Skip to content
Merged
Changes from 1 commit
Commits
Show all changes
72 commits
Select commit Hold shift + click to select a range
61a788d
update
NullArray Feb 7, 2018
d927ebb
Update autosploit.py
NullArray Feb 7, 2018
4a149dd
created some updates and moved the modules and usage into etc/ folder…
Feb 7, 2018
cb3bece
Merge branch 'dev-beta' into dev-beta
Ekultek Feb 7, 2018
e7ad52f
Merge pull request #32 from Ekultek/dev-beta
NullArray Feb 7, 2018
82756f2
Merge branch 'master' of git://github.com/nullarray/autosploit into d…
Feb 8, 2018
ef06d32
fixed all errors (most anyways) so that it will run successfully. cre…
Feb 8, 2018
0799c07
fixed the numbers
Feb 8, 2018
86d4f68
Update autosploit.py
NullArray Feb 8, 2018
0458fc7
Update autosploit.py
NullArray Feb 8, 2018
dcad3fd
Merge branch 'dev-beta' into dev-updates
Ekultek Feb 8, 2018
00e313d
Merge remote-tracking branch 'NullArray/master'
ehlewis Feb 8, 2018
a8bf69b
Added ability to limit number of hosts
ehlewis Feb 8, 2018
c467672
Merge pull request #34 from Ekultek/dev-updates
NullArray Feb 14, 2018
79ea890
Merge branch 'dev-beta' into dev-beta
ehlewis Feb 14, 2018
5e23e7f
Merge branch 'master' of git://github.com/NullArray/AutoSploit into d…
Feb 15, 2018
8f9874e
created an animation that will run while the program sorts, or writes…
Feb 15, 2018
1676499
Update autosploit.py
Ekultek Feb 15, 2018
be124aa
Merge pull request #46 from Ekultek/animation
NullArray Feb 16, 2018
c31373e
Stylized .yml, .py, .md, and .txt
thehappydinoa Feb 16, 2018
6a8fb98
Merge pull request #48 from thehappydinoa/dev-beta
NullArray Feb 16, 2018
ceb6851
Create modules.json
NullArray Feb 19, 2018
dde825b
Update autosploit.py
NullArray Feb 19, 2018
2ea9170
created a function that will take a text file and turn it into a JSON…
Feb 19, 2018
bbb9bc2
Merge pull request #52 from NullArray/jsonize
Ekultek Feb 20, 2018
8a9f4ad
Merge branch 'dev-beta' into dev-beta
ehlewis Feb 20, 2018
7a7e587
Merge pull request #37 from ehlewis/dev-beta
NullArray Feb 20, 2018
a9f00db
Implemented Censys Functionality (#60) (#56 dome)
ehlewis Feb 21, 2018
c2c260e
Fixed targets() input infinite loop (#61)
ehlewis Feb 22, 2018
042c864
started creating the arguments for issue #57
Feb 22, 2018
cd0483d
Merge pull request #62 from NullArray/cmdline
NullArray Feb 22, 2018
2217366
voided blessings in favor of ANSI codes
Feb 22, 2018
aadc942
changed all the output to new favorable output
Feb 22, 2018
91ae0cf
changed all the output to new favorable output
Feb 22, 2018
8e50ad6
finished the '-e' argument, will now convert a text file containing e…
Feb 22, 2018
ba39cb9
changed all the output to new favorable output
Feb 22, 2018
9a7b0aa
created a way to validate IP addresses pythonically, also created pro…
Feb 22, 2018
6f93e79
voided blessings
Feb 22, 2018
f792e27
Merge pull request #63 from NullArray/updates
NullArray Feb 22, 2018
3d777f2
refractor to the way that the processes are started, will now run thr…
Feb 22, 2018
52f95c7
Merge pull request #65 from NullArray/more-updates
NullArray Feb 22, 2018
e309f3e
pushing the API packages to Github, will implement them later on (iss…
Feb 23, 2018
4201d9e
Merge pull request #66 from NullArray/api
Ekultek Feb 23, 2018
e889bea
nuclear option
NullArray Feb 23, 2018
f9c1578
nuclear option
NullArray Feb 23, 2018
fb53eaa
created a new banner, made it so that banner always displays, fixed t…
Feb 23, 2018
4c1783c
Merge pull request #67 from NullArray/banner_fix
Ekultek Feb 23, 2018
28a5c86
created a method to load the API keys since we now use multiple of th…
Feb 23, 2018
778bcce
fixed the ID call for censys, will now also prompt for an ID instead …
Feb 24, 2018
da27f08
Merge pull request #69 from NullArray/updates
NullArray Feb 26, 2018
81e3028
fixed shebang line
NullArray Feb 26, 2018
861959a
fixed shebang line
NullArray Feb 26, 2018
38e7329
created a terminal output for the program that implements #64 and #49
Feb 27, 2018
afc6567
moved some stuff to settings, created a class for the exploitation so…
Feb 27, 2018
a6ba889
Merge pull request #70 from NullArray/terminal
NullArray Feb 27, 2018
5099df6
fixes the issue
Feb 27, 2018
bc1994b
Merge pull request #71 from NullArray/animation
Ekultek Feb 27, 2018
ef52595
created an issue template for furture issues
Feb 27, 2018
38122d2
fixed the docker file to download the correct requirements
Feb 27, 2018
2a90d89
fixed the README to have the correct requirements
Feb 27, 2018
c7f05ca
fixed the req file to have the correct requirements
Feb 27, 2018
a4c13bd
Merge pull request #72 from NullArray/trivial
NullArray Feb 28, 2018
9adb6eb
implemented the switches, search engines, and everything else, issue …
Feb 28, 2018
eb3d938
ready for deployment
Mar 1, 2018
a88d06c
Merge pull request #73 from NullArray/trivial
NullArray Mar 1, 2018
ae80ecb
Update CONTRIBUTING.md
NullArray Mar 1, 2018
7d3af30
Update general
NullArray Mar 1, 2018
c85ebc1
Update README.md
NullArray Mar 1, 2018
72ad39c
Update README.md
NullArray Mar 1, 2018
03e73e9
minor edits to fix minor banner issues
Mar 1, 2018
11d2888
Merge branch 'master' into dev-beta
NullArray Mar 1, 2018
13260b5
Merge pull request #75 from NullArray/trivial
Ekultek Mar 1, 2018
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Update README.md
  • Loading branch information
NullArray authored Mar 1, 2018
commit c85ebc197c0e1c5be58f231e34b87048a2eff98f
85 changes: 64 additions & 21 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,44 +1,85 @@
# AutoSploit

