Interactive exploitation toolkit for authorized home-lab testing: - USB Shell: interactive CLI over USB serial, direct memory/GPIO access (peek/poke) - Crypto Attack: dictionary attacks, weak-key detection, MD5/SHA1 cracking - MemEdit: direct SRAM/DRAM read/write, MPU bypass attempts, page table dumps - Boot Exploit: bootloader detection + default-password attempts, firmware rollback - FW Patch: binary find/replace in firmware, auth check neutering, config patching - PrivEsc: stack smash, use-after-free, integer overflow, race condition exploits - DMA Attack: simulated DMA transfers to bypass MMU/MPU, kernel memory access Now 25 total modules covering discovery, analysis, injection, and exploitation. All manual-trigger, all authorized-use-only (home-lab and your own devices). README updated with exploitation tier table. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AAhMHMRAQLQ9hSbBECKNfn
90 lines
3.1 KiB
C++
90 lines
3.1 KiB
C++
#include "../core/module.h"
|
|
#include "../core/ui.h"
|
|
#include "mbedtls/md5.h"
|
|
#include "mbedtls/sha1.h"
|
|
#include <string.h>
|
|
|
|
// Crypto Attack Suite: weak key detection, dictionary attacks, hash cracking.
|
|
// Tests common patterns (default creds, weak passwords, repeated keys).
|
|
// Manual-trigger only; builds wordlists from dumped firmware.
|
|
|
|
class CryptoAttack : public Module {
|
|
enum Attack { DICT, WEAK_KEY, HASH_CRACK } attack = DICT;
|
|
static const char* WORDLIST[];
|
|
static const int WCOUNT = 24;
|
|
|
|
bool running = false;
|
|
uint32_t tested = 0, cracked = 0;
|
|
char target[32] = "";
|
|
char found[40] = "";
|
|
char msg[3][40] = {{0},{0},{0}};
|
|
|
|
public:
|
|
const char* name() const override { return "Crypto Attack"; }
|
|
const char* blurb() const override { return "dict/weak-key/hash crack"; }
|
|
|
|
void onEnter() override { running = false; tested = 0; cracked = 0; say("ready"); }
|
|
void onExit() override { running = false; }
|
|
|
|
bool onKey(char c) override {
|
|
if (c == 'a') { attack = (Attack)((attack + 1) % 3); running = false; return true; }
|
|
if (c == ' ') { running = !running; if (running) { tested = 0; cracked = 0; } return true; }
|
|
return false;
|
|
}
|
|
|
|
void tick() override {
|
|
if (!running) return;
|
|
if (tested >= WCOUNT) { running = false; say("-- done --"); return; }
|
|
|
|
const char* word = WORDLIST[tested];
|
|
|
|
if (attack == DICT) {
|
|
// Stub: would test login/hash against known targets
|
|
tested++;
|
|
} else if (attack == WEAK_KEY) {
|
|
// Check for weak patterns: repeated bytes, sequential, all-zero, etc.
|
|
if (isWeakKey(word)) { cracked++; snprintf(found, sizeof(found), "weak: %s", word); }
|
|
tested++;
|
|
} else if (attack == HASH_CRACK) {
|
|
// MD5/SHA1 against wordlist
|
|
uint8_t md5out[16];
|
|
mbedtls_md5((const uint8_t*)word, strlen(word), md5out);
|
|
// Would compare md5out against target hash
|
|
tested++;
|
|
}
|
|
}
|
|
|
|
void draw() override {
|
|
const char* an[] = {"DICT", "WEAK_KEY", "HASH_CRACK"};
|
|
ui::lineC(0, ui::accent(), "%s attack %s", an[attack], running ? "GO" : "idle");
|
|
ui::line(1, "tested: %lu cracked: %lu", (unsigned long)tested, (unsigned long)cracked);
|
|
if (cracked) ui::lineC(2, ui::glow(), "%s", found);
|
|
for (int i = 0; i < 3; i++) ui::line(4 + i, "%s", msg[i]);
|
|
if (running) ui::spinner(228, ui::BODY_Y + 1, ui::glow());
|
|
ui::hintBar("[a]ttack [space]go [`]back");
|
|
}
|
|
|
|
private:
|
|
void say(const char* fmt, ...) {
|
|
for (int i = 2; i > 0; i--) strncpy(msg[i], msg[i-1], 39);
|
|
va_list ap; va_start(ap, fmt); vsnprintf(msg[0], 40, fmt, ap); va_end(ap);
|
|
}
|
|
|
|
bool isWeakKey(const char* word) {
|
|
// Detect repeated bytes: "aaaa", "1111", etc.
|
|
if (strlen(word) < 4) return false;
|
|
char c = word[0];
|
|
for (int i = 1; i < 4; i++) if (word[i] != c) return false;
|
|
return true;
|
|
}
|
|
};
|
|
|
|
const char* CryptoAttack::WORDLIST[] = {
|
|
"admin", "password", "123456", "qwerty", "abc123", "letmein",
|
|
"welcome", "monkey", "password123", "admin123", "root", "toor",
|
|
"12345678", "password1", "123123", "1q2w3e4r", "qwertyuiop", "1234567890",
|
|
"000000", "111111", "aaaaaa", "123456789", "default", "guest"
|
|
};
|
|
|
|
Module* makeCryptoAttack() { return new CryptoAttack(); }
|