ycoya/laravel-telnet-brute-force 问题修复 & 功能扩展

解决BUG、新增功能、兼容多环境部署,快速响应你的开发需求

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

ycoya/laravel-telnet-brute-force

Composer 安装命令:

composer require ycoya/laravel-telnet-brute-force

包简介

A package to brute force a telnet connection

README 文档

README

Recovering password from telnet service by using brute force.

This was made to meet my own needs, it is not expected to be used in a real web application. This was more to learn and practice to build packages. If someone needs it, well here it is.

This package contains two artisan console command which will run the brute force attack.

One command will use an users and passwords lists from files and the other one generate the passwords internally.

It is important to say, that the steps used to determine that we succeed in guessing the password is by checking we do not receive the ´login´ back from the telnet reply. This way we could have a $, #, or C:> as prompt. So this is for those cases where we do not know what we will see when we log in. We could have false positive too. I'm not responsible if someone use this in a wrong way.

Installation

  composer require ycoya/laravel-telnet-brute-force

Requirements

php 8.0+

Documentation

Brute Force With Dictionary

php artisan telnet:attack-dict --host=127.0.0.1 
--userDb=utils/users.txt --passDb=utils/passwords.txt

To receive help from command, just type

 php artisan help telnet:attack-dict

The host option will define the machine target. The options --userDB and --passDb are the path from where the users and passwords will be taken.

The procedure is: first user is selected and then this user is tested through all the passwords from password.txt, if nothing is found, then it will take the second user, and it repeats the same procedure. We can also type a full path for example:

--userDb=C:\brute-force\dictionary\utils\users.txt

same for

--passDb=C:\brute-force\dictionary\utils\passwords.txt

Or it could be relative to the laravel application root folder. like this:

--userDb=utils/users.txt

If this file is not found in this path, then it will try to search in storage/app folder. There are three options then:

1-full path

2-relative path to laravel root folder

3-relative path to (laravel_root_folder)/storage/app.

The files should have the structure of one string by line. Example:

In users.txt, we could have.

root

john

juan

...

In passwords.txt, we could have.

admin

password

1234

...

This command saves the index of current user and password from users and password list used. If the command is interrupted or we stop it for any reason we could resume from where we left of automatically.

Brute Force With Password Generation

php artisan telnet:attack-gp --host=172.0.0.1 --user=root
 -m CharMap.txt --min=1 --max=5

The host option will define the machine target.

--user option is the user that will be use with all the password generated.

-m|char_map_path is the path to the file where we will obtain the chars to generate the passwords

This is the same as before, char_map_path could contain:

1-full path

2-relative path to laravel root folder

3-relative path to (laravel_root_folder)/storage/app.

The structure for the charMap is an array:

charMap.txt

["a","b","c","d","e","f","g","h","i","j","k","l","m",
"n","o","p","q","r","s","t","u","v","w","x","y","z"]

The commmand will use these chars to compose the password.

--min option is to set the start length of the password to compose.

--max option is to set the final lenght of the password to compose.

From the above example we will get passwords from one length, when all chars are passed, then it will move to generate password of two lengths, using the charMap combining. Example: aa, ab, ac...etc, when this finishes then it will use a password of lenght 3, and so on until the max value For this example it is five. length 5.

If we only want to use specific length, let's say a password of 4 chars to test all combinations. Then we can pass as options

php artisan telnet-attack-gp --min=4 --max=4

The same value for both options.

If we pass --max value only then we will have password length from 1 to this max value, So in the example above we could omit --min=value any combinations of these we could use.

There is a --debug option that will output to laravel.log more info if needed, but it won't display it in console.

This command is saving the progress of the generated password and the times used to generate it. So if the command is interrupted or we stop it for any reason we could resume from where we left of automatically.

If we need to restart again then the --reset option is the one for this.

This progress is saved in storage/app/telnet-brute-force-gp folder. These are the basics. For additional help run:

php artisan help telnet:attack-dict

or

php artisan help telnet:attack-gp 

for futher options.

ycoya/laravel-telnet-brute-force 适用场景与选型建议

ycoya/laravel-telnet-brute-force 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 24 次下载、GitHub Stars 达 2, 最近一次更新时间为 2022 年 12 月 28 日, 在 PHP 生态内属于活跃度较高的组件。

它主要适用于以下技术方向: 「php」 「laravel」 「telnet」 「brute force attack」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。

我们在过去多个企业项目中使用过 ycoya/laravel-telnet-brute-force 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。

围绕 ycoya/laravel-telnet-brute-force 我们能提供哪些服务?
定制开发 / 二次开发

基于 ycoya/laravel-telnet-brute-force 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。

BUG 修复 & 性能优化

线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。

项目外包 & 长期维护

承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。

yvsm@zunyunkeji.com QQ:316430983 微信:yvsm316 西安尊云信息科技 · 专注 PHP / Go / 分布式系统研发

统计信息

  • 总下载量: 24
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 2
  • 点击次数: 11
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 2
  • Watchers: 1
  • Forks: 0
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2022-12-28