Skip to content

Add legba module for bruteforcing various services - #2530

Closed
christianfl wants to merge 2 commits into
blacklanternsecurity:devfrom
svaredteam:add_module_legba
Closed

Add legba module for bruteforcing various services#2530
christianfl wants to merge 2 commits into
blacklanternsecurity:devfrom
svaredteam:add_module_legba

Conversation

@christianfl

@christianfl christianfl commented Jul 18, 2025

Copy link
Copy Markdown
Contributor

Hey there!

Saw the discussion on: #1689

We developed a Legba module internally and I did a thorough review. Would you mind include it and/or have some comments?

Best wishes,
Christian

Supported protocols

  • SSH
  • FTP
  • TELNET
  • VNC
  • MSSQL
  • MySQL
  • PostgreSQL

Screenshot

image

ToDo

  • Write tests
  • Support all distros
  • Manual tests

@christianfl
christianfl marked this pull request as draft July 18, 2025 16:02
@TheTechromancer

Copy link
Copy Markdown
Contributor

This looks great, nice work! Legba has been a much requested module.

The trick will be writing tests for the different protocols, and also getting Legba to compile properly on all the different platforms.

@Vinnie64 may be able to help as he's been working on something similar to this

@christianfl

Copy link
Copy Markdown
Contributor Author

Nice! I can start working on it and see how it goes. Input from @Vinnie64 is also appreciated

@christianfl

Copy link
Copy Markdown
Contributor Author

I think the distro tests are now failing because deps_ansible run before deps_common:

Is it intended this way? At least I expected it to be the other way around @TheTechromancer

@codecov

codecov Bot commented Jul 28, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 84.09091% with 21 lines in your changes missing coverage. Please review.
✅ Project coverage is 92%. Comparing base (580fe5e) to head (e9f694f).
⚠️ Report is 43 commits behind head on dev.

Files with missing lines Patch % Lines
bbot/modules/deadly/legba.py 79% 19 Missing ⚠️
...test/test_step_2/module_tests/test_module_legba.py 96% 2 Missing ⚠️
Additional details and impacted files
@@          Coverage Diff          @@
##             dev   #2530   +/-   ##
=====================================
- Coverage     92%     92%   -0%     
=====================================
  Files        411     411           
  Lines      34054   34139   +85     
=====================================
+ Hits       31072   31134   +62     
- Misses      2982    3005   +23     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheTechromancer

TheTechromancer commented Jul 28, 2025

Copy link
Copy Markdown
Contributor

deps_ansible run before deps_common

I think deps_common should run first. I'll see about fixing.

EDIT:

@TheTechromancer

Copy link
Copy Markdown
Contributor

@christianfl that fix has been merged; you may need to rebase from dev.

@christianfl

Copy link
Copy Markdown
Contributor Author

Thanks @TheTechromancer !
Looking good, Arch and Fedora left

@christianfl
christianfl force-pushed the add_module_legba branch 2 times, most recently from c82ab51 to 1f5bd15 Compare August 25, 2025 13:16
@christianfl
christianfl marked this pull request as ready for review August 26, 2025 11:11
@christianfl

Copy link
Copy Markdown
Contributor Author

Hey! Did a bit of work again 😎

Feedback welcome! If you'd consider merging, feel free to squash the commits into one.

@christianfl

Copy link
Copy Markdown
Contributor Author

Saw that you are in the process of deprecate vulnerability events in favor of finding events here. Changed code accordingly. Even if severity and confidence are not yet supported attributes of finding, it still runs with the current changes.

@liquidsec

Copy link
Copy Markdown
Collaborator

Saw that you are in the process of deprecate vulnerability events in favor of finding events here. Changed code accordingly. Even if severity and confidence are not yet supported attributes of finding, it still runs with the current changes.

Hi, yes this is happening - but it wont make into stable until 3.0. Could be a while before that happens.

Going to try to test this out next week, from what I had a chance to look at so far, looks great. Really appreciate all the work writing tests and supporting all the distros, etc.

@christianfl

Copy link
Copy Markdown
Contributor Author

You're very welcome! Ok good to know, cool to see those event type merged. Feel free to ping me in case anything's needed here.

@TheTechromancer

TheTechromancer commented Sep 3, 2025

Copy link
Copy Markdown
Contributor

Fantastic work on this module. A couple small changes and then it should be good to merge:

  1. Let's use the scan's temp directory instead of /tmp
  2. We don't need to specify defaults in the option descriptions since they're already shown in bbot -mh legba
diff --git a/bbot/modules/deadly/legba.py b/bbot/modules/deadly/legba.py
index b6d7da6e4..91d7b5488 100644
--- a/bbot/modules/deadly/legba.py
+++ b/bbot/modules/deadly/legba.py
@@ -41,15 +41,15 @@ class legba(BaseModule):
     }
 
