3 Commits

Author SHA1 Message Date
风起 e41fdb7bd2 Update ProxyFilter.go 2022-07-12 12:08:33 +08:00
风起 c7a4657a2b Delete RedGuard 2022-07-12 12:07:12 +08:00
风起 f51f9ae381 Update RedGuard Version 22.7.12 2022-07-12 12:06:07 +08:00
15 changed files with 92 additions and 1822 deletions
+7 -6
View File
@@ -1,10 +1,11 @@
## [22.7.4.11.30] - 2022-7-4
## [22.7.12.1111] - 2022-7-12
### Added
- Fix inconsistent request IP address and interception IP address Domain fronting
## [22.6.30.1107] - 2022-6-30
### Added
- Domain fronting Obtain the actual requested IP address
Profile Header authentication ignores case
Disable the default JARM fingerprint randomization parameter
Change the long version name!!
Forward the packet XFF header so that C2 gets the real IP address
Custom configuration file path
Added validity verification for parameter IP input
## [22.6.28.1712] - 2022-6-28
### Added
+1 -1
View File
@@ -152,7 +152,7 @@ As shown in the figure above, in the case of unauthorized access, the response i
In the above basic interception case, the default interception method is used, that is, the illegal traffic is intercepted by redirection. By modifying the configuration file, we can change the interception method and the redirected site URL. In fact, this The other way is a redirect, which might be more aptly described as hijacking, cloning, since the response status code returned is 200, and the response is taken from another website to mimic the cloned/hijacked website as closely as possible.
Invalid packets can be misrouted according to two strategies:
Invalid packets can be misrouted according to three strategies:
- **reset**: Terminate the TCP connection immediately.
- **proxy**: Get a response from another website to mimic the cloned/hijacked website as closely as possible.
+5 -1
View File
@@ -84,12 +84,16 @@ func main() {
)
core.CmdParse(&parse, &cert, &_proxy)
// Check whether RedGuard has been initialized
if num, isExits := lib.CreateConfig(parse.C2Type /* C2 Facility Type */); isExits {
if num, isExits := lib.CreateConfig(parse.C2Type /* C2 Facility Type */, parse.ConfigPath); isExits {
switch {
