ื›ื™ืฆื“ ืœื”ืชื—ื‘ืจ ืœ-VPN ืืจื’ื•ื ื™ ื‘ืœื™ื ื•ืงืก ื‘ืืžืฆืขื•ืช openconnect ื•-vpn-slice

ื”ืื ืืชื” ืจื•ืฆื” ืœื”ืฉืชืžืฉ ื‘ืœื™ื ื•ืงืก ื‘ืขื‘ื•ื“ื”, ืื‘ืœ ื”-VPN ื”ืืจื’ื•ื ื™ ืฉืœืš ืœื ืžืืคืฉืจ ืœืš? ืื– ืžืืžืจ ื–ื” ืขืฉื•ื™ ืœืขื–ื•ืจ, ืœืžืจื•ืช ืฉื–ื” ืœื ื‘ื˜ื•ื—. ืื ื™ ืจื•ืฆื” ืœื”ื–ื”ื™ืจ ืื•ืชืš ืžืจืืฉ ืฉืื ื™ ืœื ืžื‘ื™ืŸ ื”ื™ื˜ื‘ ืืช ื‘ืขื™ื•ืช ื ื™ื”ื•ืœ ื”ืจืฉืช, ืื– ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉืขืฉื™ืชื™ ื”ื›ืœ ืœื ื ื›ื•ืŸ. ืžืฆื“ ืฉื ื™, ื™ืชื›ืŸ ืฉืื•ื›ืœ ืœื›ืชื•ื‘ ืžื“ืจื™ืš ื‘ืฆื•ืจื” ื›ื–ื• ืฉื™ื”ื™ื” ืžื•ื‘ืŸ ืœืื ืฉื™ื ืจื’ื™ืœื™ื, ืื– ืื ื™ ืžืžืœื™ืฅ ืœืš ืœื ืกื•ืช ืื•ืชื•.

ื”ืžืืžืจ ืžื›ื™ืœ ื”ืจื‘ื” ืžื™ื“ืข ืžื™ื•ืชืจ, ืืš ืœืœื ื”ื™ื“ืข ื”ื–ื” ืœื ื”ื™ื™ืชื™ ืžืฆืœื™ื— ืœืคืชื•ืจ ืืช ื”ื‘ืขื™ื•ืช ืฉืฆืฆื• ืœื™ ื‘ืžืคืชื™ืข ื‘ื”ืงืžืช VPN. ืื ื™ ื—ื•ืฉื‘ ืฉืœื›ืœ ืžื™ ืฉื™ื ืกื” ืœื”ืฉืชืžืฉ ื‘ืžื“ืจื™ืš ื”ื–ื” ื™ื”ื™ื• ื‘ืขื™ื•ืช ืฉืœื ื”ื™ื• ืœื™, ื•ืื ื™ ืžืงื•ื•ื” ืฉื”ืžื™ื“ืข ื”ื ื•ืกืฃ ื”ื–ื” ื™ืขื–ื•ืจ ืœืคืชื•ืจ ืืช ื”ื‘ืขื™ื•ืช ื”ืœืœื• ื‘ืขืฆืžื•.

ืจื•ื‘ ื”ืคืงื•ื“ื•ืช ื”ืžืฉืžืฉื•ืช ื‘ืžื“ืจื™ืš ื–ื” ืฆืจื™ื›ื•ืช ืœื”ื™ื•ืช ืžื•ืคืขืœื•ืช ื‘ืืžืฆืขื•ืช sudo, ืืฉืจ ื”ื•ืกืจ ืœืงื™ืฆื•ืจ. ื–ื›ื•ืจ.

ืจื•ื‘ ื›ืชื•ื‘ื•ืช ื”-IP ื”ื•ื˜ืฉื• ืžืื•ื“, ื›ืš ืฉืื ืืชื” ืจื•ืื” ื›ืชื•ื‘ืช ื›ืžื• 435.435.435.435, ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืฉื IP ืจื’ื™ืœ, ืกืคืฆื™ืคื™ ืœืžืงืจื” ืฉืœืš.

ื™ืฉ ืœื™ ืื•ื‘ื•ื ื˜ื• 18.04, ืื‘ืœ ืื ื™ ื—ื•ืฉื‘ ืฉืขื ืฉื™ื ื•ื™ื™ื ืงืœื™ื ื ื™ืชืŸ ืœื”ื—ื™ืœ ืืช ื”ืžื“ืจื™ืš ืขืœ ื”ืคืฆื•ืช ืื—ืจื•ืช. ืขื ื–ืืช, ื‘ื˜ืงืกื˜ ื”ื–ื” ืœื™ื ื•ืงืก == ืื•ื‘ื•ื ื˜ื•.

Cisco Connect

ืžื™ ืฉื ืžืฆื ื‘-Windows ืื• MacOS ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœ-VPN ื”ืืจื’ื•ื ื™ ืฉืœื ื• ื“ืจืš Cisco Connect, ืฉืฆืจื™ืš ืœืฆื™ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”ืฉืขืจ ื•ื‘ื›ืœ ืคืขื ืฉืืชื” ืžืชื—ื‘ืจ, ืœื”ื–ื™ืŸ ืกื™ืกืžื” ื”ืžื•ืจื›ื‘ืช ืžื—ืœืง ืงื‘ื•ืข ื•ืงื•ื“ ืฉื ื•ืฆืจ ืขืœ ื™ื“ื™ Google Authenticator.

ื‘ืžืงืจื” ืฉืœ ืœื™ื ื•ืงืก, ืœื ื”ืฆืœื—ืชื™ ืœื”ืคืขื™ืœ ืืช Cisco Connect, ืื‘ืœ ื”ืฆืœื—ืชื™ ืœื—ืคืฉ ื‘ื’ื•ื’ืœ ื”ืžืœืฆื” ืœื”ืฉืชืžืฉ ื‘-openconnect, ืฉื ืขืฉืชื” ื‘ืžื™ื•ื—ื“ ื›ื“ื™ ืœื”ื—ืœื™ืฃ ืืช Cisco Connect.

Openconnect

ื‘ืชื™ืื•ืจื™ื”, ืœืื•ื‘ื ื˜ื• ื™ืฉ ืžืžืฉืง ื’ืจืคื™ ืžื™ื•ื—ื“ ืœ-openconnect, ืื‘ืœ ื–ื” ืœื ืขื‘ื“ ื‘ืฉื‘ื™ืœื™. ืื•ืœื™ ื–ื” ืœื˜ื•ื‘ื”.

ื‘ืื•ื‘ื•ื ื˜ื•, openconnect ืžื•ืชืงืŸ ืžืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช.

apt install openconnect

ืžื™ื“ ืœืื—ืจ ื”ื”ืชืงื ื”, ืืชื” ื™ื›ื•ืœ ืœื ืกื•ืช ืœื”ืชื—ื‘ืจ ืœ-VPN

openconnect --user poxvuibr vpn.evilcorp.com

vpn.evilcorp.com ื”ื™ื ื”ื›ืชื•ื‘ืช ืฉืœ VPN ืคื™ืงื˜ื™ื‘ื™
poxvuibr - ืฉื ืžืฉืชืžืฉ ืคื™ืงื˜ื™ื‘ื™

openconnect ื™ื‘ืงืฉ ืžืžืš ืœื”ื–ื™ืŸ ืกื™ืกืžื”, ืืฉืจ, ืœื”ื–ื›ื™ืจืš, ืžื•ืจื›ื‘ืช ืžื—ืœืง ืงื‘ื•ืข ื•ืงื•ื“ ืž-Google Authenticator, ื•ืื– ื”ื™ื ืชื ืกื” ืœื”ืชื—ื‘ืจ ืœ-vpn. ืื ื–ื” ืขื•ื‘ื“, ื›ืœ ื”ื›ื‘ื•ื“, ืืคืฉืจ ืœื“ืœื’ ื‘ื‘ื˜ื—ื” ืขืœ ื”ืืžืฆืข, ืฉื–ื” ื›ืื‘ ืจื‘, ื•ืœื”ืžืฉื™ืš ืœื ืงื•ื“ื” ืฉืœ ืจื™ืฆื” ืคืชื•ื—ื” ื‘ืจืงืข. ืื ื–ื” ืœื ืขื•ื‘ื“, ืืชื” ื™ื›ื•ืœ ืœื”ืžืฉื™ืš. ืœืžืจื•ืช ืฉืื ื–ื” ืขื‘ื“ ื‘ืขืช ื—ื™ื‘ื•ืจ, ืœืžืฉืœ, ืž-Wi-Fi ืฉืœ ืื•ืจื— ื‘ืขื‘ื•ื“ื”, ืื– ืื•ืœื™ ืžื•ืงื“ื ืžื“ื™ ืœืฉืžื•ื—; ื›ื“ืื™ ืœื ืกื•ืช ืœื—ื–ื•ืจ ืขืœ ื”ื”ืœื™ืš ืžื”ื‘ื™ืช.

