
Kit de ataque a servidores de aplicaciones
clusterd es un conjunto de herramientas de ataque para servidores de aplicaciones de código abierto. Nacido de la frustración con los métodos actuales de fingerprinting y explotación, clusterd automatiza las fases de fingerprinting, reconocimiento y explotación de un ataque a servidores de aplicaciones. Consulte la wiki para más información.
La instalación recomendada de clusterd es clonar el repositorio de Github
git clone https://github.com/hatRiot/clusterd.git
clusterd actualmente soporta seis plataformas diferentes de servidores de aplicaciones, con varias más actualmente en desarrollo y fases de investigación
JBoss
ColdFusion
WebLogic
Tomcat
Railo
Axis2
Glassfish
API simple para añadir nuevas plataformas, huellas digitales, desplegadores y exploits
Varios módulos auxiliares para vulnerabilidades y técnicas de explotación
$ ./clusterd.py
clusterd/0.3.1 - clustered attack toolkit
[Supporting 7 platforms]
usage: ./clusterd.py [options]
optional arguments:
-h, --help show this help message and exit
Connection:
Options for configuring the connection
-i [ip address] Server address
-iL [file] Server list
-p [port] Server port
--proxy [proxy://server:port]
Connect through proxy [http|https]
--proxy-auth [username:password]
Proxy credentials
--timeout [seconds] Connection timeout [5s]
--random-agent Use a random User-Agent for requests
--ssl Force SSL
Remote Host:
Settings specific to the remote host
-a [jboss|coldfusion|weblogic|tomcat|railo|axis2|glassfish]
Hint at remote host service
-o [windows|linux] Hint at remote host OS
-v [version] Specific version to test
--usr-auth [username:password]
Login credentials for service
--fingerprint Fingerprint the remote system
--arch [x86|x64] Specify remote OS architecture
Deploy:
Deployment flags and settings
--deploy [file] Deploy to the discovered service
--undeploy [context] Undeploy file from server
--deployer [deployer]
Specify a deployer to use
--invoke Invoke payload after deployment
--rand-payload Use a random name for the deployed file
-b [user] Brute force credentials for user [admin]
--wordlist [path] Wordlist for brute forcing passwords
Other:
Miscellaneous flags
--deployer-list List all available deployers
--aux-list [platform]
List all available exploits
--gen-payload [host:port] for reverse connection
Generate a reverse shell payload
--discover [discovery_file]
Attempt to discover application servers using the
specified nmap gnmap output (use -sV when scanning)
--listen [adapter] Adapter to listen on when needed
-d Enable debug output
-l Log output to file [$time$_log.log]
huella digital de jboss e información del host
$ ./clusterd.py -i 192.168.1.105 -a jboss --jb-info --random-agent
clusterd/0.3 - clustered attack toolkit
[Supporting 6 platforms]