NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

htbscan.sh (2723B)


      1 # htbscan — the usual nmap passes, written where htbbox looks for them.
      2 #
      3 #   htbscan [target]           quick: -sC -sV, top 1000 ports   → recon/quick
      4 #   htbscan full [target]      -p- sweep, then -sC -sV on what is open
      5 #                                                    → recon/full, recon/targeted
      6 #   htbscan ports 22,80 [target]  -sC -sV on just these → recon/targeted
      7 #   htbscan udp [target]       top 100 UDP (sudo)      → recon/udp
      8 #
      9 # Target: the argument, else the current htbtarget. Output: $BOXDIR/recon when
     10 # a box is current (htbbox use), else ./recon. Every pass is -oA, and when a
     11 # box is current the result is imported with `htbbox ports`, so box.json and
     12 # `htbbox info` show the ports without another step.
     13 #
     14 # The IceBreaker nmap-init / nmap-allports / nmap-targeted trio, folded into
     15 # one command; `full` runs the targeted pass itself instead of making you copy
     16 # the port list across.
     17 
     18 STATE="${XDG_STATE_HOME:-$HOME/.local/state}/htb"
     19 
     20 mode=quick
     21 case "${1:-}" in
     22   -h | --help) echo "usage: htbscan [quick|full|udp|ports <list>] [target]"; exit 0 ;;
     23   quick | full | udp) mode=$1; shift ;;
     24   ports)
     25     mode=ports
     26     plist=${2:-}
     27     case "$plist" in
     28       '' | *[!0-9,-]*) echo "htbscan: ports wants a list like 22,80,445" >&2; exit 2 ;;
     29     esac
     30     shift 2
     31     ;;
     32 esac
     33 
     34 target=${1:-}
     35 if [ -z "$target" ] && [ -s "$STATE/target" ]; then target=$(cat "$STATE/target"); fi
     36 target=${target:-${TARGET:-}}
     37 if [ -z "$target" ]; then
     38   echo "htbscan: no target — htbscan <ip>, or htbtarget <ip> first" >&2
     39   exit 2
     40 fi
     41 
     42 box=""
     43 if [ -s "$STATE/box" ] && dir=$(htbbox path 2>/dev/null); then
     44   box=$(cat "$STATE/box")
     45   out="$dir/recon"
     46 else
     47   out="$PWD/recon"
     48 fi
     49 mkdir -p "$out"
     50 
     51 run() {
     52   echo "» nmap $*" >&2
     53   "$@"
     54 }
     55 
     56 ingest() {
     57   if [ -n "$box" ]; then htbbox ports "$1.xml" || true; fi
     58 }
     59 
     60 case "$mode" in
     61   quick)
     62     run nmap -sC -sV -oA "$out/quick" "$target"
     63     ingest "$out/quick"
     64     ;;
     65   full)
     66     run nmap -p- --min-rate 5000 -T4 -oA "$out/full" "$target"
     67     open=$(grep -oE '[0-9]+/open/tcp' "$out/full.gnmap" | cut -d/ -f1 | sort -un | paste -sd, -) || true
     68     if [ -z "$open" ]; then
     69       echo "htbscan: no open TCP ports found (host down? try -Pn: nmap -Pn -p- $target)" >&2
     70       exit 1
     71     fi
     72     echo "open: $open" >&2
     73     run nmap -sC -sV -p"$open" -oA "$out/targeted" "$target"
     74     ingest "$out/targeted"
     75     ;;
     76   ports)
     77     run nmap -sC -sV -p"$plist" -oA "$out/targeted" "$target"
     78     ingest "$out/targeted"
     79     ;;
     80   udp)
     81     # Root output in the user's box tree: hand the files back afterwards.
     82     run sudo "$(command -v nmap)" -sU --top-ports 100 -oA "$out/udp" "$target"
     83     sudo chown "$(id -u):$(id -g)" "$out"/udp.*
     84     ingest "$out/udp"
     85     ;;
     86 esac