outis 是一款自定义远程管理工具(RAT)或类似的东西。可以把它想象成 Meterpreter 或 Empire-Agent。然而,这款工具的重点既不是利用工具包(它不包含任何漏洞利用程序),也不是对目标的持久管理。其核心在于通过各种方法和平台在服务器与目标系统之间进行通信,以及传输文件、共享套接字、生成 Shell 等。
荷马史诗《奥德赛》中的独眼巨人波吕斐摩斯在名字解析方面遇到了一些问题。当他询问奥德修斯的名字时,这位黑客告诉他,自己的名字是“Outis”,在古希腊语中意为“没有人”。因此,当波吕斐摩斯后来大喊“没有人”要杀死他时,奇怪的是没有任何救援到来。
感谢 Marcel 让我想起这个绝妙的经典故事片段。
Archlinux 用户可以安装以下软件包:
在其他发行版中,名称可能有所不同,例如有一个名为 crypto 的模块和一个名为 pycrypto 的模块。我们需要的是后者。
此外,旧版本可能会引发问题:
$ python3 -c 'import OpenSSL; print(OpenSSL.version.__version__)'
你可以相当轻松地设置一个 Python 虚拟环境:
$ virtualenv outis-venv
$ source ./outis-venv/bin/activate
(outis-venv) $ pip install progressbar2 dnspython pycrypto pyopenssl
这将生成以下包列表,它们在我这里可以正常工作:
$ pip freeze
appdirs==1.4.3
asn1crypto==0.22.0
cffi==1.10.0
cryptography==1.8.1
dnspython==1.15.0
idna==2.5
packaging==16.8
progressbar2==3.18.1
pycparser==2.17
pycrypto==2.6.1
pyOpenSSL==16.2.0
pyparsing==2.2.0
python-utils==2.1.0
six==1.10.0
使用递归标志克隆此仓库,以同时克隆其第三方工具文件夹中的子模块:
git clone --recursive ...
处理器运行在 Python 3 上。安装其依赖项并运行它。它将为你生成阶段程序、代理程序以及所有其他内容。
如需绑定低端口而无需 root 权限,可考虑使用能力包装器。
使用 PowerShell 平台并通过阶段化 DNS 传输下载文件的过程如下所示:
$ outis
outis> set TRANSPORT DNS
outis> set ZONE zfs.sy.gs
outis> set AGENTDEBUG TRUE
outis> info
[+] Options for the Handler:
Name Value Required Description
----------------- ---------- -------- -----------------------------------------------------------------
TRANSPORT DNS True Communication way between agent and handler (Options: REVERSETCP,
DNS)
CHANNELENCRYPTION TLS True Encryption Protocol in the transport (Options: NONE, TLS)
PLATFORM POWERSHELL True Platform of agent code (Options: POWERSHELL)
PROGRESSBAR TRUE True Display a progressbar for uploading / downloading? (only if not
debugging the relevant module) (Options: TRUE, FALSE)
[+] Options for the TRANSPORT module DNS:
Name Value Required Description
--------- ----------- -------- ------------------------------------------------------------------------
ZONE zfs.sy.gs True DNS Zone for handling requests
LHOST 0.0.0.0 True Interface IP to listen on
LPORT 53 True UDP-Port to listen on for DNS server
DNSTYPE TXT True DNS type to use for the connection (stager only, the agent will
enumerate all supported types on its own) (Options: TXT, A)
DNSSERVER False IP address of DNS server to connect for all queries