<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>rats Archives - Tech Chronicles</title>
	<atom:link href="http://kostacipo.stream/tag/rats/feed/" rel="self" type="application/rss+xml" />
	<link>https://kostacipo.stream/tag/rats/</link>
	<description>Ramblings of a Tech Dude</description>
	<lastBuildDate>Mon, 28 Dec 2020 19:16:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>

<image>
	<url>https://kostacipo.stream/wp-content/uploads/2019/12/cropped-profile-32x32.jpg</url>
	<title>rats Archives - Tech Chronicles</title>
	<link>https://kostacipo.stream/tag/rats/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>ToRat: A Remote Administration Tool Written in GO Using Tor as a Transport Mechanism &#038; RPC for Communication</title>
		<link>http://kostacipo.stream/torat-a-remote-administration-tool-written-in-go-using-tor-as-a-transport-mechanism-rpc-for-communication/</link>
					<comments>http://kostacipo.stream/torat-a-remote-administration-tool-written-in-go-using-tor-as-a-transport-mechanism-rpc-for-communication/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Mon, 28 Dec 2020 19:16:38 +0000</pubDate>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[rats]]></category>
		<guid isPermaLink="false">http://kostacipo.stream/?p=1997</guid>

					<description><![CDATA[<p>ToRat is a Cross Platform Remote Administration tool written in Go using Tor as its transport mechanism currently supporting Windows, Linux, MacOS clients. How to? git clone https://github.com/lu4p/ToRat.git cd ./ToRat sudo docker build . -t torat sudo docker run -it -v “$(pwd)”/dist:/dist_ext torat Prerequisites Install Docker on Linux ubuntu https://docs.docker.com/install/linux/docker-ce/ubuntu/ debian https://docs.docker.com/install/linux/docker-ce/debian/ fedora https://docs.docker.com/install/linux/docker-ce/fedora/ centos [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/torat-a-remote-administration-tool-written-in-go-using-tor-as-a-transport-mechanism-rpc-for-communication/">ToRat: A Remote Administration Tool Written in GO Using Tor as a Transport Mechanism &#038; RPC for Communication</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>ToRat</strong> is a Cross Platform Remote Administration tool written in Go using Tor as its transport mechanism currently supporting Windows, Linux, MacOS clients.</p>
<p class="has-text-align-center has-vivid-green-cyan-background-color has-background"><strong>How to?</strong></p>
<p class="has-vivid-green-cyan-color has-black-background-color has-text-color has-background"><strong>git clone https://github.com/lu4p/ToRat.git<br />
cd ./ToRat<br />
sudo docker build . -t torat<br />
sudo docker run -it -v “$(pwd)”/dist:/dist_ext torat </strong></p>
<p class="has-text-align-center has-vivid-green-cyan-background-color has-background"><strong>Prerequisites</strong></p>
<ul>
<li>Install Docker on Linux
<ul>
<li>ubuntu <a href="https://docs.docker.com/install/linux/docker-ce/ubuntu/">https://docs.docker.com/install/linux/docker-ce/ubuntu/</a></li>
<li>debian <a href="https://docs.docker.com/install/linux/docker-ce/debian/">https://docs.docker.com/install/linux/docker-ce/debian/</a></li>
<li>fedora <a href="https://docs.docker.com/install/linux/docker-ce/fedora/">https://docs.docker.com/install/linux/docker-ce/fedora/</a></li>
<li>centos <a href="https://docs.docker.com/install/linux/docker-ce/centos/">https://docs.docker.com/install/linux/docker-ce/centos/</a></li>
<li>arch <code>sudo pacman -s docker</code></li>
</ul>
</li>
</ul>
<p class="has-text-align-center has-vivid-green-cyan-background-color has-background"><strong>Install</strong></p>
<ul>
<li>Clone this repo via git</li>
</ul>
<p class="has-vivid-green-cyan-color has-black-background-color has-text-color has-background"><strong>git clone https://github.com/lu4p/ToRat.git </strong></p>
<ul>
<li>Change Directory to ToRat</li>
</ul>
<p class="has-vivid-green-cyan-color has-black-background-color has-text-color has-background"><strong>cd ./ToRat </strong></p>
<ul>
<li>Build the ToRat Docker Container</li>
</ul>
<ul>
<li>you need to build a part of the container yourself to get a own onion address and certificate all prerequisites are met by the prebuilt torat-pre image in other to make quick build times possible</li>
</ul>
<p class="has-vivid-green-cyan-color has-black-background-color has-text-color has-background"><strong>sudo docker build . -t torat </strong></p>
<ul>
<li>Run the container
<ul>
<li>will drop directly into the ToRat Server shell</li>
<li>the -v flag copies the compiled binaries to the host file system</li>
<li>to connect a machine to the server shell just run one of the client binaries on another system</li>
</ul>
</li>
</ul>
<p class="has-vivid-green-cyan-color has-black-background-color has-text-color has-background"><strong>sudo docker run -it -v “$(pwd)”/dist:/dist_ext torat </strong></p>
<ul>
<li>In another shell run the client.</li>
</ul>
<p class="has-vivid-green-cyan-color has-black-background-color has-text-color has-background"><strong>sudo chown $USER dist/ -R<br />
cd dist/dist/client/<br />
./client_linux </strong></p>
<ul>
<li>See the client connect</li>
</ul>
<p>In your Server shell you should now see something like <code>[+] New Client H9H2FHFuvUs9Jz8U connected!</code> You can now select this client by running <code>select</code> in the Server Shell which will give you a nice interactive chooser for the client you want to connect to. After you choose a client you drop in an interactive shell on the client system.</p>
<p class="has-text-align-center has-vivid-green-cyan-background-color has-background"><strong>Notes</strong></p>
<p>Contents of <code>ToRat/dist</code> after docker run</p>
<pre class="wp-block-code"><code>$ find ./dist
./dist/
./dist/dist
./dist/dist/client
./dist/dist/client/client_linux                   # linux client binary
./dist/dist/client/client_windows.exe             # windows client binary
./dist/dist/server
./dist/dist/server/key.pem                              # tls private-key
./dist/dist/server/banner.txt                           # banner
./dist/dist/server/cert.pem                             # tls cert
./dist/dist/server/ToRat_server                         # linux server binary
</code></pre>
<p class="has-text-align-center has-vivid-green-cyan-background-color has-background"><strong>Current Features</strong></p>
<ul>
<li>RPC (Remote procedure Call) based communication for easy addition of new functionallity</li>
<li>Automatic upx leads to client binaries of ~6MB with embedded Tor</li>
<li>the ToRAT_client communicates over TLS encrypted RPC proxied through Tor with the ToRat_server (hidden service)
<ul>
<li>anonymity of client and server</li>
<li>end-to-end encryption</li>
</ul>
</li>
<li>Cross Platform reverse shell (Windows, Linux, Mac OS)</li>
<li>Windows:
<ul>
<li>Multiple User Account Control Bypasses (Privilege escalation)</li>
<li>Multiple Persistence methods (User, Admin)</li>
</ul>
</li>
<li>Linux:
<ul>
<li>Multiple Persistence methods (User, Admin)</li>
</ul>
</li>
<li>optional transport without Tor e.g. Use Tor2Web, a DNS Hostname or public/ local IP
<ul>
<li>smaller binary ~7MB upx’ed</li>
<li>anonymity of client and server</li>
</ul>
</li>
<li>embedded Tor</li>
<li>Unique persistent ID for every client
<ul>
<li>give a client an Alias</li>
<li>all Downloads from client get saved to ./$ID/$filename</li>
</ul>
</li>
<li>sqlite via gorm for storing information about the clients</li>
<li>client is obfuscated via <a href="https://github.com/burrowers/garble">garble</a></li>
</ul>
<p class="has-text-align-center has-vivid-green-cyan-background-color has-background"><strong>Server Shell</strong></p>
<ul>
<li>Supports multiple connections</li>
<li>Welcome Banner</li>
<li>Colored Output</li>
<li>Tab-Completion of:
<ul>
<li>Commands</li>
<li>Files/ Directories in the working directory of the server</li>
</ul>
</li>
</ul>
<figure class="wp-block-table">