ืชึฐืขื•ึผื“ึธื”

ื™ืฉ ืกื‘ื™ืจื•ืช ื’ื‘ื•ื”ื” ืฉืฉื•ื ื“ื‘ืจ ืœื ื™ืชื—ื™ืœ, ื•ืคืœื˜ ื”-openconnect ื™ื™ืจืื” ื‘ืขืจืš ื›ืš:

POST https://vpn.evilcorp.com/
Connected to 777.777.777.777:443
SSL negotiation with vpn.evilcorp.com
Server certificate verify failed: signer not found

Certificate from VPN server "vpn.evilcorp.com" failed verification.
Reason: signer not found
To trust this server in future, perhaps add this to your command line:
    --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444
Enter 'yes' to accept, 'no' to abort; anything else to view: fgets (stdin): Operation now in progress

ืžืฆื“ ืื—ื“, ื–ื” ืœื ื ืขื™ื, ื›ื™ ืœื ื”ื™ื” ื—ื™ื‘ื•ืจ ืœ-VPN, ืื‘ืœ ืžืฆื“ ืฉื ื™, ืื™ืš ืœืชืงืŸ ืืช ื”ื‘ืขื™ื”, ื‘ืื•ืคืŸ ืขืงืจื•ื ื™, ื‘ืจื•ืจ.

ื›ืืŸ ื”ืฉืจืช ืฉืœื— ืœื ื• ืื™ืฉื•ืจ, ืฉื‘ืืžืฆืขื•ืชื• ืื ื• ื™ื›ื•ืœื™ื ืœืงื‘ื•ืข ืฉื”ื—ื™ื‘ื•ืจ ืžืชื‘ืฆืข ืœืฉืจืช ืฉืœ ื”ืชืื’ื™ื“ ื”ืžืงื•ืžื™ ืฉืœื ื•, ื•ืœื ืœืจืžืื™ ืžืจื•ืฉืข, ื•ืชืขื•ื“ื” ื–ื• ืื™ื ื” ื™ื“ื•ืขื” ืœืžืขืจื›ืช. ื•ืœื›ืŸ ื”ื™ื ืœื ื™ื›ื•ืœื” ืœื‘ื“ื•ืง ืื ื”ืฉืจืช ืืžื™ืชื™ ืื• ืœื. ื•ื›ืš, ืœืžืงืจื” ืฉื”ื•ื ื™ืคืกื™ืง ืœืขื‘ื•ื“.

ืขืœ ืžื ืช ืฉ-openconnect ื™ืชื—ื‘ืจ ืœืฉืจืช, ืขืœื™ืš ืœื•ืžืจ ืœื• ื‘ืžืคื•ืจืฉ ืื™ื–ื” ืื™ืฉื•ืจ ืืžื•ืจ ืœื”ื’ื™ืข ืžืฉืจืช ื”-VPN ื‘ืืžืฆืขื•ืช ืžืคืชื— -servercert

ื•ืชื•ื›ืœื• ืœื’ืœื•ืช ืื™ื–ื• ืชืขื•ื“ื” ื”ืฉืจืช ืฉืœื— ืœื ื• ื™ืฉื™ืจื•ืช ืžืžื” ืฉ-openconnect ื”ื“ืคื™ืก. ื”ื ื” ืžื”ืงื˜ืข ื”ื–ื”:

To trust this server in future, perhaps add this to your command line:
    --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444
Enter 'yes' to accept, 'no' to abort; anything else to view: fgets (stdin): Operation now in progress

ืขื ืคืงื•ื“ื” ื–ื• ืชื•ื›ืœ ืœื ืกื•ืช ืœื”ืชื—ื‘ืจ ืฉื•ื‘

openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 --user poxvuibr vpn.evilcorp.com

ืื•ืœื™ ืขื›ืฉื™ื• ื–ื” ืขื•ื‘ื“, ื•ืื– ืืชื” ื™ื›ื•ืœ ืœื”ืžืฉื™ืš ืœืกื•ืฃ. ืื‘ืœ ื‘ืื•ืคืŸ ืื™ืฉื™, ืื•ื‘ื•ื ื˜ื” ื”ืจืืชื” ืœื™ ืชืื ื” ื‘ืฆื•ืจื” ื”ื–ื•

POST https://vpn.evilcorp.com/
Connected to 777.777.777.777:443
SSL negotiation with vpn.evilcorp.com
Server certificate verify failed: signer not found
Connected to HTTPS on vpn.evilcorp.com
XML POST enabled
Please enter your username and password.
POST https://vpn.evilcorp.com/
Got CONNECT response: HTTP/1.1 200 OK
CSTP connected. DPD 300, Keepalive 30
Set up DTLS failed; using SSL instead
Connected as 192.168.333.222, using SSL
NOSSSSSHHHHHHHDDDDD
3
NOSSSSSHHHHHHHDDDDD
3
RTNETLINK answers: File exists
/etc/resolvconf/update.d/libc: Warning: /etc/resolv.conf is not a symbolic link to /run/resolvconf/resolv.conf

/ Etc / resolv.conf

# Generated by NetworkManager
search gst.evilcorpguest.com
nameserver 127.0.0.53

/run/resolvconf/resolv.conf

# Dynamic resolv.conf(5) file for glibc resolver(3) generated by resolvconf(8)
#     DO NOT EDIT THIS FILE BY HAND -- YOUR CHANGES WILL BE OVERWRITTEN
# 127.0.0.53 is the systemd-resolved stub resolver.
# run "systemd-resolve --status" to see details about the actual nameservers.

nameserver 192.168.430.534
nameserver 127.0.0.53
search evilcorp.com gst.publicevilcorp.com

habr.com ื™ืคืชื•ืจ, ืื‘ืœ ืœื ืชื•ื›ืœ ืœืœื›ืช ืœืฉื. ื›ืชื•ื‘ื•ืช ื›ืžื• jira.evilcorp.com ืื™ื ืŸ ืคืชื•ืจื•ืช ื›ืœืœ.

ืžื” ืฉืงืจื” ื›ืืŸ ืœื ื‘ืจื•ืจ ืœื™. ืื‘ืœ ื”ื ื™ืกื•ื™ ืžืจืื” ืฉืื ืชื•ืกื™ืฃ ืืช ื”ืฉื•ืจื” ืœ-/etc/resolv.conf

nameserver 192.168.430.534

ั‚ะพ ะฐะดั€ะตัะฐ ะฒะฝัƒั‚ั€ะธ VPN ะฝะฐั‡ะฝัƒั‚ ะผะฐะณะธั‡ะตัะบะธะผ ะพะฑั€ะฐะทะพะผ ั€ะตัะพะปะฒะธั‚ัŒัั ะธ ะฟะพ ะฝะธะผ ะผะพะถะฝะพ ะฑัƒะดะตั‚ ั…ะพะดะธั‚ัŒ, ั‚ะพ ะตัั‚ัŒ ั‚ะพ, ั‡ั‚ะพ ะธั‰ะตั‚ ะบะฐะบะธะผะธ DNS ั€ะตัะพะปะฒะธั‚ัŒ ะฐะดั€ะตัะฐ, ัะผะพั‚ั€ะธั‚ ะธะผะตะฝะฝะพ ะฒ /etc/resolv.conf, ะฐ ะฝะต ะบัƒะดะฐ-ั‚ะพ ะตั‰ั‘.

ืืชื” ื™ื›ื•ืœ ืœื•ื•ื“ื ืฉื™ืฉ ื—ื™ื‘ื•ืจ ืœ-VPN ื•ื”ื•ื ืขื•ื‘ื“ ืžื‘ืœื™ ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘-/etc/resolv.conf; ืœืฉื ื›ืš, ืคืฉื•ื˜ ื”ื–ืŸ ื‘ื“ืคื“ืคืŸ ืœื ืืช ื”ืฉื ื”ืกืžืœื™ ืฉืœ ื”ืžืฉืื‘ ืžื”-VPN, ืืœื ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœื•.

ื›ืชื•ืฆืื” ืžื›ืš, ื™ืฉื ืŸ ืฉืชื™ ื‘ืขื™ื•ืช

  • ื‘ืขืช ื—ื™ื‘ื•ืจ ืœ-VPN, ื”-DNS ืฉืœื• ืœื ื ืงืœื˜
  • ื›ืœ ื”ืชืขื‘ื•ืจื” ืขื•ื‘ืจืช ื“ืจืš VPN, ืฉืื™ื ื• ืžืืคืฉืจ ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜

ืื ื™ ืื’ื™ื“ ืœืš ืžื” ืœืขืฉื•ืช ืขื›ืฉื™ื•, ืื‘ืœ ืงื•ื“ื ืงืฆืช ืื•ื˜ื•ืžืฆื™ื”.

ื”ื–ื ื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ื”ื—ืœืง ื”ืงื‘ื•ืข ืฉืœ ื”ืกื™ืกืžื”

ืขื“ ืขื›ืฉื™ื•, ืกื‘ื™ืจ ืœื”ื ื™ื— ืฉื›ื‘ืจ ื”ื–ื ืช ืืช ื”ืกื™ืกืžื” ืฉืœืš ืœืคื—ื•ืช ื—ืžืฉ ืคืขืžื™ื ื•ื”ื”ืœื™ืš ื”ื–ื” ื›ื‘ืจ ืขื™ื™ืฃ ืื•ืชืš. ืจืืฉื™ืช, ื›ื™ ื”ืกื™ืกืžื” ืืจื•ื›ื”, ื•ืฉื ื™ืช, ื›ื™ ื‘ืขืช ื”ื›ื ื™ืกื” ืฆืจื™ืš ืœื”ืชืื™ื ืœืคืจืง ื–ืžืŸ ืงื‘ื•ืข

ื”ืคืชืจื•ืŸ ื”ืกื•ืคื™ ืœื‘ืขื™ื” ืœื ื ื›ืœืœ ื‘ืžืืžืจ, ืืš ื ื™ืชืŸ ืœื•ื•ื“ื ืฉืื™ืŸ ืฆื•ืจืš ืœื”ื–ื™ืŸ ืืช ื”ื—ืœืง ื”ืงื‘ื•ืข ืฉืœ ื”ืกื™ืกืžื” ืคืขืžื™ื ืจื‘ื•ืช.

ื ื ื™ื— ืฉื”ื—ืœืง ื”ืงื‘ื•ืข ืฉืœ ื”ืกื™ืกืžื” ื”ื•ื fixedPassword, ื•ื”ื—ืœืง ืž-Google Authenticator ื”ื•ื 567 987. ื ื™ืชืŸ ืœื”ืขื‘ื™ืจ ืืช ื”ืกื™ืกืžื” ื›ื•ืœื” ืœ-openconnect ื‘ืืžืฆืขื•ืช ืงืœื˜ ืจื’ื™ืœ ื‘ืืžืฆืขื•ืช ื”ืืจื’ื•ืžื ื˜ --passwd-on-stdin.

echo "fixedPassword567987" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 --user poxvuibr vpn.evilcorp.com --passwd-on-stdin

ืขื›ืฉื™ื• ืืชื” ื™ื›ื•ืœ ื›ืœ ื”ื–ืžืŸ ืœื—ื–ื•ืจ ืœืคืงื•ื“ื” ื”ืื—ืจื•ื ื” ืฉื”ื•ื›ื ืกื” ื•ืœืฉื ื•ืช ืจืง ื—ืœืง ืž-Google Authenticator ืฉื.

VPN ืืจื’ื•ื ื™ ืœื ืžืืคืฉืจ ืœืš ืœื’ืœื•ืฉ ื‘ืื™ื ื˜ืจื ื˜.

ื‘ืื•ืคืŸ ื›ืœืœื™, ื–ื” ืœื ืžืื•ื“ ืœื ื ื•ื— ื›ืฉืืชื” ืฆืจื™ืš ืœื”ืฉืชืžืฉ ื‘ืžื—ืฉื‘ ื ืคืจื“ ื›ื“ื™ ืœืขื‘ื•ืจ ืืœ Habr. ื—ื•ืกืจ ื”ื™ื›ื•ืœืช ืœื”ืขืชื™ืง-ื”ื“ื‘ืง ืž-stackoverfow ื™ื›ื•ืœ ื‘ื“ืจืš ื›ืœืœ ืœืฉืชืง ืืช ื”ืขื‘ื•ื“ื”, ืื– ืฆืจื™ืš ืœืขืฉื•ืช ืžืฉื”ื•.

ืื ื—ื ื• ืฆืจื™ื›ื™ื ืื™ื›ืฉื”ื• ืœืืจื’ืŸ ืืช ื–ื” ื›ืš ืฉื›ืืฉืจ ืืชื” ืฆืจื™ืš ืœื’ืฉืช ืœืžืฉืื‘ ืžื”ืจืฉืช ื”ืคื ื™ืžื™ืช, ืœื™ื ื•ืงืก ืขื•ื‘ืจืช ืœ-VPN, ื•ื›ืืฉืจ ืืชื” ืฆืจื™ืš ืœืœื›ืช ืœื”ืื‘ืจ, ื”ื™ื ืขื•ื‘ืจืช ืœืื™ื ื˜ืจื ื˜.

openconnect, ืœืื—ืจ ื”ืคืขืœื” ื•ื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ ืขื vpn, ืžื‘ืฆืข ืกืงืจื™ืคื˜ ืžื™ื•ื—ื“, ืฉื ืžืฆื ื‘- /usr/share/vpnc-scripts/vpnc-script. ืžืฉืชื ื™ื ืžืกื•ื™ืžื™ื ืžื•ืขื‘ืจื™ื ืœืกืงืจื™ืคื˜ ื›ืงืœื˜, ื•ื”ื•ื ืžื’ื“ื™ืจ ืืช ื”-VPN. ืœืจื•ืข ื”ืžื–ืœ, ืœื ื”ืฆืœื—ืชื™ ืœื”ื‘ื™ืŸ ื›ื™ืฆื“ ืœืคืฆืœ ืืช ื–ืจื™ืžื•ืช ื”ืชืขื‘ื•ืจื” ื‘ื™ืŸ VPN ืืจื’ื•ื ื™ ืœืฉืืจ ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช ืกืงืจื™ืคื˜ ืžืงื•ืจื™.

ื›ื›ืœ ื”ื ืจืื”, ื›ืœื™ ื”ืฉื™ืจื•ืช vpn-slice ืคื•ืชื— ื‘ืžื™ื•ื—ื“ ืขื‘ื•ืจ ืื ืฉื™ื ื›ืžื•ื ื™, ื”ืžืืคืฉืจ ืœืฉืœื•ื— ืชื ื•ืขื” ื‘ืฉื ื™ ืขืจื•ืฆื™ื ืžื‘ืœื™ ืœืจืงื•ื“ ืขื ื˜ืžื‘ื•ืจื™ืŸ. ื•ื‘ื›ืŸ, ื›ืœื•ืžืจ, ืืชื” ืชืฆื˜ืจืš ืœืจืงื•ื“, ืื‘ืœ ืืชื” ืœื ืฆืจื™ืš ืœื”ื™ื•ืช ืฉืžืืŸ.

ื”ืคืจื“ืช ืชื ื•ืขื” ื‘ืืžืฆืขื•ืช vpn-slice

ืจืืฉื™ืช, ืชืฆื˜ืจืš ืœื”ืชืงื™ืŸ vpn-slice, ืชืฆื˜ืจืš ืœื”ื‘ื™ืŸ ื–ืืช ื‘ืขืฆืžืš. ืื ื™ืฉ ืฉืืœื•ืช ื‘ืชื’ื•ื‘ื•ืช, ืื›ืชื•ื‘ ืขืœ ื–ื” ืคื•ืกื˜ ื ืคืจื“. ืื‘ืœ ื–ื• ืชื•ื›ื ื™ืช Python ืจื’ื™ืœื”, ืื– ืœื ืืžื•ืจื™ื ืœื”ื™ื•ืช ืงืฉื™ื™ื. ื”ืชืงื ืชื™ ื‘ืืžืฆืขื•ืช virtualenv.

