Ekultek / Zeus-Scanner

Advanced reconnaissance utility
952 stars 246 forks source link

ValueError: No JSON object could be decoded (pMeKdiQ) #163

Closed ZeusIssueReporter closed 6 years ago

ZeusIssueReporter commented 6 years ago

Zeus version: 1.2.29

Firefox version: (57, 0)

Geckodriver version: geckodriver-v0.19.0-linux64.tar.gzgeckodriver-v0.19.0-linux64.tar.gz

Error info:

  File "/mnt/g/sql/zeus-scanner/lib/attacks/sqlmap_scan/__init__.py", line 222, in sqlmap_scan_main
    sqlmap_scan.show_sqlmap_log(api_id)
  File "/mnt/g/sql/zeus-scanner/lib/attacks/sqlmap_scan/__init__.py", line 126, in show_sqlmap_log
    log_json = json.loads(log_req.content)
  File "/usr/lib/python2.7/json/__init__.py", line 339, in loads
    return _default_decoder.decode(s)
  File "/usr/lib/python2.7/json/decoder.py", line 364, in decode
    obj, end = self.raw_decode(s, idx=_w(s, 0).end())
  File "/usr/lib/python2.7/json/decoder.py", line 382, in raw_decode
    raise ValueError("No JSON object could be decoded")
ValueError: No JSON object could be decoded

Running details: Linux-4.4.0-43-Microsoft-x86_64-with-Ubuntu-16.04-xenial

Commands used: zeus.py -d inurl:php?= inurl:https:// intext:order now intext:bra intext:select size --random-agent -s --exclude-none --auto

Log file info:

