htbscan.sh (2723B)
1 # htbscan — the usual nmap passes, written where htbbox looks for them. 2 # 3 # htbscan [target] quick: -sC -sV, top 1000 ports → recon/quick 4 # htbscan full [target] -p- sweep, then -sC -sV on what is open 5 # → recon/full, recon/targeted 6 # htbscan ports 22,80 [target] -sC -sV on just these → recon/targeted 7 # htbscan udp [target] top 100 UDP (sudo) → recon/udp 8 # 9 # Target: the argument, else the current htbtarget. Output: $BOXDIR/recon when 10 # a box is current (htbbox use), else ./recon. Every pass is -oA, and when a 11 # box is current the result is imported with `htbbox ports`, so box.json and 12 # `htbbox info` show the ports without another step. 13 # 14 # The IceBreaker nmap-init / nmap-allports / nmap-targeted trio, folded into 15 # one command; `full` runs the targeted pass itself instead of making you copy 16 # the port list across. 17 18 STATE="${XDG_STATE_HOME:-$HOME/.local/state}/htb" 19 20 mode=quick 21 case "${1:-}" in 22 -h | --help) echo "usage: htbscan [quick|full|udp|ports <list>] [target]"; exit 0 ;; 23 quick | full | udp) mode=$1; shift ;; 24 ports) 25 mode=ports 26 plist=${2:-} 27 case "$plist" in 28 '' | *[!0-9,-]*) echo "htbscan: ports wants a list like 22,80,445" >&2; exit 2 ;; 29 esac 30 shift 2 31 ;; 32 esac 33 34 target=${1:-} 35 if [ -z "$target" ] && [ -s "$STATE/target" ]; then target=$(cat "$STATE/target"); fi 36 target=${target:-${TARGET:-}} 37 if [ -z "$target" ]; then 38 echo "htbscan: no target — htbscan <ip>, or htbtarget <ip> first" >&2 39 exit 2 40 fi 41 42 box="" 43 if [ -s "$STATE/box" ] && dir=$(htbbox path 2>/dev/null); then 44 box=$(cat "$STATE/box") 45 out="$dir/recon" 46 else 47 out="$PWD/recon" 48 fi 49 mkdir -p "$out" 50 51 run() { 52 echo "» nmap $*" >&2 53 "$@" 54 } 55 56 ingest() { 57 if [ -n "$box" ]; then htbbox ports "$1.xml" || true; fi 58 } 59 60 case "$mode" in 61 quick) 62 run nmap -sC -sV -oA "$out/quick" "$target" 63 ingest "$out/quick" 64 ;; 65 full) 66 run nmap -p- --min-rate 5000 -T4 -oA "$out/full" "$target" 67 open=$(grep -oE '[0-9]+/open/tcp' "$out/full.gnmap" | cut -d/ -f1 | sort -un | paste -sd, -) || true 68 if [ -z "$open" ]; then 69 echo "htbscan: no open TCP ports found (host down? try -Pn: nmap -Pn -p- $target)" >&2 70 exit 1 71 fi 72 echo "open: $open" >&2 73 run nmap -sC -sV -p"$open" -oA "$out/targeted" "$target" 74 ingest "$out/targeted" 75 ;; 76 ports) 77 run nmap -sC -sV -p"$plist" -oA "$out/targeted" "$target" 78 ingest "$out/targeted" 79 ;; 80 udp) 81 # Root output in the user's box tree: hand the files back afterwards. 82 run sudo "$(command -v nmap)" -sU --top-ports 100 -oA "$out/udp" "$target" 83 sudo chown "$(id -u):$(id -g)" "$out"/udp.* 84 ingest "$out/udp" 85 ;; 86 esac