mirror of
https://github.com/Arcanum-Sec/wraith
synced 2026-08-08 10:45:03 +00:00
Browser-hooking framework for red teams, researchers, and educators: a clean-room successor to BeEF (hook + Pretty Theft overlays) fused with blind-XSS callback tooling, built to hook browsers across modern (incl. AI) app ecosystems. - One-command Docker install (setup.sh): auto-detects public IP/domain, provisions operator username + password, prints hook/XSS URLs - Operator console: live keystrokes, captured creds, page capture, page mirror, calibrated localhost/LAN scan, XSS payload catalog - Overlays (LinkedIn/Facebook/Microsoft), built-in vulnerable practice lab - Apache-2.0 licensed For authorized security testing, research, and education only.
29 lines
836 B
Docker
29 lines
836 B
Docker
# WRAITH — browser hook lab. Small, single-process Node image.
|
|
FROM node:20-alpine
|
|
|
|
# tini for correct signal handling so SIGTERM flushes the session store on stop.
|
|
RUN apk add --no-cache tini
|
|
|
|
WORKDIR /app
|
|
|
|
# Install production deps first so the layer caches across source edits.
|
|
COPY package.json package-lock.json ./
|
|
RUN npm ci --omit=dev || npm install --omit=dev
|
|
|
|
# App source (node_modules, .env, data/ are excluded via .dockerignore).
|
|
COPY . .
|
|
|
|
# Session store lives here; also declared a volume so loot persists across
|
|
# container restarts and never bakes into the image.
|
|
RUN mkdir -p /app/data && chown -R node:node /app
|
|
VOLUME ["/app/data"]
|
|
|
|
# Drop root inside the container.
|
|
USER node
|
|
|
|
# Informational; the real port comes from WRAITH_PORT at runtime.
|
|
EXPOSE 8090
|
|
|
|
ENTRYPOINT ["/sbin/tini", "--"]
|
|
CMD ["node", "server.js"]
|