Repository navigation
Expand file tree
/
Copy pathtest.patch
More file actions
147 lines (141 loc) · 7.06 KB
/
Copy pathtest.patch
File metadata and controls
147 lines (141 loc) · 7.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
--- a/exploit_analyzer.py
+++ b/exploit_analyzer.py
@@ -127,7 +127,7 @@ def analyze_exploit(edb_id: str, host) -> dict:
file_path = meta["file_path"]
file_ext = os.path.splitext(file_path)[1].lower()
- if len(source) > 10000:
+ if len(source) > 30000:
print(f"[-] Exploit source is {len(source)} bytes, too large for LLM. Using generic profile.")
profile = {
"language": "python3" if file_ext == ".py" else "other",
--- a/tools/exploitdb_poc.py
+++ b/tools/exploitdb_poc.py
@@ -60,6 +60,10 @@ def _patch_code(code, target_ip, local_ip, bind_port=None):
return code
def _execute_script(code, file_ext, target_ip, local_ip, extra_args, bind_port=None):
+ # Basic Python 2 to 3 print statement conversion
+ if file_ext == ".py":
+ code = re.sub(r'^(\s*)print\s+(?!\()(.*?)(\s*)$', r'\1print(\2)\3', code, flags=re.MULTILINE)
+
patched = _patch_code(code, target_ip, local_ip, bind_port)
ext = (file_ext or "").lower()
@@ -90,22 +94,36 @@ def _execute_script(code, file_ext, target_ip, local_ip, extra_args, bind_port=N
if extra_args:
cmd.extend(shlex.split(extra_args))
- try:
- proc = subprocess.Popen(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True)
- stdout, stderr = proc.communicate(timeout=30)
- return {
- "cmd": " ".join(cmd),
- "code": proc.returncode,
- "stdout": (stdout or "")[:8192],
- "stderr": (stderr or "")[:4096],
- }
- except subprocess.TimeoutExpired:
- proc.kill()
- stdout, stderr = proc.communicate()
- return {"code": 124, "stdout": (stdout or "")[:8192], "stderr": f"Timed out after 30s."}
- except FileNotFoundError:
- return {"code": 1, "stdout": "", "stderr": f"'{cmd_prefix[0]}' not installed."}
- finally:
- if os.path.exists(tmp_path):
- os.unlink(tmp_path)
+ max_retries = 2
+ for attempt in range(max_retries):
+ try:
+ proc = subprocess.Popen(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True)
+ stdout, stderr = proc.communicate(timeout=30)
+
+ # Auto-install missing modules
+ if attempt < max_retries - 1 and "ModuleNotFoundError: No module named" in (stderr or ""):
+ match = re.search(r"No module named '([^']+)'", stderr)
+ if match:
+ mod = match.group(1)
+ pip_mod = {"smb": "pysmb", "Crypto": "pycryptodome", "win32com": "pywin32"}.get(mod, mod)
+ print(f"[*] Attempting to install missing module: {pip_mod}")
+ subprocess.run([sys.executable, "-m", "pip", "install", pip_mod], capture_output=True)
+ continue # Retry execution
+
+ return {
+ "cmd": " ".join(cmd),
+ "code": proc.returncode,
+ "stdout": (stdout or "")[:8192],
+ "stderr": (stderr or "")[:4096],
+ }
+ except subprocess.TimeoutExpired:
+ proc.kill()
+ stdout, stderr = proc.communicate()
+ return {"code": 124, "stdout": (stdout or "")[:8192], "stderr": f"Timed out after 30s."}
+ except FileNotFoundError:
+ return {"code": 1, "stdout": "", "stderr": f"'{cmd_prefix[0]}' not installed."}
+
+ if os.path.exists(tmp_path):
+ os.unlink(tmp_path)
+ return {"code": 1, "stdout": "", "stderr": "Failed after retrying module installation."}
def _run_exploitdb_poc(args):
--- a/validate_exploit.py
+++ b/validate_exploit.py
@@ -291,15 +291,26 @@ def run_vuln_validation_and_exploit(host: Host, campaign: Campaign):
cve_id = h.get("cve_id") or norm.get("facts", {}).get("vuln_id", "")
if cve_id:
merge(host.vulnerabilities, {
cve_id: {"verified": True, "source": "validation"}
})
- cve_context = {}
- if cve_id:
- cve_context = research_cve_context(
- cve_id, host,
- search_tools=search_catalog,
- search_tool_objects=search_tools_list
- )
+
+ # Curated map to bypass LLM hallucination for common CTF vulns
+ KNOWN_EXPLOITS = {
+ "vsftpd 2.3.4": "49757",
+ "shellshock": "34900",
+ "cve-2014-6271": "34900",
+ "samba 3.0.20": "42060"
+ }
+ desc_lower = h.get("description", "").lower()
+ cve_context = {}
+ for keyword, edb_id in KNOWN_EXPLOITS.items():
+ if keyword in desc_lower:
+ print(f"[+] Found known EDB-ID {edb_id} for {keyword}. Overriding CVE research.")
+ cve_context = {"edb_ids": [edb_id], "trigger_mechanism": "Known exploit"}
+ break
+ else:
+ if cve_id:
+ cve_context = research_cve_context(
+ cve_id, host,
+ search_tools=search_catalog,
+ search_tool_objects=search_tools_list
+ )
+
if cve_context and cve_context.get("edb_ids"):
all_edbs = []
import re #alr have it up top but wtv
@@ -441,6 +452,11 @@ def run_vuln_validation_and_exploit(host: Host, campaign: Campaign):
else:
reflection = evaluate_action_progress(host, norm, exploit_queue, "exploit_vuln")
print(f"[*] Reflector decision: {reflection.get('decision', 'continue')}")
+
+ # Suppress false positive foothold verification if no foothold was actually claimed
+ if reflection.get("decision") == "attempt_verify" and not host.foothold:
+ print("[-] Reflector requested verify without a foothold. Forcing replan.")
+ reflection["decision"] = "replan"
+
decision = reflection.get("decision", "continue")
if decision == "research_needed":
@@ -556,6 +572,11 @@ def run_vuln_validation_and_exploit(host: Host, campaign: Campaign):
reflection = evaluate_action_progress(host, {"error": err, "ok": False}, exploit_queue, "exploit_vuln")
print(f"[*] Reflector decision: {reflection.get('decision', 'continue')}")
reflection["reason"] = err
+
+ # Suppress false positive foothold verification on failed executions
+ if reflection.get("decision") == "attempt_verify":
+ print("[-] Reflector attempted to verify a foothold on a failed execution. Forcing replan.")
+ reflection["decision"] = "replan"
+
if err == "tool_missing_or_not_found":
reflection["reason"] = f"Tool {tool_str} is not available. Do not suggest it again. Choose a different exploit approach."
elif err == "insufficient_privilege":