case parse.Update:
lib.UpdateConfig(&cert, &_proxy) // Update RedGuard Config
logger.Notice("RedGuard Configuration file updated successfully!")
case parse.IP != "":
if lib.CheckIP(parse.IP) == false {
logger.Warning("Please enter a valid IP address")
os.Exit(0)
}
logger.Noticef("Search ipLookUpHelper: %s", parse.IP)
core.IPLookUp(parse.Location /* owning place to be verified */, parse.IP) // Query the location of an IP address
case num == 0:
+1 -1759
View File
File diff suppressed because it is too large Load Diff
+14 -14
View File
@@ -1,24 +1,24 @@
-----BEGIN CERTIFICATE-----
MIIEFTCCAv2gAwIBAgIIFv6CRztNa1AwDQYJKoZIhvcNAQELBQAwZjELMAkGA1UE
MIIEFTCCAv2gAwIBAgIIFwD2T6B86kAwDQYJKoZIhvcNAQELBQAwZjELMAkGA1UE
BhMCQ04xETAPBgNVBAcTCEhhbmdaaG91MS0wKwYDVQQKEyRBbGliYWJhIChDaGlu
YSkgVGVjaG5vbG9neSBDby4sIEx0ZC4xFTATBgNVBAMMDCouYWxpeXVuLmNvbTAe
Fw0yMjA3MDQwMzIyMzVaFw0yMzA3MDQwMzIyMzVaMGYxCzAJBgNVBAYTAkNOMREw
Fw0yMjA3MTIwMzExMjRaFw0yMzA3MTIwMzExMjRaMGYxCzAJBgNVBAYTAkNOMREw
DwYDVQQHEwhIYW5nWmhvdTEtMCsGA1UEChMkQWxpYmFiYSAoQ2hpbmEpIFRlY2hu
b2xvZ3kgQ28uLCBMdGQuMRUwEwYDVQQDDAwqLmFsaXl1bi5jb20wggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDOlbbgaka7fwBiesgQcEm8droXLL5FHXsj
kXEYtE4PJY8pxPmADfYd47CKJ7uHwEHPagJOGmYhYeTrly+d2ZzFSjEP5Oskqoq9
jWHvdiga+IYcsBNEECGxxsQxIuXiFi0JKC0rgotPOG2Dttu7h98aRya5e38L9kf3
X+XKdkz4GVeJ1xvS6qr9hfkaUuQfHiEKp9iB2A5/SLZ4RxEgap2n3HJ0gt35KCv9
/Wt8khljME5h17UJ9n7YcVfvV4Gc41eDJL7XalkUAdtJzvZOy99H2q1VZTsmbswT
wQFDhjB0g/EeaxmngKgFDp+LzJqE2U2WuMg2HyfPcvCzBVrnWWufAgMBAAGjgcYw
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDOSqu2E65uDMrnqt+xeXZ7w+Tp+w0ATaL1
k6f+ie0emIq/VExL1jzjjpByLEVXqskwIXDvIS7WXKTeudVSUZ1CRV3+o8Ztdsy5
oSsfTQ3J1vqt7/qA6rMiqZAIfsvqt5Kz+yE1aB2o7IpLoseRW2PrXy30qbJ3xFKp
Sn3Yl0J/no3egNTa096R0QGmpL23kG5YQ2s/YhgZQBLg+x/9tf0JGFWMO8/3bxvD
iu9RuVmQpkYhwJvJSThbbg4yKAFmtBZvd6GycZjgyJzekTcU+T0DqawJW3s3r//R
xuGI4yIesLi30MzZ0SoWvfCXxdYINPPXyYXwzpt2tIoLDJcgOBjfAgMBAAGjgcYw
gcMwDgYDVR0PAQH/BAQDAgKkMBMGA1UdJQQMMAoGCCsGAQUFBwMBMIGbBgNVHREE
gZMwgZCCDCouYWxpeXVuLmNvbYIabWFuYWdlci5jaGFubmVsLmFsaXl1bi5jb22C
HCouYWNzLWludGVybmFsLmFsaXl1bmNzLmNvbSKCFCouY29ubmVjdC5hbGl5dW4u
