
Bluewall es un framework de firewall diseñado para profesionales cibernéticos ofensivos y defensivos.

Bluewall es un framework de firewall diseñado para profesionales del ciberespacio ofensivo y defensivo. Este framework permite a los profesionales de la ciberseguridad configurar rápidamente su entorno mientras se mantienen dentro de su alcance.
Inspirado en el script de generación de iptables hostfw de Andrew Benson hostfw iptable generation script.
* Configurar Firewall
* Configurar nombre de host
* Configurar Interfaz(es)
* Redhat/CentOS
* La configuración de Windows se puede generar pero no ejecutar.
* bluewall -c config/example.ini
** Ver configuración de ejemplo
* Enumerate - Identificar hosts activos dentro de su red (próximamente)
* Host Destino - Comunicación saliente
* Host de Confianza - Comunicación bidireccional
* No Strike - Dispositivos con los que su computadora no debe comunicarse
# BUILT FOR PYTHON 2.x
sudo python setup.py install
sudo bluewall -h (for help)
# Setup Initial Environment using Configuration
sudo bluewall -c config/hostconfig.ini
# Export optional windows configuration
sudo bluewall -c config/hostconfig.ini -w autoconfig.ps1
# Add additional inbound host or ranges
sudo bluewall -ih 192.168.0.3,192.168.1.0/24
# Exclude host to communicate with
sudo bluewall -eh 192.168.1.1
# Super easy wizard mode
sudo bluewall --wizard
usage: bluewall [-h] [-V] [-v] [-r] [-p] [-i] [-d] [-w WINDOWS_CONFIG]
[-ot TCP_PORTS_OUT] [-ou UDP_PORTS_OUT] [-it TCP_PORTS_IN]
[-iu UDP_PORTS_IN] [-oh OUTBOUND_HOSTS] [-ih INBOUND_HOSTS]
[-eh EXCLUDE_HOSTS] [-l] [-s] [-q] [-D] [-A] [-F] [-S] [-c CONFIG]
[--info]
/////////////////////////////////////////////////////
| _____ __ _____ _____ _ _ _ _____ __ __ |
| | __ | | | | | __| | | | - | | | | |
| | __-| |__| | | __| | | | | |__| |__ |
| |_____|_____|_____|_____|_____|__|__|_____|_____| |
| |
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
Un framework de Python para automatizar la configuración del firewall.
Valores predeterminados:
Se permitirán conexiones salientes en todos los puertos hacia todos los hosts.
Las conexiones entrantes se limitarán al tráfico saliente relacionado.
DHCP estará habilitado.
Las respuestas a ping estarán habilitadas.
Las conexiones entrantes no solicitadas serán descartadas.
argumentos opcionales:
-h, --help Muestra este mensaje de ayuda y sale.
-V, --version Muestra la versión.
-v, --verbose Modo detallado.
-r, --reset Enviar TCP RST en lugar de descartar el paquete.
-p, --disallow_ping No permitir PING entrante.
-i, --allow_outbound_icmp
No restringir tipos ICMP.
-d, --disallow_dhcp No permitir DHCP.
-w WINDOWS_CONFIG, --windows_config WINDOWS_CONFIG
Generar configuración de Windows. Uso: bluewall -w config.ps1
-ot TCP_PORTS_OUT, --tcp_ports_out TCP_PORTS_OUT
Lista separada por comas de puertos TCP salientes permitidos.
-ou UDP_PORTS_OUT, --udp_ports_out UDP_PORTS_OUT
Lista separada por comas de puertos UDP salientes permitidos.
-it TCP_PORTS_IN, --tcp_ports_in TCP_PORTS_IN
Lista separada por comas de puertos TCP entrantes permitidos.
-iu UDP_PORTS_IN, --udp_ports_in UDP_PORTS_IN
Lista separada por comas de puertos UDP entrantes permitidos.
-oh OUTBOUND_HOSTS, --outbound_hosts OUTBOUND_HOSTS
Restringir salida a los hosts especificados. -oh 192.168.3.0/24,192.168.4.0/24
-ih INBOUND_HOSTS, --inbound_hosts INBOUND_HOSTS
Restringir entrada a los hosts especificados. -ih 192.168.3.0/24,192.168.4.0/24
-eh EXCLUDE_HOSTS, --exclude_hosts EXCLUDE_HOSTS
Excluir hosts -eh 192.168.3.0/24
-l, --log_exceptions Registrar excepciones.
-s, --simulate Solo simular.
-q, --quiet Modo silencioso (no mostrar mensajes de estado).
-D, --deny_all Denegar absolutamente todo.
-A, --allow_all Permitir absolutamente todo.
