Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Nebula — Nebula是一个云C2框架,目前提供对AWS的侦察、枚举、利用、后利用功能,但仍在努力支持测试其他云提供商和DevOps组件。 | Kitploit
工具/GitHubGitHub/gl4ssesbo1/nebula
渗透测试框架侦察漏洞利用框架后渗透利用云安全命令与控制
GitHubgl4ssesbo1/nebula

Nebula

Nebula是一个云C2框架,目前提供对AWS的侦察、枚举、利用、后利用功能,但仍在努力支持测试其他云提供商和DevOps组件。

查看仓库
6351081年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Nebula

logo

Nebula是一个云和(希望)DevOps渗透测试框架。它针对每个提供商和每个功能构建模块。截至2021年4月,它只涵盖AWS,但目前是一个持续进行的项目,希望将继续发展,测试GCP、Azure、Kubernetes、Docker或自动化引擎如Ansible、Terraform、Chef等。我开始编写它时正在阅读《Hands-On AWS Penetration Testing with Kali Linux》(https://www.amazon.com/Hands-Penetration-Testing-Kali-Linux/dp/1789136725)并基于Pacu(https://github.com/RhinoSecurityLabs/pacu)。

演讲:

  • BlackHat Europe 2021: https://www.blackhat.com/eu-21/arsenal/schedule/index.html#nebula-a-case-study-in-penetrating-something-as-soft-as-a-cloud-25174

当前涵盖:

  • AWS、Azure(Graph和Management API)以及DigitalOcean的枚举、利用和后期利用

目前有53个模块覆盖:

  • 侦察
  • 枚举
  • 利用
  • 清理

版本3.0包括:

  • 通过客户端-团队服务器架构进行团队协作
  • 所有请求都需要认证(当然除了认证请求本身)
  • 所有信息都存储在MongoDB服务器中,并可通过命令访问。当然,信息在此之前必须已被枚举,但这允许你不枚举某个特定对象

安装

服务器

Nebula使用python3.11编写。它使用boto3库访问AWS。要安装,只需进入teamserver目录并构建容器:``` $ docker build -t nebula-teamserver .

root@kitploit:~
然后,只需使用docker运行它:```
$ docker run -it nebula-teamserver -dH <database host> -du <database user> -dp <database password> -dn <database name> --p <teamserver password>
------------------------------------------------------------
           _   _      _           _
          | \ | |    | |         | |
          |  \| | ___| |__  _   _| | __ _
          | . ` |/ _ \ '_ \| | | | |/ _` |
  _______ | |\  |  __/ |_) | |_| | | (_| |
 |__   __||_| \_|\___|_.__/ \__,_|_|\__,_|
    | | ___  __ _ _ __ ___  ___  ___ _ ____   _____ _ __
    | |/ _ \/ _` | '_ ` _ \/ __|/ _ \ '__\ \ / / _ \ '__|
    | |  __/ (_| | | | | | \__ \  __/ |   \ V /  __/ |
    |_|\___|\__,_|_| |_| |_|___/\___|_|    \_/ \___|_|
-------------------------------------------------------------
37 aws          0 gcp           4 azure         0 office365
0 docker        0 kubernetes    4 misc          11 azuread
4 digitalocean
-------------------------------------------------------------
60 modules      6 cleanup               0 detection
19 enum         5 exploit               2 persistence
1 listeners     0 lateral movement      7 detection bypass
7 privesc       10 reconnaissance       2 stager        0 postexploitation
1 misc

[*] Port is busy. Is a MongoDB instance running there? [y/N] y
------------------------------------------------------------
[*] JWT Secret Key set to: '<secret value>'
[*] Database Server set to: '<db host>:<db port>'
[*] Database set to: '<db name>'
[*] Teamserver IP address is '<teamserver host>'
[*] User 'cosmonaut' was created!
[*] API Server set to: '<api host>:<api port>'
------------------------------------------------------------

