Linux servers use the OpenSSL protocol, but some low versions of OpenSSL have vulnerabilities, such as the famous "Heartbleed" or "Poodle" vulnerabilities. Here, the Python paramiko library is used to write a small GUI program for Windows that can batch-detect whether the OpenSSL on Linux servers has these two vulnerabilities.

Scanner2.py file code (Python2.x):

# -*- coding:UTF-8 -*- '''OpenSSL Heartbleed and Freak vulnerability detection script DesignBy:XB 2016.07''' import paramiko import os from Tkinter import * server=[] sjl_sign="Server certificate\n" freak_sign="Server certificate\n" ip=raw_input("Please Input Plart IP:") username=raw_input("Username:") pwd=raw_input("Password:") def ReadServerlist(): print "The Plart:%s(Confirm Platform Always Online)"%ip if os.path.exists("serverlist.txt"): print "Find The Existing Serverlist." else: print "Didn't Find The Existing Serverlist,We Will Create It." create=open("serverlist.txt",'w') create.close() ReadServerlist() def scan(): read=file("serverlist.txt","r") for line in read.readlines(): server.append(line) for i in server: i=i.strip("\n") # Remove the newline at the end of the line cmd_sjl="openssl s_client -connect"+" "+i+":443 -cipher RC4" cmd_freak="openssl s_client -connect"+" "+i+":443 -cipher EXPORT" print "\nScanning %s..."%i scanbody(ip,username,pwd,cmd_sjl,cmd_freak) print "\nAll Done" print "@Colasoft2016" def scanbody(ip,username,pwd,cmd_sjl,cmd_freak): try: ssh=paramiko.SSHClient() ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy()) ssh.connect(ip,22,username,pwd) stdin,stdout,stderr=ssh.exec_command(cmd_sjl) sjl=stdout.readlines() stdin,stdout,stderr=ssh.exec_command(cmd_freak) freak=stdout.readlines() ssh.close() list_sjl=[] list_freak=[] for k in sjl: list_sjl.append(k) for j in freak: list_freak.append(j) if sjl_sign in list_sjl: if freak_sign in list_freak: print "Danger: The server has the OpenSSL Heartbleed vulnerability and the Freak vulnerability" else: print "Danger: The server has the OpenSSL Heartbleed vulnerability" else: if freak_sign in list_freak: print "Danger: The server has the OpenSSL Freak vulnerability" else: print "Congratulations: The server does not have the OpenSSL Heartbleed vulnerability or the Freak vulnerability" except paramiko.AuthenticationException,e: print 'Error' print 'Error Detail',e #GUI Program root=Tk() root.title("OpenSSL Heartbleed and Freak vulnerability detection program") root.geometry('380x380') # Set the window size, the middle is x root.resizable(width=False,height=False) # Set whether the window can resize; here width and height are fixed; notice1=Label(root,text="Please enter the server IPs to be scanned (one IP per line)",fg='red') notice1.pack(side=TOP) # Scrollbar scrollbar=Scrollbar(root) scrollbar.pack(side=RIGHT,fill=Y) scrollbar.set(1,5) # Get file contents content=file("serverlist.txt","r") readtext=content.read() content.close() # Write to file server_list=Text(root,width=35,height=22,yscrollcommand=scrollbar.set) server_list.place(x=5,y=80) server_list.insert(END,readtext) scrollbar.config(command=server_list.yview) # Save function def save(): save=server_list.get('0.0',END).strip() print "Save:" print save file_object=open("serverlist.txt","w") file_object.writelines(save) file_object.close() # Save and scan buttons save_button=Button(root,text="Save",width=9,height=2,command=save).place(x=260,y=80) scan_button=Button(root,text="Scan",width=9,height=2,command=scan).place(x=260,y=150) root.mainloop()

Contributor: Song Xiaobing

Nickname: Xiaobing

Email: ssbandjl@163.com