
Framework di phishing modulare con CLI per clonare siti, inviare email basate su modelli e lanciare campagne di phishing tramite email, SMS, iMessage e LinkedIn.
http://section9labs.github.io/Cartero/
Un robusto framework di phishing con un'interfaccia CLI completa. Il progetto è nato dalla necessità, maturata in anni di engagement con strumenti che semplicemente non facevano il loro lavoro. Anche se esistono molti progetti in circolazione, non siamo riusciti a trovare una soluzione adatta che ci garantisse sia facilità d'uso che personalizzazione.
Cartero è un progetto modulare suddiviso in comandi che svolgono attività indipendenti (ad es. Mailer, Cloner, Listener, AdminConsole, ecc...). Inoltre ogni sottocomando dispone di opzioni di configurazione ripetibili per configurare e automatizzare il proprio lavoro.
Ad esempio, se volessimo clonare gmail.com, dovremmo semplicemente eseguire i seguenti comandi.```shell ❯❯❯ ./cartero Cloner --url https://gmail.com --path /tmp --webserver gmail_com ❯❯❯ ./cartero Listener --webserver /tmp/gmail_com -p 80 Launching mongodb Puma starting in single mode...
Una volta che abbiamo un sito in funzione possiamo semplicemente usare il comando Mailer per inviare email basate su modelli alle nostre vittime:```shell
❯❯❯ ./cartero Mailer --data victims.json --server gmail_com --subject "Internal Memo" --htmlbody email_html.html --attachment payload.pdf --from "John Doe <[email protected]>"
Sending [email protected]
Sending [email protected]
Sending [email protected]
Unisciti alla nostra community Slack su https://carteroslack.herokuapp.com/
Utilizzando brew 2.1.5 con ruby come libreria ruby predefinita```shell ❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash
Utilizzo dell'installazione di Ruby 2.1.5 di RVM```shell
❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash -s -- -r
❯❯❯ \curl -sSL https://get.rvm.io | bash -s stable --ruby
##### MongoDB
Cartero utilizza MongoDB + la libreria MongoID per archiviare i dati lato Listener e lato Admin.
Su OSX:```shell
❯❯❯ brew install mongodb
Su Ubuntu / Kali / Debian```shell ❯❯❯ apt-get install mongodb
Su Arch Linux```
❯❯❯ pacman -Syu mongodb
❯❯❯ git clone https://github.com/section9labs/Cartero ❯❯❯ cd Cartero ❯❯❯ gem install bundle ❯❯❯ bundle install ❯❯❯ cd bin
### Utilizzo
### Comandi
Cartero è una CLI molto potente e facile da usare.```shell
❯❯❯ ./cartero
Usage: cartero [options]
List of Commands:
AdminConsole, AdminWeb, Mailer, Cloner, Listener, Servers, Templates
Global options:
--proxy [HOST:PORT] Sets TCPSocket Proxy server
-c, --config [CONFIG_FILE] Provide a different cartero config file
-v, --[no-]verbose Run verbosely
-p [PORT_1,PORT_2,..,PORT_N], Global Flag fo Mailer and Webserver ports
--ports
-m, --mongodb [HOST:PORT] Global Flag fo Mailer and Webserver ports
-d, --debug Sets debug flag on/off
--editor [EDITOR] Edit Server
Common options:
-h, --help [COMMAND] Show this message
--list-commands Prints list of commands for bash completion
--version Shows cartero CLI version
Questo è un semplice wrapper per MongoDB che ci permette di avviare e fermare il database con i comandi corrispondenti e sul percorso corretto ~/.cartero.```shell ❯❯❯ ./cartero Mongo Usage: Cartero Mongo [options] -s, --start Start MongoDB -k, --stop Stop MongoDB -r, --restart Restart MongoDB -b, --bind [HOST:PORT] Set MongoDB bind_ip and port
Common options: -h, --help Show this message --list-options Show list of available options
#### Cloner
Un Cloner di siti web che ci consente di scaricare e convertire un sito web in un'applicazione Cartero WebServer.
Possiamo personalizzare rapidamente e facilmente il sito web per raccogliere credenziali, distribuire payload sul server o modificare completamente il sito per qualsiasi numero di scopi.```shell
❯❯❯ ./cartero Cloner
Usage: Cartero Cloner [options]
-U, --url [URL_PATH] Full Path of site to clone
-W, --webserver [SERVER_NAME] Sets WebServer name to use
-p, --path [PATH] Sets path to save webserver
-P, --payload [PAYLOAD_PATH] Sets payload path
--useragent [UA_STRING] Sets user agent for cloning
--wget Use wget to clone url
--apache Generate Apache Proxy conf
Common options:
-h, --help Show this message
--list-options Show list of available options
Per impostazione predefinita, il comando utilizza la nostra implementazione Ruby per scaricare e convertire i link da renderizzare, ma supportiamo anche un'opzione --wget che utilizzerà il comando di sistema wget locale.
Il listener è responsabile dell'esecuzione del WebServer creato tramite Cloner o di un sito creato manualmente. Per impostazione predefinita, presentiamo un sito web molto semplice se non ne viene fornito uno.```shell ❯❯❯ ./cartero Listener Usage: Cartero Listener [options] -i, --ip [1.1.1.1] Sets IP interface, default is 0.0.0.0 -p [PORT_1,PORT_2,..,PORT_N], Sets Email Payload Ports to scan --ports -s, --ssl Run over SSL. [this also requires --sslcert and --sslkey] -C, --sslcert [CERT_PATH] Sets Email Payload Ports to scan -K, --sslkey [KEY_PATH] Sets SSL key to use for Listener. -V, --views [VIEWS_FOLDER] Sets SSL Certificate to use for Listener. -P, --public [PUBLIC_FOLDER] Sets a Sinatra public_folder -W [WEBSERVER_FOLDER], Sets the sinatra full path from cloner. --webserver --payload [PAYLOAD] Sets a payload download to serve on /download --customapp [CUSTOM_SINATRA] Sets a custom Sinatra::Base WebApp. Important, WebApp name should be camelized of filename
Common options: -h, --help Show this message --list-options Show list of available options
I WebServers supportano chiavi ssl e virtual hosts su più IP, hostname e porte.
#### Server
Per inviare campagne email, dobbiamo configurare i server email e questo comando consente a Cartero di creare, archiviare e elencare i server. Tutti i dati sono memorizzati nella directory di configurazione ~/.cartero.```shell
./cartero Servers
Usage: Cartero Servers [options]
-a, --add [NAME] Add Server
-e, --edit [NAME] Edit Server
-d, --delete [NAME] Edit Server
-l, --list List servers
Configuration options:
-T, --type [TYPE] Set the type
-U, --url [DOMAIN] Set the Mail or WebMail url/address
-M, --method [METHOD] Sets the WebMail Request Method to use [GET|POST]
--api-access [API_KEY] Sets the Linkedin API Access Key
--api-secret [API_SECRET] Sets the Linkedin API Secret Key
--oauth-token [OAUTH_TOKEN] Sets the Linkedin OAuth Token Key
--oauth-secret [OAUTH_SECRET]
Sets the Linkedin OAuth Secret Key