     options_desc = {
-        "ssh_wordlist": "Wordlist URL for SSH combined username:password wordlist, newline separated (default https://raw.githubusercontent.com/danielmiessler/SecLists/refs/heads/master/Passwords/Default-Credentials/ssh-betterdefaultpasslist.txt)",
-        "ftp_wordlist": "Wordlist URL for FTP combined username:password wordlist, newline separated (default https://raw.githubusercontent.com/danielmiessler/SecLists/refs/heads/master/Passwords/Default-Credentials/ftp-betterdefaultpasslist.txt)",
-        "telnet_wordlist": "Wordlist URL for TELNET combined username:password wordlist, newline separated (default https://raw.githubusercontent.com/danielmiessler/SecLists/refs/heads/master/Passwords/Default-Credentials/telnet-betterdefaultpasslist.txt)",
-        "vnc_wordlist": "Wordlist URL for VNC password wordlist, newline separated (default https://raw.githubusercontent.com/danielmiessler/SecLists/refs/heads/master/Passwords/Default-Credentials/vnc-betterdefaultpasslist.txt)",
-        "mssql_wordlist": "Wordlist URL for MSSQL combined username:password wordlist, newline separated (default https://raw.githubusercontent.com/danielmiessler/SecLists/refs/heads/master/Passwords/Default-Credentials/mssql-betterdefaultpasslist.txt)",
-        "mysql_wordlist": "Wordlist URL for MySQL combined username:password wordlist, newline separated (default https://raw.githubusercontent.com/danielmiessler/SecLists/refs/heads/master/Passwords/Default-Credentials/mysql-betterdefaultpasslist.txt)",
-        "postgresql_wordlist": "Wordlist URL for PostgreSQL combined username:password wordlist, newline separated (default https://raw.githubusercontent.com/danielmiessler/SecLists/refs/heads/master/Passwords/Default-Credentials/postgres-betterdefaultpasslist.txt)",
-        "concurrency": "Number of concurrent workers, gets overridden for SSH (default 3)",
-        "rate_limit": "Limit the number of requests per second, gets overridden for SSH (default 3)",
+        "ssh_wordlist": "Wordlist URL for SSH combined username:password wordlist, newline separated",
+        "ftp_wordlist": "Wordlist URL for FTP combined username:password wordlist, newline separated",
+        "telnet_wordlist": "Wordlist URL for TELNET combined username:password wordlist, newline separated",
+        "vnc_wordlist": "Wordlist URL for VNC password wordlist, newline separated",
+        "mssql_wordlist": "Wordlist URL for MSSQL combined username:password wordlist, newline separated",
+        "mysql_wordlist": "Wordlist URL for MySQL combined username:password wordlist, newline separated",
+        "postgresql_wordlist": "Wordlist URL for PostgreSQL combined username:password wordlist, newline separated",
+        "concurrency": "Number of concurrent workers, gets overridden for SSH",
+        "rate_limit": "Limit the number of requests per second, gets overridden for SSH",
     }
 
     deps_common = ["rust"]
@@ -120,7 +120,7 @@ class legba(BaseModule):
     ]
 
     async def setup(self):
-        self.output_dir = "/tmp/legba-output"
+        self.output_dir = self.scan.temp_dir / "legba-output"
         self.helpers.mkdir(self.output_dir)
 
         return True

@christianfl
christianfl force-pushed the add_module_legba branch 2 times, most recently from 886f709 to 5bac4ad Compare September 4, 2025 07:23
@christianfl

christianfl commented Sep 4, 2025

Copy link
Copy Markdown
Contributor Author

Thanks for reviewing! I applied the suggested changes but the test is failing for me locally. I'll have to look at it later.

@christianfl

Copy link
Copy Markdown
Contributor Author

My fault 😁 Works again. I squashed commits so I think it's ready to be merged!

@christianfl

Copy link
Copy Markdown
Contributor Author

Just FYI, I think the one failed test was only due to a CI hickup.

@TheTechromancer

Copy link
Copy Markdown
Contributor

@christianfl thanks again for your work on this. I want to merge it but it's adding 30 minutes to the tests. I noticed even when running it on my laptop it takes upwards of 10 minutes to compile 😬

I hate to ask since I know you already fought with the ansible stuff. But now that legba finally has precompiled releases, can we opt for downloading those directly?

@christianfl

Copy link
Copy Markdown
Contributor Author

No worries @TheTechromancer
A colleague of mine was working on this already, he'll push the changes to the branch directly.

@TheTechromancer

Copy link
Copy Markdown
Contributor

Any update on this? We got so close, would love to get it merged!

@christianfl

Copy link
Copy Markdown
Contributor Author

Sorry for the delay, we were exceedingly busy. We'll look at it soon. Be assured, I can only rest once this is merged!

…or legba

Move away from compiling legba locally to reduce build time
{
"name": "Download legba (x86)",
"unarchive": {
"src": "https://github.com/evilsocket/legba/releases/download/#{BBOT_MODULES_LEGBA_VERSION}/legba-#{BBOT_MODULES_LEGBA_VERSION}-linux-x86_64.tar.gz",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should be able to do this all in one go similar to here:

"src": "https://github.com/projectdiscovery/httpx/releases/download/v#{BBOT_MODULES_HTTPX_VERSION}/httpx_#{BBOT_MODULES_HTTPX_VERSION}_#{BBOT_OS}_#{BBOT_CPU_ARCH}.zip",

@TheTechromancer

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants