[ Beneath the Waves ]

She Wore A Mirrored Mask

article by Ben Lincoln

 

This article describes security testing-related software whose use may be restricted or prohibited in your place of residence or your workplace. The penalties for violating laws and regulations regarding security testing-related tools can be severe. Ensuring that you are allowed to use this software is your responsibility.

The software described is a "preview release" which is not yet feature-complete and which is has not been tested on a variety of systems. Even if you are allowed to use the software, you should do so with caution, on systems which can be easily restored to their previous state if they are damaged.

Table of contents

  1. Introduction — what is She Wore A Mirrored Mask?
  2. Known Limitations
  3. Future Releases and Planned Features
  4. If You Would Like To Contribute
  5. Artwork and Historical Screenshots
  6. Downloads

Introduction — what is She Wore A Mirrored Mask?

She Wore A Mirrored Mask is a Python-based lightweight webserver specifically designed for penetration-testing use.

The current release is only a tiny subset of its full potential — it is limited for the most part to working in conjunction with On The Outside, Reaching In, which uses She Wore A Mirrored Mask to store malicious XML documents and fragments, as well as the staging of exfiltrated content.

The fact that even this limited preview includes functionality related to masquerading as a variety of other webservers should provide some insight into what She Wore A Mirrored Mask is intended to become someday: a service which can be deployed on a target network where it will appear to be a benign, ordinary component, but offer the following hidden capabilities (and more) to its true owner:

  1. Data exfiltration
  2. Hidden port-forwarding
  3. Hidden HTTP proxying
  4. Cookie-catching

In addition, it should be able to serve reverse-engineers well in the lab, offering canned/stub responses to client requests directed to it via DNS, IP, ARP spoofing, or other means.

Known Limitations

In the interest of making a potentially-useful tool available sooner rather than later, the current release of She Wore A Mirrored Mask is a preview which has significant missing functionality compared to the intended "feature-complete" alpha release of the future:

Future Releases and Planned Features

Some of the things I'd like to include in future releases (not in any particular order):

If You Would Like To Contribute

Please get in touch with me using the Contact form.

Artwork and Historical Screenshots

Artwork and Historical Screenshots
[ Screenshot of the highest-resolution banner ]
Screenshot of the highest-resolution banner
[ Higher-resolution version of the icon/banner sketch ]
Higher-resolution version of the icon/banner sketch
     

 

 

Downloads

She Wore A Mirrored Mask is distributed along with On The Outside, Reaching In, so if you are planning on using them together, you just need to download that package. However, if you would like to take advantage of the ability to run She Wore A Mirrored Mask on a separate system, a standalone package can be downloaded below.

 
Download
File Size Version Release Date Author
She Wore A Mirrored Mask 265 KiB 0.3 2014-07-20 Ben Lincoln
 
 
Download
File Size Version Release Date Author
She Wore A Mirrored Mask 249 KiB 0.2 2014-06-15 Ben Lincoln
 
 
[ Page Icon ]