As the name might suggest AutoSploit attempts to automate the exploitation of remote hosts. Targets are collected automatically as well by employing the Shodan.io API. The program allows the user to enter their platform specific search query such as; `Apache`, `IIS`, etc, upon which a list of candidates will be retrieved.

After this operation has been completed the 'Exploit' component of the program will go about the business of attempting to exploit these targets by running a series of Metasploit modules against them. Which Metasploit modules will be employed in this manner is determined by programmatically comparing the name of the module to the initial search query. However, I have added functionality to run all available modules against the targets in a 'Hail Mary' type of attack as well.

The available Metasploit modules have been selected to facilitate Remote Code Execution and to attempt to gain Reverse TCP Shells and/or Meterpreter sessions. Workspace, local host and local port for MSF facilitated back connections are configured through the dialog that comes up before the 'Exploit' component is started.
As the name might suggest AutoSploit attempts to automate the exploitation of remote hosts. Targets can be collected automatically through Shodan, Censys or Zoomeye. But options to add your custom targets and host lists have been included as well.
The available Metasploit modules have been selected to facilitate Remote Code Execution and to attempt to gain Reverse TCP Shells and/or Meterpreter sessions. Workspace, local host and local port for MSF facilitated back connections are configured by filling out the dialog that comes up before the exploit component is started

**Operational Security Consideration**

Receiving back connections on your local machine might not be the best idea from an OPSEC standpoint. Instead consider running this tool from a VPS that has all the dependencies required, available.

The new version of AutoSploit has a feature that allows you to set a proxy before you connect and a custom user-agent.

