Compare commits

..

3 Commits

Author SHA1 Message Date
its-a-feature b1e7ed1771 adding svg agent_icon 2026-02-05 09:22:22 -06:00
github-actions 038c0b9ea8 Bump Dockerfile tag to match release 'v0.0.3.2' 2025-10-27 13:58:08 +00:00
its-a-feature caac20d991 updating extra methods to handle missing params 2025-10-27 08:47:27 -05:00
6 changed files with 205 additions and 159 deletions
+7
View File
@@ -1,4 +1,11 @@
## [1.1.1] - 2025-10-27
### Changed
- Updated processing to not error out if missing get/post uris
- this is in support of new payload type c2 prarameter deviations
## [1.1.0] - 2025-10-07
### Changed
+5 -5
View File
@@ -4,7 +4,7 @@ go 1.25.1
//replace github.com/MythicMeta/MythicContainer => ../../../../MythicMeta/MythicContainer
require github.com/MythicMeta/MythicContainer v1.5.0
require github.com/MythicMeta/MythicContainer v1.5.1
require (
github.com/fsnotify/fsnotify v1.9.0 // indirect
@@ -29,10 +29,10 @@ require (
go.uber.org/multierr v1.11.0 // indirect
go.yaml.in/yaml/v3 v3.0.4 // indirect
golang.org/x/exp v0.0.0-20251002181428-27f1f14c8bb9 // indirect
golang.org/x/net v0.45.0 // indirect
golang.org/x/sys v0.36.0 // indirect
golang.org/x/text v0.29.0 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20251007200510-49b9836ed3ff // indirect
golang.org/x/net v0.46.0 // indirect
golang.org/x/sys v0.37.0 // indirect
golang.org/x/text v0.30.0 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20251022142026-3a174f9686a8 // indirect
google.golang.org/grpc v1.76.0 // indirect
google.golang.org/protobuf v1.36.10 // indirect
gopkg.in/ini.v1 v1.67.0 // indirect
+10
View File
@@ -14,6 +14,8 @@ github.com/MythicMeta/MythicContainer v1.4.19 h1:/85sOCafRuCyvWpEl/zoC1YEOGghJ8z
github.com/MythicMeta/MythicContainer v1.4.19/go.mod h1:BnUYftqQ9KsGxBd6RlyRcAHBrqV1CUcrRCjktWwc2Do=
github.com/MythicMeta/MythicContainer v1.5.0 h1:KA9GxgPwBiQ60jGo00Km6B1MQjvlJM5903RuOkMiUlE=
github.com/MythicMeta/MythicContainer v1.5.0/go.mod h1:st3wSmozT/3a4Q19R6JIOkHKWxwXW6RcGcyaDuxkRGQ=
github.com/MythicMeta/MythicContainer v1.5.1 h1:IWvGiM6kWmDuWjhXrF+rG2Bj1xRjWJVsgA/87mqTRUc=
github.com/MythicMeta/MythicContainer v1.5.1/go.mod h1:st3wSmozT/3a4Q19R6JIOkHKWxwXW6RcGcyaDuxkRGQ=
github.com/coreos/go-systemd/v22 v22.5.0/go.mod h1:Y58oyj3AT4RCenI/lSvhwexgC+NSVTIJ3seZv2GcEnc=
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
@@ -154,6 +156,8 @@ golang.org/x/net v0.44.0 h1:evd8IRDyfNBMBTTY5XRF1vaZlD+EmWx6x8PkhR04H/I=
golang.org/x/net v0.44.0/go.mod h1:ECOoLqd5U3Lhyeyo/QDCEVQ4sNgYsqvCZ722XogGieY=
golang.org/x/net v0.45.0 h1:RLBg5JKixCy82FtLJpeNlVM0nrSqpCRYzVU1n8kj0tM=
golang.org/x/net v0.45.0/go.mod h1:ECOoLqd5U3Lhyeyo/QDCEVQ4sNgYsqvCZ722XogGieY=
golang.org/x/net v0.46.0 h1:giFlY12I07fugqwPuWJi68oOnpfqFnJIJzaIIm2JVV4=
golang.org/x/net v0.46.0/go.mod h1:Q9BGdFy1y4nkUwiLvT5qtyhAnEHgnQ/zd8PfU6nc210=
golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
@@ -169,6 +173,8 @@ golang.org/x/sys v0.30.0 h1:QjkSwP/36a20jFYWkSue1YwXzLmsV5Gfq7Eiy72C1uc=
golang.org/x/sys v0.30.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
golang.org/x/sys v0.36.0 h1:KVRy2GtZBrk1cBYA7MKu5bEZFxQk4NIDV6RLVcC8o0k=
golang.org/x/sys v0.36.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
golang.org/x/sys v0.37.0 h1:fdNQudmxPjkdUTPnLn5mdQv7Zwvbvpaxqs831goi9kQ=
golang.org/x/sys v0.37.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
