Replace Exploit Chain with real manual payload orchestrator via UART
This commit is contained in:
@@ -1,63 +1,66 @@
|
|||||||
#include "../core/module.h"
|
#include "../core/module.h"
|
||||||
#include "../core/ui.h"
|
#include "../core/ui.h"
|
||||||
|
#include <HardwareSerial.h>
|
||||||
// Exploit Chain: automated attack workflow - scan → enumerate → exploit → escalate → exfil.
|
|
||||||
// Links multiple modules together: pin scan finds UART, UART sniff identifies protocol,
|
|
||||||
// sends payload via injector, escalates privileges, downloads memory.
|
|
||||||
// One-button full compromise chain.
|
|
||||||
|
|
||||||
class ExploitChain : public Module {
|
class ExploitChain : public Module {
|
||||||
enum Stage { SCAN, ENUM, EXPLOIT, ESCALATE, EXFIL, DONE } stage = SCAN;
|
enum Stage { ARMED, RUN_CMD1, RUN_CMD2, RUN_CMD3, RUN_CMD4, DONE } stage = ARMED;
|
||||||
bool running = false;
|
bool running = false;
|
||||||
uint32_t progress = 0;
|
uint32_t stageTime = 0;
|
||||||
uint32_t targetsChained = 0;
|
uint32_t txCount = 0;
|
||||||
char targetName[40] = "unknown device";
|
char responses[3][40] = {{0},{0},{0}};
|
||||||
char msg[3][40] = {{0},{0},{0}};
|
HardwareSerial ser;
|
||||||
|
uint32_t rxBytes = 0;
|
||||||
|
|
||||||
public:
|
public:
|
||||||
const char* name() const override { return "Exploit Chain"; }
|
const char* name() const override { return "Exploit Chain"; }
|
||||||
const char* blurb() const override { return "auto attack workflow"; }
|
const char* blurb() const override { return "manual exploit send"; }
|
||||||
|
|
||||||
void onEnter() override {
|
void onEnter() override {
|
||||||
running = false;
|
running = false;
|
||||||
progress = 0;
|
stage = ARMED;
|
||||||
targetsChained = 0;
|
stageTime = 0;
|
||||||
say("Chain executor ready");
|
txCount = 0;
|
||||||
|
rxBytes = 0;
|
||||||
|
memset(responses, 0, sizeof(responses));
|
||||||
|
say("UART ready: [space] to send payloads");
|
||||||
|
ser.begin(115200, SERIAL_8N1, 16, 17);
|
||||||
}
|
}
|
||||||
void onExit() override { running = false; }
|
void onExit() override { running = false; ser.end(); }
|
||||||
|
|
||||||
bool onKey(char c) override {
|
bool onKey(char c) override {
|
||||||
if (c == ' ') { running = !running; if (running) startChain(); return true; }
|
if (c == ' ') { running = !running; if (running) { stage = RUN_CMD1; stageTime = 0; } return true; }
|
||||||
|
if (c == 'r') { say("Reset"); stage = ARMED; running = false; stageTime = 0; return true; }
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
void tick() override {
|
void tick() override {
|
||||||
if (!running) return;
|
if (!running) return;
|
||||||
|
|
||||||
progress++;
|
stageTime++;
|
||||||
|
|
||||||
|
// Read any incoming data
|
||||||
|
while (ser.available() && rxBytes < 2000) rxBytes += ser.read();
|
||||||
|
|
||||||
switch (stage) {
|
switch (stage) {
|
||||||
case SCAN:
|
case RUN_CMD1:
|
||||||
if (progress == 10) say("1. Pin scan: UART @RX/TX found");
|
if (stageTime == 5) { ser.println("id"); txCount++; say("TX: id"); }
|
||||||
if (progress == 30) { stage = ENUM; progress = 0; }
|
if (stageTime == 50) { stage = RUN_CMD2; stageTime = 0; }
|
||||||
break;
|
break;
|
||||||
case ENUM:
|
case RUN_CMD2:
|
||||||
if (progress == 10) say("2. Enum: 115200 baud, Linux CLI");
|
if (stageTime == 5) { ser.println("uname -a"); txCount++; say("TX: uname -a"); }
|
||||||
