diff --git a/source/betteroverflow.src b/source/betteroverflow.src index 066b325..1ea6c5f 100644 --- a/source/betteroverflow.src +++ b/source/betteroverflow.src @@ -1,6 +1,6 @@ if params.len < 1 or params[0] == "-h" or params[0] == "--help" then current_program = get_shell.host_computer.File(program_path) - exit("Usage: " + current_program.name + " [remote port]") + exit "Usage: " + current_program.name + " [remote port]" end if mx = include_lib("/lib/metaxploit.so") @@ -10,7 +10,7 @@ extract_value = function(line) start = line.indexOf("") finish = line.indexOf("") if start != -1 and finish != -1 and finish > start then - return line[start + 3:finish] + return line[start + 3 : finish] end if before_dot = line.split("\.")[0] @@ -37,7 +37,7 @@ end if if not sess then exit("Unable to establish session") -lib = sess.dump_lib() +lib = sess.dump_lib adds = mx.scan(lib) found = 0 candidates = [] @@ -54,7 +54,7 @@ for add in adds value = extract_value(line) if value == "" then continue - candidates.push(add + " " + value) + candidates.push add + " " + value end for end for @@ -69,43 +69,43 @@ for candidate in candidates sess = mx.net_use(ip, port) end if if not sess then continue - lib = sess.dump_lib() + lib = sess.dump_lib if not lib then continue - of = lib.overflow(add, value) -if typeof(of) == "shell" then - // create a temporary file for whoami output - tmp_name = "/tmp/whoami_" + add + "_" + value + "_" + candidate - // run whoami and capture output - of.launch("/bin/sh -c 'whoami > " + tmp_name + "'") - // small wait to ensure command completes - wait(0.1) - // read the output via host computer - host = of.host_computer - f = host.File(tmp_name) - if not f then - // if file reading failed, skip cleanup and continue - continue - end if - output = f.get_content - // remove trailing newline and carriage return - if output.endsWith(char(10)) then - output = output[0:output.len-1] - end if - if output.endsWith(char(13)) then - output = output[0:output.len-1] - end if - // determine privilege level - if output == "root" then - priv = "root" - else - priv = "guest" - end if - print(add + " " + value + " user:" + output + " privilege:" + priv) - // cleanup - of.launch("/bin/rm -f " + tmp_name) - found = 1 - end if + oflow = lib.overflow(add, value) + if typeof(oflow) == "shell" then + // create a temporary file for whoami output + tmp_name = "/tmp/whoami_" + add + "_" + value + // run whoami and capture output + oflow.launch "whoami > " + tmp_name + // small wait to ensure command completes + wait 0.1 + // read the output via host computer + host = oflow.host_computer + f = host.File(tmp_name) + if not f then + // if file reading failed, skip cleanup and continue + continue + end if + output = f.get_content + // remove trailing newline and carriage return + if output.endsWith(char(10)) then + output = output[0 : output.len - 1] + end if + if output.endsWith(char(13)) then + output = output[0 : output.len - 1] + end if + // determine privilege level + if output == "root" then + priv = "root" + else + priv = "guest" + end if + print add + " " + value + " user:" + output + " privilege:" + priv + // cleanup + oflow.launch "/bin/rm -f " + tmp_name + found = 1 + end if end for if found == 0 then print("Nothing found")