PiRogueToolSuite / project-management

Put in one place all the user stories and the tasks associated to them
0 stars 0 forks source link

Take a watermarked capture/recording of the phone screen #21

Open U039b opened 10 months ago

U039b commented 10 months ago

Users can take a watermarked capture or recording of their phone screen.

U039b commented 4 months ago

Proposed implementation: The entry point is a single command to be executed on the PiRogue. This command will:

  1. ask for an arbitrary name corresponding to the victim's name, organization name, etc.
  2. ask for the responder's name, email and organization
  3. save the information into a JSON file
  4. create a directory where the files will be stored
  5. tell the victim to take screenshots and/or record the screen of their phone (Android doc, iOS doc)
  6. start a droopy server accessible from the isolated network
  7. connect the victim's phone to the PiRogue access point
  8. browse Droopy URL (has to be simple)
  9. upload all the screenshots and/or recordings
  10. shutdown the Droopy server
  11. append exif data including responder's name, email and organization
  12. add a watermark on the files
  13. store the checksum of the files
U039b commented 3 months ago

This month

Along with a reorganization of the PiRogue Debian packages, we are introducing a new package pirogue-evidence-collector creating the following entry points:

Next month

We are planning to release this Debian package next month.

Challenges

The primary challenge was to establish a mechanism for offline timestamp verification exclusively reliant upon OpenSSL.

U039b commented 2 months ago

This month

The two commands responsible for intercepting TLS client randoms now utilize friTap. Given that friTap supports a broader range of TLS implementations compared to our initial implementation, we have decided to integrate friTap directly.

We have added the dynamic generation of hooks to the commands pirogue-intercept-[gated|single]. The different Frida hooks to be generated and injected are defined by the user in JSON format. This feature will be documented when the Debian package will be released.

The release of the Debian package has been postponed, more testing has to be performed before its first release.

Next month

We are planning to document and release this Debian package next month.

Challenges

None.

U039b commented 3 weeks ago

This month

The first version of the pirogue-evidence-collector has been released, but it's not documented yet. This package is now installed by default on PiRogue and provides the user with the following commands:

Next month

The implementation of the command pirogue-file-drop is not completed, as it needs to interact with the newly released administration tool to temporarily open a port on the isolated network. This integration will be done next month. Once all the commands are fully functional, we will publish the documentation.

Challenges

None.