Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/mrbrutti/cartero
钓鱼工具社会工程学OSINTPayload生成钓鱼攻击社会工程学
GitHubmrbrutti/cartero

Cartero

具有CLI的模块化钓鱼框架,用于克隆网站、发送模板化电子邮件,以及通过电子邮件、短信、iMessage和LinkedIn发起钓鱼活动。

查看仓库网站
4944526个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

邮件

Cartero

URL

http://section9labs.github.io/Cartero/

描述

一个功能强大的网络钓鱼框架,带有功能完整的 CLI 界面。该项目的诞生源于多年的实战需求——现有工具始终无法胜任工作。尽管市面上已有许多项目,但我们始终未能找到一个兼具易用性和可定制性的合适解决方案。

Cartero 是一个模块化项目,分为执行独立任务的命令(例如 Mailer、Cloner、Listener、AdminConsole 等)。此外,每个子命令都具有可重复的配置选项,用于配置和自动化你的工作。

例如,如果我们想要克隆 gmail.com,只需执行以下命令即可。```shell ❯❯❯ ./cartero Cloner --url https://gmail.com --path /tmp --webserver gmail_com ❯❯❯ ./cartero Listener --webserver /tmp/gmail_com -p 80 Launching mongodb Puma starting in single mode...

  • Version 2.8.2 (ruby 2.1.1-p76), codename: Sir Edmund Percival Hillary
  • Min threads: 4, max threads: 16
  • Environment: production
  • Listening on tcp://0.0.0.0:80 Use Ctrl-C to stop
一旦我们有一个网站运行起来,就可以直接使用 Mailer 命令向受害者发送模板化电子邮件:```shell
❯❯❯ ./cartero Mailer --data victims.json --server gmail_com --subject "Internal Memo" --htmlbody email_html.html --attachment payload.pdf --from "John Doe <[email protected]>"
Sending [email protected]
Sending [email protected]
Sending [email protected]

社区

加入我们的 Slack 社区:https://carteroslack.herokuapp.com/

安装

自动安装

使用 brew 2.1.5 ruby 作为默认 ruby 库```shell ❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash

使用 RVM 安装 Ruby 2.1.5```shell
❯❯❯ curl -L https://raw.githubusercontent.com/Section9Labs/Cartero/master/data/scripts/setup.sh | bash -s -- -r

依赖项

Ruby```shell

❯❯❯ \curl -sSL https://get.rvm.io | bash -s stable --ruby

##### MongoDB
Cartero 使用 MongoDB + MongoID 库来在 Listener 和 Admin 端存储数据。 

在 OSX 上:```shell
❯❯❯ brew install mongodb

在 Ubuntu / Kali / Debian 上```shell ❯❯❯ apt-get install mongodb

在 Arch Linux 上```
❯❯❯ pacman -Syu mongodb

框架```shell

❯❯❯ git clone https://github.com/section9labs/Cartero ❯❯❯ cd Cartero ❯❯❯ gem install bundle ❯❯❯ bundle install ❯❯❯ cd bin

### 用法
### 命令
Cartero 是一个功能非常强大且易于使用的 CLI。```shell
❯❯❯ ./cartero
Usage: cartero [options]

List of Commands:
    AdminConsole, AdminWeb, Mailer, Cloner, Listener, Servers, Templates

Global options:
        --proxy [HOST:PORT]          Sets TCPSocket Proxy server
    -c, --config [CONFIG_FILE]       Provide a different cartero config file
    -v, --[no-]verbose               Run verbosely
    -p [PORT_1,PORT_2,..,PORT_N],    Global Flag fo Mailer and Webserver ports
        --ports
    -m, --mongodb [HOST:PORT]        Global Flag fo Mailer and Webserver ports
    -d, --debug                      Sets debug flag on/off
        --editor [EDITOR]            Edit Server


Common options:
    -h, --help [COMMAND]             Show this message
        --list-commands              Prints list of commands for bash completion
        --version                    Shows cartero CLI version

Basic Commands

Mongo

这是一个简单的 MongoDB 封装器,允许我们使用相应命令在正确的 ~/.cartero 路径上启动或停止数据库。```shell ❯❯❯ ./cartero Mongo Usage: Cartero Mongo [options] -s, --start Start MongoDB -k, --stop Stop MongoDB -r, --restart Restart MongoDB -b, --bind [HOST:PORT] Set MongoDB bind_ip and port

Common options: -h, --help Show this message --list-options Show list of available options

#### Cloner
一个网站克隆器,允许我们将网站下载并转换为 Cartero WebServer 应用程序。
我们可以快速轻松地定制网站,用于收集凭据、服务端 Payload,或出于各种目的全面修改网站。```shell
❯❯❯ ./cartero Cloner
Usage: Cartero Cloner [options]
    -U, --url [URL_PATH]             Full Path of site to clone
    -W, --webserver [SERVER_NAME]    Sets WebServer name to use
    -p, --path [PATH]                Sets path to save webserver
    -P, --payload [PAYLOAD_PATH]     Sets payload path
        --useragent [UA_STRING]      Sets user agent for cloning
        --wget                       Use wget to clone url
        --apache                     Generate Apache Proxy conf

