Jump to content
Nytro

Tunna

Recommended Posts

Posted

Overview

Tunna is a tool designed to bypass firewall restrictions on remote webservers. It consists of a local application (supporting Ruby and Python) and a web application (supporting ASP.NET, Java and PHP).

simple_tunna.png

Description

Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled environments. The web application file must be uploaded on the remote server. It will be used to make a local connection with services running on the remote web server or any other server in the DMZ. The local application communicates with the webshell over the HTTP protocol. It also exposes a local port for the client application to connect to.

Since all external communication is done over HTTP it is possible to bypass the filtering rules and connect to any service behind the firewall using the webserver on the other end.

Tunna framework

Tunna framework comes witht he following functionality:

[TABLE=width: 90%, align: center]

[TR]

[TD]icolockblack.gif[/TD]

[TD=class: txt12]Ruby client - proxy bind: Ruby client proxy to perform the tunnel to the remote web application and tunnel TCP traffic.[/TD]

[/TR]

[TR]

[TD]icolockblack.gif[/TD]

[TD=class: txt12]Python client - proxy bind: Python client proxy to perform the tunnel to the remote web application and tunnel TCP traffic.[/TD]

[/TR]

[TR]

[TD]icolockblack.gif[/TD]

[TD=class: txt12]Metasploit integration module, which allows transparent execution of metasploit payloads on the server[/TD]

[/TR]

[TR]

[TD]icolockblack.gif[/TD]

[TD=class: txt12]ASP.NET remote script[/TD]

[/TR]

[TR]

[TD]icolockblack.gif[/TD]

[TD=class: txt12]Java remote script[/TD]

[/TR]

[TR]

[TD]icolockblack.gif[/TD]

[TD=class: txt12]PHP remote script[/TD]

[/TR]

[/TABLE]

Author

Tunna has been developed by Nikos Vassakis.

Download:

http://www.secforce.com/research/tunna_download.html

Sursa: SECFORCE :: Penetration Testing :: Research

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...