Class: Msf::Exploit
- Inherits:
-
Module
- Object
- Module
- Msf::Exploit
- Defined in:
- lib/msf/core/exploit.rb,
lib/msf/core/exploit/capture.rb,
lib/msf/core/exploit/remote/unirpc.rb,
lib/msf/core/exploit/remote/http/nifi.rb,
lib/msf/core/exploit/remote/http/sccm.rb,
lib/msf/core/exploit/format/webarchive.rb,
lib/msf/core/exploit/remote/http/gitea.rb,
lib/msf/core/exploit/remote/http/jboss.rb,
lib/msf/core/exploit/remote/http/typo3.rb,
lib/msf/core/exploit/remote/http/gitlab.rb,
lib/msf/core/exploit/remote/http/joomla.rb,
lib/msf/core/exploit/remote/http/moodle.rb,
lib/msf/core/exploit/remote/http/pihole.rb,
lib/msf/core/exploit/remote/http/splunk.rb,
lib/msf/core/exploit/remote/http/webmin.rb,
lib/msf/core/exploit/remote/http/flowise.rb,
lib/msf/core/exploit/remote/http/freepbx.rb,
lib/msf/core/exploit/remote/http/jenkins.rb,
lib/msf/core/exploit/remote/http/pretalx.rb,
lib/msf/core/exploit/remote/http/exchange.rb,
lib/msf/core/exploit/remote/java/rmi/util.rb,
lib/msf/core/exploit/remote/http/nagios_xi.rb,
lib/msf/core/exploit/remote/http/wordpress.rb,
lib/msf/core/exploit/remote/http/sharepoint.rb,
lib/msf/core/exploit/remote/java/rmi/client.rb,
lib/msf/core/exploit/remote/kerberos/client.rb,
lib/msf/core/exploit/remote/kerberos/ticket.rb,
lib/msf/core/exploit/remote/http/apache_solr.rb,
lib/msf/core/exploit/remote/http/beyondtrust.rb,
lib/msf/core/exploit/remote/http/http_cookie.rb,
lib/msf/core/exploit/remote/http/sitecore_xp.rb,
lib/msf/core/exploit/remote/http/smartermail.rb,
lib/msf/core/exploit/remote/java/rmi/builder.rb,
lib/msf/core/exploit/remote/http/complete_pbx.rb,
lib/msf/core/exploit/remote/http/flask_unsign.rb,
lib/msf/core/exploit/remote/http/web_enrollment.rb,
lib/msf/core/exploit/remote/java/rmi/client/jmx.rb,
lib/msf/core/exploit/remote/kerberos/client/pac.rb,
lib/msf/core/exploit/remote/http/http_cookie_jar.rb,
lib/msf/core/exploit/remote/kerberos/client/base.rb,
lib/msf/core/exploit/remote/http/kubernetes/error.rb,
lib/msf/core/exploit/remote/http/php_filter_chain.rb,
lib/msf/core/exploit/remote/http/kubernetes/client.rb,
lib/msf/core/exploit/remote/kerberos/client/pkinit.rb,
lib/msf/core/exploit/remote/java/rmi/client/registry.rb,
lib/msf/core/exploit/format/rar_symlink_path_traversal.rb,
lib/msf/core/exploit/remote/java/rmi/client/jmx/server.rb,
lib/msf/core/exploit/remote/kerberos/client/ap_request.rb,
lib/msf/core/exploit/remote/kerberos/client/as_request.rb,
lib/msf/core/exploit/remote/kerberos/client/as_response.rb,
lib/msf/core/exploit/remote/kerberos/client/tgs_request.rb,
lib/msf/core/exploit/remote/kerberos/client/tgs_response.rb,
lib/msf/core/exploit/remote/relay/kerberos/relay_handler.rb,
lib/msf/core/exploit/remote/http/rails_active_storage_vips.rb,
lib/msf/core/exploit/remote/java/rmi/client/jmx/connection.rb,
lib/msf/core/exploit/remote/http/manage_engine_adaudit_plus.rb,
lib/msf/core/exploit/remote/java/rmi/client/registry/parser.rb,
lib/msf/core/exploit/remote/java/rmi/client/registry/builder.rb,
lib/msf/core/exploit/remote/java/rmi/client/jmx/server/parser.rb,
lib/msf/core/exploit/remote/relay/kerberos/target/http/client.rb,
lib/msf/core/exploit/remote/java/rmi/client/jmx/server/builder.rb,
lib/msf/core/exploit/remote/java/rmi/client/jmx/connection/builder.rb
Overview
This module provides methods for sending and receiving raw packets. It should be preferred over the soon-to-be deprecated Rex::Socket::Ip and Msf::Exploit::Remote::Ip mixins.
Please see the pcaprub documentation for more information on how to use capture objects.
Direct Known Subclasses
Defined Under Namespace
Modules: Android, AutoTarget, Brute, BruteTargets, Cacti, Capture, CmdStager, CompatDefaults, DECT_COA, DHCPServer, EXE, Egghunter, FILEFORMAT, FileDropper, Format, FormatString, Git, HTTP, JSObfu, Java, JavaDeserialization, KernelMode, LaravelCryptoKiller, NTLM, ORACLE, Omelet, PDF, PDF_Parse, PgAdmin, PhpEXE, Powershell, RIFF, Retry, RopDb, RubyDeserialization, SMB, SQLi, Seh, Stance, TFTPServer, Type, VBSObfuscate, ViewState, WbemExec, Windows_Constants Classes: CheckCode, Complete, Failed, Local, Remote
Instance Attribute Summary collapse
-
#active_timeout ⇒ Object
protected
Maximum number of seconds for active handlers.
-
#default_target ⇒ Object
The default target.
-
#fail_detail ⇒ Object
Detailed exception string indicating why the exploit was not successful.
-
#fail_message ⇒ Object
A formatted, human-readable failure message describing why the exploit was not successful.
-
#fail_reason ⇒ Object
The reason why the exploit was not successful (one of Msf::Module::Failure).
-
#last_vuln_attempt ⇒ Object
The VulnAttempt object created during this run, or nil/false if none was recorded.
-
#needs_cleanup ⇒ Object
Returns the value of attribute needs_cleanup.
-
#payload ⇒ Object
The encoded payload instance.
-
#payload_info ⇒ Object
The payload requirement hash.
-
#payload_instance ⇒ Object
The active payload instance.
-
#session_count ⇒ Object
The number of active sessions created by this instance.
-
#successful ⇒ Object
The boolean indicating whether the exploit succeeded.
-
#targets ⇒ Object
The list of targets.
Class Method Summary collapse
-
.mixins ⇒ Array
Returns an array of all of the exploit mixins.
-
.type ⇒ Object
Returns MODULE_EXPLOIT to indicate that this is an exploit module.
Instance Method Summary collapse
-
#add_handler(opts = {}) ⇒ Object
Allows the payload handler to spawn a new monitor.
-
#aggressive? ⇒ Boolean
Returns true if the exploit has an aggressive stance.
-
#autofilter ⇒ Object
Performs last-minute sanity checking of exploit parameters.
-
#autofilter_ports ⇒ Object
Provides a list of ports that can be used for matching this module against target systems.
