<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=MReiss</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=MReiss"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/MReiss"/>
	<updated>2026-09-10T15:30:52Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5985</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5985"/>
		<updated>2021-02-09T22:29:34Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Key_Stroke_Injection&amp;diff=5984</id>
		<title>Key Stroke Injection</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Key_Stroke_Injection&amp;diff=5984"/>
		<updated>2021-02-09T22:20:02Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Bash Bunny */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This document describes Keystroke Injection and it&#039;s different usecases. It lists a selection of tools and how to protect a system against such attacks. &lt;br /&gt;
&lt;br /&gt;
Keystroke Injection describes the act of simulating keystrokes by a real person. In fact the keystrokes are generated by a script or other software. Thus wantet and unwanted inputs can be entered very fast. This works over the HID protocol (human interface device), with which every common keyboard works. Because computers trust human input in the form of keystrokes.&lt;br /&gt;
&lt;br /&gt;
To show the actual danger by Keystroke Injection attacks, mostly done with rogue USB flash drives, the paper [https://ieeexplore.ieee.org/document/7546509 Users Really Do Plug in USB Drives They Find] got published on IEEE in May 2016. It shows that 45-98% of the users plug in a found USB flash drive, mostly with the intention to find the drive&#039;s owner.&lt;br /&gt;
&lt;br /&gt;
== Usage ==&lt;br /&gt;
The ability to type over 9000 characters per minute opens a few use cases. Ethical correct ones and also not. Beside the probably best-known use as attack vector, also the automation of tasks benefits from this feature.&lt;br /&gt;
&lt;br /&gt;
==== Automation ====&lt;br /&gt;
Even simple tasks like adding network shares or printers are much faster over commandline than over a GUI. Maybe these could also be typed manually, the benefit kicks in thinking of larger scripts to be automatically executed on single computers.&lt;br /&gt;
&lt;br /&gt;
==== Penetration Testing ====&lt;br /&gt;
Penetration Testing is more or less the same use case as Hacking but with another purpose. Instead of really attacking a system you show and document open vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
==== Hacking ====&lt;br /&gt;
The most famous use case for Keystroke Injection is to attack systems over command line. With the command line all sorts of attacks are possible. From running a simple script, over downloading and running an exe file, up to opening a reverse shell and many more. Attackers can just collect valuable informations or exploit the access. Enough examples can be found online.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
[[File:Usb-rubber-ducky.jpg|thumb|right|150px|Rubber Ducky]]&lt;br /&gt;
There are a few different hardware tools, mostly disguised as simple USB falsh drives, also called BadUSB. They are in some sort programmable or loadable with a specific payload to execute.&lt;br /&gt;
&lt;br /&gt;
==== Rubber Ducky ====&lt;br /&gt;
A well known example is the USB Rubberducky. A detailed description is available in the Elvis Wiki: [[Hak5 Rubber Ducky]].&lt;br /&gt;
[[File:KSI_pocketadmin.jpg|thumb|right|150px|Pocket Admin]]&lt;br /&gt;
&lt;br /&gt;
==== Pocket Admin ====&lt;br /&gt;
Pocket Admin is an open source variant of Rubber Ducky to build by yourself. It states that it&#039;s cheaper and that it has a extended functionality. The projects description and manual can be found [https://www.electronics-lab.com/project/pocketadmin-keystroke-injection-device/ here].&lt;br /&gt;
[[File:Usbninja.png|thumb|right|150px|USB Ninja]]&lt;br /&gt;
&lt;br /&gt;
==== USB Ninja ====&lt;br /&gt;
USB Ninja is a more expensive variant of BadUSB. It features different modules lika a bluetooth expansion and can also be built into normal keyboards. An overview is available [https://usbninja.com/ here].&lt;br /&gt;
[[File:Rubberbunny.png|thumb|right|150px|Bash Bunny]]&lt;br /&gt;
&lt;br /&gt;
==== Bash Bunny ====&lt;br /&gt;
Bash Bunny is something like Rubber Duckys big brother. Its more expensive but also offers more tools like nmap, responder, impacket and metasploit, additional to the known Ducky Script. It&#039;s a small Linux machine on a USB drive mimicking multiple trusted devices. A full description can be found in the articel [[Hak5 Bash Bunny]].&lt;br /&gt;
&lt;br /&gt;
==== Standard Hardware ====&lt;br /&gt;
An emerging trend is to not use special hardware, but to built in keystroke injection hardware/software in common peripheral devices. Imagine a standard HP office mouse, nobody would expect any threat from it. Examples and manuals can be found online.&lt;br /&gt;
&lt;br /&gt;
== Possible Protections ==&lt;br /&gt;
&lt;br /&gt;
=== Linux ===&lt;br /&gt;
Google published a tool called &amp;quot;USB Keystroke Injection Protection&amp;quot; which runs as daemon and blocks badUSBs. A full [https://opensource.googleblog.com/2020/03/usb-keystroke-injection-protection.html description] and [https://github.com/google/ukip#installation-prerequisites installation guide] are available online.&lt;br /&gt;
