Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MysqlT Mysql蜜罐 #15

Closed
BeichenDream opened this issue Jan 29, 2021 · 12 comments
Closed

MysqlT Mysql蜜罐 #15

BeichenDream opened this issue Jan 29, 2021 · 12 comments

Comments

@BeichenDream
Copy link

MysqlT Mysql蜜罐

[MysqlT ]

项目链接

https://github.com/BeichenDream/MysqlT

项目简介

伪造Myslq服务端,并利用Mysql逻辑漏洞来获取客户端的任意文件反击攻击者

项目特点、亮点

该程序利用了Mysql客户端LoadData的逻辑漏洞

与其它软件不同,本软件支持大文件无损传输

支持用户验证

支持自定义Mysql版本

随机的Salt加密,加上用户验证,让攻击者毫无察觉

@LoRexxar
Copy link
Contributor

感觉有点儿意思,就是不能开箱即用,有点儿麻烦

@BeichenDream
Copy link
Author

BeichenDream commented Jan 29, 2021

感觉有点儿意思,就是不能开箱即用,有点儿麻烦

可以开箱即用 设置好账号密码路径之后 输入 mysql run 命令即可开启蜜罐

@LoRexxar
Copy link
Contributor

看上去需要环境编译呀

@BeichenDream
Copy link
Author

看上去需要环境编译呀

在windows是不用编译的开箱即用 在mac os linux 需要安装dotnet环境

@LoRexxar
Copy link
Contributor

我试试看

@BeichenDream
Copy link
Author

我试试看

稍等我发布一个版本 我刚刚看到git上没有编译好的

@BeichenDream
Copy link
Author

我试试看

已发布编译好的 顺便修复了一个bug
https://github.com/BeichenDream/MysqlT/releases/tag/v1.0

@LoRexxar
Copy link
Contributor

嗯哼

@LoRexxar
Copy link
Contributor

感觉文档还可以再完善下,有点儿简单

@BeichenDream
Copy link
Author

BeichenDream commented Jan 29, 2021

感觉文档还可以再完善下,有点儿简单

输入mysql help命令即可看到所有命令的详细用法 这相当于内置的文档
这里是详细是演示及使用教程 https://www.bilibili.com/video/BV1s4411j7po
这个项目在Kcon 2019 兵器谱发布过

@LoRexxar
Copy link
Contributor

LoRexxar commented Feb 2, 2021

嗯嗯,我感觉是,但是查了好多就没搜到,我还以为我记错了

@LoRexxar
Copy link
Contributor

收录入第四期

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants