Files
s-b-repo-rustsploit/docs/Exploit-Modules-Guide.md
T
S.B fb9ae7f3c2 api migrations and migration from legacy stuff and fixing shiz
migrated away from free rdp lots of improvements there and created native libs feel free to use native libs but contribute  if you improve please add more wider api support and cli and shell payload mutator for api endpoint going to do that   for payloads gens and other stuff later and im also planning some more bug changes and improvement check the api template
2026-03-19 17:35:15 +02:00

4.0 KiB

Exploit Modules Guide

Best practices for writing and extending exploit modules in Rustsploit.


CVE Referencing

Always mention CVE IDs, vendor names, and affected products in:

  • The module file docstring / top-level comments
  • Output messages (e.g., [*] Testing CVE-2025-14847 on {}, target)
  • The Module Catalog

Response Validation

Validate server responses before declaring success — false positives hurt credibility:

if response.status() == 200 && body.contains("expected_indicator") {
    println!("{} Confirmed vulnerable: {}", "[+]".green(), target);
} else {
    println!("{} Not vulnerable or patched", "[-]".red());
}

Artifact Handling

If the exploit downloads or writes files (e.g., memory dumps, webshells):

  • Store in the current working directory or a named subfolder
  • Name files descriptively: mongobleed_results_{target}.txt, nginx_pwner_results_{target}.txt
  • Inform the operator where output was written

Clean-Up Instructions

If the exploit adds credentials or accounts (e.g., camera modules), document:

  • The impact of the change
  • How to revert (e.g., default creds to restore, commands to run)

Interactive Options

Use prompt_* helpers from crate::utils if end-user input is needed:

use crate::utils::{prompt_input, prompt_yes_no};

let command = prompt_input("Enter command to execute (or leave blank for shell): ")?;
let deploy = prompt_yes_no("Deploy webshell?", true)?;

Mass-Scan Support

For modules supporting internet-wide scanning (target 0.0.0.0/0):

if target == "0.0.0.0" || target == "0.0.0.0/0" || target == "random" {
    loop {
        let ip = generate_random_public_ip();
        if !is_excluded_ip(ip) {
            execute(ip.to_string().as_str()).await.ok();
        }
    }
}

See EXCLUDED_RANGES documentation in Security & Validation.

Disable honeypot detection in mass-scan mode to avoid interactive prompts blocking the scan loop.


Module-Specific Notes

Hikvision RCE (CVE-2021-36260)

  • Safe check — writes/reads a test file to verify exploitability
  • Unsafe reboot — reboots the device to confirm (destructive)
  • Command exec — output retrieved, supports blind mode
  • SSH shell — deploys Dropbear SSH on port 1337

MongoBleed (CVE-2025-14847)

  • Sends malicious compressed packet with inflated uncompressedSize
  • Parses error response to extract leaked memory chunks (field names / types)
  • Prints any leaked strings (potential credentials / data) to console
  • Includes deep-scan mode for extended analysis

n8n RCE (CVE-2025-68613)

  • Authenticates via /rest/login (token / cookie-based)
  • Creates a malicious workflow with expression injection payload
  • Triggers via /rest/workflows/{id}/run
  • Cleans up test workflow after execution
  • 6 payload types: Info, Command, Environment, Read File, Write File, Reverse Shell

FortiWeb SQLi → RCE (CVE-2025-25257)

  • SQL injection via Authorization: Bearer ';{injection} header
  • Writes webshell via SELECT INTO OUTFILE
  • Uses .pth trigger for Python chmod execution
  • Interactive modes: deploy webshell, execute command, test SQLi only

NginxPwner

  • 10 checks: version disclosure, CRLF injection, PURGE method, variable leakage, merge slashes, header bypass / IP spoofing, alias traversal, X-Accel-Redirect bypass, PHP detection, CVE-2017-7529 integer overflow
  • Results saved to nginx_pwner_results_{target}.txt
  • Prints reminders for manual checks (Redis, CORS, request smuggling)

DoS / Stress Testing

⚠️ Authorized testing only. These modules can cause service disruption.

Module Notes
null_syn_exhaustion Raw socket, IP spoofing, XorShift128+ RNG, configurable PPS, >1M PPS capable
connection_exhaustion_flood FD-bounded semaphore, supports infinite mode with graceful Ctrl+C
tcp_connection_flood DNS pre-resolved, high-concurrency handshake stress, infinite mode
http2_rapid_reset CVE-2023-44487 — HTTP/2 stream reset flood