Sploitus

Exploit for blitzstrike

githubexploit Β· 2026-09-12

Exploit Code

README290 lines
## https://sploitus.com/exploit?id=F5248EA4-BB82-5C01-80E9-4F1E66BD8A42
BlitzStrike
MCP security-audit toolbelt β€” blitz triage β†’ eagle-eye trace β†’ strike verify, universal across every MCP client

---

## Overview

**BlitzStrike** is a Model Context Protocol (MCP) server (TypeScript / Bun) that
packages a 3-tier security-audit methodology as callable tools β€” and runs the
whole engagement **server-side**, so a single `run_engagement` call works from
Claude Code, Cursor, Hermes, OpenCode, Claude Desktop, Gemini, or any MCP client.

One rule drives every tool: **a scan hit is a HYPOTHESIS β€” a live test is the
VERDICT.** The toolbelt kills the two most common agent failures in security
auditing: grep-monkey false positives, and unverified hallucinated findings.

### The 3 tiers

| Tier | Name | What it does |
|---|---|---|
| 1 | **BLITZ** | Fast attack-surface triage. Map unauth entry points + dangerous sinks + auth gates. |
| 2 | **EAGLE-EYE** | Source-to-sink deep trace + chain enrichment (chains.json). |
| 3 | **STRIKE** | Live verification, recon, scope enforcement, and server-side orchestration. |

---

## Why TypeScript / Bun

- **Single static binary** via `bun build --compile` β€” ship one executable per platform.
- **Zero-install distribution** via `bunx blitzstrike` / `npx blitzstrike`.
- **MCP TypeScript SDK** first-class (`@modelcontextprotocol/sdk`).
- **One toolchain** for dev + test + build + compile.

---

## Quickstart (30 seconds)

```bash
# From source
git clone https://github.com/shinthink/blitzstrike.git
cd blitzstrike
bun install
bun run src/index.ts serve --mcp
```

Or a single pre-built binary:

```bash
./blitzstrike serve --mcp
```

---

## Client Configuration (works in any MCP client)

```json
{
  "mcpServers": {
    "blitzstrike": {
      "command": "blitzstrike",
      "args": ["serve", "--mcp"]
    }
  }
}
```

- **Claude Code / Desktop**: `claude_desktop_config.json` or `.mcp.json`
- **Cursor**: `.cursor/mcp.json`
- **OpenCode**: `.mcp.json`
- **Hermes**: `mcp_servers:` in `config.yaml`
- **Gemini / Copilot**: native MCP config

Run `blitzstrike install` to print the exact snippet.

---

## CLI

```bash
blitzstrike serve --mcp       # start MCP server over stdio (default)
blitzstrike doctor            # health check: runtime + 130-tool catalog + creds
blitzstrike install           # write MCP config to detected clients (Claude/Cursor/OpenCode)
blitzstrike install --dry-run # preview the config without writing
blitzstrike version           # print version
```

### What doctor checks

| Check | Status you'll see |
|---|---|
| Runtime (bun/node) | OK / FAIL + fix |
| Security tools catalog | 63/130 installed, 67 on-demand |
| FOFA credentials | OK / WARN + fix |
| Data layers (chains + tools-catalog) | present / missing |

Each issue carries a `fix:` line β€” no guessing.

### What install does

`blitzstrike install` detects which MCP client config files already exist
(Claude `~/.claude.json`, Cursor `~/.cursor/mcp.json`, project `.mcp.json`) and
**merges** the BlitzStrike server entry in β€” it never overwrites your existing
MCP servers. With no client detected, it prints the snippet for manual paste.

