
outis è un tool di amministrazione remota (RAT) personalizzato o qualcosa del genere. È stato costruito per supportare vari metodi di trasporto (come DNS) e piattaforme (come Powershell).
outis è un tool personalizzato di Amministrazione Remota (RAT) o qualcosa del genere. Pensate a Meterpreter o Empire-Agent. Tuttavia, l'attenzione di questo tool non è né un kit di exploit (non ci sono exploit) né la gestione persistente dei target. L'obiettivo è comunicare tra server e sistema target e trasferire file, condividere socket, generare shell e così via utilizzando vari metodi e piattaforme.
Il ciclope Polifemo nell'Odissea di Omero aveva qualche problema con la risoluzione dei nomi. Quando chiese il nome di Ulisse, l'hacker gli disse che era "Outis", che in greco antico significa "Nessuno". Così, quando Polifemo urlò che Nessuno stava per ucciderlo, stranamente non arrivò alcun aiuto. I miei ringraziamenti a Marcel per aver ricordato questo meraviglioso pezzo di storia classica.
Gli utenti Archlinux possono installare i seguenti pacchetti:
In altre distribuzioni i nomi possono differire; ad esempio, esiste un modulo chiamato crypto e uno chiamato pycrypto. Noi abbiamo bisogno del secondo.
Inoltre, versioni più vecchie potrebbero causare problemi:
$ python3 -c 'import OpenSSL; print(OpenSSL.version.__version__)'
Puoi configurare un ambiente virtuale Python abbastanza facilmente:
$ virtualenv outis-venv
$ source ./outis-venv/bin/activate
(outis-venv) $ pip install progressbar2 dnspython pycrypto pyopenssl
Ciò porta al seguente elenco di pacchetti, che sembra funzionare per me:
$ pip freeze
appdirs==1.4.3
asn1crypto==0.22.0
cffi==1.10.0
cryptography==1.8.1
dnspython==1.15.0
idna==2.5
packaging==16.8
progressbar2==3.18.1
pycparser==2.17
pycrypto==2.6.1
pyOpenSSL==16.2.0
pyparsing==2.2.0
python-utils==2.1.0
six==1.10.0
Clona questo repository git con il flag recursive per clonare anche i suoi sottomoduli nella cartella thirdpartytools:
git clone --recursive ...
L'handler gira su Python 3. Installa le sue dipendenze ed eseguilo. Genererà stager, agent e tutto il resto per te.
Per associare porte basse senza bisogno di privilegi di root, considera l'uso di un wrapper di capability.
Quando si utilizza il trasporto DNS con stager e powershell, è possibile eseguire lo staging del tool dnscat2 / dnscat2-powershell dalla directory thirdpartytools invece dell'agent outis predefinito. Imposta l'opzione di piattaforma AGENTTYPE su DNSCAT2 (richiederà un po' di tempo, ma utilizza solo DNS per lo staging) o DNSCAT2DOWNLOADER (tenta di scaricare usando HTTPS).
Il download di un file utilizzando il trasporto DNS con staging sulla piattaforma POWERSHELL potrebbe essere simile a questo:
$ outis
outis> set TRANSPORT DNS
outis> set ZONE zfs.sy.gs
outis> set AGENTDEBUG TRUE
outis> info
[+] Options for the Handler:
Name Value Required Description
----------------- ---------- -------- -----------------------------------------------------------------
TRANSPORT DNS True Communication way between agent and handler (Options: REVERSETCP,
DNS)
CHANNELENCRYPTION TLS True Encryption Protocol in the transport (Options: NONE, TLS)
PLATFORM POWERSHELL True Platform of agent code (Options: POWERSHELL)
PROGRESSBAR TRUE True Display a progressbar for uploading / downloading? (only if not
debugging the relevant module) (Options: TRUE, FALSE)
[+] Options for the TRANSPORT module DNS:
Name Value Required Description
--------- ----------- -------- ------------------------------------------------------------------------
ZONE zfs.sy.gs True DNS Zone for handling requests
LHOST 0.0.0.0 True Interface IP to listen on
LPORT 53 True UDP-Port to listen on for DNS server
DNSTYPE TXT True DNS type to use for the connection (stager only, the agent will
enumerate all supported types on its own) (Options: TXT, A)
DNSSERVER False IP address of DNS server to connect for all queries