
नेबुला एक क्लाउड C2 फ्रेमवर्क है, जो फिलहाल AWS पर रिकॉनिसेंस, एन्युमरेशन, एक्सप्लॉइटेशन और पोस्ट-एक्सप्लॉइटेशन की सुविधा प्रदान करता है, लेकिन अन्य क्लाउड प्रदाताओं और DevOps घटकों के परीक्षण की अनुमति देने के लिए अभी भी कार्य जारी है।
नेबुला एक क्लाउड और (उम्मीद है) DevOps पेनिट्रेशन टेस्टिंग फ्रेमवर्क है। यह प्रत्येक प्रदाता और प्रत्येक कार्यक्षमता के लिए मॉड्यूल के साथ बनाया गया है। अप्रैल 2021 तक, यह केवल AWS को कवर करता है, लेकिन वर्तमान में यह एक चालू प्रोजेक्ट है और उम्मीद है कि यह GCP, Azure, Kubernetes, Docker, या Ansible, Terraform, Chef जैसे ऑटोमेशन इंजनों का परीक्षण करने के लिए बढ़ता रहेगा। मैंने इसे "Hands-On AWS Penetration Testing with Kali Linux" (https://www.amazon.com/Hands-Penetration-Testing-Kali-Linux/dp/1789136725) पढ़ते समय लिखना शुरू किया था और यह Pacu (https://github.com/RhinoSecurityLabs/pacu) पर आधारित था।
प्रस्तुतियाँ:
वर्तमान में कवर करता है:
वर्तमान में 53 मॉड्यूल कवर करते हैं:
संस्करण 3.0 में शामिल हैं:
नेबुला python3.11 में कोडित है। यह AWS तक पहुँचने के लिए boto3 लाइब्रेरी का उपयोग करता है।
स्थापित करने के लिए, बस teamserver निर्देशिका पर जाएँ और कंटेनर बनाएँ:```
$ docker build -t nebula-teamserver .
फिर, बस इसे docker का उपयोग करके चलाएँ:```
$ docker run -it nebula-teamserver -dH <database host> -du <database user> -dp <database password> -dn <database name> --p <teamserver password>
------------------------------------------------------------
_ _ _ _
| \ | | | | | |
| \| | ___| |__ _ _| | __ _
| . ` |/ _ \ '_ \| | | | |/ _` |
_______ | |\ | __/ |_) | |_| | | (_| |
|__ __||_| \_|\___|_.__/ \__,_|_|\__,_|
| | ___ __ _ _ __ ___ ___ ___ _ ____ _____ _ __
| |/ _ \/ _` | '_ ` _ \/ __|/ _ \ '__\ \ / / _ \ '__|
| | __/ (_| | | | | | \__ \ __/ | \ V / __/ |
|_|\___|\__,_|_| |_| |_|___/\___|_| \_/ \___|_|
-------------------------------------------------------------
37 aws 0 gcp 4 azure 0 office365
0 docker 0 kubernetes 4 misc 11 azuread
4 digitalocean
-------------------------------------------------------------
60 modules 6 cleanup 0 detection
19 enum 5 exploit 2 persistence
1 listeners 0 lateral movement 7 detection bypass
7 privesc 10 reconnaissance 2 stager 0 postexploitation
1 misc
[*] Port is busy. Is a MongoDB instance running there? [y/N] y
------------------------------------------------------------
[*] JWT Secret Key set to: '<secret value>'
[*] Database Server set to: '<db host>:<db port>'
[*] Database set to: '<db name>'
[*] Teamserver IP address is '<teamserver host>'
[*] User 'cosmonaut' was created!
[*] API Server set to: '<api host>:<api port>'
------------------------------------------------------------
client client के साथ भी ऐसा ही। बस client निर्देशिका पर जाएं और कंटेनर बनाएं:```
$ docker build -t nebula-client .
