Wrench

Analyse passive d’un site web : robots.txt, métadonnées, IP / DNS, commentaires HTML et outils OSINT externes.

  1. // ==UserScript==
  2. // @name Wrench
  3. // @namespace http://tampermonkey.net/
  4. // @version 2.9.1
  5. // @description Analyse passive d’un site web : robots.txt, métadonnées, IP / DNS, commentaires HTML et outils OSINT externes.
  6. // @author Th3rd
  7. // @match *://*/*
  8. // @grant GM_xmlhttpRequest
  9. // @connect ipwhois.app
  10. // @connect dns.google
  11. // @connect www.google.com
  12. // @connect urlscan.io
  13. // @connect shodan.io
  14. // @connect hunter.io
  15. // @connect who.is
  16. // @connect web.archive.org
  17. // @grant unsafeWindow
  18. // @connect *
  19. // @run-at document-end
  20. // @license GPL-3.0
  21. // @icon https://github.com/Th3rdMan/wrench-userscript/blob/main/wrench.png?raw=true
  22. // @namespace https://github.com/Th3rdMan/wrench-userscript
  23. // ==/UserScript==
  24.  
  25. (function () {
  26. 'use strict';
  27. if (window.top !== window) return;
  28.  
  29. const ICON_WRENCH = '';
  30. const ICON_CLOSE = '';
  31. const baseUrl = location.origin;
  32. const robotsUrl = `${baseUrl}/robots.txt`;
  33. // flagcdn bloqué par CSP
  34. const FLAG_EMOJIS = {
  35. "AD": "🇦🇩", "AE": "🇦🇪", "AF": "🇦🇫", "AG": "🇦🇬", "AI": "🇦🇮", "AL": "🇦🇱", "AM": "🇦🇲", "AO": "🇦🇴",
  36. "AR": "🇦🇷", "AS": "🇦🇸", "AT": "🇦🇹", "AU": "🇦🇺", "AW": "🇦🇼", "AX": "🇦🇽", "AZ": "🇦🇿", "BA": "🇧🇦",
  37. "BB": "🇧🇧", "BD": "🇧🇩", "BE": "🇧🇪", "BF": "🇧🇫", "BG": "🇧🇬", "BH": "🇧🇭", "BI": "🇧🇮", "BJ": "🇧🇯",
  38. "BL": "🇧🇱", "BM": "🇧🇲", "BN": "🇧🇳", "BO": "🇧🇴", "BQ": "🇧🇶", "BR": "🇧🇷", "BS": "🇧🇸", "BT": "🇧🇹",
  39. "BV": "🇧🇻", "BW": "🇧🇼", "BY": "🇧🇾", "BZ": "🇧🇿", "CA": "🇨🇦", "CC": "🇨🇨", "CD": "🇨🇩", "CF": "🇨🇫",
  40. "CG": "🇨🇬", "CH": "🇨🇭", "CI": "🇨🇮", "CK": "🇨🇰", "CL": "🇨🇱", "CM": "🇨🇲", "CN": "🇨🇳", "CO": "🇨🇴",
  41. "CR": "🇨🇷", "CU": "🇨🇺", "CV": "🇨🇻", "CW": "🇨🇼", "CX": "🇨🇽", "CY": "🇨🇾", "CZ": "🇨🇿", "DE": "🇩🇪",
  42. "DJ": "🇩🇯", "DK": "🇩🇰", "DM": "🇩🇲", "DO": "🇩🇴", "DZ": "🇩🇿", "EC": "🇪🇨", "EE": "🇪🇪", "EG": "🇪🇬",
  43. "EH": "🇪🇭", "ER": "🇪🇷", "ES": "🇪🇸", "ET": "🇪🇹", "FI": "🇫🇮", "FJ": "🇫🇯", "FM": "🇫🇲", "FO": "🇫🇴",
  44. "FR": "🇫🇷", "GA": "🇬🇦", "GB": "🇬🇧", "GD": "🇬🇩", "GE": "🇬🇪", "GF": "🇬🇫", "GG": "🇬🇬", "GH": "🇬🇭",
