Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
mose — 配置管理服务器的后渗透利用工具。 | Kitploit
工具/GitHubGitHub/master-of-servers/mose
Payload生成配置审计后渗透利用渗透测试红队
GitHubmaster-of-servers/mose

mose

配置管理服务器的后渗透利用工具。

查看仓库
7717198个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

MOSE(服务器大师)

DEF CON 27 License Go Report Card Tests Pre-Commit Semgrep Renovate GoReleaser

版权 2020 桑迪亚国家技术与工程解决方案公司(NTESS)。 根据合同 DE-NA0003525 与 NTESS 的规定, 美国政府保留对此软件的某些权利。

MOSE 是一款后利用工具,帮助安全专业人员在入侵后利用配置管理(CM)系统。像 Puppet、Chef、Salt 和 Ansible 这样的 CM 工具可以在大规模主机群上运行命令,但它们的 DSL 和工作流在压力下往往难以快速掌握。MOSE 允许你描述想要执行的操作,然后为你构建 CM 特定的有效载荷。

MOSE 的功能

  1. 抽象 CM 特定有效载荷,让你专注于意图而非工具特定语法。
  2. 针对子集或整个清单进行精确操作。
  3. 自动化有效载荷生成与暂存,减少操作员负担。

支持的 CM 目标

  • Puppet
  • Chef
  • Salt
  • Ansible

MOSE + Puppet

MOSE 与 Puppet

MOSE + Chef

MOSE 与 Chef

依赖

安装以下内容:

  • Golang - 测试版本 1.12.7 到 1.15.2

    • 确保正确设置 GOROOT、PATH 和 GOPATH 环境变量。
  • Docker - 测试版本 18.09.2 到 19.03.12

快速开始

从源码安装

无需克隆仓库即可获取代码:

go get -u -v github.com/master-of-servers/mose

安装所有 Go 特定依赖并构建二进制文件(运行前请确保 cd 进入仓库目录):

make build

用法

Usage:
  github.com/master-of-servers/mose [command]

Available Commands:
  ansible     Create MOSE payload for ansible
  chef        Create MOSE payload for chef
  help        Help about any command
  puppet      Create MOSE payload for puppet
  salt        Create MOSE payload for salt

Flags:
      --basedir string            Location of payloads output by mose
                                 (default "/Users/l/programs/go/src/github.com/master-of-servers/mose")
  -c, --cmd string                Command to run on the targets
      --config string             config file (default is $PWD/.settings.yaml)
      --debug                     Display debug output
      --exfilport int             Port used to exfil data from chef server
                                 (default 9090, 443 with SSL) (default 9090)
  -f, --filepath string           Output binary locally at <filepath>
  -u, --fileupload string         File upload option
  -h, --help                      help for github.com/master-of-servers/mose
  -l, --localip string            Local IP Address
      --nocolor                   Disable colors for mose
  -a, --osarch string             Architecture that the target CM tool is running on
  -o, --ostarget string           Operating system that the target CM server is on (default "linux")
  -m, --payloadname string        Name for backdoor payload (default "my_cmd")
      --payloads string           Location of payloads output by mose
                                 (default "/Users/l/programs/go/src/github.com/master-of-servers/mose/payloads")
      --remoteuploadpath string   Remote file path to upload a script to
                                 (used in conjunction with -fu)
                                 (default "/root/.definitelynotevil")
  -r, --rhost string              Set the remote host for /etc/hosts in the chef workstation container (format is hostname:ip)
      --ssl                       Serve payload over TLS
      --tts int                   Number of seconds to serve the payload (default 60)
      --websrvport int            Port used to serve payloads
                                 (default 8090, 443 with SSL) (default 8090)

Use "github.com/master-of-servers/mose [command] --help" for more information about a command.

TLS 证书

建议

生成并使用由受信任证书颁发机构签名的 TLS 证书。

我们为您提供了一个自签名证书和密钥,但强烈建议不要使用它们。此密钥和证书已广泛分发,如果您选择使用,则无法保证隐私。它们可以在 data 目录中找到。

示例

您可以在 EXAMPLES.md 中找到一些运行 MOSE 的示例。

测试实验室

以下位置提供可与 MOSE 一起运行的测试实验室:

  • https://github.com/master-of-servers/puppet-test-lab
  • https://github.com/master-of-servers/chef-test-lab
  • https://github.com/master-of-servers/ansible-test-lab
  • https://github.com/master-of-servers/salt-test-lab

责任使用

MOSE 仅用于授权的安全测试和研究。请确保您拥有针对任何环境进行操作的明确许可。

致谢

以下资源对本项目的创建起到了激励作用:

  • https://oneplus-x.github.io/2017/06/11/Enterprise-Offense-IT-Operations-Part-1/
  • https://www.chef.io/blog/detecting-repairing-shellshock-with-chef
下载工具