Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Inveigh — .NET strumento machine-in-the-middle IPv4/IPv6 per penetration tester | Kitploit
Strumenti/GitHubGitHub/kevin-robertson/inveigh
Penetration TestingRed Teaming
GitHubkevin-robertson/inveigh

Inveigh

.NET strumento machine-in-the-middle IPv4/IPv6 per penetration tester

Vedi Repository
3.0k4721310 mesi faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Inveigh

Inveigh è uno strumento .NET multipiattaforma IPv4/IPv6 per attacchi machine-in-the-middle per penetration tester. Questo repository contiene la versione principale in C# e la versione legacy PowerShell.

Panoramica

Inveigh esegue attacchi di spoofing e cattura di hash/credenziali tramite sia packet sniffing che listener/socket specifici per protocollo. Il metodo di packet sniffing, che è stato la base per la versione originale PowerShell di questo strumento, ha i seguenti vantaggi:

  • Cattura di challenge/response NTLM SMB tramite il servizio SMB di Windows
  • Meno binding di porta visibili sul sistema host

Lo svantaggio principale è la necessità di accesso elevato.

Nelle versioni correnti di Windows, i servizi UDP in esecuzione predefiniti consentono il riutilizzo delle porte. Pertanto, il packet sniffing non offre più un vantaggio per aggirare le porte UDP in uso. Tutti i listener UDP di Inveigh sono configurati per sfruttare il riutilizzo delle porte.

Descrizione delle versioni

  • PowerShell Inveigh - versione originale sviluppata per molti anni. Per ora, almeno, questa versione (1.506) rimarrà senza ulteriori aggiornamenti. La documentazione si trova qui.
  • C# Inveigh (alias InveighZero) - codice POC C# originale combinato con una porta C# della maggior parte del codice della versione PowerShell. Questa versione è stata ora ricostruita per C# e sta diventando la versione principale.

Funzionalità

La versione C# di Inveigh contiene attacchi per i seguenti protocolli:

  • LLMNR [packet sniffer | listener]
  • DNS [packet sniffer | listener]
  • mDNS [packet sniffer | listener]
  • NBNS [packet sniffer | listener]
  • DHCPv6 [packet sniffer | listener]
  • ICMPv6 [socket raw privilegiato]
  • HTTP [listener]
  • HTTPS [listener]
  • SMB [packet sniffer | listener]
  • LDAP [listener]
  • WebDAV [listener]
  • Proxy Auth [listener]

Inveigh funziona sia con IPv4 che con IPv6 nei casi in cui il protocollo sottostante fornisce supporto per entrambi.

Supporto Multipiattaforma

Il file di progetto in stile SDK di Inveigh è configurato per .NET 3.5, 4.6.2 e 6.0, con 6.0 come versione che funziona anche con Linux e macOS.

<TargetFrameworks>net35;net62;net6.0</TargetFrameworks>

Problemi Noti

  • Il packet sniffer è disponibile solo su Windows a causa delle differenze nella configurazione dei socket raw. Quando compilato per Linux o macOS, il packet sniffer sarà semplicemente disattivato. Invece, è possibile utilizzare il listener SMB di Inveigh se la porta 445 è aperta.
  • macOS richiede che le route siano disponibili per unirsi ai gruppi multicast. Nei miei test, ho dovuto aggiungere route per il multicast DHCPv6 per poter eseguire quell'attacco su questa piattaforma. sudo route -nv add -net ff02::1:2 -interface en0

Esecuzione

dotnet Inveigh.dll

Build Mirate per Linux/macOS

  • Con .NET 6.0 installato sul sistema di destinazione
    dotnet publish -r linux-x64 -f net8.0 -p:AssemblyName=inveigh
    dotnet publish -r osx-x64 -f net8.0 -p:AssemblyName=inveigh

  • Senza .NET 6.0 installato sul sistema di destinazione
    dotnet publish --self-contained=true -p:PublishSingleFile=true -r linux-x64 -f net8.0 -p:AssemblyName=inveigh
    dotnet publish --self-contained=true -p:PublishSingleFile=true -r osx-x64 -f net8.0 -p:AssemblyName=inveigh

Utilizzo

I valori predefiniti dei parametri si trovano all'inizio di Program.cs. Raccomando di rivedere e impostare tutto per adattarlo alle proprie esigenze prima della compilazione. Tutti i parametri di abilitazione/disabilitazione possono essere impostati con valori Y/N.``` //begin parameters - set defaults as needed before compile public static string argCert = "MIIKaQIBAzCCC..." public static string argCertPassword = "password"; public static string argChallenge = ""; public static string argConsole = "5"; public static string argConsoleLimit = "-1"; public static string argConsoleStatus = "0"; public static string argConsoleUnique = "Y"; public static string argDHCPv6 = "N"; public static string argDHCPv6TTL = "30"; public static string argDNS = "Y"; ... //end parameters

### Aiuto sui parametri```
.\Inveigh.exe -?

Control:

  -Inspect        Default=Disabled: (Y/N) inspect traffic only.