फिर, इसे docker का उपयोग करके चलाएँ:```
$ docker run -it nebula-client -ah <api host> -p <teamserver password> -b
-------------------------------------------------------------
37 aws 0 gcp 4 azure 0 office365
0 docker 0 kubernetes 4 misc 13 azuread
4 digitalocean
-------------------------------------------------------------
62 modules 6 cleanup 0 detection
19 enum 5 exploit 2 persistence
1 listeners 0 lateral movement 7 detection bypass
7 privesc 10 reconnaissance 2 stager
1 misc 2 initialaccess 0 postexploitation
-------------------------------------------------------------
[*] Importing sessions found on ~/.aws
[*] No sessions found on ~/.aws
()()(Nebula) >>>
...........
...''''''''''''''...
..'''''...........''''''............
..''''.. ...'''''''''''''''...
..'''.. ..............'''''..
.''''. .;loddool:'. ..''''..
..'''. .;clokXWWMWNKkl;. .''''.
.'''. .',,'.. ';dNMMMMMWKko;. .'''..
.''''. .cx0NWWNX0koc;,'cKMMMMMMMMMWXOo:. .''''....
.'''. .',',:oONMMMMMWNNNWMMMMMMWKk0WMMWXx' .''''''''...
..'''. .,dXMMMMMMMMMMMMMNOl',oONWWd. .......'''''..
...'''''.. :o' cXMMMMMMMMMMMMMWNXKKXNWWKxc,. ..''''..
..''''.... oNKl'. ..oXMMMMMMMMMMMMMMMMMMMMMMMMMNKOdc,.. ..''''.
..''''.. ,OWWX0O0XWMMMMMMMMMMMMMMMMMMWWWWMMMMMMMMMWXOxooxk:. ..'''.
..'''''''''''''''''''''. .l0NMMMMMMMMMMMMMMMMMMMMN0dc;;;coONMMMMMMMMMMMMMK: ..'''.
....................... .,dXMMMMMMMMMMMMMMMMMMWX0ko:. .;OWMMMMMMMMMMMWx. .'''.
.oWMMMMMMMMMMMMMMWNXXXWMMWKd' .:lccclodOXWMWd. .'''.
,lc' .................. ',. .,OWMMMMMMMMMMMMXx:'...:0WMMMKl. .. .'oKO, .'''.
,0MWx. .''''''''''''''''''. ;OKOOOO0NWMMMMMMMMMMMMNl. .cdoox0XOl;'....... ... .'''.
.;ol' ................... ;kXWMMMMMMMMMMMMMMMMMWx. .:0WNKkdo:. ... .'''.
.................... .:ldxk0XWMMMMMMMMMMMW0o' .';;,. .... ..'''.
;k00000000000000000000x' ..;lkXWMMMMMMMMMWXkc. ..'''.
.lXWWWWWWWWWWWWWWWWWWMMWKl. ;OWMMMMMMMMMMMWKx:. ..''''.
.,,,,,,,,,,,,,,,,,:kNMMW0o,. 'kWMMMMMMMMMMMMMMWKd,. ..''''..
.:ONMMMNKkdlc:::::::::ccldkKWMMMMMMMMMMMMMMMMMMNOl' ...........'''''..
.,oOXWMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMWXkc....''''''''''...
.':ldkO0000000000000000000000000000000000000000Ox:. ........
...........................................
_ _______ ______ _ _______
( ( /|( ____ \( ___ \ |\ /|( \ ( ___ )
| \ ( || ( \/| ( ) )| ) ( || ( | ( ) |
| \ | || (__ | (__/ / | | | || | | (___) |
| (\ \) || __) | __ ( | | | || | | ___ |
| | \ || ( | ( \ \ | | | || | | ( ) |
| ) \ || (____/\| )___) )| (___) || (____/\| ) ( |
|/ )_)(_______/|/ \___/ (_______)(_______/|/ \|
Because Clouds are so AWSome
-------------------------------------------------------------
Created by: gl4ssesbo1
-------------------------------------------------------------
48 aws 1 gcp 7 azure 0 office365
0 docker 0 kubernetes 6 misc 4 azuread
4 digitalocean
-------------------------------------------------------------
81 modules 6 cleanup 0 detection
19 enum 22 exploit 2 persistence
2 listeners 0 lateral movement 7 detection bypass
0 privesc 16 reconnaissance 2 stager 1 postexploitation
4 misc
Remember:
-------------------------------------------------------------
1) Only use this tool if you have permissions from the
infrastructure's owner. Don't be a dick. Don't choose jail.