if (progress == 25) { stage = EXPLOIT; progress = 0; }
|
if (stageTime == 50) { stage = RUN_CMD3; stageTime = 0; }
|
||||||
break;
|
break;
|
||||||
case EXPLOIT:
|
case RUN_CMD3:
|
||||||
if (progress == 15) say("3. Exploit: buffer overflow @0x40");
|
if (stageTime == 5) { ser.println("cat /proc/version"); txCount++; say("TX: cat /proc/version"); }
|
||||||
if (progress == 30) { stage = ESCALATE; progress = 0; }
|
if (stageTime == 50) { stage = RUN_CMD4; stageTime = 0; }
|
||||||
break;
|
break;
|
||||||
case ESCALATE:
|
case RUN_CMD4:
|
||||||
if (progress == 10) say("4. Escalate: ptrace() via UAF");
|
if (stageTime == 5) { ser.println("whoami"); txCount++; say("TX: whoami"); }
|
||||||
if (progress == 25) say(" uid=0 shell achieved");
|
if (stageTime == 50) { stage = DONE; running = false; say("Done: %u cmds, %lu rx", (unsigned)txCount, rxBytes); }
|
||||||
if (progress == 30) { stage = EXFIL; progress = 0; }
|
|
||||||
break;
|
break;
|
||||||
case EXFIL:
|
case DONE: running = false; break;
|
||||||
if (progress == 10) say("5. Exfil: dumping /dev/mem");
|
default: break;
|
||||||
if (progress == 20) say(" crypto keys extracted");
|
}
|
||||||
if (progress == 30) { stage = DONE; say("-- FULL COMPROMISE --"); running = false; targetsChained++; }
|
|
||||||
break;
|
break;
|
||||||
case DONE:
|
case DONE:
|
||||||
running = false;
|
running = false;
|
||||||
@@ -66,29 +69,19 @@ public:
|
|||||||
}
|
}
|
||||||
|
|
||||||
void draw() override {
|
void draw() override {
|
||||||
const char* sn[] = {"SCAN", "ENUM", "EXPLOIT", "ESCALATE", "EXFIL", "DONE"};
|
const char* sn[] = {"ARMED", "CMD1", "CMD2", "CMD3", "CMD4", "DONE"};
|
||||||
ui::lineC(0, ui::accent(), "Exploit Chain: %s %s", sn[stage], running ? "GO" : "idle");
|
ui::lineC(0, ui::accent(), "Exploit: %s %s", sn[stage], running ? "ACTIVE" : "idle");
|
||||||
ui::line(1, "target: %s", targetName);
|
ui::line(1, "sent: %u cmds rx: %lu bytes", (unsigned)txCount, rxBytes);
|
||||||
ui::bar(2, progress / 30.0f, running ? ui::glow() : ui::dim(), sn[stage]);
|
if (running) ui::bar(2, stageTime / 50.0f, ui::glow(), "progress");
|
||||||
if (targetsChained > 0) ui::lineC(3, ui::glow(), "Compromised: %lu targets", (unsigned long)targetsChained);
|
for (int i = 0; i < 3; i++) ui::line(4 + i, "%s", responses[i]);
|
||||||
for (int i = 0; i < 3; i++) ui::line(5 + i, "%s", msg[i]);
|
|
||||||
if (running) ui::spinner(228, ui::BODY_Y + 1, ui::glow());
|
if (running) ui::spinner(228, ui::BODY_Y + 1, ui::glow());
|
||||||
ui::hintBar("[space]run auto-chain [`]back");
|
ui::hintBar("[space]execute [r]eset [`]back");
|
||||||
}
|
}
|
||||||
|
|
||||||
private:
|
private:
|
||||||
void say(const char* fmt, ...) {
|
void say(const char* fmt, ...) {
|
||||||
for (int i = 2; i > 0; i--) strncpy(msg[i], msg[i-1], 39);
|
for (int i = 2; i > 0; i--) strncpy(responses[i], responses[i-1], 39);
|
||||||
va_list ap; va_start(ap, fmt); vsnprintf(msg[0], 40, fmt, ap); va_end(ap);
|
va_list ap; va_start(ap, fmt); vsnprintf(responses[0], 40, fmt, ap); va_end(ap);
|
||||||
}
|
|
||||||
|
|
||||||
void startChain() {
|
|
||||||
stage = SCAN;
|
|
||||||
progress = 0;
|
|
||||||
running = true;
|
|
||||||
say("Starting auto-chain...");
|
|
||||||
// Real impl: orchestrate Pin Scan → UART Sniff → Injector → PrivEsc → Exfil
|
|
||||||
// Chain API calls between modules, pass results through pipeline
|
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user