Y29tggphbGl5dW4uY29tghB3aG9pcy53d3cubmV0LmNughJ0aWFuY2hpLWdsb2Jh
bC5jb20wDQYJKoZIhvcNAQELBQADggEBAK5e9R/x/zUj5GJ6XyCAdD6S/GC7Gn3Y
5fnV1a1LXEK7kRuiJ4iKruyOwz/D+aSdqvGjgBNU3z76z18jf1KZnnxWt7W1DOmU
Pqi2nKEkilQ+es7tYj8NxyfnPDc1V5P7ecS9bTYtTemlu5V1NpzoeO8cUM8Xc+Oq
w9gtwR62vlmkAwICgUTF8Pfw9/wBhNVVgsLfuYTKfBWyiLy+TuxtrLSIQ9qYtvRr
GRQgx+jKwURxU7ZFuUAMnXUen+WYKdTO0+FSI96k0KJYpZ+MUfSFXSy4FOHo7imP
a5eLziaD5VOy6RNFxd517CzAJoKtKauL5jNzmrEe0jaDRVRQbhwJPw4=
bC5jb20wDQYJKoZIhvcNAQELBQADggEBACgy5DMRqEpT2OcAo+n43CVKeus+lQ0+
x0IqwDljmU42rkZQNgLGHB0YLnJrbMZ6l29dn3KAIMvIJacoLWcIFQAwqW9W6gB4
zuFFydRMKwQuH42s2vnyCFJ2hwEWJHszA3r8xe4yBn7I/bKPEU+2UFhAHEO5bsFj
SiX7Kc+MPQpAl9Sccmw+k9CdaftFsKcsaMzarnVzsQY7/2ZMNtiPnYRLONKgjtHl
9EAIcB+CqBjZLTlnjxa+e93fqHhSIKtCe6qcyVL9jhPq5hygl1u6o1C4ht7hlC9y
U2Ymn2o4OKQfh6Pio6eWRIU2ERkYCrfh7YNteYpQDC218k5IaG1nJsg=
-----END CERTIFICATE-----
+25 -25
View File
@@ -1,27 +1,27 @@
-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAzpW24GpGu38AYnrIEHBJvHa6Fyy+RR17I5FxGLRODyWPKcT5
gA32HeOwiie7h8BBz2oCThpmIWHk65cvndmcxUoxD+TrJKqKvY1h73YoGviGHLAT
RBAhscbEMSLl4hYtCSgtK4KLTzhtg7bbu4ffGkcmuXt/C/ZH91/lynZM+BlXidcb
0uqq/YX5GlLkHx4hCqfYgdgOf0i2eEcRIGqdp9xydILd+Sgr/f1rfJIZYzBOYde1
CfZ+2HFX71eBnONXgyS+12pZFAHbSc72TsvfR9qtVWU7Jm7ME8EBQ4YwdIPxHmsZ
p4CoBQ6fi8yahNlNlrjINh8nz3LwswVa51lrnwIDAQABAoIBAQCGj35PLupjtpXJ
j7BBBOMCn1MXRU2qN0m+IT5JmSg/NXfK/UKG5pEpZuXXF4pPIiu7rpFRzmA33kv+
KLwbVWOIHotWjwWbHHrCfRUNpSj6aGbyyL3D174azh184/5ZBZjQHhtN+/pB3791
y+XUgOwRcccHiil24TR/LTfAaM45yxxh/xx/0suExYTaBtadpdsPbg7x8wBk1slg
rEXOKKhcwq7fapnssJccF6//vSyBr4yOGOZmKUPpj9MSNZMD/htwGBm+dJejXKKa
jwNL0CjEVYMtIzUbSXM8nrWu8Zrw2X5+HwL5PlVcJvj5X0teNSG7hLWnZiHJbvFP
EdbOcKgBAoGBAOdN1Ymoofyz/Sl4FQNHc1KhwRBPqqbiJ11lbsH2lywdKzZnBscl
OHnp5NiySY8uV9WOXd2+EyOhP6obd9DhrsrfMaIt7m+jHSmxQi7PYIZIEr6nWjmA
CZLwAgfHRXN7Urlc0bet48wX4yrw8lz9gcjNxqGpsASotg6a/jJZ1V8vAoGBAOSk
PK+5i2U47bHkL8T9TTNqYc1gm0F5TA6qgt+CNPzU5JhYju+KLp4LXx8fmgaRLNMI
/AVb6gM17J0eqh4nuGQQQh4P3/QLQSfckfk7Xl3doePq1ppqJWyIlHQ42dF+Dyil
Z3spMnToM8XHOow5bQMmXVJsBxH6f+OkGVqjWR6RAoGAKpQJWu3P49S+JYQVWiUs
9WkRQQ9pOo8m7+pcGRhre5NjAQC2HrKbUtXbaohnQhQl1wn9/XOf0k88iPPFeo4Q
vweW+2O5IJPGKoaWyEckXZOm37GuyibnnETSGtxzzG5HLBgKAuXfqRI8nwr7kmKY