-
#autofilter_services ⇒ Object
Provides a list of services that can be used for matching this module against target systems.
-
#cleanup ⇒ Object
Performs any cleanup that may be necessary, such as disconnecting connections and any other such fun things.
-
#compatible_encoders ⇒ Object
Returns a list of compatible encoders based on architecture.
-
#compatible_payloads(excluded_platforms: [], excluded_archs: []) ⇒ Object
Returns a list of compatible payloads based on platform, architecture, and size requirements.
-
#define_context_encoding_reqs(reqs) ⇒ Object
protected
Gets the memory map file and other context information that is required when wanting to support context keyed encoding.
-
#encode_begin(real_payload, reqs) ⇒ Object
Called prior to encoding a payload.
-
#encode_end(real_payload, reqs, encoded) ⇒ Object
Called after an encoded payload has been generated.
-
#encode_shellcode_stub(code, badchars = payload_badchars) ⇒ Object
Allows arbitrary shellcode to be encoded from within an exploit.
-
#exploit ⇒ Object
Kicks off the actual exploit.
-
#exploit_type ⇒ Object
If we don't know the exploit type, then I guess it's omnipresent!.
-
#fail_with(reason, msg = nil) ⇒ void
Raises a Msf::Exploit::Failed exception.
-
#generate_payload(pinst = nil) ⇒ Object
Generates the encoded version of the supplied payload using the payload requirements specific to this exploit.
-
#generate_single_payload(pinst = nil, platform = nil, arch = nil, explicit_target = nil) ⇒ Object
This method generates a non-cached payload which is typically useful for passive exploits that will have more than one client.
-
#handle_exception(e) ⇒ Object
Handle the exception.
-
#handler(*args) ⇒ Object
Passes the connection to the associated payload handler to see if the exploit succeeded and a connection has been established.
-
#handler_bind? ⇒ Boolean
If the payload uses a bind handler.
-
#handler_enabled? ⇒ Boolean
Allow the user to disable the payload handler.
- #has_auto_target?(targets = []) ⇒ Boolean
-
#init_compat ⇒ Object
protected
Overrides the base class method and serves to initialize default compatibilities for exploits.
-
#initialize(info = {}) ⇒ Exploit
constructor
Creates an instance of the exploit module.
- #interrupt_handler ⇒ Object
-
#is_payload_compatible?(name) ⇒ Boolean
Returns whether the requested payload is compatible with the module.
-
#make_fast_nops(count) ⇒ String
Generates a NOP sled using the #make_nops method.
-
#make_nops(count) ⇒ Object
Generates a nop sled of a supplied length and returns it to the caller.
-
#nop_generator ⇒ Object
Returns the first compatible NOP generator for this exploit's payload instance.
-
#nop_save_registers(explicit_target = nil) ⇒ Object
Returns the list of registers that the NOP generator should save, if any.
- #normalize_platform_arch ⇒ Object
-
#on_new_session(session) ⇒ Object
This is called by the payload when a new session is created.
-
#passive? ⇒ Boolean
Returns if the exploit has a passive stance.
-
#pattern_create(length, sets = nil) ⇒ Object
Generate a non-repeating static random string.
-
#payload_append(explicit_target = nil) ⇒ Object
Return any text that should be appended to the payload.
-
#payload_append_encoder(explicit_target = nil) ⇒ Object
Return any text that should be appended to the encoder of the payload.
-
#payload_badchars(explicit_target = nil) ⇒ Object
Returns the bad characters that cannot be in any payload used by this exploit.
-
#payload_disable_nops(explicit_target = nil) ⇒ Object
Whether NOP generation should be enabled or disabled.
-
#payload_encoder(explicit_target = nil) ⇒ Object
Returns the payload encoder that is associated with either the current target or the exploit in general.
-
#payload_encoder_options(explicit_target = nil) ⇒ Object
Returns the payload encoder option hash that is used to initialize the datastore of the encoder that is selected when generating an encoded payload.
-
#payload_encoder_type(explicit_target = nil) ⇒ Object
Returns the payload encoder type that is associated with either the current target or the exploit in general.
-
#payload_extended_options(explicit_target = nil) ⇒ Object
Returns the payload extended options hash which is used to provide a location to store extended information that may be useful to a particular type of payload or mixin.
-
#payload_max_nops(explicit_target = nil) ⇒ Object
Maximum number of nops to use as a hint to the framework.
-
#payload_min_nops(explicit_target = nil) ⇒ Object
Minimum number of nops to use as a hint to the framework.
-
#payload_nop(explicit_target = nil) ⇒ Object
Returns the payload NOP generator that is associated with either the current target or the exploit in general.
-
#payload_prepend(explicit_target = nil) ⇒ Object
Return any text that should be prepended to the payload.
-
#payload_prepend_encoder(explicit_target = nil) ⇒ Object
Return any text that should be prepended to the encoder of the payload.
-
#payload_space(explicit_target = nil) ⇒ Object
Returns the maximum amount of room the exploit has for a payload.
-
#rand_char(bad = payload_badchars) ⇒ Object
Generate a random character avoiding the exploit's bad characters.
-
#rand_text(length, bad = payload_badchars) ⇒ Object
Generate random text characters avoiding the exploit's bad characters.
-
#rand_text_alpha(length, bad = payload_badchars) ⇒ Object
Generate random alpha characters avoiding the exploit's bad characters.
-
#rand_text_alpha_lower(length, bad = payload_badchars) ⇒ Object
Generate random alpha lower characters avoiding the exploit's bad characters.
-
#rand_text_alpha_upper(length, bad = payload_badchars) ⇒ Object
Generate random alpha upper characters avoiding the exploit's bad characters.
-
#rand_text_alphanumeric(length, bad = payload_badchars) ⇒ Object
Generate random alphanumeric characters avoiding the exploit's bad characters.
-
#rand_text_debug(length, char = 'A') ⇒ Object
Utility methods for generating random text that implicitly uses the exploit's bad character set.
-
#rand_text_english(length, bad = payload_badchars) ⇒ Object
Generate random english-like avoiding the exploit's bad characters.
-
#rand_text_hex(length, bad = payload_badchars) ⇒ Object
Generate random hexadecimal characters avoiding the exploit's bad characters.
-
#rand_text_highascii(length, bad = payload_badchars) ⇒ Object
Generate random high ascii characters avoiding the exploit's bad characters.
-
#rand_text_numeric(length, bad = payload_badchars) ⇒ Object
Generate random numeric characters avoiding the exploit's bad characters.
-
#regenerate_payload(platform = nil, arch = nil, explicit_target = nil) ⇒ Object
(also: #exploit_regenerate_payload)
Re-generates an encoded payload, typically called after something in the datastore has changed.
-
#register_autofilter_ports(ports = []) ⇒ Object
Adds a port into the list of ports.
- #register_autofilter_services(services = []) ⇒ Object
-
#reset_session_counts ⇒ Object
Reset the session counter to zero (which occurs during set up of the exploit prior to calling exploit).
-
#session_created? ⇒ Boolean
A boolean for whether a session has been created yet.
