Coder Social home page Coder Social logo

s0md3v / blazy Goto Github PK

View Code? Open in Web Editor NEW
832.0 38.0 247.0 35 KB

Blazy is a modern login bruteforcer which also tests for CSRF, Clickjacking, Cloudflare and WAF .

License: GNU General Public License v3.0

Python 100.00%
brute-force bruteforce scanner

blazy's Issues

I keep getting this error when I enter website URL

I can get the program to run fine. When I'm ask to enter a URL it says:
Traceback (most recent call last):
File "blazy.py", line 48, in
br.open(url)
File "/home/home/.local/lib/python2.7/site-packages/mechanize/_mechanize.py", line 253, in open
return self._mech_open(url_or_request, data, timeout=timeout)
File "/home/home/.local/lib/python2.7/site-packages/mechanize/_mechanize.py", line 283, in _mech_open
response = UserAgentBase.open(self, request, data)
File "/home/home/.local/lib/python2.7/site-packages/mechanize/_opener.py", line 193, in open
response = urlopen(self, req, data)
File "/home/home/.local/lib/python2.7/site-packages/mechanize/_urllib2_fork.py", line 353, in _open
'_open', req)
File "/home/home/.local/lib/python2.7/site-packages/mechanize/_urllib2_fork.py", line 341, in _call_chain
result = func(*args)
File "/home/home/.local/lib/python2.7/site-packages/mechanize/_urllib2_fork.py", line 1209, in https_open
return self.do_open(conn_factory, req)
File "/home/home/.local/lib/python2.7/site-packages/mechanize/_urllib2_fork.py", line 1156, in do_open
raise URLError(err)
urllib2.URLError: <urlopen error [Errno -2] Name or service not known>

Lack of support for unicode

$ python blazy.py 
    ____   _                    
   |  _ \ | |              
   | |_) || |  __ _  ____ _   _ 
   |  _ < | | / _` ||_  /| | | |
   | |_) || || (_| | / / | |_| |
   |____/ |_| \__,_|/___| \__, |
                           __/ |
    Made with <3 By D3V   |___/ 
    
[?] Enter target URL: https://XXXX/wp-login.php
[>] Usernames loaded: 13
[>] Passwords loaded: 25
Traceback (most recent call last):
  File "blazy.py", line 204, in <module>
    find()
  File "blazy.py", line 106, in find
    data = str(f) #Converts the response recieved to string
  File "/home/rozie/programs/Blazy/blaze_venv3/local/lib/python2.7/site-packages/mechanize/_form_controls.py", line 1934, in __str__
    rep.append("  %s" % str(control))
UnicodeEncodeError: 'ascii' codec can't encode character u'\u0119' in position 35: ordinal not in range(128)

Tried with Wordpress set up for Polish language, but that looks like general problem as it is very similar to #10

Ascii Encoding Error

I have attached the trace below:

Traceback (most recent call last):
  File "blazy.py", line 204, in <module>
    find()
  File "blazy.py", line 106, in find
    data = str(f) #Converts the response recieved to string
  File "/Users/xyz/Blazy/blazyenv/lib/python2.7/site-packages/mechanize/_form_controls.py", line 1932, in __str__
    rep.append("  %s" % str(control))
UnicodeEncodeError: 'ascii' codec can't encode character u'\u2713' in position 20: ordinal not in range(128)

always can't find the path of wordlist

888888 888888 BRUTE
8 8 eeeee e e eeeee eeee 8 8 e e eeeeeee FORCE
8eeee8ee 8 8 8 8 8 8 8e 8 8 8 8 8 8 JUST
88 8 8eee8e 8e 8 8e 8eee 88 8 8e 8 8e 8 8 FOR
88 8 88 8 88 8 88 88 88 8 88 8 88 8 8 THE
88eeeee8 88 8 88ee8 88 88ee 88eee8 88ee8 88 8 8 DUMMIES

[i] BruteDum - Brute Force attacks SSH, FTP, Telnet, PostgreSQL, RDP, VNC with Hydra, Medusa and Ncrack
Author: https://GitHackTools.blogspot.com

[i] Target: 104.27.XXX.XXX
Protocol: ssh
[?] Do you want to use username list? [Y/n]: n
[?] Enter the username: root
[?] Enter the path of wordlist: ~/hacktools/BruteDum/passs^H
[!] That path os doesn't exist
[?] Enter the path of wordlist: ^[[A^H^H^H^H^H
[!] That path os doesn't exist
[?] Enter the path of wordlist: ~/hacktools/BruteDum/passwd.txt
[!] That path os doesn't exist
[?] Enter the path of wordlist: ^[[A^H^H^H^H
[!] That path os doesn't exist
[?] Enter the path of wordlist: ~/hacktools/BruteDum/passwd.txt/

Trying my custom login page

It has an https address but not an http address. Blazy freezes up while trying to reach the http version. There doesn't appear to be a working timeout.

modified

line 45 i removed br.open(url, timeout=10.0)")" <----- and script worked ok.

thx in adv.

http protocol error', 0, 'got a bad status line', None

Hi.

I get the following error.

root@lol:~/Blazy# python blazy.py
    ____   _
   |  _ \ | |
   | |_) || |  __ _  ____ _   _
   |  _ < | | / _` ||_  /| | | |
   | |_) || || (_| | / / | |_| |
   |____/ |_| \__,_|/___| \__, |
                           __/ |
    Made with <3 By D3V   |___/

[?] Enter target URL: https://xxxx/login/login.jsp
[+] Heuristic found a Clickjacking Vulnerability
Traceback (most recent call last):
  File "blazy.py", line 77, in <module>
    WAF_detector()
  File "blazy.py", line 68, in WAF_detector
    res1 = urlopen(fuzz) #Opens the noise injected payload
  File "/usr/lib/python2.7/urllib.py", line 87, in urlopen
    return opener.open(url)
  File "/usr/lib/python2.7/urllib.py", line 213, in open
    return getattr(self, name)(url)
  File "/usr/lib/python2.7/urllib.py", line 357, in open_http
    'got a bad status line', None)
IOError: ('http protocol error', 0, 'got a bad status line', None)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.