Full-stack C2 framework for IoT exploitation (CVE-2020-25078) with real-time web panel, multi-source target acquisition, vulnerability scanning, post-exploitation, persistence, lateral movement, and botnet orchestration.
⚠️ EDUCATIONAL / DEMONSTRATION PURPOSES ONLY
This software is provided exclusively for educational and authorized security research purposes. It is designed to demonstrate common IoT vulnerabilities and post-exploitation techniques in a controlled, authorized environment.
You MUST NOT use this software on:
- Any system or device you do not own
- Any system or device you do not have explicit written authorization to test
- Any production infrastructure without prior approval
The creator assumes NO responsibility or liability for any misuse, damage, or illegal activity conducted with this software. By using this software, you acknowledge that you are solely responsible for ensuring compliance with all applicable laws and regulations in your jurisdiction. Unauthorized access to computer systems is illegal under laws such as the Computer Fraud and Abuse Act (CFAA) and similar statutes worldwide.
This project exists to demonstrate:
- How CVE-2020-25078 (HiSilicon DVR information disclosure) works
- IoT device security weaknesses and why firmware updates matter
- Post-exploitation techniques so defenders understand attacker TTPs
- The importance of network segmentation and credential hygiene
If you don't own it, don't touch it.
ABYSS C2 is a full-stack Command & Control framework built in Python/Flask with a real-time dark-themed web panel. It demonstrates the full attack chain against IoT devices (specifically HiSilicon-based DVRs and IP cameras affected by CVE-2020-25078) — from reconnaissance and target acquisition to exploitation, post-exploitation, persistence, lateral movement, and data exfiltration.
CVE-2020-25078 is a path traversal / information disclosure vulnerability in HiSilicon Hi3516/Hi3518/Hi3519-based DVR/NVR devices. Unauthenticated attackers can access configuration files (/mnt/mtd/Config/Account*) containing plaintext admin credentials via directory traversal in the HTTP server.
panel/
├── server.py # Flask + SocketIO C2 web panel (~1200 lines, 50+ API routes)
├── database.py # SQLite ORM — 11 tables (cameras, vulns, creds, shells, DNS, ASN, etc.)
├── scanner.py # Multi-threaded TCP/HTTP vulnerability scanner
├── exploit.py # CVE-2020-25078 exploit — 37 vulnerable paths, 14 credential parsers
├── telnet_client.py # Raw telnet command execution against owned devices
├── brute.py # Multi-threaded brute force engine
├── web_exploit.py # Full website vulnerability scanner (CMS detection, exposed files, SQLi)
├── web_cves.py # CVE scanner — Log4Shell, Spring4Shell, Confluence, Ghostcat, etc.
├── web_bugs.py # Bug class scanner — SQLi, LFI, SSRF, XXE, CmdI, JWT, etc.
├── web_brute.py # Web brute force — forms, WordPress xmlrpc, Basic Auth, cred stuffing
├── network_exploit.py # Network service exploit scanner — SMB, RDP, VNC, databases, etc.
├── cred_spray.py # Multi-service credential spraying
├── recon_asn.py # ASN import, organization search, IP-to-ASN lookup
├── recon_dns.py # DNS recon — all record types, subdomain brute, zone transfer
├── recon_jarm.py # JARM TLS server fingerprinting
├── recon_waf.py # WAF detection and identification
├── recon_geoip.py # GeoIP lookup and bulk IP geolocation
├── portscan.py # TCP port scanner with banner grabbing, SYN option, multiple presets
├── persistence.py # SSH key injection, cron backdoors, full deployment
├── reverse_shell.py # Payload generator + multi-session listener
├── pivot_chain.py # Multi-hop command execution and TCP relay
├── socks_pivot.py # SOCKS5 proxy through compromised hosts
├── botnet.py # Bot grouping, fan-out commands, health checks, payload deployment
├── intel.py # Telegram/Discord webhooks, AbuseIPDB, screenshot capture
├── scheduler.py # APScheduler-based job scheduling
├── proxy_rotation.py # Proxy list rotation for stealth
├── stealth.py # Traffic obfuscation utilities
├── inject_key.py # SSH key injection variants
├── inject_ssh.py # SSH-based injection
├── launch.py # Simple launcher wrapper
├── auto_exploit.py # Automated exploitation routines
├── templates/
│ └── index.html # Dark-themed SPA — 8 tabs, real-time updates, terminal
└── requirements.txt # Python dependencies
The SQLite database (cameras.db, auto-created on first run) contains 11 tables:
| Table | Purpose |
|---|---|
cameras | Compromised devices — IP, credentials, model, firmware, serial, status |
command_log | Full audit trail of every command executed and its output |
scan_results | Scan history — which IPs were scanned and whether they were vulnerable |
web_vulns | Discovered web vulnerabilities (CVE, severity, evidence) |
network_vulns | Discovered network service vulnerabilities |
shells | Active reverse shell sessions |
dns_records | DNS reconnaissance results |
cred_vault | Harvested credentials organized by service |
asn_targets | ASN prefixes and imported IP ranges |
web_targets | Web targets with metadata (status, server, CMS, JARM, WAF) |
scan_jobs | Job tracking — scan type, target, duration, results count |
scan_log | Module-level activity log for auditing |
git clone https://github.com/YOUR_USERNAME/abyss-c2.git
cd abyss-c2
python -m venv venv
# Windows
venv\Scripts\activate