---

## Tools

### BLITZ β€” attack-surface triage

| Tool | Purpose |
|---|---|
| `blitz_scan(path, max_files)` | Scan a source tree: enumerate unauth entry points + dangerous sinks with file:line refs. |
| `blitz_file(path)` | Same scan, single file. |

### EAGLE-EYE β€” deep trace

| Tool | Purpose |
|---|---|
| `eagle_eye(path, symbol)` | Return a function's full body, sinks in scope, and auth gates in scope. |
| `eagle_grep(path, sink, max_hits)` | Precision sink grep β€” report a hit ONLY inside a function body, flagged guarded/un-guarded. |
| `enrich_scan(path, max_files)` | Scan + match detected sinks to escalation chains (chains.json). |

### STRIKE β€” verify + recon + orchestrate

| Tool | Purpose |
|---|---|
| `strike_verify(url, method, data, headers, marker, timeout)` | Live HTTP verification with marker + negative control. |
| `scope_check(target, scope, mode)` | Enforce scope before active testing (no-DoS, exclusion-aware, mode-gated). |
| `run_engagement(target, scope, mode, max_files)` | Full 3-tier audit in ONE call β€” scope gate β†’ triage β†’ chain enrichment β†’ findings. |
| `list_chains()` | List all escalation chains in the data layer. |
| `fofa_search(query, size, fields)` | FOFA asset index search (needs `FOFA_EMAIL` + `FOFA_KEY`). |
| `nvd_lookup(cve_id)` | CVE lookup from NVD 2.0 (no key required). |

### CATALOG β€” breadth layer (tools + skills knowledge base)

| Tool | Purpose |
|---|---|
| `tool_lookup(name)` | Look up a tool's command + flags + install + check. |
| `list_tools()` | List all catalog tools, grouped by category. |
| `skill_lookup(topic)` | Search the skills/ playbook knowledge base by topic. |
| `list_skills()` | List all skill playbooks. |
| `read_skill(name)` | Read the full content of a playbook. |
| `ensure_tool(name)` | Check if a tool is installed; if not, auto-install it. |

### MANUALS β€” deep tool reference + playbooks (wired into flow)

| Tool | Purpose |
|---|---|
| `read_tool_manual(name)` | Read a full deep manual for a tool (270+ manuals). |
| `list_manuals()` | List all manuals + playbooks. |
| `read_playbook(name)` | Read an engagement playbook (web-app, api-security, AD, etc.). |
| `list_playbooks()` | List all 17 engagement playbooks. |

### INTELLIGENCE β€” data layer (WAF + correlations + fuzzer)

| Tool | Purpose |
|---|---|
| `detect_waf(headers, body)` | Detect a WAF from response headers/body (139 signatures). |
| `tech_correlation(tech)` | Correlate tech to known vulns + CVEs (89 technologies). |
| `cve_correlation(cve)` | Correlate CVE to product + targets + severity (53 CVEs). |
| `port_correlation(port)` | Correlate port to service + attack vectors (103 ports). |
| `fuzzer_payloads(category)` | Fuzzing payloads + vulnerable patterns + chain rules. |
| `intel_summary()` | Counts of every intelligence dataset. |
| `payload_lookup(topic)` | Find exploit payloads (66 categories from PayloadsAllTheThings). |
| `read_payload(category)` | Read a full payload collection. |
| `template_lookup(topic)` | Find nuclei detection templates (11.9k YAML signatures). |

The intelligence layer (WAF signatures, tech/CVE/port correlations, fuzzer
data, vuln ontology, exploit payloads, nuclei detection templates) is sourced
from airecon (MIT), PayloadsAllTheThings (MIT), and nuclei-templates (MIT) β€”
loaded at runtime and wired into the tool surface above.

270 tool manuals + 17 playbooks from kali-pentest (Apache-2.0). These are NOT
decoration β€” they are wired into the flow:

- `tool_lookup(name)` auto-attaches the tool's full manual.
- `run_engagement()` attaches the relevant manual per matched chain's `tools` field.

### MEMORY β€” long-term knowledge (self-growing)

| Tool | Purpose |
|---|---|
| `remember(topic, content, type, tags, verified)` | Save a reusable insight (deduped). verified=true only if marker reflected + negative control inert. |
| `memory_lookup(query)` | Search memory by topic/tag/content, scored. |
| `memory_list()` | List all memory entries, grouped by type. |

Memory is append-only JSONL at `~/.blitzstrike/memory.jsonl` (override with
`BLITZSTRIKE_HOME`). `run_engagement` auto-captures matched escalation chains
as `pattern` entries (deduped by chain id), so the knowledge base grows with
every engagement β€” no duplicate spam, and only `verified=true` entries are
authoritative.

