if params.len < 1 or params[0] == "-h" or params[0] == "--help" then current_program = get_shell.host_computer.File(program_path) exit "Usage: " + current_program.name + " [remote port]" end if mx = include_lib("/lib/metaxploit.so") if not mx then exit("Unable to load /lib/metaxploit.so") extract_value = function(line) start = line.indexOf("") finish = line.indexOf("") if start != -1 and finish != -1 and finish > start then return line[start + 3 : finish] end if before_dot = line.split("\.")[0] words = before_dot.split(" ") value = "" for word in words if word != "" then value = word end for return value end function computer_is_root = function(comp) if not comp then return 0 root_dir = comp.File("/root") if root_dir and root_dir.has_permission("w") then return 1 passwd = comp.File("/etc/passwd") if passwd and passwd.has_permission("w") then return 1 return 0 end function dump_remote_passwd = function(comp, add, value) if not computer_is_root(comp) then return 0 passwd = comp.File("/etc/passwd") if not passwd then return 0 if not passwd.has_permission("r") then return 0 content = passwd.get_content if not content then return 0 local_cp = get_shell.host_computer passwd_name = "remote_passwd.txt" passwd_path = home_dir + "/" + passwd_name existing = local_cp.File(passwd_path) if existing then existing.delete created = local_cp.touch(home_dir, passwd_name) if typeof(created) == "string" then return 0 local_passwd = local_cp.File(passwd_path) if not local_passwd then return 0 written = local_passwd.set_content(content) if typeof(written) == "string" then local_passwd.delete return 0 end if decipher = local_cp.File("/bin/decipher") if not decipher then local_passwd.delete return 0 end if print add + " " + value + " type:computer privilege:root" get_shell.launch("/bin/decipher", passwd_path) leftover = local_cp.File(passwd_path) if leftover then leftover.delete return 1 end function ip = params[0] port = 0 if params.len > 1 then port = params[1].to_int end if if port == 0 then sess = mx.net_use(ip) else sess = mx.net_use(ip, port) end if if not sess then exit("Unable to establish session") lib = sess.dump_lib adds = mx.scan(lib) found = 0 candidates = [] for add in adds info = mx.scan_address(lib, add) if not info then continue lines = info.split(char(10)) for line in lines pos = line.indexOf("Unsafe check:") if pos == null then continue if pos == -1 then continue value = extract_value(line) if value == "" then continue candidates.push add + " " + value end for end for for candidate in candidates parts = candidate.split(" ") add = parts[0] value = parts[1] if port == 0 then sess = mx.net_use(ip) else sess = mx.net_use(ip, port) end if if not sess then continue lib = sess.dump_lib if not lib then continue oflow = lib.overflow(add, value) if typeof(oflow) == "shell" then // create a temporary file for whoami output tmp_name = "/tmp/whoami_" + add + "_" + value // run whoami and capture output oflow.launch "whoami > " + tmp_name // small wait to ensure command completes wait 0.1 // read the output via host computer host = oflow.host_computer f = host.File(tmp_name) if not f then // if file reading failed, skip cleanup and continue continue end if output = f.get_content // remove trailing newline and carriage return if output.endsWith(char(10)) then output = output[0 : output.len - 1] end if if output.endsWith(char(13)) then output = output[0 : output.len - 1] end if // determine privilege level if output == "root" then priv = "root" else priv = "guest" end if print add + " " + value + " user:" + output + " privilege:" + priv // cleanup oflow.launch "/bin/rm " + tmp_name found = 1 else if typeof(oflow) == "computer" then if dump_remote_passwd(oflow, add, value) then found = 1 end if end if end for if found == 0 then print("Nothing found")