int main(int argc, char *argv[]) { char buffer[1024]; int s; int listener; struct sockaddr_in addr; int port; size_t len; memset(buffer, 0, 1024); winsock_initialize(); s = tcp_connect("www.google.ca", 80); if(s < 0) DIE("Fail"); tcp_send(s, "GET / HTTP/1.0\r\nHost: www.google.com\r\n\r\n", 41); tcp_recv(s, buffer, 1024); tcp_close(s); printf("%s\n", buffer); printf("Listening on TCP/6666\n"); listener = tcp_listen("0.0.0.0", 6666); s = tcp_accept(listener, &addr, &port); if(s < 0) DIE("Fail"); printf("Connection accepted from %s:%d\n", inet_ntoa(addr.sin_addr), ntohs(addr.sin_port)); memset(buffer, 0, 1024); strcpy(buffer, "HELLO!"); len = 7; while(len > 0 && tcp_send(s, buffer, len) >= 0) { memset(buffer, 0, 1024); len = tcp_recv(s, buffer, 1024); printf("Received: %s [%d]\n", buffer, len); } printf("%s\n", buffer); return 1; }
int main(int argc, char *argv[]) { settings_t *s = safe_malloc(sizeof(settings_t)); char c; int option_index; const char *option_name; /* Build the long-options array for parsing the options. */ struct option long_options[] = { /* General options. */ {"help", no_argument, 0, 0}, /* Help. */ {"h", no_argument, 0, 0}, {"H", no_argument, 0, 0}, {"name", required_argument, 0, 0}, /* Name. */ {"n", required_argument, 0, 0}, {"port", required_argument, 0, 0}, /* Port. */ {"p", required_argument, 0, 0}, {"source", required_argument, 0, 0}, /* Source. */ {"s", required_argument, 0, 0}, {"username", no_argument, 0, 0}, /* Username. */ {"u", no_argument, 0, 0}, {"version", no_argument, 0, 0}, /* Version. */ {"V", no_argument, 0, 0}, {"wait", required_argument, 0, 0}, /* Wait time. */ {"w", required_argument, 0, 0}, /* Actions (exactly one has to be selected). */ {"sniff", optional_argument, 0, 1}, /* View traffic. */ {"poison", optional_argument, 0, 1}, /* Send poisoned responses. */ {"conflict", optional_argument, 0, 1}, /* Send conflict responses. */ {0, 0, 0, 0} }; /* Initialize Winsock (if we're on Windows). */ winsock_initialize(); /* Get ready to randomize. */ srand((unsigned int)time(NULL)); /* Clear the settings. */ memset(s, sizeof(s), 0); /* Set some defaults. */ s->port = 137; s->source = NULL; s->name = NULL; s->user = "******"; s->wait = -1; /* Catch SIGINT. */ signal(SIGINT, interrupt); /* Catch all exit events. */ atexit(cleanup); /* Parse the commandline options. */ opterr = 0; while((c = getopt_long_only(argc, argv, "", long_options, &option_index)) != EOF) { switch(c) { case 0: option_name = long_options[option_index].name; /* General options. */ if(!strcmp(option_name, "help") || !strcmp(option_name, "h") || !strcmp(option_name, "H")) { usage(argv[0], NULL); } else if(!strcmp(option_name, "name") || !strcmp(option_name, "n")) { s->name = optarg; } else if(!strcmp(option_name, "port") || !strcmp(option_name, "p")) { s->port = atoi(optarg); } else if(!strcmp(option_name, "source") || !strcmp(option_name, "s")) { s->source = optarg; } else if(!strcmp(option_name, "username") || !strcmp(option_name, "u")) { s->user = optarg; } else if(!strcmp(option_name, "version") || !strcmp(option_name, "V")) { version(); } else if(!strcmp(option_name, "wait") || !strcmp(option_name, "w")) { s->wait = atoi(optarg); } break; case 1: { /* Set up the option name. */ option_name = long_options[option_index].name; /* Set the name. It's ok if optarg is NULL. */ if(!optarg) optarg = "*"; /* Figure out which request type we're settings. */ if(!strcmp(option_name, "poison")) s->poison = optarg; else if(!strcmp(option_name, "conflict")) s->conflict = optarg; else usage(argv[0], "Invalid request type."); } break; case '?': default: usage(argv[0], "Couldn't parse arguments"); break; } } /* Sanity checking. */ if(s->poison && !s->source) usage(argv[0], "--poison requires a source address to return (--source)."); if(s->port != 137) fprintf(stderr, "WARNING: You probably don't want to change the port.