sigh
This commit is contained in:
@@ -0,0 +1,634 @@
|
||||
---
|
||||
# FlokiNET full deployment playbook (C2 + Redirector)
|
||||
|
||||
- name: Prepare FlokiNET infrastructure deployment
|
||||
hosts: localhost
|
||||
gather_facts: false
|
||||
connection: local
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
# Generate random shell handler port if not provided
|
||||
shell_handler_port: "{{ shell_handler_port | default(4000 + 60000 | random) }}"
|
||||
redirector_subdomain: "{{ redirector_subdomain | default('cdn') }}"
|
||||
c2_subdomain: "{{ c2_subdomain | default('mail') }}"
|
||||
|
||||
tasks:
|
||||
- name: Validate required FlokiNET configuration
|
||||
assert:
|
||||
that:
|
||||
- redirector_ip is defined and redirector_ip != ""
|
||||
- c2_ip is defined and c2_ip != ""
|
||||
fail_msg: "FlokiNET requires both redirector_ip and c2_ip. Set these values in vars.yaml or via command line arguments."
|
||||
|
||||
- name: Add redirector to inventory
|
||||
add_host:
|
||||
name: "redirector"
|
||||
groups: "redirectors"
|
||||
ansible_host: "{{ redirector_ip }}"
|
||||
ansible_user: "{{ ssh_user | default('root') }}"
|
||||
ansible_ssh_private_key_file: "{{ ssh_key_path | replace('.pub', '') }}"
|
||||
ansible_ssh_port: "{{ ssh_port | default(22) }}"
|
||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null"
|
||||
|
||||
- name: Add C2 server to inventory
|
||||
add_host:
|
||||
name: "c2"
|
||||
groups: "c2servers"
|
||||
ansible_host: "{{ c2_ip }}"
|
||||
ansible_user: "{{ ssh_user | default('root') }}"
|
||||
ansible_ssh_private_key_file: "{{ ssh_key_path | replace('.pub', '') }}"
|
||||
ansible_ssh_port: "{{ ssh_port | default(22) }}"
|
||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null"
|
||||
|
||||
- name: Verify SSH connection to redirector
|
||||
wait_for:
|
||||
host: "{{ redirector_ip }}"
|
||||
port: "{{ ssh_port | default(22) }}"
|
||||
delay: 10
|
||||
timeout: 60
|
||||
state: started
|
||||
ignore_errors: true
|
||||
|
||||
- name: Verify SSH connection to C2 server
|
||||
wait_for:
|
||||
host: "{{ c2_ip }}"
|
||||
port: "{{ ssh_port | default(22) }}"
|
||||
delay: 10
|
||||
timeout: 60
|
||||
state: started
|
||||
ignore_errors: true
|
||||
|
||||
- name: Configure FlokiNET redirector
|
||||
hosts: redirectors
|
||||
become: true
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Wait for apt to be available
|
||||
apt:
|
||||
update_cache: yes
|
||||
register: apt_result
|
||||
until: apt_result is success
|
||||
retries: 5
|
||||
delay: 10
|
||||
|
||||
- name: Set hostname
|
||||
hostname:
|
||||
name: "redirector"
|
||||
|
||||
- name: Update apt cache
|
||||
apt:
|
||||
update_cache: yes
|
||||
|
||||
- name: Upgrade all packages
|
||||
apt:
|
||||
upgrade: dist
|
||||
|
||||
- name: Install base utilities and tools via apt
|
||||
apt:
|
||||
name:
|
||||
- git
|
||||
- wget
|
||||
- curl
|
||||
- unzip
|
||||
- python3-pip
|
||||
- python3-virtualenv
|
||||
- tmux
|
||||
- pipx
|
||||
- nmap
|
||||
- tcpdump
|
||||
- nginx
|
||||
- certbot
|
||||
- python3-certbot-nginx
|
||||
- socat
|
||||
- netcat-openbsd
|
||||
- secure-delete
|
||||
state: present
|
||||
|
||||
- name: Set a custom MOTD
|
||||
template:
|
||||
src: motd-flokinet.j2
|
||||
dest: /etc/motd
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
vars:
|
||||
letsencrypt_email: "{{ letsencrypt_email }}"
|
||||
domain: "{{ domain }}"
|
||||
redirector_subdomain: "{{ redirector_subdomain }}"
|
||||
|
||||
- name: Create directories for operational scripts
|
||||
file:
|
||||
path: "{{ item }}"
|
||||
state: directory
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
with_items:
|
||||
- /opt/c2
|
||||
- /opt/shell-handler
|
||||
|
||||
- name: Copy clean-logs.sh script
|
||||
copy:
|
||||
src: "../files/clean-logs.sh"
|
||||
dest: /opt/c2/clean-logs.sh
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Copy secure-exit.sh script
|
||||
copy:
|
||||
src: "../files/secure-exit.sh"
|
||||
dest: /opt/c2/secure-exit.sh
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Copy shell handler script
|
||||
copy:
|
||||
src: "../files/persistent-listener.sh"
|
||||
dest: /opt/shell-handler/persistent-listener.sh
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Configure shell handler script with C2 IP
|
||||
replace:
|
||||
path: /opt/shell-handler/persistent-listener.sh
|
||||
regexp: 'C2_HOST="127.0.0.1"'
|
||||
replace: 'C2_HOST="{{ c2_ip }}"'
|
||||
|
||||
- name: Configure shell handler script with listening port
|
||||
replace:
|
||||
path: /opt/shell-handler/persistent-listener.sh
|
||||
regexp: 'LISTEN_PORT=4444'
|
||||
replace: 'LISTEN_PORT={{ shell_handler_port }}'
|
||||
|
||||
- name: Create shell handler service
|
||||
template:
|
||||
src: shell-handler.service.j2
|
||||
dest: /etc/systemd/system/shell-handler.service
|
||||
mode: '0644'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Configure NGINX for zero-logging if enabled
|
||||
template:
|
||||
src: nginx.conf.j2
|
||||
dest: /etc/nginx/nginx.conf
|
||||
mode: '0644'
|
||||
owner: root
|
||||
group: root
|
||||
when: zero_logs | bool
|
||||
|
||||
- name: Configure NGINX for C2 redirection
|
||||
template:
|
||||
src: redirector-site.conf.j2
|
||||
dest: /etc/nginx/sites-available/default
|
||||
mode: '0644'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Create legitimate-looking index.html
|
||||
template:
|
||||
src: redirector-index.html.j2
|
||||
dest: /var/www/html/index.html
|
||||
mode: '0644'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
|
||||
- name: Start and enable shell handler service
|
||||
systemd:
|
||||
name: shell-handler
|
||||
state: started
|
||||
enabled: yes
|
||||
daemon_reload: yes
|
||||
|
||||
- name: Set up cron job for log cleaning if zero-logs enabled
|
||||
cron:
|
||||
name: "Clean logs"
|
||||
minute: "0"
|
||||
hour: "*/6"
|
||||
job: "/opt/c2/clean-logs.sh > /dev/null 2>&1"
|
||||
when: zero_logs | bool
|
||||
|
||||
- name: Install Let's Encrypt certificate if domain specified
|
||||
shell: |
|
||||
certbot --nginx -d {{ redirector_subdomain }}.{{ domain }} --non-interactive --agree-tos -m {{ letsencrypt_email }}
|
||||
args:
|
||||
creates: /etc/letsencrypt/live/{{ redirector_subdomain }}.{{ domain }}/fullchain.pem
|
||||
when: domain != "example.com"
|
||||
|
||||
- name: Restart NGINX
|
||||
systemd:
|
||||
name: nginx
|
||||
state: restarted
|
||||
|
||||
- name: FlokiNET-specific security configurations
|
||||
include_tasks: flokinet-security.yml
|
||||
when: enable_hardened_security | default(true)