-
#setup ⇒ Object
Prepares the module for exploitation, initializes any state, and starts the payload handler.
- #setup_fail_detail_from_exception(e) ⇒ Object
-
#stack_adjustment ⇒ Object
This method returns the encoded instruction(s) required to adjust the stack pointer prior to executing any code.
-
#stance ⇒ Object
Generally, all exploits take an aggressive stance.
-
#target ⇒ Object
Returns the active target for this exploit.
-
#target_arch ⇒ Object
Returns the target's architecture, or the one assigned to the module itself.
-
#target_index ⇒ Object
The target index that has been selected.
-
#target_platform ⇒ Object
Returns the target's platform, or the one assigned to the module itself.
-
#type ⇒ Object
Returns MODULE_EXPLOIT to indicate that this is an exploit module.
-
#wfs_delay ⇒ Object
The minimum "wait for session" delay is 3 seconds for all exploits, the WfsDelay configuration option is added on top of this.
Constructor Details
#initialize(info = {}) ⇒ Exploit
Creates an instance of the exploit module. Mad skillz.
249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 |
# File 'lib/msf/core/exploit.rb', line 249 def initialize(info = {}) # Ghetto compat mirroring for payload compatibilities. This mirrors # # Payload => Compat => xyz # # to # # Compat => Payload => xyz if (info['Payload'] and info['Payload']['Compat']) info['Compat'] = Hash.new if (info['Compat'] == nil) info['Compat']['Payload'] = Hash.new if (info['Compat']['Payload'] == nil) info['Compat']['Payload'].update(info['Payload']['Compat']) end # Call the parent constructor after making any necessary modifications # to the information hash. super(info) if info.key? 'DefaultTarget' self.default_target = info['DefaultTarget'] else self.default_target = 0 # Add an auto-target to the exploit if it doesn't have one if info['Targets'] && info['Targets'].count > 1 && !has_auto_target?(info['Targets']) # Finally, only add the target if there is a remote host option if self.respond_to?(:rhost) && self.respond_to?(:auto_targeted_index) auto = ["Automatic", {'AutoGenerated' => true}.merge(info['Targets'][self.default_target][1])] info['Targets'].unshift(auto) end end end self.targets = Rex::Transformer.transform(info['Targets'], Array, [ Target ], 'Targets') self.payload_info = info['Payload'] || {} self.successful = false self.session_count = 0 self.active_timeout = 120 self.fail_reason = Msf::Exploit::Failure::None if (info['Payload'] and info['Payload']['ActiveTimeout']) self.active_timeout = info['Payload']['ActiveTimeout'].to_i end # Initialize exploit datastore with target information import_target_defaults # All exploits can increase the delay when waiting for a session. # However, this only applies to aggressive exploits. if aggressive? ( [ OptInt.new('WfsDelay', [ false, "Additional delay in seconds to wait for a session", 2 ]) ], Msf::Exploit) end ( [ # Allow all exploits to leverage context keyed encoding OptBool.new('EnableContextEncoding', [ false, "Use transient context when encoding payloads", false ]), OptPath.new('ContextInformationFile', [ false, "The information file that contains context information", nil ]), # Allow all exploits to disable their payload handlers OptBool.new('DisablePayloadHandler', [ false, "Disable the handler code for the selected payload", false ]) ], Msf::Exploit) end |
Instance Attribute Details
#active_timeout ⇒ Object (protected)
Maximum number of seconds for active handlers
1589 1590 1591 |
# File 'lib/msf/core/exploit.rb', line 1589 def active_timeout @active_timeout end |
#default_target ⇒ Object
The default target.
1542 1543 1544 |
# File 'lib/msf/core/exploit.rb', line 1542 def default_target @default_target end |
#fail_detail ⇒ Object
Detailed exception string indicating why the exploit was not successful
1517 1518 1519 |
# File 'lib/msf/core/exploit.rb', line 1517 def fail_detail @fail_detail end |
#fail_message ⇒ Object
A formatted, human-readable failure message describing why the exploit
was not successful. Populated by #handle_exception with the same string
that is printed to the operator's console, so that non-console consumers
(RPC/MCP job listeners, logs) can surface an identical description
without having to intercept user_output.
1526 1527 1528 |
# File 'lib/msf/core/exploit.rb', line 1526 def @fail_message end |
#fail_reason ⇒ Object
The reason why the exploit was not successful (one of Msf::Module::Failure)
1512 1513 1514 |
# File 'lib/msf/core/exploit.rb', line 1512 def fail_reason @fail_reason end |
#last_vuln_attempt ⇒ Object
The VulnAttempt object created during this run, or nil/false if none was recorded. Used to prevent duplicate attempts when report_failure is called later and to enrich the attempt with check code details.
1533 1534 1535 |
# File 'lib/msf/core/exploit.rb', line 1533 def last_vuln_attempt @last_vuln_attempt end |
#needs_cleanup ⇒ Object
Returns the value of attribute needs_cleanup.
244 245 246 |
# File 'lib/msf/core/exploit.rb', line 244 def needs_cleanup @needs_cleanup end |
#payload ⇒ Object
The encoded payload instance. An instance of an EncodedPayload object.
1555 1556 1557 |
# File 'lib/msf/core/exploit.rb', line 1555 def payload @payload end |
#payload_info ⇒ Object
The payload requirement hash.
1546 1547 1548 |
# File 'lib/msf/core/exploit.rb', line 1546 def payload_info @payload_info end |
#payload_instance ⇒ Object
The active payload instance.
1550 1551 1552 |
# File 'lib/msf/core/exploit.rb', line 1550 def payload_instance @payload_instance end |
#session_count ⇒ Object
The number of active sessions created by this instance
1560 1561 1562 |
# File 'lib/msf/core/exploit.rb', line 1560 def session_count @session_count end |
#successful ⇒ Object
The boolean indicating whether the exploit succeeded
1565 1566 1567 |
# File 'lib/msf/core/exploit.rb', line 1565 def successful @successful end |
#targets ⇒ Object
The list of targets.
1538 1539 1540 |
# File 'lib/msf/core/exploit.rb', line 1538 def targets @targets end |
Class Method Details
.mixins ⇒ Array
Returns an array of all of the exploit mixins. Lame algorithm right now. We search the Msf::Exploit namespace for all modules that do not have any constants in them. In the future we can replace this with a better algorithm. It's just important that it returns an array of all of the mixin modules.
212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 |
# File 'lib/msf/core/exploit.rb', line 212 def self.mixins mixins = [] wl = [ Msf::Exploit ] visited = {} until wl.length == 0 wl.delete_if { |mod| mod.constants.each { |const| child = mod.const_get(const) next if child.to_s !~ /^Msf::Exploit/ next if visited[child] next if child.kind_of?(::Module) == false visited[child] = true if child.constants.length > 0 wl << child else mixins << child end } true } end return mixins end |
.type ⇒ Object
Returns MODULE_EXPLOIT to indicate that this is an exploit module.
