sensepost / snoopy-ng

Snoopy v2.0 - modular digital terrestrial tracking framework
429 stars 128 forks source link

Wigle lookups exception #48

Open maximcherny opened 9 years ago

maximcherny commented 9 years ago

Periodically, I get:

Exception in thread wigle:
Traceback (most recent call last):
  File "/usr/lib/python2.7/", line 810, in __bootstrap_inner
  File "/opt/snoopy-ng/plugins/", line 112, in run
    if 'shun' in locations['error']:
TypeError: string indices must be integers

I suspect this happens when you eventually go over the daily query limit, but haven't been able to confirm. Have you seen this before?

maximcherny commented 9 years ago

Also, there is an occasional:

/usr/lib/python2.7/dist-packages/MySQLdb/ Warning: Out of range value for column 'last_update' at row 1
  r = r + self.execute(query, a)
maximcherny commented 9 years ago

In addition, it may be worthwhile considering switching to the JSON-based API (the one introduced with the site refresh circa November 2014) as the now legacy one has a somewhat unobtrusive "NOTE: this version of the site is slated for deactivation!" warning at the very top of the page.

I have got a working prototype if you are interested.

maximcherny commented 9 years ago

Going back to my original comment, the issue is caused by the fact that the string "error" can actually be a valid portion of the returned HTML. For example, looking up SSID "infinity":

<tr class="search">
    <td><a href="/gps/gps/Map/onlinemap2/?maplat=37.68862915&maplon=-97.32712555&mapzoom=17&ssid=infinity&netid=00:0a:95:f3:23:4f">Get Map</a></td>
    <td>0000-00-00 00:00:00</td>
    <td>2008-10-24 03:10:00</td>

Somewhat unexpected but still possible.

glennzw commented 9 years ago

Well found on that bug, there are a few SSIDs that mess things up (e.g. an SSID with the word "error" in it), as well as account shun.

Yes it'd be great to have a look at your new API.

maximcherny commented 9 years ago

Below is my code, but luckily someone already implemented a Python-based API client and made it available via the cheese shop - | I haven't played with it yet but it looks like it ticks all the boxes including the built-in pagination handling.

import datetime
import requests
import json

class InvalidCredentials(Exception):

class InvalidQueryParams(Exception):

class WigleApi():
    api_root       = ''
    login_endpoint = 'jsonLogin'
    user_endpoint  = 'jsonUser'
    query_endpoint = 'jsonSearch'
    query_args     = {'Query': 'Query'}
    user_agent     = 'Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)'
    timeout        = 5

    def __init__(self, username, password):
        self.username      = username
        self.password      = password
        self.user_info     = None
        self.last_params   = None
        self.last_result   = None
        self.session       = requests.Session()


    def init_session(self):
        r = + self.login_endpoint, data={
                              'credential_0': self.username,
                              'credential_1': self.password},
                              headers=self.get_headers(), timeout=self.timeout)
        data = json.loads(r.text)
        if data['success']:
            del data['success']
            self.user_info = data
            raise InvalidCredentials

    def get_headers(self):
        return {'User-Agent': self.user_agent}

    def get_user_info(self):
        return self.user_info

    def query(self, **kwargs):
        self.last_result = None

        params = {
            'addresscode': '',
            'statecode'  : '',
            'zipcode'    : '',
            'variance'   : 0.01,
            'latrange1'  : '',
            'latrange2'  : '',
            'longrange1' : '',
            'longrange2' : '',
            'lastupdt'   : '',
            'netid'      : '',
            'ssid'       : '',
            'freenet'    : False,
            'paynet'     : False,
            'onlymine'   : False,
            'Query'      : 'Query'

        if set(kwargs.keys()) - set(params.keys()):
            raise InvalidQueryParams


        for key in ['freenet', 'paynet', 'onlymine']:
            if not params[key]:
                del params[key]

        if isinstance(params['lastupdt'], datetime.datetime):
            params['lastupdt'] = params['lastupdt'].strftime('%Y%m%d%H%M%S')

        self.last_params = params

        r = + self.query_endpoint,
                              data=params, headers=self.get_headers(),

        return self.process_query_response(r)

    def has_next(self):
        return self.last_result and self.last_result['count'] == 100

    def get_next(self):
        if not self.has_next() or not self.last_params:
            return None

        params = self.last_params
        params['first'] = self.last_result['last'] + 1
        params['last'] = self.last_result['last'] + self.last_result['count']

        self.last_params = params

        r = self.session.get(url=self.api_root + self.query_endpoint,
                              data=params, headers=self.get_headers(),

        return self.process_query_response(r)

    def process_query_response(self, r):
        data = json.loads(r.text)

        if not ['success']:
            print data['message']
            return []

        self.last_result = {
            'count' : data['resultCount'],
            'first' : data['first'],
            'last'  : data['last']

        return data['results']