Skip to content

Instantly share code, notes, and snippets.

@angeloped
Last active May 26, 2020 12:12
Show Gist options
  • Save angeloped/1658252bf0db14c453eac7f0c7369cdd to your computer and use it in GitHub Desktop.
Save angeloped/1658252bf0db14c453eac7f0c7369cdd to your computer and use it in GitHub Desktop.
A simplified admin panel finder compatible in Python 3.
import re
import time
import urllib.request
import _thread
paths = ["/Login/Admin", "/UserLogin", "/acceso.asp", "/acceso.aspx", "/acceso.brf", "/acceso.cfm", "/acceso.cgi", "/acceso.js", "/acceso.php", "/access", "/access.asp", "/access.aspx", "/access.php", "/account.asp", "/account.aspx", "/account.brf", "/account.cfm", "/account.cgi", "/account.html", "/account.js", "/account.php", "/accounts", "/accounts.asp", "/accounts.aspx", "/accounts.php", "/adm", "/adm.asp", "/adm.aspx", "/adm.brf", "/adm.cfm", "/adm.cgi", "/adm.html", "/adm.js", "/adm.php", "/adm/admloginuser.asp", "/adm/admloginuser.aspx", "/adm/admloginuser.brf", "/adm/admloginuser.cfm", "/adm/admloginuser.cgi", "/adm/admloginuser.js", "/adm/admloginuser.php", "/adm/index.asp", "/adm/index.aspx", "/adm/index.brf", "/adm/index.cfm", "/adm/index.cgi", "/adm/index.html", "/adm/index.js", "/adm/index.php", "/adm_auth.asp", "/adm_auth.aspx", "/adm_auth.brf", "/adm_auth.cfm", "/adm_auth.cgi", "/adm_auth.js", "/adm_auth.php", "/admin", "/admin-login.asp", "/admin-login.aspx", "/admin-login.brf", "/admin-login.cfm", "/admin-login.cgi", "/admin-login.html", "/admin-login.js", "/admin-login.php", "/admin.asp", "/admin.aspx", "/admin.brf", "/admin.cfm", "/admin.cgi", "/admin.html", "/admin.js", "/admin.php", "/admin/account.asp", "/admin/account.aspx", "/admin/account.brf", "/admin/account.cfm", "/admin/account.cgi", "/admin/account.html", "/admin/account.js", "/admin/account.php", "/admin/admin-login.asp", "/admin/admin-login.aspx", "/admin/admin-login.brf", "/admin/admin-login.cfm", "/admin/admin-login.cgi", "/admin/admin-login.html", "/admin/admin-login.js", "/admin/admin-login.php", "/admin/admin.asp", "/admin/admin.aspx", "/admin/admin.brf", "/admin/admin.cfm", "/admin/admin.cgi", "/admin/admin.html", "/admin/admin.js", "/admin/admin.php", "/admin/adminLogin.asp", "/admin/adminLogin.aspx", "/admin/adminLogin.brf", "/admin/adminLogin.cfm", "/admin/adminLogin.cgi", "/admin/adminLogin.html", "/admin/adminLogin.js", "/admin/adminLogin.php", "/admin/admin_login.asp", "/admin/admin_login.aspx", "/admin/admin_login.brf", "/admin/admin_login.cfm", "/admin/admin_login.cgi", "/admin/admin_login.html", "/admin/admin_login.js", "/admin/admin_login.php", "/admin/controlpanel.asp", "/admin/controlpanel.aspx", "/admin/controlpanel.brf", "/admin/controlpanel.cfm", "/admin/controlpanel.cgi", "/admin/controlpanel.html", "/admin/controlpanel.js", "/admin/controlpanel.php", "/admin/cp.asp", "/admin/cp.aspx", "/admin/cp.brf", "/admin/cp.cfm", "/admin/cp.cgi", "/admin/cp.html", "/admin/cp.js", "/admin/cp.php", "/admin/home.asp", "/admin/home.aspx", "/admin/home.brf", "/admin/home.cfm", "/admin/home.cgi", "/admin/home.html", "/admin/home.js", "/admin/home.php", "/admin/index.asp", "/admin/index.aspx", "/admin/index.brf", "/admin/index.cfm", "/admin/index.cgi", "/admin/index.html", "/admin/index.js", "/admin/index.php", "/admin/login", "/admin/login.asp", "/admin/login.aspx", "/admin/login.brf", "/admin/login.cfm", "/admin/login.cgi", "/admin/login.html", "/admin/login.js", "/admin/login.php", "/admin2.asp", "/admin2.aspx", "/admin2.brf", "/admin2.cfm", "/admin2.cgi", "/admin2.js", "/admin2.php", "/admin2/index.asp", "/admin2/index.aspx", "/admin