golang.org/x/text v0.16.0 h1:a94ExnEXNtEwYLGJSIUxnWoxoRz/ZcCsV63ROupILh4=
golang.org/x/text v0.16.0/go.mod h1:GhwF1Be+LQoKShO3cGOHzqOgRrGaYc9AvblQOmPVHnI=
golang.org/x/text v0.17.0 h1:XtiM5bkSOt+ewxlOE/aE/AKEHibwj/6gvWMl9Rsh0Qc=
@@ -181,6 +187,8 @@ golang.org/x/text v0.22.0 h1:bofq7m3/HAFvbF51jz3Q9wLg3jkvSPuiZu/pD1XwgtM=
golang.org/x/text v0.22.0/go.mod h1:YRoo4H8PVmsu+E3Ou7cqLVH8oXWIHVoX0jqUWALQhfY=
golang.org/x/text v0.29.0 h1:1neNs90w9YzJ9BocxfsQNHKuAT4pkghyXc4nhZ6sJvk=
golang.org/x/text v0.29.0/go.mod h1:7MhJOA9CD2qZyOKYazxdYMF85OwPdEr9jTtBpO7ydH4=
golang.org/x/text v0.30.0 h1:yznKA/E9zq54KzlzBEAWn1NXSQ8DIp/NYMy88xJjl4k=
golang.org/x/text v0.30.0/go.mod h1:yDdHFIX9t+tORqspjENWgzaCVXgk0yYnYuSZ8UzzBVM=
google.golang.org/genproto/googleapis/rpc v0.0.0-20240709173604-40e1e62336c5 h1:SbSDUWW1PAO24TNpLdeheoYPd7kllICcLU52x6eD4kQ=
google.golang.org/genproto/googleapis/rpc v0.0.0-20240709173604-40e1e62336c5/go.mod h1:Ue6ibwXGpU+dqIcODieyLOcgj7z8+IcskoNIgZxtrFY=
google.golang.org/genproto/googleapis/rpc v0.0.0-20240827150818-7e3bb234dfed h1:J6izYgfBXAI3xTKLgxzTmUltdYaLsuBxFCgDHWJ/eXg=
@@ -195,6 +203,8 @@ google.golang.org/genproto/googleapis/rpc v0.0.0-20250929231259-57b25ae835d4 h1:
google.golang.org/genproto/googleapis/rpc v0.0.0-20250929231259-57b25ae835d4/go.mod h1:HSkG/KdJWusxU1F6CNrwNDjBMgisKxGnc5dAZfT0mjQ=
google.golang.org/genproto/googleapis/rpc v0.0.0-20251007200510-49b9836ed3ff h1:A90eA31Wq6HOMIQlLfzFwzqGKBTuaVztYu/g8sn+8Zc=
google.golang.org/genproto/googleapis/rpc v0.0.0-20251007200510-49b9836ed3ff/go.mod h1:7i2o+ce6H/6BluujYR+kqX3GKH+dChPTQU19wjRPiGk=
google.golang.org/genproto/googleapis/rpc v0.0.0-20251022142026-3a174f9686a8 h1:M1rk8KBnUsBDg1oPGHNCxG4vc1f49epmTO7xscSajMk=
google.golang.org/genproto/googleapis/rpc v0.0.0-20251022142026-3a174f9686a8/go.mod h1:7i2o+ce6H/6BluujYR+kqX3GKH+dChPTQU19wjRPiGk=
google.golang.org/grpc v1.65.0 h1:bs/cUb4lp1G5iImFFd3u5ixQzweKizoZJAwBNLR42lc=
google.golang.org/grpc v1.65.0/go.mod h1:WgYC2ypjlB0EiQi6wdKixMqukr6lBc0Vo+oOgjrM5ZQ=
google.golang.org/grpc v1.66.0 h1:DibZuoBznOxbDQxRINckZcUvnCEvrW9pcWIE2yF9r1c=
+146 -153
View File
@@ -4,11 +4,12 @@ import (
"encoding/base64"
"encoding/json"
"fmt"
c2structs "github.com/MythicMeta/MythicContainer/c2_structs"
"github.com/MythicMeta/MythicContainer/logging"
"os"
"path/filepath"
"strings"
c2structs "github.com/MythicMeta/MythicContainer/c2_structs"
"github.com/MythicMeta/MythicContainer/logging"
)
type config struct {
@@ -51,7 +52,7 @@ func writeC2JsonConfig(cfg *config) error {
return os.WriteFile(filepath.Join(".", "http", "c2_code", "config.json"), jsonBytes, 644)
}
const version = "1.1.0"
const version = "1.1.1"
var httpc2definition = c2structs.C2Profile{
Name: "http",
@@ -66,94 +67,98 @@ var httpc2definition = c2structs.C2Profile{
Success: true,
Message: fmt.Sprintf("Called config check\n%v", message),
}
if suppliedPort, ok := message.Parameters["callback_port"]; !ok {
suppliedPort, ok := message.Parameters["callback_port"]
if !ok {
response.Success = false
response.Error = "Failed to get callback_port attribute"
return response
} else if suppliedHost, ok := message.Parameters["callback_host"]; !ok {
}
suppliedHost, ok := message.Parameters["callback_host"]
if !ok {
response.Success = false
response.Error = "Failed to get callback_host attribute"
return response
} else if currentConfig, err := getC2JsonConfig(); err != nil {
}
currentConfig, err := getC2JsonConfig()
if err != nil {
