1aN0rmus/TekDefense

Handled defanged URLs, hostnames & IPs for tekcollect.py

Opened this issue · 0 comments

Handle "defanged" URLs, hostnames & IPs for tekcollect.py by "re-fanging" them before trying to match.

Some observed examples:
meow://www.bad.com
h[tt]p://www.bad.com
hxxp://www.bad.com
http://www[.]bad[.]com
http://www.bad[.]com
meows://www.bad.com
h[tt]ps://www.bad.com
hxxps://www.bad.com
https://www[.]bad[.]com
https://www.bad[.]com
bad[.]com
bad[dot]com
really.bad[.]com
reall.bad[dot]com