ื•ืื– ื™ืฉ ืœื”ื—ื™ืœ ืืช ื›ืœื™ ื”ืฉื™ืจื•ืช, ื‘ืืžืฆืขื•ืช ืžืชื’ -script, ื”ืžืฆื™ื™ืŸ ืœ-openconnect ืฉื‘ืžืงื•ื ื”ืกืงืจื™ืคื˜ ื”ืกื˜ื ื“ืจื˜ื™, ืขืœื™ืš ืœื”ืฉืชืžืฉ ื‘-vpn-slice

echo "fixedPassword567987" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 --user poxvuibr --passwd-on-stdin 
--script "./bin/vpn-slice 192.168.430.0/24  " vpn.evilcorp.com 

--script ืžื•ืขื‘ืจืช ืžื—ืจื•ื–ืช ืขื ืคืงื•ื“ื” ืฉืฆืจื™ืš ืœืงืจื•ื ื‘ืžืงื•ื ื”ืกืงืจื™ืคื˜. ./bin/vpn-slice - ื ืชื™ื‘ ืœืงื•ื‘ืฅ ื”ื”ืคืขืœื” vpn-slice 192.168.430.0/24 - ืžืกื›ืช ื›ืชื•ื‘ื•ืช ืฉืืœื™ื”ื ื™ืฉ ืœืขื‘ื•ืจ ื‘-vpn. ื›ืืŸ, ืื ื• ืžืชื›ื•ื•ื ื™ื ืฉืื ื”ื›ืชื•ื‘ืช ืžืชื—ื™ืœื” ื‘-192.168.430, ื™ืฉ ืœื—ืคืฉ ืืช ื”ืžืฉืื‘ ืขื ื›ืชื•ื‘ืช ื–ื• ื‘ืชื•ืš ื”-VPN

ื”ืžืฆื‘ ื›ืขืช ืืžื•ืจ ืœื”ื™ื•ืช ื›ืžืขื˜ ื ื•ืจืžืœื™. ื›ึผึดืžืขึทื˜. ืขื›ืฉื™ื• ืืชื” ื™ื›ื•ืœ ืœืœื›ืช ืœ-Habr ื•ืืชื” ื™ื›ื•ืœ ืœืœื›ืช ืœืžืฉืื‘ ื”ืคื ื™ื-ืชืื’ื™ื“ื™ ืœืคื™ ip, ืื‘ืœ ืืชื” ืœื ื™ื›ื•ืœ ืœืœื›ืช ืœืžืฉืื‘ ื”ืคื ื™ื-ืืจื’ื•ื ื™ ืœืคื™ ืฉื ืกืžืœื™. ืื ืืชื” ืžืฆื™ื™ืŸ ื”ืชืืžื” ื‘ื™ืŸ ื”ืฉื ื”ืกืžืœื™ ืœื›ืชื•ื‘ืช ื‘ืžืืจื—ื™ื, ื”ื›ืœ ืืžื•ืจ ืœืขื‘ื•ื“. ื•ืขื‘ื•ื“ ืขื“ ืฉื”-IP ื™ืฉืชื ื”. ืœื™ื ื•ืงืก ื™ื›ื•ืœื” ื›ืขืช ืœื’ืฉืช ืœืื™ื ื˜ืจื ื˜ ืื• ืœืื™ื ื˜ืจืื ื˜, ื‘ื”ืชืื ืœ-IP. ืื‘ืœ ืขื“ื™ื™ืŸ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-DNS ืฉืื™ื ื• ืชืื’ื™ื“ ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื”ื›ืชื•ื‘ืช.

ื”ื‘ืขื™ื” ื™ื›ื•ืœื” ืœื”ืชื‘ื˜ื ื’ื ื‘ืฆื•ืจื” ื–ื• - ื‘ืขื‘ื•ื“ื” ื”ื›ืœ ื‘ืกื“ืจ, ืื‘ืœ ื‘ื‘ื™ืช ืืชื” ื™ื›ื•ืœ ืœื’ืฉืช ืจืง ืœืžืฉืื‘ื™ื ืคื ื™ืžื™ื™ื ืืจื’ื•ื ื™ื™ื ื‘ืืžืฆืขื•ืช IP. ื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื ืฉื›ืืฉืจ ืืชื” ืžื—ื•ื‘ืจ ืœ-Wi-Fi ืืจื’ื•ื ื™, ื ืขืฉื” ืฉื™ืžื•ืฉ ื’ื ื‘-DNS ื”ืืจื’ื•ื ื™, ื•ื ืคืชืจื•ืช ื‘ื• ื›ืชื•ื‘ื•ืช ืกืžืœื™ื•ืช ืžื”-VPN, ืœืžืจื•ืช ืฉืขื“ื™ื™ืŸ ืื™ ืืคืฉืจ ืœื”ื’ื™ืข ืœื›ืชื•ื‘ืช ื›ื–ื• ืœืœื ืฉื™ืžื•ืฉ ื‘-VPN.

ืฉื™ื ื•ื™ ืื•ื˜ื•ืžื˜ื™ ืฉืœ ืงื•ื‘ืฅ ื”ืžืืจื—ื™ื

ืื vpn-slice ื ืฉืืœ ื‘ื ื™ืžื•ืก, ืื– ืœืื—ืจ ื”ืขืœืืช ื”-VPN, ื”ื•ื ื™ื›ื•ืœ ืœืœื›ืช ืœ-DNS ืฉืœื•, ืœืžืฆื•ื ืฉื ืืช ื›ืชื•ื‘ื•ืช ื”-IP ืฉืœ ื”ืžืฉืื‘ื™ื ื”ื“ืจื•ืฉื™ื ืœืคื™ ื”ืฉืžื•ืช ื”ืกืžืœื™ื™ื ืฉืœื”ื ื•ืœื”ื–ื™ืŸ ืื•ืชื ื‘ืžืืจื—ื™ื. ืœืื—ืจ ื›ื™ื‘ื•ื™ ื”-VPN, ื”ื›ืชื•ื‘ื•ืช ื”ืœืœื• ื™ื•ืกืจื• ืžื”ืžืืจื—ื™ื. ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ืขืœื™ืš ืœื”ืขื‘ื™ืจ ืฉืžื•ืช ืกืžืœื™ื™ื ืœ-vpn-slice ื›ืืจื’ื•ืžื ื˜ื™ื. ื›ื›ื”.

echo "fixedPassword567987" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 --user poxvuibr --passwd-on-stdin
--script "./bin/vpn-slice 192.168.430.0/24  jira.vpn.evilcorp.com git.vpn.evilcorp.com " vpn.evilcorp.com 

ืขื›ืฉื™ื• ื”ื›ืœ ืืžื•ืจ ืœืขื‘ื•ื“ ื’ื ื‘ืžืฉืจื“ ื•ื’ื ืขืœ ื”ื—ื•ืฃ.

ื—ืคืฉ ืืช ื”ื›ืชื•ื‘ื•ืช ืฉืœ ื›ืœ ืชืช-ื”ื“ื•ืžื™ื™ื ื™ื ื‘-DNS ืฉื ื™ืชืŸ ืขืœ ื™ื“ื™ ื”-VPN

ืื ื™ืฉ ืžืขื˜ ื›ืชื•ื‘ื•ืช ื‘ืจืฉืช, ื”ื’ื™ืฉื” ืฉืœ ืฉื™ื ื•ื™ ืื•ื˜ื•ืžื˜ื™ ืฉืœ ืงื•ื‘ืฅ ื”ืžืืจื—ื™ื ืขื•ื‘ื“ืช ื“ื™ ื˜ื•ื‘. ืื‘ืœ ืื ื™ืฉ ื”ืจื‘ื” ืžืฉืื‘ื™ื ื‘ืจืฉืช, ืื– ืชืฆื˜ืจืš ื›ืœ ื”ื–ืžืŸ ืœื”ื•ืกื™ืฃ ืฉื•ืจื•ืช ื›ืžื• zoidberg.test.evilcorp.com ืœืชืกืจื™ื˜ zoidberg ื”ื•ื ืฉืžื• ืฉืœ ืื—ื“ ืžืกืคืกืœื™ ื”ื‘ื“ื™ืงื”.

ืื‘ืœ ืขื›ืฉื™ื•, ื›ืฉืื ื—ื ื• ืžื‘ื™ื ื™ื ืงืฆืช ืœืžื” ืืคืฉืจ ืœื‘ื˜ืœ ืืช ื”ืฆื•ืจืš ื”ื–ื”.

ืื, ืœืื—ืจ ื”ืขืœืืช ื”-VPN, ืืชื” ืžืกืชื›ืœ ื‘-/etc/hosts, ืืชื” ื™ื›ื•ืœ ืœืจืื•ืช ืืช ื”ืฉื•ืจื” ื”ื–ื•

192.168.430.534 dns0.tun0 # vpn-slice-tun0 ื ื•ืฆืจ ืื•ื˜ื•ืžื˜ื™ืช

ื•ืฉื•ืจื” ื—ื“ืฉื” ื ื•ืกืคื” ืœ-resolv.conf. ื‘ืงื™ืฆื•ืจ, vpn-slice ืงื‘ืข ืื™ื›ืฉื”ื• ื”ื™ื›ืŸ ื ืžืฆื ืฉืจืช ื”-dns ืขื‘ื•ืจ ื”-vpn.

