{"id":17383774,"url":"https://github.com/e3prom/ruse","last_synced_at":"2025-04-15T10:05:39.319Z","repository":{"id":74891294,"uuid":"158600242","full_name":"e3prom/ruse","owner":"e3prom","description":"a secure and highly-portable reverse proxy (redirector) for your Red Team infrastructure.","archived":true,"fork":false,"pushed_at":"2019-09-04T12:16:09.000Z","size":88,"stargazers_count":34,"open_issues_count":0,"forks_count":10,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-04-15T10:05:15.030Z","etag":null,"topics":["http-listener","proxy-server","redirector","redteam","shellcode"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/e3prom.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":"AUTHORS","dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-11-21T20:04:23.000Z","updated_at":"2025-04-10T09:14:53.000Z","dependencies_parsed_at":"2023-02-26T21:30:55.024Z","dependency_job_id":null,"html_url":"https://github.com/e3prom/ruse","commit_stats":null,"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/e3prom%2Fruse","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/e3prom%2Fruse/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/e3prom%2Fruse/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/e3prom%2Fruse/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/e3prom","download_url":"https://codeload.github.com/e3prom/ruse/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":249048730,"owners_count":21204306,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["http-listener","proxy-server","redirector","redteam","shellcode"],"created_at":"2024-10-16T07:43:45.581Z","updated_at":"2025-04-15T10:05:39.299Z","avatar_url":"https://github.com/e3prom.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"![Ruse Logo](docs/images/ruse_240x122.png \"Ruse - Redirector\")\n\nRuse is secure, multi-platform, selective Reverse Proxy (or Redirector) that is\nfast and easy to deploy. It can help you concealing C2 communications, and\nreverse shells traffic using the HTTP protocol.\n\nRuse combines the core features of Python's\n[SimpleHTTPServer](https://docs.python.org/2/library/simplehttpserver.html),\nApache's\n[mod_rewrite](https://httpd.apache.org/docs/current/mod/mod_rewrite.html),\nand SSL ProxyPass, all in a single, self-contained and highly-portable\nexecutable.\n\nIt supports both plain-text HTTP and HTTPS, in a fast and easy to configure\nportable server executable. Ruse can be rapidly deployed from the command-line\nor inside a Docker container for added security.\n\n## Features\n * Runs under Linux, \\*BSD, Mac OS X, and Windows (7, Server 2008R2 and later)\n * Supports Intel x86, AMD64, ARM, ARM64 and PPC64 (little-endian)\n * No external dependencies (outside the Go standard library)\n * HTTP and HTTPS (SSL/TLS) support\n * Support IPv4 and IPv6 addressing\n * Selective Reverse Proxying based on:\n   * User-Agent header field, matching:\n     * Exact String(s)\n     * Regular Expression(s)\n   * Client's network (CIDR matching)\n * Support for VirtualHosts\n * Serves static files (with optional directory listing)\n * HTTP Logging\n \n## Use-cases\nRuse help you overcome multiple challenges, such as:\n * Hiding your HTTP listeners from Incident Response teams.\n * Load-balancing to multiple remote listeners.\n * Simultaneously serving static files and listening for reverse HTTP shellcodes on a single port.\n * Leveraging domain-fronting by exposing the redirector from a trusted location or domain.\n * Pivoting traffic post-exploitation by proxying reverse HTTP shellcodes.\n * Easily [proxy your Metasploit's reverse_http(s) payloads](docs/msf-reverse-https.md).\n * Selectively [proxy your reverse shellcodes traffic with vhosts and regex matching](docs/virtualhost-with-regex.md).\n\nIf you're doing Red Team operations or you may simply want to hide your HTTP\nlisteners during an engagement, Ruse may be for you!\n\n## Building from source\nTo build Ruse from source, simply enter `make`, it will build the `ruse`\nexecutable in the current working directory:\n```\n$ make\ngo build -o ruse -v src/ruse/main.go\n```\n\nAlternatively, you can build Ruse inside a Docker container using the `make\ncontainer` command:\n```\n$ make container\nbuilding: bin/amd64/ruse\n[...]\n```\n\n## Running from the command-line\nRuse can run unprivileged from a terminal:\n```\n$ ./ruse -c conf/ruse.conf\nStarting HTTP Server on localhost:8000\n```\nBy default Ruse ships with a [basic configuration file](conf/ruse.conf)\nwhich only allows plain-text HTTP connections from localhost on port tcp/8000.\nIt's also configured to proxy traffic from metasploit's reverse HTTP payloads\nby exact matching their default User-Agent header fields.\n\n## Building and running under Docker\nRuse can also run under a Docker container, and thus in a matter of seconds.\nEnter the `make container` command to build the Docker image and to push it to\nyour local registry. Once the image has been created, simply start a new\ncontainer like demonstrated in the below example:\n```\n$ make container\n[...]