From 9788f0fadbe4380c65d90167ef3d733ba0bfdad3 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 25 Sep 2026 03:54:56 +0000 Subject: [PATCH] Replace Exploit Chain with real manual payload orchestrator via UART --- src/modules/exploitchain.cpp | 97 +++++++++++++++++------------------- 1 file changed, 45 insertions(+), 52 deletions(-) diff --git a/src/modules/exploitchain.cpp b/src/modules/exploitchain.cpp index a4eac29..3203ed1 100644 --- a/src/modules/exploitchain.cpp +++ b/src/modules/exploitchain.cpp @@ -1,63 +1,66 @@ #include "../core/module.h" #include "../core/ui.h" - -// Exploit Chain: automated attack workflow - scan → enumerate → exploit → escalate → exfil. -// Links multiple modules together: pin scan finds UART, UART sniff identifies protocol, -// sends payload via injector, escalates privileges, downloads memory. -// One-button full compromise chain. +#include class ExploitChain : public Module { - enum Stage { SCAN, ENUM, EXPLOIT, ESCALATE, EXFIL, DONE } stage = SCAN; + enum Stage { ARMED, RUN_CMD1, RUN_CMD2, RUN_CMD3, RUN_CMD4, DONE } stage = ARMED; bool running = false; - uint32_t progress = 0; - uint32_t targetsChained = 0; - char targetName[40] = "unknown device"; - char msg[3][40] = {{0},{0},{0}}; + uint32_t stageTime = 0; + uint32_t txCount = 0; + char responses[3][40] = {{0},{0},{0}}; + HardwareSerial ser; + uint32_t rxBytes = 0; public: const char* name() const override { return "Exploit Chain"; } - const char* blurb() const override { return "auto attack workflow"; } + const char* blurb() const override { return "manual exploit send"; } void onEnter() override { running = false; - progress = 0; - targetsChained = 0; - say("Chain executor ready"); + stage = ARMED; + stageTime = 0; + txCount = 0; + rxBytes = 0; + memset(responses, 0, sizeof(responses)); + say("UART ready: [space] to send payloads"); + ser.begin(115200, SERIAL_8N1, 16, 17); } - void onExit() override { running = false; } + void onExit() override { running = false; ser.end(); } bool onKey(char c) override { - if (c == ' ') { running = !running; if (running) startChain(); return true; } + if (c == ' ') { running = !running; if (running) { stage = RUN_CMD1; stageTime = 0; } return true; } + if (c == 'r') { say("Reset"); stage = ARMED; running = false; stageTime = 0; return true; } return false; } void tick() override { if (!running) return; - progress++; + stageTime++; + + // Read any incoming data + while (ser.available() && rxBytes < 2000) rxBytes += ser.read(); switch (stage) { - case SCAN: - if (progress == 10) say("1. Pin scan: UART @RX/TX found"); - if (progress == 30) { stage = ENUM; progress = 0; } + case RUN_CMD1: + if (stageTime == 5) { ser.println("id"); txCount++; say("TX: id"); } + if (stageTime == 50) { stage = RUN_CMD2; stageTime = 0; } break; - case ENUM: - if (progress == 10) say("2. Enum: 115200 baud, Linux CLI"); - if (progress == 25) { stage = EXPLOIT; progress = 0; } + case RUN_CMD2: + if (stageTime == 5) { ser.println("uname -a"); txCount++; say("TX: uname -a"); } + if (stageTime == 50) { stage = RUN_CMD3; stageTime = 0; } break; - case EXPLOIT: - if (progress == 15) say("3. Exploit: buffer overflow @0x40"); - if (progress == 30) { stage = ESCALATE; progress = 0; } + case RUN_CMD3: + if (stageTime == 5) { ser.println("cat /proc/version"); txCount++; say("TX: cat /proc/version"); } + if (stageTime == 50) { stage = RUN_CMD4; stageTime = 0; } break; - case ESCALATE: - if (progress == 10) say("4. Escalate: ptrace() via UAF"); - if (progress == 25) say(" uid=0 shell achieved"); - if (progress == 30) { stage = EXFIL; progress = 0; } + case RUN_CMD4: + if (stageTime == 5) { ser.println("whoami"); txCount++; say("TX: whoami"); } + if (stageTime == 50) { stage = DONE; running = false; say("Done: %u cmds, %lu rx", (unsigned)txCount, rxBytes); } break; - case EXFIL: - if (progress == 10) say("5. Exfil: dumping /dev/mem"); - if (progress == 20) say(" crypto keys extracted"); - if (progress == 30) { stage = DONE; say("-- FULL COMPROMISE --"); running = false; targetsChained++; } + case DONE: running = false; break; + default: break; + } break; case DONE: running = false; @@ -66,29 +69,19 @@ public: } void draw() override { - const char* sn[] = {"SCAN", "ENUM", "EXPLOIT", "ESCALATE", "EXFIL", "DONE"}; - ui::lineC(0, ui::accent(), "Exploit Chain: %s %s", sn[stage], running ? "GO" : "idle"); - ui::line(1, "target: %s", targetName); - ui::bar(2, progress / 30.0f, running ? ui::glow() : ui::dim(), sn[stage]); - if (targetsChained > 0) ui::lineC(3, ui::glow(), "Compromised: %lu targets", (unsigned long)targetsChained); - for (int i = 0; i < 3; i++) ui::line(5 + i, "%s", msg[i]); + const char* sn[] = {"ARMED", "CMD1", "CMD2", "CMD3", "CMD4", "DONE"}; + ui::lineC(0, ui::accent(), "Exploit: %s %s", sn[stage], running ? "ACTIVE" : "idle"); + ui::line(1, "sent: %u cmds rx: %lu bytes", (unsigned)txCount, rxBytes); + if (running) ui::bar(2, stageTime / 50.0f, ui::glow(), "progress"); + for (int i = 0; i < 3; i++) ui::line(4 + i, "%s", responses[i]); if (running) ui::spinner(228, ui::BODY_Y + 1, ui::glow()); - ui::hintBar("[space]run auto-chain [`]back"); + ui::hintBar("[space]execute [r]eset [`]back"); } private: void say(const char* fmt, ...) { - for (int i = 2; i > 0; i--) strncpy(msg[i], msg[i-1], 39); - va_list ap; va_start(ap, fmt); vsnprintf(msg[0], 40, fmt, ap); va_end(ap); - } - - void startChain() { - stage = SCAN; - progress = 0; - running = true; - say("Starting auto-chain..."); - // Real impl: orchestrate Pin Scan → UART Sniff → Injector → PrivEsc → Exfil - // Chain API calls between modules, pass results through pipeline + for (int i = 2; i > 0; i--) strncpy(responses[i], responses[i-1], 39); + va_list ap; va_start(ap, fmt); vsnprintf(responses[0], 40, fmt, ap); va_end(ap); } };