Files
greyhack/source/betteroverflow.src

164 lines
3.9 KiB
Plaintext

if params.len < 1 or params[0] == "-h" or params[0] == "--help" then
current_program = get_shell.host_computer.File(program_path)
exit "Usage: " + current_program.name + " <remote ip> [remote port]"
end if
mx = include_lib("/lib/metaxploit.so")
if not mx then exit("Unable to load /lib/metaxploit.so")
extract_value = function(line)
start = line.indexOf("<b>")
finish = line.indexOf("</b>")
if start != -1 and finish != -1 and finish > start then
return line[start + 3 : finish]
end if
before_dot = line.split("\.")[0]
words = before_dot.split(" ")
value = ""
for word in words
if word != "" then value = word
end for
return value
end function
computer_is_root = function(comp)
if not comp then return 0
root_dir = comp.File("/root")
if root_dir and root_dir.has_permission("w") then return 1
passwd = comp.File("/etc/passwd")
if passwd and passwd.has_permission("w") then return 1
return 0
end function
dump_remote_passwd = function(comp, add, value)
if not computer_is_root(comp) then return 0
passwd = comp.File("/etc/passwd")
if not passwd then return 0
if not passwd.has_permission("r") then return 0
content = passwd.get_content
if not content then return 0
local_cp = get_shell.host_computer
passwd_name = "remote_passwd.txt"
passwd_path = home_dir + "/" + passwd_name
existing = local_cp.File(passwd_path)
if existing then existing.delete
created = local_cp.touch(home_dir, passwd_name)
if typeof(created) == "string" then return 0
local_passwd = local_cp.File(passwd_path)
if not local_passwd then return 0
written = local_passwd.set_content(content)
if typeof(written) == "string" then
local_passwd.delete
return 0
end if
decipher = local_cp.File("/bin/decipher")
if not decipher then
local_passwd.delete
return 0
end if
print add + " " + value + " type:computer privilege:root"
get_shell.launch("/bin/decipher", passwd_path)
leftover = local_cp.File(passwd_path)
if leftover then leftover.delete
return 1
end function
ip = params[0]
port = 0
if params.len > 1 then
port = params[1].to_int
end if
if port == 0 then
sess = mx.net_use(ip)
else
sess = mx.net_use(ip, port)
end if
if not sess then exit("Unable to establish session")
lib = sess.dump_lib
adds = mx.scan(lib)
found = 0
candidates = []
for add in adds
info = mx.scan_address(lib, add)
if not info then continue
lines = info.split(char(10))
for line in lines
pos = line.indexOf("Unsafe check:")
if pos == null then continue
if pos == -1 then continue
value = extract_value(line)
if value == "" then continue
candidates.push add + " " + value
end for
end for
for candidate in candidates
parts = candidate.split(" ")
add = parts[0]
value = parts[1]
if port == 0 then
sess = mx.net_use(ip)
else
sess = mx.net_use(ip, port)
end if
if not sess then continue
lib = sess.dump_lib
if not lib then continue
oflow = lib.overflow(add, value)
if typeof(oflow) == "shell" then
// create a temporary file for whoami output
tmp_name = "/tmp/whoami_" + add + "_" + value
// run whoami and capture output
oflow.launch "whoami > " + tmp_name
// small wait to ensure command completes
wait 0.1
// read the output via host computer
host = oflow.host_computer
f = host.File(tmp_name)
if not f then
// if file reading failed, skip cleanup and continue
continue
end if
output = f.get_content
// remove trailing newline and carriage return
if output.endsWith(char(10)) then
output = output[0 : output.len - 1]
end if
if output.endsWith(char(13)) then
output = output[0 : output.len - 1]
end if
// determine privilege level
if output == "root" then
priv = "root"
else
priv = "guest"
end if
print add + " " + value + " user:" + output + " privilege:" + priv
// cleanup
oflow.launch "/bin/rm " + tmp_name
found = 1
else if typeof(oflow) == "computer" then
if dump_remote_passwd(oflow, add, value) then
found = 1
end if
end if
end for
if found == 0 then print("Nothing found")