Archeagus icon

Mapscan v2.4 - Archeagus Grey Hack Series, Episode 6

Archeagus | PRO | 06/14/26 08:24:35 AM UTC (Edited) | 0 ⭐ | 27539 👁️ | Never ⏰ | [hacking, hacker, simulation, Grey Hack, greyscript, Hacking Simulation, Archeagus, Archeagus Gaming]
JavaScript |

12.26 KB

|

Gaming

|

0 👍

/

0 👎

// Command mapscan
script_version = 2.4 
 
// Changes:
// - Added support for separate library/version logging
// - Removed system.log text logic and replaced with Log Viewer logic
// - Added --interactive mode for password privilege level processing
// - Added first pass of color formatting to terminal output
// Version 2.0
// - Added password variable for vulnerability testing
// - Added logic to capture and display new objects returned by exploit testing
// - Added logic to determine the privilege level of shell objects returned by exploit testing
// - Added logic to show and delete system.log using highest level shell access (DEPRECATED) 
 
if params.len < 1 or params.len > 2 or params[0] == "-h" or params[0] == "--help" then exit("<color=yellow>Usage: "+program_path.split("/")[-1]+" [ip_address] [optional --interactive]</color>")
 
// Get metax library
metax = include_lib("/lib/metaxploit.so")
if not metax then exit("<color=red>Error: Unable to find 'metaxploit.so'. Put missing library in the 'lib' folder.</color>")
 
// Function to strip all HTML tags from a given string
stripHtml = function(inputString)
    if not inputString then return ""
    result = ""
    inTag = false
    // Loop through each character in the string
    for i in range(0, inputString.len - 1)
        char = inputString[i]
        
        if char == "<" then
            inTag = true
            continue
        else if char == ">" then
            inTag = false
            continue
        end if
        
        // Append character only if it's outside of a tag
        if not inTag then
            result = result + char
        end if
    end for    
    return result
end function
 
// Global (local) variables
shell = get_shell
computer = shell.host_computer
password = "password"
 
// Optional interactive mode - Allows user to provide password privilege levels from terminal output
interactive_mode = 0
if params.len == 2 then
    if params[1] == "--interactive" then interactive_mode = 1
end if
 
if not is_valid_ip(params[0]) then exit("<color=white>MapScan:</color> invalid ip address")
if not computer.is_network_active then exit("<color=white>MapScan:</color> No internet access.")
 
ipAddress = params[0]
if ipAddress == "127.0.0.1" then ipAddress = computer.local_ip
isLanIp = is_lan_ip( ipAddress )
 
if isLanIp then
   router = get_router;
else 
   router = get_router( ipAddress )
end if
 
if router == null then exit("<color=white>MapScan:</color> ip address not found")
 
ports = null
 
if not isLanIp then
   ports = router.used_ports
else
   ports = router.device_ports(ipAddress)
end if
 
if ports == null then exit("<color=white>MapScan:</color> ip address not found")
if typeof(ports) == "string" then exit(ports)
 
mapscanFolderPath = "/home/"+active_user
targetsFolderName = "Targets"
targetsFolder = mapscanFolderPath + "/" + targetsFolderName
if computer.File(targetsFolder) == null then computer.create_folder(mapscanFolderPath, targetsFolderName)
explibFolderName = "ExpLib"
explibFolder = mapscanFolderPath + "/" + explibFolderName
if computer.File(explibFolder) == null then computer.create_folder(mapscanFolderPath, explibFolderName)
 
tgtFile = computer.File(targetsFolder + "/" + ipAddress + ".txt")
if tgtFile == null then
    computer.touch(targetsFolder, ipAddress + ".txt")
    tgtFile = computer.File(targetsFolder + "/" + ipAddress + ".txt")
end if
 
output = ""
      
info = "PORT STATE SERVICE VERSION LAN"
info_length = info.len  
clear_screen
line1 = "<color=white>[+] MapScan v"+script_version+" - Advanced Network Exploitation Engine</color>"
line2 = "<color=white>[+] Target: </color>" + params[0]
line3 = "<color=white>[+] Time: "+ current_date + "</color>"
line4 = "<color=white>[+] PHASE 1: SERVICE ANALYSIS</color>"
print(line1)
output = output + line1 + char(10)
print(line2)
output = output + line2 + char(10)
print(line3)
output = output + line3 + char(10)
print(line4)
output = output + line4 + char(10)
if(ports.len == 0) then exit("<color=white>Scan finished. No open ports.</color>")
 