2017-11-24 17:34:51,866;zeus-log;INFO;using default search engine...
2017-11-24 17:34:51,867;zeus-log;INFO;starting dork scan with query 'inurl:php?= inurl:https://  intext:order now intext:bra intext:select size'...
2017-11-24 17:34:51,868;zeus-log;WARNING;will not parse webcache URL's (to parse webcache pass -W)...
2017-11-24 17:34:51,868;zeus-log;INFO;attempting to gather query URL...
2017-11-24 17:34:52,076;zeus-log;INFO;firefox browser display will be hidden while it performs the query...
2017-11-24 17:34:52,077;zeus-log;WARNING;your web browser will be automated in order for Zeus to successfully bypass captchas and API calls. this is done in order to grab the URL from the search and parse the results. please give selenium time to finish it's task...
2017-11-24 17:34:55,098;zeus-log;INFO;browser will open shortly...
2017-11-24 17:34:57,360;zeus-log;INFO;searching search engine using query 'http://google.com'...
2017-11-24 17:35:00,505;zeus-log;INFO;closing the browser and continuing process..
2017-11-24 17:35:00,650;zeus-log;INFO;URL successfully gathered, searching for GET parameters...
2017-11-24 17:35:00,651;zeus-log;INFO;no proxy configuration detected...
2017-11-24 17:35:01,945;zeus-log;INFO;adjusting user-agent header to Opera/9.10 (Windows NT 5.1; U; fi)...
2017-11-24 17:35:01,955;zeus-log;INFO;successfully wrote found items to '/mnt/g/sql/zeus-scanner/log/url-log/url-log-13.log'...
2017-11-24 17:35:01,956;zeus-log;INFO;found a total of 24 URLs with given query 'inurl:php?= inurl:https://  intext:order now intext:bra intext:select size'...
2017-11-24 17:35:01,959;zeus-log;WARNING;ran into unexpected webcache URL skipping...
2017-11-24 17:35:01,959;zeus-log;WARNING;ran into unexpected webcache URL skipping...
2017-11-24 17:35:01,960;zeus-log;INFO;currently running on 'https://++intext:order+now+intext:bra+intext:select+size' (target #3)...
2017-11-24 17:35:01,960;zeus-log;INFO;checking URL headers...
2017-11-24 17:35:01,961;zeus-log;INFO;checking if target URL is protected by some kind of WAF/IPS/IDS...
2017-11-24 17:35:01,962;zeus-log;WARNING;detection request timed out, assuming no protection and continuing...
2017-11-24 17:35:01,964;zeus-log;INFO;no WAF/IDS/IPS has been identified on target URL...
2017-11-24 17:35:01,970;zeus-log;INFO;attempting to get request headers for 'https://++intext:order+now+intext:bra+intext:select+size'...
2017-11-24 17:35:01,971;zeus-log;ERROR;unable to retrieve headers for site 'https://++intext:order+now+intext:bra+intext:select+size'...
2017-11-24 17:35:04,880;zeus-log;WARNING;skipping 'https://++intext:order+now+intext:bra+intext:select+size'...
2017-11-24 17:35:04,882;zeus-log;INFO;currently running on 'https://www.mandmdirect.com/01/clearance' (target #4)...
2017-11-24 17:35:04,882;zeus-log;INFO;checking URL headers...
2017-11-24 17:35:04,883;zeus-log;INFO;checking if target URL is protected by some kind of WAF/IPS/IDS...
2017-11-24 17:35:06,213;zeus-log;WARNING;detection request timed out, assuming no protection and continuing...
2017-11-24 17:35:06,213;zeus-log;INFO;no WAF/IDS/IPS has been identified on target URL...
2017-11-24 17:35:06,215;zeus-log;INFO;attempting to get request headers for 'https://www.mandmdirect.com/01/clearance'...
2017-11-24 17:35:16,859;zeus-log;ERROR;unable to retrieve headers for site 'https://www.mandmdirect.com/01/clearance'...
2017-11-24 17:35:20,184;zeus-log;WARNING;skipping 'https://www.mandmdirect.com/01/clearance'...
2017-11-24 17:35:20,184;zeus-log;WARNING;ran into unexpected webcache URL skipping...
2017-11-24 17:35:20,184;zeus-log;WARNING;ran into unexpected webcache URL skipping...
2017-11-24 17:35:20,184;zeus-log;WARNING;ran into unexpected webcache URL skipping...
2017-11-24 17:35:20,185;zeus-log;INFO;currently running on 'https://www.jabong.com/floret-Pack-Of-3-Multicoloured-Solid-Bra-1542004.html' (target #8)...
2017-11-24 17:35:20,186;zeus-log;INFO;checking URL headers...
2017-11-24 17:35:20,186;zeus-log;INFO;checking if target URL is protected by some kind of WAF/IPS/IDS...
2017-11-24 17:35:22,578;zeus-log;WARNING;detection request timed out, assuming no protection and continuing...
2017-11-24 17:35:22,579;zeus-log;INFO;no WAF/IDS/IPS has been identified on target URL...
2017-11-24 17:35:22,581;zeus-log;INFO;attempting to get request headers for 'https://www.jabong.com/floret-Pack-Of-3-Multicoloured-Solid-Bra-1542004.html'...
2017-11-24 17:35:27,006;zeus-log;INFO;found a request cookie, saving to file...
2017-11-24 17:35:27,017;zeus-log;INFO;successfully wrote found items to '/mnt/g/sql/zeus-scanner/log/cookies/www.jabong.com(1).log'...
2017-11-24 17:35:27,018;zeus-log;WARNING;provided target has protection against clickjacking vulnerabilities...
2017-11-24 17:35:27,019;zeus-log;INFO;writing found headers to log file...
2017-11-24 17:35:27,023;zeus-log;INFO;successfully wrote found items to '/mnt/g/sql/zeus-scanner/log/header-log/www.jabong.com(1).json'...
2017-11-24 17:35:29,091;zeus-log;WARNING;skipping 'https://www.jabong.com/floret-Pack-Of-3-Multicoloured-Solid-Bra-1542004.html'...
2017-11-24 17:35:29,093;zeus-log;INFO;currently running on 'https://www.aldipresscentre.co.uk/+inurl:php?=+inurl:https://++intext:order+now+intext:bra+intext:select+size' (target #9)...
2017-11-24 17:35:29,095;zeus-log;INFO;checking URL headers...
2017-11-24 17:35:29,095;zeus-log;INFO;checking if target URL is protected by some kind of WAF/IPS/IDS...
2017-11-24 17:35:30,748;zeus-log;WARNING;detection request timed out, assuming no protection and continuing...
