Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
Show all changes
72 commits
Select commit Hold shift + click to select a range
61a788d
update
NullArray Feb 7, 2018
d927ebb
Update autosploit.py
NullArray Feb 7, 2018
4a149dd
created some updates and moved the modules and usage into etc/ folder…
Feb 7, 2018
cb3bece
Merge branch 'dev-beta' into dev-beta
Ekultek Feb 7, 2018
e7ad52f
Merge pull request #32 from Ekultek/dev-beta
NullArray Feb 7, 2018
82756f2
Merge branch 'master' of git://github.com/nullarray/autosploit into d…
Feb 8, 2018
ef06d32
fixed all errors (most anyways) so that it will run successfully. cre…
Feb 8, 2018
0799c07
fixed the numbers
Feb 8, 2018
86d4f68
Update autosploit.py
NullArray Feb 8, 2018
0458fc7
Update autosploit.py
NullArray Feb 8, 2018
dcad3fd
Merge branch 'dev-beta' into dev-updates
Ekultek Feb 8, 2018
00e313d
Merge remote-tracking branch 'NullArray/master'
ehlewis Feb 8, 2018
a8bf69b
Added ability to limit number of hosts
ehlewis Feb 8, 2018
c467672
Merge pull request #34 from Ekultek/dev-updates
NullArray Feb 14, 2018
79ea890
Merge branch 'dev-beta' into dev-beta
ehlewis Feb 14, 2018
5e23e7f
Merge branch 'master' of git://github.com/NullArray/AutoSploit into d…
Feb 15, 2018
8f9874e
created an animation that will run while the program sorts, or writes…
Feb 15, 2018
1676499
Update autosploit.py
Ekultek Feb 15, 2018
be124aa
Merge pull request #46 from Ekultek/animation
NullArray Feb 16, 2018
c31373e
Stylized .yml, .py, .md, and .txt
thehappydinoa Feb 16, 2018
6a8fb98
Merge pull request #48 from thehappydinoa/dev-beta
NullArray Feb 16, 2018
ceb6851
Create modules.json
NullArray Feb 19, 2018
dde825b
Update autosploit.py
NullArray Feb 19, 2018
2ea9170
created a function that will take a text file and turn it into a JSON…
Feb 19, 2018
bbb9bc2
Merge pull request #52 from NullArray/jsonize
Ekultek Feb 20, 2018
8a9f4ad
Merge branch 'dev-beta' into dev-beta
ehlewis Feb 20, 2018
7a7e587
Merge pull request #37 from ehlewis/dev-beta
NullArray Feb 20, 2018
a9f00db
Implemented Censys Functionality (#60) (#56 dome)
ehlewis Feb 21, 2018
c2c260e
Fixed targets() input infinite loop (#61)
ehlewis Feb 22, 2018
042c864
started creating the arguments for issue #57
Feb 22, 2018
cd0483d
Merge pull request #62 from NullArray/cmdline
NullArray Feb 22, 2018
2217366
voided blessings in favor of ANSI codes
Feb 22, 2018
aadc942
changed all the output to new favorable output
Feb 22, 2018
91ae0cf
changed all the output to new favorable output
Feb 22, 2018
8e50ad6
finished the '-e' argument, will now convert a text file containing e…
Feb 22, 2018
ba39cb9
changed all the output to new favorable output
Feb 22, 2018
9a7b0aa
created a way to validate IP addresses pythonically, also created pro…
Feb 22, 2018
6f93e79
voided blessings
Feb 22, 2018
f792e27
Merge pull request #63 from NullArray/updates
NullArray Feb 22, 2018
3d777f2
refractor to the way that the processes are started, will now run thr…
Feb 22, 2018
52f95c7
Merge pull request #65 from NullArray/more-updates
NullArray Feb 22, 2018
e309f3e
pushing the API packages to Github, will implement them later on (iss…
Feb 23, 2018
4201d9e
Merge pull request #66 from NullArray/api
Ekultek Feb 23, 2018
e889bea
nuclear option
NullArray Feb 23, 2018
f9c1578
nuclear option
NullArray Feb 23, 2018
fb53eaa
created a new banner, made it so that banner always displays, fixed t…
Feb 23, 2018
4c1783c
Merge pull request #67 from NullArray/banner_fix
Ekultek Feb 23, 2018
28a5c86
created a method to load the API keys since we now use multiple of th…
Feb 23, 2018
778bcce
fixed the ID call for censys, will now also prompt for an ID instead …
Feb 24, 2018
da27f08
Merge pull request #69 from NullArray/updates
NullArray Feb 26, 2018
81e3028
fixed shebang line
NullArray Feb 26, 2018
861959a
fixed shebang line
NullArray Feb 26, 2018
38e7329
created a terminal output for the program that implements #64 and #49
Feb 27, 2018
afc6567
moved some stuff to settings, created a class for the exploitation so…
Feb 27, 2018
a6ba889
Merge pull request #70 from NullArray/terminal
NullArray Feb 27, 2018
5099df6
fixes the issue
Feb 27, 2018
bc1994b
Merge pull request #71 from NullArray/animation
Ekultek Feb 27, 2018
ef52595
created an issue template for furture issues
Feb 27, 2018
38122d2
fixed the docker file to download the correct requirements
Feb 27, 2018
2a90d89
fixed the README to have the correct requirements
Feb 27, 2018
c7f05ca
fixed the req file to have the correct requirements
Feb 27, 2018
a4c13bd
Merge pull request #72 from NullArray/trivial
NullArray Feb 28, 2018
9adb6eb
implemented the switches, search engines, and everything else, issue …
Feb 28, 2018
eb3d938
ready for deployment
Mar 1, 2018
a88d06c
Merge pull request #73 from NullArray/trivial
NullArray Mar 1, 2018
ae80ecb
Update CONTRIBUTING.md
NullArray Mar 1, 2018
7d3af30
Update general
NullArray Mar 1, 2018
c85ebc1
Update README.md
NullArray Mar 1, 2018
72ad39c
Update README.md
NullArray Mar 1, 2018
03e73e9
minor edits to fix minor banner issues
Mar 1, 2018
11d2888
Merge branch 'master' into dev-beta
NullArray Mar 1, 2018
13260b5
Merge pull request #75 from NullArray/trivial
Ekultek Mar 1, 2018
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 15 additions & 15 deletions Docker/README.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
Docker deployment instructions
=====
# Docker deployment instructions