for port in ports
   service_info = router.port_info(port)
   lan_ips = port.get_lan_ip
   port_status = "open"
 
   if(port.is_closed and not isLanIp) then
      port_status = "closed"
   end if
   new_entry = port.port_number + " " + port_status + " " + service_info + " " + lan_ips
   if info_length < new_entry.len then info_length = new_entry.len
   info = info + "\n" + new_entry
end for
dashes = "<color=white>"
for c in range(1, info_length+8)
    dashes = dashes + "-"
end for
dashes = dashes + "</color>"
print(dashes)
print(format_columns(info))
print(dashes)
output = stripHtml(output + char(10) + dashes + char(10) + format_columns(info) + char(10) + dashes + char(10))
tgtFile.set_content(output)
 
// New variables for tracking new result objects and SQL library scans and capturing root shell access
new_types = []
sql_scanned = false
cuZone = null
cuExploit = null
cuPort = null
cuType = null
 
line5 = "<color=white>[+] PHASE 2: VULNERABILITY MAPPING & TESTING</color>"
print(dashes + char(10) + line5)
output = ""
for port in ports
   net_session = metax.net_use(ipAddress, port.port_number)
   if not net_session then exit("<color=red>Error: Unable to connect to port "+port.port_number+"</color>")
      
   metaLib = net_session.dump_lib
   expFilename = metaLib.lib_name + "-v" + metaLib.version + ".txt"
   expFile = computer.File(explibFolder + "/" + expFilename)
   if expFile == null then
      computer.touch(explibFolder, expFilename)
      expFile = computer.File(targetsFolder + "/" + ipAddress + ".txt")
      print("\nScanning " + metaLib.lib_name + " v" + metaLib.version + " on port " + port.port_number)
      expFile = computer.File(explibFolder + "/" + metaLib.lib_name + "-v" + metaLib.version + ".txt")
      output = metaLib.lib_name + " v" + metaLib.version
      scanResult = metax.scan(metaLib)
 
      for zone in scanResult
         memory_scan = metax.scan_address(metaLib, zone)
         print("\nFound memory zone: " + zone)
         output = output + char(10) + char(10) + "Exploits for zone: " + zone
         xpList = memory_scan.split("Unsafe check: ")[1:]
         exploits = []
         for xp in xpList
            labelStart = xp.indexOf("<b>")
            labelEnd = xp.indexOf("</b>")
            exploit = xp[labelStart + 3: labelEnd]
         print("\nTesting: " + exploit)
         wait(1)
            // Added password parameter for number type results
            result = metaLib.overflow(zone, exploit, password)
            if result == null then
               status = "Undefined / Conditional"
            else if typeof(result) == "shell" then
               status = "Shell (?)"
               
               target_comp = result.host_computer
               shell_user = "guest" // Default
                  // Create a file in /var (accessible by all accounts)
                  target_comp.touch("/var", "tmp.txt")
                  temp_file = target_comp.File("/var/tmp.txt")
                  
                  if temp_file != null then
                     shell_user = temp_file.owner // The owner of a newly touched file is the active shell user
                     temp_file.delete // More deletions to cleanup later
                  end if               
 
               if shell_user == "root" then
                    status = "Shell (ROOT)"
                  
                  // Flag the root exploit details if we don't have a root yet
                  if cuType == null or cuType != "Root" then
                     cuZone = zone
                     cuExploit = exploit
                     cuPort = port.port_number
                     cuType = "Root"
                     print("Saved as final cleanup vector.")
                  end if
               else
                  
