[{"data":1,"prerenderedAt":1046},["ShallowReactive",2],{"\u002Fblog\u002F2020\u002Flike-a-spy-with-hak5-toys":3,"\u002Fblog\u002F2020\u002Flike-a-spy-with-hak5-toys-surround":1035},{"id":4,"title":5,"author":6,"badge":11,"body":13,"date":1023,"description":1024,"draft":1025,"extension":1026,"image":1027,"meta":1029,"navigation":1030,"path":1031,"seo":1032,"stem":1033,"__hash__":1034},"posts\u002Fblog\u002F2020\u002Flike-a-spy-with-hak5-toys.md","Like A Spy With Hak5 Toys",{"name":7,"to":8,"avatar":9},"Nir Galon","https:\u002F\u002Fx.com\u002Fnirgn975",{"src":10},"\u002Favatar.webp",{"label":12},"hacking",{"type":14,"value":15,"toc":1016},"minimark",[16,33,48,53,56,62,87,90,100,122,131,142,155,164,179,206,213,224,235,272,281,292,311,329,370,381,390,397,406,410,415,418,429,436,449,464,473,484,493,496,514,517,532,538,541,544,551,562,569,587,599,603,608,611,614,623,640,654,673,676,683,696,703,720,724,732,739,771,789,810,836,848,870,876,926,932,967,977,993,1002,1006,1009,1012],[17,18,19,20,27,28,32],"p",{},"One of the things you always see in spy movies is how the main character plants a covert device to monitor the user's computer (screen and keystrokes). As a kid I thought \"This is very cool!\", and I always wanted to be able to do this. ",[21,22,26],"a",{"href":23,"rel":24},"https:\u002F\u002Fhak5.org",[25],"nofollow","Hak5"," makes it very easy to accomplish with a combination of couple of their ",[29,30,31],"del",{},"toys"," tools.",[17,34,35,36,41,42,47],{},"What we'll do is to connect 2 devices, the ",[21,37,40],{"href":38,"rel":39},"https:\u002F\u002Fshop.hak5.org\u002Fproducts\u002Fscreen-crab",[25],"screen crab"," to see the user's screen (video stream, in real time), and a ",[21,43,46],{"href":44,"rel":45},"https:\u002F\u002Fshop.hak5.org\u002Fproducts\u002Fkey-croc",[25],"key croc"," to key log the user's keystrokes.",[49,50,52],"h2",{"id":51},"_1-c2-cloud","1. C2 Cloud",[17,54,55],{},"Before we even start to mess around with the physical toys, let's create a C2 Cloud instance on the cloud. You can do it on your local machine, but let's pretend this is a real operation and in a real environment we don't want the target to connect directly to our machine and we don't want to expose our local machine to the internet.",[57,58,59],"blockquote",{},[17,60,61],{},"Cloud C2 is a self-hosted web-based command and control suite for networked Hak5 gear that lets you pentest from anywhere.",[17,63,64,65,70,71,75,76,81,82,86],{},"I chose to do it in ",[21,66,69],{"href":67,"rel":68},"https:\u002F\u002Fdigitalocean.com",[25],"digitalocean.com"," because they're easy, cheap and I love their community and open source support. So, their VPS called ",[72,73,74],"code",{},"droplets",", after you registered and confirmed your email, you'll see it at the top of the left side menu. When you're at the ",[21,77,80],{"href":78,"rel":79},"https:\u002F\u002Fcloud.digitalocean.com\u002Fdroplets",[25],"droplets page"," you'll have a ",[83,84,85],"em",{},"\"Create Droplet\""," button right at the center of the page (if you don't have any, if you already have some, you'll see it as a green button at the top of the page).",[17,88,89],{},"We'll choose an Ubuntu distribution, a basic plan (shared cpu, the $5\u002Fmonth should do the job), and add a volume (I chose to add 20GB, I think it'll be enough for all the loot). Now you can choose whichever datacenter region you want, and don't forget to add your SSH key.",[17,91,92],{},[93,94],"img",{"alt":95,"className":96,"src":99},"My digital ocean droplet configuration",[97,98],"rounded-lg","mx-auto","\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fdigital-ocean-create-droplet.webp",[17,101,102,103,106,107,112,113,116,117,121],{},"We have two ways to create the C2 instance, use the instance public IP (your droplet will receive one right after it will start) as a ",[72,104,105],{},"hostname"," or use a DNS name. I'll use the DNS name way, so we can add https support with ",[21,108,111],{"href":109,"rel":110},"https:\u002F\u002Fletsencrypt.org",[25],"Let's Encrypt",". If you choose to do this the way I do