And if you have some scruples, don't hack others just because
you can (or cannot, in which case that's why you chose this
tool to do it).
2) There is a template file on module directory that you can
use if you want to develop new modules. If you want to
contribute on this tool, be my guest.
3) Thank you for using this tool and Hack the Planet Legally!
-------------------------------------------------------------
[] Importing sessions found on ~/.aws [] Imported sessions found on ~/.aws. Enter 'show credentials' to get the credentials. (test)()(Nebula)
### सहायता
*help* कमांड चलाने पर, आपको उन कमांड्स की सूची मिलेगी जिनका उपयोग किया जा सकता है:```
()()(AWS) >>> help
Help Command: Description:
------------- ------------
help Show help for all the commands
help credentials Show help for credentials
help module Show help for modules
help workspace Show help for credentials
help user-agent Show help for credentials
help shell Show help for shell connections
Module Commands Description
--------------- -----------
show modules List all the modules
show enum List all Enumeration modules
show exploit List all Exploit modules
show persistence List all Persistence modules
show privesc List all Privilege Escalation modules
show reconnaissance List all Reconnaissance modules
show listener List all Reconnaissance modules
show cleanup List all Enumeration modules
show detection List all Exploit modules
show detectionbypass List all Persistence modules
show lateralmovement List all Privilege Escalation modules
show stager List all Reconnaissance modules
use module <module> Use a module.
options Show options of a module you have selected.
run Run a module you have selected. Eg: 'run <module name>'
search Search for a module via pattern. Eg: 'search s3'
back Unselect a module
set <option> Set option of a module. Need to have the module used first.
unset <option> Unset option of a module. Need to have the module used first.
User-Agent commands Description
------------------- -----------
set user-agent windows Set a windows client user agent
set user-agent linux Set a linux client user agent
set user-agent custom Set a custom client user agent
show user-agent Show the current user-agent
unset user-agent Use the user agent that boto3 produces
Workspace Commands Description
------------------ -----------
create workspace <wp> Create a workspace
use workspace <wp> Use one of the workspaces
remove workspace <wp> Remove a workspace
Shell commands Description
------------------- -----------
shell check_env Check the environment you are in, get data and meta-data
shell exit Kill a connection
shell <command> Run a command on a system. You don't need " on the command, just shell <command1> <command2>
जब आपके पास एक सेट क्रेडेंशियल्स होते हैं, तो आप उपयोगकर्ता प्राप्त करने के लिए getuid दर्ज कर सकते हैं या क्रेडेंशियल्स के सेट की पढ़ने की अनुमति जांचने के लिए enum_user_privs दर्ज कर सकते हैं।
UserID: A******************Q
Arn: arn:aws:iam::012345678912:user/user_user
Account: 012345678912
[*] Output is saved to './workspaces/test/12_07_2021_02_22_54_getuid_dev_brian'
यदि creds में स्वयं पर नीचे दिए गए privs नहीं हैं,```
STS:GetUserIdentity
IAM:GetUser
IAM:ListAttachedUserPolicies
IAM:GetPolicy (for all policies)
आपको एक त्रुटि मिलेगी:``` [*] An error occurred (AccessDenied) when calling the GetUser operation: User: arn:aws:iam::012345678912:user/user_user is not authorized to perform: iam:GetUser on resource: user user_user
#### Enum_User_Privs
यह कमांड क्रेडेंशियल्स के एक सेट पर विशेषाधिकारों को सूचीबद्ध और वर्णित करने की जाँच करता है।```
(test)()(AWS) >>> enum_user_privs
User: user_user
UserID: A******************Q
Arn: arn:aws:iam::012345678912:user/user_user
Account: 012345678912
--------------------------
Service: ec2
--------------------------
[*] Trying the 'Describe' functions:
[*] 'describe_account_attributes' worked!
