2008-07-22 15:51:01 +00:00
|
|
|
##
|
2010-04-30 08:40:19 +00:00
|
|
|
# This file is part of the Metasploit Framework and may be subject to
|
2008-07-22 15:51:01 +00:00
|
|
|
# redistribution and commercial restrictions. Please see the Metasploit
|
2012-02-21 01:40:50 +00:00
|
|
|
# web site for more information on licensing and terms of use.
|
|
|
|
# http://metasploit.com/
|
2008-07-22 15:51:01 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
|
|
|
|
require 'msf/core'
|
|
|
|
require 'resolv'
|
|
|
|
|
|
|
|
|
2008-10-02 05:23:59 +00:00
|
|
|
class Metasploit3 < Msf::Auxiliary
|
2008-07-22 15:51:01 +00:00
|
|
|
|
2008-10-02 05:23:59 +00:00
|
|
|
include Msf::Auxiliary::Report
|
2008-07-22 15:51:01 +00:00
|
|
|
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2008-07-22 15:51:01 +00:00
|
|
|
def initialize
|
|
|
|
super(
|
2008-07-23 21:59:57 +00:00
|
|
|
'Name' => 'DNS Spoofing Helper Service',
|
2008-07-22 15:51:01 +00:00
|
|
|
'Description' => %q{
|
|
|
|
This module provides a DNS service that returns TXT
|
|
|
|
records indicating information about the querying service.
|
|
|
|
Based on Dino Dai Zovi DNS code from Karma.
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2008-07-22 15:51:01 +00:00
|
|
|
},
|
|
|
|
'Author' => ['hdm', 'ddz'],
|
|
|
|
'License' => MSF_LICENSE,
|
|
|
|
'Actions' =>
|
|
|
|
[
|
2010-09-20 08:06:27 +00:00
|
|
|
[ 'Service' ]
|
2008-07-22 15:51:01 +00:00
|
|
|
],
|
2010-04-30 08:40:19 +00:00
|
|
|
'PassiveActions' =>
|
2008-07-22 15:51:01 +00:00
|
|
|
[
|
|
|
|
'Service'
|
|
|
|
],
|
|
|
|
'DefaultAction' => 'Service'
|
|
|
|
)
|
|
|
|
|
|
|
|
register_options(
|
|
|
|
[
|
|
|
|
OptAddress.new('SRVHOST', [ true, "The local host to listen on.", '0.0.0.0' ]),
|
|
|
|
OptPort.new('SRVPORT', [ true, "The local port to listen on.", 53 ]),
|
|
|
|
], self.class)
|
|
|
|
end
|
|
|
|
|
2010-04-30 08:40:19 +00:00
|
|
|
|
|
|
|
def run
|
2008-07-22 15:51:01 +00:00
|
|
|
@targ = datastore['TARGETHOST']
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2008-07-22 15:51:01 +00:00
|
|
|
if(@targ and @targ.strip.length == 0)
|
|
|
|
@targ = nil
|
|
|
|
end
|
|
|
|
|
|
|
|
@port = datastore['SRVPORT'].to_i
|
|
|
|
|
2008-07-23 21:59:57 +00:00
|
|
|
# MacOS X workaround
|
|
|
|
::Socket.do_not_reverse_lookup = true
|
|
|
|
|
|
|
|
@sock = ::UDPSocket.new()
|
|
|
|
@sock.setsockopt(::Socket::SOL_SOCKET, ::Socket::SO_REUSEADDR, 1)
|
|
|
|
@sock.bind(datastore['SRVHOST'], @port)
|
|
|
|
@run = true
|
|
|
|
|
2008-07-22 15:51:01 +00:00
|
|
|
# Wrap in exception handler
|
|
|
|
begin
|
2008-07-23 21:59:57 +00:00
|
|
|
while @run
|
2008-07-26 02:53:49 +00:00
|
|
|
reply = false
|
2008-07-23 21:59:57 +00:00
|
|
|
packet, addr = @sock.recvfrom(65535)
|
|
|
|
if (packet.length == 0)
|
|
|
|
break
|
2008-07-22 15:51:01 +00:00
|
|
|
end
|
2008-07-23 21:59:57 +00:00
|
|
|
|
2008-07-26 02:59:56 +00:00
|
|
|
names = []
|
2008-07-23 21:59:57 +00:00
|
|
|
request = Resolv::DNS::Message.decode(packet)
|
|
|
|
|
|
|
|
request.each_question {|name, typeclass|
|
|
|
|
tc_s = typeclass.to_s().gsub(/^Resolv::DNS::Resource::/, "")
|
|
|
|
|
|
|
|
request.qr = 1
|
|
|
|
request.ra = 1
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2008-07-26 02:59:56 +00:00
|
|
|
names << "IN #{tc_s} #{name}"
|
2008-07-23 21:59:57 +00:00
|
|
|
case tc_s
|
|
|
|
when 'IN::TXT'
|
2010-04-30 08:40:19 +00:00
|
|
|
print_status("#{Time.now} PASSED #{addr[3]}:#{addr[1]} XID #{request.id} #{name}")
|
2008-07-26 02:59:56 +00:00
|
|
|
answer = Resolv::DNS::Resource::IN::TXT.new("#{addr[3]}:#{addr[1]} #{names.join(",")}")
|
2008-07-23 21:59:57 +00:00
|
|
|
request.add_answer(name, 1, answer)
|
2008-07-26 02:53:49 +00:00
|
|
|
reply = true
|
2008-07-23 21:59:57 +00:00
|
|
|
end
|
|
|
|
}
|
2010-04-30 08:40:19 +00:00
|
|
|
|
2008-07-26 02:59:56 +00:00
|
|
|
if(reply)
|
|
|
|
@sock.send(request.encode(), 0, addr[3], addr[1])
|
|
|
|
else
|
2008-12-19 07:11:08 +00:00
|
|
|
print_status("#{Time.now} IGNORE #{addr[3]}:#{addr[1]} XID #{request.id} #{names.join(",")}")
|
2008-07-26 02:59:56 +00:00
|
|
|
end
|
2008-07-23 21:59:57 +00:00
|
|
|
end
|
|
|
|
|
2008-07-22 15:51:01 +00:00
|
|
|
# Make sure the socket gets closed on exit
|
|
|
|
rescue ::Exception => e
|
|
|
|
print_error("spoofhelper: #{e.class} #{e} #{e.backtrace}")
|
|
|
|
ensure
|
|
|
|
@sock.close
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-03-18 05:07:27 +00:00
|
|
|
end
|