From 773970211297c39b2d86cd67dd510c0b0aaabcd7 Mon Sep 17 00:00:00 2001 From: Samuel Pritchard Date: Wed, 31 Mar 2021 16:22:08 +0100 Subject: [PATCH 1/2] Add the update cron and clean up ssh keys --- terraform/cloudinit/kali-instance.yaml | 11 +++++++++++ terraform/main.tf | 6 +++++- 2 files changed, 16 insertions(+), 1 deletion(-) diff --git a/terraform/cloudinit/kali-instance.yaml b/terraform/cloudinit/kali-instance.yaml index 0200225..942b372 100644 --- a/terraform/cloudinit/kali-instance.yaml +++ b/terraform/cloudinit/kali-instance.yaml @@ -23,6 +23,17 @@ write_files: empiredir=`dirname $empirecmd` cd $empiredir ./empire + - path: /usr/local/bin/update-kali + permissions: '0755' + content: | + #!/bin/sh + apt-get update -y && apt-get upgrade -y && apt-get dist-upgrade -y + apt-get autoclean -y && apt-get clean -y + apt-get autoremove + - path: /etc/crontab + content: | + 0 7 * * * /usr/local/bin/update-kali + append: true bootcmd: - | diff --git a/terraform/main.tf b/terraform/main.tf index 2828d50..1b41561 100644 --- a/terraform/main.tf +++ b/terraform/main.tf @@ -17,9 +17,13 @@ locals { # Set your SSH public keys here for who you want to be able to access the instance # Remove the existing keys ssh-keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQChXVB0+ZEc2KB1147WHGbhSUGyB2xeLnwJ4CW9V9hWdTgGWMuiWOcgFc1BGGbQ2I6Be939/JzqmsNOlguB0Qq5OJgcHelgB2+qAqEb1I9gYwKFFoIOIpiG5WNNKfbY+C2OjW6zCy9n0bNdXuSDzG2becfeCtSurdoVQNwt54AEXNtQAjUqPk+T4pHpMdWpDIMamDw8PY8PG3hypr6ao5vy/vBOaIKezAGIsDnr8eVIVkaV/TCE9RRQLxpN/tXCowzRbAmIko7so5iKoQOXSzHLMk/dehDk4oQg8pdRG7n/QW3NXFg1KbS3STgUb/8uigwAVRWCEd9LysDaceUISZ2JOP2f692f/z2rA1gCQiM5qJBOTGzL980PfcnTcKA8LI7A//S+UdWEONThQlpnZf+aFTaLHLvuBNO4awOoMorDkI7FMUvyGTHKJVHqebHwBoFMKghn9tzQ/GKK+o0zNgZ5nZaVGRRzRhxv/UueYVPPlRAf0w5GRPzx4vyOc7PE4M6amIDrIG8xojVFn8m3KwQumU78m297HzWtK3CSJSDrU1k2gpHdM/8AArRtYhIyPl7w/CaC+GrVMpG3I4r1HFzR92qQ66aUanoqr40CXwL+kbyZirt3u4km2c140/qX3UJQYcmObk43MjepFxuVmRIqCqjsfBFp4ZpIqOhQdsr37Q==", + # Sam Pritchard "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDNNsdJTe3Z6n+Qa2i8bVAnT7Db/23tOCKnBmeSBtqkU1EyVL2ByV22qm6SqvOqPCokuXFeY+0llkDWps9K/ZOEAlhGIZ6iRZQVeuc4O37g1Jd5Pe+ITAorqhSXpEzefr2rbR4zfKqI2eQs1LxT+RRrx+e4JqTucGBqIxJofuz2Wka06dXzFtUYv/3wPs5KAdGnLGawnQRhE0LibeSP5ut2NJ0xTkbWBoBgyWMKrzR0+iyqFNR9RghcJLvcmFK/J6KpGrc+FcJQKbQGBkMyR6+Tfs9rwnoOW4JyIpM5XkkhXFrBxVckM1vR6Wt0cNJPlNBBngw9TytnIgijbyjixru3rJd2RU1yjvC5a1SMwhyfYaZAJlNCuJmNDTwKTXeoi5hi7nqmNP7EoywWz+y1Z6BHu02waclYvkMMozU7/Nn6j6EIltbghsNiFL4I2amQDcfRMjjhYqV7wzhPsGV4OSlOwvziEO9kbyl2nPJtYAMKQd5Ox8e8Y6Xu7qFnOJGLKLMr2FZm+xCh8IO5428YbziIqo8JUSQknFaTW+wQYPxbNys7oyeOd5OH8pkvzwyyQYEu83AiMcwzbqLwBdNxoQ0Q17pQw+jnFuPq4EgMrGupI8hwYRVzR9AkQtOABZ0hi9sSDT4VAxQvbcymnCed3MGMi4urnASOXWcHQXgfaxPK2w==", + # Ovas