  45. "GI": "🇬🇮", "GL": "🇬🇱", "GM": "🇬🇲", "GN": "🇬🇳", "GP": "🇬🇵", "GQ": "🇬🇶", "GR": "🇬🇷", "GT": "🇬🇹",
  46. "GU": "🇬🇺", "GW": "🇬🇼", "GY": "🇬🇾", "HK": "🇭🇰", "HM": "🇭🇲", "HN": "🇭🇳", "HR": "🇭🇷", "HT": "🇭🇹",
  47. "HU": "🇭🇺", "ID": "🇮🇩", "IE": "🇮🇪", "IL": "🇮🇱", "IM": "🇮🇲", "IN": "🇮🇳", "IO": "🇮🇴", "IQ": "🇮🇶",
  48. "IR": "🇮🇷", "IS": "🇮🇸", "IT": "🇮🇹", "JE": "🇯🇪", "JM": "🇯🇲", "JO": "🇯🇴", "JP": "🇯🇵", "KE": "🇰🇪",
  49. "KG": "🇰🇬", "KH": "🇰🇭", "KI": "🇰🇮", "KM": "🇰🇲", "KN": "🇰🇳", "KP": "🇰🇵", "KR": "🇰🇷", "KW": "🇰🇼",
  50. "KY": "🇰🇾", "KZ": "🇰🇿", "LA": "🇱🇦", "LB": "🇱🇧", "LC": "🇱🇨", "LI": "🇱🇮", "LK": "🇱🇰", "LR": "🇱🇷",
  51. "LS": "🇱🇸", "LT": "🇱🇹", "LU": "🇱🇺", "LV": "🇱🇻", "LY": "🇱🇾", "MA": "🇲🇦", "MC": "🇲🇨", "MD": "🇲🇩",
  52. "ME": "🇲🇪", "MF": "🇲🇫", "MG": "🇲🇬", "MH": "🇲🇭", "MK": "🇲🇰", "ML": "🇲🇱", "MM": "🇲🇲", "MN": "🇲🇳",
  53. "MO": "🇲🇴", "MP": "🇲🇵", "MQ": "🇲🇶", "MR": "🇲🇷", "MS": "🇲🇸", "MT": "🇲🇹", "MU": "🇲🇺", "MV": "🇲🇻",
  54. "MW": "🇲🇼", "MX": "🇲🇽", "MY": "🇲🇾", "MZ": "🇲🇿", "NA": "🇳🇦", "NC": "🇳🇨", "NE": "🇳🇪", "NF": "🇳🇫",
  55. "NG": "🇳🇬", "NI": "🇳🇮", "NL": "🇳🇱", "NO": "🇳🇴", "NP": "🇳🇵", "NR": "🇳🇷", "NU": "🇳🇺", "NZ": "🇳🇿",
  56. "OM": "🇴🇲", "PA": "🇵🇦", "PE": "🇵🇪", "PF": "🇵🇫", "PG": "🇵🇬", "PH": "🇵🇭", "PK": "🇵🇰", "PL": "🇵🇱",
  57. "PM": "🇵🇲", "PN": "🇵🇳", "PR": "🇵🇷", "PT": "🇵🇹", "PW": "🇵🇼", "PY": "🇵🇾", "QA": "🇶🇦", "RE": "🇷🇪",
  58. "RO": "🇷🇴", "RS": "🇷🇸", "RU": "🇷🇺", "RW": "🇷🇼", "SA": "🇸🇦", "SB": "🇸🇧", "SC": "🇸🇨", "SD": "🇸🇩",
  59. "SE": "🇸🇪", "SG": "🇸🇬", "SH": "🇸🇭", "SI": "🇸🇮", "SJ": "🇸🇯", "SK": "🇸🇰", "SL": "🇸🇱", "SM": "🇸🇲",
  60. "SN": "🇸🇳", "SO": "🇸🇴", "SR": "🇸🇷", "SS": "🇸🇸", "ST": "🇸🇹", "SV": "🇸🇻", "SX": "🇸🇽", "SY": "🇸🇾",
  61. "SZ": "🇸🇿", "TC": "🇹🇨", "TD": "🇹🇩", "TF": "🇹🇫", "TG": "🇹🇬", "TH": "🇹🇭", "TJ": "🇹🇯", "TK": "🇹🇰",
  62. "TL": "🇹🇱", "TM": "🇹🇲", "TN": "🇹🇳", "TO": "🇹🇴", "TR": "🇹🇷", "TT": "🇹🇹", "TV": "🇹🇻", "TZ": "🇹🇿",
  63. "UA": "🇺🇦", "UG": "🇺🇬", "UM": "🇺🇲", "US": "🇺🇸", "UY": "🇺🇾", "UZ": "🇺🇿", "VA": "🇻🇦", "VC": "🇻🇨",
  64. "VE": "🇻🇪", "VG": "🇻🇬", "VI": "🇻🇮", "VN": "🇻🇳", "VU": "🇻🇺", "WF": "🇼🇫", "WS": "🇼🇸", "YE": "🇾🇪",
  65. "YT": "🇾🇹", "ZA": "🇿🇦", "ZM": "🇿🇲", "ZW": "🇿🇼"
  66. };
  67. function getFlagEmoji(countryCode) {
  68. return FLAG_EMOJIS[countryCode?.toUpperCase()] || '';
  69. }
  70.  
  71. let bannerVisible = false;
  72.  