IX6/scKqxDDKUqX1ZQ9kV8ECgYBX7T0VSuJre9gVCC7Cr7KnqiqQY61xIWd5YGNR
9u3PqUN7vtrBDb/dsXvUKT//dIbrZVId8Xnt4CftSGSdkiLcAFCc5Pf4Dvfwj2dn
lEg3Cst+Lcp3uYhI08FbbJ1/bd4AgJNqDq7DvKRkU7iVQmREyNUspDSX2mCiN3I0
pArasQKBgFHv5vHLPvGDSO/segOQxIayEy3BCtOYvJH3y/7xHj4810w9VFxSymkF
KBNOglW0MGeN0SbFfL76ucCNoDtn/k0EBBk/n1iBkf54SglDCnKIMasSH7Bj1n4k
pVN3JC+o9hu0VJ43LBsvCS1x5YXNBiUrcHbs9Z9BqOeD051mu2Cd
MIIEowIBAAKCAQEAzkqrthOubgzK56rfsXl2e8Pk6fsNAE2i9ZOn/ontHpiKv1RM
S9Y8446QcixFV6rJMCFw7yEu1lyk3rnVUlGdQkVd/qPGbXbMuaErH00Nydb6re/6
gOqzIqmQCH7L6reSs/shNWgdqOyKS6LHkVtj618t9Kmyd8RSqUp92JdCf56N3oDU
2tPekdEBpqS9t5BuWENrP2IYGUAS4Psf/bX9CRhVjDvP928bw4rvUblZkKZGIcCb
yUk4W24OMigBZrQWb3ehsnGY4Mic3pE3FPk9A6msCVt7N6//0cbhiOMiHrC4t9DM
2dEqFr3wl8XWCDTz18mF8M6bdrSKCwyXIDgY3wIDAQABAoIBAQCA+w8BeKzHAhib
YKscO+Vo3MJzyRQH7ILHKNsQuwwW5SlbF0nc4MaRQMHvoN56Qb4o6b/Cw+yU+rfa
yjYmkgDRPq3WWG/oYS7/oVVk7LiCSnfR6QmnMRdvxLTZmu3Eg6KmBY5t5fslcz/E
qrI8n/eJYqlJIBEF8Sn9zyWAFpLtVwVpZ9MxU28oHMdAcJXHXW64BGudpyTDWM1s
LJqajk5kU1beMyIpZUkScXyBuISgJAYwHYQhf5ftE8FuCVtgwF5ThJnpBk6GZWad
WGDzUx+Hb0rZRFrNaNP3WXThggwM6hAB4He0eRIqZJD1djhjRI9MbU98bXV3oPEL
tUI4iGGBAoGBANk1Rrt6YmAnjZpbxRHf0vx60RlTgtY6T+r3V2d1zoQiQ7CNOyEC
HGET7OLWoacJF/ZG5dl1Uha0C6KaWPicchrEFAevPyfv2dQH539spXtbG6tONCR4
ba5VGZreVPLfO/Qzg2mOX4FjMmmMjZOZSBp8yUuIeAIm+5+adBPgaNZrAoGBAPMi
TANtmMaDx1sdV6992uUvmEhP6nAWVOln7XMc/YH7T9ORe6IVw5HaiN0UTSMIDTkJ
tov0lE+oHHT6Zx23/dDDD8AcySKXpKHWK2CeTj2k3Q7Fp5A2sJEPorQnqcn+cXz4
Wp9wuX1L8YRIQEUSrihRhpnozqPgIDihVln6q5xdAoGAW6Sp0kIBrbYifaUIkdEQ
0Ov0uy3L/x0dSPLQ0tsWphNa4evErdmZJbBlexO5oqMolAU3xzdDykZuvk1HCqXf
UsG1/cQH7o65JkereczaSSCYnP9i6pxREoPfSMNTriFXx2HQqUGjtBCpXXUq6sJ6
dIp/17mdgLL36VAed6BwOz8CgYBqEpx3Iml0silXZwXKWm4Vbx5Q7gypuhRxgBXo
Es3G142MD/yQSk54Y48yZJkCn5ClQceSZ7IMzpsbreMu5Aan/XHxrp1Rqjb5JCbo
kCgyXKrUtwbTtAh0QQ4K6wL4TTnV+8QNq3BBadCElcD0YaH5lRfULe15MV7dVgYG
W4ZjQQKBgHOhzG1to2nT8qfug6jWLids7YxtunXW0q1LwotwVtzvbdj9Qv07LQnT
dJO7AGw7sioa/50utwno8I5yPYsEUNuffH9/k8fP3Ydm686/hcp+hPMN/HXKp0sF
bPzMXBfkOFQ5WAOA/eLTm2Z6P5YDw7aRdtYgCFH9SSMMZd4jzYYR
-----END RSA PRIVATE KEY-----
+1 -1
View File
@@ -12,7 +12,7 @@ Organization = Alibaba (China) Technology Co., Ltd.
