Skip to content
/ flower Public
forked from secgroup/flower

TCP flow analyzer with sugar for A/D CTF

License

Notifications You must be signed in to change notification settings

chgue/flower

 
 

Repository files navigation

Flower

Automatic packet analyzer made by Ca' Foscari team (unive) for CyberChallenge attack/defense CTF of 27/06/2018. This tool was written in less than ten days. Every pull request is welcome!

Presentation of Flower (from min 7:30), and general introduction to CTF at ESC2K18 in italian:

tools presentation

Install

git clone https://github.com/secgroup/flower
cd flower
npm install 
pip install -r services/requirements.txt

Setup

Env var to set:

  • REACT_APP_FLOWER_SERVER_IP ip of the host that will have flower services and db active
  • REACT_APP_FLAG_REGEX regex that match flags. Mongodb is required on the same machine that run the services. To start it: sudo mongod --dbpath /path/to/mongodb/db --bind_ip 0.0.0.0

Run

Start flower

./run.sh

Start flower services

cd services
./run_ws.sh

Once everything has been started, flower should be accessible at the address of the machine that started it on port 3000.

Pcap import

You must first install pynids from here. The pip version is outdated! Good luck with the installation. Then, you can import pcaps into mongodb by executing the provided script importer.py as follows:

cd services
./importer.py pcap_file.pcap

You can find a test_pcap in services/test_pcap. For a quick demo, run ./importer.py test_pcap/dump-2018-06-27_13:25:31.pcap

Security tips

If you are going to use flower in a CTF, remember to set up the firewall in the most appropriate way, as the current implementation does not use other security techniques.

Features

  • Flow list
  • Vim like navigation ( k and j to navigate the list)
  • Regex filtering with highlight
  • Highlight in red flow with flags
  • Favourite management
  • Time filter
  • Service filter
  • Colored hexdump
  • Automatic export GET/POST request directly in python format
  • Automatic export to pwntools

Credits

With the support of c00kies@venice

About

TCP flow analyzer with sugar for A/D CTF

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages

  • JavaScript 67.0%
  • Python 19.6%
  • Shell 7.0%
  • CSS 3.6%
  • HTML 2.8%