{"repo":"ice-wzl/DataReaper","free":true,"listed":false,"github":"https://github.com/ice-wzl/DataReaper","clone":"git clone https://github.com/ice-wzl/DataReaper.git","description":"DataReaper is a powerful Python tool designed to harvest data from publicly accessible HTTP servers. It combines the capabilities of Shodan search with web scraping techniques to efficiently gather information from targeted websites.","language":"Python","stars":15,"topics":["data-visualization","datascience","datascraping","osint","osint-python","osint-tool","python3","redteam","vulnerability"],"license":"MIT","category":"security-tools","readme_excerpt":"DataReaper (DARE) Disclaimer: DataReaper is intended for authorized security research and educational purposes only. Users are solely responsible for ensuring they have proper authorization before scanning any systems. Unauthorized access to computer systems is illegal. The authors assume no liability for misuse of this tool. DataReaper is a Python-based reconnaissance tool designed to discover and enumerate publicly accessible HTTP servers with directory listings exposed. It leverages the Shodan API to identify targets, performs automated directory traversal to catalog exposed files, downloads sensitive content, and can exploit discovered SSH keys to access remote hosts. Features - Shodan Integration : Query Shodan for HTTP servers with open directory listings and store results in a local SQLite database - Automated Enumeration : Recursively scan and catalog exposed directories and files - Sensitive File Detection : Built-in detection for security-relevant files including SSH keys, credentials, configuration files, and more - Automated File Download : Download files matching keyword lists from discovered targets - SSH Key Exploitation : Parse downloaded SSH keys and public key files to extract usernames, then attempt SSH access against targets - Bash History Parsing : Extract potential usernames from downloaded .bash history files for use during SSH exploitation - Shadow File Processing : Extract password hashes from downloaded /etc/shadow files and store them for offline cr","default_branch":null,"files":null,"tree":[],"storefront":"/r/ice-wzl","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ice-wzl/DataReaper/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}