Professional Documents
Culture Documents
65-beta
unlocking without popping banners, errors and restarts.
Method is named “MITM F#CK Cesbo”!
Please keep this stuff to yourself, if you want it to work in
future versions.
Brief description:
I don’t know what the heck, but Astra does not encrypt the
traffic carrying licensing information between their servers
and executable binary in up to current 5.65 beta versions
at the moment of writing. It just passed in plain http, so we
are going to intercept and alter it. However, dev does try to
do weird stuff with DNS records of his lic servers and
bypassed system hosts file (this is actually funny and pity
attempts), also uses some sort of signing of requests,
which makes it unable to fake with local server, so this
method IS STILL ONLINE but using either expired or
currently active trial license.
Things needed:
———————————————————
- Enable forwarding:
net.ipv4.ip_forward=1
Execute
sysctl -p
- Install
apt install redsocks
- Enable on boot
systemctl enable redsocks
- Edit /etc/redsocks.conf, wipe it all down clean and
paste following:
base {
log_debug = on;
log_info = on;
log = "syslog:daemon";
daemon = on;
user = redsocks;
group = redsocks;
redirector = iptables;
}
redsocks {
local_ip = 127.0.0.1;
local_port = 9050;
- Start service
systemctl start redsocks
*filter
:INPUT ACCEPT [8:26556]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [8:26556]
COMMIT
*nat
:OUTPUT ACCEPT [0:0]
-A OUTPUT -p tcp -d
104.248.91.131,78.128.94.139,46.47.24.76,95.217.208.47
,95.217.236.37,95.216.178.128 -m multiport --dports
80,443 -m owner ! --uid-owner redsocks -j REDIRECT --
to-ports 9050
COMMIT
- Execute
systemctl restart netfilter-persistent
Has to show no errors!!! Otherwise you did not enter the
rules above correctly, check again!
3) Astra Cesbo ON Linux (Ubuntu explained) host
Check http://LINUX_HOST_IP_WITH_ASTRA:8000
If all set right, you will see it like this below (this document
is encoded as RTFD, if you don’t see screenshot below,
look in the folder):
Now click the same line again and select “Map Local” all the way on the bottom. Leave
everything as is, but point a location of saved previously file. If you need to edit this
later, Map menu is located in Tools.
Now Restart Astra, select the appeared line in Sessions again, verify HEADERS
response is X-Charles-Map-Local
The secure tunnel whatever is for used to spy after you, will be automatically cut off by
Charles, you’ll see red crosses, it’s expected.