2013-03-07 23:53:19 +00:00
|
|
|
##
|
2013-10-15 18:50:46 +00:00
|
|
|
# This module requires Metasploit: http//metasploit.com/download
|
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
2013-03-07 23:53:19 +00:00
|
|
|
##
|
|
|
|
|
2012-01-24 16:16:56 +00:00
|
|
|
require 'msf/core'
|
|
|
|
require 'rex/proto/natpmp'
|
|
|
|
|
|
|
|
class Metasploit3 < Msf::Auxiliary
|
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
include Msf::Auxiliary::Report
|
|
|
|
include Msf::Auxiliary::Scanner
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def initialize
|
|
|
|
super(
|
|
|
|
'Name' => 'NAT-PMP External Address Scanner',
|
|
|
|
'Description' => 'Scan NAT devices for their external address using NAT-PMP',
|
|
|
|
'Author' => 'Jon Hart <jhart[at]spoofed.org>',
|
|
|
|
'License' => MSF_LICENSE
|
|
|
|
)
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
register_options(
|
|
|
|
[
|
|
|
|
Opt::RPORT(Rex::Proto::NATPMP::DefaultPort),
|
|
|
|
Opt::CHOST
|
|
|
|
],
|
|
|
|
self.class
|
|
|
|
)
|
|
|
|
end
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def run_host(host)
|
|
|
|
begin
|
|
|
|
udp_sock = Rex::Socket::Udp.create({
|
|
|
|
'LocalHost' => datastore['CHOST'] || nil,
|
|
|
|
'Context' => {'Msf' => framework, 'MsfExploit' => self}
|
|
|
|
})
|
|
|
|
add_socket(udp_sock)
|
|
|
|
vprint_status "#{host}:#{datastore['RPORT']} - NATPMP - Probing for external address"
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
udp_sock.sendto(Rex::Proto::NATPMP.external_address_request, host, datastore['RPORT'].to_i, 0)
|
|
|
|
while (r = udp_sock.recvfrom(12, 1.0) and r[1])
|
|
|
|
handle_reply(host, r)
|
|
|
|
end
|
|
|
|
rescue ::Interrupt
|
|
|
|
raise $!
|
|
|
|
rescue ::Rex::HostUnreachable, ::Rex::ConnectionTimeout, ::Rex::ConnectionRefused
|
|
|
|
nil
|
|
|
|
rescue ::Exception => e
|
|
|
|
print_error("#{host}:#{datastore['RPORT']} Unknown error: #{e.class} #{e}")
|
|
|
|
end
|
|
|
|
end
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def handle_reply(host, pkt)
|
|
|
|
return if not pkt[1]
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
if(pkt[1] =~ /^::ffff:/)
|
|
|
|
pkt[1] = pkt[1].sub(/^::ffff:/, '')
|
|
|
|
end
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
(ver, op, result, epoch, external_address) = Rex::Proto::NATPMP.parse_external_address_response(pkt[0])
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
if (result == 0)
|
|
|
|
print_status("#{host} -- external address #{external_address}")
|
|
|
|
end
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
# report the host we scanned as alive
|
|
|
|
report_host(
|
|
|
|
:host => host,
|
|
|
|
:state => Msf::HostState::Alive
|
|
|
|
)
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
# also report its external address as alive
|
|
|
|
if inside_workspace_boundary(external_address)
|
|
|
|
report_host(
|
|
|
|
:host => external_address,
|
|
|
|
:state => Msf::HostState::Alive
|
|
|
|
)
|
|
|
|
end
|
2012-01-24 16:16:56 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
# report NAT-PMP as being open
|
|
|
|
report_service(
|
|
|
|
:host => host,
|
|
|
|
:port => pkt[2],
|
|
|
|
:proto => 'udp',
|
|
|
|
:name => 'natpmp',
|
|
|
|
:state => Msf::ServiceState::Open
|
|
|
|
)
|
|
|
|
end
|
2012-01-24 16:16:56 +00:00
|
|
|
end
|