2/index.brf", "/admin2/index.cfm", "/admin2/index.cgi", "/admin2/index.js", "/admin2/index.php", "/admin2/login.asp", "/admin2/login.aspx", "/admin2/login.brf", "/admin2/login.cfm", "/admin2/login.cgi", "/admin2/login.js", "/admin2/login.php", "/adminLogin", "/adminLogin.asp", "/adminLogin.aspx", "/adminLogin.brf", "/adminLogin.cfm", "/adminLogin.cgi", "/adminLogin.html", "/adminLogin.js", "/adminLogin.php", "/admin_area", "/admin_area/admin.asp", "/admin_area/admin.aspx", "/admin_area/admin.brf", "/admin_area/admin.cfm", "/admin_area/admin.cgi", "/admin_area/admin.html", "/admin_area/admin.js", "/admin_area/admin.php", "/admin_area/index.asp", "/admin_area/index.aspx", "/admin_area/index.brf", "/admin_area/index.cfm", "/admin_area/index.cgi", "/admin_area/index.html", "/admin_area/index.js", "/admin_area/index.php", "/admin_area/login.asp", "/admin_area/login.aspx", "/admin_area/login.brf", "/admin_area/login.cfm", "/admin_area/login.cgi", "/admin_area/login.html", "/admin_area/login.js", "/admin_area/login.php", "/admin_login.asp", "/admin_login.aspx", "/admin_login.brf", "/admin_login.cfm", "/admin_login.cgi", "/admin_login.html", "/admin_login.js", "/admin_login.php", "/adminarea", "/adminarea/admin.asp", "/adminarea/admin.aspx", "/adminarea/admin.brf", "/adminarea/admin.cfm", "/adminarea/admin.cgi", "/adminarea/admin.html", "/adminarea/admin.js", "/adminarea/admin.php", "/adminarea/index.asp", "/adminarea/index.aspx", "/adminarea/index.brf", "/adminarea/index.cfm", "/adminarea/index.cgi", "/adminarea/index.html", "/adminarea/index.js", "/adminarea/index.php", "/adminarea/login.asp", "/adminarea/login.aspx", "/adminarea/login.brf", "/adminarea/login.cfm", "/adminarea/login.cgi", "/adminarea/login.html", "/adminarea/login.js", "/adminarea/login.php", "/admincontrol", "/admincontrol.asp", "/admincontrol.aspx", "/admincontrol.brf", "/admincontrol.cfm", "/admincontrol.cgi", "/admincontrol.html", "/admincontrol.js", "/admincontrol.php", "/admincontrol/login.asp", "/admincontrol/login.aspx", "/admincontrol/login.brf", "/admincontrol/login.cfm", "/admincontrol/login.cgi", "/admincontrol/login.html", "/admincontrol/login.js", "/admincontrol/login.php", "/admincp", "/admincp.asp", "/admincp.aspx", "/admincp.php", "/admincp/index.asp", "/admincp/index.html", "/admincp/login.asp", "/administration", "/administration.aspx", "/administration.php", "/administrator", "/administrator.asp", "/administrator.aspx", "/administrator.brf", "/administrator.cfm", "/administrator.cgi", "/administrator.html", "/administrator.js", "/administrator.php", "/administrator/account.asp", "/administrator/account.aspx", "/administrator/account.brf", "/administrator/account.cfm", "/administrator/account.cgi", "/administrator/account.html", "/administrator/account.js", "/administrator/account.php", "/administrator/index.asp", "/administrator/index.aspx", "/administrator/index.brf", "/administrator/index.cfm", "/administrator/index.cgi", "/administrator/index.html", "/administrator/index.js", "/administrator/index.php", "/administrator/login.asp", "/administrator/login.aspx", "/administrator/login.brf", "/administrator/login.cfm", "/administrator/login.cgi", "/administrator/login.html", "/administrator/login.js", "/administrator/login.php", "/administratorlogin", "/administratorlogin.asp", "/administratorlogin.aspx", "/administratorlogin.brf", "/administratorlogin.cfm", "/administratorlogin.cgi", "/administratorlogin.js", "/administratorlogin.php", "/administrators", "/administrators.asp", "/administrators.aspx", "/administrators.php", "/adminlogin.asp", "/adminlogin.aspx", "