Showing posts with label local. Show all posts
Showing posts with label local. Show all posts
Wednesday, April 26, 2017
Zarp Local Network Attack Framework
Zarp Local Network Attack Framework

Zarp is a network attack tool centered around the exploitation of local networks. This does not include system exploitation, but rather abusing networking protocols and stacks to take over, infiltrate, and knock out. Sessions can be managed to quickly poison and sniff multiple systems at once, dumping sensitive information automatically or to the attacker directly. Various sniffers are included to automatically parse usernames and passwords from various protocols, as well as view HTTP traffic and more. DoS attacks are included to knock out various systems and applications. These tools open up the possibility for very complex attack scenarios on live networks quickly, cleanly, and quietly.
The long-term goal of zarp is to become the master command center of a network; to provide a modular, well-defined framework that provides a powerful overview and in-depth analysis of an entire network. This will come to light with the future inclusion of a web application front-end, which acts as the television screen, whereas the CLI interface will be the remote. This will provide network topology reports, host relationships, and more. zarp aims to be your window into the potential exploitability of a network and its hosts, not an exploitation platform itself; it is the manipulation of relationships and trust felt within local intranets. Look for zeb, the web-app frontend to zarp, sometime in the future.
Tool Overview
Broad categories are (see wiki for more information on these):
- Poisoners
- Denial of Service
- Sniffers
- Scanners
- Services
- Parameter
- Attacks
List of modules accessible from the command line:
bryan@debdev:~/tools/zarp$ sudo ./zarp.py --help
[!] Loaded 34 modules.
____ __ ____ ____
(__ ) / _ ( _ ( _
/ _/ / ) / ) __/
(____)_/_/(___)(__) [Version: 0.1.5]
usage: zarp.py [-h] [-q FILTER] [--update] [--wap] [--ftp] [--http] [--smb]
[--ssh] [--telnet] [-w] [-s] [--service-scan]
optional arguments:
-h, --help show this help message and exit
-q FILTER Generic network sniff
--update Update Zarp
Services:
--wap Wireless access point
--ftp FTP server
--http HTTP Server
--smb SMB Service
--ssh SSH Server
--telnet Telnet server
Scanners:
-w Wireless AP Scan
-s Network scanner
--service-scan Service scanner
bryan@debdev:~/tools/zarp$ Download Zarp
Go to link download
Friday, April 14, 2017
LinEnum Local Linux Enumeration Privilege Escalation Checks
LinEnum Local Linux Enumeration Privilege Escalation Checks