it, you'll need a domain. I'll use ",[72,114,115],{},"cloud-c2.dev",", and I'll create a custom DNS A record, so ",[21,118,119],{"href":119,"rel":120},"https:\u002F\u002Fcloud-c2.dev",[25]," will point to the instance public IP.",[17,123,124],{},[93,125],{"alt":126,"className":127,"src":128,"height":129,"width":130},"Google Domains custom record",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fgoogle-domains-custom-record.webp",337,1034,[17,132,133,134,137,138,141],{},"You'll need to wait a little (probably couple of hours) to let the DNS propagation to finish, plus ",[21,135,111],{"href":109,"rel":136},[25]," DNS seems to take a little bit longer than the Google ones (keep it in mind in case you encounter ",[72,139,140],{},"TLS handshake error from **** acme\u002Fautocert: missing certificate"," error).",[17,143,144,145,150,151,154],{},"To download the ",[21,146,149],{"href":147,"rel":148},"https:\u002F\u002Fshop.hak5.org\u002Fproducts\u002Fc2#c2-versions",[25],"c2 community edition from hak5"," you need to choose ",[83,152,153],{},"\"FREE DOWNLOAD\""," and then to checkout, at the end of the checkout process you'll get an email with the download link and a license key, save it somewhere safe.",[17,156,157],{},[93,158],{"alt":159,"className":160,"src":161,"height":162,"width":163},"Hak5 C2 Email",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fc2-email.webp",552,944,[17,165,166,167,170,171,174,175,178],{},"Let's finish our droplet setup by opening the relevant ports. Click on the ",[83,168,169],{},"\"Networking\""," tab at the left menu, and from there go to the ",[83,172,173],{},"\"Firewalls\""," page. Click on ",[83,176,177],{},"\"Create Firewall\""," button, give it a name and add a couple of inbound rules:",[180,181,182,190,196],"ul",{},[183,184,185,186,189],"li",{},"Port ",[72,187,188],{},"2022"," so the Hak5 gear will be able to communicate with our C2.",[183,191,185,192,195],{},[72,193,194],{},"443"," so we can open our C2 dashboard in the browser with SSL\u002FTLS.",[183,197,185,198,201,202,205],{},[72,199,200],{},"80"," so ",[21,203,111],{"href":109,"rel":204},[25]," can validate the domain and put back the certificate.",[17,207,208],{},[93,209],{"alt":210,"className":211,"src":212},"My Digital Ocean firewall configuration",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fdigital-ocean-firewall.webp",[17,214,215,216,219,220,223],{},"Don't forget to add our droplet in ",[83,217,218],{},"\"Apply to Droplets\""," input, right before the green ",[83,221,222],{},"\"Create firewall\""," button at the bottom.",[17,225,226,227,230,231,234],{},"Now the fun part begins, let's ssh to our server (replace ",[72,228,229],{},"\u003CDROPLET-IP>"," with your droplet ip, in my case it's ",[72,232,233],{},"165.227.156.17",").",[236,237,243],"pre",{"className":238,"code":239,"filename":240,"language":241,"meta":242,"style":242},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","ssh root@\u003CDROPLET-IP>\n","terminal","bash","",[72,244,245],{"__ignoreMap":242},[246,247,250,254,258,262,265,269],"span",{"class":248,"line":249},"line",1,[246,251,253],{"class":252},"sBMFI","ssh",[246,255,257],{"class":256},"sfazB"," root@",[246,259,261],{"class":260},"sMK4o","\u003C",[246,263,264],{"class":256},"DROPLET-I",[246,266,268],{"class":267},"sTEyZ","P",[246,270,271],{"class":260},">\n",[17,273,274],{},[93,275],{"alt":276,"className":277,"src":278,"height":279,"width":280},"SSH into droplet",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fssh-to-droplet.webp",475,573,[17,282,283,284,287,288,291],{},"And install the ",[72,285,286],{},"unzip"," package so we can unzip the ",[72,289,290],{},"zip"," file we'll download with all the edition for Windows, Mac and Linux of C2 from Hak5.",[236,293,295],{"className":238,"code":294,"filename":240,"language":241,"meta":242,"style":242},"sudo apt install unzip\n",[72,296,297],{"__ignoreMap":242},[246,298,299,302,305,308],{"class":248,"line":249},[246,300,301],{"class":252},"sudo",[246,303,304],{"class":256}," apt",[246,306,307],{"class":256}," install",[246,309,310],{"class":256}," unzip\n",[17,312,313,314,317,318,320,321,324,325,328],{},"Now