ื›ืขืช ืขืœื™ื ื• ืœื•ื•ื“ื ืฉื›ื“ื™ ืœื’ืœื•ืช ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืฉื ืชื—ื•ื ื”ืžืกืชื™ื™ื ื‘-evilcorp.com, ืœื™ื ื•ืงืก ืขื•ื‘ืจืช ืœ-DNS ื”ืืจื’ื•ื ื™, ื•ืื ื™ืฉ ืฆื•ืจืš ื‘ืžืฉื”ื• ืื—ืจ, ืื– ืœื‘ืจื™ืจืช ื”ืžื—ื“ืœ.

ื—ื™ืคืฉืชื™ ื‘ื’ื•ื’ืœ ื“ื™ ื”ืจื‘ื” ื–ืžืŸ ื•ื’ื™ืœื™ืชื™ ืฉืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื›ื–ื• ื–ืžื™ื ื” ื‘ืื•ื‘ื•ื ื˜ื• ืžื”ืงื•ืคืกื”. ืžืฉืžืขื•ืช ื”ื“ื‘ืจ ื”ื™ื ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืฉืจืช ื”-DNS ื”ืžืงื•ืžื™ dnsmasq ื›ื“ื™ ืœืคืชื•ืจ ืฉืžื•ืช.

ื›ืœื•ืžืจ, ืืชื” ื™ื›ื•ืœ ืœื•ื•ื“ื ืฉืœื™ื ื•ืงืก ื”ื•ืœืš ืชืžื™ื“ ืœืฉืจืช ื”-DNS ื”ืžืงื•ืžื™ ืขื‘ื•ืจ ื›ืชื•ื‘ื•ืช IP, ืืฉืจ ื‘ืชื•ืจื•, ื‘ื”ืชืื ืœืฉื ื”ื“ื•ืžื™ื™ืŸ, ื™ื—ืคืฉ ืืช ื”-IP ื‘ืฉืจืช ื”-DNS ื”ื—ื™ืฆื•ื ื™ ื”ืžืชืื™ื.

ื›ื“ื™ ืœื ื”ืœ ืืช ื›ืœ ืžื” ืฉืงืฉื•ืจ ืœืจืฉืชื•ืช ื•ื—ื™ื‘ื•ืจื™ ืจืฉืช, ืื•ื‘ื•ื ื˜ื• ืžืฉืชืžืฉืช ื‘-NetworkManager, ื•ื”ืžืžืฉืง ื”ื’ืจืคื™ ืœื‘ื—ื™ืจืช, ืœืžืฉืœ, ื—ื™ื‘ื•ืจื™ Wi-Fi ื”ื•ื ืจืง ืงืฆื” ืงืฆื” ืฉืœื•.

ื ืฆื˜ืจืš ืœื˜ืคืก ื‘ืชืฆื•ืจื” ืฉืœื•.

  1. ืฆื•ืจ ืงื•ื‘ืฅ ื‘- /etc/NetworkManager/dnsmasq.d/evilcorp

address=/.evilcorp.com/192.168.430.534

ืฉื™ืžื• ืœื‘ ืœื ืงื•ื“ื” ืžื•ืœ evilcorp. ื–ื” ืžืกืžืŸ ืœ-dnsmasq ืฉื™ืฉ ืœื—ืคืฉ ื‘ื›ืœ ืชืช-ื”ื“ื•ืžื™ื™ื ื™ื ืฉืœ evilcorp.com ื‘-dns ื”ืืจื’ื•ื ื™.

  1. ืืžื•ืจ ืœ-NetworkManager ืœื”ืฉืชืžืฉ ื‘-dnsmasq ืœืคืชืจื•ืŸ ืฉื

ืชืฆื•ืจืช ืžื ื”ืœ ื”ืจืฉืช ืžืžื•ืงืžืช ื‘- /etc/NetworkManager/NetworkManager.conf ืืชื” ืฆืจื™ืš ืœื”ื•ืกื™ืฃ ืฉื:

[ืจืืฉื™] dns=dnsmasq

  1. ื”ืคืขืœ ืžื—ื“ืฉ ืืช NetworkManager

service network-manager restart

ื›ืขืช, ืœืื—ืจ ื”ืชื—ื‘ืจื•ืช ืœ-VPN ื‘ืืžืฆืขื•ืช openconnect ื•-vpn-slice, ื”-ip ื™ื™ืงื‘ืข ื›ืจื’ื™ืœ, ื’ื ืื ืœื ืชื•ืกื™ืฃ ื›ืชื•ื‘ื•ืช ืกืžืœื™ื•ืช ืœืืจื’ื•ืžื ื˜ื™ื ืœ-vpnslice.

ื›ื™ืฆื“ ืœื’ืฉืช ืœืฉื™ืจื•ืชื™ื ื‘ื•ื“ื“ื™ื ื‘ืืžืฆืขื•ืช VPN

ืื—ืจื™ ืฉื”ืฆืœื—ืชื™ ืœื”ืชื—ื‘ืจ ืœ-VPN, ืฉืžื—ืชื™ ืžืื•ื“ ื‘ืžืฉืš ื™ื•ืžื™ื™ื, ื•ืื– ื”ืชื‘ืจืจ ืฉืื ืื ื™ ืžืชื—ื‘ืจ ืœ-VPN ืžื—ื•ืฅ ืœืจืฉืช ื”ืžืฉืจื“ื™ืช, ืื– ื”ื“ื•ืืจ ืœื ืขื•ื‘ื“. ื”ืกื™ืžืคื˜ื•ื ืžื•ื›ืจ, ืœื?

ื”ื“ื•ืืจ ืฉืœื ื• ืžืžื•ืงื ื‘-mail.publicevilcorp.com, ืžื” ืฉืื•ืžืจ ืฉื”ื•ื ืœื ื ื•ืคืœ ืชื—ืช ื”ื›ืœืœ ื‘-dnsmasq ื•ื›ืชื•ื‘ืช ืฉืจืช ื”ื“ื•ืืจ ืžืชื‘ืฆืขืช ื‘ืืžืฆืขื•ืช DNS ืฆื™ื‘ื•ืจื™.

ื•ื‘ื›ืŸ, ื”ืžืฉืจื“ ืขื“ื™ื™ืŸ ืžืฉืชืžืฉ ื‘-DNS, ืฉืžื›ื™ืœ ืืช ื”ื›ืชื•ื‘ืช ื”ื–ื•. ื–ื” ืžื” ืฉื—ืฉื‘ืชื™. ืœืžืขืฉื”, ืœืื—ืจ ื”ื•ืกืคืช ื”ืฉื•ืจื” ืœ-dnsmasq

address=/mail.publicevilcorp.com/192.168.430.534

ื”ืžืฆื‘ ืœื ื”ืฉืชื ื” ื›ืœืœ. ip ื ืฉืืจ ืื•ืชื• ื”ื“ื‘ืจ. ื”ื™ื™ืชื™ ืฆืจื™ืš ืœืœื›ืช ืœืขื‘ื•ื“ื”.

ื•ืจืง ืื—ืจ ื›ืš, ื›ืฉื”ืขืžืงืชื™ ื‘ืกื™ื˜ื•ืืฆื™ื” ื•ื”ื‘ื ืชื™ ืงืฆืช ืืช ื”ื‘ืขื™ื”, ืื“ื ื—ื›ื ืื—ื“ ืืžืจ ืœื™ ืื™ืš ืœืคืชื•ืจ ืื•ืชื”. ื”ื™ื” ืฆื•ืจืš ืœื”ืชื—ื‘ืจ ืœืฉืจืช ื”ื“ื•ืืจ ืœื ืกืชื, ืืœื ื“ืจืš VPN

ืื ื™ ืžืฉืชืžืฉ ื‘-vpn-slice ื›ื“ื™ ืœืขื‘ื•ืจ ื“ืจืš ื”-VPN ืœื›ืชื•ื‘ื•ืช ืฉืžืชื—ื™ืœื•ืช ื‘-192.168.430. ื•ืœืฉืจืช ื”ื“ื•ืืจ ืœื ืจืง ื™ืฉ ื›ืชื•ื‘ืช ืกืžืœื™ืช ืฉืื™ื ื” ืชืช-ื“ื•ืžื™ื™ืŸ ืฉืœ evilcorp, ื’ื ืื™ืŸ ืœื• ื›ืชื•ื‘ืช IP ืฉืžืชื—ื™ืœื” ื‘-192.168.430. ื•ื›ืžื•ื‘ืŸ ืฉื”ื•ื ืœื ืžืืคืฉืจ ืœืืฃ ืื—ื“ ืžื”ืจืฉืช ื”ื›ืœืœื™ืช ืœื”ื’ื™ืข ืืœื™ื•.