## tl;dr

Expand All @@ -24,19 +23,19 @@ docker build -t autosploit .
docker run -it --network haknet -p 80:80 -p 443:443 -p 4444:4444 autosploit
```


## Abstract

* Launching `Autosploit` as a Docker container makes it very easy to use the tool in a hosted cloud environment (AWS, Azure, ...)
* Separate `postgres` database into individual service for data persistence and potential async updating of the database
* Create a small bridge network ``haknet`` so the service discovery is automatic
* Launch `postgres` and `Autosploit` container, both linked by `haknet`
* Autosploit will automatically launch preconfigured `msfconsole` to the external `postgres` container through `haknet` transparent network
* Total image size of Kali + Metasploit + Autosploit : 1.75GB
- Launching `Autosploit` as a Docker container makes it very easy to use the tool in a hosted cloud environment (AWS, Azure, ...)
- Separate `postgres` database into individual service for data persistence and potential async updating of the database
- Create a small bridge network `haknet` so the service discovery is automatic
- Launch `postgres` and `Autosploit` container, both linked by `haknet`
- Autosploit will automatically launch preconfigured `msfconsole` to the external `postgres` container through `haknet` transparent network
- Total image size of Kali + Metasploit + Autosploit : 1.75GB

## Deploy

##### Step 1 - Create bridge network
### Step 1 - Create bridge network

This will enable the Metasploit Framework to talk to the `postgres` database using its hostname, making it abstract.

A Tor Socks Proxy can also be added to perform transparent proxy when launching exploits (not for reverse shells though, obviously).
Expand All @@ -45,22 +44,23 @@ A Tor Socks Proxy can also be added to perform transparent proxy when launching
docker network create -d bridge haknet
```

##### Step 2 - Launch services
### Step 2 - Launch services

All automagically linked


###### Step 2.1 - Launch postgres
#### Step 2.1 - Launch postgres

Launch a vanilla `postgres` service, linked to `haknet`

```bash
docker run --network haknet --name msfdb -e POSTGRES_PASSWORD=s3cr3t -d postgres
```
###### Step 2.2 - Launch Autosploit

#### Step 2.2 - Launch Autosploit

Launch `Autosploit`.

This Dockerfile will copy the default database config to ```~/.msf4/database.yml```. You can edit the configuration file `database.yml` to your liking before building.
This Dockerfile will copy the default database config to `~/.msf4/database.yml`. You can edit the configuration file `database.yml` to your liking before building.

