You've already forked greyhack
210 lines
4.8 KiB
Plaintext
210 lines
4.8 KiB
Plaintext
if params.len > 0 and (params[0] == "-h" or params[0] == "--help") then
|
|
current_program = get_shell.host_computer.File(program_path)
|
|
print "Usage: " + current_program.name + " [-h|<library path> [extra]]"
|
|
print " -h show this help message"
|
|
print " <library path> only exploit the specified library (e.g. /lib/init.so)"
|
|
print " extra optional overflow value to attempt"
|
|
print " (no args) try all libraries in /lib and current_path"
|
|
exit
|
|
end if
|
|
|
|
mx = include_lib("/lib/metaxploit.so")
|
|
if not mx then mx = include_lib(current_path + "/metaxploit.so")
|
|
if not mx then exit("Unable to load metaxploit.so")
|
|
|
|
computer = get_shell.host_computer
|
|
|
|
ends_with = function(s, suffix)
|
|
if s.len < suffix.len then return 0
|
|
return s[s.len - suffix.len : ] == suffix
|
|
end function
|
|
|
|
extra = ""
|
|
target_lib = null
|
|
if params.len > 0 then
|
|
if params[0].indexOf("/") != null or ends_with(params[0], ".so") then
|
|
target_lib = params[0]
|
|
if params.len > 1 then extra = params[1]
|
|
else
|
|
extra = params[0]
|
|
end if
|
|
end if
|
|
|
|
extract_value = function(line)
|
|
start = line.indexOf("<b>")
|
|
finish = line.indexOf("</b>")
|
|
if start == null or finish == null then return ""
|
|
if start == -1 or finish == -1 then return ""
|
|
if finish > start then
|
|
return line[start + 3 : finish]
|
|
end if
|
|
|
|
before_dot = line.split("\.")[0]
|
|
words = before_dot.split(" ")
|
|
value = ""
|
|
for word in words
|
|
if word != "" then value = word
|
|
end for
|
|
return value
|
|
end function
|
|
|
|
shell_user = function(sh)
|
|
comp = sh.host_computer
|
|
if not comp then return "guest"
|
|
|
|
rootf = comp.File("/root")
|
|
if rootf and rootf.has_permission("w") then return "root"
|
|
|
|
passwd = comp.File("/etc/passwd")
|
|
if passwd and passwd.has_permission("w") then return "root"
|
|
|
|
home = comp.File("/home")
|
|
if not home then return "guest"
|
|
folders = home.get_folders
|
|
if not folders then return "guest"
|
|
for folder in folders
|
|
if folder.name == "guest" then continue
|
|
if folder.has_permission("w") then return folder.name
|
|
end for
|
|
return "guest"
|
|
end function
|
|
|
|
known_paths = []
|
|
libs = []
|
|
|
|
add_lib_dir = function(dirpath)
|
|
folder = computer.File(dirpath)
|
|
if not folder then return
|
|
if not folder.is_folder then return
|
|
if not folder.has_permission("r") then return
|
|
files = folder.get_files
|
|
if not files then return
|
|
for f in files
|
|
if not f.has_permission("r") then continue
|
|
if not ends_with(f.name, ".so") then continue
|
|
already = 0
|
|
for p in known_paths
|
|
if p == f.path then
|
|
already = 1
|
|
break
|
|
end if
|
|
end for
|
|
if already then continue
|
|
lib = mx.load(f.path)
|
|
if not lib then continue
|
|
known_paths.push f.path
|
|
libs.push {
|
|
"path": f.path,
|
|
"name": lib.lib_name,
|
|
"version": lib.version,
|
|
"lib": lib,
|
|
}
|
|
end for
|
|
end function
|
|
|
|
if target_lib then
|
|
lf = computer.File(target_lib)
|
|
if not lf then exit("Unable to locate library: " + target_lib)
|
|
lib = mx.load(target_lib)
|
|
if not lib then exit("Unable to load library: " + target_lib)
|
|
libs.push {
|
|
"path": target_lib,
|
|
"name": lib.lib_name,
|
|
"version": lib.version,
|
|
"lib": lib,
|
|
}
|
|
else
|
|
add_lib_dir "/lib"
|
|
if current_path != "/lib" then add_lib_dir(current_path)
|
|
end if
|
|
|
|
if libs.len == 0 then
|
|
print "Nothing found"
|
|
exit
|
|
end if
|
|
|
|
preferred = [
|
|
"kernel_module.so",
|
|
"init.so",
|
|
"net.so",
|
|
"kernel_router.so",
|
|
]
|
|
ordered = []
|
|
for name in preferred
|
|
for item in libs
|
|
if ends_with(item.path, "/" + name) or item.name == name then
|
|
ordered.push item
|
|
end if
|
|
end for
|
|
end for
|
|
for item in libs
|
|
already = 0
|
|
for o in ordered
|
|
if o.path == item.path then
|
|
already = 1
|
|
break
|
|
end if
|
|
end for
|
|
if already then continue
|
|
ordered.push item
|
|
end for
|
|
libs = ordered
|
|
|
|
lines = "PATH LIBRARY VERSION"
|
|
for item in libs
|
|
lines = lines + "\n" + item.path + " " + item.name + " " + item.version
|
|
end for
|
|
print format_columns(lines)
|
|
|
|
try_overflow = function(lib, add, value)
|
|
of = lib.overflow(add, value)
|
|
if typeof(of) == "shell" then return of
|
|
if extra != "" then
|
|
of = lib.overflow(add, value, extra)
|
|
if typeof(of) == "shell" then return of
|
|
end if
|
|
return null
|
|
end function
|
|
|
|
user_shell = null
|
|
for item in libs
|
|
if not target_lib then
|
|
print "---"
|
|
print item.name
|
|
print "---"
|
|
end if
|
|
adds = mx.scan(item.lib)
|
|
if not adds then continue
|
|
for add in adds
|
|
info = mx.scan_address(item.lib, add)
|
|
if not info then continue
|
|
parts = info.split("Unsafe check:")
|
|
first = 1
|
|
for part in parts
|
|
if first then
|
|
first = 0
|
|
continue
|
|
end if
|
|
value = extract_value(part)
|
|
if value == "" then continue
|
|
of = try_overflow(item.lib, add, value)
|
|
if typeof(of) != "shell" then continue
|
|
user = shell_user(of)
|
|
if user == "root" then
|
|
of.start_terminal
|
|
exit
|
|
end if
|
|
if active_user == "guest" and user != "guest" and user != active_user then
|
|
if not user_shell then user_shell = of
|
|
end if
|
|
end for
|
|
end for
|
|
end for
|
|
|
|
if active_user == "guest" and user_shell then
|
|
user_shell.start_terminal
|
|
exit
|
|
end if
|
|
|
|
print "Nothing found"
|