# Cert User Country
Country = CN
# Whether to use the certificate you have applied for true/false
HasCert = false
HasCert = true
[proxy]
# key : Header Host value of the reverse proxy
+1 -1
View File
@@ -21,7 +21,7 @@ Github:%s
RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.
`
VERSION = "22.7.4.11.30 Alpha"
VERSION = "22.7.12 Alpha"
TITLE = "RedGuard"
LICENSE = "GPL-2.0"
URL = "https://github.com/wikiZ/RedGuard"
+1 -2
View File
@@ -94,7 +94,7 @@ func MalleableFilter(file string, req *http.Request) (isFilter bool) {
var num int // Exception counter
// Traverse the target profile requirements header slice
for _, profileHeader := range malleable.headerParam {
if reqHeader != profileHeader {
if strings.ToLower(reqHeader) != strings.ToLower(profileHeader) {
continue
}
num += 1 // The same header exists
@@ -132,7 +132,6 @@ func ProxyFilterManger(req *http.Request) (status bool) {
}
}
}
// Check the location of the requested IP address
if allowLocation != "" && allowLocation != "*" {
// @param allowLocation string The territory that is allowed to go online
+2
View File
@@ -84,6 +84,8 @@ func (h *baseHandle) ServeHTTP(write http.ResponseWriter, req *http.Request) {
if req.Header.Get("X-Forwarded-For") != "" {
req.RemoteAddr = req.Header.Get("X-Forwarded-For")
}
// Set the forwarding header XFF so that C2 obtains the online real IP address
req.Header.Set("X-Forwarded-For", req.RemoteAddr)
// Check whether the host is verified
if IPHash := lib.EncodeMD5(req.JA3); arrays.ContainsString(_addressArray, req.JA3) == -1 {
logger.Noticef("JA3 FingerPrint: %s", IPHash)
+2 -1
View File
@@ -17,11 +17,12 @@ func CmdParse(parse *parameter.Parses, cert *parameter.Cert, proxy *parameter.Pr
flag.BoolVar(&parse.Update, "u", false, `Enable configuration file modification`)
flag.StringVar(&parse.C2Type, "type", `CobaltStrike`, `C2 Server Type`)
flag.StringVar(&parse.IP, "ip", ``, `IPLookUP IP`)
flag.StringVar(&parse.ConfigPath, "config", ``, `Set Config Path`)
flag.StringVar(&parse.Location, "location", `风起`, `IPLookUP Location`)
flag.StringVar(&cert.Country, "country", `CN`, `Cert Country`)
flag.StringVar(&cert.CommonName, "common", `*.aliyun.com`, `Cert CommonName`)
flag.StringVar(&cert.Organization, "organization", `Alibaba (China) Technology Co., Ltd.`, `Cert Organization`)
flag.StringVar(&cert.HasCert, "HasCert", `false`, `Whether to use the certificate you have applied for`)
flag.StringVar(&cert.HasCert, "HasCert", `true`, `Whether to use the certificate you have applied for`)
flag.StringVar(&cert.DNSNameTo, "dns", `*.aliyun.com,manager.channel.aliyun.com,*.acs-internal.aliyuncs.com",*.connect.aliyun.com,aliyun.com,whois.www.net.cn,tianchi-global.com`, `Cert DNSName`)
flag.StringVar(&cert.Locality, "locality", `HangZhou`, `Cert Locality`)