客户端

与客户端 client 相同。只需转到 client 目录并构建容器:``` $ docker build -t nebula-client .

root@kitploit:~
然后,只需使用 docker 运行它:```
$ docker run -it nebula-client -ah <api host> -p <teamserver password> -b
-------------------------------------------------------------
37 aws          0 gcp           4 azure         0 office365
0 docker        0 kubernetes    4 misc          13 azuread
4 digitalocean
-------------------------------------------------------------
62 modules      6 cleanup               0 detection
19 enum         5 exploit               2 persistence
1 listeners     0 lateral movement      7 detection bypass
7 privesc       10 reconnaissance       2 stager
1 misc          2 initialaccess         0 postexploitation
-------------------------------------------------------------

[*] Importing sessions found on ~/.aws
[*] No sessions found on ~/.aws
()()(Nebula) >>>

使用```

root@kitploit:~
                                                  ...........
                                          ...''''''''''''''...
                                       ..'''''...........''''''............
                                     ..''''..             ...'''''''''''''''...
                                   ..'''..                   ..............'''''..
                                  .''''.          .;loddool:'.              ..''''..
                                 ..'''.          .;clokXWWMWNKkl;.             .''''.
                                 .'''.      .',,'..    ';dNMMMMMWKko;.           .'''..
                                .''''.   .cx0NWWNX0koc;,'cKMMMMMMMMMWXOo:.        .''''....
                                .'''.   .',',:oONMMMMMWNNNWMMMMMMWKk0WMMWXx'       .''''''''...
                               ..'''.          .,dXMMMMMMMMMMMMMNOl',oONWWd.        .......'''''..
                            ...'''''..   :o'      cXMMMMMMMMMMMMMWNXKKXNWWKxc,.             ..''''..
                          ..''''....     oNKl'. ..oXMMMMMMMMMMMMMMMMMMMMMMMMMNKOdc,..         ..''''.
                        ..''''..         ,OWWX0O0XWMMMMMMMMMMMMMMMMMMWWWWMMMMMMMMMWXOxooxk:.    ..'''.
     ..'''''''''''''''''''''.             .l0NMMMMMMMMMMMMMMMMMMMMN0dc;;;coONMMMMMMMMMMMMMK:     ..'''.
     .......................                .,dXMMMMMMMMMMMMMMMMMMWX0ko:.  .;OWMMMMMMMMMMMWx.     .'''.
                                              .oWMMMMMMMMMMMMMMWNXXXWMMWKd'  .:lccclodOXWMWd.      .'''.
         ,lc'    ..................   ',.    .,OWMMMMMMMMMMMMXx:'...:0WMMMKl.      .. .'oKO,       .'''.
        ,0MWx.  .''''''''''''''''''.  ;OKOOOO0NWMMMMMMMMMMMMNl.     .cdoox0XOl;'....... ...        .'''.
        .;ol'    ...................   ;kXWMMMMMMMMMMMMMMMMMWx.          .:0WNKkdo:.  ...         .'''.
       ....................              .:ldxk0XWMMMMMMMMMMMW0o'        .';;,.         ....     ..'''.
     ;k00000000000000000000x'                  ..;lkXWMMMMMMMMMWXkc.                            ..'''.
    .lXWWWWWWWWWWWWWWWWWWMMWKl.                     ;OWMMMMMMMMMMMWKx:.                       ..''''.
      .,,,,,,,,,,,,,,,,,:kNMMW0o,.                  'kWMMMMMMMMMMMMMMWKd,.                  ..''''..
                         .:ONMMMNKkdlc:::::::::ccldkKWMMMMMMMMMMMMMMMMMMNOl'    ...........'''''..
                           .,oOXWMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMWXkc....''''''''''...
                              .':ldkO0000000000000000000000000000000000000000Ox:.  ........
                                     ...........................................


                               _        _______  ______            _        _______
                              ( (    /|(  ____ \(  ___ \ |\     /|( \      (  ___  )
                              |  \  ( || (    \/| (   ) )| )   ( || (      | (   ) |
                              |   \ | || (__    | (__/ / | |   | || |      | (___) |
                              | (\ \) ||  __)   |  __ (  | |   | || |      |  ___  |
                              | | \   || (      | (  \ \ | |   | || |      | (   ) |
                              | )  \  || (____/\| )___) )| (___) || (____/\| )   ( |
                              |/    )_)(_______/|/ \___/ (_______)(_______/|/     \|
                                                    Because Clouds are so AWSome

                            -------------------------------------------------------------
                                                            Created by: gl4ssesbo1
                            -------------------------------------------------------------
                            48 aws          1 gcp           7 azure         0 office365
                            0 docker        0 kubernetes    6 misc          4 azuread
                            4 digitalocean
                            -------------------------------------------------------------
                            81 modules      6 cleanup               0 detection
                            19 enum         22 exploit              2 persistence
                            2 listeners     0 lateral movement      7 detection bypass
                            0 privesc       16 reconnaissance       2 stager        1 postexploitation
                            4 misc

                            Remember:
                            -------------------------------------------------------------
                            1) Only use this  tool  if  you  have  permissions  from  the
                            infrastructure's owner. Don't be a dick. Don't  choose  jail.
                            And if you have some scruples, don't hack others just because
                            you can (or cannot, in which case that's why you  chose  this
                            tool to do it).

                            2) There is a template file on module directory that you  can
                            use if you want to  develop  new  modules.  If  you  want  to
                            contribute on this tool, be my guest.

                            3) Thank you for using this tool and Hack the Planet Legally!
                            -------------------------------------------------------------

[] Importing sessions found on ~/.aws [] Imported sessions found on ~/.aws. Enter 'show credentials' to get the credentials. (test)()(Nebula)

root@kitploit:~
### 帮助
运行 *help* 命令,将显示可使用的命令列表:```
()()(AWS) >>> help

    Help Command:               Description:
    -------------               ------------

    help                        Show help for all the commands
    help credentials            Show help for credentials
    help module                 Show help for modules
    help workspace              Show help for credentials
    help user-agent             Show help for credentials
    help shell                  Show help for shell connections


    Module Commands             Description
    ---------------             -----------

    show modules                List all the modules
    show enum                   List all Enumeration modules
    show exploit                List all Exploit modules
    show persistence            List all Persistence modules
    show privesc                List all Privilege Escalation modules
    show reconnaissance         List all Reconnaissance modules
    show listener               List all Reconnaissance modules
    show cleanup                List all Enumeration modules
    show detection              List all Exploit modules
    show detectionbypass        List all Persistence modules
    show lateralmovement        List all Privilege Escalation modules
    show stager                 List all Reconnaissance modules

    use module <module>         Use a module.
    options                     Show options of a module you have selected.
    run                         Run a module you have selected. Eg: 'run <module name>'
    search                      Search for a module via pattern. Eg: 'search s3'
    back                        Unselect a module
    set <option>                Set option of a module. Need to have the module used first.
    unset <option>              Unset option of a module. Need to have the module used first.


    User-Agent commands         Description
    -------------------         -----------

    set user-agent windows      Set a windows client user agent
    set user-agent linux        Set a linux client user agent
    set user-agent custom       Set a custom client user agent
    show user-agent             Show the current user-agent
    unset user-agent            Use the user agent that boto3 produces


    Workspace Commands          Description
    ------------------          -----------

    create workspace <wp>       Create a workspace
    use workspace <wp>          Use one of the workspaces
    remove workspace <wp>       Remove a workspace


    Shell commands              Description
    -------------------         -----------

    shell check_env             Check the environment you are in, get data and meta-data
    shell exit                  Kill a connection
    shell <command>             Run a command on a system. You don't need " on the command, just shell <command1> <command2>