-F, --flush Vaciar IPTables.
-S, --show_rules Mostrar reglas después de configurar.
--wizard Modo asistente de direccionamiento y firewall.
-c CONFIG, --config CONFIG
Configuración para el firewall.
--info Acerca de Bluewall.
example.ini
[local_config]
iface=em1
rh_host=RHEL-Example
rh_ipaddr=192.168.1.42
netmask=255.255.255.0
gateway_addr=172.16.63.1
dns=8.8.8.8
#win_ipaddr=192.168.1.42 - Optional windows IP Address
#
# Optional Windows host (Bluewall will generate a config file for windows)
win_host=WINExample
# MAC Addresses must be ALL CAPS Valid: AA:93:AB:EF:00:01
# rh_mac=* will generate random MAC address
rh_mac=*
[firewall_config]
# Target Range are networks you want to allow outbound communication with.
target_range=172.16.63.0/24
target_range=192.168.2.0/24
#
# Nostrike addresses are devices your computer should NOT communicate with
nostrike=192.168.2.1
#
# Trusted Range are networks you wish to have bi-directional communication with
trusted_range=172.16.63.0/24
trusted_host=42.42.42.42
[ataylor@localhost bluewall]$ sudo bluewall -c configs/exampleconfig.ini
[OK] 192.168.1.101 is a valid setting for dns
[OK] 192.168.1.1 is a valid setting for gateway_addr
[OK] 24 is a valid setting for cidr_prefix
[OK] 192.168.1.254 is a valid setting for nostrike
[OK] * is a valid setting for rh_mac
[OK] WINtaylor is a valid setting for win_host
[OK] 192.168.2.0/24 is a valid setting for target_range
[OK] 192.168.3.0/24 is a valid setting for target_range
[OK] 192.168.1.30 is a valid setting for rh_ipaddr
[OK] RHEL-taylor is a valid setting for rh_host
[OK] 42.42.42.42 is a valid setting for trusted_host
[OK] 192.168.1.0/24 is a valid setting for trusted_range
[OK] 192.168.1.50 is a valid setting for win_ipaddr
==============================
[VALID CONFIG] No Errors Detected.
CONFIGURING
writing eth config to /etc/sysconfig/network-scripts/ifcfg-ens33
[CONFIGURATION]
TYPE="Ethernet"
BOOTPROTO=none
NAME=ens33
DEVICE="ens33"
ONBOOT=no
DEFROUTE="yes"
IPV4_FAILURE_FATAL=no
DNS1=192.168.1.101
IPADDR=192.168.1.30
PREFIX=24
GATEWAY=192.168.1.1
MACADDR=00:16:3E:52:7F:8D
[+] Interface ens33 shutdown.
[+] Restarting Network Service
[+] Interface ens33 brought up.
[+] Rules Flushed!
[+] Allowing outbound ICMP/traceroute to 192.168.2.0/24...
[+] Allowing outbound ICMP/traceroute to 192.168.3.0/24...
[+] Allowing outbound ICMP/traceroute to 192.168.1.0/24...
[+] Limiting outbound TCP connections to 192.168.2.0/24.
[+] Limiting outbound TCP connections to 192.168.3.0/24.
[+] Limiting outbound TCP connections to 192.168.1.0/24.
[+] Limiting outbound UDP connections to 192.168.2.0/24.
[+] Limiting outbound UDP connections to 192.168.3.0/24.
[+] Limiting outbound UDP connections to 192.168.1.0/24.
[+] Limiting inbound UDP connections to 192.168.1.0/24.
[+] Limiting inbound TCP connections to 192.168.1.0/24.
[+] Allowing traffic for localhost.
[+] 192.168.1.254 applied to NOSTRIKE
$ iptables -nvL
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 192.168.1.254 0.0.0.0/0
0 0 ACCEPT all -- * * 127.0.0.0/8 127.0.0.0/8
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.1.0/24
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.1.0/24
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 192.168.1.254
0 0 ACCEPT all -- * * 127.0.0.0/8 127.0.0.0/8
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.1.0/24
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.3.0/24
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.2.0/24
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.1.0/24
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.3.0/24
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.2.0/24
0 0 ACCEPT icmp -- * * 0.0.0.0/0 192.168.1.0/24 icmptype 0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 192.168.1.0/24 icmptype 8
0 0 ACCEPT icmp -- * * 0.0.0.0/0 192.168.3.0/24 icmptype 0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 192.168.3.0/24 icmptype 8
0 0 ACCEPT icmp -- * * 0.0.0.0/0 192.168.2.0/24 icmptype 0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 192.168.2.0/24 icmptype 8
[+] Setup Complete.