  73. const toggleIcon = document.createElement('img');
  74. toggleIcon.src = ICON_WRENCH;
  75. toggleIcon.style.cssText = 'position:fixed;top:60px;right:10px;width:36px;height:36px;cursor:pointer;z-index:100000;border-radius:50%;box-shadow:0 2px 6px rgba(0,0,0,0.4);transition:transform 0.2s;';
  76. toggleIcon.addEventListener('mouseenter', () => { toggleIcon.style.transform = 'scale(1.1)'; });
  77. toggleIcon.addEventListener('mouseleave', () => { toggleIcon.style.transform = 'scale(1)'; });
  78. toggleIcon.addEventListener('click', toggleBanner);
  79. document.body.appendChild(toggleIcon);
  80.  
  81. const banner = document.createElement('div');
  82. banner.id = 'osinter-banner';
  83. banner.style.cssText = 'display:none;position:fixed;top:0;left:0;width:100%;max-height:300px;overflow:auto;background:#111;color:#0f0;font-family:monospace;font-size:13px;white-space:pre-wrap;padding:10px 16px;z-index:99999;border-bottom:2px solid #444;box-shadow:0 2px 4px rgba(0,0,0,0.3);';
  84. document.body.prepend(banner);
  85.  
  86. const menu = document.createElement('div');
  87. menu.style.cssText = 'display:flex;flex-wrap:wrap;gap:8px;margin-bottom:8px;';
  88. banner.appendChild(menu);
  89.  
  90. const content = document.createElement('div');
  91. banner.appendChild(content);
  92.  
  93. function addButton(label, action) {
  94. const btn = document.createElement('button');
  95. btn.textContent = label;
  96. btn.style.cssText = 'background:#222;color:#0f0;border:1px solid #444;padding:4px 8px;cursor:pointer;font-family:monospace;';
  97. btn.addEventListener('click', action);
  98. menu.appendChild(btn);
  99. }
  100.  
  101. function toggleBanner() {
  102. bannerVisible = !bannerVisible;
  103. banner.style.display = bannerVisible ? 'block' : 'none';
  104. toggleIcon.src = bannerVisible ? ICON_CLOSE : ICON_WRENCH;
  105. }
  106.  
  107. function loadRobotsTxt() {
  108. content.innerHTML = 'Chargement robots.txt...';
  109. GM_xmlhttpRequest({
  110. method: 'GET',
  111. url: robotsUrl,
  112. onload: res => {
  113. if (res.status === 404) {
  114. content.innerHTML = "Aucun fichier robots.txt trouvé (404).";
  115. return;
  116. }
  117. if (res.status >= 400) {
  118. content.innerHTML = `Erreur lors du chargement du robots.txt (HTTP ${res.status})`;
  119. return;
  120. }
  121. const lines = res.responseText.trim().split('\n');
  122. const sitemaps = [], others = [];
  123. for (let line of lines) {
  124. if (/^Sitemap:/i.test(line)) {
  125. const url = line.replace(/^Sitemap:\s*/i, '').trim();
  126. sitemaps.push(`<strong><u>Sitemap:</u></strong> <a href='${url}' target='_blank' style='color:#6cf'>${url}</a>`);
  127. } else if (/^User-agent:/i.test(line)) others.push(`<span style='color:#ff0;'>${line}</span>`);
  128. else if (/^Disallow:/i.test(line)) others.push(`<span style='color:#f55;'>${line}</span>`);
  129. else if (/^Allow:/i.test(line)) others.push(`<span style='color:#5f5;'>${line}</span>`);
  130. else others.push(line);
  131. }
  132. content.innerHTML = [...sitemaps, ...others].join('\n');
  133. },
  134. onerror: () => { content.innerHTML = 'Erreur lors du chargement.'; }
  135. });
  136. }
  137.  
  138. function loadMeta() {
  139. const meta = document.getElementsByTagName('meta');
  140. let info = `<strong>Titre</strong> : ${document.title}`;
  141. for (let m of meta) {
  142. if (m.name === 'description') info += `<br><strong>Description</strong> : ${m.content}`;
  143. if (m.name === 'author') info += `<br><strong>Auteur</strong> : ${m.content}`;
  144. }
  145. const c = document.querySelector("link[rel='canonical']");
  146. if (c) info += `<br><strong>Canonical</strong> : ${c.href}`;
  147. content.innerHTML = info;
  148. }
  149.  