枚举权限

当你拥有一组凭据时,可以输入 getuid 来获取用户,或输入 enum_user_privs 来检查一组凭据的读取权限。

GetUID```

(test)()(AWS) >>> getuid

UserId: A******************Q

root@kitploit:~
    UserID: A******************Q
    Arn: arn:aws:iam::012345678912:user/user_user
    Account: 012345678912

[*] Output is saved to './workspaces/test/12_07_2021_02_22_54_getuid_dev_brian'

root@kitploit:~
如果凭据自身没有以下权限,```
STS:GetUserIdentity
IAM:GetUser
IAM:ListAttachedUserPolicies
IAM:GetPolicy (for all policies)

你会得到一个错误:``` [*] An error occurred (AccessDenied) when calling the GetUser operation: User: arn:aws:iam::012345678912:user/user_user is not authorized to perform: iam:GetUser on resource: user user_user

root@kitploit:~
#### Enum_User_Privs
该命令检查并列出和描述一组凭据的权限。```
(test)()(AWS) >>> enum_user_privs
User: user_user
        UserID: A******************Q
        Arn: arn:aws:iam::012345678912:user/user_user
        Account: 012345678912
--------------------------
Service: ec2
--------------------------
[*] Trying the 'Describe' functions:
[*] 'describe_account_attributes' worked!
[*] 'describe_addresses' worked!
[*] 'describe_aggregate_id_format' worked!
[*] 'describe_availability_zones' worked!
[*] 'describe_bundle_tasks' worked!
[*] 'describe_capacity_reservations' worked!
[*] 'describe_client_vpn_endpoints' worked!
[*] 'describe_coip_pools' worked!
[*] 'describe_customer_gateways' worked!
[*] 'describe_dhcp_options' worked!
[*] 'describe_egress_only_internet_gateways' worked!
^C[*] Stopping. It might take a while. Please wait.
[*] Output of the allowed functions is saved to './workspaces/test/12_07_2021_02_24_09_enum_user_privs'
[*] The list of the allowed functions is saved to './workspaces/test/12_07_2021_02_24_09_allowed_functions'

模块

列出模块

你可以列出所有模块或指定模块:``` ()()(AWS) >>> show modules cleanup/aws_iam_delete_access_key Delete access key of a user by providing it.

root@kitploit:~
    cleanup/aws_iam_delete_login_profile                                  Delete access of a user to the Management
                                                                            Console

    enum/aws_ec2_enum_elastic_ips                                         Lists User data of an Instance provided.
                                                                            Requires Secret Key and Access Key of an IAM that has access
                                                                            to it.

    enum/aws_ec2_enum_images                                              List all ec2 images. Needs credentials of an
                                                                            IAM with DescribeImages right. Output is dumpled on a file.
                                                                            It takes a sh*tload of time, unfortunately. And boy, is it a
                                                                            huge output.

    enum/aws_ec2_enum_instances                                           Describes instances attribues: Instances, VCP,
                                                                            Zones, Images, Security Groups, Snapshots, Subnets, Tags,
                                                                            Volumes. Requires Secret Key and Access Key of an IAM that
                                                                            has access to all or any of the API calls:
                                                                            DescribeAvailabilityZones, DescribeImages,
                                                                            DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups,
                                                                            DescribeSnapshots, DescribeSubnets, DescribeTags,
                                                                            DescribeVolumes, DescribeVpcs
root@kitploit:~
就这样,你可以使用:```
     show module
     show enum
     show exploit
     show persistence
     show privesc
     show reconnaissance
     show listener
     show cleanup
     show detection
     show detectionbypass
     show lateralmovement
     show stager

搜索模块

使用 search 命令搜索包含特定词的模块:``` ()()(AWS) >>> search instance enum/aws_ec2_enum_instances Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

root@kitploit:~
    enum/aws_iam_list_instance_profiles                                   List all the instance profiles.

    exploit/aws_ec2_create_instance_with_user_data                        You must provide policies in JSON format in
                                                                            IAM. However, for AWS CloudFormation templates formatted in
                                                                            YAML, you can provide the policy in JSON or YAML format. AWS
                                                                            CloudFormation always converts a YAML policy to JSON format
                                                                            before submitting it to IAM.

