Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
abyss-c2 — Full-stack C2 framework for IoT exploitation (CVE-2020-25078) with real-time web panel, multi-source target acquisition, vulnerability scanning, post-exploitation, persistence, lateral movement, and botnet orchestration. | Kitploit
Tools/GitHubGitHub/flags-alt/abyss-c2
Penetration Testing FrameworksReconnaissanceVulnerability ScannersExploit FrameworksIoT SecurityPersistence MechanismsLateral MovementPost-ExploitationCommand and ControlLearning & Education
GitHub
21194 months agoNot yet reviewed
flags-alt/abyss-c2

abyss-c2

Full-stack C2 framework for IoT exploitation (CVE-2020-25078) with real-time web panel, multi-source target acquisition, vulnerability scanning, post-exploitation, persistence, lateral movement, and botnet orchestration.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ABYSS C2 — HiSilicon DVR Exploit Framework

⚠️ EDUCATIONAL / DEMONSTRATION PURPOSES ONLY

This software is provided exclusively for educational and authorized security research purposes. It is designed to demonstrate common IoT vulnerabilities and post-exploitation techniques in a controlled, authorized environment.

You MUST NOT use this software on:

  • Any system or device you do not own
  • Any system or device you do not have explicit written authorization to test
  • Any production infrastructure without prior approval

The creator assumes NO responsibility or liability for any misuse, damage, or illegal activity conducted with this software. By using this software, you acknowledge that you are solely responsible for ensuring compliance with all applicable laws and regulations in your jurisdiction. Unauthorized access to computer systems is illegal under laws such as the Computer Fraud and Abuse Act (CFAA) and similar statutes worldwide.

This project exists to demonstrate:

  • How CVE-2020-25078 (HiSilicon DVR information disclosure) works
  • IoT device security weaknesses and why firmware updates matter
  • Post-exploitation techniques so defenders understand attacker TTPs
  • The importance of network segmentation and credential hygiene

If you don't own it, don't touch it.


Overview

ABYSS C2 is a full-stack Command & Control framework built in Python/Flask with a real-time dark-themed web panel. It demonstrates the full attack chain against IoT devices (specifically HiSilicon-based DVRs and IP cameras affected by CVE-2020-25078) — from reconnaissance and target acquisition to exploitation, post-exploitation, persistence, lateral movement, and data exfiltration.

CVE-2020-25078 is a path traversal / information disclosure vulnerability in HiSilicon Hi3516/Hi3518/Hi3519-based DVR/NVR devices. Unauthenticated attackers can access configuration files (/mnt/mtd/Config/Account*) containing plaintext admin credentials via directory traversal in the HTTP server.

Features

  • Real-time Web Dashboard — Dark-themed single-page UI with WebSocket live updates, 8 operational tabs, built-in terminal
  • Target Acquisition — Fetch vulnerable devices via Shodan, FOFA, ZoomEye APIs, plus free scraping (Censys, Onyphe, Shodan free facet, InternetDB)
  • Vulnerability Scanner — Multi-threaded TCP/HTTP scanner with CIDR support, DVR fingerprinting, credential extraction
  • Post-Exploitation — Interactive telnet shell, mass command execution across all owned devices, file upload
  • Web Vulnerability Scanning — CVE detection (Log4Shell, Spring4Shell, Confluence, Ghostcat, Struts2, Jenkins, GitLab, Exchange, F5 BIG-IP, Citrix, MOVEit, Ivanti, vCenter, PHPUnit, GeoServer, Solr, WordPress) and bug class testing (SQLi, LFI, SSRF, XXE, Command Injection, JWT attacks, Subdomain Takeover, HTTP Smuggling, GraphQL, CORS)
  • Network Exploitation — SMB/EternalBlue, RDP/BlueKeep, VNC, FTP, SNMP, Redis, MongoDB, Elasticsearch, CouchDB, MySQL/MSSQL/PostgreSQL, Memcached, IPMI, Mirai-IoT
  • Credential Attacks — Multi-protocol brute force (Telnet, SSH, FTP, HTTP Basic, WordPress, SMB, Redis, MySQL, MongoDB, VNC), credential spraying, credential vault
  • Reconnaissance — ASN lookup/import, full DNS reconnaissance (A/AAAA/MX/NS/TXT/SOA + subdomain brute + AXFR), JARM TLS fingerprinting, WAF detection, GeoIP lookup, multi-preset port scanning
  • Persistence — SSH public key injection, cron backdoors, init.d/systemd persistence, full automated deployment
  • Reverse Shells — Payload generator (bash, python, perl, php, nc, ruby, node, lua, etc.), multi-session listener with interaction
  • Pivoting — Multi-hop chain execution, TCP relay, SOCKS5 proxy through compromised hosts, automatic pivot scanning of local networks
  • Botnet Orchestration — Bot tagging/grouping, fan-out commands, health checks, payload deployment
  • Intel & Notifications — Telegram/Discord webhook notifications, AbuseIPDB integration, camera screenshot capture
  • Scheduler — Automated recurring tasks (scans, recon, health checks)