\n"); #ifndef WIN32 /* Check for the root user. */ if(getuid() != 0 && s->port < 1024) fprintf(stderr, "WARNING: If the bind() fails, please re-run as root (privileges will be dropped as soon as the socket is created).\n"); #endif /* Create a socket */ fprintf(stderr, "Creating a UDP socket.\n"); s->socket = udp_create_socket(s->port, "0.0.0.0"); /* Drop privileges, if they're running as root. */ drop_privileges(s->user); /* Set the global settings -- this lets us clean up when a signal is caught. */ global_settings = s; /* Let the user know what's going on. */ if(s->poison) fprintf(stderr, "Poisoning requests containing '%s' sent from '%s'\n", s->name ? s->name : "*", s->poison); if(s->conflict) fprintf(stderr, "Sending conflicts on requests containing '%s' sent from '%s'\n", s->name ? s->name : "*", s->conflict); /* Poll for data. */ nb_poll(s); return 0; }
int main(int argc, char *argv[]) { /* Define the options specific to the DNS protocol. */ struct option long_options[] = { /* General options */ {"help", no_argument, 0, 0}, /* Help */ {"h", no_argument, 0, 0}, {"version", no_argument, 0, 0}, /* Version */ #if 0 {"name", required_argument, 0, 0}, /* Name */ {"n", required_argument, 0, 0}, {"download",required_argument, 0, 0}, /* Download */ {"n", required_argument, 0, 0}, {"chunk", required_argument, 0, 0}, /* Download chunk */ {"isn", required_argument, 0, 0}, /* Initial sequence number */ #endif {"delay", required_argument, 0, 0}, /* Retransmit delay */ {"steady", no_argument, 0, 0}, /* Don't transmit immediately after getting a response. */ {"max-retransmits", required_argument, 0, 0}, /* Set the max retransmissions */ {"retransmit-forever", no_argument, 0, 0}, /* Retransmit forever if needed */ /* i/o options. */ {"console", no_argument, 0, 0}, /* Enable console */ {"exec", required_argument, 0, 0}, /* Enable execute */ {"e", required_argument, 0, 0}, {"command", no_argument, 0, 0}, /* Enable command (default) */ {"ping", no_argument, 0, 0}, /* Ping */ /* Tunnel drivers */ {"dns", required_argument, 0, 0}, /* Enable DNS */ #if 0 {"tcp", optional_argument, 0, 0}, /* Enable TCP */ #endif /* Debug options */ {"d", no_argument, 0, 0}, /* More debug */ {"q", no_argument, 0, 0}, /* Less debug */ {"packet-trace", no_argument, 0, 0}, /* Trace packets */ /* Sentry */ {0, 0, 0, 0} /* End */ }; char c; int option_index; const char *option_name; NBBOOL tunnel_driver_created = FALSE; NBBOOL driver_created = FALSE; log_level_t min_log_level = LOG_LEVEL_WARNING; session_t *session = NULL; group = select_group_create(); system_dns = dns_get_system(); /* Seed with the current time; not great, but it'll suit our purposes. */ srand((unsigned int)time(NULL)); /* This is required for win32 support. */ winsock_initialize(); /* Set the default log level */ log_set_min_console_level(min_log_level); /* Parse the command line options. */ opterr = 0; while((c = getopt_long_only(argc, argv, "", long_options, &option_index)) != EOF) { switch(c) { case 0: option_name = long_options[option_index].name; /* General options */ if(!strcmp(option_name, "help") || !strcmp(option_name, "h")) { usage(argv[0], "--help requested"); } if(!strcmp(option_name, "version")) { printf(NAME" v"VERSION" (client)\n"); exit(0); } else if(!strcmp(option_name, "isn")) { uint16_t isn = (uint16_t) (atoi(optarg) & 0xFFFF); debug_set_isn(isn); } else if(!strcmp(option_name, "delay")) { int delay = (int) atoi(optarg); session_set_delay(delay); LOG_INFO("Setting delay between packets to %dms", delay); } else if(!strcmp(option_name, "steady")) { session_set_transmit_immediately(FALSE); } else if(!strcmp(option_name, "max-retransmits")) { controller_set_max_retransmits(atoi(optarg)); } else