()()(AWS) >>>

root@kitploit:~
#### 使用模块
要使用模块,只需输入 *use* 和模块名称。三个括号中会显示模块名称。```
(work1)()(enum/aws_ec2_enum_instances) >>> use module enum/aws_iam_get_group
(work1)()(enum/aws_ec2_enum_instances) >>>

选项

使用 options,我们可以列出模块的信息:``` (work1)()(enum/aws_ec2_enum_instances) >>> options Desctiption:

root@kitploit:~
    Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

Author:

root@kitploit:~
    name:   gl4ssesbo1
    twitter:        https://twitter.com/gl4ssesbo1
    github: https://github.com/gl4ssesbo1
    blog:   https://www.pepperclipp.com/

AWSCLI Command:

root@kitploit:~
    aws ec2 describe-instances --region {} --profile {}

Needs Credentials: True

Options:

root@kitploit:~
    SERVICE:        ec2
            Required: true
            Description: The service that will be used to run the module. It cannot be changed.

    INSTANCE-ID:
            Required: false
            Description: The ID of the instance you want to enumerate. If not supplied, all instances will be enumerated.

(work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
要设置选项,请使用 *set* 和选项名称:```
(work1)()(enum/aws_ec2_enum_instances) >>> set INSTANCE-ID 1234
(work1)()(enum/aws_ec2_enum_instances) >>> options
Desctiption:
-----------------------------
        Describes instances attribues: Instances, VCP, Zones, Images, Security Groups, Snapshots, Subnets, Tags, Volumes. Requires Secret Key and Access Key of an IAM that has access to all or any of the API calls: DescribeAvailabilityZones, DescribeImages, DescribeInstances, DescribeKeyPairs, DescribeSecurityGroups, DescribeSnapshots, DescribeSubnets, DescribeTags, DescribeVolumes, DescribeVpcs

Author:
-----------------------------
        name:   gl4ssesbo1
        twitter:        https://twitter.com/gl4ssesbo1
        github: https://github.com/gl4ssesbo1
        blog:   https://www.pepperclipp.com/

Needs Credentials: True
-----------------------------

AWSCLI Command:
-----------------------------
        aws ec2 describe-instances --region {} --profile {}

Options:
-----------------------------
        SERVICE:        ec2
                Required: true
                Description: The service that will be used to run the module. It cannot be changed.

        INSTANCE-ID:    1234
                Required: false
                Description: The ID of the instance you want to enumerate. If not supplied, all instances will be enumerated.

(work1)()(enum/aws_ec2_enum_instances) >>>

同时使用 unset 取消设置它们。``` (work1)()(enum/aws_ec2_enum_instances) >>> unset INSTANCE-ID (work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
#### 运行模块
要运行该模块,如果它需要凭证,您需要已导入一组具备运行所需权限的凭证。这会在模块的选项中显示为:```
Needs Credentials: True
-----------------------------

要运行它,只需输入 run。根据输出,它会显示分页视图,或者直接打印。分页功能使用了 less 二进制文件,Windows 系统使用来自 https://github.com/jftuga/less-Windows 的二进制文件。该 exe 的副本位于 less_binary 目录中。 输出也会保存在工作区目录中的文件里:``` (work1)()(enum/aws_ec2_enum_instances) >>> run [*] Content dumped on file './workspaces/work1/16_04_2021_18_16_48_ec2_enum_instances'.

root@kitploit:~
### 凭据
#### 输入凭据
Nebula 可以使用 AccessKeyID + SecretKey 组合以及 AccessKeyID + SecretKey + SessionKey 组合来认证到基础设施中。
要插入一组凭据,请使用:```
()()(AWS) >>> set credentials test1
Profile Name: test1
Access Key ID: A*********2
Secret Key ID: a****************************7
Region: us-west-3

Do you also have a session token?[y/N]
[*] Credentials set. Use 'show credentials' to check them.
[*] Currect credential profile set to 'test1'.Use 'show current-creds' to check them.