604 605 606 |
# File 'lib/msf/core/exploit.rb', line 604 def self.type Msf::MODULE_EXPLOIT end |
Instance Method Details
#add_handler(opts = {}) ⇒ Object
Allows the payload handler to spawn a new monitor
471 472 473 474 475 |
# File 'lib/msf/core/exploit.rb', line 471 def add_handler(opts={}) return if not payload_instance return if not handler_enabled? payload_instance.add_handler(opts) end |
#aggressive? ⇒ Boolean
Returns true if the exploit has an aggressive stance.
632 633 634 |
# File 'lib/msf/core/exploit.rb', line 632 def aggressive? stance.include?(Stance::Aggressive) end |
#autofilter ⇒ Object
Performs last-minute sanity checking of exploit parameters. This method is called during automated exploitation attempts and allows an exploit to filter bad targets, obtain more information, and choose better targets based on the available data. Returning anything that evaluates to "false" will cause this specific exploit attempt to be skipped. This method can and will change datastore values and may interact with the backend database.
353 354 355 |
# File 'lib/msf/core/exploit.rb', line 353 def autofilter true end |
#autofilter_ports ⇒ Object
Provides a list of ports that can be used for matching this module against target systems.
361 362 363 |
# File 'lib/msf/core/exploit.rb', line 361 def autofilter_ports @autofilter_ports || [] end |
#autofilter_services ⇒ Object
Provides a list of services that can be used for matching this module against target systems.
369 370 371 |
# File 'lib/msf/core/exploit.rb', line 369 def autofilter_services @autofilter_services || [] end |
#cleanup ⇒ Object
Performs any cleanup that may be necessary, such as disconnecting connections and any other such fun things. If a payload is active then its handler cleanup routines are called as well.
423 424 425 426 427 428 |
# File 'lib/msf/core/exploit.rb', line 423 def cleanup if (payload_instance and handler_enabled?) payload_instance.cleanup_handler end self.abort_sockets if self.respond_to?(:abort_sockets) end |
#compatible_encoders ⇒ Object
Returns a list of compatible encoders based on architecture
767 768 769 770 771 772 773 774 775 776 777 778 |
# File 'lib/msf/core/exploit.rb', line 767 def compatible_encoders encoders = [] c_platform, c_arch = normalize_platform_arch framework.encoders.each_module_ranked( 'Arch' => c_arch, 'Platform' => c_platform) { |name, mod| encoders << [ name, mod ] } return encoders; end |
#compatible_payloads(excluded_platforms: [], excluded_archs: []) ⇒ Object
Returns a list of compatible payloads based on platform, architecture, and size requirements.
743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 |
# File 'lib/msf/core/exploit.rb', line 743 def compatible_payloads(excluded_platforms: [], excluded_archs: []) payloads = [] c_platform, c_arch = normalize_platform_arch # The "All" platform name represents generic payloads results = Msf::Modules::Metadata::Cache.instance.find( 'type' => [['payload'], []], 'platform' => [[*c_platform.names, 'All'], excluded_platforms], 'arch' => [c_arch, excluded_archs] ) results.each do |res| if is_payload_compatible?(res.ref_name) payloads << [res.ref_name, framework.payloads[res.ref_name]] end end payloads end |
#define_context_encoding_reqs(reqs) ⇒ Object (protected)
Gets the memory map file and other context information that is required when wanting to support context keyed encoding
1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 |
# File 'lib/msf/core/exploit.rb', line 1626 def define_context_encoding_reqs(reqs) return unless datastore['EnableContextEncoding'] # At present, we don't support any automatic methods of obtaining # context information. In the future, we might support obtaining # temporal information remotely. # Pass along the information specified in our exploit datastore as # encoder options reqs['EncoderOptions'] = {} if reqs['EncoderOptions'].nil? reqs['EncoderOptions']['EnableContextEncoding'] = datastore['EnableContextEncoding'] reqs['EncoderOptions']['ContextInformationFile'] = datastore['ContextInformationFile'] end |
#encode_begin(real_payload, reqs) ⇒ Object
Called prior to encoding a payload.
582 583 |
# File 'lib/msf/core/exploit.rb', line 582 def encode_begin(real_payload, reqs) end |
#encode_end(real_payload, reqs, encoded) ⇒ Object
Called after an encoded payload has been generated. This gives exploits or mixins a chance to alter the encoded payload.
589 590 591 |
# File 'lib/msf/core/exploit.rb', line 589 def encode_end(real_payload, reqs, encoded) encoded end |
#encode_shellcode_stub(code, badchars = payload_badchars) ⇒ Object
Allows arbitrary shellcode to be encoded from within an exploit
452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 |
# File 'lib/msf/core/exploit.rb', line 452 def encode_shellcode_stub(code, badchars=payload_badchars) platform = self.platform if(self.payload_instance) self.payload_instance.platform end compatible_encoders.each do |name, mod| begin enc = framework.encoders.create(name) raw = enc.encode(code, badchars, nil, platform) return raw if raw rescue ::Exception end end nil end |
#exploit ⇒ Object
Kicks off the actual exploit. Prior to this call, the framework will have validated the data store using the options associated with this exploit module. It will also pre-generate the desired payload, though exploits can re-generate the payload if necessary.
This method is designed to be overridden by exploit modules.
341 342 |
# File 'lib/msf/core/exploit.rb', line 341 def exploit end |
#exploit_type ⇒ Object
If we don't know the exploit type, then I guess it's omnipresent!
618 619 620 |
# File 'lib/msf/core/exploit.rb', line 618 def exploit_type Type::Omni end |
#fail_with(reason, msg = nil) ⇒ void
This method returns an undefined value.
Raises a Msf::Exploit::Failed exception. It overrides the fail_with method in lib/msf/core/module.rb
1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 |
# File 'lib/msf/core/exploit.rb', line 1360 def fail_with(reason,msg=nil) # The reason being registered here will be used later on, so it's important we don't actually # provide a made-up one. allowed_values = Msf::Module::Failure.constants.collect {|e| Msf::Module::Failure.const_get(e)} if allowed_values.include?(reason) self.fail_reason = reason else self.fail_reason = Msf::Module::Failure::Unknown end self.fail_detail = msg raise Msf::Exploit::Failed, (msg || "No failure message given") end |
#generate_payload(pinst = nil) ⇒ Object
Generates the encoded version of the supplied payload using the payload requirements specific to this exploit. The encoded instance is returned to the caller. This method is exposed in the manner that it is such that passive exploits and re-generate an encoded payload on the fly rather than having to use the pre-generated one.
The return value is an EncodedPayload instance.
439 440 441 442 443 444 445 446 447 |
# File 'lib/msf/core/exploit.rb', line 439 def generate_payload(pinst = nil) # Set the encoded payload to the result of the encoding process self.payload = generate_single_payload(pinst) # Save the payload instance self.payload_instance = (pinst) ? pinst : self.payload_instance return self.payload end |
#generate_single_payload(pinst = nil, platform = nil, arch = nil, explicit_target = nil) ⇒ Object
This method generates a non-cached payload which is typically useful for passive exploits that will have more than one client.
