// Command mapscan v2.0 (RC)
if params.len != 1 or params[0] == "-h" or params[0] == "--help" then exit("Usage: "+program_path.split("/")[-1]+" [ip_address]")
metax = include_lib("/lib/metaxploit.so")
if not metax then exit("Error: Unable to find 'metaxploit.so'. Put missing library in the 'lib' folder.")
// Adding password variable for vulnerability testing
shell = get_shell
computer = shell.host_computer
password = "password"
if not is_valid_ip(params[0]) then exit("nmap: invalid ip address")
if not computer.is_network_active then exit("nmap: No internet access.")
ipAddress = params[0]
if ipAddress == "127.0.0.1" then ipAddress = computer.local_ip
isLanIp = is_lan_ip( ipAddress )
if isLanIp then
router = get_router;
else
router = get_router( ipAddress )
end if
if router == null then exit("nmap: ip address not found")
ports = null
if not isLanIp then
ports = router.used_ports
else
ports = router.device_ports(ipAddress)
end if
if ports == null then exit("nmap: ip address not found")
if typeof(ports) == "string" then exit(ports)
targetsFolderName = "Targets"
targetsFolderPath = "/home/"+active_user
targetsFolder = targetsFolderPath + "/" + targetsFolderName
if computer.File(targetsFolder) == null then computer.create_folder(targetsFolderPath, targetsFolderName)
outputFile = computer.File(targetsFolder + "/" + ipAddress + ".txt")
if outputFile == null then
computer.touch(targetsFolder, ipAddress + ".txt")
outputFile = computer.File(targetsFolder + "/" + ipAddress + ".txt")
end if
output = ""
info = "PORT STATE SERVICE VERSION LAN"
clear_screen
print("Starting nmap v2.0 at " + current_date)
print("Interesting ports on " + params[0] + "\n")
if(ports.len == 0) then exit("Scan finished. No open ports.")
for port in ports
service_info = router.port_info(port)
lan_ips = port.get_lan_ip
port_status = "open"
if(port.is_closed and not isLanIp) then
port_status = "closed"
end if
info = info + "\n" + port.port_number + " " + port_status + " " + service_info + " " + lan_ips
end for
print(format_columns(info) + "\n")
output = output + format_columns(info) + char(10)
// New variables for tracking new result objects and SQL library scans and capturing root shell access
new_types = []
sql_scanned = false
cuZone = null
cuExploit = null
cuPort = null
cuType = null
for port in ports
net_session = metax.net_use(ipAddress, port.port_number)
if not net_session then exit("Error: Unable to connect.")
metaLib = net_session.dump_lib
if not metaLib.lib_name.indexOf("sql") or not sql_scanned then
print("\nScanning " + metaLib.lib_name + " v" + metaLib.version + " on port " + port.port_number)
output = output + char(10) + char(10) + metaLib.lib_name + " v" + metaLib.version + " on port " + port.port_number
scanResult = metax.scan(metaLib)
for zone in scanResult
memory_scan = metax.scan_address(metaLib, zone)
print("\nFound memory zone: " + zone)
output = output + char(10) + char(10) + "Exploits for zone: " + zone
xpList = memory_scan.split("Unsafe check: ")[1:]
exploits = []
for xp in xpList
labelStart = xp.indexOf("")
labelEnd = xp.indexOf("")
exploit = xp[labelStart + 3: labelEnd]
print("\nTesting: " + exploit)
wait(1)
// Added password parameter for number type results
result = metaLib.overflow(zone, exploit, password)
if result == null then
status = "Undefined / Conditional"
else if typeof(result) == "shell" then
status = "Shell (?)"
target_comp = result.host_computer
shell_user = "guest" // Default
// Create a file in /var (accessible by all accounts)
target_comp.touch("/var", "tmp.txt")
temp_file = target_comp.File("/var/tmp.txt")
if temp_file != null then
shell_user = temp_file.owner // The owner of a newly touched file is the active shell user
temp_file.delete // More deletions to cleanup later
end if
if shell_user == "root" then
status = "Shell (ROOT)"
// Flag the root exploit details if we don't have a root yet
if cuType == null or cuType != "Root" then
cuZone = zone
cuExploit = exploit
cuPort = port.port_number
cuType = "Root"
print("Saved as final cleanup vector.")
end if
else
status = "Shell ("+shell_user+")"
if cuType == null then
cuZone = zone
cuExploit = exploit
cuPort = port.port_number
cuType = shell_user
print("Saved as possible cleanup vector.")
else if cuType == "guest" and shell_user != "guest" then
cuZone = zone
cuExploit = exploit
cuPort = port.port_number
cuType = shell_user
print("Saved as possible cleanup vector.")
end if
end if
else if typeof(result) == "file" then
status = "File"
else if typeof(result) == "number" then
status = "Password: '"+password+"'"
else if typeof(result) == "computer" then
status = "Computer"
else
status ="New type found: " + typeof(result)
if new_types.indexOf(typeOf(result)) == null then new_types.push(typeOf(result))
end if
exploits.push(exploit + " (" + status + ")")
wait(0.5)
end for
print("\nMemory zone: " + zone + "\nAvailable vulnerabilities:\n" + exploits.join("\n"))
output = output + char(10) + exploits.join(char(10))
if new_types.len > 0 then
print("\nNew vulnerability types found:\n" + new_types.join("\n"))
output = output + char(10) + char(10) + "New Vulnerability Types:" + char(10) + new_types.join(char(10))
end if
if metaLib.lib_name.indexOf("sql") then sql_scanned = true
end for
end if
end for
outputFile.set_content(output)
print ("\nNMAP Scan completed.\nResults saved to " + ipAddress + ".txt in " + targetsFolderName + " folder.")
// --- V2: Clear Our Tracks ---
if cuExploit != null then
print("\nCleaning tracks")
// Re-trigger the saved root vulnerability
cleanup_session = metax.net_use(ipAddress, cuPort)
if cleanup_session then
cleanup_lib = cleanup_session.dump_lib
root_shell = cleanup_lib.overflow(cuZone, cuExploit)
if typeof(root_shell) == "shell" then
tgt_comp = root_shell.host_computer
log_file = tgt_comp.File("/var/system.log")
//if log_file != null then
// Show the log before deletion
// print("\nTarget system log before deletion:")
// print("--------------------------------------------------")
// log_content = log_file.get_content
// if log_content == "" or log_content == null then
// print("[Log is currently empty]")
//else
// print(log_content)
//end if
//print("--------------------------------------------------")
//wait(3)
// Deletion / Fresh log
log_file.delete
tgt_comp.touch("/var", "system.log")
print("\nProcessing deletion... Replacing with blank structure...")
wait(1)
// Show the fresh log
//fresh_log_file = tgt_comp.File("/var/system.log")
//print("\nTarget system log after deletion:")
//print("--------------------------------------------------")
//if fresh_log_file != null then
//new_content = fresh_log_file.get_content
//if new_content == "" or new_content == null then
// print("[SUCCESS] Log is completely blank. Tracks cleared!")
// else
// print(new_content)
//end if
//else
//print("[ERROR] Failed to verify replacement log file.")
//end if
//print("--------------------------------------------------")
//else
// print("Error: /var/system.log missing or inaccessible.")
//end if
// Let's talk aboug "start_terminal" and bash ...
root_shell.launch("/bin/bash")
end if
end if
else
print("\n[WARNING] Scan complete, but no root exploit was found. Logs could not be cleared automatically.")
end if