Common options:
    -h, --help                       Show this message
        --list-options               Show list of available options

默认情况下,该命令使用我们的 Ruby 实现来下载并转换链接以进行渲染,但我们也支持 --wget 选项,该选项将使用本地的 wget 系统命令。

监听器

监听器负责运行通过 Cloner 创建的 WebServer 或手动创建的站点。默认情况下,如果未提供任何站点,我们会展示一个非常简单的网站。```shell ❯❯❯ ./cartero Listener Usage: Cartero Listener [options] -i, --ip [1.1.1.1] Sets IP interface, default is 0.0.0.0 -p [PORT_1,PORT_2,..,PORT_N], Sets Email Payload Ports to scan --ports -s, --ssl Run over SSL. [this also requires --sslcert and --sslkey] -C, --sslcert [CERT_PATH] Sets Email Payload Ports to scan -K, --sslkey [KEY_PATH] Sets SSL key to use for Listener. -V, --views [VIEWS_FOLDER] Sets SSL Certificate to use for Listener. -P, --public [PUBLIC_FOLDER] Sets a Sinatra public_folder -W [WEBSERVER_FOLDER], Sets the sinatra full path from cloner. --webserver --payload [PAYLOAD] Sets a payload download to serve on /download --customapp [CUSTOM_SINATRA] Sets a custom Sinatra::Base WebApp. Important, WebApp name should be camelized of filename

Common options: -h, --help Show this message --list-options Show list of available options

Web 服务器支持跨多个 IP、主机名和端口的 SSL 密钥和虚拟主机。

#### 服务器
为了发送电子邮件活动,我们需要设置电子邮件服务器,该命令允许 Cartero 创建、存储和列出服务器。所有数据都存储在 ~/.cartero 配置目录中。```shell
./cartero Servers
Usage: Cartero Servers [options]
    -a, --add [NAME]                 Add Server
    -e, --edit [NAME]                Edit Server
    -d, --delete [NAME]              Edit Server
    -l, --list                       List servers

Configuration options:
    -T, --type [TYPE]                Set the type
    -U, --url [DOMAIN]               Set the Mail or WebMail url/address
    -M, --method [METHOD]            Sets the WebMail Request Method to use [GET|POST]
        --api-access [API_KEY]       Sets the Linkedin API Access Key
        --api-secret [API_SECRET]    Sets the Linkedin API Secret Key
        --oauth-token [OAUTH_TOKEN]  Sets the Linkedin OAuth Token Key
        --oauth-secret [OAUTH_SECRET]
                                     Sets the Linkedin OAuth Secret Key

Common options:
    -h, --help                       Show this message
        --list-options               Show list of available options

模板

与 Servers 类似,电子邮件活动也需要一个预定义的模板来向受害者发送内容。该模块允许攻击者跟踪、创建、列出和编辑其活动中使用的模板。

注意:此处设置模板并非必需,Mailer 接受来自 CLI 的电子邮件模板直接路径。```shell ❯❯❯ ./cartero Templates Usage: Cartero Templates [options] -a, --add [NAME] Add Template -e, --edit [NAME] Edit Template -d, --delete [NAME] Edit Template -l, --list List Templates -h, --help Show this message

#### Mailer
Mailer 是 Cartero Framework 中的主要命令和组件——它允许 Cartero 向一个或多个电子邮件地址发送自定义模板电子邮件。

每封电子邮件都可以使用强大的 erb 模板引擎进行自定义,允许用户在模板中创建复杂的程序化规则,从而发送大量极具针对性的电子邮件。

有关如何构建自定义模板的更多信息,请参阅我们的 Examples。```shell
❯❯❯ ./cartero Mailer
Usage: Cartero Mailer [options]
    -D, --data [DATA_FILE]           File containing template data sets
    -S, --server [SERVER_NAME]       Sets Email server to use
    -s, --subject [EMAIL_SUBJECT]    Sets Email subject
    -f, --from [EMAIL_FROM]          Sets Email from
    -r, --reply-to [EMAIL_REPLY_TO]  Sets Email from
    -b, --body [FILE_PATH]           Sets Email Text Body
    -B, --htmlbody [FILE_PATH]       Sets Email HTML Body
    -c, --charset [CHARSET]          Sets Email charset
    -C [CONTENT_TYPE],               Sets Email content type
        --content-type
    -a [FILE_1,FILE_2,..,FILE_N],    Sets Email Attachments
        --attachment
    -p [PORT_1,PORT_2,..,PORT_N],    Sets Email Payload Ports to scan
        --ports
下载工具