  -IPv4           Default=Enabled: (Y/N) IPv4 spoofing/capture.

  -IPv6           Default=Enabled: (Y/N) IPv6 spoofing/capture.

  -RunCount       Default=Unlimited: Number of NetNTLM captures to perform before auto-exiting.

  -RunTime        Default=Unlimited: Run time duration in minutes.


Output:

  -Console        Default=5: Set the level for console output. (0=none, 1=only captures/spoofs, 2=no disabled, no informational, 3=no disabled, no filtered, 4=no disabled, 5=all)  

  -ConsoleLimit   Default=Unlimited: Limit to queued console entries.

  -ConsoleStatus  Default=Disabled: Interval in minutes for auto-displaying capture details.

  -ConsoleUnique  Default=Enabled: (Y/N) displaying only unique (user and system combination) hashes at time of capture.

  -FileDirectory  Default=Working Directory: Valid path to an output directory for enabled file output.

  -FileOutput     Default=Enabled: (Y/N) real time file output.

  -FilePrefix     Default=Inveigh: Prefix for all output files.

  -FileUnique     Default=Enabled: (Y/N) outputting only unique (user and system combination) hashes.

  -LogOutput      Default=Disabled: (Y/N) outputting log entries.


Spoofers:

  -DHCPV6         Default=Disabled: (Y/N) DHCPv6 spoofing.

  -DHCPv6TTL      Default=300: Lease lifetime in seconds.

  -DNS            Default=Enabled: (Y/N) DNS spoofing.

  -DNSHost        Fully qualified hostname to use SOA/SRV responses.

  -DNSSRV         Default=LDAP: Comma separated list of SRV request services to answer.

  -DNSSuffix      DNS search suffix to include in DHCPv6/ICMPv6 responses.

  -DNSTTL         Default=30: DNS TTL in seconds.

  -DNSTYPES       Default=A: (A, AAAA, SOA, SRV) Comma separated list of DNS types to spoof.

  -ICMPv6         Default=Enabled: (Y/N) sending ICMPv6 router advertisements.

  -ICMPv6Interval Default=200: ICMPv6 RA interval in seconds.
  
  -ICMPv6TTL	  Default=300: ICMPv6 TTL in seconds.

  -IgnoreDomains  Default=None: Comma separated list of domains to ignore when spoofing.



  -IgnoreIPs      Default=Local: Comma separated list of source IP addresses to ignore when spoofing.

  -IgnoreMACs     Default=Local: Comma separated list of MAC addresses to ignore when DHCPv6 spoofing.
  
  -IgnoreQueries  Default=None: Comma separated list of name queries to ignore when spoofing.

  -Local          Default=Disabled: (Y/N) performing spoofing attacks against the host system.

  -LLMNR          Default=Enabled: (Y/N) LLMNR spoofing.

  -LLMNRTTL       Default=30: LLMNR TTL in seconds.

  -MAC            Local MAC address for DHCPv6.

  -MDNS           Default=Enabled: (Y/N) mDNS spoofing.

  -MDNSQuestions  Default=QU,QM: Comma separated list of question types to spoof. (QU,QM)

  -MDNSTTL        Default=120: mDNS TTL in seconds.

  -MDNSTypes      Default=A: Comma separated list of mDNS record types to spoof. (A,AAAA,ANY)

  -MDNSUnicast    Default=Enabled: (Y/N) sending a unicast only response to a QM request.

  -NBNS           Default=Disabled: (Y/N) NBNS spoofing.

  -NBNSTTL        Default=165: NBNS TTL in seconds.

  -NBNSTypes      Default=00,20: Comma separated list of NBNS types to spoof. (00,03,20,1B)

  -ReplyToDomains Default=All: Comma separated list of domains to respond to when spoofing.

  -ReplyToIPs     Default=All: Comma separated list of source IP addresses to respond to when spoofing.
Scarica lo strumento