-
Notifications
You must be signed in to change notification settings - Fork 362
/
Copy pathshow-explodedDns.go
121 lines (106 loc) · 2.72 KB
/
show-explodedDns.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
package commands
import (
"bytes"
"fmt"
"os"
"strings"
"github.com/activecm/rita-legacy/pkg/explodeddns"
"github.com/activecm/rita-legacy/resources"
"github.com/olekukonko/tablewriter"
"github.com/urfave/cli"
)
func init() {
command := cli.Command{
Name: "show-exploded-dns",
Usage: "Print dns analysis. Exposes covert dns channels",
ArgsUsage: "<database>",
Flags: []cli.Flag{
ConfigFlag,
humanFlag,
limitFlag,
noLimitFlag,
delimFlag,
},
Action: func(c *cli.Context) error {
db := c.Args().Get(0)
if db == "" {
return cli.NewExitError("Specify a database", -1)
}
res := resources.InitResources(getConfigFilePath(c))
res.DB.SelectDB(db)
data, err := explodeddns.Results(res, c.Int("limit"), c.Bool("no-limit"))
if err != nil {
res.Log.Error(err)
return cli.NewExitError(err, -1)
}
if len(data) == 0 {
return cli.NewExitError("No results were found for "+db, -1)
}
if c.Bool("human-readable") {
err := showDNSResultsHuman(data)
if err != nil {
return cli.NewExitError(err.Error(), -1)
}
return nil
}
err = showDNSResults(data, c.String("delimiter"))
if err != nil {
return cli.NewExitError(err.Error(), -1)
}
return nil
},
}
bootstrapCommands(command)
}
// splitSubN splits s every n characters
func splitSubN(s string, n int) []string {
sub := ""
subs := []string{}
runes := bytes.Runes([]byte(s))
l := len(runes)
for i, r := range runes {
sub = sub + string(r)
if (i+1)%n == 0 {
subs = append(subs, sub)
sub = ""
} else if (i + 1) == l {
subs = append(subs, sub)
}
}
return subs
}
func showDNSResults(dnsResults []explodeddns.Result, delim string) error {
headers := []string{"Domain", "Unique Subdomains", "Times Looked Up"}
// Print the headers and analytic values, separated by a delimiter
fmt.Println(strings.Join(headers, delim))
for _, result := range dnsResults {
fmt.Println(
strings.Join(
[]string{result.Domain, i(result.SubdomainCount), i(result.Visited)},
delim,
),
)
}
return nil
}
func showDNSResultsHuman(dnsResults []explodeddns.Result) error {
const DOMAINRECLEN = 80
table := tablewriter.NewWriter(os.Stdout)
table.SetAutoWrapText(true)
table.SetRowSeparator("-")
table.SetRowLine(true)
table.SetHeader([]string{"Domain", "Unique Subdomains", "Times Looked Up"})
for _, result := range dnsResults {
domain := result.Domain
if len(domain) > DOMAINRECLEN {
// Reformat the result.Domain value adding a newline every DOMAINRECLEN chars for wrapping
subs := splitSubN(result.Domain, DOMAINRECLEN)
domain = strings.Join(subs, "\n")
}
table.Append([]string{
domain, i(result.SubdomainCount), i(result.Visited),
})
}
table.Render()
return nil
}