fixing aws
This commit is contained in:
+18
@@ -262,11 +262,29 @@
|
|||||||
ansible_ssh_private_key_file: "~/.ssh/c2deploy_{{ deployment_id }}.pem"
|
ansible_ssh_private_key_file: "~/.ssh/c2deploy_{{ deployment_id }}.pem"
|
||||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o IdentitiesOnly=yes"
|
ansible_ssh_common_args: "-o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o IdentitiesOnly=yes"
|
||||||
ansible_python_interpreter: "/usr/bin/python3"
|
ansible_python_interpreter: "/usr/bin/python3"
|
||||||
|
# Add these lines to pass all required variables:
|
||||||
|
smtp_auth_user: "{{ smtp_auth_user }}"
|
||||||
|
smtp_auth_pass: "{{ smtp_auth_pass }}"
|
||||||
|
gophish_admin_port: "{{ gophish_admin_port }}"
|
||||||
|
domain: "{{ domain }}"
|
||||||
|
redirector_subdomain: "{{ redirector_subdomain }}"
|
||||||
|
letsencrypt_email: "{{ letsencrypt_email }}"
|
||||||
|
havoc_teamserver_port: "{{ havoc_teamserver_port | default(40056) }}"
|
||||||
|
havoc_http_port: "{{ havoc_http_port | default(8080) }}"
|
||||||
|
havoc_https_port: "{{ havoc_https_port | default(443) }}"
|
||||||
|
zero_logs: "{{ zero_logs | default(true) }}"
|
||||||
|
secure_memory: "{{ secure_memory | default(true) }}"
|
||||||
|
disable_history: "{{ disable_history | default(true) }}"
|
||||||
|
setup_integrated_tracker: "{{ setup_integrated_tracker | default(false) }}"
|
||||||
|
tracker_domain: "{{ tracker_domain | default('track.' + domain) | default('') }}"
|
||||||
|
|
||||||
# Configure C2 server with a proper structure
|
# Configure C2 server with a proper structure
|
||||||
- name: Configure C2 server
|
- name: Configure C2 server
|
||||||
hosts: c2servers
|
hosts: c2servers
|
||||||
become: yes
|
become: yes
|
||||||
|
gather_facts: true
|
||||||
|
vars_files:
|
||||||
|
- vars.yaml # Add this line to load the variables
|
||||||
vars:
|
vars:
|
||||||
redirector_ip: "{{ hostvars['localhost']['redirector_ip'] | default('127.0.0.1') }}"
|
redirector_ip: "{{ hostvars['localhost']['redirector_ip'] | default('127.0.0.1') }}"
|
||||||
c2_subdomain: "{{ c2_subdomain | default('mail') }}"
|
c2_subdomain: "{{ c2_subdomain | default('mail') }}"
|
||||||
|
|||||||
@@ -374,8 +374,9 @@ def gather_common_parameters():
|
|||||||
config['secure_memory'] = input("Enable secure memory settings? (y/n) [default: y]: ").lower() != 'n'
|
config['secure_memory'] = input("Enable secure memory settings? (y/n) [default: y]: ").lower() != 'n'
|
||||||
config['zero_logs'] = input("Enable zero-logs configuration? (y/n) [default: y]: ").lower() != 'n'
|
config['zero_logs'] = input("Enable zero-logs configuration? (y/n) [default: y]: ").lower() != 'n'
|
||||||
|
|
||||||
# Add SSH option that was missing
|
# Fix: SSH option that defaults to 'y' properly
|
||||||
config['ssh_after_deploy'] = input("\nSSH into instance after deployment? (y/n) [default: y]: ").lower() == 'y'
|
ssh_response = input("\nSSH into instance after deployment? (y/n) [default: y]: ").lower()
|
||||||
|
config['ssh_after_deploy'] = ssh_response != 'n' # Default to True unless they type 'n'
|
||||||
|
|
||||||
return config
|
return config
|
||||||
|
|
||||||
@@ -511,20 +512,26 @@ def execute_deployment(config):
|
|||||||
if success:
