4 ms·
This is a great comment! Next steps are BPF pinning and probably a few userspace hiding tactics. Constraints for the project is that I will not use a kernel mo
by kris-nova 5y ago
This is a great comment!
Next steps are BPF pinning and probably a few userspace hiding tactics. Constraints for the project is that I will not use a kernel module or LD Preload. Additionally I’m going to have sets of triggers in addition to a bad IPv4 checksum. Most modern network equipment will drop the malformed packet long before it reaches a target with a bad checksum.
Other ideas are encapsulating RCE over IPv6 (there are 24 bytes available) and using SYNACK retries and TCP RST to also trigger the reverse protocol.
We can also probably slim compile time and runtime dependencies down if we lose the hacky double ncat protocol thing I have going on and just open up a reverse socket directly. Which means we should also have the remote not run as root for obvious reasons.
I have a lot of ideas, as our friends in Ukraine tell me their needs I’ll be posting more research to the repository to aid them as much as possible.
- deleted 5y ago[deleted]