|
||||
|
||||
- name: Configure FlokiNET C2 server
|
||||
hosts: c2servers
|
||||
become: true
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Wait for apt to be available
|
||||
apt:
|
||||
update_cache: yes
|
||||
register: apt_result
|
||||
until: apt_result is success
|
||||
retries: 5
|
||||
delay: 10
|
||||
|
||||
- name: Set hostname
|
||||
hostname:
|
||||
name: "c2"
|
||||
|
||||
- name: Update apt cache
|
||||
apt:
|
||||
update_cache: yes
|
||||
|
||||
- name: Upgrade all packages
|
||||
apt:
|
||||
upgrade: dist
|
||||
|
||||
- name: Set a custom MOTD
|
||||
template:
|
||||
src: motd-flokinet.j2
|
||||
dest: /etc/motd
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
vars:
|
||||
letsencrypt_email: "{{ letsencrypt_email }}"
|
||||
domain: "{{ domain }}"
|
||||
c2_subdomain: "{{ c2_subdomain }}"
|
||||
|
||||
- name: Install base utilities and tools via apt
|
||||
apt:
|
||||
name:
|
||||
- git
|
||||
- wget
|
||||
- curl
|
||||
- unzip
|
||||
- python3-pip
|
||||
- python3-virtualenv
|
||||
- tmux
|
||||
- pipx
|
||||
- nmap
|
||||
- tcpdump
|
||||
- hydra
|
||||
- john
|
||||
- hashcat
|
||||
- sqlmap
|
||||
- gobuster
|
||||
- dirb
|
||||
- enum4linux
|
||||
- dnsenum
|
||||
- seclists
|
||||
- responder
|
||||
- golang
|
||||
- proxychains
|
||||
- tor
|
||||
- crackmapexec
|
||||
- jq
|
||||
- unzip
|
||||
- postfix
|
||||
- certbot
|
||||
- opendkim
|
||||
- opendkim-tools
|
||||
- dovecot-core
|
||||
- dovecot-imapd
|
||||
- dovecot-pop3d
|
||||
- dovecot-sieve
|
||||
- dovecot-managesieved
|
||||
- yq
|
||||
state: present
|
||||
|
||||
- name: Create Tools directory
|
||||
file:
|
||||
path: /root/Tools
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0755'
|
||||
|
||||
- name: Ensure pipx path is configured
|
||||
shell: |
|
||||
pipx ensurepath
|
||||
args:
|
||||
executable: /bin/bash
|
||||
|
||||
- name: Install tools via pipx
|
||||
shell: |
|
||||
export PATH=$PATH:/root/.local/bin
|
||||
pipx ensurepath
|
||||
pipx install git+https://github.com/Pennyw0rth/NetExec
|
||||
pipx install git+https://github.com/blacklanternsecurity/TREVORspray
|
||||
pipx install impacket
|
||||
args:
|
||||
executable: /bin/bash
|
||||
|
||||
- name: Download Kerbrute
|
||||
shell: |
|
||||
mkdir -p ~/Tools/Kerbrute
|
||||
wget https://github.com/ropnop/kerbrute/releases/latest/download/kerbrute_linux_amd64 -O ~/Tools/Kerbrute/kerbrute
|
||||
chmod +x ~/Tools/Kerbrute/kerbrute
|
||||
args:
|
||||
executable: /bin/bash
|
||||
creates: /root/Tools/Kerbrute/kerbrute
|
||||
|
||||
- name: Clone SharpCollection nightly builds
|
||||
git:
|
||||
repo: https://github.com/Flangvik/SharpCollection.git
|
||||
dest: ~/Tools/SharpCollection
|
||||
version: master
|
||||
ignore_errors: yes
|
||||
|
||||
- name: Clone PEASS-ng
|
||||
git:
|
||||
repo: https://github.com/carlospolop/PEASS-ng.git
|
||||
dest: ~/Tools/PEASS-ng
|
||||
ignore_errors: yes
|
||||
|
||||
- name: Clone MailSniper
|
||||
git:
|
||||
repo: https://github.com/dafthack/MailSniper.git
|
||||
dest: ~/Tools/MailSniper
|
||||
ignore_errors: yes
|
||||
|
||||
- name: Clone Inveigh
|
||||
git:
|
||||
repo: https://github.com/Kevin-Robertson/Inveigh.git
|
||||
dest: ~/Tools/Inveigh
|
||||
ignore_errors: yes
|
||||
|
||||
- name: Install Sliver C2 server
|
||||
shell: |
|
||||
curl https://sliver.sh/install | bash
|
||||
systemctl enable sliver
|
||||
systemctl start sliver
|
||||
|
||||
- name: Install Metasploit Framework (Nightly Build)
|
||||
shell: |
|
||||
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > ~/Tools/msfinstall
|
||||
chmod 755 ~/Tools/msfinstall
|
||||
~/Tools/msfinstall
|
||||
args:
|
||||
executable: /bin/bash
|
||||
creates: /usr/bin/msfconsole
|
||||
|
||||
- name: Grab GoPhish
|
||||
shell: |
|
||||
curl -L "$(curl -s https://api.github.com/repos/gophish/gophish/releases/latest | jq -r '.assets[] | select(.browser_download_url | contains("linux-64bit.zip")) | .browser_download_url')" -o ~/Tools/gophish.zip
|
||||
unzip ~/Tools/gophish.zip -d ~/Tools/gophish
|
||||
rm -rf ~/Tools/gophish.zip
|
||||
chmod +x ~/Tools/gophish/gophish
|
||||
args:
|
||||
creates: /root/Tools/gophish/gophish
|
||||
|
||||
- name: Deploy Gophish config.json with custom admin port
|
||||
template:
|
||||
src: gophish-config.j2
|
||||
dest: ~/Tools/gophish/config.json
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
vars:
|
||||
gophish_admin_port: "{{ gophish_admin_port }}"
|
||||
domain: "{{ domain }}"
|
||||
|
||||
- name: Configure Postfix main.cf
|
||||
lineinfile:
|
||||
path: /etc/postfix/main.cf
|
||||
regexp: "{{ item.regexp }}"
|
||||
line: "{{ item.line }}"
|
||||
with_items:
|
||||
- { regexp: '^myhostname', line: "myhostname = mail.{{ domain }}" }
|
||||
- { regexp: '^mydomain', line: "mydomain = {{ domain }}" }
|
||||
- { regexp: '^myorigin', line: "myorigin = $mydomain" }
|
||||
- { regexp: '^inet_interfaces', line: "inet_interfaces = all" }
|
||||
- { regexp: '^inet_protocols', line: "inet_protocols = ipv4" }
|
||||
- { regexp: '^smtpd_banner', line: "smtpd_banner = $myhostname ESMTP $mail_name" }
|
||||
- { regexp: '^mynetworks', line: "mynetworks = 127.0.0.0/8 [::1]/128" }
|
||||
- { regexp: '^relay_domains', line: "relay_domains = $mydestination" }
|
||||
- { regexp: '^smtpd_tls_cert_file', line: "smtpd_tls_cert_file = /etc/letsencrypt/live/{{ domain }}/fullchain.pem" }
|
||||
- { regexp: '^smtpd_tls_key_file', line: "smtpd_tls_key_file = /etc/letsencrypt/live/{{ domain }}/privkey.pem" }
|
||||
- { regexp: '^smtpd_tls_security_level', line: "smtpd_tls_security_level = encrypt" }
|
||||
- { regexp: '^smtpd_tls_session_cache_database', line: "smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache" }
|
||||
- { regexp: '^smtp_tls_session_cache_database', line: "smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache" }
|
||||
- { regexp: '^smtpd_use_tls', line: "smtpd_use_tls = yes" }
|
||||
- { regexp: '^smtpd_tls_auth_only', line: "smtpd_tls_auth_only = yes" }
|
||||
- { regexp: '^milter_default_action', line: "milter_default_action = accept" }
|
||||
- { regexp: '^milter_protocol', line: "milter_protocol = 6" }
|
||||
- { regexp: '^smtpd_milters', line: "smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
|
||||
- { regexp: '^non_smtpd_milters', line: "non_smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock" }
|
||||
|
||||
- name: Configure OpenDKIM
|
||||
lineinfile:
|
||||
path: /etc/opendkim.conf
|
||||
regexp: "{{ item.regexp }}"
|
||||
line: "{{ item.line }}"
|
||||
with_items:
|