ื›ื“ื™ ืฉืœื™ื ื•ืงืก ื™ืขื‘ื•ืจ ื“ืจืš ื”-VPN ื•ืœืฉืจืช ื”ื“ื•ืืจ, ืขืœื™ืš ืœื”ื•ืกื™ืฃ ืื•ืชื• ื’ื ืœ-vpn-slice. ื ื ื™ื— ืฉื›ืชื•ื‘ืช ื”ื“ื•ืืจ ื”ื™ื 555.555.555.555

echo "fixedPassword567987" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 --user poxvuibr --passwd-on-stdin
--script "./bin/vpn-slice 555.555.555.555 192.168.430.0/24" vpn.evilcorp.com 

ืกืงืจื™ืคื˜ ืœื”ืขืœืืช VPN ืขื ืืจื’ื•ืžื ื˜ ืื—ื“

ื›ืœ ื–ื”, ื›ืžื•ื‘ืŸ, ืœื ืžืื•ื“ ื ื•ื—. ื›ืŸ, ืืชื” ื™ื›ื•ืœ ืœืฉืžื•ืจ ืืช ื”ื˜ืงืกื˜ ื‘ืงื•ื‘ืฅ ื•ืœื”ืขืชื™ืง-ื”ื“ื‘ืง ืื•ืชื• ื‘ืงื•ื ืกื•ืœื” ื‘ืžืงื•ื ืœื”ืงืœื™ื“ ืื•ืชื• ื‘ื™ื“, ืื‘ืœ ื–ื” ืขื“ื™ื™ืŸ ืœื ื ืขื™ื ื‘ืžื™ื•ื—ื“. ื›ื“ื™ ืœื”ืงืœ ืขืœ ื”ืชื”ืœื™ืš, ื ื™ืชืŸ ืœืขื˜ื•ืฃ ืืช ื”ืคืงื•ื“ื” ื‘ืกืงืจื™ืคื˜ ืฉื™ืžื•ืงื ื‘-PATH. ื•ืื– ืชืฆื˜ืจืš ืจืง ืœื”ื–ื™ืŸ ืืช ื”ืงื•ื“ ืฉื”ืชืงื‘ืœ ืž-Google Authenticator

#!/bin/sh  
echo "fixedPassword$1" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 --user poxvuibr --passwd-on-stdin 
--script "./bin/vpn-slice 192.168.430.0/24  jira.vpn.evilcorp.com git.vpn.evilcorp.com " vpn.evilcorp.com 

ืื ืชืฉื™ื ืืช ื”ืกืงืจื™ืคื˜ ื‘-connect~evilcorp~ ืืชื” ื™ื›ื•ืœ ืคืฉื•ื˜ ืœื›ืชื•ื‘ ื‘ืงื•ื ืกื•ืœื”

connect_evil_corp 567987

ืื‘ืœ ืขื›ืฉื™ื• ืืชื” ืขื“ื™ื™ืŸ ืฆืจื™ืš ืœืฉืžื•ืจ ืืช ื”ืงื•ื ืกื•ืœื” ืฉื‘ื” openconnect ืคื•ืขืœ ืคืชื•ื— ืžืกื™ื‘ื” ื›ืœืฉื”ื™

ื”ืคืขืœืช openconnect ื‘ืจืงืข

ืœืžืจื‘ื” ื”ืžื–ืœ, ื”ืžื—ื‘ืจื™ื ืฉืœ openconnect ื“ืื’ื• ืœื ื• ื•ื”ื•ืกื™ืคื• ืžืคืชื— ืžื™ื•ื—ื“ ืœืชื•ื›ื ื™ืช -background, ืฉื’ื•ืจื ืœืชื•ื›ื ื™ืช ืœืขื‘ื•ื“ ื‘ืจืงืข ืœืื—ืจ ื”ื”ืฉืงื”. ืื ืชืคืขื™ืœ ืื•ืชื• ื›ืš, ืชื•ื›ืœ ืœืกื’ื•ืจ ืืช ื”ืงื•ื ืกื•ืœื” ืœืื—ืจ ื”ื”ืฉืงื”

#!/bin/sh  
echo "fixedPassword$1" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 
--user poxvuibr 
--passwd-on-stdin 
--background 
--script "./bin/vpn-slice 192.168.430.0/24  jira.vpn.evilcorp.com git.vpn.evilcorp.com " vpn.evilcorp.com  

ืขื›ืฉื™ื• ืคืฉื•ื˜ ืœื ื‘ืจื•ืจ ืœืืŸ ื”ื•ืœื›ื™ื ื”ื™ื•ืžื ื™ื. ื‘ืื•ืคืŸ ื›ืœืœื™, ืื ื—ื ื• ืœื ื‘ืืžืช ืฆืจื™ื›ื™ื ื™ื•ืžื ื™ื, ืื‘ืœ ืื™ ืืคืฉืจ ืœื“ืขืช. openconnect ื™ื›ื•ืœ ืœื”ืคื ื•ืช ืื•ืชื ืœ-syslog, ืฉื ื”ื ื™ื™ืฉืžืจื• ื‘ื˜ื•ื—ื™ื ื•ืžืื•ื‘ื˜ื—ื™ื. ืืชื” ืฆืจื™ืš ืœื”ื•ืกื™ืฃ ืืช ื”ืžืชื’ โ€“syslog ืœืคืงื•ื“ื”

#!/bin/sh  
echo "fixedPassword$1" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 
--user poxvuibr 
--passwd-on-stdin 
--background 
--syslog 
--script "./bin/vpn-slice 192.168.430.0/24  jira.vpn.evilcorp.com git.vpn.evilcorp.com " vpn.evilcorp.com  

ื•ื›ืš, ืžืกืชื‘ืจ ืฉ-openconnect ืขื•ื‘ื“ ืื™ืคืฉื”ื• ื‘ืจืงืข ื•ืœื ืžืคืจื™ืข ืœืืฃ ืื—ื“, ืื‘ืœ ืœื ื‘ืจื•ืจ ืื™ืš ืœืขืฆื•ืจ ืืช ื–ื”. ื›ืœื•ืžืจ, ืืคืฉืจ ื›ืžื•ื‘ืŸ ืœืกื ืŸ ืืช ืคืœื˜ ื”-ps ื‘ืืžืฆืขื•ืช grep ื•ืœื—ืคืฉ ืชื”ืœื™ืš ืฉืฉืžื• ืžื›ื™ืœ openconnect, ืื‘ืœ ื–ื” ืื™ื›ืฉื”ื• ืžื™ื™ื’ืข. ืชื•ื“ื” ื’ื ืœื›ื•ืชื‘ื™ื ืฉื—ืฉื‘ื• ืขืœ ื–ื”. ืœ-Openconnect ื™ืฉ ืžืคืชื— -pid-file, ืฉื‘ืืžืฆืขื•ืชื• ืืชื” ื™ื›ื•ืœ ืœื”ื•ืจื•ืช ืœ-openconnect ืœื›ืชื•ื‘ ืืช ืžื–ื”ื” ื”ืชื”ืœื™ืš ืฉืœื• ืœืงื•ื‘ืฅ.