response.Success = false
response.Error = err.Error()
return response
} else {
possibleSSLPorts := []int{}
possiblePorts := []int{}
parameterPort := int(suppliedPort.(float64))
parameterHost := suppliedHost.(string)
for _, instance := range currentConfig.Instances {
if instance.UseSSL {
possibleSSLPorts = append(possibleSSLPorts, instance.Port)
} else {
possiblePorts = append(possiblePorts, instance.Port)
}
if instance.Port == parameterPort {
// we found a match for our port and a configured port
if strings.HasPrefix(parameterHost, "https") && !instance.UseSSL {
// callback_host of https:// on port, but port isn't configured with ssl
message := fmt.Sprintf("C2 Profile container is configured to NOT use SSL on port %d, but the callback host for the agent is using https, %s.\n\n",
instance.Port, parameterHost)
message += "This means there should be the following connectivity for success:\n"
message += fmt.Sprintf("Agent via SSL to %s on port %d, then redirection to C2 Profile container WITHOUT SSL on port %d",
parameterHost, parameterPort, parameterPort)
response.Error = message
//response.Success = false
//return response
} else if !strings.HasPrefix(parameterHost, "https") && instance.UseSSL {
// callback_host of http:// on port, but port is configured with ssl
message := fmt.Sprintf("C2 Profile container is configured to use SSL on port %d, but the callback host for the agent is using http, %s.\n\n",
instance.Port, parameterHost)
message += "This means there should be the following connectivity for success:\n"
message += fmt.Sprintf("Agent via NO SSL to %s on port %d, then redirection to C2 Profile container WITH SSL on port %d",
parameterHost, parameterPort, parameterPort)
response.Error = message
//response.Success = false
//return response
} else {
// either http:// on port without ssl or https:// on port with ssl, all good
response.Message = fmt.Sprintf("C2 Profile container and agent configuration match port, %d, and SSL expectations (%v)\n",
instance.Port, instance.UseSSL)
return response
}
}
}
message := "Specified use of SSL and ports indicate the use of a redirector, or a mismatch in expected connectivity.\n\n"
message += "This means there should be the following connectivity for success:\n"
if strings.HasPrefix(parameterHost, "https") {
message += fmt.Sprintf("Agent via HTTPS on port %d to %s (should be a redirector).\n",
parameterPort, parameterHost)
} else {
message += fmt.Sprintf("Agent via HTTP on port %d to %s (should be a redirector).\n",
parameterPort, parameterHost)
}
if len(possibleSSLPorts) > 0 {
message += fmt.Sprintf("Redirector then forwards request to C2 Profile container WITH SSL on one of the following ports: %v\n",
possibleSSLPorts)
}
if len(possiblePorts) > 0 {
if len(possibleSSLPorts) > 0 {
message += fmt.Sprintf("Alternatively, redirector could forward request to C2 Profile container WITHOUT SSL on one of the following ports: %v\n",
possiblePorts)
} else {
message += fmt.Sprintf("Redirector then forwards request to C2 Profile container WITHOUT SSL on one of the following ports: %v\n",
possiblePorts)
}
}
if strings.HasPrefix(parameterHost, "https") {
message += "\nAlternatively, this might mean that you want to do SSL but are not using SSL within your C2 Profile container.\n"
message += "To add SSL to your C2 profile:\n"
message += "\t1. Go to the C2 Profile page\n"
