Skip to content

Releases: BishopFox/sliver

v1.6.2

08 Jan 21:11
v1.6.2
016299c

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v1.6.1...v1.6.2

v1.6.1

04 Jan 20:33
v1.6.1
dc736f6

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v1.6.0...v1.6.1

v1.6.0

01 Jan 15:55
v1.6.0
704285f

Choose a tag to compare

What's Changed

Read more

v1.5.44

28 Oct 20:12
v1.5.44
9122878

Choose a tag to compare

v1.5.44

v1.5.43

19 Feb 20:00
v1.5.43
e116a5e

Choose a tag to compare

v1.5.43

v1.5.42

28 Feb 20:00
v1.5.42
85b0e87

Choose a tag to compare

Fix for DNS C2, and other small backports. Hoping to have a v1.6 release soon with many more updates!

v1.5.41

11 Jul 21:41
v1.5.41
f2a3915

Choose a tag to compare

v1.5.41

v1.5.40

20 Jun 18:32
v1.5.40
c17c378

Choose a tag to compare

⚠️ Backwards incompatible changes ⚠️

This release fixes a vulnerability (CVE-2023-34758) in the Sliver Key Encapsulation Mechanism (KEM), where improper use of Nacl Box (libsodium) could allow a MitM attacker with a copy of the implant binary to recover the session key and arbitrarily encrypt/decrypt C2 messages. Note that the Sliver KEM is only used over insecure protocols such as HTTP and DNS, and does not affect mTLS or Wireguard.

The issue was addressed by switching to a combination age for the KEM and HMAC-SHA2-256 to verify the implant.

More details: GHSA-8jxm-xp43-qh3q

Special thanks to Ting-Wei Hsieh from CHT Security Co. Ltd. for reporting the vulnerability.

v1.5.39

16 May 15:43
v1.5.39
af46878

Choose a tag to compare

Commits

  • ad53f90: Bump github.com/miekg/dns from 1.1.53 to 1.1.54 (dependabot[bot]) #1217
  • 5b22e6d: Bump modernc.org/sqlite from 1.22.0 to 1.22.1 (dependabot[bot]) #1218
  • d921c3c: Add ESET Internet Security to kwnown security processes (smeukinou) #1220
  • 2f9c84c: FIX implant generation with locale limit not compiling when not in debug mode (smeukinou) #1221
  • b5e611d: FIX windows screenshot when multiple monitors are used, and they are not exactly side-by-side (smeukinou) #1222
  • a468ec8: Allow migrate to use process names (rkervella) #1223
  • 64c40ba: Bump google.golang.org/grpc from 1.54.0 to 1.55.0 (dependabot[bot]) #1226
  • 27c6e8e: Bump golang.org/x/term from 0.7.0 to 0.8.0 (dependabot[bot]) #1227
  • d547708: Go v1.20.4 (moloch--) #1229
  • 4690430: update installer to symlink sliver/sliver-client (moloch--)
  • 38a740a: Bump golang.org/x/crypto from 0.8.0 to 0.9.0 (dependabot[bot]) #1232
  • 52daa1a: Adding support for specifying DNS resolvers through advanced options (Raf) #1235

v1.5.38

28 Apr 16:33
v1.5.38
649960a

Choose a tag to compare

Commits

  • 57ddb1a: Bump golang.org/x/crypto from 0.7.0 to 0.8.0 (dependabot[bot]) #1199
  • 8c06b83: Bump gorm.io/gorm from 1.24.7-0.20230306060331-85eaf9eeda11 to 1.25.0 (dependabot[bot]) #1200
  • ef1c034: Bump gorm.io/driver/sqlite from 1.4.4 to 1.5.0 (dependabot[bot]) #1201
  • 7479e86: Bump gorm.io/driver/mysql from 1.4.7 to 1.5.0 (dependabot[bot]) #1202
  • 77ab598: pull latest beacon or session configuration on info command even if a beacon or session is currently selected to avoid displaying outdated values after a reconfiguration (Tim Makram Ghatas) #1207
  • 9e12db9: Bump modernc.org/sqlite from 1.21.1 to 1.22.0 (dependabot[bot]) #1212
  • 3599af1: Fixed nil pointer (b0yd) #1213
  • fce0221: Add Rapid 7 (cmprmsd) #1214
  • 7522a0b: Apply XOR to protobuf raw data (rkervella) #1215
  • 7c33022: Apply XOR to dnspb and commonpb too (rkervella) #1215