Please be aware that the first build will take some time (~10mn)

Expand Down
20 changes: 10 additions & 10 deletions Docker/database.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
development: &pgsql
adapter: postgresql
database: postgres
username: postgres
password: s3cr3t
host: msfdb
port: 5432
pool: 200
timeout: 5
adapter: postgresql
database: postgres
username: postgres
password: s3cr3t
host: msfdb
port: 5432
pool: 200
timeout: 5

production: &production
<<: *pgsql
production: &production
<<: *pgsql
9 changes: 4 additions & 5 deletions Docker/docker-compose.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
version: '3'
version: '3'

services:
autosploit:
build:
context: .
context: .
ports:
- 80:80
- 443:433
Expand All @@ -13,7 +13,7 @@ services:
depends_on:
- postgres
postgres:
image: postgres
image: postgres
environment:
- POSTGRES_PASSWORD=s3cr3t
networks:
Expand All @@ -23,8 +23,7 @@ services:

networks:
haknet:
driver: bridge
driver: bridge

volumes:
db:

39 changes: 26 additions & 13 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# AutoSploit

As the name might suggest AutoSploit attempts to automate the exploitation of remote hosts. Targets are collected automatically as well by employing the Shodan.io API. The program allows the user to enter their platform specific search query such as; `Apache`, `IIS`, etc, upon which a list of candidates will be retrieved.
As the name might suggest AutoSploit attempts to automate the exploitation of remote hosts. Targets are collected automatically as well by employing the Shodan.io API. The program allows the user to enter their platform specific search query such as; `Apache`, `IIS`, etc, upon which a list of candidates will be retrieved.

After this operation has been completed the 'Exploit' component of the program will go about the business of attempting to exploit these targets by running a series of Metasploit modules against them. Which Metasploit modules will be employed in this manner is determined by programmatically comparing the name of the module to the initial search query. However, I have added functionality to run all available modules against the targets in a 'Hail Mary' type of attack as well.

Expand All @@ -17,41 +17,54 @@ Clone the repo. Or deploy via Docker. Details for which can be found [here](http
`git clone https://github.com/NullArray/AutoSploit.git`

After which it can be started from the terminal with `python autosploit.py`. After which you can select one of five actions. Please see the option summary below.

```
+------------------+----------------------------------------------------+
| Option | Summary |
+------------------+----------------------------------------------------+
|1. Usage | Display this informational message. |
|2. Gather Hosts | Query Shodan for a list of platform specific IPs. |
|3. View Hosts | Print gathered IPs/RHOSTS. |
|4. Exploit | Configure MSF and Start exploiting gathered targets|
|5. Quit | Exits AutoSploit. |
|1\. Usage | Display this informational message. |
|2\. Gather Hosts | Query Shodan for a list of platform specific IPs. |
|3\. View Hosts | Print gathered IPs/RHOSTS. |
|4\. Exploit | Configure MSF and Start exploiting gathered targets|
|5\. Quit | Exits AutoSploit. |
+------------------+----------------------------------------------------+
```

## Available Modules

The Metasploit modules available with this tool are selected for RCE. You can find them in the `modules.txt` file that is included in this repo. Should you wish to add more or other modules please do so in the following format.

```
use exploit/linux/http/netgear_wnr2000_rce;exploit -j;
use exploit/linux/http/netgear_wnr2000_rce;exploit -j;
```

With each new module on it's own line.

## Dependencies

AutoSploit depends on the following Python2.7 modules.

```
shodan
blessings
```

Should you find you do not have these installed get them with pip like so.

```bash
pip install shodan blessings
```
pip install shodan
pip install blessings

or

```bash
pip install -r requirements.txt
```
Since the program invokes functionality from the Metasploit Framework you need to have this installed also.
Get it from Rapid7 by clicking [here](https://www.rapid7.com/products/metasploit/).

Since the program invokes functionality from the Metasploit Framework you need to have this installed also. Get it from Rapid7 by clicking [here](https://www.rapid7.com/products/metasploit/).

### Note

While this isn't exactly a Beta release it is an early release nonetheless as such the tool might be subject to changes in the future. If you happen to encounter a bug or would like to contribute to the tool's improvement please feel free to [Open a Ticket](https://github.com/NullArray/AutoSploit/issues) or [Submit a Pull Request](https://github.com/NullArray/AutoSploit/pulls)

Thanks.


Loading