message += "\t2. Click configure for the http profile\n"
message += fmt.Sprintf(
"\t3. Change 'use_ssl' to 'true' and make sure the port is %d\n",
parameterPort)
message += "\t4. Click to stop the profile and then start it again\n"
}
response.Message = message
return response
}
possibleSSLPorts := []int{}
possiblePorts := []int{}
parameterPort := int(suppliedPort.(float64))
parameterHost := suppliedHost.(string)
for _, instance := range currentConfig.Instances {
if instance.UseSSL {
possibleSSLPorts = append(possibleSSLPorts, instance.Port)
} else {
possiblePorts = append(possiblePorts, instance.Port)
}
if instance.Port == parameterPort {
// we found a match for our port and a configured port
if strings.HasPrefix(parameterHost, "https") && !instance.UseSSL {
// callback_host of https:// on port, but port isn't configured with ssl
message := fmt.Sprintf("C2 Profile container is configured to NOT use SSL on port %d, but the callback host for the agent is using https, %s.\n\n",
instance.Port, parameterHost)
message += "This means there should be the following connectivity for success:\n"
message += fmt.Sprintf("Agent via SSL to %s on port %d, then redirection to C2 Profile container WITHOUT SSL on port %d",
parameterHost, parameterPort, parameterPort)
response.Error = message
//response.Success = false
//return response
} else if !strings.HasPrefix(parameterHost, "https") && instance.UseSSL {
// callback_host of http:// on port, but port is configured with ssl
message := fmt.Sprintf("C2 Profile container is configured to use SSL on port %d, but the callback host for the agent is using http, %s.\n\n",
instance.Port, parameterHost)
message += "This means there should be the following connectivity for success:\n"
message += fmt.Sprintf("Agent via NO SSL to %s on port %d, then redirection to C2 Profile container WITH SSL on port %d",
parameterHost, parameterPort, parameterPort)
response.Error = message
//response.Success = false
//return response
} else {
// either http:// on port without ssl or https:// on port with ssl, all good
response.Message = fmt.Sprintf("C2 Profile container and agent configuration match port, %d, and SSL expectations (%v)\n",
instance.Port, instance.UseSSL)
return response
}
}
}
messageOutput := "Specified use of SSL and ports indicate the use of a redirector, or a mismatch in expected connectivity.\n\n"
messageOutput += "This means there should be the following connectivity for success:\n"
if strings.HasPrefix(parameterHost, "https") {
messageOutput += fmt.Sprintf("Agent via HTTPS on port %d to %s (should be a redirector).\n",
parameterPort, parameterHost)
} else {
messageOutput += fmt.Sprintf("Agent via HTTP on port %d to %s (should be a redirector).\n",
parameterPort, parameterHost)
}
if len(possibleSSLPorts) > 0 {
messageOutput += fmt.Sprintf("Redirector then forwards request to C2 Profile container WITH SSL on one of the following ports: %v\n",
possibleSSLPorts)
}
if len(possiblePorts) > 0 {
if len(possibleSSLPorts) > 0 {
messageOutput += fmt.Sprintf("Alternatively, redirector could forward request to C2 Profile container WITHOUT SSL on one of the following ports: %v\n",
possiblePorts)
} else {
messageOutput += fmt.Sprintf("Redirector then forwards request to C2 Profile container WITHOUT SSL on one of the following ports: %v\n",
possiblePorts)
}
}
if strings.HasPrefix(parameterHost, "https") {