481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 |
# File 'lib/msf/core/exploit.rb', line 481 def generate_single_payload(pinst = nil, platform = nil, arch = nil, explicit_target = nil) explicit_target ||= target if (explicit_target == nil) raise MissingTargetError, "No target has been specified.", caller end # If a payload instance was supplied, use it, otherwise # use the active payload instance real_payload = (pinst) ? pinst : self.payload_instance if (real_payload == nil) raise MissingPayloadError, "No payload has been selected.", caller end # If this is a generic payload, then we should specify the platform # and architecture so that it knows how to pass things on. if real_payload.kind_of?(Msf::Payload::Generic) # Convert the architecture specified into an array. if arch and arch.kind_of?(String) arch = [ arch ] end # Define the explicit platform and architecture information only if # it's been specified. if platform real_payload.explicit_platform = Msf::Module::PlatformList.transform(platform) end if arch real_payload.explicit_arch = arch end # Force it to reset so that it will find updated information. real_payload.reset end # Duplicate the exploit payload requirements reqs = self.payload_info.dup # Pass save register requirements to the NOP generator reqs['Space'] = payload_space(explicit_target) reqs['SaveRegisters'] = nop_save_registers(explicit_target) reqs['Prepend'] = payload_prepend(explicit_target) reqs['PrependEncoder'] = payload_prepend_encoder(explicit_target) reqs['BadChars'] = payload_badchars(explicit_target) reqs['Append'] = payload_append(explicit_target) reqs['AppendEncoder'] = payload_append_encoder(explicit_target) reqs['DisableNops'] = payload_disable_nops(explicit_target) reqs['MaxNops'] = payload_max_nops(explicit_target) reqs['MinNops'] = payload_min_nops(explicit_target) reqs['Encoder'] = datastore['ENCODER'] || payload_encoder(explicit_target) reqs['Nop'] = datastore['NOP'] || payload_nop(explicit_target) reqs['EncoderType'] = payload_encoder_type(explicit_target) reqs['EncoderOptions'] = (explicit_target) reqs['ExtendedOptions'] = (explicit_target) reqs['Exploit'] = self # Pass along the encoder don't fall through flag reqs['EncoderDontFallThrough'] = datastore['EncoderDontFallThrough'] # Incorporate any context encoding requirements that are needed define_context_encoding_reqs(reqs) # For generic payloads, constrain encoder (and NOP) module selection to the # architecture and platform of the concrete payload that was resolved above. # Without this, EncodedPayload#compatible_encoders falls back to the generic # payload's ARCH_ALL and considers encoders for every architecture. An # arch-inappropriate encoder (e.g. riscv64le/byte_xori applied to x86 # shellcode) can then spin effectively forever brute-forcing a key that # avoids the exploit's bad characters. if real_payload.is_a?(Msf::Payload::Generic) reqs['Arch'] ||= real_payload.resolved_arch reqs['Platform'] ||= real_payload.resolved_platform end # Call the encode begin routine. encode_begin(real_payload, reqs) # Generate the encoded payload. encoded = EncodedPayload.create(real_payload, reqs) # Call the encode end routine which is expected to return the actual # encoded payload instance. return encode_end(real_payload, reqs, encoded) end |
#handle_exception(e) ⇒ Object
Handle the exception
1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 |
# File 'lib/msf/core/exploit.rb', line 1391 def handle_exception e msg = setup_fail_detail_from_exception e case e when Msf::Exploit::Complete # Nothing to show in this case return when Msf::OptionValidateError self.fail_reason = Msf::Exploit::Failure::BadConfig # The multi-line per-option formatter is emitted to the console; a # single-line summary is stashed on the module for non-console # consumers (RPC/MCP job listeners, log aggregators, etc.). self. = "Exploit aborted due to failure: #{self.fail_reason}: #{msg}" ::Msf::Ui::Formatter::OptionValidateError.print_error(self, e) elog("Exploit failed (#{self.refname}): #{msg}", error: e) when Msf::Exploit::Failed self. = "Exploit aborted due to failure: #{self.fail_reason}: #{msg}" self.print_error(self.) # The caller should have already set self.fail_reason if self.fail_reason == Msf::Exploit::Failure::None self.fail_reason = Msf::Exploit::Failure::Unknown end when Rex::ConnectionError self.fail_reason = Msf::Exploit::Failure::Unreachable self. = "Exploit failed [#{self.fail_reason}]: #{msg}" self.print_error(self.) elog("Exploit failed (#{self.refname}): #{msg}", error: e) when Rex::BindFailed self.fail_reason = Msf::Exploit::Failure::BadConfig self. = "Exploit failed [#{self.fail_reason}]: #{msg}" self.print_error(self.) elog("Exploit failed (#{self.refname}): #{msg}", error: e) when Timeout::Error self.fail_reason = Msf::Exploit::Failure::TimeoutExpired self. = "Exploit failed [#{self.fail_reason}]: #{msg}" self.print_error(self.) elog("Exploit failed (#{self.refname}): #{msg}", error: e) when ::Interrupt self.fail_reason = Msf::Exploit::Failure::UserInterrupt self. = "Exploit failed [#{self.fail_reason}]: #{msg}" self.print_error(self.) elog("Exploit failed (#{self.refname}): #{msg}", error: e) else # Compare as a string since not all error classes may be loaded case msg when /access.denied|Login Failed/i # Covers SMB as well as some generic errors self.fail_reason = Msf::Exploit::Failure::NoAccess when /connection reset/i self.fail_reason = Msf::Exploit::Failure::Disconnected when /connection timed out|SSL_connect|unreachable|connection was refused/i self.fail_reason = Msf::Exploit::Failure::Unreachable when /unable.*target/i self.fail_reason = Msf::Exploit::Failure::NoTarget when /execution expired/i self.fail_reason = Msf::Exploit::Failure::TimeoutExpired when /(doesn.t|not).*vulnerable|may.*patched/i self.fail_reason = Msf::Exploit::Failure::NotVulnerable end # The caller should have already set self.fail_reason if self.fail_reason == Msf::Exploit::Failure::None self.fail_reason = Msf::Exploit::Failure::Unknown end self. = if self.fail_reason == Msf::Exploit::Failure::Unknown "Exploit failed: #{msg}" else "Exploit failed [#{self.fail_reason}]: #{msg}" end self.print_error(self.) elog("Exploit failed (#{self.refname}): #{msg}", error: e) end # Record the error to various places self.framework.events.on_module_error(self, msg) # Report the failure (and attempt) in the database self.report_failure # Interrupt any session waiters in the handler self.interrupt_handler return self.fail_reason end |
#handler(*args) ⇒ Object
Passes the connection to the associated payload handler to see if the exploit succeeded and a connection has been established. The return value can be one of the Handler::constants.