||||
- { regexp: '^Domain', line: "Domain {{ domain }}" }
|
||||
- { regexp: '^KeyFile', line: "KeyFile /etc/opendkim/keys/{{ domain }}/mail.private" }
|
||||
- { regexp: '^Selector', line: "Selector mail" }
|
||||
- { regexp: '^Socket', line: "Socket local:/var/spool/postfix/opendkim/opendkim.sock" }
|
||||
- { regexp: '^Syslog', line: "Syslog yes" }
|
||||
- { regexp: '^UMask', line: "UMask 002" }
|
||||
- { regexp: '^Mode', line: "Mode sv" }
|
||||
|
||||
- name: Create DKIM directory
|
||||
file:
|
||||
path: /etc/opendkim/keys/{{ domain }}
|
||||
state: directory
|
||||
owner: opendkim
|
||||
group: opendkim
|
||||
mode: 0700
|
||||
|
||||
- name: Generate DKIM keys
|
||||
command: >
|
||||
opendkim-genkey -D /etc/opendkim/keys/{{ domain }} -d {{ domain }} -s mail
|
||||
args:
|
||||
creates: /etc/opendkim/keys/{{ domain }}/mail.private
|
||||
|
||||
- name: Set permissions for DKIM keys
|
||||
file:
|
||||
path: /etc/opendkim/keys/{{ domain }}/mail.private
|
||||
owner: opendkim
|
||||
group: opendkim
|
||||
mode: 0600
|
||||
|
||||
- name: Configure OpenDKIM TrustedHosts
|
||||
copy:
|
||||
content: |
|
||||
127.0.0.1
|
||||
::1
|
||||
localhost
|
||||
{{ domain }}
|
||||
dest: /etc/opendkim/TrustedHosts
|
||||
owner: opendkim
|
||||
group: opendkim
|
||||
mode: 0644
|
||||
|
||||
- name: Enable submission port (587) in master.cf
|
||||
blockinfile:
|
||||
path: /etc/postfix/master.cf
|
||||
insertafter: '^#submission'
|
||||
block: |
|
||||
submission inet n - y - - smtpd
|
||||
-o syslog_name=postfix/submission
|
||||
-o smtpd_tls_security_level=encrypt
|
||||
-o smtpd_sasl_auth_enable=yes
|
||||
-o smtpd_recipient_restrictions=permit_sasl_authenticated,reject
|
||||
-o smtpd_relay_restrictions=permit_sasl_authenticated,reject
|
||||
|
||||
- name: Configure Dovecot for Postfix SASL
|
||||
blockinfile:
|
||||
path: /etc/dovecot/conf.d/10-master.conf
|
||||
insertafter: '^service auth {'
|
||||
block: |
|
||||
# Postfix smtp-auth
|
||||
unix_listener /var/spool/postfix/private/auth {
|
||||
mode = 0660
|
||||
user = postfix
|
||||
group = postfix
|
||||
}
|
||||
|
||||
- name: Set Dovecot auth_mechanisms
|
||||
lineinfile:
|
||||
path: /etc/dovecot/conf.d/10-auth.conf
|
||||
regexp: '^auth_mechanisms'
|
||||
line: 'auth_mechanisms = plain login'
|
||||
|
||||
- name: Create Dovecot password file for SASL authentication
|
||||
file:
|
||||
path: /etc/dovecot/passwd
|
||||
state: touch
|
||||
mode: '0600'
|
||||
owner: dovecot
|
||||
group: dovecot
|
||||
|
||||
- name: Add SMTP auth user to Dovecot
|
||||
lineinfile:
|
||||
path: /etc/dovecot/passwd
|
||||
line: "{{ smtp_auth_user }}:{{ smtp_auth_pass | password_hash('sha512_crypt') }}"
|
||||
|
||||
- name: Disable system auth and use passwd-file
|
||||
lineinfile:
|
||||
path: /etc/dovecot/conf.d/10-auth.conf
|
||||
regexp: '^!include auth-system.conf.ext'
|
||||
line: '#!include auth-system.conf.ext'
|
||||
|
||||
- name: Add auth-passwdfile configuration
|
||||
blockinfile:
|
||||
path: /etc/dovecot/conf.d/10-auth.conf
|
||||
insertafter: '^auth_mechanisms ='
|
||||
block: |
|
||||
passdb {
|
||||
driver = passwd-file
|
||||
args = scheme=sha512_crypt /etc/dovecot/passwd
|
||||
}
|
||||
userdb {
|
||||
driver = static
|
||||
args = uid=vmail gid=vmail home=/var/vmail/%u
|
||||
}
|
||||
|
||||
- name: Create vmail user/group
|
||||
group:
|
||||
name: vmail
|
||||
gid: 5000
|
||||
state: present
|
||||
|
||||
- name: Create vmail user
|
||||
user:
|
||||
name: vmail
|
||||
uid: 5000
|
||||
group: vmail
|
||||
create_home: no
|
||||
|
||||
- name: Create directories for operational scripts
|
||||
file:
|
||||
path: "{{ item }}"
|
||||
state: directory
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
with_items:
|
||||
- /opt/c2
|
||||
- /opt/beacons
|
||||
|
||||
- name: Copy clean-logs.sh script
|
||||
copy:
|
||||
src: "../files/clean-logs.sh"
|
||||
dest: /opt/c2/clean-logs.sh
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Copy secure-exit.sh script
|
||||
copy:
|
||||
src: "../files/secure-exit.sh"
|
||||
dest: /opt/c2/secure-exit.sh
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Copy serve-beacons.sh script
|
||||
copy:
|
||||
src: "../files/serve-beacons.sh"
|
||||
dest: /opt/c2/serve-beacons.sh
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Configure serve-beacons.sh with C2 IP
|
||||
replace:
|
||||
path: /opt/c2/serve-beacons.sh
|
||||
regexp: 'C2_HOST=.*'
|
||||
replace: 'C2_HOST="{{ c2_ip }}"'
|
||||
|
||||
- name: Set up cron job for log cleaning if zero-logs enabled
|
||||
cron:
|
||||
name: "Clean logs"
|
||||
minute: "0"
|
||||
hour: "*/6"
|
||||
job: "/opt/c2/clean-logs.sh > /dev/null 2>&1"
|
||||
when: zero_logs | bool
|
||||
|
||||
- name: Install Let's Encrypt certificate if domain specified
|
||||
shell: |
|
||||
certbot certonly --standalone -d {{ c2_subdomain }}.{{ domain }} --non-interactive --agree-tos -m {{ letsencrypt_email }}
|
||||
args:
|
||||
creates: /etc/letsencrypt/live/{{ c2_subdomain }}.{{ domain }}/fullchain.pem
|
||||
when: domain != "example.com"
|
||||
|
||||
- name: Restart Postfix
|
||||
service:
|
||||
name: postfix
|
||||
state: restarted
|
||||
|
||||
- name: Restart Dovecot
|
||||
service:
|
||||
name: dovecot
|
||||
state: restarted
|
||||
|
||||
- name: FlokiNET-specific security configurations
|
||||
include_tasks: flokinet-security.yml
|
||||
when: enable_hardened_security | default(true)
|
||||
|
||||
- name: Print deployment summary
|
||||
debug:
|
||||
msg:
|
||||
- "FlokiNET Deployment Complete!"
|
||||
- "-------------------------------"
|
||||
- "C2 Server Domain: {{ c2_subdomain }}.{{ domain }} (Update DNS A record)"
|
||||
- "Redirector Domain: {{ redirector_subdomain }}.{{ domain }} (Update DNS A record)"
|
||||
- "Shell Handler Port: {{ shell_handler_port }}"
|
||||
- "GoPhish Admin Port: {{ gophish_admin_port }}"
|
||||
when: not disable_summary | default(false)
|
||||
+101
@@ -0,0 +1,101 @@
|
||||
---
|
||||
# FlokiNET C2-only Configuration Playbook
|
||||
# Note: FlokiNET requires pre-provisioned servers
|
||||
|
||||
- name: Prepare FlokiNET C2 configuration
|
||||
hosts: localhost
|
||||
gather_facts: false
|
||||
connection: local
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
c2_subdomain: "{{ c2_subdomain | default('mail') }}"
|
||||
|
||||
tasks:
|
||||
- name: Validate required FlokiNET configuration
|
||||
assert:
|
||||
that:
|
||||
- c2_ip is defined and c2_ip != ""
|
||||
fail_msg: "FlokiNET requires C2 IP address. Set c2_ip in vars.yaml or via --flokinet-c2-ip."
|
||||
|
||||
- name: Add C2 to inventory
|
||||
add_host:
|
||||
name: "c2"
|
||||
groups: "c2servers"
|
||||
ansible_host: "{{ c2_ip }}"
|
||||
ansible_user: "{{ ssh_user | default('root') }}"
|
||||
ansible_ssh_private_key_file: "{{ ssh_key_path | replace('.pub', '') }}"
|
||||
ansible_ssh_port: "{{ ssh_port | default(22) }}"
|
||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null"
|
||||
|
||||
- name: Verify SSH connection to C2
|
||||
wait_for:
|
||||
host: "{{ c2_ip }}"
|
||||
port: "{{ ssh_port | default(22) }}"
|
||||
delay: 10
|
||||
timeout: 60
|
||||
state: started
|
||||
ignore_errors: true
|
||||
|
||||
- name: Provision FlokiNET C2 server
|
||||
hosts: c2servers
|
||||
become: true
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Wait for apt to be available
|
||||
apt:
|
||||
update_cache: yes
|
||||
register: apt_result
|
||||
until: apt_result is success
|
||||
retries: 5
|
||||
delay: 10
|
||||
|
||||
- name: Set hostname
|
||||
hostname:
|
||||
name: "c2"
|
||||
|
||||
- name: Update apt cache
|
||||
apt:
|
||||
update_cache: yes
|
||||
|
||||
- name: Upgrade all packages
|
||||
apt:
|
||||
upgrade: dist
|
||||
|
||||
- name: Install base security packages
|
||||
apt:
|
||||
name:
|
||||
- apt-transport-https
|
||||
- ca-certificates
|
||||
- curl
|
||||
- gnupg
|
||||
- lsb-release
|
||||
- unattended-upgrades
|
||||
- ufw
|
||||
- fail2ban
|
||||
- secure-delete
|
||||
state: present
|
||||
|
||||
- name: Include common security hardening tasks
|
||||
include_tasks: "../tasks/security_hardening.yml"
|
||||
|
||||
- name: Include common tool installation tasks
|
||||
include_tasks: "../tasks/install_tools.yml"
|
||||
|
||||
- name: Include common C2 configuration tasks
|
||||
include_tasks: "../tasks/configure_c2.yml"
|
||||
|
||||
- name: Include common mail server configuration tasks
|
||||
include_tasks: "../tasks/configure_mail.yml"
|
||||
|
||||
- name: Print deployment summary
|
||||
debug:
|
||||
msg:
|
||||
- "C2 Server Configuration Complete!"
|
||||
- "-------------------------------"
|
||||
- "C2 Server IP: {{ ansible_host }}"
|
||||
- "C2 Server Domain: {{ c2_subdomain }}.{{ domain }} (Update DNS A record)"
|
||||
- "GoPhish Admin Port: {{ gophish_admin_port }}"
|
||||
when: not disable_summary | default(false)
|
||||
@@ -0,0 +1,75 @@
|
||||
---
|
||||
# FlokiNET Cleanup Playbook
|
||||
# Used for documentation since FlokiNET requires manual cleanup through their interface
|
||||
|
||||
- name: Document FlokiNET cleanup procedure
|
||||
hosts: localhost
|
||||
connection: local
|
||||
gather_facts: false
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
cleanup_redirector: "{{ (redirector_ip is defined and redirector_ip != '') | ternary(true, false) }}"
|
||||
cleanup_c2: "{{ (c2_ip is defined and c2_ip != '') | ternary(true, false) }}"
|
||||
confirm_cleanup: "{{ confirm_cleanup | default(true) }}"
|
||||
|
||||
tasks:
|
||||
- name: Confirm cleanup if required
|
||||
pause:
|
||||
prompt: "WARNING: This script provides guidance for manual FlokiNET cleanup. Type 'yes' to continue"
|
||||
register: confirmation
|
||||
when: confirm_cleanup
|
||||
|
||||
- name: Exit if not confirmed
|
||||
meta: end_play
|
||||
when: confirm_cleanup and confirmation.user_input != 'yes'
|
||||
|
||||
- name: Display cleanup instructions
|
||||
debug:
|
||||
msg:
|
||||
- "FlokiNET Cleanup Instructions"
|
||||
- "========================================"
|
||||
- "Since FlokiNET resources must be manually terminated through their control panel,"
|
||||
- "this playbook provides guidance on the steps needed for cleanup."
|
||||
- ""
|
||||
- "Resources to clean up:"
|
||||
- "{{ cleanup_redirector | ternary('- Redirector server: ' + redirector_ip, '') }}"
|
||||
- "{{ cleanup_c2 | ternary('- C2 server: ' + c2_ip, '') }}"
|
||||
- ""
|
||||
- "Steps to terminate FlokiNET servers:"
|
||||
- "1. Log in to your FlokiNET control panel"
|
||||
- "2. Navigate to the Virtual Servers section"
|
||||
- "3. Select each server from the list"
|
||||
- "4. Click 'Terminate' and confirm termination"
|
||||
- ""
|
||||
- "For security, consider also:"
|
||||
- "- Manually executing the secure-exit.sh script on each server before termination"
|
||||
- "- Removing DNS records associated with these servers"
|
||||
- "- Ensuring any SSH keys used for these servers are removed or rotated"
|
||||
|
||||
- name: Remove SSH key file if it's not a shared key
|
||||
file:
|
||||
path: "{{ ssh_key_path | replace('.pub', '') }}"
|
||||
state: absent
|
||||
when:
|
||||
- ssh_key_path is defined
|
||||
- ssh_key_path is search('c2deploy_')
|
||||
ignore_errors: true
|
||||
|
||||
- name: Remove SSH public key file if it's not a shared key
|
||||
file:
|
||||
path: "{{ ssh_key_path }}"
|
||||
state: absent
|
||||
when:
|
||||
- ssh_key_path is defined
|
||||
- ssh_key_path is search('c2deploy_')
|
||||
ignore_errors: true
|
||||
|
||||
- name: Pre-termination security recommendations
|
||||
debug:
|
||||
msg:
|
||||
- "Security Recommendations before manual termination:"
|
||||
- "------------------------------------------------"
|
||||
- " SSH Command: ssh -i {{ ssh_key_path | replace('.pub', '') }} {{ ssh_user | default('root') }}@SERVER_IP -p {{ ssh_port | default('22') }}"
|
||||
- " Then run: /opt/c2/secure-exit.sh"
|
||||
when: (cleanup_redirector or cleanup_c2) and ssh_key_path is defined
|
||||
@@ -0,0 +1,167 @@
|
||||
---
|
||||
# FlokiNET-specific security tasks
|
||||
# Enhanced security features for FlokiNET servers
|
||||
|
||||
- name: Configure FlokiNET networking for maximum anonymity
|
||||
lineinfile:
|
||||
path: /etc/sysctl.conf
|
||||
regexp: "{{ item.regexp }}"
|
||||
line: "{{ item.line }}"
|
||||
state: present
|
||||
with_items:
|
||||
- { regexp: '^net.ipv4.tcp_timestamps', line: 'net.ipv4.tcp_timestamps = 0' }
|
||||
- { regexp: '^net.ipv4.tcp_syncookies', line: 'net.ipv4.tcp_syncookies = 1' }
|
||||
- { regexp: '^net.ipv4.conf.all.accept_redirects', line: 'net.ipv4.conf.all.accept_redirects = 0' }
|
||||
- { regexp: '^net.ipv6.conf.all.accept_redirects', line: 'net.ipv6.conf.all.accept_redirects = 0' }
|
||||
- { regexp: '^net.ipv4.conf.all.send_redirects', line: 'net.ipv4.conf.all.send_redirects = 0' }
|
||||
- { regexp: '^net.ipv4.conf.all.accept_source_route', line: 'net.ipv4.conf.all.accept_source_route = 0' }
|
||||
- { regexp: '^net.ipv6.conf.all.accept_source_route', line: 'net.ipv6.conf.all.accept_source_route = 0' }
|
||||
- { regexp: '^net.ipv4.conf.all.log_martians', line: 'net.ipv4.conf.all.log_martians = 1' }
|
||||
notify: Apply sysctl settings
|
||||
|