messageOutput += "\nAlternatively, this might mean that you want to do SSL but are not using SSL within your C2 Profile container.\n"
messageOutput += "To add SSL to your C2 profile:\n"
messageOutput += "\t1. Go to the C2 Profile page\n"
messageOutput += "\t2. Click configure for the http profile\n"
messageOutput += fmt.Sprintf(
"\t3. Change 'use_ssl' to 'true' and make sure the port is %d\n",
parameterPort)
messageOutput += "\t4. Click to stop the profile and then start it again\n"
}
response.Message = messageOutput
return response
},
GetRedirectorRulesFunction: func(message c2structs.C2GetRedirectorRuleMessage) c2structs.C2GetRedirectorRuleMessageResponse {
response := c2structs.C2GetRedirectorRuleMessageResponse{
@@ -190,23 +195,24 @@ var httpc2definition = c2structs.C2Profile{
// Create URI string in modrewrite syntax. "*" are needed in regex to support GET and uri-append parameters on the URI
urisString := strings.Join(uris, ".*|") + ".*"
c2RewriteOutput := []string{}
if currentConfig, err := getC2JsonConfig(); err != nil {
currentConfig, err := getC2JsonConfig()
if err != nil {
logging.LogError(err, "Failed to get current json configuration")
response.Error = "Failed to get current json configuration"
response.Success = false
return response
} else {
c2RewriteTemplate := "RewriteRule ^.*$ \"%s%%{REQUEST_URI}\" [P,L]"
for _, instance := range currentConfig.Instances {
if instance.UseSSL {
serverURL := fmt.Sprintf("https://C2_SERVER_HERE:%d", instance.Port)
c2RewriteOutput = append(c2RewriteOutput, fmt.Sprintf(c2RewriteTemplate, serverURL))
} else {
serverURL := fmt.Sprintf("http://C2_SERVER_HERE:%d", instance.Port)
c2RewriteOutput = append(c2RewriteOutput, fmt.Sprintf(c2RewriteTemplate, serverURL))
}
}
c2RewriteTemplate := "RewriteRule ^.*$ \"%s%%{REQUEST_URI}\" [P,L]"
for _, instance := range currentConfig.Instances {
if instance.UseSSL {
serverURL := fmt.Sprintf("https://C2_SERVER_HERE:%d", instance.Port)
c2RewriteOutput = append(c2RewriteOutput, fmt.Sprintf(c2RewriteTemplate, serverURL))
} else {
serverURL := fmt.Sprintf("http://C2_SERVER_HERE:%d", instance.Port)
c2RewriteOutput = append(c2RewriteOutput, fmt.Sprintf(c2RewriteTemplate, serverURL))
}
}
output += "#\tReplace 'C2_SERVER_HERE' with the IP/Domain address of where matching traffic should go\n"
htaccessTemplate := `
@@ -246,23 +252,29 @@ RewriteCond %%{HTTP_USER_AGENT} "%s"`
Success: true,
Message: fmt.Sprintf("Called opsec check:\n%v", message),
}
if callbackHost, ok := message.Parameters["callback_host"]; !ok {
callbackHost, ok := message.Parameters["callback_host"]
if !ok {
response.Success = false
response.Error = "Failed to get callback_host attribute"
return response
} else if callbackPort, ok := message.Parameters["callback_port"]; !ok {
}
callbackPort, ok := message.Parameters["callback_port"]
if !ok {
response.Success = false
response.Error = "Failed to get callback_port attribute"
return response
} else if callbackHost.(string) == "https://domain.com" {
}
if callbackHost.(string) == "https://domain.com" {
response.Success = false
response.Error = "Callback Host is set to default of https://domain.com!\n"
return response
} else if len(strings.Split(callbackHost.(string), ":")) != 2 {
}
if len(strings.Split(callbackHost.(string), ":")) != 2 {
response.Success = false
response.Error = fmt.Sprintf("callback host is improperly configured! %v shouldn't specify a port, that should be in the callback_port field", callbackHost)
