mitre / caldera

Automated Adversary Emulation Platform
https://caldera.mitre.org
Apache License 2.0
5.54k stars 1.05k forks source link

'Exfilled Files' zip files are returning inaccurate files #2995

Open timbrigham-oc opened 3 months ago

timbrigham-oc commented 3 months ago

Describe the bug When a zip file is exfiltrated and then downloaded from the caldera UI, an internal caldera HTML file is returned instead.

To Reproduce Steps to reproduce the behavior:

  1. Utilize the 'Thief' adversary template
  2. On successful 'Exfil staged directory' completion
  3. Verify that the 'staged.zip' file is accurate on the agent (it opens normally and contains a list of files)
  4. Download the zip file from 'Exfilled Files', attempt to open as a zip. Reports malformed.
  5. Open in a text editor.

Screenshots Operation image Exfilled file UI image Downloaded staged.zip image

Desktop (please complete the following information): Windows 11, happens in latest Chrome and Edge. CALDERA is version 5.0.0.

guillaume-duong-bib commented 3 months ago

I do not encounter this issue on the latest versions of Chrome, Edge, or Firefox (win10 however), with the latest master branch. image*

Can you check manually what the file looks like on the server, so that we know whether it's the file or the download process that fails?

elegantmoose commented 2 months ago

@timbrigham-oc are you still having this issue?

github-actions[bot] commented 2 weeks ago

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days