[*] 'describe_addresses' worked!
[*] 'describe_aggregate_id_format' worked!
[*] 'describe_availability_zones' worked!
[*] 'describe_bundle_tasks' worked!
[*] 'describe_capacity_reservations' worked!
[*] 'describe_client_vpn_endpoints' worked!
[*] 'describe_coip_pools' worked!
[*] 'describe_customer_gateways' worked!
[*] 'describe_dhcp_options' worked!
[*] 'describe_egress_only_internet_gateways' worked!
^C[*] Stopping. It might take a while. Please wait.
[*] Output of the allowed functions is saved to './workspaces/test/12_07_2021_02_24_09_enum_user_privs'
[*] The list of the allowed functions is saved to './workspaces/test/12_07_2021_02_24_09_allowed_functions'
आप सभी मॉड्यूल या विशिष्ट मॉड्यूल सूचीबद्ध कर सकते हैं:``` ()()(AWS) >>> show modules cleanup/aws_iam_delete_access_key Delete access key of a user by providing it.
cleanup/aws_iam_delete_login_profile Delete access of a user to the Management
Console
enum/aws_ec2_enum_elastic_ips Lists User data of an Instance provided.
Requires Secret Key and Access Key of an IAM that has access
to it.
enum/aws_ec2_enum_images List all ec2 images. Needs credentials of an
IAM with DescribeImages right. Output is dumpled on a file.
It takes a sh*tload of time, unfortunately. And boy, is it a
huge output.
enum/aws_ec2_enum_instances Describes instances attribues: Instances, VCP,
Zones, Images, Security Groups, Snapshots, Subnets, Tags,
Volumes. Requires Secret Key and Access Key of an IAM that
has access to all or any of the API calls:
DescribeAvailabilityZones, DescribeImages,
DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups,
DescribeSnapshots, DescribeSubnets, DescribeTags,
DescribeVolumes, DescribeVpcs
और इस प्रकार आप उपयोग कर सकते हैं:```
show module
show enum
show exploit
show persistence
show privesc
show reconnaissance
show listener
show cleanup
show detection
show detectionbypass
show lateralmovement
show stager
किसी विशिष्ट शब्द के साथ मॉड्यूल खोजने के लिए search कमांड का उपयोग करें:``` ()()(AWS) >>> search instance enum/aws_ec2_enum_instances Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs
enum/aws_iam_list_instance_profiles List all the instance profiles.
exploit/aws_ec2_create_instance_with_user_data You must provide policies in JSON format in
IAM. However, for AWS CloudFormation templates formatted in
YAML, you can provide the policy in JSON or YAML format. AWS
CloudFormation always converts a YAML policy to JSON format
before submitting it to IAM.
()()(AWS) >>>
#### मॉड्यूल का उपयोग करना
मॉड्यूल का उपयोग करने के लिए, बस *use* और मॉड्यूल का नाम टाइप करें। 3 ब्रैकेट्स में मॉड्यूल का नाम होगा।```
(work1)()(enum/aws_ec2_enum_instances) >>> use module enum/aws_iam_get_group
(work1)()(enum/aws_ec2_enum_instances) >>>
Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs
name: gl4ssesbo1
twitter: https://twitter.com/gl4ssesbo1
github: https://github.com/gl4ssesbo1
blog: https://www.pepperclipp.com/
aws ec2 describe-instances --region {} --profile {}
SERVICE: ec2
Required: true
Description: The service that will be used to run the module. It cannot be changed.
INSTANCE-ID:
Required: false
Description: The ID of the instance you want to enumerate. If not supplied, all instances will be enumerated.
(work1)()(enum/aws_ec2_enum_instances) >>>
विकल्प सेट करने के लिए, *set* और विकल्प का नाम उपयोग करें:```
(work1)()(enum/aws_ec2_enum_instances) >>> set INSTANCE-ID 1234
(work1)()(enum/aws_ec2_enum_instances) >>> options
Desctiption:
-----------------------------
Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs
Author:
-----------------------------
name: gl4ssesbo1
twitter: https://twitter.com/gl4ssesbo1
github: https://github.com/gl4ssesbo1
blog: https://www.pepperclipp.com/
Needs Credentials: True
-----------------------------
AWSCLI Command:
-----------------------------
aws ec2 describe-instances --region {} --profile {}
Options:
-----------------------------
SERVICE: ec2
Required: true
Description: The service that will be used to run the module. It cannot be changed.
INSTANCE-ID: 1234
Required: false
Description: The ID of the instance you want to enumerate. If not supplied, all instances will be enumerated.
(work1)()(enum/aws_ec2_enum_instances) >>>
साथ ही उन्हें अनसेट करने के लिए unset का उपयोग करना।``` (work1)()(enum/aws_ec2_enum_instances) >>> unset INSTANCE-ID (work1)()(enum/aws_ec2_enum_instances) >>>
#### मॉड्यूल चलाना
मॉड्यूल को चलाने के लिए, यदि इसमें क्रेडेंशियल्स की आवश्यकता है, तो आपको उन क्रेडेंशियल्स का एक सेट आयात करना होगा जिनके पास इसे चलाने के लिए आवश्यक अनुमति हो। यह मॉड्यूल के विकल्पों में इस प्रकार दिखाया गया है:```
Needs Credentials: True
-----------------------------
इसे चलाने के लिए, बस run दर्ज करें। आउटपुट के आधार पर, यह या तो पेजिनेटेड दृश्य दिखाएगा, या बस इसे प्रिंट करेगा। पेजिनेशन, less बाइनरी का उपयोग करता है, जो विंडोज़ के लिए https://github.com/jftuga/less-Windows से बाइनरी का उपयोग करता है। exe की एक प्रति less_binary निर्देशिका में है। आउटपुट वर्कस्पेस निर्देशिका में फ़ाइलों पर भी सहेजा जाता है:``` (work1)()(enum/aws_ec2_enum_instances) >>> run [*] Content dumped on file './workspaces/work1/16_04_2021_18_16_48_ec2_enum_instances'.
### क्रेडेंशियल्स
#### क्रेडेंशियल्स इनपुट करना
Nebula बुनियादी ढांचे में प्रमाणीकरण के लिए AccessKeyID + SecretKey संयोजन और AccessKeyID + SecretKey + SessionKey संयोजन दोनों का उपयोग कर सकता है।
क्रेडेंशियल्स का एक सेट डालने के लिए, उपयोग करें:```
()()(AWS) >>> set credentials test1
Profile Name: test1
Access Key ID: A*********2
Secret Key ID: a****************************7
Region: us-west-3
Do you also have a session token?[y/N]
[*] Credentials set. Use 'show credentials' to check them.
[*] Currect credential profile set to 'test1'.Use 'show current-creds' to check them.
और आपको कुछ इनपुट मिलेंगे जो आपको उन्हें सेट करने की अनुमति देंगे। क्रेडेंशियल दर्ज करते समय y टाइप करके सत्र टोकन जोड़ा जा सकता है, जब पूछा जाए क्या आपके पास भी कोई सत्र टोकन है?[y/N]।
####क्रेडेंशियल का उपयोग करना दूसरे क्रेडेंशियल का उपयोग करने के लिए, बस दर्ज करें:``` ()()(AWS) >>> use credentials test1 [*] Currect credential profile set to 'test1'.Use 'show current-creds' to check them.