return response
} else if strings.HasPrefix(callbackHost.(string), "https") {
}
if strings.HasPrefix(callbackHost.(string), "https") {
standardHttpsPorts := []int{443, 8443, 7443}
for _, port := range standardHttpsPorts {
if port == int(callbackPort.(float64)) {
@@ -272,10 +284,9 @@ RewriteCond %%{HTTP_USER_AGENT} "%s"`
response.Success = true
response.Message = fmt.Sprintf("Callback port, %d, is unusual for https scheme", int(callbackPort.(float64)))
return response
} else {
response.Message = "No immediate issues with configuration"
return response
}
response.Message = "No immediate issues with configuration"
return response
},
GetIOCFunction: func(message c2structs.C2GetIOCMessage) c2structs.C2GetIOCMessageResponse {
response := c2structs.C2GetIOCMessageResponse{Success: true}
@@ -291,64 +302,35 @@ RewriteCond %%{HTTP_USER_AGENT} "%s"`
response.Error = "Failed to get callback_port"
return response
}
getURI, err := message.GetStringArg("get_uri")
if err != nil {
response.Success = false
response.Error = "Failed to get get_uri"
return response
}
postURI, err := message.GetStringArg("post_uri")
if err != nil {
response.Success = false
response.Error = "Failed to get post_uri"
return response
if err == nil {
response.IOCs = append(response.IOCs, c2structs.IOC{
Type: "url",
IOC: fmt.Sprintf("%s:%v/%s", callbackHost, callbackPort, postURI),
})
}
queryPathForGet, err := message.GetStringArg("query_path_name")
if err != nil {
response.Success = false
response.Error = "Failed to get query_path_name"
return response
getURI, err := message.GetStringArg("get_uri")
if err == nil {
queryPathForGet, err := message.GetStringArg("query_path_name")
if err == nil {
response.IOCs = append(response.IOCs, c2structs.IOC{
Type: "url",
IOC: fmt.Sprintf("%s:%v/%s?%s=", callbackHost, callbackPort, getURI, queryPathForGet),
})
}
}
response.IOCs = append(response.IOCs, c2structs.IOC{
Type: "url",
IOC: fmt.Sprintf("%s:%v", callbackHost, callbackPort),
})
response.IOCs = append(response.IOCs, c2structs.IOC{
Type: "url",
IOC: fmt.Sprintf("%s:%v/%s?%s=", callbackHost, callbackPort, getURI, queryPathForGet),
})
response.IOCs = append(response.IOCs, c2structs.IOC{
Type: "url",
IOC: fmt.Sprintf("%s:%v/%s", callbackHost, callbackPort, postURI),
})
return response
},
SampleMessageFunction: func(message c2structs.C2SampleMessageMessage) c2structs.C2SampleMessageResponse {
response := c2structs.C2SampleMessageResponse{Success: true}
getURI, err := message.GetStringArg("get_uri")
if err != nil {
response.Success = false
response.Error = "Failed to get get_uri"
return response
}
postURI, err := message.GetStringArg("post_uri")
if err != nil {
response.Success = false
response.Error = "Failed to get post_uri"
return response
}
queryPathForGet, err := message.GetStringArg("query_path_name")
if err != nil {
response.Success = false
response.Error = "Failed to get query_path_name"
return response
}
headers, err := message.GetDictionaryArg("headers")
if err != nil {
response.Success = false
response.Error = "Failed to get headers"
return response
logging.LogError(err, "failed to get dictionary headers")
headers = make(map[string]string)
}
callbackHost, err := message.GetStringArg("callback_host")
if err != nil {
@@ -375,8 +357,24 @@ RewriteCond %%{HTTP_USER_AGENT} "%s"`
sampleCURLGet += fmt.Sprintf("-H \"%s: %s\" ", key, value)
