Giter VIP home page Giter VIP logo

wanetty / multievilnovnc Goto Github PK

View Code? Open in Web Editor NEW

This project forked from joelgmsec/evilnovnc

25.0 1.0 5.0 353 KB

Ready to go Phishing Platform

License: GNU General Public License v3.0

Shell 3.01% JavaScript 85.28% Python 2.67% HTML 5.17% Dockerfile 1.19% Go 2.57% Makefile 0.11%
evilnovnc golang nginx phishing evilnginx 2fabypass docker novnc platform multiuser mfa multiserver phishing-tool redteam

multievilnovnc's Introduction

EvilnoVNC

EvilnoVNC

EvilnoVNC is a Ready to go Phishing Platform.

Unlike other phishing techniques, EvilnoVNC allows 2FA bypassing by using a real browser over a noVNC connection.

In addition, this tool allows us to see in real time all of the victim's actions, access to their downloaded files and the entire browser profile, including cookies, saved passwords, browsing history and much more.

Requirements

  • Docker

Installation

It's recommended to clone the complete repository or download the zip file. Additionally, it's necessary to build Docker manually. You can do this by running the following commands:

Auto

git clone https://github.com/wanetty/MultiEvilnoVNC.git
cd EvilnoVNC
make build

Manual

git clone https://github.com/wanetty/MultiEvilnoVNC.git
cd EvilnoVNC ; sudo chown -R 103 Downloads
sudo docker build -f evilnovnc.Dockerfile -t evilnovnc .
sudo docker build -f nginx.Dockerfile -t evilnginx .

Cleanup

If you want to remove the automatically built docker images on your system simply run the following commands.

make clean

Usage MultiServer

./start_auto.sh $url [--no-ddos-protection]

If you want to make it more credible, modify the index.html by adapting the js code.

You will find the cookies and the keylogger output inside the Downloads folder in its corresponding id.

Attention: If you want a guide on how to make it work with HTTPS feel free to visit: https://blog.wanetty.com/blog/tools/multievilnovnc

Last Update (Not More DoS)

In this latest version a system has been added so that in the event that users start to enter in an uncontrolled manner, the system does not break, as before they started to create containers infinitely and this could bring down the server, with the new system that has been created, now the maximum possible containers will be created so that they work with maximum performance.

You can always set it back to the way it worked before, i.e. without restrictions, using the `--no-ddos-protection' flag.

Features & To Do

  • Export Evil-Chromium profile to host
  • Save download files on host
  • Disable parameters in URL (like password)
  • Disable key combinations (like Alt+1 or Ctrl+S)
  • Disable access to Thunar
  • Decrypt cookies in real time
  • Expand cookie life to 99999999999999999
  • Dynamic title from original website

Features added in this project!!

  • Dynamic resolution from preload page
  • Multiple users
  • Basic keylogger
  • Replicate real user-agent and other stuff
  • Anti DoS attack
  • Blacklisting of User Agents
  • Whitelisting of User Agents
  • Any idea...

License

This project is licensed under the GNU 3.0 license - see the LICENSE file for more details.

Credits and Acknowledgments

Original idea by @mrd0x: https://mrd0x.com/bypass-2fa-using-novnc
The base docker has been created by Joel Gámez Molina // @JoelGMSec

Contact

This software does not offer any kind of guarantee. Its use is exclusive for educational environments and / or security audits with the corresponding consent of the client. I am not responsible for its misuse or for any possible damage caused by it.

For more information, you can find me on Twitter as @gm_eduard, and my bog blog.wanetty.com or on @JoelGMSec blog darkbyte.net .

multievilnovnc's People

Contributors

joelgmsec avatar wanetty avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.