&lt;br /&gt;
An other tool is [https://usbguard.github.io/ USB Guard]. It&#039;s an open source software project in which you can write own USB device authorization policies.&lt;br /&gt;
&lt;br /&gt;
=== Windows ===&lt;br /&gt;
&lt;br /&gt;
The probably best protection against Keystroke Injection, is to block all unknwon USB devices and allow specific known devices only. This can be achieved by Group Policies by denying installation of removeable devices and only allow devices with a specific serial ID. But this approach has two disadvantages. Thinking of enterprise solutions, it&#039;s a very high effort to allow the good devices and also the serial ID can be faked or surpressed by such attacking devices. &lt;br /&gt;
&lt;br /&gt;
A possible software solution is surprisingly [https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection Windows Defender ATP], an enterprise endpoint security platform.  &lt;br /&gt;
&lt;br /&gt;
A open source solution would be [http://konukoii.com/blog/2016/10/26/duckhunting-stopping-automated-keystroke-injection-attacks/ Duckhunt]. This script rezognizes the average typing speed and blocks key strokes that are too fast. It even has a &amp;quot;Sneaky&amp;quot; mode to not let the attacker know, his attack has been blocked.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* M. Tischer et al., &amp;quot;Users Really Do Plug in USB Drives They Find,&amp;quot; 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, 2016, pp. 306-319, doi: 10.1109/SP.2016.26.&lt;br /&gt;
* https://www.electronics-lab.com/project/pocketadmin-keystroke-injection-device/&lt;br /&gt;
* https://usbninja.com/&lt;br /&gt;
* https://shop.hak5.org/&lt;br /&gt;
* https://github.com/google/ukip#installation-prerequisites&lt;br /&gt;
* https://opensource.googleblog.com/2020/03/usb-keystroke-injection-protection.html&lt;br /&gt;
* https://usbguard.github.io/&lt;br /&gt;
* https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Key_Stroke_Injection&amp;diff=5983</id>
		<title>Key Stroke Injection</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Key_Stroke_Injection&amp;diff=5983"/>
		<updated>2021-02-09T22:19:00Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Rubber Ducky */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This document describes Keystroke Injection and it&#039;s different usecases. It lists a selection of tools and how to protect a system against such attacks. &lt;br /&gt;
&lt;br /&gt;
Keystroke Injection describes the act of simulating keystrokes by a real person. In fact the keystrokes are generated by a script or other software. Thus wantet and unwanted inputs can be entered very fast. This works over the HID protocol (human interface device), with which every common keyboard works. Because computers trust human input in the form of keystrokes.&lt;br /&gt;
&lt;br /&gt;
To show the actual danger by Keystroke Injection attacks, mostly done with rogue USB flash drives, the paper [https://ieeexplore.ieee.org/document/7546509 Users Really Do Plug in USB Drives They Find] got published on IEEE in May 2016. It shows that 45-98% of the users plug in a found USB flash drive, mostly with the intention to find the drive&#039;s owner.&lt;br /&gt;
&lt;br /&gt;
== Usage ==&lt;br /&gt;
The ability to type over 9000 characters per minute opens a few use cases. Ethical correct ones and also not. Beside the probably best-known use as attack vector, also the automation of tasks benefits from this feature.&lt;br /&gt;
&lt;br /&gt;
==== Automation ====&lt;br /&gt;
Even simple tasks like adding network shares or printers are much faster over commandline than over a GUI. Maybe these could also be typed manually, the benefit kicks in thinking of larger scripts to be automatically executed on single computers.&lt;br /&gt;
&lt;br /&gt;
==== Penetration Testing ====&lt;br /&gt;
Penetration Testing is more or less the same use case as Hacking but with another purpose. Instead of really attacking a system you show and document open vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
==== Hacking ====&lt;br /&gt;
The most famous use case for Keystroke Injection is to attack systems over command line. With the command line all sorts of attacks are possible. From running a simple script, over downloading and running an exe file, up to opening a reverse shell and many more. Attackers can just collect valuable informations or exploit the access. Enough examples can be found online.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
[[File:Usb-rubber-ducky.jpg|thumb|right|150px|Rubber Ducky]]&lt;br /&gt;
There are a few different hardware tools, mostly disguised as simple USB falsh drives, also called BadUSB. They are in some sort programmable or loadable with a specific payload to execute.&lt;br /&gt;
&lt;br /&gt;
==== Rubber Ducky ====&lt;br /&gt;
A well known example is the USB Rubberducky. A detailed description is available in the Elvis Wiki: [[Hak5 Rubber Ducky]].&lt;br /&gt;
[[File:KSI_pocketadmin.jpg|thumb|right|150px|Pocket Admin]]&lt;br /&gt;
&lt;br /&gt;
==== Pocket Admin ====&lt;br /&gt;
