
Melody è un sensore internet trasparente progettato per l'intelligence sulle minacce. Supporta regole di tagging personalizzate e simulazione di applicazioni vulnerabili.
Monitora il rumore di fondo di Internet
Melody è un sensore Internet trasparente costruito per l'intelligence sulle minacce e supportato da un framework di regole di rilevamento che ti permette di etichettare i pacchetti di interesse per ulteriori analisi e monitoraggio delle minacce.
Ecco alcune caratteristiche principali di Melody:
Dato che ora devo concentrarmi su altri progetti, non posso dedicare molto tempo allo sviluppo di Melody.
C'è comunque molto margine di miglioramento, quindi ecco alcune funzionalità che mi piacerebbe implementare un giorno:
cmd/meloctl
Ottieni l'ultima release da https://github.com/ma111e/melody/releases.
make install # Set default outfacing interface
make cap # Set network capabilities to start Melody without elevated privileges
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
make service # Create a systemd service to restart the program automatically and launch it at startup
sudo systemctl stop melody # Stop the service while we're configuring it
Aggiorna il file filter.bpf per filtrare i pacchetti indesiderati.
sudo systemctl start melody # Start Melody
sudo systemctl status melody # Check that Melody is running
I log dovrebbero accumularsi in /opt/melody/logs/melody.ndjson.
tail -f /opt/melody/logs/melody.ndjson # | jq
git clone https://github.com/ma111e/melody /opt/melody
cd /opt/melody
make build
Prosegui poi con i passaggi dal TL;DR della release.
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
mkdir -p /opt/melody/logs
cd /opt/melody/
docker pull ma111e/melody:latest
MELODY_CLI="" # Inserisci qui le tue opzioni CLI. Esempio: export MELODY_CLI="-s -i 'lo' -F 'dst port 5555' -o 'server.http.port: 5555'"
docker run \
--net=host \
-e "MELODY_CLI=$MELODY_CLI" \
--mount type=bind,source="$(pwd)/filter.bpf",target=/app/filter.bpf,readonly \
--mount type=bind,source="$(pwd)/config.yml",target=/app/config.yml,readonly \
--mount type=bind,source="$(pwd)/var",target=/app/var,readonly \
--mount type=bind,source="$(pwd)/rules",target=/app/rules,readonly \
--mount type=bind,source="$(pwd)/logs",target=/app/logs/ \
ma111e/melody
I log dovrebbero accumularsi in /opt/melody/logs/melody.ndjson.
Dettagli sulla sintassi delle regole.
CVE-2020-14882 Oracle Weblogic Server RCE:
layer: http
meta:
id: 3e1d86d8-fba6-4e15-8c74-941c3375fd3e
version: 1.0
author: BonjourMalware
status: stable
created: 2020/11/07
modified: 2020/20/07
description: "Checking or trying to exploit CVE-2020-14882"
references:
- "https://nvd.nist.gov/vuln/detail/CVE-2020-14882"
match:
http.uri:
startswith|any|nocase:
- "/console/css/"
- "/console/images"
contains|any|nocase:
- "console.portal"
- "consolejndi.portal?test_handle="
tags:
cve: "cve-2020-14882"
vendor: "oracle"
product: "weblogic"
impact: "rce"
Dettagli sul contenuto dei log.
Pacchetto TCP Netcat su IPv4:
{
"tcp": {
"window": 512,
"seq": 1906765553,
"ack": 2514263732,
"data_offset": 8,
"flags": "PA",
"urgent": 0,
"payload": {
"content": "I made a discovery today. I found a computer.\n",
"base64": "SSBtYWRlIGEgZGlzY292ZXJ5IHRvZGF5LiAgSSBmb3VuZCBhIGNvbXB1dGVyLgo=",
"truncated": false
}
},
"ip": {
"version": 4,
"ihl": 5,
"tos": 0,
"length": 99,
"id": 39114,
"fragbits": "DF",
"frag_offset": 0,
"ttl": 64,
"protocol": 6
},
"timestamp": "2020-11-16T15:50:01.277828+01:00",
"session": "bup9368o4skolf20rt8g",
"type": "tcp",
"src_ip": "127.0.0.1",
"dst_port": 1234,
"matches": {},
"inline_matches": [],
"embedded": {}
}