并且你将获得一些输入,允许你设置它们。在输入凭证时,可以通过在被提示 Do you also have a session token?[y/N] 时输入 y 来添加会话令牌。

####使用凭证 要使用另一个凭证,只需输入:``` ()()(AWS) >>> use credentials test1 [*] Currect credential profile set to 'test1'.Use 'show current-creds' to check them.

root@kitploit:~
####当前凭据
当您输入凭据时,它们会自动成为当前凭据,即您将用于身份验证的凭据。要检查当前凭据,请使用:```
()()(AWS) >>> show current-creds
{
    "profile": "test1",
    "access_key_id": "A*********2",
    "secret_key": "a****************************7",
    "region": "us-west-3"
}

####删除凭据 如果你不想保留你的凭据,你可以使用以下命令删除它们:``` ()()(AWS) >>> remove credentials test1 You are about to remove credential 'test1'. Are you sure? [y/N] y

root@kitploit:~
#### 转储和导入凭据
如果你想把凭据保存在本地机器上,可以使用:```
()()(AWS) >>> dump credentials
[*] Credentials dumped on file './credentials/16_04_2021_17_37_59'.

它们将被保存到一个包含转储时间和日期的文件中,该文件位于Nebula目录下的 credentials 目录中。 要导入它们,只需输入:``` ()()(AWS) >>> import credentials 16_04_2021_17_37_59 ()()(AWS) >>> show credentials [ { "profile": "test1", "access_key_id": "A*******2", "secret_key": "a**************************7", "region": "us-west-3" } ]

root@kitploit:~
### 工作区
Nebula 使用工作区来保存每条命令的输出。输出以 json 数据格式保存在 *workspaces* 目录下创建的文件夹中(s3_name_fuzzer 除外,它保存为 XML 格式)。
#### 创建工作区
要创建工作区,请输入:```
()()(AWS) >>> create workspace work1
[*] Workspace 'work1' created.
[*] Current workspace set at 'work1'.
(work1)()(AWS) >>> ls ./workspaces


    Directory: C:\Users\***\Desktop\Nebula\workspaces


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         4/16/2021   5:42 PM                work1
-a----         4/16/2021   4:40 PM              0 __init__.py

创建时,第一个括号将包含您正在使用的工作区的名称。 如果您想使用现有工作区,只需输入:``` ()()(AWS) >>> use workspace work1 (work1)()(AWS) >>>

root@kitploit:~
工作区是必需使用的,因此即使您当前没有使用任何工作区,在运行模块时,它会要求您创建一个随机名称的工作区,或者自行创建一个自定义名称的工作区。```
()()(enum/aws_ec2_enum_instances) >>> run
A workspace is not configured. Workstation 'qxryiuct' will be created. Are you sure? [y/N] n
[*] Create a workstation first using 'create workstation <workstation name>'.
()()(enum/aws_ec2_enum_instances) >>>

列出工作区

要获取工作区列表,请使用:``` (work1)()(enum/aws_ec2_enum_instances) >>> show workspaces

Workspaces:

root@kitploit:~
    work1

(work1)()(enum/aws_ec2_enum_instances) >>>

root@kitploit:~
#### 移除工作区
要移除工作区,请输入:```
()()(AWS) >>> remove workspace work1
[*] Are you sure you want to delete the workspace? [y/N] y
()()(AWS) >>> show workspaces
-----------------------------------
Workspaces:
-----------------------------------