  150. function loadIPDNS() {
  151. const d = location.hostname;
  152. content.innerHTML = 'Résolution DNS...';
  153. GM_xmlhttpRequest({
  154. method: 'GET',
  155. url: `https://dns.google/resolve?name=${d}&type=A`,
  156. onload: res => {
  157. const data = JSON.parse(res.responseText);
  158. if (!data.Answer) {
  159. content.innerHTML = 'Aucune IP trouvée.';
  160. return;
  161. }
  162. const aRecords = data.Answer.filter(a => a.type === 1);
  163. if (aRecords.length === 0) {
  164. content.innerHTML = 'Aucune IP trouvée.';
  165. return;
  166. }
  167. content.innerHTML = 'Chargement des infos IP...';
  168. Promise.all(
  169. aRecords.map(a => new Promise(resolve => {
  170. const ip = a.data;
  171. GM_xmlhttpRequest({
  172. method: 'GET',
  173. url: `https://ipwhois.app/json/${ip}`,
  174. onload: r => {
  175. const g = JSON.parse(r.responseText);
  176. const f = getFlagEmoji(g.country_code);
  177. resolve(`IP : ${ip}<br>Pays : ${g.country} ${f} (${g.country_code})<br>ASN : ${g.org}`);
  178. },
  179. onerror: () => resolve(`IP : ${ip}<br>Localisation indisponible.`)
  180. });
  181. }))
  182. ).then(results => {
  183. content.innerHTML = results.join('<br><br>');
  184. });
  185. },
  186. onerror: function() { content.innerHTML = 'Erreur DNS.'; }
  187. });
  188. }
  189.  
  190. function showTools() {
  191. const d = location.hostname;
  192. const tools = [
  193. { name: 'URLScan', url: `https://urlscan.io/domain/${d}` },
  194. { name: 'Shodan', url: `https://www.shodan.io/search?query=hostname:${d}` },
  195. { name: 'Hunter.io', url: `https://hunter.io/search/${d}` },
  196. { name: 'WHOIS', url: `https://who.is/whois/${d}` },
  197. { name: 'Wayback Machine', url: `https://web.archive.org/web/*/${d}` }
  198. ];
  199.  
  200. const emojiMap = {
  201. "URLScan": "🔎",
  202. "Shodan": "🛰️",
  203. "Hunter.io": "🦊",
  204. "WHOIS": "🕵️",
  205. "Wayback Machine": "⏳"
  206. };
  207.  
  208. content.innerHTML = tools.map(t =>
  209. `${emojiMap[t.name] || '🔗'} <a href="${t.url}" target="_blank" style="color:#6cf;text-decoration:none;">${t.name}</a>`
  210. ).join('<br>');
  211. }
  212.  
  213. function escapeHTML(str) {
  214. return str.replace(/[&<>'"]/g, c => ({ '&':'&amp;', '<':'&lt;', '>':'&gt;', "'":'&#39;', '"':'&quot;' }[c]));
  215. }
  216.  
  217. function extractCommentsFromDOM(node, arr = []) {
  218. for (let child of node.childNodes) {
  219. if (child.nodeType === Node.COMMENT_NODE) arr.push(child.nodeValue.trim());
  220. else extractCommentsFromDOM(child, arr);
  221. }
  222. return arr;
  223. }
  224.  
  225. function showComments() {
  226. content.innerHTML = 'Chargement et analyse du code source...';
  227. GM_xmlhttpRequest({
  228. method: 'GET',
  229. url: document.location.href,
  230. onload: res => {
  231. const matches = [...res.responseText.matchAll(/<!--([\s\S]*?)-->/g)];
  232. const uniqueComments = Array.from(new Set(
  233. matches.map(m => m[1].trim()).filter(Boolean)
  234. ));
  235. const emails = [...res.responseText.matchAll(/[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}/g)]
  236. .map(m => m[0]);
  237. const uniqueEmails = Array.from(new Set(emails));
  238.  
  239. let html = '';
  240. html += `<strong><u>Commentaires HTML trouvés :</u></strong><br>`;
  241. html += uniqueComments.length
  242. ? uniqueComments.map(c => `<pre style="white-space:pre-wrap;background:#222;color:#6cf;padding:4px;">&lt;!-- ${escapeHTML(c)} --&gt;</pre>`).join('')
  243. : "<i>Aucun commentaire HTML détecté dans le code source.</i>";
  244.  
  245. html += `<hr style="margin:10px 0;border:0;border-top:1px solid #333;">`;
  246. html += `<strong><u>Adresses e-mail détectées :</u></strong><br>`;
  247. html += uniqueEmails.length
  248. ? uniqueEmails.map(email => `<span style="color:#ffd700">${escapeHTML(email)}</span>`).join('<br>')
  249. : "<i>Aucune adresse e-mail détectée dans le code source.</i>";
  250.  
  251. content.innerHTML = html;
  252. },
  253. onerror: function() { content.innerHTML = 'Erreur lors du chargement du code source.'; }
  254. });
  255. }
  256.  
  257. [
  258. ['Robots.txt', loadRobotsTxt],
  259. ['Métadonnées', loadMeta],
  260. ['IP / DNS', loadIPDNS],
  261. ['Code Source', showComments],
  262. ['Outils externes', showTools]
  263. ].forEach(([label, action]) => addButton(label, action));
  264. })();