if(!strcmp(option_name, "retransmit-forever")) { controller_set_max_retransmits(-1); } /* i/o drivers */ else if(!strcmp(option_name, "console")) { driver_created = TRUE; session = session_create_console(group, "Console session"); controller_add_session(session); } else if(!strcmp(option_name, "exec") || !strcmp(option_name, "e")) { driver_created = TRUE; session = session_create_exec(group, optarg, optarg); controller_add_session(session); } else if(!strcmp(option_name, "command")) { driver_created = TRUE; session = session_create_command(group, "Command session"); controller_add_session(session); } else if(!strcmp(option_name, "ping")) { driver_created = TRUE; session = session_create_ping(group, "Ping session"); controller_add_session(session); } /* Listener options. */ else if(!strcmp(option_name, "listen") || !strcmp(option_name, "l")) { LOG_FATAL("--listen isn't implemented yet! :(\n"); exit(1); /*listen_port = atoi(optarg);*/ /*input_type = TYPE_LISTENER;*/ } /* Tunnel driver options */ else if(!strcmp(option_name, "dns")) { tunnel_driver_created = TRUE; tunnel_driver = create_dns_driver(group, optarg); } else if(!strcmp(option_name, "tcp")) { tunnel_driver_created = TRUE; create_tcp_driver(optarg); } /* Debug options */ else if(!strcmp(option_name, "d")) { if(min_log_level > 0) { min_log_level--; log_set_min_console_level(min_log_level); } } else if(!strcmp(option_name, "q")) { min_log_level++; log_set_min_console_level(min_log_level); } else if(!strcmp(option_name, "packet-trace")) { session_enable_packet_trace(); } else { usage(argv[0], "Unknown option"); } break; case '?': default: usage(argv[0], "Unrecognized argument"); break; } } /* If no output was set, use the domain, and use the last option as the * domain. */ if(!tunnel_driver_created) { /* Make sure they gave a domain. */ if(optind >= argc) { printf("Starting DNS driver without a domain! This will only work if you\n"); printf("are directly connecting to the dnscat2 server.\n"); printf("\n"); printf("You'll need to use --dns server=<server> if you aren't.\n"); tunnel_driver = create_dns_driver_internal(group, NULL, "0.0.0.0", 53, DEFAULT_TYPES, NULL); } else { tunnel_driver = create_dns_driver_internal(group, argv[optind], "0.0.0.0", 53, DEFAULT_TYPES, NULL); } } /* If no i/o was set, create a command session. */ if(!driver_created) { session = session_create_command(group, "command (default)"); controller_add_session(session); } /* Be sure we clean up at exit. */ atexit(cleanup); /* Start the driver! */ driver_dns_go(tunnel_driver); return 0; }
int main(int argc, char *argv[]) { /* Define the options specific to the DNS protocol. */ struct option long_options[] = { /* General options */ {"help", no_argument, 0, 0}, /* Help */ {"h", no_argument, 0, 0}, {"version", no_argument, 0, 0}, /* Version */ #if 0 {"name", required_argument, 0, 0}, /* Name */ {"n", required_argument, 0, 0}, {"download",required_argument, 0, 0}, /* Download */ {"n", required_argument, 0, 0}, {"chunk", required_argument, 0, 0}, /* Download chunk */ {"isn", required_argument, 0, 0}, /* Initial sequence number */ #endif {"delay", required_argument, 0, 0}, /* Retransmit delay */ {"steady", no_argument, 0, 0}, /* Don't transmit immediately after getting a response. */ {"max-retransmits", required_argument, 0, 0}, /* Set the max retransmissions */ {"retransmit-forever", no_argument, 0, 0}, /* Retransmit forever if needed */ #ifndef NO_ENCRYPTION {"secret", required_argument, 0, 0}, /* Pre-shared secret */ {"no-encryption", no_argument, 0, 0}, /* Disable encryption */ #endif /* i/o options. */ {"console", no_argument, 0, 0}, /* Enable console */ {"exec", required_argument, 0, 0}, /* Enable execute */ {"e", required_argument, 0, 0}, {"command", no_argument, 0, 0}, /* Enable command (default) */ {"ping", no_argument, 0, 0}, /* Ping */ /* Tunnel drivers */ {"dns", required_argument, 0, 0}, /* Enable DNS */ #if 0 {"tcp", optional_argument, 0, 0}, /* Enable TCP */ #endif /* Debug options */ {"d", no_argument, 0, 0}, /* More debug */ {"q", no_argument, 0, 0}, /* Less debug */ {"packet-trace", no_argument, 0, 0}, /* Trace packets */ /* Sentry */ {0, 0, 0, 0} /* End */ }; int c; int option_index; const char *option_name; NBBOOL tunnel_driver_created = FALSE; ll_t *drivers_to_create = ll_create(NULL); uint32_t drivers_created = 0; log_level_t min_log_level = LOG_LEVEL_WARNING; group = select_group_create(); system_dns = dns_get_system(); /* Seed with the current time; not great, but it'll suit our purposes. */ srand((unsigned int)time(NULL)); /* This is required for win32 support. */ winsock_initialize(); #ifndef WIN32 /* set the SIGCHLD handler to SIG_IGN causing zombie child processes to be reaped automatically */ if(signal(SIGCHLD, SIG_IGN) == SIG_ERR) { perror("Couldn't set SIGCHLD handler to SIG_IGN"); exit(1); } #endif /* Set the default log level */ log_set_min_console_level(min_log_level); /* Parse the command line options. */ opterr = 0; while((c = getopt_long_only(argc, argv, "", long_options, &option_index)) != -1) { switch(c) { case 0: option_name = long_options[option_index].name; /* General options */ if(!strcmp(option_name, "help") || !strcmp(option_name, "h")) { usage(argv[0], "--help requested"); } if(!strcmp(option_name, "version")) { printf(NAME" "VERSION" (client)\n"); exit(0); } else if(!strcmp(option_name, "isn")) { uint16_t isn = (uint16_t) (atoi(optarg) & 0xFFFF); debug_set_isn(isn); } else if(!strcmp(option_name, "delay")) { int delay = (int) atoi(optarg); session_set_delay(delay); LOG_INFO("Setting delay between packets to %dms", delay); } else if(!strcmp(option_name, "steady")) { session_set_transmit_immediately(FALSE); } else if(!strcmp(option_name, "max-retransmits")) { controller_set_max_retransmits(atoi(optarg)); } else if(!strcmp(option_name, "retransmit-forever")) { controller_set_max_retransmits(-1); } #ifndef NO_ENCRYPTION else if(!strcmp(option_name, "secret")) { session_set_preshared_secret(optarg); } else if(!strcmp(option_name, "no-encryption")) { session_set_encryption(FALSE); } #endif /* i/o drivers */ else if(!strcmp(option_name, "console")) { ll_add(drivers_to_create, ll_32(drivers_created++), make_console()); /* session = session_create_console(group, "console"); controller_add_session(session); */ } else if(!strcmp(option_name, "exec") || !strcmp(option_name, "e")) { ll_add(drivers_to_create, ll_32(drivers_created++), make_exec(optarg)); /* session = session_create_exec(group, optarg, optarg); controller_add_session(session); */ } else if(!strcmp(option_name, "command")) { ll_add(drivers_to_create, ll_32(drivers_created++), make_command()); /* session = session_create_command(group, "command"); controller_add_session(session); */ } else if(!strcmp(option_name, "ping")) { ll_add(drivers_to_create, ll_32(drivers_created++), make_ping()); /* session = session_create_ping(group, "ping"); controller_add_session(session); */ } /* Tunnel driver options */ else if(!strcmp(option_name, "dns")) { tunnel_driver_created = TRUE; tunnel_driver = create_dns_driver(group, optarg); } else if(!strcmp(option_name, "tcp")) { tunnel_driver_created = TRUE; create_tcp_driver(optarg); } /* Debug options */ else if(!strcmp(option_name, "d")) { if(min_log_level > 0) { min_log_level--; log_set_min_console_level(min_log_level); } } else if(!strcmp(option_name, "q")) { min_log_level++; log_set_min_console_level(min_log_level); } else if(!strcmp(option_name, "packet-trace")) { session_enable_packet_trace(); } else { usage(argv[0], "Unknown option"); } break; case '?': default: usage(argv[0], "Unrecognized argument"); break; } } create_drivers(drivers_to_create); ll_destroy(drivers_to_create); if(tunnel_driver_created && argv[optind]) { printf("It looks like you used --dns and also passed a domain on the commandline.