Tools Github
  18. Hack Website Online Tool
  19. Pentest Tools List
  20. Kik Hack Tools
  21. Pentest Tools Subdomain
  22. Hack Tools
  23. Computer Hacker
  24. Best Pentesting Tools 2018
  25. Hacker Tools Github
  26. What Is Hacking Tools
  27. Hacking Apps
  28. Free Pentest Tools For Windows
  29. Hacking Tools For Mac
  30. Hack Tools Mac
  31. What Are Hacking Tools
  32. Pentest Tools
  33. Hacking Apps
  34. Hack Tools 2019
  35. Easy Hack Tools
  36. Hacking Tools Software
  37. Computer Hacker
  38. Hacker Tools For Mac
  39. Hacker Tools 2019
  40. Kik Hack Tools
  41. Hacking App
  42. Nsa Hacker Tools
  43. Pentest Tools Bluekeep
  44. Bluetooth Hacking Tools Kali
  45. Pentest Tools Free
  46. Easy Hack Tools
  47. New Hacker Tools
  48. Hacking Tools For Games
  49. Physical Pentest Tools
  50. Hack Tools For Windows
  51. Hack Tools For Pc
  52. Pentest Tools Url Fuzzer
  53. Pentest Tools Alternative
  54. Hack Tool Apk
  55. Hacker Tools Apk Download
  56. Pentest Tools Alternative
  57. Bluetooth Hacking Tools Kali
  58. Hacking Tools 2020
  59. Hacker Tools 2019
  60. Hacking Tools Github
  61. How To Hack
  62. Hack Tools For Windows
  63. Pentest Tools Android
  64. Hacker Hardware Tools
  65. Hack Tools For Windows
  66. Hacker Tools Linux
  67. Best Hacking Tools 2019
  68. Hacker Tools Software
  69. Pentest Tools Bluekeep
  70. What Are Hacking Tools
  71. Android Hack Tools Github
  72. Hacker Tools For Ios
  73. Pentest Tools Tcp Port Scanner
  74. Pentest Tools
  75. Hacker Tool Kit
  76. Pentest Automation Tools
  77. Pentest Tools List
  78. Android Hack Tools Github
  79. Pentest Tools Url Fuzzer
  80. Hacker Tools Hardware
  81. Pentest Tools Website
  82. Hacker Tools Online
  83. Pentest Tools Website
  84. Hack Tools Mac
  85. Pentest Tools Website
  86. Hacker Tools
  87. Pentest Tools Website
  88. Hackers Toolbox
  89. Nsa Hack Tools Download
  90. Pentest Tools Website Vulnerability
  91. Hack Tools For Ubuntu
  92. Pentest Tools Windows
  93. Pentest Tools Url Fuzzer
  94. Pentest Tools Review
  95. Hacking Tools Online
  96. Hacker Tools For Pc
  97. Hack Tools For Games
  98. Pentest Tools Open Source
  99. Hacker Tool Kit
  100. Hacking Tools Windows 10
  101. Hacker Hardware Tools
  102. Hacking Tools Software
  103. Hacking Tools Software
  104. Hack Tools
  105. Hack Tool Apk No Root
  106. Hacks And Tools
  107. Hacking Tools Software
  108. Hacking Tools Windows
  109. Hack Tools Github
  110. Hacking Apps
  111. Hack Rom Tools
  112. Hacking Tools Usb
  113. Hacker Tools For Ios
  114. Pentest Tools Android
  115. Hack Tools Github
  116. Hacking Tools 2020
  117. Hacker Tools Mac
  118. Hackrf Tools
  119. Pentest Tools Review
  120. Pentest Tools Find Subdomains
  121. Pentest Tools Alternative
  122. How To Make Hacking Tools
  123. Hack Tool Apk
  124. Pentest Tools Url Fuzzer
  125. Hacker Tools
  126. Pentest Recon Tools
  127. Hacking Tools Software
  128. Hacking Tools For Kali Linux
  129. Top Pentest Tools
  130. Pentest Tools Bluekeep
  131. Hack And Tools
  132. Hacking Tools For Games
  133. Hacking Tools For Beginners
  134. Pentest Tools Tcp Port Scanner
  135. Hacking Tools Download
  136. World No 1 Hacker Software
  137. Hack Tool Apk No Root
  138. Hacker Tools 2019
  139. Top Pentest Tools

Your Ad Here
 

blogger templates 3 columns | Make Money Online