
kit de ataque a servidores de aplicação
clusterd é um kit de ferramentas de ataque de servidor de aplicação open source. Nascido da frustração com os métodos atuais de fingerprinting e exploração, o clusterd automatiza as fases de fingerprinting, reconhecimento e exploração de um ataque a servidores de aplicação. Consulte a wiki para mais informações.
A instalação recomendada do clusterd é clonar o repositório Github
git clone https://github.com/hatRiot/clusterd.git
O clusterd atualmente suporta seis plataformas de servidor de aplicação diferentes, com várias outras atualmente em fases de desenvolvimento e pesquisa
JBoss
ColdFusion
WebLogic
Tomcat
Railo
Axis2
Glassfish
API simples para adicionar novas plataformas, fingerprints, deployers e exploits
Vários módulos auxiliares para vulnerabilidades e técnicas de exploração
$ ./clusterd.py
clusterd/0.3.1 - clustered attack toolkit
[Supporting 7 platforms]
usage: ./clusterd.py [options]
optional arguments:
-h, --help show this help message and exit
Connection:
Options for configuring the connection
-i [ip address] Server address
-iL [file] Server list
-p [port] Server port
--proxy [proxy://server:port]
Connect through proxy [http|https]
--proxy-auth [username:password]
Proxy credentials
--timeout [seconds] Connection timeout [5s]
--random-agent Use a random User-Agent for requests
--ssl Force SSL
Remote Host:
Settings specific to the remote host
-a [jboss|coldfusion|weblogic|tomcat|railo|axis2|glassfish]
Hint at remote host service
-o [windows|linux] Hint at remote host OS
-v [version] Specific version to test
--usr-auth [username:password]
Login credentials for service
--fingerprint Fingerprint the remote system
--arch [x86|x64] Specify remote OS architecture
Deploy:
Deployment flags and settings
--deploy [file] Deploy to the discovered service
--undeploy [context] Undeploy file from server
--deployer [deployer]
Specify a deployer to use
--invoke Invoke payload after deployment
--rand-payload Use a random name for the deployed file
-b [user] Brute force credentials for user [admin]
--wordlist [path] Wordlist for brute forcing passwords
Other:
Miscellaneous flags
--deployer-list List all available deployers
--aux-list [platform]
List all available exploits
--gen-payload [host:port] for reverse connection
Generate a reverse shell payload
--discover [discovery_file]
Attempt to discover application servers using the
specified nmap gnmap output (use -sV when scanning)
--listen [adapter] Adapter to listen on when needed
-d Enable debug output
-l Log output to file [$time$_log.log]
fingerprint e informações de host do JBoss
$ ./clusterd.py -i 192.168.1.105 -a jboss --jb-info --random-agent
clusterd/0.3 - clustered attack toolkit
[Supporting 6 platforms]