|
if success:
|
||||||
print(f"\n{COLORS['GREEN']}Deployment completed successfully!{COLORS['RESET']}")
|
print(f"\n{COLORS['GREEN']}Deployment completed successfully!{COLORS['RESET']}")
|
||||||
|
|
||||||
|
# ALWAYS generate deployment information for successful deployments
|
||||||
|
deployment_info_log = generate_deployment_info(config, success=True)
|
||||||
|
print(f"\n{COLORS['CYAN']}Deployment information saved to: {deployment_info_log}{COLORS['RESET']}")
|
||||||
|
|
||||||
# Explicitly handle SSH after deployment if requested
|
# Explicitly handle SSH after deployment if requested
|
||||||
if config.get('ssh_after_deploy', False):
|
if config.get('ssh_after_deploy', True): # Default to True if not specified
|
||||||
print(f"\n{COLORS['BLUE']}Connecting to instance via SSH...{COLORS['RESET']}")
|
print(f"\n{COLORS['BLUE']}Connecting to instance via SSH...{COLORS['RESET']}")
|
||||||
ssh_to_instance(config)
|
ssh_to_instance(config)
|
||||||
else:
|
else:
|
||||||
print(f"\n{COLORS['RED']}Deployment failed.{COLORS['RESET']}")
|
print(f"\n{COLORS['RED']}Deployment failed.{COLORS['RESET']}")
|
||||||
|
deployment_info_log = generate_deployment_info(config, success=False)
|
||||||
|
print(f"\n{COLORS['YELLOW']}Deployment information saved to: {deployment_info_log}{COLORS['RESET']}")
|
||||||
|
|
||||||
input("\nPress Enter to return to menu...")
|
input("\nPress Enter to return to menu...")
|
||||||
# Clean up shared infrastructure state file if present
|
# Clean up shared infrastructure state file if present
|
||||||
try:
|
try:
|
||||||
state_file = os.path.join(os.getcwd(), 'infrastructure_state.json')
|
state_file = os.path.join(os.getcwd(), f'infrastructure_state_{config["deployment_id"]}.json')
|
||||||
if os.path.exists(state_file):
|
if os.path.exists(state_file):
|
||||||
os.remove(state_file)
|
os.remove(state_file)
|
||||||
logging.info('Removed shared infrastructure state file')
|
logging.info(f'Removed shared infrastructure state file: {state_file}')
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
logging.warning(f'Failed to remove infra state file: {e}')
|
logging.warning(f'Failed to remove infra state file: {e}')
|
||||||
|
|
||||||
@@ -1503,13 +1510,17 @@ def ssh_to_instance(config):
|
|||||||
logging.info("Connecting to instance via SSH...")
|
logging.info("Connecting to instance via SSH...")
|
||||||
|
|
||||||
# Determine which IP to use based on deployment type
|
# Determine which IP to use based on deployment type
|
||||||
if config.get('deploy_tracker'):
|
if config.get('redirector_only', False):
|
||||||
ip_key = 'tracker_ip'
|
|
||||||
instance_type = 'tracker'
|
|
||||||
elif config.get('redirector_only'):
|
|
||||||
ip_key = 'redirector_ip'
|
ip_key = 'redirector_ip'
|
||||||
instance_type = 'redirector'
|
instance_type = 'redirector'
|
||||||
|
elif config.get('c2_only', False):
|
||||||
|
ip_key = 'c2_ip'
|
||||||
|
instance_type = 'C2 server'
|
||||||
|
elif config.get('deploy_tracker', False) and not config.get('integrated_tracker', False):
|
||||||
|
ip_key = 'tracker_ip'
|
||||||
|
instance_type = 'tracker'
|
||||||
else:
|
else:
|
||||||
|
# Default to C2 server for full deployments
|
||||||
ip_key = 'c2_ip'
|
ip_key = 'c2_ip'