1298 1299 1300 1301 1302 |
# File 'lib/msf/core/exploit.rb', line 1298 def handler(*args) if payload_instance && handler_enabled? payload_instance.handler(*args) end end |
#handler_bind? ⇒ Boolean
If the payload uses a bind handler
1283 1284 1285 |
# File 'lib/msf/core/exploit.rb', line 1283 def handler_bind? payload_instance && payload_instance.connection_type == 'bind' end |
#handler_enabled? ⇒ Boolean
Allow the user to disable the payload handler
1276 1277 1278 |
# File 'lib/msf/core/exploit.rb', line 1276 def handler_enabled? !datastore['DisablePayloadHandler'] end |
#has_auto_target?(targets = []) ⇒ Boolean
315 316 317 318 319 320 321 |
# File 'lib/msf/core/exploit.rb', line 315 def has_auto_target?(targets=[]) target_names = targets.collect { |target| target.first} target_names.each do |target| return true if target =~ /Automatic/ end return false end |
#init_compat ⇒ Object (protected)
Overrides the base class method and serves to initialize default compatibilities for exploits
1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 |
# File 'lib/msf/core/exploit.rb', line 1601 def init_compat super # # Merge in payload compatible defaults # p = module_info['Compat']['Payload'] CompatDefaults::Payload.each_pair { |k,v| p[k] = p[k] ? "#{p[k]} #{v}" : v } # # Set the default save registers if none have been explicitly # specified. # if (module_info['SaveRegisters'] == nil) module_info['SaveRegisters'] = [ 'esp', 'ebp' ] end end |
#interrupt_handler ⇒ Object
1304 1305 1306 1307 1308 |
# File 'lib/msf/core/exploit.rb', line 1304 def interrupt_handler if payload_instance && handler_enabled? && payload_instance.respond_to?(:interrupt_wait_for_session) payload_instance.interrupt_wait_for_session() end end |
#is_payload_compatible?(name) ⇒ Boolean
Returns whether the requested payload is compatible with the module.
716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 |
# File 'lib/msf/core/exploit.rb', line 716 def is_payload_compatible?(name) p = framework.payloads[name] return false unless p # Skip over payloads that are too big return false if payload_space && p.cached_size && p.cached_size > payload_space begin pi = p.new rescue ::Exception, ::LoadError => e wlog("Module #{name} failed to initialize payload when checking exploit compatibility: #{e}", 'core', LEV_0) return false end # Are we compatible in terms of conventions and connections and # what not? return false if !compatible?(pi) # If the payload is privileged but the exploit does not give # privileged access, then fail it. return false if !self.privileged && pi.privileged return true end |
#make_fast_nops(count) ⇒ String
Generates a NOP sled using the #make_nops method. The difference between this and #make_nops is this method is much faster, good for exploit developers that actually want huge chunks of NOPs. The downside of using this is the NOP sled is less randomized.
1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 |
# File 'lib/msf/core/exploit.rb', line 1065 def make_fast_nops(count) max_nop_chunk_size = 100 if count < max_nop_chunk_size return make_nops(count) end nops = make_nops(max_nop_chunk_size) nops += nops while nops.length < count nops[0, count] end |
#make_nops(count) ⇒ Object
Generates a nop sled of a supplied length and returns it to the caller.
1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 |
# File 'lib/msf/core/exploit.rb', line 1082 def make_nops(count) # If we're debugging, then make_nops will return a safe sled. We # currently assume x86. if debugging? return "\x90" * count end nop_sled = nil # If there is no payload instance then we can't succeed. return nil if (!payload_instance) payload_instance.compatible_nops.each { |nopname, nopmod| # Create an instance of the nop module nop = nopmod.new # The list of save registers save_regs = nop_save_registers || [] if (save_regs.empty? == true) save_regs = nil end begin nop.copy_ui(self) nop_sled = nop.generate_sled(count, 'BadChars' => payload_badchars || '', 'SaveRegisters' => save_regs) if nop_sled && nop_sled.length == count break else wlog("#{self.refname}: Nop generator #{nop.refname} failed to generate sled for exploit", 'core', LEV_0) end rescue wlog("#{self.refname}: Nop generator #{nop.refname} failed to generate sled for exploit: #{$!}", 'core', LEV_0) end } nop_sled end |
#nop_generator ⇒ Object
Returns the first compatible NOP generator for this exploit's payload instance.
1047 1048 1049 1050 1051 1052 1053 |
# File 'lib/msf/core/exploit.rb', line 1047 def nop_generator return nil if (!payload_instance) payload_instance.compatible_nops.each { |nopname, nopmod| return nopmod.new } end |
#nop_save_registers(explicit_target = nil) ⇒ Object
Returns the list of registers that the NOP generator should save, if any. It will use the current target's save registers in precedence over those defined globally for the exploit module.
If there are no save registers, nil is returned.
1033 1034 1035 1036 1037 1038 1039 1040 1041 |
# File 'lib/msf/core/exploit.rb', line 1033 def nop_save_registers(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.save_registers) return explicit_target.save_registers else return module_info['SaveRegisters'] end end |
#normalize_platform_arch ⇒ Object
703 704 705 706 707 708 |
# File 'lib/msf/core/exploit.rb', line 703 def normalize_platform_arch c_platform = (target && target.platform) ? target.platform : platform c_arch = (target && target.arch) ? target.arch : (arch == []) ? nil : arch c_arch ||= [ ARCH_X86 ] return c_platform, c_arch end |
#on_new_session(session) ⇒ Object
This is called by the payload when a new session is created
1319 1320 1321 1322 |
# File 'lib/msf/core/exploit.rb', line 1319 def on_new_session(session) self.session_count += 1 self.successful = true end |
#passive? ⇒ Boolean
Returns if the exploit has a passive stance. Aggressive exploits are always aggressive.
639 640 641 |
# File 'lib/msf/core/exploit.rb', line 639 def passive? stance.include?(Stance::Passive) && !stance.include?(Stance::Aggressive) end |
#pattern_create(length, sets = nil) ⇒ Object
Generate a non-repeating static random string
1260 1261 1262 |
# File 'lib/msf/core/exploit.rb', line 1260 def pattern_create(length, sets = nil) Rex::Text.pattern_create(length, sets) end |
#payload_append(explicit_target = nil) ⇒ Object
Return any text that should be appended to the payload. The payload module is passed so that the exploit can take a guess at architecture and platform if it's a multi exploit.
832 833 834 835 836 837 838 839 840 |
# File 'lib/msf/core/exploit.rb', line 832 def payload_append(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_append) explicit_target.payload_append else payload_info['Append'] || '' end end |
#payload_append_encoder(explicit_target = nil) ⇒ Object
Return any text that should be appended to the encoder of the payload. The payload module is passed so that the exploit can take a guess at architecture and platform if it's a multi exploit.
864 865 866 867 868 869 870 871 872 873 874 |
# File 'lib/msf/core/exploit.rb', line 864 def payload_append_encoder(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_append_encoder) p = explicit_target.payload_append_encoder else p = payload_info['AppendEncoder'] || '' end p end |
#payload_badchars(explicit_target = nil) ⇒ Object
Returns the bad characters that cannot be in any payload used by this exploit.
936 937 938 939 940 941 942 943 944 |
# File 'lib/msf/core/exploit.rb', line 936 def payload_badchars(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_badchars) explicit_target.payload_badchars else payload_info['BadChars'] end end |
#payload_disable_nops(explicit_target = nil) ⇒ Object
Whether NOP generation should be enabled or disabled
879 880 881 882 883 884 885 886 887 |
# File 'lib/msf/core/exploit.rb', line 879 def payload_disable_nops(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_disable_nops) explicit_target.payload_disable_nops else payload_info['DisableNops'] end end |
#payload_encoder(explicit_target = nil) ⇒ Object
Returns the payload encoder that is associated with either the current target or the exploit in general.