<table>
<thead>
<tr>
<th>Command</th>
<th>Info</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>select</strong></td>
<td>Select client to interact with</td>
</tr>
<tr>
<td><strong>list</strong></td>
<td>list all connected clients</td>
</tr>
<tr>
<td><strong>alias</strong></td>
<td>Select client to give an alias</td>
</tr>
<tr>
<td><strong>cd</strong></td>
<td>change the working directory of the server</td>
</tr>
<tr>
<td><strong>help</strong></td>
<td>lists possible commands with usage info</td>
</tr>
<tr>
<td><strong>exit</strong></td>
<td>exit the server</td>
</tr>
</tbody>
</table>
</figure>
<p class="has-light-green-cyan-background-color has-background"><strong>Shell after selection of a client</strong></p>
<ul>
<li>Tab-Completion of:
<ul>
<li>Commands</li>
<li>Files/ Directories in the working directory of the client</li>
</ul>
</li>
</ul>
<figure class="wp-block-table">
<table>
<thead>
<tr>
<th>Command</th>
<th>Info</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>cd</strong></td>
<td>change the working directory of the client</td>
</tr>
<tr>
<td><strong>ls</strong></td>
<td>list the content of the working directory of the client</td>
</tr>
<tr>
<td><strong>shred</strong></td>
<td>delete files/ directories unrecoverable</td>
</tr>
<tr>
<td><strong>shredremove</strong></td>
<td>same as shred + removes the shredded files</td>
</tr>
<tr>
<td><strong>screen</strong></td>
<td>take a Screenshot of the client</td>
</tr>
<tr>
<td><strong>cat</strong></td>
<td>view Textfiles from the client including .docx, .rtf, .pdf, .odt</td>
</tr>
<tr>
<td><strong>alias</strong></td>
<td>give the client a custom alias</td>
</tr>
<tr>
<td><strong>down</strong></td>
<td>download a file from the client</td>
</tr>
<tr>
<td><strong>up</strong></td>
<td>upload a file to the client</td>
</tr>
<tr>
<td><strong>escape</strong></td>
<td>escape a command and run it in a native shell on the client</td>
</tr>
<tr>
<td><strong>reconnect</strong></td>
<td>tell the client to reconnect</td>
</tr>
<tr>
<td><strong>help</strong></td>
<td>lists possible commands with usage info</td>
</tr>
<tr>
<td><strong>exit</strong></td>
<td>background current session and return to main shell</td>
</tr>
<tr>
<td>else</td>
<td>the command will be executed in a native shell on the client</td>
</tr>
</tbody>
</table>
</figure>
<p class="has-text-align-center has-vivid-green-cyan-background-color has-background"><strong>Upcoming Features</strong></p>
<ul>
<li>Privilege escalation for Linux</li>
<li>Persistence and privilege escalation for Mac OS</li>
<li>Support for Android and iOS needs fix of <a href="https://github.com/ipsn/go-libtor/issues/12">https://github.com/ipsn/go-libtor/issues/12</a></li>
<li><a href="https://github.com/ewhitehats/InvisiblePersistence">File-less Persistence on Windows</a></li>
</ul>
<p class="has-text-align-center has-vivid-green-cyan-background-color has-background"><strong>Preview</strong></p>
<p><a href="https://asciinema.org/a/318534" target="_blank" rel="noopener noreferrer"><img decoding="async" class="td-animation-stack-type0-2" src="https://asciinema.org/a/318534.svg" data-large_image_width="3220.7023026315787" data-large_image_height="1903"></a></p>
<div class="wp-block-buttons aligncenter">
<div class="wp-block-button is-style-outline"><a class="wp-block-button__link has-vivid-cyan-blue-background-color has-background" href="https://github.com/lu4p/ToRat" target="_blank" rel="noreferrer noopener"><strong>Download</strong></a></div>
</div>
<p>The post <a href="http://kostacipo.stream/torat-a-remote-administration-tool-written-in-go-using-tor-as-a-transport-mechanism-rpc-for-communication/">ToRat: A Remote Administration Tool Written in GO Using Tor as a Transport Mechanism &#038; RPC for Communication</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/torat-a-remote-administration-tool-written-in-go-using-tor-as-a-transport-mechanism-rpc-for-communication/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
