
kit di attacco per server applicativi
clusterd è un toolkit open source per attacchi a server applicativi. Nato dalla frustrazione con gli attuali metodi di fingerprinting e sfruttamento, clusterd automatizza le fasi di fingerprinting, ricognizione e sfruttamento di un attacco a un server applicativo. Vedi il wiki per maggiori informazioni.
L'installazione consigliata di clusterd è quella di clonare il repository Github
git clone https://github.com/hatRiot/clusterd.git
clusterd supporta attualmente sei diverse piattaforme di server applicativi, con molte altre attualmente in fase di sviluppo e ricerca
JBoss
ColdFusion
WebLogic
Tomcat
Railo
Axis2
Glassfish
API semplice per aggiungere nuove piattaforme, impronte digitali, deployer ed exploit
Vari moduli ausiliari per vulnerabilità e tecniche di sfruttamento
$ ./clusterd.py
clusterd/0.3.1 - clustered attack toolkit
[Supporting 7 platforms]
usage: ./clusterd.py [options]
optional arguments:
-h, --help show this help message and exit
Connection:
Options for configuring the connection
-i [ip address] Server address
-iL [file] Server list
-p [port] Server port
--proxy [proxy://server:port]
Connect through proxy [http|https]
--proxy-auth [username:password]
Proxy credentials
--timeout [seconds] Connection timeout [5s]
--random-agent Use a random User-Agent for requests
--ssl Force SSL
Remote Host:
Settings specific to the remote host
-a [jboss|coldfusion|weblogic|tomcat|railo|axis2|glassfish]
Hint at remote host service
-o [windows|linux] Hint at remote host OS
-v [version] Specific version to test
--usr-auth [username:password]
Login credentials for service
--fingerprint Fingerprint the remote system
--arch [x86|x64] Specify remote OS architecture
Deploy:
Deployment flags and settings
--deploy [file] Deploy to the discovered service
--undeploy [context] Undeploy file from server
--deployer [deployer]
Specify a deployer to use
--invoke Invoke payload after deployment
--rand-payload Use a random name for the deployed file
-b [user] Brute force credentials for user [admin]
--wordlist [path] Wordlist for brute forcing passwords
Other:
Miscellaneous flags
--deployer-list List all available deployers
--aux-list [platform]
List all available exploits
--gen-payload [host:port] for reverse connection
Generate a reverse shell payload
--discover [discovery_file]
Attempt to discover application servers using the
specified nmap gnmap output (use -sV when scanning)
--listen [adapter] Adapter to listen on when needed
-d Enable debug output
-l Log output to file [$time$_log.log]
jboss fingerprint and host info
$ ./clusterd.py -i 192.168.1.105 -a jboss --jb-info --random-agent
clusterd/0.3 - clustered attack toolkit
[Supporting 6 platforms]