Pocket Admin is an open source variant of Rubber Ducky to build by yourself. It states that it&#039;s cheaper and that it has a extended functionality. The projects description and manual can be found [https://www.electronics-lab.com/project/pocketadmin-keystroke-injection-device/ here].&lt;br /&gt;
[[File:Usbninja.png|thumb|right|150px|USB Ninja]]&lt;br /&gt;
&lt;br /&gt;
==== USB Ninja ====&lt;br /&gt;
USB Ninja is a more expensive variant of BadUSB. It features different modules lika a bluetooth expansion and can also be built into normal keyboards. An overview is available [https://usbninja.com/ here].&lt;br /&gt;
[[File:Rubberbunny.png|thumb|right|150px|Bash Bunny]]&lt;br /&gt;
&lt;br /&gt;
==== Bash Bunny ====&lt;br /&gt;
Bash Bunny is something like Rubber Duckys big brother. Its more expensive but also offers more tools like nmap, responder, impacket and metasploit, additional to the known Ducky Script. It&#039;s a small Linux machine on a USB drive mimicking multiple trusted devices. A full description can be found [https://shop.hak5.org/products/bash-bunny here].&lt;br /&gt;
&lt;br /&gt;
==== Standard Hardware ====&lt;br /&gt;
An emerging trend is to not use special hardware, but to built in keystroke injection hardware/software in common peripheral devices. Imagine a standard HP office mouse, nobody would expect any threat from it. Examples and manuals can be found online.&lt;br /&gt;
&lt;br /&gt;
== Possible Protections ==&lt;br /&gt;
&lt;br /&gt;
=== Linux ===&lt;br /&gt;
Google published a tool called &amp;quot;USB Keystroke Injection Protection&amp;quot; which runs as daemon and blocks badUSBs. A full [https://opensource.googleblog.com/2020/03/usb-keystroke-injection-protection.html description] and [https://github.com/google/ukip#installation-prerequisites installation guide] are available online.&lt;br /&gt;
&lt;br /&gt;
An other tool is [https://usbguard.github.io/ USB Guard]. It&#039;s an open source software project in which you can write own USB device authorization policies.&lt;br /&gt;
&lt;br /&gt;
=== Windows ===&lt;br /&gt;
&lt;br /&gt;
The probably best protection against Keystroke Injection, is to block all unknwon USB devices and allow specific known devices only. This can be achieved by Group Policies by denying installation of removeable devices and only allow devices with a specific serial ID. But this approach has two disadvantages. Thinking of enterprise solutions, it&#039;s a very high effort to allow the good devices and also the serial ID can be faked or surpressed by such attacking devices. &lt;br /&gt;
&lt;br /&gt;
A possible software solution is surprisingly [https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection Windows Defender ATP], an enterprise endpoint security platform.  &lt;br /&gt;
&lt;br /&gt;
A open source solution would be [http://konukoii.com/blog/2016/10/26/duckhunting-stopping-automated-keystroke-injection-attacks/ Duckhunt]. This script rezognizes the average typing speed and blocks key strokes that are too fast. It even has a &amp;quot;Sneaky&amp;quot; mode to not let the attacker know, his attack has been blocked.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* M. Tischer et al., &amp;quot;Users Really Do Plug in USB Drives They Find,&amp;quot; 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, 2016, pp. 306-319, doi: 10.1109/SP.2016.26.&lt;br /&gt;
* https://www.electronics-lab.com/project/pocketadmin-keystroke-injection-device/&lt;br /&gt;
* https://usbninja.com/&lt;br /&gt;
* https://shop.hak5.org/&lt;br /&gt;
* https://github.com/google/ukip#installation-prerequisites&lt;br /&gt;
* https://opensource.googleblog.com/2020/03/usb-keystroke-injection-protection.html&lt;br /&gt;
* https://usbguard.github.io/&lt;br /&gt;
* https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5982</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5982"/>
		<updated>2021-02-09T22:17:12Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Tunneling Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud click on the plus button and choose the device. On the dashboard open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the overview you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to yout Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5981</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5981"/>
		<updated>2021-02-09T22:16:33Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud click on the plus button and choose the device. On the dashboard open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the overview you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to yout Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5980</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5980"/>
		<updated>2021-02-09T22:15:55Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud click on the plus button and choose the device. On the dashboard open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the overview you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to yout Packetsquirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5979</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5979"/>
		<updated>2021-02-09T22:11:38Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud click on the plus button and choose the device. On the dashboard open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5978</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5978"/>
		<updated>2021-02-09T22:10:17Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud click on the plus button and choose the device. On the dashboard open the added device and click on&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5977</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5977"/>
		<updated>2021-02-09T22:09:07Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud click on the plus button and choose the device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5976</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5976"/>
		<updated>2021-02-09T22:07:23Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 Start&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5975</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5975"/>
		<updated>2021-02-09T22:06:06Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Example */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5974</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5974"/>
		<updated>2021-02-09T22:05:53Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5973</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5973"/>
		<updated>2021-02-09T22:05:23Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5972</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5972"/>
		<updated>2021-02-09T22:04:54Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 squirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Hak5_c2_sqirrel.jpg&amp;diff=5971</id>
		<title>File:Hak5 c2 sqirrel.jpg</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Hak5_c2_sqirrel.jpg&amp;diff=5971"/>
		<updated>2021-02-09T22:02:35Z</updated>

		<summary type="html">&lt;p&gt;MReiss: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Hak5_c2_dashboard.jpg&amp;diff=5970</id>
		<title>File:Hak5 c2 dashboard.jpg</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Hak5_c2_dashboard.jpg&amp;diff=5970"/>
		<updated>2021-02-09T22:02:17Z</updated>

		<summary type="html">&lt;p&gt;MReiss: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Hak5_C2_start.jpg&amp;diff=5969</id>
		<title>File:Hak5 C2 start.jpg</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Hak5_C2_start.jpg&amp;diff=5969"/>
		<updated>2021-02-09T22:02:00Z</updated>

		<summary type="html">&lt;p&gt;MReiss: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5968</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5968"/>
		<updated>2021-02-09T22:01:38Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5967</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5967"/>
		<updated>2021-02-09T21:55:30Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Tunneling Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The Hak5 Cloud C2 is a command and control server for Hak5 devices. In combination with Packet Squirrel if offers the following features&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5966</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5966"/>
		<updated>2021-02-09T21:48:09Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Tunneling Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
[code]wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh[/code]&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The Hak5 Cloud C2 is a command and control server for Hak5 devices. In combination with Packet Squirrel if offers the following features&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5965</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5965"/>
		<updated>2021-02-06T19:31:07Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* with Cloud C2 Server */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The Hak5 Cloud C2 is a command and control server for Hak5 devices. In combination with Packet Squirrel if offers the following features&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5964</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5964"/>
		<updated>2021-02-06T19:29:37Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Using Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 Server ==&lt;br /&gt;
&lt;br /&gt;
The Hak5 Cloud C2 Server is a command and control server for Hak5 devices. In combination with Packet Squirrel if offers the following features&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5963</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5963"/>
		<updated>2021-02-06T19:26:39Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5962</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5962"/>
		<updated>2021-02-06T19:24:39Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is switch1, switch2, switch3 or switch4.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5961</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5961"/>
		<updated>2021-02-06T19:24:06Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is switch1, switch2, switch3 or switch4.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Example&#039;&#039;&#039;&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5960</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5960"/>
		<updated>2021-02-06T19:10:50Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Example */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is switch1, switch2, switch3 or switch4.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5959</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5959"/>
		<updated>2021-02-06T19:09:37Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Example */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is switch1, switch2, switch3 or switch4.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
Title: Caternet&lt;br /&gt;
Author: Hak5Darren&lt;br /&gt;
Version: 1.0&lt;br /&gt;
Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5958</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5958"/>
		<updated>2021-02-06T19:07:22Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Example */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is switch1, switch2, switch3 or switch4.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
&amp;lt;code&amp;gt;Title: Caternet&lt;br /&gt;
Author: Hak5Darren&lt;br /&gt;
Version: 1.0&lt;br /&gt;
Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5957</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5957"/>
		<updated>2021-02-06T19:06:25Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is switch1, switch2, switch3 or switch4.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5956</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5956"/>
		<updated>2021-02-06T19:04:41Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is switch1, switch2, switch3 or switch4.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5955</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5955"/>
		<updated>2021-02-06T18:58:24Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5954</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5954"/>
		<updated>2021-02-06T18:49:46Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5953</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5953"/>
		<updated>2021-02-06T18:45:12Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Example&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Example&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Example&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || Example&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Example&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5952</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5952"/>
		<updated>2021-02-06T18:40:06Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5951</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5951"/>
		<updated>2021-02-05T21:02:59Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Using with Cloud C2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Using Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5950</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5950"/>
		<updated>2021-02-05T21:02:34Z</updated>

		<summary type="html">&lt;p&gt;MReiss: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Using with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5949</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5949"/>
		<updated>2021-02-05T21:01:44Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Paylaods */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5948</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5948"/>
		<updated>2021-02-05T21:00:14Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* OpenVPN Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5947</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5947"/>
		<updated>2021-02-05T21:00:04Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Access Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5946</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5946"/>
		<updated>2021-02-05T20:58:55Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5945</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5945"/>
		<updated>2021-02-05T20:58:17Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
=== Basic Cable Setup ===&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
=== Firmware Upgrade ===&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Rubber_Ducky&amp;diff=5944</id>
		<title>USB Rubber Ducky</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Rubber_Ducky&amp;diff=5944"/>
		<updated>2021-02-05T20:56:30Z</updated>

		<summary type="html">&lt;p&gt;MReiss: MReiss moved page USB Rubber Ducky to Hak5 Rubber Ducky: naming&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[Hak5 Rubber Ducky]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Rubber_Ducky&amp;diff=5943</id>
		<title>Hak5 Rubber Ducky</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Rubber_Ducky&amp;diff=5943"/>
		<updated>2021-02-05T20:56:30Z</updated>

		<summary type="html">&lt;p&gt;MReiss: MReiss moved page USB Rubber Ducky to Hak5 Rubber Ducky: naming&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation is about the USB Rubber Ducky, a [https://wiki.elvis.science/index.php?title=Key_Stroke_Injection keystroke injection] tool. It will explain USB Rubber Ducky basics, show some available tools for writing and encoding/decoding scripts, as well to change Rubber Ducky&#039;s firmware.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
Rubber Ducky itself is operating system independent but you will need a pc with an USB A port in order to be able to create and deploy your own payloads.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:rubber_ducky_inside.png|thumb|Rubber Ducky under the hood]]&lt;br /&gt;
USB Rubber Ducky, is a keyboard injection tool, mainly used from penetration testers and system administrators.&lt;br /&gt;
The Rubber Ducky comes disguised with an innocent USB flash drive chassis, to aid in social engineering.&lt;br /&gt;
But under the hood hides a 60 MHz 32-bit AT32UC3B1256 CPU with 256K onboard flash, and a micro SD card storage to host the payload, which is ready to deploy with over 9000 characters per minute, once connected into an USB slot.&lt;br /&gt;
&lt;br /&gt;
The device where Rubber Ducky is connected, recognizes it as a USB Keyboard. But it is also possible to change the PID/VID (Product ID/Vendor ID), so Rubber Ducky can claim to be any USB Human Interface Device (HID).&lt;br /&gt;
The payload, is written in Ducky Script, which is a very simple scripting language. Its syntax consists of just a few keywords, so everyone can directly start developing their own ducky scripts.&lt;br /&gt;
&lt;br /&gt;
== Package Content ==&lt;br /&gt;
&lt;br /&gt;
[[File:USBRubberDucky.jpg|thumb|Rubber Ducky package content]]&lt;br /&gt;
&lt;br /&gt;
If you purchase the USB Rubber Ducky form Hak5 you will find this content:&lt;br /&gt;
&lt;br /&gt;
* USB Rubber Ducky&lt;br /&gt;
* 128 MB micro SD Card&lt;br /&gt;
* The casing of the USB Rubber Ducky&lt;br /&gt;
* USB micro SD Card reader&lt;br /&gt;
* USB A female to micro USB male adapter&lt;br /&gt;
* USB Rubber Ducky field guide&lt;br /&gt;
&lt;br /&gt;
The USB micro SD Card reader to transfer the encoded the program onto the micro SD Card.&lt;br /&gt;
The USB A female to micro USB male adapter allows to use the USB Rubber Ducky on mobile devices.&lt;br /&gt;
&lt;br /&gt;
== Rubber Ducky Basics ==&lt;br /&gt;
Before diving into the world of keystroke injection attacks, a reader should be familiar with the following terms:&lt;br /&gt;
&lt;br /&gt;
=== Payload ===&lt;br /&gt;
The payload tells USB Rubber Ducky what keystroke sequence shall be injected, once connected into a USB jack. Payloads are written in a language called Ducky Script.&lt;br /&gt;
&lt;br /&gt;
=== Ducky Script ===&lt;br /&gt;
Ducky Script is the script language, in which payloads are written. Ducky Scripts are pure text, so any ascii based text editor can be used. The syntax is very easy, each command (all capital letters) resides on a new line with options to follow. See [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript here] a list of commands and their functions.&lt;br /&gt;
&lt;br /&gt;
=== Duck Encoder ===&lt;br /&gt;
Since Rubber Ducky is not able to interpret text files natively, the scripts need to be encoded into a binary keystroke injection file. There are many tools out there and they come in different flavors, as a browser app, a cli program or with a VB GUI. They all work the same, and produce an inject.bin file. There are also decoder tools available to reverse the process and produce ducky scripts from binary files.&lt;br /&gt;
&lt;br /&gt;
=== inject.bin ===&lt;br /&gt;
The inject.bin file is the compiled version of the ducky script. This file is then transferred on to a micro SD card and placed in Rubber Ducky&#039;s SD card reader, in order to be read and processed by the firmware.&lt;br /&gt;
&lt;br /&gt;
=== Firmware ===&lt;br /&gt;
Rubber Ducky&#039;s source code is open, so many different firmware alternatives are published from the community. Depending on the attack strategy, choose the firmware with specialized functionality, like: &lt;br /&gt;
* Multi Operating System Support (Duck)&lt;br /&gt;
* Mass Storage (FAT Duck)&lt;br /&gt;
* Multiple Payload Delivery (Detour Duck)&lt;br /&gt;
* Mass Storage &amp;amp; HID Keyboard Emulation (Twin Duck)&lt;br /&gt;
For more information read the appendix of [http://amarketplaceofideas.com/wp-content/uploads/2015/04/The-USB-Rubber-Ducky-Draft.doc this] developer guide.&amp;lt;br /&amp;gt;&lt;br /&gt;
Tools to flash firmware for Unix/OSX and Windows, including a tutorial can be found [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Flashing-ducky here].&lt;br /&gt;
&lt;br /&gt;
== Attack Workflow ==&lt;br /&gt;
No matter what kind of device the chosen target will be, the workflow will be basically similar for all devices.&lt;br /&gt;
&lt;br /&gt;
=== Research ===&lt;br /&gt;
Since Rubber Ducky acts as a simple preprogrammed input device, an attack is more likely to be successful, the more detailed information is gathered during reconnaissance phase, using social engineering and open source intelligence gathering techniques.&lt;br /&gt;
Once you know details about the used hardware and software running on it, try to rebuild the setup in bare metal or in a virtual environment, to test and optimize payload. &lt;br /&gt;
&lt;br /&gt;
=== Write ===&lt;br /&gt;
Writing ducky scripts always starts with trying out the payload by typing it directly into the test machine using the keyboard, and make step by step notes how you completed some tasks. Once all the necessary keystroke and shortcut combinations are found to complete the attack, the actual writing of the ducky script can start. But keep in mind that all machines vary in performance, especially when dealing with GUI elements. So be sure to add enough delay in the script, so the victim hosts has time enough to follow the keystrokes. A payload generator for multiple OS platforms can be found [https://ducktoolkit.com/payload here].&lt;br /&gt;
&lt;br /&gt;
=== Encode ===&lt;br /&gt;
Once the ducky script is completed, it&#039;s time to convert the human readable file into the binary formatted inject.bin file.  There is an online Encoder IDE which can be found on [https://ducktoolkit.com/encode ducktoolkit.com]. Or download an offline version from [https://downloads.hak5.org/api/devices/usbrubberducky/tools/jsencoder/1.0 here]. After encoding place the inject.bin file to the root folder of your micro SD card.&lt;br /&gt;
In case you need to convert back a binary file to ascii, use [https://ducktoolkit.com/decode this] or other decoding tools.&lt;br /&gt;
&lt;br /&gt;
=== Test and Optimize ===&lt;br /&gt;
Once the tests succeeded on a test environment, it&#039;s time to optimize the code in sense of speed (number of keystrokes and delays) and discreetness (to make the attack stealthier). But keep in mind, a less optimized version of your script might be slower, but more reliable when run on different devices.&lt;br /&gt;
&lt;br /&gt;
=== Deploy ===&lt;br /&gt;
&lt;br /&gt;
* Deploy the encoded script on the USB Rubber Ducky by Pasting the inject.bin file onto the micro SD Card.&lt;br /&gt;
* Use the USB Rubber Ducky and watch it type&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://github.com/hak5darren/USB-Rubber-Ducky/wiki&lt;br /&gt;
* https://ducktoolkit.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5942</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5942"/>
		<updated>2021-02-05T20:54:15Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* DNS Spoofing Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
=== Basic Cable Setup ===&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
=== Firmware Upgrade ===&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5941</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5941"/>
		<updated>2021-02-05T20:51:50Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
=== Basic Cable Setup ===&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
=== Firmware Upgrade ===&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/abc.com/216.58.207.164&amp;lt;/code&amp;gt; as show in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing the spoofed domain the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5940</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5940"/>
		<updated>2021-02-05T20:51:25Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* DNS Spoofing Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
=== Basic Cable Setup ===&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
=== Firmware Upgrade ===&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/abc.com/216.58.207.164&amp;lt;/code&amp;gt; as show in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing the spoofed domain the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5939</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5939"/>
		<updated>2021-02-05T20:51:20Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Logging Network Traffic */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
=== Basic Cable Setup ===&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
=== Firmware Upgrade ===&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/abc.com/216.58.207.164&amp;lt;/code&amp;gt; as show in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
By browsing the spoofed domain the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5938</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5938"/>
		<updated>2021-02-05T20:51:10Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* DNS Spoofing Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
=== Basic Cable Setup ===&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
=== Firmware Upgrade ===&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/abc.com/216.58.207.164&amp;lt;/code&amp;gt; as show in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
By browsing the spoofed domain the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Hak5_Squirrel_version.jpg&amp;diff=5937</id>
		<title>File:Hak5 Squirrel version.jpg</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Hak5_Squirrel_version.jpg&amp;diff=5937"/>
		<updated>2021-02-05T20:47:03Z</updated>

		<summary type="html">&lt;p&gt;MReiss: MReiss uploaded a new version of File:Hak5 Squirrel version.jpg&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5936</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=5936"/>
		<updated>2021-02-05T20:44:34Z</updated>

		<summary type="html">&lt;p&gt;MReiss: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
=== Basic Cable Setup ===&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
=== Firmware Upgrade ===&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Paylaods ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/abc.com/216.58.207.164&amp;lt;/code&amp;gt; as show in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
By browsing the spoofed domain the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
* openvpn&lt;br /&gt;
* autossh&lt;br /&gt;
* tcpdump&lt;br /&gt;
* meterpreter-https&lt;br /&gt;
* cron&lt;br /&gt;
* nmap&lt;br /&gt;
* ncat-ssl&lt;br /&gt;
* ncat&lt;br /&gt;
* sshfs&lt;br /&gt;
* tcpdump&lt;br /&gt;
* wget&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MReiss</name></author>
	</entry>
</feed>