Files
s-b-repo-rustsploit/README.md
T
S.B f51d7c111b unifying more stuff and new docs
adding unify support for api and prompt usage and improving. also adding some preformance improvements new documentations and improvement
2026-03-24 16:17:10 +02:00

4.9 KiB

Rustsploit

Modular offensive tooling for embedded targets, written in Rust and inspired by RouterSploit/Metasploit. Rustsploit ships an interactive shell, a command-line runner, and an ever-growing library of exploits, scanners, and credential modules for routers, cameras, appliances, and general network services.

Screenshot Screenshot


📖 Wiki & Documentation

Full documentation lives in the Rustsploit Wiki. Below is a quick index — click through for detailed guides, examples, and reference material.

Document Description
Getting Started Installation, build, quick-start, Docker deployment
Interactive Shell Shell walkthrough, command palette, chaining, shortcuts
CLI Reference Command-line flags, non-shell usage, output formats
API Server REST API startup, endpoints, auth, rate limiting, hardening
API Usage Examples Practical curl workflows, request/response samples
Module Catalog All modules by category — exploits, scanners, creds
Module Development How to author new modules, lifecycle, dispatcher
Security & Validation Input validation, security patterns, honeypot detection
Credential Modules Guide Best practices for brute-force / cred modules
Exploit Modules Guide Best practices for exploit modules
Utilities & Helpers utils.rs public API, target normalization, honeypot check
Testing & QA Build checks, smoke tests, wordlist validation
Changelog Release notes and version history
Contributing Fork guide, PR checklist, code style
Credits Authors, acknowledgements, legal notice

Highlights

  • Auto-discovered modules: build.rs indexes src/modules/** — drop in new code, no manual registration needed
  • Interactive shell: Color prompts, shortcuts (help/?, modules/m, run/go), command chaining with &
  • Comprehensive credential tooling: FTP(S), SSH, Telnet, POP3(S), SMTP, RDP, RTSP, SNMP, L2TP, MQTT, Fortinet — with IPv6 and TLS support
  • Exploit coverage: CVEs for GNU inetutils-telnetd, Apache Tomcat, TP-Link, Ivanti, Zabbix, OpenSSH, Jenkins, PAN-OS, Heartbleed, and more
  • Scanners & utilities: Port scanner, ping sweep, SSDP, HTTP title grabber, DNS recursion tester, directory bruteforcer, sequential fuzzer
  • REST API server: Authentication, rate limiting, IP tracking, dynamic key rotation, hardening mode
  • Security hardened: Input validation, path traversal protection, honeypot detection, memory-safe operations
  • IPv4/IPv6 ready: Both address families work out-of-the-box across all modules

Quick Start

# Install dependencies (Debian/Ubuntu/Kali)
sudo apt update
sudo apt install pkg-config libssl-dev rustc libdbus-1-dev freerdp2-x11

# Install Rust
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source $HOME/.cargo/env

# Clone & build
git clone https://github.com/s-b-repo/rustsploit.git
cd rustsploit
cargo build

# Run
cargo run

For other distros (Arch, Gentoo, Fedora), Docker deployment, and one-liner installs, see Getting Started.


Quick Navigation


Private Internet Recommendations

The built-in proxy system has been removed in favor of system-level VPN solutions. We recommend Mullvad VPN for its no-registration, audited no-logs policy, WireGuard support, and excellent Linux CLI. Simply connect your VPN before running the tool — all traffic routes through the tunnel.


Contributing

Contributions welcome! See the Contributing Guide for the full process. In short:

  1. Fork + branch from main
  2. Add your module under the appropriate category
  3. Run cargo fmt and cargo check before opening a PR

Credits

  • Project Lead: s-b-repo
  • Language: 100% Rust
  • Inspired by: RouterSploit, Metasploit Framework, pwntools

⚠️ Rustsploit is intended for authorized security testing and research purposes only. Obtain explicit permission before targeting any system you do not own.