Forgottenhell Mac OS
And I'm on a Mac. I'm at the point where I have an object file created from nasm, and I want to turn it into an ELF executable using ld. The ld on a mac doesn't look like it supports the ELF format, but I don't want to run a virtual machine with Ubuntu just to do this link step. Note: The headings on this list indicate the Macintosh System bundle names; the bullet points indicate the version of the System File included in that bundle. This is to make it clearer for people searching for specific bundle versions as opposed to System File versions. Finder File versions are not indicated. 1 Classic Mac OS 1.1 Macintosh System Software (0 - 0.3) 1.1.1 System File 1 1.1.2.
Introduction
EggShell is an iOS/macOS and Linux post exploitation surveillance pentesting tool written in Python. With EggShell you’ll be able to:
- upload/download files, take pictures, track location, execute shell command, retrieve passwords, and much more.
EggShell: Post Exploitation Surveillance Tool
This remote administration tool provides a command line session with additional functionality between you and target machine. EggShell comes packed with a wide variety of features.
Features:
- Tab completion,
- File manipulation (upload/download/delete, etc.),
- Full camera and microphone control,
- Location Tracking,
- Shell command execution,
- Persistence,
- Escalating privileges,
- Tacking Pictures,
- Password Retrieval,
- iTunes/iMessages manipulation, etc.
EggShell Install
Requirements:
- python 2.7
Clone it from the Githhub.
MacOS/Linux:
iOS (Jailbroken Only):
- Add Cydia source: http://lucasjackson.io/repo
- Install EggShell 3
- Run the command
eggshell
(use any mobile terminal application)
Payloads
Eggshell payloads are executed on the target machine. After we retrieve device details, server will establish a secure remote control session. There are 2 different payload options:
- bash
- Teensy (macOS)
Forgotten Hell Mac Os X
Forgotten Hell Mac Os Catalina
Sessions
After a session is established, you can execute commands on that device through the EggShell command line interface. Type help
to show all available commands.
Multihandler
Multihandler option allow us to handle multiple sessions. You can also show Multihandler commands (similar to the sessions), just type help
.
Taking Pictures/Recording Audio
Both iOS and macOS sessions support taking pictures and recording audio.
Taking pictures:
macOS
: (picture command) takes a picture through the front facing iSight camera,iOS
: requires 1 argument specifying ‘front’ or ‘back’ facing camera.
Recording audio:
- When it came to recording audio, the process is same for both iOS and macOS. The argument for this command will specify the
record
orstop
action. Recording will run in the background, so you’ll be able to execute additional commands during the recording. When the recording is finished, the file will be downloaded and saved.
To see detailed EggShell feature explanation, click the documentation link bellow.
Commands
macOS:
brightness
: adjust screen brightnesscd
: change directorydownload
: download filegetfacebook
: retrieve facebook session cookiesgetpaste
: pasteboard contentsgetvol
: get speaker output volumeidletime
: get the amount of time since the keyboard/cursor were touchedimessage
: send message through the messages appitunes
: iTunes Controllerkeyboard
: your keyboard -> is target’s keyboardlazagne
: firefox password retrievalls
: list contents of a directorymic
: record micpersistence
: attempts to re establish connection after closepicture
: take picture through iSightpid
: get process idprompt
: prompt user to type passwordscreenshot
: take screenshotsetvol
: set output volumesleep
: put device into sleep modesu
: su loginsuspend
: suspend current session (goes back to login screen)upload
: upload file
Linux:
cd
: change directorydownload
: download filels
: list contents of a directorypid
: get process idpwd
: show current directoryupload
: upload file
Forgotten Hell Mac Os Catalina
iOS:
alert
: make alert show up on devicebattery
: get battery levelbundleids
: list bundle identifierscd
: change directorydhome
: simulate a double home button pressdial
: dial a phone numberdownload
: download filegetcontacts
: gets addressbookgetnotes
: download notesgetpasscode
: retreive the device passcodegetsms
: download SMSgetvol
: get volume levelhome
: simulate a home button pressinstallpro
: install substrate commandsipod
: control music playerislocked
: check if the device is lockedlastapp
: get last opened applicationlocate
: get device location coordinateslocationservice
: toggle location serviceslock
: simulate a lock button pressls
: list contents of a directorymic
: record micmute
: update and view mute statusopen
: open appsopenurl
: open url on devicepersistence
: attempts to re establish connection after closepicture
: take picture through the front or back camerapid
: get process idrespring
: restart springboardsafemode
: put device into safe modesay
: text to speachsetvol
: set device volumesysinfo
: view system informationupload
: upload filevibrate
: vibrate device
You may also like:
Is the copy of El Capitan you are retrying to install an old copy you downloaded some time ago.
Recently the certificates for certain Mac OS's expired making it difficult or impossible to install them.
Apple released updated versions with new valid certificates, so you could try downloading the updated
release of El Capitan, from here. How to upgrade to OS X El Capitan – Apple Support
Please note there are different instructions, read Sections 4 to 7 completely.
At Section 4 you click on Download OS X El Capitan, this will download Install MACOSX.dmg.
Double-click on Install MACOSX.dmg and you will then get Install MACOSX.pkg.
Double click on that and an installation window will open, this does not install El Capitan but converts
Install MACOSX.pkg to Install OS X El Capitan.app which will be in your Application folder.
Use that to install El Capitan.
Dec 1, 2019 11:17 PM