Experimental Design of Intranet Penetration for Anti Anti-Virus Traffic Characterization

Peifeng Xiong, Deqiang Yang, Bin Wen · 2024

Due to the continuous evolution of modern network threats, comprehensive internal network penetration testing experiments can assist penetration testers in simulating external attacks and identifying potential threats. This, in turn, aids in the development and deployment of effective defense measures. However, the traffic characteristics generated by Frp intranet penetration are currently recognized and blocked by existing network security devices, resulting in the termination of established TCP connections. Therefore, this paper presents a complete internal network penetration testing experiment designed to address the issues of evading Frp traffic characteristics and implementing multi-layer encoding evasion for reverse shell files. The experiment involves setting up an Frp server on Alibaba Cloud and configuring a client on the Kali attack machine. Various evasion techniques are applied to Frp tools, including source code modifications, traffic encryption, and feature obfuscation. Additionally, Cobalt Strike penetration testing tools are used to disassemble and pack reverse shell files, thereby gaining control of the target machine's shell. This successful implementation of internal network penetration testing evading Frp features across different local area network environments is crucial for penetration testers to address internal network penetration challenges, allowing them to circumvent antivirus software and security protection effectively and conduct penetration testing activities seamlessly.

Read the paper · More papers on PaperTik