Iqbal + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC9kI6Dv5GgmlGgHymBnCAAZabXaR8Df+OMZJN1iw/w7R4l9jqvPNa+G9Te5X5BE2TVLATsucd6jTzIDAIz2xGpWnEFt+I8REVKXfCHBKAoBLaIHqBOoW6U+eTvC8pUWMpjXSda2d6Ew/Ggj3R+VylyR4Ouq2cgxK3Dxlg1cm7nc34V0HsPZdxqzMR1BUGzDnUk+ehrgArsuNj1pxnmMK3YkoftLPIeIrBzfqQ7p6sg/k1eWwPumfoGQegA8fYaJshpM8wxIbL7N6EJ9GTg2PJMsN11BF7ko0qax+qwisAWOvXupm315U0D3LQ6Ikv88+SItqdalKu0Qkyt3Q22a1TM+uzfzrcc5Q0ZQmvtzftioCzkjw8bpDciagXMD7Q8rl5E35syzmR3jeiymamw31BBpRsAGHhWQoGY8xscvEUJKnXuWSb7Q9CG89MTOcfHgEWpx46bmjFqKSENOC9EcjlF7UxF7+aYvAC/3vWt1FiBF5Sw6BnjbanyCovR1TSqr7LogoJ95nY7oxUXrLnDmDGrF9z8MnXtTrDLBt6upttumb5O1uTbmrFVKPRDryYGgH81/YSLjeoRjj1NhruVGO7gRbzJe9fRWLgsWDGgxWlr1xqnxfD6sNSLmEJ0+x1FYwTtxM2CdzfrkqIT5q3y0BqbcdvWxlqE9bquy6NZd3tLHw==", + # Mohamed Hussain "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDQSE+tf9oN32B40RypJH8ov7A2K/V45F3R3DblhI8n7H1l/JnbJwsgYAmQMLGqcXlCbre8xZ5qEyR+vPVGF9/2vdnF1Fke3bNuyx8vpdFz+Kx3zDXJ7G20R2sNziVOFnRK93Go/pBtpxpWrrR9sI5vpdI4Cjp7sxFbo7/lL/fipBLA1H5ieUo7b0vVDM8cdNt7aTtc6FmSmjT2T1x4ILAuKptVU68JTLZoEE29RwdCZgkjPkZuaBHF78c3vQXbp8p4mA3gqGG9SYgSoPIGDBY1YQCkBiUm+m4JA+5LmRto9AAZjRff1NbQvEdzFojMuBF4bWTSasteLZwkkMdbP8XP cardno:000606445046", + # David Cliff "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC6kTpy2KaYo/Ai7xOWuKMnpi+a68Ur2fRVXuOWw+mkHH4RDPLJbU6rH19vwTg8rKRemQy8f4haenB9fyGE9VLgHXEJPsnpjTiS6dREweh8P+V3/JyjIlmznZbGLgJt6cFy4T2L5PRtEZVvmLFQw48sLOvR4fmP7qTUNuYlBf+sjbrpM2PcTMMG/QQJHBZlZQhNqJQf/1OFMVdGJ83VsxPfj9VZNFPnaWRylAJY48JscFHrPIOUVuR0yzQSrbE071N3m8NopqMc2KJgLTRRLP8puBDtsF7yPvYGmTX64LBAuV2gzl182utRP2RBa3Tzl/f0vuRAgUhO7dkHBbp2BoRmzZAtjgXgaHvzFAg/2U91oj0ceEYCLZ3nXdc/lgs6QVfDRTjJIpfdnQDJz66SE7lxLJoJ5t1b4DeWqfBbaikN3qQb4PfuSrafWCS5Z81qHjZ9L2eV22IPmGoOBfQq5ynJ2CeIapesOLTxfFXDUKoabvp30BqYpc2FtdNUSbzvlpU= davidcliff@GDS10099" ] # The office-ips below are set to the GDS office egress ips, this local var is used to whitelist inbound ssh connections From 779667e7e57e6df9162112c04479b8672926bd6d Mon Sep 17 00:00:00 2001 From: Samuel Pritchard Date: Tue, 6 Apr 2021 16:41:52 +0100 Subject: [PATCH 2/2] Space needed --- terraform/cloudinit/kali-instance.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/terraform/cloudinit/kali-instance.yaml b/terraform/cloudinit/kali-instance.yaml index 942b372..2293f10 100644 --- a/terraform/cloudinit/kali-instance.yaml +++ b/terraform/cloudinit/kali-instance.yaml @@ -10,10 +10,12 @@ users: groups: users, admin ssh_import_id: None lock_passwd: true + shell: /bin/bash ssh_authorized_keys: %{ for key in ssh-keys ~} - ${key} %{ endfor ~} + write_files: - path: /usr/local/bin/empire permissions: '0755'