-
Notifications
You must be signed in to change notification settings - Fork 0
/
selenium_login.py
executable file
·161 lines (115 loc) · 4.8 KB
/
selenium_login.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
from selenium import webdriver
from selenium.webdriver.common.by import By
from selenium.webdriver.support.ui import WebDriverWait
from selenium.webdriver.support import expected_conditions as EC
from selenium.webdriver.common.keys import Keys
import time
import os
import subprocess
import yaml
import platform
import json
import argparse
def set_secret(name, value):
if name == "_csrf":
os.environ["CSRF"] = value
with open("secrets.yaml", "r") as secrets_yaml:
secrets = secrets_yaml.read()
secrets = secrets.replace("CSRF_VALUE", value)
with open("secrets.yaml", "w") as secrets_yaml:
secrets_yaml.write(secrets)
with open("cookies.txt", "r") as cookies:
secrets = cookies.read()
secrets = secrets.replace("CSRF", value)
with open("cookies.txt", "w") as cookies:
cookies.write(secrets)
elif name == "session":
os.environ["SESSION"] = value
with open("secrets.yaml", "r") as secrets_yaml:
secrets = secrets_yaml.read()
secrets = secrets.replace("SESSION_VALUE", value)
with open("secrets.yaml", "w") as secrets_yaml:
secrets_yaml.write(secrets)
with open("cookies.txt", "r") as cookies:
secrets = cookies.read()
secrets = secrets.replace("SESSION", value)
with open("cookies.txt", "w") as cookies:
cookies.write(secrets)
def run_gospider():
with open("secrets.yaml", "r") as secrets_yaml:
yaml_secrets = yaml.safe_load(secrets_yaml)
cookies_list = yaml_secrets["static"][0]["cookies"]
for cookie in cookies_list:
if cookie["key"] == "session":
session = cookie["value"]
elif cookie["key"] == "_csrf":
csrf = cookie["value"]
gospider = subprocess.run(f"gospider --site https://pp-services.signin.education.gov.uk --cookie 'session={session}; _csrf={csrf}' --blacklist '(\.(js|png|ico|css|1)|session\/end|signout)' --output ./ -vv --debug --json -d 4", shell=True)
def get_spider_urls():
with open("pp-services_signin_education_gov_uk", "r") as urls_file:
urls = urls_file.readlines()
urls_list = []
for url in urls:
url_json = json.loads(url)
match url_json["type"]:
case "subdomain":
if url_json["output"].endswith("signin.education.gov.uk"):
urls_list.append(f"https://{url_json['output']}")
case "url":
urls_list.append(url_json["output"])
case "form":
if url_json["output"].endswith(".ico"):
continue
elif url_json["output"].endswith(".png"):
continue
elif "css" in url_json["output"]:
continue
elif "signin.education.gov.uk" not in url_json["output"]:
continue
else:
urls_list.append(url_json['output'])
case "javascript":
continue
with open("urls.txt", "w") as output_urls:
for url in list(set(urls_list)):
output_urls.write(f"{url}\n")
def run_nuclei():
nuclei = subprocess.run("nuclei -l urls.txt -sf secrets.yaml -json-export nuclei_output.json", shell=True)
def dfe_login():
options = webdriver.FirefoxOptions()
options.add_argument("-headless")
driver = webdriver.Firefox(options=options)
driver.get("https://pp-services.signin.education.gov.uk/")
WebDriverWait(driver, 1000).until(EC.element_to_be_clickable((By.LINK_TEXT, "Start now"))).click()
username = os.getenv("USER")
password = os.getenv("PASSWORD")
username_box = driver.find_element(By.ID, "username")
username_box.send_keys(username)
password_box = driver.find_element(By.ID, "password")
password_box.send_keys(password)
password_box.send_keys(Keys.ENTER)
time.sleep(3)
print(driver.title)
if driver.title == "Access DfE services":
for cookie in driver.get_cookies():
# print(f"Cookie Name: {cookie['name']}\nCookie Value: {cookie['value']}")
set_secret(cookie['name'], cookie['value'])
driver.quit()
# Run the spider and nuclei from python if local - do in actions steps in github
if platform.system() == "Darwin":
run_gospider()
get_spider_urls()
run_nuclei()
else:
driver.quit()
if __name__ == '__main__':
parser = argparse.ArgumentParser()
parser.add_argument("command", help="Can be dfe-login, spider, or nuclei")
args = parser.parse_args()
if args.command == "dfe-login":
dfe_login()
elif args.command == "spider":
run_gospider()
get_spider_urls()
elif args.command == "nuclei":
run_nuclei()