950 951 952 953 954 955 956 957 958 |
# File 'lib/msf/core/exploit.rb', line 950 def payload_encoder(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_encoder) explicit_target.payload_encoder else payload_info['Encoder'] end end |
#payload_encoder_options(explicit_target = nil) ⇒ Object
Returns the payload encoder option hash that is used to initialize the datastore of the encoder that is selected when generating an encoded payload.
993 994 995 996 997 998 999 1000 1001 |
# File 'lib/msf/core/exploit.rb', line 993 def (explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.) explicit_target. else payload_info['EncoderOptions'] end end |
#payload_encoder_type(explicit_target = nil) ⇒ Object
Returns the payload encoder type that is associated with either the current target or the exploit in general.
978 979 980 981 982 983 984 985 986 |
# File 'lib/msf/core/exploit.rb', line 978 def payload_encoder_type(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_encoder_type) explicit_target.payload_encoder_type else payload_info['EncoderType'] end end |
#payload_extended_options(explicit_target = nil) ⇒ Object
Returns the payload extended options hash which is used to provide a location to store extended information that may be useful to a particular type of payload or mixin.
1008 1009 1010 1011 1012 1013 1014 1015 1016 |
# File 'lib/msf/core/exploit.rb', line 1008 def (explicit_target = nil) explicit_target ||= target if explicit_target and explicit_target. explicit_target. else payload_info['ExtendedOptions'] end end |
#payload_max_nops(explicit_target = nil) ⇒ Object
Maximum number of nops to use as a hint to the framework. Nil signifies that the framework should decide.
893 894 895 896 897 898 899 900 901 |
# File 'lib/msf/core/exploit.rb', line 893 def payload_max_nops(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_max_nops) explicit_target.payload_max_nops else payload_info['MaxNops'] || nil end end |
#payload_min_nops(explicit_target = nil) ⇒ Object
Minimum number of nops to use as a hint to the framework. Nil signifies that the framework should decide.
907 908 909 910 911 912 913 914 915 |
# File 'lib/msf/core/exploit.rb', line 907 def payload_min_nops(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_min_nops) explicit_target.payload_min_nops else payload_info['MinNops'] || nil end end |
#payload_nop(explicit_target = nil) ⇒ Object
Returns the payload NOP generator that is associated with either the current target or the exploit in general.
964 965 966 967 968 969 970 971 972 |
# File 'lib/msf/core/exploit.rb', line 964 def payload_nop(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_nop) explicit_target.payload_nop else payload_info['Nop'] end end |
#payload_prepend(explicit_target = nil) ⇒ Object
Return any text that should be prepended to the payload. The payload module is passed so that the exploit can take a guess at architecture and platform if it's a multi exploit. This automatically takes into account any require stack adjustments.
815 816 817 818 819 820 821 822 823 824 825 |
# File 'lib/msf/core/exploit.rb', line 815 def payload_prepend(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_prepend) p = explicit_target.payload_prepend else p = payload_info['Prepend'] || '' end stack_adjustment + p end |
#payload_prepend_encoder(explicit_target = nil) ⇒ Object
Return any text that should be prepended to the encoder of the payload. The payload module is passed so that the exploit can take a guess at architecture and platform if it's a multi exploit.
847 848 849 850 851 852 853 854 855 856 857 |
# File 'lib/msf/core/exploit.rb', line 847 def payload_prepend_encoder(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_prepend_encoder) p = explicit_target.payload_prepend_encoder else p = payload_info['PrependEncoder'] || '' end p end |
#payload_space(explicit_target = nil) ⇒ Object
Returns the maximum amount of room the exploit has for a payload.
920 921 922 923 924 925 926 927 928 929 930 |
# File 'lib/msf/core/exploit.rb', line 920 def payload_space(explicit_target = nil) explicit_target ||= target if (explicit_target and explicit_target.payload_space) explicit_target.payload_space elsif (payload_info['Space']) payload_info['Space'].to_i else nil end end |
#rand_char(bad = payload_badchars) ⇒ Object
Generate a random character avoiding the exploit's bad characters.
1249 1250 1251 1252 1253 1254 1255 |
# File 'lib/msf/core/exploit.rb', line 1249 def rand_char(bad=payload_badchars) if debugging? "A" else Rex::Text.rand_char(bad) end end |
#rand_text(length, bad = payload_badchars) ⇒ Object
Generate random text characters avoiding the exploit's bad characters.
1141 1142 1143 1144 1145 1146 1147 |
# File 'lib/msf/core/exploit.rb', line 1141 def rand_text(length, bad=payload_badchars) if debugging? rand_text_debug(length) else Rex::Text.rand_text(length, bad) end end |
#rand_text_alpha(length, bad = payload_badchars) ⇒ Object
Generate random alpha characters avoiding the exploit's bad characters.
1177 1178 1179 1180 1181 1182 1183 |
# File 'lib/msf/core/exploit.rb', line 1177 def rand_text_alpha(length, bad=payload_badchars) if debugging? rand_text_debug(length) else Rex::Text.rand_text_alpha(length, bad) end end |
#rand_text_alpha_lower(length, bad = payload_badchars) ⇒ Object
Generate random alpha lower characters avoiding the exploit's bad characters.
1201 1202 1203 1204 1205 1206 1207 |
# File 'lib/msf/core/exploit.rb', line 1201 def rand_text_alpha_lower(length, bad=payload_badchars) if debugging? rand_text_debug(length, 'a') else Rex::Text.rand_text_alpha_lower(length, bad) end end |
#rand_text_alpha_upper(length, bad = payload_badchars) ⇒ Object
Generate random alpha upper characters avoiding the exploit's bad characters.
1189 1190 1191 1192 1193 1194 1195 |
# File 'lib/msf/core/exploit.rb', line 1189 def rand_text_alpha_upper(length, bad=payload_badchars) if debugging? rand_text_debug(length) else Rex::Text.rand_text_alpha_upper(length, bad) end end |
#rand_text_alphanumeric(length, bad = payload_badchars) ⇒ Object
Generate random alphanumeric characters avoiding the exploit's bad characters.
1213 1214 1215 1216 1217 1218 1219 |
# File 'lib/msf/core/exploit.rb', line 1213 def rand_text_alphanumeric(length, bad=payload_badchars) if debugging? rand_text_debug(length) else Rex::Text.rand_text_alphanumeric(length, bad) end end |
#rand_text_debug(length, char = 'A') ⇒ Object
Utility methods for generating random text that implicitly uses the exploit's bad character set.
1133 1134 1135 |
# File 'lib/msf/core/exploit.rb', line 1133 def rand_text_debug(length, char = 'A') char * (length.kind_of?(Range) ? length.first : length) end |
#rand_text_english(length, bad = payload_badchars) ⇒ Object
Generate random english-like avoiding the exploit's bad characters.
1153 1154 1155 1156 1157 1158 1159 |
# File 'lib/msf/core/exploit.rb', line 1153 def rand_text_english(length, bad=payload_badchars) if debugging? rand_text_debug(length) else Rex::Text.rand_text_english(length, bad) end end |
#rand_text_hex(length, bad = payload_badchars) ⇒ Object
Generate random hexadecimal characters avoiding the exploit's bad characters.