LinEnum will automate many of the checks that Ive documented in the Local Linux Enumeration & Privilege Escalation Cheatsheet. Its a very basic shell script that performs over 65 checks, getting anything from kernel information to locating possible escalation points such as potentially useful SUID/GUID files and Sudo/rhost mis-configurations and more.
An additional extra feature is that the script will also use a provided keyword to search through *.conf and *.log files. Any matches will be displayed along with the full file path and line number on which the keyword was identified.
After the scan has completed (please be aware that it make take some time) youll be presented with (possibly quite extensive) output, to which any key findings will be highlighted in yellow with everything else documented under the relevant headings.
Below is a high-level summary of the checks/tasks performed by LinEnum:
- Kernel and distribution release details
- System Information:
- Hostname
- Networking details:
- Current IP
- Default route details
- DNS server information
- User Information:
- Current user details
- Last logged on users
- Llist all users including uid/gid information
- List root accounts
- Extract full details for default uids such as 0, 1000, 1001 etc
- Attempt to read restricted files i.e. /etc/shadow
- List current users history files (i.e .bash_history, .nano_history etc.)
- Privileged access:
- Determine if /etc/sudoers is accessible
- Determine if the current user has Sudo access without a password
- Are known good breakout binaries available via Sudo (i.e. nmap, vim etc.)
- Is roots home directory accessible
- List permissions for /home/
- Environmental:
- Display current $PATH
- Jobs/Tasks:
- List all cron jobs
- Locate all world-writable cron jobs
- Locate cron jobs owned by other users of the system
- Services:
- List network connections (TCP & UDP)
- List running processes
- Lookup and list process binaries and associated permissions
- List inetd.conf/xined.conf contents and associated binary file permissions
- List init.d binary permissions
- Version Information (of the following):
- Sudo
- MYSQL
- Postgres
- Apache
- Default/Weak Credentials:
- Checks for default/weak Postgres accounts
- Checks for default root/root access to local MYSQL services
- Searches:
- Locate all SUID/GUID files
- Locate all world-writable SUID/GUID files
- Locate all SUID/GUID files owned by root
- Locate interesting SUID/GUID files (i.e. nmap, vim etc)
- List all world-writable files
- Find/list all accessible *.plan files and display contents
- Find/list all accesible *.rhosts files and display contents
- Show NFS server details
- Locate *.conf and *.log files containing keyword supplied at script runtime
- List all *.conf files located in /etc
- Locate mail
Some of the above commands are privileged/and or the related task may be nonexistent and will therefore most likely fail. The user shouldnt be alerted to failed results, just the output from successful commands should be displayed.
Download LinEnum
Go to link download
Labels:
checks,
enumeration,
escalation,
linenum,
linux,
local,
privilege
Saturday, March 4, 2017
Isowall A mini firewall that completely isolates a target device from the local network
Isowall A mini firewall that completely isolates a target device from the local network

This is a mini-firewall that completely isolates a target device from the local network. This is for allowing infected machines Internet access, but without endangering the local network.
Building
This project depends upon
libpcap, and of course a C compiler.On Debian, the following should work:
# apt-get install git gcc make libpcap-dev
# git clone https://github.com/robertdavidgraham/isowall
# cd isowall
# makeThis will put the binary
isowall in the local isowall/bin directory.This should also work on Windows, Mac OS X, xBSD, and pretty much any operating system that supports
libpcap.Running
First, setup a machine with three network interfaces.
The first network interface (like
eth0) will be configured as normal, with a TCP/IP stack, so that you can SSH to it.The other two network interfaces should have no TCP/IP stack, no IP address, no anything. This is the most important configuration step, and the most common thing youll get wrong. For example, the DHCP software on the box may be configured to automatically send out DHCP requests on these additional interfaces. You have to go fix that so nothing is bound to these interfaces.
To run, simply type:
# ./bin/isowall --internal eth1 --external eth2 -c xxxx.confwhere
xxxx.conf contains your configuration, which is described below.Configuration
The following shows a typical configuration file.
internal = eth1
internal.target.ip = 10.0.0.129
internal.target.mac = 02:60:8c:37:87:f3
external = eth2
external.router.ip = 10.0.0.1
external.router.mac = 66:55:44:33:22:11
allow = 0.0.0.0/0
block = 192.168.0.0/16
block = 10.0.0.0/8
block = 224.0.0.0-255.255.255.255The target device we are isolating has the indicated IP and MAC address.
Only IPv4 and ARP packets are passed.
Outbound packets must have the following conditions:
- source MAC address equal to
internal.target.mac - destination MAC address equal to
external.router.mac - EtherType of 0x800 or 0x806
- source IPv4 address equal to
internal.target.ip - destination IPv4 address within an
allowrange, but not in ablockrange - if an ARP packet, then the destination IPv4 address must equal that
external.router.ip - if an ARP packet, must be a "request"
Inbound packets must have the following conditions:
- destination MAC address equal to
internal.target.mac - source MAC address equal to
external.router.mac - EtherType of 0x800 or 0x806
- destination IPv4 address equal to
internal.target.ip - source IPv4 address within an
allowrange, but not in ablockrange - if an ARP packet, then the source IPv4 address must equal that
external.router.ip - if an ARP packet, then must be a "reply"
Download Isowall
Go to link download
Subscribe to:
Posts (Atom)