2017-11-24 17:35:30,748;zeus-log;INFO;no WAF/IDS/IPS has been identified on target URL...
2017-11-24 17:35:30,749;zeus-log;INFO;attempting to get request headers for 'https://www.aldipresscentre.co.uk/+inurl:php?=+inurl:https://++intext:order+now+intext:bra+intext:select+size'...
2017-11-24 17:35:32,832;zeus-log;INFO;found a request cookie, saving to file...
2017-11-24 17:35:32,835;zeus-log;INFO;successfully wrote found items to '/mnt/g/sql/zeus-scanner/log/cookies/www.aldipresscentre.co.uk(1).log'...
2017-11-24 17:35:32,836;zeus-log;WARNING;provided target has protection against multiple attacks...
2017-11-24 17:35:32,837;zeus-log;WARNING;provided target has protection against clickjacking vulnerabilities...
2017-11-24 17:35:32,838;zeus-log;WARNING;provided target has protection against MIME type attacks...
2017-11-24 17:35:32,838;zeus-log;WARNING;provided target has protection against XSS attacks...
2017-11-24 17:35:32,839;zeus-log;WARNING;provided target has protection against unencrypted connections (force HTTPS connection)...
2017-11-24 17:35:32,840;zeus-log;INFO;writing found headers to log file...
2017-11-24 17:35:32,844;zeus-log;INFO;successfully wrote found items to '/mnt/g/sql/zeus-scanner/log/header-log/www.aldipresscentre.co.uk(1).json'...
2017-11-24 17:35:36,526;zeus-log;WARNING;skipping 'https://www.aldipresscentre.co.uk/+inurl:php?=+inurl:https://++intext:order+now+intext:bra+intext:select+size'...
2017-11-24 17:35:36,529;zeus-log;WARNING;ran into unexpected webcache URL skipping...
2017-11-24 17:35:36,531;zeus-log;INFO;currently running on 'https://vk.com/away.php?to=http%3A%2F%2Fwww.victoriassecret.com%2Fbras%2Fbombshell&post=-43077649_12' (target #11)...
2017-11-24 17:35:36,532;zeus-log;INFO;checking URL headers...
2017-11-24 17:35:36,533;zeus-log;INFO;checking if target URL is protected by some kind of WAF/IPS/IDS...
2017-11-24 17:35:38,913;zeus-log;INFO;no WAF/IDS/IPS has been identified on target URL...
2017-11-24 17:35:38,915;zeus-log;INFO;attempting to get request headers for 'https://vk.com/away.php?to=http%3A%2F%2Fwww.victoriassecret.com%2Fbras%2Fbombshell&post=-43077649_12'...
2017-11-24 17:35:41,407;zeus-log;INFO;writing found headers to log file...
2017-11-24 17:35:41,412;zeus-log;INFO;successfully wrote found items to '/mnt/g/sql/zeus-scanner/log/header-log/vk.com(1).json'...
2017-11-24 17:35:44,918;zeus-log;WARNING;skipping 'https://vk.com/away.php?to=http%3A%2F%2Fwww.victoriassecret.com%2Fbras%2Fbombshell&post=-43077649_12'...
2017-11-24 17:35:44,920;zeus-log;INFO;currently running on 'https://hyper-db.de/monopedia/wiki/index.php?title=Talk:Bra_size' (target #12)...
2017-11-24 17:35:44,921;zeus-log;INFO;checking URL headers...
2017-11-24 17:35:44,921;zeus-log;INFO;checking if target URL is protected by some kind of WAF/IPS/IDS...
2017-11-24 17:35:46,558;zeus-log;INFO;no WAF/IDS/IPS has been identified on target URL...
2017-11-24 17:35:46,561;zeus-log;INFO;attempting to get request headers for 'https://hyper-db.de/monopedia/wiki/index.php?title=Talk:Bra_size'...
2017-11-24 17:35:48,283;zeus-log;INFO;writing found headers to log file...
2017-11-24 17:35:48,290;zeus-log;INFO;successfully wrote found items to '/mnt/g/sql/zeus-scanner/log/header-log/hyper(1).json'...
2017-11-24 17:35:52,885;zeus-log;INFO;creating arguments for sqlmap...
2017-11-24 17:35:52,890;zeus-log;INFO;attempting to launch sqlmap API...
2017-11-24 17:35:52,905;zeus-log;INFO;sqlmap API is up and running, continuing process...
2017-11-24 17:35:52,906;zeus-log;INFO;initializing new sqlmap scan with given URL 'https://hyper-db.de/monopedia/wiki/index.php?title=Talk:Bra_size'...
2017-11-24 17:35:52,913;zeus-log;INFO;gathering sqlmap API scan ID...
2017-11-24 17:35:52,922;zeus-log;INFO;starting sqlmap scan on url: 'https://hyper-db.de/monopedia/wiki/index.php?title=Talk:Bra_size'...
2017-11-24 17:35:52,922;zeus-log;WARNING;please keep in mind that this is the API, output will not be saved to log file, it may take a little longer to finish processing, launching sqlmap...
2017-11-24 17:35:54,871;zeus-log;ERROR;ran into error 'No JSON object could be decoded', seems something went wrong, error has been saved to current log file.
Traceback (most recent call last):
  File "/mnt/g/sql/zeus-scanner/lib/attacks/sqlmap_scan/__init__.py", line 222, in sqlmap_scan_main
    sqlmap_scan.show_sqlmap_log(api_id)
  File "/mnt/g/sql/zeus-scanner/lib/attacks/sqlmap_scan/__init__.py", line 126, in show_sqlmap_log
    log_json = json.loads(log_req.content)
  File "/usr/lib/python2.7/json/__init__.py", line 339, in loads
    return _default_decoder.decode(s)
  File "/usr/lib/python2.7/json/decoder.py", line 364, in decode
    obj, end = self.raw_decode(s, idx=_w(s, 0).end())
  File "/usr/lib/python2.7/json/decoder.py", line 382, in raw_decode
    raise ValueError("No JSON object could be decoded")
ValueError: No JSON object could be decoded

2017-11-24 17:36:05,042;zeus-log;INFO;Zeus got an unexpected error and will automatically create an issue for this error, please wait...
2017-11-24 17:36:05,043;zeus-log;INFO;getting authorization...
2017-11-24 17:36:05,046;zeus-log;INFO;extracting traceback from log file...
2017-11-24 17:36:05,047;zeus-log;INFO;attempting to get firefox browser version...
Ekultek commented 6 years ago

My guess here is that sqlmapapi is started, but for some reason it ends after it starts, or you have it running in the background

Ekultek commented 6 years ago

patched via https://github.com/Ekultek/Zeus-Scanner/commit/5757f311b2689ee2c1b56f8506ea2869ea74ec9d please update