Giter VIP home page Giter VIP logo

dogcs4.4's Introduction

Typing SVG

Hey 👋 What's up?

这是一个学习安全的菜鸡脚本小子.欢迎多多交流学习.

About me

✨ Golang.
📚 Game....
🎯 Vme50...
🎲 Sleep...
And 巴拉巴拉一堆.

How to Contact Me?

WeChat: WebDemoSec
Email: [email protected]
Blog: https://www.nctry.com

stats graph languages graph

I code with

java logo javascript logo go logo python logo nginx logo html5 logo

Commits.

dogcs4.4's People

Contributors

trygotry avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

dogcs4.4's Issues

修复dogcs 无法下载x64位stager shellcode 和Processes Browser beacon进程高亮显示问题

x64 Stager shellcode无法下载原因:

CommonUtilsMSFURI_X64的方法直接默认返回DogCsDogCsDogCs.jsWebServerisStagerX64方法进行checksum8uri.matches("/[A-Za-z0-9]{5}")验证
之所以x64 stager无法下载就是出在uri.matches结果为false

image
image
image

修复只要把uri.matches删掉就可以了

image

成功下载x64 stager shellcode

image

成功上线

image

Processes Browser 显示不出beacon进程高亮的问题

image

可以看到beacon进程因为主题的原因显示不了原来的黄色高亮

修改Processes中getNewRenderer方法, 在不点击beacon进程的时候, 前景色为红色

image

可以看到beacon进程默认是红色显示了

image

师傅有点bug啊 java.io.EOFException

java.io.EOFException
at java.base/java.io.DataInputStream.readInt(DataInputStream.java:397)
at ssl.SecureSocket.authenticate(SecureSocket.java:77)
at aggressor.browsers.Connect.dialogAction(Connect.java:119)
at dialog.DialogManager$2$1.run(Unknown Source)
at java.base/java.lang.Thread.run(Thread.java:834)

powershell服务起不来

Attacks----Web Drive-by ----Scripted web Delivery(S) 32/64都起不来 看了下服务端也没报错 不知道什么情况

切换输入法闪退,稳定复现

Nice project!

然而发现一个闪退的情况:切换到其他 App,然后切换到中文输入法会闪退,或许是 Monterey 的原因?

$ java -version
java version "11.0.13" 2021-10-19 LTS
Java(TM) SE Runtime Environment 18.9 (build 11.0.13+10-LTS-370)
Java HotSpot(TM) 64-Bit Server VM 18.9 (build 11.0.13+10-LTS-370, mixed mode)

系统版本:macOS Monterey 12.4

Screenshot2022-07-28 16 17 45

vnc问题

大佬,这个vnc桌面无法开启开启就报vnc server connection is not responding,这是为啥,如何修复

Cobalt Strike团队服务器不可用

连接错误?读取超时退出指定主机和端口上的Cobalt Strike团队服务器不可用。你必须先启动一个Cobalt Strike团队服务器。您想尝试其他连接吗?是(Y)否(N)

修复Hashdump Mimikatz execute-assembly 等功能inject时问题

起因突然发现使用Hashdump 在x86 进程下无法使用

报了一个an x86 process (can't inject x64 content) 错误, 难道x86进程使用的是x64位反射dll?

image

答案是确实是这样的, 主要原因还是出在BeaconEntry中的is64()方法, 这个方法判断是当前主机是否是x64的

可以看到当前进程arch是x86, is64确为true

image

所以解决方法显而易见, 传入inject方法的arch直接用arch()获取

image

我发现还影响Mimikatz execute-assembly powerpick , 如上修复即可

image
image

有趣的是portscan确用的arch()获取, 应该不是同一个开发写的

image

现在在x86进程上没有报错了, 但是确无法dump hash, 这可能是hashdump x86反射dll问题吧........

image

ssh 连接报错

用了一段时间,很多功能很赞,非常喜欢!!🚀🚀

但是发现 DogCS 调用 sshssh-key 连接 linux 机器有报错: Could not connect to pipe: 2
使用原版 CS 可正常连接,作者大大帮忙看看这个问题?感恩感恩 🙏

@TryGOTry

64位木马运行的时候向c2请求payload返回404

请教大佬:
利用profile文件自定义http-stager,可以发一个profile模板吗?
配置了C2 profile,但是不知道http-stager这里具体怎么写,set uri_x86 “***”,这里面的地址填写哪里呢

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.