#!/bin/sh  
echo "fixedPassword$1" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 
--user poxvuibr 
--passwd-on-stdin 
--background  
--syslog 
--script "./bin/vpn-slice 192.168.430.0/24  jira.vpn.evilcorp.com git.vpn.evilcorp.com " vpn.evilcorp.com  
--pid-file ~/vpn-pid

ืขื›ืฉื™ื• ืืชื” ืชืžื™ื“ ื™ื›ื•ืœ ืœื”ืจื•ื’ ืชื”ืœื™ืš ืขื ื”ืคืงื•ื“ื”

kill $(cat ~/vpn-pid)

ืื ืื™ืŸ ืชื”ืœื™ืš, ืœื”ืจื•ื’ ื™ืงืœืœ, ืื‘ืœ ืœื ื™ื–ืจื•ืง ืฉื’ื™ืื”. ืื ื”ืงื•ื‘ืฅ ืœื ืงื™ื™ื, ื’ื ืฉื•ื ื“ื‘ืจ ืจืข ืœื ื™ืงืจื”, ื›ืš ืฉืชื•ื›ืœ ืœื”ืจื•ื’ ืืช ื”ืชื”ืœื™ืš ื‘ื‘ื˜ื—ื” ื‘ืฉื•ืจื” ื”ืจืืฉื•ื ื” ืฉืœ ื”ืกืงืจื™ืคื˜.

kill $(cat ~/vpn-pid)
#!/bin/sh  
echo "fixedPassword$1" | openconnect --servercert sha256:4444444444444444444444444444444444444444444444444444444444444444 
--user poxvuibr 
--passwd-on-stdin 
--background 
--syslog 
--script "./bin/vpn-slice 192.168.430.0/24  jira.vpn.evilcorp.com git.vpn.evilcorp.com " vpn.evilcorp.com  
--pid-file ~/vpn-pid

ืขื›ืฉื™ื• ืืชื” ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืืช ื”ืžื—ืฉื‘, ืœืคืชื•ื— ืืช ื”ืžืกื•ืฃ ื•ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื”, ืœื”ืขื‘ื™ืจ ืœื” ืืช ื”ืงื•ื“ ืž-Google Authenticator. ืœืื—ืจ ืžื›ืŸ ื ื™ืชืŸ ืœืžืกืžืจ ืืช ื”ืงื•ื ืกื•ืœื”.

ืœืœื ืคืจื•ืกืช VPN. ื‘ืžืงื•ื ืคืชื™ื—

ื”ืชื‘ืจืจ ืฉืงืฉื” ืžืื•ื“ ืœื”ื‘ื™ืŸ ืื™ืš ืœื—ื™ื•ืช ื‘ืœื™ ื ืชื— VPN. ื”ื™ื™ืชื™ ืฆืจื™ืš ืœืงืจื•ื ื•ืœื—ืคืฉ ื”ืจื‘ื” ื‘ื’ื•ื’ืœ. ืœืžืจื‘ื” ื”ืžื–ืœ, ืื—ืจื™ ืฉื‘ื™ืœื™ืชื™ ื›ืœ ื›ืš ื”ืจื‘ื” ื–ืžืŸ ื‘ื‘ืขื™ื”, ืžื“ืจื™ื›ื™ื ื˜ื›ื ื™ื™ื ื•ืืคื™ืœื• ื—ื™ื‘ื•ืจ ืคืชื•ื— ืœืื“ื ื ืงืจืื• ื›ืžื• ืจื•ืžื ื™ื ืžืจื’ืฉื™ื.

ื›ืชื•ืฆืื” ืžื›ืš, ื’ื™ืœื™ืชื™ ืฉ-vpn-slice, ื›ืžื• ื”ืกืงืจื™ืคื˜ ื”ืžืงื•ืจื™, ืžืฉื ื” ืืช ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘ ืœืจืฉืชื•ืช ื ืคืจื“ื•ืช.

ื˜ื‘ืœืช ื ื™ืชื•ื‘

ื‘ืžื™ืœื™ื ืคืฉื•ื˜ื•ืช, ื–ื• ื˜ื‘ืœื” ื‘ืขืžื•ื“ื” ื”ืจืืฉื•ื ื” ืฉืžื›ื™ืœื” ืžื” ื”ื›ืชื•ื‘ืช ืฉืœื™ื ื•ืงืก ืจื•ืฆื” ืœืขื‘ื•ืจ ื‘ื” ืฆืจื™ื›ื” ืœื”ืชื—ื™ืœ, ื•ื‘ืขืžื•ื“ื” ื”ืฉื ื™ื™ื” ืขืœ ืื™ื–ื” ืžืชืื ืจืฉืช ืœืขื‘ื•ืจ ื‘ื›ืชื•ื‘ืช ื”ื–ื•. ืœืžืขืฉื”, ื™ืฉ ื™ื•ืชืจ ื“ื•ื‘ืจื™ื, ืื‘ืœ ื–ื” ืœื ืžืฉื ื” ืืช ื”ืžื”ื•ืช.

ืขืœ ืžื ืช ืœืฆืคื•ืช ื‘ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘, ืขืœื™ืš ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื” ip route

default via 192.168.1.1 dev wlp3s0 proto dhcp metric 600 
192.168.430.0/24 dev tun0 scope link 
192.168.1.0/24 dev wlp3s0 proto kernel scope link src 192.168.1.534 metric 600 
192.168.430.534 dev tun0 scope link 

ื›ืืŸ, ื›ืœ ืงื• ืื—ืจืื™ ืœืืŸ ืืชื” ืฆืจื™ืš ืœื”ื’ื™ืข ื›ื“ื™ ืœืฉืœื•ื— ื”ื•ื“ืขื” ืœื›ืชื•ื‘ืช ื›ืœืฉื”ื™. ื”ืจืืฉื•ืŸ ื”ื•ื ืชื™ืื•ืจ ื”ื™ื›ืŸ ื”ื›ืชื•ื‘ืช ืฆืจื™ื›ื” ืœื”ืชื—ื™ืœ. ื›ื“ื™ ืœื”ื‘ื™ืŸ ืื™ืš ืœืงื‘ื•ืข ืฉ-192.168.0.0/16 ืื•ืžืจ ืฉื”ื›ืชื•ื‘ืช ืฆืจื™ื›ื” ืœื”ืชื—ื™ืœ ื‘-192.168, ืฆืจื™ืš ืœื—ืคืฉ ื‘ื’ื•ื’ืœ ืžื”ื™ ืžืกื™ื›ืช ื›ืชื•ื‘ืช IP. ืื—ืจื™ dev ื™ืฉ ืืช ืฉื ื”ืžืชืื ืฉืืœื™ื• ื™ืฉ ืœืฉืœื•ื— ืืช ื”ื”ื•ื“ืขื”.

ืขื‘ื•ืจ VPN, ืœื™ื ื•ืงืก ื™ืฆืจื” ืžืชืื ื•ื™ืจื˜ื•ืืœื™ - tun0. ื”ืงื• ืžื‘ื˜ื™ื— ืฉืชืขื‘ื•ืจื” ืœื›ืœ ื”ื›ืชื•ื‘ื•ืช ื”ื—ืœ ืž-192.168 ืขื•ื‘ืจืช ื“ืจื›ื•

192.168.0.0/16 dev tun0 scope link 

ืืชื” ื™ื›ื•ืœ ื’ื ืœื”ืกืชื›ืœ ืขืœ ื”ืžืฆื‘ ื”ื ื•ื›ื—ื™ ืฉืœ ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘ ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ืžืกืœื•ืœ -ื  (ื›ืชื•ื‘ื•ืช IP ืขื•ื‘ืจื•ืช ืื ื•ื ื™ืžื™ื•ืช ื‘ืฆื•ืจื” ื—ื›ืžื”) ืคืงื•ื“ื” ื–ื• ืžืคื™ืงื” ืชื•ืฆืื•ืช ื‘ืฆื•ืจื” ืฉื•ื ื” ื•ื‘ื“ืจืš ื›ืœืœ ืžื‘ื•ื˜ืœืช, ืืš ื”ืคืœื˜ ืฉืœื” ื ืžืฆื ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื‘ืžื“ืจื™ื›ื™ื ื‘ืื™ื ื˜ืจื ื˜ ื•ืืชื” ืฆืจื™ืš ืœื”ื™ื•ืช ืžืกื•ื’ืœ ืœืงืจื•ื ืื•ืชื•.