                  status = "Shell ("+shell_user+")"
                  if cuType == null then
                     cuZone = zone
                     cuExploit = exploit
                     cuPort = port.port_number
                     cuType = shell_user
                     print("Saved as possible cleanup vector.")
                  else if cuType == "guest" and shell_user != "guest" then
                     cuZone = zone
                     cuExploit = exploit
                     cuPort = port.port_number
                     cuType = shell_user
                     print("Saved as possible cleanup vector.")
                  end if
               end if
            else if typeof(result) == "file" then
               status = "File"
            else if typeof(result) == "number" then
                status = ""
               if interactive_mode == 1 then
                    print("Privelege level?")
                    paused = 5
                    pwdLevel = ""
                    while paused and pwdLevel != "r" and pwdLevel != "u" and pwdLevel != "g"
                        pwdLevel = user_input("[R]oot, [U]ser or [G]uest: ")
                        wait(1)
                        paused = paused - 1 
                    end while
                    if pwdLevel == "r" then
                        status = "Privilege: Root" + char(10)       
                    else if pwdLevel == "u" then
                        username = user_input("Username? ")
                        status = "User: " + username + char(10)
                    else if pwdLevel == "g" then
                        status = "Privilege: Guest" + char(10)
                    end if
                end if
                status = status + "Password: '"+password+"'"
            else if typeof(result) == "computer" then
               status = "Computer"
            else
               status ="New type found: " + typeof(result)
               if new_types.indexOf(typeOf(result)) == null then new_types.push(typeOf(result))
            end if
            exploits.push(exploit + " (" + status + ")")
         wait(0.5)
         end for
         print("\nMemory zone: " + zone + "\nAvailable vulnerabilities:\n" + exploits.join("\n"))
         output = output + char(10) + exploits.join(char(10))
         if new_types.len > 0 then
            print("\nNew vulnerability types found:\n" + new_types.join("\n"))
            output = output + char(10) + char(10) + "New Vulnerability Types:" + char(10) + new_types.join(char(10))
         end if
         if metaLib.lib_name.indexOf("sql") then sql_scanned = true
      end for
      expFile.set_content(output)
   else
      print(expFilename + " found in Exploit library.")
   end if
   print(dashes)
end for
print ("\n<color=white>MapScan completed.</color>\n<color=white>Results saved to " + ipAddress + ".txt in " + targetsFolderName + " folder.</color>")
line6 = "<color=white>[+] PHASE 3: SYSTEM LOG CLEANUP</color>"
print(dashes + char(10) + line6)
// --- V2: Clear Our Tracks ---
if cuExploit != null then
    print("\n<color=white>[+] Cleaning tracks ..................")
    
    // Re-trigger the saved root vulnerability
    cleanup_session = metax.net_use(ipAddress, cuPort)
    if cleanup_session then
        cleanup_lib = cleanup_session.dump_lib
        tgt_shell = cleanup_lib.overflow(cuZone, cuExploit)
        
        if typeof(tgt_shell) == "shell" then
            tgt_comp = tgt_shell.host_computer
            log_file = tgt_comp.File("/var/system.log")
            
            if log_file != null then
                // Show the log before deletion
                print("\n<color=white>[+] Sending target system log to Log Viewer.</color>")
                tgt_shell.launch("/usr/bin/LogViewer.exe", "/var/system.log")
                wait(6)
                
                // Deletion / Fresh log
                log_file.delete
                tgt_comp.touch("/var", "system.log")
                print("\n<color=white>[+] Processing deletion... Replacing with blank structure...</color>")
                wait(2)
                
                // Show the fresh log
                print("\n<color=white>[+] Sending refreshed system log to Log Viewer.</color>")
                tgt_shell.launch("/usr/bin/LogViewer.exe", "/var/system.log")
                wait(6)
                
            else
                print("<color=red>Error: /var/system.log missing or inaccessible.</color>")
            end if
            print(dashes)
            // Let's talk aboug "start_terminal" and bash ...
            tgt_shell.launch("/bin/bash")
        end if
    end if
else
    print(dashes)
    print("\n<color=#FF0000>[WARNING] Scan complete, but no root exploit was found. Logs could not be cleared automatically.</color>")
end if
 

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  • Archeagus icon
    Archeagus PRO
    06/18/26 02:39:04 AM UTC
    text |

    0 B

    |

    0 👍

    /

    0 👎

    Do not trust any of the "Leaked Exploit Documentation" links you find below my scripts, or posted to any other scripts you find on Pastebin.com. These are links to a cryptocurrency scam that will look like you are receiving funds, when in fact they are exposing and clearing your own wallet. I've reported these commenters to Pastebin, but they appear to be supporting these users and in no hurry to remove the comments.
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