/adminlogin.php", "/adminpanel", "/adminpanel.asp", "/adminpanel.aspx", "/adminpanel.brf", "/adminpanel.cfm", "/adminpanel.cgi", "/adminpanel.html", "/adminpanel.js", "/adminpanel.php", "/admins", "/admins.asp", "/admins.aspx", "/admins.php", "/adminsite", "/admloginuser.asp", "/admloginuser.aspx", "/admloginuser.brf", "/admloginuser.cfm", "/admloginuser.cgi", "/admloginuser.js", "/admloginuser.php", "/affiliate.asp", "/affiliate.aspx", "/affiliate.brf", "/affiliate.cfm", "/affiliate.cgi", "/affiliate.js", "/affiliate.php", "/auth.php", "/bb-admin", "/bb-admin/admin.asp", "/bb-admin/admin.aspx", "/bb-admin/admin.brf", "/bb-admin/admin.cfm", "/bb-admin/admin.cgi", "/bb-admin/admin.html", "/bb-admin/admin.js", "/bb-admin/admin.php", "/bb-admin/index.asp", "/bb-admin/index.aspx", "/bb-admin/index.brf", "/bb-admin/index.cfm", "/bb-admin/index.cgi", "/bb-admin/index.html", "/bb-admin/index.js", "/bb-admin/index.php", "/bb-admin/login.asp", "/bb-admin/login.aspx", "/bb-admin/login.brf", "/bb-admin/login.cfm", "/bb-admin/login.cgi", "/bb-admin/login.html", "/bb-admin/login.js", "/bb-admin/login.php", "/cmsadmin", "/control", "/control.asp", "/control.aspx", "/control.php", "/controlpanel", "/controlpanel.asp", "/controlpanel.aspx", "/controlpanel.brf", "/controlpanel.cfm", "/controlpanel.cgi", "/controlpanel.html", "/controlpanel.js", "/controlpanel.php", "/cp", "/cp.asp", "/cp.aspx", "/cp.brf", "/cp.cfm", "/cp.cgi", "/cp.html", "/cp.js", "/cp.php", "/cpanel", "/cpanel.html", "/cpanel.php", "/home.asp", "/home.aspx", "/home.brf", "/home.cfm", "/home.cgi", "/home.html", "/home.js", "/home.php", "/instadmin", "/log-in", "/log-in.php", "/login", "/login.asp", "/login.aspx", "/login.brf", "/login.cfm", "/login.cgi", "/login.html", "/login.js", "/login.php", "/manage", "/manage.asp", "/manage.aspx", "/manage.php", "/management", "/management.asp", "/management.aspx", "/management.php", "/manager", "/manager.asp", "/manager.aspx", "/manager.php", "/member", "/member.asp", "/member.aspx", "/member.php", "/memberadmin", "/memberadmin.asp", "/memberadmin.aspx", "/memberadmin.brf", "/memberadmin.cfm", "/memberadmin.cgi", "/memberadmin.js", "/memberadmin.php", "/modelsearch/admin.asp", "/modelsearch/admin.aspx", "/modelsearch/admin.brf", "/modelsearch/admin.cfm", "/modelsearch/admin.cgi", "/modelsearch/admin.html", "/modelsearch/admin.js", "/modelsearch/admin.php", "/modelsearch/index.asp", "/modelsearch/index.aspx", "/modelsearch/index.brf", "/modelsearch/index.cfm", "/modelsearch/index.cgi", "/modelsearch/index.html", "/modelsearch/index.js", "/modelsearch/index.php", "/modelsearch/login.asp", "/modelsearch/login.aspx", "/modelsearch/login.brf", "/modelsearch/login.cfm", "/modelsearch/login.cgi", "/modelsearch/login.html", "/modelsearch/login.js", "/modelsearch/login.php", "/moderator", "/moderator.asp", "/moderator.aspx", "/moderator.brf", "/moderator.cfm", "/moderator.cgi", "/moderator.html", "/moderator.js", "/moderator.php", "/moderator/admin.asp", "/moderator/admin.aspx", "/moderator/admin.brf", "/moderator/admin.cfm", "/moderator/admin.cgi", "/moderator/admin.html", "/moderator/admin.js", "/moderator/admin.php", "/moderator/login.asp", "/moderator/login.aspx", "/moderator/login.brf", "/moderator/login.cfm", "/moderator/login.cgi", "/moderator/login.html", "/moderator/login.js", "/moderator/login.php", "/nsw/admin/login.aspx", "/nsw/admin/login.brf", "/nsw/admin/login.cfm", "/nsw/admin/login.cgi", "/nsw/admin/login.js", "/nsw/admin/login.php", "/pages/admin/admin-login.asp", "/pages/admin/admin-login.aspx", "/pages/admin/admin-login.brf", "/pages/admin/admin-login.cfm", "/pages/admin/admin-login.cgi", "/pages/admin/admin-login.html", "/pages/admin/admin-login.js", "/pages/admin/admin-login.php", "/panel", "/panel-administracion", "/panel-administracion/admin.asp", "/panel-administracion/admin.aspx", "/panel-administracion/admin.brf", "/panel-administracion/admin.cfm", "/panel-administracion/admin.cgi", "/panel-administracion/admin.html", "/panel-administracion/admin.js", "/panel-administracion/admin.php", "/panel-administracion/index.asp", "/panel-administracion/index.aspx", "/panel-administracion/index.brf", "/panel-administracion/index.cfm", "/panel-administracion/index.cgi", "/panel-administracion/index.html", "/panel-administracion/index.js", "/panel-administracion/index.php", "/panel-administracion/login.asp", "/panel-administracion/login.aspx", "/panel-administracion/login.brf", "/panel-administracion/login.cfm", "/panel-administracion/login.cgi", "/panel-administracion/login.html", "/panel-administracion/login.js", "/panel-administracion/login.php", "/panel.asp", "/panel.aspx", "/panel.php", "/rcjakar/admin/login.aspx", "/rcjakar/admin/login.brf", "/rcjakar/admin/login.cfm", "/rcjakar/admin/login.cgi", "/rcjakar/admin/login.js", "/rcjakar/admin/login.php", "/root", "/secret", "/secretsadmin_area/admin.html", "/secure", "/sign_in", "/sign_in.php", "/signin", "/signin.asp", "/signin.aspx", "/signin.php", "/siteadmin", "/siteadmin.asp", "/siteadmin.aspx", "/siteadmin.php", "/siteadmin/index.asp", "/siteadmin/index.aspx", "/siteadmin/index.brf", "/siteadmin/index.cfm", "/siteadmin/index.cgi", "/siteadmin/index.js", "/siteadmin/index.php", "/siteadmin/login.asp", "/siteadmin/login.aspx", "/siteadmin/login.brf", "/siteadmin/login.cfm", "/siteadmin/login.cgi", "/siteadmin/login.html", "/siteadmin/login.js", "/siteadmin/login.php", "/staff", "/supervisor", "/user.asp", "/user.aspx", "/user.brf", "/user.cfm", "/user.cgi", "/user.html", "/user.js", "/user.php", "/usuario", "/usuarios", "/usuarios/login.aspx", "/usuarios/login.brf", "/usuarios/login.cfm", "/usuarios/login.cgi", "/usuarios/login.js", "/usuarios/login.php", "/webadmin", "/webadmin.asp", "/webadmin.aspx", "/webadmin.brf", "/webadmin.cfm", "/webadmin.cgi", "/webadmin.html", "/webadmin.js", "/webadmin.php", "/webadmin/admin.asp", "/webadmin/admin.aspx", "/webadmin/admin.brf", "/webadmin/admin.cfm", "/webadmin/admin.cgi", "/webadmin/admin.html", "/webadmin/admin.js", "/webadmin/admin.php", "/webadmin/index.asp", "/webadmin/index.aspx", "/webadmin/index.brf", "/webadmin/index.cfm", "/webadmin/index.cgi", "/webadmin/index.html", "/webadmin/index.js", "/webadmin/index.php", "/webadmin/login.asp", "/webadmin/login.aspx", "/webadmin/login.brfbrf", "/webadmin/login.cfm", "/webadmin/login.cgi", "/webadmin/login.html", "/webadmin/login.js", "/webadmin/login.php", "/webmaster", "/webmaster.asp", "/webmaster.aspx", "/webmaster.php", "/wp-admin", "/wp-login", "/wp-login.aspx", "/wp-login.brf", "/wp-login.cfm", "/wp-login.cgi", "/wp-login.js", "/wp-login.php"]
def admin_stat(uri):
try:
openurl = urllib.request.urlopen(uri)
print("found: {0}".format(uri))
found.append(uri)
except:
print("none: {0}".format(uri))
def find_admin(url="", delay=.1):
found = []
try:
if re.match(r"[(http(s)?):\/\/(www\.)?a-zA-Z0-9@:%._\+~#=]{2,256}\.[a-z]{2,6}\b([-a-zA-Z0-9@:%_\+.~#?&//=]*)", url):
for path in paths:
uri = re.sub(r'[\W\d]*$', '', url) + path
_thread.start_new_thread(admin_stat,(uri,))
time.sleep(delay)
return found
else:
return "Er"
except:
return "Er"
print(find_admin("https://demo.opencart.com/"))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment