You've already forked greyhack
first commit
This commit is contained in:
2
.gitignore
vendored
Normal file
2
.gitignore
vendored
Normal file
@@ -0,0 +1,2 @@
|
|||||||
|
__pycache__
|
||||||
|
provision.src
|
||||||
119
provision.py
Normal file
119
provision.py
Normal file
@@ -0,0 +1,119 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
from pathlib import Path
|
||||||
|
import re
|
||||||
|
|
||||||
|
|
||||||
|
ROOT = Path(__file__).resolve().parent
|
||||||
|
SOURCE_DIR = ROOT / "source"
|
||||||
|
OUTPUT = ROOT / "provision.src"
|
||||||
|
|
||||||
|
|
||||||
|
def variable_name(path: Path) -> str:
|
||||||
|
stem = re.sub(r"\W+", "_", path.stem.lower()).strip("_")
|
||||||
|
if not stem:
|
||||||
|
raise ValueError(f"cannot derive variable name from {path.name!r}")
|
||||||
|
if stem[0].isdigit():
|
||||||
|
stem = f"_{stem}"
|
||||||
|
return stem
|
||||||
|
|
||||||
|
|
||||||
|
def greyscript_string(value: str) -> str:
|
||||||
|
return '"' + value.replace('"', '""') + '"'
|
||||||
|
|
||||||
|
|
||||||
|
def content_lines(var: str, content: str) -> list[str]:
|
||||||
|
lines = [f'{var}_content = ""']
|
||||||
|
for line in content.splitlines():
|
||||||
|
lines.append(
|
||||||
|
f"{var}_content = {var}_content + {greyscript_string(line)} + NL"
|
||||||
|
)
|
||||||
|
return lines
|
||||||
|
|
||||||
|
|
||||||
|
def source_files() -> list[Path]:
|
||||||
|
files = sorted(SOURCE_DIR.glob("*.src"), key=lambda p: p.name)
|
||||||
|
bbuild = SOURCE_DIR / "bbuild.src"
|
||||||
|
if bbuild not in files:
|
||||||
|
raise RuntimeError(f"required bootstrap source missing: {bbuild}")
|
||||||
|
if bbuild in files:
|
||||||
|
files.remove(bbuild)
|
||||||
|
files.insert(0, bbuild)
|
||||||
|
return files
|
||||||
|
|
||||||
|
|
||||||
|
def install_binary_lines(var: str, bin_name: str) -> list[str]:
|
||||||
|
return [
|
||||||
|
f'{var}_bin = cp.File("/bin/{bin_name}")',
|
||||||
|
f'if not {var}_bin then exit("Failed to install {bin_name}")',
|
||||||
|
f'{var}_bin.set_group("root")',
|
||||||
|
f'{var}_bin.set_owner("root")',
|
||||||
|
f'{var}_bin.chmod("u+rwx,g+rx,o+rx")',
|
||||||
|
"",
|
||||||
|
]
|
||||||
|
|
||||||
|
|
||||||
|
def build_provision() -> str:
|
||||||
|
sources = source_files()
|
||||||
|
if not sources:
|
||||||
|
raise RuntimeError(f"no .src files found in {SOURCE_DIR}")
|
||||||
|
|
||||||
|
output: list[str] = [
|
||||||
|
"cp = get_shell.host_computer",
|
||||||
|
'home = "/home/" + active_user',
|
||||||
|
"NL = char(10)",
|
||||||
|
'cp.create_folder(home, "source")',
|
||||||
|
"",
|
||||||
|
]
|
||||||
|
|
||||||
|
for src in sources:
|
||||||
|
var = variable_name(src)
|
||||||
|
output.extend(
|
||||||
|
[
|
||||||
|
f'cp.touch(home + "/source/", "{src.name}")',
|
||||||
|
f'{var}_source = cp.File(home + "/source/{src.name}")',
|
||||||
|
*content_lines(var, src.read_text()),
|
||||||
|
f"{var}_source.set_content({var}_content)",
|
||||||
|
"",
|
||||||
|
]
|
||||||
|
)
|
||||||
|
|
||||||
|
bbuild = sources[0]
|
||||||
|
bbuild_var = variable_name(bbuild)
|
||||||
|
output.extend(
|
||||||
|
[
|
||||||
|
f"build_result = get_shell.build({bbuild_var}_source.path, current_path)",
|
||||||
|
'if build_result != "" then exit(build_result)',
|
||||||
|
f'{bbuild_var}_bin = cp.File(current_path + "/bbuild")',
|
||||||
|
f'if not {bbuild_var}_bin then exit("Failed to build bbuild")',
|
||||||
|
f'{bbuild_var}_bin.move("/bin", "bbuild")',
|
||||||
|
*install_binary_lines(bbuild_var, "bbuild"),
|
||||||
|
]
|
||||||
|
)
|
||||||
|
|
||||||
|
for src in sources[1:]:
|
||||||
|
var = variable_name(src)
|
||||||
|
bin_name = src.stem
|
||||||
|
output.extend(
|
||||||
|
[
|
||||||
|
f'get_shell.launch("/bin/bbuild", {var}_source.path)',
|
||||||
|
*install_binary_lines(var, bin_name),
|
||||||
|
]
|
||||||
|
)
|
||||||
|
|
||||||
|
output.extend(
|
||||||
|
[
|
||||||
|
'provision_source = cp.File(home + "/provision.src")',
|
||||||
|
"if provision_source then provision_source.delete",
|
||||||
|
'provision_bin = cp.File(home + "/provision")',
|
||||||
|
"if provision_bin then provision_bin.delete",
|
||||||
|
]
|
||||||
|
)
|
||||||
|
return "\n".join(output) + "\n"
|
||||||
|
|
||||||
|
|
||||||
|
def main() -> None:
|
||||||
|
OUTPUT.write_text(build_provision())
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
35
source/bbuild.src
Normal file
35
source/bbuild.src
Normal file
@@ -0,0 +1,35 @@
|
|||||||
|
if params.len < 1 or params[0] == "-h" or params[0] == "--help" then
|
||||||
|
current_program = get_shell.host_computer.File(program_path)
|
||||||
|
exit("Usage: "+current_program.name+" <source code path>")
|
||||||
|
end if
|
||||||
|
source_file = get_shell.host_computer.File(params[0])
|
||||||
|
if not source_file then
|
||||||
|
source_file = get_shell.host_computer.File(current_path + params[0])
|
||||||
|
if not source_file then exit("Unable to locate source file")
|
||||||
|
end if
|
||||||
|
|
||||||
|
cp = get_shell.host_computer
|
||||||
|
get_shell.build(source_file.path, current_path)
|
||||||
|
bin_name = source_file.name.split("\.")[0]
|
||||||
|
bin_file = cp.File(current_path + "/" + bin_name)
|
||||||
|
if not bin_file then exit("Compiler error")
|
||||||
|
bin_file.move("/bin", bin_name)
|
||||||
|
bin_file.set_group("root")
|
||||||
|
bin_file.set_owner("root")
|
||||||
|
|
||||||
|
source_content = source_file.get_content
|
||||||
|
if source_content.indexOf("""/lib/metaxploit.so""") and bin_name != "bbuild" then
|
||||||
|
source_content = source_content.replace("""/lib/metaxploit.so""", "current_path + ""/metaxploit.so""")
|
||||||
|
cp.touch(current_path, bin_name + "_guest.src")
|
||||||
|
guest_source = cp.File(current_path + "/" + bin_name + "_guest.src")
|
||||||
|
guest_source.set_content(source_content)
|
||||||
|
get_shell.build(guest_source.path, current_path)
|
||||||
|
guest_source.delete
|
||||||
|
guest_file = cp.File(current_path + "/" + bin_name + "_guest")
|
||||||
|
else
|
||||||
|
get_shell.build(source_file.path, current_path)
|
||||||
|
guest_file = cp.File(current_path + "/" + bin_name)
|
||||||
|
end if
|
||||||
|
guest_file.move("/home/" + active_user + "/guest/", bin_name)
|
||||||
|
guest_file.set_group("guest")
|
||||||
|
guest_file.set_owner("guest")
|
||||||
42
source/bnmap.src
Normal file
42
source/bnmap.src
Normal file
@@ -0,0 +1,42 @@
|
|||||||
|
if params.len < 1 or params[0] == "-h" or params[0] == "--help" then
|
||||||
|
current_program = get_shell.host_computer.File(program_path)
|
||||||
|
exit("Usage: "+current_program.name+" <remote ip>")
|
||||||
|
end if
|
||||||
|
mx = include_lib("/lib/metaxploit.so")
|
||||||
|
ip = params[0]
|
||||||
|
// ROUTER
|
||||||
|
router_sess = mx.net_use(ip)
|
||||||
|
if not router_sess then
|
||||||
|
exit("Unable to connect to router")
|
||||||
|
end if
|
||||||
|
router_lib = router_sess.dump_lib
|
||||||
|
data_out = "PORT STATE LIBRARY VERSION LAN"
|
||||||
|
data_out = data_out + "\n" +
|
||||||
|
" " + // port
|
||||||
|
"open" + " " + // state
|
||||||
|
router_lib.lib_name + " " + // library
|
||||||
|
router_lib.version + " " + // version
|
||||||
|
"" // lan ip
|
||||||
|
// PORTS
|
||||||
|
router = get_router(ip)
|
||||||
|
for port in router.used_ports
|
||||||
|
if port.is_closed == 0 then state = "open" else state = "closed"
|
||||||
|
sess = mx.net_use(ip, port.port_number)
|
||||||
|
if not sess then
|
||||||
|
data_out = data_out + "\n" +
|
||||||
|
port.port_number + " " + // port
|
||||||
|
state + " " + // state
|
||||||
|
"N/A" + " " + // library
|
||||||
|
"N/A" + " " + // version
|
||||||
|
"" // lan ip
|
||||||
|
continue
|
||||||
|
end if
|
||||||
|
lib = sess.dump_lib
|
||||||
|
data_out = data_out + "\n" +
|
||||||
|
port.port_number + " " + // port
|
||||||
|
state + " " + // state
|
||||||
|
lib.lib_name + " " + // library
|
||||||
|
lib.version + " " + // version
|
||||||
|
port.get_lan_ip
|
||||||
|
end for
|
||||||
|
print(format_columns(data_out))
|
||||||
12
source/libversion.src
Normal file
12
source/libversion.src
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
if params.len < 1 or params[0] == "-h" or params[0] == "--help" then
|
||||||
|
current_program = get_shell.host_computer.File(program_path)
|
||||||
|
exit("Usage: "+current_program.name+" <library path> [library path...]")
|
||||||
|
end if
|
||||||
|
mx = include_lib("/lib/metaxploit.so")
|
||||||
|
for lib_path in params
|
||||||
|
lib = mx.load(lib_path)
|
||||||
|
if not lib then
|
||||||
|
print("Unable to load library "+lib_path)
|
||||||
|
end if
|
||||||
|
print("Library "+lib.lib_name+" - "+lib.version)
|
||||||
|
end for
|
||||||
5
source/locallib.src.disabled
Normal file
5
source/locallib.src.disabled
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
if params[0] == "-h" or params[0] == "--help" then
|
||||||
|
current_program = get_shell.host_computer.File(program_path)
|
||||||
|
exit("Usage: "+current_program.name+" <remote ip> <remote port> <address> <data>")
|
||||||
|
end if
|
||||||
|
mx = include_lib("metaxploit.so")
|
||||||
22
source/lscan.src
Normal file
22
source/lscan.src
Normal file
@@ -0,0 +1,22 @@
|
|||||||
|
if params.len < 1 or params[0] == "-h" or params[0] == "--help" then
|
||||||
|
current_program = get_shell.host_computer.File(program_path)
|
||||||
|
exit("Usage: "+current_program.name+" <library path>")
|
||||||
|
end if
|
||||||
|
mx = include_lib("/lib/metaxploit.so")
|
||||||
|
lib_path = params[0]
|
||||||
|
lib_file = get_shell.host_computer.File(lib_path)
|
||||||
|
if not lib_file then
|
||||||
|
lib_file = get_shell.host_computer.File(current_path + lib_path)
|
||||||
|
if not lib_file then
|
||||||
|
exit("Unable to find library")
|
||||||
|
end if
|
||||||
|
end if
|
||||||
|
lib = mx.load(lib_file.path)
|
||||||
|
if not lib then
|
||||||
|
exit("Unable to load library")
|
||||||
|
end if
|
||||||
|
adds = mx.scan(lib)
|
||||||
|
for add in adds
|
||||||
|
print("Address: " + add)
|
||||||
|
print(mx.scan_address(lib, add))
|
||||||
|
end for
|
||||||
58
source/overflow.src
Normal file
58
source/overflow.src
Normal file
@@ -0,0 +1,58 @@
|
|||||||
|
if params.len < 1 or params[0] == "-h" or params[0] == "--help" then
|
||||||
|
current_program = get_shell.host_computer.File(program_path)
|
||||||
|
print("Usage: " + current_program.name + " <library path>")
|
||||||
|
print("--- OR ---")
|
||||||
|
exit("Usage: " + current_program.name + " <remote ip> <remote port> <address> <data>")
|
||||||
|
end if
|
||||||
|
mx = include_lib("/lib/metaxploit.so")
|
||||||
|
extra_data = ""
|
||||||
|
if params.len == 1 or params.len == 2 then
|
||||||
|
lib_file = get_shell.host_computer.File(params[0])
|
||||||
|
if not lib_file then
|
||||||
|
lib_file = get_shell.host_computer.File(current_path + params[0])
|
||||||
|
if not lib_file then exit("Unable to load library from local path")
|
||||||
|
end if
|
||||||
|
lib = mx.load(lib_file.path)
|
||||||
|
if params.len == 2 then
|
||||||
|
extra_data = params[1]
|
||||||
|
end if
|
||||||
|
else
|
||||||
|
ip = params[0]
|
||||||
|
port = params[1].to_int
|
||||||
|
address = params[2]
|
||||||
|
data = params[3]
|
||||||
|
if port == 0 then
|
||||||
|
sess = mx.net_use(ip)
|
||||||
|
else
|
||||||
|
sess = mx.net_use(ip, port)
|
||||||
|
end if
|
||||||
|
if not sess then
|
||||||
|
exit("Unable to establish session")
|
||||||
|
end if
|
||||||
|
lib = sess.dump_lib()
|
||||||
|
if params.len == 5 then
|
||||||
|
extra_data == params[4]
|
||||||
|
end if
|
||||||
|
end if
|
||||||
|
|
||||||
|
if extra_data != "" then
|
||||||
|
extra_data = params[4]
|
||||||
|
of = lib.overflow(address, data, extra_data)
|
||||||
|
else
|
||||||
|
of = lib.overflow(address, data)
|
||||||
|
end if
|
||||||
|
to = typeof(of)
|
||||||
|
if to == "shell" then
|
||||||
|
of.start_terminal
|
||||||
|
else if to == "file" then
|
||||||
|
print(of.path(true))
|
||||||
|
if of.is_folder then
|
||||||
|
for f in of.get_files
|
||||||
|
print(f.owner+" "+f.group+" "+f.permissions+" "+f.name)
|
||||||
|
end for
|
||||||
|
else
|
||||||
|
print(of.get_content)
|
||||||
|
end if
|
||||||
|
else
|
||||||
|
print(typeof(of))
|
||||||
|
end if
|
||||||
21
source/rscan.src
Normal file
21
source/rscan.src
Normal file
@@ -0,0 +1,21 @@
|
|||||||
|
if params.len < 2 or params[0] == "-h" or params[0] == "--help" then
|
||||||
|
current_program = get_shell.host_computer.File(program_path)
|
||||||
|
exit("Usage: "+current_program.name+" <remote ip> [remote port]")
|
||||||
|
end if
|
||||||
|
mx = include_lib("/lib/metaxploit.so")
|
||||||
|
ip = params[0]
|
||||||
|
port = params[1].to_int
|
||||||
|
if port == 0 then
|
||||||
|
sess = mx.net_use(ip)
|
||||||
|
else
|
||||||
|
sess = mx.net_use(ip, port)
|
||||||
|
end if
|
||||||
|
if not sess then
|
||||||
|
exit("Unable to establish session")
|
||||||
|
end if
|
||||||
|
lib = sess.dump_lib
|
||||||
|
adds = mx.scan(lib)
|
||||||
|
for add in adds
|
||||||
|
print("Address: " + add)
|
||||||
|
print(mx.scan_address(lib, add))
|
||||||
|
end for
|
||||||
38
source/wifi.src
Normal file
38
source/wifi.src
Normal file
@@ -0,0 +1,38 @@
|
|||||||
|
crypto = include_lib("/lib/crypto.so")
|
||||||
|
computer = get_shell.host_computer
|
||||||
|
cappath = current_path + "/file.cap"
|
||||||
|
info = "BSSID STRENGTH ESSID"
|
||||||
|
netname = ""
|
||||||
|
command = ""
|
||||||
|
if params.len > 0 then command = params[0] end if
|
||||||
|
for letter in computer.network_devices
|
||||||
|
if letter == " " then
|
||||||
|
break
|
||||||
|
end if
|
||||||
|
netname = netname + letter
|
||||||
|
end for
|
||||||
|
nets = computer.wifi_networks(netname)
|
||||||
|
for net in nets
|
||||||
|
bssid = net.split(" ")[0]
|
||||||
|
strength = net.split(" ")[1][0:2].to_int
|
||||||
|
essid = net.split(" ")[2]
|
||||||
|
if command == "-l" then
|
||||||
|
info = info + "\n" + net
|
||||||
|
continue
|
||||||
|
else if command == essid or command == bssid or command == "" then
|
||||||
|
crypto.airmon("start", netname)
|
||||||
|
crypto.aireplay(bssid, essid, floor(300000 / strength))
|
||||||
|
pwd = crypto.aircrack(cappath)
|
||||||
|
print(pwd)
|
||||||
|
capfile = computer.File(cappath)
|
||||||
|
capfile.delete
|
||||||
|
crypto.airmon("stop", netname)
|
||||||
|
connected = computer.connect_wifi(netname, bssid, essid, pwd)
|
||||||
|
if connected then
|
||||||
|
print("Connected to " + essid)
|
||||||
|
end if
|
||||||
|
end if
|
||||||
|
end for
|
||||||
|
if command == "-l" then
|
||||||
|
print(format_columns(info))
|
||||||
|
end if
|
||||||
Reference in New Issue
Block a user