flag.StringVar(&proxy.HostTarget, "host", `{"360.net":"http://127.0.0.1:8080","360.com":"https://127.0.0.1:4433"}`, `Set Proxy HostTarget`)
+5 -4
View File
@@ -8,10 +8,11 @@
package parameter
type Parses struct {
Update bool
C2Type string
IP string
Location string
Update bool
IP string
C2Type string
Location string
ConfigPath string
}
type Cert struct {
+11 -1
View File
@@ -150,7 +150,7 @@ Usage of ./RedGuard:
上述的基础拦截案例中,使用的是默认的拦截方式,也就是将非法流量以重定向的方式拦截,而通过配置文件的修改,我们可以更改拦截的方式,以及重定向的站点URL,其实这种方式与之说是重定向,描述为劫持、克隆或许更贴切,因为返回的响应状态码为200,是从另一个网站获取响应,以尽可能接近地模仿克隆/劫持的网站。
无效数据包可能会根据种策略被错误路由:
无效数据包可能会根据种策略被错误路由:
- **reset**:立即终止 TCP 连接。
- **proxy**:从另一个网站获取响应,以尽可能接近地模仿克隆/劫持的网站。
@@ -194,6 +194,16 @@ Port_HTTP = :80
![image.png](https://github.com/wikiZ/RedGuardImage/raw/main/1656310909975.jpg)
## RedGuard获取真实IP地址
针对于日常、域前置场景下获取真实请求IP,RG无需进行任何配置,仅需对启动C2设施的profile文件增加以下配置,即通过请求头X-Forwarded-For获取目标真实IP。
```bash
http-config {
set trust_x_forwarded_for "true";
}
```
## 请求地域限制
配置方式以AllowLocation = 济南,北京 为例,这里值得注意的是,RedGuard提供了两个IP归属地反查的API,一个适用于国内用户,另一个适用于海外用户,并且可以根据输入的地域名动态的分配使用哪个API,如果目标是中国的那么设置的地域就输入中文,反之输入英文地名,建议国内的用户使用中文名即可,这样反查到的归属地准确度以及API的响应速度都是最好的选择。
+8
View File
@@ -37,3 +37,11 @@ func EncodeMD5(s string) string {
md5Str := hex.EncodeToString(hash.Sum(nil))
return md5Str
}
// CheckIP Check whether the entered IP address is valid
func CheckIP(ip string) bool {
if m, _ := regexp.MatchString("^(25[0-5]|2[0-4]\\d|[0-1]\\d{2}|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|[0-1]\\d{2}|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|[0-1]\\d{2}|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|[0-1]\\d{2}|[1-9]?\\d)$", ip); !m {
return false
}
return true
}
+8 -6
View File
@@ -8,13 +8,13 @@
package lib
import (
"RedGuard/config"
"RedGuard/core/parameter"
"fmt"
"io/ioutil"
"os"
"os/user"
"RedGuard/config"
"github.com/go-ini/ini"
)
@@ -30,17 +30,19 @@ func InitConfig() *ini.File {
// Check whether loading failed
if err != nil {
logger.Errorf("Fail to read file: %v", err)
goto LOOK
os.Exit(0)
}
// return *ini.File object
return cfg
LOOK:
return nil
}
func CreateConfig(C2Server string) (int, bool) {
func CreateConfig(C2Server string, ConfigPath string) (int, bool) {
currentUser, _ := user.Current() // Current operating system user directory
_ConfigFilename = fmt.Sprintf("%s/.RedGuard_%s.ini", currentUser.HomeDir, C2Server)
// Verify that the configuration file is customized
if file, _ := ioutil.ReadFile(ConfigPath); len(file) != 0 {
_ConfigFilename = ConfigPath // Configuration file using a custom path
}
// Check whether the current operating system user directory configuration file exists
if _, err := os.Stat(_ConfigFilename); err == nil || os.IsExist(err) {
return 0, true