---

## Tools Catalog (tools-catalog.json)

130 self-written security tools (not copied from any project), each with command
base, key flags, install command per platform, check_installed probe, phase,
tags, alternatives, requires_root, pipes, and homepage.

| Category | Count | Examples |
|---|---|---|
| recon | 23 | subfinder, amass, httpx, naabu, katana, trufflehog |
| exploitation | 13 | sqlmap, commix, dalfox, hydra, hashcat, phpggc |
| blue-team (defensive) | 13 | suricata, zeek, osquery, wazuh, sigma, yara, trivy |
| reverse-engineering | 12 | ghidra, radare2, gdb, pwndbg, angr, binwalk |
| enumeration | 11 | nuclei, ffuf, gobuster, arjun, wafw00f |
| forensics | 10 | volatility3, autopsy, tshark, foremost, steghide |
| active-directory | 8 | netexec, impacket, bloodhound, certipy, kerbrute |
| mobile | 7 | frida, objection, mobsf, apktool, jadx |
| post-exploitation | 6 | linpeas, pspy, chisel, ligolo-ng, pwncat |
| red-team | 6 | sliver, havoc, metasploit, evilginx3, gophish |
| utility | 6 | curl, jq, anew, notify |
| web | 4 | wpscan, joomscan, droopescan, cmseek |
| wireless | 4 | aircrack-ng, wifite, bettercap |
| cloud | 4 | pacu, prowler, scoutsuite, cloudfox |
| crypto | 3 | hashid, ciphey, rsactftool |

## Skills Knowledge Base (skills/)

32 skill playbooks (markdown) β€” universal, license-safe hidden gems from the
internet (MIT). Our personal attack-tree playbooks were removed (they were
private methodology, not universal exploit scripts).

- **adversary-playbook (14, MIT)** β€” `ap-*` prefix. Rare offensive playbooks:
  cross-forest-trust-abuse, gitea-ci-injection, kerberos-trust-abuse,
  multi-domain-ad-attacks, client-side-crypto-forgery.
- **hack.proof (18, MIT)** β€” `hp-*` prefix. End-to-end audit playbooks:
  full-security-audit, smart-contract-audit, api-security-test, sast-code-review,
  container-image-scan, iac-cloud-posture.

See `ATTRIBUTION.md` for full license/copyright notices.

---

## Escalation Chains (chains.json)

22 data-driven escalation chains, each with ordered steps carrying:

- `tool_hint` β€” which BlitzStrike tool to use
- `success_criteria` β€” binary observable for the step
- `invariant_check` β€” the assumption that MUST hold for exploitation
- `negative_control` β€” how to refute the finding

Examples: `ssrf_cloud_metadata`, `lfi_log_poison_rce`, `appkey_leak_deserialization_rce`,
`hmac_empty_key_forgery`, `intval_form_id_bypass`, `extract_variable_injection_lfi`,
`split_controller_upload_bypass`, `race_condition_double_spend`, `ssti_template_injection_rce`,
`jwt_alg_confusion_forgery`, `cache_poisoning_xss`, `subdomain_takeover`, and more.

Edit `chains.json` to add knowledge β€” never hardcode in source.

---

## Environment Variables

| Variable | Required | Purpose |
|---|---|---|
| `FOFA_EMAIL` | For `fofa_search` | FOFA account email |
| `FOFA_KEY` | For `fofa_search` | FOFA API key |

All other tools need no credentials.

---

## Build

```bash
bun install          # deps
bun run typecheck    # tsc --noEmit
bun run build        # ESM bundle β†’ dist/index.js
bun run compile      # single static binary β†’ dist/blitzstrike
```

---

## Methodology Notes

- **Sink β‰  vuln.** A dangerous function in the same *file* as an unauth handler does not mean the handler calls it. Use `eagle_eye` to confirm scope.
- **File write β‰  RCE (CF-003).** A writable file must be *loaded by the runtime* to be execution.
- **Default server config only.** Default Apache `FilesMatch .+\.ph(ar|p|tml)$` has a `$` anchor β€” `.php.jpg` does not execute.
- **Every finding is a HYPOTHESIS** until `strike_verify` reflects your marker AND the chain's `negative_control` stays inert.

---

## Disclaimer

This tool is provided for educational and authorized security research only.
Do not use against systems without explicit permission from the owner.