|
||||||
instance_type = 'C2 server'
|
instance_type = 'C2 server'
|
||||||
|
|
||||||
@@ -1526,18 +1537,35 @@ def ssh_to_instance(config):
|
|||||||
|
|
||||||
if not ip:
|
if not ip:
|
||||||
logging.error(f"No IP address found for {instance_type}")
|
logging.error(f"No IP address found for {instance_type}")
|
||||||
|
print(f"{COLORS['RED']}No IP address found for {instance_type}. Cannot SSH.{COLORS['RESET']}")
|
||||||
return False
|
return False
|
||||||
|
|
||||||
# Get SSH key and user
|
# Get SSH key and user
|
||||||
ssh_key = config.get('ssh_key')
|
ssh_key = config.get('ssh_key')
|
||||||
if not ssh_key:
|
if not ssh_key:
|
||||||
logging.error("No SSH key specified")
|
logging.error("No SSH key specified")
|
||||||
|
print(f"{COLORS['RED']}No SSH key specified. Cannot SSH.{COLORS['RESET']}")
|
||||||
return False
|
return False
|
||||||
|
|
||||||
ssh_user = config.get('ssh_user')
|
# Get SSH user based on provider and instance type
|
||||||
if not ssh_user:
|
if config.get('ssh_user'):
|
||||||
logging.error("No SSH user specified")
|
ssh_user = config.get('ssh_user')
|
||||||
return False
|
elif config['provider'] == 'aws':
|
||||||
|
ssh_user = config.get('ami_ssh_user', 'kali')
|
||||||
|
elif config['provider'] == 'linode':
|
||||||
|
ssh_user = 'root'
|
||||||
|
else:
|
||||||
|
ssh_user = DEFAULT_SSH_USER.get(config['provider'], 'root')
|
||||||
|
|
||||||
|
# Print SSH connection information
|
||||||
|
print(f"\n{COLORS['CYAN']}SSH Connection Information:{COLORS['RESET']}")
|
||||||
|
print(f" Host: {ip}")
|
||||||
|
print(f" User: {ssh_user}")
|
||||||
|
print(f" Key: {ssh_key}")
|
||||||
|
print(f"\n{COLORS['YELLOW']}Manual SSH command:{COLORS['RESET']}")
|
||||||
|
print(f" ssh -i {ssh_key} {ssh_user}@{ip}")
|
||||||
|
|
||||||
|
print(f"\n{COLORS['BLUE']}Attempting to connect now...{COLORS['RESET']}")
|
||||||
|
|
||||||
# Build SSH command
|
# Build SSH command
|
||||||
ssh_cmd = [
|
ssh_cmd = [
|
||||||
@@ -1547,25 +1575,24 @@ def ssh_to_instance(config):
|
|||||||
"-o", "UserKnownHostsFile=/dev/null",
|
"-o", "UserKnownHostsFile=/dev/null",
|
||||||
"-o", "IdentitiesOnly=yes",
|
"-o", "IdentitiesOnly=yes",
|
||||||
"-i", ssh_key,
|
"-i", ssh_key,
|
||||||
f"{ssh_user}@{ip}",
|
f"{ssh_user}@{ip}"
|
||||||
"tmux new"
|
|
||||||
]
|
]
|
||||||
|
|
||||||
# Add port if specified
|
# Add port if specified
|
||||||
if config.get('ssh_port'):
|
if config.get('ssh_port'):
|
||||||
ssh_cmd.extend(["-p", str(config['ssh_port'])])
|
ssh_cmd.extend(["-p", str(config['ssh_port'])])
|
||||||
|
|
||||||
logging.info(f"SSH command: {' '.join(ssh_cmd)}")
|
|
||||||
|
|
||||||
# Execute SSH command
|
# Execute SSH command
|
||||||
try:
|
try:
|
||||||
subprocess.run(ssh_cmd)
|
subprocess.run(ssh_cmd)
|
||||||
return True
|
return True
|
||||||
except subprocess.CalledProcessError as e:
|
except subprocess.CalledProcessError as e:
|
||||||
logging.error(f"SSH connection failed: {e}")
|
logging.error(f"SSH connection failed: {e}")
|
||||||
|
print(f"{COLORS['RED']}SSH connection failed: {e}{COLORS['RESET']}")
|
||||||
return False
|
return False
|
||||||
except KeyboardInterrupt:
|
except KeyboardInterrupt:
|
||||||
logging.info("SSH connection interrupted by user")