()()(AWS) >>>

反向Shell

要创建反向Shell,您需要创建一个存根程序并运行一个监听器。要使用此功能,您需要以root身份运行Nebula(以打开端口)。

存根程序

要生成存根程序,请使用存根程序模块:``` ()()(AWS) >>> use module stager/aws_python_tcp ()()(stager/aws_python_tcp) >>> options Desctiption:

root@kitploit:~
    The TCP Reverse Shell that is used by listeners/aws_python_tcp_listener

Author:

root@kitploit:~
    name:   gl4ssesbo1
    twitter:        https://twitter.com/gl4ssesbo1
    github: https://github.com/gl4ssesbo1
    blog:   https://www.pepperclipp.com/

Needs Credentials: False

AWSCLI Command:

root@kitploit:~
    None

Options:

root@kitploit:~
    SERVICE:        none
            Required: true
            Description: The service that will be used to run the module. It cannot be changed.

    HOST:
            Required: true
            Description: The Host/IP of the C2 Server.

    PORT:
            Required: true
            Description: The C2 Server Port.

    FORMAT:
            Required: true
            Description: The format of the stager. Currently only allows 'py' for Python and 'elf' for ELF Binary.

    CALLBACK-TIME:  None
            Required: true
            Description: The time in seconds between callbacks from Stager. The Stager calls back even if the server crashes or is stoped in a loop.

    OUTPUT-FILE-NAME:
            Required: true
            Description: The name of the stager output file.
root@kitploit:~
要填写的选项有:
   - **HOST**:C2服务器的IP或域名
   - **Port**:C2服务器端口
   - **Format**:当前仅支持python raw文件和elf二进制文件
   - **Callback-Time**:会话回调的时间(秒)。即使当前会话处于活动状态,或者服务器崩溃或关闭,它也会进行回调,这样你就不会失去对机器的访问。
   - **Output File Name**:输出文件的名称。

运行模块将生成一个存根器,保存在 **./workspaces/workspacename/stagername** 下。

#### 监听器
监听器很简单。只需配置Host(默认设置为0.0.0.0)和Port,即可创建服务器。要运行监听器,你需要以root身份运行Nebula。```
()()(stager/aws_python_tcp) >>> use module listeners/aws_python_tcp_listener
()()(listeners/aws_python_tcp_listener) >>> options
Desctiption:
-----------------------------
        TCP Listener for Reverse Shell stagers/aws_python_tcp

Author:
-----------------------------
        name:   gl4ssesbo1
        twitter:        https://twitter.com/gl4ssesbo1
        github: https://github.com/gl4ssesbo1
        blog:   https://www.pepperclipp.com/

Needs Credentials: False
-----------------------------

AWSCLI Command:
-----------------------------
        None

Options:
-----------------------------
        SERVICE:        none
                Required: true
                Description: The service that will be used to run the module. It cannot be changed.

        HOST:   0.0.0.0
                Required: true
                Description: The Host/IP of the C2 Server.

        PORT:
                Required: true
                Description: The C2 Server Port.

用户代理

用户代理可以设置为Linux、Windows或自定义。要显示它们,只需使用show。``` ()()(AWS) >>> set user-agent linux User Agent: Boto3/1.9.89 Python/3.8.1 Linux/4.1.2-34-generic was set ()()(AWS) >>> show user-agent [] User Agent is: Boto3/1.9.89 Python/3.8.1 Linux/4.1.2-34-generic ()()(AWS) >>> set user-agent windows User Agent: Boto3/1.7.48 Python/3.9.1 Windows/7 Botocore/1.10.48 was set ()()(AWS) >>> show user-agent [] User Agent is: Boto3/1.7.48 Python/3.9.1 Windows/7 Botocore/1.10.48 ()()(AWS) >>> set user-agent custom Enter the User-Agent you want: sth User Agent: sth was set ()()(AWS) >>> show user-agent [*] User Agent is: sth ()()(AWS) >>>

root@kitploit:~
要取消设置用户代理,请输入:```
()()(AWS) >>> unset user-agent
[*] User Agent set to empty.

这将具有系统的用户代理。

下载工具