Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
BlockchainC2 — Un server C2 e un agente POC per esplorare se e come la blockchain di Ethereum possa essere utilizzata per il C2. | Kitploit
Strumenti/GitHubGitHub/xpn/blockchainc2
ExploitPenetration TestingCommand and ControlRed TeamingSviluppo Payload
GitHubxpn/blockchainc2

BlockchainC2

Un server C2 e un agente POC per esplorare se e come la blockchain di Ethereum possa essere utilizzata per il C2.

Vedi Repository
7922127 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

BlockchainC2

BlockchainC2 è un piccolo POC server/agente per valutare come la Blockchain (in particolare la funzionalità Smart Contract di Ethereum) possa essere utilizzata da un attaccante per il C2.

I dettagli su questa applicazione sono disponibili qui.

Smart Contract

Lo Smart Contract utilizzato in questo POC è piuttosto semplice:

pragma solidity ^0.5.0;

contract EventC2 {

    address owner;

    event _ServerData(bool f, bool enc, int seq, string agentID, string data);
    event _ClientData(bool f, bool enc, int seq, string agentID, string data);

    constructor() public {
        owner = msg.sender;
    }
    
    function AddClientData(string memory agentID, string memory d, int id, bool f, bool enc) public {
        emit _ClientData(f, enc, id, agentID, d);
    }

    function AddServerData(string memory agentID, string memory d, int id, bool f, bool enc) public {
        emit _ServerData(f, enc, id, agentID, d);
    }
}

L'obiettivo di questo codice Solidity è passare eventi tra un server e più client sotto forma di eventi.

Compilazione

BlockchainC2 è stato progettato per essere eseguito su MacOS/Linux, ma l'agente può essere compilato per essere eseguito su MacOS, Windows o Linux.

Per compilare su MacOS usando brew:

# Installare solidity ed ethereum
brew tap ethereum/ethereum
brew install ethereum
brew install solidity

# Compilare
make all

Per compilare su Ubuntu:

# Installare solidity ed ethereum
sudo add-apt-repository ppa:ethereum/ethereum
sudo apt-get update
sudo apt-get install solc ethereum

# Compilare  
make all

Per cross-compilare un agente per Windows:

CGO_ENABLED=1 CC="x86_64-w64-mingw32-gcc" GOOS=windows go build blockchainc2/cmd/bc2agent

Esecuzione

Dovrai impostare un account che possa essere utilizzato dal componente server. Il modo più semplice per farlo è con geth:

geth account new --keystore /tmp/mykeystore/
cat /tmp/mykeystore/*

Puoi aggiungere Ether al tuo wallet sulla rete di test Ropsten utilizzando https://faucet.ropsten.be/.

Aggiungi il keychain al tuo config.json, ad esempio:

{
	"Key": "{\"address\":\"ADDRESS\",\"crypto\":{\"cipher\":\"aes-128-ctr\",\"ciphertext\":\"CT\",\"cipherparams\":{\"iv\":\"IV\"},\"kdf\":\"scrypt\",\"kdfparams\":{\"dklen\":32,\"n\":262144,\"p\":1,\"r\":8,\"salt\":\"06470fcc2121994e014f85e5ab9cdb3714c76b873a1f1186c3e623e87abc4a7a\"},\"mac\":\"SALT\"},\"id\":\"ID\",\"version\":3}",
	"Endpoint": "wss://ropsten.infura.io/_ws",
	"ContractAddress": "TODO_VIA_SETUP",
	"GasPrice": 0
}

Per distribuire un contratto usando bc2server:

./bin/bc2server -config ./config.json -pass Passw0rd -setup

Una volta distribuito il contratto, aggiungi l'indirizzo al tuo config.json e avvia il server con:

./bin/bc2server -config ./config.json -pass Passw0rd

Con il server in esecuzione, gli agenti possono essere collegati usando:

./bin/bc2agent -config ./agent_config.json -pass Passw0rd

Si consiglia di utilizzare un account nuovo per un agente per evitare errori con transazioni in sospeso.

Scarica lo strumento