ื”ื™ื›ืŸ ืืžื•ืจื” ืœื”ืชื—ื™ืœ ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืžืกืœื•ืœ ื ื™ืชืŸ ืœื”ื‘ื™ืŸ ืžื”ืฉื™ืœื•ื‘ ืฉืœ ื”ืขืžื•ื“ื•ืช Destination ื•- Genmask. ืื•ืชื ื—ืœืงื™ื ืฉืœ ื›ืชื•ื‘ืช ื”-IP ื”ืชื•ืืžื™ื ืืช ื”ืžืกืคืจื™ื 255 ื‘-Genmask ื ืœืงื—ื™ื ื‘ื—ืฉื‘ื•ืŸ, ืื‘ืœ ืืœื” ืฉื‘ื”ื ื™ืฉ 0 ืœื. ื›ืœื•ืžืจ, ื”ืฉื™ืœื•ื‘ ืฉืœ ื™ืขื“ 192.168.0.0 ื•-Genmask 255.255.255.0 ืื•ืžืจ ืฉืื ื”ื›ืชื•ื‘ืช ืžืชื—ื™ืœื” ื‘-192.168.0, ืื– ื”ื‘ืงืฉื” ืืœื™ื” ืชืขื‘ื•ืจ ื‘ืžืกืœื•ืœ ื–ื”. ื•ืื ื™ืขื“ 192.168.0.0 ืื‘ืœ Genmask 255.255.0.0, ืื– ื‘ืงืฉื•ืช ืœื›ืชื•ื‘ื•ืช ืฉืžืชื—ื™ืœื•ืช ื‘-192.168 ื™ืขื‘ืจื• ืœืื•ืจืš ื”ืžืกืœื•ืœ ื”ื–ื”

ื›ื“ื™ ืœื”ื‘ื™ืŸ ืžื” ื‘ืขืฆื ืขื•ืฉื” vpn-slice, ื”ื—ืœื˜ืชื™ ืœื”ืกืชื›ืœ ืขืœ ื”ืžืฆื‘ื™ื ืฉืœ ื”ื˜ื‘ืœืื•ืช ืœืคื ื™ ื•ืื—ืจื™

ืœืคื ื™ ื”ืคืขืœืช ื”-VPN ื–ื” ื”ื™ื” ื›ื›ื”

route -n 

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         222.222.222.1   0.0.0.0         UG    600    0        0 wlp3s0
222.222.222.0   0.0.0.0         255.255.255.0   U     600    0        0 wlp3s0
333.333.333.333 222.222.222.1   255.255.255.255 UGH   0      0        0 wlp3s0

ืœืื—ืจ ื”ืชืงืฉืจื•ืช ืœ-openconnect ืœืœื vpn-slice ื–ื” ื”ืคืš ืœื”ื™ื•ืช ื›ื›ื”

route -n

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         0.0.0.0         0.0.0.0         U     0      0        0 tun0
0.0.0.0         222.222.222.1   0.0.0.0         UG    600    0        0 wlp3s0
222.222.222.0   0.0.0.0         255.255.255.0   U     600    0        0 wlp3s0
333.333.333.333 222.222.222.1   255.255.255.255 UGH   0      0        0 wlp3s0
192.168.430.0   0.0.0.0         255.255.255.0   U     0      0        0 tun0
192.168.430.534 0.0.0.0         255.255.255.255 UH    0      0        0 tun0

ื•ืื—ืจื™ ืฉื”ืชืงืฉืจืชื™ ืœ-openconnect ื‘ืฉื™ืœื•ื‘ ืขื vpn-slice ื›ืžื• ื–ื”

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         222.222.222.1   0.0.0.0         UG    600    0        0 wlp3s0
222.222.222.0   0.0.0.0         255.255.255.0   U     600    0        0 wlp3s0
333.333.333.333 222.222.222.1   255.255.255.255 UGH   0      0        0 wlp3s0
192.168.430.0   0.0.0.0         255.255.255.0   U     0      0        0 tun0
192.168.430.534 0.0.0.0         255.255.255.255 UH    0      0        0 tun0

ื ื™ืชืŸ ืœืจืื•ืช ืฉืื ืืชื” ืœื ืžืฉืชืžืฉ ื‘-vpn-slice, ืื– openconnect ื›ื•ืชื‘ ื‘ืžืคื•ืจืฉ ืฉื™ืฉ ืœื’ืฉืช ืœื›ืœ ื”ื›ืชื•ื‘ื•ืช, ืžืœื‘ื“ ืืœื• ืฉืฆื•ื™ื ื• ื‘ืžืคื•ืจืฉ, ื“ืจืš vpn.

ืžืžืฉ ื›ืืŸ:

0.0.0.0         0.0.0.0         0.0.0.0         U     0      0        0 tun0

ืฉื, ืœื™ื“ื•, ืžืฆื•ื™ืŸ ืžื™ื“ ื ืชื™ื‘ ื ื•ืกืฃ, ืฉื‘ื• ื™ืฉ ืœื”ืฉืชืžืฉ ืื ื”ื›ืชื•ื‘ืช ืฉ-Linux ืžื ืกื” ืœืขื‘ื•ืจ ื“ืจื›ื” ืื™ื ื” ืชื•ืืžืช ืืฃ ืžืกื™ื›ื” ืžื”ื˜ื‘ืœื”.

0.0.0.0         222.222.222.1   0.0.0.0         UG    600    0        0 wlp3s0

ื›ื‘ืจ ื›ืชื•ื‘ ื›ืืŸ ืฉื‘ืžืงืจื” ื–ื” ืฆืจื™ืš ืœื”ืฉืชืžืฉ ื‘ืžืชืื Wi-Fi ืกื˜ื ื“ืจื˜ื™.

ืื ื™ ืžืืžื™ืŸ ืฉื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื ืชื™ื‘ ื”-VPN ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ื”ืจืืฉื•ืŸ ื‘ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘.

ื•ืชื™ืื•ืจื˜ื™ืช, ืื ืชืกื™ืจ ืืช ื ืชื™ื‘ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื–ื” ืžื˜ื‘ืœืช ื”ื ื™ืชื•ื‘, ืื– ื‘ืฉื™ืœื•ื‘ ืขื dnsmasq openconnect ืืžื•ืจ ืœื”ื‘ื˜ื™ื— ืคืขื•ืœื” ืชืงื™ื ื”.

ื ื™ืกื™ืชื™

route del default

ื•ื”ื›ืœ ืขื‘ื“.

ื ื™ืชื•ื‘ ื‘ืงืฉื•ืช ืœืฉืจืช ื“ื•ืืจ ืœืœื vpn-slice

ืื‘ืœ ื™ืฉ ืœื™ ื’ื ืฉืจืช ื“ื•ืืจ ืขื ื”ื›ืชื•ื‘ืช 555.555.555.555, ืฉื’ื ืืœื™ื• ืฆืจื™ืš ืœื’ืฉืช ื“ืจืš VPN. ื™ืฉ ืœื”ื•ืกื™ืฃ ื’ื ืืช ื”ืžืกืœื•ืœ ืืœื™ื• ื‘ืื•ืคืŸ ื™ื“ื ื™.

ip route add 555.555.555.555 via dev tun0

ื•ืขื›ืฉื™ื• ื”ื›ืœ ื‘ืกื“ืจ. ืื– ืืชื” ื™ื›ื•ืœ ืœื”ืกืชื“ืจ ื‘ืœื™ vpn-slice, ืื‘ืœ ืืชื” ืฆืจื™ืš ืœื“ืขืช ื”ื™ื˜ื‘ ืžื” ืืชื” ืขื•ืฉื”. ืขื›ืฉื™ื• ืื ื™ ื—ื•ืฉื‘ ืœื”ื•ืกื™ืฃ ืœืฉื•ืจื” ื”ืื—ืจื•ื ื” ืฉืœ ื”ืกืงืจื™ืคื˜ ื”ืžืงื•ืจื™ ืฉืœ openconnect ืืช ื”ืกืจืช ืžืกืœื•ืœ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื•ืœื”ื•ืกื™ืฃ ืžืกืœื•ืœ ืขื‘ื•ืจ ื”ื“ื•ืืจ ืœืื—ืจ ื”ืชื—ื‘ืจื•ืช ืœ-vpn, ืจืง ื›ื“ื™ ืฉื™ื”ื™ื• ืคื—ื•ืช ื—ืœืงื™ื ื ืขื™ื ื‘ืื•ืคื ื™ื™ื ืฉืœื™.

ื›ื›ืœ ื”ื ืจืื”, ื”ืžืืžืจ ื”ื‘ื ื”ื–ื” ื™ืกืคื™ืง ื›ื“ื™ ืฉืžื™ืฉื”ื• ื™ื‘ื™ืŸ ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ VPN. ืื‘ืœ ื‘ื–ืžืŸ ืฉื ื™ืกื™ืชื™ ืœื”ื‘ื™ืŸ ืžื” ื•ืื™ืš ืœืขืฉื•ืช, ืงืจืืชื™ ื“ื™ ื”ืจื‘ื” ืžื“ืจื™ื›ื™ื ื›ืืœื” ืฉืขื•ื‘ื“ื™ื ืขื‘ื•ืจ ื”ืžื—ื‘ืจ, ืื‘ืœ ืžืฉื•ื ืžื” ืœื ืขื•ื‘ื“ื™ื ื‘ืฉื‘ื™ืœื™, ื•ื”ื—ืœื˜ืชื™ ืœื”ื•ืกื™ืฃ ื›ืืŸ ืืช ื›ืœ ื”ืงื˜ืขื™ื ืฉืžืฆืืชื™. ื”ื™ื™ืชื™ ืžืื•ื“ ืฉืžื— ืขืœ ื“ื‘ืจ ื›ื–ื”.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”