1237 1238 1239 1240 1241 1242 1243 |
# File 'lib/msf/core/exploit.rb', line 1237 def rand_text_hex(length, bad=payload_badchars) if debugging? rand_text_debug(length, '0') else Rex::Text.rand_text_hex(length, bad) end end |
#rand_text_highascii(length, bad = payload_badchars) ⇒ Object
Generate random high ascii characters avoiding the exploit's bad characters.
1165 1166 1167 1168 1169 1170 1171 |
# File 'lib/msf/core/exploit.rb', line 1165 def rand_text_highascii(length, bad=payload_badchars) if debugging? rand_text_debug(length) else Rex::Text.rand_text_highascii(length, bad) end end |
#rand_text_numeric(length, bad = payload_badchars) ⇒ Object
Generate random numeric characters avoiding the exploit's bad characters.
1225 1226 1227 1228 1229 1230 1231 |
# File 'lib/msf/core/exploit.rb', line 1225 def rand_text_numeric(length, bad=payload_badchars) if debugging? rand_text_debug(length, '0') else Rex::Text.rand_text_numeric(length, bad) end end |
#regenerate_payload(platform = nil, arch = nil, explicit_target = nil) ⇒ Object Also known as: exploit_regenerate_payload
Re-generates an encoded payload, typically called after something in the datastore has changed. An optional platform and architecture can be supplied as well.
575 576 577 |
# File 'lib/msf/core/exploit.rb', line 575 def regenerate_payload(platform = nil, arch = nil, explicit_target = nil) generate_single_payload(nil, platform, arch, explicit_target) end |
#register_autofilter_ports(ports = []) ⇒ Object
Adds a port into the list of ports
376 377 378 379 380 381 |
# File 'lib/msf/core/exploit.rb', line 376 def register_autofilter_ports(ports=[]) @autofilter_ports ||= [] @autofilter_ports << ports @autofilter_ports.flatten! @autofilter_ports.uniq! end |
#register_autofilter_services(services = []) ⇒ Object
383 384 385 386 387 388 |
# File 'lib/msf/core/exploit.rb', line 383 def register_autofilter_services(services=[]) @autofilter_services ||= [] @autofilter_services << services @autofilter_services.flatten! @autofilter_services.uniq! end |
#reset_session_counts ⇒ Object
Reset the session counter to zero (which occurs during set up of the exploit prior to calling exploit).
1338 1339 1340 |
# File 'lib/msf/core/exploit.rb', line 1338 def reset_session_counts self.session_count = 0 end |
#session_created? ⇒ Boolean
A boolean for whether a session has been created yet
1327 1328 1329 1330 1331 1332 |
# File 'lib/msf/core/exploit.rb', line 1327 def session_created? # Start bind handlers before checking session creation payload_instance.start_handler if handler_bind? (self.session_count > 0) ? true : false end |
#setup ⇒ Object
Prepares the module for exploitation, initializes any state, and starts the payload handler.
394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 |
# File 'lib/msf/core/exploit.rb', line 394 def setup alert_user # Reset the session counts to zero. reset_session_counts return if not payload_instance return if not handler_enabled? # Configure the payload handler payload_instance.exploit_config = { 'active_timeout' => self.active_timeout } # Set up the payload handlers payload_instance.setup_handler # Defer starting bind handlers until after exploit completion return if handler_bind? # Start the payload handler payload_instance.start_handler end |
#setup_fail_detail_from_exception(e) ⇒ Object
1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 |
# File 'lib/msf/core/exploit.rb', line 1374 def setup_fail_detail_from_exception e # Build a user-friendly error message msg = "#{e}" unless e.class == Msf::Exploit::Failed msg = "#{e.class} #{e}" end self.error = e # Record the detailed reason self.fail_detail ||= e.to_s msg end |
#stack_adjustment ⇒ Object
This method returns the encoded instruction(s) required to adjust the stack pointer prior to executing any code. The number of bytes to adjust is indicated to the routine through the payload 'StackAdjustment' attribute or through a target's payload 'StackAdjustment' attribute.
786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 |
# File 'lib/msf/core/exploit.rb', line 786 def stack_adjustment if target && target.payload_stack_adjustment adj = target.payload_stack_adjustment else adj = payload_info['StackAdjustment'] end return '' unless adj # Get the architecture for the current target or use the one specific to # this exploit arch = (target && target.arch) ? target.arch : self.arch # Default to x86 if we can't find a list of architectures if arch && !arch.empty? arch = [arch].flatten.join(', ') else arch = 'x86' end Rex::Arch::adjust_stack_pointer(arch, adj) || '' end |
#stance ⇒ Object
Generally, all exploits take an aggressive stance.
625 626 627 |
# File 'lib/msf/core/exploit.rb', line 625 def stance module_info['Stance'] || Stance::Aggressive end |
#target ⇒ Object
Returns the active target for this exploit. If not target has been defined, nil is returned. If no target was defined but there is a default target, that one will be automatically used.
648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 |
# File 'lib/msf/core/exploit.rb', line 648 def target if self.respond_to?(:auto_targeted_index) if auto_target? auto_idx = auto_targeted_index if auto_idx.present? datastore['TARGET'] = auto_idx else # If our inserted Automatic Target was selected but we failed to # find a suitable target, we just grab the original first target. datastore['TARGET'] = 1 end end end target_idx = target_index return (target_idx) ? targets[target_idx.to_i] : nil end |
#target_arch ⇒ Object
Returns the target's architecture, or the one assigned to the module itself.
699 700 701 |
# File 'lib/msf/core/exploit.rb', line 699 def target_arch (target and target.arch) ? target.arch : (arch == []) ? nil : arch end |
#target_index ⇒ Object
The target index that has been selected.
669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 |
# File 'lib/msf/core/exploit.rb', line 669 def target_index target_idx = begin Integer(datastore['TARGET']) rescue TypeError, ArgumentError datastore['TARGET'] end default_idx = default_target || 0 # Use the default target if one was not supplied. if (target_idx == nil and default_idx and default_idx >= 0) target_idx = default_idx elsif target_idx.is_a?(String) target_idx = targets.index { |target| target.name == target_idx } end return (target_idx) ? target_idx.to_i : nil end |
#target_platform ⇒ Object
Returns the target's platform, or the one assigned to the module itself.
691 692 693 |
# File 'lib/msf/core/exploit.rb', line 691 def target_platform (target and target.platform) ? target.platform : platform end |
#type ⇒ Object
Returns MODULE_EXPLOIT to indicate that this is an exploit module.
611 612 613 |
# File 'lib/msf/core/exploit.rb', line 611 def type Msf::MODULE_EXPLOIT end |
#wfs_delay ⇒ Object
The minimum "wait for session" delay is 3 seconds for all exploits, the WfsDelay configuration option is added on top of this. The delay allows time for the session handler to perform any session verification.
1269 1270 1271 |
# File 'lib/msf/core/exploit.rb', line 1269 def wfs_delay (datastore['WfsDelay'] || 0).to_i + 3 end |