Shell-style script to search exploit-db.com exploits.
There is already a similar script shipped with the Kali distribution, but I think it's not flexible enough. This script is an attempt at providing a more flexible tool, with a fancy shell-style interface.
updatedb
commandplatform
, type
and port
fields)Just run the exploitdb.py
script without any argument, you will be given a pseudo-shell interface.
If running for the first time, the script will automatically download the latest exploits archive at startup.
The search
command allows you to search for a given pattern in any field of the original exploit-db's
CSV file. The search query must be in the form of field_name:pattern
couples, if no field name is
given, description
is the default.
Available fields are:
id
- the internal exploit's IDfile
- the path where the exploit file can be founddescription
- informations about exploit and targetted softwaredate
- the date the exploit was releasedauthor
- well, self-explanatory, huh?platform
- the platform type the exploit runs ontype
- exploit classification, possible values are:
local
shellcode
dos
remote
webapps
If the pattern you want to search contains spaces, you can quote it using either single or double quotes (see screenshot below).
To show all the available details about an exploit, use the info
command. This command takes a
single argument, which is the ID of the exploit you want details for.
Running the updatedb
command will download the latest exploits archive from exploit-db.com and
extract it in an exploits
folder in current directory.
This script is under the FreeBSD (2-clause BSD) License.