####वर्तमान क्रेडेंशियल्स
जब आप क्रेडेंशियल्स दर्ज करते हैं, तो वे स्वचालित रूप से वर्तमान क्रेडेंशियल्स बन जाते हैं, जिनका अर्थ है कि आप उनके साथ प्रमाणीकरण करेंगे। वर्तमान क्रेडेंशियल्स की जांच करने के लिए, उपयोग करें:```
()()(AWS) >>> show current-creds
{
"profile": "test1",
"access_key_id": "A*********2",
"secret_key": "a****************************7",
"region": "us-west-3"
}
####क्रेडेंशियल्स हटाना यदि आप अपने क्रेडेंशियल्स नहीं रखना चाहते, तो आप उन्हें निम्न का उपयोग करके हटा सकते हैं:``` ()()(AWS) >>> remove credentials test1 You are about to remove credential 'test1'. Are you sure? [y/N] y
####डंप करना और प्रमाण-पत्र आयात करना
यदि आप अपने प्रमाण-पत्र मशीन पर सहेजना चाहते हैं, तो आप इसका उपयोग कर सकते हैं:```
()()(AWS) >>> dump credentials
[*] Credentials dumped on file './credentials/16_04_2021_17_37_59'.
और वे नेबुला निर्देशिका पर credentials निर्देशिका में डंप के समय और तारीख वाली एक फ़ाइल में सहेजे जाएँगे। उन्हें आयात करने के लिए, बस दर्ज करें:``` ()()(AWS) >>> import credentials 16_04_2021_17_37_59 ()()(AWS) >>> show credentials [ { "profile": "test1", "access_key_id": "A*******2", "secret_key": "a**************************7", "region": "us-west-3" } ]
### कार्यक्षेत्र
नेबुला हर कमांड के आउटपुट को सहेजने के लिए कार्यक्षेत्रों का उपयोग करता है। आउटपुट *workspaces* निर्देशिका पर बनाए गए एक फ़ोल्डर में json डेटा के रूप में सहेजा जाता है (s3_name_fuzzer को छोड़कर जो इसे XML के रूप में सहेजता है)।
#### कार्यक्षेत्र बनाएं
एक बनाने के लिए, दर्ज करें:```
()()(AWS) >>> create workspace work1
[*] Workspace 'work1' created.
[*] Current workspace set at 'work1'.
(work1)()(AWS) >>> ls ./workspaces
Directory: C:\Users\***\Desktop\Nebula\workspaces
Mode LastWriteTime Length Name
---- ------------- ------ ----
d----- 4/16/2021 5:42 PM work1
-a---- 4/16/2021 4:40 PM 0 __init__.py
जब बनाया जाता है, तो पहले कोष्ठक में आप जिस कार्यस्थल पर काम कर रहे हैं उसका नाम होगा। यदि आप किसी मौजूदा कार्यस्थल का उपयोग करना चाहते हैं, तो बस टाइप करें:``` ()()(AWS) >>> use workspace work1 (work1)()(AWS) >>>
वर्कस्पेस का उपयोग अनिवार्य है, इसलिए भले ही आप वर्तमान में किसी का उपयोग नहीं कर रहे हों, मॉड्यूल चलाते समय, यह आपसे एक यादृच्छिक नाम से बनाने या स्वयं एक कस्टम नाम से बनाने के लिए कहेगा।```
()()(enum/aws_ec2_enum_instances) >>> run
A workspace is not configured. Workstation 'qxryiuct' will be created. Are you sure? [y/N] n
[*] Create a workstation first using 'create workstation <workstation name>'.
()()(enum/aws_ec2_enum_instances) >>>
work1
(work1)()(enum/aws_ec2_enum_instances) >>>
#### वर्कस्पेस हटाएं
वर्कस्पेस हटाने के लिए, दर्ज करें:```
()()(AWS) >>> remove workspace work1
[*] Are you sure you want to delete the workspace? [y/N] y
()()(AWS) >>> show workspaces
-----------------------------------
Workspaces:
-----------------------------------
()()(AWS) >>>
रिवर्स शेल बनाने के लिए, आपको एक स्टेजर बनाना होगा और एक लिसनर चलाना होगा। इस सुविधा का उपयोग करने के लिए, आपको Nebula को रूट के रूप में चलाना होगा (पोर्ट खोलने के लिए)।
The TCP Reverse Shell that is used by listeners/aws_python_tcp_listener
name: gl4ssesbo1
twitter: https://twitter.com/gl4ssesbo1
github: https://github.com/gl4ssesbo1
blog: https://www.pepperclipp.com/
None
SERVICE: none
Required: true
Description: The service that will be used to run the module. It cannot be changed.