let's build a command to download the c2 (you can get the download URL from the email), save the file in the name ",[72,315,316],{},"c2.zip",", unzip it, and run the relevant binary for our OS with the ",[72,319,105],{}," point to our domain, and the ",[72,322,323],{},"https"," flag so ",[21,326,111],{"href":109,"rel":327},[25]," will automatically create a certificate for us.",[236,330,332],{"className":238,"code":331,"filename":240,"language":241,"meta":242,"style":242},"wget https:\u002F\u002Fc2.hak5.org\u002Fdownload\u002Fcommunity -O c2.zip && unzip c2.zip && .\u002Fc2_community-linux-64 -hostname cloud-c2.dev -https\n",[72,333,334],{"__ignoreMap":242},[246,335,336,339,342,345,348,351,354,356,358,361,364,367],{"class":248,"line":249},[246,337,338],{"class":252},"wget",[246,340,341],{"class":256}," https:\u002F\u002Fc2.hak5.org\u002Fdownload\u002Fcommunity",[246,343,344],{"class":256}," -O",[246,346,347],{"class":256}," c2.zip",[246,349,350],{"class":260}," &&",[246,352,353],{"class":252}," unzip",[246,355,347],{"class":256},[246,357,350],{"class":260},[246,359,360],{"class":252}," .\u002Fc2_community-linux-64",[246,362,363],{"class":256}," -hostname",[246,365,366],{"class":256}," cloud-c2.dev",[246,368,369],{"class":256}," -https\n",[17,371,372,373,376,377,380],{},"The first time C2 runs, a database file is generated (named ",[72,374,375],{},"c2.db"," by default) in the same directory as the C2 binary. In that first run you'll see it print a ",[83,378,379],{},"\"Setup token\"",", copy it, we'll need it to continue the setup process.",[17,382,383],{},[93,384],{"alt":385,"className":386,"src":387,"height":388,"width":389},"First C2 Run",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fc2-is-running.webp",245,733,[17,391,392,393,396],{},"Now, when we head over to ",[21,394,119],{"href":119,"rel":395},[25]," we can see the initial setup of C2. Now you'll need that setup token that the C2 generated in the first run, and also the license key.",[17,398,399],{},[93,400],{"alt":401,"className":402,"src":403,"height":404,"width":405},"Cloud C2 initial setup",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fcloud-c2-initial-setup.webp",507,566,[49,407,409],{"id":408},"_2-screen-crab","2. Screen Crab",[57,411,412],{},[17,413,414],{},"A stealthy video man-in-the-middle that captures screenshots or videos to disk and streams live to the Internet for remote viewing.",[17,416,417],{},"The Screen Crab, by default, saves photos every couple of seconds to the SD card that you plug in the back of the device. But to get the most out of this device you need to connect it to the Cloud C2 dashboard, then you'll be able to remotely view, configure, and manage the device.",[17,419,420,421,424,425,428],{},"It's quite simple to do this, let's go to the ",[72,422,423],{},"devices"," tab, and then (if you don't have any device enrolled yet), you'll see a big blue button says ",[83,426,427],{},"\"Add Device\"",".",[17,430,431],{},[93,432],{"alt":433,"className":434,"src":435},"Add a new device",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fc2-add-device.webp",[17,437,438,439,442,443,445,446,448],{},"Then, call the device whatever you want, and choose the type, in our case right now it's ",[83,440,441],{},"\"Screen Crab\"",", and click ",[83,444,427],{},". After you did it, you'll see it in the list at the same ",[72,447,423],{}," page, click on it to configure the device.",[17,450,451,452,455,456,459,460,463],{},"At the left side a menu will be opened, click on the ",[83,453,454],{},"\"Setup\""," button and then ",[83,457,458],{},"\"Download\"",", a file named ",[72,461,462],{},"device.config"," will start to be downloaded, copy this file to the root of the Screen Crab SD card.",[17,465,466],{},[93,467],{"alt":468,"className":469,"src":470,"height":471,"width":472},"Screen Crab setup",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fscreen-carb-setup.webp",454,1016,[17,474,475,476,479,480,483],{},"Also, create a file named ",[72,477,478],{},"config.txt"," and in it add the wifi configuration. The first parameter is the network name (SSID), and the second one is the network password. Note that if your network or password contains spaces or special characters you'll need to add a back slash (",[72,481,482],{},"\\",") at the start of each and every one of them.",[485,486,487,490],"ol",{},[183,488,489],{},"WIFI_SSID – the network name",[183,491,492],{},"WIFI_PASS – the WPA-PSK password",[17,494,495],{},"For example:",[236,497,501],{"className":498,"code":499,"filename":478,"language":500,"meta":242,"style":242},"language-txt shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","WIFI_SSID This network\nWIFI_PASS The P@$$word!!\n","txt",[72,502,503,508],{"__ignoreMap":242},[246,504,505],{"class":248,"line":249},[246,506,507],{},"WIFI_SSID This network\n",[246,509,511],{"class":248,"line":510},2,[246,512,513],{},"WIFI_PASS The P@$$word!!\n",[17,515,516],{},"Will be:",[236,518,520],{"className":498,"code":519,"filename":478,"language":500,"meta":242,"style":242},"WIFI_SSID This\\ network\nWIFI_PASS The\\ P\\@\\$\\$word\\!\\!\n",[72,521,522,527],{"__ignoreMap":242},[246,523,524],{"class":248,"line":249},[246,525,526],{},"WIFI_SSID This\\ network\n",[246,528,529],{"class":248,"line":510},[246,530,531],{},"WIFI_PASS The\\ P\\@\\$\\$word\\!\\!\n",[17,533,534,535,537],{},"After you created this file, add it to the root of the SD card that goes into the Screen Crab (together with ",[72,536,462],{},"). In my case I just add the configuration of my home wifi, but in a real environment I would add a simple old android device in the bathroom floor and create an AP from it, or a simple raspberry pi with an expansion card, or even crack the wifi password of that office in advance.",[17,539,540],{},"Now we're ready to connect our device to any HDMI (computer screen, projector, a conference room tv, chromecast, etc). We need to connect the input HDMI to the port in the antenna (and the button) side, and the output (to the screen\u002Ftv\u002Fprojector) to the port on the other side (where the usb-c port located). And finally the usb-c port to a power source.",[17,542,543],{},"After all is connected, we'll see a green light from the LED of the device for about 30 seconds. Then, a cyan color when it's connecting to the wifi, and finally a solid blue color when it has input from the HDMI port. And a couple of seconds after that we can see our Screen Crab is online and connected to our C2.",[17,545,546],{},[93,547],{"alt":548,"className":549,"src":550},"Screen Crab is online",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fscreen-crab-is-online.webp",[17,552,553,554,557,558,561],{},"When we toggle the ",[72,555,556],{},"streaming"," button we'll get the screenshots live and can see everything right as it happens. And if we want to download one of the images to our local machine we have all of them in the ",[83,559,560],{},"\"Loot\""," tab in the left menu.",[17,563,564],{},[93,565],{"alt":566,"className":567,"src":568},"Screen Crab configuration",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fscreen-crab-configuration.webp",[17,570,571,575,576,579,580,582,583,586],{},[572,573],"binding",{"value":574},"\u003C admonition type=bug title=\"Debugging\" open=true >","\nIf you encounter some problems, you can add ",[72,577,578],{},"DEBUG_LOG ON"," as a third line in the ",[72,581,478],{}," file and the Screen Crab will save the logs to a ",[72,584,585],{},"crab.log"," file so you can see what's going on.",[17,588,589,590,592,593,595,596],{},"Another way is to just reset everything by delete all of the files the Screen Crab will create on the SD card (except from the ",[72,591,478],{}," and the ",[72,594,462],{}," that we add earlier).\n",[572,597],{"value":598},"\u003C \u002Fadmonition >",[49,600,602],{"id":601},"_3-key-croc","3. Key Croc",[57,604,605],{},[17,606,607],{},"A keylogger armed with pentest tools, remote access and payloads that trigger multi-vector attacks when chosen keywords are typed.",[17,609,610],{},"The Key Croc is the second part of our spy tool, because we don't want to get just the screen, we want the keystrokes too. And with the Key Croc we can even trigger stuff with it and inject keystrokes to the target computer, but this is out of scope for this post.",[17,612,613],{},"Plug your Key Croc to the computer and click on the hidden key at the back of the device with a sim tool or a paper clip, then the light of the LED will turn off and then turn on with a blue color. This means the device is in arming mode - the device will emulate both a serial device and USB flash disk, so it's easy to just see a new look inside the drive.",[17,615,616],{},[93,617],{"alt":618,"className":619,"src":620,"height":621,"width":622},"The Key Croc drive",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fkey-croc-drive.webp",395,399,[17,624,625,626,629,630,633,634,636,637,639],{},"Let's connect our Key Croc to our C2. Go to the C2 dashboard and add a new device in ",[83,627,628],{},"\"Devices\""," page, choose the ",[83,631,632],{},"\"Key Croc\""," as the device type, and then enter to the device configuration page. From there just hit the ",[83,635,454],{}," button at the left menu and a ",[72,638,462],{}," file will be downloaded, as with the Screen Crab, this file should go to the root directory in the Key Croc.",[17,641,642,643,645,646,649,650,653],{},"And let's add our wifi configuration so it would be able to connect to our C2 server. Like with the Screen Crab we need to edit the ",[72,644,478],{}," file (we already have the file in this case, and there're quite a few comments in there), we'll uncomment the ",[72,647,648],{},"WIFI_SSID"," and ",[72,651,652],{},"WIFI_PASS"," lines and add our wifi configuration there, in the same exact way we did with the Screen Crab, but in this case we have a new option to play with, an ssh one, so we can connect to the Key Croc via ssh and program it on the fly!",[236,655,657],{"className":498,"code":656,"filename":478,"language":500,"meta":242,"style":242},"WIFI_SSID This\\ network\nWIFI_PASS The\\ P\\@\\$\\$word\\!\\!\nSSH ENABLE\n",[72,658,659,663,667],{"__ignoreMap":242},[246,660,661],{"class":248,"line":249},[246,662,526],{},[246,664,665],{"class":248,"line":510},[246,666,531],{},[246,668,670],{"class":248,"line":669},3,[246,671,672],{},"SSH ENABLE\n",[17,674,675],{},"We're ready to connect the device to a test keyboard. When we plug the device in, the LED is white, and once we connect the keyboard dongle to the usb of the Key Croc, the LED is turned off - which says that we're in business. Couple of minutes later and we have a connection to our C2.",[17,677,678],{},[93,679],{"alt":680,"className":681,"src":682},"Key Croc is connected to our C2",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fc2-key-croc-online.webp",[17,684,685,686,689,690,695],{},"In the Key Croc configuration we can see live keystrokes (and the history), enable ",[72,687,688],{},"QUACK"," mode - which enables us to inject keystrokes using the Hak5 Ducky Script, view the payloads on the device and create new ones (Hak5 have a ",[21,691,694],{"href":692,"rel":693},"https:\u002F\u002Fgithub.com\u002Fhak5\u002Fkeycroc-payloads",[25],"repo with all the open source payloads"," people created for the Key Croc with the Ducky Script), and even open an ssh to the device.",[17,697,698],{},[93,699],{"alt":700,"className":701,"src":702},"Key Croc configuration",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fkey-croc-configuration.webp",[17,704,705,706,709,710,713,714,716,717,719],{},"The Key Croc can literally be programmed to ",[72,707,708],{},"match"," keystrokes so every time the user types something we save the next ",[72,711,712],{},"n"," number of keystrokes or even the last ",[72,715,712],{}," number of keystrokes (before the user typed that ",[72,718,708],{}," string\u002Fregex). This is so powerful because now we don't have to filter from so much garbage like we usually need to with keyloggers.",[49,721,723],{"id":722},"_4-cleanup","4. Cleanup",[17,725,726,727,428],{},"Everything is connected and working, but as soon as we leave our Digital Ocean server, our C2 will stop. We need a way to keep it going without connecting to the server and run it manually (it also will stop if we get an error or something similar) - and the right way to accomplish it is with ",[21,728,731],{"href":729,"rel":730},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSystemd",[25],"systemd",[57,733,734],{},[17,735,736,738],{},[72,737,731],{}," is a suite of basic building blocks for a Linux system. It provides a system and service manager that runs as PID 1 and starts the rest of the system.",[17,740,741,742,745,746,749,750,754,755,758,759,762,763,766,767,770],{},"First we're going to move the c2 file to ",[72,743,744],{},"\u002Fusr\u002Flocal\u002Fbin",". Why this directory? Because this is the directory in Linux for programs that a normal user may run. ",[83,747,748],{},"\"usr\""," - ",[751,752,753],"strong",{},"U","NIX ",[751,756,757],{},"S","ystem ",[751,760,761],{},"R","esources, the location that system programs and libraries are stored. ",[83,764,765],{},"\"local\""," - for resources that were not shipped with the standard distribution. ",[83,768,769],{},"\"bin\""," - binary compiled executables.",[236,772,774],{"className":238,"code":773,"filename":240,"language":241,"meta":242,"style":242},"sudo mv c2_community-linux-64 \u002Fusr\u002Flocal\u002Fbin\n",[72,775,776],{"__ignoreMap":242},[246,777,778,780,783,786],{"class":248,"line":249},[246,779,301],{"class":252},[246,781,782],{"class":256}," mv",[246,784,785],{"class":256}," c2_community-linux-64",[246,787,788],{"class":256}," \u002Fusr\u002Flocal\u002Fbin\n",[17,790,791,792,795,796,798,799,801,802,805,806,809],{},"and then create a new directory (in ",[72,793,794],{},"\u002Fvar",") for our database (the ",[72,797,375],{}," file that was automatically created). Why in ",[72,800,794],{},"? Because according to Linux its abbreviation is ",[83,803,804],{},"\"variable\"",", and it should contain things that are prone to changes (such as websites, temporary files (",[72,807,808],{},"\u002Fvar\u002Ftmp",") and databases).",[236,811,813],{"className":238,"code":812,"filename":240,"language":241,"meta":242,"style":242},"sudo mkdir \u002Fvar\u002Fc2\nsudo mv c2.db \u002Fvar\u002Fc2\n",[72,814,815,825],{"__ignoreMap":242},[246,816,817,819,822],{"class":248,"line":249},[246,818,301],{"class":252},[246,820,821],{"class":256}," mkdir",[246,823,824],{"class":256}," \u002Fvar\u002Fc2\n",[246,826,827,829,831,834],{"class":248,"line":510},[246,828,301],{"class":252},[246,830,782],{"class":256},[246,832,833],{"class":256}," c2.db",[246,835,824],{"class":256},[17,837,838,839,841,842,844,845,847],{},"Now we need to create a new ",[72,840,731],{}," service. This is the \"right way\" to keep the process alive once we leave the ssh connection, because this way (with ",[72,843,731],{},") if it crashes the ",[72,846,731],{}," will automatically reboot it and also we can capture the process logs to check what happened.",[236,849,851],{"className":238,"code":850,"filename":240,"language":241,"meta":242,"style":242},"sudo touch \u002Fetc\u002Fsystemd\u002Fsystem\u002Fc2.service\nnano \u002Fetc\u002Fsystemd\u002Fsystem\u002Fc2.service\n",[72,852,853,863],{"__ignoreMap":242},[246,854,855,857,860],{"class":248,"line":249},[246,856,301],{"class":252},[246,858,859],{"class":256}," touch",[246,861,862],{"class":256}," \u002Fetc\u002Fsystemd\u002Fsystem\u002Fc2.service\n",[246,864,865,868],{"class":248,"line":510},[246,866,867],{"class":252},"nano",[246,869,862],{"class":256},[17,871,872,873,875],{},"And paste the text below (change the ",[72,874,115],{}," to your domain name), save and exit nano.",[236,877,879],{"className":498,"code":878,"language":500,"meta":242,"style":242},"[Unit]\nDescription=Cloud C2\nAfter=c2.service\n[Service]\nType=idle\nExecStart=\u002Fusr\u002Flocal\u002Fbin\u002Fc2_community-linux-64 -hostname cloud-c2.dev -https -db \u002Fvar\u002Fc2\u002Fc2.db\n[Install]\nWantedBy=multi-user.target\n",[72,880,881,886,891,896,902,908,914,920],{"__ignoreMap":242},[246,882,883],{"class":248,"line":249},[246,884,885],{},"[Unit]\n",[246,887,888],{"class":248,"line":510},[246,889,890],{},"Description=Cloud C2\n",[246,892,893],{"class":248,"line":669},[246,894,895],{},"After=c2.service\n",[246,897,899],{"class":248,"line":898},4,[246,900,901],{},"[Service]\n",[246,903,905],{"class":248,"line":904},5,[246,906,907],{},"Type=idle\n",[246,909,911],{"class":248,"line":910},6,[246,912,913],{},"ExecStart=\u002Fusr\u002Flocal\u002Fbin\u002Fc2_community-linux-64 -hostname cloud-c2.dev -https -db \u002Fvar\u002Fc2\u002Fc2.db\n",[246,915,917],{"class":248,"line":916},7,[246,918,919],{},"[Install]\n",[246,921,923],{"class":248,"line":922},8,[246,924,925],{},"WantedBy=multi-user.target\n",[17,927,928,929,931],{},"All we have left to do is to reload the ",[72,930,731],{}," daemon, enable the new service we just created (if it's not enabled the service will start and stop only when you write the commands to start and stop it, if it's enabled it'll automatically start when the server is back up), and finally start it.",[236,933,935],{"className":238,"code":934,"filename":240,"language":241,"meta":242,"style":242},"sudo systemctl daemon-reload && systemctl enable c2.service && systemctl start c2.service\n",[72,936,937],{"__ignoreMap":242},[246,938,939,941,944,947,949,951,954,957,959,961,964],{"class":248,"line":249},[246,940,301],{"class":252},[246,942,943],{"class":256}," systemctl",[246,945,946],{"class":256}," daemon-reload",[246,948,350],{"class":260},[246,950,943],{"class":252},[246,952,953],{"class":256}," enable",[246,955,956],{"class":256}," c2.service",[246,958,350],{"class":260},[246,960,943],{"class":252},[246,962,963],{"class":256}," start",[246,965,966],{"class":256}," c2.service\n",[17,968,969,970,973,974,428],{},"You can check the status of the service we created with the ",[72,971,972],{},"status"," command of ",[72,975,976],{},"systemctl",[236,978,980],{"className":238,"code":979,"filename":240,"language":241,"meta":242,"style":242},"sudo systemctl status c2.service\n",[72,981,982],{"__ignoreMap":242},[246,983,984,986,988,991],{"class":248,"line":249},[246,985,301],{"class":252},[246,987,943],{"class":256},[246,989,990],{"class":256}," status",[246,992,966],{"class":256},[17,994,995],{},[93,996],{"alt":997,"className":998,"src":999,"height":1000,"width":1001},"systemd service runs our c2 successfully",[97,98],"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fsystemd-service-running.webp",218,762,[49,1003,1005],{"id":1004},"_5-summary","5. Summary",[17,1007,1008],{},"That's it, we are spies now 😂 . Everywhere we go we can implant those devices and see and read what's going on, even insert some keystrokes and cause mayhem. In the right time and the right place, it can be very valuable. But we're just playing around here and learning new stuff, because it's fun and cool.",[17,1010,1011],{},"I don't know about you, but I had a really fun time playing Q (from James Bond) for a day.",[1013,1014,1015],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":242,"searchDepth":510,"depth":510,"links":1017},[1018,1019,1020,1021,1022],{"id":51,"depth":510,"text":52},{"id":408,"depth":510,"text":409},{"id":601,"depth":510,"text":602},{"id":722,"depth":510,"text":723},{"id":1004,"depth":510,"text":1005},"2020-10-01","Using Hak5's Screen Crab and Key Croc to remotely spy on a screen.",false,"md",{"src":1028},"\u002Fposts\u002F2020\u002Flike-a-spy-with-hak5-toys\u002Fspy-cover.webp",{},true,"\u002Fblog\u002F2020\u002Flike-a-spy-with-hak5-toys",{"title":5,"description":1024},"blog\u002F2020\u002Flike-a-spy-with-hak5-toys","qsoPpd9rQOB1LjX5s3WNRepIAov6kOmL3pzqONgCSGY",[1036,1041],{"title":1037,"path":1038,"stem":1039,"description":1040,"children":-1},"Jekyll Starter Kit generator 3.x.x","\u002Fblog\u002F2020\u002Fjekyll-starter-kit-generator-3.x.x","blog\u002F2020\u002Fjekyll-starter-kit-generator-3.x.x","The Jekyll Starter Kit generator jumps to version 3.x.x after Jekyll 4.",{"title":1042,"path":1043,"stem":1044,"description":1045,"children":-1},"New design for the blog!","\u002Fblog\u002F2020\u002Fnew-design-for-the-blog","blog\u002F2020\u002Fnew-design-for-the-blog","Unveiling the blog's fifth redesign, with dark mode and privacy-friendly tooling.",1786001638688]