||||
- name: Install Tor for anonymous outbound connections
|
||||
apt:
|
||||
name:
|
||||
- tor
|
||||
- torsocks
|
||||
- obfs4proxy
|
||||
state: present
|
||||
update_cache: yes
|
||||
register: tor_installed
|
||||
when: use_tor_proxy | default(true)
|
||||
|
||||
- name: Create Tor configuration directory
|
||||
file:
|
||||
path: /etc/tor
|
||||
state: directory
|
||||
mode: '0755'
|
||||
when: use_tor_proxy | default(true) and tor_installed is succeeded
|
||||
|
||||
- name: Configure Tor for hardened privacy settings
|
||||
template:
|
||||
src: torrc.j2
|
||||
dest: /etc/tor/torrc
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
notify: Restart Tor service
|
||||
when: use_tor_proxy | default(true) and tor_installed is succeeded
|
||||
|
||||
- name: Configure ProxyChains for routing through Tor
|
||||
template:
|
||||
src: proxychains.conf.j2
|
||||
dest: /etc/proxychains.conf
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
when: use_tor_proxy | default(true) and tor_installed is succeeded
|
||||
|
||||
- name: Install iptables-persistent for firewall persistence
|
||||
apt:
|
||||
name: iptables-persistent
|
||||
state: present
|
||||
update_cache: yes
|
||||
|
||||
- name: Configure hardened iptables rules for FlokiNET
|
||||
template:
|
||||
src: iptables-rules.j2
|
||||
dest: /etc/iptables/rules.v4
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
notify: Apply iptables rules
|
||||
|
||||
- name: Create SSH security hardening script
|
||||
template:
|
||||
src: secure-ssh.sh.j2
|
||||
dest: /opt/c2/secure-ssh.sh
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0700'
|
||||
when: use_hardened_ssh | default(true)
|
||||
|
||||
- name: Run SSH security hardening script
|
||||
command: /opt/c2/secure-ssh.sh
|
||||
args:
|
||||
creates: /opt/c2/.ssh_hardened
|
||||
when: use_hardened_ssh | default(true)
|
||||
|
||||
- name: Install timezone data
|
||||
apt:
|
||||
name: tzdata
|
||||
state: present
|
||||
|
||||
- name: Set timezone to UTC
|
||||
timezone:
|
||||
name: UTC
|
||||
|
||||
- name: Configure DNS to use secure DNS servers
|
||||
template:
|
||||
src: resolv.conf.j2
|
||||
dest: /etc/resolv.conf
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
when: enable_dns_encryption | default(true)
|
||||
|
||||
- name: Create directory for DNS cache configuration
|
||||
file:
|
||||
path: /etc/systemd/resolved.conf.d
|
||||
state: directory
|
||||
mode: '0755'
|
||||
when: enable_dns_encryption | default(true)
|
||||
|
||||
- name: Configure DNS caching with DNSCrypt
|
||||
template:
|
||||
src: dnscrypt.conf.j2
|
||||
dest: /etc/systemd/resolved.conf.d/dnscrypt.conf
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
notify: Restart systemd-resolved
|
||||
when: enable_dns_encryption | default(true)
|
||||
|
||||
# Configure memory security if enabled
|
||||
- name: Set memory security measures
|
||||
lineinfile:
|
||||
path: /etc/sysctl.conf
|
||||
line: "{{ item }}"
|
||||
state: present
|
||||
with_items:
|
||||
- "vm.swappiness=0"
|
||||
- "kernel.randomize_va_space=2"
|
||||
when: secure_memory | default(true)
|
||||
notify: Apply sysctl settings
|
||||
|
||||
# Configure history settings if disabled
|
||||
- name: Disable system history
|
||||
lineinfile:
|
||||
path: "{{ item.file }}"
|
||||
line: "{{ item.line }}"
|
||||
state: present
|
||||
create: yes
|
||||
with_nested:
|
||||
- [{ file: '/etc/profile' }, { file: '/root/.bashrc' }]
|
||||
- [{ line: 'export HISTFILESIZE=0' }, { line: 'export HISTSIZE=0' }, { line: 'unset HISTFILE' }]
|
||||
when: disable_history | default(true)
|
||||
|
||||
handlers:
|
||||
- name: Apply sysctl settings
|
||||
command: sysctl -p
|
||||
|
||||
- name: Restart Tor service
|
||||
service:
|
||||
name: tor
|
||||
state: restarted
|
||||
enabled: yes
|
||||
when: use_tor_proxy | default(true)
|
||||
|
||||
- name: Apply iptables rules
|
||||
command: iptables-restore < /etc/iptables/rules.v4
|
||||
|
||||
- name: Restart systemd-resolved
|
||||
service:
|
||||
name: systemd-resolved
|
||||
state: restarted
|
||||
enabled: yes
|
||||
when: enable_dns_encryption | default(true)
|
||||
@@ -0,0 +1,134 @@
|
||||
---
|
||||
- name: Common provisioning for FlokiNET servers
|
||||
hosts: all
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Set hostname
|
||||
ansible.builtin.hostname:
|
||||
name: "{{ inventory_hostname }}"
|
||||
become: true
|
||||
|
||||
- name: Update apt cache
|
||||
ansible.builtin.apt:
|
||||
update_cache: yes
|
||||
become: true
|
||||
|
||||
- name: Upgrade all packages
|
||||
ansible.builtin.apt:
|
||||
upgrade: dist
|
||||
become: true
|
||||
|
||||
- name: Install base security packages
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
- apt-transport-https
|
||||
- ca-certificates
|
||||
- curl
|
||||
- gnupg
|
||||
- lsb-release
|
||||
- unattended-upgrades
|
||||
- ufw
|
||||
- fail2ban
|
||||
- secure-delete
|
||||
state: present
|
||||
become: true
|
||||
|
||||
- name: Configure UFW
|
||||
ansible.builtin.ufw:
|
||||
state: enabled
|
||||
policy: deny
|
||||
logging: 'on'
|
||||
become: true
|
||||
|
||||
- name: Add SSH rule to UFW
|
||||
ansible.builtin.ufw:
|
||||
rule: allow
|
||||
port: "{{ ssh_port }}"
|
||||
proto: tcp
|
||||
become: true
|
||||
|
||||
- name: Configure SSH for better security
|
||||
ansible.builtin.lineinfile:
|
||||
path: /etc/ssh/sshd_config
|
||||
regexp: "{{ item.regexp }}"
|
||||
line: "{{ item.line }}"
|
||||
state: present
|
||||
with_items:
|
||||
- { regexp: '^#?PermitRootLogin', line: 'PermitRootLogin prohibit-password' }
|
||||
- { regexp: '^#?PasswordAuthentication', line: 'PasswordAuthentication no' }
|
||||
- { regexp: '^#?X11Forwarding', line: 'X11Forwarding no' }
|
||||
- { regexp: '^#?AllowTcpForwarding', line: 'AllowTcpForwarding no' }
|
||||
- { regexp: '^#?Port', line: 'Port {{ ssh_port }}' }
|
||||
- { regexp: '^#?LogLevel', line: 'LogLevel ERROR' }
|
||||
- { regexp: '^#?MaxAuthTries', line: 'MaxAuthTries 3' }
|
||||
- { regexp: '^#?ClientAliveInterval', line: 'ClientAliveInterval 300' }
|
||||
become: true
|
||||
|
||||
- name: Restart SSH service
|
||||
ansible.builtin.service:
|
||||
name: ssh
|
||||
state: restarted
|
||||
become: true
|
||||
|
||||
- name: Setup directory for operational scripts
|
||||
ansible.builtin.file:
|
||||
path: /opt/c2
|
||||
state: directory
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
become: true
|
||||
|
||||
- name: Copy operational scripts
|
||||
ansible.builtin.copy:
|
||||
src: "../files/{{ item }}"
|
||||
dest: "/opt/c2/{{ item }}"
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