## Usage

Clone the repo. Or deploy via Docker. Details for which can be found [here](https://github.com/NullArray/AutoSploit/tree/master/Docker) Special thanks to [Khast3x](https://github.com/khast3x) for their contribution in this regard.

`git clone https://github.com/NullArray/AutoSploit.git`

After which it can be started from the terminal with `python autosploit.py`. After which you can select one of five actions. Please see the option summary below.
Starting the program with `python autosploit.py` will open an AutoSploit terminal session. The options for which are as follows.

```
+------------------+----------------------------------------------------+
| Option | Summary |
+------------------+----------------------------------------------------+
|1\. Usage | Display this informational message. |
|2\. Gather Hosts | Query Shodan for a list of platform specific IPs. |
|3\. View Hosts | Print gathered IPs/RHOSTS. |
|4\. Exploit | Configure MSF and Start exploiting gathered targets|
|5\. Quit | Exits AutoSploit. |
+------------------+----------------------------------------------------+
1. Usage And Legal
2. Gather Hosts
3. Custom Hosts
4. Add Single Host
5. View Gathered Hosts
6. Exploit Gathered Hosts
99. Quit
```

## Available Modules
Choosing option `2` will prompt you for a platform specific search query. Enter `IIS` or `Apache` in example and choose a search engine. After doing so the collected hosts will be saved to be used in the `Exploit` component.

The Metasploit modules available with this tool are selected for RCE. You can find them in the `modules.txt` file that is included in this repo. Should you wish to add more or other modules please do so in the following format.
As of version 2.0 AutoSploit can be started with a number of command line arguments/flags as well. Type `python autosploit.py -h`
to display all the options available to you. I've posted the options below as well for reference.

```
use exploit/linux/http/netgear_wnr2000_rce;exploit -j;
usage: python autosploit.py -[c|z|s|a] -[q] QUERY
[-C] WORKSPACE LHOST LPORT [-e]
[--ruby-exec] [--msf-path] PATH [-E] EXPLOIT-FILE-PATH
[--rand-agent] [--proxy] PROTO://IP:PORT [-P] AGENT

optional arguments:
-h, --help show this help message and exit

search engines:
possible search engines to use

-c, --censys use censys.io as the search engine to gather hosts
-z, --zoomeye use zoomeye.org as the search engine to gather hosts
-s, --shodan use shodan.io as the search engine to gather hosts
-a, --all search all available search engines to gather hosts

requests:
arguments to edit your requests

--proxy PROTO://IP:PORT
run behind a proxy while performing the searches
--random-agent use a random HTTP User-Agent header
-P USER-AGENT, --personal-agent USER-AGENT
pass a personal User-Agent to use for HTTP requests
-q QUERY, --query QUERY
pass your search query

exploits:
arguments to edit your exploits

-E PATH, --exploit-file PATH
provide a text file to convert into JSON and save for
later use
-C WORKSPACE LHOST LPORT, --config WORKSPACE LHOST LPORT
set the configuration for MSF (IE -C default 127.0.0.1
8080)
-e, --exploit start exploiting the already gathered hosts

misc arguments:
arguments that don't fit anywhere else

--ruby-exec if you need to run the Ruby executable with MSF use
this
--msf-path MSF-PATH pass the path to your framework if it is not in your
ENV PATH
```

With each new module on it's own line.

## Dependencies

Expand All @@ -65,6 +106,8 @@ Since the program invokes functionality from the Metasploit Framework you need t

### Note

While this isn't exactly a Beta release it is an early release nonetheless as such the tool might be subject to changes in the future. If you happen to encounter a bug or would like to contribute to the tool's improvement please feel free to [Open a Ticket](https://github.com/NullArray/AutoSploit/issues) or [Submit a Pull Request](https://github.com/NullArray/AutoSploit/pulls)
If you happen to encounter a bug please feel free to [Open a Ticket](https://github.com/NullArray/AutoSploit/issues).

If you wish to contribute to the development of this project please be sure to read [CONTRIBUTING.md](https://github.com/NullArray/AutoSploit/blob/master/CONTRIBUTING.md) before you get started as it contains our contribution guidelines.

Thanks.
Thanks in advance.