Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Stowaway - Multi-hop Proxy Tool For Pentesters

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Stowaway - Multi-hop Proxy Tool For Pentesters


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: feedproxy.google.com


Stowaway is Multi-hop proxy tool for security researchers and pentesters
Users can easily proxy their network traffic to intranet nodes (multi-layer)
PS: The files under demo folder are Stowaway's beta version,it's still functional, you can check the detail by README.md file under the demo folder
This tool is limited to security research and teaching, and the user bears all legal and related responsibilities caused by the use of this tool! The author does not assume any legal and related responsibilities!

Features
  • obvious node topology
  • multi-hop socks5 traffic proxy
  • multi-hop ssh traffic proxy
  • remote interactive shell
  • network traffic encryption with AES-256(CBC mode)
  • support macos and linux

Usage

Stowaway can be excuted as two kinds of mode: admin && agent
If you don't want to compile the project by yourself, you can check the release folder to get ONE!
Simple example๏ผš
  Admin mode๏ผš./stowaway admin -l 9999 -s 123

Meaning๏ผš

admin It means Stowaway is started as admin mode

-l It means Stowaway is listening on port 9999 and waiting for incoming connection

-s It means Stowaway has used 123 as the encrypt key during the communication

Be aware! -s option's value must be as same as the agents'

For now, there are only three options above are supported!

  agent mode๏ผš ./stowaway agent -m 127.0.0.1:9999 -l 10000 --startnode -s 123 -r

Meaning๏ผš

agent It means Stowaway is started as agent mode

-m It means Stowaway's monitor node's address (In this case,it's the node we started above)

-l It means Stowaway is listening on port 10000 and waiting for incoming connection

-s It means Stowaway has used 123 as the encrypt key during the communication

--startnode It means Stowaway is started as FIRST agent node(if the node is the first one , you MUST add this option!!! And there are two submode of agent mode,if you want to start the second, third one....., just remove this option)

-r It means you want to start the node in reverse mode(For instance: you can add node 2 into the net via node 1 actively connect to node 2, instead of node 1 just waiting for the connection from node 2 )

Be aware! -s option's value must be as same as the agents'

For now, there are only five options above are supported!
Example
For instance(one admin;one startnode;two simple nodes)
Admin

Startnode

First simple Nodeย (setting as reverse mode)

Now, use admin and type in "use 1" -> "connect 127.0.0.1:10001" ,then you can add node 1 into the net
Second simple Node

When all agent nodes connected๏ผŒcheck the topology in admin

Now we manipulate the second simple node through admin

Open the remote interactive shell

Now you can use interactive shell (the second simple node's) through admin
Start socks5 proxy service

Now you can use the admin's port 7777 as the socks5 proxy service
And it can proxy your traffic to the second simple node and the second simple node will do its work as socks server๏ผˆ When you want to shut down this socks5 service, just type in "stopsocks" under this mode to turn off it)
Open ssh

And it can proxy your ssh traffic to the second simple node and the second simple node will do its work as ssh cilent
PS: In this function,you can type in pwd to check where you currently are
For more detail, just type help to get further informations

Attention
  • This porject is coding just for fun , the logic structure and code structure are not strict enough, please don't be so serious about it
  • When the admin offline, all agent nodes will offline too(maybe it will be changed in future)
  • When one of the agents offline, the agent nodes after it will offline
  • Once the admin started, you need to connect at least one agent node to it before you do any operations
  • If you want to compile this project for supporting more platform, you can use go build -ldflags="-w -s" to do that
  • Temporarily does not support Windows

Thanks

...



๐Ÿ“Œ Ligolo - Reverse Tunneling Made Easy For Pentesters, By Pentesters


๐Ÿ“ˆ 40.84 Punkte

๐Ÿ“Œ Flight simulator comes bundled with password stealing stowaway


๐Ÿ“ˆ 35.31 Punkte

๐Ÿ“Œ theHarvester-Advanced Information Gathering Tool for Pentesters & Ethical Hackers


๐Ÿ“ˆ 25.8 Punkte

๐Ÿ“Œ Remot3d v2.0 - Tool Created For Large Pentesters As Well As Just For The Pleasure Of Defacers To Control Server By Backdoors


๐Ÿ“ˆ 25.8 Punkte

๐Ÿ“Œ Remot3d v2.0 - Tool Created For Large Pentesters As Well As Just For The Pleasure Of Defacers To Control Server By Backdoors


๐Ÿ“ˆ 25.8 Punkte

๐Ÿ“Œ Botb - A Container Analysis And Exploitation Tool For Pentesters And Engineers


๐Ÿ“ˆ 25.8 Punkte

๐Ÿ“Œ S3Enum - Fast Amazon S3 Bucket Enumeration Tool For Pentesters


๐Ÿ“ˆ 25.8 Punkte

๐Ÿ“Œ Jenkins Attack Framework (JAF), a new free tool for pentesters to analyze security of automation servers


๐Ÿ“ˆ 25.8 Punkte

๐Ÿ“Œ APPSEC Cali 2018 - Hunter โ€“ Optimize your Pentesters Time


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ APPSEC Cali 2018 - Hunter โ€“ Optimize your Pentesters Time


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Five tips for pentesters in iOS


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ The PenTesters Framework - Install Penetration Testing Tools On Any Distribution


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Active Directory Best Practices That Frustrate Pentesters


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ EvilTwinFramework - A Framework for Pentesters to Perform Evil Twin attacks


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ PODCAST: Active Directory Best Practices that Frustrate Pentesters


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Security Hole of Love (Theme song for Japanese game teaching young pentesters)


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Pentesters breach 92 percent of companies, report claims


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Pentesters breach 92 percent of companies, report claims


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Commando VM โ€” New Windows-based Distribution for Hackers and Pentesters


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Pentesters say a keyless smart lock made by u-tec, called ultraloq, is neither ultra or secure.


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Two pentesters, one glitch: Firefox browser menaced by ancient file-snaffling bug, er, feature


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Pentesters and Phishing- Kevin O'Brien, GreatHorn - ESW #158


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Pentesters find mysterious Black box connected to ships engines


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Awesome Android Security - A Curated List Of Android Security Materials And Resources For Pentesters And Bug Hunters


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ HackerOne Rolls Out Pentest Review System for Customers and Pentesters


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Anonymous Logins for Pentesters


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Why Two Pentesters In Iowa Are Facing A Criminal Investigation and Trespassing Charges


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Good news for pentesters and network admins: US issues ransomware guidance asking biz to skill up security teams


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ HackerOne Rolls Out Pentest Review System for Customers and Pentesters


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Docker for Pentesters Nightingale - Raja Nagori


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Networking for Pentesters: Beginner | Serena DiPenti | 1-Hour


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Part 1-Networking for Pentesters: Beginner | Serena DiPenti


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Part 2-Networking for Pentesters: Beginner | Serena DiPenti


๐Ÿ“ˆ 20.42 Punkte

๐Ÿ“Œ Pentesters - Is this considered exploitation or info gathering?


๐Ÿ“ˆ 20.42 Punkte











matomo