with_items:
|
||||
- clean-logs.sh
|
||||
- secure-exit.sh
|
||||
become: true
|
||||
|
||||
- name: Setup cron to clean logs
|
||||
ansible.builtin.cron:
|
||||
name: "Log cleanup"
|
||||
minute: "*/{{ log_rotation_hours * 60 }}"
|
||||
job: "/opt/c2/clean-logs.sh >/dev/null 2>&1"
|
||||
become: true
|
||||
when: disable_history | bool
|
||||
|
||||
- name: Disable system history
|
||||
ansible.builtin.lineinfile:
|
||||
path: "{{ item }}"
|
||||
line: "{{ line_item }}"
|
||||
state: present
|
||||
create: yes
|
||||
with_items:
|
||||
- /etc/profile
|
||||
- /root/.bashrc
|
||||
with_nested:
|
||||
- [ 'export HISTFILESIZE=0', 'export HISTSIZE=0', 'unset HISTFILE' ]
|
||||
loop_control:
|
||||
loop_var: line_item
|
||||
become: true
|
||||
when: disable_history | bool
|
||||
|
||||
- name: Set memory security measures
|
||||
ansible.builtin.lineinfile:
|
||||
path: /etc/sysctl.conf
|
||||
line: "{{ item }}"
|
||||
state: present
|
||||
with_items:
|
||||
- "vm.swappiness=0"
|
||||
- "kernel.randomize_va_space=2"
|
||||
become: true
|
||||
when: secure_memory | bool
|
||||
|
||||
- name: Apply sysctl settings
|
||||
ansible.builtin.command: sysctl -p
|
||||
become: true
|
||||
when: secure_memory | bool
|
||||
@@ -0,0 +1,97 @@
|
||||
---
|
||||
# FlokiNET Redirector-only Configuration Playbook
|
||||
# Note: FlokiNET requires pre-provisioned servers
|
||||
|
||||
- name: Prepare FlokiNET redirector configuration
|
||||
hosts: localhost
|
||||
gather_facts: false
|
||||
connection: local
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
# Generate random shell handler port if not provided
|
||||
shell_handler_port: "{{ shell_handler_port | default(4000 + 60000 | random) }}"
|
||||
redirector_subdomain: "{{ redirector_subdomain | default('cdn') }}"
|
||||
|
||||
tasks:
|
||||
- name: Validate required FlokiNET configuration
|
||||
assert:
|
||||
that:
|
||||
- redirector_ip is defined and redirector_ip != ""
|
||||
fail_msg: "FlokiNET requires redirector IP address. Set redirector_ip in vars.yaml or via --flokinet-redirector-ip."
|
||||
|
||||
- name: Add redirector to inventory
|
||||
add_host:
|
||||
name: "redirector"
|
||||
groups: "redirectors"
|
||||
ansible_host: "{{ redirector_ip }}"
|
||||
ansible_user: "{{ ssh_user | default('root') }}"
|
||||
ansible_ssh_private_key_file: "{{ ssh_key_path | replace('.pub', '') }}"
|
||||
ansible_ssh_port: "{{ ssh_port | default(22) }}"
|
||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null"
|
||||
|
||||
- name: Verify SSH connection to redirector
|
||||
wait_for:
|
||||
host: "{{ redirector_ip }}"
|
||||
port: "{{ ssh_port | default(22) }}"
|
||||
delay: 10
|
||||
timeout: 60
|
||||
state: started
|
||||
ignore_errors: true
|
||||
|
||||
- name: Provision FlokiNET redirector
|
||||
hosts: redirectors
|
||||
become: true
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Wait for apt to be available
|
||||
apt:
|
||||
update_cache: yes
|
||||
register: apt_result
|
||||
until: apt_result is success
|
||||
retries: 5
|
||||
delay: 10
|
||||
|
||||
- name: Set hostname
|
||||
hostname:
|
||||
name: "redirector"
|
||||
|
||||
- name: Update apt cache
|
||||
apt:
|
||||
update_cache: yes
|
||||
|
||||
- name: Upgrade all packages
|
||||
apt:
|
||||
upgrade: dist
|
||||
|
||||
- name: Install base security packages
|
||||
apt:
|
||||
name:
|
||||
- apt-transport-https
|
||||
- ca-certificates
|
||||
- curl
|
||||
- gnupg
|
||||
- lsb-release
|
||||
- unattended-upgrades
|
||||
- ufw
|
||||
- fail2ban
|
||||
- secure-delete
|
||||
state: present
|
||||
|
||||
- name: Include common security hardening tasks
|
||||
include_tasks: "../tasks/security_hardening.yml"
|
||||
|
||||
- name: Include common redirector configuration tasks
|
||||
include_tasks: "../tasks/configure_redirector.yml"
|
||||
|
||||
- name: Print deployment summary
|
||||
debug:
|
||||
msg:
|
||||
- "Redirector Configuration Complete!"
|
||||
- "---------------------------------"
|
||||
- "Redirector IP: {{ ansible_host }}"
|
||||
- "Redirector Domain: {{ redirector_subdomain }}.{{ domain }} (Update DNS A record)"
|
||||
- "Shell Handler Port: {{ shell_handler_port }}"
|
||||
when: not disable_summary | default(false)
|
||||
@@ -0,0 +1,80 @@
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name {{ domain }};
|
||||
|
||||
# Redirect to HTTPS
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name {{ domain }};
|
||||
|
||||
# SSL Configuration
|
||||
ssl_certificate /etc/letsencrypt/live/{{ domain }}/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/{{ domain }}/privkey.pem;
|
||||
|
||||
# Root directory
|
||||
root /var/www/html;
|
||||
index index.html;
|
||||
|
||||
# Primary location for legitimate website traffic
|
||||
location / {
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
|
||||
# Special URI patterns for C2 traffic
|
||||
# These will redirect to the actual C2 server
|
||||
|
||||
# Sliver HTTP C2 channel
|
||||
location /ajax/ {
|
||||
proxy_pass http://{{ c2_host }}:8888;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
}
|
||||
|
||||
# Static resources that actually redirect to C2
|
||||
location ~ ^/static/(css|js|images)/.*\.(css|js|png|jpg|jpeg|gif|ico)$ {
|
||||
proxy_pass http://{{ c2_host }}:8888;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
}
|
||||
|
||||
# Additional security headers
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
add_header X-Frame-Options "SAMEORIGIN" always;
|
||||
add_header X-XSS-Protection "1; mode=block" always;
|
||||
add_header Referrer-Policy "no-referrer" always;
|
||||
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:;" always;
|
||||
|
||||
# Disable logging for this server block
|
||||
access_log off;
|
||||
error_log /dev/null crit;
|
||||
}
|
||||
|
||||
# Catch-all server block to respond to unknown hosts
|
||||
server {
|
||||
listen 80 default_server;
|
||||
listen [::]:80 default_server;
|
||||
listen 443 ssl default_server;
|
||||
listen [::]:443 ssl default_server;
|
||||
|
||||
# Self-signed cert for catch-all
|
||||
ssl_certificate /etc/ssl/certs/ssl-cert-snakeoil.pem;
|
||||
ssl_certificate_key /etc/ssl/private/ssl-cert-snakeoil.key;
|
||||
|
||||
# Redirect all unknown traffic to a legitimate-looking site
|
||||
return 301 https://www.google.com;
|
||||
|
||||
# Disable logs
|
||||
access_log off;
|
||||
error_log /dev/null crit;
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
{
|
||||
"admin_server": {
|
||||
"listen_url": "0.0.0.0:{{ gophish_admin_port }}",
|
||||
"use_tls": true,
|
||||
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
|
||||