\n"); printf("That's not allowed! Either use '--dns domain=xxx' or don't use a --dns\n"); printf("argument!\n"); exit(1); } /* If no output was set, use the domain, and use the last option as the * domain. */ if(!tunnel_driver_created) { /* Make sure they gave a domain. */ if(optind >= argc) { printf("Starting DNS driver without a domain! This will only work if you\n"); printf("are directly connecting to the dnscat2 server.\n"); printf("\n"); printf("You'll need to use --dns server=<server> if you aren't.\n"); tunnel_driver = create_dns_driver_internal(group, NULL, "0.0.0.0", 53, DEFAULT_TYPES, NULL); } else { tunnel_driver = create_dns_driver_internal(group, argv[optind], "0.0.0.0", 53, DEFAULT_TYPES, NULL); } } /* Be sure we clean up at exit. */ atexit(cleanup); /* Start the driver! */ driver_dns_go(tunnel_driver); return 0; }
int main(int argc, char *argv[]) { /* Define the options specific to the DNS protocol. */ struct option long_options[] = { /* General options */ {"help", no_argument, 0, 0}, /* Help */ {"h", no_argument, 0, 0}, {"name", required_argument, 0, 0}, /* Name */ {"n", required_argument, 0, 0}, {"download",required_argument, 0, 0}, /* Download */ {"n", required_argument, 0, 0}, {"chunk", required_argument, 0, 0}, /* Download chunk */ {"ping", no_argument, 0, 0}, /* Ping */ /* Console options. */ {"console", no_argument, 0, 0}, /* Enable console (default) */ /* Execute-specific options. */ {"exec", required_argument, 0, 0}, /* Enable execute */ {"e", required_argument, 0, 0}, /* Listener options */ {"listen", required_argument, 0, 0}, /* Enable listener */ {"l", required_argument, 0, 0}, /* DNS-specific options */ {"dns", required_argument, 0, 0}, /* Enable DNS (default) */ {"dnshost", required_argument, 0, 0}, /* DNS server */ {"host", required_argument, 0, 0}, /* (alias) */ {"dnsport", required_argument, 0, 0}, /* DNS port */ {"port", required_argument, 0, 0}, /* (alias) */ /* Debug options */ {"d", no_argument, 0, 0}, /* More debug */ {"q", no_argument, 0, 0}, /* Less debug */ {0, 0, 0, 0} /* End */ }; /* Define DNS options so we can set them later. */ struct { char *host; uint16_t port; } dns_options = { DEFAULT_DNS_HOST, DEFAULT_DNS_PORT }; char c; int option_index; const char *option_name; NBBOOL output_set = FALSE; char *name = NULL; char *download = NULL; uint32_t chunk = -1; log_level_t min_log_level = LOG_LEVEL_WARNING; drivers_t input_type = TYPE_NOT_SET; char *exec_process = NULL; int listen_port = 0; /* Initialize the modules that need initialization. */ log_init(); sessions_init(); group = select_group_create(); /* Seed with the current time; not great, but it'll suit our purposes. */ srand((unsigned int)time(NULL)); /* This is required for win32 support. */ winsock_initialize(); /* Set the default log level */ log_set_min_console_level(min_log_level); /* Parse the command line options. */ opterr = 0; while((c = getopt_long_only(argc, argv, "", long_options, &option_index)) != EOF) { switch(c) { case 0: option_name = long_options[option_index].name; /* General options */ if(!strcmp(option_name, "help") || !strcmp(option_name, "h")) { usage(argv[0], "--help requested"); } else if(!strcmp(option_name, "name") || !strcmp(option_name, "n")) { name = optarg; } else if(!strcmp(option_name, "download")) { download = optarg; } else if(!strcmp(option_name, "chunk")) { chunk = atoi(optarg); } else if(!strcmp(option_name, "ping")) { if(input_type != TYPE_NOT_SET) too_many_inputs(argv[0]); input_type = TYPE_PING; /* Turn off logging, since this is a simple ping. */ min_log_level++; log_set_min_console_level(min_log_level); } /* Console-specific options. */ else if(!strcmp(option_name, "console")) { if(input_type != TYPE_NOT_SET) too_many_inputs(argv[0]); input_type = TYPE_CONSOLE; } /* Execute options. */ else if(!strcmp(option_name, "exec") || !strcmp(option_name, "e")) { if(input_type != TYPE_NOT_SET) too_many_inputs(argv[0]); exec_process = optarg; input_type = TYPE_EXEC; } /* Listener options. */ else if(!strcmp(option_name, "listen") || !strcmp(option_name, "l")) { if(input_type != TYPE_NOT_SET) too_many_inputs(argv[0]); listen_port = atoi(optarg); input_type = TYPE_LISTENER; } /* DNS-specific options */ else if(!strcmp(option_name, "dns")) { output_set = TRUE; driver_dns = driver_dns_create(group, optarg); } else if(!strcmp(option_name, "dnshost") || !strcmp(option_name, "host")) { dns_options.host = optarg; } else if(!strcmp(option_name, "dnsport") || !strcmp(option_name, "port")) { dns_options.port = atoi(optarg); } /* Debug options */ else if(!strcmp(option_name, "d")) { if(min_log_level > 0) { min_log_level--; log_set_min_console_level(min_log_level); } } else if(!strcmp(option_name, "q")) { log_set_min_console_level(min_log_level); } else { usage(argv[0], "Unknown option"); } break; case '?': default: usage(argv[0], "Unrecognized argument"); break; } } if(chunk != -1 && !download) { LOG_FATAL("--chunk can only be used with --download"); exit(1); } /* If no input was created, default to command. */ if(input_type == TYPE_NOT_SET) input_type = TYPE_COMMAND; switch(input_type) { case TYPE_CONSOLE: LOG_WARNING("INPUT: Console"); driver_console_create(group, name, download, chunk); break; case TYPE_COMMAND: LOG_WARNING("INPUT: Command"); driver_command_create(group, name); break; case TYPE_EXEC: LOG_WARNING("INPUT: Executing %s", exec_process); if(exec_process == NULL) usage(argv[0], "--exec set without a process!"); driver_exec_create(group, exec_process, name); break; case TYPE_LISTENER: LOG_WARNING("INPUT: Listening on port %d", driver_listener->port); if(listen_port == 0) usage(argv[0], "--listen set without a port!"); driver_listener = driver_listener_create(group, "0.0.0.0", listen_port, name); break; case TYPE_PING: LOG_WARNING("INPUT: ping"); driver_ping = driver_ping_create(group); break; case TYPE_NOT_SET: usage(argv[0], "You have to pick an input type!"); break; default: usage(argv[0], "Unknown type?"); } /* If no output was set, use the domain, and use the last option as the * domain. */ if(!output_set) { /* Make sure they gave a domain. */ if(optind >= argc) { LOG_WARNING("Starting DNS driver without a domain! You'll probably need to use --host to specify a direct connection to your server."); driver_dns = driver_dns_create(group, NULL); } else { driver_dns = driver_dns_create(group, argv[optind]); } } if(driver_dns) { if(dns_options.host == DEFAULT_DNS_HOST) driver_dns->dns_host = dns_get_system(); else driver_dns->dns_host = safe_strdup(dns_options.host); if(!driver_dns->dns_host) { LOG_FATAL("Couldn't determine the system DNS server! Please use --host to set one."); LOG_FATAL("You can also create a proper /etc/resolv.conf file to fix this"); exit(1); } driver_dns->dns_port = dns_options.port; if(driver_dns->domain) LOG_WARNING("OUTPUT: DNS tunnel to %s via %s:%d", driver_dns->domain, driver_dns->dns_host, driver_dns->dns_port); else LOG_WARNING("OUTPUT: DNS tunnel to %s:%d (no domain set! This probably needs to be the exact server where the dnscat2 server is running!)", driver_dns->dns_host, driver_dns->dns_port); } else { LOG_FATAL("OUTPUT: Ended up with an unknown output driver!"); exit(1); } /* Be sure we clean up at exit. */ atexit(cleanup); /* Add the timeout function */ select_set_timeout(group, timeout, NULL); while(TRUE) select_group_do_select(group, 1000); return 0; }