-
-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
9674cc8
commit a5b18c5
Showing
7 changed files
with
150,096 additions
and
20 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
<mxfile host="app.diagrams.net" modified="2022-06-30T19:42:38.663Z" agent="5.0 (X11)" etag="bwqtTWnJdg6Q0cPReM3U" version="20.0.4"><diagram id="nb3tS5KzVcpROlKnmKRc" name="Page-1">1VVRb5swEP41PKYyELK8JmnZtK3TtGyq1JfKwQa8Gs4zJpD9+p3BhJCk0lrtZU82353vO393Z7xwU7TvNVX5PTAuvYCw1gtvvSDw5/4SF4sceuTd0u+BTAvmnEZgK35zBxKH1oLxauJoAKQRagomUJY8MROMag3N1C0FOWVVNOMXwDah8hJ9EMzkPbqMyIh/4CLLB2afOEtBB2cHVDll0JxA4Z0XbjSA6XdFu+HSijfo0p+LX7AeE9O8NH9z4Juie/794/2XR//p0/Yhf/yZ65mLsqeydhd2yZrDoADmrexWFJ1U6z3XRqBAn+mOy69QCSOgRPsOjIECHaQ1rGnynGmoS7YBCRrtjKe0luYkwkqKzJ40oBClleoLmIqWY87rjnA1oGRAcJ8bY8u/spcNYlryVtCbBMmDeCchw6VRM+wIY6UJ4lpJoKzCXUD8CBeC144T7FXkF4brJzwEN6rMkMMJginy9kWl/WP9sPE5FNzoA7q00949TD+bsX+ioSny09459q3r2ewYeSwrblxlX1Hl4EqVF10pmNhPqr34Vdt+XKco3qzqphFVJnOi2k6bwW6zdNUbQclTc+qyyNzaUYlzwHK8kbwPtOVVZXvPxUNp+pBTGoQvqBHrbj5F/2sxfpSVTcGF2+krV36rOmcPAg6GxXNTYBPe+ritjIZnPgx6CaV9J1Ih5Rk0qNRpc/kOFIIxS7JucpzKraKJZWzwx4JY95bYd6F7CexVti4l330PZF4QxvGSEPJvpjmKpuM8vxzn4No4L8lN9Op5xs/xj9DZTv6r4d0f</diagram></mxfile> |
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,15 +1,56 @@ | ||
# CodeIgniter-session-unsign | ||
data:image/s3,"s3://crabby-images/ce590/ce590356bcf522501ee033874b7a8b9d3d790a28" alt="" | ||
|
||
## e | ||
<p align="center"> | ||
A multithreaded bruteforcer of CodeIgniter ci_session cookies. | ||
<br> | ||
<img alt="GitHub release (latest by date)" src="https://img.shields.io/github/v/release/p0dalirius/CodeIgniter-session-unsign"> | ||
<a href="https://twitter.com/intent/follow?screen_name=podalirius_" title="Follow"><img src="https://img.shields.io/twitter/follow/podalirius_?label=Podalirius&style=social"></a> | ||
<a href="https://www.youtube.com/c/Podalirius_?sub_confirmation=1" title="Subscribe"><img alt="YouTube Channel Subscribers" src="https://img.shields.io/youtube/channel/subscribers/UCF_x5O7CSfr82AfNVTKOv_A?style=social"></a> | ||
<br> | ||
</p> | ||
|
||
## Features | ||
|
||
- [x] Extract the `ci_session` cookie from an URL (with `--url`) or from a file (with `--cookie`) | ||
- [x] Progress updated every second with the number of processed hashes per second. | ||
- [x] Multithreaded bruteforce. | ||
|
||
## Usage | ||
|
||
``` | ||
$ ./CodeIgniter-session-unsign.py -h | ||
CodeIgniter-session-unsign v1.1 - by @podalirius_ | ||
usage: CodeIgniter-session-unsign.py [-h] [-u URL | -c COOKIE] -w WORDLIST [-t THREADS] [-k] [--md5 MD5 | --sha1 SHA1 | --sha256 SHA256] | ||
Description message | ||
optional arguments: | ||
-h, --help show this help message and exit | ||
-u URL, --url URL URL of the CodeIgniter website. | ||
-c COOKIE, --cookie COOKIE | ||
CodeIgniter session cookie. | ||
-w WORDLIST, --wordlist WORDLIST | ||
Wordlist of keys to test. | ||
-t THREADS, --threads THREADS | ||
Number of threads (default: 8) | ||
-k, --insecure Allow insecure server connections when using SSL (default: False) | ||
--md5 MD5 Use MD5 algorithm. | ||
--sha1 SHA1 Use SHA1 algorithm. | ||
--sha256 SHA256 Use SHA256 algorithm. | ||
``` | ||
|
||
## Example | ||
|
||
```angular2html | ||
./CodeIgniter-session-unsign.py --cookie $(cat ./example/cookie) -k -w pass | ||
``` | ||
./CodeIgniter-session-unsign.py -c ./example/cookie -w ./example/wordlist | ||
``` | ||
|
||
data:image/s3,"s3://crabby-images/60763/60763f8197007b18c301608a141ec05a67a75146" alt="" | ||
|
||
## Contributing | ||
|
||
Pull requests are welcome. Feel free to open an issue if you want to add other features. | ||
|
||
## References | ||
- https://www.websec.ca/publication/blog/insecure-session-data-CodeIgniter |
Oops, something went wrong.