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem",
|
||||
"trusted_origins": []
|
||||
},
|
||||
"phish_server": {
|
||||
"listen_url": "0.0.0.0:80",
|
||||
"use_tls": false,
|
||||
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
|
||||
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem"
|
||||
},
|
||||
"db_name": "sqlite3",
|
||||
"db_path": "gophish.db",
|
||||
"migrations_prefix": "db/db_",
|
||||
"contact_address": "",
|
||||
"logging": {
|
||||
"filename": "",
|
||||
"level": ""
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,122 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>{{ redirector_subdomain }} - Content Delivery Network</title>
|
||||
<style>
|
||||
body {
|
||||
font-family: Arial, sans-serif;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
background-color: #f4f4f4;
|
||||
color: #333;
|
||||
}
|
||||
header {
|
||||
background-color: #2c3e50;
|
||||
color: white;
|
||||
padding: 1em;
|
||||
text-align: center;
|
||||
}
|
||||
.container {
|
||||
width: 80%;
|
||||
margin: 0 auto;
|
||||
padding: 2em;
|
||||
}
|
||||
.card {
|
||||
background-color: white;
|
||||
border-radius: 5px;
|
||||
padding: 1.5em;
|
||||
margin-bottom: 1.5em;
|
||||
box-shadow: 0 2px 5px rgba(0,0,0,0.1);
|
||||
}
|
||||
.feature {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
margin-bottom: 1em;
|
||||
}
|
||||
.feature-icon {
|
||||
background-color: #3498db;
|
||||
color: white;
|
||||
border-radius: 50%;
|
||||
width: 40px;
|
||||
height: 40px;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
margin-right: 1em;
|
||||
font-weight: bold;
|
||||
}
|
||||
footer {
|
||||
background-color: #2c3e50;
|
||||
color: white;
|
||||
text-align: center;
|
||||
padding: 1em;
|
||||
position: fixed;
|
||||
bottom: 0;
|
||||
width: 100%;
|
||||
}
|
||||
.btn {
|
||||
display: inline-block;
|
||||
background-color: #3498db;
|
||||
color: white;
|
||||
padding: 0.7em 1.5em;
|
||||
border-radius: 5px;
|
||||
text-decoration: none;
|
||||
font-weight: bold;
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<header>
|
||||
<h1>{{ redirector_subdomain }}.{{ domain }}</h1>
|
||||
<p>Enterprise Content Delivery Network</p>
|
||||
</header>
|
||||
|
||||
<div class="container">
|
||||
<div class="card">
|
||||
<h2>Welcome to Our CDN</h2>
|
||||
<p>This server is part of our global content delivery network, optimizing digital asset delivery for enterprise applications. Our CDN provides fast, reliable, and secure content distribution across our global network.</p>
|
||||
<p><em>This is a private service. Unauthorized access is prohibited.</em></p>
|
||||
</div>
|
||||
|
||||
<div class="card">
|
||||
<h2>Our Features</h2>
|
||||
|
||||
<div class="feature">
|
||||
<div class="feature-icon">1</div>
|
||||
<div>
|
||||
<h3>Global Distribution</h3>
|
||||
<p>Content cached and distributed across multiple geographic locations for minimum latency.</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="feature">
|
||||
<div class="feature-icon">2</div>
|
||||
<div>
|
||||
<h3>DDoS Protection</h3>
|
||||
<p>Enterprise-grade protection against distributed denial of service attacks.</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="feature">
|
||||
<div class="feature-icon">3</div>
|
||||
<div>
|
||||
<h3>Asset Optimization</h3>
|
||||
<p>Automatic compression and format optimization for images, scripts, and styles.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="card" style="text-align: center;">
|
||||
<h2>Need Access?</h2>
|
||||
<p>If you're a client requiring access to our CDN services, please contact your account representative.</p>
|
||||
<a href="#" class="btn">Contact Sales</a>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<footer>
|
||||
<p>© 2025 {{ domain }} CDN Services. All rights reserved.</p>
|
||||
</footer>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,59 @@
|
||||
Welcome to your secure FlokiNET C2 Server!
|
||||
|
||||
╔═══════════════════════════════════════════════╗
|
||||
║ OPERATIONAL SECURITY ║
|
||||
║ ║
|
||||
║ This server has enhanced security features ║
|
||||
║ including hardened SSH, Tor routing, and ║
|
||||
║ zero-logs configuration. ║
|
||||
╚═══════════════════════════════════════════════╝
|
||||
|
||||
The following tools and utilities have been installed:
|
||||
|
||||
Apt-Installed Tools:
|
||||
--------------------
|
||||
- git, wget, curl, unzip
|
||||
- python3-pip, python3-venv, pipx
|
||||
- tmux, nmap, tcpdump, hydra, john, hashcat
|
||||
- sqlmap, gobuster, dirb, enum4linux, dnsenum, seclists, responder
|
||||
- golang, proxychains, tor, crackmapexec, jq, unzip
|
||||
- postfix, certbot, opendkim, opendkim-tools
|
||||
|
||||
Pipx-Installed Tools:
|
||||
---------------------
|
||||
- NetExec: git+https://github.com/Pennyw0rth/NetExec
|
||||
- TREVORspray: git+https://github.com/blacklanternsecurity/TREVORspray
|
||||
- impacket: (various network protocols and service tools)
|
||||
|
||||
Custom Tools Installed in ~/Tools:
|
||||
----------------------------------
|
||||
- SharpCollection: ~/Tools/SharpCollection
|
||||
- Kerbrute: ~/Tools/Kerbrute
|
||||
- PEASS-ng: ~/Tools/PEASS-ng
|
||||
- MailSniper: ~/Tools/MailSniper
|
||||
- Inveigh: ~/Tools/Inveigh
|
||||
- Gophish: ~/Tools/gophish (unzipped here)
|
||||
|
||||
Other Installed C2 Frameworks:
|
||||
------------------------------
|
||||
- Metasploit Framework: system installed (run 'msfconsole')
|
||||
- Sliver C2: system installed (run 'sliver')
|
||||
|
||||
Security Scripts in /opt/c2/:
|
||||
-----------------------------
|
||||
- clean-logs.sh: Securely clears all logs on the system
|
||||
- secure-exit.sh: Perform secure wipe for termination
|
||||
- serve-beacons.sh: Hosts generated implants for delivery
|
||||
|
||||
Also, remember that many reconnaissance and attack tools are now available system-wide due to the apt and pipx installations.
|
||||
|
||||
Once your DNS record points to this server's public IP, you can obtain a Let's Encrypt certificate by running:
|
||||
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d {{ c2_subdomain }}.{{ domain }}
|
||||
|
||||
**IMPORTANT:**
|
||||
|
||||
To route traffic through Tor for additional anonymity, prefix commands with 'proxychains':
|
||||
proxychains curl ifconfig.me
|
||||
|
||||
Don't forget to set up a DMARC record for your domain. Update your DNS provider's dashboard to add a TXT record named `_dmarc` with a suitable DMARC policy (e.g., `v=DMARC1; p=reject; rua=mailto:admin@{{ domain }}; ruf=mailto:admin@{{ domain }}; pct=100`). This ensures better email deliverability and security for your domain.