HOST:
Required: true
Description: The Host/IP of the C2 Server.
PORT:
Required: true
Description: The C2 Server Port.
FORMAT:
Required: true
Description: The format of the stager. Currently only allows 'py' for Python and 'elf' for ELF Binary.
CALLBACK-TIME: None
Required: true
Description: The time in seconds between callbacks from Stager. The Stager calls back even if the server crashes or is stoped in a loop.
OUTPUT-FILE-NAME:
Required: true
Description: The name of the stager output file.
The options to fill are:
- **HOST**: C2 सर्वर का IP या डोमेन
- **Port**: C2 सर्वर पोर्ट
- **Format**: वर्तमान में केवल python raw file और elf binary समर्थित हैं
- **Callback-Time**: वे सेकंड जिनके लिए सत्रों को वापस कॉल करना चाहिए। यह तब भी कॉल करता है जब वर्तमान सत्र चालू हो, और यदि सर्वर क्रैश या बंद हो जाए, ताकि मशीन तक पहुँच न खोए।
- **Output File Name**: आउटपुट फ़ाइल का नाम।
मॉड्यूल चलाने से **./workspaces/workspacename/stagername** पर एक स्टेजर जनरेट होगा।
#### Listener
लिसनर सरल है। बस Host (डिफ़ॉल्ट रूप से 0.0.0.0 पर सेट) और Port कॉन्फ़िगर करें और यह सर्वर बनाता है। लिसनर चलाने के लिए, आपको Nebula को रूट के रूप में चलाना होगा।```
()()(stager/aws_python_tcp) >>> use module listeners/aws_python_tcp_listener
()()(listeners/aws_python_tcp_listener) >>> options
Desctiption:
-----------------------------
TCP Listener for Reverse Shell stagers/aws_python_tcp
Author:
-----------------------------
name: gl4ssesbo1
twitter: https://twitter.com/gl4ssesbo1
github: https://github.com/gl4ssesbo1
blog: https://www.pepperclipp.com/
Needs Credentials: False
-----------------------------
AWSCLI Command:
-----------------------------
None
Options:
-----------------------------
SERVICE: none
Required: true
Description: The service that will be used to run the module. It cannot be changed.
HOST: 0.0.0.0
Required: true
Description: The Host/IP of the C2 Server.
PORT:
Required: true
Description: The C2 Server Port.
यूज़र एजेंट को लिनक्स, विंडोज या कस्टम के रूप में सेट किया जा सकता है। उन्हें दिखाने के लिए, बस show का उपयोग करें।``` ()()(AWS) >>> set user-agent linux User Agent: Boto3/1.9.89 Python/3.8.1 Linux/4.1.2-34-generic was set ()()(AWS) >>> show user-agent [] User Agent is: Boto3/1.9.89 Python/3.8.1 Linux/4.1.2-34-generic ()()(AWS) >>> set user-agent windows User Agent: Boto3/1.7.48 Python/3.9.1 Windows/7 Botocore/1.10.48 was set ()()(AWS) >>> show user-agent [] User Agent is: Boto3/1.7.48 Python/3.9.1 Windows/7 Botocore/1.10.48 ()()(AWS) >>> set user-agent custom Enter the User-Agent you want: sth User Agent: sth was set ()()(AWS) >>> show user-agent [*] User Agent is: sth ()()(AWS) >>>
उपयोगकर्ता एजेंट को हटाने के लिए, दर्ज करें:```
()()(AWS) >>> unset user-agent
[*] User Agent set to empty.
जिसमें सिस्टम का user agent होगा।