|
logging.info("SSH connection interrupted by user")
|
||||||
|
print(f"\n{COLORS['YELLOW']}SSH connection interrupted by user{COLORS['RESET']}")
|
||||||
return True
|
return True
|
||||||
|
|
||||||
def cleanup_resources(config, interactive=True):
|
def cleanup_resources(config, interactive=True):
|
||||||
@@ -1904,7 +1931,16 @@ def generate_deployment_info(config, success=True):
|
|||||||
info.append("SERVER INFORMATION")
|
info.append("SERVER INFORMATION")
|
||||||
info.append("-----------------")
|
info.append("-----------------")
|
||||||
ssh_key = config.get('ssh_key', 'N/A')
|
ssh_key = config.get('ssh_key', 'N/A')
|
||||||
ssh_user = config.get('ssh_user', 'root')
|
|
||||||
|
# Determine SSH user based on provider
|
||||||
|
if config.get('ssh_user'):
|
||||||
|
ssh_user = config.get('ssh_user')
|
||||||
|
elif config.get('provider') == 'aws':
|
||||||
|
ssh_user = config.get('ami_ssh_user', 'kali')
|
||||||
|
elif config.get('provider') == 'linode':
|
||||||
|
ssh_user = 'root'
|
||||||
|
else:
|
||||||
|
ssh_user = DEFAULT_SSH_USER.get(config.get('provider', 'aws'), 'root')
|
||||||
|
|
||||||
if not config.get('c2_only'):
|
if not config.get('c2_only'):
|
||||||
redirector_ip = config.get('redirector_ip', 'N/A')
|
redirector_ip = config.get('redirector_ip', 'N/A')
|
||||||
@@ -2033,9 +2069,9 @@ def generate_deployment_info(config, success=True):
|
|||||||
info.append("---------------")
|
info.append("---------------")
|
||||||
info.append(f"python3 deploy.py --provider {config.get('provider', 'PROVIDER')} --c2-name {config.get('c2_name', 'C2_NAME')} --redirector-name {config.get('redirector_name', 'REDIRECTOR_NAME')} --teardown")
|
info.append(f"python3 deploy.py --provider {config.get('provider', 'PROVIDER')} --c2-name {config.get('c2_name', 'C2_NAME')} --redirector-name {config.get('redirector_name', 'REDIRECTOR_NAME')} --teardown")
|
||||||
if config.get('provider') == 'linode':
|
if config.get('provider') == 'linode':
|
||||||
info.append(f"Additional parameters: --linode-token YOUR_TOKEN --c2-name {config.get('c2_name', 'C2_NAME')} --redirector-name {config.get('redirector_name', 'REDIRECTOR_NAME')}")
|
info.append(f"Additional parameters: --linode-token YOUR_TOKEN")
|
||||||
elif config.get('provider') == 'aws':
|
elif config.get('provider') == 'aws':
|
||||||
info.append(f"Additional parameters: --aws-key YOUR_KEY --aws-secret YOUR_SECRET --c2-name {config.get('c2_name', 'C2_NAME')} --redirector-name {config.get('redirector_name', 'REDIRECTOR_NAME')}")
|
info.append(f"Additional parameters: --aws-key YOUR_KEY --aws-secret YOUR_SECRET")
|
||||||
|
|
||||||
# Write to file
|
# Write to file
|
||||||
with open(log_file, 'w') as f:
|
with open(log_file, 'w') as f:
|
||||||
|
|||||||
@@ -161,7 +161,7 @@
|
|||||||
group: "{{ ansible_user }}"
|
group: "{{ ansible_user }}"
|
||||||
mode: '0644'
|
mode: '0644'
|
||||||
vars:
|
vars:
|
||||||
gophish_admin_port: 8088
|
gophish_admin_port: "{{ gophish_admin_port }}"
|
||||||
domain: "{{ domain }}"
|
domain: "{{ domain }}"
|
||||||
|
|
||||||
- name: Set proper ownership for Tools directory
|
- name: Set proper ownership for Tools directory
|
||||||
|
|||||||
Reference in New Issue
Block a user