|
||||
@@ -0,0 +1,59 @@
|
||||
user www-data;
|
||||
worker_processes auto;
|
||||
pid /run/nginx.pid;
|
||||
include /etc/nginx/modules-enabled/*.conf;
|
||||
|
||||
events {
|
||||
worker_connections 1024;
|
||||
multi_accept on;
|
||||
}
|
||||
|
||||
http {
|
||||
# Basic Settings
|
||||
sendfile on;
|
||||
tcp_nopush on;
|
||||
tcp_nodelay on;
|
||||
keepalive_timeout 65;
|
||||
types_hash_max_size 2048;
|
||||
server_tokens off;
|
||||
|
||||
# MIME
|
||||
include /etc/nginx/mime.types;
|
||||
default_type application/octet-stream;
|
||||
|
||||
# Zero-logs configuration
|
||||
# This completely disables all access logs
|
||||
access_log off;
|
||||
# Minimal error logs - critical only
|
||||
error_log /dev/null crit;
|
||||
|
||||
# SSL Settings
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_prefer_server_ciphers on;
|
||||
ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256';
|
||||
ssl_session_timeout 1d;
|
||||
ssl_session_cache shared:SSL:10m;
|
||||
ssl_session_tickets off;
|
||||
|
||||
# Headers to confuse fingerprinting
|
||||
# Microsoft-IIS/8.5 server header to throw off analysis
|
||||
#more_set_headers 'Server: Microsoft-IIS/8.5';
|
||||
add_header Server "Microsoft-IIS/8.5";
|
||||
server_name_in_redirect off;
|
||||
|
||||
# OPSEC: Hide proxy headers
|
||||
proxy_hide_header X-Powered-By;
|
||||
proxy_hide_header X-AspNet-Version;
|
||||
proxy_hide_header X-Runtime;
|
||||
|
||||
# IP Rotation and proxying
|
||||
real_ip_header X-Forwarded-For;
|
||||
set_real_ip_from 127.0.0.1;
|
||||
|
||||
# Gzip Settings
|
||||
gzip off; # Disabled to avoid BREACH attack
|
||||
|
||||
# Virtual Host Configs
|
||||
include /etc/nginx/conf.d/*.conf;
|
||||
include /etc/nginx/sites-enabled/*;
|
||||
}
|
||||
@@ -0,0 +1,67 @@
|
||||
# FlokiNET/templates/proxychains.conf.j2
|
||||
# ProxyChains configuration for C2 server
|
||||
# Routes traffic through Tor for anonymity
|
||||
|
||||
# Dynamic chain - Each connection through the proxy list
|
||||
# Uses chained proxies in the order they appear in the list
|
||||
dynamic_chain
|
||||
|
||||
# Proxy DNS requests - no leak for DNS data
|
||||
proxy_dns
|
||||
|
||||
# Randomize the order of the proxies on each start
|
||||
# random_chain
|
||||
|
||||
# Set the type of chain (dynamic, strict, random)
|
||||
# strict_chain
|
||||
# random_chain
|
||||
|
||||
# Quiet mode (less console output)
|
||||
quiet_mode
|
||||
|
||||
# ProxyList format:
|
||||
# type host port [user pass]
|
||||
# (values separated by 'tab' or 'blank')
|
||||
[ProxyList]
|
||||
# add proxy here ...
|
||||
# socks5 127.0.0.1 1080
|
||||
socks5 127.0.0.1 9050
|
||||
|
||||
# FlokiNET/templates/iptables-rules.j2
|
||||
# Hardened iptables rules for FlokiNET C2 server
|
||||
# Applied at system startup
|
||||
|
||||
*filter
|
||||
:INPUT DROP [0:0]
|
||||
:FORWARD DROP [0:0]
|
||||
:OUTPUT ACCEPT [0:0]
|
||||
|
||||
# Allow established and related connections
|
||||
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
|
||||
|
||||
# Allow loopback
|
||||
-A INPUT -i lo -j ACCEPT
|
||||
|
||||
# Allow SSH
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport {{ ssh_port | default(22) }} -j ACCEPT
|
||||
|
||||
# Allow HTTP/HTTPS
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
|
||||
# Allow Sliver C2 ports
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport 8888 -j ACCEPT
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport 31337 -j ACCEPT
|
||||
|
||||
# Allow shell handler port
|
||||
{% if shell_handler_port is defined %}
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport {{ shell_handler_port }} -j ACCEPT
|
||||
{% endif %}
|
||||
|
||||
# Block all other incoming traffic
|
||||
-A INPUT -j DROP
|
||||
|
||||
# Allow all outbound traffic by default
|
||||
-A OUTPUT -j ACCEPT
|
||||
|
||||
COMMIT
|
||||
@@ -0,0 +1,18 @@
|
||||
# FlokiNET/templates/resolv.conf.j2
|
||||
# Secure DNS configuration
|
||||
# Uses privacy-respecting DNS servers
|
||||
|
||||
nameserver 9.9.9.9
|
||||
nameserver 1.1.1.1
|
||||
options edns0 single-request-reopen
|
||||
options timeout:1
|
||||
options attempts:2
|
||||
|
||||
# FlokiNET/templates/dnscrypt.conf.j2
|
||||
[Resolve]
|
||||
DNS=9.9.9.9 1.1.1.1
|
||||
FallbackDNS=8.8.8.8 8.8.4.4
|
||||
DNSSEC=yes
|
||||
DNSOverTLS=yes
|
||||
Cache=yes
|
||||
DNSStubListener=yes
|
||||
@@ -0,0 +1,27 @@
|
||||
[Unit]
|
||||
Description=Reverse Shell Handler Service
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
Group=root
|
||||
ExecStart=/opt/shell-handler/persistent-listener.sh
|
||||
Restart=always
|
||||
RestartSec=10
|
||||
|
||||
# Hide process information
|
||||
PrivateTmp=true
|
||||
ProtectSystem=full
|
||||
NoNewPrivileges=true
|
||||
|
||||
# Make shell handler hard to find
|
||||
StandardOutput=null
|
||||
StandardError=null
|
||||
|
||||
# Environment variables
|
||||
Environment="C2_HOST={{ c2_ip }}"
|
||||
Environment="LISTEN_PORT={{ shell_handler_port }}"
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,24 @@
|
||||
[Unit]
|
||||
Description=Sliver C2 Server
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
Group=root
|
||||
WorkingDirectory=/root/.sliver
|
||||
ExecStart=/usr/local/bin/sliver-server daemon
|
||||
Restart=always
|
||||
RestartSec=10
|
||||
|
||||
# Security measures
|
||||
PrivateTmp=true
|
||||
ProtectHome=false
|
||||
NoNewPrivileges=true
|
||||
|
||||
# Hide process information
|
||||
StandardOutput=null
|
||||
StandardError=null
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,48 @@
|
||||
# FlokiNET/templates/torrc.j2
|
||||
#
|
||||
# Tor configuration for C2 server
|
||||
# Hardened configuration for operational security
|
||||
|
||||
# General settings
|
||||
DataDirectory /var/lib/tor
|
||||
RunAsDaemon 1
|
||||
ControlPort 9051
|
||||
CookieAuthentication 1
|
||||
CookieAuthFileGroupReadable 0
|
||||
DisableDebuggerAttachment 1
|
||||
|
||||
# Network settings
|
||||
SOCKSPort 127.0.0.1:9050
|
||||
SOCKSPolicy accept 127.0.0.1/8
|
||||
SOCKSPolicy reject *
|
||||
Log notice file /var/log/tor/notices.log
|
||||
SafeSocks 1
|
||||
TestSocks 0
|
||||
|
||||
# Circuit settings
|
||||
NumEntryGuards 4
|
||||
EnforceDistinctSubnets 1
|
||||
CircuitBuildTimeout 60
|
||||
PathsNeededToBuildCircuits 0.95
|
||||
NewCircuitPeriod 900
|
||||
MaxCircuitDirtiness 1800
|
||||
|
||||
# Security settings
|
||||
StrictNodes 1
|
||||
WarnPlaintextPorts 23,109,110,143,80,21
|
||||
ReachableAddresses *:80,*:443
|
||||
ReachableAddresses reject *:*
|
||||
ReachableAddresses accept *:80
|
||||
ReachableAddresses accept *:443
|
||||
|
||||
# Obfuscation settings
|
||||
Bridge obfs4 {{ bridge_address | default('placeholderbridge.example.org:443') }} {{ bridge_fingerprint | default('PLACEHOLDERFINGERPRINT') }} cert=PLACEHOLDER
|
||||
UseBridges 1
|
||||
ClientTransportPlugin obfs4 exec /usr/bin/obfs4proxy
|
||||
ClientTransportPlugin meek exec /usr/bin/obfs4proxy
|
||||
|
||||
# Exit policy (no exits allowed)
|
||||
ExitPolicy reject *:*
|
||||
|
||||
# DNS resolution
|
||||
AutomapHostsOnResolve 1
|
||||
Reference in New Issue
Block a user