\n$ docker run -v `pwd`/conf/ruse.conf:/etc/ruse.conf -p 127.0.0.1:8000:8000/tcp registry/ruse-amd64:1.0.2\nStarting HTTP Server on localhost:8000\n```\n\n## Binaries\nIf you do not want to build Ruse from source, you can directly download the binaries below:\n\n### Releases\n| Filename                                                                                                                | OS                         | Architecture | Version | SHA256 Checksum                                                             |\n| ----------------------------------------------------------------------------------------------------------------------- | -------------------------- | ------------ | ------- | --------------------------------------------------------------------------- |\n| [ruse-1.0.2-linux-debian-amd64.deb](//github.com/e3prom/ruse/releases/download/1.0.2/ruse-1.0.2-linux-debian-amd64.deb) | Linux Debian (derivatives) | x86-64       | 1.0.2   | \u003csub\u003e63b0f3fff7dd0bfa506b2623d1690d3fe9fc69ec15737a235f0c8712764a4c39\u003c/sub\u003e |\n| [ruse-1.0.2-linux-aarch64.tar.xz](//github.com/e3prom/ruse/releases/download/1.0.2/ruse-1.0.2-linux-aarch64.tar.xz)     | Linux (Generic)            | AArch64      | 1.0.2   | \u003csub\u003e0ae13d43fc1279afb330116d4f16e894907f445413617823464df06d52ef45ad\u003c/sub\u003e |\n| [ruse-1.0.2-win-amd64.zip](//github.com/e3prom/ruse/releases/download/1.0.2/ruse-1.0.2-win-amd64.zip)                   | Windows (amd64)            | x86-64       | 1.0.2   | \u003csub\u003e0615349405a47c59984827cf4d8e60480df274d25f430db70e8c2c1c0fb7dbb5\u003c/sub\u003e |\n| [ruse-1.0.2-win-i386.zip](//github.com/e3prom/ruse/releases/download/1.0.2/ruse-1.0.2-win-i386.zip)                     | Windows (i386)             | x86-32       | 1.0.2   | \u003csub\u003ee34566725a0a31b37e9d66a84123f2b667185fb3862d1db4208a35feed6f0ba9\u003c/sub\u003e |\n| [ruse-1.0.2-darwin-amd64.zip](//github.com/e3prom/ruse/releases/download/1.0.2/ruse-1.0.2-darwin-amd64.zip)             | Mac OS X                   | x86-64       | 1.0.2   | \u003csub\u003e52e9804a413db8dca6470bcd13f55dd683e1559aa32c89107b892d98457c4ab3\u003c/sub\u003e |\n\n## Configuring\nTo configure the redirector, edit and copy the [ruse.conf](conf/ruse.conf)\nconfiguration file in the `/conf` directory to `/etc/ruse.conf`. The latter is\nthe default configuration file path, and can be manually specified using the\ncommand-line `-c` switch. Also Ruse reloads its configuration file when it\nreceives the SIGHUP signal.\n\nThe configuration file is in JSON format, and accepts various configuration\noptions, please see the tables below for further reference:\n\n### Configuration file - Primary Keys\n| Key Name    | Type     | Default value(s) | Supported value(s) / Description       |\n| ----------- | -------- | ---------------- | -------------------------------------- |\n| Hostname    | optional | localhost        | valid hostname or IPv4/IPv6 address[¹] |\n| Protocols   | optional | plain            | plain, tls                             |\n| Port        | optional | 8000             | 0-65535                                |\n| TLSPort     | optional | 8443             | 0-65535                                |\n| TLSKey      | optional | server.key       | a valid PEM encoded private key file   |\n| TLSCert     | optional | server.crt       | a valid X.509 certificate chain file   |\n| Root        | optional | /var/www         | root directory for static content      |\n| Index       | optional |                  | directory index file[²]                |\n| Verbose     | optional | 0                | 0(off), 1(low), 2(medium), 3(high)     |\n| Logfile     | optional |                  | readable and writable log file         |\n| Proxy       | optional |                  | see Proxy array's keys table below     |\n| VirtualHost | optional |                  | see VirtualHost array's keys table     |\n\n#### ¹ IP Addresses\n[¹]:#-ip-addresses\nEnter a valid IP address to listen on. IPv6 addresses must be enclosed in\nsquare brackets `[]`. Use the special values `0.0.0.0/0` or `[::0]` to listen\non all interfaces.\n\n#### ² Directory Index\n[²]:#-directory-index\nUse an empty `\"\"` string value as the index page to enable recursive directory\nlisting.\n\n----\n### Configuration file - Proxy Array's Keys\n| Key Name    | Type     | Default value(s) | Supported value(s) / Description        |\n| ----------- | -------- | ---------------- | --------------------------------------- |\n| Type        | optional |                  | only 'reverse' is actually supported    |\n| Description | optional |                  | administrative description of the proxy |\n| Match       | required |                  | see Match object's keys table below     |\n| Target      | required |                  | valid http:// or https:// schemes URI   |\n\n----\n### Configuration file - Match Object's Keys\n| Key Name  | Type     | Default value(s) | Supported value(s) / Description                             |\n| --------- | -------- | ---------------- | ------------------------------------------------------------ |\n| UserAgent | optional |                  | an array of User-Agent string(s) or Regular Expression(s)[³] |\n| Network   | optional |                  | an array or list of network(s) in CIDR notation[⁴]           |\n\n### Configuration file - VirtualHost Array's Keys\n| Key Name | Type     | Default value(s) | Supported value(s) / Description       |\n| -------- | -------- | ---------------- | -------------------------------------- |\n| Hostname | optional | localhost        | valid hostname or IPv4/IPv6 address[¹] |\n| Root     | optional |                  | root directory for static content      |\n| Index    | optional |                  | directory index file[²]                |\n| Proxy    | optional |                  | see Proxy array's keys table above     |\n\n\n#### ³ Regular Expression Matching\n[³]:#-regular-expression-matching\nYou can leverage [Regular\nExpressions](https://en.wikipedia.org/wiki/Regular_expression) for matching\nHTTP User-Agent header field's values. Use the special tilde `~` character\nfollowed by a valid regular expression.\n\n#### ⁴ CIDR Invert Matching\n[⁴]:#-cidr-invert-matching\nYou can negate CIDR networks matching using the exclamation mark `!` character.\n\n## Contributing\nIf you find this project useful and want to contribute, we will be more than\nhappy to receive your contribution in the form of code, documentation and even\nbug reports. To contribute code, feel free to fork this project and send your\npull request(s).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fe3prom%2Fruse","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fe3prom%2Fruse","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fe3prom%2Fruse/lists"}