sampleCURLPost += fmt.Sprintf("-H \"%s: %s\" ", key, value)
}
sampleCURLGet += fmt.Sprintf("%s:%d/%s?%s=%s", callbackHost, int(callbackPort), getURI, queryPathForGet, base64URLEncoding)
sampleCURLPost += fmt.Sprintf("%s:%d/%s", callbackHost, int(callbackPort), postURI)
getURI, err := message.GetStringArg("get_uri")
if err == nil {
queryPathForGet, err := message.GetStringArg("query_path_name")
if err == nil {
sampleCURLGet += fmt.Sprintf("%s:%d/%s?%s=%s", callbackHost, int(callbackPort), getURI, queryPathForGet, base64URLEncoding)
} else {
sampleCURLGet = "Missing query_path_name"
}
} else {
sampleCURLGet = "Missing get_uri"
}
postURI, err := message.GetStringArg("post_uri")
if err == nil {
sampleCURLPost += fmt.Sprintf("%s:%d/%s", callbackHost, int(callbackPort), postURI)
} else {
sampleCURLPost = "Missing post_uri"
}
response.Message = fmt.Sprintf("GET:\n%s\n\nPOST:\n%s\n\n", sampleCURLGet, sampleCURLPost)
return response
},
@@ -550,12 +548,7 @@ var httpc2parameters = []c2structs.C2Parameter{
}
func Initialize() {
agentBytes, err := os.ReadFile(filepath.Join(".", "http.svg"))
if err != nil {
logging.LogError(err, "failed to get http svg icon")
} else {
httpc2definition.AgentIcon = &agentBytes
}
c2structs.AllC2Data.Get("http").AddC2Definition(httpc2definition)
c2structs.AllC2Data.Get("http").AddIcon(filepath.Join(".", "http.svg"))
c2structs.AllC2Data.Get("http").AddParameters(httpc2parameters)
}
+36
View File
@@ -0,0 +1,36 @@
<svg viewBox="0 0 200 200" xmlns="http://www.w3.org/2000/svg">
<!-- Browser window -->
<rect x="10" y="20" width="180" height="160" rx="8" fill="none" stroke="#2196F3" stroke-width="4"/>
<!-- Browser title bar -->
<rect x="10" y="20" width="180" height="35" rx="8" fill="#2196F3" opacity="0.2"/>
<line x1="10" y1="55" x2="190" y2="55" stroke="#2196F3" stroke-width="4"/>
<!-- Window control buttons -->
<circle cx="25" cy="37" r="5" fill="#FF5F56"/>
<circle cx="42" cy="37" r="5" fill="#FFBD2E"/>
<circle cx="59" cy="37" r="5" fill="#27C93F"/>
<!-- Address bar -->
<rect x="20" y="70" width="160" height="40" rx="6" fill="none" stroke="#2196F3" stroke-width="3"/>
<!-- Lock icon (unlocked for HTTP) -->
<g transform="translate(32, 82)">
<rect x="0" y="7" width="14" height="12" rx="1.5" fill="none" stroke="#FF5722" stroke-width="2.5"/>
<path d="M 2 7 L 2 4 Q 2 0, 7 0 Q 12 0, 12 4 L 12 5.5" fill="none" stroke="#FF5722" stroke-width="2.5" stroke-linecap="round"/>
</g>
<!-- http:// text -->
<text x="55" y="96" font-family="monospace" font-size="22" font-weight="bold" fill="#2196F3">http://</text>
<!-- Cursor blink -->
<rect x="163" y="80" width="3" height="22" fill="#2196F3">
<animate attributeName="opacity" values="1;0;1" dur="1.2s" repeatCount="indefinite"/>
</rect>
<!-- Browser content area representation -->
<rect x="30" y="125" width="140" height="45" rx="3" fill="#2196F3" opacity="0.1"/>
<line x1="40" y1="138" x2="100" y2="138" stroke="#2196F3" stroke-width="2.5" opacity="0.3"/>
<line x1="40" y1="150" x2="140" y2="150" stroke="#2196F3" stroke-width="2.5" opacity="0.3"/>
<line x1="40" y1="162" x2="120" y2="162" stroke="#2196F3" stroke-width="2.5" opacity="0.3"/>
</svg>

After

Width:  |  Height:  |  Size: 1.7 KiB

+1 -1
View File
@@ -5,6 +5,6 @@
"exclude_documentation_c2": false,
"exclude_agent_icons": false,
"remote_images": {
"http": "ghcr.io/mythicc2profiles/http:v0.0.3.1"
"http": "ghcr.io/mythicc2profiles/http:v0.0.3.2"
}
}