Architecture

panel/
├── server.py              # Flask + SocketIO C2 web panel (~1200 lines, 50+ API routes)
├── database.py            # SQLite ORM — 11 tables (cameras, vulns, creds, shells, DNS, ASN, etc.)
├── scanner.py             # Multi-threaded TCP/HTTP vulnerability scanner
├── exploit.py             # CVE-2020-25078 exploit — 37 vulnerable paths, 14 credential parsers
├── telnet_client.py       # Raw telnet command execution against owned devices
├── brute.py               # Multi-threaded brute force engine
├── web_exploit.py         # Full website vulnerability scanner (CMS detection, exposed files, SQLi)
├── web_cves.py            # CVE scanner — Log4Shell, Spring4Shell, Confluence, Ghostcat, etc.
├── web_bugs.py            # Bug class scanner — SQLi, LFI, SSRF, XXE, CmdI, JWT, etc.
├── web_brute.py           # Web brute force — forms, WordPress xmlrpc, Basic Auth, cred stuffing
├── network_exploit.py     # Network service exploit scanner — SMB, RDP, VNC, databases, etc.
├── cred_spray.py          # Multi-service credential spraying
├── recon_asn.py           # ASN import, organization search, IP-to-ASN lookup
├── recon_dns.py           # DNS recon — all record types, subdomain brute, zone transfer
├── recon_jarm.py          # JARM TLS server fingerprinting
├── recon_waf.py           # WAF detection and identification
├── recon_geoip.py         # GeoIP lookup and bulk IP geolocation
├── portscan.py            # TCP port scanner with banner grabbing, SYN option, multiple presets
├── persistence.py         # SSH key injection, cron backdoors, full deployment
├── reverse_shell.py       # Payload generator + multi-session listener
├── pivot_chain.py         # Multi-hop command execution and TCP relay
├── socks_pivot.py         # SOCKS5 proxy through compromised hosts
├── botnet.py              # Bot grouping, fan-out commands, health checks, payload deployment
├── intel.py               # Telegram/Discord webhooks, AbuseIPDB, screenshot capture
├── scheduler.py           # APScheduler-based job scheduling
├── proxy_rotation.py      # Proxy list rotation for stealth
├── stealth.py             # Traffic obfuscation utilities
├── inject_key.py          # SSH key injection variants
├── inject_ssh.py          # SSH-based injection
├── launch.py              # Simple launcher wrapper
├── auto_exploit.py        # Automated exploitation routines
├── templates/
│   └── index.html         # Dark-themed SPA — 8 tabs, real-time updates, terminal
└── requirements.txt       # Python dependencies

Database Schema

The SQLite database (cameras.db, auto-created on first run) contains 11 tables:

TablePurpose
camerasCompromised devices — IP, credentials, model, firmware, serial, status
command_logFull audit trail of every command executed and its output
scan_resultsScan history — which IPs were scanned and whether they were vulnerable
web_vulnsDiscovered web vulnerabilities (CVE, severity, evidence)
network_vulnsDiscovered network service vulnerabilities
shellsActive reverse shell sessions
dns_recordsDNS reconnaissance results
cred_vaultHarvested credentials organized by service
asn_targetsASN prefixes and imported IP ranges
web_targetsWeb targets with metadata (status, server, CMS, JARM, WAF)
scan_jobsJob tracking — scan type, target, duration, results count
scan_logModule-level activity log for auditing

Installation

Prerequisites

  • Python 3.10 or newer
  • pip
  • Git (optional)

Step 1 — Clone or download

git clone https://github.com/YOUR_USERNAME/abyss-c2.git
cd abyss-c2

Step 2 — Create virtual environment (recommended)

python -m venv venv

# Windows
venv\Scripts\activate
Download Tool